Hello all Fossologists
We have been using Fossology as a text-search tool in license checking and
we have found it very useful. (We are working for Validos, an initiative in
which a number of companies validate FOSS-packages in a unified manner and
share the results of validation, thus avoiding repeated validation of the
same package by different companies.) Thanks to everybody for the tool and
its continued development. As we are lawyers we cannot that well contribute
to the development itself, but we are happy to contribute in other ways.
I have generated notes on how we use Fossology and what issues there are to
consider. This will be our internal instruction, but I hope others can
benefit of it too. I would also appreciate any comments and suggestions.
We have e.g. noticed that many do not necessarily understand that Fossology
is actually a robust text-search tool that is very useful in license
checking, but the tool doesn't know the licenses files are licensed under,
it just searches for built-in texts.
Best,
Martin
- start of notes -
Lawyer's Notes on Using Fossology in License Checking
(based on Fossology 1.0.0RC1)
Validation of FOSS Packages
A validation process for a FOSS-package aims to ensure satisfactory
knowledge on license terms of a FOSS-package. The process includes gathering
information and then processing it. This note handles the gathering of
information with Fossology together with some very preliminary processing.
Fossology is a GPL-licensed tool available from fossology.org. (In addition
to Fossology, manual inspection of project web pages and the root of the
distribution package and some files are typically necessary. Also,
contacting projects can be an option.)
Information is gathered to answer the following questions:
- What is the license the project uses for out-licensing (i.e. the
main license)? Is the license and its version satisfactorily clear? (Are
there any doubts?)
- What components and files does the packages consist of? How are
they licensed? Are these licenses compatible with the main license? (Are
there any doubts?)
Levels of Diligence in Gathering Licensing Information on FOSS Packages
Information can be gathered in several ways, but three levels of depth can
be noted:
1. Inspecting project web pages, documentation and root of the
distribution package
2. Conducting a text search on the source code of the package with an
aim to find licensing relevant information from the package. Different
options for doing this are e.g.:
a. Fossology is probably the most robust tool for text-searching
b. Grep-search can be used for collection of some keywords or phrases
which then are manually sorted out
3. Comparing source code against an existing database of source code
including licensing information collected earlier. This is offered by e.g.
Black Duck or Palamida.
Fossology
As for different levels of diligences for gathering information we have
deemed the text-based search on licensing information from the source code
(such as Fossology) suitable for our needs. It aims to collect the
information the licensor is passing on. It assumes that the licensor or
somebody earlier in the chain has not altered the information on purpose to
become incorrect, incomplete or misleading. However, since there is no
practical way to totally avoid incorrect licensing information, we have
deemed text-based search to be a satisfactory solution for our needs.
Fossology is essentially a text-search tool which automates the search
process and produces a result based on the search algorithm and a set of
license texts, license attachment clauses and certain phrases ("Programmed
Licenses") that have been added to Fossology at build stage. The
search-algorithm matches exact results _and_ non-exact results from the
searched package against the Programmed Licenses. Non-exact results are
shown with a percentage.
We have found Fossology to be a reliable tool _in what it does_ (in the
situations we have reviewed it). See below for important considerations.
Important Considerations
1. Fossology is a text-search tool, it finds exact and non-exact matched to
license texts. It does NOT search for the legal license under which a file
is licensed, since there is no uniform way to report such information. That
conclusion will need to be done by the person using Fossology. The
License-view of a package is correct vis-à-vis the text-search, but
typically misleading, inaccurate, or even incorrect vis-à-vis the licenses
that really are applicable to the package or the files. See examples below.
Examples:
- Fossology finds matches for GPLv2 from all files licensed with alternative
licenses (e.g. MIT or GPLv2) in a way, where the licensee may choose which
license to apply: it may well be that a project under Mozilla Public License
(MPL) uses these files. There is no incompatibility, since MIT is compatible
with MPL.
- Fossology finds matches of LGPLv2.1 in files which are licensed with MIT,
if there is e.g. text "an alternative library xxx is also available,
licensed under LGPL...."
- Fossology finds matches of GPLv2 from files containing an exception from
GPLv2: "However, this file may be used under X License in Project Y".
Conclusion: Fossology is a good tool, but its results need to be analysed by
a person knowledgeable in e.g. copyright matters and open source. Beware of
the typical misconception that the License-view would show the licensing
situation of the package or its files. Most packages are far better
compliant than based on the Fossology License-view on all text-matches.
2. Fossology does not find or search for copyright notices. This means that
a file with "Copyright 2009 XXXX. All rights reserved." and without any
license notice, is not picked-up by Fossology. If the copyright holder is a
third party in relation to the project, it could well be that there is no
license to copy, redistribute or modify at all. We have benchmarked
Fossology against manual grep-searches and third party checking tools and
have found that this is a repeated issue. This is, as we see it, the most
important lack of Fossology, however, we anticipate that new versions of
Fossology will include search agents that allow for searching of copyright
notices too.
3. Programmed Licenses do not contain all possible license texts. E.g. the
PHP license (PHP 4.4.8) was not matched at all by Fossology 1.0.0RC1.
It is not possible to include all possible license texts into Fossology,
therefore you can never get all matches _directly_ connected to the relevant
licenses. However, copyright notice collection will probably solve this
issue. Another way to solve this is using short phrase searches including
very generic terms, such as (copyright, copy, redistribute, license etc.).
We currently accept this issue in waiting of the copyright notice
search-agent.
Since Fossology searches for non-exact matches too, this issue is less
important. However, at some point, non-exact matches are not found anymore
(we are not exactly sure, when this happens).
Process to Use Fossology
(This assumes that the package has been processed by Fossology.)
1. Establish main license (or anticipated main license) from project
web pages and package root.
2. Look at the license-view page and start reviewing found licenses, as
follows:
a. Skip those matches that match with the main license (check a few)
b. Skip those matches that are clearly compatible with the main license
c. Review manually (easiest to do via Fossology interface) each other
found license
d. Review manually (easiest to do via Fossology interface) each found
phrase
e. If there are licenses that require copyright-holder level attention
(marketing clauses, attribution clauses), collect those
f. Collect are the license documents that require publication in
documentation or similar (something more than just retaining and not
changing)
1. Refer a file that already includes these,
2. Refer all files, in which these are found, and/or
3. Generate a file into which these are copied.
Draft version by Martin von Willebrand, 4 April 2009
- end of notes -
Martin von Willebrand, Attorney
HH Partners, Attorneys-at-law Ltd
Mannerheimintie 14 A
P.O. Box 232, 00101 Helsinki
Tel: +358 9 177 613, Fax: +358 9 653 873
GSM: +358 40 770 1818
<mailto:[email protected]>
[email protected]
<http://www.hhpartners.fi> www.hhpartners.fi
_______________________________________________
fossology mailing list
[email protected]
http://fossology.org/mailman/listinfo/fossology