Hi Martin,

On Mon May 4, 2009 at 02:05 AM -0700, Martin von Willebrand wrote:
> ...
> I have generated notes on how we use Fossology and what issues there 
> are to consider. This will be our internal instruction, but I hope 
> others can benefit of it too. I would also appreciate any comments and
suggestions.

Your "Lawyer's Notes on Using FOSSology" provide us with a really good
example of how FOSSology is used in the real world to perform license
analysis.  I really appreciate your work in writing this up and sharing it
here!

I have a few comments and questions which I'll address in line...

> ...
> Important Considerations
> 
> 1. Fossology is a text-search tool, it finds exact and non-exact 
> matched to license texts. It does NOT search for the legal license 
> under which a file is licensed, since there is no uniform way to 
> report such information. That conclusion will need to be done by the 
> person using Fossology. The License-view of a package is correct 
> vis-à-vis the text- search, but typically misleading, inaccurate, or 
> even incorrect vis-à-vis the licenses that really are applicable to 
> the package or the files. See examples below.

This is exactly right.  There is no way (none we've found at least) to
"automatically" make a determination of a file's license.  The best we can
hope to do is report on the most likely candidate(s) based on the artifacts
we find in the file.

> Examples:
> 
> - Fossology finds matches for GPLv2 from all files licensed with 
> alternative licenses (e.g. MIT or GPLv2) in a way, where the licensee 
> may choose which license to apply: it may well be that a project under 
> Mozilla Public License (MPL) uses these files. There is no 
> incompatibility, since MIT is compatible with MPL.

Are you saying that we do not report dual-licensed files as dual-licensed?
That is, a file that "Ma be licensed as GPL or ___ at the user's
discretion"?  If so that is correct.  But if you're saying that some MIT
licensed files are being reported by FOSSology as GPL, we would like to know
more about that to try and fix it.

> - Fossology finds matches of LGPLv2.1 in files which are licensed with 
> MIT, if there is e.g. text “an alternative library xxx is also 
> available, licensed under LGPL….”

This situation MAY improve somewhat in the future when we introduce the "F1"
algorithm sometime late this year or early next year.  Bob could probably
say more about this.  But of course the more complex the language or
references to other projects, etc, the harder it becomes to make the right
choice. 

> - Fossology finds matches of GPLv2 from files containing an exception 
> from GPLv2: “However, this file may be used under X License in Project 
> Y”.

Yes, guilty as charged.  This is another hard problem to solve, not sure if
our newer algorithms will fix this. 

> ...
> 2. Fossology does not find or search for copyright notices. This means 
> that a file with “Copyright 2009 XXXX. All rights reserved.” and 
> without any license notice, is not picked-up by Fossology. If the 
> copyright holder is a third party in relation to the project, it could 
> well be that there is no license to copy, redistribute or modify at 
> all. We have benchmarked Fossology against manual grep-searches and 
> third party checking tools and have found that this is a repeated 
> issue. This is, as we see it, the most important lack of Fossology, 
> however, we anticipate that new versions of Fossology will include 
> search agents that allow for searching of copyright notices too.

Indeed this should be fixed with FOSSology version 1.2, due out later this
year.  It is supposed to include an explicit copyright detector that would
find these instances and report on them separately from licenses.

> 3. Programmed Licenses do not contain all possible license texts. E.g.
> the PHP license (PHP 4.4.8) was not matched at all by Fossology 1.0.0RC1.

This is a concern.  Are you saying that FOSSology did not report any license
whatsoever where a PHP license was indicated?  Or did FOSSology report, for
example, a "BSD" license?   

In fact with 1.0 we shipped the PHP license version 3.0 as one of our
license templates.  In some circumstances, FOSSology can mis-identify this
if some parts of the license text are not included or are modified.  But we
should have found this.  

Perhaps it goes without saying, but everyone is welcome and encouraged to
file bugs for this sort of shortcoming.

> ...

Thanks again for your excellent write-up.  Recognizing that the system is
not flawless, please let me know if we should pursue filing bugs to address
the situations you described above.  

Dan


_______________________________________________
fossology mailing list
[email protected]
http://fossology.org/mailman/listinfo/fossology

Reply via email to