My comments are inline, starting with MW (my email client doesn't support
inline comments really well).

 -----Alkuperäinen viesti-----
Lähettäjä: Dan Stangel [mailto:[email protected]] 
Hi Martin,

> Examples:
> 
> - Fossology finds matches for GPLv2 from all files licensed with 
> alternative licenses (e.g. MIT or GPLv2) in a way, where the licensee 
> may choose which license to apply: it may well be that a project under 
> Mozilla Public License (MPL) uses these files. There is no 
> incompatibility, since MIT is compatible with MPL.

-Are you saying that we do not report dual-licensed files as dual-licensed?
-That is, a file that "Ma be licensed as GPL or ___ at the user's
-discretion"?  If so that is correct.  But if you're saying that some MIT
-licensed files are being reported by FOSSology as GPL, we would like to
know
-more about that to try and fix it.

MW: It is just an example that shows that there can be many GPL reports by
Fossology in an e.g. Apache-licensed package and the package can still be
compliant (because the files are dual licensed as described above).
Fossology just finds a GPL-hit. (We have noted that some incorrectly believe
this to indicate that the package would be incompliant due to this.) We
think Fossology does this correctly.


> - Fossology finds matches of LGPLv2.1 in files which are licensed with 
> MIT, if there is e.g. text "an alternative library xxx is also 
> available, licensed under LGPL...."

-This situation MAY improve somewhat in the future when we introduce the
"F1"
-algorithm sometime late this year or early next year.  Bob could probably
-say more about this.  But of course the more complex the language or
-references to other projects, etc, the harder it becomes to make the right
-choice. 

MW: This was just an observation from our part (I think Fossology does this
correctly). Hopefully any changes won't lead to possible missed
license-references (since license references in files are not necessarily in
standard formats). I would prefer having a good tool to review license etc.
matches over to having a tool that misses licenses but that "guesses" 95 %
correct results. Of course, if the advanced algorithm was an additional
layer, you could have the certainty of the lower layer (text-match + manual
review) and then compare those results with the advanced algorithm.

> - Fossology finds matches of GPLv2 from files containing an exception 
> from GPLv2: "However, this file may be used under X License in Project 
> Y".

Yes, guilty as charged.  This is another hard problem to solve, not sure if
our newer algorithms will fix this. 

MW: I don't necessarily think there is anything to fix. 

> ...
> 2. Fossology does not find or search for copyright notices. This means 
> that a file with "Copyright 2009 XXXX. All rights reserved." and 
> without any license notice, is not picked-up by Fossology. If the 
> copyright holder is a third party in relation to the project, it could 
> well be that there is no license to copy, redistribute or modify at 
> all. We have benchmarked Fossology against manual grep-searches and 
> third party checking tools and have found that this is a repeated 
> issue. This is, as we see it, the most important lack of Fossology, 
> however, we anticipate that new versions of Fossology will include 
> search agents that allow for searching of copyright notices too.

-Indeed this should be fixed with FOSSology version 1.2, due out later this
-year.  It is supposed to include an explicit copyright detector that would
-find these instances and report on them separately from licenses.

MW: Of course reviewing all copyright notice matches would be quite a task.
It would be useful, if there could be a possibility to review copyright
notices from files in which there were no license match at all. (We could
find non-found licenses.) Also, if these copyright notices (with no license
matches in the same file) could be grouped by holder, it could help. E.g. I
find it legally less concerning to have a copyright notice of Linus Torvalds
in the Linux-kernel with no license reference in that file (there is
multiple files with license references and general license notices by him)
in contrast to a single file with a XXXX Company copyright without any
license reference.

> 3. Programmed Licenses do not contain all possible license texts. E.g.
> the PHP license (PHP 4.4.8) was not matched at all by Fossology 1.0.0RC1.

-This is a concern.  Are you saying that FOSSology did not report any
license
-whatsoever where a PHP license was indicated?  Or did FOSSology report, for
-example, a "BSD" license?   

-In fact with 1.0 we shipped the PHP license version 3.0 as one of our
-license templates.  In some circumstances, FOSSology can mis-identify this
-if some parts of the license text are not included or are modified.  But we
-should have found this.  

MW: This license was not identified at all, not as PHP, not as BSD or
anything else either. The package name: php-4.4.8.tar.bz2. The file /
php-4.4.8/ main/ main.c includes an example of the not found license.

-Thanks again for your excellent write-up.  Recognizing that the system is
-not flawless, please let me know if we should pursue filing bugs to address
-the situations you described above.  

MW: I think Fossology is great. Hopefully you can benefit from our comments.
We also recognise it is not flawless, but when correctly used it improves
and speeds up license checking and as such promotes the common interest. 

MW: My point really is that one should use Fossology correctly, otherwise
people start thinking (incorrectly) either i) all or almost all open source
packages are incompliant or ii) Fossology does not work. 


_______________________________________________
fossology mailing list
[email protected]
http://fossology.org/mailman/listinfo/fossology

Reply via email to