Hello Neil and everyone else on this list!
I really should have been subscribed to this list since my first day as
starting as the new licensing & compliance manager of the FSF over a
year ago.
>
help that person collect the evidence they need and get set
up properly to do the usual easy things that might yield compliance?
Do you have standard list of questions / pieces of evidence you tend to collate
in your triage process, which could be used as a framework here?
I can share with you all a little of what we do in our triage process.
Please note that this does not address all of the kinds of compliance
work the FSF does. How we approach GPL violations happening on free
software projects or from members of the free software community will
often be different, at least in terms of the kinds of information we
collect.
free software projects or community
These are all of the steps we take before we contact the company
suspected of violating the terms of the GPL on FSF suspected of
violating FSF copyright. Please note that when the party suspected of
violating
## Step 1
I often ask the person submitting a report to help me fill in as much of
the information as they can on this page:
* <http://www.gnu.org/licenses/gpl-violation.html>
I usually check to see if we have had any past correspondence with the
organization suspected of violating.
If it is clear that the FSF is not a copyright holder on the software in
question, then I will encourage them to collect the information in the
above and to contact the appropriate copyright holder(s).
## Step 2: Confirm suspected violation
The next step is to try to do an initial confirmation.
When all we can find is a binary or installation file, you sometimes
need to do a little digging. Some of the tools that can be helpful include:
* <https://gitorious.org/gpl-compliance-tools/gpl-compliance-scripts/>
* file, tree, find, less, strings, grep, dtrx, wine, mount, unsquashfs,
cramfsswap, cpio, gzrecover, dd, ld, and several other programs are all
in my rotation.
And of course, sometimes the violation report isn't on a failure to
provide source. It could relate to not providing the corresponding
source, installation information, etc. Or, other times it is a failure
to provide a copy of the license or make appropriate notifications, etc.
## Step 3: Gather additional info
Once I've done a basic confirmation, I will then open a compliance case.
I will inform the person who submitted it that I am doing so, explain to
them our approach and that we will let them know of any outcome, and ask
them to let us know of any response or future correspondence they have
with the company, and I often ask if the current compliance case is
being discussed publicly or with other parties.
I then gather some more info on the company suspected of violating the
GPL. This includes:
* corporate structure and jurisdictions of operation
* upstream distributor/manufacturer of device/system in question
* existing policies or publications (blog posts, etc) w.r.t to FLOSS
* and I'll do a quick search of the web for discussions about the
company and the product/software in question and for any info relating
to past compliance enforcement work done against the company.
In general, I try to document everything I am doing, files I've saved
(which sometimes includes relevant web pages, manuals, etc), the amount
of time I work on the report, and of course any correspondences I have.
Often a violation report will come in on a particular version of
software, and if there are newer or older versions, I will sometimes try
to capture information on these or save some of them as I go.
Anyhow, that is basically my triage process. I hope that this is a
helpful answer, even if it is a little verbose. :-)
Josh
--
Joshua Gay
Licensing & Compliance Manager
Free Software Foundation
http://www.fsf.org/licensing