Hello Neil and everyone else on this list!

I really should have been subscribed to this list since my first day as starting as the new licensing & compliance manager of the FSF over a year ago.

>
help that person collect the evidence they need and get set
up properly to do the usual easy things that might yield compliance?

Do you have standard list of questions / pieces of evidence you tend to collate 
in your triage process, which could be used as a framework here?

I can share with you all a little of what we do in our triage process.

Please note that this does not address all of the kinds of compliance work the FSF does. How we approach GPL violations happening on free software projects or from members of the free software community will often be different, at least in terms of the kinds of information we collect.

 free software projects or community
These are all of the steps we take before we contact the company suspected of violating the terms of the GPL on FSF suspected of violating FSF copyright. Please note that when the party suspected of violating

## Step 1

I often ask the person submitting a report to help me fill in as much of the information as they can on this page:

* <http://www.gnu.org/licenses/gpl-violation.html>

I usually check to see if we have had any past correspondence with the organization suspected of violating.

If it is clear that the FSF is not a copyright holder on the software in question, then I will encourage them to collect the information in the above and to contact the appropriate copyright holder(s).


## Step 2: Confirm suspected violation

The next step is to try to do an initial confirmation.

When all we can find is a binary or installation file, you sometimes need to do a little digging. Some of the tools that can be helpful include:

* <https://gitorious.org/gpl-compliance-tools/gpl-compliance-scripts/>
* file, tree, find, less, strings, grep, dtrx, wine, mount, unsquashfs, cramfsswap, cpio, gzrecover, dd, ld, and several other programs are all in my rotation.

And of course, sometimes the violation report isn't on a failure to provide source. It could relate to not providing the corresponding source, installation information, etc. Or, other times it is a failure to provide a copy of the license or make appropriate notifications, etc.

## Step 3: Gather additional info

Once I've done a basic confirmation, I will then open a compliance case. I will inform the person who submitted it that I am doing so, explain to them our approach and that we will let them know of any outcome, and ask them to let us know of any response or future correspondence they have with the company, and I often ask if the current compliance case is being discussed publicly or with other parties.


I then gather some more info on the company suspected of violating the GPL. This includes:

* corporate structure and jurisdictions of operation
* upstream distributor/manufacturer of device/system in question
* existing policies or publications (blog posts, etc) w.r.t to FLOSS
* and I'll do a quick search of the web for discussions about the company and the product/software in question and for any info relating to past compliance enforcement work done against the company.


In general, I try to document everything I am doing, files I've saved (which sometimes includes relevant web pages, manuals, etc), the amount of time I work on the report, and of course any correspondences I have. Often a violation report will come in on a particular version of software, and if there are newer or older versions, I will sometimes try to capture information on these or save some of them as I go.


Anyhow, that is basically my triage process. I hope that this is a helpful answer, even if it is a little verbose. :-)

Josh

--
Joshua Gay
Licensing & Compliance Manager
Free Software Foundation
http://www.fsf.org/licensing

Reply via email to