From: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
To: buildroot@busybox.net
Subject: [Buildroot] [RFC 0/2] script to find package licenses
Date: Thu, 4 Aug 2016 18:33:35 +0200 [thread overview]
Message-ID: <20160804183335.0947f9a9@free-electrons.com> (raw)
In-Reply-To: <1470320164-8241-1-git-send-email-rahul.bedarkar@imgtec.com>
Hello,
On Thu, 4 Aug 2016 19:46:02 +0530, Rahul Bedarkar wrote:
> Legal information is a kind of thing that we can't automate completely.
> But we want it to be correct when new package is added or version bumps.
>
> This patch set attempts to add a script to find license information from
> package source files to verify or correct legal info for buildroot packages.
>
> Legal information may get outdated with version bumps or even may not get
> correct in first place if source package does not provide any license files.
> In such cases, we need to look into file header to get that information.
> But it could be very difficult if there are number of source files.
>
> find-licenses script scans package source files for known licenses to
> find under which license package is released. It aggregates license
> information for all source files found in a package.
>
> For finding license, we rely on file's license header. Generally
> most of packages use standard license headers which helps us to detect
> license of packages.
>
> Currently it supports notable licenses. But we can later add other
> licenses based on regx.
>
> Script outputs licenses found on standard output file-wise, directory-
> wise and final aggregation of all licenses found. It also lists files
> which don't have license header. Directory-wise license listing will be
> useful when different components are licensed under different license.
>
> Since final license list is just aggregation of licenses found for all
> source files, we can not surely say if package is dual or
> multi-licensed or different components are licensed under different
> license. That's why we can't use final license list directly in our
> package .mk file, but it at least helps us to find or verify license
> information quickly.
Thanks for this proposal. However, there are already some tools that do
the same thing I believe. I'm thinking especially at the tools used by
the Fossology project (https://www.fossology.org/). It is surely more
complicated to install and use that your Python script, but it is also
a lot more complete, and even more importantly: maintained by other
people.
Best regards,
Thomas
--
Thomas Petazzoni, CTO, Free Electrons
Embedded Linux, Kernel and Android engineering
http://free-electrons.com
next prev parent reply other threads:[~2016-08-04 16:33 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-08-04 14:16 [Buildroot] [RFC 0/2] script to find package licenses Rahul Bedarkar
2016-08-04 14:16 ` [Buildroot] [RFC 1/2] scripts: add a script to find licenses of package Rahul Bedarkar
2016-08-04 14:16 ` [Buildroot] [RFC 2/2] new make target <PKG>-find-licenses Rahul Bedarkar
2016-08-04 16:33 ` Thomas Petazzoni [this message]
2016-08-05 2:03 ` [Buildroot] [RFC 0/2] script to find package licenses Khem Raj
2016-08-05 7:42 ` Rahul Bedarkar
2016-08-05 7:53 ` Thomas Petazzoni
2016-08-08 17:42 ` Yann E. MORIN
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160804183335.0947f9a9@free-electrons.com \
--to=thomas.petazzoni@free-electrons.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox