Git development
 help / color / mirror / Atom feed
From: Todd Zullinger <tmz@pobox.com>
To: "D. Ben Knoble" <ben.knoble@gmail.com>
Cc: Sam Reis <sam@opencanopy.dev>,
	Sebastian Thiel <sebastian.thiel@icloud.com>,
	Scott Chacon <schacon@gmail.com>,
	Junio C Hamano <gitster@pobox.com>,
	Scott Chacon <scott@gitbutler.net>,
	git@vger.kernel.org
Subject: Re: [PATCH 0/4] faster SHA-1 collision detection
Date: Sat, 10 Oct 2026 11:37:21 -0400	[thread overview]
Message-ID: <20261010153721.943RqWnW@teonanacatl.net> (raw)
In-Reply-To: <CALnO6CAEcjieW48DkA9Pt1eqZ5hctwihmTXMxZ29YBrmzrp1QA@mail.gmail.com>

D. Ben Knoble wrote:
> On Fri, Oct 9, 2026 at 4:37 PM Todd Zullinger <tmz@pobox.com> wrote:
>> Fedora's Git package has:
>>
>>     BSD-3-Clause AND GPL-2.0-only AND GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT
> 
> Oh, curious! Where are the (using Gentoo identifiers for the moment)
> BSD and LGPL-2.1+ sources? I guess I assume by looking at our COPYING
> that the GPL-2+ came from contributions that said they were willing to
> be 2+?

There are various bits of code imported that are under
difference licenses, among other things.  The code in
reftable/ is BSD-3-Clause (using the SPDX naming), for
example, while xdiff/xhistogram.c is BSD-3-Clause and/or
EDL-1.0 while most of the rest of it is LGPL-2.1-or-later;
ewah/ is GPL-2.0-or-later; compat/obstack.[ch] and
compat/regex/ are also LGPL-2.1-or-later.

I used the perl licensecheck tool¹ to generate the initial
list, then reviewed it and filtered out some bits from the
test suite which are not shipped in the binary packages for
Fedora.

The command to do that is (without the filtering of any
code):

    find -type f -exec licensecheck --shortname-scheme spdx {} + |
    grep -v 'UNKNOWN$' | LANG=C sort >licensecheck

A more complete analysis would require reviewing all of the
files which are UNKNOWN to ensure none have a copyright that
licensecheck simply didn't find (or isn't in the file but
can be found from the git history).  I was a bit lazy and
didn't do all of that work. :)

> Anyway, thanks all! I'll assume the Gentoo maintainers knew what they
> were doing :)

Yeah, I've found most distribution packagers try to be
diligent about this.  Though it can be a somewhat tedious
tasks and can change if the distribution switches from
expecting packages to list the "effective" license to some
other method.

Fedora used to do (or allow) that license simplification,
e.g.: boiling down our distributing Git to GPL-2-only, but
clarified things a number of years ago to not do so.  It
ends up slightly easier to just enumerate all the licenses
of the code which goes into the binary packages we ship.

¹ https://metacpan.org/release/App-Licensecheck

-- 
Todd

  reply	other threads:[~2026-10-10 15:37 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 11:25 [PATCH 0/4] faster SHA-1 collision detection Scott Chacon
2026-09-29 11:25 ` [PATCH 1/4] sha1dc-accel: add a block loop for sha1dc's SHA1_CTX Scott Chacon
2026-10-07 12:17   ` Johannes Schindelin
2026-09-29 11:25 ` [PATCH 2/4] sha1dc-accel: vectorize the unavoidable-bitconditions check Scott Chacon
2026-10-07 12:17   ` Johannes Schindelin
2026-10-07 21:32     ` Junio C Hamano
2026-09-29 11:25 ` [PATCH 3/4] sha1dc-accel: compress with SHA-NI on x86-64 Scott Chacon
2026-09-29 11:25 ` [PATCH 4/4] sha1dc-accel: compress with the ARMv8 SHA-1 instructions Scott Chacon
2026-10-07 12:17 ` [PATCH 0/4] faster SHA-1 collision detection Johannes Schindelin
2026-10-07 17:23 ` Junio C Hamano
2026-10-07 18:13   ` Scott Chacon
2026-10-08  6:21     ` Sebastian Thiel
2026-10-08 11:20       ` Sam Reis
2026-10-08 13:25         ` D. Ben Knoble
2026-10-08 13:59           ` Sam Reis
2026-10-08 17:10           ` Junio C Hamano
2026-10-08 17:46             ` D. Ben Knoble
2026-10-08 21:03               ` Junio C Hamano
2026-10-09 20:37           ` Todd Zullinger
2026-10-10 14:10             ` D. Ben Knoble
2026-10-10 15:37               ` Todd Zullinger [this message]
2026-10-09 23:41           ` Junio C Hamano
2026-10-08 15:55         ` Junio C Hamano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261010153721.943RqWnW@teonanacatl.net \
    --to=tmz@pobox.com \
    --cc=ben.knoble@gmail.com \
    --cc=git@vger.kernel.org \
    --cc=gitster@pobox.com \
    --cc=sam@opencanopy.dev \
    --cc=schacon@gmail.com \
    --cc=scott@gitbutler.net \
    --cc=sebastian.thiel@icloud.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox