Skip to content

Add a license for the PSK contributions to OpenSSL - #1341

Merged
pombredanne merged 1 commit into
aboutcode-org:developfrom
fviernau:openssl-nokia-psk-contribution-license
Feb 7, 2019
Merged

Add a license for the PSK contributions to OpenSSL#1341
pombredanne merged 1 commit into
aboutcode-org:developfrom
fviernau:openssl-nokia-psk-contribution-license

Conversation

@fviernau

Copy link
Copy Markdown
Contributor

Add the proprietary Nokia license (text) used for the Pre-Shared Key
contributions to OpenSSL by Nokia, see

openssl/openssl@ddac1974

@codecov

codecov Bot commented Jan 28, 2019

Copy link
Copy Markdown

Codecov Report

Merging #1341 into develop will decrease coverage by 14.36%.
The diff coverage is n/a.

Impacted file tree graph

@@             Coverage Diff              @@
##           develop    #1341       +/-   ##
============================================
- Coverage    84.19%   69.82%   -14.37%     
============================================
  Files          117      117               
  Lines        13154    13154               
============================================
- Hits         11075     9185     -1890     
- Misses        2079     3969     +1890
Impacted Files Coverage Δ
src/commoncode/urn.py 0% <0%> (-100%) ⬇️
src/commoncode/version.py 0% <0%> (-100%) ⬇️
src/licensedcode/legal.py 0% <0%> (-92.86%) ⬇️
src/licensedcode/tracing.py 0% <0%> (-86.96%) ⬇️
src/licensedcode/seq.py 9.83% <0%> (-86.89%) ⬇️
src/summarycode/copyright_summary.py 0% <0%> (-75.45%) ⬇️
src/formattedcode/output_csv.py 13.88% <0%> (-70.84%) ⬇️
src/summarycode/utils.py 32% <0%> (-68%) ⬇️
src/formattedcode/output_spdx.py 26.59% <0%> (-66.49%) ⬇️
src/typecode/entropy.py 32% <0%> (-64%) ⬇️
... and 54 more

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 617d59a...12c397c. Read the comment docs.

@codecov

codecov Bot commented Jan 28, 2019

Copy link
Copy Markdown

Codecov Report

Merging #1341 into develop will increase coverage by <.01%.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff             @@
##           develop   #1341      +/-   ##
==========================================
+ Coverage    84.19%   84.2%   +<.01%     
==========================================
  Files          117     117              
  Lines        13154   13154              
==========================================
+ Hits         11075   11076       +1     
+ Misses        2079    2078       -1
Impacted Files Coverage Δ
src/scancode/cli.py 76.41% <0%> (-0.48%) ⬇️
src/typecode/contenttype.py 84.75% <0%> (+0.26%) ⬆️
src/scancode/extract_cli.py 88% <0%> (+3%) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 617d59a...516d6b2. Read the comment docs.

@pombredanne pombredanne left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@fviernau Thank you ++
I wonder if this should not be treated as an exception? the text explicitly mentions ... and is licensed pursuant to the OpenSSL open source license. so the core licensing terms would be these of the OpenSSL license ... and then these extra patent-related terms are some exception/supplemental terms to the base OpenSSL.
In this case the text would be only this for the exception .LICENSE file:

No patent licenses or other rights except those expressly stated in
the OpenSSL open source license shall be deemed granted or received
expressly, by implication, estoppel, or otherwise.

No assurances are provided by Nokia that the Contribution does not
infringe the patent or other intellectual property rights of any third
party or that the license provides you with all the necessary rights
to make use of the Contribution.

THE SOFTWARE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. IN
ADDITION TO THE DISCLAIMERS INCLUDED IN THE LICENSE, NOKIA
SPECIFICALLY DISCLAIMS ANY LIABILITY FOR CLAIMS BROUGHT BY YOU OR ANY
OTHER ENTITY BASED ON INFRINGEMENT OF INTELLECTUAL PROPERTY RIGHTS OR
OTHERWISE.

and there could be a rule that would return openssl-ssleay WITH openssl-nokia-psk-contribution for the combo of

The portions of the attached software ("Contribution") is developed by
Nokia Corporation and is licensed pursuant to the OpenSSL open source
license.

I'd like to get @DennisClark opinion on this: new license or new exception?

Yet another possibility would be to treat this disclaimer text as a rule for the generic patent-disclaimer https://github.com/nexB/scancode-toolkit/blob/develop/src/licensedcode/data/licenses/patent-disclaimer.yml
instead.

short_name: OpenSSL Nokia PSK Contribution
category: Permissive
owner: Nokia
spdx_license_key: LicenseRef-OpenSSL-Nokia-PSK-Contribution

@pombredanne pombredanne Jan 28, 2019

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now the approach has been not to put any LicenseRef for the license that are not known in the SPDX license list. There is a pending ticket #1328 by @sschuberth to review this approach and possibly assign always a LicenseRef (and there is also #532).

@fviernau fviernau Jan 28, 2019

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! Removed the LicenseRef and updated the PR.

It seems I looked at the only .yml underneath licenses containing such LicenseRef, e.g. ./src/licensedcode/data/licenses/here-proprietary.yml. Out-of-scope here: should the LicenseRef be removed from that file?

Add the proprietary Nokia license (text) used for the `Pre-Shared Key`
contributions to OpenSSL by Nokia, see

openssl/openssl@ddac1974

Signed-off-by: Frank Viernau <frank.viernau@here.com>
@DennisClark

Copy link
Copy Markdown
Member

A few comments:

  • I think the patent-related text above could be considered as a candidate for a new license or exception. The details need working out; stay tuned.
  • I think the idea of always assigning a LIcenseRef for licenses not known to the SPDX list is a good idea.

@pombredanne

Copy link
Copy Markdown
Member

@DennisClark any update?

@DennisClark

DennisClark commented Feb 6, 2019

Copy link
Copy Markdown
Member

new license exception Patent Disclaimer for OpenSSL (openssl-nokia-psk-contribution) created in DejaCode

@DennisClark

Copy link
Copy Markdown
Member

public access to the new license exception is at https://enterprise.dejacode.com/licenses/public/openssl-nokia-psk-contribution/

@sschuberth

Copy link
Copy Markdown
Collaborator

@pombredanne, as @fviernau is currently on vacation feel free to either do any still required chnages yourself, or tell me about it.

@pombredanne

Copy link
Copy Markdown
Member

@sschuberth we are good and I will merge and possibly update afterwards based on @DennisClark feedback

@pombredanne
pombredanne merged commit a763b50 into aboutcode-org:develop Feb 7, 2019
sschuberth added a commit to oss-review-toolkit/ort that referenced this pull request Feb 7, 2019
In particular, this fixes the swapped bsl-1.0 / bsl-1.1 licenses [1] and
adds the openssl-nokia-psk-contribution license (exception) [2].

[1] aboutcode-org/scancode-toolkit#1338
[2] aboutcode-org/scancode-toolkit#1341

Signed-off-by: Sebastian Schuberth <sebastian.schuberth@here.com>
sschuberth added a commit to oss-review-toolkit/ort that referenced this pull request Feb 7, 2019
In particular, this fixes the swapped bsl-1.0 / bsl-1.1 licenses [1] and
adds the openssl-nokia-psk-contribution license (exception) [2].

[1] aboutcode-org/scancode-toolkit#1338
[2] aboutcode-org/scancode-toolkit#1341

Signed-off-by: Sebastian Schuberth <sebastian.schuberth@here.com>
sschuberth added a commit to oss-review-toolkit/ort that referenced this pull request Feb 7, 2019
In particular, this fixes the swapped bsl-1.0 / bsl-1.1 licenses [1] and
adds the openssl-nokia-psk-contribution license (exception) [2].

[1] aboutcode-org/scancode-toolkit#1338
[2] aboutcode-org/scancode-toolkit#1341

Signed-off-by: Sebastian Schuberth <sebastian.schuberth@here.com>
pombredanne added a commit that referenced this pull request Feb 9, 2019
Reported-by: Frank Viernau <frank.viernau@here.com>
Reported-by: @DennisClark
Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants