{"thread":{"id":"38877","subject":"[PATCH] clone: Warn if clone lacks LICENSE or COPYING file","startedAt":"2015-03-21T18:06:33Z","lastAt":"2015-04-03T21:26:34Z","messageCount":10,"participants":["David A. Wheeler","Dennis Kaarsemaker","Stefan Beller","Junio C Hamano","Ævar Arnfjörð Bjarmason","Kevin D"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"258253","messageId":"E1YZNn7-0002Lc-7O@rmm6prod02.runbox.com","threadId":"38877","inReplyTo":null,"subject":"[PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"David A. Wheeler","fromEmail":"dwheeler@dwheeler.com","sentAt":"2015-03-21T18:06:33Z","receivedAt":"2015-03-21T18:06:33Z","isPatch":true,"sender":{"key":"dwheeler@dwheeler.com","avatar":"https://avatars.githubusercontent.com/u/813150?v=4"},"body":"Warn cloners if there is no LICENSE* or COPYING* file that makes\nthe license clear.  This is a useful warning, because if there is\nno license somewhere, then local copyright laws (which forbid many uses)\nand terms of service apply - and the cloner may not be expecting that.\nMany projects accidentally omit a license, so this is common enough to note.\nFor more info on the issue, feel free to see:\nhttp://choosealicense.com/no-license/\nhttp://www.wired.com/2013/07/github-licenses/\nhttps://twitter.com/stephenrwalli/status/247597785069789184\n\nSigned-off-by: David A. Wheeler <dwheeler@dwheeler.com>\n---\n builtin/clone.c | 38 ++++++++++++++++++++++++++++++++++++++\n 1 file changed, 38 insertions(+)\n\ndiff --git a/builtin/clone.c b/builtin/clone.c\nindex 9572467..9863b04 100644\n--- a/builtin/clone.c\n+++ b/builtin/clone.c\n@@ -748,6 +748,41 @@ static void dissociate_from_references(void)\n \t\tdie_errno(_(\"cannot unlink temporary alternates file\"));\n }\n \n+static int starts_with_ignore_case(const char *str, const char *prefix)\n+{\n+\tfor (; ; str++, prefix++)\n+\t\tif (!*prefix)\n+\t\t\treturn 1;\n+\t\telse if (tolower(*str) != tolower(*prefix))\n+\t\t\treturn 0;\n+}\n+\n+static int contains_license(void)\n+{\n+\tDIR *dir = opendir(\".\"); /* Examine current directory for license. */\n+\tstruct dirent *e;\n+\tstruct stat st;\n+\tint ret = 0;\n+\n+\tif (!dir)\n+\t\treturn 0;\n+\n+\twhile ((e = readdir(dir)) != NULL)\n+\t\tif (starts_with_ignore_case(e->d_name, \"license\") ||\n+\t\t    starts_with_ignore_case(e->d_name, \"copyright\")) {\n+\t\t\tif (stat(e->d_name, &st))\n+\t\t\t\tcontinue;\n+\t\t\tif (st.st_size > 1) {\n+\t\t\t\tret = 1;\n+\t\t\t\tbreak;\n+\t\t\t}\n+\t\t}\n+\n+\tclosedir(dir);\n+\treturn ret;\n+}\n+\n+\n int cmd_clone(int argc, const char **argv, const char *prefix)\n {\n \tint is_bundle = 0, is_local;\n@@ -1016,6 +1051,9 @@ int cmd_clone(int argc, const char **argv, const char *prefix)\n \tjunk_mode = JUNK_LEAVE_REPO;\n \terr = checkout();\n \n+\tif (!option_no_checkout && !contains_license())\n+\t\twarning(_(\"Repository has no LICENSE or COPYING file with content.\"));\n+\n \tstrbuf_release(&reflog_msg);\n \tstrbuf_release(&branch_top);\n \tstrbuf_release(&key);\n-- \n2.1.4\n"},{"id":"258256","messageId":"1426969262.3756.1.camel@kaarsemaker.net","threadId":"38877","inReplyTo":"E1YZNn7-0002Lc-7O@rmm6prod02.runbox.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Dennis Kaarsemaker","fromEmail":"dennis@kaarsemaker.net","sentAt":"2015-03-21T20:21:02Z","receivedAt":"2015-03-21T20:21:02Z","isPatch":true,"sender":{"key":"dennis@kaarsemaker.net","avatar":"https://avatars.githubusercontent.com/u/200649?v=4"},"body":"On za, 2015-03-21 at 14:06 -0400, David A. Wheeler wrote:\n> Warn cloners if there is no LICENSE* or COPYING* file that makes\n> the license clear.  This is a useful warning, because if there is\n> no license somewhere, then local copyright laws (which forbid many uses)\n> and terms of service apply - and the cloner may not be expecting that.\n\nPlease no, especially not without an option to switch this off. Git is\nnot only used in open source settings, this would be highly annoying at\n$work, where no repo has (or needs) such a file.\n\n-- \nDennis Kaarsemaker\nwww.kaarsemaker.net\n"},{"id":"258271","messageId":"550E430F.9010308@gmail.com","threadId":"38877","inReplyTo":"1426969262.3756.1.camel@kaarsemaker.net","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Stefan Beller","fromEmail":"stefanbeller@gmail.com","sentAt":"2015-03-22T04:20:31Z","receivedAt":"2015-03-22T04:20:31Z","isPatch":true,"sender":{"key":"stefanbeller@gmail.com","avatar":"https://avatars.githubusercontent.com/u/455868?v=4"},"body":"On 21.03.2015 13:21, Dennis Kaarsemaker wrote:\n> On za, 2015-03-21 at 14:06 -0400, David A. Wheeler wrote:\n>> Warn cloners if there is no LICENSE* or COPYING* file that makes\n>> the license clear.  This is a useful warning, because if there is\n>> no license somewhere, then local copyright laws (which forbid many uses)\n>> and terms of service apply - and the cloner may not be expecting that.\n> \n> Please no, especially not without an option to switch this off. Git is\n> not only used in open source settings, this would be highly annoying at\n> $work, where no repo has (or needs) such a file.\n> \n\nTo spin this further it would be interesting to have\na server advertisement during git clone which indicates\nif this setting is recommended to be set.\nThen hosting sites popular in the open source world such as\ngithub could enable this feature, and the client may enable\nthis for the currently cloned repository (the user may have\na global setting set to suppress this message though).\n\nAt $work the default of not advertising checking for such a\nfeature would be set.\n"},{"id":"258272","messageId":"xmqqoanld3v1.fsf@gitster.dls.corp.google.com","threadId":"38877","inReplyTo":"550E430F.9010308@gmail.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-03-22T04:59:30Z","receivedAt":"2015-03-22T04:59:30Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Stefan Beller <stefanbeller@gmail.com> writes:\n\n> To spin this further it would be interesting to have\n> a server advertisement during git clone which indicates\n> if this setting is recommended to be set.\n> Then hosting sites popular in the open source world such as\n> github could enable this feature, and the client may enable\n> this for the currently cloned repository (the user may have\n> a global setting set to suppress this message though).\n>\n> At $work the default of not advertising checking for such a\n> feature would be set.\n\nHmm.\n\nAn open source hosting site can help better by checking at the\nproject creation time, because the people who interact with that\ninterface are solely in the position to set and publish licensing\nterms.  The general consumer who are cloning and fetching do not\nhave direct control over this, and the only thing the could do to\nnudge the publishers is with an out-of-line communication, e.g.\nsending e-mails telling the publisher \"I am interested in using your\nware, but you do not have licensing terms described, which makes me\nwary; please improve\".\n\nAn approach that checks only the top-level directory for fixed\nfilename pattern would not be an effective way to protect the\ncloners, either.\n\nI am personally not interested in the patch under discussion, with\nor without \"please be quiet\" configuration.\n\nThanks.\n"},{"id":"258296","messageId":"CACBZZX67igE67+y7Tme=_OC7JiT726qB4X18+8Mvg1ewssQ_ug@mail.gmail.com","threadId":"38877","inReplyTo":"E1YZNn7-0002Lc-7O@rmm6prod02.runbox.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2015-03-22T17:56:52Z","receivedAt":"2015-03-22T17:56:52Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"On Sat, Mar 21, 2015 at 7:06 PM, David A. Wheeler <dwheeler@dwheeler.com> wrote:\n> Warn cloners if there is no LICENSE* or COPYING* file that makes\n> the license clear.  This is a useful warning, because if there is\n> no license somewhere, then local copyright laws (which forbid many uses)\n> and terms of service apply - and the cloner may not be expecting that.\n> Many projects accidentally omit a license, so this is common enough to note.\n> For more info on the issue, feel free to see:\n> http://choosealicense.com/no-license/\n> http://www.wired.com/2013/07/github-licenses/\n> https://twitter.com/stephenrwalli/status/247597785069789184\n\nAs others have indicated here this feature is really specific to a\nsingle lint-like use-case and doesn't belong in clone as a built-in\nfeature.\n\nHowever perhaps an interesting generalization of this would be\nsomething like a post-clone hook, obviously you couldn't store that in\n.git/hooks/ like other githooks(5) since there's no repo yet, but\nhaving it configured via the user/system config might be an\ninteresting feature.\n\nIf you're still interested in getting this functionality perhaps a\npatch to have some general post-clone hook mechanism would be\naccepted, then you could check license files or anything else you\ncared about.\n\nYou could also just have a shell alias that wrapped git-clone...\n"},{"id":"258369","messageId":"E1Ya5V2-0001bT-QE@rmm6prod02.runbox.com","threadId":"38877","inReplyTo":"xmqqoanld3v1.fsf@gitster.dls.corp.google.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"David A. Wheeler","fromEmail":"dwheeler@dwheeler.com","sentAt":"2015-03-23T16:46:48Z","receivedAt":"2015-03-23T16:46:48Z","isPatch":true,"sender":{"key":"dwheeler@dwheeler.com","avatar":"https://avatars.githubusercontent.com/u/813150?v=4"},"body":"Junio C Hamano:\n>    An open source hosting site can help better by checking at the\n>   project creation time, because the people who interact with that\n>    interface are solely in the position to set and publish licensing terms.\n\nThat doesn't help with the many projects that have *already* been created.\nE.G., GitHub has a license chooser now, but didn't for years, and it's still optional.\nAlso, repos stored as shared filesystems don't do that kind of checking.\n\nMore importantly, focusing on the \"hosting site\" doesn't warn people\nwho *clone* from repos. The people who take on legal risks are often not\nthe posters, but the people who clone *from* the sites.  Thus, *they* are the\nones who need the warning, and git is in an especially good spot to detect the issue.\n\n\n>     The general consumer who are cloning and fetching do not\n>    have direct control over this, and the only thing the could do to\n>     nudge the publishers is with an out-of-line communication...\n\nThat's an option, but another option is to NOT use it. Often\npeople have no idea there's an issue, and in their rush and lack of warning\nthey forget to check the basics.\n\n\n>    An approach that checks only the top-level directory for fixed\n>    filename pattern would not be an effective way to protect the\n>    cloners, either.\n\nI disagree, I think it's remarkably effective. *Many* projects\ndo this, including git itself. After all, many humans need to find out the licensing\nbasics too; having a simple convention for *finding* it helps humans and tools alike.\nIt's not even limited to open source software; developers of proprietary materials\n(software or now) *also* typically want to declare licensing.\n\nSure, the top-level licensing text might be incomplete, but having that information\nprovides a big help, and it's what most people rely on anyway. Indeed, a *lack*\nof this is a sign of trouble, which is exactly what warnings are good for.\n\n--- David A. Wheeler\n\n(P.S. I posted this previously but it seems to have failed for some reason,\nso I'm resending this in a different way.)\n"},{"id":"258385","messageId":"CACBZZX7JRAavMV4W91k-3ABYj8NPevBvF+CQKSMASYMjghB5pg@mail.gmail.com","threadId":"38877","inReplyTo":"E1Ya5V2-0001bT-QE@rmm6prod02.runbox.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2015-03-23T21:00:31Z","receivedAt":"2015-03-23T21:00:31Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"On Mon, Mar 23, 2015 at 5:46 PM, David A. Wheeler <dwheeler@dwheeler.com> wrote:\n> Junio C Hamano:\n>>    An approach that checks only the top-level directory for fixed\n>>    filename pattern would not be an effective way to protect the\n>>    cloners, either.\n>\n> I disagree, I think it's remarkably effective. *Many* projects\n> do this, including git itself. After all, many humans need to find out the licensing\n> basics too; having a simple convention for *finding* it helps humans and tools alike.\n> It's not even limited to open source software; developers of proprietary materials\n> (software or now) *also* typically want to declare licensing.\n>\n> Sure, the top-level licensing text might be incomplete, but having that information\n> provides a big help, and it's what most people rely on anyway. Indeed, a *lack*\n> of this is a sign of trouble, which is exactly what warnings are good for.\n\nI don't think you're going to find people disagreeing with you that\nit's good to have license information where appropriate, but Git is\nthe wrong tool to warn about this.\n\nIt's a generic content tracking tool, it shouldn't be warning on the\nassumption that what you're tracking is a) an open source project and\nb) that you care to be notified about some arbitrary files being\nmissing.\n\nA lot of Git repositories don't care at all about licensing, and\nhaving git-clone warn about this would just be useless noise most of\nthe time. E.g. anything I put on gist.github.com, the code hundreds of\npeople contribute to at work (we never distribute it anywhere, so a\nlicense would be pointless). I even have open source projects myself\nwhere there's no LICENSE or COPYING files since that would be\nredundant to notices in the files themselves, but I digress.\n"},{"id":"258557","messageId":"20150326165635.GA14879@vps892.directvps.nl","threadId":"38877","inReplyTo":"E1YZNn7-0002Lc-7O@rmm6prod02.runbox.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Kevin D","fromEmail":"me@ikke.info","sentAt":"2015-03-26T16:56:35Z","receivedAt":"2015-03-26T16:56:35Z","isPatch":true,"sender":{"key":"me@ikke.info","avatar":"https://avatars.githubusercontent.com/u/135698?v=4"},"body":"On Sat, Mar 21, 2015 at 02:06:33PM -0400, David A. Wheeler wrote:\n> Warn cloners if there is no LICENSE* or COPYING* file that makes\n> the license clear.  This is a useful warning, because if there is\n> no license somewhere, then local copyright laws (which forbid many uses)\n> and terms of service apply - and the cloner may not be expecting that.\n> Many projects accidentally omit a license, so this is common enough to note.\n> For more info on the issue, feel free to see:\n> http://choosealicense.com/no-license/\n> http://www.wired.com/2013/07/github-licenses/\n> https://twitter.com/stephenrwalli/status/247597785069789184\n> \n\nLWN article that lead to this patch: https://lwn.net/Articles/636261/\n"},{"id":"258945","messageId":"E1Ye8z3-000617-SW@rmm6prod02.runbox.com","threadId":"38877","inReplyTo":"CACBZZX67igE67+y7Tme=_OC7JiT726qB4X18+8Mvg1ewssQ_ug@mail.gmail.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"David A. Wheeler","fromEmail":"dwheeler@dwheeler.com","sentAt":"2015-04-03T21:18:33Z","receivedAt":"2015-04-03T21:18:33Z","isPatch":true,"sender":{"key":"dwheeler@dwheeler.com","avatar":"https://avatars.githubusercontent.com/u/813150?v=4"},"body":"On Sun, 22 Mar 2015 18:56:52 +0100, Ævar Arnfjörð Bjarmason <avarab@gmail.com> wrote:\n> However perhaps an interesting generalization of this would be\n> something like a post-clone hook, obviously you couldn't store that in\n> .git/hooks/ like other githooks(5) since there's no repo yet, but\n> having it configured via the user/system config might be an\n> interesting feature.\n\nWould that be acceptable to the wider group?\n\n--- David A. Wheeler\n"},{"id":"258946","messageId":"xmqqtwwwgayd.fsf@gitster.dls.corp.google.com","threadId":"38877","inReplyTo":"CACBZZX67igE67+y7Tme=_OC7JiT726qB4X18+8Mvg1ewssQ_ug@mail.gmail.com","subject":"Re: [PATCH] clone: Warn if clone lacks LICENSE or COPYING file","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-04-03T21:26:34Z","receivedAt":"2015-04-03T21:26:34Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason <avarab@gmail.com> writes:\n\n> As others have indicated here this feature is really specific to a\n> single lint-like use-case and doesn't belong in clone as a built-in\n> feature.\n>\n> However perhaps an interesting generalization of this would be\n> something like a post-clone hook, obviously you couldn't store that in\n> .git/hooks/ like other githooks(5) since there's no repo yet,\n\nYes, and these things come from templates, and you can specify the\ntemplate source location when running \"git clone\".\n\nSo I do not think anything is needed on our side and it's all doable\nwith what the users already have, as long as we are talking about\nmaking it only an opt-in feature.\n\nWhich means\n\n> You could also just have a shell alias that wrapped git-clone...\n\nis also perfectly acceptable, I would think.\n"}]}