From: Todd Zullinger Date: Sat, 10 Oct 2026 15:37:21 GMT Subject: Re: [PATCH 0/4] faster SHA-1 collision detection Message-ID: <20261010153721.943RqWnW@teonanacatl.net> In-Reply-To: D. Ben Knoble wrote: > On Fri, Oct 9, 2026 at 4:37 PM Todd Zullinger wrote: >> Fedora's Git package has: >> >> BSD-3-Clause AND GPL-2.0-only AND GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT > > Oh, curious! Where are the (using Gentoo identifiers for the moment) > BSD and LGPL-2.1+ sources? I guess I assume by looking at our COPYING > that the GPL-2+ came from contributions that said they were willing to > be 2+? There are various bits of code imported that are under difference licenses, among other things. The code in reftable/ is BSD-3-Clause (using the SPDX naming), for example, while xdiff/xhistogram.c is BSD-3-Clause and/or EDL-1.0 while most of the rest of it is LGPL-2.1-or-later; ewah/ is GPL-2.0-or-later; compat/obstack.[ch] and compat/regex/ are also LGPL-2.1-or-later. I used the perl licensecheck tool¹ to generate the initial list, then reviewed it and filtered out some bits from the test suite which are not shipped in the binary packages for Fedora. The command to do that is (without the filtering of any code): find -type f -exec licensecheck --shortname-scheme spdx {} + | grep -v 'UNKNOWN$' | LANG=C sort >licensecheck A more complete analysis would require reviewing all of the files which are UNKNOWN to ensure none have a copyright that licensecheck simply didn't find (or isn't in the file but can be found from the git history). I was a bit lazy and didn't do all of that work. :) > Anyway, thanks all! I'll assume the Gentoo maintainers knew what they > were doing :) Yeah, I've found most distribution packagers try to be diligent about this. Though it can be a somewhat tedious tasks and can change if the distribution switches from expecting packages to list the "effective" license to some other method. Fedora used to do (or allow) that license simplification, e.g.: boiling down our distributing Git to GPL-2-only, but clarified things a number of years ago to not do so. It ends up slightly easier to just enumerate all the licenses of the code which goes into the binary packages we ship. ¹ https://metacpan.org/release/App-Licensecheck -- Todd