Re: Take on concluded license; introducing effective license


Karsten Klein
 

Resending unsigned due to issues with the list and my signature; I hope this solves the problem…

 

 

Hi all,

 

in today’s SPDX-Docfest I took the action item to raise a question regarding the interpretation of concluded license.

 

My point is the concluded license is semantically overloaded:

  1. Used as the result of curation process
  2. Used as the result of automatic process applying best efforts
  3. Used to determine the license under which the item is further distributed (in particular when there is a licensing option)

 

While 1) and 2) appear ok to me I took the argument that we need to differentiate case 3) from the other two. I argued along

  • There is a license conclusion under which we consume the license (from upstream)
  • There is a license decision (to not use the term conclusion here) to specify how we pass on the item (downstream)
  • That we need to convey the upstream and downstream licenses
  • That the license decision is policy-driven and use-case (or rather business-case) specific and determined in the context of my distribution or application and that this does not yet apply to the concluded license
  • That this must be tracible by the recipient of my SPDX document (downstream)

 

I sketched a picture that shows where I would like SPDX to go introducing an effective license separated from concluded license:

 

 

The illustration separates this overloaded semantics of concluded license by adding effective license, which then is also the reference/commitment towards the binding terms and conditions, the obligations and restrictions that apply for my distribution/application.

 

Some examples to illustrate this:

 

A:

  • Detected one more license than the authors declared
  • Remove “or-later” on effective license to determine explicit license conditions

 

B:

  • Author declared license correct and complete, but with option
  • Policy-based decision towards more permissive license with less obligations in the use case

 

Please let us know what you think.

 

Kind regards,

Karsten

 

 

metaeffekt GmbH

Firmensitz: Renettenweg 6/1, 69124 Heidelberg

Registergericht: Amtsgericht Mannheim, HRB 725313

Geschäftsführer: Karsten Klein

USt.-IdNr.: DE307084554

 

Diese E-Mail kann vertrauliche und/oder rechtlich geschützte Informationen beinhalten. Sollten Sie diese E-Mail irrtümlich erhalten haben, informieren Sie bitte den Absender und löschen Sie diese E-Mail und alle Kopien umgehend. Eine unbefugte Weitergabe der E-Mail oder deren Inhalte und Anhänge ist nicht gestattet.

 

Möchten Sie als Empfänger keine Informationen dieser Art erhalten, setzen Sie sich bitte unmittelbar mit dem Absender der E-Mail in Verbindung. Die metaeffekt GmbH unterstützt Ihre Datenhoheit und informationelle Selbstbestimmung und übermittelt Informationen ausschließlich auf der Rechtsgrundlage der europäischen Datenschutzgrundverordnung (DSGVO). Weitere Informationen zu den Datenverarbeitungsvorgängen und insbesondere Ihrer Rechte entnehmen Sie der Datenschutzerklärung der metaeffekt GmbH.

 

Join Spdx-legal@lists.spdx.org to automatically receive all group messages.