From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.0 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 40D06C28CC5 for ; Sat, 8 Jun 2019 19:05:35 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 0F138214AE for ; Sat, 8 Jun 2019 19:05:35 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=pobox.com header.i=@pobox.com header.b="vEbxumbU"; dkim=fail reason="key not found in DNS" (0-bit key) header.d=lohutok.net header.i=@lohutok.net header.b="OftowBux" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727469AbfFHTFe (ORCPT ); Sat, 8 Jun 2019 15:05:34 -0400 Received: from pb-smtp21.pobox.com ([173.228.157.53]:61642 "EHLO pb-smtp21.pobox.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727424AbfFHTFe (ORCPT ); Sat, 8 Jun 2019 15:05:34 -0400 Received: from pb-smtp21.pobox.com (unknown [127.0.0.1]) by pb-smtp21.pobox.com (Postfix) with ESMTP id 0F5E25AD90; Sat, 8 Jun 2019 15:05:32 -0400 (EDT) (envelope-from allison@lohutok.net) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=pobox.com; h=subject:to :references:from:message-id:date:mime-version:in-reply-to :content-type:content-transfer-encoding; s=sasl; bh=3HZz38oB+wGT N2PkMZjMYjxfq1U=; b=vEbxumbU56i1diIXiydj9Czk5R/xStsZ67RN24+IR3wR I2bzOTbpSqOpy15OoEBvGENzFesjtvSbApSm+EOPMK1eo7yXpUGIQ3xyieHD6b0e dczpDpz4yrOp5N4An9mZsEq920dKxFOpKr7pGqNjZ2zXeJvq9nfye0eR6v/sUBY= Received: from pb-smtp21.sea.icgroup.com (unknown [127.0.0.1]) by pb-smtp21.pobox.com (Postfix) with ESMTP id E7F1E5AD8E; Sat, 8 Jun 2019 15:05:31 -0400 (EDT) (envelope-from allison@lohutok.net) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=lohutok.net; h=subject:to:references:from:message-id:date:mime-version:in-reply-to:content-type:content-transfer-encoding; s=2018-11.pbsmtp; bh=oaRW9O3h0CbKi0u7gwfCzgx9vSVkzeX1F1uQZYhySCQ=; b=OftowBuxF1Pta7lVOzRJ/QaZESjlGWrk8cC8lrGoQAi7IFDNwRJSo5JJoEo2YU2+t2xYaEKyLI5ZR9d4cMAIyifYojuZFhaDAzoxauXiej3DnjTUufqQpUkqMZEu3qr5Y5WxBNrHfibZCpuFqeLBLDIyPNYlTXIXMqCGNXlihaU= Received: from [10.0.0.75] (unknown [24.47.52.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pb-smtp21.pobox.com (Postfix) with ESMTPSA id A4B915AD8D; Sat, 8 Jun 2019 15:05:28 -0400 (EDT) (envelope-from allison@lohutok.net) Subject: Re: [ASIS-1 patch 0/6] Deep review of 'AS IS' disclaimers - part 1 To: Thomas Gleixner , linux-spdx@vger.kernel.org References: <20190605101543.586282830@linutronix.de> From: Allison Randal Message-ID: <6e615331-9b3d-612b-5802-610b207d3d41@lohutok.net> Date: Sat, 8 Jun 2019 15:05:26 -0400 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.5.1 MIME-Version: 1.0 In-Reply-To: <20190605101543.586282830@linutronix.de> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit X-Pobox-Relay-ID: 61622AAE-8A20-11E9-B459-8D86F504CC47-44123303!pb-smtp21.pobox.com Sender: linux-spdx-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-spdx@vger.kernel.org On 6/5/19 6:15 AM, Thomas Gleixner wrote: > > The first batch is from the 'AS IS' category. All patches in this series > have the same modification of the standard GPLv2 disclaimer. > > Standard disclaimer: > > this program is distributed in the hope that it will be useful > but without any warranty without even the implied warranty of > merchantability or fitness for a particular purpose > > Modified diclaimer: > > this program is distributed as is without any warranty of any kind > whether express[ed] or implied without even the implied warranty of > merchantability or fitness for a particular purpose > > The NO WARRANTY section of the GPLv2 contains: > > PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER > EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED > WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE > > In my opinion the modified disclaimer contains nothing which is > substantially different, but I might be wrong as usual. I agree, they seem to have simply copied disclaimer language from the GPLv2 and added it to the disclaimer notice. So they aren't adding any disclaimers beyond what would have applied to the file anyway, and the SPDX identifier is equivalent to the existing notice. I'll go ahead and review the patches in this set positively, but I suggest waiting for at least one lawyer to review before moving ahead with these patches. > In case we agree on that, I would amend the changelogs of the individual > patches with a paragraph explaining our conclusion. Something along the > lines: > > The patterns deviate from the standard GPLv2 disclaimer, but the > modification does not expand beyond the standard disclaimer and the NO > WARRANTY section of the GPLv2. So replacing the license notice > including the modified disclaimer with the SPDX license identifier > results in the same protections and conditions. > > Feel free to suggest better wording or deeper explanation. Seems fine to me. Maybe add the word "notice" to the end of the first sentence? It just seems a little confusing that the paragraph has the word "disclaimer" referring to both the file notice and the license itself. Someone else may have a better idea how to clarify. Allison