Skip to content

fix: identify GPL-2.0, not LGPL-2.0, when the GPLv2 preamble names the LGPL - #28

Merged
nmatt0 merged 1 commit into
masterfrom
fix/license-gpl-vs-lgpl
Sep 18, 2026
Merged

nmatt0 merged 1 commit into
masterfrom
fix/license-gpl-vs-lgpl

Conversation

@nmatt0

@nmatt0 nmatt0 commented Sep 18, 2026

Copy link
Copy Markdown
Owner

What

The license text matcher misidentified GPL-2.0 as LGPL-2.0 (and dropped GPL-2.0 entirely) whenever a GPL-2.0 file's preamble named the LGPL.

identify_license_text treated the mixed-case phrase "Library General Public License" as an LGPL-2.0 signal. That phrase is in the GPLv2 preamble itself:

(Some other Free Software Foundation software is covered by the GNU Library General Public License instead.)

So any real GPL-2.0 license file set library = true and was emitted as LGPL-2.0; because the "Version 2, June 1991" branch prefers the library case, GPL-2.0 was never added. GPL and LGPL carry materially different obligations, so this is a compliance-relevant misclassification.

Fix

GPL-2.0 and LGPL-2.0 share the same date line (Version 2, June 1991), so the only reliable discriminator is the document title. library now matches only the all-caps LGPL-2.0 title GNU LIBRARY GENERAL PUBLIC LICENSE, never the mixed-case preamble mention.

  • A genuine GPL-2.0 file (title GNU GENERAL PUBLIC LICENSE, whose preamble names the LGPL) now reports GPL-2.0.
  • A real LGPL-2.0 file (title GNU LIBRARY GENERAL PUBLIC LICENSE) still reports LGPL-2.0.

Tests

Added two regression cases to test_license: a GPLv2 fixture that includes the preamble's LGPL mention (asserts GPL-2.0), and an LGPL-2.0 fixture with the caps title plus a preamble (asserts LGPL-2.0). The existing minimal caps-title GPL/LGPL cases still pass.

Full unit suite (1385 checks) and integration suite pass; clean under ASan+UBSan.

…e LGPL

The license text matcher treated the mixed-case phrase "Library General Public
License" as an LGPL-2.0 signal. That phrase appears in the GPLv2 preamble
itself ("...covered by the GNU Library General Public License instead."), so
any real GPL-2.0 license file set library=true and was emitted as LGPL-2.0 --
and because the version-2 branch prefers the library case, GPL-2.0 was dropped
entirely. GPL and LGPL carry materially different obligations, so this is a
compliance-relevant misclassification.

GPL-2.0 and LGPL-2.0 share the "Version 2, June 1991" date line, so the only
reliable discriminator is the document title. Match `library` on the all-caps
LGPL-2.0 title "GNU LIBRARY GENERAL PUBLIC LICENSE" only, never the mixed-case
preamble mention. A genuine GPL-2.0 file now reports GPL-2.0; a real LGPL-2.0
file (caps title) still reports LGPL-2.0.

Add regression tests: a GPLv2 fixture that includes the preamble's LGPL mention
(must be GPL-2.0) and an LGPL-2.0 fixture with the caps title plus a preamble
(must stay LGPL-2.0).
@nmatt0
nmatt0 merged commit 93960e6 into master Sep 18, 2026
4 checks passed
@nmatt0
nmatt0 deleted the fix/license-gpl-vs-lgpl branch September 18, 2026 02:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant