fix: identify GPL-2.0, not LGPL-2.0, when the GPLv2 preamble names the LGPL - #28
Merged
Merged
Conversation
…e LGPL
The license text matcher treated the mixed-case phrase "Library General Public
License" as an LGPL-2.0 signal. That phrase appears in the GPLv2 preamble
itself ("...covered by the GNU Library General Public License instead."), so
any real GPL-2.0 license file set library=true and was emitted as LGPL-2.0 --
and because the version-2 branch prefers the library case, GPL-2.0 was dropped
entirely. GPL and LGPL carry materially different obligations, so this is a
compliance-relevant misclassification.
GPL-2.0 and LGPL-2.0 share the "Version 2, June 1991" date line, so the only
reliable discriminator is the document title. Match `library` on the all-caps
LGPL-2.0 title "GNU LIBRARY GENERAL PUBLIC LICENSE" only, never the mixed-case
preamble mention. A genuine GPL-2.0 file now reports GPL-2.0; a real LGPL-2.0
file (caps title) still reports LGPL-2.0.
Add regression tests: a GPLv2 fixture that includes the preamble's LGPL mention
(must be GPL-2.0) and an LGPL-2.0 fixture with the caps title plus a preamble
(must stay LGPL-2.0).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The license text matcher misidentified GPL-2.0 as LGPL-2.0 (and dropped GPL-2.0 entirely) whenever a GPL-2.0 file's preamble named the LGPL.
identify_license_texttreated the mixed-case phrase"Library General Public License"as an LGPL-2.0 signal. That phrase is in the GPLv2 preamble itself:So any real GPL-2.0 license file set
library = trueand was emitted asLGPL-2.0; because the "Version 2, June 1991" branch prefers the library case,GPL-2.0was never added. GPL and LGPL carry materially different obligations, so this is a compliance-relevant misclassification.Fix
GPL-2.0 and LGPL-2.0 share the same date line (
Version 2, June 1991), so the only reliable discriminator is the document title.librarynow matches only the all-caps LGPL-2.0 titleGNU LIBRARY GENERAL PUBLIC LICENSE, never the mixed-case preamble mention.GNU GENERAL PUBLIC LICENSE, whose preamble names the LGPL) now reportsGPL-2.0.GNU LIBRARY GENERAL PUBLIC LICENSE) still reportsLGPL-2.0.Tests
Added two regression cases to
test_license: a GPLv2 fixture that includes the preamble's LGPL mention (assertsGPL-2.0), and an LGPL-2.0 fixture with the caps title plus a preamble (assertsLGPL-2.0). The existing minimal caps-title GPL/LGPL cases still pass.Full unit suite (1385 checks) and integration suite pass; clean under ASan+UBSan.