Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Bug#1029055: Debian Expat and SPDX MIT License Text

5 views
Skip to first unread message

Axel Beckert

unread,
Jan 17, 2023, 2:00:02 AM1/17/23
to
Hi,

Soren Stoutner wrote:
> There appears to be some question of opinion

Not opinion. Just the point of what the meaning of _text colors_
*rollingeyes* in a license do mean. I just ignored them and then those
two licenses differ.

> as to if the Debian MIT (Expat) License is
> the same as the SPDX MIT License.
[…]
> Can somebody at Debian Legal please comment?

Yes, thanks! I'd prefer to have a good explanation, too.

Please also note that I didn't mark the bug report as wontfix, just as
moreinfo.

Regards, Axel
--
,''`. | Axel Beckert <a...@debian.org>, https://people.debian.org/~abe/
: :' : | Debian Developer, ftp.ch.debian.org Admin
`. `' | 4096R: 2517 B724 C5F6 CA99 5329 6E61 2FF9 CD59 6126 16B5
`- | 1024D: F067 EA27 26B9 C3FC 1486 202E C09E 1D89 9593 0EDE

Soren Stoutner

unread,
Jan 17, 2023, 2:02:32 AM1/17/23
to

SPDX itself might have an answer that is satisfactory:


"The original replaceable text appears on the SPDX License List webpage in red text."


"Omittable text appears on the SPDX License List webpage in blue text."


https://spdx.github.io/spdx-spec/v2.3/license-matching-guidelines-and-templates/


On Monday, January 16, 2023 11:48:48 PM MST Soren Stoutner wrote:

> There appears to be some question of opinion as to if the Debian MIT (Expat)

> License is the same as the SPDX MIT License.

>

>

> Can somebody at Debian Legal please comment?



--

Soren Stoutner

so...@stoutner.com

signature.asc

Soren Stoutner

unread,
Jan 17, 2023, 2:02:32 AM1/17/23
to

There appears to be some question of opinion as to if the Debian MIT (Expat) License is the same as the SPDX MIT License.


https://www.debian.org/legal/licenses/mit


signature.asc

Richard Fontana

unread,
Jan 18, 2023, 3:10:03 PM1/18/23
to
On Tue, Jan 17, 2023 at 2:06 AM Axel Beckert <a...@debian.org> wrote:
>
> Hi,
>
> Soren Stoutner wrote:
> > There appears to be some question of opinion
>
> Not opinion. Just the point of what the meaning of _text colors_
> *rollingeyes* in a license do mean. I just ignored them and then those
> two licenses differ.
>
> > as to if the Debian MIT (Expat) License is
> > the same as the SPDX MIT License.
> […]
> > Can somebody at Debian Legal please comment?
>
> Yes, thanks! I'd prefer to have a good explanation, too.
>
> Please also note that I didn't mark the bug report as wontfix, just as
> moreinfo.

The SPDX definition of "MIT" is given in
https://github.com/spdx/license-list-XML/blob/main/src/MIT.xml
Based on a lot of experience now, you really have to consult the XML
files rather than rely on the convenience publication of license texts
at https://spdx.org/licenses

Based on that, and https://www.debian.org/legal/licenses/mit, and
https://spdx.github.io/spdx-spec/v2.3/license-matching-guidelines-and-templates/

I think the answer is that what Debian calls "MIT (Expat)" on that
page matches what SPDX calls "MIT" (I don't think they are "the same"
because the underlying concepts of what a license is and so forth are
not the same).

Richard

Soren Stoutner

unread,
Jan 18, 2023, 4:12:42 PM1/18/23
to
Thanks Richard. I was unaware of the XML versions.

So, this would mean that SPDX considers what Debian calls the MIT (Expat)
license to match what SPDX calls MIT because the differences are all either
considered by SPDX to be omittable or replaceable as demonstrated by the tags
in the XML file and the text colors in the HTML version.

On Wednesday, January 18, 2023 12:52:23 PM MST Richard Fontana wrote:
> The SPDX definition of "MIT" is given in
> https://github.com/spdx/license-list-XML/blob/main/src/MIT.xml
> Based on a lot of experience now, you really have to consult the XML
> files rather than rely on the convenience publication of license texts
> at https://spdx.org/licenses
>
> Based on that, and https://www.debian.org/legal/licenses/mit, and
> https://spdx.github.io/spdx-spec/v2.3/license-matching-guidelines-and-templa
> tes/
>
> I think the answer is that what Debian calls "MIT (Expat)" on that
> page matches what SPDX calls "MIT" (I don't think they are "the same"
> because the underlying concepts of what a license is and so forth are
> not the same).
>
> Richard


--
Soren Stoutner
so...@stoutner.com
signature.asc
0 new messages