licenses.rst 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520
  1. .. SPDX-License-Identifier: CC-BY-SA-2.0-UK
  2. Working With Licenses
  3. *********************
  4. As mentioned in the ":ref:`overview-manual/development-environment:licensing`"
  5. section in the Yocto Project Overview and Concepts Manual, open source
  6. projects are open to the public and they consequently have different
  7. licensing structures in place. This section describes the mechanism by
  8. which the :term:`OpenEmbedded Build System`
  9. tracks changes to
  10. licensing text and covers how to maintain open source license compliance
  11. during your project's lifecycle. The section also describes how to
  12. enable commercially licensed recipes, which by default are disabled.
  13. Tracking License Changes
  14. ========================
  15. The license of an upstream project might change in the future. In order
  16. to prevent these changes going unnoticed, the
  17. :term:`LIC_FILES_CHKSUM`
  18. variable tracks changes to the license text. The checksums are validated
  19. at the end of the configure step, and if the checksums do not match, the
  20. build will fail.
  21. Specifying the ``LIC_FILES_CHKSUM`` Variable
  22. --------------------------------------------
  23. The :term:`LIC_FILES_CHKSUM` variable contains checksums of the license text
  24. in the source code for the recipe. Following is an example of how to
  25. specify :term:`LIC_FILES_CHKSUM`::
  26. LIC_FILES_CHKSUM = "file://COPYING;md5=xxxx \
  27. file://licfile1.txt;beginline=5;endline=29;md5=yyyy \
  28. file://licfile2.txt;endline=50;md5=zzzz \
  29. ..."
  30. .. note::
  31. - When using "beginline" and "endline", realize that line numbering
  32. begins with one and not zero. Also, the included lines are
  33. inclusive (i.e. lines five through and including 29 in the
  34. previous example for ``licfile1.txt``).
  35. - When a license check fails, the selected license text is included
  36. as part of the QA message. Using this output, you can determine
  37. the exact start and finish for the needed license text.
  38. The build system uses the :term:`S`
  39. variable as the default directory when searching files listed in
  40. :term:`LIC_FILES_CHKSUM`. The previous example employs the default
  41. directory.
  42. Consider this next example::
  43. LIC_FILES_CHKSUM = "file://src/ls.c;beginline=5;endline=16;\
  44. md5=bb14ed3c4cda583abc85401304b5cd4e"
  45. LIC_FILES_CHKSUM = "file://${WORKDIR}/license.html;md5=5c94767cedb5d6987c902ac850ded2c6"
  46. The first line locates a file in ``${S}/src/ls.c`` and isolates lines
  47. five through 16 as license text. The second line refers to a file in
  48. :term:`WORKDIR`.
  49. Note that :term:`LIC_FILES_CHKSUM` variable is mandatory for all recipes,
  50. unless the :term:`LICENSE` variable is set to "CLOSED".
  51. Explanation of Syntax
  52. ---------------------
  53. As mentioned in the previous section, the :term:`LIC_FILES_CHKSUM` variable
  54. lists all the important files that contain the license text for the
  55. source code. It is possible to specify a checksum for an entire file, or
  56. a specific section of a file (specified by beginning and ending line
  57. numbers with the "beginline" and "endline" parameters, respectively).
  58. The latter is useful for source files with a license notice header,
  59. README documents, and so forth. If you do not use the "beginline"
  60. parameter, then it is assumed that the text begins on the first line of
  61. the file. Similarly, if you do not use the "endline" parameter, it is
  62. assumed that the license text ends with the last line of the file.
  63. The "md5" parameter stores the md5 checksum of the license text. If the
  64. license text changes in any way as compared to this parameter then a
  65. mismatch occurs. This mismatch triggers a build failure and notifies the
  66. developer. Notification allows the developer to review and address the
  67. license text changes. Also note that if a mismatch occurs during the
  68. build, the correct md5 checksum is placed in the build log and can be
  69. easily copied to the recipe.
  70. There is no limit to how many files you can specify using the
  71. :term:`LIC_FILES_CHKSUM` variable. Generally, however, every project
  72. requires a few specifications for license tracking. Many projects have a
  73. "COPYING" file that stores the license information for all the source
  74. code files. This practice allows you to just track the "COPYING" file as
  75. long as it is kept up to date.
  76. .. note::
  77. - If you specify an empty or invalid "md5" parameter,
  78. :term:`BitBake` returns an md5
  79. mis-match error and displays the correct "md5" parameter value
  80. during the build. The correct parameter is also captured in the
  81. build log.
  82. - If the whole file contains only license text, you do not need to
  83. use the "beginline" and "endline" parameters.
  84. Enabling Commercially Licensed Recipes
  85. ======================================
  86. By default, the OpenEmbedded build system disables components that have
  87. commercial or other special licensing requirements. Such requirements
  88. are defined on a recipe-by-recipe basis through the
  89. :term:`LICENSE_FLAGS` variable
  90. definition in the affected recipe. For instance, the
  91. ``poky/meta/recipes-multimedia/gstreamer/gst-plugins-ugly`` recipe
  92. contains the following statement::
  93. LICENSE_FLAGS = "commercial"
  94. Here is a
  95. slightly more complicated example that contains both an explicit recipe
  96. name and version (after variable expansion)::
  97. LICENSE_FLAGS = "license_${PN}_${PV}"
  98. In order for a component restricted by a
  99. :term:`LICENSE_FLAGS` definition to be enabled and included in an image, it
  100. needs to have a matching entry in the global
  101. :term:`LICENSE_FLAGS_ACCEPTED`
  102. variable, which is a variable typically defined in your ``local.conf``
  103. file. For example, to enable the
  104. ``poky/meta/recipes-multimedia/gstreamer/gst-plugins-ugly`` package, you
  105. could add either the string "commercial_gst-plugins-ugly" or the more
  106. general string "commercial" to :term:`LICENSE_FLAGS_ACCEPTED`. See the
  107. ":ref:`dev-manual/licenses:license flag matching`" section for a full
  108. explanation of how :term:`LICENSE_FLAGS` matching works. Here is the
  109. example::
  110. LICENSE_FLAGS_ACCEPTED = "commercial_gst-plugins-ugly"
  111. Likewise, to additionally enable the package built from the recipe
  112. containing ``LICENSE_FLAGS = "license_${PN}_${PV}"``, and assuming that
  113. the actual recipe name was ``emgd_1.10.bb``, the following string would
  114. enable that package as well as the original ``gst-plugins-ugly``
  115. package::
  116. LICENSE_FLAGS_ACCEPTED = "commercial_gst-plugins-ugly license_emgd_1.10"
  117. As a convenience, you do not need to specify the
  118. complete license string for every package. You can use
  119. an abbreviated form, which consists of just the first portion or
  120. portions of the license string before the initial underscore character
  121. or characters. A partial string will match any license that contains the
  122. given string as the first portion of its license. For example, the
  123. following value will also match both of the packages
  124. previously mentioned as well as any other packages that have licenses
  125. starting with "commercial" or "license".
  126. ::
  127. LICENSE_FLAGS_ACCEPTED = "commercial license"
  128. License Flag Matching
  129. ---------------------
  130. License flag matching allows you to control what recipes the
  131. OpenEmbedded build system includes in the build. Fundamentally, the
  132. build system attempts to match :term:`LICENSE_FLAGS` strings found in
  133. recipes against strings found in :term:`LICENSE_FLAGS_ACCEPTED`.
  134. A match causes the build system to include a recipe in the
  135. build, while failure to find a match causes the build system to exclude
  136. a recipe.
  137. In general, license flag matching is simple. However, understanding some
  138. concepts will help you correctly and effectively use matching.
  139. Before a flag defined by a particular recipe is tested against the
  140. entries of :term:`LICENSE_FLAGS_ACCEPTED`, the expanded
  141. string ``_${PN}`` is appended to the flag. This expansion makes each
  142. :term:`LICENSE_FLAGS` value recipe-specific. After expansion, the
  143. string is then matched against the entries. Thus, specifying
  144. ``LICENSE_FLAGS = "commercial"`` in recipe "foo", for example, results
  145. in the string ``"commercial_foo"``. And, to create a match, that string
  146. must appear among the entries of :term:`LICENSE_FLAGS_ACCEPTED`.
  147. Judicious use of the :term:`LICENSE_FLAGS` strings and the contents of the
  148. :term:`LICENSE_FLAGS_ACCEPTED` variable allows you a lot of flexibility for
  149. including or excluding recipes based on licensing. For example, you can
  150. broaden the matching capabilities by using license flags string subsets
  151. in :term:`LICENSE_FLAGS_ACCEPTED`.
  152. .. note::
  153. When using a string subset, be sure to use the part of the expanded
  154. string that precedes the appended underscore character (e.g.
  155. ``usethispart_1.3``, ``usethispart_1.4``, and so forth).
  156. For example, simply specifying the string "commercial" in the
  157. :term:`LICENSE_FLAGS_ACCEPTED` variable matches any expanded
  158. :term:`LICENSE_FLAGS` definition that starts with the string
  159. "commercial" such as "commercial_foo" and "commercial_bar", which
  160. are the strings the build system automatically generates for
  161. hypothetical recipes named "foo" and "bar" assuming those recipes simply
  162. specify the following::
  163. LICENSE_FLAGS = "commercial"
  164. Thus, you can choose to exhaustively enumerate each license flag in the
  165. list and allow only specific recipes into the image, or you can use a
  166. string subset that causes a broader range of matches to allow a range of
  167. recipes into the image.
  168. This scheme works even if the :term:`LICENSE_FLAGS` string already has
  169. ``_${PN}`` appended. For example, the build system turns the license
  170. flag "commercial_1.2_foo" into "commercial_1.2_foo_foo" and would match
  171. both the general "commercial" and the specific "commercial_1.2_foo"
  172. strings found in the :term:`LICENSE_FLAGS_ACCEPTED` variable, as expected.
  173. Here are some other scenarios:
  174. - You can specify a versioned string in the recipe such as
  175. "commercial_foo_1.2" in a "foo" recipe. The build system expands this
  176. string to "commercial_foo_1.2_foo". Combine this license flag with a
  177. :term:`LICENSE_FLAGS_ACCEPTED` variable that has the string
  178. "commercial" and you match the flag along with any other flag that
  179. starts with the string "commercial".
  180. - Under the same circumstances, you can add "commercial_foo" in the
  181. :term:`LICENSE_FLAGS_ACCEPTED` variable and the build system not only
  182. matches "commercial_foo_1.2" but also matches any license flag with
  183. the string "commercial_foo", regardless of the version.
  184. - You can be very specific and use both the package and version parts
  185. in the :term:`LICENSE_FLAGS_ACCEPTED` list (e.g.
  186. "commercial_foo_1.2") to specifically match a versioned recipe.
  187. Other Variables Related to Commercial Licenses
  188. ----------------------------------------------
  189. There are other helpful variables related to commercial license handling,
  190. defined in the
  191. ``poky/meta/conf/distro/include/default-distrovars.inc`` file::
  192. COMMERCIAL_AUDIO_PLUGINS ?= ""
  193. COMMERCIAL_VIDEO_PLUGINS ?= ""
  194. If you
  195. want to enable these components, you can do so by making sure you have
  196. statements similar to the following in your ``local.conf`` configuration
  197. file::
  198. COMMERCIAL_AUDIO_PLUGINS = "gst-plugins-ugly-mad \
  199. gst-plugins-ugly-mpegaudioparse"
  200. COMMERCIAL_VIDEO_PLUGINS = "gst-plugins-ugly-mpeg2dec \
  201. gst-plugins-ugly-mpegstream gst-plugins-bad-mpegvideoparse"
  202. LICENSE_FLAGS_ACCEPTED = "commercial_gst-plugins-ugly commercial_gst-plugins-bad commercial_qmmp"
  203. Of course, you could also create a matching list for those
  204. components using the more general "commercial" in the
  205. :term:`LICENSE_FLAGS_ACCEPTED` variable, but that would also enable all
  206. the other packages with :term:`LICENSE_FLAGS`
  207. containing "commercial", which you may or may not want::
  208. LICENSE_FLAGS_ACCEPTED = "commercial"
  209. Specifying audio and video plugins as part of the
  210. ``COMMERCIAL_AUDIO_PLUGINS`` and ``COMMERCIAL_VIDEO_PLUGINS`` statements
  211. (along with the enabling :term:`LICENSE_FLAGS_ACCEPTED`) includes the
  212. plugins or components into built images, thus adding support for media
  213. formats or components.
  214. Maintaining Open Source License Compliance During Your Product's Lifecycle
  215. ==========================================================================
  216. One of the concerns for a development organization using open source
  217. software is how to maintain compliance with various open source
  218. licensing during the lifecycle of the product. While this section does
  219. not provide legal advice or comprehensively cover all scenarios, it does
  220. present methods that you can use to assist you in meeting the compliance
  221. requirements during a software release.
  222. With hundreds of different open source licenses that the Yocto Project
  223. tracks, it is difficult to know the requirements of each and every
  224. license. However, the requirements of the major FLOSS licenses can begin
  225. to be covered by assuming that there are three main areas of concern:
  226. - Source code must be provided.
  227. - License text for the software must be provided.
  228. - Compilation scripts and modifications to the source code must be
  229. provided.
  230. There are other requirements beyond the scope of these three and the
  231. methods described in this section (e.g. the mechanism through which
  232. source code is distributed).
  233. As different organizations have different methods of complying with open
  234. source licensing, this section is not meant to imply that there is only
  235. one single way to meet your compliance obligations, but rather to
  236. describe one method of achieving compliance. The remainder of this
  237. section describes methods supported to meet the previously mentioned
  238. three requirements. Once you take steps to meet these requirements, and
  239. prior to releasing images, sources, and the build system, you should
  240. audit all artifacts to ensure completeness.
  241. .. note::
  242. The Yocto Project generates a license manifest during image creation
  243. that is located in ``${DEPLOY_DIR}/licenses/``\ `image_name`\ ``-``\ `datestamp`
  244. to assist with any audits.
  245. Providing the Source Code
  246. -------------------------
  247. Compliance activities should begin before you generate the final image.
  248. The first thing you should look at is the requirement that tops the list
  249. for most compliance groups --- providing the source. The Yocto Project has
  250. a few ways of meeting this requirement.
  251. One of the easiest ways to meet this requirement is to provide the
  252. entire :term:`DL_DIR` used by the
  253. build. This method, however, has a few issues. The most obvious is the
  254. size of the directory since it includes all sources used in the build
  255. and not just the source used in the released image. It will include
  256. toolchain source, and other artifacts, which you would not generally
  257. release. However, the more serious issue for most companies is
  258. accidental release of proprietary software. The Yocto Project provides
  259. an :ref:`archiver <ref-classes-archiver>` class to
  260. help avoid some of these concerns.
  261. Before you employ :term:`DL_DIR` or the :ref:`archiver <ref-classes-archiver>` class, you need to
  262. decide how you choose to provide source. The source :ref:`archiver <ref-classes-archiver>` class
  263. can generate tarballs and SRPMs and can create them with various levels
  264. of compliance in mind.
  265. One way of doing this (but certainly not the only way) is to release
  266. just the source as a tarball. You can do this by adding the following to
  267. the ``local.conf`` file found in the :term:`Build Directory`::
  268. INHERIT += "archiver"
  269. ARCHIVER_MODE[src] = "original"
  270. During the creation of your
  271. image, the source from all recipes that deploy packages to the image is
  272. placed within subdirectories of ``DEPLOY_DIR/sources`` based on the
  273. :term:`LICENSE` for each recipe.
  274. Releasing the entire directory enables you to comply with requirements
  275. concerning providing the unmodified source. It is important to note that
  276. the size of the directory can get large.
  277. A way to help mitigate the size issue is to only release tarballs for
  278. licenses that require the release of source. Let us assume you are only
  279. concerned with GPL code as identified by running the following script:
  280. .. code-block:: shell
  281. # Script to archive a subset of packages matching specific license(s)
  282. # Source and license files are copied into sub folders of package folder
  283. # Must be run from build folder
  284. #!/bin/bash
  285. src_release_dir="source-release"
  286. mkdir -p $src_release_dir
  287. for a in tmp/deploy/sources/*; do
  288. for d in $a/*; do
  289. # Get package name from path
  290. p=`basename $d`
  291. p=${p%-*}
  292. p=${p%-*}
  293. # Only archive GPL packages (update *GPL* regex for your license check)
  294. numfiles=`ls tmp/deploy/licenses/$p/*GPL* 2> /dev/null | wc -l`
  295. if [ $numfiles -ge 1 ]; then
  296. echo Archiving $p
  297. mkdir -p $src_release_dir/$p/source
  298. cp $d/* $src_release_dir/$p/source 2> /dev/null
  299. mkdir -p $src_release_dir/$p/license
  300. cp tmp/deploy/licenses/$p/* $src_release_dir/$p/license 2> /dev/null
  301. fi
  302. done
  303. done
  304. At this point, you
  305. could create a tarball from the ``gpl_source_release`` directory and
  306. provide that to the end user. This method would be a step toward
  307. achieving compliance with section 3a of GPLv2 and with section 6 of
  308. GPLv3.
  309. Providing License Text
  310. ----------------------
  311. One requirement that is often overlooked is inclusion of license text.
  312. This requirement also needs to be dealt with prior to generating the
  313. final image. Some licenses require the license text to accompany the
  314. binary. You can achieve this by adding the following to your
  315. ``local.conf`` file::
  316. COPY_LIC_MANIFEST = "1"
  317. COPY_LIC_DIRS = "1"
  318. LICENSE_CREATE_PACKAGE = "1"
  319. Adding these statements to the
  320. configuration file ensures that the licenses collected during package
  321. generation are included on your image.
  322. .. note::
  323. Setting all three variables to "1" results in the image having two
  324. copies of the same license file. One copy resides in
  325. ``/usr/share/common-licenses`` and the other resides in
  326. ``/usr/share/license``.
  327. The reason for this behavior is because
  328. :term:`COPY_LIC_DIRS` and
  329. :term:`COPY_LIC_MANIFEST`
  330. add a copy of the license when the image is built but do not offer a
  331. path for adding licenses for newly installed packages to an image.
  332. :term:`LICENSE_CREATE_PACKAGE`
  333. adds a separate package and an upgrade path for adding licenses to an
  334. image.
  335. As the source :ref:`archiver <ref-classes-archiver>` class has already archived the original
  336. unmodified source that contains the license files, you would have
  337. already met the requirements for inclusion of the license information
  338. with source as defined by the GPL and other open source licenses.
  339. Providing Compilation Scripts and Source Code Modifications
  340. -----------------------------------------------------------
  341. At this point, we have addressed all we need to prior to generating the
  342. image. The next two requirements are addressed during the final
  343. packaging of the release.
  344. By releasing the version of the OpenEmbedded build system and the layers
  345. used during the build, you will be providing both compilation scripts
  346. and the source code modifications in one step.
  347. If the deployment team has a :ref:`overview-manual/concepts:bsp layer`
  348. and a distro layer, and those
  349. those layers are used to patch, compile, package, or modify (in any way)
  350. any open source software included in your released images, you might be
  351. required to release those layers under section 3 of GPLv2 or section 1
  352. of GPLv3. One way of doing that is with a clean checkout of the version
  353. of the Yocto Project and layers used during your build. Here is an
  354. example:
  355. .. code-block:: shell
  356. # We built using the dunfell branch of the poky repo
  357. $ git clone -b dunfell git://git.yoctoproject.org/poky
  358. $ cd poky
  359. # We built using the release_branch for our layers
  360. $ git clone -b release_branch git://git.mycompany.com/meta-my-bsp-layer
  361. $ git clone -b release_branch git://git.mycompany.com/meta-my-software-layer
  362. # clean up the .git repos
  363. $ find . -name ".git" -type d -exec rm -rf {} \;
  364. One thing a development organization might want to consider for end-user
  365. convenience is to modify
  366. ``meta-poky/conf/templates/default/bblayers.conf.sample`` to ensure that when
  367. the end user utilizes the released build system to build an image, the
  368. development organization's layers are included in the ``bblayers.conf`` file
  369. automatically::
  370. # POKY_BBLAYERS_CONF_VERSION is increased each time build/conf/bblayers.conf
  371. # changes incompatibly
  372. POKY_BBLAYERS_CONF_VERSION = "2"
  373. BBPATH = "${TOPDIR}"
  374. BBFILES ?= ""
  375. BBLAYERS ?= " \
  376. ##OEROOT##/meta \
  377. ##OEROOT##/meta-poky \
  378. ##OEROOT##/meta-yocto-bsp \
  379. ##OEROOT##/meta-mylayer \
  380. "
  381. Creating and
  382. providing an archive of the :term:`Metadata`
  383. layers (recipes, configuration files, and so forth) enables you to meet
  384. your requirements to include the scripts to control compilation as well
  385. as any modifications to the original source.
  386. Compliance Limitations with Executables Built from Static Libraries
  387. -------------------------------------------------------------------
  388. When package A is added to an image via the :term:`RDEPENDS` or :term:`RRECOMMENDS`
  389. mechanisms as well as explicitly included in the image recipe with
  390. :term:`IMAGE_INSTALL`, and depends on a static linked library recipe B
  391. (``DEPENDS += "B"``), package B will neither appear in the generated license
  392. manifest nor in the generated source tarballs. This occurs as the
  393. :ref:`license <ref-classes-license>` and :ref:`archiver <ref-classes-archiver>`
  394. classes assume that only packages included via :term:`RDEPENDS` or :term:`RRECOMMENDS`
  395. end up in the image.
  396. As a result, potential obligations regarding license compliance for package B
  397. may not be met.
  398. The Yocto Project doesn't enable static libraries by default, in part because
  399. of this issue. Before a solution to this limitation is found, you need to
  400. keep in mind that if your root filesystem is built from static libraries,
  401. you will need to manually ensure that your deliveries are compliant
  402. with the licenses of these libraries.
  403. Copying Non Standard Licenses
  404. =============================
  405. Some packages, such as the linux-firmware package, have many licenses
  406. that are not in any way common. You can avoid adding a lot of these
  407. types of common license files, which are only applicable to a specific
  408. package, by using the
  409. :term:`NO_GENERIC_LICENSE`
  410. variable. Using this variable also avoids QA errors when you use a
  411. non-common, non-CLOSED license in a recipe.
  412. Here is an example that uses the ``LICENSE.Abilis.txt`` file as
  413. the license from the fetched source::
  414. NO_GENERIC_LICENSE[Firmware-Abilis] = "LICENSE.Abilis.txt"