|
|
Log in / Subscribe / Register

Streamlining the compliance process

Streamlining the compliance process

Posted May 6, 2017 13:25 UTC (Sat) by aggelos (subscriber, #41752)
In reply to: Streamlining the compliance process by corbet
Parent article: The rise of copyright trolls

LF is doing quite a bit in this area. OpenChain is there to help companies set up their compliance programs. SPDX is a long-running effort to make it easy to document the provenance of the software in any given distribution. There's a whole list of publications, including the book by Armijn and Shane mentioned elsewhere in this conversation. They also offer an online course in "compliance basics" for free.

It's clear the LF is publishing a lot of documents on how to do compliance as a company - I skimmed the book by Armijn et al. and the thing that stood out, other than the erasure of GPLv3 (people don't ship samba in embedded devices?), is the number of LF documents mentioned in Appendix 1. Only LF documents, come to think of it. Almost as if there are no other publications on the subject.

Documenting an arduous process is well and good and will remain necessary. It is however not the same thing as making said process easier (for instance, by pursuing tooling improvements). My question was about the latter aspect.

My own wish is that the LF would do more to address the outright compliance problems in the industry, and I've told them so. If there's anything happening there it's below the radar, but they are doing quite a bit to make things easier for the companies that want to follow the rules.

It is good to hear about preventive work. What more do you think they could be doing to address the ongoing compliance problems?


to post comments

Streamlining the compliance process

Posted May 6, 2017 14:06 UTC (Sat) by pabs (subscriber, #43278) [Link] (1 responses)

> (people don't ship samba in embedded devices?)

They definitely do; I have a router that I only found out runs Linux (and is not GPL compliant) because of a mention of Samba in the web interface.

Streamlining the compliance process

Posted May 6, 2017 20:34 UTC (Sat) by zlynx (guest, #2285) [Link]

Just wanted to point out that Samba does not imply a Linux OS. Samba also runs on BSD, OS X, and could have been ported to almost any POSIX supporting OS. Haiku and QNX for example.

Streamlining the compliance process

Posted May 7, 2017 17:05 UTC (Sun) by jra (subscriber, #55261) [Link] (1 responses)

> people don't ship samba in embedded devices?

Oh that's just wrong. We have *many* OEMs who ship Samba in embedded devices. Google even ships Samba code (as an app) in ChromeOS.

https://chrome.google.com/webstore/detail/network-file-sh...

Streamlining the compliance process

Posted May 7, 2017 18:09 UTC (Sun) by aggelos (subscriber, #41752) [Link]

people don't ship samba in embedded devices?
Oh that's just wrong.

Notice the question mark. I was simply pointing out how odd it is that a book called "Practical GPL Compliance" which

is designed for engineers shipping products with GPL-licensed software included (e.g., consumer electronics, drones, IoT devices)
acts as if GPLv3 does not exist (other than a nod) or is not relevant to their target audience.

Personally, I'm also missing the tiniest bit of explanation for copyleft as a concept or motivation to comply with it. I.e. something to the effect of "the GPL is not just a nuisance, it is also beneficial to your organization because [...]". This is something I expect to find in texts which describe to engineers how to take care of a non-engineering task that is probably low in their priority list. Opinions (and intentions) might differ, of course.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds