|
|
Log in / Subscribe / Register

Protecting the open-source license commons

Protecting the open-source license commons

Posted Nov 2, 2018 18:10 UTC (Fri) by Cyberax (✭ supporter ✭, #52523)
In reply to: Protecting the open-source license commons by Paf
Parent article: Protecting the open-source license commons

I have two suggestions:
1) Convert Linux to Apache 2 license just to be honest with everyone.
2) Change the Linux mascot to a giraffe.

More seriously, I want to see concerted efforts to sue violating companies from the core IP holders of Linux (to avoid VMWare's "minor contributor" issues).

And no wishy-washy "sue for compliance". Sue for damages, including punitive damage in jurisdictions that allow for it.

The current status quo actually rewards companies that are behaving badly, while hurting the honest players.


to post comments

Protecting the open-source license commons

Posted Nov 2, 2018 19:18 UTC (Fri) by mpr22 (subscriber, #60784) [Link] (15 responses)

> Sue for damages, including punitive damage in jurisdictions that allow for it.

I would find it very satisfying to see high-profile infringers get sued for enormous piles of money.

I don't think I'd find the job losses attendant on the subsequent liquidations, or the increased ability for anti-software-freedom propagandists to point to "real cases" that "support" their "GPL is burning radioactive poison and you shouldn't let it get anywhere near your computers" stance, anywhere near as satisfying.

So I'm kind of conflicted on the subject.

Protecting the open-source license commons

Posted Nov 2, 2018 19:40 UTC (Fri) by farnz (subscriber, #17727) [Link] (13 responses)

On the other hand, in the current situation, I've had big vendors (under NDA, or I'd disclose names) tell me that their closed-source Linux kernel (not kernel modules - entire kernel binaries) are fine, because there are no real cases of someone being sued and facing real penalties for failing to distribute source.

It's a tradeoff - do you want semiconductor vendors to consider it OK to send binaries only for their entire "SDK" that you're supposed to modify and redistribute, or do you want to risk the anti-freedom people pointing to real cases?

Protecting the open-source license commons

Posted Nov 2, 2018 20:54 UTC (Fri) by pbonzini (subscriber, #60935) [Link] (12 responses)

You had received a derivative work of Linux and you were entitled to receive the sources in the form preferred to make modifications.

So why didn't you request sources? This is not about _you_ getting sued, it's about then not getting sued _by you_.

Protecting the open-source license commons

Posted Nov 2, 2018 20:57 UTC (Fri) by Cyberax (✭ supporter ✭, #52523) [Link] (4 responses)

Because large hardware vendors just say: "Sucks to be you. Go on sue us. Make my day"

Protecting the open-source license commons

Posted Nov 2, 2018 21:22 UTC (Fri) by jebba (guest, #4439) [Link] (3 responses)

When I asked Dell lawyers for source to one of their $10k+ Debian based switches (S4048T-ON), they said no one had asked before. They subsequently pointed me to a newly created repo they had of the linux kernel. It wasn't complete sources, but they did something. I think if more people just push to get sources from big companies like that, they'll start to provide more.

Protecting the open-source license commons

Posted Nov 2, 2018 21:27 UTC (Fri) by jebba (guest, #4439) [Link]

It looks like they have added more:

737.7 MB OS10_10.4.0-R3_debian_source.tgz

https://bintray.com/dell-networking/os10-linux-sources/linux

Protecting the open-source license commons

Posted Nov 2, 2018 21:51 UTC (Fri) by Cyberax (✭ supporter ✭, #52523) [Link] (1 responses)

Dell are good guys, remember DKMS and those nice Dell laptops with Linux?

The main offenders are companies making mobile or IoT hardware. There's not a single smartphone out there that runs without binary kernel modules.

Protecting the open-source license commons

Posted Nov 4, 2018 23:22 UTC (Sun) by excors (subscriber, #95769) [Link]

I'd be very surprised if that was true, since I've worked with a few kernels for various SoCs and don't remember seeing anything in the kernel that wasn't built from source. The only exception I remember is that VTune supplied some profiling drivers as .ko files, but they were only used by a few people during development.

They do usually have kernel drivers that are designed to work exclusively with userspace binary blobs that the phone vendor doesn't have full source access to (for 3D graphics, cameras, etc), or to work with firmware blobs, but that's probably not a GPL issue since the kernel driver source is released and the binary parts are clearly separate from the kernel.

Protecting the open-source license commons

Posted Nov 2, 2018 21:13 UTC (Fri) by farnz (subscriber, #17727) [Link] (6 responses)

We did request sources - they pointed out that, under the NDA we'd signed, we could not ask for sources. And how exactly could we have sued them - we weren't ourselves copyright holders in the Linux kernel - as the GPL does not give us standing to sue when they say that they are not distributing to us under the GPL?

Protecting the open-source license commons

Posted Nov 6, 2018 3:57 UTC (Tue) by bkuhn (subscriber, #58642) [Link] (5 responses)

farnz, as I understand the situation you describe, it sounds likely that both parties involved are violating the GPL. (IANAL and TINLA and I'd need to study the situation closer to be sure of anything). I have heard about these kinds of NDAs, and even been shown them by GPL violation reporters. If you'd like to report the violation to Conservancy, compliance@sfconservancy.org is the address.

Protecting the open-source license commons

Posted Nov 6, 2018 9:06 UTC (Tue) by farnz (subscriber, #17727) [Link] (4 responses)

At the time, we reported it to the SFC, SFLC and FSFE; none of you were able to take sufficient action to get the violator to do anything.

AFAICT, the violator we informed you of at the time is still functioning this way several years later - they've certainly approached my current employer with a similar setup, and been forcefully declined.

Protecting the open-source license commons

Posted Nov 6, 2018 18:06 UTC (Tue) by bkuhn (subscriber, #58642) [Link] (3 responses)

Please refresh the thread with Conservancy if you don't mind. Of those organizations, Conservancy is the only one that enforces the GPL for Linux (and I believe, at all). I'll mention to Denver to expect your email when next he works (he works only one day a week).

Protecting the open-source license commons

Posted Nov 6, 2018 18:09 UTC (Tue) by farnz (subscriber, #17727) [Link] (2 responses)

I no longer have access to the thread - I've changed employer, and thus don't have access to my old employer's email system.

At the time, IIRC, it all fizzled out because our legal advisor stopped us sharing with you (because we had agreed to the NDA, and were getting distribution from the vendor under the NDA), and you could not take action without more evidence of the infringement than we could provide given the NDA we had agreed to.

Protecting the open-source license commons

Posted Nov 16, 2018 16:28 UTC (Fri) by Wol (subscriber, #4433) [Link] (1 responses)

iirc, farnz, you're British? And in Britain, violating copyright for commercial gain is a criminal offence.

NDAs are unenforceable when they're used to cover up illegal behaviour.

Of course that's the theory. Practice may be different ... but I really think that if they sue you for breaking the NDA, and you come back to the Judge "hey, they are behaving criminally and asking us to cover it up", the Judge will at least have to investigate that claim, and chuck the case out if you're right.

Cheers,
Wol

Protecting the open-source license commons

Posted Nov 16, 2018 16:49 UTC (Fri) by farnz (subscriber, #17727) [Link]

It's not as simple as "violating copyright for commercial gain is a criminal offence". The offences in the Copyright. Designs and Patents Act 1988 only apply if the violator has reason to believe that they're not violating; in the case I'm thinking of, the violator believed that as they were copyright owner of one part of the combined work, their license supersedes the GPL. Had they also committed the offence named in 107 subsection 2A (which requires monetary damages to the owner of the infringed copyright, not just infringement), then our legal advisor thought a prosecution might succeed; as it is, the violator raised the SFC's "principles of enforcement" as reason that they did not commit that offence.

Protecting the open-source license commons

Posted Nov 2, 2018 19:42 UTC (Fri) by Cyberax (✭ supporter ✭, #52523) [Link]

> I don't think I'd find the job losses attendant on the subsequent liquidations
Use the money from damages to fund OpenSource projects. Duh.

> or the increased ability for anti-software-freedom propagandists to point to "real cases" that "support" their "GPL is burning radioactive poison and you shouldn't let it get anywhere near your computers" stance, anywhere near as satisfying.
Then switch GPL to Apache 2 to be honest.

Protecting the open-source license commons

Posted Nov 3, 2018 14:19 UTC (Sat) by bkuhn (subscriber, #58642) [Link] (7 responses)

Cyberax, more Linux copyright holders joining our coalition at Conservancy would be welcome. "The more, the better" is always the case, and the coalition gets incrementally more strong with each person added. If you want to recruit for that, please do.

Note that another thing companies have done is sought to keep Conservancy representatives from speaking at places where Linux copyright holders are likely to go, in an effort to prevent those copyright holders from receiving the message that there is a GPL enforcement option for Linux copyright holders.

I think many of the critics of Conservancy who want more aggressive GPL enforcement are not realistic about what is politically viable in the current climate. We aren't capitulating by any means, but remember that every single day, big companies involved in Linux have a high agenda item to see if they can end GPL enforcement. This is a political reality. We are working around it, but it's not a trivially solvable problem. If you have ideas on how to succeed in this political struggle, again, I'm open to ideas.

Protecting the open-source license commons

Posted Nov 3, 2018 17:32 UTC (Sat) by Cyberax (✭ supporter ✭, #52523) [Link] (6 responses)

> Cyberax, more Linux copyright holders joining our coalition at Conservancy would be welcome. "The more, the better" is always the case, and the coalition gets incrementally more strong with each person added. If you want to recruit for that, please do.
My past employer is one of the good guys who takes licensing seriously, and I personally donated quite a bit to the SFC. I'm on board of several small private companies and as long as I'm there, they won't be doing GPL violations.

> I think many of the critics of Conservancy who want more aggressive GPL enforcement are not realistic about what is politically viable in the current climate. We aren't capitulating by any means
Yes you do. You said that yourself: "more aggressive GPL enforcement is not realistic".

> We are working around it, but it's not a trivially solvable problem. If you have ideas on how to succeed in this political struggle, again, I'm open to ideas.
Get a bunch of core kernel copyright holders (to make sure that they are not "minor contributors") and start lawsuits. Do it without resources from the Linux Foundation or any other violator-friendly body. It's really as simple as that.

Alternatively just relicense the kernel under Apache 2 to be honest with the good members of the community.

Protecting the open-source license commons

Posted Nov 5, 2018 7:48 UTC (Mon) by jospoortvliet (guest, #33164) [Link] (2 responses)

Wrt your last point - I think bhuhn has been reasonably clear that if he had those volunteers and resources, you could expect a lot more enforcement. I would also like to see a large corp pay significant damages or see an exec jailed for violations as I agree the good guys pay and bad ones don't right now but I am sure it isn't as easy as you male it seem.

Protecting the open-source license commons

Posted Nov 5, 2018 8:15 UTC (Mon) by paulj (subscriber, #341) [Link] (1 responses)

The solution is easy: Put a (significant) price on use outside of the copyleft licence conditions.

Protecting the open-source license commons

Posted Nov 5, 2018 10:43 UTC (Mon) by pizza (subscriber, #46) [Link]

There is another strategy that can sometimes be employed -- In some jurisdictions, removing copyright information/attribution from the work in question is a separate offence, with statutory penalties unrelated to actual damages.

Protecting the open-source license commons

Posted Nov 6, 2018 4:08 UTC (Tue) by bkuhn (subscriber, #58642) [Link] (2 responses)

> Get a bunch of core kernel copyright holders (to make sure that they are not "minor
> contributors") and start lawsuits. Do it without resources from the Linux Foundation or any
> other violator-friendly body. It's really as simple as that.

Funding lawsuits is not easy, because even if you expect to win, you won't get your judgement and attorney's fees paid until the *end* of the case, which could be a decade away. If you'd like to make a very large directed donation to Conservancy for a GPL enforcement lawsuit, Karen would be glad to talk to you about it.

If additional lawsuits were done as easily as you say, we'd have done them already, of course. There are certainly bad actor violators who refuse to comply and are taking a "fine, sue us" attitude.

But keep in mind that in addition to the expense of doing the litigation, there are powerful political actors who are working regularly to discredit and attack Conservancy to prevent us from moving forward on enforcement as well. They aren't fully successful by any means, but dealing with those attacks is still non-trivial effort.

Protecting the open-source license commons

Posted Nov 6, 2018 6:02 UTC (Tue) by Cyberax (✭ supporter ✭, #52523) [Link] (1 responses)

I can make a sizeable donation personally, but I probably won't be able to fund the whole lawsuit. How about a crowd-funding campaign though?

I understand that the actual lawsuits are not easy, but you do have to start somewhere.

It would be nice if you changed your policy to reflect that you WILL sue for punitive damages. To avoid moral conflict, pledge all the damages (minus lawsuit costs) to fund OpenSource development and further enforcement.

Protecting the open-source license commons

Posted Nov 6, 2018 18:04 UTC (Tue) by bkuhn (subscriber, #58642) [Link]

Not sure what you mean by punitive damages. Copyright cases in the USA have actual and statutory damages. In the BusyBox cases, Conservancy asked for both the maximum allowable. The cases settled, but our claim was for the most the court would allow.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds