Microsoft WinObjC: Restore original licenses
github.com
github.com
No org can be 100% perfect all of the time, no matter what processes they put in place. This looks like just a regular process failure.
I don't know what MS's are specifically, but we do everything from training new employees to verifying headers on outgoing releases (much to the annoyance of plenty of engineers who just want to release shit). I suspect they do the same.
Replacing headers with a standard header is pretty common. However, we require code segregation to prevent the issue that happened here (IE all third party codes goes in third party directories with an associating LICENSE file describing the license/notices). That makes it easy to tell that someone screwed up when replacing headers.
Doing that is uncommon for most companies in practice (at least, when i surveyed my counterparts, most want to be doing it, but it doesn't really happen in practice with a > 50% rate due to not being closely involved enough with engineering and development practices to make it easy).
Most of them are happy to mix up third party code with their own code, or really bad at enforcing, and then when you go to release it, you don't notice things like what happened here.
Then again, we also tell new employees that we care about getting the notices and credits right not because we are worried about legal repercussions, but because of the golden rule (you'd be pissed if you ask for one small thing to use you code, and they can't be bothered to do it, and we don't want other people to feel that way about us).
I suspect that is pretty different too :)
But this seems like an object lesson in proving that. The people whose headers were changed feel aggrieved regardless of the fact that it was probably a simple process screwup / whatever. They don't care about that. They care that somebody decided they really wanted to use it, and that it saved them time/energy/helped/whatever, but despite that, when they made the choice to use it, they didn't seem to bother to put the one small thing the author asked of them on "the list of things to do before release"
(Regardless of whether this is actually the case).
The process was incredibly cumbersome and I'm somewhat glad they've scaled back a bit, but this is much too far.
It shouldn't be. That's a fundamentally bad idea.
It'd be reasonable to put a standard header at the top, immediately followed by "Based on (other project):" and the header for that project. But changing those headers is never OK.
I don't think it's that bad of an idea. The MIT license says:
The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.
What that means is anybody's guess. I'd say if you include one copy somewhere you're pretty much off the hook.---
Per-file licenses are different. The only one I looked at is MPL2 and IIRC it mentions the little note doesn't have to be in the file.
Not "erasing MIT license headers", which is completely wrong.
Someone probably wrote a script (as often happens) that removes the first comment block (which they expected to be some internal-use +copyright comment) or something similar and added their headers , and it got applied to these files.
I know this, because we've stopped people from making the same mistake :)
Something for startups to keep in mind: if an IP acquisition by a large tech player is among your exit strategies, it behooves you to get your intellectual property ducks in a row, otherwise you're in for some awkward conversations with the acquiring company's legal team about the provenance of your codebase.
It is specifically to avoid these issues that most companies don't go through the trouble of open-sourcing their code. Not at all saying it's wrong to enforce licenses I'm just pointing out the obvious that companies that don't want to get into legal trouble avoid the issue altogether and discourage open source. A well known company I used to work for requires legal to sign-off anything that has to be open-sourced. A startup I currently work-off had to be audited for license compliance before a round of funding. One primary reason I see is that most engineers don't understand licensing very well. They don't understand when it's safe to use GPL and when it's not.
Hopefully they'll learn and get better at it as they go along. I really hope they don't get deterred from open sourcing their code and stop the current trend.
1. discourages people from committing code that isn't theirs 2. if there is bad code committed, we can determine the extent of it and so take corrective action 3. it's a great defense against false claims of bad code
If you're copying code from elsewhere, document where you got it from, and preserve all licenses. Don't delete copyright notices and license headers, ever. That's neither ridiculously complicated nor burdensome.
Complying with other license conditions is another matter, and that's why many companies have people or groups whose primary job is to understand and deal with those kinds of issues. But basic due diligence about copyright and license headers needs to be fundamental 101-level understanding.
Full disclosure: some of my code is in there, so I'm not an unbiased source.
I would expect better of Microsoft -- especially from a company that supported Oracle when suing Google over Android's copying of an API (which included an incidentally small number of actually-copied source). [1]
[1] http://www.infoworld.com/article/2613305/patents/microsoft--...
I have no idea how MS is going to rectify this.
1. Buy the rights from the original owners (if you are the owner, you can re - license your code under a different license).
2. MS can reimplement from scratch the problematic pieces of code.
3. MS can hire someone to write these missing pieces for them.
If I'm the writer of a GPL'd piece of software can I just decide to make it MIT one day?
What happens if I die tomorrow, could that code still be relicensed eventually?
What happens when there is no clear owner?
Other examples include MySQL, which was dual-licensed GPL and commercial, and KDE/Qt which also had a dual-licensing (and then a re-licensing).
If all contributors also accept to transfer copyright/ownership up-front, re-licensing is easier.
I'm guessing re-licensing after death would require waiting whatever period (70+ years?) for copyright to expire.
This stuff is relatively simple at its core. Copyright says, "You may not redistribute this work without permission from the copyright holder." An open source license says, "I grant you permission to redistribute this work, as long as you follow these conditions." Relicensing is just a matter of making another statement like that with different conditions.
If you die tomorrow, then the copyright transfers to your heirs, who could then do all the stuff you used to be able to do.
If there's no clear owner, then life becomes interesting. If there once was a clear owner who released the stuff with a license, that license is still valid, but relicensing isn't possible unless someone can demonstrate that they're the owner. If there was never a clear owner then you can't really use the stuff, although if you're brave you could proceed under the theory that if nobody claims ownership there is nobody to sue you.
Note to Microsoft: I will be happy to write you a new ObjC runtime if you'd like, at my usual rates.
I don't know offhand if their license would be suitable for Microsoft's purposes.
It's also kind of weird they're using OpenSSL instead of Microsoft's SChannel. Usually Microsoft are pretty good at only giving you one way to hang yourself in the security department - I'm a big fan of SSPI, even if the API is occasionally unwieldy. (And as soon as I wrote that, I remembered CryptoAPI vs CNG...)
Note that the commenting individual is the founder of the company acquired by Microsoft that provided this code.
For example, could I write program Foo.c (using CDDL license), which uses GPL'ed Bar.c and MIT'ed Dad.c (both unmodified)?
In some cases, such as with WinObjC, reverting to the most restrictive license makes the work unsuited for its intended purpose.
However, many copyleft OSS licenses have clauses that are genuinely incompatible with both other copyleft licenses, and less-liberal OSS licenses -- in such cases it's impossible to legally combine code under the licenses.
In your example, the CDDL and the GPL have incompatible copyleft restrictions; your resulting program wouldn't be distributable under the provided licenses.
A more common incompatibility example is that of the OpenSSL license and the GPL; GNU maintains a fairly complete list of incompatibile licenses here: http://www.gnu.org/licenses/license-list.en.html#GPLIncompat...
The GPL can basically not coexist with any other license, though lots of licenses (though perhaps fewer than the FSF claims, especially for GPLv2 and previous) allow code to be relicensed under the GPL (which is different from the code coexisting.)
The reverse is emphatically not true, GPL code generally cannot be relicensed (downstream; the copyright owner can do whatever they want) to another license, except newer GPL versions if the optional "or any later version" clause is included with the GPL.
Anybody who's terribly interested in all of this will probably enjoy reading the GPL FAQ, especially this bit:
http://www.gnu.org/licenses/gpl-faq.en.html#WhatIsCompatible
IANAL, YMMV, HTH, WTFBBQ, ETC.
By default, all code is copyrighted and effectively proprietary. Open-source licenses are one way to grant permission to copy them. Fancy contracts with expensive lawyers are another way. You can only do what the licenses way you can do, and in particular, the GPL says that you may not apply "additional restrictions" and the CDDL has some clauses that the GPL doesn't. So there is no way to satisfy both licenses with regards to redistribution.
You can negotiate for a different license. (This seems to be what MS did with objfw.)
Some would even claim that CDDL was designed solely to ensure ZFS could not be integrated with linux.
s5msft commented 3 hours ago
@cjwl We're on it and definitely want to make this right. As a bit of background, (some of) our source code was originally C++ based (marked up to act like Objective-C). We then ran that source through a tool to generate "real" Objective-C code.
In any case, we're going through Foundation right now and will absolutely make this right.
They seem pretty serious about me, and honestly, their acknowledged mistake is pretty understandable. They also have loads of money that people could sue them for, so I'm sure they don't want to risk themselves either.They also got the copyright headers wrong when trying to fix Cocotron's stripped copyrights:
https://github.com/Microsoft/WinObjC/issues/35#issuecomment-...
I was afraid my post might generate some crap in the comments over there, but I hope it's a net gain overall!
The "I can assure you that I do not read HN and am far more intelligent than you" comment from MTWomg was amusing but overall I'm afraid that one guy is capable of doing more damage to an unmoderated conversation than the rest of us are capable of mitigating. (how would we actually do that?)
However, last I heard, the only way to ban a user from a GitHub organization's issue tracker (as opposed to an individual's) is to contact support.
With respect, it genuinely isn't. Nothing changed from you submitting this thread, because the resolutions were already in flight by the time this hit the front page.
I have contacted GitHub for clarity on these points, since as it stands, it seems like locking was a kneejerk "put out a fire" mechanism that is really unsupported and betrays GitHub not caring about abuse on their platform. They join Twitter in that regard.
HN destroys threads more than Reddit, in my experience, but both are worth hitting.
Everything else is just too odd. And if I or any other people below me pulls a library in that isn't APL2 i will refuse the PR. It just sucks how aweful it is to write programs with awesome licenses that are incompatible. But you just want to use existing things, which you can't do cause people are dumb and doesn't write licenses which are happy together. I mean why can't I write GPLv3 Code and pull other Open Source licensed things, too? It's still Open. And that's the problem the Open in Open Source mostly isn't open. I see the source, but I can't do anything with it.