Alpine Linux 3.4.0 Released
alpinelinux.org
alpinelinux.org
I don't see a new Docker tag yet: https://hub.docker.com/r/library/alpine/tags/ Anyone know when it's expected to hit? Edit: here's the issue tracking it https://github.com/gliderlabs/docker-alpine/issues/178
Did that change?
Re: GRsecurity is preventing others from employing their rights under version 2 the GPL to redistribute source code Richard Stallman (May 31 2016 10:27 PM)
[[[ To any NSA and FBI agents reading my email: please consider ]]] [[[ whether defending the US Constitution against all enemies, ]]] [[[ foreign or domestic, requires you to follow Snowden's example. ]]]
If I understand right, this is a matter of GPL 2 on the Linux patches. Is that right? If so, I think GRsecurity is violating the GPL on Linux.
-- Dr Richard Stallman President, Free Software Foundation (gnu.org, fsf.org) Internet Hall-of-Famer (internethalloffame.org) Skype: No way! See stallman.org/skype.html.
>54843968 The GPLv2 is a text that outlines by what ways a licensee may use a copyrighted work provided by the licensor. In the case that the agreement is not followed standard copyright law applies (all rights reserved).
Contracts are often known as "private law", it allows parties to make their own agreement.
So yes, the agreement here is controlling "law", while the public law that allows such agreements to alienate rights to copyrighted works to be enforceable by the licensee so as to protect him against the licensor is the 1973 us copyright act.
However when the licensee violates the agreement he cannot find refuge in that agreement any longer.
Go attend law school.
And YES, I have both graduated law school and passed the bar.
Have you? No.
Might be a reason why you don't know what your talking about and can only cite the GPL itself (a small 1 page document) and nothing that surrounds it (you don't even know what it hangs on).
Please people, do not listen to that fool
I'm also surprised nobody has asked the SFConservancy to take GRSecurity to court over it. You'd think even Linus (who doesn't agree with the underlying spirit of the GPL -- all software should be free) would have a problem with "not getting patches back".
Thing is, your distribution chain needs to be extremely tight (watermarked data or careful chain of trust) or else content will just get leaked every patch.
Some more excerpts: ---------------------------------
>>54842691
>Are they not redistributing the source? Correct > Are they forbidding others from redistributing the source? Correct.
> Seems to me they're saying "if you redistribute the source, we won't do business with you again/charge you a lot for a renewal". >How is this illegal? Hmm so there is Licensor (Linux Devs), they place their copyrighted work out there, under conditions.
There is Licensee (Brad Spengler, Grsecurity), he takes the copyrighted work under the terms and conditions and creates a derivative work (not allowed under pure copyright, only permissible as per the will of the rightsholder, as stated in the agreement)
The license states that, for permission to create a derivative work, one must allow others who gain access to that derivative work to redistribute said work, modify it, so on and so forth (otherwise there is no permission under the agreement).
Licensee creates derivative work.
Licensee sublicenses derivative work to sublicensee. Licensee stipulates that sublicensee may not redistribute derivative work. Licensee makes threats to ensure compliance with this demand that sublicensee not distribute derivative work. These demands are met: sublicensee dares not redistribute the work.
The conditions the Licensor placed on his work have been spurned, ignored, and abolished by the actions of the licensee.
Licensee has frustrated the purpose of the grant he has been give by licensor. It does not matter specifically how he went about doing so. He did so.
>You can argue that they're assholes, but this isn't illegal.
So in other words you are saying "you can argue that Brad Spengler has treated the agreement in... bad faith". Thank you for restating a portion of my case, in inadvertently
"But JUDGE, bad faith, when it comes to business dealings, contracts, grants, and the like is fine and good!"
>bla bla
So have you attended law school and passed the bar?
I have.
Here are some additional arguments by lay people defending GRSecurity and rebuttals based in an understanding of the law (which are rejected with bays and hollers from the lay crowd who seem to believe that an NDA makes the GPL equal in fact to the BSD license grant):
---------------
>>54842745 >>54842791 >>54842820
There is a legal term for this. It's called acting in bad faith. That often gets your contract nullified. Here there is a license grant. Spengler is acting in bad faith to frustrate its purpose. It does not matter if he is breaking legs, threatening to expose secrets, or threatining to raise prices to exorbidant rates, or to cease sending the patches: What matters is that his goal is to deny the sublicensee the right given to the sublicensee by the original licensor, and that he has obtained that goal via his actions (the threats here).
He has frustrated the purpose of the agreement (the grant) he had with the original licensor, and thus the grant fails. In other words: he has violated the license.
It's very simple, I don't know why some here do not understand it, it's like you never graduated law school nor passed the bar.
The courts are not dumb, they've seen people try to be "clever" like this before for well over 100 years. Just because some here have never heard of any of it doesn't mean what they then grind together their uneducated brain is correct (even though they will swear to high heaven it is, cuz it makes sence to them, centuries of caselaw and even black letter law be damned).
--------------------------
>>54844263 >Which was not broken since the sub-licensee still has all the privileges and obligations given to them by the GPL.
Incorrect in practice: the sublicensees have been effectively prevented from exercising the right given to them by the original licensor (linux devs) by the action of the intimediary (grsecurity). In this case, since spengler is working to frustrate the purpose of the grant given by the original licensor the court may very well nullify his right to seek cover of the license: IE: he has acted in bad faith in attempting (successfully here) to DENY a permission granted to the sublicensee by the original licensor and thus has violated the license and can be sued by the original licensor for copyright infringement. (Not to mention the sublicensee for tort violations). Spengler has interfered with the relationship between the licensor (the rightsholder) and the sublicensee (likely a quazi-contractual relationship).
Why is this so hard for you to understand?
Please, go to law school or keep you mouth shut.
And other people here, why is it that you choose to believe people who have not been to law school and who have not passed the bar, over me, who has done both?
Why?
They read ONE document, the agreement. I've read books.
Yet you decide that THEY know what they are talking about? That the written grant exists in a vacume.
It's ONE FUCKING PAGE. That's a completely integrated, four corners, covers all cases document to you people?
Do you even know what I just said?
Because ignorance (of the law) is bliss.
Here are some discussions on this topic and some excerps: http://boards.4chan.org/g/thread/54839391 https://sys.8ch.net/tech/res/605120.html
---------------------- GRsecurity is preventing others from employing their rights under version 2 the GPL to redistribute (by threatening them with a non-renewal of a contract to recive this patch to the linux kernel.) (GRsecurity is a derivative work of the linux kernel (it is a patch))
People who have dealt with them have attested to this fact: https://www.reddit.com/r/KotakuInAction/comments/4grdtb/cens... "You will also lose the access to the patches in the form of grsec not renewing the contract. Also they've asked us (a Russian hosting company) for $17000+ a year for access their stable patches. $17k is quite a lot for us. A question about negotiating a lower price was completely ignored. Twice." -- fbt2lurker
And it is suggested to be the case here aswell: https://www.reddit.com/r/linux/comments/4gxdlh/after_15_year... "Do you work for some company that pays for Grsecurity? If so then would you kindly excersise the rights given to you by GPL and send me a tarball of all the latest patches and releases?" -- lolidaisuki "sadly (for this case) no, i work in a human rights organization where we get the patches by a friendly and richer 3rd party of the same field. we made the compromise to that 3rd party to not distribute the patches outside and as we deal with some critical situations i cannot afford to compromise that even for the sake of gpl :/ the "dumber" version for unstable patches will make a big problem for several projects, i would keep an eye on them. this situation cannot be hold for a long time" -- disturbio
Is this not tortious interference, on grsecurity's (Brad Spengler) part, with the quazi-contractual relationship the sublicensee has with the original licensor?
(Also Note: the stable branch now contains features that will never make it to the "testing" branch, and are not allowed to be redistributed, per the scheme mentioned above (which has been successful: not one version of the stable branch has been released by anyone, even those asked to do so, since the scheme has been put in place (they say they cannot as they cannot lose access to the patch as that may cost the lives and freedom of activists in latin america))) https://twitter.com/marcan42/status/726101158561882112 @xoreipeip @grsecurity they call it a "demo" version "20:14 < spender> what's in the public version is < 1/5th the size of the full version" oreipeip @grsecurity "20:21 < spender> also it wouldn't be as fast as the commercial version [...] there are missing optimization passes" ------------------------------
Big news. This was a huge blocker in containerized environments, now can't wait to try this out. Great work!
It is mainly about size on the base install, long before shellshock. Many use cases only need basic tools, eg configuring the Alpine system itself.
If you have no reason to interact with the userland tools inside a Docker container, you similarly have no reason to introduce their complexity and attack surface in a container designed to run one service.
My current "minimal" installation shows 25 SUID binaries (a large amount of them being systemd related...) and my server services need very few of these.
We still haven't hit any apparent bottlenecks using debian:jessie. Where are said bottlenecks? Where should I be paying attention?