A discussion of Fedora’s legal state
lwn.net
lwn.net
There's an incredible amount of self-invented licenses and if there's one advice I'd like to give to all free and open source devs: Don't do this. It annoys people in Linux distros who have to decide what to do with your code, whether it's free and there almost certainly is an existing, widely used license that does what you want. Choose one of the mainstream licenses like MIT, GPL (2 or 3, whatever, we know what it means, it's fine), Apache-2 or even something like WTFPL. It's all fine, we know what it means. But don't pick three chapters of license A and one of License B to have your unique mix.
I also remember we had a LICENSE as-is, which was supposed to mean something very specific, but it had a horrible result: Many devs used it as the license dumpster: "I don't know what license it is, so I'll tag it as 'as-is'." Thanks to lots of work, mostly done by Ulrich Müller, all of that mess is now cleaned up.
In 2009, the Open Source Initiative chose not to approve the license as an open-source license.
Is there a widely accepted "do anything you like"-license that everyone can agree upon? I noticed github had cc0 for a while, but now they offer "the unlicense".
There's an understandable wish by some people to just radically reduce the complexity of this whole topic. I don't want to have to say "You can use this for whatever, you just have to ...", even if "..." just means "you have to keep this line with the copyright info". I simply want to be able to say "you can use this for whatever you want, no restrictions".
If I'm putting my stuff out on WTFPL, it basically implies that I'm already OK with someone taking it, relicensing it, and distributing it under a new license (and even under a new attribution). Personally, I would have a problem with it, so I've never licensed anything under WTFPL.
Navigate to about:license in Firefox. Does it seem like a good idea to have to reproduce every variant (with each unique notice) of MIT and BSD license?
It sounds to me like the unlicense is the best option - the OSI's concern about CC0 sounds reasonable to me, and the WTFPL doesn't have any fallback for jurisdictions that consider public domain dedications invalid.
One option is of course to "hack" the osi approval by, e.g., saying "this is licensed under CC0, alternatively it's licensed under MIT". (MIT is just an example and can be replaced with any other OSI-approved license). But it seems a bit stupid that there isn't an easy solution for this.
I've heard that the ability to dedicate your work to the public domain may not be possible in some European jurisdictions, and this concern was why public domain dedications were frowned upon.
I.e. they're not saying it's bad, just superfluous.
Also, i wonder what effect approval/rejection by the OSI has in any case. Does anyone care what they say?
You want your library used in the next big project? Don't use WTFPL.
Also, in a corporate environment, there's typically some additional overhead cost and bureaucracy and approvals that a new license text brings in, even when the engineers and lawyers manage to agree everything is OK.
Which is a problem.
If you are operating internationally (like nearly the entire tech industry), complying in as many jurisdictions as possible is very valuable
There's also SQLite, which is probably one of the most widely use libraries in existence. It's in the public domain.
With an additional license for countries, like Germany, where the public domain doesn’t exist (as copyright isn’t really a thing, but only "creator rights" and "usage rights")
This is false in the large corporate environments I've worked in. The WTFPL is sufficiently established and mainstream that legal knows what it is and has a position that it's fine. Use of anything GPL requires a lot more specific review to ensure we'll be compliant.
Very few companies are fine to write "fuck" in documents that reaches customers. Very few are fine to have no license attached to software.
A lot of companies distribute unmodified GPL software and have no issue with including the GPL licensing text (and source code) in ways that reaches customers.
Redistribute it under another license then? The WTFPL gives you permission to do that, after all.
> A lot of companies distribute unmodified GPL software and have no issue with including the GPL licensing text (and source code) in ways that reaches customers.
It's perfectly doable. But it's nonzero effort and it creates an ongoing obligation (as long as you're going to keep distributing the software, or something like 3 years after if you do the more customer-friendly thing of only distributing the source on request). I'm not surprised that a company would do it, but I'm amazed that a company would consider it less burdensome than the WTFPL.
As for the GPL ongoing obligation, I am not sure how many picks the source-on-request method or the subgroup of those that also get a request. Its a fix-it-later issue compared to the more immediate issue of "fuck" appearing in the product.
Just to be a bit clearer on my own opinion, a good company should have no issue of using both licenses. Writing code is costly and time consuming, and a good company should focus on core aspects rather than reinventing programming infrastructure. If the license is compatible with the business model then use it. If its not, ask the author for a exception. If all fails, then and only then waste developers time. In video games I often see software licenses in game credits, and many game studios will use any and all licenses that isn't in direct conflict with the business model, and I assume its because that market is too competitive to not do so. Including LGPLv3 source code on the disk (or offering) isn't a big deal compared to a game shipping a month or two later.
Sure, it's a slightly unusual thing to do. But I think it's less unusual than what you have to do for GPL compliance.
> As for the GPL ongoing obligation, I am not sure how many picks the source-on-request method or the subgroup of those that also get a request. Its a fix-it-later issue compared to the more immediate issue of "fuck" appearing in the product.
Legal should not be treating it as a fix-it-later issue if they're caring about licensing at all. Distributing GPL code not in compliance with the license is exactly as bad as distributing code you have no license to at all (and opens you up to exactly the same liability, given that the damages for copyright infringement are statutory).
Don't get me wrong, I support the GPL, but license compliance is important and nontrivial. Note that the LGPL is a very different license from the GPL, and much easier to comply with.
* Warning - no actual grant of privacy included.
If you feel you need something like that, use the Developer Certificate of Origin: https://developercertificate.org/
That's what "Signed-off-by:" lines indicate agreement with, and conveniently, git has built-in support for adding such lines.
> That's what "Signed-off-by:" lines indicate agreement with
Not to me (I've been using -s for years, assuming it was just a way to include developer information in the commit message), so I doubt that would hold up in court.
Also many of the WiFi drivers have such crazy firmware because they're actually (at least partly) software defined radios and thus each country needs a slightly different flavor and that's related to regulations and testing.
Everything would be much easier if we could just have some part of the UN that every country agrees to follow manage a universal spectrum allocation and anyone that disagrees should just expect all of the electronics to break.
Software is great exactly because it allows for infinite flexibility, so you don't need to involve the UN when allocating wifi spectrum.
Not sure it would be. As I understood that's more or less how it works today bar the UN bit. Key industry players chatter and come up with standards that all are reasonably happy with. But then throw in a few countries that want to do things differently just for the sake of it, prior spectrum allocation, and protectionist moves, and you end up where we are today...
Sad thing is that is is USA that is the problem child in all this. Being largely isolated from Eurasia, and having just a few big neighbors that are easy to convince to play along, they can basically define the spectrum within their broadcast reach as they see fit.
It is basically the same reasoning behind it as why metric is still not the default over there.
Well, and that works in our situation.
> It is basically the same reasoning behind it as why metric is still not the default over there.
There's also the simple fact that the 'metric' system is just different, not superior in general (i.e., it's better at some things and worse in others). Why impose a bunch of costs for no net benefit? If every other country jumped off a bridge, ought we?
Three, I'll give you.
Useful amounts of precision is a nothing, if you ask me. We start teaching decimals in third grade, and the only real issue with decimals is weather, for which the difference is saying "80F vs 81F", or "26.7 versus 27.2", whose utility is ... limited.
For distance, the metric system has finer grained units for precision (come on, break down inches: 1/16, 1/8, 3/16, 1/4, 5/16, 3/8, 1/2, etc... are you going to argue that is better than 25.7cm or 257mm?).
I'm not really buying it, as someone who has lived in both worlds.
You can say 1.5 cups instead of 375 mL.
Just like who hexadecimal is very natural in 8/16/32/64 bit computing, the "real life" usage of measures would be much easier if it was in Base-12.
BTW, does anyone know if Canonical still pay licensing fees to cover Ubuntu for this sort of thing? I believe they used to.
Likely Dell leave that up to the user to install after unboxing.
And that is one reason that Mint got popular, because they took Ubuntu and bundled that stuff right on the ISO.
https://arstechnica.com/tech-policy/2017/02/blackberry-sues-...
The source for that blob is available, but legally the binary must be distributed by someone, who is paying the fees.
While this may indicate that LWN needs to improve (or create) its paywall, if articles like this lead to new subscriptions they may be able to just chalk it up to "advertising" without breaking limited sharing of articles.
I really wasn't familiar with LWN prior to seeing links to subscriber-only articles semi-frequently on HN, and honestly these days I'm embarrassed I didn't know about it sooner as I'm a Linux sysadmin and LWN's weekly edition is just about exactly the news I want to keep up with my job.
I'm the one who posted this article and so far, I have not had any warning mail from lwn.net about posting subscriber only content. But I do take care to try to only post content that I believe is of interest to HN.
I'm joining in on a project that uses the Zend framework. The Framework is under the New BSD License.
We'd like our code to be under the same license. Do we just leave things as they are? Do we add our license to the files we create and leave the Zend files as they are? Do we need to add our stuff to all the files, even those that came with Zend?
I apologize if there is an obvious place to go to understand this, I have not been able to find it.
That said: put the license in the root of your project (as Zend probably does). Put your own copyright headers on any files that you create. Leave Zend's copyright headers on any files you don't modify. Add your own copyright to the a copyright header on any files you do modify.