See this HN comment from a year ago for a fuller exploration of how that can be problematic: https://news.ycombinator.com/item?id=12597488
What the patent system gives a patentholder is the ability to selectively prohibit others from making, selling, or using some product or method protected by the patent. The Lil License is weird in that it only explicitly mentions the latter.
Its text regarding copies of the license is also very weird.
Please do not use this license.
Maybe this should be made clearer somehow, e.g. 'and including any herefore necessary license to patents the authors may hold'.
I also don't see why open source contributors should give away the copyright to their work. All it accomplishes, is that the "original author" (= the copyright holder, usually a company) can re-license the work without agreement from all contributors. It strips contributors from parts of their rights.
It makes sense in the case where I contribute, say, an entire new module. Then I should have the right to do with it as I please. But there needs to be a line drawn somewhere, and I sure as hell couldn't tell you where.
Yes, and it makes sense, after all you made that part of the code. The same holds true for licenses like the GPL.
Remember the shitstorm about MIR and the CLA that it required? People do not want to sign their rights away and allow a company to sell away their code.
* if the license is permissive
* if the license is copyleft and the organization is a non profit.
Canonical fit neither of those.
If you fix a piece of software, why would you send the fix to the original creator? To show off? The only reason I can see is for the creator to merge your fix into the project.
But it seems to me that it makes the most sense to clarify that when the creator merges the changes. I don't see why the license should include a CLA any more than it should encourage potential contributors to be nice to each other, or to look both ways before crossing the street.
With git, the contributor has an even harder case to make. A pull request is literally a request to incorporate your contribution into the project. If the pull request doesn't include a proposed change to the license, it would be very hard to claim that the fix couldn't be distributed under the terms of the existing license.
I'm not aware of any court rulings directly on the subject. The best I can think of is the Prenda Law case. They sued people for copyright infringement for downloading some porn videos. A few of the people targeted showed evidence that Prenda Law had uploaded the videos themselves, and Prenda Law immediately tried to withdraw their cases. Some of the judges were very upset about that behavior. I'm pretty confident about how a court would handle a case where somebody claimed the contents of their pull request weren't meant to be distributed.
The traditional concerns have been cases where people try to contribute code that actually belongs to their employer, which remains a concern with this CLA-in-the-license approach, or projects interpreting their own licenses in obtuse ways ( https://lists.debian.org/debian-legal/2002/11/msg00138.html ).
I imagine this could be an issue if, say, it's a project like Firefox and they start including some binary blobs. Without an explicit CLA, couldn't a FOSS-zealot contributor now sue to have their code excised from the product?
Broadly speaking, the CLAs I've seen either (1) fall into the classic legal "belt and suspenders" approach of being explicit where there is arguably an implicit promise, or (2) require the contributor to transfer copyright to the project and then make promises about what the project will do with the code, including promises about relicensing, and a broad license back to the original contributor.
US copyright law sometimes assumes that there is some kind of agreement between people who collaborate on a copyrightable project, and generally speaking, the CLA looks like it serves that purpose.
However, I believe most open source projects are actually joint works, and the rules for joint copyrights are wildly different from what programmers seem to expect (e.g., http://copyright.universityofcalifornia.edu/ownership/joint-... , but you can find other explanations online, including at http://copyright.gov ). It's clear to me that the law assumes people who collaborate on a joint work will have some kind of agreement between them, like a CLA. I'm not able to find it right now, but I'm aware of one case where somebody contributed to a proprietary program, declared that made him a joint copyright holder, and started selling copies of the software without permission. The court agreed that if he had been a joint owner he would have had authority to sell copies without coordinating with the other owners, but the court decided he only had copyright in his contribution, like a collective work, not because the contribution could stand alone, but because it was relatively small and easily identified.
Based on that ruling, if I maintained an open source project under some kind of restrictive license that I intended to enforce, I wouldn't worry about getting a CLA for small patches (aside from getting some statement that they had authority to offer the contribution), but I would worry about getting one from regular contributors.
There is some point when a contributor crosses a threshold and becomes a joint owner. You want a clear agreement between the joint owners, but I don't believe the license is the right place for that agreement.