Rust's Freedom Flaws
wiki.hyperbola.info
wiki.hyperbola.info
https://www.gnu.org/licenses/gpl-3.0.en.html#section7
Quoting the relevant bit:
Notwithstanding any other provision of this License, for material you add to a covered work, you may (if authorized by the copyright holders of that material) supplement the terms of this License with terms:
…
c) Prohibiting misrepresentation of the origin of that material, or requiring that modified versions of such material be marked in reasonable ways as different from the original version; or
…
e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or
…
> Distributing a modified version of the Rust programming language or the Cargo package manager and calling it Rust or Cargo requires explicit, written permission from the Rust core team.
So, either you distribute something you can't call Rust; or you need explicit permission. It is not good enough that you mark is as modified.
There is an explicit controlling motivation here:
> The Rust and Cargo names and brands make it possible to say what is officially part of the Rust community, and what isn’t. So we’re careful about where we allow them to appear.
(From the Rust media guide.)
Nothing in the FOSS ethos gives you a right to misrepresent a product, you get the right to modify software, not to say it's something it isn't.
Let's consider two cases:
1. I forked rust, made a bunch of changes that are not compatible with upstream and setup rust.engineering (which is free right now) to say my fork is the rust then the rust devs should be able to tell me to not use their name for my product.
2. I forked rust, made a bunch of changes that are not compatible with upstream and setup feo.engineering (which is free right now) to point to my fork and say "feo is a rust-derived language" then that should be fine.
My reading of the license allows for the second use case, but not the first, which I feel is the right way. What is the problem with not allowing people to misrepresent the source of the code?
For example, ImageMagick and GraphicsMagick, or FFmpeg and Libav. When these things use the same name, but they diverge, it just means hassle for everyone downstream. So a different name makes sense.
In the past, Mozilla's defense of similar trademark guidelines for Firefox resulted in a weird revoking of the "Firefox" trademark for Debian, so Debian rebranded Firefox to "Iceweasel" for a while. But then, what I think happened (I'm guessing here) is that the browser got so big and complicated that Debian ran out of geekpower to patch it, so just redistributed whatever Mozilla did verbatim. Mozilla then re-granted Debian the right to use the Firefox trademark.
If Debian starts distributing Rust with bugfixes, I wonder if Mozilla is going to tell them again to change the name.
I'm thinking of some auto-maintenance stuff for MySQL, and a Debian change to atop which made it log to /var/run (an in-memory file system) - see https://bugs.launchpad.net/ubuntu/+source/atop/+bug/1393175 .
As noted by steveklabnik, Debian already does ship Rust with their own patches without issue.
I guess we'll have to hope someone at Mozilla doesn't get picky again and decide to enforce their trademark policy, which I think says Debian is in violation of, but being tolerated.
There was no change of guard, just a very long discussion on how you can make some of the stars align: Mozillas interest that things shipped as "Firefox" are something they can vouch for and Debians interest to use them as free software.
Mozilla felt changing the logo fell outside their trademark guidelines to still call it Firefox.
Imagine a vendor shipping rustc and cargo + 20 subcommands that are not behind the -Z flag. People may start relying on them and be annoyed of the Rust project if that happens. For that reason, you need explicit permission here, because we want to discuss with you how to phrase the messaging to avoid these situations.
However, if a company creates a hard fork of Rust but still insists on calling it Rust, they want the ability to say "don't use our name".
The problem is, what's the best license to express that intent? Reusing the Firefox one makes sense in some ways (it's been well studied) but perhaps Rust would benefit from a custom license?
Rust the name is a trademark and the software licenses deal with copyright. Someone can hard fork under a different name and the copyright carries but the trademark wouldn't. Plus, this isn't an EULA where more info is conveyed.
Not sure there is a clean way to fit multiple separate things into a copyright policy and maybe IP grant. Trademark law works a little different, right?
In Kubernetes-land, the code is all standard Apache 2 but the trademark is governed by a custom set of policies the community decided on.
For example, companies must pass the conformance program before they can use the name in marketing.
> 2. Altered source versions must be plainly marked as such, and must not be misrepresented as being the original software.
There's a reasonably complete alternative (it compiles most code but doesn't enforce borrow checker rules so is more permissive than rustc) called mrustc.
Cpython and Python are similar here.
But would you be allowed to call it a Rust compiler, even if it compiled a slightly modified version of the Rust language ?
There are many C/C++ compilers, often they have some compiler-specific extensions, but they still call themselves C/C++ compilers. Would a similar situation be possible for Rust with the current license?
So it's not necessarily an unchecked freedom but it's also not limiting in most cases either.
AFAIK Rust is not specified by a fixed standard. Thus, it would be hard if not practically impossible to comply with a definition of what Rust is if none was ever done.
You can see Debian's patches to rustc here: https://sources.debian.org/patches/rustc/1.34.2+dfsg1-1/
So, yes, the intention of this policy is basically to prevent people from confusion around forking the language itself. It would be very bad if, for example, a distro would strip out the borrow checker and still called the language “Rust.”
Distributions do make some patches to Rust, and still call it Rust. The team is fine with this. Nobody has explicitly asked to do so either. The only trademark inquiries we get are around things like “can I sell this tshirt”, honestly.
Now, there is one thing of interest here. Mozilla does own these trademarks. I often comment here about how Mozilla does not run Rust governance, and that’s true, but this is the one single way in which they do have some leverage. However, I can’t imagine a world in which they do something against the will of the team. When discussing the idea for a foundation, a place for these trademarks is often one of the largest pros of doing such a thing.
I will note that a lot of people have brought up Iceweasel; this issue resolved itself long ago and distros like Debian ship Firefox now.
* Stating accurately that software is written in the Rust programming language, that it is compatible with the Rust programming language, or that it contains the Rust programming language, is allowed. In those cases, you may use the Rust trademarks to indicate this, without prior approval. This is true both for non-commercial and commercial uses.
I would call a compiler that compiles Rust, but does not name itself "rustc" falling under that explicit approval.
(Full disclosure: I'm part of the Rust community and core team and often handle trademark decisions)
> They do prohibit abuse of their trademarks, e.g. you cannot create a company called “Python”, but this does not effect your ability to modify their free software and/or apply patches.
I think it is reasonable for certain kinds of software to have an expectation that users get the same results anywhere they use software by that name, and (therefore) that incompatible changes will not be distributed under the same name. Whether (1) that applies to Rust, and (2) that makes it non-free software, is the question here.
The word “Linux” no longer has a singular meaning. And distributions have their own branding.
If someone wants to release DebianRust and DebianCargo that would be perfectly fine and non-confusing. A distribution could also make an agreement to use the Rust/Cargo trademark under some mutually agreeable terms. Likely having to do with no major changes and staying updated.
Sounds like a fair and reasonable outcome?
IMO it's better that alternative distributions just don't call themselves rust unless they actually are the upstream rust.