Linus Torvalds says GPL v3 violates everything that GPLv2 stood for (2014)
youtube.com
youtube.com
Overall Linus Torvalds did not like how V3 was forced onto 'unsuspecting' GPL v2 users due to the 'or later' license assignment.
It is putting one's work into the hands of license that does not yet exist, it is irrevocable and once the F.S.F. brings a new version and one does not like provisions thereof, one cannot go back.
While you are granting the FSF the ability to relicense your code, they only have the ability to re-license your existing code. As it is already under the current version of the license, if you do not like the new version, you can simply stop using it for future additions. If I license something under "GPLv2 or later", and the FSF releases GPLv3 that is the SSPL, I can simply keep using my existing code under GPLv2. If the FSF releases GPLv3 and it is CC0, then I can once again keep using my code under GPLv2. In either of these cases, I don't have use the new version of the license on new versions of the software. While the existing software is always "GPLv2 or later", later additions can be "GPLv2 only".
An "or later" license allows for making my license compatible with future versions of the GPL. Personally, I see this as a good thing.
If you have accepted third party contribution and don't have any copyright assignment agreement (which is... Most of the projects out there), you can't relicense easily.
Its not about the user keeping his code under GPL2, its about other parties being required to keep their changes under GPL2 and accessible.
Would you provide a point-by-point rebuttal? If not, would you at least provide some evidence of your position that my post is "fundamentally wrong"?
> I don't care if you like GPLv2 or not, but this is clearly showing you can't read or haven't read it.
I have read GPLv1, GPLv2, GPLv3, aGPLv3, the X.ORG license, all forms of the BSD license, the appache license, several versions of the Mozilla License, amongst others. Please refrain from personal insults ("clearly showing you can't read") as well.
> Its not about the user keeping his code under GPL2,
My argument is that the FSF will probably not grant anybody privileges with the existing code that I don't like. Even once a new version of the GPL is released, other contributors will have to contribute under a version of the GPL. If the best versions are only under a later version of the GPL, maybe I will switch to GPLv4.
> its about other parties being required to keep their changes under GPL2 and accessible.
So it seems that you are worried that future contributors will release their contributioins only under the "later" version of the GPL and these new contributions will thus not be compatible with the older version of the GPL. This definitely could happen. However, many projects already dual license under GPLv2or3 so I don't see this as much of a concern. Sure we are adding GPLv2,3,orLater but these issues already exist and already don't cause too great an issue (in my opinion).
> Please refrain from personal insults ("clearly showing you can't read") as well.
I think the issue stems from:
> "I don't think it is near as big a deal as you make it out to be."
It is ambiguous weather you are "not sure about your logic", or if you are "not sure about Blikkentrekker logic". I took it to mean the latter. This puts your comment in a very bad light and set me off because it fails to acknowledge the issue Blikkentrekker is raising.
> "While you are granting the FSF the ability to relicense your code, they only have the ability to re-license your existing code"
A developer chooses the GPLv2 in part to what it does to _future_ code. `I provide this for free and we are all required to contribute future improvements for free, no-take-backsies`.
>"If the FSF releases GPLv3 and it is CC0"
is among the worse case scenario's for a developer that chooses GPLv2. It invalidates their choice and leaves only `I provide this for free` and is the core of the issue at hand.
> My argument is that the FSF will probably not grant anybody privileges with the existing code that I don't like.
And this is a perfectly fine counter. Its a matter of if you think the risk is worth it.
Then someone else comes along and chooses to use it under GPLv3, then proceeds to sue me because I can't lock down GPLv3 software.
Problem is... when you choose the GPL version in an "or later" scenario, you're choosing for yourself, not others.
Thus "or later" posed no problems by itself.
(The same exercise can be made regarding the patent clauses.)
Users of GPLv2-or-later software cannot use GPLv3 clauses against other users (such as patent grants), as either party can always claim to be using the code under either license. GPLv2-or-later is thus fine.
The "unsuspecting part" comes from people relicensing under v3 without understanding how radioactive it is. And it is radioactive not because of any software-related concerns, but because of extraneous stuff (like Linus says).
Funny enough, the most radioactive bits come from trying to cover things that are better fought in other grounds, like software patents.
* Antitivoization clause: it bars its use in software that will only run if signatures are required. This guarantees freedom 0 (freedom to use the software) will not be circumvented and discourages vendors from shipping hardware that requires signed software.
* Antipatent clause: The license is revoked from an attacker if patents are used to attack users of the software.
These clauses maybe desired in some cases. Probably, a sensible direction could be to add flags to the GPLv2 to particularly enable these clauses. Somewhat similar to how it is done with CC licenses which may have BY, SA, or NC flags.
It's a little bit more nuanced than this. It's okay to require signed code as long as the end user has control over which signing keys to trust (e.g., x86 Secure Boot, but not ARM Secure Boot). In particular, this means you don't have to choose between security and freedom - you can have both.
The GPLv2 instead terminates your license, requiring a reinstatement by the copyright holders.
The legal argument is that since the GPLv2 is a public offer that one can accept by complying with it's terms, regardless of the original holder's specific permissions, the offer is even extended to past violators, so all violators have to do to re-accept the offer is to simply come into terms with it again, but for the duration that they are out of terms, the offer is terminated.
Try telling the NFL that you're only violating their copyright during for duration of the super bowl. If you stop committing a crime, it's not like it never happened. Sure, most copyright holders of GPL licensed code won't sue you if you make an honest effort, but the 30 day clause just makes that official.
That has nothing to do with copyright per sē, and is simply a provision of the GPL, and thus has nothing to do with the Superbowl.
The GPLv2 rightsholder can independent of that elect to sue and seek damages for the duration of the copyright violation, but once one come into compliance again, one can re-use it, and the GPLv2 rightsholder cannot stop that.
We might be arguing semantics here. I am trying to convey the idea that the rights holder can sue for damages after the duration of the violation, even if they can only sue for damages that took place during the violation. That is, once you are in compliance with the license you don't retroactively have a license for the time it was revoked.
The principle if true means that one can never obtain a new licence when coming in compliance except by gaining permission from every single rightsholder which for large projects can be thousands. — this is theoretically true by the letter of the GPLv2, but the common legal opinion is that this provision is not legally enforceable.
The GPLv3 fixed this unintentional problem, as the GPLv2 was never written with the idea of thousands of rightsholders in mind.
Some of the other commenters here seem to stress the Tivoization clause, but it appears to me that that is not the real issue. Linus even says so, at one point when the guy asking the questions repeatedly tries to stress that point.
Linux is chock full of potential patent release deathtraps: that it is still using v2 is kinda scary.
Look at that table!
Certainly simple! /s
Apple takes away the ability to run the software, then sells it back to you.
- If you like the idea of sharing code and want people to share code back. Use GPL
- If you like the idea of sharing code, and merely want credit for it. Use BSD.
Your point about patent is an import part of his generalization that is not addressed.
GPLv3 solves the first bucket WRT patents. Is there a license that falls under Linus's SECOND bucket, that solves the patent issue?
EDIT: formatting and clarifying words.
Apache 2.0 License.
Apache 2.0 has some clauses which (most people tend to ignore and which) make it somewhat incompatible with modern open-source fork and pull request workflows.
In particular 4.b)
> You must cause any modified files to carry prominent notices stating that You changed the files;
For the most part, people just throw their name in the file, in an attempt to "meet" this requirement without massacring the file header/notice.
However, if the Apache 2 license is taken at face value, when you fork and modify a file, you have to mark it as such. Then when you submit back, the project (in adherence with the Apache 2.0 license) has to retain this notice. Technically the project may even then need to add their own notice to indicate they modified the file since you did.
Clearly, that's not tenable, so most (small) projects just offer leeway. Larger projects instead have contributor agreements (AOSP and alike).
Large Apache licensed projects without contributor agreements exist (LLVM for example).
For example, GPL has language requiring you to make clear that you changed the software, but leaves open how you do it, and doesn't require you to mark individual files.
If not, is there any other similar standard license with a patent clause that I could use?
For example, if I were writing some kind of calendar application which contained a date parsing module within it and someone wanted to copy some code out of that date parsing module and paste it into their own application, I'd be perfectly fine with that. If they later make improvements to that code they copied, I'd prefer it if they'd contribute those changes back, but I absolutely don't want to try to force them to make their entire application open-source, or if it's already open source, to force them to re-license it under my license.
I recognize that the line between "unrelated code" and "improvements to my code" can get really blurry, which is why right now I prefer to err on the side of freedom by using permissive licenses like the MIT, but I wouldn't mind using a copyleft license that took greater pains to ensure it isn't "viral" like the GPL.
Their preferred strategy apparently consists of using two properties of the Linux kernel as leverage: the massive scale of its development and the instability of its internal interfaces. Linux kernel hackers get about 20 patches every hour and that figure comes from a video I watched years ago. Those patches improve things all over the place and nobody cares about code that isn't in the kernel tree. As a result, out-of-tree code quickly becomes out of date and the companies must pay the constant maintenance costs or be left behind.
Isn't BSD widely accepted to have an implicit patent license? e.g.: https://github.com/facebook/zstd/issues/335
The stakes for software freedom have never been higher.
From the preamble:
Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for this service if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs; and that you know you can do these things.
This jives well with Linus's intention of "I give you software to do whatever you want with, and if you make improvements you have to give them back"Some of us were always suspicious before the change -- "what if RMS sells out and v(n+1) grants non-reciprocity to his employer" type of crap -- but we went with v2+ because it was popular at the time. I don't think I've seen "v3 or later", probably because we've been burned already.
I don’t think it is that much of a stretch to say preventing people from running modified versions of the software went against the goals of GPLv2 to allow users the ability to “change the software or use pieces of it in new free programs”
Not being able to run the software you change certainly means you can’t use it.
There was a printer driver that RMS wanted to change but couldn't. If the system he was working with had had code signing for printer drivers and refused to run with his modifications because of it, we'd have had the TiVo clause in the very first version of the GPL already.
This jives well with Linus's intention of "I give you software to do whatever you want with, and if you make improvements you have to give them back"
Except the GPL does not require you give any improvements back. It only requires that you give the same freedoms to whoever you give the improved software to. That is, the end users. There are plenty of enterprise "appliances" that come with modified GPL code that is only given to the companies that pay for these computers. That is perfectly within the spirit of the gpl, because it's goal is to give the end users freedom.
edit:
What else would be the point of "that you can change the software" without having a means to run it?
Porting the software to new hardware?
But it is. Let's quote another paragraph of the preamble too, shall we?
if you distribute copies of such a program, whether gratis or for a fee, you must give the recipients all the rights that you have.
This surely says, in spirit, that if you as manufacturer have the right to deploy this software on certain hardware, that the recipient must have the same rights?Linus's intention of "I give you software to do whatever you want with, and if you make improvements you have to give them back"
This, on the other hand, is not a stated goal of GPLv2. Your obligation, as a software distributor, is only downstream (your recipients/customers), not upstream (your suppliers).
It is the goal of Stallman and the Free Software Foundation. Free software licenses are one of the means to that end.
Free software started in universities decades ago. The software was written for Unix computers, many years before things like trusted computing. The GPLv2 reflects this environment: it takes hardware freedom for granted and focuses entirely on software freedom. Tivoization was an unforeseen development.
- There is no legal viable way to upgrade to v3, even if the "or later" clause would be there it would have been a legal disaster.
- It's also makes it much more viable to upstream drivers in Linux
- Let's be honest the patent system is by now utter garbage failing the one fundamental thing it was invented for: Driving/Improving Innovation. The only reason it didn't fall on our head yet is because many companies simple don't enforce patents. Also you could argue it already fell on our head in some areas due to innovation having slowed to a crawl, while certain competitions (mostly in Asia) are not affected as they ignore patents. I mean sharing and cloning software (between companies!) is what enabled us to have massive innovations (through some maybe stupid) in software space. Non of this would have been possible with enforced software patents.
I'd much rather stick with "archaic" but understandable licenses like BSD, over verbose licenses that intertwine US Patent Law with Copyright law, such as Apache 2 or GPLv3.
And we're seeing that the GPLv3 didn't "solve" the problems it was meant to solve and now we have multiplications of "open source" licenses designed to protect business models.
The other side-effect of all this license proliferation is that companies clearly "know" where they stand with them - and are scared to move to new ones, especially if they have "patent side effects" that the lawyers don't want to investigate or stick their neck out on.
Apple stopped with the GPLv2 and hasn't moved forward in anything GPLv3; sure you can argue they never contributed much but the license should be about source code freedom - and it has morphed to be so much more.
This is not true, GPL is about "user freedom", repeat it 3 times, "USER" freedom. This is why it gates hate from some developers or entrepreneurs here, it removes the freedom of the developer to abuse the user or in recent cases companies to profit from community work and not give anything back or even harming the original project with FUD or unfair competition.
And as Linus is arguing, it's perhaps a perfectly FINE license, but it is NOT the GPLv2 and it has different aims and desires: and he gives examples where if the kernel had the "and any other version" the GPLv3 could be used to do exactly what the GPLv2 is supposed to prevent - someone taking the code and modifying it and distributing it in a way so that he can't use the modifications.
No it doesn't. You can do whatever you want with GPLv3 software, provided you don't distribute it. It's disingenuous to use the word "developer" to equate "person who edits their own software" with "person who distributes software to others".
Or if you disagree, can you articulate exactly what USER freedom you think is being infringed?
"Your freedom to swing your fist ends at my face."
GPLv3 puts requirements on what a DEVELOPER can do with the code
then he should not put restrictions on other users then himself. The point is that all users should have the freedoms not only the developers, the only limitation is that you can't abuse users.
A good example would be a quote I heard in a play of Uncle Tom's cabin (this was a translated and adapted so it might not be present exactly like this in the book). So in the play a french and some americans debate slavery and the salve owner says something like "America is the land of the free because we are free to own slaves" , like that slaver some companies and developers want to be more free to abuse others (put DRM to lock people, create proprietary formats, spy on users, nag them etc).
IMO we all are free to chose the license for our work, and if anyone wants to make his work BSD or proprietary it is his rights, but they should not complain when someone chose GPL because he decided that he is concerned about user abuse.
> the license should be about source code freedom
no, it is about USER freedom.
You can USE gpl software for any purpose whatsoever.
Do anything you like with it. modify it, run it, it is yours.
It's just that when you redistribute it, you have to pass on that freedom.
I don't know why people in business freak out about this. They have money. Pay people to write software. If they want to redistribute software, just get MIT stuff, fork and close it, make modifications that restrict the use/redistribution, then sell it.
And it introduces a gigantic single point of failure with the FSF. If someone legally takes over the FSF, and publishes GPL 4 which is a BSD style license, then copyleft goes away for a lot of GPL software.
https://en.wikipedia.org/wiki/GNU_FDL#Compatibility_with_Cre...
To the slight dismay of some in my immediate family, I chose to study CS instead of law, so IANAL, but in the scenario you describe, I would try to argue into the direction that the hypothetical GPLv4 without copyleft clause is very much not "similar in spirit" to the intent outlined in the older versions in great detail, and hence should not apply.
I'm frankly surprised that ANY lawyers signed off on the GPLv2 (as in, picking it for a company sponsored project) as the "any later version" and "similar in spirit" are quite open to interpretation.
And all we'd need to see in GPLv5 or v6 is some line like "nothing in this license shall be taken as being incompatible with the BSD/CDDL" to open a huge can of worms.
Honestly, if you want to do "or later" I'd instead just assign your code to the FSF to do with it what they will.
Of course, and it would be a real PITA, but I don't see how it would be that much different from a GPL violation law suit right now. If you publish your source code, even under GPLv3, there is nothing that really stops anybody else from taking it and violating the crap out of the terms and conditions.
In pretty much all jurisdictions I'm aware of, the copyright holders are the only ones who can sue for copyright infringement (setting aside the whole "is the GPL a contract?" debate for the moment[1][2], which would also open up suing for breach of contract in some juristicions).
You can slap any license constraints you like on your source code and publish it, but if you really don't have the resources to pursue legal action for violations to begin with, that already isn't worth anything and the software is effectively in the public domain.
[1] https://perens.com/2017/05/28/understanding-the-gpl-is-a-con...
[2] https://en.wikipedia.org/wiki/GNU_General_Public_License#Lic...
This distinction is actually important, because the GPL forbids adding more conditions on top of the license while still being GPL-compatible.
The FSF does agree[0] with you that code licensed "GPLv2-only" cannot be included in a GPLv3 project.
[0] See table at http://gplv3.fsf.org/dd3-faq
People are always free to reinvent the entire free software ecosystem. They are also free to choose different licenses. I knew it was over when LLVM compilers started replacing GCC in a lot of systems.
> I love Linus so much. He has opinions and doesn't hold back with them.
Yep, this is the steve jobs era people that were straightforward. Linus can be a lot better with his initial reaction "It's horrible" but you can see through the outer shell that he is a really reasonable person and doesn't come across as this evil lord archetype people push on him. His knee-jerk reactions are so outlandish that after a while you just dismiss them as comedy.
Our society is eradicating people with strong opinions. It's is a huge loss.
His comments on AVX-512 are a great example. He later toned them down after his ridiculous excess was challenged, just like you say. But nobody ever brings that up when the topic is discussed, just "HAY GUYS DID U KNOW LINUS SAID AVX-512 IS JUST BENCHMARKETEERING AND NEEDS TO DIE A PAINFUL DEATH!?!?". And now apparently it's such a worthless waste of silicon that AMD is implementing it on Zen4 too... cause Lisa Su loves spending a bunch of silicon on a "few meaningless benchmark wins" too apparently.
It's like the old adage, "a lie gets halfway around the world before the truth has got its pants on". Well, the ridiculous hyperbole gets halfway around the world before the correction gets its pants on too. Nobody ever hears his retractions, just the initial hyperbole. First impressions matter.
I personally enjoy the way Linus tends to lead with his emotional reaction and then explain the layers behind it. I get the impression he often backtracks from his initial position because he's just giving the topic more thought, which is a mature response. The fact that he's a well-known figure doesn't excuse him from the privilege of being a human who learns.
being a well-known leader does convey a certain expectation of emotional maturity and moderation. Hyperbolic and mercurial individuals are generally considered to be a poor fit for leadership positions.
Yes, it may be human nature to react emotionally, but this is something most people grow out of at a fairly young age, and we certainly expect our leaders to be reasoned and measured about their reactions.
Linus - FSF is "filled with crazy bigoted people"
Then the guy keeps on going on how "we" can get Linus to stop. Who is this "We" attacking linus?
"When somebody else wrote the code, you don't get that choice, right?"