Where is the source code for the actual bootloader shipped with the Prusa Mini+?
github.com
github.com
Personally, I think that in this era of Hardware Root of Trust devices and locked bootloaders, if we were to try to prevent such devices from existing, I think the appendix is a fairly brilliant solution that could be applied elsewhere.
For example, my iPhone. Apple doesn't allow side-loading because, well, they're afraid Facebook or Epic would force users to side-load against their will, among other business reasons. But if they were legally mandated to offer an appendix that could be snapped to enable sideloading, it would hopefully keep Facebook at bay (there's no way Facebook can convince people broadly to do such a thing), and would satisfy us hardware hackers.
It's still not perfect, but I think it could be an excellent "first step" in unlocking these devices that, among many solutions, could potentially be bipartisan and harder for tech companies to argue against.
Furthermore:
> Apple doesn't allow side-loading because, well, they're afraid Facebook or Epic would force users to side-load against their will, among other business reasons.
I think "other business reasons" are the bigger issue here. Facebook and Epic wouldn't "force" users to side-load content any more than Apple "forces" you to use the App Store on iOS. It's an available option that you can use at your own discretion.
Apple (unlike Prusa) has painted themselves into a pretty favorable corner. They've made their value proposition immaterial, which allows them to pretty easily deflect any accusations that their 30% cut is out of line. Apple has full control over the goalposts here: they could claim that their cut goes to hosting alone or covers the entirety of the review process.
The seller can not absolve themselves of liability in this way. They still assume liability under their warranty and must prove changes you made are the cause of malfunction even if you modify the device.
https://en.wikipedia.org/wiki/Magnuson%E2%80%93Moss_Warranty...
But even if it was in the US, what you are citing mostly applies to things like cars that you can put aftermarket parts on. They could just say that modifying the firmware is "[using] a product for something other than its intended purpose" and the FTC will just look at you and shrug.
However, if you want to invoke your legal warranty more than 6 months after purchase date YOU have to prove that your modifications didn't cause the defect.
If you are slighted by a foreign company you can still receive a judgement against them or their functionaries, and in extreme matters the company and its distributors would start having issues with CBP and with their banks.
The damages required for such issues can be quite high, $50-75k for federal court filing, but existing precedent would allow you to go after distributors in a local court for a lower amount.
CBP will only get involved if the product is illegal or dangerous.
The solution is to not offer a warranty, though some states do not allow you to disclaim suitability for a particular purpose and establish an implied warranty for items you sell.
https://en.wikipedia.org/wiki/Magnuson%E2%80%93Moss_Warranty...
The damages required for such issues can be quite high, $50-75k for federal court filing, but existing precedent would allow you to go after distributors in a local court for a lower amount.
But anyway: If I travel outside the US and buy a harmful appliance in a local shop, a US court would probably not take the case. Am I right? What would the manufacturer have to do to get exposure to US law?
I bet Facebook would be able to get users to do it. "Sorry, you can't see this photo from your friend until you upgrade your iPhone by following these instructions." You refuse and your friends stop including you in activities. You basically get peer pressured into doing what a large corporation says.
(I actually wonder why they don't sell peer pressure as a service. "If you don't pay your balance due of $123.45 by 7/1, we'll message your friends saying that you're a deadbeat." Maybe I should patent that before someone else does, because it sounds horrible.)
Alas, this is not a new idea:
- https://www.theatlantic.com/technology/archive/2010/11/faceb...
- https://restofworld.org/2020/okash-microlending-public-shami...
- https://www.experian.com/blogs/ask-experian/can-a-debt-colle...
- https://www.theguardian.com/money/2021/may/09/loan-sharks-ta...
That and most state's consumers protections prevent this sort of behavior.
https://chromium.googlesource.com/chromiumos/docs/+/HEAD/wri...
As an Apple user, this is my biggest fear about allowing other App stores. Facebook, etc hate Apple’s privacy policies, but the iPhone market is too big and too rich to ignore. If now they can tap the iPhone market without having to deal with Apple’s privacy requirements, I am sure they would be delighted. Soon, they would at least have more features in the side-loaded version to try to push people towards it.
The companies like Epic and Facebook would have saved money by this move, but I as a privacy minded consumer, would have lost.
In the same way as warranty seals, this sort of stuff can usually be worked around with not a lot of effort. One of the comments there already mentions:
You can test if the "appendix" is the issue by connection BOOT0 and SWDIO to GND. That is all the appendix does.
"There's a few thousand mice but only one cat." "What you can make, we can break."
It’s not meant to be complicated. It’s only meant to be easily identified during the RMA process.
no it doesnt, at least not in US (magnusson moss) https://www.npr.org/sections/thetwo-way/2018/04/11/601582169...
Also, this person (https://github.com/prusa3d/Prusa-Firmware-Buddy/issues/1440#...) misread the GPL, when they said this:
> but the license clearly states that it is not an aggregate if they are combined to form a larger program in or on a storage or distribution medium
The GPL very much does not say that:
> which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate”
Hmm, its not so easy, I think. A bootloader is code that might be in the address space after boot and may well run even after boot. Real world examples of this are the PC-BIOS (if you agree to classify it as kind of a boot loader) and Sun OpenBoot PROM. The PC-BIOS routines are used during runtime of older Operating Systems and to bring up the newer ones. Diagnostics Mode on a Sun can be entered any time by pressing a special key combo (Stop+A) and this will run OpenBoot code.
Even for more modern systems using U-Boot it is not clear cut. At least U-Boot deemed it necessary to clarify it in its license:
"U-Boot is Free Software. It is copyrighted by Wolfgang Denk and many others who contributed code (see the actual source code and the git commit messages for details). You can redistribute U-Boot and/or modify it under the terms of version 2 of the GNU General Public License as published by the Free Software Foundation. Most of it can also be distributed, at your option, under any later version of the GNU General Public License -- see individual files for exceptions.
NOTE! This license does not cover the so-called "standalone" applications that use U-Boot services by means of the jump table provided by U-Boot exactly for this purpose - this is merely considered normal use of U-Boot, and does not fall under the heading of "derived work" -- see file Licenses/Exceptions for details. "
EDIT: Just to be clear, I agree with lights0123's main argument, I just wanted to point out that it's not trivial and that "they don't even ever run at the same time." is not the strongest supporting point.
It does not make sense to me to consider a bootloader and whatever it boots to be one program. seems like GRUB (GPLv3) generally is not considered to infect everything it boots / chainloads.
> Where's the line between two separate programs, and one program with two parts? This is a legal question, which ultimately judges will decide. We believe that a proper criterion depends both on the mechanism of communication (exec, pipes, rpc, function calls within a shared address space, etc.) and the semantics of the communication (what kinds of information are interchanged).
It also doesn’t make sense to consider different, independently engineered pieces to be one in the same simply because they were shipped on the same storage medium.
Yes the name says it: a bootloader loads some other program into memory.
https://hackaday.com/2019/12/16/prusa-dares-you-to-break-the...
Any design worth its salt should incorporate a thermal soft-fuse at the heater element that cuts power off if the printhead ever goes above the maximum temperature that any filament can handle.
Pure software interlocks are not sufficient. One might think people would have learned a lesson, nearly half a decade after Therac-25.
Loading untrusted firmware onto a PCB with high current outputs - like motor control - should absolutely void your warranty (for that PCB and anything connected downstream of it).
[1]: The most popular firmware, Marlin, has a feature called Thermal Runaway Protection which turned off the printer when it detected temperature has reached certain threshold. Prusa printers have TRP enabled by default, but some manufacture doesn't.
[2]: https://www.reddit.com/r/3Dprinting/comments/8ah96r/anet_a8_... this is about ANET A8, but flashing custom firmware with TRP disabled or with higher temperature limit may result in the similar situation (ANET A8 stock firmware don't have TRP enabled)
I think the fear would be that non-expert users would try to flash their custom firmware, run into issues, then try to get warranty relief claiming there is a hardware problem.
There would be no easy way for Prusa to tell whether the boot issue is actually a hardware problem covered by the warranty or a firmware issue caused by bad firmware being flashed.
They don't want to sign themselves up for having to assist users recovering from flashing their firmware.
Warranty and customer service abuse is one of the biggest reasons that shipping hackable hardware is a pain. For every 1 person who knows what they’re doing when they mod their device, there are at least 10 or more who will try to get customer support, refunds, or warranty claims going when they get in over their head after copy-and-pasting commands from the internet to mod their device.
I think it’s reasonable to expect users who modify their hardware to forfeit their warranty rights. The company making these devices shouldn’t have to warranty or support every untested, 3rd-party modification.
Bad move.
In this case, because they are wrong and the GPL does not say what they think it says.
Essentially, it's an irreversible switch which allows you to run firmware that is not signed by their private key, which makes it a end-user choice: you can be in a safe and protected world, or you can be in a free do-what-you-want world; all you have to do is choose.