Court Ruling shows the GPL is both copyright license and contractual agreement
sfconservancy.org
sfconservancy.org
For another example, think of someone who is hired to handle disbursing an estate by someone who is dying. Their kids/heirs can sue the executor for contractual issues if the executor does anything shady because even though they weren't party to the contract because they stood to explicitly benefit.
I think technically yes, practically it is a separate up hill battle. Monetary damages have to be not-speculative, something like "because of defendant not complying with the contract I ended up spending <this> money on <these> software licenses" would probably work, but something like "because of defendant not complying with the contract I ended up making an inferior product (since I had to rewrite this code from scratch)" probably wouldn't.
I doubt that leaves many big lawsuits, it's hard to think of concrete damages that result from people improperly modifying and distributing linux (unfortunately common). Maybe customers of ChessBase who purchased Fat Fritz 2 or Houdini 6 (context: [1]) would have a claim for the return of their license fees, since if ChessBase was properly distributing it as GPL software they almost certainly would have been able to acquire it for free - that's like $50/person though - not a huge money maker.
[1] https://stockfishchess.org/blog/2021/our-lawsuit-against-che...
So that is to say, if I sell you some hardware-software package where the software is based on GPL code, then I paid for that software too, and so we are in a contract, part and parcel of which is the content of the GPL.
Suppose I sell you just the hardware, and you download and install the GPLed software separately from that. My sales agreement doesn't mention the existence of that software at all. Then there can be no contract there; that's just some free stuff you got somewhere. Perhaps that somewhere was my own server, where I prepared the images, but that is neither here nor there.
IANAL, but I believe a contract is binding once a party has made some undertaking in relation to it (eg if you order bespoke goods from me, the contract is enforceable once I start working on them, or when you pay for them).
Training staff in the use of some software could be ruled a relevant undertaking.
E.g. we can't sign a document which says I will mow your lawn every Wednesday, April to October and call it a contract. It's missing the compensation clauses, so it's saying the mowing will be free of charge. The GPL is one-sided in that it spells out that some receiving user's rights are to be upheld in such and such a ways, without requiring that user to lift a finger. It's like the free lawn-mowing document in that sense.
But, obviously, that part of it will come from some larger umbrella contract whereby the user is sold the software. Those parts of the GPL which resemble contract clauses should be effectively absorbed into that sales contract. According to the larger contract, the user paid for the software, and so the counterparty is bound by the GPL clauses contractually. (Or so it would seem is the court decision here.)
I doubt that the court decision means that if you give someone a Debian DVD-ROM at a party (let's pretend for a second people still do that) you are now obliged to do additional things for them by a contract.
Civil law is meaningless without a willingness to engage in litigation; you aren't obliged to do additional things because nobody would spend money that way. As a result, I think this example muddies the waters rather than clarifying anything.
Yes. But, generally speaking, that thing of value doesn't have to be money. You could have a perfectly good contract where I get to use your software in exchange for agreeing to your terms, since both (the use of the software, and the commitment to comply with the terms) are valuable.
[Hopefully I'm stating the obvious here but, this is not legal advice. It's a general observations about U.S. law, and does not necessarily apply to any particular situation.]
(2) Ruling that the GPL is (at least in the context of specific facts between particular parties) a valid contract isn't new [0], so (even if this ruling did find that), it would be odd to paint this ruling as a watershed for finding that:
[0] https://qz.com/981029/a-federal-court-has-ruled-that-an-open...
These decisions otherwise seem to get overturned in the future when you have a party with sufficient motivation+resources which is incidentally when they would matter the most.
It stuck with me because then I read the news and realised they were right! The lowest level court rulings very often get overturned when challenged in higher level courts.
Of course, even later, I realised it's just selection bias. Cases are not brought before higher level courts unless in those specific case someone is fairly sure they can get the verdict overturned.
If the GPL is a contractual agreement, does that mean that a court can require that an entity to release the closed source portion of infringing software that uses the GPL?
If that is the case, the legal jeopardy involved with using GPL software just got a lot higher.
One of the interesting effect of finally litigating the GPL is that the 'theoretical' implications become a matter of fact. And with that comes a bunch of clarity around what the risks are of using GPL software in your products.
It will be interesting if GPL "wins" and a bunch of companies immediately tells their employees to strip every bit of GPL code out of the system and rewrite from first principles any function that is required for the product to operate. There will be a market for programmers who do systems programming (which is currently not a big market, but it will get bigger.)
"Risk" is a weird way to phrase it. It's a cost for taking advantage of someone else's work, just the same as if you paid for a library. If you're not willing to pay the cost, don't use the software, just like companies would tell their employees not to use a pirated version of Photoshop.
> It will be interesting if GPL "wins" and a bunch of companies immediately tells their employees to strip every bit of GPL code out of the system and rewrite from first principles any function that is required for the product to operate.
This seems unlikely. Is it really that common for companies to violate the GPL today?
Every company I've worked at is careful about GPL. Some are more careful than others, but they all put at least some effort into ensuring nobody brings in GPL libraries.
As a lawyer explained to me, they understand at some point GPL code will be shipped - it is too tempting. The real goal is to ensure that when it happens they can convince the courts it is a rouge employee doing something he wasn't supposed to, as then the penalty is a slap on the wrist and a bunch of developers emergency switched to rid our stuff of GPL. If the courts decide the company didn't do enough to prevent infringement then the court will decide that it was company policy to make their product open source and the courts will force the release of source code. This is why all developers I work with have to take open source training, we have someone assigned to audit all our code, and we have bought tools that look for potential open source code, it all builds a case before the court. To my knowledge the above as kept us from infringing in the first place, which is the real goal, but since all tools have holes eventually we can assume it won't.
From that perspective the choice to use open source software in their product seemed to often include two risks, one was how would you respond if it broke and the other was what would you have to do to replace it if it became unavailable for some reason. To use a pretty well known example, the Android system from Google, which you could compile and run on your phone for "free" but the risk was that Microsoft would (and did) come after you for patent infringement if you used it in a phone [1].
The risk here was to margins, where a manager might assume the cost of shipping this software was $0 (no license cost) and have it end up costing $Y because of patent fees.
When Blekko was acquired by IBM we had to "blue wash" our code, which was to go through and identify every copyright, every comment that might imply ownership, and figure out if it was "okay", "not okay", or "needs more research." That entire exercise was described as "Minimizing the risk that the IBM company will be sued because they are using the code for your product."
So that is where I'm coming from here.
[1] https://finance.yahoo.com/news/microsoft-may-relinquishing-b...
What‽ The market for systems programmers is enormous! You think "smart" things program themselves? What about cars or industrial systems or traffic lights or well, literally everything that isn't running on a full blown computer?
Systems programmers don't get much play on open source sites like Github but they're probably the majority of software developers world-wide because there's vastly more embedded systems than there are desktop and servers.
Some software you pay for in dollars. Some in postcards. Some by exchanging patent rights, or promising not to sue. Some by accepting contracts to contribute back changes you make, under certain circumstances.
There is no legal jeopardy involved in using GPL software that is different from buying a math library: you read the contract, you pay the price, you use the software in accordance with the contract.
Violate the contract, penalties attach, starting with enforcement of the contract.
That has always been the case. The alternative would be to disclaim the GPL and face straight copyright infringement, which in the US can be as high as $150K per copy. No company making wide use of GPL and infringing it would want to go the copyright route.
The GPL is not really dangerous except to someone with no legal clue who is deliberately ripping off free software.
Per work, not per copy.
Statutory damages in the US start out in the $750-30000 range, and can be raised up to $150000 in the case of willful infringement. The burden of proving willfulness is on the plaintiff, but that shouldn't be too hard if the defendant already lost once and is continuing to infringe.
I'd expect courts to start going higher and higher up the range for damages the more times they see the same defendant losing for continued infringement of the same work.
I'd expect that this would get the defendants to start complying with the license and release the source.
Not at all. If you are a developer, this only protects you from patent trolls or any confused company that might sue the wrong person.
Same if you are a user.
The only "legal jeopardy" is for those who repeatedly violate developers and users right. And that's a good thing.
I think historically distribution of source code was seen as a condition of the copyright license (which meant copyright holders enforced), not as a separate contract right available to third parties (which would mean users and other can go after a variety of claims).
Anything that amounts to less pestering of developers is (probably) a good thing
I don't have time, money or energy to sue someone for using my code and not giving back.
But if downstream users can, and the math changes.
Downstream users can also of course sue you if you work on a project with a few other people under the GPL even if they didn't write any code or contribute.
However where 'personal use' ends and 'publishing copyrighted code' begins is not entirely clear to me. Does an internal tool in a company still count?
I would think so, yes. If I take a piece of information and do something to it inside my house, that's my business. If I show it to my friend, it's between him and me. If it let my coworkers see it so that they can only see it within the office, it's between them and me. And so on. The only issue would arise if an employee asked to see the source of such an internal tool and was denied.
It's probably a good thing on balance since it's one less barrier to companies using code under the license, but considering companies and their assets (including their internal tools) can be bought and sold, I'd personally consider that distribution enough.
This seems different from something that's purely personal use. I don't think it makes much sense to force a program to show a notice its GPL licensed if you're the only one using it for instance. In fact that seems to run counter to the intent of free software.
It's possible that legal systems treat this situation differently, but I think it makes far more sense if you don't need an additional license to use stuff that's already published by the copyright holder until what you're doing starts to go beyond just personal use.
The important point is to prevent freeloaders from taking credit from your work [and sometime even competing against you].
Interestingly in this case, this ruling also reduces intermediate developer hassle for devs who are already used to working with GPL code. So that's a nice win (=
Will be interesting to see where development / contributions by various players go in the future.
Actually it also reduces intermediate developer hassle: it's better if I don't have to rely on closed source firmware, firmware updaters, drivers, SDKs, proprietary tools.
It create openness in the whole software stack.
You of course may be sued yourself if you have a project using GPL'ed code that doesn't comply with the the current view of GPL (ie, release of encryption keys) or if you infringe your own GPL copyright in some proprietary project (ie, GPL code where user was promised access is in something that you don't want available broadly).
This is all good for users for sure for things like open core projects and projects that used to be open but moved away etc
That is what is so exciting / different about this. When you make available software under the GPL, you have now entered into a CONTRACT (not copyright anymore) with all users that binds you to the terms of the GPL and gives them a right to sue for violations of THEIR independent rights.
This is the power of this new ruling, they can then sue you or anyone for breaking this agreement with them. Obviously will take some experience to see how far this can be taken. My understanding is the conservancy may want to try to leverage this to try to get GPLv3 effects into GPLv2 and a few other things the developers of for example Linux are not so hot on.
Sure, anyone can sue you for anything. However nothing in this removes the copyright holders' ability to issue non-GPL licenses. A user of a product that uses a non-GPL license for that code would still have no standing for that suit.
Historically one could contribute to a GPL project (potentially on a significant level for a corp) but wouldn't worry too much about using it in your own product that was potentially locked down - ie, DRM / motor duty cycle control, rev limits etc.
Linus / Linux have a long history of being pretty relaxed about your use cases, with the one key provision that you share your code.
Now, the group of people who can sue you is much larger. And some of them (conservancy in particular) may have views that don't align with your GPLv2 interpretation (particularly around tivoization / lock down issues for hardware devices). So if you are contributing too and shipping GPLv2 code - yes, you as the distributor of a larger body of code probably have a higher risk now of being sued.
https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...
The main reason the GPL exists was to insure changes to code (forks) were available to original developers of the code so they could include those changes if they wanted (this was a result of issues with earlier unix systems that had fragmentation from forks). Additional, Linus, author of Linux, has been clear that his focus is getting code back, what happens to hardware was not covered in his mind by GPLv2.
So there is a dispute as to what GPLv2 requires with respect to hardware. It's clear that the code must be shared, and that's what a lot of GPLv2 devs have focused on. That the source code be shared, including scripts used for compilation and installation.
But (one view) is that is separate from mandating behavior of hardware, and that hardware can still check if its running approved code and refuse to run if approved code is not loaded.
That's why this case is so huge. The actual developers of Linux are not likely to try to enforce a term they don't think exists, the SFC very well may.
So what Linus wants from the GPL isn't even mentioned in the GPL.
It is only through a culture of contributing upstream and through upstreams reaching out to downstream redistributors and asking them to contribute upstream that anything gets upstream at all.
I suggest you read Conservancy's posts and the GPL, it does mention that installation is required to be possible and this requirement has always been present and enforced by copyright holders for GPL software, including for Linux itself.
Only if you had a time machine. Once you’ve distributed the code the horse has left the barn.
You can impose a new license on new versions of the software though.
> you infringe your own GPL copyright in some proprietary project
You can't infringe your own copyright. If you own the copyright to the code, you can't violate GPL by using it, even if that code is licensed under GPL. This is because a copyright holder releasing only their code under one license, can also release that code under another, proprietary license.
If you contribute to an open source project, then use that code in for example a locked down device, a user / conservancy who views that as a violation of GPL can sue you. That's important because historically developers on linux kernel have not agreed with conservancy views on things like encryption keys, and so have not pursued these types of claims and were somewhat unlikely to fully litigate claims against other contributors especially beyond just sharing code back.
As the conservancy notes, the universe of potential claimants (even with bogus claims) is now much much larger.
If it is only code you wrote and you haven't transfered your copyright to the project, then No, this creates no standing.
> That's what's so new about this. There is now a contract (not copyright) element - which binds you and the recipients of your code.
Incorrect, there is a contract that binds you and recipients of the code under a GPL license.
If you receive that code under a different license, that contract doesn't exist.
Edit: Let me put it this way. Let's say you create a library and make it available under GPL. Any company that uses your code under that GPL license, has entered a contract with you that allows users of their software to sue them for GPL violations. However, you can also simultaneously offer a non-GPL, proprietary license for that library to paying customers. Those paying customers would not be part of any GPL contract, they would instead have whatever contract they signed with you when buying the proprietary license. The users of that paying customer would have no grounds to sue that paying customer, because that paying customer never agreed to the GPL contract. (OFC if you use other people's code in your library under a GPL license, then you don't have the legal right to offer a propriety license for that code.)
Consider carefully your example, you've contributed to some GPLv2 body of code. Now you ship that code on your device (making available corresponding source code, but not decryption keys). You are not the only copyright holder, this is a collective effort.
Can you avoid the GPL'ed requirements? No. More critically, this allows new requirements to be asserted (under the GPL) that GPLv2 developers might not have considered something they want to enforce (hardware unlock) but users and activists might want to try and enforce.
All good for the users. Glad to hear this is welcomed by developers and those hiring open source contributors. This is still going to be a change from past GPLv2 experience I think for some / many.
edit: if not, maybe you're trying to say that the people who control the license to the project (and have the contributors' agreements to prove it) can't relicense the code however they want (and however is allowed in the agreement) for whoever they want? Because I don't think that's true.
There are different views on the GPLv2. Most of the contributors / developers on GPLv2 just wanted you to share back your code, so most litigation in this space followed that approach. Even there, it was at times pretty cooperative.
The SFC has a MUCH more aggressive view. They have views around DRM / unlocks on hardware and much more that are very user rights focused, but pose complications to developers. In the past though, they really couldn't pursue these claims because despite lots of contributors to projects, many didn't support their approach and so wouldn't work with them to make copyright claims. To give you a sense of some developers views:
"lawyering has become a nasty festering disease, and the SFC [Software Freedom Conservancy] and Bradley Kuhn has been the Typhoid Mary spreading the disease." - Linus Torvalds (key player in the Linux kernel development).
They and the EFF created Affero GPLv3 and GPLv3 to try and solve for some of the issues they felt were important, but developers didn't really get on board.
The key is SFC can now sue folks making and distributing devices with OSS software WITHOUT any permission or input from the creators and copyright holders of the software, that is what is so huge. And this is particularly important because many authors and copyright holders have different views on these issues compared to the SFC.
We went though this once with GPLv3 already. SAMBA for example moved pretty aggressively to GPLv3. I'm not sure apple kept contributing to it or updating it in their software once that happened.
Sure, its easier to get standing to enforce GPL, but the legal requirements of abiding by GPL have not changed due to this decision. The only change is that GPL violations that were hard to pursue are now easier and people that have been violating GPL will be more likely to face consequences.
If this that GPL projects have lower adoption rates then that is because fewer people who would have violated the license will bow avoid it. Similarly, if fewer projects areadr available as under GPL, it is because they are adopting licenses that have fewer restrictions.
I don't personally see the advantage of having a more difficult to enforce license. Either your license accurately matches your intent in a court of law and should be enforced rigorously, or it doesn't match your intent and you should use a different license.
Selectively enforced licenses seems like selectively enforced laws: ripe for corruption.
On the contrary: the GPL is meant to PROTECT developers from patent trolls and freeloaders who what to turn FOSS into unpaid labor.
It also protect users, and all developers are also users.
The only thing the GPL does is give the same access copyright holders have to software to downstream users.
I think that's what GP meant by preventing freeloading. Anything you do with the source code to GPL software needs to itself be distributed freely. Ie, a company can't freeload off of your work to build and then sell a proprietary project.
Simply using or modifying for internal use is OK.
We cross the line into unpaid labor when I release an application or a game, and somebody changes the name, maybe makes minor improvements, then sells it and takes all the money, takes all the credit, and even competes against my own software.
I think that what you want (no competition from forks or downstream redistributors) would not comply with the Open Source Definition (or DFSG) nor the Free Software Definition.
https://opensource.org/osd https://www.gnu.org/philosophy/free-sw.html
For me, the biggest problems are:
1) Strong copyleft licenses often end up being incompatible with other free software licenses, especially other strong copyleft licenses. GPLv2(not +) and GPLv3 are incompatible, GPLv2 is incompatible with Apache 2.0, etc. Proliferation of strong copyleft licenses can therefore create serious interoperability challenges even within the free/libre software ecosystem.
2) LGPL is deeply tied to the technical specifics of how libraries and executables are linked together. This might have been reasonable when 90% of software on Linux was written in C and most developers could be expected to deeply understand those concepts, but it is no longer a reasonable expectation. Understanding how to comply with LGPL when it comes to C++ with templates, or Rust, or Go, or C with LTO techniques and inlining, is now an incredible headache when compared to licenses like MPLv2 that are approximately similar in scope but much simpler to understand.
3) The definition of "derivative work" is too broad. The FSF considers that re-implementing a library in an entirely different language would be a "derivative work" [0] Perhaps that's fair enough - if the translation is basically identical. But what if it's not? Where does the line between derivative and non-derivative work lie? If I was a very active contributor to some GPL project, and years later I decide to write a vaguely-similar-but-different program in some entirely different language, is that a derivative work? Do I need to walk a lawyer through every line of code?
These incompatibilities and chilling effects do come with a cost to free software as a whole. I still think GPL can be good for many types of software but in some respects it really can get in the way of proliferating free software.
If someone creates derivative works of GPL software, they could of course claim that they have not accepted the GPL contract, but in that case they would plainly have committed copyright infringement.
So, now it's back to state court where that court will decide whether there is any merit to SFC's claims.
That's all true until the process servers turn up.
If a U.S. corporation has a registered mail address for legal service, is there ever a need to get a process server involved?
https://www.sos.ca.gov/business-programs/business-entities/s...
EDIT: I’m wrong and need to pay more attention. See comments below.
The federal court said that because this was a contract issue, not just a copyright concern, that copyright law could not be used to bypass the contract law to move the case to federal court.
>The May 13 ruling by the Honorable Josephine L. Staton stated that the claim from Software Freedom Conservancy succeeded in the “extra element test” and was not preempted by copyright claims, and the court finds “that the enforcement of ‘an additional contractual promise separate and distinct from any rights provided by the copyright laws’ amounts to an ‘extra element,’ and therefore, SFC's claims are not preempted.“
This isn't California specific at all.
It's a District court. This is specific to California by nature of the jurisdiction. The finding of the Honorable Josephine L. Staton is, an element of that case, not the ruling. This will end up in the Appellate.
It's a good first step, but don't overstate the facts.
Maybe, but that isn't clear. They will try to appeal, but it isn't clear if the appeals court will accept the appeal. If the court doesn't accept the appeal, then all courts will be informed about this for future cases as lawyers try to build their case before whatever court they are in front of. If it is appealed, then whatever the final appeal result is will win (final appeal can be different in different courts so there could be conflicts until the supreme court takes this.).
My guess is the appeals court won't take this. Just a guess though.
(Late addition): In fact, it seems that SFConservancy _wants_ the case to be tried "just" in California, hence the fought in Federal court and brought the case back in a State court. Perhaps the advantage is that it's easier to win the case at State level, but the ramifications of a win will be US-wide, or even Worldwide, as explained above.
The tricky bit in common-law countries like the USA and UK is that normally, a contract requires three things: an offer, acceptance, and consideration -- something of value exchanged for the offer in the contract. No consideration means no contract, and the license reverts to a bare license -- one that can be revoked at any time for any reason. If we now have case law establishing that the GPL fulfills the requirements of a contract, that will make software under the GPL safer, as it will not be at risk of having the copyright holders revoke permission to use or distribute it once it's out there under the GPL.