Debian Violating Rust Trademark
bugs.debian.org
bugs.debian.org
Also, Rust needs some legal mechanism to shut down malware. Otherwise someone could throw up a build of "Rust" that does bad things to compile products and they would have no legal recourse to shut that down.
If someone is distributing malicious software, 1) I don’t think they care about whether anyone has legal recourse to stop them, partly because 2) they’ve already taken steps to become anonymous and resist takedowns.
Debian is open-source, open about the patches it applies and not in any way purporting it's the 'official' upstream Rust distribution or the patches are official upstream patches. I don't see how someone could make the argument the Debian project is somehow legally acting in bad faith with intent in a way that could either confuse consumers or cause financial damage and/or harm the Rust projects reputation.
To me claims like this just set a bad precedence in the open-source software ecosystem. The broadness of the clause has serious potential for abuse. It seems like a way to leverage the benefits of the open-source community while still protecting IP through copyright claims. That's how we ended up with the Oracle/Java debacle. Don't get me wrong I'm not saying the Rust project is just flat out evil like Oracle but the potential for abuse is there and definitely not in the spirit or intention of open-source software.
Arch: https://github.com/archlinux/svntogit-packages/tree/packages...
Alpine: https://git.alpinelinux.org/aports/tree/community/rust?h=mas...
FreeBSD: https://cgit.freebsd.org/ports/tree/lang/rust/files
I don't think anything other than a Mozilla distribution would comply?
* Paths - distro don't need to keep path detection and can simplify it (ex: headers detections)
* Archs that upstream don't care about (ex: m86k).
* Kernel that upstream don't care about (kfreebsd)
* Some old CPU support. example: https://salsa.debian.org/rust-team/rust/-/blob/debian/sid/de...
* simplification of the build system (ex: skipping windows support)
* Use libraries provided by the system (ex: compiler-rt for rustc: https://salsa.debian.org/rust-team/rust/-/blob/debian/sid/de...). This could be forwarded upstream.
* Some minor doc changes - for example, https://salsa.debian.org/rust-team/rust/-/blob/debian/sid/de... will use the local css file and not a remote css file (for offline support)
* Cherry-pick upstream fixes before the next upstream release: https://salsa.debian.org/rust-team/rust/-/blob/debian/sid/de...
* etc
As you can see, these patches do not impact the quality of Rustc itself. Some could be forwarded upstream (it is a pain for packagers to maintain patches - so, we do have strong incentives to contribute upstream).
Luke Kenneth Casson Leighton apparently knows nothing about how trademark law works.
Having something trademarked does not mean the owner of the trademark has absolute control over its use and force you remove any mention of said trademark. Trademark protects your mark from being used by others, commercially, to describe or name their products.
I cannot open a burger stand and call it McDonalds. I absolutely can have a "McDonalds Enthusiasts website", and there is fuck-all McDonalds can do about it in court, because my use of the trademark is descriptive. I can have a mailing list for fast food enthusiasts for said website, and we can discuss McFlurries and Big Macs and all manner of McDonalds products that are trademarked. I can sell a "Big Mac Storage Container."
And further: no, there's no grounds for financial compensation because Rust would have to prove damages, and good luck with that.
Further demonstration that Luke Kenneth Casson Leighton apparently knows nothing about how trademark law works:
> and no, the existence of the Copyright License does not invalidate or override the Legal requirement to also comply with Trademark Law. it is astonishing the number of FOSS developers who genuinely believe that they can blatantly disregard Trademark Law "Because Open Source"
>> For instance, here is an excerpt without context from Debian's policy: >> "You cannot use Debian trademarks in a company or organization name or >> as the name of a product or service."
>this is standard fare as part of Trademark Law. it causes "confusion".
Debian can say that all it likes, and corporations do often try to give people the impression that they have less rights than granted to them under fair use doctrines.
I can still open and operate a company called KennyBlanken's Debian Consultancy Shop and there is fuck all the Debian project can do about it, because it is descriptive.
I'm optimistic that a solution will be found. But brushing this aside with "it's descriptive" is not helpful.
just debian prefers to ship a stripped variant and calls it rust and cargo, which violates the rust trademark. debian can call it debrust, and the kernel can choose to support this and the official rustc.
The Rust foundation has added explicit provisions for porting, path fixes, and applying upstreamed patches.
This goes way beyond the Iceweasel situation.
[0] https://bit.ly/3RH3zdn (Link goes to, https://en.wikipedia.org/wiki/Google_LLC_v._Oracle_America,_.... but HN strips the trailing dot).
I think Debian should just move Rust over into "non-free" and call it a day. Most people are OK with installing non-free software. And those that aren't are probably skilled enough to compile their own Rust binaries.
As for having Rust in the kernel, I believe that either needs a special permit from Mozilla or there shouldn't be Rust in the kernel. It would feel very icky to open the door to using non-free products in the kernel, because that will surely invite me-toos.