It does according to MSFT lawyers: https://techcommunity.microsoft.com/t5/hardware-dev-center/u...
It does according to MSFT lawyers: https://techcommunity.microsoft.com/t5/hardware-dev-center/u...
There's nowhere in the GPLv3 that says that (then again, that sentence doesn't imply there is). Anyone can download and modify the grub source code, and compile it. It doesn't mean Microsoft is obliged to sign their fork. I wonder if there's something that confused (or was bad faith interpreted) by Microsoft's lawyers?
Maybe someone can just use another open source license? Ie, anything not called 'GPLv3' which, like every other OSS license, does not purport to give someone the right to demand authorization keys to be able to install modified forms of the code on a device.
It does, commonly called the anti-tivoization clause. Here's the text:
> “Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
> If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM).
> The requirement to provide Installation Information does not include a requirement to continue to provide support service, warranty, or updates for a work that has been modified or installed by the recipient, or for the User Product in which it has been modified or installed. Access to a network may be denied when the modification itself materially and adversely affects the operation of the network or violates the rules and protocols for communication across the network.
> Corresponding Source conveyed, and Installation Information provided, in accord with this section must be in a format that is publicly documented (and with an implementation available to the public in source code form), and must require no special password or key for unpacking, reading or copying.
From GPLv3, section 6. Conveying Non-Source Forms.
From what I understand, allowing the user to install their own trusted keys is enough; there's no need to allow users to sign with the "official" trusted key as long as that alternative exists.
I suspect that Microsoft's worry is that they don't control the firmware (the motherboard manufacturers do), and some UEFI firmware might be broken and not allow installing alternative trusted keys. I believe shim solves this by adding an intermediate layer which also allows the user to manually install their own trusted keys, even if the firmware doesn't.
> “Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
> If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM).
I believe the MSFT lawyers are right here, but obviously I'm not a lawyer.
I now think I was wrong earlier.
Summarizing https://www.gnu.org/licenses/gpl-3.0.html:
> The information (ie 'methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work') must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.
The purpose of allowing signing is exactly to ensure modified code does not function in that environment.
Yes MS (and you) would be right. GPLv2, BSD or MIT would be fine but GPLv3 would not.
-----------------------------------
Edit reply to baobun (rate limit means I can't post)
I did think about that, but:
> continued functioning of the modified object code
is vague. Does it mean a new firmware binary should continue working on the same device as the unmodified predecessor or using is a new device (that allows arbitrary entities to sign) considered to be "continued functioning"?
> GPLv2 assures, to the purchaser of an embedded product, their absolute right to receive the information necessary to install a modified version of the GPLv2'd works. [...] installation of the GPL'd works must succeed and operate in a useful and functional fashion on the device.
I believe the FSF position is different, but it's unclear. At least one member of the SFC who was a member of the FSF in the past (Bradley Kuhn) [1] believes that the FSF has the same position - that both GPLv2 software and GPLv3 software must be accompanied by full instructions (and ability) for a user to install their own modified versions on any hardware containing this software. He believes that the only difference with GPLv3 is that, in addition to this requirement, other proprietary software on the device must continue to operate just as before; whereas, with the GPLv2, it's fine for other proprietary software to say "you're running an unsigned version of Linux, failing to start". Linus Torvalds' public statements about the GPLv3, as well as the FSF page on Tivoization [2], seem to suggest otherwise.
Either way, this is not some invention of MS lawyers meant to make the GPL look scarier, it is very much how the free software community sees the GPL working.
[0] https://sfconservancy.org/blog/2021/mar/25/install-gplv2/
[1] https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t...