GNU LibreJS: blocks JavaScript traps
gnu.org
gnu.org
* If an identifier on the banned list exists, it is non-trivial. The list is here: https://git.savannah.gnu.org/cgit/librejs.git/tree/common/fn...
* If an identifier is ever followed by the square bracket indexing operator, it's non-trivial. (Looking at Stallman's requirement, it looks like this should only apply to accessing properties on an object, but the authors don't seem to have found a way to differentiate using [] on an object's identifier and [] on an array's identifier)
* If there are more than three loops, it's non-trivial.
* If it uses fetch(), chrome, browser, XMLHttpRequest, or eval(), it's non-trivial.
Oddly, referencing "document" is commented out, even though Stallman explicitly said any DOM modification makes a script non-trivial. I wonder what broke (outside of what they expected to break).
https://rya.nc/files/librejs-poc.html
<script id="harmlessNullScript" type="text/javascript"></script>
<skript id="derp" style="display:none;">
/**
* @license Proprietary
* @copyright Copyright 2018 Ryan Castellucci, All Rights Reserved
*/
// WARNING: Code here needs to avoid the "less than" symbol.
(function(){
// LibreJS modifies the text of script tags onced they've been
// checked, which offers a very convienant way to detect it.
if (harmlessNullScript.textContent.indexOf("LibreJS: ") > 0) {
eval("alert('LibreJS detected, but non-free eval works');");
}
})();
</skript>
<script type="text/javascript">
/**
* @license Proprietary
* @copyright Copyright 2018 Ryan Castellucci, All Rights Reserved
*/
// An eval that works in the WebExtension port of LibreJS.
// Untested on the original XPI version.
Function(derp.textContent)();
</script>
In any event, there are a lot of ways to eval code...Client-side LGPL JavaScript is neither statically linked nor dynamically linked but potentially could be a "mere aggregation" i.e. it is hard to use LGPL legally. Perhaps you could meet the legal definition of calling a library by using web assembly or web workers (see your IP lawyer!).
Unfortunately the FSF appear to be intentionally vague when documenting this issue.
For more details see:
https://greendrake.info/publications/js-gpl
https://opensource.stackexchange.com/questions/4360/what-are... (be careful reading it because part of that answer is about what circumstances client-side GPL mean that the server-side should be GPLed).
This issue can affect the HTML and CSS too:
It is possible to write Javascript code which is strongly bound to a particular HTML document. The Javascript code in this case would have hard-coded references to parts of the HTML document and would rely on that document's particular structure to work. This would be a strong indication that the Javascript and the document should be considered a single work.
Edit: [1] Well conveyed: https://www.gnu.org/licenses/gpl-faq.html#ConveyVsDistributeEdit: [2] or object code (transpiled/minified) but distributing/conveying object code usually requires you to provde source.
> Unfortunately the FSF appear to be intentionally vague when documenting this issue.
This is only unfortunate when you don't allign with their purpose, in which case there is no reason to talk of using GPL at all. For people who allign with these purposes, this "vagueness" is fortunate
For interpreted (or JIT-compiled) code, then yes, by definition, the source needs to be distributed to end users in order to be executed.
For compiled code, only the resultant binary needs to be shared after compiling the source.
What about if my source code is in TypeScript and gets transpiled + bundled + minified into JS? Is that still source code?
That is object code (I wrote source code incorrectly).
But if the object code is part of a work then you may need to provide your "Corresponding Source" TypeScript code plus build files plus sometimes compiler tools. See my other comment https://news.ycombinator.com/item?id=40340774
The GPL and FSF are difficult to comply with depending on your situation. Also depends on your jurisdiction and the jurisdiction of the client using the browser (amongst other complexities).
Minified or obfuscated is certainly not source code under GPLv3’s definition <https://www.gnu.org/licenses/gpl-3.0.html#section1>:
> The “source code” for a work means the preferred form of the work for making modifications to it. “Object code” means any non-source form of a work.
The transformation very obviously makes it be considered object code.
And when you convey object code then you need to provide the "corresponding source" as per section 6.
But my comment is more about: how much of a web page is a "work based on the Program" or "modified version" when you distribute/convey GPL licensed JavaScript as part of your page?
Abridged excerpts from: https://www.gnu.org/licenses/gpl-3.0.html#license-text
“The Program” refers to any copyrightable work licensed under this License.
A “covered work” means either the unmodified Program or a work based on the Program.
Propagation includes copying, distribution (with or without modification), making available to the public
To “convey” a work means any kind of propagation that enables other parties to make or receive copies
The “Corresponding Source” for a work in object code form means all the source code needed to generate, install, and (for an executable work) run the object code and to modify the work, including scripts to control those activities. However, it does not include the work's System Libraries, or general-purpose tools or generally available free programs which are used unmodified in performing those activities but which are not part of the work.
6. Conveying Non-Source Forms. You may convey a covered work in object code form [snip] provided that you also convey the machine-readable Corresponding Source under the terms of this License ...
This is not legal advice.The FSF appears to be deliberately unclear about how GPL and JavaScript interact. And LibreJS is fairly useless to help you legally decide if your web page is a derived/modified work or not.
Congratulations, you've been shipping the built objects and need to provide the source now too for license compliance. ;)
And when you run it that is exactly what happens. It assumes the worst and the vast majority of things do not work. All it really does is slow your browser down to an absolute crawl as it tries to do its thing. I just ended up with Noscript and making a few exceptions where needed. It is a much better middle ground than this.
The whole premise of a website is that the owner gives you a licese of some kind to view it. Blocking only a technical part of it makes no logical sense. It's not like you are going to take the JS code under a free license that is likely dependent on the HTML structure under a non-free license and do stuff with it.
What about things like htmx that put logic directly into html attributes?
The way you want. Nobody forces you to run this plugin. You can run this plugin, or not, or even change the plugin source code to better fit your needs (something that you cannot do with the javascript programs this add-on is designed to protect you from).
I am honestly not sure were you got the 2 year commit gap, the latest commit is 3 months ago on master
https://git.savannah.gnu.org/cgit/librejs.git
> There's also no date on the article, so I can't easily tell how old this is
The article is many many years old, archive.org has a snapshot of it from 2012
OTOH, there hasn't been a test release since 2016, so keeping that section does contribute to the idea that it's no longer active.
It's clear the page is pretty old, with both "http" and "ftp" download links. FWIW, the http link redirects to https, and (warming the heart of this old Unix developer) the ftp link still works.
Probably from https://pagure.io/librejs/commits/master which is also mentioned on the page and supposed to be a mirror.
Even after whitelisting the domain for the iDRAC interface on the servers, just having it installed is completely breaking the remote console (something I need to use multiple times a day).
Damn, I wanted this to be ok too.
I don't get the hate against javascript tbh. With this, web components won't work I assume unless the license is known before hand? Or is that considered trivial?
What about wasm? Does it block that? Javascript is at least better than wasm since you can inspect javascript. So people that hate javascript should really hate wasm.
Also, how can the plugin know if the provided source code is correct without compiling it and comparing the outputs?
In a nutshell, Richard Stallman worked in MIT’s AI lab in the 1970s. The lab had a certain ethos that he loved ( https://www.gnu.org/gnu/rms-lisp.html , https://www.gnu.org/philosophy/stallman-kth.en.html ), but when it became common for software to be sold without the source code, he actually decided to start a foundation to recreate that lab ethos ( https://www.gnu.org/gnu/manifesto.en.html ). A lot of programmers agree with his view that refusing to give users source code, and legal permission to use that source code without restriction, is a terrible afront to freedom.
However, people have spent decades telling Stallman that if they adopted his principles, they couldn’t use their computers in the modern world. Every so often, he makes a declaration about various distinctions (it’s okay to use a computer even though the firmware isn’t free; it’s okay to read documents on the web, but any JavaScript should be treated as a program and you should insist on an acceptable license; he, personally doesn’t own a cell phone, but sees no problem with using somebody else’s non-free phone in a case-by-case basis; etc.). This is simply an extension to enforce one of his rules. Some programmers will feel bad about themselves if they don’t live up to Stallman’s expectations.
How can it know when to block a website? Does an human curate a white/black list of valid websites?
I guess what I am really asking is how would it say so? Because even if it is free software I assume this plugin would block it anyway since it don't know.
You could write an html comment just above it but how will I as a website owner know that this plugin:
1. Exists.
2. How to respect it.
There are plenty of plugins but this seems just like a plugin if you like to suffer when you really don't have to. I can kind of understand the goal of the FSF and I do hate some modern software today and companies trying to remove ownership but I have never thought the way FSF is doing stuff is a good way to reach their goal.