Part of the hardware:
- Can be restricted to specific devices
- Must be available under GPLv3, including anti-tivoization provisions (forced bootloader unlock)
- May not attempt to use TPMs, DRM, or other systems to support assertions about client devices
Not part of the hardware:
- May only interact with hardware through public, documented, APIs in the "part of hardware" category
- Using alternatives from competitors must be fully supported
- When made by a company that also makes hardware, must also work on competitors' hardware (at least one, more if technically feasible)
- May be under a proprietary license
- Must not attempt to assert anything regarding the hardware, so things like Google Safteynet are now illegal. Security boundary must be shifted to consider client devices insecure
This is, I think, a good compromise to allow software developers to get paid without taking away ownership of hardware devices. Developers can be paid for "part of the hardware" software with money from selling the hardware, and "not part of the hardware" software can be trivially commercialized under a proprietary license. But, there is no way for a user to end up unable to control their hardware, or incentivized to configure it in a specific way.