2 ms·
If you consider signed blobs derivative works (which means hashing and producing a signature creates a derivative work), then any signed statement referring to
by devit 11y ago
If you consider signed blobs derivative works (which means hashing and producing a signature creates a derivative work), then any signed statement referring to an hash of the source code (or including the source itself) is also a derivative work.
This means that someone sending a PGP signed e-mail saying "I audited that the source code of GNU Foo with hash 0xdeadbeef... is free of backdoors" is violating GNU Foo's copyrights unless he releases his private keys.
This is obviously a very undesirable outcome, and so it's resonable to hope that hashing does not create derivative works, and thus signing doesn't either.
Including the scripts to install in the "preferred form" also seems very problematic because then you might also be forced to include a full copy of the hard drive of your development machine since that's an even more "preferred form" under that theory.
This is also a very undesirable outcome, so it's again reasonable to hope that "preferred form" does not necessarily include things that were absent in the original work and that aren't essential for reproducing the binary derived work itself.
- mindslight 11y agoIt's not the hashing of the object code that makes the signature a derivative work. It's the appending the signature and object code that creates one whole work.