9 ms·
ZFS Licensing and Linux
- tw04 11y agoI find it odd he uses the term "quite obviously" twice in his post. If it was so obvious, why bother seeking legal counsel? I think he's doing Ubuntu a disservice with that kind of response. It makes it seems as though they haven't put in an appropriate amount of effort to vet this thing out. I'm also curious as to why they'd have waited so long to include it if the legal questions were so trivial.
- lallysingh 11y ago.. because he makes more than 2 conclusions, and the rest aren't "quite obviously" true?
- __michaelg 11y agoYes. As one of my professors used to say: Using "quite obviously" in non-fiction is quite obviously wrong in most cases.
- jpgvm 11y agoI imagine the wait was mostly that it wasn't deemed necessary to have ZFS on Ubuntu until now. Containerisation has drastically increased interest in CoW filesystems. Traditionally their only use-case has been for implementing livecds and similar ro + rw layer environments. For this AUFS has been the gold standard since basically forever. However AUFS has some flaws and lack of features that make it undesirable to use in production container workloads, hence looking to ZFS to fill this gap.
- opk 11y agoNote that AUFS has been succeeded by overlayfs which, unlike the various earlier union fs attempts, has actually been merged into the kernel. I'm not sure where it stands with regard to flaws
- mjg59 11y agoIt's pretty flawed - for example, if you open a file read-only, open it again read-write and the write to it, any read from the first file descriptor won't show the writes. The corner cases don't bite people under most circumstances, but when they do they're awful.
- vetrom 11y agoThat sounds like a fairly normal structured file/multiprocess workload, not much of a corner case there :(
- nathwill 11y agoits still pretty raw. check out cve-2015-8660, which basically let unprivileged users bypass normal file permissions without even trying. it's fixed in mainline now, but still hasn't hit a lot of distros.
- ElijahLynn 11y agoObviously the word obvious is used incorrectly most of the time.
- ryao 11y agoIt is always good to double check things on the off chance that you are wrong. Many of the critics of Canonical's decision cannot claim to have done that.
- na85 11y agoPerhaps they're exercising due diligence by consulting their lawyers. What seems obvious to the legal layperson is not always a cut-and-dry issue for the law.
- protomyth 11y agoCan someone explain the circumstances around nvidia.ko and why that has been allowed?
- rogerbinns 11y agoI believe the claims are along the lines that the core of the Nvidia blob is actually the Windows driver, which is then not a derived work of Linux. They do provide the source for the bit that adapts between the Linux kernel and their blob. If you are being most charitable, you could consider this like NDISWrapper which doesn't make the driver used become part of the kernel from a license point of view. The least charitable is that Nvidia are circumventing / violating the kernel GPL by their stunt. Ultimately it would likely take some lawyers, time and money to get a strong decision, which no one seems willing to do, yet.
- sdca 11y ago"we make exceptions for a small set of tools and drivers that make it possible to install Ubuntu and its free applications on everyday hardware" -- https://help.ubuntu.com/community/Repositories#Restricted https://help.ubuntu.com/community/Repositories#Restricted
- tkinom 11y agoWhat is the worst case can happen in this use case? Let's say a NAS company (WD?) takes the linux + zfs and build a NAS incorporate all the zfs features. Who will/can/should file a lawsuit against them and on what probable cause? Would/should EFF do it? Why?
- lmm 11y ago> Who will/can/should file a lawsuit against them and on what probable cause? A copyright holder for the linux kernel, on the grounds that they are distributing an unlicensed derivative work thereof (there would be no need to show damages, there are statutory damages; it's definitely unlicensed, the part that's not clear is whether it's a derivative work). It's not really in the EFF's wheelhouse; mjg59 (who holds at least some kernel copyrights) claimed to be talking to the software freedom law center about his options. I'm unsure why he'd regard zfs.ko as more problematic than nvidia.ko (I mean fundamentally end users have the access they need to fix bugs in the ZFS source, the CDDL is basically the same as the GPL, whereas end users cannot fix bugs in the NVidia video drivers, not in some theoretical legal sense but in actual practice), and if the legal theory is correct then it surely applies equally well to both, but he's the one with standing to sue so it's his call. IANAL.
- ploxiln 11y agoTheoretically, nvidia.ko never comes in the same dvd / usb-stick / download as the kernel, it's always a separate piece installed by the user later (even if with a helper program). "Super Easy" derivatives of mainstream distros may include nvidia.ko (and libdvdcss etc) in the initial install, but mainstream distros including ubuntu do not. So they could say, if there was some violation of license going on, it wasn't them doing it, because they were not distributing something derived from the linux kernel. They may separately offer some "shim" code and binary under a separate license that the user then combines with the linux kernel headers on their own machine, and does not distribute the combination. That's one of the attempted justifications anyway. So what's more "audacious" here is Ubuntu distributing zfs.ko included in the initial install, and not requiring a dkms-like setup. There's disagreement, even among core kernel developers, about whether nvidia's binary kernel module is OK. The fact that they've gotten away with it for a long time doesn't mean that it's OK, just that it's somewhere between hard and impossible to enforce copyleft (for various reasons worth of a separate post). ref: https://lkml.org/lkml/2012/8/1/411 https://lkml.org/lkml/2012/8/1/411
- pilif 11y ago> Our conclusion is good for Ubuntu users, good for Linux, and good for all of free and open source software I would say that your conclusion is bad for linux and bad for all of free software. Because if linking your non-gpl-licensed binary blob with the GPLed kernel is legal then linking any other non-gpl-licensed binary blobs with any other GPL binary is also legal and thus the GPL is completely worthless. Is it worth setting such a precedent over the ability to run ZFS on Linux?
- FireBeyond 11y agoIs it somehow Ubuntu's fault if these behaviors are found to be legal and not protected by the GPL?
- snuxoll 11y agoThere is already precedent set for loading non-GPL blobs into GPL binaries, and the FSF even has some information on what they believe to be the line for this case [0]. Now, mind you, this specific case does fall under what the FSF believes - so we start falling into the argument of what constitutes a derived work. Linus obviously believes it is possible to create kernel modules that aren't GPL'ed, and he has allowed nvidia, amd and many other vendors to create proprietary blobs without legal issues. We also see something similar with Illumos' KVM support, where they are loading the GPL'ed KVM module into their CDDL kernel. The argument is that KVM was not developed as "part" or dependent on Illumos, only minor changes had to be made to allow it to work there instead of on Linux, as such it is not a derived work of Illumos and can be used even though the GPL and CDDL are incompatible. The same case is being made here for ZFS, the OpenZFS code has been modified to work as a Linux kernel module but it is not a derived work of Linux as it is a standalone product that someone just so happened to port. Legal precedent on this is going to be very interesting to watch if someone decides to take this case to court. http://www.gnu.org/licenses/gpl-faq.en.html#GPLAndPlugins http://www.gnu.org/licenses/gpl-faq.en.html#GPLAndPlugins
- bjornsing 11y agoI think Torvald's is a much more nuanced and reasonable approach to this issue: http://yarchive.net/comp/linux/gpl_modules.html http://yarchive.net/comp/linux/gpl_modules.html. Also, if you feel that kernel modules should be GPL without exception then you should lobby the Linux kernel maintainers to export all symbols with the EXPORT_SYMBOL_GPL macro. As it now stands, the division of exported symbols into two classes ("normal" and "GPL only") is a strong indication that the copyright holders do believe that kernel modules are not necessarily derivative works.
- geofft 11y agoWouldn't the same logic let you conclude that, say, CLISP under a proprietary license + readline under GPL can be distributed together, if readline is distributed as a loadable module instead of a static binary? readline is "quite obviously" not a derivative of CLISP, or vice versa. http://clisp.cvs.sourceforge.net/viewvc/clisp/clisp/doc/Why-CLISP-is-under-GPL http://clisp.cvs.sourceforge.net/viewvc/clisp/clisp/doc/Why-...
- snuxoll 11y agoThe definition of a derivative work comes into play here. An argument has been made by Illumos who ported the KVM module from Linux that since they did not have to make any changes to Illumos to support KVM, and they only made minor modifications to allow KVM to be loaded into the Illumos kernel that it does not constitute a derived work since it in no way depends on Illumos to function and that there was no changes made to Illumos to support it. Illumos gets to stay as CDDL and KVM remains GPL. A program that functionally requires libreadline to function is very obviously a derived work in copyright law, calling dlopen() isn't going to save you from that.
- vbit 11y agoInteresting that it took so long to reach this conclusion. I thought Linux devs stayed away from ZFS mainly due to the licensing which leads me to believe it's not quite as 'obvious' as this post mentions.
- shmerl 11y agoLinux stayed away from including it into the shipped kernel, which is indeed a derivative work. Their argument is that kernel module loaded into kernel separately is acceptable to avoid GPL violation.
- davexunit 11y agoIf this is acceptable then the GPL is useless. This behavior is not in the spirit of the GPL and copyleft.
- shmerl 11y agoGPL defines what is supposed to be the subject to its limitations. And apparently this use case isn't part of it. So how do you define what's in spirit and what is in the letter of the law here?
- ajross 11y ago> And zfs.ko, as a self-contained file system module, is clearly not a derivative work of the Linux kernel but rather quite obviously a derivative work of OpenZFS and OpenSolaris I don't see at all why that follows. Why not both? Building a kernel module requires including headers and writing glue code to conform to the kernel API, which is licensed only under the GPLv2. It strains reason to argue that a ELF binary with Linux metadata and Linux module entry points registering functions to implement a Linux filesystem is "clearly not" derivative of Linux.
- dsp1234 11y agoIt strains reason to argue... So then the question is, why is "nvidia.ko"'s binary blob not a derivative of Linux? What's the logic that says one binary blob is a derivative work, and the other is not when they both are 'ELF binary with Linux metadata and Linux module entry points'.
- ajross 11y agoThe NVIDIA driver has been long subject to exactly this controversy, which is one reason why distros don't like to ship it.
- wnoise 11y agoMany people think it is, but apparently no one with authority to go to court over it has done so.
- dsp1234 11y agoIt certainly would be interesting to see a "Software Freedom Law Center" vs "Free Software Foundation" legal battle. But if no one wants to fight over a clearly more egregious graphics blob, then why would they go after Canonical for something seemingly less of an issue.
- ryao 11y agoThe Linux community already had this discussion over the Andrew Filesystem, which was a proprietary port. That is partly why we have symbols designated as being okay for non-GPL code. As for using headers, few consider them to be subject to copyright and those that do would likely find a fair use case for using them for compatibility. However, complex macros and inline functions are a concern. There are not many that are quite so large that they would be considered non-trivial. So far, I have yet to see any that should pose a problem for legal review, although I have only paid attention to ones used by ZFS. Also, if it is not clear, this was raised inside Gentoo. There was a discussion involving this with myself, the ZoL project lead, the concerned developer and a member of the licensing team who had final call on the matter. The descriptions of what was being done and why it should be okay passed review.
- silveira 11y agoOracle America, Inc. v. Canonical Ltd. (2020).
- ivl 11y agoIf one group were to sue Canonical, it would likely be the Conservancy, as the issue is the GPL not allowing for ZFS to be included.
- cjbprime 11y ago> Equivalent exceptions have existed for many years, for various other stand alone, self-contained, non-GPL and even proprietary (hi, nvidia.ko) kernel modules. If your conclusion depends on asserting the obvious legality of nvidia.ko and saying that you're just doing what they are, you're in a super bad place.
- ealexhudson 11y agoThat, plus at least one of the authors in question (Oracle, nee Sun) appears to have picked a license deliberately to ensure that ZFS couldn't be distributed with Linux. They were otherwise happy to dual-license with some form of GPL where it suited them; Apple dropped the thing like a hot rock too. A read of the license text is one thing, the intent of the author is quite another...
- freebasedgirl 11y agoThe CDDL is an anti-forking license. It requires spooning.
- shiftoutbox 11y agoWhy not just use FreeBSD or OmniOS ? Why do I want to use Ubuntu. So I can say "Bro we use the ubuntu it rocks" ?