11 ms·
Apple's Great GPL Purge (2014)
- yuhong 10y agoThe fun thing is that Mac OS X don't have the same restrictions as iOS.
- AceJohnny2 10y agoYou'd think, but considering how much shared code they have between the different systems, they ended up following their maximum constraints. Thank god, then, for HomeBrew/MacPorts/Fink/et. al. A 'chsh' and I can have a modern Bash as a shell.
- saurik 10y agoYet. (One way to accomplish this will be merging the operating systems, and the other way is continuing the march to making these restrictions more and more similar.)
- toyg 10y agoA default OSX install these days will only allow sandboxed installs from AppStore, or unsandboxed from developers registered with Apple. The jump from that to "only Appstore" is not that big and sooner or later will happen, it's mostly a commercial issue. Some time after that, the various options to change these policies will go away, and you will be left with something very similar to iOS in terms of lockdown. Seriously, mobile dragged us back to the bad old days of the '80s and basically made sure IBM clones and DOS couldn't exist. We're all screwed.
- pjmlp 10y agoI had fun in those days. The computers were a packaged experience of hardware and software, designed to work together. Hence why people have found memories of their 8 or 16 bit systems, while most might not even remember how their MS-DOS systems looked like or what OEM brand it was.
- CodeWriter23 10y agoI know. And then came the malware.
- pjmlp 10y agoWhich doesn't have anything to do with PCs, MS-DOS and being open.
- toyg 10y agoYeah: four different manufacturers, four different spreadsheet programs. Loads of fun, that was - not. We will soon look back to the Microsoft era as a golden age where you only had to avoid getting milked by one company, rather than every single one out there.
- deleted 10y ago[deleted]
- acqq 10y agoWere there the changes since 2014? Anybody knows?
- ksherlock 10y ago> JavaScriptCore, bash, bc, emacs, efax, gnudiff, gnuserv, gnutar, groff, gpatch, keymgr, libstdcxx, man, nano, screen, texinfo, and uucp. as of 10.12 (opensource.apple.com not yet updated): gnutar replaced by bsd tar keymgr gone? efex gone? (gnu) make is also included
- sfblah 10y agoI'm just glad they still include uucp.
- acqq 10y agoForgive me for not knowing, what is UUCP used for in OS X, and what is your use case?
- jlgaddis 10y agoI think that was sarcasm.
- guitarbill 10y agothat was probably sarcasm. almost nobody uses uucp so it's an obvious candidate to purge...
- saurik 10y agoJavaScriptCore seems to have been almost entirely relicensed under APSL; there are at most just two or three files still under GPL (involving date parsing), and in many configurations those are no longer compiled.
- bdash 10y agoJavaScriptCore code is either LGPL or BSD licensed, depending on whether it derives from the original KJS source base or is new code written by Apple. There's no APSL code in JavaScriptCore last I checked.
- oneplane 10y agoIt's that that big of a deal actually. You can still disable SIP, you can still override kernel extension signing (and signing on pretty much anything else), and you can sill install any GPLv3 software you want. It's just the default base install that has changed, and everyone knows there is no one-size fits all. While there are plenty of commercial reasons to not go beyond GPLv3 from the vendor point of view, it doesn't really change anything for "us". Even if we had a stable bash from 2015, we'd still want the 2016 version and install it anyway...
- tobltobs 10y agoJust out of curiosity (never used a Mac), how to you install all those versions you need? Via a package manager or from source?
- bearand 10y agoThere are lots of options, but Homebrew (http://brew.sh/ http://brew.sh/) is the most popular package manager for macOS.
- pauloday 10y agoPersonally I use a package manager called Homebrew. It's pretty good, I'd recommend it.
- panglott 10y agoI used the nix package manager for a while, but it's arcane, so I went to MacPorts. Homebrew is obviously the main one, though. It's always been better to install more up-to-date software, since the system default unix software has been ancient for a long time. It seems like default system Python was python 2.3 or 2.4 forever, although they've upgraded to python 2.7.
- rhinoceraptor 10y agoI've been using NetBSD pkgsrc: https://pkgsrc.joyent.com/install-on-osx/ https://pkgsrc.joyent.com/install-on-osx/
- 10y ago
- 0x0 10y agoCould it be they avoid GPL3 just because they don't want to release their Apple Inc code signing keys?
- teddyh 10y agoApple would not have to release their keys. They would have to make it possible for users to run their own modified versions of software. This can obviously be accomplished in many ways.
- Someone 10y agoBut if they shipped GPL3 software with the OS, they would like to code-sign the binaries. I doubt you will find a competent lawyer willing to state that releasing the source code for those tools without disclosing the signing key is 100% guaranteed compatible with the GPLv3. As a semi-workaround, they could use a separate signing key for GPLv3-licensed code they ship or even separate keys for each tool, but again, I don't think you will find a lawyer who is willing to claim it would be legal to retract the signing keys when people start signing malware with it.
- deleted 10y ago[deleted]
- teddyh 10y agoI doubt you would find a competent lawyer making any claim which has the word “guaranteed” in it. This still leaves it completely obvious that anyone could, for instance, ask the FSF what they would consider reasonable, and do that, and thereby avoid any reasonable risk of getting sued. The FSF has never been against code-signing.
- 0x0 10y agoBut the FSF GPL faq says they would have to release the keys: "The only time you would be required to release signing keys is if you conveyed GPLed software inside a User Product, and its hardware checked the software for a valid cryptographic signature before it would function. In that specific case, you would be required to provide anyone who owned the device, on demand, with the key to sign and install modified software on the device so that it will run." https://www.gnu.org/licenses/gpl-faq.en.html#GiveUpKeys https://www.gnu.org/licenses/gpl-faq.en.html#GiveUpKeys Sounds exactly like how iOS code signing works...?
- X86BSD 10y agoIt's not just Apple. FreeBSD for the last several years has been purging itself of GPL software as well. Going so far as to go through the pain of yanking out gcc for the llvm suite for the OS and ported applications.
- eltoozero 10y agoFreeBSD (and the other BSD flavors) are under the BSD license, no?
- pmb777 10y agoIs it really a "purge" if they do it over a decade? Seems like more of an "obvious preference".
- TAForObvReasons 10y agoStrictly speaking, "purge" does not have to be immediate or sudden. A purge can happen over a decade. In this case, "GPL Purge" is actually incorrect. They haven't eliminated the bash shell, emacs text editor, and other packages that are GPL, just chose not to ship with later versions that are GPLv3.
- X86BSD 10y agoIt takes a long time and lots of work to replace things like the gcc toolchain, purge pour code of gcc'isms, test, debug, add missing or equivalent features.
- ksherlock 10y agoXcode 4.0 (2010) was the last version to include gcc; it's been gone since 4.1 (2011)
- jordigh 10y agoI get the feeling everyone's purging the GPL, and I'm not sure this is a good long-term goal. I still think we need legal protection against backdoors, spying, and DRM; and our legislators have only given us copyright law to try to perform legal judo with. We'll see how things work out, but I'm not optimistic with the overall GPL purge. I fear that it's taking us to a world where Black Mirror is a familiar reality instead of a fictional horror.
- grzm 10y agoCan you expand on the relationship between the "overall GPL purge" and "a world where Black Mirror is a familiar reality"?
- jordigh 10y agoThe GPL is a defense mechanism. OpenWrt is the source code for routers, which are quite literally the gatekeepers of the internet. It was obtained via GPL enforcement. It doesn't look like that would have happened without the GPL. When source code is available, evil actors are just less likely to act evil. Even if nobody is reading the source code, just the act of publishing it psychologically nudges people towards acting less sociopathically. When people feel watched, they are less likely to try to cheat others, delete their ebooks, spy on them, or experiment on their emotions like Facebook did. This happens even if nobody is actually watching; just the potential of being watched is enough. And people do need a nudge to publish source code. Sure, unimportant bits of code that you don't really care about, that aren't core to your business, that you'd rather have someone else maintain for you; that's when you really love "open source" and you push your changes upstream and you look like a wonderful community member. It's for the missing important bits, the secret firmware blobs controlling our phone chips, our BIOS, our cars; even our refrigerators and our light bulbs; that's when you need GPL enforcement. I know hackers hate lawyers, but GPL enforcement rarely goes as far as lawyers. The GPL is a deterrent, a firearm that anyone can use and almost always remains dormant. People seem to be pushing towards legal disarmament, MIT license everywhere. I don't think this is enough to deter bad actors.
- 10y ago
- IBM 10y agoI really liked this last bit given the reaction to the MBP: >I’m also intrigued to see how far they are prepared to go with this. They already annoyed and inconvenienced a lot of people with the Samba and GCC removal. Having wooed so many developers to the Mac in the last decade, are they really prepared to throw away all that goodwill by shipping obsolete tools and making it a pain in the ass to upgrade them? Seems like developers have been overstating their importance to Apple forever.
- deong 10y agoAlso, it's hard to argue that an ancient version of bash shipping in 2016 is driving away developers when they've shipped an ancient version of bash forever, and developers were lining up for Macs during most of that time. If anything, I think Apple's increased focus on iOS and the rest of the industry finally making really good stuff would be a more significant factor if Apple starts to bleed developers.
- pjmlp 10y ago> Seems like developers have been overstating their importance to Apple forever. Apple cares about developers, those that love and enjoy writing applications for Apple OSes. The ones that were there in the good and bad days. Those that jumped into Apple OS just when they coincidently had a UNIX with a pretty UI because they choose not to get Be instead, not so much.
- jsz0 10y agoThe scenario the author outlined 4 years ago was one possible outcome but it turns out he was wrong. Instead projects like homebrew have flourished and it's now easier than ever to get fresh packages for popular GPL software on macOS.
- payne92 10y agoI think GPL has served its purpose, leaving a healthy ecosystem of open source software along with professional acceptance of the model. Now, paradoxically, GPL is less free than many open source licenses. The GPL restrictions will limit adoptions, as we're seeing here. Stated differently, GPL was an important starting "assist" that's now slowing us down. It's time to turn it off.
- candiodari 10y agoGPL is not about maximizing adoption, it's about maximizing freedom of your work and anything based upon it. It's about not having your work just stolen, embraced and extended, monopolized, and disappeared.
- X86BSD 10y agoExcept that other licenses already do that. The BSD license allows anyone to do what they wish with that BSD licensed code. Nothing happens to the original BSD licensed code just because someone uses it in a closed product. It's still available under the same bsd license.
- candiodari 10y agoNo it does not. For instance, if I write router code, and a vendor uses it in a product, it does not allow me to fix a bug in a product I paid for. It does not allow me to see and learn from how they did it. And given telco behavior it effectively locks me out of using my own code.
- grzm 10y ago"it does not allow me to fix a bug in a product I paid for" Would you go into more detail here? It seems to me, to use the router as an example, even if they were to make the source code available, getting updated code to run on the router would still be difficult, if not impossible, depending on how the software is running on the hardware. Is it burned into ROM? Are you able to flash firmware? I'm admittedly speaking from ignorance here. How are these types of issues addressed purely from the point of view of the GPL (or any other license, for that matter)?
- pjmlp 10y agoGoogle is doing the same. They just gave a death sentence to GCC on the NDK, by declaring it as deprecated and it will only stay around until clang support catches up with GCC. Brillo has even less GPL components than Android and in Fuchsia I imagine not a single one, given that they are even doing their own micro-kernel.
- cdibona 10y agoThis isn't the case, we use and release plenty of gplv2/3 code and LK was permissively licensed before it was adopted by the Fuschia people. GCC wasn't given a death sentence, we are just moving on to llvm. GCC devs have been moving to llvm for years and not because of the license. I'm sure DannyBee will say something about this down thread..
- pjmlp 10y agoIt might be the case, but it surely looks like something else from the outside.
- ksec 10y agoWait a min, as far as I can tell this is a GPL v3 Purge? That is huge difference.
- rincebrain 10y agoI can't be sure without looking up the lists of older software that was removed, but while almost all of the remaining packages he's listed are now GPLv3 upstream, I don't think the majority of software decided to do the GPLv3 conversion - Samba, or anything that's actually under the GNU project, certainly, but I'd be surprised if all the packages (or even 99% of them) happened to have all relicensed under GPLv3.
- paulddraper 10y agoWhat?!? Apple is getting rid of Bash? When?