11 ms·
Apple not providing LGPL webkit source code for latest iOS 4.3.x
- Hov 15y agoSeems to be Apple's M.O. to only act once someone raises a fuss in public. They'll release the source if this story spreads.
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- Xuzz 15y agoFor iOS 4.1, which came out in September 2010, absolutely no GPL code for it (or later versions, like 4.2) was posted until March 2011. That's not 8 weeks: that's about 6 months. When comex (http://twitter.com/comex http://twitter.com/comex) and saurik (http://saurik.com/ http://saurik.com/) asked for it (via emails to opensource@apple.com and copyright@apple.con) around last November, I don't think they got any response from Apple —until this year. Then, Apple let them know that it would be up "within a week". I think the iOS 4.1 and 4.2 code actually went up about three weeks after they received that email. saurik has even more examples of them not releasing the [L]GPL'd code near the top of this post: http://www.saurik.com/id/4 http://www.saurik.com/id/4 — "Frankly, I wouldn't be surprised at all if Apple ends up on the bad end of a GPL-related lawsuit." (In my opinion, the fact Apple has posted any code for iOS 4.3 at this point is a big step in the right direction: they're not perfect yet, but at least they've got 8/10 of the projects up.)
- masklinn 15y ago> In my opinion, the fact Apple has posted any code for iOS 4.3 at this point is a big step in the right direction: they're not perfect yet, but at least they've got 8/10 of the projects up. The truly weird part, to me, is that with as much (L)GPL code Apple releases they don't seem to have an automatic, systematic system in place to handle that. Even for a project as big as iOS.
- jpk 15y agoI think the problem is that doing so is a zero-revenue effort. Why spend man-hours putting together an automated workflow for source release when you can just do it manually (and lazily) every time someone complains? That doesn't justify it, of course, but looking at it that way makes it seem not-weird.
- jrockway 15y agoThis is risky, because lawsuits can have damage awards. If you decide not to comply with a contract you've agreed to because "it's a zero-revenue effort", that could look bad in court. Legality aside, it looks pretty bad from a human interaction perspective: "we took thousands of man-hours worth of code from the community, but we were too lazy to spend even one man hour to upload a tarball to our website and follow that community's wishes". The fact that they are legally-obligated to not act like that just makes it even worse.
- Xuzz 15y agoBut is it really an hour? I doubt that Apple uploads the code they actually used: it's likely that code, and then lots of removed components that would reveal too much about how something works (e.g. there are no build scripts or Xcode projects for JavaScriptCore releases, only the code itself). At least, they would need to make sure that none of their proprietary code slips out. That likely involves more than "svn checkout; tar; ftp", maybe even lawyers to check it.
- openbear 15y agothere are no build scripts or Xcode projects for JavaScriptCore releases, only the code itself Not true. See JavaScriptCore.xcodeproj in ... http://www.opensource.apple.com/source/JavaScriptCore/JavaScriptCore-7533.20.20/ http://www.opensource.apple.com/source/JavaScriptCore/JavaSc... http://svn.webkit.org/repository/webkit/trunk/Source/JavaScriptCore/ http://svn.webkit.org/repository/webkit/trunk/Source/JavaScr... ... and if Xcode isn't your thing, just run the script "build-webkit" ... http://svn.webkit.org/repository/webkit/trunk/Tools/Scripts/ http://svn.webkit.org/repository/webkit/trunk/Tools/Scripts/ ... build instructions in plain English here ... http://www.webkit.org/building/build.html http://www.webkit.org/building/build.html
- chuckywhat 15y ago6 mo. is ridiculous but I roll my eyes @ GPL lawsuit.
- saurik 15y agoIt is actually worse than that, as Apple has /never/ been in compliance with this license: I want the code to WAK*. It is simply not possible to compile a copy of iOS WebCore with the incomplete code that Apple has chosen to provide.
- Macha 15y agoApple, as with many other companies, does not understand that it has to release the source simultaneously with the program using it. Despite the articles claim, Apple has not released the source in s timely manner for previous versions of iOS, instead waiting for it to be pointed out or for version N+1 or N+2 to be released first.
- skidooer 15y agoThey are only required to provide the source upon request. If they are rejecting those requests, that is another matter, but that doesn't seem to be the case here.
- bobds 15y agoThe problem is when they take 6 months to respond to such requests. What if they decide to wait a year next time? The ambiguity of "timely manner" in the license isn't helping, perhaps it's time for an improved version of the license.
- yason 15y agoDoesn't say anything of "timely manner" in the license text. It just says that besides distributing the sources with the binary it's sufficient to accompany "a written offer to give any third party the source code". Thus, they're on clear only if they give the source code to anyone who asks. Apparently they don't: giving it "soon" is not giving the source code but merely stating a promise to do so which is not allowed by the license. Ditto for not responding.
- bobds 15y agoYou are right, I can't find "timely manner" there. I was reading through various comments and it was mentioned multiple times so I didn't check. See this thread: http://news.ycombinator.com/item?id=2521911 http://news.ycombinator.com/item?id=2521911 "You may obtain a complete machine-readable copy of the source code for the LGPL-licensed portions under the terms of LGPL, without charge except for the cost of media, shipping, and handling, upon written request to Apple." My point is that if it takes a year to "process" such requests, it renders their promise to share the source kind of useless. Now we can argue about how many months would be acceptable, but I'm not sure there's much of a point in that. So a license that has some more specific rules regarding how such requests should be handled, would be an improvement.
- vaporstun 15y agoAnyone else find this to be a bit over-dramatic? They have released every other version and just haven't released the 4.3.x one yet. There is no indication that they refuse to release it ever, the site still says "Coming Soon" and it has still been < 2 months since 4.3 was released. Yes, I understand that under the GPL they're supposed to release it simultaneously with the launch, which they failed to do, but is this really front page news?
- docgnome 15y agoYes. I take license violation very seriously. Imagine if Apple was violating a Microsoft license in this way. They'd be sued in a heart beat. Companies need to realize the (L)GPL is serious. It's not something you can just ignore because it's convenient.
- msbarnett 15y agoBut surely openness is a spectrum, and if they've released versions in the past, and they claim they will be releasing this one, then that still counts as being "open"?
- rimantas 15y agoAnything related to Apple is always a good source for some sensationalist piece.
- Hov 15y agoWait, how is someone stating facts sensationalist?
- Macha 15y agoBut the conditions of the (L)GPL is that they are _required_ to do so when they release the source at the same time. Releasing it later is more open than not releasing it, but it's still not allowed with the (L)GPL.
- 15y ago
- rewqwefqwerf 15y agoYou just need the copyright owners to sue now. The copyright holders can also ask the SFLC do it for them, I'm sure they would love it.
- alecco 15y agoIt's a hard place. If they sue, they will be blamed as hardcore radicals. Remember most of the tech journalists depend on advertising.
- ekidd 15y agoIf you hold copyrights on your software, it's not radical to ask people to refrain from republishing it without a license. That's the central goal of copyright law, and not a new idea invented by the FSF.
- perlgeek 15y agoMr. Welte's approach so far has been to talk to the companies first, and only sued if there has been absolutely no (or negative) response. I think the blog post is part of the "not yet suing" process too, it tries to build a bit of pressure on Apple in the hope that no lawsuit will be necessary.
- mechanical_fish 15y agoOne doesn't have to start with a lawsuit. One starts with a nice polite letter, on actual paper, to Apple's legal department reminding them of their LGPL obligations and pointing out that they're past deadline and perhaps they should poke the relevant engineering team? Then if that gets no satisfaction you have your lawyer send the same letter. Then a nastier letter. Only then do you begin to think about preparing a lawsuit, which is expensive and probably overkill. What you don't do is put up a passive-aggressive blog post. This post doesn't even tell us how many letters have been sent, or by whom, or to whom, or when. Have we even asked the support folks or the engineers, let alone Apple legal? I can barely find the stomach to blame Apple's engineering team for prioritizing strict and timely license compliance somewhere below: Making their boss Steve Jobs happy, releasing features that paying customers care about, and sleeping. Fortunately, it is not my job to blame them. It is the job of Apple's legal department to blame them. Has anyone asked Apple's legal department?
- cppsnob 15y agoI'm still waiting for that "open" FaceTime specification.
- Maci 15y agoWhile in all likelihood it's a legal and bureaucratic issue causing delay, I can see how this is considered bad form. However, I've made an attempt at understanding the source release obligations under the GPL and all I get from it is: When you release to the public, you've got to release the source. But at no point have I found a "it has to be released immediately." http://www.gnu.org/licenses/gpl-faq.html#GPLRequireSourcePostedPublic http://www.gnu.org/licenses/gpl-faq.html#GPLRequireSourcePos... The only clause I can see Apple potentially hiding under is Section 3.B of the GPL. ie. as long as they have the door open for written requests all is well. http://www.gnu.org/licenses/gpl-2.0.html http://www.gnu.org/licenses/gpl-2.0.html Can someone please clarify for me how the "well intended" spirit of the license works versus the real world legalities and requirements ?
- jancona 15y agoCopyright law prohibits distribution of derived works. The LGPL is a license which gives permission to distribute software if certain conditions are met. In this case the license is from the many authors of Webkit and it permits Apple to distribute a derivative work (the iOS browser). If you think about it that way then "immediately" doesn't really come into play. If Apple provides a copy of the source when asked, they're complying with the license. If they don't they have no license. Technically, they are infringing copyright every time they distribute a copy of iOS. If someone sues, would a court award damages for the copies distributed or enjoin distribution of iOS until they comply? I doubt anyone knows because AFAIK no case has ever made it that far. Typically (L)GPL disputes are settled long before they make it to court, because the cost of litigation for both sides is high compared to the remedy desired (release of modified source). I wonder if there's a role for "Copyleft Trolls", i.e. litigators who acquire copyrights to GPL or LGPL source, then sue license violators with the intention of collecting damages rather than just compelling release? US copyright law allows statutory damages of up to $150,000 per work infringed.[1] If each source file is a separate work, there could be a lot of money at stake. In other words, the Righthaven strategy[2] applied to source code instead of newspaper pictures. Perhaps I should apply for a business method patent on that idea.[3] [1] http://en.wikipedia.org/wiki/Statutory_damages_for_copyright_infringement http://en.wikipedia.org/wiki/Statutory_damages_for_copyright... [2] http://www.google.com/search?q=righthaven+site%3Anews.ycombinator.com http://www.google.com/search?q=righthaven+site%3Anews.ycombi... [3] http://en.wikipedia.org/wiki/Business_method_patent http://en.wikipedia.org/wiki/Business_method_patent
- r00fus 15y agoAs a hardcore Apple fan, I strongly hope one of the non-Apple contributors to Webkit sends a source request to Apple with the implicit threat of lawsuit. Big companies don't treat others with kid gloves when it comes to licensing and copyright, so why should we take it from them?
- eru 15y agoYou can send the request yourself. Any third party is allowed.
- nikcub 15y agoThis only becomes a real issue when one of the KHTML copyright holders makes it an issue which they haven't.
- GHFigs 15y agoAre you sure about that? http://trac.webkit.org/browser/trunk/Source/WebCore http://trac.webkit.org/browser/trunk/Source/WebCore Edit: I would greatly appreciate an explanation of what is inappropriate about the above link.
- xentronium 15y agoCould downvoters explain what's wrong with link to webcore trunk?
- angusgr 15y agoI didn't downvote, and IANAL, but I believe I know the difference. When releasing a product with GPL/LGPL source, the requirement is to provide either the source or an offer to provide the source which corresponds to the exact version of the source code used in that product "on a medium customarily used for software interchange". So, if there were tags in the webkit repository that said "iOS-4.3.2", "iOS-4.3.3", etc. then Apple could take a tarball of it and someone requesting source could be provided with the tarball and optionally a link to the correct tag in the repository. However, waving in the general direction of the source repository and saying "it's all in there somewhere" doesn't constitute compliance. Even if one of the Safari versions tagged in that repository happens to be the exact source that ships in some iOS 4.x, Apple has to make that relationship clear because (AFAIK) iOS is the "product" in this case, not Mobile Safari, given that the two are indivisible from the end user's perspective. (Again IANAL, so this is all mostly based on lurking the Gpl-Violations.org list, reading their Vendor FAQ, and dealing with some reluctanctly GPL compliant companies.)
- trythis5 15y agoThis is what I'm guessing as well, but unless Apple uses heavily customized versions of WebCore for their iOS releases, this seems like a decidedly trivial violation. Doesn't excuse Apple, but hardly worth all this fuss. Also, seriously, downvoting both GHFigs' and xentronium's comments is pretty lame, folks. (Feel free to downvote mine: I'll never see the score.)
- crs 15y agoSo is the issue here that they have not packaged it up for people and put it on opensource.apple.com? Is the source not available in the official repository at webkit.org?
- saurik 15y agoNo, it isn't: Apple uses a modified version of WebKit and WebCore for iOS that is not present in trunk. For WebKit they are allowed to hold back these changes, but for WebCore they are not. They do anyway, however, and have actually /never/ provided a copy of WebCore for iOS that is complete enough to compile (in particular, the code for WAK* is redacted).
- dedward 15y agoWho holds the copyright on that webkit source code in question?
- 0x1337 15y agoKnowing how evil and secretive Apple is, I would not expect them to care much about open licenses.
- benatkin 15y agoWe have an update! http://news.ycombinator.com/item?id=2530086 http://news.ycombinator.com/item?id=2530086