4 ms·
I think it may matter in specifics of how Red Hat chose to implement GPL compliance recently. This means that even non-clients of Red Hat can ask for copy of so
by hamilyon2 3y ago
I think it may matter in specifics of how Red Hat chose to implement GPL compliance recently. This means that even non-clients of Red Hat can ask for copy of source code as long as they have binaries. And you should definitely have right to give away binaries without asking Red Hat for permission.
- bonzini 3y ago> you should definitely have right to give away binaries without asking Red Hat for permission. You do, and you have to provide sources in that case. But, Red Hat can choose to stop doing business with you if you give away binaries for reasons that they judge to be against their interest. They aren't forced to accept your money.
- AnthonyMouse 3y agoHow would they even know who it is? Alice is a Red Hat customer, gives binaries and sources to Bob in private, now Bob publishes them on the internet for the world without telling anyone it was Alice he got them from. "Tell us who it was so we can retaliate against them for exercising their rights under the license" doesn't seem like a good faith request.
- trimistermota 3y agoNobody's going to use untrusted binaries/sources in this age of supply chain security..
- AnthonyMouse 3y agoAnybody can diff the sources against upstream if they want to. But also, how does that even mean anything? Bob submitted a patch to the mainline Linux kernel which Red Hat forked which Alice downloaded which Bob uploaded and now you're trusting Bob that the code is safe, which you were already doing anyway unless you were comparing the changes to the code yourself, which you can still do.
- wizzwizz4 3y agoUntrusted? They're from RedHatSourceDumps.onion! A few years back, my mate in Contoso gave me some sources a few years back, and they were identical to the ones that showed up on RHSD the next day; I don't know anyone who's ever noticed a bit out of place. Why would they choose today to start injecting malware, when somebody would raise the alarm within a week? Back in the real world: binary RPM packages are cryptographically signed, and I'm pretty sure source packages are as well. Who needs provenance when you can blindly assume that nobody's cracked the crypto yet (or, more realistically, leaked the keys)?
- yjftsjthsd-h 3y agoThat is certainly what RH likes to claim, but it always struck me as extremely suspicious logic. If the license says you have to share code with users and cannot restrict their rights to do the same, and they exercise those rights and you immediately retaliate, it sure seems like a reasonable person would say that you're restricting the rights of your customers in direct contravention of the license terms.
- arccy 3y agoan ongoing (future) relationship isn't a right
- torstenvl 3y agoNeither is employment. But there are still consequences for firing someone for an unlawful reason. I'm not saying Red Hat is wrong—I'm still undecided—but I don't think your logic is very persuasive.
- cool_dude85 3y agoIf you sign an employment contract that specifies you can only be fired for X and Y, and the company fires you for Z, you can sue. That doesn't mean your ongoing relationship is a right, it means one party didn't live up to the contract.
- yjftsjthsd-h 3y agoOf course not. Just as use of GPL software isn't a right. Stop using copyleft software and you won't have to worry about those licenses giving your customers rights.
- bruce511 3y agoI think we can agree that businesses have the right to "fire" their customers, for (pretty much) any reason try like. Of course, as with any "subjective" behavior right, there can be regulatory implications (Christian cake shops selling wedding cakes to gay couples springs to mind.) I'm not aware of any regulations though that would force RH to keep customers that broke their source-distribution-embargo. Clearly RH is not impinging on the users rights to distribute the source. They are impinging on the "privilege" of being a customer. Does that second-order effect fall under the GPL? Smarter lawyers than me will decide, but it seems like a tough sell. Of course we may not -like- that restriction, but its a long way from there to -legal- requirements. It's hard really to see how one can mandate an OSS company to -have- to do business with "any customer" when the moral-principle-premise is so high in OSS. I'm not sure that a regulation against RH would be a win for OSS in general.
- tsimionescu 3y ago> This means that even non-clients of Red Hat can ask for copy of source code as long as they have binaries. No, that is not a part of this trial. The SFC is a customer of Vizio, if they weren't they would not have had any kind of standing. The novelty is that a company who buys RHEL and redistributes it might be able to sue IBM if they then refuse future contracts. As it stands today, only Linus or other Linux copyright holders could sue. End users have never tried before.
- dagmx 3y agoThat is part of what Alma and Rocky argued they could do to get upstream source. However they’d likely have to sue the middle man first. E.g if you need RHEL source, but you’re a customer of <cloud provider>, you have to use cloud provider to provide you RHEL sources. They can then get it from RHEL, but the cloud provider is not a reseller in this case, but just someone who built their house on a product. However that does allow RHEL or the cloud provider to cut off customers who are actively engaging in source forwarding. The GPL doesn’t dictate who you do business with, and you effectively end up in a stalemate. Vizio on the other hand doesn’t have the power to prevent you buying their product. Buying from a reseller like Best Buy is legally equivalent to buying from Vizio when it comes to support. Therefore Vizio has a direct customer relationship with anyone who wants the source.