Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Linus Speaks Out On GPLv3

Posted by Zonk on Fri Jul 28, 2006 04:39 PM
from the that's-a-spicy-os-dev dept.
Slagged writes to mention the word that Linus Torvalds isn't a fan of the new GPL draft. News.com has the story, and someone purporting to be Linus is causing a ruckus in the Groklaw thread on the subject. From the News.com article: "Say I'm a hardware manufacturer. I decide I love some particular piece of open-source software, but when I sell my hardware, I want to make sure it runs only one particular version of that software, because that's what I've validated. So I make my hardware check the cryptographic signature of the binary before I run it ... The GPLv3 doesn't seem to allow that, and in fact, most of the GPLv3 changes seem to be explicitly designed exactly to not allow the above kind of use, which I don't think it has any business doing."
+ -
story

Related Stories

[+] News: GPLv3 Second Discussion Draft Released 242 comments
thppft! writes "The second discussion draft of the GNU General Public License version 3 was released, along with the first discussion draft of the GNU Lesser General Public License. Along with the text for the licenses , the GPLv3 website also includes an introduction by Eben Moglen along with markup changes to the rationale and the GPL itself."
[+] News: Torvalds Critiques of GPLv3 and FSF Refuted 548 comments
j00bar writes "After Linus Torvalds' impassioned critiques of the second draft of GPLv3 and the community process the FSF has organized, Newsforge's Bruce Byfield discovered in conversations with the members of the GPLv3 committees that the committee members disagree; they believe not only has the FSF been responsive to the committees' feedback but also that the second draft includes some modifications in response to Torvalds' earlier criticisms." NewsForge and Slashdot are both owned by OSTG.
This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Linus is wrong (Score:5, Insightful)

    by Anonymous Coward on Friday July 28 2006, @04:43PM (#15801817)
    I don't think manufacturers have any business preventing me from running my own code on hardware I purchased, at that stage I may as well be using MS Windows.
    • by Phillup (317168) on Friday July 28 2006, @04:52PM (#15801899)
      Manufacturers should be able to go out of business in any method they desire.
      • Re:You are wrong (Score:5, Interesting)

        by tomhudson (43916) <hudson&videotron,ca> on Friday July 28 2006, @06:28PM (#15802622) Journal

        Manufacturers should be able to go out of business in any method they desire.

        Yup. GPLv3 is just plain dumb. It "addresses" a non-existent problem. People have a choice between DRM and non-DRM platforms and software. They can and do vote with their wallets.

        And for those who are thinking "what about when there are no more non-drm devices, smarty-pants" - a GPLv3 won't address that issue; a swift kick to your political masters' behinds will.

        The GPLv2 isn't broken. v3 doesn't pass the "smell test"; it won't "fix" anything, certainly not a situation such as a fully-drm'd, fully closed world.

        Funny, the biggest push for DRM is from the so-called "free world." What sort of frigging time-warp alternate universe have we been living in for the last 6 years?

        • Re:You are wrong (Score:5, Informative)

          by Anonymous Coward on Friday July 28 2006, @08:56PM (#15803259)

          Yup. GPLv3 is just plain dumb. It "addresses" a non-existent problem. People have a choice between DRM and non-DRM platforms and software. They can and do vote with their wallets.

          Yes, but currently Free Software authors are subsidising the development of platforms that takes their Free code and locks it up so that it can't be modified or replaced. A lot of Free Software authors don't like this because it defeats the whole point of Free Software. That is the problem that it solves.

          • Re:You are wrong (Score:5, Insightful)

            by tomhudson (43916) <hudson&videotron,ca> on Friday July 28 2006, @09:42PM (#15803428) Journal

            Whoa, I think you missed the whole point of freedom :-)

            If they apply drm to anything I write, then *that* particular binary isn't modifiable, but so what? They still have to provide the source on demand to anyone they give the binary to. That, after modification, the source can't be compiled to run on that particular hardware isn't an issue. Why? Because when it happens enough times, people will say f*ck this and buy hardware w/o the lock-in. Nothing worse than a horde of pissed-off customers.

            The original source can still be modded and run fine on non-locked-out platforms.

            Now I understand your point - that if they had to develop their own software, this would cost them extra. But any software that they developed themselves would be totally locked up, and there would be absolutely no leverage to ever convince them to go non-drm, or even a sort of "open drm", where the content might be locked, but not the app.

            GPLv2 deals fine with these issues, by putting everything where it belongs - the push and shove of the marketplace. GPLv3, on the other hand, is both premature and heavy-handed. I'm sticking with v2, not just out of "political" reasons, but because I believe the marketplace works.

            Take a look at what's happening. Microsoft, with all its monopoly power, is scared of linux, firefox, etc. The marketplace IS speaking out. Now, if someone insists on running Windows, this hasn't diminished me in any way - I haven't lost anything. If they want to run my code on a winbox instead of a linbox, how have I, or anyone else, lost out?

            Same thing if they wanted to run it on a box that only allowed signed drm binaries. The only loser is the person who actually does this, then can't take advantage of any updates I do. Their loss, not mine. And its up to them to bear the cost of dumping their locked-in solution and switch.

            The first freedom of free software is to run it on anything you want. That includes proprietary and/or closed systems. Now, personally, I think that's a dumb thing to do in most cases, since open systems have consistently better performance and higher-quality code, but that's my choice - my freedom.

            What are people complaining about? Stuff like Tivo. Really, now - they're complaining about goddamn TV shows! Come on, there are more important things than that ... and if you don't like it, you can always make your own Freevio,or pay someone else to slap one toghether for you. Tivo didn't suddenly make Freevio impossible. What it DID do was give a target to shoot for.

            Lets take a real-life example. I've got some code for an integrated back-end/front-end inventory and web site. If/when I get around to cleaning it up and gpl'ing it, if someone else takes it and mods it so that it runs on a particular piece of hardware, but that only mods "signed" by them will run on that hardware, all they've really done is limited their market to people stupid enough to buy closed hardware. Everyone else is enjoying the benefits of open code on open hardware for less. What's the problem? Its just like a lottery, a tax on stupidity, right :-)

            Just this last week had a demonstration that eventually the market rights itself no matter what, when Microsoft's profits were down by a quarter, with the long-term outlook being more of the same. Closed systems just can't compete over the long term.

            Another example. I wrote the beginning of a c2java converter, because java lacks a lot of the constructs I like. One of these days I'll finish it and put it out there for people to play with. What would be the incentive for someone to pay for a drm'd version, wehn they can have the original one, with source that they can modify and run, for free? There is none. Anyone trying to market such a setup would be doing the "web 0.0" dot-bomb thing.

            Anyway, that's my take on it at this point. Let the free market handle it. There are too many of "us", and too few of "them", for us to fail unless we just stand there bent over with our hands around our ankles and buy any and all locked-in products. And if we do that, then we really do deserve the shafting we get.

        • No, it fixes a very important issue.

          You know the story of rms' printer driver: he wanted to be able to modify the printer driver so it would bloody work right or work better. He couldn't do that, so he made GNU.

          Now let's say the new rms. smr wants to fix his printer which is running embedded GPL software. Great, he thinks, I have the source code to this, so I can just fix the source and make my printer work/better.

          Oops! The printer doesn't allow you to do this. This is an awful loophole that restricts your freedom to modify the program. You can modify it, but you might as well write it on on a piece of paper for all that's worth. What the user needs to be able to do is modify the software and use it to really have that freedom. GPLv3 protects this. Linus is really being a stubborn idiot about this.
    • Re:Linus is wrong (Score:5, Insightful)

      by Spazmania (174582) on Friday July 28 2006, @05:43PM (#15802310) Homepage
      This is a twisted and difficult issue.

      On the one hand, the whole point of open source is that you can change it and then run your changed version. That shouldn't be suddenly untrue at the arbitrary border between hardware and software. Hardware that uses approved versions of open source while actively preventing my version from running violates the spirit of the thing.

      On the other hand, most of us have spent the last decade saying that its OK to use both open source and closed source software on the same machine. No one argues, for example, that you can't run GCC on top of a closed-source unix kernel even though it requires that kernel in order to run. Nor does anyone argue that the processor and other chips used by the kernel must be an open, free design.

      The real problem, I think, is that RMS (via the FSF) is trying to force it down our throats as usual. He's a strange bird in that he really gets the freedom issue at one level while it flies totally over his head at another.

      I think I'd put the DRM stuff in GPL3 as an optional component and see what happens. Let us authors decide whether we want it. If it works for us, it can be made permanant in GPLv4.

      So I'd do something like this: Software released under the GPL MAY designate (on either a file-by-file or full release basis) that it can not be used by any device which by design actively prevents its legitimate owner from adjusting the software or data. Distribution of code so designated would be fully compatible with distribution of any other interlinked GPLv3 code with the sole exception that binary forms of the portions so designated may not be distributed for use with the restricted systems.

      But then I'm a vi guy. Maybe if I'd written emacs I'd see it differently.
  • by BlackGriffen (521856) on Friday July 28 2006, @04:45PM (#15801840)
    It's fine to have the hardware validate the software, I don't think anyone can rationally argue against that. What's not fine is to have the hardware refuse to run the software at all. If the user is conscious that the software is modified and therefor unsupported, then the user should have the ability to run any software he chooses.

    So, have a cryptographic check alongside a message or error light or something about running in unsupported mode, but don't completely cripple the hardware just because you want to avoid support headaches.
    • by HairyCanary (688865) on Friday July 28 2006, @04:51PM (#15801893)
      You are failing to see this from the point of view of the manufacturer. What you have proposed simply gives you a way to run unsupported software. Where does it actually help the manufacturer? They are still going to get the calls, error light or not. Only now, in addition to providing support, they have to explain why they will not support a particular version of the code.
      • by AuMatar (183847) on Friday July 28 2006, @04:55PM (#15801925)
        No, I don't. I have to look at it from the point of view of the owner. If I buy a piece of hardware I damn well have the *right* to run any software I want with it. Now, doing so may void the warranty. But as the owner of the hardware I am allowed to make that choice.
        • by timeOday (582209) on Friday July 28 2006, @05:05PM (#15802002)
          Exactly. What if that "hardware" is a PC and that "validated software" is Windows? So much for Linux.

          I don't find this far-fetched in the slightest.

          • by Anonymous Coward on Friday July 28 2006, @05:10PM (#15802036)
            And the copyright owner of the software has the right to restrict the use of that software on devices which perform that hardware check. What's your point?
              • by GigsVT (208848) on Friday July 28 2006, @05:47PM (#15802328) Journal
                Linus's whole point is that the GPL 3 dictates technical details of projects that use it, where V2 didn't.

                GPLv2 dictated technical details that affected the next user's right to modify the software. For example, you couldn't link a modified GPL program with a closed source library, since that would hamper the ability to modify the software.

                The spirit of the GPL has not changed. The "political goal" is to ensure that all downsteam users that wind up using GPL software have the same rights to modify and distribute the software that earlier users had. That has not changed. It's only closing a loophole that some companies can use to take away those rights without violating the letter of the GPL.
    • BlackGriffen wrote:
      It's fine to have the hardware validate the software, I don't think anyone can rationally argue against that. What's not fine is to have the hardware refuse to run the software at all. If the user is conscious that the software is modified and therefor unsupported, then the user should have the ability to run any software he chooses. So, have a cryptographic check alongside a message or error light or something about running in unsupported mode, but don't completely cripple the hardware just because you want to avoid support headaches.
      What you say makes sense; however, I don't think the current language of the GPLv3 draft is clear on this point. Here is the relevant passage, emphasis mine:

      The Corresponding Source also includes any encryption or authorization keys necessary to install and/or execute modified versions from source code in the recommended or principal context of use, such that they can implement all the same functionality in the same range of circumstances. (For instance, if the work is a DVD player and can play certain DVDs, it must be possible for modified versions to play those DVDs. If the work communicates with an online service, it must be possible for modified versions to communicate with the same online service in the same way such that the service cannot distinguish.)
      It seems that the first phrase in bold allows what you describe: "implement all the same functionality" does not seem to prohibit a pop-up warning that the code is unsigned. However, the second phrase in bold says that modified versions must be indistinguishible from the original source from the point of view of an outside device. This seems to prohibit that same pop-up warning. So, it seems that Moglen & Stallman still have some clarifying work to do.
      • by radtea (464814) on Friday July 28 2006, @05:08PM (#15802024)
        If it's controlling some flight systems or some medical device, then it should be very stringent about the environment that it operates in

        This is why flight systems and medical devices are maintained by trained engineers who are governed by institutional policies that mandate the software changes that are permitted.

        The only thing that Linus' is defending is manufacturer's right to prevent anyone from ever running anything they don't approve of. I personally want to be able to run anything I want on my hardware (that's what "my" means) and if the manufacturer has to tell a bunch of lame customers who've broken stuff that they don't get no support, I'm sure that the manufacturers won't have any trouble at all doing that.

        I have managed support teams and had to deal personally with irate customers who were trying to run our product on WinME and the like, which was not supported. I had no trouble explaining to them clearly that they were not on a supported platform and they needed to upgrade their OS. It just isn't that hard, and honestly such users are a minisucle fraction of the total support burden.

        Likewise, at this very moment, there is code running on computers in hospitals around the world that is secured only by hospital policy. I'm talking about systems in ORs and imaging suites, most of which...well, you don't want to know about the situtation with regard to passwords on such systems.

        So far as I know, not one single accident has ever occured anywhere due to a user loading alternative code onto such a system. But I do know of cases where researchers have used their freedom to run alternative software to repurpose such system for all kinds of interesting and valuable experimental purposes.

        Linus is proposing to allow hardware manufacturers to use software validation to prevent the owners of such hardware from being free to use it in novel ways.

        There is no risk to the public due from the freedom to run alternate code. There is a very low added support burden from users running alternate code. There is currently a very good mechanism to prevent people from running alternate code in situations where it matters, starting with "voiding the warranty" and moving on up to "opening yourself to a lawsuit". Therefore there is no risk to anyone from hardware owners having the freedom to use their hardware as they see fit, and specious arguments invoking speculative situations with mission-critical hardware simply do not hold water.

  • Closing OSS (Score:5, Insightful)

    by saterdaies (842986) on Friday July 28 2006, @04:48PM (#15801855)
    Part of the point of OSS is that anything that you can modify should be modifyable. From the FSF's perspective, a hardware vendor shouldn't be allowed to lock you into using their approved software. You should be able to run whatever software you'd like on the hardware that you paid for. I'm not from the heart of OSS evangalism, but by allowing a hardware vendor to lock you into a certain version of an OSS application, you've closed the source of that app. It can be modified, but not run - and, to me at least, running is the ultimate point of software.
  • on the other hand (Score:5, Insightful)

    by ptr2004 (695756) on Friday July 28 2006, @04:48PM (#15801859)
    Say I'm a hardware consumer. I decide I love some particular piece of hardware and buy it with my hard earned money. But when I try to run one particular version of open source software customized for me, it doesnt run because the hardware complains it is not validated.
  • by cygnus (17101) on Friday July 28 2006, @05:12PM (#15802053) Homepage

    imagine a world where there's an open source electronic voting software package that everybody used... wouldn't you want the voting machine to be able to reject software that wasn't say verified by a voting auditing board and signed?

    the same thing could be true of open source ATM software. would you want your ATM to whine like HAL having his memory yanked when malware was loaded onto it, or would you want it to refuse to run?

  • by d.3.l.t.r.3.3 (892347) on Friday July 28 2006, @05:39PM (#15802285) Homepage

    By my point of view a benevolent dictator is still a dictator.

    We should thank Torvalds to keep the questioning open, otherwise it would be like Christian Church: the Pope speaks, the lambs obey.

    The article also makes a very saddening statement: the GPL3 is basically written by the companies behind the FSF. The article cites that HP is pushing to have their own interests protected. Do you really think that other GPL-oriented companies (like IBM or Novell) will just stay and look or they will also try to drive the boat towards their coasts?

    After all, FSF made just a favour to many commercial distributions (another case of uninterested philantrophism?), claryfying that if you have to fork a distro, you have to redistribute every single packet by yourself, instead of shipping only the relevant, modified ones like GPL says. GPL is too generalized and vague. You can't have a license that has hundreds of pages of "clarifications" continuosly swapped and rewritten to praise an actor or to damage another. Most of the clarifications are just more ambiguos or simply idiotic. Do you know that by FSF interpretation, subclassing or implementing an interface is considered a derivative work? That's makes impossible to use any object oriented library released over LGPL by the term of the license, they will be as plain and simple GPL licensed code. There's a lot of OOP libraries wrongly placed in the LGPL domain. Do you really think that their author bothered about the implications? They just followed the leader. For not good reason and without a clue. Why LGPL3 talks only about header files and libraries? Open source licenses should be technlogy neutral and C/C++ is not the only language out there. Sure our benevolent dictator may pretend that the other technologies are not there gut they will not fade away. Today IT rarely uses anything compiled aside core OS programs and it's hard to find a place for the delusional aims of a puppet in the hands of other non-Microsoft corporations.

    Sure A guru's life is expensive and big corporations makes hefty donations. Let Stallman explain to us mortals why Microsoft has to be destroyed and IBM or HP are valiant partners whose interests are to be protected.

    HP advanced pressures to make the GPL3 more friendly towards their PATENTS! The world got upside down or what?

  • by PostPhil (739179) on Friday July 28 2006, @11:10PM (#15803717)
    The FSF's stance is controversial (as exemplified by the GPL 3) because it's about freedom, which for all of human history has been hardly understood.

    Licenses like BSD/MIT have a view of freedom that is more like anarchy: the "do anything you want" style of so-called freedom (but at least give credit to who wrote the code). This stance doesn't actually create freedom because "anything you want to do" can also include taking freedom away from others. BSD people used to argue that you would still have freedom, only it's with the old code before the proprietary fork, etc. But DRM and other methods of preventing you from modifying and running software is not protected by BSD licensing. So, it is even more true today that BSD-like licensing in actuality has little to do with freedom and more to do with technological research without regard to the sustained openness that made studying that code possible.

    Freedom must be preserved and encouraged in order to exist! It is not a spontaneous choice that can be made after neglecting its preservation. Once freedom is gone, once official mechanisms are in place to restrict you, you can't simply make a choice to be free again. When I think of the FSF, I believe they understand freedom as many others have realized throughout history...

    "You can only protect your liberties in this world by protecting the other man's freedom. You can only be free if I am free." - Clarence Darrow

    "None are so hopelessly enslaved as those who falsely believe they are free." -Goethe

    "Liberty without learning is always in peril and learning without liberty is always in vain." - John F. Kennedy

    ...while the FSF would probably characterize false freedom as this:

    "After I asked him what he meant, he replied that freedom consisted of the unimpeded right to get rich, to use his ability, no matter what the cost to others, to win advancement." - Norman Thomas

    The more we are tempted by money to deprive others of freedom, the less freedom we all have in the end, and the less it's worth living in such a society even if you're rich. Don't worry about people crying about loss of profitability, etc. History has always shown that there will always be clever people that will find some way to make money, whether people are free or in chains.
    • Re:not surprising (Score:5, Insightful)

      by linvir (970218) * on Friday July 28 2006, @04:54PM (#15801919)
      http://en.wikiquote.org/wiki/Linus_Torvalds [wikiquote.org]
      "Making Linux GPL'd was definitely the best thing I ever did."


      http://hotwired.goo.ne.jp/matrix/9709/5_linus.html [goo.ne.jp]

      I'm generally a very pragmatic person: that which works, works. When it comes to software, I _much_ prefer free software, because I have very seldom seen a program that has worked well enough for my needs, and having sources available can be a life-saver.

      So in that sense I am an avid promoter of free software, and GPL'd stuff in particular (because once it's GPL'd I _know_ it's going to stay free, so I don't have to worry about future releases).


      In other words, Linus likes the GPL for the actual reasons that it is a good license, not out of any kind of narrow-minded 'software ideology'.
    • Re:GPL v3 will fail (Score:5, Interesting)

      by Prof.Phreak (584152) on Friday July 28 2006, @05:40PM (#15802292) Homepage
      I don't see what the big deal is. I mean really, if you have the source code, it is implied that you should be able to tweak how things work. What's the point of having the source code without the ability to tweak things (ie: if the hardware is locked to not accept your tweaks?).

      This leads to "trusted computing"---while this discussion is centered around `devices', it might find its way into computers. Imagine all the motherboard manufacturers being forced (by the paid off politicians?) to not allow you to run non-signed operating system. Obviously MS will get a signature, as well as major Linux distributions, but... What's the use of having the entire source for Linux, if you cannot compile and run your own version?

      I see GPL3 as an extention and realization that hardware now a days is exactly like software. General purpose microcontrollers running some software is NOT a `device' in the same sense it was a few years back, it's a computer running software. Very few devices are `custom built'---most are just microcontrollers with software determining how the thing works and `what it is'. GPL3 essentially says hardware = software as far as licensing is concerned. You cannot close hardware if you use open software on it. I think it makes sense.

      Anyone who disagrees with this isn't a consumer of hardware/software. They're hardware vendors looking to lock out users, while at the same time getting a free ride from open software.
    • by Prof.Phreak (584152) on Friday July 28 2006, @05:50PM (#15802342) Homepage
      When you get past the misinformation, errors and outright lies, trusted computing is not as bad as people think it is.

      I don't think you realize that "trusted computing" generally means "distrust the USER/OWNER of the computer". I think what everyone is afraid of is losing control of THEIR computer to some government/corporate organization.

      And yes, you have a point, it's not as bad as it may appear... if you're the one in control of what trust. Unfortunately, from the talk that's going around, it's likely users won't be in control (ie: hardware vendor ensures that any OS that runs on the box must be signed by some authority, etc.)---I franky cannot see how that benefits anyone but some corporation.

      And slowly but surely this technology is getting here. Music players, etc., many of them already restrict their owners. In a few years, it's not unlikely this will happen to PCs.
          • by evanbd (210358) on Friday July 28 2006, @06:11PM (#15802511)
            Not so. If I write software, and release it under GPLv3, there's nothing that prevents me from also releasing it on a DRM'd platform. I lose nothing. I can dual license the software; I've always been able to.

            What is happening, is that I'm saying that if you want to use *my* software on a DRM platform, *then* you have to hand out the keys or whatever else is needed. Which, for software I write, is exactly what I want. (Of course, I have trouble imagining how it would be relevant for things I write, but that's a different matter -- I don't write media players or kernels or other obvious targets).

            As a software *author*, I lose nothing. As a user of other people's software, I lose out only if I'm trying to redistribute their copyrighted work in ways they don't want. And, in that case, too bad for me -- just like it's always been.

            This license is about giving authors more choices, not less. And personally, this is an option I like.