Re: DCO: Was: Re: Contributing to gdb
Simon Marchi via Gdb <[email protected]>
| Newsgroups | gmane.comp.gdb.devel |
|---|---|
| Message-ID | <[email protected]> |
On 2025-01-14 10:28, Luis Machado wrote: > On 1/14/25 15:10, Simon Marchi wrote: >> >> >> On 2025-01-14 04:49, Luis Machado via Gdb wrote: >>> While I agree having gdb be the sole bureaucratic entity not accepting DCO >>> with the other GNU tools projects accepting it (in particular because we >>> share code with binutils, so technically we'd have to make a joint decision), >>> DCO's don't seem to come for free, as we need to track each and every one of >>> those contributions so we can refer back to them when/if we ever decide to >>> update/switch licenses or if a legal problem arises. >>> >>> The contributions are not gdb's, they are still owned by their contributors, >>> but those are granted the right to be distributed by gdb under the GPL, if I >>> understand it correctly. >>> >>> That is potentially a lot of work, and really needs to be taken seriously if >>> we really want to do things by the book. Makes me wonder how we're supposed >>> to track this. >> >> My understanding is that the tracking is done using the "Signed-off-by" >> git trailer. I don't know of any project tracking contributions more >> extensively than that. >> >> Simon > > That's what I see as well. But my understanding is that the identifier used > in the Signed-off-by needs to translate to a reachable entity/person. If ever > there is a problem with a particular contribution, whether it needs to be > reverted or the code ownership is being challenged, that person needs to > be reachable so appropriate action could be taken to rectify the situation. > > Also, if the project ever wants to do a change/move to new licensing terms, > the project will need the approval of these contributors. Hence my observation > that this seems like a significant amount of work (for the project) that needs to > be done to ensure these contributors are always known and reachable. It is just not possible for all contributors to stay reachable forever. For instance, people die. My interpretation is that once we adopt DCO contributions and there are enough of them in, we accept that the license will never be changed, as it would be too practically complicated. This is the reality for pretty much all projects with a wide spectrum of contributors, like the Linux kernel. > > From reading things about DCO, it seems to rely on country-specific > interpretations and legal systems. The Signed-off-by git tag may or > may not be enough guarantee compared to CLA's. > > Obvious disclaimer, this is from doing some research on the topic. I don't > have a background in legal. But it doesn't seem to me like DCO's are as simple > as just adding tags to git commits as some seem to assume. "not as simple" I suppose. For some large projects (like the Linux kernel) it seems that easy, so I keep thinking "if it works for them, with a gazillion more contributions and big greedy compagnies having stake in it (so the potential for litigation), why wouldn't it work for us". But yeah, my opinion is absolutely not legally informed either, I am really just interested in simplifying the process, and reducing the unnecessary proces differences between us and binutils/gcc. At the end of the day, I personally don't care who owns the copyright. I understand the risks that somebody might claim they hold the copyright when they don't. I'm not sure how that differs from the contribution assignment though. Someone could sign the copyright assignment contract when they don't really own the copyright in the first place. If a company claims ownership of some code contributed by some individual who signed a copyright assignment but didn't have the right to contribute it, what would we do today? Wouldn't we have to go and delete that code? Simon