Re: DCO
Krzysztof Siewicz via Gdb <[email protected]>
| Newsgroups | gmane.comp.gdb.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, Thank you Mark for CCing the FSF on that thread. I'm the FSF's licensing and compliance manager and let me please also add Craig Topham, FSF's copyright and licensing associate so that our complete Licensing Team can participate in the discussion. We are not on this list and it took us some time to catch up with your conversation. We at the FSF have once promised to accept DCOs and to draft variant(s) of theDCO that would best serve the needs of the GNU project. So we are happy that this discussion takes place and that so many people communicate their needs and have informed opinions about ways for having the needs met. Since the last Cauldron, we have been meaning to look at the DCO again, and we're happy to work with people at GDB to help implement something directly. I hope it is OK for you if I present the FSF's position and rationale towards copyright assignments, and what guides us when considering DCOs. DCOs sound like a great tool for cutting bureaucratic overhead in a project, but it comes at a cost that should be well understood and risks that should be managed. For the time being, copyright assignments bring a lot of certainty and security, but with an overhead, so perhaps we should focus on minimizing the overhead instead of dropping assignments altogether. I explain in detail below why: The FSF's copyright handling policy is designedwithenforcement of the GNU GPLvia copyright actionsin mind. Other goals are: to give FSF explicit permission to include the material in a GNU package, to make it possible to add additional permission to specific pieces of code, and to protect the community from employers' surprise claims (including patent claims). The FSF asks contributors for two kinds of legal papers: copyright assignments, and employer copyright disclaimers. Sometimes, for small parts of programs we also accept placing them in the public domain or giving the FSF an unlimited perpetual nonexclusive license. Employer disclaimers are important, including for effective GPL enforcement. If we accepted a copyright assignment but it turned out that copyrights had been actually held by the employer, the copyright assignment would not transfer any rights to the FSF. The employer disclaimer used by the FSF also addressesthe employer's patents and interface copyrights that might cover the contributor's code. From what we know, projects collecting DCOs do not require separate employer disclaimers, but this looks less burdensome for developers only at first glance. AsBradley noted in his post, the Linux DCO text simply shifts all the burden for these important tasks onto the individual developer. The developer must personallymake sure that the employer won't claim copyrights or patents on the code. Also, DCOs are issued by employees, not employers. So even if a DCO includes a statement of the employee that no employer can claim rights on the code, it is hardly equivalent to such a statement made directly by the employer. Whatever the contributor agreed with the employer might be not enforceable by the project or users, and they are definitely more legally secure if the employer issues a disclaimer towards the project and its users directly. Copyright assignment by its nature includes a transfer of standing to bring copyright claims undera license and to add additional permissions. We believe that GPL enforcement via copyright is very important for the future of software freedom. Thus, the FSF is and will remain committed to holding copyrights to preserve software freedom. This is not guaranteed for projects where copyrights are assigned toorganizations with no commitment to uphold the GPL for the community, e.g. to for-profit employers of the developers, that could as well be incentivized to relicense the code under a nonfree license. I hope this is helpful. This is not legal advice as the FSF cannot give legal advice, but it is intended to clarify our policy approach. We are open to hearing any ideas for improving our copyright handling policy. FSF is also hosting a panel at FOSDEM in the Legal and Policy DevRoom about some of these issues in a few weeks and I welcome those interested to find us there H.1301 (Cornil) on Saturday at 12:30: https://fosdem.org/2025/schedule/event/fosdem-2025-5376-managing-copyrights-in-free-software-projects-discussion-panel-with-gnu-maintainers/ If you have any questions, do not hesitate to contact us. Best regards, -- Krzysztof Siewicz | Licensing and Compliance Manager, Free Software Foundation GPG Key: 6DC9 E663 36DB 9588 81AB 7E43 2671 24EF FC9C D84E https://fsf.org We moved! The FSF changed address, find us at:https://www.fsf.org/about/contact Free software is important for a free society! Build a better world with us by matching the average donation of USD $46.22 https://donate.fsf.org Give the gift of an FSF associate membership: https://my.fsf.org/gift-a-membership Follow the FSF on Mastodon:https://hostux.social/@fsf Sign up for the FSF's newsletter:https://www.fsf.org/fss US government employee? Use CFC charity code 63210 to support us through the Combined Federal Campaign.https://cfcgiving.opm.gov/