Re: d/copyright years when upstream does not use years?

The Wanderer <[email protected]>
Newsgroups gmane.linux.debian.devel.general
Organization This space intentionally left blank.
Message-ID <[email protected]>
On 2026-08-21 at 14:13, Russ Allbery wrote:

> Walter Landry <[email protected]> writes:
>
>> Peter Pentchev <[email protected]> writes:

>>> So IMHO there are both good and bad things in copyright notices that
>>> do not include years:
>>> - good thing: you don't need to update it each year, and it does not
>>>   get very, very long as you skip a year every now and then :)
>>> - bad thing: it seems that, at least in the United States, such
>>>   a copyright notice may not be recognized in court
> 
>> Copyright attaches even if you do not have a copyright notice.  A year
>> makes it more clear when it applies, so enforcement gets easier if you
>> can point to it.
> 
> In US law specifically, you have to have a copyright notice to claim
> statutory damages, which in practice often means that claiming damages is
> effectively impossible without a copyright notice. (My understanding is
> that you would then have to prove actual harm, which is expensive and
> difficult.)
> 
> But there is no legal requirement to have a copyright notice, and upstream
> is entitled to not have one if they don't want to have one. That's not
> something Debian gets to decide for upstream. I think our obligation under
> the license (and just in general as good citizens) is to reproduce
> whatever notice upstream uses, even if it's not a legal copyright notice
> under US law.

(For avoidance of doubt, I concur with and/or confirm - as applicable -
all of this.)

> If upstream doesn't use such a notice, or omits some customary part
> of it like the years, I'm kind of dubious about us inventing one, and
> I'm not sure what would require us to do so.

I can see one benefit from having years, which isn't really relevant
yet, but could become so in the future:

Unless I'm very much mistaken (which is always possible), the date of a
copyright determines when that copyright will expire, and the
copyrighted material will enter the public domain.

AFAIK, we're well short of the first code that could still run on modern
hardware entering the public domain - but it will presumably happen
eventually, and having the copyright dates for the material in question
could be valuable when that "eventually" becomes "currently". It's
potentially even more relevant for non-code data, because that may be
much more likely to still be usable (even if by newer code) on future
hardware.

Of course, some (possibly many, or even most?) upstreams seem to just
blindly bump the claimed copyright year each year, even when no
copyrightable changes were made to (a given part of) the copyrighted
material in that year, and so the copyright wouldn't actually be
extended... but although that makes this use case for copyright years
less practical, I'd prefer not to allow it to prevent us from getting
what value there does remain out of having them.


The level of invested effort from DDs that requiring the addition of
copyright years to debian/copyright files for projects whose upstreams
do not provide them, much less requiring any kind of validation of
"actual" copyright date rather than trusting the years claimed by
upstream, might well - and I suspect in fact would - be greater than
what that value could justify. I do, however, think the value is
sufficient to warrant at least taking into explicit consideration.

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEJCOqsZEc2qVC44pUBKk1jTQoMmsFAmqInUkACgkQBKk1jTQo
Mmt6ug//U4pkAf3K+D+ZQScMVuFRRx4XyPY1xgQ9TvcxWGlrHS3+KGTssWCnBjm0
GI22mzcqv2sLvq8Yy+Q0MYdLHdyIqdIJw+p33LxxET6DatEns/m/wOZ07ER1qvAF
58fezmMnth09t6Mu0xlyAjxlNFXwsVqpIKlge6VaPzS0q9EiOgz39oDN+/kXSzlJ
Ie5qqyGbYnuZdxlcug1H9p9+24opmIYvXZdY2N1CNlHZmeYuUaDpafd30XiEX5hS
BI//VUnu75GcAWEYtsfFcw0KSuDRJi3cGXVXnZjj9mZEjodbZdWUCdPWQ59vKDCJ
VKH9l6QmTkNKGk14oxn5yNQX3Hyl7CvD8LckGqUqYvQsPErIrHx5N6ekr0DdVTqr
DgQI69cCwkzIY/JdT1I61bHsDZzIagch8sGBJ/0swG751EAwbcTu5Q0LOL2sxsmk
x743GA65Gemz6aQ9mRrgwgngGdNSc53BUWHl51A0f7VZoX0zKjB/aam1yrBxYNP4
EHschd+9AojPUFcZ/ixJ0t6i7+/I0DeEcx89u2sT6bQJgS0Xrsf5j7abvd61rgSQ
rsci+S86+aa8bkgu+qz9Wm6l4a9s4RozrWgh2Zh4cB4vQ3q/ZdwcQssX6HVaIPa1
ccYIMelzu19hUx8rlTbC+jetvejXe+dXtUX2YZMg3mdceWmq+Hs=
=AGCy
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.