Re: "freenginx" open source package and "nginx" from F5 open source, potential conflict?

Richard Laager <[email protected]>
Newsgroups gmane.linux.debian.devel.legal
Message-ID <[email protected]>
First off, I don't know anyone involved in this.

On 2024-02-26 11:49, Thomas Ward wrote:

> Back on February 14^th , an email went to the standard NGINX mailing 
> list that NGINX (F5) open source development changed a lot of policies 
> and interfered with security policy use cases
>
I don't know what other factors lead to the fork, but as far as the 
security policy thing goes...

Note that, per Maxim's own statement, the security policy disagreement 
is that he did NOT want to issue CVEs because the code was marked 
"experimental": 
https://mailman.nginx.org/pipermail/nginx/2024-February/FRVX4M5JLFSFESRG7RLWWRBZ6D4AKKQU.html

MZMegaZone on Hacker News claims to be the person at F5 on the other 
side of that. Here's the top-level article:
https://news.ycombinator.com/item?id=39373327

These two sub-threads are most relevant:
https://news.ycombinator.com/item?id=39373834
https://news.ycombinator.com/item?id=39373966

As MZMegaZone said, "Honestly, anyone could have gone to a CNA and 
demanded a CVE and he would not have been able to stop it. That's how it 
works." As I replied there, "I recently did exactly that when a vendor 
refused to obtain a CVE themselves."

MZMegaZone also said, "Also, something that keeps getting lost here, the 
CVE is NOT just against NGINX OSS, but also NGINX+, the commercial 
product. And the packaging, release, and messaging on that is a bit 
different. That had to be part of the decision process too. Since it is 
the same code the CVE applies to both." And in another comment, "We know 
a number of customers/users have the code in production, experimental or 
not. And that was part of decision process. The security advisories we 
published do state the feature is experimental."

So, in effect, Maxim seems to have wanted F5 to either NOT publish a 
security vulnerability for their commercial product, knowing their 
customers/users had this code in production, or to issue a CVE for the 
commercial product but not the underlying OSS project with the exact 
same code. Neither of those makes any sense to me.


> So, before I follow through with Debian packaging (which would be 
> synced to Ubuntu downstream), may I get the opinion of debian-legal on 
> whether there’s any copyright or trademark violation concerns that 
> exist before I pursue getting this into Debian?
>
I'm not a lawyer, but it sure seems like an obvious trademark problem to 
me. In my opinion, Maxim really should pick a brand new name if he's 
serious about this as an ongoing project.

Does Canonical have lawyers you could ask?

-- 
Richard
OpenPGP_signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE1Ot9lOeOTujs4H+U+HlhmcBFhs4FAmXc+8QACgkQ+HlhmcBF
hs7DdA//U2VU1AANIJjB5ASKIYqdLkdkR8dLWdEpYxMdv8AdZTEdlpJhz/m4dMGZ
XL0NPJMvkiYnuMeHoiAaCrfjzjO0+r1ePLO87r6i32zZp2LCt2TAKo27o+lzFsaO
UFFSRR6Fj7JSeLbxHfVLRyP+zc8nOsRQbX0rj9ESwdOqT8mvzE9AefXziUvHLOzR
SlFlZFaqFDankKhGdgIQoNXROK22V86CWrao8RAAeJ3m3yZ8LnEakC9vY//NMd/h
wUU9JrNkKy7BEgX6WTaeR3NiiP52rSojtf6Y+8E4LHmbZNfATZIrWw46OpmrlBB5
2ELAvqVnB3JAQ63UezalG0UOmjWau+fAhwrPrhDkCHpeIums57DLZu+p+qRe0apB
bXBC02dDkI1damiHcjprb4jCLA0hf8xrarS8Bm5FySwYu23P0aFLRdlyJIv354jh
RlLUytf0ztP7FKgWOEODvmeVTG87b4F3kTH/f+jIkK9VPfRmkgjZgCefZYubzgUX
PHEP15M7nD3NQea3yCRoXCf5PJsfhHi5z9O3hJiYq584qZS8uXHMr7xKfdD3v4Rl
RyBV4L14q+R89oM5fZAFbUIV81uQXlCKfUM6Ry1MjnhyjZeylweQrKl/5/9LcJiT
uj5ULxXpTHq9PyNdSrDpRGkOGnOK89m4ndcxGdVuK77qV5+0xlY=
=ILW6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.