Re: "freenginx" open source package and "nginx" from F5 open source, potential conflict?
Richard Laager <[email protected]>
| Newsgroups | gmane.linux.debian.devel.legal |
|---|---|
| Message-ID | <[email protected]> |
First off, I don't know anyone involved in this. On 2024-02-26 11:49, Thomas Ward wrote: > Back on February 14^th , an email went to the standard NGINX mailing > list that NGINX (F5) open source development changed a lot of policies > and interfered with security policy use cases > I don't know what other factors lead to the fork, but as far as the security policy thing goes... Note that, per Maxim's own statement, the security policy disagreement is that he did NOT want to issue CVEs because the code was marked "experimental": https://mailman.nginx.org/pipermail/nginx/2024-February/FRVX4M5JLFSFESRG7RLWWRBZ6D4AKKQU.html MZMegaZone on Hacker News claims to be the person at F5 on the other side of that. Here's the top-level article: https://news.ycombinator.com/item?id=39373327 These two sub-threads are most relevant: https://news.ycombinator.com/item?id=39373834 https://news.ycombinator.com/item?id=39373966 As MZMegaZone said, "Honestly, anyone could have gone to a CNA and demanded a CVE and he would not have been able to stop it. That's how it works." As I replied there, "I recently did exactly that when a vendor refused to obtain a CVE themselves." MZMegaZone also said, "Also, something that keeps getting lost here, the CVE is NOT just against NGINX OSS, but also NGINX+, the commercial product. And the packaging, release, and messaging on that is a bit different. That had to be part of the decision process too. Since it is the same code the CVE applies to both." And in another comment, "We know a number of customers/users have the code in production, experimental or not. And that was part of decision process. The security advisories we published do state the feature is experimental." So, in effect, Maxim seems to have wanted F5 to either NOT publish a security vulnerability for their commercial product, knowing their customers/users had this code in production, or to issue a CVE for the commercial product but not the underlying OSS project with the exact same code. Neither of those makes any sense to me. > So, before I follow through with Debian packaging (which would be > synced to Ubuntu downstream), may I get the opinion of debian-legal on > whether there’s any copyright or trademark violation concerns that > exist before I pursue getting this into Debian? > I'm not a lawyer, but it sure seems like an obvious trademark problem to me. In my opinion, Maxim really should pick a brand new name if he's serious about this as an ongoing project. Does Canonical have lawyers you could ask? -- Richard
OpenPGP_signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1Ot9lOeOTujs4H+U+HlhmcBFhs4FAmXc+8QACgkQ+HlhmcBF hs7DdA//U2VU1AANIJjB5ASKIYqdLkdkR8dLWdEpYxMdv8AdZTEdlpJhz/m4dMGZ XL0NPJMvkiYnuMeHoiAaCrfjzjO0+r1ePLO87r6i32zZp2LCt2TAKo27o+lzFsaO UFFSRR6Fj7JSeLbxHfVLRyP+zc8nOsRQbX0rj9ESwdOqT8mvzE9AefXziUvHLOzR SlFlZFaqFDankKhGdgIQoNXROK22V86CWrao8RAAeJ3m3yZ8LnEakC9vY//NMd/h wUU9JrNkKy7BEgX6WTaeR3NiiP52rSojtf6Y+8E4LHmbZNfATZIrWw46OpmrlBB5 2ELAvqVnB3JAQ63UezalG0UOmjWau+fAhwrPrhDkCHpeIums57DLZu+p+qRe0apB bXBC02dDkI1damiHcjprb4jCLA0hf8xrarS8Bm5FySwYu23P0aFLRdlyJIv354jh RlLUytf0ztP7FKgWOEODvmeVTG87b4F3kTH/f+jIkK9VPfRmkgjZgCefZYubzgUX PHEP15M7nD3NQea3yCRoXCf5PJsfhHi5z9O3hJiYq584qZS8uXHMr7xKfdD3v4Rl RyBV4L14q+R89oM5fZAFbUIV81uQXlCKfUM6Ry1MjnhyjZeylweQrKl/5/9LcJiT uj5ULxXpTHq9PyNdSrDpRGkOGnOK89m4ndcxGdVuK77qV5+0xlY= =ILW6 -----END PGP SIGNATURE-----