Re: Software implementing patented techniques

Simon Josefsson <[email protected]> Sun, 15 Feb 2026 16:30:33 +0100
Newsgroups gmane.linux.debian.devel.legal
Message-ID <[email protected]>
Don Armstrong <[email protected]> writes:

> On Sat, 14 Feb 2026, Simon Josefsson wrote:n
>> Is anyone following the policy? https://www.debian.org/legal/patent
>
> Because of the necessity to maintain attorney client privilege, there
> may not be any public evidence of Debian following the policy.
>
>> Is a violation against the policy RC-worthy?
>
> If someone knew (or thought) that we were distributing software that
> violated a specific patent, they should e-mail [email protected] to
> discuss the issue. They shouldn't file a bug, nor should they discuss it
> on this mailing list. They may be wrong or right, but discussing it here
> could expose Debian to additional risk.
>
>> If we would start to look, I believe there are tons of violations in
>> Debian here, to the point where one would quickly question if
>> enforcing this policy is a realistic goal. Patent encumbered FOSS is
>> widely deployed these days.
>
> Determining whether a specific application is likely to infringe on an
> enforceable patent is incredibly tricky, and requires significant domain
> knowledge in both the area of the patent and case law in the domain of
> the patent (and always involves some amount of uncertainty). Multiply
> that complication by the number of patent systems that Debian is
> distributed in and the complexity is even higher.
>
> Without that knowledge (which in my experience usually involves a team
> of experts), it's challenging to weigh the risks of infringing.
>
> If you have knowledge of violations or are concerned about a specific
> patent, follow the policy and notify [email protected], not this
> mailing list.

Who is on that list?  Is it an official Debian project delegation?  What
is the charter of the team?  Do you make any public reports about what
the team is doing?

It smells like a self-appointed team that sets its own rules, and even
further, suggests that not deferring to the team would harm Debian.

I find that way of working against Debian's Social Contract ยง3 "We will
not hide problems" and inconsistent with Debian Policy:

    Packages must be placed in non-free if they are not compliant with
    the DFSG or are encumbered by patents or other legal issues that
    make their distribution problematic.

Thus I would disagree and believe it would be fine to report violations
of debian-policy requirements as public bug reports, and that the spirit
of doing things in public would be helped instead of hiding things on a
private mailing list with (from what I can tell) no clear authority to
actually properly deal with the topic.

Discussing and making deliberations about patent concerns in private is
fine, and I think Debian would be helped by having an official team
working on that, reporting to the rest of the project once in a while.

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmmR5pkUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFokIuAQD+pSo7BTK+
sIJ1mxzFZ5zELdntxPy2d0MEyCHcF75POwEAxQsik9epnNgiT6efO20ot/oAyhPZ
gieNpAvYo3kpiQY=
=wKfZ
-----END PGP SIGNATURE-----