Innuos Samba GPLv3 Section 6 Compliance and RMA Traps

Melvin Hyde via samba <[email protected]> Mon, 03 Aug 2026 09:01:43 +0000
Newsgroups gmane.network.samba.general
Message-ID <QmljyvueeQM_CElxqtR7ajclg6s5ryp1ObM4u3uONZJ6lS_ChfipotBRXh8-XXFafXQCo2AhG1KTLqvLGurlBOO3UQEe1d6Md1c__U2IXQw=@proton.me>
Hi Samba Team,

I wanted to raise a specific compliance strategy used by commercial hardware vendor Innuos (manufacturers of Linux-based audiophile servers) regarding their distribution of Samba under GPLv3.

While they technically host source code for GPL components on an unlinked open-source portal at opensource.innuos.com, their implementation of GPLv3 Section 6 regarding Conveying Non-Source Forms and Installation Information sets a concerning precedent for embedded Linux appliances using Samba.

I wanted to share how this is being executed and get the community's perspective on whether this practice undermines the spirit of GPLv3 in embedded devices.

1. Obfuscation of Open-Source Disclosures
Innuos does not include written GPL notices, disclosures, or source offers in customer manuals, marketing materials, or main website navigation. They host a bare-metal restoration image containing GPL components (including Samba) at an orphaned subdomain at opensource.innuos.com. Standard customers are kept entirely unaware of the open-source components powering the device.

2. The GPLv3 "RMA Trap": Financial and Technical Friction
Innuos distributes embedded hardware containing Samba under GPLv3. To fulfill their Section 6 obligation to allow users to modify and reinstall GPL software on the User Product, they provide a bare-metal Clonezilla restore image named SenseOS-OSS.zip stripped of all their proprietary applications.

However, their open-source portal explicitly attaches the following condition:
"After restoring this image, it will not be possible to reinstall the original SenseOS without sending the device to an Innuos Service Center, which is subject to a fee."

How the compliance trap operates:

First, the legal shield: They offer an OS image containing Samba that users can modify and write to the drive, theoretically fulfilling Section 6.

Second, the economic penalty: If a user exercises their right to audit or modify GPLv3 software like Samba on hardware they purchased, Innuos wipes the proprietary software environment. Restoring full device functionality requires paying an undisclosed service fee and physically shipping the unit to a service center.

Third, omission as intimidation: Innuos provides zero technical guidance advising users to take a simple Clonezilla drive backup prior to writing the OSS image. A single line of text explaining how to back up the factory disk would allow any user to safely inspect modified GPL software and restore the original OS themselves. Instead, they leverage technical fear to scare users away from ever touching the code.

3. Legal and Structural Questions for the Samba Community
While vendors are not strictly required by the GPL to provide free re-installation of separate, non-GPL proprietary software once a drive is wiped, using proprietary re-installation fees as a direct barrier against running modified GPL binaries feels like a deliberate loophole.

Does holding device functionality hostage behind a mandatory physical repair fee violate the spirit of GPLv3 Section 6 regarding usable Installation Information?

Has the Samba team or Software Freedom Conservancy encountered similar commercial strategies where weaponized RMA friction is used to deter end-users from exercising their copyleft rights?

I would love to hear thoughts from maintainers and developers on how the community views these types of distribution traps.

Best regards,
Melvin
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba