Re: adding and forking someone else's GPL software - what should i do?

Daniel Pittman <[email protected]> Mon, 21 Nov 2011 20:03:16 -0800
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <CABNGp=S7OXEd9cOZk+YZz2WpxAH2e+bDGvgsOf+3UVrRWvzK0g@mail.gmail.com>
On Mon, Nov 21, 2011 at 02:18, Volker Kuhlmann <[email protected]> wrote:
> On Mon 21 Nov 2011 11:42:03 NZDT +1300, Daniel Pittman wrote:
>
>> > It's actually not an unreasonable concern raised by Debain.
>
> Yes it is, in this case.
>
>> ...and, also, incompatible with the GPL.
>
> And that matters one bit why? The TeX engine and computer modern fonts
> are (C) American Mathematical Society (they paid for it) and they use
> whatever license I don't remember and am not looking up now.

So, my comments were mostly in the context of the original post, which
was about a specific GPL licensed software package.  In the specific
case of the LaTeX license and all.

> So changing name when making modifications is a really brilliant idea. I
> don't recall anyone having a problem with that, except for a bunch of
> jokers

...a bunch of people who have a different set of priorities and values
to you; part of the Debian social contract is about very specific
forms of freedom, and many of these issues crop up because of that.
Using pejorative terms doesn't make a convincing argument; it would be
better to recognise their position as sane, and argue against it.

Also, the specific requirement was that the *filename* was changed
when a file was modified, not just the name of the package; this is,
oh, how the file is loaded.  That made it impossible to, eg, patch a
file along the way.

>> Most of the Debian concerns, though, are that they want to patch the
>> software: their policy on security is that they will not ship a newer
>> version for a security issue, but rather will make the minimal patch
>> to their release version.
>
> who are allowed to have whatever policy they want, but then start
> screaming it's someone else's problem if they choose to be in their own
> way.

So, if I understand you correctly, Debian et al should STFU, because
expressing disagreement about license conditions is unwelcome?

It is, I suppose, a position to take; personally, I would take the
view that allowing people to freely express their views about the
license is reasonable.  Which includes discussing the issue with the
people proposing the license change and, as happened, negotiating a
satisfactory license that met the goals on both sides of the fence.

>> In the LaTeX case, of course, that means they are obligated to change
>> the name of the package in the security release, breaking the entire
>> world.  Boom.
>
> We're talking about macro packages for typesetting here. The security
> risk is about the same as that of some C source code turning someone's
> gcc into a security problem. I don't recall someone's LaTeX document
> being turned into a program and becoming a security issue... And neither
> TeX nor gcc are really designed as or meant to be used as a secure
> service.

You already established that you have no interest in allowing
different opinions to your own.  I suppose it should come as no
surprise that you dismiss out of hand, eg, local security
vulnerabilities because they happen to be less interesting in your own
conception of risk.

Daniel
-- 
♲ Made with 100 percent post-consumer electrons

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug