{"thread":{"id":"34921","subject":"[PATCH/RFC] Developer's Certificate of Origin: default to COPYING","startedAt":"2013-09-12T22:11:02Z","lastAt":"2013-09-13T01:18:29Z","messageCount":7,"participants":["Richard Hansen","Junio C Hamano","Linus Torvalds","Theodore Ts'o","W. Trevor King"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"227586","messageId":"1379023862-29953-1-git-send-email-rhansen@bbn.com","threadId":"34921","inReplyTo":null,"subject":"[PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Richard Hansen","fromEmail":"rhansen@bbn.com","sentAt":"2013-09-12T22:11:02Z","receivedAt":"2013-09-12T22:11:02Z","isPatch":true,"sender":{"key":"rhansen@rhansen.org","avatar":null},"body":"The \"Developer's Certificate of Origin\" refers to \"the open source\nlicense indicated in the file\", but there is no such indication in\nmost files in the Git repository.\n\nUpdate the text to indicate that the license in COPYING should be\nassumed if a file doesn't excplicitly indicate which license applies\nto the file.\n\nThe phrase \"accompanies the file\" was chosen to support different\ndefault licenses in different subdirectories (e.g., 2-clause BSD for\nvcs-svn/*, LGPL2.1+ for xdiff/*).\n\nSigned-off-by: Richard Hansen <rhansen@bbn.com>\n---\nI'm bringing this up because, to this layman's eyes, it seems like a\npotentially troublesome oversight.  IIUC, one of the purposes of the\nDeveloper's Certificate of Origin is to make it easy for developers to\ndeclare which license covers a contribution.  Requiring a license\ndeclaration protects the project and its users from copyright\nlitigation.\n\nWhat happens if the file(s) being modified do not indicate which\nlicense applies to the file?  Is there no license?  Does it default to\nthe main project license in COPYING?  This lack of clarity makes me a\nbit nervous (law is already too nondeterministic for my liking), so\nI'd like to see a change that makes it explicit.\n\nNotes:\n  * I am not a lawyer.  (Maybe a lawyer should be consulted?)\n  * This change might not be necessary.\n  * This change might be wrong.\n  * I hope I'm not just wasting everyone's time by bringing this up.\n\n Documentation/SubmittingPatches | 9 ++++++---\n 1 file changed, 6 insertions(+), 3 deletions(-)\n\ndiff --git a/Documentation/SubmittingPatches b/Documentation/SubmittingPatches\nindex 7055576..c5ff744 100644\n--- a/Documentation/SubmittingPatches\n+++ b/Documentation/SubmittingPatches\n@@ -227,13 +227,15 @@ the patch, which certifies that you wrote it or otherwise have\n the right to pass it on as a open-source patch.  The rules are\n pretty simple: if you can certify the below:\n \n-        Developer's Certificate of Origin 1.1\n+        Developer's Certificate of Origin 1.2\n \n         By making a contribution to this project, I certify that:\n \n         (a) The contribution was created in whole or in part by me and I\n             have the right to submit it under the open source license\n-            indicated in the file; or\n+            indicated in the file (or, if no license is indicated in\n+            the file, the license in COPYING that accompanies the\n+            file); or\n \n         (b) The contribution is based upon previous work that, to the best\n             of my knowledge, is covered under an appropriate open source\n@@ -241,7 +243,8 @@ pretty simple: if you can certify the below:\n             work with modifications, whether created in whole or in part\n             by me, under the same open source license (unless I am\n             permitted to submit under a different license), as indicated\n-            in the file; or\n+            in the file (or, if no license is indicated in the file,\n+            the license in COPYING that accompanies the file); or\n \n         (c) The contribution was provided directly to me by some other\n             person who certified (a), (b) or (c) and I have not modified\n-- \n1.8.4\n"},{"id":"227589","messageId":"xmqqy571n05d.fsf@gitster.dls.corp.google.com","threadId":"34921","inReplyTo":"1379023862-29953-1-git-send-email-rhansen@bbn.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-09-12T22:30:22Z","receivedAt":"2013-09-12T22:30:22Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Linus, this is not limited to us, so I am bothering you; sorry about\nthat.\n\nMy instinct tells me that some competent lawyers at linux-foundation\nhelped you with the wording of DCO, and we amateurs shouldn't be\nmucking with the text like this patch does at all, but just in case\nyou might find it interesting...\n\n\nRichard Hansen <rhansen@bbn.com> writes:\n\n> The \"Developer's Certificate of Origin\" refers to \"the open source\n> license indicated in the file\", but there is no such indication in\n> most files in the Git repository.\n>\n> Update the text to indicate that the license in COPYING should be\n> assumed if a file doesn't excplicitly indicate which license applies\n> to the file.\n>\n> The phrase \"accompanies the file\" was chosen to support different\n> default licenses in different subdirectories (e.g., 2-clause BSD for\n> vcs-svn/*, LGPL2.1+ for xdiff/*).\n>\n> Signed-off-by: Richard Hansen <rhansen@bbn.com>\n> ---\n> I'm bringing this up because, to this layman's eyes, it seems like a\n> potentially troublesome oversight.  IIUC, one of the purposes of the\n> Developer's Certificate of Origin is to make it easy for developers to\n> declare which license covers a contribution.  Requiring a license\n> declaration protects the project and its users from copyright\n> litigation.\n>\n> What happens if the file(s) being modified do not indicate which\n> license applies to the file?  Is there no license?  Does it default to\n> the main project license in COPYING?  This lack of clarity makes me a\n> bit nervous (law is already too nondeterministic for my liking), so\n> I'd like to see a change that makes it explicit.\n>\n> Notes:\n>   * I am not a lawyer.  (Maybe a lawyer should be consulted?)\n>   * This change might not be necessary.\n>   * This change might be wrong.\n>   * I hope I'm not just wasting everyone's time by bringing this up.\n>\n>  Documentation/SubmittingPatches | 9 ++++++---\n>  1 file changed, 6 insertions(+), 3 deletions(-)\n>\n> diff --git a/Documentation/SubmittingPatches b/Documentation/SubmittingPatches\n> index 7055576..c5ff744 100644\n> --- a/Documentation/SubmittingPatches\n> +++ b/Documentation/SubmittingPatches\n> @@ -227,13 +227,15 @@ the patch, which certifies that you wrote it or otherwise have\n>  the right to pass it on as a open-source patch.  The rules are\n>  pretty simple: if you can certify the below:\n>  \n> -        Developer's Certificate of Origin 1.1\n> +        Developer's Certificate of Origin 1.2\n>  \n>          By making a contribution to this project, I certify that:\n>  \n>          (a) The contribution was created in whole or in part by me and I\n>              have the right to submit it under the open source license\n> -            indicated in the file; or\n> +            indicated in the file (or, if no license is indicated in\n> +            the file, the license in COPYING that accompanies the\n> +            file); or\n>  \n>          (b) The contribution is based upon previous work that, to the best\n>              of my knowledge, is covered under an appropriate open source\n> @@ -241,7 +243,8 @@ pretty simple: if you can certify the below:\n>              work with modifications, whether created in whole or in part\n>              by me, under the same open source license (unless I am\n>              permitted to submit under a different license), as indicated\n> -            in the file; or\n> +            in the file (or, if no license is indicated in the file,\n> +            the license in COPYING that accompanies the file); or\n>  \n>          (c) The contribution was provided directly to me by some other\n>              person who certified (a), (b) or (c) and I have not modified\n"},{"id":"227590","messageId":"CA+55aFyQZ8EiOg+CZy-KMaX0Hnkdmvq1+8b9p6uuMuHAUzYaAg@mail.gmail.com","threadId":"34921","inReplyTo":"xmqqy571n05d.fsf@gitster.dls.corp.google.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2013-09-12T22:44:04Z","receivedAt":"2013-09-12T22:44:04Z","isPatch":true,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"On Thu, Sep 12, 2013 at 3:30 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> Linus, this is not limited to us, so I am bothering you; sorry about\n> that.\n>\n> My instinct tells me that some competent lawyers at linux-foundation\n> helped you with the wording of DCO, and we amateurs shouldn't be\n> mucking with the text like this patch does at all, but just in case\n> you might find it interesting...\n\nThere were lawyers involved, yes.\n\nI'm not sure there is any actual confusion, because the fact is,\nlawyers aren't robots or programmers, and they have the human\nqualities of understanding implications. So I'm actually inclined to\nnot change legal text unless a lawyer actually tells me that it's\nneeded.\n\nPlus even if this change was needed, why would anybody point to\n\"COPYING\". It's much better to just say \"the copyright license of the\nfile\", knowing that different projects have different rules about this\nall, and some projects mix files from different sources, where parts\nof the tree may be under different licenses that may be explained\nelsewhere..\n\n            Linus\n"},{"id":"227591","messageId":"52324B1A.2030001@bbn.com","threadId":"34921","inReplyTo":"CA+55aFyQZ8EiOg+CZy-KMaX0Hnkdmvq1+8b9p6uuMuHAUzYaAg@mail.gmail.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Richard Hansen","fromEmail":"rhansen@bbn.com","sentAt":"2013-09-12T23:15:38Z","receivedAt":"2013-09-12T23:15:38Z","isPatch":true,"sender":{"key":"rhansen@rhansen.org","avatar":null},"body":"On 2013-09-12 18:44, Linus Torvalds wrote:\n> On Thu, Sep 12, 2013 at 3:30 PM, Junio C Hamano <gitster@pobox.com> wrote:\n>> Linus, this is not limited to us, so I am bothering you; sorry about\n>> that.\n>>\n>> My instinct tells me that some competent lawyers at linux-foundation\n>> helped you with the wording of DCO, and we amateurs shouldn't be\n>> mucking with the text like this patch does at all, but just in case\n>> you might find it interesting...\n> \n> There were lawyers involved, yes.\n> \n> I'm not sure there is any actual confusion, because the fact is,\n> lawyers aren't robots or programmers, and they have the human\n> qualities of understanding implications.\n\nWell stated.  :)\n\n> So I'm actually inclined to\n> not change legal text unless a lawyer actually tells me that it's\n> needed.\n\nIs it worthwhile to poke a lawyer about this as a precaution?  (If so,\nwho?)  Or do we wait for a motivating event?\n\n> \n> Plus even if this change was needed, why would anybody point to\n> \"COPYING\". It's much better to just say \"the copyright license of the\n> file\", knowing that different projects have different rules about this\n> all, and some projects mix files from different sources, where parts\n> of the tree may be under different licenses that may be explained\n> elsewhere..\n\nI agree that your phrasing is better.\n\n-Richard\n"},{"id":"227593","messageId":"20130912232454.GA5279@thunk.org","threadId":"34921","inReplyTo":"52324B1A.2030001@bbn.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Theodore Ts'o","fromEmail":"tytso@mit.edu","sentAt":"2013-09-12T23:24:54Z","receivedAt":"2013-09-12T23:24:54Z","isPatch":true,"sender":{"key":"tytso@mit.edu","avatar":"https://avatars.githubusercontent.com/u/51416?v=4"},"body":"I certainly wouldn't recommend messing with the text of the DCO\nwithout first consulting some lawyers.  There should also be some\ncentralized coordination about any changes in the text and the version\nnumber.\n\n\t\t\t\t\t\t- Ted\n"},{"id":"227594","messageId":"CA+55aFzNUr8-LQ1JqCBboFktmJRB1ctxP3=huOt5H=GQRLFbow@mail.gmail.com","threadId":"34921","inReplyTo":"52324B1A.2030001@bbn.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2013-09-12T23:25:03Z","receivedAt":"2013-09-12T23:25:03Z","isPatch":true,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"On Thu, Sep 12, 2013 at 4:15 PM, Richard Hansen <rhansen@bbn.com> wrote:\n>\n> Is it worthwhile to poke a lawyer about this as a precaution?  (If so,\n> who?)  Or do we wait for a motivating event?\n\nI can poke the lawyer that was originally involved. If people know\nother lawyers, feel free to poke them too. Just ask them to be\nrealistic, not go into some kind of super-anal lawyer mode where they\ngo off on some \"what if\" thing.\n\nNote that one issue is that this is kind of like a license change,\neven if it's arguably just a clarification. I'd expect that a lawyer\nwho is so anal that they think this wording needs change would also\nthink that the DCO version number needs change and then spend half an\nhour (and $500) talking about how this only affects new sign-offs and\nhow you'd want to make it very obvious how things have changed, Yadda\nyadda.\n\nIOW, my personal opinion is that if you get a lawyer that is _that_\ninterested in irrelevant details, you have much bigger problems than\nthis particular wording. Lawyers do tend to be particular about\nwording, but in the end, they tend to also agree that intent matters.\nAt least the good ones who have a case. Once they start talking about\nthe \"meaning of the word 'is'\", you know they are just weaselwording\nand don't actually have any real argument.\n\n              Linus\n"},{"id":"227602","messageId":"20130913011829.GH31410@odin.tremily.us","threadId":"34921","inReplyTo":"CA+55aFzNUr8-LQ1JqCBboFktmJRB1ctxP3=huOt5H=GQRLFbow@mail.gmail.com","subject":"Re: [PATCH/RFC] Developer's Certificate of Origin: default to COPYING","fromName":"W. Trevor King","fromEmail":"wking@tremily.us","sentAt":"2013-09-13T01:18:29Z","receivedAt":"2013-09-13T01:18:29Z","isPatch":true,"sender":{"key":"wking@tremily.us","avatar":"https://avatars.githubusercontent.com/u/209920?v=4"},"body":"On Thu, Sep 12, 2013 at 04:25:03PM -0700, Linus Torvalds wrote:\n> On Thu, Sep 12, 2013 at 4:15 PM, Richard Hansen <rhansen@bbn.com> wrote:\n> >\n> > Is it worthwhile to poke a lawyer about this as a precaution?  (If so,\n> > who?)  Or do we wait for a motivating event?\n> \n> I can poke the lawyer that was originally involved.\n\nFor what it's worth, there is an existing push to clarify the\nlicensing terms for the DCO [1].  Involved parties include Luis\nRodriguez, Richard Fontana, Bradley Kuhn, Mike Dolan, and Karen\nCopenhaver.  Hopefully they'll have something to say after the New\nOrleans LinuxCon.  The DCO licensing is not quite the same as changing\nthe DCO text, but they're probably closely related ;).\n\nCheers,\nTrevor\n\n[1]: http://thread.gmane.org/gmane.linux.kernel/1397613/focus=1400065\n\n-- \nThis email may be signed or encrypted with GnuPG (http://www.gnupg.org).\nFor more information, see http://en.wikipedia.org/wiki/Pretty_Good_Privacy\n"}]}