Legal Issues

Revision as of 12:41, 1 December 2015 by Tim Bird (talk | contribs) (add info about GPL v3)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Legal Issues using Linux in embedded projects

The intricacies of using the GPL license have been hashed out repeatedly in many other forums.

Here are some highlights of a few specific issues that come up occasionaly:

Kernel is licensed GPL v2 only

The Linux kernel is licensed under the GNU General Public License, version 2.0 ONLY!

This is different from many other projects, which use the default wording in the license to allow GPL v2 or any later version.

This means it is unlikely that the kernel will switch to GPL version 3.0.

In September of 2006, a group of Linux kernel developers signed a position statement indicating that they objected to GPL version 3.0 (as then drafted). This further indicates the unlikelyhood of any change of the kernel to the GPL v3 license.

GPL/LGPL license version (v3) issues

GPLv3 and LGPLv3 raise interesting new issues for embedded products. One aspect of GPLv3 is the "anti-TIVOization" clause, which prohibits hardware manufacturers from digitally signing software (thus preventing substitution of modified software in the field). See Tivoization for more information.

The new versions of the GPL and LGPL raise issues with license compatibility with previous versions. See the following page for a matrix showing what code under which licenses and be released, under what circumstances:

Finally, here is a statement from a developer of a library, indicating some problems using LGPLv3:

Many embedded companies avoid using GPLv3 and LGPLv3 software in their products, due to the additional restrictions in those licenses, compared to GPLv2 and LGPLv2.

Signed-off-by lines and the DCO

When developers contribute to the kernel, they must provide a "Signed-off-by" line, indicating that they acknowledge the licensing and declare the work (to the best of their knowledge) to be either original, or derivative of something compatible with GPL v2.

See the Developer Certificate Of Origin which is contained in the kernel's Documentation/SubmittingPatches file.

Resources for legal analysis and compliance



In January of 2008, Greg Kroah Hartman submitted a patch to change the core USB API to EXPORT_SYMBOL_GPL. Here is some information about that change:

Binary proprietary kernel modules

One outstanding legal question with Linux, that is of particular importance in embedded, is whether or not binary (non-GPL) kernel modules violate the GPL license of the Linux kernel.

Opinions on this topic differ.

Here is an article with some interesting information:

Use of kernel header files in user-space

It is allowed to use kernel header files in user space, in order for user-space programs to interact with the kernel via ordinary system calls. This is allowed without the result that the user-space program becomes a derivative work of the kernel and therefore subject to GPL.

In general, use of header files do not create derivative works, although there can be exceptions. There used to be a lot of attention paid to the amount of code (e.g. number of lines) included from a header file, but no one seems to care about that these days, and this is almost never a problem. Richard Stallman has stated that use of header files for data structures, constant definitions, and enumerations (and even small inlines) does not create a derivative work. See:

The user-space use of the kernel header files is expected and ordinary. This explicitly encompasses non-GPL software using these files, and not being affected by the GPL. In order to calm fears about using the header files directly, and to prevent leakage of kernel internal information to user-space (where it might be abused), the mainline kernel developers added an option to the kernel build system to specifically create "sanitized" headers that are deemed safe for use by user-space programs, without incurring licensing issues.

These are the "make headers_check" and "make headers_install" targets in the kernel build system.

In general, it is legally safest to use such sanitized headers (that is, headers that have specifically been stripped of large inline macros or anything not required for user space.)

This article explains how to create sanitized kernel headers using the kernel build system.

Note that a different process was used by the developers of the Android operating system, to sanitize headers for bionic for their system. Their process was developed around the same time as the mainline header sanitization feature.

Other Links