Earlier quoted context omitted.
Of course you can. https://01.org/linuxgraphics/gfx-docs/drm/admin-guide/tainte... Edit: --- Good point about the distinction between adding modules modifying existing source. It is an interesting question, actually and I haven't been able to find an authoritative answer on the subject. A patch is a description of changes that would be made to a work, if they were made. Does it trigger the licence before it is applie…
Ah I see. So as long as they don't distribute the patch together with the GPL base codebase, they are good. Does that sound right?
Passing the Baton
11–20 of 82 posts
Re: Passing the Baton
#12I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.
Maybe they're just thinking "our customers value our work, so let's focus on providing value to them instead of to people who don't value our work". Whether or not that's true, I don't blame them.
Re: Passing the Baton
#13Earlier quoted context omitted.
I thought the same thing. The Linux kernel has been "freely available" for a measly 26 years, and will continue to be so.
Why are the grsecurity patches not included in the Vanilla Kernel? https://unix.stackexchange.com/questions/59020/why-are-the-g...
To clarify some technical aspects, SELinux and grsecurity are not answers to the same problems, and they never meant to be. SELinux was always meant to implement things like multi-level security, bell-lapadula model, and extending 3rd party application with SeLinux roles, and the security daemon. Grsecurity has file oriented rbac system that was more approachable, and a variety of other patches (which are what grsecurity has been more known for - they have been always very excellent).
Knowing Spender, he was probably actually paid to stop. That's my guess. Not going to iterate on that.
Re: Passing the Baton
#14I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.
They have, in fact, been generous in providing patches for free. Other people have been generous too. Generosity doesn't cancel itself out. It must be particularly irritating in Spengler's case, because he works in a field where most of the best people make millions turning poorer versions of the same ideas into commercial products that only huge companies ever get to play with, while he spends his career arguing wit…
> The apparent inability (and perhaps more importantly - total unwilling[n]ess) from the PaX team to be able to see what makes sense in a long-term general kernel and what does not, and split things up and try to push the sensible things up (and know which things are too ugly or too specialized to make sense), caused many PaX features to never be merged.
In a comment [0] the PAX team says
> we never ever considered submitting grsecurity or PaX for mainline inclusion [...] anything similar in the past was user action, not on our behalf
I don't know how Spengler and PAX relate.
Re: Passing the Baton
#15I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.
I think they're just tired of doing work and the kernel community going shrug (or worse, dismissing it). Of course, the kernel developers are also doing work for free, but at least their work is actually being accepted into the kernel. Maybe they're just thinking "our customers value our work, so let's focus on providing value to them instead of to people who don't value our work". Whether or not that's true, I don't…
https://unix.stackexchange.com/questions/59020/why-are-the-g...
Re: Passing the Baton
#16Earlier quoted context omitted.
They have, in fact, been generous in providing patches for free. Other people have been generous too. Generosity doesn't cancel itself out. It must be particularly irritating in Spengler's case, because he works in a field where most of the best people make millions turning poorer versions of the same ideas into commercial products that only huge companies ever get to play with, while he spends his career arguing wit…
Torvalds claims [0] that he did not do enough arguing with upstream: > The apparent inability (and perhaps more importantly - total unwilling[n]ess) from the PaX team to be able to see what makes sense in a long-term general kernel and what does not, and split things up and try to push the sensible things up (and know which things are too ugly or too specialized to make sense), caused many PaX features to never be me…
Re: Passing the Baton
#17How does this work at a licensing level? GRSecurity are patches to the Linux kernel right? Can you distribute patches for a GPL licensed software without the patches themselves being GPL?
Of course you can. https://01.org/linuxgraphics/gfx-docs/drm/admin-guide/tainte... Edit: --- Good point about the distinction between adding modules modifying existing source. It is an interesting question, actually and I haven't been able to find an authoritative answer on the subject. A patch is a description of changes that would be made to a work, if they were made. Does it trigger the licence before it is applie…
Re: Passing the Baton
#18Earlier quoted context omitted.
They have, in fact, been generous in providing patches for free. Other people have been generous too. Generosity doesn't cancel itself out. It must be particularly irritating in Spengler's case, because he works in a field where most of the best people make millions turning poorer versions of the same ideas into commercial products that only huge companies ever get to play with, while he spends his career arguing wit…
Torvalds claims [0] that he did not do enough arguing with upstream: > The apparent inability (and perhaps more importantly - total unwilling[n]ess) from the PaX team to be able to see what makes sense in a long-term general kernel and what does not, and split things up and try to push the sensible things up (and know which things are too ugly or too specialized to make sense), caused many PaX features to never be me…
Torvalds does great work. Spengler does great work. The kernel team does great work. The PaX team does great work. Torvalds is not always the easiest person to get along with. Spengler is not always the easiest person to get along with. Life is sometimes complicated. None of this takes away from anyone's achievements.
Re: Passing the Baton
#19I love how grsecurity is always quick to point out how generous they have been by providing the patches for free. > We have been providing grsecurity freely for 16 years. Meanwhile the kernel upon which their work is built has been provided for free for much longer, and continues to be.
I think they're just tired of doing work and the kernel community going shrug (or worse, dismissing it). Of course, the kernel developers are also doing work for free, but at least their work is actually being accepted into the kernel. Maybe they're just thinking "our customers value our work, so let's focus on providing value to them instead of to people who don't value our work". Whether or not that's true, I don't…
Re: Passing the Baton
#20How does this work at a licensing level? GRSecurity are patches to the Linux kernel right? Can you distribute patches for a GPL licensed software without the patches themselves being GPL?
Of course you can. https://01.org/linuxgraphics/gfx-docs/drm/admin-guide/tainte... Edit: --- Good point about the distinction between adding modules modifying existing source. It is an interesting question, actually and I haven't been able to find an authoritative answer on the subject. A patch is a description of changes that would be made to a work, if they were made. Does it trigger the licence before it is applie…
The 'P' taint flag exists because upstream kernel maintainers aren't interested in dealing with bug reports where the bug may have been caused by proprietary code loaded by end users, which often can't be examined or copied even for the purpose of discussing the bug. Total waste of time, so the flag makes those cases obvious to anyone reading the bug report. The user can be told upfront to remove the proprietary code and try to reproduce the bug again.
End users can combine proprietary code with GPL code if they want to, because end users aren't bound by the GPL unless and until they distribute something covered by it. You don't even have to accept the terms of the GPL just to run the program[1].
A company distributing a proprietary module for the kernel may or may not be violating the GPL, depending on what it does and who you ask.
In contrast to the module stuff, GRSecurity is a set of patches to very low level parts of the Linux kernel itself. It could never be licensed in a way that prevented the patch set or the resulting patched kernel source/binaries from being covered and distributed under the GPLv2. If that were the case, the kernel would effectively not be covered by the GPL at all.