[xwiki-devs] XWiki Enterprise 4.1.x GPL vs. LGPL question
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro). If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license? Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
Hi Mark, I've just checked and I don't see this jar in our distribution. Could you point me to where you've seen it? Thanks -Vincent On Jul 27, 2012, at 11:07 PM, Mark Wallace wrote:
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro).
If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license?
Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
When you unzip, e.g., xwiki-enterprise-jetty-hsqldb-4.1.2.zip, it is in the webapps\xwiki\WEB-INF\lib folder ________________________________________ From: devs-bounces@xwiki.org [devs-bounces@xwiki.org] on behalf of Vincent Massol [vincent@massol.net] Sent: Friday, July 27, 2012 5:13 PM To: XWiki Developers Subject: Re: [xwiki-devs] XWiki Enterprise 4.1.x GPL vs. LGPL question Hi Mark, I've just checked and I don't see this jar in our distribution. Could you point me to where you've seen it? Thanks -Vincent On Jul 27, 2012, at 11:07 PM, Mark Wallace wrote:
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro).
If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license?
Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
_______________________________________________ devs mailing list devs@xwiki.org http://lists.xwiki.org/mailman/listinfo/devs
On Jul 28, 2012, at 4:53 AM, Mark Wallace wrote:
When you unzip, e.g., xwiki-enterprise-jetty-hsqldb-4.1.2.zip, it is in the webapps\xwiki\WEB-INF\lib folder
ok I'll try. I have 4.1.3 and it's not there for me. Thanks -Vincent
_______________________________________ From: devs-bounces@xwiki.org [devs-bounces@xwiki.org] on behalf of Vincent Massol [vincent@massol.net] Sent: Friday, July 27, 2012 5:13 PM To: XWiki Developers Subject: Re: [xwiki-devs] XWiki Enterprise 4.1.x GPL vs. LGPL question
Hi Mark,
I've just checked and I don't see this jar in our distribution.
Could you point me to where you've seen it?
Thanks -Vincent
On Jul 27, 2012, at 11:07 PM, Mark Wallace wrote:
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro).
If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license?
Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
On 07/27/2012 10:59 PM, Vincent Massol wrote:
On Jul 28, 2012, at 4:53 AM, Mark Wallace wrote:
When you unzip, e.g., xwiki-enterprise-jetty-hsqldb-4.1.2.zip, it is in the webapps\xwiki\WEB-INF\lib folder
ok I'll try. I have 4.1.3 and it's not there for me.
It is in a 4.2-SNAPSHOT that I have locally. I agree that this is wrong and this jar should be removed. I traced to see where it comes from, and it's a dependency used by Infinispan, which means that Infinispan is in the wrong here. I created https://issues.jboss.org/browse/ISPN-2179 and I hope that it will be addressed soon.
Thanks -Vincent
_______________________________________ From: devs-bounces@xwiki.org [devs-bounces@xwiki.org] on behalf of Vincent Massol [vincent@massol.net] Sent: Friday, July 27, 2012 5:13 PM To: XWiki Developers Subject: Re: [xwiki-devs] XWiki Enterprise 4.1.x GPL vs. LGPL question
Hi Mark,
I've just checked and I don't see this jar in our distribution.
Could you point me to where you've seen it?
Thanks -Vincent
On Jul 27, 2012, at 11:07 PM, Mark Wallace wrote:
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro).
If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license?
Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
-- Sergiu Dumitriu http://purl.org/net/sergiu/
My understanding is this does not affect the licensing of XWiki any more than the GPL packages in Debian affect the LGPL packages because they are on the same installer disk. The LGPL originated from the C compiling and linking mechanism where a header file was prepended to the .c file in the compiling cycle, making what was arguably a derived work. While the GPL is fuzzy about it, the LGPL explicitly says this is ok. I am not aware of any claims arising from using GPL licensed .jar files being included in a .zip distribution. The LGPL license file only applies to the XWiki codebase itself, we use libraries which are licensed under a range of different licenses including Apache and BSD like licenses. That said, we do not use GPL'd libraries so this is something which will have to be fixed, thanks for letting us know. Caleb On 07/30/2012 04:53 PM, Sergiu Dumitriu wrote:
On 07/27/2012 10:59 PM, Vincent Massol wrote:
On Jul 28, 2012, at 4:53 AM, Mark Wallace wrote:
When you unzip, e.g., xwiki-enterprise-jetty-hsqldb-4.1.2.zip, it is in the webapps\xwiki\WEB-INF\lib folder
ok I'll try. I have 4.1.3 and it's not there for me.
It is in a 4.2-SNAPSHOT that I have locally.
I agree that this is wrong and this jar should be removed.
I traced to see where it comes from, and it's a dependency used by Infinispan, which means that Infinispan is in the wrong here. I created https://issues.jboss.org/browse/ISPN-2179 and I hope that it will be addressed soon.
Thanks -Vincent
_______________________________________ From: devs-bounces@xwiki.org [devs-bounces@xwiki.org] on behalf of Vincent Massol [vincent@massol.net] Sent: Friday, July 27, 2012 5:13 PM To: XWiki Developers Subject: Re: [xwiki-devs] XWiki Enterprise 4.1.x GPL vs. LGPL question
Hi Mark,
I've just checked and I don't see this jar in our distribution.
Could you point me to where you've seen it?
Thanks -Vincent
On Jul 27, 2012, at 11:07 PM, Mark Wallace wrote:
I noticed that the rhq-pluginAnnotations-3.0.4.jar JAR is used in xwiki-enterprise-jetty-hsqldb-4.1.2. The source code for rhq-pluginAnnotations-3.0.4 [1] uses the GNU General Public License. However, the overall licence for xwiki-enterprise-jetty-hsqldb-4.1.2 is GNU LESSER GENERAL PUBLIC LICENSE (see xwiki-enterprise-jetty-hsqldb-4.1.2\META-INF\LICENSE file that comes with the distro).
If the overall distro uses a GPL library, don't the copy left provisions of the GPL require shouldn't that require the whole distro fall under the GPL license?
Refs. [1] http://grepcode.com/file/repository.jboss.org/nexus/content/repositories/rel...
Apparently this jar is not needed at run time https://issues.jboss.org/browse/AS7-2343 But it's still pulled if you end up with it. You can wait for infinispan to get rid of it or we could exclude it ourselves Since our code is not really linking to it in the end we are ok but we should still make sure it does not end in our distro Ludovic Envoyé de mon iPhone Le 31 juil. 2012 à 01:35, Caleb James DeLisle <calebdelisle@lavabit.com> a écrit :
rhq-pluginAnnotations
Thanks for the research, everybody. Now for another one. XWiki 4.0 and 4.1.2 (and possibly others? I'm downloading 4.1.3 now to check it but has 54 minutes left) have itext-2.1.5.jar in the lib directory. http://itextpdf.com/terms-of-use/index.php says it is copy lefted under an AGPL license, and says, "Buying such a license is mandatory as soon as you develop commercial activities distributing the iText software inside your product or deploying it on a network without disclosing the source code of your own applications under the AGPL license." This sounds about as copy lefted as GPL to me. Is this jar file used/mandatory for xwiki 4.1.x? Thanks, -Mark
On 07/31/2012 09:54 PM, Mark Wallace wrote:
Thanks for the research, everybody.
Now for another one. XWiki 4.0 and 4.1.2 (and possibly others? I'm downloading 4.1.3 now to check it but has 54 minutes left) have itext-2.1.5.jar in the lib directory.
http://itextpdf.com/terms-of-use/index.php says it is copy lefted under an AGPL license, and says, "Buying such a license is mandatory as soon as you develop commercial activities distributing the iText software inside your product or deploying it on a network without disclosing the source code of your own applications under the AGPL license."
This sounds about as copy lefted as GPL to me. Is this jar file used/mandatory for xwiki 4.1.x?
You're wrong, the AGPL is actually more viral/restrictive than GPL. I traced back to JFreeChart, another LGPL library that we're using for generating charts. I don't think that we need iText, since we're not generating PDF versions of the charts, so I guess that if you want to stay clear of the AGPL, you could try to remove it from your lib directory. I raised https://sourceforge.net/tracker/?func=detail&aid=3552914&group_id=15494&atid... hoping to get this problem addressed (still no answer from Infinispan). -- Sergiu Dumitriu http://purl.org/net/sergiu/
On 07/31/2012 10:19 PM, Sergiu Dumitriu wrote:
On 07/31/2012 09:54 PM, Mark Wallace wrote:
Thanks for the research, everybody.
Now for another one. XWiki 4.0 and 4.1.2 (and possibly others? I'm downloading 4.1.3 now to check it but has 54 minutes left) have itext-2.1.5.jar in the lib directory.
http://itextpdf.com/terms-of-use/index.php says it is copy lefted under an AGPL license, and says, "Buying such a license is mandatory as soon as you develop commercial activities distributing the iText software inside your product or deploying it on a network without disclosing the source code of your own applications under the AGPL license."
This sounds about as copy lefted as GPL to me. Is this jar file used/mandatory for xwiki 4.1.x?
You're wrong, the AGPL is actually more viral/restrictive than GPL.
I traced back to JFreeChart, another LGPL library that we're using for generating charts. I don't think that we need iText, since we're not generating PDF versions of the charts, so I guess that if you want to stay clear of the AGPL, you could try to remove it from your lib directory.
I raised https://sourceforge.net/tracker/?func=detail&aid=3552914&group_id=15494&atid... hoping to get this problem addressed (still no answer from Infinispan).
Their response is that the version that they use (2.1.5) was distributed under the LGPL. I checked, and actually it was dual-licensed under the LGPL and the MPL. They also said that it's not a mandatory dependency, since it's only used for the demo application, not for the main functionality of the charting library, so we could remove it completely (even though it's not required for license reasons, it's still good to prune out unneeded classes). See http://jira.xwiki.org/browse/XWIKI-8106 -- Sergiu Dumitriu http://purl.org/net/sergiu/
On 07/30/2012 06:35 PM, Caleb James DeLisle wrote:
My understanding is this does not affect the licensing of XWiki any more than the GPL packages in Debian affect the LGPL packages because they are on the same installer disk. The LGPL originated from the C compiling and linking mechanism where a header file was prepended to the .c file in the compiling cycle, making what was arguably a derived work. While the GPL is fuzzy about it, the LGPL explicitly says this is ok. I am not aware of any claims arising from using GPL licensed .jar files being included in a .zip distribution. The LGPL license file only applies to the XWiki codebase itself, we use libraries which are licensed under a range of different licenses including Apache and BSD like licenses. That said, we do not use GPL'd libraries so this is something which will have to be fixed, thanks for letting us know.
I don't agree here, but when it comes to licenses nobody can be sure; even judges contradict each other. My understanding is that GPL does disperse through jars used in the same application. They're not just individual programs that happen to sit in the same zip, they are used together in the same application, with direct calls from one class to another. "Derivative work" doesn't refer to [intermediary] source code alone (the .h being copied into the .c that uses it), it refers to end programs as a whole, since the *functionality* of a library is present in the end program. The fact that we use non-xGPL libraries doesn't mean that we can use any library because the licenses don't interfere with each other. It means that Apache and BSD licenses can be used within a LGPL project, because they permit relicensing. This means that we're not using the Apache-licensed Lucene library, we're using the LGPL-licensed Lucene library derived from the Apache-licensed Lucene library. This works because: - ASL/BSD/MIT allow relicensing (they are compatible with the xGPL) - LGPL is stronger than ASL/BSD, so by relicensing we're only adding restrictions, not removing any - Since we don't actually make any changes to these libraries, we don't have to provide any source code other than what's already offered by the official code repositories of those libraries, so the fact that we're relicensing doesn't have any real implications This makes me wonder what happens with the libraries that we do modify/repackage, like Pygments and Jython. -- Sergiu Dumitriu http://purl.org/net/sergiu/
On Wed, Aug 1, 2012 at 4:39 AM, Sergiu Dumitriu <sergiu@xwiki.com> wrote:
On 07/30/2012 06:35 PM, Caleb James DeLisle wrote:
My understanding is this does not affect the licensing of XWiki any more than the GPL packages in Debian affect the LGPL packages because they are on the same installer disk. The LGPL originated from the C compiling and linking mechanism where a header file was prepended to the .c file in the compiling cycle, making what was arguably a derived work. While the GPL is fuzzy about it, the LGPL explicitly says this is ok. I am not aware of any claims arising from using GPL licensed .jar files being included in a .zip distribution. The LGPL license file only applies to the XWiki codebase itself, we use libraries which are licensed under a range of different licenses including Apache and BSD like licenses. That said, we do not use GPL'd libraries so this is something which will have to be fixed, thanks for letting us know.
I don't agree here, but when it comes to licenses nobody can be sure; even judges contradict each other.
My understanding is that GPL does disperse through jars used in the same application. They're not just individual programs that happen to sit in the same zip, they are used together in the same application, with direct calls from one class to another.
"Derivative work" doesn't refer to [intermediary] source code alone (the .h being copied into the .c that uses it), it refers to end programs as a whole, since the *functionality* of a library is present in the end program.
The fact that we use non-xGPL libraries doesn't mean that we can use any library because the licenses don't interfere with each other. It means that Apache and BSD licenses can be used within a LGPL project, because they permit relicensing. This means that we're not using the Apache-licensed Lucene library, we're using the LGPL-licensed Lucene library derived from the Apache-licensed Lucene library. This works because:
- ASL/BSD/MIT allow relicensing (they are compatible with the xGPL) - LGPL is stronger than ASL/BSD, so by relicensing we're only adding restrictions, not removing any - Since we don't actually make any changes to these libraries, we don't have to provide any source code other than what's already offered by the official code repositories of those libraries, so the fact that we're relicensing doesn't have any real implications
This makes me wonder what happens with the libraries that we do modify/repackage, like Pygments and Jython.
We don't actually modify/repackage Jython in any way the last version is even in Maven central. For Pygments it's basically just a conversion from egg to jar package to be recognized by Maven and loaded in the classloader so we don't really modify much either.
-- Sergiu Dumitriu http://purl.org/net/sergiu/
_______________________________________________ devs mailing list devs@xwiki.org http://lists.xwiki.org/mailman/listinfo/devs
-- Thomas Mortagne
participants (6)
-
Caleb James DeLisle -
Ludovic Dubost -
Mark Wallace -
Sergiu Dumitriu -
Thomas Mortagne -
Vincent Massol