Home Blog Page 10325

Security advisory for Apache

Author: JT Smith

The advisory is at LWN.net: Red Hat has put out an update to the apache package that fixes some
vulnerabilities in the mod_rewrite module, and a problem in the
virtual hosting facilities. They have also released an update to the
php3 package, fixing a potential exploit with a format string problem
in that package.

Category:

  • Linux

Commentary: Don’t rush out to buy a Transmeta-based laptop

Author: JT Smith

From Gartner Viewpoint on CNet: “Crusoe-based computers are a major milestone for Transmeta and a critical step toward long-term
viability for the company. Nonetheless, Crusoe-based devices will likely appeal most to a niche
market: mobile users who want a small, light computing device but believe current personal digital
assistants aren’t powerful enough.” A ZDNet story says critics of Transmeta don’t like that the chip sacrifices speed for battery life.

Category:

  • Unix

Licensing primer, part two: a look at GPL from the BSD side

Author: JT Smith

By Tina Gasperson
News Editor

No Open Source or Free Software license is perfect. The BSD licenses allow closed-source proprietors to swipe code created under it and turn it into non-free software. And while the GPL license (authored by Richard Stallman and the Free Software Foundation) seems to be completely unrestrictive in its freedom, in actuality, some say, it ends up more restrictive. In fact, opponents of the GPL say that it infects code like a virus. The offending part of the GPL license, according to the BSD guys, is section 2b, which states: “You must cause any work that you distribute or publish, that in whole or in part contains or is derived from the Program or any part thereof, to be licensed as a whole at no charge to all third parties under the terms of this License.” (For a GPL perspective, see Part 1.)

The way anti-GPL’ers see it, even the tiniest code snippet can force an entire project to be handed over to the GPL, which could be disastrous for a proprietary software company, and extremely distasteful for a programmer who just wants to maintain control over his own creations.

“If you modify GPL’d code, then Richard Stallman is telling you what you can do with your creativity,” say some Open Source advocates. Say you write one line of code to insert a tweak in your favorite Linux tool. The tool happens to be under the General Public License, therefore, say some, your code snippet must be licensed under the GPL as well.

But Georg C. F. Greve doesn’t see Stallman holding any sway over programmers. Greve frequently represents the GNU project at conferences, and he writes a column called “Georg’s Brave GNU World,” which is published in the German Linux-Magazin,” the French Linux Magazine, the U.K. Linux-Magazine, and others. He’s also a Free Software programmer.

“An author puts his or her code under the GNU General Public License and not under Richard M. Stallman’s control,” says Greve. “What the GPL says is very much open and can be checked by anyone willing to read it. Those are the terms that a program is being distributed under. Of course what the GPL says has been influenced by the work and thoughts of Richard Stallman, but short of travelling back in time to reverse-modify the GPL there is nothing he could do to gain [that] power.”

Here’s what the GPL license says about code snippets: “…when you distribute [outside] sections [of code] as part of a whole which is a work based on the [GPL] Program, the distribution of the whole must be on the terms of this License, whose permissions for other licensees extend to the entire whole, and thus to each and every part regardless of who wrote it.” BSD translation: GPL is hungry, GPL say, “feed me, Seymour.”

Tim Kientzle, former executive editor of Dr. Dobb’s Journal, owns a software consultancy and development company by day, and spends part of his spare time in the evenings working on Open Source projects. He says he is careful to avoid working with GPL’d code on these volunteer projects because there’s always the possibility the commercial code could be infected by the GPL.

“If I copy code from a GPL project into one of my client’s commercial projects, I’ve placed my client into a precarious legal position. On the other hand, if I’m working on a BSD-licensed project
during the evenings, I can reuse that work in commercial projects or other free projects as I see fit,” says Kientzle, who holds a PhD in mathematics from the University of California at Berkeley.

Professor Eben Moglen of the Columbia University Law School, who has given his time for the last seven years as volunteer General Counsel of the Free Software Foundation, the author of the GPL, disagrees. “[Kientzle] may not have fully grasped the legal situation. Any code he writes himself he can both add to existing GPL’d programs and also give to his clients,” for inclusion in their projects, says Moglen.

“The GPL isn’t greedy, just protective of the work of programmers,” he says. “If you devote time and energy to working on a programming project and want to be sure that no subsequent modifier can ever ‘take the program private’ by making whizzbang improvements or necessary repairs and only releasing that work on proprietary terms, you need the GPL.”

To a casual observer, it appears that the two sides are diametrically opposed. But the insiders say that whatever side they take, they all just want freedom of choice. “The GNU movement and the FreeBSD movement have very much common goals, we only differ about how to achieve them,” says Greve.

To that sentiment, Kientzle adds: “I think the majority of software users probably feel the same way I do: If you don’t like the terms, don’t use it. GPL-licensed, BSD-licensed, closed-source are all ultimately just different choices for the consumer, who has the right to make that choice in whatever way suits them. Likewise, software developers have the right to not release their original work or release it under the
terms that suit them.”

Even the founder of the Free Software movement, and author of the GPL license Richard Stallman, says the two groups are not squaring off for battle. “This is not just a ‘side’ issue,” says Stallman. But he is adamant that the differences between the Open Source Movement and the Free Software Movement are real and fundamental.

“The Open Source Movement gets a lot of publicity nowadays, with the
result that people often think they have absorbed or replaced the Free
Software Movement,” he says. “Media articles labeling our work as ‘open source’
often feed this confusion; every week I get mail from someone
addressing me mistakenly as a fellow ‘open source developer.’ There
must be thousands of people who support the Open Source Movement
because they think I do.”

Author’s note: I am available to respond to questions, comments, and criticisms. Please post your thoughts in our discussion forumTG.

Category:

  • Linux

EBIZ Enterprises announces $2.5 investment

Author: JT Smith

EBIZ Enterprises Inc., the country’s largest
vendor-neutral Linux solutions builder, Thursday announced that The Canopy Group Inc., a venture-capital,
management and resource corporation devoted to growing the high-tech industry, purchased an equity stake in the
company of 2.5 million shares of common stock on Oct. 19. The press release is from Business Wire. CNet also has a news report.

Category:

  • Open Source

Zope Weekly News for Oct. 25

Author: JT Smith

It’s posted at LWN.net: “Last week saw some new active projects added to dev.zope.org.
Jeffrey Shell’s “Write Locking” project will add some missing
infrastructure to support DAV-aware Web tools that require DAV
locking support on the server.”

Zero Knowledge releases of Freedom 2.0

Author: JT Smith

Upside.com features Zero Knowledge and its decision to release source code:

“When Mozilla veteran Mike Shaver joined Zero Knowledge as chief
software officer in January, one of his initial pledges was to give the
Montreal-based security startup more of an open source development style.

Monday, both Shaver and Zero Knowledge finally lived
up to that pledge when the company released the source
code for the Linux version of its Freedom 2.0 client.”

Category:

  • Open Source

Conventive, Metro Link work together on embedded Linux

Author: JT Smith

From Business Wire: Coventive Technologies and Metro Link have announced the
formation of a strategic partnership that will combine Coventive’s embedded Linux operating
system kernel and Metro Link’s graphic display technology to create a complete embedded
Linux solution for Information Appliance manufacturers. Together, the companies intend to
develop and offer the industry’s smallest footprint Linux operating system and graphics solution
for new IA’s, such as hand held computers, set top boxes and web pads.

Playstation hopefuls threaten each other while in line

Author: JT Smith

From The Associated Press: “Frustrated consumers lined up at retail
stores across the nation Thursday in what for
many was a vain attempt at obtaining what is
expected to be one of holiday’s hottest toys —
Sony’s new PlayStation 2 video game console.
Scuffles broke out at some locations. In Minot,
N.D., police were called to a Wal-Mart store
after receiving reports of people were
threatening others waiting in line for the console.”

Candidates for GNOME Foundation announced

Author: JT Smith

From news.gnome.org: “The GNOME Foundation elections committee is proud to announce the
final list of 33 candidates for election to the initial Board of Directors of the GNOME
Foundation. If you are registered to vote, be sure to read the following summary of the
election procedures and each of the candidates’ background (mailed to foundation-list
and all registered voters, and included below). If you are a GNOME contributor and
have not yet registered to vote, read on to read how you can register — the deadline is
Monday, October 30.”

See the IBM Linux wrist watch, up close and personal

Author: JT Smith

From LinuxDevices: For those in the Boston area, you have a unique opportunity to see the “amazing” IBM Linux
wrist watch Friday (Oct. 27) and meet the leader of the IBM Linux Wrist
Watch Project (Alex Morrow). It’s at the Embedded Linux Expo & Conference, at the Wyndham Westborough Hotel, 5400
Computer Drive, Westborough, MA.