All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Fertser <fercerpav@gmail.com>
To: Patrick Williams <patrick@stwcx.xyz>
Cc: OpenBMC List <openbmc@lists.ozlabs.org>
Subject: Re: Update on some maintainers / contributors.
Date: Thu, 3 Apr 2025 23:43:06 +0300	[thread overview]
Message-ID: <Z+7y2oCR9xxVxDyF@home.paul.comp> (raw)
In-Reply-To: <Z-6jiKlhgkOStFZp@heinlein>

Hello Patrick,

On Thu, Apr 03, 2025 at 11:04:40AM -0400, Patrick Williams wrote:
> The Linux Foundation made a clarifying post on this situation[1].
> 
> [1]: https://www.linuxfoundation.org/blog/navigating-global-regulations-and-open-source-us-ofac-sanctions

Kudos to the Linux Foundation lawyers for this prompt,
well-thought-out and, most importantly, directly applicable advice.

For those who get a little bit sea-sick reading legalese I took the
liberty of extracting what I found to be the most relevant to the
OpenBMC community:

"
developers[...] need to be cautious about who you interact with and
where your contributions come from.
[...]
Specially Designated Nationals and Blocked Persons ("SDN") List. OFAC
updates this list regularly, adding or removing names as global
situations change.
[...]
Key Points for Developers
[...]
you should consult your legal counsel immediately
[...]
1. OFAC's SDN "List" Is Not Enough
[...]
First there's the 50% percent rule if an entity is 50% or more owned
directly or indirectly by one or more SDNs. That requires identifying
who owns an entity, and (in many cases) who also owns that entity, up
until all owners are identified. Second, some sanctions apply to
entire countries (e.g. Iran), regions (e.g., the Crimea region of
Ukraine), or governments (e.g., the Government of
Venezuela)[...]. Additionally, the SDN List is constantly
changing. Just because an individual or entity is not on the SDN List
today does not mean they, or their owner, will not be added
tomorrow.
[...]
3. Avoid Two-Way Engagement
[...] help improve a patch or modify code would likely cross the line.
[...]
5. Avoid Indirect Contributions
[...]
seek legal advice early to avoid compliance issues.[...] By staying
aware and proactive, you can contribute to open source confidently

"

HTH

      reply	other threads:[~2025-04-03 20:43 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-10-31  4:31 Update on some maintainers / contributors Patrick Williams
2024-10-31 10:05 ` Paul Fertser
2024-10-31 11:14   ` Patrick Williams
2025-04-03 15:04 ` Patrick Williams
2025-04-03 20:43   ` Paul Fertser [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Z+7y2oCR9xxVxDyF@home.paul.comp \
    --to=fercerpav@gmail.com \
    --cc=openbmc@lists.ozlabs.org \
    --cc=patrick@stwcx.xyz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.