Git development
 help / color / mirror / Atom feed
From: Junio C Hamano <gitster@pobox.com>
To: "D. Ben Knoble" <ben.knoble@gmail.com>
Cc: Sam Reis <sam@opencanopy.dev>,
	 Sebastian Thiel <sebastian.thiel@icloud.com>,
	 Scott Chacon <schacon@gmail.com>,
	 Scott Chacon <scott@gitbutler.net>,
	 git@vger.kernel.org
Subject: Re: [PATCH 0/4] faster SHA-1 collision detection
Date: Fri, 09 Oct 2026 16:41:37 -0700	[thread overview]
Message-ID: <xmqq7bjqjvbi.fsf@gitster.g> (raw)
In-Reply-To: <CALnO6CBbtKomawqc81MPV5Ngtc9J3M1ej4enGD3ZUzWnPSfsgw@mail.gmail.com> (D. Ben Knoble's message of "Thu, 8 Oct 2026 09:25:08 -0400")

"D. Ben Knoble" <ben.knoble@gmail.com> writes:

> The sha1collisiondetection submodule and the sha1dc code (extracted
> from that submodule's upstream, if I'm reading 28dc98e343 (sha1dc: add
> collision-detecting sha1 implementation, 2017-03-16) correctly?) are
> MIT licensed, too, so there is some precedent for Git here. I skimmed
> what I could find of the original threads:
>
> - https://lore.kernel.org/git/20170223195753.ppsat2gwd3jq22by@sigill.intra.peff.net/
> - https://lore.kernel.org/git/?q=sha1dc%3A+add+collision-detecting+sha1+implementation
>
> but I didn't see a discussion of licensing at that time. Perhaps the
> idea is that we are clear that such code carries a different license
> from Git?
>
> Anyway, I suppose the fair thing would then be for Scott's code to be
> MIT (and/or Apache2), in which case it would need similar
> clarifications? (Or are we prepared to take the stance that de nouveau
> code based on existing code can be license-washed, in this case to
> GPL-2?)
>
> Interestingly, Gentoo claims Git's license is only GPL-2, but I think
> they compile in the sha1dc code since it's the default in meson.
> Should we be claiming the Git package (with sha1dc) is actually GPL-2
> and MIT?

In the abov, Gentoo's mention is about "Git package" as a whole.
Git package as a whole can be distributed under GPLv2 only.

MIT, BSD-2 or BSD-3 are permissive and essentially says "you can do
whatever you want with the code (including combining with other code
or making it proprietary), as long as you keep our copyright notice,
keep our disclaimer, and (in the case of BSD-3) do not use our names
for endorsement".  Specifically, they do not forbid us from
incorporating their ware into our project that is licensed
differently, as long as we honor their licensing terms on the source
files we got from them.

Because we have mixed "permissive" code into GPLv2 code to form a
single "work based on the Program", GPLv2 Section 2(b) dictates that
the entire combined work must be distributed under the terms of the
GPLv2 (and again, the permissiveness of "other" licenses is what
allows us to do so).  You cannot distribute the finished binary or
the combined sources under a permissive license, because doing so
would violate the GPLv2's copyleft requirement.

The original "permissively licensed" files (and any modifications
made purely to those files) still maintain their original copyright
headers and original "permissive" license text.  This is because the
original copyright holder of the code granted a license to use their
files under the original "permissive" licensing terms, which
requires us to keep their copyright notice.  We do not own the
copyright to the original "permissive" code.  We are only licensed
to use them.  So we have no legal authority to strip these
"permissive" licenses or unilaterally "relicense" those files into
GPLv2.

So to answer your question in the last sentence, we should say "Git
package as a whole is GPLv2 only, but parts are borrowed from
copyright holders who licensed them under different terms, and these
parts can be used under these different parts.  For example, sha1dc
can be copied from our source tree to your non GPLv2 project as long
as you honor their MIT license".


  parent reply	other threads:[~2026-10-09 23:41 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 11:25 [PATCH 0/4] faster SHA-1 collision detection Scott Chacon
2026-09-29 11:25 ` [PATCH 1/4] sha1dc-accel: add a block loop for sha1dc's SHA1_CTX Scott Chacon
2026-10-07 12:17   ` Johannes Schindelin
2026-09-29 11:25 ` [PATCH 2/4] sha1dc-accel: vectorize the unavoidable-bitconditions check Scott Chacon
2026-10-07 12:17   ` Johannes Schindelin
2026-10-07 21:32     ` Junio C Hamano
2026-09-29 11:25 ` [PATCH 3/4] sha1dc-accel: compress with SHA-NI on x86-64 Scott Chacon
2026-09-29 11:25 ` [PATCH 4/4] sha1dc-accel: compress with the ARMv8 SHA-1 instructions Scott Chacon
2026-10-07 12:17 ` [PATCH 0/4] faster SHA-1 collision detection Johannes Schindelin
2026-10-07 17:23 ` Junio C Hamano
2026-10-07 18:13   ` Scott Chacon
2026-10-08  6:21     ` Sebastian Thiel
2026-10-08 11:20       ` Sam Reis
2026-10-08 13:25         ` D. Ben Knoble
2026-10-08 13:59           ` Sam Reis
2026-10-08 17:10           ` Junio C Hamano
2026-10-08 17:46             ` D. Ben Knoble
2026-10-08 21:03               ` Junio C Hamano
2026-10-09 20:37           ` Todd Zullinger
2026-10-09 23:41           ` Junio C Hamano [this message]
2026-10-08 15:55         ` Junio C Hamano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=xmqq7bjqjvbi.fsf@gitster.g \
    --to=gitster@pobox.com \
    --cc=ben.knoble@gmail.com \
    --cc=git@vger.kernel.org \
    --cc=sam@opencanopy.dev \
    --cc=schacon@gmail.com \
    --cc=scott@gitbutler.net \
    --cc=sebastian.thiel@icloud.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox