Return-Path: X-Original-To: apmail-incubator-general-archive@www.apache.org Delivered-To: apmail-incubator-general-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 08D45D889 for ; Mon, 27 Aug 2012 10:15:54 +0000 (UTC) Received: (qmail 23857 invoked by uid 500); 27 Aug 2012 10:15:52 -0000 Delivered-To: apmail-incubator-general-archive@incubator.apache.org Received: (qmail 23427 invoked by uid 500); 27 Aug 2012 10:15:51 -0000 Mailing-List: contact general-help@incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: general@incubator.apache.org Delivered-To: mailing list general@incubator.apache.org Received: (qmail 23403 invoked by uid 99); 27 Aug 2012 10:15:51 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 27 Aug 2012 10:15:51 +0000 X-ASF-Spam-Status: No, hits=-0.7 required=5.0 tests=RCVD_IN_DNSWL_LOW,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of jukka.zitting@gmail.com designates 209.85.212.47 as permitted sender) Received: from [209.85.212.47] (HELO mail-vb0-f47.google.com) (209.85.212.47) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 27 Aug 2012 10:15:44 +0000 Received: by vbbfr13 with SMTP id fr13so3983443vbb.6 for ; Mon, 27 Aug 2012 03:15:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type; bh=ODFF8yrOCVq0CtoQbLKtOcYHLOKSWWW2oxxXD38lGiQ=; b=EPBuWnYHbcy2J2LkdgYcUsLoLkyf74KZPpztIJA2YJ8BzdnuuVM1cZ+1b9dRgn0X81 ma+VCCGEX7KlnbTIFuY4JfPiYxzFZBKUOurU3Q/aUFxaah8J0FxlpzzMlVRTfaC4gXXs 6VHcVt5n//NX2xCfkfpupy30o3rnMlRuZoe79VNvy57NbrhrhIhulEmVdl4VNYes35JZ a5zlhB67YpqoVX7NEb+FONhC2T09Xtoqc4N5pzTKb6Y776gYJFHaZ+avW4jdbXJBGWzk sbWxj1/MvcK2WWRQ5w/WSi6hDc+5AwW71iQ+odRK7v2rp1MN1vwnBoX8NJcMBS75/DgK jqHA== Received: by 10.52.26.236 with SMTP id o12mr9567378vdg.81.1346062523429; Mon, 27 Aug 2012 03:15:23 -0700 (PDT) MIME-Version: 1.0 Received: by 10.58.91.194 with HTTP; Mon, 27 Aug 2012 03:15:03 -0700 (PDT) In-Reply-To: <006d01cd83be$a3689f20$ea39dd60$@apache.org> References: <1345500234.7229.10.camel@sybil-gnome> <1345510775.7229.29.camel@sybil-gnome> <00dc01cd7f3f$55498080$ffdc8180$@apache.org> <006d01cd83be$a3689f20$ea39dd60$@apache.org> From: Jukka Zitting Date: Mon, 27 Aug 2012 12:15:03 +0200 Message-ID: Subject: Re: [VOTE] Apache OpenOffice Community Graduation Vote To: general Content-Type: text/plain; charset=ISO-8859-1 Hi, I'm jumping in late to this discussion after returning from vacation. To summarize my understanding: * As Joe says, there's no problem with current OpenOffice releases. * The project is looking for ways to produce "blessed binaries" as a part of future releases, and has been working with the relevant parties (infra, legal, etc.) on the implications. * I trust that the project is capable of continuing that work and abiding with whatever conclusion also as after graduation. Thus I don't see this as a blocker for graduation. Also below my answer's to some of Dennis' questions: On Sun, Aug 26, 2012 at 9:11 PM, Dennis E. Hamilton wrote: > 3. AVAILABILITY OF SOURCE FOR INSPECTION, AUDIT, AND PROVENANCE > > On this thread, the importance of having source code available has been stated > as a strong requirement. As far as I can tell, this is a requirement for IP provenance > more than anything else. It goes way deeper than IP provenance. If you don't release the source, you're not doing open source [1]. > Of course, the good-faith reliance on upstream sources always comes to bear, even for > source-code contributions. But having access to all source is reported by some as being > essential for ASF releases and that is tied to the notion that the source code is the > release. (This is despite specific provision in the treatment of licenses for distributing > certain binary artifacts in order to avoid license confusion.) That confusion is nicely resolved by the recent clarification that such binary dependencies are to be separately downloaded and not included in our source releases. > I don't have any clarity on this. I know that it would be a serious burden to some projects > if there were restriction to authenticated builds for open-source platforms only and/or > restriction to exclusively open-source libraries for other dependencies not satisfied by > the platform itself. The software we (i.e. the ASF) release must be in source form ("source materials needed to make changes to the software" [2]), but building and using a release may well require differently licensed and possibly binary-only dependencies or a platform [3]. Distributing the result of building a source release is also fine as long as the licenses of all the included bits allow redistribution. > To the extent that the requirement is for more than IP provenance and license > reconciliation, I am not clear who is being held to account for any deeper scrutiny > than that. Are the PMC votes for a release expected to establish some sort of > serious attestation concerning the nature of the source? Yes. > Instead, is the requirement of specific source-code availability instead a requirement > for potential forensic requirements later in the lifecycle of a release? No, without source code there by definition can be no release. > Can this be satisfied without the source be in the release, by whatever arrangement > and assurance that could be made to ensure its availability whenever needed? No. Note that this does not mean that a binary artifact produced from the sources would need to include the source code, just that all the source code needed to produce the intended binary artifacts must be included in a release. [1] http://opensource.org/docs/OSD#include-source-code [2] http://www.apache.org/dev/release.html#what [3] http://www.apache.org/legal/ BR, Jukka Zitting --------------------------------------------------------------------- To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org For additional commands, e-mail: general-help@incubator.apache.org