Visitar URL original
Apache Kvrocks kvrocks.conf is bundled but not attributed in LICENSE/NOTICE · Issue #262 · apache/openserverless · GitHub
Skip to content

Apache Kvrocks kvrocks.conf is bundled but not attributed in LICENSE/NOTICE #262

Description

@pjfanning

The 0.9.0-incubating-RC7 source release (apache-openserverless-0.9.0-incubating-src.tar.gz) ships a copy of the Apache Kvrocks configuration file that is not attributed in the top-level LICENSE or NOTICE.

The file

oplugins-op/openserverless/templates/kvrocks-cm.yaml (935 lines) is a ConfigMap whose kvrocks.conf key embeds the upstream kvrocks.conf from Apache Kvrocks v2.8.0. Both are 913 lines long; only 8 settings differ:

Setting Upstream v2.8.0 Shipped
bind 127.0.0.1 0.0.0.0
port 6666 6379
repl-namespace-enabled no yes
requirepass commented out {{redis_password}}
masterauth commented out {{redis_password}}
db-name change.me.db openserverless-redis.db
dir /tmp/kvrocks /var/lib/kvrocks/data
rocksdb.write_buffer_size 64 128

The rest, including all of upstream's explanatory comments, is copied verbatim. The file carries the ASF header (added above the ConfigMap), and nothing in it says where the configuration comes from.

Why it matters

Apache Kvrocks is an ASF project under the Apache License 2.0, so there is no licence conflict. But it is still a bundled third-party work:

  • the top-level LICENSE "Bundled components" section should list it, as it does for Apache OpenWhisk;

  • NOTICE should carry the relevant part of Kvrocks' own NOTICE (Apache-2.0 §4(d)). Only the project's own attribution applies here, since the config file does not include any of Kvrocks' third-party dependencies:

    Apache Kvrocks
    Copyright 2022-2024 The Apache Software Foundation
    

See https://www.apache.org/legal/src-headers.html#3party and https://infra.apache.org/licensing-howto.html.

Suggested fix

  1. Add an entry to LICENSE, e.g.:

    Apache Kvrocks
      The file oplugins-op/openserverless/templates/kvrocks-cm.yaml embeds
      the kvrocks.conf configuration file from Apache Kvrocks v2.8.0, with
      local changes to a few settings. Licensed under the Apache License,
      Version 2.0. See the NOTICE file for the required attribution.
    
  2. Add the Kvrocks attribution above to NOTICE.

  3. Optionally, add a comment in kvrocks-cm.yaml recording the upstream source and version, so it can be kept in sync.

This was also noted in #250 (found while verifying RC5). Related: #260, which tracks the other third-party files missing from LICENSE.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions