The 0.9.0-incubating-RC7 source release (apache-openserverless-0.9.0-incubating-src.tar.gz) ships a copy of the Apache Kvrocks configuration file that is not attributed in the top-level LICENSE or NOTICE.
The file
oplugins-op/openserverless/templates/kvrocks-cm.yaml (935 lines) is a ConfigMap whose kvrocks.conf key embeds the upstream kvrocks.conf from Apache Kvrocks v2.8.0. Both are 913 lines long; only 8 settings differ:
| Setting |
Upstream v2.8.0 |
Shipped |
bind |
127.0.0.1 |
0.0.0.0 |
port |
6666 |
6379 |
repl-namespace-enabled |
no |
yes |
requirepass |
commented out |
{{redis_password}} |
masterauth |
commented out |
{{redis_password}} |
db-name |
change.me.db |
openserverless-redis.db |
dir |
/tmp/kvrocks |
/var/lib/kvrocks/data |
rocksdb.write_buffer_size |
64 |
128 |
The rest, including all of upstream's explanatory comments, is copied verbatim. The file carries the ASF header (added above the ConfigMap), and nothing in it says where the configuration comes from.
Why it matters
Apache Kvrocks is an ASF project under the Apache License 2.0, so there is no licence conflict. But it is still a bundled third-party work:
-
the top-level LICENSE "Bundled components" section should list it, as it does for Apache OpenWhisk;
-
NOTICE should carry the relevant part of Kvrocks' own NOTICE (Apache-2.0 §4(d)). Only the project's own attribution applies here, since the config file does not include any of Kvrocks' third-party dependencies:
Apache Kvrocks
Copyright 2022-2024 The Apache Software Foundation
See https://www.apache.org/legal/src-headers.html#3party and https://infra.apache.org/licensing-howto.html.
Suggested fix
-
Add an entry to LICENSE, e.g.:
Apache Kvrocks
The file oplugins-op/openserverless/templates/kvrocks-cm.yaml embeds
the kvrocks.conf configuration file from Apache Kvrocks v2.8.0, with
local changes to a few settings. Licensed under the Apache License,
Version 2.0. See the NOTICE file for the required attribution.
-
Add the Kvrocks attribution above to NOTICE.
-
Optionally, add a comment in kvrocks-cm.yaml recording the upstream source and version, so it can be kept in sync.
This was also noted in #250 (found while verifying RC5). Related: #260, which tracks the other third-party files missing from LICENSE.
The 0.9.0-incubating-RC7 source release (
apache-openserverless-0.9.0-incubating-src.tar.gz) ships a copy of the Apache Kvrocks configuration file that is not attributed in the top-levelLICENSEorNOTICE.The file
oplugins-op/openserverless/templates/kvrocks-cm.yaml(935 lines) is a ConfigMap whosekvrocks.confkey embeds the upstreamkvrocks.conffrom Apache Kvrocks v2.8.0. Both are 913 lines long; only 8 settings differ:bind127.0.0.10.0.0.0port66666379repl-namespace-enablednoyesrequirepass{{redis_password}}masterauth{{redis_password}}db-namechange.me.dbopenserverless-redis.dbdir/tmp/kvrocks/var/lib/kvrocks/datarocksdb.write_buffer_size64128The rest, including all of upstream's explanatory comments, is copied verbatim. The file carries the ASF header (added above the ConfigMap), and nothing in it says where the configuration comes from.
Why it matters
Apache Kvrocks is an ASF project under the Apache License 2.0, so there is no licence conflict. But it is still a bundled third-party work:
the top-level
LICENSE"Bundled components" section should list it, as it does for Apache OpenWhisk;NOTICEshould carry the relevant part of Kvrocks' own NOTICE (Apache-2.0 §4(d)). Only the project's own attribution applies here, since the config file does not include any of Kvrocks' third-party dependencies:See https://www.apache.org/legal/src-headers.html#3party and https://infra.apache.org/licensing-howto.html.
Suggested fix
Add an entry to
LICENSE, e.g.:Add the Kvrocks attribution above to
NOTICE.Optionally, add a comment in
kvrocks-cm.yamlrecording the upstream source and version, so it can be kept in sync.This was also noted in #250 (found while verifying RC5). Related: #260, which tracks the other third-party files missing from
LICENSE.