WEBVTT

00:00.000 --> 00:10.720
I am extremely excited to introduce Denver Gingrich, who is the director of compliance

00:10.720 --> 00:14.280
at the Software Freedom Conservancy, who will be talking about the Vizio lawsuit.

00:14.280 --> 00:16.560
Let's give him a round of applause.

00:16.560 --> 00:27.560
Thank you very much, Karen, so yes, I am Denver Gingrich and I want to talk today about

00:27.560 --> 00:28.560
the Vizio lawsuit.

00:28.560 --> 00:35.800
Now, what I wanted to talk to you about today was how the trial concluded in this lawsuit.

00:35.800 --> 00:42.800
Unfortunately, it was rescheduled at the last minute, two hours before our pre-trial hearing.

00:42.800 --> 00:46.840
The court called us and said this has been rescheduled, so I will talk more about that

00:46.840 --> 00:53.560
in a little bit, but so today, instead I want to talk about the lawsuit, so far, give you

00:53.560 --> 00:59.680
a summary, tell you about what is likely to come up, and also go into some technical details

00:59.680 --> 01:02.480
which I think you might be interested in.

01:02.480 --> 01:10.760
So first of all, I want to note that Vizio is actually now Walmart and Vizio for those who aren't

01:10.760 --> 01:18.160
familiar is a TV manufacturer, so they operate mostly in the US, and Vizio was purchased

01:18.160 --> 01:21.840
by Walmart in 2024 for $2 billion.

01:21.840 --> 01:28.000
It was announced in February and that closed in December, and they are a wholly owned subsidiary

01:28.000 --> 01:33.720
of Walmart, but now they have a lot more resources.

01:33.720 --> 01:40.040
So I'm going to be talking about Vizio throughout, but you can insert Walmart in place of

01:40.040 --> 01:47.760
Vizio in basically every situation here, and in case I realize Walmart is not that popular

01:47.760 --> 01:59.080
around here, but the world's largest company by gross revenue, and also worth $938 billion.

01:59.080 --> 02:05.200
So they're pretty big, but we believe that we are on the side of right, and so we are

02:05.200 --> 02:08.280
very confident in our case.

02:08.280 --> 02:12.960
So anyway, that's a little bit of background about where we are in the context for this

02:12.960 --> 02:15.320
case here.

02:15.320 --> 02:20.080
So now to kind of go into how we got to where we are.

02:20.080 --> 02:27.720
So we received reports as we often do to our email address compliance at sfconservancy.org,

02:27.720 --> 02:35.400
that there were issues with the Vizio televisions in terms of their GPL and LGPL compliance.

02:35.400 --> 02:39.640
That is, there was no source code or offer for source code, even though its heavies were

02:39.640 --> 02:42.960
using software under these licenses.

02:42.960 --> 02:48.360
So the first such reports was in 2012, and then we got a couple more reports over the

02:48.360 --> 02:55.600
next six years, and then in April of 2018, we chose to purchase a Vizio television and

02:55.600 --> 02:58.000
a tablet that they produced at the time.

02:58.000 --> 03:03.840
We determined that they did indeed include Linux and other software under the GPL and

03:03.840 --> 03:05.120
LGPL.

03:05.120 --> 03:09.640
And so we checked if there was an offer for source code.

03:09.680 --> 03:13.320
We could not find any, and so we contacted them for months later.

03:13.320 --> 03:16.320
We sent them a letter in August.

03:16.320 --> 03:23.920
So we would expect that within, at the very most 30 days, we received source code that

03:23.920 --> 03:25.920
is complete and corresponding.

03:25.920 --> 03:31.960
So not only was it not 30 days, they took us five months to get back to us.

03:31.960 --> 03:37.400
They also did not provide complete source code, and we had to go through many, many rounds

03:37.440 --> 03:40.360
with them, and it still was not complete at the end of that.

03:40.360 --> 03:46.040
So we had to call with them after the sixth source of candidate, which was still in complete

03:46.040 --> 03:53.000
after a year, and then after that, we emailed them a few times, a bunch of times, over

03:53.000 --> 03:55.920
five months, and they just ghosted us.

03:55.920 --> 03:58.560
So we weren't really sure what was going on.

03:58.560 --> 04:03.680
I guess that is what we're not going to do anything else, but we decided to check a year

04:03.680 --> 04:07.000
later, whether they had fixed any of these issues.

04:07.000 --> 04:13.320
So we purchased new visual televisions, new models, to see if they had fixed any of these

04:13.320 --> 04:16.720
issues that we reported.

04:16.720 --> 04:22.640
Now you might guess from the title of the slide, what we determined after testing those

04:22.640 --> 04:27.880
new devices, they were also not in compliance with the licenses.

04:27.880 --> 04:31.160
We still did not have the source code.

04:31.160 --> 04:39.000
So we filed the lawsuit in October of 2021, and this lawsuit is interesting in a couple

04:39.000 --> 04:40.000
ways.

04:40.000 --> 04:47.480
So similar to the AVM lawsuit that you may have been here for, if you were at this

04:47.480 --> 04:53.080
devroom last year, it was filed as a purchaser of the device.

04:53.080 --> 04:59.560
And in particular, the legal mechanism that we're using here is called the right of third-party

04:59.560 --> 05:00.880
beneficiaries.

05:00.880 --> 05:06.640
So there is a contract between Vizio and the developers of the software that Vizio chose

05:06.640 --> 05:09.440
to use in their devices.

05:09.440 --> 05:15.120
And that contract says that a third-party, namely the purchaser of the device, the person

05:15.120 --> 05:20.640
who received distribution of the device, is owed source code.

05:20.640 --> 05:27.200
So in particular, the way we're asking the remedy we're asking for here is not in junction,

05:27.240 --> 05:32.720
it's not money, it is specific performance that is we want Vizio to provide the source

05:32.720 --> 05:39.160
code to perform the act of giving us source code, which is something that is a remedy

05:39.160 --> 05:41.160
available under contract law.

05:41.160 --> 05:48.360
So you might have heard Gabriel talk about the GPL and LGPL as copyright licenses, and

05:48.360 --> 05:51.400
they are, but they are also contracts.

05:51.400 --> 05:55.920
And so that is what we are filing the suit as here.

05:55.920 --> 06:02.640
So a number of things happened in the case, in May of 2022, Vizio decided to try to get

06:02.640 --> 06:07.880
the case removed to federal court, because it was a contract case that was being tried

06:07.880 --> 06:14.040
in state court, Vizio said, actually this can only ever be tried as a copyright case.

06:14.040 --> 06:18.720
So they asked the federal judge to say, yeah, sure.

06:18.720 --> 06:23.160
And the federal judge said, no, no, this is not just a copyright case, it can be tried

06:23.160 --> 06:24.840
as a contract case.

06:24.840 --> 06:30.560
And so then it was remanded to state court, and that is where it has been since then.

06:30.560 --> 06:37.800
So over the next three years, there were mediation attempts as often the case in a lawsuit,

06:37.800 --> 06:40.120
we tried to find some common ground.

06:40.120 --> 06:44.120
We were not able to get the complete source code that way.

06:44.120 --> 06:48.760
And then there was also the usual process of discovering in these cases, and at least in

06:48.760 --> 06:54.200
these types of cases, in the United States, where this is being tried.

06:54.200 --> 07:00.240
This discovery is quite intense, involves thousands of documents going back and forth between

07:00.240 --> 07:04.360
the parties, many people being deposed as well.

07:04.360 --> 07:12.360
So I was deposed for 10 hours by Vizio's Council, Karen and Bradley, also of Conservancy,

07:12.360 --> 07:18.720
we're similarly deposed, so yeah, we've had to put quite a bit into this to make sure

07:18.720 --> 07:26.560
that we are giving everything that we need to provide for this and getting everything from Vizio.

07:26.560 --> 07:33.880
So in April of 2024, this was mostly a procedural thing, but we amended the complaint,

07:33.880 --> 07:40.080
due to some changes in the offer for source code that happened, but by this time we

07:40.080 --> 07:47.440
already received some initial source candidate from Vizio, and it was quite incomplete.

07:47.440 --> 07:51.040
So we still had these issues here.

07:51.040 --> 07:55.920
Then in the next two years, there were some motions for summary and education, including

07:55.920 --> 08:03.200
some other things alongside those, but the motion, including the legal documents that

08:03.200 --> 08:08.440
are at issue here, like all of the filings, et cetera, that have happened.

08:08.440 --> 08:12.800
You can check out this website, and you can also check back to see, you know, when we

08:12.800 --> 08:17.400
have a trial date set and other things like that.

08:17.400 --> 08:24.840
Now, we haven't listed every single document there, because the docket for the case,

08:24.840 --> 08:31.840
as I checked this morning has 710 items in it, so those would each be like separate documents,

08:31.840 --> 08:37.160
some as many as 435 pages of exhibits.

08:37.160 --> 08:41.440
So we haven't put every single one of those on many are very procedural, so you can just

08:41.440 --> 08:46.360
check out the ones that are kind of most important to the case there.

08:46.360 --> 08:53.560
So I wanted to spend a little bit of time talking now about what exactly this source candidate

08:53.560 --> 08:58.480
is missing, because I think that's something that I've seen in a lot of discussions

08:58.480 --> 09:03.720
in the case, it's like, well, what is it that's actually wrong here, like why is Vizio

09:03.720 --> 09:08.920
still in this lawsuit, you know, can't they just provide these things and be done with

09:08.920 --> 09:09.920
this?

09:09.920 --> 09:14.240
And so, to be clear, we've asked repeatedly for the things that are mentioned here,

09:14.280 --> 09:19.760
we've told Vizio about them early on, and so these are the things that are still missing.

09:19.760 --> 09:24.040
And I'll go into some detail after summarizing them here.

09:24.040 --> 09:32.120
So first of all, there is GPL and LG PILD code on the TV that is code in binary form,

09:32.120 --> 09:33.920
for which we have no source code at all.

09:33.920 --> 09:38.360
So there are several binaries for which we have no source code whatsoever.

09:38.360 --> 09:43.320
And also when I say GPL and LG PILD here, I'm talking specifically about GPL version

09:43.320 --> 09:49.880
2 and LG PILD version 2.1, because those are the licenses of the software that we have

09:49.880 --> 09:56.120
alleged in this lawsuit that Vizio is not providing source code for.

09:56.120 --> 10:02.600
So we also have GPL that LG PILD code on the TV that has a license that is incompatible

10:02.600 --> 10:05.560
with the GPL and the LG PILD.

10:05.560 --> 10:11.560
So that is to say there is code on the TV binary code for which Vizio has provided

10:11.600 --> 10:17.320
some source code, however this source code has notes in it that indicate that its license

10:17.320 --> 10:19.320
is not compatible with the GPL.

10:19.320 --> 10:23.880
So this is a problem, we've told Vizio, you know, look at this, you need to delete this

10:23.880 --> 10:26.320
and they have not done that.

10:26.320 --> 10:32.320
There is also binary code on the TV for which we are missing the scripts and I'll go

10:32.320 --> 10:37.240
into some detail about what I mean by the scripts, but if you've seen some of my recent

10:37.240 --> 10:41.520
talks, you probably have some good guesses about what I'm talking about here.

10:41.520 --> 10:49.200
And lastly, and this is particularly related to the LG PILD, we need the information needed

10:49.200 --> 10:57.120
such that a binary, a proprietary binary, links with an LG PIL library will operate properly

10:57.120 --> 10:58.680
with a modified version.

10:58.680 --> 11:04.320
So that is our question, can we have this binary operate properly with a modified version

11:04.320 --> 11:06.880
of the library and we are unable to answer that?

11:06.880 --> 11:17.280
On here, okay, we're good, all right, great.

11:17.280 --> 11:23.520
And so Vizio has not provided us with the information required to make that determination

11:23.520 --> 11:27.840
which is something that is required by the LG PIL.

11:27.840 --> 11:34.400
So you can, if you like, you can confirm some of these findings of hours for yourself,

11:34.400 --> 11:40.200
and Vizio has published the most recent source candidates that they have given to us at

11:40.200 --> 11:41.200
this URL.

11:41.200 --> 11:46.520
Now you might think that this is a source code repository, sadly it is not, it is a read-me file

11:46.520 --> 11:52.960
that has a link to a page where you can enter some information and including an email address

11:52.960 --> 11:56.880
and then Vizio will then give you the source candidate.

11:56.880 --> 12:03.720
Now my understanding is that they do not verify an email address or phone number that you

12:03.760 --> 12:07.960
use in there, so it should be straightforward to get what you need.

12:07.960 --> 12:14.240
If you do wish to do that, but yeah, if you go to this website, click on the link.

12:14.240 --> 12:22.840
You will get these are particularly modules in Linux and so these modules here all appear

12:22.840 --> 12:29.680
on the TV and we don't have source code for any of these eight modules here.

12:29.680 --> 12:36.680
And I would love to be able to share with you the TV firmware that where you can see all

12:36.680 --> 12:41.680
of these modules, but for a number of reasons including that we are in active litigation

12:41.680 --> 12:42.680
here.

12:42.680 --> 12:46.760
I can't give you that firmware image, but if you have questions about these, I'm happy

12:46.760 --> 12:50.040
to discuss what I can with you about them.

12:50.040 --> 12:55.320
And so these are the modules for which we have no source code.

12:55.320 --> 13:01.800
And interestingly, most of these modules, if you run the Mod Info command on these modules,

13:01.800 --> 13:07.200
they will show you that the license field has a value of GPL, so they are explicitly

13:07.200 --> 13:13.320
labeled as being under the GPL, but for some reason Vizio has not provided the source code

13:13.320 --> 13:18.680
for it, even though they have indicated to us that they believe they are under the GPL.

13:18.680 --> 13:25.000
So I'm a little confused about that, but that is something for us to resolve here.

13:25.000 --> 13:30.120
So there is also the issue of the incompatible license that we find.

13:30.120 --> 13:36.120
And in particular, the text we found in the source code files that they provided to us was,

13:36.120 --> 13:40.480
this is right at the top of the file and a comment, it says, the information contained

13:40.480 --> 13:43.240
here in is confidential and proprietary.

13:43.240 --> 13:47.760
And it goes on to explain how you cannot redistribute it, et cetera, et cetera.

13:47.760 --> 13:54.760
So okay, that might be okay if we're not under the GPL, but you know, we'll take a

13:54.760 --> 13:57.120
look at the files that we find this in.

13:57.120 --> 14:02.680
So if you open up this zip file, you will find inside another zip file, inside a tarball

14:02.680 --> 14:09.280
and that zip file, this file right here, GCPU underscore iF.c.

14:09.280 --> 14:14.720
And you will note that this is in a directory that is called huboot, so huboot is licensed

14:14.720 --> 14:21.200
under the GPL version 2, and therefore you cannot have a source code file that has a proprietary

14:21.280 --> 14:24.280
license because it must be, of course,

14:24.280 --> 14:28.280
compatible with the GPL version 2 to be included in Uboot.

14:28.280 --> 14:33.600
So there are a number of other examples where we see the same incompatible license text

14:33.600 --> 14:38.600
again inside the tarball, inside the zip file, inside the zip file, and you can find them

14:38.600 --> 14:42.600
in this at this location or this location here.

14:42.600 --> 14:48.520
So you can see some stuff possibly included in some kernel drivers there, and that is,

14:48.560 --> 14:53.800
you know, not awesome, and we definitely want them to fix that and have told them to fix it

14:53.800 --> 14:55.840
and they haven't.

14:55.840 --> 14:58.440
So we are also missing the scripts.

14:58.440 --> 14:59.880
And what do I mean by that?

14:59.880 --> 15:07.560
Well GPL version 2 and LGPL version 2.1 require the scripts you can, you know, go to the

15:07.560 --> 15:12.280
read me file and then click on the link and enter in, anyway, to you, you get it.

15:12.280 --> 15:18.640
So yeah, I will first talk about the Samsung TV and what it included.

15:18.640 --> 15:24.440
So I've, I've bridged it a little bit here, but you can get the whole text files from

15:24.440 --> 15:25.760
that source code candidate.

15:25.760 --> 15:28.440
So what does Samsung tell us to do?

15:28.440 --> 15:33.760
So in the text file, it says, for building Linux, you unpack the Linux tarball, you

15:33.760 --> 15:40.040
go into that directory, and then you copy this config file into place, run, make old config,

15:40.040 --> 15:46.040
and run, make image, and then add to the end of that, you have this image binary that

15:46.040 --> 15:49.560
to copy into a, you image location here.

15:49.560 --> 15:55.640
And then for busy box, and then we'll use that location in a little bit here.

15:55.640 --> 16:02.680
For busy box, you do a similar thing, you run, make with this cross compilation variable.

16:02.680 --> 16:12.040
And so that is using across, hopefully, included this rootffs.img file in the, in the source

16:12.040 --> 16:18.360
release itself, and so you can unpack that, and then replace the busy box binary in there

16:18.360 --> 16:25.360
with your own busy box binary, and then you can create a new rootffs.img file, and then

16:25.360 --> 16:27.560
you will be ready for the next step here.

16:27.560 --> 16:28.560
And what is that stuff?

16:28.560 --> 16:31.880
Well, it is, of course, to install these onto the television.

16:31.880 --> 16:39.360
So you first Samsung tells us, connect a serial cable to the serial port on the TV.

16:39.360 --> 16:45.360
And this excellent port is a kind of special kind of port, which they explained how to use elsewhere.

16:45.360 --> 16:52.440
You make a folder called update in USB memory stick, and copy these files like this rootffs

16:52.440 --> 16:57.960
image, and the U image file, which is that kernel binary, into the update folder on that

16:58.000 --> 17:04.080
USB memory stick, you connect the USB memory stick to the USB port of the TV.

17:04.080 --> 17:09.640
Then with the serial console, that is connected to the serial port of the TV.

17:09.640 --> 17:12.280
You push shift, and then tilt at the same time.

17:12.280 --> 17:17.680
You plug in the power cable to the TV, and two seconds later, you press enter.

17:17.680 --> 17:22.280
And then you will find a U-boot menu in the serial console output.

17:22.320 --> 17:25.000
Then you press zero on the keyboard.

17:25.000 --> 17:29.440
That is of the serial console and press enter.

17:29.440 --> 17:32.440
And then you get a shell.

17:32.440 --> 17:36.680
And this is a shell of the bootloader, and you can type BBM USB.

17:36.680 --> 17:40.880
And then you will get a list of things that you can update on the TV, which include the kernel

17:40.880 --> 17:45.680
image, option number four, and the rootfile system, option number five.

17:45.680 --> 17:51.160
So if you select number four, and then type slash update slash U image, then it will

17:51.200 --> 17:58.160
copy that kernel image binary into the firmware, or rather into the flash of the television.

17:58.160 --> 18:04.440
And similarly for the rootfile system, doing a similar command will copy that rootfile system

18:04.440 --> 18:07.960
into a partition on the flash of the television.

18:07.960 --> 18:14.560
So then when you unplug that USB stick and you reboot the TV, then it will boot using the

18:14.560 --> 18:21.840
kernel image, or the files that you install onto the rootfs through that rootfs image.

18:21.840 --> 18:27.320
So that is the sort of thing that we would be expecting for the scripts used to control

18:27.320 --> 18:33.360
compilation and installation seems pretty straightforward to me in terms of achieving all

18:33.360 --> 18:35.960
of the goals we have here.

18:35.960 --> 18:37.760
Let's see what busy it did.

18:37.760 --> 18:44.040
So they have a text file, and one of the sections is labeled build instructions.

18:44.040 --> 18:49.760
In fact, this is the main section and the last section of the text file.

18:49.760 --> 18:56.960
It says that you should unzip this zip file to a folder in your Ubuntu 20D.04 VM, okay?

18:56.960 --> 19:03.680
So we set up such a VM, and we unzip that zip file to a folder in there, then run this

19:03.680 --> 19:06.440
command to make some things executable, okay?

19:06.440 --> 19:09.280
That seems a little weird, but we'll go ahead and do that.

19:09.280 --> 19:14.880
We run each of these next four build scripts after the prep script.

19:14.880 --> 19:19.520
So we see we can run this prep script like this, and then there are four other scripts

19:19.520 --> 19:24.400
that they have set up and ask us to run.

19:24.400 --> 19:32.200
Now after several hours these scripts do eventually complete, but there is nothing else.

19:32.200 --> 19:34.680
There are no further instructions.

19:34.680 --> 19:40.880
The last thing that the last script prints out is pretty uninformative.

19:40.880 --> 19:44.040
You can confirm that for yourself if you would like.

19:44.040 --> 19:50.920
And so what we are left with is a little over a million files in various parts of the

19:50.920 --> 19:56.160
directory we have in front of us, and basically no information about what we're supposed

19:56.160 --> 20:01.240
to do with these files, what they might correspond to, how we might install them.

20:01.240 --> 20:06.840
That is it, apparently something has been compiled, but as you can see from what we discussed

20:06.840 --> 20:09.360
earlier, it is not complete.

20:09.360 --> 20:13.640
We are missing a lot of things in the things that have been compiled, and Vizio has

20:13.640 --> 20:19.120
not told us what we can do with this in particular, you know, these missing scripts to

20:19.120 --> 20:24.400
control compilation and installation, since we would expect a lot more, you know, of the

20:24.400 --> 20:28.160
sort of thing that Samsung had provided to us.

20:28.160 --> 20:37.560
So finally, the issue of us being unable to get a binary using the LGPL libraries to operate

20:37.560 --> 20:42.000
properly with a modified version of the library.

20:42.000 --> 20:50.360
So we have a situation where Vizio statically links the Websocket client library for Python,

20:50.360 --> 20:57.200
the version of which they use, which is licensed under LGPL version 2.1, and they have

20:57.240 --> 21:04.240
not provided us with a way to modify that library and relink it with this program.

21:04.240 --> 21:11.080
And in particular, in one of the responses that we gave to Vizio as part of the discovery

21:11.080 --> 21:16.840
process, we noted that there is no information provided for how to cause the relevant

21:16.840 --> 21:24.040
third-party portions, that is the proprietary portions of this specific binary file at

21:24.040 --> 21:31.720
this path in the TV's firmware to operate properly with a modified version of the library.

21:31.720 --> 21:40.040
And this is text straight from LGPL version 2.1, saying that the program that is this binary,

21:40.040 --> 21:45.960
that uses an LGPL work will operate properly with a modified version of the library.

21:45.960 --> 21:51.320
So all we want to do is make sure that we can run it properly with a modified version of

21:51.320 --> 21:57.080
the library, but we have no information provided for how we might do that.

21:57.080 --> 21:59.480
And so that is another issue we have here.

21:59.480 --> 22:05.480
And notably this happens with other programs on the TV, there are other programs that

22:05.480 --> 22:12.560
are dynamically linked, and there are other programs that, for example, use FFMPEG.

22:12.560 --> 22:18.920
And one such program is the program that does the automatic content recognition, and if

22:19.000 --> 22:24.120
you're unfamiliar with that term, basically it means the program that watches what you

22:24.120 --> 22:29.400
are watching on the TV, it matches that up with known TV shows or other programs, and

22:29.400 --> 22:35.560
then sends that information to Vizio so that they can sell that information to people who

22:35.560 --> 22:37.080
might be interested in that.

22:37.080 --> 22:41.360
Maybe Netflix wants to know what you're watching at Amazon or vice versa.

22:41.360 --> 22:43.720
That is the sort of thing they will do.

22:43.720 --> 22:48.880
So this is a reason that you may want to modify the behavior of some of these programs

22:49.520 --> 22:54.800
because they are perhaps not doing the thing that you are wanting them to do or not do.

22:54.800 --> 23:00.480
So that is one of the other issues here we have with this source code candidate.

23:01.360 --> 23:08.720
So to summarize what we want, we want source code for the programs and modules for which we

23:08.720 --> 23:10.720
are missing source code right now.

23:10.720 --> 23:17.760
We want this incompatible license text fix, so there is no ambiguity about whether these files

23:17.840 --> 23:25.280
that they provided for you boot or other programs are licensed under the GPL or LGPL.

23:25.280 --> 23:32.800
We want to be able to operate these binary programs, these proprietary programs that use

23:32.800 --> 23:34.160
LGPL works.

23:34.160 --> 23:40.160
We want them to operate properly if we modify the LGPL work as is required by the LGPL.

23:41.040 --> 23:46.800
And we want these scripts used to control compilation and installation of the executable in the

23:46.880 --> 23:51.280
case of GPL or of the library in the case of LGPL.

23:51.280 --> 23:58.160
So this seems to us pretty straightforward, but for some reason physio does not want to provide

23:58.160 --> 24:02.640
us with this and so that is why the lawsuit is still going on.

24:02.640 --> 24:10.400
So we want physio in short to fix this source code candidate here, roughly speaking, a source

24:10.400 --> 24:16.560
code candidate, so that is like this source code release that we received from Samsung for

24:16.560 --> 24:22.880
their television. They're both TVs. They would seem to operate properly, so we would like to

24:22.880 --> 24:29.120
receive the information that we got similar to what Samsung provided with all the scripts used to

24:29.120 --> 24:35.680
control compilation and installation. So that is what we want and that is what we are hoping to

24:35.680 --> 24:44.560
get when the decision comes back after the trial. So you might be wondering, well, how can I help in the

24:44.560 --> 24:52.000
meantime? Well, we would of course appreciate financial support, which I'll go into in a little bit,

24:52.000 --> 24:59.200
but we would really like to encourage you to join this consumer association, which is doing similar

24:59.200 --> 25:06.640
work. So you may recall that in this devroom last year, we talked about the AVM lawsuit,

25:06.640 --> 25:11.840
which I'd concluded in the previous year with Sebastian Steck, the plaintiff,

25:12.560 --> 25:19.840
receiving the complete source code for the LGPL works that he was suing over, and so Sebastian

25:19.840 --> 25:27.360
Steck has started this consumer association called Fossusers EV, and this consumer association

25:27.360 --> 25:34.640
will make it much easier to do lawsuits of that nature if they are required in the future. And so

25:34.640 --> 25:41.120
we are very excited about initiatives like this, and we would like to strongly encourage you to join

25:41.200 --> 25:47.520
this consumer association. So all we need is information like your name, if you want to join,

25:47.520 --> 25:54.240
and then you essentially have no obligations beyond that. Basically, you're just saying that we wish

25:54.240 --> 26:01.360
to have our rights enforced, but if a lawsuit comes up, it's not necessary for you to be involved in

26:01.360 --> 26:08.720
any way. It's just making sure we have that Sebastian is able to show that there is this general

26:08.720 --> 26:15.920
support base. And so we need a few more people to be in the consumer association before it

26:15.920 --> 26:21.520
before it can be registered officially, and so we'd really appreciate if you could do that. So

26:22.240 --> 26:28.720
there is a handwritten signature required, so I have a bunch of forms here at the front of

26:28.720 --> 26:35.200
some in German, some in English, and so this is a consumer association being registered in

26:35.840 --> 26:41.040
Germany, and so it is most helpful if we have people who live in Germany sign up, but it is also

26:41.040 --> 26:48.160
helpful if other sign up as well. So if you could sign up, we would love to have you participate in

26:48.160 --> 26:53.360
that way. And again, it's just you signing saying you're interested in this stuff happening,

26:53.360 --> 26:59.200
and then you have no obligations beyond that. All we need is the form saying that that is something

26:59.360 --> 27:05.520
that interests you. And technically speaking, you have to be either someone who develops software

27:06.240 --> 27:12.320
under these licenses, or who has ever received software under these licenses. So I would posit

27:12.320 --> 27:18.560
that that would include 100% of the people in this room, so you would all be eligible to join

27:19.200 --> 27:25.200
the Foss users EV. So I would encourage you also to sign up for software freedom,

27:25.200 --> 27:30.720
Conservancies, announced mailing list, where we will provide updates about the Vizio case,

27:30.720 --> 27:36.960
and also about things that the Foss users EV might be involved in for those who are interested in

27:36.960 --> 27:45.040
that. So just before I take questions here, I did want to note that software freedom,

27:45.040 --> 27:51.280
Conservancy, as has been mentioned briefly in the opening to this devroom, has a few days left

27:51.280 --> 27:59.360
of a match that will expire then. And so we would really encourage you if you like what we are

27:59.360 --> 28:05.280
doing to support software freedom Conservancy by becoming a sustainer, or otherwise donating to

28:05.280 --> 28:11.760
software freedom Conservancy. And if you do so within the next couple days, your donation will count

28:11.760 --> 28:19.040
for double. So please do do that if you like what we're doing. Join the Foss users EV using

28:19.040 --> 28:25.840
these forms here or go to the software freedom Conservancy booth in the K building on the second

28:25.840 --> 28:32.800
four, and we have some forms there as well if you would like to fill that out. So thank you very

28:32.800 --> 28:38.000
much, and I am happy to take questions for looks like about 25 minutes.

28:38.240 --> 28:51.360
All right, so we have a question over here, so please keep your hands up if you have questions

28:51.360 --> 28:59.520
so that they can make a good message. Thank you very much. I have two questions. The first is,

28:59.520 --> 29:06.560
what do you think Vizio's goal is here? I mean, it would be so easy for them to do the right thing

29:06.560 --> 29:10.160
and provide this software and they could have avoided all of this. So I don't really understand

29:10.160 --> 29:17.600
what their hesitation is. And then secondly, you mentioned that you're not doing for money or anything

29:17.600 --> 29:21.680
like that, you're suing to have them do what they're supposed to do, what they're obligated to do.

29:22.400 --> 29:27.520
But and then you went through arbitration and to me or mediation, to me mediation suggests that

29:27.520 --> 29:33.760
there's going to be some sort of compromise potentially. In which case, then the solution from

29:33.920 --> 29:38.800
the point of view of the mediator is that you're going to be getting less than what you really

29:38.800 --> 29:45.280
deserve to get. And so I'm just curious, why not ask for a bunch of money or something?

29:45.280 --> 29:51.200
You know, damages well beyond just being able to get the source code that you're entitled to. Thank you.

29:52.400 --> 29:58.560
So I'll answer the first question, sorry, the latter question first. And so

29:58.560 --> 30:06.640
yeah, I mean, I can't really say much about what we've done in mediation because those

30:06.640 --> 30:14.160
negotiations are confidential. But I mean, generally speaking, yes, you're right, you know, different

30:14.160 --> 30:21.040
things can be discussed in mediation. But you're also correct that we did not ask for money.

30:21.040 --> 30:26.000
We were asking only for source code. And that was partly to make it make it clear to the judge

30:26.000 --> 30:31.360
that, you know, there's no number. We don't have a number like we want the source code.

30:31.360 --> 30:38.400
That is what we want from this. And so I think that has been effective so far. And we look

30:38.400 --> 30:46.000
forward to being to it being effective in trial and to answer your first question. We're really

30:46.000 --> 30:52.640
not sure why they haven't provided this source code. I mean, you could maybe make some hypotheses

30:52.640 --> 30:57.840
based on this automatic content recognition thing that they have, which might suggest some

30:57.840 --> 31:04.480
level of control. They might wish to keep over their TVs. But I think it's also, you know,

31:04.480 --> 31:09.440
pretty evident that they're not going to, you know, they're not going to lose a lot from allowing

31:10.720 --> 31:18.080
you know, technically sophisticated individuals to have control over their TV. So yeah,

31:19.040 --> 31:26.560
I mean, it could be a number of other things. I mean, sometimes the files that might be on the

31:26.560 --> 31:33.520
device could come from like a supplier or something like that. But you know, I mean, with a 938

31:33.520 --> 31:38.240
billion dollar company, I would hope that they have a little bit of leverage with their supplier.

31:38.240 --> 31:45.520
So it is a bit confusing to me that they can't get the source code for those files if that is

31:45.520 --> 31:56.240
the situation, indeed. I have a question about operate properly. Is that the GPL and LGPL

31:56.240 --> 32:04.160
licensed software that has to operate properly or all the functions of the TV? So the, so the

32:05.120 --> 32:12.720
specifically, the LGPL, so the phrase operate properly comes out only in the LGPL. And so

32:13.680 --> 32:19.120
what it is talking about is a proprietary program that's being linked with an LGPL work.

32:20.080 --> 32:26.160
And the text, and let me see if I can just pull it up here. But based on

32:27.760 --> 32:32.720
a reading of the text, and you can take a look if you do like a text search for operate,

32:32.720 --> 32:38.800
will operate properly. You can find sections 6B fairly quickly. And so

32:39.360 --> 32:45.360
at least, you know, to be clear, I'm not a lawyer. I cannot provide legal advice all of that stuff.

32:45.920 --> 32:52.640
But at least my understanding of this is that we are talking about the combination of the proprietary

32:52.640 --> 33:00.160
program and the thing that is linked with it. And so if you change that library, that this proprietary

33:00.160 --> 33:06.000
program is linking with, then the combination of those two should continue to work properly. And it

33:06.000 --> 33:13.280
has some, some caveat saying, you know, if you change the interfaces like, you know, you don't have

33:13.280 --> 33:18.240
to guarantee that that will work properly. But if you're using the same interface that the proprietary

33:18.240 --> 33:24.400
program expects, then the proprietary program should continue to work properly. And so that is what

33:24.400 --> 33:31.360
we are, we are looking for here. Now it's, you know, we don't know exactly, you know, how many

33:31.360 --> 33:38.320
proprietary programs that are not using LGPL works, you know, may cease to function if something,

33:39.360 --> 33:44.000
if something were changed below them, like say the Linux kernel or something like that.

33:44.800 --> 33:51.600
But, but if a program is proprietary and is not under, is not linked with an LGPL work,

33:52.480 --> 33:58.720
we would not necessarily expect that program to continue working if something else has changed in

33:58.720 --> 34:05.760
its environment. So, you know, we're, we're not saying that we, we expect videos TV to continue to

34:06.080 --> 34:11.120
perform all of the same, everything across all of its programs. If we change something on the TV,

34:11.760 --> 34:17.120
we understand that that is impractical and the license does not demand that, at least the GPL version

34:17.120 --> 34:23.440
two and LGPL version 2.1. And so we would fully expect that we may have to rewrite some components.

34:24.240 --> 34:31.520
You know, once we get to like a busy box shell after booting up Linux and busy box and whatever

34:31.520 --> 34:37.120
other components are in the TV, you know, there's more than a dozen programs under the GPL and

34:37.120 --> 34:42.960
LGPL that we've alleged that we expect to receive source code for as a result of this lawsuit.

34:42.960 --> 34:48.800
There's, we would expect to be able to need to rewrite some software in order to get an

34:48.800 --> 34:54.640
interface back up on the TV. But, you know, I'm very encouraged by the work of projects like

34:54.640 --> 34:59.920
OpenWRT that have done similar things in the past where, you know, they did not get the user interface

35:00.720 --> 35:06.080
that that links this had on the routers way back in the day when that project started and they

35:06.080 --> 35:11.280
implemented their own interface. And so, so yeah, that's totally, totally reasonable, but we don't

35:11.280 --> 35:16.160
have enough information to even get to that point where we could do that as the next step.

35:16.480 --> 35:19.200
Well, there's another question over here.

35:21.200 --> 35:25.520
When you receive the source code from VZO and try to create the binary out of it,

35:25.520 --> 35:30.800
could you figure out what this binary doing anything or what it just a bunch of binary code

35:30.800 --> 35:31.760
that does nothing?

35:31.760 --> 35:39.040
All right, so are you talking about the source code candidate when we want to build it again with

35:39.040 --> 35:43.760
the instructions from VZO? What did in the end functional Linux system with, I would say,

35:44.640 --> 35:48.320
in general functionalities, what did just nothing to use?

35:48.320 --> 35:50.320
You can use every anywhere.

35:50.320 --> 35:56.960
Well, basically what we got in the end was like over a million files which, you know,

35:56.960 --> 36:02.400
VZO had not described in any way what what they do or what they, they might or might not do.

36:02.400 --> 36:08.320
So, you know, we could, we could try pretty hard to guess about, you know, what, what these

36:08.320 --> 36:14.400
the usefulness of these files might be, but certainly, you know, despite a lot of trying,

36:14.400 --> 36:22.880
including, you know, from our expert in the case, there's no way we can see to like a symbol

36:22.880 --> 36:30.960
them into something that we could then use in some way as like a complete system, you know,

36:30.960 --> 36:35.040
and to be clear, I'm just talking about a complete system in the sense of all of the programs

36:35.120 --> 36:40.320
under the GPL and LGPL were correctly, not necessarily anything else, but there's certainly no

36:40.320 --> 36:48.000
way we can, we can see to get that from these million-ish files, which you are happy to reproduce

36:48.000 --> 36:53.200
if you like using the source code candidate. But yeah, that would be the answer there.

36:54.400 --> 37:01.120
So another one here. Thank you. So the novelty of this lawsuit is that you're

37:01.120 --> 37:06.080
assuming as a third party beneficiary rather than on behalf of an open-source program, all right?

37:06.880 --> 37:14.560
So the, you could say in some sense that that is novel, I mean, it may be the case that this is the first

37:14.560 --> 37:23.600
such lawsuit on using this particular strategy in the U.S., but the AVM lawsuit that

37:24.320 --> 37:30.000
concluded in Germany a year and a half ago, that one was done in a very similar way, it was as a

37:30.000 --> 37:35.840
purchaser of the device, so I think. So anyway, go ahead. All right, it wasn't actually my question.

37:36.720 --> 37:45.120
So historically, obviously, you're assuming for copy left, so want to receive the source code.

37:45.120 --> 37:51.280
The other reason why I focus you are incorrect or so, incomplete or missing legal notices.

37:51.280 --> 37:56.800
So that's the different aspect. What the same pattern of the lawsuit that you are establishing

37:57.120 --> 38:03.600
or have been working on also work for a customer who buys a product. Only was

38:03.600 --> 38:07.440
permissively licensed software in there and then it doesn't have good legal notices.

38:08.640 --> 38:15.760
I mean, the facts would be a lot different in a case like that. I would certainly like to make

38:15.760 --> 38:24.400
sure that any of those violations are resolved, but I frankly, we prefer to prioritize situations

38:24.400 --> 38:30.560
where users rights are being taken away from them in strong and serious ways.

38:30.560 --> 38:37.760
And I definitely agree developers should be attributed 100% and that the legal notices have to be there.

38:38.400 --> 38:42.480
But in a situation where a company is only using permissively licensed code,

38:42.480 --> 38:50.000
there's really no way for us to get people's right to modify the software through source code they

38:50.000 --> 38:55.440
might receive. I wish there were other laws and things that might exist for that,

38:55.440 --> 39:02.320
but that's not the current situation we live in. And so we use the tools that we have available

39:02.320 --> 39:08.160
to us. And so that's why we prioritize situations involving the GPL and LGPL because those

39:08.160 --> 39:16.400
allow us to get the user rights that we strongly believe and that the licenses say that we should have.

39:17.360 --> 39:19.760
All right, another question over here.

39:21.120 --> 39:25.680
Yeah, a question about the timeline. So you said like it's more than 10 years and it was first

39:25.680 --> 39:30.720
discovered that there's like GPL code on it. So just it that's I guess that's not a normal case.

39:30.720 --> 39:35.600
So how long does it usually take before you can get source code from companies?

39:36.320 --> 39:42.400
Yeah, so that is a good question. I think it depends where and how you ask like in the case of the

39:42.400 --> 39:49.040
AVM lawsuit, which was brought by Sebastian the plaintiff, but which we funded and provided support for.

39:49.760 --> 39:55.200
That was a situation I think approximately two or three years from the time that the

39:55.920 --> 40:01.520
violation was first uncovered until the complete source code was received. And that could be a difference

40:01.520 --> 40:07.360
in, for example, the efficiency of the German legal system versus the US legal system or a number of

40:07.360 --> 40:13.440
other things. But yeah, that would be an example of when it maybe took a different amount of time.

40:13.440 --> 40:17.600
And you know, conservancy has been involved in different lawsuits over over time.

40:19.600 --> 40:27.600
Around the 2010s, for example, where it was more in the order of a few years versus like 10 plus

40:27.600 --> 40:33.760
years. But also, you know, it does speak to how we are, you know, we're not quick to assume

40:34.080 --> 40:41.840
the worst, you know, we would like to make sure that we know that there is an issue. We confirm it.

40:41.840 --> 40:47.120
And certainly, you know, if we receive multiple reports about the same company that does increase the

40:47.120 --> 40:54.400
priority to us. So for anyone who does have devices where they have not received source code or

40:54.400 --> 41:00.080
the source code is incomplete, please do tell us about that. Email compliance at sfconservancy.org

41:00.480 --> 41:06.720
because, you know, the more reports we get about a device than, you know, the more important we know

41:06.720 --> 41:10.960
that it is to the community to get the source code for that.

41:12.160 --> 41:18.240
All right, another question here. Thank you. So you finally get the source code by visual.

41:18.240 --> 41:22.960
Is that a way that we can guarantee that that source code matches the binary that was

41:22.960 --> 41:28.800
distributed initially? Or maybe they would have extracted some source code of some

41:28.800 --> 41:33.280
fishy thing that we're doing and then sell us that the source that they provide it is the

41:33.280 --> 41:40.400
one that is bundled when it's not. So yeah, the question sounds like it's roughly asking about

41:40.400 --> 41:46.720
how do we determine that the source code is complete and corresponding to the binaries that we receive.

41:46.720 --> 41:55.120
So there are a number of ways that we can do that. Now the GPL and LGPL use the term corresponding.

41:55.120 --> 42:01.120
And so there's not like a requirement for reproducible builds. For example, like it doesn't

42:01.120 --> 42:06.240
have to be bit forbid identical. But yeah, there are a number of things we would do to confirm that

42:07.360 --> 42:13.760
that the binaries are corresponding, such as trying to run them and determining if they have

42:13.760 --> 42:19.360
the same general functionality. Also, you know, doing some binary analysis to see if the binaries

42:19.360 --> 42:24.720
are quite similar, even if they're not the same. But yeah, those are the general steps that we

42:24.720 --> 42:31.760
do to confirm that. And generally, that's been pretty successful in the past at analyzing these situations.

42:33.280 --> 42:41.360
Oh, okay. So you mentioned that you had success with Samsung. Do you know if

42:41.360 --> 42:47.600
new Samsung TVs have released the full necessary source code or how do you ensure compliance

42:47.600 --> 42:50.800
if they release, you know, a visual comes along in a couple of years, releases a new TV,

42:50.800 --> 42:57.440
you have to sue them again? Yeah. So that is a good question. And you can actually go

42:57.440 --> 43:03.040
on use the source. And you can find other Samsung source code candidates on use the source

43:03.040 --> 43:09.040
from more recent televisions. And I have not analyzed them in great detail. But other people

43:09.040 --> 43:15.760
have contributed their own analyses of them. And their analyses would suggest to me that

43:15.920 --> 43:22.960
the newer Samsung TVs are not in compliance. But yeah, that is a thing that happens. And

43:24.080 --> 43:30.480
I would certainly agree that it's frustrating. And it could be a situation where

43:31.280 --> 43:35.600
another lawsuit might be necessary. But it, you know, it depends how the follow-up would go

43:36.000 --> 43:41.360
with the company, of course, because, you know, we don't sue unless it's necessary. We always

43:41.440 --> 43:48.400
contact a company first and give them a good amount of time to resolve the situation before

43:48.400 --> 43:56.080
we would ever consider that. So yeah, I mean, I am hopeful that companies do and will learn from

43:56.080 --> 44:03.120
these sorts of situations. And I mean, if you do work inside of a company that's where you, you,

44:03.120 --> 44:08.080
you know, are concerned about some of these things that are happening, perhaps like make,

44:08.400 --> 44:12.880
make them aware of the work that software freedom Conservancy is doing because sometimes companies

44:13.680 --> 44:19.680
only understand risk. And if you say, well, it is risky for you to not provide the complete

44:19.680 --> 44:24.000
source code because of all of these things that are happening with companies that are not

44:24.000 --> 44:29.840
providing the complete source code, that may help encourage them to change their analysis and to

44:29.840 --> 44:35.760
provide that complete source code. So they, you know, don't have unfortunate consequences.

44:36.400 --> 44:46.240
Yeah, so. Hi, thanks. So my understanding is that one of the main points is the installation

44:46.240 --> 44:51.280
on the actual physical device. And from my reading is that there's probably some cryptographic

44:51.280 --> 44:57.200
keys or something like that, you need to actually do that. Can you go into details about that?

44:58.080 --> 45:08.000
Sure. So the GPL version 2 and the LGPL version 2.1 say nothing one way or the other about keys.

45:09.040 --> 45:14.400
But they do talk about install. And so the thing that we've noticed on a lot of devices that

45:14.400 --> 45:24.160
would ostensibly require some key material is that you can simply remove the portion

45:24.160 --> 45:31.360
of whatever bootloader or other thing does key verification. You know, you can either flash it

45:31.360 --> 45:36.800
with a shim or do something else like that. And so, you know, that is the sort of thing that we

45:36.800 --> 45:44.080
would expect in this situation. You know, we're not asking for keys. We're just asking to install things.

45:44.080 --> 45:48.880
And you know, there have been things that have come up in the lawsuit where at least it suggests

45:48.880 --> 45:54.160
to me that that busier was maybe worried about like leaking keys from that they might have from

45:54.160 --> 45:59.440
Netflix or something else like that. And to be clear, we are not asking for any of those keys.

45:59.440 --> 46:06.000
You know, busier was free to delete all of those keys so that we don't have any access to those

46:06.000 --> 46:11.040
keys. That's not anything we're asking for. It's not something we think they have to give up or

46:11.040 --> 46:17.280
anything. And so I would think that there would be no agreement that they might have with someone

46:17.360 --> 46:22.960
about these keys that they would be violating if they gave us the rights that we are asking for.

46:24.320 --> 46:34.240
In the last question. So just to clarify, is the SFC arguing that you should be able to

46:34.240 --> 46:42.400
install a modified version or the device and that it should work properly after installing it on the

46:42.560 --> 46:50.080
device. Yes, that's right. So for example, any of the programs under the GPL or LGPL, for example,

46:50.080 --> 46:56.080
like Linux and Busybox, should continue to work properly after they have been reinstalled onto the

46:56.080 --> 47:03.520
device. So if we, you know, get all those components built and then installed and then the TV boots

47:03.520 --> 47:10.240
into a prompt. And you know, there's no user interface because perhaps that was all proprietary.

47:10.240 --> 47:15.840
That's totally fine. That would be fine with us. And that's what we're looking for. We would be

47:15.840 --> 47:22.640
fine. And I'm sure there would be a lot of developers who would be interested in putting some

47:22.640 --> 47:29.040
TV design software or otherwise onto the TV at that point. And the other part of the room,

47:29.040 --> 47:34.640
another question. So you talked about the fact that the, the, the, the video had binaries using

47:34.720 --> 47:40.000
copy-lefted code. So A, how did you know that those binaries had copy-lefted code? And B,

47:40.000 --> 47:43.680
how did you know that that code was modified? And they, they weren't just conveying of a

47:43.680 --> 47:54.480
bait and copy of the copy-lefted code, which would be fine. So B. So there's a couple things there.

47:54.480 --> 48:02.720
So how did we identify them first of all? Is that, you know, if you take a look at say,

48:03.680 --> 48:09.680
a Linux image, like the U image file or whatever it might be, if there are generally strings in there that

48:09.680 --> 48:16.240
identify it as being Linux. And, you know, if you attach a serial console or something, you can see

48:16.240 --> 48:21.840
the usual Linux boot messages. So that would be, those would be examples of how we would determine

48:21.840 --> 48:27.520
that these are in use similarly for busy box, you know, it tells you it's busy box in the binary itself.

48:28.480 --> 48:35.760
And then in terms of, so, so your question then was about, you know, whether they would have to

48:35.760 --> 48:43.520
convey the source if it was unmodified. Well, as far as I know, there is no information in the

48:43.520 --> 48:51.360
upstream kernel that would describe how to compile and install the kernel on a video television.

48:51.360 --> 48:57.360
So there must be something that they've added to the kernel source code that would

48:57.440 --> 49:00.720
allow them to achieve that. And so that is what we are asking for.

49:03.360 --> 49:12.480
All right, is there any other question? Well, then there's a, like it's a final one.

49:17.440 --> 49:22.240
How binding do you think it is that they set the module license on all those kernel modules to

49:22.240 --> 49:27.120
GPL? Because they just claim that, oh, that's what the file had in it. When I started editing it,

49:27.120 --> 49:31.680
or whatever, do you think that's material that they have to claim it's GPL?

49:31.680 --> 49:36.960
I mean, it's, it's something they might claim. I think, you know, again, I'm not a lawyer.

49:36.960 --> 49:40.960
Don't provide legal advice, you know, can't make legal opinions on things.

49:42.160 --> 49:46.160
I mean, to me, it seems pretty obvious. I mean, it's someone had to write

49:46.160 --> 49:52.880
module license, brackets, GPL in that file at some point. And so to me, that seems like

49:52.880 --> 50:00.160
pretty explicit, you know, agreement that it is licensed under the GPL, but who knows? I expect

50:00.160 --> 50:07.040
they'll have some arguments at trial. I suspect they will be unconvincing, but I guess we'll see what

50:07.040 --> 50:14.400
happens. I did just want to note here that if you do want to use the QR code here, that does

50:15.040 --> 50:20.400
bring you to the Sustainer website that I mentioned earlier. And also, there is slide source code

50:20.400 --> 50:25.440
available at the link there. If you go to the talk URL and then go to the last slide, you can click

50:25.440 --> 50:31.520
on that. To get the source code for the slides, as you might expect for a talk for me. And if there

50:31.520 --> 50:38.000
were no other questions, then there's a big applause for that. Thank you.

