The Linux-libre 6.12 kernel is now available. Addressing licensing issues with Tuxedo drivers

The Latin American Free Software Foundation has released a fully free version of the Linux kernel 6.12 — Linux-libre 6.12-gnu, cleaned of firmware and driver elements containing non-free components or code sections restricted by the manufacturer. In addition, Linux-libre disables kernel features for loading external non-free components not included with the kernel, and removes references to the use of non-free components from the documentation.

To clean the kernel of non-free parts, the Linux-libre project has created a universal shell script that contains thousands of templates to identify the presence of binary inserts and exclude false positives. Ready-to-download patches created based on the use of the aforementioned script are also available. The Linux-libre kernel is recommended for use in distributions that meet the Free Software Foundation's criteria for building fully free GNU/Linux distributions. For example, Linux-libre is used in such distributions as Dragora Linux, Trisquel, Dyne:Bolic, gNewSense, Parabola, Musix, and Kongoni.

The Linux-libre 6.12-gnu release adds code for cleaning blobs in drivers for the SoC CPM/QE QMC, wireless chips Realtek 8852BE-VT, bluetooth adapters Amlogic, network adapters amcc qt2025, sensors aw96103/aw96105, and TI TLV320AIC31XX codecs. Additional blob cleaning has been performed in drivers for Renesas and Intel ISH (Integrated Sensor Hub) HID xHCI controllers. The code for removing blobs in drivers and MHI PCI host subsystems, Adreno 620/621, r8169, Qualcomm q6v5 remoteproc, rtw8852c, rtw8922a, as well as in dts files for ARM54 chips TI PRU and Qualcomm, has been updated. Cleaning of drivers for wireless cards ks7010 and the Intel SkyLake audio subsystem has been discontinued, as these drivers have been removed from the kernel.

It is noteworthy that one of the drivers was found in the source texts containing executable object code generated from unpublished source texts and embedded as a sequence of hexadecimal numbers. The problematic driver is not explicitly named, but based on the changes, it refers to the presence of shader microcode in the file gfx_v9_4_3_cleaner_shader.h included in the AMDGPU driver. The first such insertion was identified in kernel 6.11 and subsequently proposed for removal by one of the developers, as the source texts were not provided (resulting in a situation where a program licensed under GPL was only available in binary form). However, in kernel 6.12, the specified binary code was retained, and another similar insertion was added to the same driver.

Additionally, the announcement of Linux-libre 6.12 mentions two more events:

  • To be included in the core, a patch has been proposed that blocks Tuxedo laptop drivers from accessing kernel subsystems available only to code licensed under GPLv2 (EXPORT_SYMBOL_GPL). The ability to block was initially introduced to restrict the linking of proprietary drivers with Linux kernel components exported only for modules under the GPLv2 license, but it is successfully bypassed by creating proxy modules that translate proprietary driver access to the necessary kernel APIs. In the case of Tuxedo drivers, the situation is the opposite — despite the fact that Tuxedo drivers are developed separately from the kernel, they are provided under the GPLv3 license, which is, on the one hand, incompatible with GPLv2, but on the other hand, advocates for more freedoms, such as protection against tivoization.

    It is noted that Tuxedo has long offered to change the license for its drivers, but it continued to provide code under the GPLv3 license while indicating in the driver code the macro ‘MODULE_LICENSE(«GPL»)’ instead of ‘MODULE_LICENSE(«GPL v3»)’ to gain access to all kernel subsystems. Tuxedo has agreed with the criticism and changed the license to GPLv2+ for some of its drivers. The change has been applied to the drivers gxtp7380, ite_8291, ite_8291_lb, ite_8297, ite_8297, stk8321, tuxedo_compatibility_check, tuxedo_nb02_nvidia_power_ctrl, and tuxedo_tuxi. More than a dozen drivers have not yet been re-licensed, as changing their license requires obtaining permission from third-party developers.

    The use of ‘MODULE_LICENSE(«GPL»)’ in the code instead of ‘MODULE_LICENSE(«GPL v3»)’ was explained by a Tuxedo representative as being due to the lack of clear explanation in the kernel documentation that the ‘GPL’ marker cannot be used for the GPLv3 license. He also mentioned that the company intends to submit its drivers to the mainline of the Linux kernel and is working on completely rewriting them under the GPLv2 license while taking into account the requirements for kernel components.

  • Kernel developers are discussing the initiative to add the X86_BUG_OLD_MICROCODE flag, which signals that an outdated version of the CPU microcode is being used in the system. When this flag is set, the system is suggested to be viewed as having potential unpatched vulnerabilities. Attempts to equate the state of a system with outdated microcode to having real unpatched vulnerabilities in the code have led to criticism from one of the maintainers of the Linux-libre project.

    According to the maintainer of Linux-libre, the kernel should not infringe on users' rights to refuse unverified proprietary firmware and microcode on their own devices. Discussions about vulnerabilities should be tied to specific fixes in particular versions of firmware, rather than labeling any systems without the latest microcode as vulnerable, regardless of whether vulnerabilities manifest in that system and whether the updated firmware includes vulnerability fixes.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster