Shareware BoxA site about free software's licences, its plumbing and who pays for it.
FILE 02 — THE PLUMBING
27 ENTRIES ON RECORD
OPEN — NO CLOSING DATE

Four projects changed their licence, the industry forked all four, and the library underneath it all had one maintainer.

Close-up of a Dell motherboard showing capacitors, chips and an open CPU socket
PLATE 01The discovery was a performance complaint: several hundred milliseconds of unexplained CPU time in an SSH login, chased down by somebody benchmarking a database.Photo: Pok Rie / Pexels

The xz/liblzma backdoor, assigned CVE-2024-3094, was discovered in March 2024 by Andres Freund while investigating an SSH login slowdown on a Debian testing machine.

SEVERITY 10.0

Exhibit A — the licence header, at the size it actually matters

Annotated · 3 marks
A licence file — its SPDX header and copyright notice clearly visible — displayed in a terminal window on a large monitor, shot at an angle that shows both the text and the room behind it
EXHIBIT AEverything downstream — package managers, build systems, corporate policy — reads this block and nothing else.Photo: Pixabay / Pexels
MARK 1 Who holds the copyright, and therefore who can change these terms without asking anybody.
MARK 2 The identifier itself — the one line every automated build reads and most readers never open.
MARK 3 Whether the licence sits on the OSI's approved list, which is where the argument keeps returning.

Three lines in a header decided four forks in eighteen months. The lever is the contributor agreement.

Stewards of open licensing

Supporters of the Plumbing file

Also supporting

F-Droid has compiled every application in its main repository on its own machines since 2010 — the only large channel where the binary is produced by the people who publish the source.

Source — F-Droid's published inclusion policy · read the entry

Plates 02–07, filed with the sections they belong to

Six entries

The record, as it was filed

Six fields
RECORD — CVE-2024-3094SEVERITY 10.0
Component
xz Utils 5.6.0, 5.6.1
Reported
29 March 2024
By
Andres Freund, to oss-security
Reached
Rolling branches only
Fix
Revert to the 5.4 series
Maintainers at the time
One, unpaid

CVE-2024-3094: Two Years to Plant, One Benchmark to Find

Open the file ›
  1. 24 Feb 2024xz Utils 5.6.0 released, carrying the backdoor
  2. 9 Mar 20245.6.1 released; Debian Sid and Fedora Rawhide ship it
  3. 29 Mar 2024Reported to oss-security; affected branches reverted to the 5.4 series
A hand signs a contract on the line marked "signature" with a pen
A signature on a contributor agreement is what makes a unilateral relicence possible.Photo: Pixabay / Pexels

The Licence Fights

The CLA Is the Lever: How Contributor Agreements Enable Relicensing

A Contributor Licence Agreement transfers or licenses copyright to the project steward, which is why HashiCorp and Elastic could relicense unilaterally while OpenTofu and OpenSearch required forks: they lacked consolidated copyright.