Skip to content

Prior art survey — commercial-trigger/reciprocity licenses & ethical-source lineage #6

Description

@zackees

Note

AI-generated first-pass legal review — not legal advice. Produced by Claude (Fable 5 coordinator; Opus agents for hard legal-analysis clusters, Sonnet agents for drafting/ecosystem clusters and prior-art research) against the repo at HEAD of main on 2026-08-24. This is input material for the human attorney review gated by LEGAL-REVIEW.md. Severity ratings: CRITICAL / HIGH / MEDIUM / LOW.

Research fan-out covering the reciprocity/commercial-trigger lineage and the ethical-source lineage. Companion prior-art issue covers RAIL-family AI-model licenses and machine-directed instruction files.

Reciprocity / commercial-trigger prior art

Parity Public License

Steward: Kyle E. Mitchell / License Zero. paritylicense.com, SPDX

Trigger: Not distribution and not sale — building with the software. Conveying a derivative, or another work that "requires" the licensed software, owes reciprocity. Written to close the ASP, private-changes, and developer-tools loopholes AGPL/GPL leave open. What/where: source to anyone who receives the object code — a "give it to your recipients" model, not publish-to-upstream. OSI: not approved (deliberately drafted outside the OSD). Adoption: modest; no litigation.
Relevance: Best precedent for scope (loophole-closing), weak precedent for the sale trigger.

Reciprocal Public License 1.5 (RPL-1.5)

Steward: Technical Pursuit Inc. OSI, SPDX, Wikipedia

Trigger: Deployment, not distribution — explicitly closes the internal-use loophole; covers Modifications "deployed in any form — either internally or to an outside party." What/where: all authored components must be made available via an "electronic distribution mechanism" and the licensee must proactively notify the community (newsgroup/weblog-style public channel) — an affirmative public-notification duty on top of availability. Timing: publish within one month of deployment; keep available at least twelve months after deployment ceases. OSI: approved (2001; v1.5 2007). Adoption: rare outside TPI; a design curiosity.
Relevance: Closest prior art for the "publish, don't just distribute" mechanism — trigger broader than conveyance + affirmative public notification, structurally nearest to FastLED's "public fork or public bug-report." The 1-month/12-month window is the key timing comparator for FastLED's stricter same-day rule.

Cryptographic Autonomy License (CAL-1.0)

Steward: Holochain Foundation (Van Lindberg). OSI, SPDX

Trigger: Conveyance or network-service use (AGPL-style). What/where: expansively-defined Source Code including config, docs, and cryptographic seeds/keys — the "data autonomy" clause is CAL's novel contribution. Timing: availability persists while the license is exercised plus at least one year. OSI: approved Feb 2020 — controversial; contributed to Bruce Perens' resignation from OSI. Adoption: Holochain; limited elsewhere.
Relevance: Precedent that OSI can approve a novel non-code obligation bolted onto a copyleft base — barely, and with controversy.

Server Side Public License (SSPL)

Steward: MongoDB. Text, Wikipedia

Trigger: Offering the program as a service. What/where: the entire service stack under SSPL — the most aggressive share-scope surveyed. OSI: rejectedOSI: "the SSPL is not an open source license" (OSD #6/#9); MongoDB withdrew the request in 2019. Adoption: MongoDB, Elastic (2021) → AWS forked OpenSearch; no court test.
Relevance: Direct precedent that OSI refuses a license whose trigger is field-specific — a sale trigger invites the same OSD #6 objection ("discriminates against the field of selling hardware"). Expect classification as "source-available."

Commons Clause

Steward: Drafted by Heather Meeker; deployed by Redis Labs, Neo4j. commonsclause.com

Trigger: "Sell" — providing to third parties, for a fee or other consideration, a product/service whose value derives substantially from the software. The field's clearest precedent for a commercial-consideration trigger — closest analog to FastLED's "sale" concept, though Commons Clause forbids the activity rather than conditioning it on publishing source. OSI: not compliant, self-acknowledged source-available. Adoption/enforcement: Redis Labs 2018 → instant community backlash and forks; Redis replaced it with RSAL within ~6 months (RedMonk).
Relevance: Key cautionary precedent — "Sell" as a bright-line trigger is well-precedented and easy to draft, but pairing it with prohibition caused fast, severe backlash. FastLED's disclosure-not-prohibition design is structurally gentler; emphasize that distinction.

Elastic License 2.0 (ELv2)

Steward: Elastic NV. Text

Trigger: hosted/managed service exposing substantial functionality; plus anti-circumvention and notice-preservation. What/where: no disclosure obligation at all — pure use restriction. Adoption/enforcement: Jan 2021 move to block AWS → AWS forked Elasticsearch 7.10.2 into OpenSearch (100M+ downloads year one). Elastic returned to open source (AGPL) in 2024 — an implicit admission the restrictive license cost more in ecosystem goodwill than it protected in revenue.
Relevance: Second major cautionary tale — even a narrowly-targeted commercial-actor trigger provoked a full fork, multi-year reputational cost, then reversal.

Business Source License (BUSL/BSL 1.1)

Steward: MariaDB Corporation. mariadb.com/bsl11, SPDX

Trigger: production/competitive use per the licensor's customizable "Additional Use Grant." Timing: the Change Date (≤4 years) converts the code to an OSI license — the inverse of FastLED's same-day rule: BUSL delays openness, FastLED accelerates it. Adoption/enforcement: very high (MariaDB, CockroachDB, HashiCorp 2023). HashiCorp's Terraform relicensing from MPL-2.0 to BUSL is nearly a dry run of FastLED's risk profile: 32K+ stars on the backlash manifesto, a Linux Foundation fork (OpenTofu) within weeks, later C&D/infringement-claim skirmishes (OpenTofu manifesto, Forbes).
Relevance: The single most important precedent for relicensing a well-known MPL-2.0 project with added commercial terms. Key lesson: announce with maximum clarity and grandfather existing versions — "little or no advance notice" was the specific community complaint.

Functional Source License (FSL) / Fair Source

Steward: Sentry (with Heather Meeker). fsl.software, Sentry announcement

Trigger: BUSL-shaped, two-year change date converting to Apache-2.0/MIT. The industry trend-line on "reasonable embargo" is compressing (4yr → 2yr) — which supports framing FastLED's zero embargo as the continuation of a visible trend rather than a break. OSI: not approved; Sentry deliberately coined "Fair Source" as a separate category, conceding the OSD question rather than contesting it.
Relevance: A credible company choosing to brand a new category instead of claiming "open source" — a path FastLED should consider explicitly.

PolyForm Project licenses (Shield, Perimeter, Noncommercial, Internal Use, Small Business)

Steward: PolyForm Project (Mitchell, Meeker, Villa et al.). polyformproject.org

Standardized modular use-restriction terms; no disclosure/copyleft obligation in any variant. Not OSI-approved.
Relevance: Evidence of convergence on standardized modular terms; FastLED's design is closer in spirit to RPL/CAL (disclosure duty) than to PolyForm (pure restriction) — worth stating explicitly.

Prosperity Public License

Steward: Kyle E. Mitchell / License Zero. prosperitylicense.com

Trigger: commercial use beyond a 30-day company-wide trial — the cleanest noncommercial/commercial dividing-line precedent, with an honor-system grace window. No source-disclosure duty; the commercial mechanism is pay-for-a-license. Not OSI-approved.
Relevance: Mitchell's portfolio treats "share it" (Parity) and "pay for it" (Prosperity) as independent levers — FastLED fuses them (sell it → must have already shared it), a genuinely novel combination not seen in either license alone.

MPL-derived custom licenses: CDDL and the rename-and-extend path

Steward (CDDL): Sun Microsystems (now Oracle). Wikipedia, FOSSA explainer

CDDL is the highest-profile precedent for taking MPL text, renaming it, and layering modified terms — built from MPL 1.1, OSI-approved January 2005. MPL 2.0's modified-versions clause was written to formalize what CDDL did improvisationally. Lower-profile same-pattern examples: Adaptive Public License, SugarCRM Public License, Zimbra Public License — all MPL-lineage forks with bespoke attribution/patent/anti-competitive riders. None attempted a sale-triggered disclosure clause — making FastLED's specific combination (MPL base + sale-triggered disclosure) apparently unprecedented within the "MPL + appended terms" lineage, even though the construction method is well-trodden and OSI has approved at least one such derivative (CDDL).

Honorable mentions

  • Sybase Open Watcom Public License 1.0 (SPDX): deployment-triggered (beyond internal R&D/personal use); source of deployed modifications publicly available for 12 months from deployment or as long as deployed, whichever is longer. OSI-approved, essentially unused. A second independent precedent (with RPL) that ~12 months is the industry floor for publication-retention in this family.
  • Open Software License (OSL) / AFL (Lawrence Rosen; OSL 3.0 rationale): "External Deployment" trigger including network use, predating AGPLv3; OSI- and FSF-approved. Precedent that trigger-broadening beyond bare distribution is not inherently disqualifying — the disqualifying factor (per SSPL) is field-of-endeavor discrimination, not trigger breadth per se.
  • AGPL (Wikipedia): the canonical trigger-broadening precedent; OSI/FSF-approved and broadly adopted, yet still "the license nobody's legal department will approve" — proof a broadened trigger can be mainstream-approved and still depress commercial adoption, a dynamic FastLED's sale-trigger will replicate in miniature.

Synthesis

Closest prior art, in combination: No single license matches FastLED's design; it sits at the intersection of three lineages. RPL-1.5 is the closest match for mechanism (deployment-triggered publication duty + affirmative public-notification + defined timing window). Commons Clause is the closest match for trigger vocabulary ("Sell," consideration-for-value-derived). CDDL is the closest match for construction method (MPL-lineage rename-and-extend, OSI-reviewed). FastLED's license is best understood as RPL's disclosure mechanism + Commons Clause's "Sell" trigger, built on MPL via the CDDL-precedented rename path — a combination that, per this survey, has not been attempted before.

Top 3 lessons:

  1. A sale/commercial trigger will very likely draw an OSD Prior art survey — commercial-trigger/reciprocity licenses & ethical-source lineage #6 objection, and this is well-precedented — it's why OSI rejected SSPL and why BSL/ELv2/Commons Clause/PolyForm never sought approval. Plan to market this as "MPL-2.0 plus source-available commercial terms" rather than unqualified "open source" — the linguistic move Sentry made with "Fair Source." Conceding the OSD point pre-emptively costs less credibility than a public OSI rejection à la MongoDB.
  2. Disclosure obligations provoke far less backlash than use-restrictions — an empirically tested distinction. Every license that triggered a major fork (Commons Clause → Redis forks, SSPL/ELv2 → OpenSearch, BUSL → OpenTofu) forbade an activity. RPL, CAL, and Parity — publish/share duties only — have essentially no fork or backlash history. FastLED's "you may sell freely; you must simply have already published" sits in the low-backlash category; state that distinction prominently in any announcement, because communities react to the headline faster than the fine print.
  3. Same-day/no-grace-period timing is aggressive relative to every comparable precedent. RPL gives 1 month; Watcom obligates only at deployment; BUSL/FSL embargo for 4/2 years in the opposite direction. No surveyed license requires same-day public availability at the trigger. The zero-day requirement is the single least-precedented design parameter in the whole proposal — keep a fallback design (e.g., a 30-day cure window analogous to Prosperity's) in case zero-grace proves unworkable for hardware manufacturing lead times.

Ethical-source prior art

Hippocratic License (1.x–2.1) / Hippocratic License 3.0 (HL3)

Steward: Coraline Ada Ehmke (2019); Organization for Ethical Source (OES), HL3 drafted with Corporate Accountability Lab. Links: firstdonoharm.dev, ethicalsource.dev/projects/hippocratic-license-3, GitHub.

Mechanism: MIT-derived permissive license conditioning use on not violating "universal standards for human rights," anchored to named international instruments (UDHR, ICESCR, ICCPR, ILO). HL3 is modular: a core text plus 16 optional add-on modules (environmental justice, labor rights, supply-chain ethics, …). HL3 also added a private right of action letting alleged victims of covered violations sue for license breach directly.

Obligation & who bears it: A legal condition on every downstream licensee — breach terminates the grant (standard conditions-not-covenants copyleft structure).

Enforceability track record: Never litigated. FSF classifies it non-free; OSI has stated software under it is not open source (fails OSD §6). Bruce Perens' widely-cited critique, "Sorry, Ms. Ehmke, the 'Hippocratic License' Can't Work": state actors capable of the targeted abuses will ignore a copyright condition, and vague human-rights standards create real compliance risk for ordinary companies. npm/SPDX tooling historically flagged the license string as invalid. Adoption real but niche. See also Corporate Accountability Lab on HL3.

Relevance to FastLED: Closest precedent for a legally-binding ethics condition riding on an otherwise-permissive base. HL3's modularity is a direct analog for optional AI-behavior addenda. But everything in HL3 is a legal condition — no split between normative and legal layers; no sale-trigger (use-based, permanent, distribution-agnostic).


Do No Harm License (née Just World License)

Steward: Community-originated, predates and informed the Hippocratic License. P2P Foundation wiki, HackerNoon origin essay.

Mechanism: Restricts use "to promote or profit from violence," environmental harm, and similarly broad unethical-purpose categories — a precursor prototype for the Hippocratic lineage. Minimal adoption; no enforcement history.

Relevance: Shows the movement's genealogy — iterating from vague "no harm" language toward HL3's legally precise text specifically because vague ethical clauses were seen as unenforceable/ambiguous. FastLED's non-remedial AI instructions should learn from this drift toward precision even while choosing the opposite (non-remedial) path.


Anti-Capitalist Software License (ACSL)

Steward: Everest Pipkin and Ramsey Nasser. anticapitalist.software, ScanCode entry, Vice coverage.

Mechanism: Explicitly not open source. Grants use to individuals, worker co-ops, nonprofits, NGOs; denies use to for-profit entities as the license defines them. Commercialization is allowed if the organizational structure qualifies — ethics is about organizational form, not act of sale. Adoption confined to indie/art/games projects; no litigation.

Relevance to FastLED: Contrast case — ACSL conditions legal permission to use on who you structurally are, not on what you do after a trigger event. Confirms identity/economic-structure field-of-use restrictions are a known but adoption-poor pattern OSI/FSF reject outright.


996.ICU / Anti-996 License

Steward: Community (996.ICU); Anti-996 License drafted by Katt Gu, advised by Suji Yan. 996.ICU repo, Anti-996-License repo.

Mechanism: MIT-derived, adding a condition of compliance with labor law where the licensee is incorporated and operates — targeting China's 996 overtime culture. ~75 GitHub projects at peak (2019); Vue.js/React discussed but did not adopt (vuejs/vue#9791); no GitHub license-picker recognition; no litigation; faded post-2020.

Relevance to FastLED: The most probable adoption arc for a legally-binding ethics condition on a permissive base: fast community enthusiasm, zero major-project adoption, no test litigation, multi-year fade.


JSON License — "The Software shall be used for Good, not Evil" (Douglas Crockford, 2002)

Links: json.org/license.html, Black Duck analysis, Debian jsonevil page.

Mechanism: MIT plus one sentence with undefined terms ("Good"/"Evil"). Crockford publicly admits the clause is "intentionally vague and unenforceable" and granted one-off exceptions (IBM "and its minions" may use JSLint "for evil").

Enforceability/adoption: Never litigated — but the practical effect was years of real compliance friction: Apache put JSON-licensed code in Category X (banned); Google stopped hosting JSON-licensed projects and rewrote Android's JSON support from scratch specifically to avoid the clause; Debian/Fedora flag it non-free.

Relevance to FastLED: The single closest textual precedent to "we admit this instruction has no legal teeth" — and the lesson is a warning: even a clause its own author calls unenforceable generated bans and rewrites because downstream legal teams couldn't be certain a court would agree it's meaningless. FastLED's in-license non-remedial disclaimer is more honest than Crockford's informal disclaiming, but expect similar "legal can't clear this" friction unless the disclaimer is airtight and prominent.


Ethical Source Principles / ethicalsource.dev movement

Steward: Organization for Ethical Source (Coraline Ada Ehmke, Dec 2020). ethicalsource.dev, Wikipedia: OES.

Mechanism: The seven Ethical Source Principles are a movement manifesto — explicitly not a license and not legally binding. OES's "ethical stack" is three independently-adoptable layers: (1) non-binding Ethical Source Principles, (2) Contributor Covenant (code-of-conduct governance document, also not a license), (3) legally-binding licenses (Hippocratic). Enforcement at the first two layers is social/community pressure only.

Adoption: Contributor Covenant is genuinely, widely adopted (a large share of major open-source projects) — OES's overwhelming success story by a wide margin. The Principles have modest adoption; the Hippocratic License is the least-adopted layer.

Relevance to FastLED — the key precedent for the "normative but not legal" split. OES's three-tier architecture is functionally the closest thing that exists to FastLED's structure: a deliberate separation between a non-binding normative/behavioral layer and a legally binding license layer, same steward, same underlying goal. The crucial data point is the adoption asymmetry: the non-binding layer succeeded at scale; the binding ethics layer lagged — direct evidence that a non-remedial companion document can achieve far broader uptake than an enforceable ethics condition.


OSI / FSF position and the Kyle Mitchell critique

Sources: OSI OSD, Kyle E. Mitchell: This Mess We're In, Ethical Subcommons Starter Kit, Outer Source; Heather Meeker, "Good and not Evil: the Advent of Ethos Licensing".

OSI/FSF position: OSD §6 and FSF's four freedoms categorically reject use-based ethical conditions — a hard, consistent institutional line.

Mitchell's contribution: This Mess We're In argues GPL is already an ethically-motivated, use-discriminating license and that excluding new ethical licenses while grandfathering copyleft is "political and marketing expedience." His Ethical Subcommons Starter Kit proposes a toolkit for ethically-scoped sub-commons he explicitly says could be "reapplied for ethical AI software development" — an early, direct nod to AI-behavior-scoped licensing.

Relevance: The OSD-§6 objection will likely be invoked against FastLED if the AI-upstreaming term were a legal condition; the non-remedial choice likely sidesteps it for that clause — but the sale-triggered publication requirement is still a legal condition and will draw the same scrutiny source-available schemes (BSL/SSPL/Commons Clause) draw.


Responsible AI Licenses (RAIL) / OpenRAIL — cross-reference

Covered in depth in the RAIL-family survey. Key contrast: RAIL puts AI-use restrictions into the legally binding license text (and has adoption because model distributors are the enforcement chokepoint). FastLED does the opposite — its AI-behavior instruction is expressly non-legal — so RAIL is mainly a contrast showing the "make AI conduct a hard legal condition" path is viable but sacrifices OSD/MPL compatibility.


Adjacent commercial-trigger precedents (for the sale-triggered-publication question)

  • Business Source License (BSL 1.1)Wikipedia, SPDX BUSL-1.1. Time-triggered (not sale-triggered): restriction lifts on a change date (≤4 years) and converts to a real open-source license. Withholds source availability during the embargo rather than requiring same-day publication on sale.
  • Bruce Perens' "Post-Open" Zero Cost License (2024) — The Register, FOSS Force. Revenue-triggered: 1% of revenue to a maintainer-payout nonprofit once a company earns >$5M/yr from a paid product using the software — modeled on music performing-rights organizations. The closest found precedent for "obligation keyed to commercial monetization rather than distribution," though the obligation is a royalty, not source publication.
  • Commons Clause / SSPL / Elastic License — restrict resale/hosting outright rather than requiring disclosure; conceptually adjacent (commerce as the dispatch boundary) but the remedy is prohibition, not publication.

Relevance: No prior license found — ethical-source or commercial — conditions a same-day public source-publication duty specifically on a sale event. BSL triggers on a date; Post-Open triggers on a revenue threshold and pays money rather than publishing code; neither is framed as ethics. This appears to be a genuinely novel trigger design.


Synthesis

Closest prior art, overall: The Organization for Ethical Source's three-tier "ethical stack" (non-binding Principles → non-binding Contributor Covenant → binding Hippocratic License, all from one steward) is the closest existing precedent for FastLED's core structural move: deliberately separating a normative/behavioral layer from a legal/remedial layer within one coherent program. Secondary precedent for the "we admit this is unenforceable" posture: the JSON license's "Good, not Evil" clause. For AI-specific binding ethics conditions: RAIL/OpenRAIL. No prior art for a sale-triggered same-day publication duty; Perens' revenue-triggered Post-Open royalty is the nearest commercial-trigger analog.

Top 3 lessons for FastLED:

  1. The non-binding layer is where the ethical-source movement's one clear win lives — lean into that, don't apologize for it. Contributor Covenant (non-binding) dwarfs the Hippocratic License (binding) in adoption. Making the AI-upstreaming instruction expressly non-remedial isn't a compromise; it replicates the one part of this movement's playbook that worked at scale. Frame it that way publicly.
  2. Vague or undefined ethical terms generate real friction even when explicitly disclaimed as non-binding. The JSON license got Apache Category-X bans and a Google rewrite despite its author calling it a joke — purely on the risk a downstream legal team couldn't be certain a court would agree. FastLED's non-remedial file needs binding-clause-grade drafting rigor — precise scope, explicit "creates no legal obligation and is not incorporated into the license grant" language, structural separation from the MPL terms — or it defeats the point of choosing non-remedial.
  3. The sale-trigger is the actual novel contribution — don't undersell it by association with failed field-of-use licenses. Every binding "ethics" condition surveyed drew the identical OSD §6 objection, and none ties an obligation to a commercial sale event. Position the same-day publication-on-sale mechanism as a distinct, separately-defensible innovation — a source-availability/anti-circumvention mechanism (legally conventional, closer to BSL/SSPL territory with a settled "source-available" bucket) rather than a use-based ethics restriction (the category OSI/FSF have never accepted and with the weakest adoption record of everything surveyed).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions