| |

LFCA 110 ๐Ÿง Copyleft vs Permissive Licenses

Open source licenses fall into two broad philosophical camps: permissive and copyleft. The distinction is not about whether the software is free to use โ€” both allow that โ€” but about what happens to derivative works. Permissive licenses grant broad freedoms with minimal conditions, allowing the code to be incorporated into proprietary products. Copyleft licenses grant the same freedoms but require that derivative works carry the same license, ensuring that the software remains open as it evolves and spreads.

This chapter covers the philosophical foundations of each approach, the specific obligations each imposes, the concept of license propagation, the compatibility issues that arise when licenses are combined, and the practical decision of which approach to use for a given project.

Key point: Permissive licenses (MIT, BSD, Apache 2.0) allow proprietary derivatives with minimal attribution requirements. Copyleft licenses (GPL, AGPL, LGPL, MPL) require that derivative works remain under the same license and that source code be shared. The difference determines whether your code can be incorporated into closed-source products.


Why the distinction exists

The freedom-for-users versus freedom-for-software problem. Permissive licenses prioritize the freedom of users to do what they want with the code, including incorporating it into proprietary products. Copyleft licenses prioritize the freedom of the software itself, ensuring that it cannot be locked away in a proprietary derivative. Both are “free software” under the Free Software Foundation’s definition, but they disagree about what protects freedom in the long run.

The tragedy-of-the-commons problem. If everyone can take from a commons and enclose what they take, the commons shrinks. A developer who releases code under a permissive license may find that a company incorporates it into a proprietary product, improves it, and never contributes the improvements back. Copyleft prevents this by requiring that improvements be shared, keeping the commons from being enclosed.

The adoption-versus-protection problem. Permissive licenses maximize adoption because they remove friction. Companies can use the code without legal review of obligations, and they can combine it with proprietary code without fear of copyleft propagation. Copyleft licenses maximize protection of the commons but reduce adoption by companies that are unwilling to open-source their derivatives. The choice is a trade-off, not a right answer.

The commercial-use problem. A company building a proprietary product cannot use GPL code without either open-sourcing the product or obtaining a commercial license from the copyright holder. This makes GPL a poor choice for libraries intended to be used by proprietary software. Permissive licenses have no such restriction.

The compatibility problem. Different licenses have different obligations, and combining code under incompatible licenses creates legal risk. GPL v2 is incompatible with Apache 2.0, so a project cannot combine GPL v2 code with Apache 2.0 code and distribute the result. GPL v3 is compatible with Apache 2.0. Understanding compatibility is essential when assembling a project from multiple sources.


a. Permissive licenses

Permissive licenses impose minimal conditions on reuse. They grant permission to use, copy, modify, merge, publish, distribute, sublicense, and sell copies of the software, subject to attribution and the disclaimer of warranty.

MIT is the simplest. It requires that the copyright notice and permission notice be included in all copies or substantial portions of the software. There is no requirement to share modifications, no copyleft propagation, and no patent grant.

BSD is similar. The 2-Clause version is nearly identical to MIT. The 3-Clause version adds a restriction against using the names of contributors to endorse derived products without permission.

Apache 2.0 adds an explicit patent grant and a NOTICE file requirement. The patent grant is irrevocable unless the licensee initiates patent litigation. The NOTICE file must be preserved in distributions.

The key characteristic of permissive licenses is that they do not propagate. A derivative work can be licensed under any terms, including proprietary terms. The original code remains under its original license, but the derivative as a whole can be proprietary.

LicenseAttributionPatent GrantSource DisclosureProprietary Derivatives
MITYesNoNoAllowed
BSD 2-ClauseYesNoNoAllowed
BSD 3-ClauseYes + no endorsementNoNoAllowed
Apache 2.0Yes + NOTICEYesNoAllowed

b. Copyleft licenses

Copyleft licenses grant the same permissions as permissive licenses but add a condition: derivative works must be distributed under the same license, and source code must be made available. This condition is what makes copyleft “viral” โ€” it propagates to anything that incorporates the licensed code.

GPL (GNU General Public License) is the canonical strong copyleft license. Any work that is based on GPL code must be licensed under GPL, and the complete corresponding source code must be provided when the work is distributed.

AGPL (Affero GPL) extends copyleft to network use. Where GPL triggers source disclosure on distribution, AGPL triggers it when the software is made available over a network. This closes the “SaaS loophole” where a company could modify GPL software, run it as a service, and never distribute it.

LGPL (Lesser GPL) is weak copyleft designed for libraries. Modifications to the LGPL-licensed library must be shared, but the library can be linked into proprietary applications without requiring the entire application to be open-sourced.

MPL (Mozilla Public License) is file-level copyleft. Modifications to MPL-licensed files must be shared, but the license does not propagate to other files in the larger work.

LicenseScopeSource DisclosureProprietary Derivatives
GPL v2/v3Whole derivative workYes, on distributionNot allowed
AGPLWhole derivative workYes, on network useNot allowed
LGPLLibrary modificationsYes, library onlyAllowed with conditions
MPL 2.0File modificationsYes, modified filesAllowed with conditions

c. License propagation

License propagation is the mechanism by which copyleft licenses extend their terms to derivative works. The scope of propagation determines how much of a combined work is affected.

Strong copyleft (GPL, AGPL) propagates to the entire derivative work. If you link GPL code with proprietary code, the combined work is subject to GPL. The legal interpretation of “derivative work” and “linking” varies, but the practical guidance is that any work that includes GPL code and is distributed must be GPL.

Weak copyleft (LGPL, MPL) propagates only to the licensed component. Modifications to LGPL libraries must be shared, but the application that links to them can remain proprietary. Modifications to MPL files must be shared, but other files in the same project are unaffected.

Permissive licenses do not propagate. The derivative work can be licensed under any terms.

The propagation question is what determines whether a license is suitable for a given use. A permissive library can be used anywhere. A weak copyleft library can be used in proprietary software as long as modifications to the library are shared. A strong copyleft library cannot be used in proprietary software that is distributed.


d. License compatibility

License compatibility is whether two licenses can be combined in a single work. Incompatible licenses cannot be combined without violating one or both.

GPL v2 is incompatible with Apache 2.0. The Apache 2.0 patent retaliation clause adds conditions that GPL v2 does not permit, so a work combining GPL v2 and Apache 2.0 code cannot be distributed. GPL v3 was written to be compatible with Apache 2.0, so GPL v3 and Apache 2.0 code can be combined.

MIT and BSD are compatible with almost everything. Their minimal conditions do not conflict with other licenses. Apache 2.0 is compatible with GPL v3 but not GPL v2. GPL v2 and GPL v3 code cannot be combined in a single work because the licenses are different.

The practical implication is that projects assembling code from multiple sources must verify compatibility. A project that uses GPL v2 code cannot include Apache 2.0 code. A project that uses GPL v3 code can include Apache 2.0 code. A project that uses MIT code can include almost anything.


e. Choosing between them

The choice between permissive and copyleft depends on what you want to happen downstream.

Choose permissive when you want maximum adoption, when the code is a library intended for broad use, when you do not want to impose obligations on users, or when you want companies to be able to build proprietary products on top of your code without legal review.

Choose copyleft when you want to ensure that improvements flow back to the community, when you want to prevent proprietary enclosure of your code, when you are building a project that should remain open in all derivatives, or when you want to use copyleft as leverage for a dual-licensing business model.

Choose weak copyleft when you want improvements to a specific component to remain open but you also want the component to be usable in proprietary applications. LGPL and MPL serve this purpose.

Choose AGPL when you want copyleft to apply to network use as well as distribution. This is appropriate for server software that is offered as a service.


Complete Example Session

# ============================================
# PART 1: IDENTIFY THE LICENSE
# ============================================
ls LICENSE*
head -5 LICENSE
# ============================================
# PART 2: PERMISSIVE LICENSE DETECTION
# ============================================
grep -l "Permission is hereby granted" LICENSE*
# MIT detected
# ============================================
# PART 3: COPYLEFT LICENSE DETECTION
# ============================================
grep -l "GNU GENERAL PUBLIC LICENSE" LICENSE*
# GPL detected
# ============================================
# PART 4: CHECK PROPAGATION SCOPE
# ============================================
# Strong copyleft: whole work affected
# Weak copyleft: component only
grep -i "lesser\|library" LICENSE
# ============================================
# PART 5: CHECK COMPATIBILITY
# ============================================
# GPL v2 incompatible with Apache 2.0
# GPL v3 compatible with Apache 2.0
grep -i "version 2\|version 3" LICENSE
# ============================================
# PART 6: AUDIT DEPENDENCIES
# ============================================
npx license-checker --summary
# ============================================
# PART 7: CHECK FOR COPYLEFT IN PROPRIETARY PRODUCT
# ============================================
npx license-checker --failOn "GPL;AGPL"
# ============================================
# PART 8: GENERATE ATTRIBUTION FILE
# ============================================
npx license-checker --json > licenses.json
# Include in THIRD_PARTY_NOTICES.md
# ============================================
# PART 9: DUAL LICENSING CHECK
# ============================================
# Some projects offer GPL + commercial
grep -i "commercial\|dual" README.md
# ============================================
# PART 10: COMPLIANCE SUMMARY
# ============================================
# Permissive: safe for proprietary
# Copyleft: requires compliance
# Incompatible combinations: avoid

These ten parts cover license identification, permissive vs copyleft detection, propagation scope, compatibility checking, dependency auditing, copyleft prohibition in proprietary products, attribution file generation, dual licensing, and compliance summary.


Quick Reference

Comparison

AspectPermissiveCopyleft
ExamplesMIT, BSD, Apache 2.0GPL, AGPL, LGPL, MPL
AttributionRequiredRequired
Source disclosureNoYes
Derivative licenseAnySame license
Proprietary useAllowedRestricted
PropagationNoneStrong or weak

Propagation Scope

LicensePropagates To
MIT, BSD, Apache 2.0Nothing
MPLModified files only
LGPLLibrary modifications
GPL, AGPLEntire derivative work

Compatibility

CombinationCompatible
MIT + anythingYes
Apache 2.0 + GPL v3Yes
Apache 2.0 + GPL v2No
GPL v2 + GPL v3No
BSD + GPLYes

Choosing a License

GoalLicense
Maximum adoptionMIT
Adoption + patent clarityApache 2.0
Library usable in proprietaryLGPL
File-level copyleftMPL
Ensure derivatives stay openGPL
Close SaaS loopholeAGPL

Best Practices

โœ… Do This:

# Audit dependencies for license types
npx license-checker --summary

# Preserve attribution and NOTICE files
# Check compatibility before combining
# Consult legal for copyleft in proprietary
# Document license obligations

โŒ Don’t Do This:

# Use GPL in proprietary distributed product
# Combine incompatible licenses
# Remove copyright notices
# Assume "open source" means "no rules"

Common Pitfalls

PitfallWhy It HappensFix
GPL in proprietary productUnaware of copyleftAudit dependencies
Incompatible license combinationNot checkedVerify compatibility
Missing attributionNotices removedInclude notices file
AGPL ignored in SaaSNetwork trigger overlookedReview AGPL obligations
LGPL treated as permissiveMisunderstanding weak copyleftShare library modifications

Visual

The License Spectrum

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PERMISSIVE          WEAK COPYLEFT       STRONG COPYLEFT     โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€         โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€       โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€     โ”‚
โ”‚  MIT                 LGPL                GPL v2/v3           โ”‚
โ”‚  BSD                 MPL                 AGPL                โ”‚
โ”‚  Apache 2.0          EPL                                     โ”‚
โ”‚                                                              โ”‚
โ”‚  Fewer obligations โ—€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ถ More obligations     โ”‚
โ”‚  More adoption                          More sharing         โ”‚
โ”‚  Proprietary OK                         Proprietary NO       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Propagation

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PERMISSIVE:                                                 โ”‚
โ”‚  Your code + MIT code โ†’ Your code can stay proprietary       โ”‚
โ”‚                                                              โ”‚
โ”‚  WEAK COPYLEFT:                                              โ”‚
โ”‚  Your code + LGPL library โ†’ Library changes shared,           โ”‚
โ”‚                             your code stays proprietary      โ”‚
โ”‚                                                              โ”‚
โ”‚  STRONG COPYLEFT:                                            โ”‚
โ”‚  Your code + GPL code โ†’ Entire work must be GPL              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Compatibility

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  MIT โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ compatible with everything                     โ”‚
โ”‚  Apache 2.0 โ”€โ”€ compatible with GPL v3, not GPL v2            โ”‚
โ”‚  GPL v2 โ”€โ”€โ”€โ”€โ”€โ”€ incompatible with Apache 2.0, GPL v3          โ”‚
โ”‚  GPL v3 โ”€โ”€โ”€โ”€โ”€โ”€ compatible with Apache 2.0, not GPL v2        โ”‚
โ”‚  BSD โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ compatible with GPL                            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Choosing a License

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Do you want proprietary derivatives allowed?                โ”‚
โ”‚       โ”‚                                                      โ”‚
โ”‚       โ”œโ”€โ”€ Yes โ”€โ”€โ–ถ Want patent clarity?                       โ”‚
โ”‚       โ”‚            โ”œโ”€โ”€ Yes โ”€โ”€โ–ถ Apache 2.0                    โ”‚
โ”‚       โ”‚            โ””โ”€โ”€ No โ”€โ”€โ–ถ MIT or BSD                     โ”‚
โ”‚       โ”‚                                                      โ”‚
โ”‚       โ””โ”€โ”€ No โ”€โ”€โ–ถ Do you want derivatives to stay open?       โ”‚
โ”‚                    โ”œโ”€โ”€ Yes โ”€โ”€โ–ถ GPL                           โ”‚
โ”‚                    โ”‚                                         โ”‚
โ”‚                    โ””โ”€โ”€ Network use? โ”€โ”€โ–ถ AGPL                 โ”‚
โ”‚                                                              โ”‚
โ”‚  Library usable in proprietary? โ”€โ”€โ–ถ LGPL or MPL              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Summary

ItemValue
PermissiveMinimal conditions; proprietary derivatives allowed
CopyleftDerivatives must use same license; source shared
Strong copyleftGPL, AGPL; propagates to entire work
Weak copyleftLGPL, MPL; propagates to component only
MITSimplest permissive; attribution only
Apache 2.0Permissive + patent grant
GPLStrong copyleft; source disclosure on distribution
AGPLNetwork copyleft; source disclosure on network use
LGPLWeak copyleft for libraries
PropagationScope of copyleft obligation
CompatibilityWhether licenses can be combined

Key takeaways:

  • Permissive licenses allow proprietary derivatives. MIT, BSD, and Apache 2.0 grant broad freedoms with only attribution requirements. They do not propagate to derivative works .
  • Copyleft licenses require derivatives to remain open. GPL, AGPL, LGPL, and MPL require that derivative works carry the same license and that source code be shared. The scope of this requirement varies by license .
  • Strong copyleft propagates to the entire work. GPL and AGPL affect everything that incorporates the licensed code. A proprietary application that links GPL code must be released under GPL .
  • Weak copyleft propagates only to the component. LGPL and MPL affect the licensed library or file but allow the larger application to remain proprietary. Modifications to the licensed component must be shared .
  • License compatibility matters. GPL v2 is incompatible with Apache 2.0. GPL v3 is compatible with Apache 2.0. MIT and BSD are compatible with almost everything. Combining incompatible licenses creates legal risk .
  • The choice depends on goals. Permissive licenses maximize adoption and allow proprietary derivatives. Copyleft licenses ensure that improvements flow back to the community and prevent proprietary enclosure.
  • Auditing is essential. Organizations must track the licenses of all open source components and ensure that their use complies with the terms. License scanning tools automate this process .

Remember: The distinction between permissive and copyleft is about what happens downstream. Permissive licenses say “do what you want, just give credit.” Copyleft licenses say “do what you want, but derivatives must remain open.” Neither is better in the abstract; they serve different goals. Permissive licenses are appropriate when you want your code to be widely adopted, including by companies building proprietary products. Copyleft licenses are appropriate when you want to ensure that your code and its improvements remain open source forever. Weak copyleft licenses are appropriate when you want a library to be usable in proprietary applications but also want improvements to the library to be shared. Understanding these distinctions, and the compatibility issues that arise when licenses are combined, is essential for anyone working with open source software.



Stop using slow, ad-bloated tool sites! ๐Ÿคฎ

๐Ÿ”Ž Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
โœ… Finance (Mortgage, Interest, Inflation)
โœ… Tech (Base64, JSON, Dev Suite, IP)
โœ… Health (BMI, BMR, TDEE)
โœ… Productivity (Timer, Workspace, QR)

โšก๏ธ Fast & Private
๐Ÿ”’ No data leaves your device
๐Ÿ’Ž 100% Free

๐Ÿ”— Use it now: https://tools.kandz.me
๐Ÿ”– Bookmark itโ€”youโ€™ll need it later!