Red Hat's new source code policy doesn't violate the GPL itself but makes it harder to verify the company's GPL compliance, angering the open-source community
A (reasonably) condensed version of two weeks' worth of heated GPL argument. — When CentOS announced in 2020 that it was shutting …
Context & Ripple Effects
The arc here runs back to CentOS 8's shutdown in 2020, which removed the free rebuild channel that had kept Red Hat Enterprise Linux honest, and lands on Red Hat's 2023 decision to limit RHEL source code access. Ars Technica's read is precise: the policy stays inside the letter of the GPL, but by restricting who can see the source it makes it practically impossible for outsiders to verify Red Hat's compliance with the license — turning a legal question into a trust question.
First-order effects
- Downstream RHEL rebuilders and the open-source community lose the source visibility they relied on, and with it the ability to independently audit whether Red Hat is meeting its GPL obligations.
Second-order effects
- Rivals move to fill the vacuum: SUSE commits $10M to a hard fork of RHEL, and Oracle, SUSE, and CIQ follow with the Open Enterprise Linux Association to keep RHEL-based distributions alive without Red Hat's cooperation.
Third-order effects
- Enterprise Linux splits into a vendor-controlled upstream versus a rival-backed rebuild coalition, and GPL enforcement shifts from community verification to contractual trust — the same tension the free software community weighed when it declined a maximalist copyright stance over Copilot's use of GPL code.
The trend: Open-source infrastructure vendors are testing how far they can close their source pipelines without breaking license terms, and each move is answered by competitor coalitions rebuilding the open path.