Felipe: "The option to host 3rd-party code under Apache has already been declined."
Declined by who? Quite the opposite. Tiago from Espressif stated they can and even prefer to donate esp-hal-3rdparty to apache controlled repo in order to assure software supply chain security as mentioned by Alin. The last remaining question here is whether it is okay to Apache to accept such donation. If yes then we can create apache/nuttx-hal-espressif repo and work on it just as any other apache/nuttx-* repo. I guess this hal needs to be a separate repo because Espressif still want to have local clone for validation / development. Your PR will be then reviewed also by NuttX committers. This is what this whole HAL fuss is about right? -- CeDeROM, SQ7MHZ, http://www.tomek.cedro.info On Fri, Oct 2, 2026 at 11:57 PM Felipe Moura Oliveira <[email protected]> wrote: > > Hi all, > > We have been discussing two options: one using a GitHub repository under > the NuttX organization to host 3rd-party HALs, and another approach hosting > 3rd-party code within Apache. > > The option to host 3rd-party code under Apache has already been declined. > > What about voting the option presented in this thread? > > Best regards, > > > *--Felipe Moura de Oliveira* > Linkedin <https://www.linkedin.com/in/felipe-oliveira-75a651a0> > > On Thu, 1 Oct 2026 at 13:11 Alan C. Assis <[email protected]> wrote: > > > Hi Tiago, > > > > Linux Foundation and the Apache Foundation have different mindsets > > (philosophies). > > > > One is about money; the other is about ideology. These are part of the > > three things that move people: money, ideology, or ego. > > > > So, LF doesn't care too much about ideology, they care about money and > > always take advantage of it (each project becomes a paying foundation for > > them). > > > > Please review the documentation regarding which licenses are allowed under > > the Apache Foundation. An external vendor should not agree to give away > > their IP or sign a SGA. > > > > Also, the Apache License is not interesting for some start-ups because if > > you hold a patent and use Apache-licensed software you cannot issue that > > patent against other companies using that software. > > > > In this case a HAL under the Apache License is a blocker for them. > > > > BR, > > > > Alan > > > > On Thu, Oct 1, 2026 at 12:43 PM Tiago Medicci Serrano < > > [email protected]> wrote: > > > > > Hi All, just a few pinpoints: > > > > > > Felipe just mentioned: > > > > > > "Keeping them outside of Apache, I know that Espressif agrees" > > > > > > > > > Actually, we prefer keeping it under ASF, at ` > > > github.com/apache/nuttx-hal-espressif` > > <http://github.com/apache/nuttx-hal-espressif> > > > <http://github.com/apache/nuttx-hal-espressif>. The license is already > > > Apache 2.0. > > > > > > Binh's last message stated: > > > > > > Yes, Renesas supports keeping HAL Renesas outside the ASF. > > > > It is similar to the model already supported for HAL Renesas in Zephyr, > > > > with shared contribution and maintenance between the community and > > > Renesas > > > > code owners. > > > > > > > > > There seems to be a misunderstanding about under ASF or not. It doesn't > > > mean transferring the ownership. Actually, *Zephyr's HALs are under > > > Zephyr's umbrella*. This is true for Espressif ( > > > https://github.com/zephyrproject-rtos/hal_espressif/) and seems to be > > true > > > for Renesas as well (https://github.com/zephyrproject-rtos/hal_renesas/ > > ). > > > Both are under `github.com/zephyrproject-rtos` > > <http://github.com/zephyrproject-rtos> > > > <http://github.com/zephyrproject-rtos> (equivalently, Zephyr's > > > umbrella, just like any other external modules). > > > > > > Just for the sake of comparison, they have clear rules about it: > > > https://docs.zephyrproject.org/latest/contribute/external.html > > > > > > An OSI-compliant license is a prerequisite (so that it'd be the same for > > ` > > > github.com/apache/nuttx-hal-<vendor>`). The goals, requirements, and > > > processes aren't that different from Zephyr's in this case. > > > > > > Best regards, > > > > > > > > > Em qua., 30 de set. de 2026 às 22:29, Binh Nguyen < > > > [email protected]> escreveu: > > > > > > > Hi all, > > > > > > > > Yes, Renesas supports keeping HAL Renesas outside the ASF. > > > > It is similar to the model already supported for HAL Renesas in Zephyr, > > > > with shared contribution and maintenance between the community and > > > Renesas > > > > code owners. > > > > > > > > Best Regards, > > > > Binh Nguyen > > > > > > > > > From: Felipe Moura Oliveira <[email protected]> > > > > > Sent: Thursday, October 1, 2026 2:24 AM > > > > > To: [email protected] > > > > > Subject: Re: Proposal: host vendor HAL repositories under > > > > github.com/NuttX > > > > > > > > > > Hi all, > > > > > > > > > > Keeping them outside of Apache, I know that Espressif agrees, and I > > > > believe Renesas and GigaDevice would as well. > > > > > I can contact Holtek too and present this approach to them and try to > > > > get support from them. > > > > > > > > > > Could the folks from Renesas and GigaDevice please confirm this? > > > > > > > > > > If so, we would already have a good starting point for this approach. > > > > > > > > > > Best regards, > > > > > > > > > > > > > > > *--Felipe Moura de Oliveira* > > > > > Linkedin <https://www.linkedin.com/in/felipe-oliveira-75a651a0> > > > > > > > > > > On Wed, 30 Sep 2026 at 15:48 Alan C. Assis <[email protected]> > > wrote: > > > > > > > > > > > I think Apache has many restrictions on what can be kept inside it. > > > > > > > > > > > > Also without the right information we cannot make a decision. For > > > > > > instance, if IP donation and SGA are requirements, keeping the HAL > > > > > > inside Apache is a blocker. > > > > > > > > > > > > For Espressif it is fine, because their license is already Apache > > and > > > > > > they have already signed the SGA in the past. > > > > > > > > > > > > However, we need to consider how we will handle vendors who cannot > > > > > > comply for some reason. > > > > > > > > > > > > BR, > > > > > > > > > > > > Alan > > > > > > > > > > > > > > > > > > > > > > > > On Wed, Sep 30, 2026 at 3:02 PM Gregory Nutt <[email protected]> > > > > wrote: > > > > > > > > > > > > > > > > > > > > +1 for Alin idea to have HAL under Apache license and umbrella in > > > > > > > +order > > > > > > to > > > > > > > keep coherent and secure SBOM.. > > > > > > > > > > > > > > I believe this would require an IP Clearance and possibly an SGA. > > > > > > > > > > > > > > "IP > > > > > > > clearance<https://incubator.apache.org/ip-clearance/index.html> > > is > > > > used to import code bases from outside Apache for future development > > > > > > > here." https://www.apache.org/legal/resolved.html#category-x > > > > > > > > > > > > > > The above statement seems to exactly describe the in-tree HAL > > case. > > > > > > > Basically, the ASF will not accept the legal liabilities of > > simply > > > > > > > taking some one else's code and hosting it in a project > > repository > > > > > > > with no legal licensing documentation, especially if it is a > > > > > > > substantial body of code that will be incorporated into the ASF > > > > project. > > > > > > > > > > > > > > IP clearance details: > > > > > > > https://in/ > > > > > > > cubator.apache.org > > > %2Fip-clearance%2Findex.html&data=05%7C02%7Cbinh.n > > > > > > > guyen.xw%40renesas.com > > > %7C62ced57e55444f955c3508df1f28b5c4%7C53d82571 > > > > > > > > > > da1947e49cb4625a166a4a2a%7C0%7C0%7C639263931847902603%7CUnknown%7CTW > > > > > > > > > > FpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMi > > > > > > > > > > IsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=XLXJ8KSIFNRpkL > > > > > > > 6OZiyBJoC7IOB02Yq8LkZ9ZAhGPvQ%3D&reserved=0 > > > > > > > > > > > > > > Alin is the expert on IP clearance and went through all of this > > in > > > > > > > the past. > > > > > > > > > > > > > > Using an external library in the link does not cause these > > problems > > > > > > > in my understanding. > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > >
