How I Reconstructed a Buildable GPL Source Release From a Vendor’s Incomplete Tarball: A Field Guide to the ‘Complete Corresponding Source’ Requirement
How I Reconstructed a Buildable GPL Source Release From a Vendor's Incomplete Tarball // FIELD GUIDE The vendor's email landed on a Tuesday afternoon. One sentence, a download link, and a 247 MB tarball named linux-source-v2.3.1-release.tar.gz. Six weeks of GPL source requests, and the Chinese ODM behind a white-label industrial IoT gateway we were auditing had finally delivered. I downloaded the archive, extracted it, stared at the contents for about ninety seconds. What they sent us was not a source release. It was a funeral. The tarball had a Linux kernel source tree—correctly versioned at 5.10.110, with the right SoC patches for the Rockchip RK3568—but it was missing every artifact that makes kernel source buildable. No Makefile at the root. No scripts/ directory. No .config, no defconfig, no toolchain definitions.…