How to Audit an Embedded Device for GPL Compliance—A Field Guide

My Blog
When you buy a router, a smart home hub, or an industrial controller, you’re not just getting a box of silicon. You’re picking up a whole stack of software that makes the hardware do anything useful. In the embedded Linux space, a big chunk of that software sits under the GNU General Public License. The GPL gives you the freedom to run, study, share, and modify the code—but only if the vendor actually follows through. Most of the time, they don’t. This guide lays out a methodical, no-nonsense audit to figure out whether a device respects the GPL, written from the perspective of an engineer who has spent years peeling back the layers of consumer and industrial firmware. Why GPL Compliance Audits Matter The GPL isn’t a polite suggestion; it’s…
Read More

How to Technically Audit a Device for GPL Compliance

My Blog
Pick up a random router, smart thermostat, or Android-based set-top box, and you’re almost certainly holding a device that runs on Linux and a stack of other GPL-licensed open source components. The GPL gives you the right to study, modify, and share that software. But that right is hollow if the manufacturer never hands over the corresponding source code. I’ve spent years reverse-engineering firmware and having uncomfortable conversations with vendors, and I’ve learned that a rigorous technical audit is the only way to turn a suspicion into a documented case. This isn’t a legal guide; it’s a hands-on, engineer’s approach to verifying whether a device truly respects the GPL. A typical embedded system PCB. The software inside it often carries GPL obligations. Why a Technical Audit Is the Only Real…
Read More

How I Audit a Device for GPL Compliance (and Why It Matters)

My Blog
If you ship a product that runs Linux or BusyBox, you’re almost certainly shipping GPL-covered code. The obligation to provide corresponding source isn’t optional, and it doesn’t vanish just because your supply chain is a tangled mess. I’ve spent years tearing apart firmware images and chasing incomplete source drops, and I’ve learned that a structured audit is the only way to know you’re actually meeting the license terms. This guide walks through the process I use when I examine a device for GNU General Public License compliance—from the first binary blob to the final source package. Why a GPL Audit Matters Compliance isn’t a legal abstraction. When a device boots, it loads a kernel, runs init scripts, and calls userspace binaries. If any of those components are derived from GPL-licensed…
Read More

How to Audit a Device for GPL Compliance: A Technical Guide

My Blog
When you pick up a router, smart TV, or IoT gadget, you’re not just getting hardware. You’re also holding a software stack that almost always includes Linux, BusyBox, and other GPL-licensed pieces. The GNU General Public License gives you the right to ask for—and actually receive—the corresponding source code. Plenty of manufacturers pretend that obligation doesn’t exist. I’ve spent years reverse-engineering embedded systems, and along the way I built a methodical approach to auditing devices for GPL compliance. This guide walks through the whole thing, from early reconnaissance down to deep binary analysis, so you can hold vendors accountable when they cut corners. Understanding the GPL’s Source Code Requirement The GPL—versions 2 and 3 both—says that anyone distributing a binary form of GPL-covered software has to make the complete corresponding…
Read More

How to Audit a Device for GPL Compliance: A Technical Guide

My Blog
Buy a router, a smart TV, or an industrial controller that runs Linux, and you’re getting more than a box of electronics. You’re also getting software covered by the GNU General Public License — the GPL. That license says you can ask for the source code, study it, change it, and share your changes. Plenty of manufacturers, though, either ignore that obligation or make it needlessly hard to fulfill. Auditing a device for GPL compliance is part forensics, part stubbornness, and part standing up for the idea that software freedom actually matters. Here’s a practical way to do it. Understanding the GPL’s Core Requirements Before you crack open a case or dump firmware, get straight on what the GPL actually asks for. GPLv2 — still the most common version in…
Read More

How to Audit a Device for GPL Compliance: A Firmware Engineer’s Field Guide

My Blog
A methodical hardware inspection often reveals the first clues about the software inside. I don't crack open a new router, IoT gateway, or industrial controller looking for build quality or antenna gain. I'm looking for the GPL. The GNU General Public License is the legal and ethical backbone of so many embedded Linux systems, and yet manufacturers violate it with a regularity that still manages to disappoint me. After years spent untangling proprietary firmware blobs from the open-source code they lean on, I've settled into a systematic way of auditing devices for compliance. This isn't a legal process—it's a technical one. My job is to collect verifiable evidence that a product ships with GPL-licensed components, then figure out whether the vendor actually meets its obligations to offer the matching source…
Read More

ESP32-S3 Secure Boot v2 and the GPLv3 Anti-Tivoization Clause: A Forensic Audit of eFuse Lockdown

My Blog
You get an IoT sensor node or edge gateway that runs a GPLv3 userspace. You rebuild the bootloader, flash it, and the ESP32-S3 sits there dead. That is not a bug. Somebody made a choice—and that choice might have legal teeth. The chip’s secure boot v2 and flash encryption engine lean on a chain of one-time-programmable eFuse bits. Burn the right ones and the silicon will only execute firmware signed by a specific private key. The question engineers, compliance officers, and procurement teams need to answer is blunt: when does flipping those eFuses turn a security feature into an installation restriction that trips GPLv3 Section 6? This piece walks through the ESP32-S3 eFuse layout, the secure boot v2 signing flow, and the exact commands that tell you whether a device…
Read More

How to Actually Audit a Device for GPL Compliance

My Blog
If you bought a gadget that runs Linux or any GPL-licensed code, you have a right to the source that built the binaries on it. Not a polite request, not a favor—a legal requirement. Yet plenty of manufacturers ship products with half-baked source drops, locked bootloaders, or sneaky proprietary kernel modules that spit in the face of the license. Whether you’re an independent auditor or a developer who just got burned by a vendor, you can check compliance methodically. This guide walks through a real, step-by-step audit process, mixing forensic-level technical checks with the legal backbone of copyleft. What the GPL Actually Demands Before you even pick up a screwdriver, get clear on what the license covers. The GPL requires “Corresponding Source”—not just a link to a random tarball, but…
Read More

How to Audit a Device for GPL Compliance: A Technical Guide

My Blog
Free software runs on a deal—code stays open, rights stay clear, expectations go both ways. The GNU General Public License turns that deal into text. When a manufacturer drops Linux, BusyBox, or U-Boot into a box and sells it, they sign up to hand over the matching source. Auditing a device for GPL compliance isn't a checkbox exercise. It's methodical evidence collection, binary archaeology, and sometimes a slow argument with a vendor who should know better. Below is a framework I've used across routers, IoT gear, and industrial controllers—something you can pick up whether you're an engineer, a lawyer with a compiler habit, or just someone tired of broken promises. Understanding the GPL Compliance Baseline The GPL is a family of licenses, not one dusty document. In embedded gear, you'll…
Read More

Auditing a Device for GPL Compliance: A Technical Walkthrough

My Blog
By Arjun Mehta, gpl-devices.org Most engineers I talk to assume the GPL is a checkbox. Release the kernel source, slap a tarball on a website, and you’re done. But when you actually sit down and audit a device — especially a router or IoT gateway running a Linux-based firmware — you quickly realize that compliance is more about traceability, build integrity, and complete corresponding source than it is about intention. I’ve performed dozens of these audits, and I can tell you: the gap between what a company thinks it ships and what the GPL actually requires is often alarmingly wide. This guide is not a legal opinion. It’s a principled, engineering-level process for verifying whether a device respects the freedoms guaranteed by the GNU General Public License. If you’re a…
Read More