That's a pretty novel interpretation of the GPL, and I doubt that it would hold up in court. Reading through the GPLv2 I can't see anything in there that even suggests Red Hat would be within their rights to do that.
They still provide all the sources, as well as easy means to build them ( a source rpm ). This is far more than what the GPL requires them to do. What they don't distribute is the srpm with all of the patches neatly broken out by bug number and CVE (if applicable).
It makes it harder to figure out what sources came from RH, and what are vanilla kernel sources, but there's nothing in the GPL that says you have to detail the provenance of every line of source code distributed
Comments
Have they actually done that to any customer?
That's a pretty novel interpretation of the GPL, and I doubt that it would hold up in court. Reading through the GPLv2 I can't see anything in there that even suggests Red Hat would be within their rights to do that.
They still provide all the sources, as well as easy means to build them ( a source rpm ). This is far more than what the GPL requires them to do. What they don't distribute is the srpm with all of the patches neatly broken out by bug number and CVE (if applicable).
It makes it harder to figure out what sources came from RH, and what are vanilla kernel sources, but there's nothing in the GPL that says you have to detail the provenance of every line of source code distributed