Slide 1

Slide 1 text

It Was BSD All Along Relicensing PHP After 30 Years Ben Ramsey • FOSSY • 7 Aug. 2026

Slide 2

Slide 2 text

SCOPE One project’s story. Not legal advice. Every licensing situation is different.

Slide 3

Slide 3 text

THE QUESTION A routine compliance question opened 30 years of history phpdbg Company policy: OSI-approved licenses only

Slide 4

Slide 4 text

THE DISCREPANCY PHP and the OSI appeared to disagree php.net 3.01 ✓ BUT OSI list 3.0

Slide 5

Slide 5 text

COMPLIANCE Substantively identical was not enough 3.0 ≈ 3.01 Policy required formal approval, not interpretation.

Slide 6

Slide 6 text

“ The fact that 3.0 and 3.01 are substantively identical is no use to us at all. MATTHEW SHEAHAN • 3 MAR. 2020

Slide 7

Slide 7 text

THE MISSED CLUE The other license never entered the conversation Zend Engine License 2.0 OSI status: not approved

Slide 8

Slide 8 text

THE FIRST FIX Legacy approval solved the reported problem May 2020 One license approved. The two-license structure remained.

Slide 9

Slide 9 text

01 How did PHP get here? One language. Two custom licenses. Three decades of history.

Slide 10

Slide 10 text

1995 PHP began under GPLv2 PHP 1 → GPLv2 The licensing story began alongside the free software movement and the nascent open source movement.

Slide 11

Slide 11 text

A CHANGING MOVEMENT Commercial adoption changed the conversation Keep it free AND Let business use it

Slide 12

Slide 12 text

“ A number of significant projects have abandoned the GPL in favour of less restrictive licensing terms. […] PHP, if I can help it, will always be free. But, I am not against letting commercial entities take a shot at a commercial version as long as the terms are such that the major contributors don’t feel cheated. RASMUS LERDORF • 23 OCT. 1997

Slide 13

Slide 13 text

PHP 3 PHP 3 tried to serve both goals GPLv2 OR Custom permissive

Slide 14

Slide 14 text

LICENSE ANCESTRY The custom license came from Apache 1.0 BSD 1995 1998 4-clause roots Apache 1.0 PHP custom license

Slide 15

Slide 15 text

THE FIRST ADDITION The first extra restriction was already troublesome PHP 3.0.14 — CONDITION 1 Commercial redistribution of larger works derived from, or works which bundle PHP, requires written permission... REMOVED

Slide 16

Slide 16 text

“ That troublesome clause which we can't enforce. RASMUS LERDORF • 29 JUN. 1999

Slide 17

Slide 17 text

PHP 4 PHP 4 ended dual licensing and added another license PHP License + Zend License

Slide 18

Slide 18 text

THE ARCHITECTURAL PREMISE The Zend split assumed the engine could stand alone PHP ≠ Zend A plausible future in 2000.

Slide 19

Slide 19 text

“ I think there is still some confusion about what role exactly Zend plays in the PHP infrastructure. The host language (PHP) uses the base services provided by the engine (Zend)—services such as memory allocation, persistent resources, compilation, and execution. PHP itself then provides the function libraries, interfaces to the Web servers, .ini file support, etc. ANDREI ZMIEVSKI • LINUXPOWER • 15 NOV. 1999

Slide 20

Slide 20 text

“ I’d very much like to see the Zend engine embedded in MySQL at some point. I think it would be great to be able to write the stored procedure code of the DB in the same language as the scripting engine used to access the DB. ANDI GUTMANS • LINUXPOWER • 15 NOV. 1999

Slide 21

Slide 21 text

THE LONG PAUSE The software evolved while the licenses stood still 2002 2006 2026 PHP 3.0 / Zend 2.0 PHP 3.01 Same custom terms

Slide 22

Slide 22 text

02 Intent and text drift apart What everyone meant was no longer what every clause clearly said.

Slide 23

Slide 23 text

TWENTY-FIVE YEARS LATER PHP and Zend were no longer separable The reason for two licenses had disappeared. Jurga Ka / Unsplash

Slide 24

Slide 24 text

PHP LICENSE 3.01 The PHP License mixed permission with project control - Name - Acknowledgement - Change authority Copyright terms, branding rules, and stewardship lived together.

Slide 25

Slide 25 text

ZEND ENGINE LICENSE 2.0 Zend carried its own historical baggage - Advertising clause - Acknowledgement - Change authority Plus a second license authority inside the same repository.

Slide 26

Slide 26 text

TODAY’S SDLC SBOMs turn forgotten license text into data Inventory → analysis → policy

Slide 27

Slide 27 text

MACHINE-READABLE REALITY An SBOM records what the license says not what maintainers meant Intent does not fit in a policy gate.

Slide 28

Slide 28 text

AUTOMATED COMPLIANCE Automation cannot infer the community’s intent OSI? GPL? SPDX? Tools evaluate metadata, approval status, and compatibility.

Slide 29

Slide 29 text

THE AMBIGUITY WAS ALREADY VISIBLE Debian and extensions kept finding edge cases Patched distributions. PECL packages. Project-specific wording.

Slide 30

Slide 30 text

“ Please pick an existing, well-known license so that we do not have to argue again over whether this really solves all of the problems. WALTER LANDRY • 30 JUL. 2014

Slide 31

Slide 31 text

THE REVEAL Remove the project-specific clauses It was BSD all along. The familiar license was already underneath.

Slide 32

Slide 32 text

THE ARITHMETIC Both custom licenses reduce to BSD-3-Clause PHP 3.01 − 4, 5, 6 Zend 2.0 − 4, 5, 6 = BSD-3

Slide 33

Slide 33 text

03 Who has authority? The easiest license choice raised the hardest governance question.

Slide 34

Slide 34 text

THE CENTRAL OBSTACLE The obvious answer raised the hardest question Who can say yes? A 30-year-old project had no single copyright owner.

Slide 35

Slide 35 text

COPYRIGHT Every contributor owns their contribution many copyrights A project copyright notice does not erase individual ownership.

Slide 36

Slide 36 text

WHAT CONTRIBUTION MEANS A contribution grants a license, not ownership License ≠ Assignment PHP contributors never transferred their copyrights to one body.

Slide 37

Slide 37 text

THE USUAL RELICENSING PROBLEM Ordinary relicensing asks everyone 30 years × many owners That path would be impractical for PHP.

Slide 38

Slide 38 text

THE DECISIVE DISTINCTION No contributor rights were reduced Same freedoms + No new restrictions

Slide 39

Slide 39 text

NARROW AUTHORITY The removed clauses belonged to two custodians PHP Group + Zend’s successor

Slide 40

Slide 40 text

PHP LICENSE — CLAUSE 5 The PHP Group already held change authority THE UPGRADE CLAUSE The PHP Group may publish revised and/or new versions of the license from time to time...

Slide 41

Slide 41 text

ZEND SUCCESSION Perforce inherited Zend’s authority Zend 2015 2019 Original custodian Rogue Wave Perforce

Slide 42

Slide 42 text

WRITTEN CONSENT The necessary custodians said yes PHP Group + Perforce

Slide 43

Slide 43 text

LEGITIMACY Legal authority was necessary. Community consent still mattered. Six months, attorney review, unanimous vote

Slide 44

Slide 44 text

04 A simplification, nothing more The legal foundation finally catches up with the software and its community.

Slide 45

Slide 45 text

THE ADOPTED CHANGE PHP License 4 and Zend Engine License 3 are BSD-3-Clause The standard license itself, not another adaptation.

Slide 46

Slide 46 text

THE REPOSITORY One standard license now covers PHP and Zend sources SPDX-License-Identifier: BSD-3-Clause One license file. No separate Zend license.

Slide 47

Slide 47 text

PEOPLE AND MACHINES Standardization closes the old gaps BSD-3-Clause OSI approved, GPL compatible, machine readable

Slide 48

Slide 48 text

EXISTING CODE Users keep their choices; maintainers gain a simpler one Old terms remain available AND New version available

Slide 49

Slide 49 text

THE LESSON The freedoms did not change The ambiguity did. License stewardship means keeping text, software, and community aligned.

Slide 50

Slide 50 text

 DISCUSSION Questions? ben.ramsey.dev  phpc.social/@ramsey  github.com/ramsey  www.linkedin.com/in/benramsey [email protected] It Was BSD All Along: Relicensing PHP After 30 Years Copyright © 2026 Ben Ramsey This work is licensed under Creative Commons Attribution-ShareAlike 4.0 International. For uses not covered under this license, please contact the author. Ramsey, Ben. “It Was BSD All Along: Relicensing PHP After 30 Years.” FOSSY, 7 Aug. 2026, University of British Columbia, Vancouver, BC, CA.

Slide 51

Slide 51 text

REFERENCES Bibliography “Apache License 1.0.” SPDX, spdx.org/licenses/Apache-1.0.html. “BSD 3-Clause ‘New’ or ‘Revised’ License.” SPDX, spdx.org/licenses/BSD-3-Clause.html. “BSD 4-Clause ‘Original’ or ‘Old’ License.” SPDX, spdx.org/licenses/BSD-4-Clause.html. Landry, Walter. Reply to “Debian and the PHP license.” php-pecl, 30 Jul. 2014, 22:34:51. PHP Mailing Lists, news-web.php.net/ php.pecl.dev/12119. Lerdorf, Rasmus. Reply to “license issues.” php-dev, 29 Jun. 1999. PHP Mailing Lists, news-web.php.net/php.dev/7762. PHP Development Team. “LICENSE.” PHP, version 3.0, 6 Jun. 1998, museum.php.net/php3/. “PHP Licensing.” PHP, www.php.net/license/, accessed 2 Aug. 2026. Ramsey, Ben. “PHP RFC: PHP License Update.” PHP Wiki, 6 Apr. 2026, wiki.php.net/rfc/php_license_update?rev=1775434811. Sheahan, Matthew. “OSI approval for PHP 3.01 license.” php-general, 3 Mar. 2020, 22:13:54. PHP Mailing Lists, news-web.php.net/ php.general/327010.