LICENSEWARE

Hellwig v. VMware

This article is about the 2015 to 2019 German copyright action by Linux kernel developer Christoph Hellwig against VMware over GPL-2.0 code in VMware ESXi. For GPL obligations in general, see GNU GPL, LGPL and AGPL obligations. It is not legal advice.

On This Page

Hellwig v. VMware was a copyright action that Linux kernel developer Christoph Hellwig brought in the Hamburg District Court (Landgericht Hamburg) against the German branch of VMware Global, Inc. Hellwig claimed that VMware’s ESXi hypervisor combined Linux code he had contributed under the GNU General Public License version 2 (GPL-2.0) with VMware’s proprietary kernel, and that VMware had no right to distribute it without complying with the licence.[2] On 8 July 2016 the court dismissed the action. It held the claim admissible but unfounded, because Hellwig had not sufficiently pleaded and proved which of his copyright-protected contributions VMware had used.[1] The Hamburg Higher Regional Court dismissed Hellwig’s appeal on 28 February 2019, and he did not appeal further. VMware said it was working, for reasons it described as unrelated to the litigation, to remove the disputed “vmklinux” module from vSphere.[5][6]

Background

The Linux kernel is licensed under GPL-2.0. As the Hamburg court summarised it, each developer who contributes to Linux allows anyone to use and further develop it on the condition that further developments are in turn licensed under the GPL, which includes disclosing the source code of the modified version.[1]

VMware’s ESXi is virtualisation software whose kernel is called “vmkernel”. The court recorded that vmkernel existed only in binary form, and that ESXi also contained a module called “vmklinux” that let device drivers written for Linux work with vmkernel. VMware had published the source code of vmklinux under the GPL. The dispute was whether vmkernel and vmklinux formed one work derived from Linux, so that the source code of vmkernel also had to be released.[1]

According to Software Freedom Conservancy, which supported the action, Conservancy found in 2011 that VMware had not provided source code for BusyBox in ESXi and negotiated with VMware on GPL compliance from 2012. Conservancy said VMware’s counsel told it in 2014 that VMware would not stop distributing the software in dispute, after which Hellwig sued. Conservancy announced the action on 5 March 2015.[2]

The dispute

Hellwig sought an order that VMware cease making the kernel of vSphere ESXi 5.5.0, including vmkernel, vmklinux and the VMK API, available to the public unless it complied with GPL-2.0, and reimbursement of the costs of a warning letter.[1] He argued that he held adapter’s copyrights in parts of the Linux kernel, in particular in the SCSI subsystem and radix tree code, that this code appeared in vmklinux, and that vmkernel and vmklinux ran in the same address space and depended on each other, so that the whole kernel was a derivative work.[1]

VMware argued that the claim was too imprecise and unsubstantiated. It said vmkernel was developed independently more than 15 years earlier and was not derived from Linux, and that vmklinux was a separate module that communicated with vmkernel through a stable, documented interface, the VMK API. VMware said that about 122 drivers and modules from 21 businesses used that interface. It also argued that any code of Hellwig’s in vmklinux was minimal: by its count, 149 lines that might originate from him out of about 214,000 lines in vmklinux.[1]

Decision or outcome

Hamburg District Court (2016)

The 10th Civil Chamber held the action admissible, because the petition named the program version said to infringe precisely enough. It then held the action unfounded.[1] The court’s approach was that Hellwig could rely only on adapter’s copyrights in his own modifications, not on rights in Linux as a whole. So he first had to show which parts of Linux he had modified, that those modifications met the threshold for copyright protection, and that VMware had taken those protected parts. Only then would the questions of whether vmkernel and vmklinux were a single work, and whether his share was significant, arise.[1]

The court found Hellwig’s pleading insufficient on each group of code. A self-compiled overview of functions had no evidential value for authorship. General references to the Linux version history did not show where his specific contributions were recorded, and changelogs were not copies of the program and did not create a presumption of authorship. For the one SCSI function where he identified matching files and lines in Linux and vmklinux, he had not explained why his code was protectable. For radix trees, he had not shown a protectable program code; the court cited the CJEU’s ruling in SAS Institute v World Programming that functionality is not protected.[1] The court ordered Hellwig to pay the costs.[1]

Hellwig announced on 9 August 2016 that he would appeal. Conservancy said the ruling turned on German evidence rules and that the court had not ruled on the merits or sought expert evidence.[3]

Appeal (2018 to 2019)

According to Conservancy, the Hamburg Higher Regional Court held a first appeal hearing on 28 November 2018 and set a deadline of 24 January 2019 for a settlement.[4] VMware stated that on 28 February 2019 the appellate court dismissed Hellwig’s appeal and let the dismissal stand.[6] Conservancy described the decision as affirming the lower court on procedural grounds without addressing the main question of the case. On 2 April 2019 it announced that Hellwig, after consulting his counsel and Conservancy, would not appeal further in the German courts.[5]

In its statement VMware said it “did not seek out this litigation” and that, for reasons unrelated to the litigation, it had been working on a multi-year project to remove vmklinux from vSphere, which it hoped to complete in an upcoming major release.[6] Conservancy noted that removing the GPL-licensed code from a product is a common alternative to releasing the whole work under the GPL.[5]

Significance for software licensing and SAM practice

The case left open the question it was brought to decide: whether a proprietary kernel that works with Linux-derived driver code through an interface is a derivative work under GPL-2.0.[5] The first-instance judgment shows how a German court approached a claim by one of many contributors to a large project. It required the contributor to identify his own protectable code, show that it was in the defendant’s product, and explain its originality, before looking at the architecture of the product.[1] Conservancy stressed after both decisions that the German civil system is not precedent-based and that the ruling set no precedent.[3][5]

For organisations that use or ship open source code, the case is a reminder that GPL enforcement can come from individual copyright holders as well as from projects, and that such disputes can take years. General obligations are covered in GNU GPL, LGPL and AGPL obligations, and other enforcement cases in Software licensing litigation.

Lessons learned

  • Keep provenance records. The case was decided on proof: the court required the plaintiff to show specific files and lines, their authorship and their use in the product, and found changelogs and a self-compiled overview insufficient.[1] A software bill of materials and component inventory per release lets a vendor or customer answer the same questions from its own side.
  • Design out combined GPL and proprietary kernels. The claim targeted a module that carried Linux-derived code into a proprietary kernel. VMware defended its interface architecture in court but still said it was working to remove the module.[1][6] Review such designs with counsel before release rather than after a claim.
  • A dismissal is not a compliance finding. The courts did not decide whether ESXi complied with GPL-2.0.[5] When assessing products that contain open source code, rely on the licence terms and the product’s architecture, not on the outcome of this case.

References

  1. Landgericht Hamburg, 310 O 89/15, Hellwig v. VMware Global, Inc., judgment of 8 July 2016 (English translation)English translation of the judgment published by the plaintiff; archived copy. The German original was published at the same locationEffective 2016-07-08. Retrieved 2026-09-30.
  2. VMware sued in Hamburg, Germany court for failure to comply with the GPL on LinuxSoftware Freedom Conservancy, which funded the plaintiff's action, 2015-03-05Effective 2015-03-05. Retrieved 2026-09-30.
  3. Hellwig Announces He Will Appeal VMware Ruling After Evidentiary Set Back in Lower CourtSoftware Freedom Conservancy, 2016-08-09Effective 2016-08-09. Retrieved 2026-09-30.
  4. Appeal Moving Forward in GPL Compliance Suit Against VMwareSoftware Freedom Conservancy, 2018-11-29Effective 2018-11-29. Retrieved 2026-09-30.
  5. VMware Announces Plans to Remove Non-complying Code, Hellwig Decides Not to AppealSoftware Freedom Conservancy, 2019-04-02Effective 2019-04-02. Retrieved 2026-09-30.
  6. VMware's Update to Mr. Hellwig's Legal ProceedingsStatement of the defendant, March 2019, as republished on Broadcom's news site; archived copyRetrieved 2026-09-30.

See also

Esc