Skip to content

Latest commit

 

History

History
58 lines (40 loc) · 6.02 KB

File metadata and controls

58 lines (40 loc) · 6.02 KB

Commercial and User Access Policy

This document explains, in plain language, the Ret2Shell-specific commercial and user-access restrictions in Sections 1 and 2 of LICENSE. It is not a second license and does not grant rights separate from LICENSE. The GPL-3.0-derived copyleft baseline incorporated through Appendix A remains governed only by LICENSE. If there is any conflict, LICENSE controls.

Purpose

Ret2Shell keeps a GPL-3.0-derived copyleft baseline and adds limited restrictions on certain user-facing monetization. The project may still be used for commercial work around operations, deployment, support, challenge production, and event services, but it may not be used to sell ordinary user access to challenges, educational resources, verification, or organization participation.

GPL-3.0-Derived Base Terms

LICENSE also carries forward the GPL-3.0 baseline through Appendix A. In plain language, that means the usual GPL-style rules still apply, including copyleft for conveyed modified works, access to Corresponding Source for conveyed non-source forms, patent grants and patent-related restrictions, anti-circumvention protection, Installation Information for User Products when required, automatic downstream licensing, and the warranty and liability disclaimers.

Defined Terms

Unless otherwise stated, capitalized terms have the same meaning as in LICENSE.

  • Project means the Ret2Shell codebase, binaries, documentation, and materially derived deployments.
  • Platform means any service or deployment that uses, embeds, wraps, extends, or materially depends on the Project.
  • User means any end user who uses or accesses the Platform, including for learning, training, practice, or challenge participation.
  • Verified Status means any account state showing that the Operator's account-validity or eligibility process has been completed.
  • Verification Process means any process used to confirm account validity, identity, eligibility, anti-abuse compliance, or organizational affiliation before granting Verified Status.
  • Organization means any team, class, school, company, club, institution, community, or similar collective represented on the Platform.
  • Organization Resources means resources made available specifically to members of an Organization.
  • User-Facing Charge means any payment, subscription, VIP fee, membership fee, token purchase, package, deposit, or similar economic consideration imposed on a User in connection with Platform access or related educational services, whether collected directly or indirectly, and whether implemented inside or outside the core Platform.
  • Private Internal Deployment means a deployment limited to a defined internal population and not open to public self-registration.
  • Bona Fide Educational Restriction means a non-commercial restriction imposed solely for curriculum sequencing, classroom management, exam integrity, age appropriateness, anti-abuse, or safety.

What the License Allows

The license allows commercial activity around the Project, including fees for:

  • operations, hosting, infrastructure, maintenance, and security;
  • deployment, migration, customization, integration, and consulting;
  • challenge design, challenge authoring, review, and event preparation;
  • event organization, sponsorship execution, and service delivery; and
  • Private Internal Deployments funded by schools, companies, or other organizations, so long as Users are not charged in violation of LICENSE.

What the License Forbids

The license forbids using the Project or a Platform to impose User-Facing Charges for ordinary educational participation. In particular, an Operator may not, for commercial advantage or private monetary gain:

  1. create, sell, or operate paid, VIP, premium, subscription, membership, or equivalent feature layers for Users;
  2. charge Users for access to challenges, writeups, learning content, practice environments, or similar educational resources on a Platform with public self-registration, except within a Private Internal Deployment or pursuant to a Bona Fide Educational Restriction;
  3. monetize Verified Status or the Verification Process;
  4. charge Users as a condition of joining an Organization or accessing Organization Resources; or
  5. use the Project or a Platform as part of a business that sells courses, training, tutoring, bootcamps, paid memberships, or similar user-facing educational products or services where payment is tied to Platform access, Platform status, Organization participation, or Platform resources.

Anti-Evasion Rule for Verified Access

On a Platform that allows public self-registration, an Operator may not use the Verification Process, Verified Status, or differences in ordinary non-staff challenge access among verified users to implement, disguise, or enforce a prohibited User-Facing Charge. In particular, ordinary non-staff challenge access that is granted to some verified users may not be withheld from other verified users because they did not pay a User-Facing Charge. Administrative, moderation, authoring, judging, and anti-abuse privileges remain outside this rule. Non-monetized distinctions based solely on Bona Fide Educational Restrictions remain permitted.

Interpretation Notes

  • A prohibited fee remains prohibited even if it is implemented through an affiliate, reseller, plugin, gateway, separate domain, or bundled service.
  • Open-source implementation does not make a prohibited User-Facing Charge permissible.
  • Separating a fee from the core Platform service does not make a prohibited User-Facing Charge permissible.
  • Reasonable, non-discriminatory verification or access controls for security, safety, anti-abuse, classroom management, or curriculum sequencing are allowed if they are not monetized and are not used as a pretext for User-Facing Charges.
  • Business-to-business fees paid by schools, companies, organizers, or sponsors remain allowed so long as those fees are not separately imposed on Users and do not become a condition of User access, User status, Organization participation, or Platform resources.