just to clarify, would a patch not be a derivative work until actually applied to licensed code? on its own its just code, (EDIT: retracted, this statement made sense: "When the second
work makes sense only in light of the original, it's derivative.")
and owned by the author. they don't have to release publicly.

And even if said-patch does infact fall under GPL, the GNU-GPL FAQ makes it clear that you can sell modified versions of GPL code to a client and not release publicly, and its up to the client whether they want to keep the modified version internal, or release it. The only thing that forces public source release, is to likewise distribute any part in any form, to the public.

If that client were to release the modified version, they would need to supply the source, but if kept internally, then no. By requiring a subscription or contract, i'd imagine thats the loop hole that allows private sale/distribution without violating the gpl (if i'm understanding that correctly.) It sounds like this company is ensuring paid-clients are supporting their efforts, while preventing every other company from doing a drive-by-only download instead. It sounds more than reasonable. In the end, the code is still going to make it to the public, eventually.
