5 ms·
There is no such thing as "no longer open source". The story here is in fact "the copyright holders of RoboVM have made a proprietary derivative".
by MikeTaylor 11y ago
There is no such thing as "no longer open source". The story here is in fact "the copyright holders of RoboVM have made a proprietary derivative".
- johncolanduoni 11y agoWell, one complication here is that the only reason they were allowed to do so was that their CLA gave RoboVM AB an unrestricted license to the contributions, not merely the license the code was released under. If that were not the case, the compiler could not have gone simply gone proprietary because it was GPL licensed. In practice, I suspect they would have been able to do this anyway because the biggest independent contributors joined RoboVM prior to this move. edit: typo
- lsaferite 11y agoAnd this is the exact reason I will not contribute code under a CLA that gives a project the right to re-license my code as commercial.
- fhd2 11y agoAll the CLAs I've seen so far give the project the right to license the code under a proprietary license, as long as it (and derivates of it) remains available under a free license as defined in the CLA. I would also have concerns signing a CLA that doesn't ensure the code will stay available under a free license, but I don't think that's a very common case.
- lsaferite 11y agoEarly in my career I signed CLAs like this and contributed code under them. Later down the road I wizened up and realized it was free work for a commercial entity that was then relicensing my work under a closed source commercial license and making a profit. They are welcome to a profit, sure, but not if it is via closed source licensing of work that I contributed to the OSS community. So, no more CLAs for me. If they require a CLA (that lets them relicense my work) then I'll just never contribute to them.
- nickpsecurity 11y agoI'm investigating combinations of proprietary and OSS models that combine benefits of both. I explained in the essay below that countered that false dichotomy as it applies to security/verification. https://www.schneier.com/blog/archives/2014/05/friday_squid_bl_424.html#c6051639 https://www.schneier.com/blog/archives/2014/05/friday_squid_... My main stance, for now, is dual licensing. Any commercial use requires a license. Any other use is free. Both are perpetual, come with source, and allow modifications. Core staff of paid developers do most work. OSS contributors get free licenses, name recognition, and possibly gifts (esp money) for big contributions. Any improvements to the software must be sent back to software owner that redistributes it under the same license. Contract requires this happen post acquisition. If company stops meaningful updates or wants to abandon it, product is released under full OSS license and that's in the contract. Company is also a non-profit, public benefit, or just private with certain structure that helps force this. What do you think of such a setup? Again, main point is to force any user to be contributing to its development or maintenance while ensuring it stays available and has key FOSS benefits. Would you contribute to such a dual-licensed, carefully-setup piece of software?
- jahewson 11y agoCLAs on their own aren't bad. All Apache projects use a CLA to ensure that the contributer has he right to contribute the code under the Apache license.
- lsaferite 11y agoYou are correct, not all CLAs are bad. That is why I said "that lets them relicense my work" to clarify that it's a specific type of CLA that I take issue with.
- s73v3r 11y agoHow else are they going to make a profit? Unless you're Red Hat, the "sell support" option just doesn't work.
- lsaferite 11y ago
- michaelmrose 11y agoThey cannot take away licenses already granted nor stop existing holders from redistribution however I would think that the other poster would agree that such contributions are effectively wasted if the company discontinued the oss version.
- adrusi 11y agoAnd so we see that the legal infrastructure they put in place as an escape hatch from free software was the very reason they received few contributions and needed to use it. There are other factors, but a medieval CLA definitely didn't help their cause.
- DannyBee 11y agoYou have literally no evidence of this?
- DannyBee 11y agoAnd you think this will work in practice? Hint: They'll just rip out your code. I know it may be shocking, but companies are going to do what they want. Replacing the code of even hundreds of contributors, given a bunch of full time engineers, is just not that big a deal. This is even more true when, as here, the project almost entirely made by a small group of engineers (which is the case for a lot of projects). Legal infrastructure will not solve these problems for single projects. Additionally, even companies that have "good" CLA's find ways to be evil. Doing things like threatening other companies over the "compilation copyright" they claim they own on the work, etc. So yeah. Bottom line: CLA's, no CLA's, whatever, none of it is loophole or problem free, and there is no simple solution to these problems.
- quadrangle 11y agoPlanning to rip out code after accepting it is silly. Yes, I suppose people could do that if they don't plan to make a proprietary fork but change their mind later. clearly, the issue is whether the contributions amount to a substantial enough part of the software that the ripping out isn't feasible. Also, if you build up a community and then violate their trust, you lose the community. It's not a great strategy.
- DannyBee 11y ago"Planning to rip out code after accepting it is silly." They didn't plan on it. Plans changed. "clearly, the issue is whether the contributions amount to a substantial enough part of the software that the ripping out isn't feasible." Having legally supervised tons of these processes for open source projects (most trying to relicense things after discovering their licenses were hurting their communities): It's always feasible. Actual code is often not that important. Knowing what code to write is often important. (I know there are beautiful unique snowflakes who think otherwise ;p) "Also, if you build up a community and then violate their trust, you lose the community. It's not a great strategy. " Sure, but you assume "random people kibitzing on hacker news" represents their community. For all you know, the actually community is entirely in favor! Again, IME, having helped projects through these processes, there is often a huge difference in opinion between the people kibitzing on the sidelines and those who actually contributed meaningfully. My experience is that people who contribute meaningfully are often more sympathetic and understanding of various situations. People who are kibitzing from the sidelines are often more ideological.
- belorn 11y agoWas it previously distributed with a patent grant?