11 ms·
Hi folks. Kevin from http://fossa.io http://fossa.io here. I worked on bringing the Commons Clause to life (https://commonsclause.com/ https://commonsclause.c
by XiZhao 8y ago
Hi folks. Kevin from http://fossa.io http://fossa.io here. I worked on bringing the Commons Clause to life (https://commonsclause.com/ https://commonsclause.com/) and led many of the project efforts here.
Happy to answer questions here (or on Twitter @kevinverse).
I wanted to write a blog post to set some context because the real story is a lot less salacious then "Redis just went proprietary", but here's a quick summary:
1/ No, Redis isn't proprietary. It's only some enterprise modules. The Commons Clause is mostly used to temporarily transition enterprise offering counterparts of OSS projects to source-available.
2/ OSS projects are mainly funded by some proprietary offering or service on top of it. Anything to help the ability to monetize this layer is really good, as the fate of the project is directly tied to this revenue stream. A quick reminder, companies like Redis sink 10s of millions into RnD and are usually contributing over 99% of the code to these repos.
3/ OSS-savvy companies aren't dumb. They understand the optics of any licensing announcement and carefully consider what it will mean. Before we react, we should push ourselves to understand what systems are forcing deeply passionate OSS devs to consider more proprietary options.
- mindcrime 8y agoI worked on bringing the Commons Clause to life Why would you intentionally give birth to such an abomination? This adds no value to the world whatsoever and is just going to confuse people and harm the overall Open Source ecosystem. I'd encourage you to retract this whole idea, stuff it in a hole, "salt and burn it" and try to pretend this whole thing never happened. If you care about putting pressure on Cloud providers vis-a-vis use of F/OSS, there is always the tried and true "AGPL or commercial license" combination. Why not just use that?
- XiZhao 8y agoAs addressed in the FAQ, AGPL doesn't satisfy many requirements -- one of which is that it's often too restrictive in the wrong ways. If not the Commons Clause, a very viable "v2" is just to draft a more cohesive source-available license, or in the worst case move the project to closed source.
- mindcrime 8y agoUsing the "Commons Clause" is already effectively making it closed source... at best that's equivalent to "Source Available". Just use the MS Commons Research License or whatever it was called. This "OSS License + garbage extensions" stuff is nonsense.
- DannyBee 8y agoAs an open source lawyer, this is definitely not an open source license in any meaningful sense (it meets no definition of open source/free software/DFSG/you name it). No restrictions on fields of endeavor and no discrimination is a pretty basic tenent that goes back a long long time (the DFSG were published in 1997, there are other things saying the same thing that pre-date it). I also know this is what other open source lawyers are saying as well (in fact, i haven't seen one who believes it is anything else). I'm sure you can make up another word other than "proprietary" to call it, but ... As for questions: The main commons clause page makes the claim "Initiated by a coalition of top infrastructure software companies to protect their rights" Care to list them? Additionally, even ignoring the significant vagueness in the clause, there are plenty of combinations of licenses with which this clause makes literally no sense. It seems there is no guide or policing of these. Truthfully, this all does not feel well thought out. Who actually participated in the drafting? Here is one that exists in practice: neo4j is commons clause + AGPLv3 AGPLv3 section 7: If the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term. ... GPLv3 is identical in this respect, and LGPLv3 is a set of permissions on top of GPLV3 that does not revoke this clause. This seems to make commons clause incompatible with a lot of software.
- john-mark 8y agoThere is a very bizarre story behind Neo4j Inc's behavior and what lead to them adding the commons clause to the enterprise AGPL license. They seem to be ready to go closed source, which they should have just done in the first place instead of behaving like they did. Adding the commons clause is just the tip of the iceberg - there is a very entertaining story behind everything that is happening. A single person, not a huge corporation, is behind this. I will write a blog post about what happened/is happening in the upcoming months - complete with supporting documents such as FOIA requests, etc.
- mchahn 8y agoI've never heard of an open-source lawyer. I understand totally how valuable it is to litigate open-source issues, but I'm curious as to who pays for such services? Being able to pay lawyers seems unlikely for a free product.
- deleted 8y ago[deleted]
- sciurus 8y agoWho else can we expect to see adopting the Commons Clause?
- mindcrime 8y agoPretty much either "nobody" or "the set of companies who want their projects forked and promoted by somebody else".
- XiZhao 8y agoIf a project has that wide of a contribution base, then the Commons Clause wouldn’t be needed in the first place. I think that’s the problem.
- hashrate 8y agoIMO 100% of ventured backed Open Source project will adopt this licence. Just to name a few : - Elastic - Docker - CockRoachDB This licence is a disguised "Oracle" intellectual property. This what Oracle has been doing for years and bring them billions in revenue. It ensure that one way or another you'll pay $$$ to the vendor of the tech. Most of these companies quoted above are not profitable and are trying to find a way to be profitable. With this licence it allows them to charge $$$ and to have full control over the IP for and become the sole allowed provider for consulting / support / training and basically anything that is related to this technology. This is proprietary software with an "unlimited trial" edition and source code hosted on Github.
- Sir_Cmpwn 8y agoWow, I remember seeing this when you first started it and I spoke out against it then. I should have spoken more loudly, because I assumed no sane maintainer would have taken you seriously. Software which uses this model is not open source, plain and simple. This is a disgrace on our community and I am sorely disappointed in you and in Redis. What pushes OSS devs to cease being OSS devs is an important problem to solve, but one I think we were making great progress on. "Solving" it with the destruction of open source is a despicable thing. The commons "clause" isn't a clause at all, it's a rape of an otherwise good license. I fear you've already let it into your head that your cause is a noble one and that you'll be unwilling to undo the damage you've done, but if you have a conscience I urge you to shut down this bastardization of open source.
- dang 8y agoThat crosses into incivility and you can't do that here, regardless of how right you are or feel you are. You surely know this. Please don't do it again. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- Sir_Cmpwn 8y agoI am very angry and showing it, but I don't think I've crossed the line into incivility. Naturally it's your call.
- vmbrasseur 8y agoHi, Kevin. VM Brasseur from https://opensource.org https://opensource.org here. It's disappointing to see FOSSA, which claims it exists to assist companies with open source management, publish and encourage use of a clause that very clearly removes projects from the pool of open source alternatives. To do so by using the word "Commons" in the title adds insult to injury and borders on wilful deception, removing software from the commons as it does. I encourage FOSSA to contact the Open Source Initiative, Open Tech Strategies, or another reputable free/libre and open source organisation to find a better solution to whatever problem it is that the Commons Clause is intended to address.
- bastawhiz 8y agoWhat efforts has your organization made to prevent software companies from selling "Hosted [open source project] as a Service (with a proprietary twist)" offerings while not contributing back to the OSS core project's development? Edit: Or rather, incentivized contributions, or disincentivized a lack of contribution
- vmbrasseur 8y agoArguably the largest users of Redis—Amazon, Google, and Microsoft—are all among the many sponsors of the Open Source Initiative and each make immense contributions to free and open source software. Redis Labs is not a sponsor (but is welcome to become one). Despite that, had they come to OSI looking for assistance with this issue we could have helped open discussions between them and their largest users. They did not ask us for help, to the best of my knowledge. Redis Labs' post does not mention what, if any, attempts they made to engage these large users and encourage more contributions before they made the decision to put this software under a proprietary license, and only implies that a lack of contributions was the motivator for the move.
- kemitchell 8y agoYou start your career later than your siblings. You land your first real job. You scrimp and save to buy your first real set of Christmas presents. Comes the day, and everyone seems grateful. You feel established, for a moment. The others exchange presents, but oddly, not with you. In the end, your hands are empty. Everyone else is okay with this. They make out great. Giving OSI money isn't giving Redis Labs money. I don't imagine OSI will be sending any of that money Redis Labs' way. On the other hand, OSI's activities will benefit its sponsors. One way: by constraining approved terms to licenses, like ancient permissive licenses, with poor upstart-business potential, but all the permission grants established enterprises require to mulch the remains of dead startups that result. I'd be willing to bet Redis Labs is contemplating return to ash pretty seriously these days. More contributions will not solve the problem. They may defer RL's trip into liquidation, but at the expense of a quicker boot out of the top spot on their own project. That, in turn, bodes ill for acquisition. Even if outsiders reduce maintenance and development cost to $0, that's savings, not earnings or recoupment.
- tomnipotent 8y ago> "including without limitation fees for hosting or consulting/ support services related to the Software" This single line completely destroys any confidence I have in Commons Clause. I will avoid any project with this license moving forward until this is fixed. It's embarrassing that I'm being told that the time & energy I've invested in deploying this software (redis in particular) will now be rewarded with the inability to commoditize that experience through consulting. No thanks.
- toomuchtodo 8y ago> It's embarrassing that I'm being told that the time & energy I've invested in deploying this software (redis in particular) will now be rewarded with the inability to commoditize that experience through consulting. No thanks. Can you explain the thought process with regards to why it's okay for you to receive compensation for your efforts, but not the OSS developer who invested significantly more time (nine years, in the case of Redis) in creating the product? What will you do as a technology practitioner if more projects move to this model to provide some semblance of financial support for their devs? Write your own RDBMS? Your own in-memory caches? I won't discount these paths as impossible, but it increases your costs and time to market significantly. Standing on the shoulder of giants is both efficient and convenient when building your product/stack by bolting together existing tooling (what products aren't using Redis/Memcached, MySQL/MariaDB/Postgresql, ElasticSearch, etc), but it should have a cost; those shoulders aren't free, and it's not reasonable that those enjoying easy revenue (AWS, for example) by providing managed services with these tools don't have to share that revenue. You can't freeload forever.
- jen20 8y agoNot even dark-ages Microsoft tried to prevent users exchanging knowledge about their products for money ("consulting", or frankly, "employment"). Such a suggestion is preposterous and should kill any company adopting it immediately.
- toomuchtodo 8y agoAt it's core, this is fundamentally about property rights. The owners of the Redis copyright are well within their right to license their property in any way they see fit. It's preposterous to you, but you're not the one who has spent the time creating Redis. It's preposterous to me that they wouldn't have the rights to govern their creation's use. You could go build your own infrastructure software, of course, that is a valid path forward. But will it be of the same quality at the same (or similar) cost? Most likely not. Will someone provide an alternative to Redis out of disdain for this? Probably. But it will take years, if not longer, to reach feature, stability, and therefore market parity. And in the interim, cloud providers will pay or have to front the costs to build their own. And that's what this is all about: internalizing the externality of providers getting a free ride.
- le-mark 8y agowe should push ourselves to understand what systems are forcing ---companies that monetize the work of--- deeply passionate OSS devs to consider more proprietary options. Fixed it for you. I'm waiting to read antirez comments.
- hn_throwaway_99 8y ago> Any license notice or attribution required by the License must also include this Commons Cause License Condition notice. FYI, think you have a typo, shouldn't it be "Common Clause" not "Common Cause".
- sriku 8y agoWhy would a dual "non commercial" and "commercial" license not solve the problem this is claiming to address. Many OSS projects do this now. There is nothing wrong with wanting to be compensated for one's work, but without saying how, what are those who adopt the software expected to do? Let's say the Apache Foundation adopts this for all of its projects. Now what?
- Canada 8y agoAll of the Apache's Foundations popular projects would be forked.
- XiZhao 8y agoI think this is close, but adds the feature of source availability. I’m the first to admit the Commons Clause bolt-on feature isn’t the most elegant. But, if it’s a bad solution, then people can fork it, and that’s okay. I hope we do, and then find a middle ground that works better for everyone. In the longer run, there will need to be a happy middle ground for people to
- ShaneCurcuru 8y agoJust to address the last sentence: the Apache Software Foundation would never adopt Commons Clause. It's antithetical to the ASF's entire licensing strategy, which is to give stuff away for the public good, with as few restrictions on users and redistribution as is legally practical. Personally, people can use whatever license they want for their copyrighted works; that's cool. But the other important issue is: don't call it the "Apache-whatever license", because it is NOT the #Apache-2.0 license. Call it the "Redis License" or whatever else you want, just don't bring the ASF's name into it.
- Nemo_bis 8y ago"It's only some enterprise modules." Sure, ownCloud said the same and eventually forced its own founder to fork and make Nextcloud under AGPL. Good luck with that. Did you completely fail to learn from experience, or are you pretending? https://fosdem.org/2018/schedule/event/nextcloud/ https://fosdem.org/2018/schedule/event/nextcloud/
- HeadsUpHigh 8y agoHey I'm not saying this license is bad but it's absolutely not free software anymore by any definition.
- macspoofing 8y ago>Happy to answer questions here You didn't answer many (any) questions. Here's mine, why is this needed? Redis could have adopted AGPL as the base license which would have effectively prevented any cloud vendors from using it as a manged service. For those companies, Redis could have provided a paid proprietary option. Why even bother with this?
- zwily 8y agoAGPL would prevent a ton of companies from using Redis at all. A surprising number of big companies flat out ban all AGPL code.
- icebraining 8y agoThe paid proprietary option wouldn't be AGPL'd.
- macspoofing 8y agoAs it stands 'Common Clause' is a poison pill for every business. It won't get past any legal department.
- etatoby 8y agoQuestion: why all this mess instead of simply re-licensing under the AGPL? (which was created to address the specific issue Redis is having)
- rurban 8y ago1. Those modules were under APGL before and moved now to the Common Clause. 2. In fact the GPLv3 is the improved and recommended variant of the APGL. They should have switched to the GPLv3 instead, and would have avoided this misleading and wrong headed discussions, where people are mostly mixing up redis with RedisLab modules and have no idea about APGL vs GPLv3.
- peterwwillis 8y ago> understand what systems are forcing deeply passionate OSS devs to consider more proprietary options Does an artist stop painting because they aren't selling enough paintings? Did Linus stop making the kernel because he "created a lot of value" that big companies didn't compensate him for? He should be a billionaire by now, but he did fine for himself, so he didn't care that people were making billions off his creation. He made it because he needed it, but also because he loved programming. Deeply passionate people just do. Not everyone can be passionate. But please don't pat these developers on the back for being capitalists.Right now they're just upset that they aren't making more cash, and are sticking it to the cloud providers out of spite. Google didn't have to open source Kubernetes. They did it because they knew the power of open source is in the community. [1] If Docker had a "commons clause", imagine how limited the technology we use would be today. The fact that this license stifles contribution to and use of the software is important, because it will probably evolve until no commercial use is allowed at all - without a paid license. Back to the good 'ol days of proprietary software companies. And even if you're not a company, but you're a consultant who gets paid to set up a cluster for someone else, this license could be construed as preventing that consultant from getting paid for setting up the software. I'm not willing to be taken to court, so I'm not touching this software with a ten foot pole. If a company uses it, I won't work with that company. [1] https://www.computerworlduk.com/cloud-computing/why-did-google-open-source-its-new-container-project-3624430/ https://www.computerworlduk.com/cloud-computing/why-did-goog...
- solomatov 8y ago>Google didn't have to open source Kubernetes. They open sourced it for pragmatic reason. In some sense, kubernetes is an open source cloud infra, and in this way it prevents AWS from monopolizing the market.
- deleted 8y ago[deleted]
- joshberkus 8y agoKevin, If the goal is to monetize the Redis Labs modules, why not just put them under straightforwards proprietary licenses? This is a well-trodden and well-understood path. This Commons Clause combines the twin mistakes of being both offensive and ineffective. It will get Redis pulled out of many OSS repositories, decreasing your distribution and mindshare. At the same time, I can see Amazon and Microsoft lawyers laughing at it now; it will do zero to prevent them from building their own cloud offerings. I really have to wonder about the quality of advice that FOSSA is providing to its clients if it went ahead with this. You say 'OSS-savvy companies aren't dumb' but it seems like the consultants of FOSSA are, or they are counting on everyone else in the industry being gullible. (and before you play the "consider the poor OSS developer" on me, I worked on Postgres for 18 years, and we never pulled this kind of nonsense)
- joshberkus 8y agoFor historical relevance: Microsoft already tried this with its "Shared Source" nonsense, an attempt to reap the marketing benefits of Open Source while actually opening anything. If Microsoft couldn't pull it off with their $billions in marketing funds, why on Earth do you think Redis Labs can? (yes, the Shared Source program still exists, but it's no longer Microsoft's answer to Open Source, but just a way of handling required government disclosure of their older proprietary products. It's pretty clear to anyone who follows MS now that they consider Shared Source to have been a complete flop)