23 ms·
MongoDB switches up its open source license
- reacharavindh 8y agoAt the outset, it sounds simple that MongoDB inc thinks why should some 3rd party cloud provider (AWS, GCP, DO and the like) be allowed to run MongoDB as a service and make money while MongoDB contributes the biggest part of the open source project that is MongoDB. But, it feels like yet another fallacy. What really is an open source project then? Say some developer X contributes to a project like MongoDB his/her open source code so that they can one day run MongoDB as a service and make money. At that time, he/she believe that status is true and submits their code. But, later, after the project is mature, the major contributor easily changes license at will, and the open source contributors walk away with nothing? I'm not saying that MongoDB Inc, does not have the majority stake here. Just wondering about whether it is a "bait & switch"esque move? Imagine if all projects did the same... Say Docker? later on chooses to say that you can use Docker for free but if you distribute your software through repositories supported by the daemon, then you need to pay up.. Wouldnt that be a loss for the contributors that are not working for the company?
- cobookman 8y agowouldn't the older versions of mongodb still be under the old license? (IANAL)
- notimetorelax 8y agoYup, article also states this.
- k__ 8y agoI had the feeling that AWS and Azure are pushing their own NoSQL solutions and don't care much about MongoDB.
- tannhaeuser 8y agoAzure offers Cosmos DB advertised as a drop-in for MongoDB. I'm guessing Cosmos is Mongo in disguise, though I don't know if it really is, and/or whether MS has made a deal with Mongo or just think they can use the AGPL version. For the record: I'm not a big fan of Mongo (the DB) but I think MongoDB, Inc. raises a valid point wrt. developers doing all the hard work including community building and a million other things, while "cloud providers" get all the money. This isn't sustainable, and we need a license which more clearly says "if you make money with it, you need to give us some", rather than using the bare AGPL license without further qualifications in the hope AGPL's "freedom" aspirations have the indirect effect of forcing commercial users and/or resellers to pay.
- kstrauser 8y agoDid the MongoDB pay for their Linux distros? GCC? Git? How much are they paying to the FOSS projects they used to build their software for sale?
- znpy 8y agoFair point, actually.
- tannhaeuser 8y agoFair point, but if you strip any money from product development, this implies you don't have a budget for further development and maintenance, except if you make it support-intensive. And for what gain? That very few cloud providers make more money and enslave customers into their walled garden? Cloud providers don't even need to provide QoS or support - they can just shrug and say "we're running an OS project as-is". If no money can come your way, then development and support is simply not sustainable. The projects you mention: Linux+git development has good financial standing from companies who could be seen as going (or having gone) aggressively against commercial Unix from a business PoV. gcc thrived on freedom enthusiasm but has seen many, many patches from commercial vendors wanting their OS, CPU or whatever supported.
- Akinato 8y ago
- Uehreka 8y agoIANAL, but I believe in this case a maintainer can just fork MongoDB from right before they changed the license, then new contributors can just contribute to that forked repo, creating an off brand “Non-goDB” that will get a lot of the updates that people want. This would fracture the development of the project and would be bad for everyone, but at least the open source community wouldn’t completely lose the project.
- greenshackle2 8y agoIANAL either but just to be pedantic, in theory I don't see what stops them from no longer distributing old versions under AGPLv3. Having distributed it at one point under GPL doesn't force them to continue doing so forever. Of course that would be pointless as anyone who forked before the license change could continue re-distributing under AGPLv3.
- zzzcpan 8y agoBut you can still offer it as a service, just as long as you opensource your infrastructure. The only thing it prevents you is profiting from lock-in of your services without sharing those profits with MongoDB. Very much in the spirit of open source.
- mbreese 8y agoYeah, but how is that really supposed to work? I can see why MongoDB would want to do this, but how on earth is this really supposed to be implemented? Where do you draw the line? What I suspect is that you'll end up with a bunch of shell scripts for creating MongoDB instances...
- darkarmani 8y ago> sharing those profits with MongoDB. Very much in the spirit of open source. I'm not sure how these ideas tie together.
- rlpb 8y agoIf you contribute to a project, you have no entitlement, moral or otherwise, to _future_ contributions to that project that others choose to make. Future contributions may be made under different terms, as you point out. The project might stop development, get forked privately, and you may never see active future developments distributed again. This is self evident from the licences themselves but also clearly reasonable if you consider the proportions of contributions made. Why should a contributor get rights to all future work on a project made primarily by others solely by making a contribution? > ...and the open source contributors walk away with nothing? Nope. As others have pointed out, they walk away with the Free Software licensed version of the code to which they contributed, together with their contributions. This code base does exactly what it did at the time of their contributions.
- gshipley 8y ago"Imagine if all projects did the same... Say Docker?...." Wait just one second here. Is docker still open source or is Moby the new open source docker? https://blog.docker.com/2017/04/introducing-the-moby-project/ https://blog.docker.com/2017/04/introducing-the-moby-project... My understanding is that recent versions of docker is indeed not open source but moby is? Is that correct according to the OSI?
- deleted 8y ago[deleted]
- ReverseCold 8y agoI used to like permissive (OSI) licenses a lot more than restrictive licenses, but now I like copyleft better (for my own projects) because… 1. You’re still helping education, nonprofits, and individuals benefit from your work. 2. It’s still open source, so people will still be able to contribute and use your work in their own projects. 3. Companies that want to use your code to make money can do so, but only if they also help out the other “worthy” causes by contributing changes back. In fact, I'm consider something more radical like a YUMMY license (you make money, I make money) - which has all the same benefits of being open source and helping worthy causes, except at least you get to make money when someone uses your work to do something that you might not even want, like selling ads.
- blattimwind 8y agoIf it's not a library meant to be used by others, just put GPL (Commonwealthy) / EUPL (Not-Commonwealth) on it.
- Doctor_Fegg 8y agoI really like WTFPL as a permissive licence in these cases. Small developers and companies without layers of lawyers will read the licence, see that it says "do what the ---- you want", and use your code accordingly. Big companies with layers of lawyers will read the licence, blanch in terror, and either refuse to use the software, or contact you for alternative terms. Case in point: Google forbids use of the WTFPL. https://opensource.google.com/docs/thirdparty/licenses/#wtfpl-not-allowed https://opensource.google.com/docs/thirdparty/licenses/#wtfp...
- DannyBee 8y agoSo i'm the one who forbid WTFPL at Google, and we forbid it mainly because it's bad for developers, believe it or not. We go over it in new googler training (and our reasoning is on the Google open source policy site we publish: https://opensource.google.com/docs/thirdparty/licenses/#wtfpl-not-allowed https://opensource.google.com/docs/thirdparty/licenses/#wtfp...) You are welcome to not (but if you go and look, it's completely consistent with my viewpoints and history in OSS so ...). I would love to live in a world where WTFPL is a good license, but we don't live in that world, and wanting it to be so will not change that. I can also tell you stories of companies we've acquired who had bad experiences, FWIW. So the "small companies" you think are being served, aren't.
- manishsharan 8y agoThis is a bad move and does not inspire confidence. Instead of switching the license, they should have gone after companies that were abusing the terms of GNU AGPLv3 license.
- michaelcampbell 8y agoExactly; what makes them think changing the license is going to make an actor in bad faith change?
- nemo44x 8y agoHow would they litigate against a mega corporation? Mongo is a very small company compared to many cloud providers. They would be tied up in the courts for years and spend hundreds of millions and possibly drive the company into bankruptcy.
- antirez 8y agoTo legally fight in China pretending that something you can't see was modified is... hard. IMHO the only wrong thing about this move is trying to get it OSI approved, otherwise I can understand that they have concerns that do not apply to most normal users. However one should boldly say we are moving away from an OSS model, to a "available source" model where you retain most rights.
- kstrauser 8y agoHow is those going to affect China? If the old enforcement methods didn’t work with the previous sane-ish license, they certainly won’t work any better with the new monstrosity.
- antirez 8y agoNow you don't have to pretend that they changed something without having any way to prove it. Now if the orchestration software is not open source, they can't use it.
- 8y ago
- a012 8y agoCould this move of Mongodb inc. makes the comeback of the rethinkdb? I hope so
- michaelcampbell 8y agoYou seem like you know something about rethink. I do not, and couldn't find this information but maybe you know? One irritating feature of Mongo (and I suppose other db's too; orientdb does this) is that once it grabs disk space, it never lets it go. It'll reuse that space, but the OS will never see it again. (EG: If I store 10GB of stuff, and delete 9GB of it, the OS still sees all 10GB of disk used). Does rethink do this as well?
- sbr464 8y agoYou just need to iterate over the collections calling the compact command. You can create a small script and schedule it.
- shadowmint 8y agodetails: https://www.mongodb.com/press/mongodb-issues-new-server-side-public-license-for-mongodb-community-server https://www.mongodb.com/press/mongodb-issues-new-server-side... actual license: https://www.mongodb.com/licensing/server-side-public-license https://www.mongodb.com/licensing/server-side-public-license Typically, TC didn’t bother to even link to either. :/
- vslira 8y agoI'm not an expert in licenses, could someone weight in and explain how the AGPLv3 was being abused? Did the mentioned companies follow the spirit of the license and were getting away with something the company didn't like or were they just improperly distributing the software, regardless of licensing terms? Also: "So while the SSPL isn’t all that different from the GNU GPLv3,(...) [it] explicitly states that anybody who wants to offer MongoDB as a service (..) needs to either get a commercial license or open source the service to give back the community." Doesn't AGPLv3 already require open sourcing server side implementations? Thanks in advance
- shadowmint 8y agohttps://webassets.mongodb.com/_com_assets/legal/SSPL-compared-to-AGPL.pdf?_ga=2.32522554.548222804.1539700834-1057506187.1539700834 https://webassets.mongodb.com/_com_assets/legal/SSPL-compare... “Service Source Code” means the Corresponding Source for the Program or the modified version, and the Corresponding Source for all programs that you use to make the Program or modified version available as a service, including, without limitation, management software, user interfaces, application program interfaces, automation software, monitoring software, backup software, storage software and hosting software, all such that a user could run an instance of the service using the Service Source Code you make available.” ^ not the same.
- notacoward 8y agoThe "all programs you use" clause seems to make it extremely viral, perhaps unprecedentedly so. It seems to me that anyone not willing to comply with AGPL would be even less likely to comply with this. Not sure how that's supposed to be a good outcome, even for Mongo.
- amyjess 8y agoThis sounds like a violation of provision 9 of the Open Source Definition and the DFSG. It's going to backfire hard when distros start removing Mongo from their main repos.
- jamescun 8y agoI guess this explains why MLab submitted to MongoDB's acquisition after all these years, let us buy you because we're killing your business model. https://blog.mlab.com/2018/10/mlab-is-becoming-a-part-of-mongodb-inc/ https://blog.mlab.com/2018/10/mlab-is-becoming-a-part-of-mon...
- beck5 8y agoThe article references cloud providers, "especially in Asia", frustrating MongoDb, does anyone know which companies these are or specifically what they have done which other did not?
- hendzen 8y agoYandex is one example: https://cloud.yandex.ru/docs/mdb/ https://cloud.yandex.ru/docs/mdb/ Probably the big public cloud providers in China (Alibaba etc) as well.
- zokier 8y agoThe license is clearly based on (A)GPL which is copyrighted by FSF, and has the following notice: "Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed." Does that mean that MongoDB is now infringing on FSF copyright of the license text itself?
- metheus 8y agoSSPL is based on the GPL, not the AGPL, so no, the SSPL isn't itself a copyright infringement. BTW, check out the "What specifically is different between the GPL and this new license and what will it be called?" section of the FAQ: https://www.mongodb.com/licensing/server-side-public-license/faq https://www.mongodb.com/licensing/server-side-public-license...
- zokier 8y ago> SSPL is based on the GPL, not the AGPL, so no, the SSPL isn't itself a copyright infringement I don't see how the distinction makes a difference here, both have the same clause about changing not being allowed.
- metheus 8y agoOh, sorry, that was a non-sequitur. The actual reason is that text doesn't mean you can't modify them and create new licenses, it means you can't modify them and still call them A/GPL. https://www.gnu.org/licenses/gpl-faq.en.html#ModifyGPL https://www.gnu.org/licenses/gpl-faq.en.html#ModifyGPL
- thekozmo 8y agoI've written a blog about this: https://www.scylladb.com/2018/10/22/the-dark-side-of-mongodbs-new-license/ https://www.scylladb.com/2018/10/22/the-dark-side-of-mongodb... Spoiler: It's a big nono Disclosure: I'm ScyllaDB co-founder
- mattl 8y agoFSF has historically let others make new licenses based on its own as long as they name it in a way that is not likely to be confused with any of the GNU licenses.
- hendzen 8y agoDisclaimer: IANAL. From MongoDB, Inc's POV, its fine to run MongoDB in-house for the purposes of supporting some user-facing application. Coinbase would be a good example, they make a consumer product that uses MongoDB as the storage backend. What is definitely not allowed is selling fully hosted MongoDB instances. E.g. (https://cloud.yandex.ru/docs/mdb/ https://cloud.yandex.ru/docs/mdb/). To do this you will need to open-source all the supporting infra/automation code which will be a deal breaker in many cases. The real grey area is a service like Parse or Firebase that is built on Mongo but offers a Mongo-like DBaaS. Is it against the SSPL to build a service like that? Or is MongoDB, Inc trying to force everyone to use its MongoDB Stitch service [0]? [0] - https://www.mongodb.com/cloud/stitch https://www.mongodb.com/cloud/stitch
- merb 8y ago> To do this you will need to open-source all the supporting infra/automation code which will be a deal breaker in many cases. it isn't actually I guess google runs their RDS on kubernetes anyway.
- oropolo 8y agoI might be reading this wrong, but doesn't this qualify as a "super viral" license in that any code that in any way is part of the stack for hosting Mongo as a Service must be open sourced as well? Granted, a company could buy a commercial license to avoid this but if (for the sake of example) Azure's Mongo hosting was using the open source license would this mean that EVERYTHING that goes into Azure, down to Windows "Redstone" source code, would need to be released?
- lacker 8y agoYeah. In practice I think the AGPL was already preventing AWS / Google / Azure from selling Mongo-as-a-service, and this license will go even further.
- e12e 8y agoI think this is what a few of the "new" db companies thought the AGPL was (neo4j comes to mind). Not simply "if you write a new query parser and link it into our db, any SaaS customers must get the modifications so the can continue running the service for themselves if you go under.", but more "if manage to extract value by hosting this software, you must give us a cut or all your code". I guess there'll be a fork, like with matiadb/mysql?
- andrewjmyers 8y agoI'm just here for the promised comment drama.
- mrkurt 8y ago(Context: I worked on Compose/MongoHQ for a very long time. We were the first to monetize MongoDB) I'm sure people will get riled up about this, but it makes sense. Building a business on an OSS database in a world of behemoth cloud providers is really hard. It's clear Google and Amazon (and maybe even Azure) are comfy taking OSS work, doing a ton of proprietary development on it, and leaving the companies who did all the groundwork flailing in the wind. These things are going to keep happening as long as mega tech companies (a) use OSS to commoditize other companies' products and (b) exploit permissive licenses to the max. I don't want to live in a world where the only infrastructure software we have access to is what the big companies deign to open source. Life is better when small groups of devs can build and sustain critical infrastructure software. We need more haproxies and redises and binds and (fill in blank). That said, MongoDB has never figured out how to work with their ecosystem in a way that's good for everyone. They've gone from trying to extort money from smaller companies to undercutting them to this. And it's likely not gonna change much this time, the world of "run a database as a service" is changing I think, and being replaced with more generic tools that just so happen to manage complex persistence well. _Also_ I bet some random licensing folks are crapping their pants at IBM right now. I'm ashamed at how funny that is.
- oropolo 8y ago> It's clear Google and Amazon (and maybe even Azure) are comfy taking OSS work, doing a ton of proprietary development on it, and leaving the companies who did all the groundwork flailing in the wind. Have you seen the degree of investment Microsoft has made lately in Open Source? It's an upside-down world where Microsoft if a bigger champion -- and funder -- of open source than a company like Google which was built on Open Source software.
- DannyBee 8y agoHere, i'll make a provocative statement: Google has released roughly every meaningful patch it has made to the open source software it was built on[1]. As for funding, that's definitely not true by the numbers last i looked (and definitely was not true in the past). Without concrete disagreements, this is just handwaving. So if you make some, i'm happy to argue with real data. [1] The only cases i can think of that this isn't true is when the Googler who worked on it left before they got a chance to do that (and nobody has picked it up since)
- oropolo 8y agoThis license seems to insure that MongoDB Inc either gets all source code to Mongo-as-a-Service from their competitors (which they can use to make a better service themselves) or they make money from all of their competitors through commercial licensing. Perhaps Oracle is preparing to acquire MongoDB Inc and this move is a prerequisite to acquisition?
- bad_user 8y agoI hope OSI and the FSF don’t approve their new “SSPL” license. AGPL style licenses impose restrictions on usage, thus violating freedom 0 in the Free Software’s definition or Open Source’s rule 6. AGPL should have never been allowed, precisely because it opens the door for commercial entities to eat their cake and have it too, being the kind of license that can be effectively used to disallow commercial products built on top. In my opinion your own modifications that are never distributed (by the copyright definition) represents mere usage. And we’re software developers after all, personally I patch most of the libraries I end up using and some patches I may contribute back, but I’m definitely not required by any license. “Open Source” and “Free Software” have great sex appeal, I get it, but if you can’t deal with competitors benefiting from your work, which is the whole point of such an endeavor, then don’t do FOSS. Go proprietary and be honest about it.
- amyjess 8y agoThis new license also gratuitously violates rule 9. Mongo just made a big mistake.
- nas 8y agoYeah, I agree it is not an open source license based on rule 9 alone. I mean, the reason for the license not being open source is not an accident. It's not some unforeseen side effect. Their whole purpose of changing the license is to restrict the freedoms of the service companies using the software. I'm somewhat sympathetic to MongoDB for wanting to extract money from them or to force them to work with the open source community. However, you can't have your cake and eat it too. Forcing them that means your license is not open source.
- nepeckman 8y agoCompletely disagree. How does AGPL interfere with your ability to run a program? I can clone any AGPL software and run it for whatever purposes I want. It also doesn't discriminate against any field of endeavor. I can run AGPL software and charge for it. "Distribution" has changed since 1991 and AGPL extends the viral qualities of GPL to apply to internet services, which is a Good Thing for free software.
- kbumsik 8y agoI personally see why MongoDB switches its license and clarify their original intention of using AGPL. I even didn't know it was AGPL until now (I'm not MongoDB user). Because so many people seem to use it as if it is Apache License or something free of charge. I haven't see any warnings on AGPL and its implications in MongoDB tutorials on the internet.
- mrkurt 8y agoThe drivers are all permissive OSS licenses. It's on purpose, they never wanted to own applications that are built on top of MongoDB, but they never wanted to give away the server bit either.
- kbumsik 8y agoI meant people seem to install the server too, thinking that the server itself it free. Most of MongoDB tutorials on the internet starts with "how to install locally" without mentioning nothing about the license.
- nepeckman 8y agoThe server _is_ free. As long as you don't modify the server, you don't have any obligations. If you do modify the server, you're only obligated to publish the changes you made to the server. No one is at risk of violating the license by installing it locally and using it in an application.
- lacker 8y agoThe server _is_ free. As long as you don't modify the server, you don't have any obligations. Well, that isn't true any more. If you start selling MongoDB functionality as a service, you now have obligations, even if you didn't modify it.
- nepeckman 8y agoYeah good point, though even under this new license, you shouldn't face issues for locally installing the server and using it in your application.
- vbezhenar 8y agoThey are hurting their own ecosystem, trying to get more money. Not a real open source project, just proprietary software mimicking open source. Compare to PostgreSQL, it's absurd to think that they would forbid using PostgreSQL as a service.
- mindcrime 8y agoMy biggest problem with this is just that it contributes to "license proliferation" even if OSI certifies it. It muddies the waters and makes OSS licensing that much more confusing. In this regard, I'm fairly leery of it. As for what they're trying to accomplish... it sounds like a slightly different version of the AGPL (in spirit), and while I'm not the biggest fan of the AGPL and similar licenses, it's not the abomination that the Common Clause stuff was. This seems to just be saying "if you want to offer a MDaaS (MongoDb as a Service), you have to release the source code to the entire service". It's probably not a license I'd choose, but it's not exactly unreasonable. Disclaimer: I haven't read the entire license yet, so my comments above are based on other people's summaries / the text of the article linked above. My opinion is subject to change once I've had time to digest this fully.
- super3 8y agoWhat really should happen is that the large cloud companies (really just Google, Amazon, and Azure) should be providing a portion of the revenue generated to the open source projects. The open source companies would make more features and drive more usage. Everybody wins. It makes no sense that the large cloud providers make billions off OSS, and don't give something more sustainable back. Classic tragedy of the commons. Disclaimer: My company Storj is building a distributed Amazon S3 competitor and we are actually partnered with MongoDB. We share revenue with MongoDB for any customers they bring us.
- algorithmmonkey 8y agoIsn't this the point of licensing? The author or company building the software requires money in exchange for using their software. The revenue acquired through the license is then use to pay for additional development. Revenue sharing seems to imply some kindness / goodwill agreement.
- mygo 8y agoI reckon they’re doing what people from some parts call a commission Paying for a license won’t get you customers but paying for referrals will
- swozey 8y agoYour 3 examples have a LOT of swes that work full time on open source/cncf projects not to mention they're platinum members of CNCF/Linux Foundation, etc. So I think that's a bit disingenuous. They're not funnelling billions into those tunnels but a huge majority of contributors are Redhat, Google, Coreos, Huawei, Alibaba, Intel and various other big names that definitely use open source tech and provide a huge benefit to us that are consuming it. K8s is moving so fast it's hard to even follow. Kubernetes was donated to CNCF and there are a lot of Google SWEs working on "removing Google" from the actual project to make it more cloud native. I really have a hard time picturing the success of CNCF/etc without the big names.
- wmf 8y ago
- jchw 8y agoPeople weren't "testing the boundaries" of AGPL. You need to know nearly nothing about AGPL to understand this. The bottom line is, AGPL merely requires you to publish your modifications. But if cloud providers are offering essentially a vanilla MongoDB instance, there is no reason they are compelled to buy a commercial license. Still, I wonder where MongoDB actually wants the boundary drawn. Anyone that tries to offer the MongoDB protocol as a service using the official code? Or is it if I provide a database interface to a MongoDB instance? Or is it only if the actual MongoDB interface from the MongoDB server is provided? I haven't read their new license but I have a strong feeling that it won't be 100% clear yet.
- e12e 8y agoAnd will they break the protocol in order to break compatability with AGPL forks?
- jchw 8y agoThis would be futile. The forks could still implement the protocol changes as long as they didn't take code from upsteam to do so. I believe there is also case law that supports the legality of reverse engineering for interoperabilility as well. I wonder if that has implications on this.
- pauldix 8y agoI don't think this really changes anything with MongoDB and how open or closed it is in practice. This really is just MongoDB clarifying their original intent with picking the AGPL. Basically, if you're going to offer MongoDB as a service, you either need to make all your service's code freely available, or you need a commercial relationship with MongoDB. This doesn't change anything for users of the software that are building applications. This is just another highlight of the cloud vendors making it very difficult to build a business based on open source infrastructure software. Either you pick an infectious license (like AGPL) or you go open core. Otherwise, if your project gets popular, the cloud providers will offer it as a service, which will eat into your revenue.
- gukspbk4gnnh 8y ago> some cloud providers — especially in Asia Alibaba & Tencent have been offering managed MongoDB offerings for a while but MongoDB, Inc. has historically not made any major investment in its own managed offering (Atlas) for that market. This license shift is aimed squarely at AWS, who is rumored to be ready to announce/release their own MongoDB-compatible service at AWS re:Invent next month.
- holografix 8y agoIs there an OSS license where it won’t allow other providers to offer the original technology as a service and charge for it? If I want to use MongoDB in my ecommerce app no worries. If I want to simply use MongoDB offer some minimal improvement or added functionality, call it ZongoDB and sell subscriptions... not so fine?
- mindcrime 8y agoIs there an OSS license where it won’t allow other providers to offer the original technology as a service and charge for it? No, because such a license would - by definition - not be an Open Source license. That's basically what the Common Clause says, but a license with that clause attached isn't OSS.
- saurik 8y ago(With the caveat that I think what really matters here is "and hoard changes and updates", not "make money at all":) The AGPL comes to mind, but I bet that is slightly too viral? It is a hard problem: how do you legally differentiate a web app built on top of MongoDB from a thin wrapper for MongoDB that provides a minority different API from the backend (or might even simply be a load balancer)?
- metheus 8y ago"Software as a service" is a well understood concept, and on the strength of that understanding, the SSPL is clear. (Although as with all things there are edge cases, there aren't more edge cases with the SSPL than with other licenses.) If your web app uses MongoDB (or any SSPL licensed software) to provide a value that is not substantially MongoDB itself, you are not making the software available as a service. If your code facilitates making MongoDB's features available to other users, you are providing MongoDB as a service and are obligated to make all that code available under the SSPL.
- perlgeek 8y ago> Is there an OSS license where it won’t allow other providers to offer the original technology as a service and charge for it? No. Open Source always implies freedom to use for any purpose. There might strings attached such as the need to open-source modifications as well, but if usage itself isn't free, it's not Open Source.
- DannyBee 8y agoFWIW: This license is almost certainly incompatible with GPLv3. They struck the portion of section 13 that allowed for such combinations. (You can see it in the redline they published here:https://webassets.mongodb.com/_com_assets/legal/SSPL-compared-to-AGPL.pdf https://webassets.mongodb.com/_com_assets/legal/SSPL-compare...)
- codemac 8y agoIt's interesting, because it seems they're making an even stronger license, requiring source to be available over a network for download - it seems they could have left that paragraph in.
- gnulinux 8y agoYes this is even more restrictive than GNU AGPLv3. If FSF is ok with these changes they might even approve it (GNU AGPLv4? Recall that AGPL wasn't a thing before Affero made it).
- detuur 8y agoEveryone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. Can someone enlighten me on the significance of this piece of text? Does it mean you're not allowed to edit the license and publish it under the same name, or does it effectively copyright the entire license text? I'm gravitating towards the former since this is a case where the text was edited but renamed, but I'd still like some clarity. As an aside, is it even possible to copyright a license? There's a copyright notice so isn't this technically plagiarism?
- qaq 8y agoI think long term model of Company opensourcing primary product will fail outside of projects that are targeting niche too small for Azure/AWS/GCP to monetize.
- vmbrasseur 8y agoVice President of the Open Source Initiative here. MongoDB submitted this new license for approval by OSI at the same time that they announced that they'd relicensed all of their code. We wish they'd started the process prior to the announcement, but what's done is done. The result, however, is that at this moment, MongoDB is under a non-approved license and therefore IS NOT OPEN SOURCE. As the license review process only started this morning, there's no way to estimate how long the process will take. There also is no guarantee that the license will be found to obey the Open Source Definition, and therefore no guarantee that it will be approved. Hopefully this will all be resolved soon, but there are far too many question marks around this license (and therefore also around any software using it) right now. It's probably best to limit your legal risk by not upgrading to an SSPL-licensed MongoDB at this point. The previous AGPL-licensed version should always be available.
- vasco 8y agoYou don't own the term open source mate.
- FooBarWidget 8y agoYour opinion isn't the only one out there. I recognize the OSI as the authority on the term open source. On a more practical level: who do you consider be the authority? If the answer is 'nobody' (except yourself) then that makes the term essentially meaningless because there is no standardization, which means that one should stop using that term.
- sangnoir 8y agoMongoDB recognizes OSI as an authority as well, which is why they submitted their license to OSI for approval. Which led us to this moment, where OSI has not (/yet) granted that approval, and that apparently raised gp's hackles for some reason.
- twblalock 8y agoMongoDB recognizes that OSI approval is a nice thing to have as a selling point. I very much doubt that they accept the OSI as an authority that can make binding rules and regulations about who gets to call their software "open source".
- emayljames 8y agoI predict a fork coming mongodb's way.
- threeseed 8y agoMongoDB has already been forked 3,760 times on Github. No need to thank me but I pressed the fork button again just to make your prediction come true.
- a13n 8y agoSo what does this mean for IBM's Compose?
- filoteo 8y agoIm wondering the same thing !
- nine_k 8y agoThe meat of the change: SSPL explicitly states that anybody who wants to offer MongoDB as a service — or really any other software that uses this license — needs to either get a commercial license or open source the service to give back the community. Looks like a pretty straightforward extension of GPL principles, by replacing the linking of licensed code to remotely calling the licensed code. It can have a lot of implications for service providers and commercial developers alike, depending on the way commercial licenses will work. (Some DB licenses have pretty stifling clauses, like Oracle's or MS SQL's.)
- johncolanduoni 8y agoMongoDB was already under the AGPL (which adds the copyleft via network provision) so I suspect there is a bigger difference than that.
- nine_k 8y agoAGPL requires you to share the changes to the licensed software you make available, that is, changes to the MongoDB itself. It was like LGPL in the local case: you alter the library and make it available through the software you link with it, so you have to share the changes you've made to the library, but not the rest of the linked code. With SSPL, it's like the full GPL in the local case: if you take the licensed software, and link it (via rpc / network) to your other software, you must share not only any changes you've made to the licensed part, but the whole thing that uses it. Another tricky question is where the border line is. If I write a wrapper that interfaces with MongoDB and repackages its data, then makes them remotely available to the rest of my service, do I only need to share the wrapper? If not, and any network connection that substantially uses an SSPL piece counts, then do I have to share my internal monitoring system? Am I even allowed to connect closed-source data analysis tools to an SSPL database? Etc.
- metheus 8y ago> if you take the licensed software, and link it (via rpc / network) to your other software, you must share not only any changes you've made to the licensed part, but the whole thing that uses it. Slight modification makes this accurate to the SSPL: if you take the licensed software, and link it (via rpc / network) to your other software which you use to offer the SSPL licensed software as a service, you must share... > Another tricky question is where the border line is. Ultimately the trigger of the SSPL is whether what you offer publicly is the SSPL-licensed software as a service. It doesn't trigger the SSPL if you make MongoDB available as a service to your application internals as long as what you're making available publicly is not "a service the value of which entirely or primarily derives from the value of the Program or modified version..."
- kureikain 8y agoMongoDB gots lot of interesting features recently and probably got to a stable line. They also have lot of product around MongoDB ecosystem: - Atlas to deploy - Stitch to run serverless - Chart for BI So they basically want to protected their leverage, which make sense to me.
- ken 8y agoIt's their code so (under current law) they can license it however they want. I see some potential issues, though. > "Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate." I don't see how to reconcile this with the new section 13, which seems to say exactly the opposite. What does this section mean, now that section 13 was completely changed? > it has now submitted the SSPL for approval from the Open Source Initiative IANAL but I don't see how it satisfies part 9 of the OSI Definition, or the DFSG. As DannyBee already mentioned, it's also incompatible with other existing open-source licenses. Why do they want to continue calling it "open source"? It sounds like they really just want to be a proprietary database. > For virtually all regular users who are currently using the community server, nothing changes because the changes to the license don’t apply to them. Really? It's written in a way that sounds like it captures all users under the same umbrella as resellers. If I wrote a data analysis web app that happened to use MongoDB (as one of my previous employers did), isn't that a case of adding "user interfaces" (and "storage software and hosting software") for it, meaning I'd need to provide source code for "all such that a user could run an instance of the service using the Service Source Code you make available"? I can't find any license pricing info on the MongoDB webpage, but some googling turned up a whitepaper that puts MongoDB licensing at around $11,000 per server per year. That basically means MongoDB's own "cloud" services are the only game in town. ("No, Mr Bond, I expect you to die.") That means there's a single provider of this API, and you can't afford to run your own server, so it's essentially cloud-only, and it might not be legally compatible with other open-source software you want to use anyway. That's a whole lot of risk you're asking me to take on. Is MongoDB so much better than any free database, for any new users, that it's worth this risk?
- rand0mthought 8y ago> IANAL but I don't see how it satisfies part 9 of the OSI Definition, or the DFSG. As DannyBee already mentioned, it's also incompatible with other existing open-source licenses. Why do they want to continue calling it "open source"? It sounds like they really just want to be a proprietary database. They want to charge money and have control as a proprietary database. But they want to keep a label "open source" purely for marketing purposes.
- jillesvangurp 8y agoIMHO a better move for them would have been to clear up the legal minefield that comes with AGPL and move to a more business friendly license like the Apache 2.0 or MIT license. These licenses are well understood and don't cripple your users in any way. I don't get why any business would want to scare their new users with a license like the AGPL that I would argue is explicitly designed to create legal uncertainty like that and popular with companies like Mongo primarily for that reason (as opposed to some strong freedom related moral arguments). Inventing your own license because the AGPL is giving your users to much freedom sounds rather desperate (not to mention misguided). Changing the license to Apache 2.0 might actually make them much more attractive as an acquisition target for any of the big tech companies out there looking to add something like mongo to their portfolio. I'd argue AGPL is actually an obstacle for most of the bigger companies out there that have existing business relations with their customers based on more business friendly licenses. It would also enable lots of people to experiment with using mongo without legal worries and thus enable them to refocus their company around actually creating value for their paying customers without alienating the vast majority of non paying users with complicated licensing options. Companies like Elastic (which recently did their IPO) are having plenty of success with using the Apache 2.0 license without compromising on commercial success. Their developer ecosystem includes lots of outsiders in the apache community, the academic community, and users. The reason they are doing pretty OK is that they have a decent monetization strategy that involves delivering actual value to their customers: stuff their users want and are willing to pay for. Stuff like proprietary add-ons (e.g. machine learning) on top of what they ship for free, good support, training, cloud based hosting, consulting, etc. We use their hosted Elastic cloud and I'd argue it is pretty good value.
- amirathi 8y agoNone of OSI's Open Source licenses (including AGPL) protect creators financial interest in the cloud first world. Period. I want to issue "View and Internal Use License" for my work. Anyone can view the source code, modify, and use the software for their own benefit as they see fit. Under no circumstances can anyone sell/re-distribute/host the paid version of software or any derivative thereof. Why can't OSI create such a license? I understand the spirit of OSI is to foster more usage of open source software. I admire it. But probably a LOT of open source software is not getting built in the world because it's not possible for everyone to spend few months/years of their prime without any financial outcome (not even a possibility of it). I'm a developer who spent 3 FULL days reading up licenses for my indie project [1] that I aim to make some money with. Not even a single license was adequate to protect me from large teams/companies if the software were to become popular. I resorted to only open sourcing a required critical library [2]. [1] https://www.nurtch.com/ https://www.nurtch.com/ [2] https://github.com/Nurtch/rubix https://github.com/Nurtch/rubix
- the_af 8y agoThe license you describe, while definitely useful, is not open source by any meaningful definition of the concept. I don't mean "not OSI open source", but "not open source as the term has evolved". Similar licenses have been tried (see Microsoft's Shared Source Initiative) and you can definitely devise one yourself and no-one can stop you. The "world" won't let you call your license open source for good reason: it's not open source.
- amirathi 8y ago> The "world" won't let you call your license open source for good reason What is that good reason? Is prohibiting commercialisation of my work not in the spirit of open source? How is my "View and Internal Use License" bad for the open source ecosystem?
- the_af 8y ago> Is prohibiting commercialisation of my work not in the spirit of open source? Exactly, it's not. > How is my "View and Internal Use License" bad for the open source ecosystem? Whether it's bad is a value judgment I can't answer; it's not open source because it forbids redistribution of the source.
- gregwebs 8y agoMy reading of the below essentially says: you cannot offer MongoDB as a (closed) SaaS (without purchasing a license). There will be debate though about how far-reaching this clause is. Note that MongoDB as the copyright holder is giving themselves a different license for running Atlas. I don't know if this is the only change to the license, but the below is certainly not part of the AGPL: 13. Offering the Program as a Service. If you make the functionality of the Program or a modified version available to third parties as a service, you must make the Service Source Code available via network download to everyone at no charge, under the terms of this License. Making the functionality of the Program or modified version available to third parties as a service includes, without limitation, enabling third parties to interact with the functionality of the Program or modified version remotely through a computer network, offering a service the value of which entirely or primarily derives from the value of the Program or modified version, or offering a service that accomplishes for users the primary purpose of the Software or modified version. "Service Source Code" means the Corresponding Source for the Program or the modified version, and the Corresponding Source for all programs that you use to make the Program or modified version available as a service, including, without limitation, management software, user interfaces, application program interfaces, automation software, monitoring software, backup software, storage software and hosting software, all such that a user could run an instance of the service using the Service Source Code you make available.
- unethical_ban 8y agoI'm embarrassed by the lack of comprehension people have for the idea of the OSI saying something isn't open source. The OSI has been around for a long time, has a consistent track record of helping organize FOSS licenses and create a framework/lexicon for this very purpose. They absolutely have the right to say if something is open source or not, according to their rules, just like anyone here gets to make their opinion heard on something. "Appeals to authority" make sense when the authority is credible, and shortcuts having to explain the four freedoms, etc. --- To the article: It sounds like the SSPL will eventually be OSI-OSS, but I wonder if they couldn't have worked with GNU to create a new version of the AGPL. Granted, GNU might take exception to the idea of "oka you don't have to share the code, you just have to pay us" portion.
- gfosco 8y agoI think it's more about the tone and the caps lock, than the exact words, although you shouldn't be embarrassed if some people disagree and think the phrase has been generalized. If anything, I think it might be embarrassing how many "defenders" jumped in and prolonged this drama, instead of just downvoting and moving on with their day. How's this for a conundrum: I support the OSI being able to claim it isn't "open source" according to them, but I think the top-level post by the VP was unprofessional and rightly called out. (I have not commented elsewhere in this thread.)
- exabrial 8y agoYou assume this "Intellectual Property" or "Copyright" thing exists in China. After working for a Chinese company, the concepts don't have an analog in their culture. Actually the concept of licensure in general doesn't have a good analog. They see open source as free and sort of brush off the strings that are attached. (this btw, should not be interpreted as bad mouthing them; I'm merely pointing out a communication problem between two cultures).
- kolderman 8y agoWhat does "switches up" mean?
- fareesh 8y agoDoes MongoDB still suffer from data loss related issues? I checked out their website and it seems to be fairly ubiquitous in usage
- jpalomaki 8y agoIIRC MySQL had a bit similar troubles with GPL license. They disliked the fact that some companies shipped closed source software which in practice required MySQL, but instead of getting the paid license, they relied on the open source version. Google revealed one relevant article: According to C|net their vice president of marketing said in 2002: "There were people misusing the GPL, using our server tightly coupled with their applications, claiming the GPL didn't apply because the client libraries weren't under the GPL, they were under the LGPL," [1] According to the article, MySQL decided to sort out this issue by changing the license of the client libraries from LGPL to GPL. [1] https://www.cnet.com/news/mysql-addresses-open-source-license-problem/ https://www.cnet.com/news/mysql-addresses-open-source-licens...
- ousta 8y agoI guess next one that will do that - if this works- will be elasticsearch and they will then have to fight amazon on this. The risk being that if someone does a better job than MongoDB at creating features for mongoDB they might loose their product as well playing that card.
- PeterZaitsev 8y agoIn my opinion whenever SSPL is classified as Open Source license or not they could have done better job rolling it out. Making announcement and having all MongoDB Community Software change license the same day for all current major versions (not just new major releases) is not very friendly to users of such software Many companies which are serious about their software licenses will need to evaluate whenever they can use SSPL, in the meanwhile being left without access to security updates... not a good place to be. Though I suspect MongoDB would just like such companies to use Commercially Licensed Enterprise Version and not deal with all these Open Source (or not) license change Advance Submission to OSI and validating it as Open Source License would reduce the concerns of companies looking to use MongoDB Community as they could rely on OSI's legal analyses rather than perform their own
- pron 8y agoIf SaaS vendors haven't opened their software that uses Mongo under AGPL then I would assume that the additional software (which would count as another "part of the aggregate" according to AGPL), then it must have been substantial. In that case, how does one determine if one is "offering a service the value of which entirely or primarily derives from the value of the Program or modified version, or offering a service that accomplishes for users the primary purpose of the Software or modified version"? I assume that an online game that uses Mongo to store player data clearly does not derive its value mostly from the database, but is the value of a PaaS built on Mongo, with an elaborate UI and management services derived primarily from the value of Mongo or not? Is the value of an online recipe management service? In both cases I can see compelling arguments in either direction. One could argue that if the value derived primarily from the DB, then very little software would need to be added and open sourcing it would not be an issue. That vendors don't open source their software shows that they believe its value does not come primarily from Mongo, and so they would be able to continue using it under the new license, defeating Mongo's purpose.
- MrStonedOne 8y ago>MongoDB switches up its open source license The correct term is forked. They forked the agpl and made modifications.
- xmichael999 8y agoThe prohibition on providing the software as a service appears to conflict with, or at least be trivially bypassed by, section 9 which states that to run the software you don't have to accept the terms of the license. Section 9 conforms with the law as written: running the software, and making the copies needed to run it, are explicitly not an infringement of copyright (USC Title 17 section 117(a)(1) [cornell.edu]). If I don't have to accept the license to do something, I'm not bound by it's terms merely because I do that something. https://www.law.cornell.edu/uscode/text/17/117 https://www.law.cornell.edu/uscode/text/17/117
- sbr464 8y agoThis question isn't directly associated with MongoDB, please forgive my lack of OSS license expertise. I was curious if exceptions were allowed under licenses like these. For example, if a company releases a GPL licensed product, (or SSPL etc) and wishes to create another product/service that they don't wish to open source, but it's based on the GPL/SSPL codebase. Could they make exceptions or separate license agreements to go around their own license choice? Would it be different if it were a third party they would like to give this exception to? In similar regard, would MongoDB have to prove that they are paying full licenses/Enterprise agreements to themselves to be able to run Atlas (their own cloud offering) and not open source Atlas? Or is there a self exclusion allowed etc? Or would they just sell themselves the licenses for $0.01 cent to get around the requirement? Truly interested in this question. Edit - and to clarify, not if the exception is stated directly in the license like a new modified MIT etc, but inherent to the existing popular OSS licenses.
- Lazare 8y agoIf I own a block of code, I can release it under as many licenses as I like, even if those licenses would totally conflict, and then each one of my users will need to track which license they received it under and adhere to those terms (only). So yes, I can give Users 1, 4, and 5 a copy under the GPL, and then users 2 and 3 a copy under some commercial license, user 6 under some GPL incompatible copyleft license, no problem. The key is where you say "wishes to create another product/service that they don't wish to open source, but it's based on the GPL/SSPL codebase". You're not creating it based on the GPL codebase, you're creating it on the codebase you own. The fact you've previously licensed it under X, Y or Z licenses is irrelevant; you can always release it again, in whole or in part, with whatever license you like. (But of course, whatever you released under the GPL is still out there, under the GPL; there's no take backs!) And you can also, of course, use it yourself however you like. The key is ownership. If you own the copyright on the code, you're fine. If you don't, you must adhere strictly to the license which the actual owners granted you. To the extent that MongoDB (the company) owns the copyright on all the code, they're free to use it how they like, and release it as often as they like under whatever licenses they like.
- 8y ago
- runciblespoon 8y ago“MongoDB switches up its open source license” Is that the same as modify and/or improve?
- l2dy 8y ago> Making the functionality of the Program or modified version available to third parties as a service includes […], or offering a service that accomplishes for users the primary purpose of the Software or modified version. Would this apply to independent implementations compatible with MongoDB?
- thayne 8y agoForgive my ignorance, but how is this different from the AGPL?
- mrahmadawais 8y agoAs an open source dev, I think the new SSPL license of @MongoDB is interesting. SaaS is the new black nowadays, I have seen too many companies burnt down trying to support their OSS licensing with SaaS taking all the benefit. SSPL can help #OpenSource. I also think that SSPL can be very helpful if you want to open source your SaaS. Most of the startups that I consult with are not interested in open sourcing their actual SaaS software since they fear being ripped off. So, what happens is that they end up not taking the benefit of open source. With SSPL these SaaS companies will be able to open source their SaaS is software to manage SaaS — without the fear of being misused by competition. If the competition just takes their free software and makes money with SaaS that hurts them instead of helping them since you can't make sure that other SaaS players will actually contribute back to the software. With SSPL, we get a safety net — companies either won't use it as a SaaS, will pay to use it as a SaaS i.e. they'll help pay for open source software support which is a very good business model and if not that, then they'll have to open source their SaaS as well. As a non-lawyer developer, it feels like GPL. GPL code that you fork should remain GPL. Similarly, if SSPL code you use as a SaaS then you should keep your SaaS as SSPL and open source it as well. Peace! ️
- bkuhn 8y agoI posted my response on a blog post at: https://sfconservancy.org/blog/2018/oct/16/mongodb-copyleft-drafting/ https://sfconservancy.org/blog/2018/oct/16/mongodb-copyleft-... TL;DR: while vmbrasseur of OSI does say "what's done is done" in comments here, I think the OSI shouldn't accept the proposal as submitted, and should demand that licenses submitted them to have gone through a prior public drafting process. This is particularly important for licenses whose stated goal is to make fundamental changes to how copyleft works. GPLv3 and (even better) copyleft-next made this the standard of how new license drafts are done, and we should follow that standard.
- vmbrasseur 8y agoMy friend, the "what's done is done" was purely in reference to the fact that the license was submitted for approval belatedly (IMO). My statement in no way implied whether the license itself would be approved as it stands. Now that the license has been submitted, folks can now analyse and discuss it, openly. Any decision on the license will spring from those discussions and the related actions (should any be needed) that MongoDB takes based on the feedback they receive. The proper place for that feedback is on the discussion thread on the review mailing list. Statements on blogs and comments on Hacker News are good for helping to frame that feedback, but aren't well placed to be included in a cohesive conversation.
- erlend_sh 8y agoIt is still unclear to me how the release of any "Service Source Code" is scoped. The license states: > If you make the functionality of the Program or a modified version available to third parties as a service, you must make the Service Source Code available via network download to everyone at no charge, under the terms of this License Would greatly appreciate it if someone could give an example of a MongoDB service company and what parts of their proprietary code they would have to release if they opted not to buy a commercial license .
- grogers 8y ago> “Service Source Code” means the Corresponding Source for the Program or the modified version, and the Corresponding Source for all programs that you use to make the Program or modified version available as a service, including, without limitation... It's as broad as it can be to make it essentially impossible to comply with and force you to use the commercial license. You can't release the Linux source under SSPL, but the OS would almost certainly qualify under this clause (but IANAL). In the definitions it seems to exclude the kernel and "System Libraries" but only if unmodified, it's still a but of a minefield.
- perseusprime11 8y ago"MongoDB is a bit miffed that some cloud providers — especially in Asia — are taking its open-source code and offering a hosted commercial version of its database to their users without playing by the open-source rules. To combat this, MongoDB today announced it has issued a new software license, the Server Side Public License (SSPL), that will apply to all new releases of its MongoDB Community Server, as well as all patch fixes for prior versions." That's how open source works. Isn't it?
- tracker1 8y agoLikely a move since the purchase of mLab to eliminate competition in the services space. Seems a lot like the recent changes with the direction of Redis. Hopefully this spurs some movement in supporting open database communities better. PostgreSQL and RethinkDB being two that come to the front of my mind.
- thekozmo 8y agoI've written a blog about this: https://www.scylladb.com/2018/10/22/the-dark-side-of-mongodbs-new-license/ https://www.scylladb.com/2018/10/22/the-dark-side-of-mongodb... Spoiler: It's a big nono Disclosure: I'm ScyllaDB co-founder