21 ms·
FUSE for macOS is no longer open source
- ixtli 7y agoI read more than two thirds of this blog post before realizing the author doesn’t seem to agree with this guy he quoted: > Then drop it and let someone else maintain it. To be clear, if maintenance of a popular open source project is too much for you then stop. Taking your marbles and going home is childish, if the authors third party analysis of the motives behind Fleischer‘s behavior is to be believed. The post says on one hand that he never financially benefited but then on the other hand that he’s justified in obscuring the source because maintenance is onerous.
- vosper 7y agoRather than "taking [his] marbles and going home" isn't it more like he's exercising his right to finally get paid after working for free for the benefit of others (including, presumably, many commercial users who aren't kicking in a cent) for a very long time?
- dmitriid 7y agoIt's not childish. That's the main problem with open source as a whole: devs expect somebody else to maintain projects indefinitely long, for free. This is what's unsustainable. See "Software below poverty line": https://staltz.com/software-below-the-poverty-line.html https://staltz.com/software-below-the-poverty-line.html
- oefrha 7y agoAs discussed in https://news.ycombinator.com/item?id=20174418 https://news.ycombinator.com/item?id=20174418, with comments from devs represented in that "Software below poverty line" article, the interpretation from the article is seriously flawed.
- dmitriid 7y agoI've skimmed through comments and I can't agree with your conclusion. Most comments are: - it's true - exploitation is a wrong term - you don't take into account devs who are already employees and work on OSS
- IfOnlyYouKnew 7y agoHow is "...then stop" different from "Taking your marbles and going home"? They didn't remove previously-published source code. So you can use the last open release in both scenarios, and the license change only adds the option of getting the maintained version under a commercial license. The commercial version probably isn't useful in many scenarios, but by the simple rules of logic, having any additional option(s) can never be worse than having fewer options. It is, however, somewhat shady to implement this license change without announcing it. Indeed I seem to remember being quite confused by this recently. I also just don't understand why that tactic was chosen? If you want to sell software, it tends not to hurt to make people aware of options to give you money.
- Epskampie 7y agoWell, all I can really think after reading this is “fuck apple”. I’m getting very very tired of their walled off closed shit where they even try to make life as hard as possible for people who try to support it despite the odds. This isn’t the first time either, it happened to VLC before.
- ixtli 7y agoWait what happened with VLC? I didn’t realize they ran afoul of the “Cathedral”
- dmitriid 7y agoThe only thing I can remember is that VLC was removed from AppStore due to GPL.
- Epskampie 7y agoapple kept changing/breaking Api’s to try to kill vlc so that they could try make money of the paid version of the QuickTime player which then existed. I must admit it was just comments made by VLC devs, so it’s anecdotal.
- saagarjha 7y agoVLC is on Apple’s “must not break list” and gets special checkfixes in the OS, FWIW.
- khc 7y agosubmitter and author of goofys here. As I see it there are 3 issues: 1. osxfuse is effectively closed source but the license is not changed 2. there's no open source fuse on latest version of OS X 3. most importantly, having only one maintainer for osxfuse is clearly not sustainable I don't really use OS X so mostly have an interest in this because some of my users are on OS X.
- f1refly 7y agoIt was BSD-licensed the whole time, so it's not like you're entitled to an "open-source" application at all. Pay the guy, or use free software so this doesn't happen.
- angry_octet 7y agoWe need something like carbon credits for open source. As in, if you contribute to open source you earn credits. If you make lots of use of open source but don't contribute back you need to buy open source credits. How we would value open source is a tricky question. Would AWS owe a gazillion credits for all the hours of linux and apache they've burnt? Probably doesn't make sense. Maybe a logarithmic scale. But the real value of open source isn't dollars but people time (which, if you've had a pile of dollars and tried to spend it to employ people to do something, you will know is not the same thing). How many people hours is there in producing something like FUSE, and how many hours saved by end users? Maybe that determines the utility. Until we have a value and a currency for open source there won't be an open source economy.
- fierarul 7y agoFWIW nobody donates their BitCoins. And very rarely their USD. So it's not for the lack of currencies or ways of showing support. People just don't value these projects until they get abandoned.
- driverdan 7y agoI used to only donate in BTC. It reduced fees and promoted the use of BTC as a currency. Unfortunately that's not longer the case. Fees have increased significantly and complexity has increased, reducing the number of non-profits that accept it.
- fierarul 7y agoImho BTC stopped being / trying to be a currency long ago. Now it's hoarded as digital gold. Which explains why it's not spent / donated as much.
- ohithereyou 7y agoTo me, this is the root of the difference between Free (libre) software as defined by the FSF and open source software as popularized by the OSI. The primary case for open source is business and money - money is more efficiently spent on supporting open source, and all of the businesses that spend money on open source get to benefit from contributions from others. In this model an open source economy is desirable because that's how you prevent one greater fool from funding all of the open source software that everyone else uses without paying. The primary case for Free (libre) software is the social utility/social value of the software. Their case is primarily moral and ethical first. They're not against making money on Free (libre) software, but that's not their end goal. Their end goals are political and focused on end users, not businesses. I'm not trying to say one is inherently better than the other, just trying to highlight the differences.
- tambourine_man 7y agoI think the issue is lack of user interest. I’ve tried using FUSE for the Mac many times throughout the years, mostly for curl_fs and ssh_fs. Believe it or not, I’m not happy with the FTP alternatives on the Mac. Transmit is beautiful but buggy and lacks features such as general purpose SOCKS proxy. FileZilla is ugly as sin. Cyberduck is neither pretty nor feature packed. Although it got better recently, FUSE for the Mac has always been incredibly slow and buggy, no matter how many command line flags I added. So between native NTFS read, ExFat read/write and decent for most people remote disk apps, there are probably very few users who care about FUSE on the Mac.
- cerberusss 7y agoThere's also Expandrive.
- tambourine_man 7y agoI briefly tried. Does it work well? Also tried Transmit's mount feature, but wasn't very satisfied.
- cerberusss 7y agoI tried it many years ago. They changed so much in the meantime. But back then, the product was pretty good.
- ChrisMarshallNY 7y agoThat was a very good write-up. Quite fair, and Kool-Aid-free. It is a pretty good synopsis of the issues faced by open-source developers, these days. Much like The September That Never Ended was probably the best thing that ever happened to the Internet, but was really tough on the folks already there, the adoption of open-source systems by commercial entities is making open-source "sexy." Open-source developers (of which I'm one) need to make extra efforts to document and "decorate" their projects, and often dream of "going viral." However, like so many folks have found on YouTube, fame != money. In fact, once your project starts getting all that lovely adoption and enthusiasm, it will also start getting demanding, pithy, threatening and abusive contacts from users. I strongly suspect that a lot of OS developers have walked away from promising projects because of this crap. I'm a stubborn, cantankerous bastard, so I haven't; but I also have the "advantage" of not having any projects that have gone massively viral. It's been a drip that I can use a saucepan to catch; not a deluge. This smells like a business opportunity. Maybe set up a service for OS developers that will field all the abuse for them, and make it real cheap.
- MayeulC 7y agoI'm starting to feel that September is slowing and it might end at some point, that in the end it really is related to the technology adoption life cycle[1]. If you look at the bell curve on that page, its integral is the technology penetration, that is a sigmoid: start slowly (initial period), accelerate (eternal september) for a while, and start to decrease the penetration speed. At some point, enough people will likely have knowledge about the technology that new entrants will take much less time for those already in to bring up. You can argue that those that enter the field now are adopting GAFAM rather than OSS alternatives, but I think that as long as you have the "eternal september" feeling, it means that a lot of people are jumping in, and will in turn help the upbringing of others later in the cycle. Hopefully FOSS culture and knowledge will become endemic in companies at some point; that's all I'm saying. But it's hard, at any point of the curve, to predict where we are in that cycle, and when it will end. I'd be curious to see some data on say, the number of Facebook users. I'm pretty sure it can be seen as a sigmoid.
- 7y ago
- kstenerud 7y agoThis is a very sucky situation to be in, and I've been on both sides of it. I wrote KSCrash [1] a decade ago, and it's become the de-facto standard for crash handling in the Apple ecosystem. I didn't intend for this to happen; I just wanted crash handling MY way. But it's my baby, and I need to support it (technically no, but yes I do), even though I get no financial benefit from it. For a year, I was paid by a private company to supercharge it, but that funding dried up, and as a result the Android port stalled because I took a new job to pay the bills, writing Java code. Musashi [2] is a smaller example. It's an emulator, so it doesn't need nearly as much attention. All the same, a number of 68k based anthology releases for popular game systems used it and contributed neither fixes nor funds. I don't mind so much with this one because, as I said, it's pretty low maintenance. Today, my latest itch is efficient and human-accessible data communications, and so I'm spearheading a new bidirectional, general-purpose, platform agnostic, encryption-capable, transport-agnostic RPC protocol [3], including all of the supporting technology it requires [4] [5] [6] [7] [8] [9]. If it takes off, it will save the entire planet a TON of time, energy, and cost, and I'll probably not see any donations or thanks from those who benefit the most. Please don't take this as complaining. I'm still going to develop and support my babies, because I'm not doing this for the money; I'm doing it to better the state of computing systems (mostly for my own sanity). However, because I'm forced to find separate employment to support my family, it leaves me with FAR less time to focus on these technologies. My estimate would be that I'm running at 1/4 my usual velocity when I require separate employment. For bigger projects that turns a 1 year project into 4 years. However, from a company perspective I also understand. Giving donations is actually a big pain in the ass, especially if it's to a foreign entity. Normal invoices are FAR easier, but then how do you structure it for free access + payment options without pissing people off? It's a tricky situation... [1] https://github.com/kstenerud/KSCrash https://github.com/kstenerud/KSCrash [2] https://github.com/kstenerud/Musashi https://github.com/kstenerud/Musashi [3] https://github.com/kstenerud/streamux https://github.com/kstenerud/streamux [4] https://github.com/kstenerud/concise-encoding https://github.com/kstenerud/concise-encoding [5] https://github.com/kstenerud/compact-float https://github.com/kstenerud/compact-float [6] https://github.com/kstenerud/compact-time https://github.com/kstenerud/compact-time [7] https://github.com/kstenerud/varpad https://github.com/kstenerud/varpad [8] https://github.com/kstenerud/variable-bit-padding https://github.com/kstenerud/variable-bit-padding [9] https://github.com/kstenerud/vlq https://github.com/kstenerud/vlq
- quotemstr 7y agoWhen a FOSS project closes itself off this way, the proper response is to treat it as abandoned and continue development from the last-good version with source available. In particular, MacPorts should not be distributing the binary-only versions. Total disengagement.
- robgibbons 7y agoSomeone should fork it and apply to Apple as a new kext.
- yborg 7y agoYou'd be forking 2 year old code, he hasn't updated the repo in the last 2 years, knowing that the next OS release would leave commercial users at his mercy. Apple also doesn't just hand out kernel extension signing certificates to everyone that signs up for a developer account, you'd have to be someone with some reputation. It was a well-executed fake punt, he'll get people to pay; Catalina is out now and if you want to pick it up from the fork it would take a long time to get it right. That said, I would imagine organizations like Google will make the effort after paying the toll this time because the price will only go up.
- koolba 7y agoI’m impressed with the business savvy applied here. Well played!
- tinus_hn 7y agoIt all sounds clever but obviously Catalina was not released yesterday, it was released some time ago and if a companies software required changes for Catalina they should have noticed many months ago while testing on the beta releases.
- Jerry2 7y agoProblem is that the 2017 version, the last version that's open source, won't run on Catalina (or Mojave or High Sierra for that matter). The amount of fixes and compatibility patches that the author did is quite extensive. Replicating his work would be quite an undertaking and wouldn't be trivial.
- ossworkerrights 7y agoWhy don't you do it for free, after work hours? Man this kind of entitlement boggles my mind.
- mike_d 7y agoIt is buried in the footnotes of the post, but the ultimate reason behind going closed source is that Google built their enterprise GDrive syncing client for mac off a fork of osxfuse. The original author of osxfuse feels entitled to some compensation for that and is doing his damnedest to make it happen.
- khc 7y agothe footnote doesn't say that's the reason osxfuse went close source
- mike_d 7y agoYou can easily infer it if you read the whole article.
- khc 7y agoI did read it but didn't come to the same conclusion
- tra3 7y agoHe doesn’t call google out by name but what grandparent says explains this: > Starting with this release, redistributions bundled with commercial software ... The question is, is google going to call his bluff and pay up or reassign some internal resources? I’m assuming they’d want their gdrive fork to work on Catalina.
- deleted 7y ago[deleted]
- oefrha 7y agoSeems like an entire valid use case of BSD-licensed code. If you don't like it you shouldn't have chosen the BSD license in the first place. Edit: Interestingly, from https://github.com/osxfuse/osxfuse/blob/master/LICENSE.txt https://github.com/osxfuse/osxfuse/blob/master/LICENSE.txt: > FUSE for macOS is a fork of MacFUSE. MacFUSE has been developed by Google Inc..
- newnewpdro 7y agoThis is why permissive licenses are bad news for users.
- kome 7y agoAmen. People have a very hard time to understand this: we don't need concessions, we don't need benevolence: we need rights.
- rahuldottech 7y agoIIRC, FUSE is also required for VeraCrypt to function. So now the source code of this library (module? whatever) that's used by popular encryption software won't be available for public scrutiny. Amazing. The author is, of course, completely within their rights to stop publishing the source code of their software, but this is a real pity. The way to go would be for members of the FOSS community to fork the last version of the source code that was published and continue development, but I don't know who (if anyone) will step up and take responsibility. This also leads to fragmentation, were now you have two popular forks of the same thing which may not be compatible with each other. Sigh.
- stouset 7y agoVeraCrypt is for Windows. This is a FUSE implementation for macOS.
- lars_francke 7y agoVeraCrypt is not limited to Windows, v it runs fine on macOS
- rahuldottech 7y agoYou are mistaken. VeraCrypt supports Windows, macOS, GNU/Linux and FreeBSD. On macOS, it requires FUSE.
- hizanberg 7y agoYou make it sound like there's a tonne of FOSS community on-hand just waiting for the chance to step in and create a popular fork that will lead to fragmentation, when he's effectively been the sole maintainer since 2012 [1]. It's far more likely there will no future well maintained OSS forks, he'll continue developing it as a closed-source product, allowing end-users to install it for free but any company who wants access to his future source code and improvements can compensate him for it. This is a far better outcome than it turning it into abandonware where that will stop working in future macOS versions. > software won't be available for public scrutiny. It's a popular cliche to think all OSS projects have healthy development communities and many eyes pouring over it, but as he's the only person contributing fixes, the only way the product was going to improve is if he spends more time working on it which is more likely to happen if he can get sponsored to continue working on it. None of your fears are likely to come to pass and the health of the project would be far worse off if he abandoned it. [1] https://github.com/osxfuse/osxfuse/graphs/contributors https://github.com/osxfuse/osxfuse/graphs/contributors
- Danieru 7y agoLet's all wait for BSD license apologists to insist true freedom is the freedom to blackmail your users. Props to the OS Xfuse maintainer, he does deserve a fat payout so begrudging him. Still, it paints the clear picture of how BSD is an inferior license when it comes to freedom for users. Maybe this comment is too slashdot 2006 era, but still, licenses matter.
- rahuldottech 7y agoCorrect me if I'm misinformed, but I don't see your point? The original author of code is always free to stop publishing their software as FOSS, regardless of which license they use, as long as they don't try and stop the re-distribution and forking of existing FOSS releases?
- kibwen 7y agoI think copyright makes it more complicated than that. If more than one person has ever contributed to the codebase (and if there's not some explicit copyright assignment), then under copyleft licenses no one person would be allowed to distribute anything containing anyone else's copyrighted code without also making the source available. (Perhaps technically it is the case that that's not "allowed" even in the case of a single copyright owner, but then you'd only have to worry about being sued by yourself?)
- Danieru 7y agoIn this case the original author was an employee of Google and is not the current maintainer. Google then released their implementation under the BSD. It was forked and worked on, and eventually it now comes to the maintainer. Had GPL been used at any point the current maintainer would not own full copyright and thus not have legal grounds to distribute binaries without source. Original authors can only unilaterally change licenses if they were the sole authors, or with agreement of all other authors. Or with copyright assignment contracts as you see in GNU projects. My comment is also not about the maintainer. My comment is about how BSD as a license is often framed as an equivalent choice to GPL or other copyleft licenses. Years ago this was a topic hackers cared a lot about. Not so much anymore I imagine, but there was indeed a time when hackers cared if their software was open source/copyleft or BSD. Most of the online chatter was hypothetical, today it is practical.
- hizanberg 7y agoLikely the best outcome for the project barring company sponsorship that pays him to continue working on it as OSS. He's been the sole maintainer on the project since 2012 [1] and has never been compensated for it, he says it will always be free to end users but wants companies that are financially benefiting from it to help sponsor continued development [2]: > I will never ask end users for financial support. FUSE will always be free. However, what I'm asking for is for companies, that are selling FUSE-based products or rebrand FUSE and bundle it with their apps, to re-invest some of the profits in the continued development of FUSE on macOS, if they can afford it. I don't think that is unreasonable. So he's just exercising the same BSD rights that all the other companies who have been taking and commercializing his work and not contributing back any fixes or funding for continued development. Given that the alternative was to abandon the project [3], the only way it was going to see continued development as an OSS project was is if others took over maintenance/development of it, which anyone is free to do by creating and maintaining a fork. [1] https://github.com/osxfuse/osxfuse/graphs/contributors https://github.com/osxfuse/osxfuse/graphs/contributors [2] https://github.com/osxfuse/osxfuse/issues/590#issuecomment-508021742 https://github.com/osxfuse/osxfuse/issues/590#issuecomment-5... [3] https://github.com/osxfuse/osxfuse/issues/590#issuecomment-501809602 https://github.com/osxfuse/osxfuse/issues/590#issuecomment-5...
- pjmlp 7y agoThis will keep going on, until FOSS community accepts that beyond university projects, someone pumping up their CVs, having a company sponsorship, or being able to pimp it up with some kind of subscription/consulting, there is little to no money to be made and everyone has bills to pay.
- IfOnlyYouKnew 7y agoI'm not sure if the signing process actually matters in this case? If the signing step is the limiting factor in maintaining a fork, he could have switched to the GPL and achieved the same result (commercial redistribution requiring a paid license) while maintaining the benefit of being open source.
- thayne 7y agoI'm surprised it doesn't say anything about security concerns with depending on a single individual to develop a kernel module without any ability to audit the code.
- pacifika 7y agoLet’s assume that is because when commercial companies contact him they pay for being able to audit the source?
- tonyedgecombe 7y agoDoes that even happen with these small projects. Having the ability to audit is pointless if it never happens.
- thayne 7y agoWell, I'd be surprised if companies like Dropbox and Google didn't audit it. And if it is used as much the article says, it would also be a decent target for security researchers, if for no other reason than they could send a bounty request to the big companies that rely on it.
- newhouseb 7y agoDropbox doesn't use FUSE -- in large part because I was terrified of adopting 60k LoC in the kernel (from FUSE) that we weren't experts on versus 1k LoC that we actually needed (and had audited by third parties).
- jasonkester 7y agoGood for him. I hope we see more of this in the future: developers realising that the work they do has value and that they’re not required to spend their lives giving it away for free. So they take control of their work product and start capturing some of that value for themselves. It’s a shame that the article is written in this tone, as it mirrors the dominant sentiment among open source folks. There is still a lot of entitlement to be seen, even here in the comments from people who are likely to end up in the same boat as the software author referenced in the article. I think it’ll take a while to get there.
- Semaphor 7y ago> It’s a shame that the article is written in this tone The article seemed pretty neutral excluding the slightly shady stuff like not mentioning the license change properly, timely or even in expected locations > the dominant sentiment among open source folks The dominant sentiment of open source folks is that they want open source instead of proprietary software? That seems expected, it’s after all the whole point. edit: positive -> neutral; shady -> slightly shady
- pjmlp 7y agoThe dominant sentiment of open source folks is that they don't want to pay for anything, even if it is open source.
- shmerl 7y ago> Isn’t there a better way? There is. Ditch Apple and use sane systems without some control obsessive entities constantly hovering over you and dictating you how to (or not to) use them. Developers abandoning Apple should be the taste of their own medicine for them.
- saagarjha 7y agoThat’s not the issue.
- shmerl 7y agoWell, it pretty much is. Apple cultivates such kind of approaches by design.
- saagarjha 7y agoThis literally has zero to do with Apple aside from the fact that the project runs on macOS.
- Athas 7y agoThe FUSE maintainer (and this article) implies that kernel driver signing certificates are so difficult to get that forking is not realistic, even without considering the technical issues. I don't know if that is true, but if it is, then that is a certainly due to Apple policies. It's also interesting to contrast with Linux FUSE, which to my knowledge has never been associated with any maintainer drama.
- hapless 7y agoThe heart of the matter is that a fairly small number of people on a proprietary UNIX are mad that they have to pay money to continue to be free riders on the Free Software movement. Mr Fleischer has done a huge amount of unpaid work so a narrow segment of wealthy software workers can avoid the choice between paying for proprietary software and supporting Free Software, after spending thousands of dollars on a MacOS system No world has ever produced a violin small enough to play an elegy for those “victims.” If you wanted a Free Software FUSE, maybe a Linux desktop would have been a better choice?
- laughinghan 7y agoI fail to see how that is in any way the heart of the matter. The articles mentions someone being mad completely in passing, in a quoted tweet. If anyone in this HN thread is mad, they're a tiny minority because I haven't seen any. Instead it seems more like the heart of your comment is that you view everything in terms of an ideological battle between the Free Software movement and everyone else. So when you came upon an article and HN thread calmly discussing a maintainer's decision to change their project's license for understandable reasons but in a somewhat underhanded way, you immediately sorted everyone into heroes and villains and self-righteously took a stand.
- CathedralBorrow 7y ago> "you immediately sorted everyone into heroes and villains and self-righteously took a stand" And when you proclaim that this person "views everything in terms of an ideological battle between the Free Software movement and everyone else", would you say that's a more nuanced and balanced take on the matter?
- laughinghan 7y agoWould I say what is a more balanced take on what matter? The two quotes you pulled appear to be takes on different matters.
- 7y ago
- captn3m0 7y agoI had a project planned for iOS[0] that would have been so much better if it could use FUSE, but looks like it can't happen now. If someone wants to try, having a generic link between FUSE and File Providers in iOS will be a great addition. You could make a generic application that interoperates various FUSE projects against the File Provider API in iOS, so you could mount all sort of crazy stuff in iOS Files application. [0]: https://github.com/captn3m0/ideas/blob/master/opds-ios-file-provider.md https://github.com/captn3m0/ideas/blob/master/opds-ios-file-...
- hhas01 7y agoWhy? Contact the guy, talk to him.
- saagarjha 7y agoMacFUSE requires deep hooks into the kernel to work correctly. Do you think the File Provider API is sufficient for this purpose?
- steeleduncan 7y agoIt's API is not very clear, but it does seem to have roughly equivalent functionality to FUSE. The only obvious restriction is that there must be a physical file on disk rather than doing everything in-memory.
- tinus_hn 7y agoThe restriction is that the FileProvider api is only used by desktop applications for user files. You can’t for instance run the application itself from there.
- otikik 7y agoI'm fortunate enough to have been paid to do open source code for the last ~10 years or so. I am thus a huge open source & free source advocate, and I am completely biased for it. I think everything done here seems legal, because BSD licensing pretty much allows for this (I am not a lawyer though, and I haven't examined how things were with third-party contributions for example). Morally, the only fault I can say on the maintainer's behavior is a lack of transparency. This kind of decisive move ideally should be accompanied by an equally decisive communication effort. Trying to do this "quietly" isn't an option when a big number of users and/or big players are involved (as it seems Google is involved to some extent).
- m000 7y ago> Morally, the only fault I can say on the maintainer's behavior is a lack of transparency. Totally agree with that. The maintainer seems to have made very little effort to get compensated for his work. It would surely be nice if some company stepped-up and offered to sponsor the development of the project. But it's also kind of childish to scheme and hold grudges for not getting something you never bothered asking for. Other open-source developers have been in a similar position in the past, but the handling of the situation was much more transparent and considerate. Off the top of my head, I can remember the example of Synergy [1]. When the developer needed support, he announced well in advance the changes to the model of development. And actually put the time to spin-up a company around the project, and offer ways for normal users to support development. [1] https://symless.com/synergy https://symless.com/synergy
- CathedralBorrow 7y ago> "But it's also kind of childish to scheme and hold grudges for not getting something you never bothered asking for." When you state that he never bothered asking for something, what are you basing that on?
- hmottestad 7y agoI'm very happy for you getting paid to contribute to open source. I wish I could find someone willing to sponsor me. My field is fairly narrow though with few users and not that much commercial action.
- rgrs 7y agoGo Benny!
- rossmohax 7y agoReading the article I cant understand, how is it possible for other companies distribute patched version of FUSE module, if they don't have certificate to sign it?
- hjmallon 7y agoYou can always build and sign something with your own cert (if you have a kext cert in this case)
- larodi 7y agothis quite reminds of the openssl saga, but on a smaller scale, with single developer more or less responsible for world's encryption for decade. it's a pity, it's a shame that companies who use FOSS benefit, but do not understand (or do, but ignore) the idea of FOSS, which is to give back to community. this also includes other FOSS companies, etc as everyone uses openssl, zlib and sqlite. to base a project on FOSS requires that you contribute back. or pay back if you can. and when your business makes 1000$ then 1$ out of every 1000$ for the FOSS guy that made it possible is money worth spending, isn't it? if it's true that VeraCrypt, the G company and others based work on this developer's efforts and forgot, for decade, to give back anything, well - it's well deserved to leave them staring at the blank repo. well deserved indeed, as they had plenty of time and resource to compensate the author while reaping benefits off his work. well done to choose the BSD license in this case. all other companies building big-software based on hundreds opensource projects should rethink their strategies. there is no free lunch, someone pays for it. and its a shame, when this someone is left alone to pay for his lunch, while hundreds benefit from it. maybe there should be the FOSS Church and at least make these people revered as saints.
- solidasparagus 7y ago> to base a project on FOSS requires that you contribute back No, it absolutely does not. If that was a requirement, it should say so in the license. If you don't want your work to be publicly usable by people who don't contribute, don't open source it.
- aembleton 7y agoWhy should companies give back when the code was licenced in such a way as to not require it? If a developer works on a project and wants commercial companies to give back then they can choose a suitable licence such as GPLv3; if they just want to get their code out there and don't really mind how it's used then BSD is more suitable.
- hmottestad 7y agoSeems like the reason he changed it up!
- mikorym 7y agoThis explains why there are banners in macOS that say "x is supported by Catalina!" where x is one of the companies using osxfuse.
- znpy 7y agoI am afraid there's nothing people can do about this issue: according to https://github.com/osxfuse/osxfuse/blob/master/LICENSE.txt https://github.com/osxfuse/osxfuse/blob/master/LICENSE.txt the project is BSD licensed and AFAIK closing the sources of a BSD-licensed project ("re-licensing") is allowed. Yep, he's allowed to do this and people basically have to suck it up. This couldn't have happened if the code was GPL-licensed. This might be a good occasion take a moment to think about all the BSD-licensed software you're currently using, and imagine it disappearing just like this piece of software. Then go back to your repository and re-license as much as you can as GPLv3.
- kjksf 7y agoCursory look at recent checkins seems to indicate that he wrote all the code. As the copyright holder of the code he could re-license it the same way even if it was GPL.
- tspiteri 7y agoIf he wanted to switch to GPL, he wouldn't have to relicence all the code; just the code that is by him alone. The contributions by others are in a permissive license that is compatible with the GPL, so they could remain in their current state; but the whole project would contain GPL code so anyone redistributing the project would have to do abide with the terms of the GPL.
- saagarjha 7y agoHe did not.
- nordsieck 7y ago> Cursory look at recent checkins seems to indicate that he wrote all the code. 1. There are github commits not by him in the project. 2. There are lots of copyright assertions scattered through the project. The first one I ran into was: > Copyright (c) 2006-2008 Amit Singh/Google Inc. but I'm sure there are way more than that.
- rmoriz 7y ago
- pilif 7y agoNitpick: > Now this may come as a shock to some of you, but Apple really doesn’t seem to like it when third party developers change just about anything about their UX > Deploying a kext requires it be signed using a special Kernel Extension Signing Certificate, which can only be acquired from Apple this restriction has nothing to do with them not liking people doing stuff about their UX and everything to do about the fact that kernel extensions bypass all security boundaries between users and processes. Kernel extensions are bloody dangerous and I'm happy with Apple putting additional scrutiny on them.
- adrianN 7y agoForbidding users from doing dangerous stuff with the machines they own is not good imho.
- tinus_hn 7y agoBut is it allowed for users to choose a machine that forbids this?
- diffeomorphism 7y agoThis clothing is made with slave labor. "But is it allowed for customers to choose to buy this?". "allowed" is irrelevant here.
- adrianN 7y agoThat's a difficult question because it might limit supply of open machines for users who want the freedom to hack their own stuff. I think it's okay to offer computers that are basically Facebook appliances, but there should always be a toggle somewhere that allows people who know what they're doing to do whatever they please.
- dkdkdjdj 7y agoWhat do you think of the counterargument that, as soon as you put a switch like that in, people will get manipulated into flipping it?
- therealmarv 7y agoAny price tag known for commercial developers? Was interested in doing something with FUSE on Mac.
- zem 7y agothink of it this way - like all the other companies, he's maintained his own private fork of the open source osxfuse code. his happens to work on catalina, and he's telling those companies that if their forks do not, he's willing to sell them access to his code.
- zellyn 7y agoI really like this articulation of the situation.
- jpincheira 7y agoIf he made a software that is making companies using it millions, and he still doesn't benefit a dime from his work and explicitly wants to, I think he has the right to go this way.
- ossworkerrights 7y agoFinally. People need to understand that expecting someone to put their OWN free time into making something open source, and the ripping off the monetary gain AND expecting them to continue maintaining and adding features for free is pure entitlement.
- syshum 7y ago>>So What now? Easy Switch to Linux and enjoy freedom
- simias 7y agoI agree that any aggressive towards the maintainer is unwarranted, even if I personally disagree with his move. In particular this comment quoted in TFA amused me: >Then drop it and let someone else maintain it. I want to reply to this person: then fork the last open source version and maintain that. That's the whole point really. Besides he apparently made the change two years ago and people only start noticing now, it's pretty clear that there's not a vibrant community of contributors ready to take the project over. It's not entirely fair in this case because of the certificate needed to sign the kernel module but if it's really that difficult to get a certificate from Apple as an open source project that seems more like a problem with Apple than with osxfuse's maintainer. Besides what can he reasonably do? Just give the certificate to whoever asks for it? That's going to get it revoked by Apple in approximately 4 femtoseconds. Companies benefiting from the work of opensource projects and not giving anything back is genuinely a big problem IMO. It's not illegal of course, but it is unethical in my opinion. Look at the state of OpenSSL, one of the most (if not the most) popular crypto library out there, who has to beg for scraps in order to fund the project. And when there's a critical vulnerability like heartbleed, who gets mocked online? The poor guy or gal who authored the commit, not the countless multi-billion dollar corporations who deployed their code for free without paying for a thorough audit or contributing anything back.
- m-p-3 7y ago> I agree that any aggressive towards the maintainer is unwarranted, even if I personally disagree with his move. I also agree, being aggressive towards a volunteer maintainer achieves nothing and brings the possibility that he'll simply stops working altogether on it for free, like what happened with wiringPi some time ago.
- tssva 7y agoThere are two possible scenarios: The developer always thought that contributing back code or financial support should be a requirement of use but failed to reflect this in the license chosen and now is correcting this. The developer over time has changed their believe of what the requirements for use should or need to be. This change of thought may have been informed by the behavior of those using the code but is still a change of thought on the developers side. In both scenarios the developer changing their license is not acting unethically nor were those previously using the code while meeting the terms it was previously available under. What may be unethical is the developer trying to put blame for the license change on those that were using the code while meeting the requirements of the previous license because under the first scenario the developer is at fault and under the 2nd neither is at fault.
- kiney 7y agoNot relevant but it's funny that the maintainer of osxfuse has the name Fleischer and is discussing on github with Metzger. Both are german words for "butcher". (but also common surnames)
- mr__y 7y agoIs there any copyright/licence specialist here? I've come up with an idea of having a free open software library that randomly displays offensive[0] messages full screen that comes with a BSD type licence with a clause that forbids removing/disabling that message. I assume that many developers or end-users[1] at home are perfectly fine with a messagebox popping up once a month with a "f## off" message, while any corporation planning to use that library will find it not acceptable to have their software display offensive content. And here comes a dual licensing, where there would be a possibility to buy a different licence that allows to disable that message. What I'm asking here is whether this would be possible to do so and enforce in a court or a legal dispute. [0] or otherwise inacceptable in corporate environment [1] I'm assuming that this would also be acceptable for the derivative projects: end-users might find that acceptable while businesses would not. edit: wording of last sentence, formatting
- progval 7y ago> with a clause that forbids removing/disabling that message This sounds similar to the "invariant sections" clause of the GNU Free Documentation License; except you're talking about software instead of documentation. > I assume that many developers or end-users[1] at home are perfectly fine with a messagebox popping up once a month with a "f## off" message Some people are really angry about GNU Parallel's citation "nag", though. eg. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884793 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884793
- saagarjha 7y agoThey’re probably angry because the nag may fall under GPL’s “no additional restrictions”.
- mr__y 7y ago>Some people are really angry about GNU Parallel's citation "nag the way I understand this, is that by requiring to interactively enter "will cite" the ability to run it as part of a larger script is broken. This would break a cron-job as well. The non-interactive nag in output would not cause such probles. The non-interactive message in output of course could create problems on its own - especially if the nag would or would not display randomly. If someone intends to parse the output, this would require additional code to discard the nag. If the nag would sometimes display and sometimes not, this could randomly break stuff - if there was no nag during tests someone could not notice that they need to discard it. But there are non-intrusive ways to insert some offensive message - they could be put to syslog, or a file with an offensive name/content would be created. My general idea is not to nag the users per se but do something that does not cause actual inconvenience for the user but is unacceptable in corporate environment. For a GUI app a simple message box appearing once a month would not cause a major problem or hurt productivity of the end-user but I assume that for example Apple or Google would not find it acceptable for their software to display "f-off" even if this was rare. For non-interactive/non-GUI software other ways to inject that message would be needed. For instance, a http server could inject additional X-F-Off header or a daemon could require env variable ICONSUMEFECES set to "daily"
- _pmf_ 7y agoGood, but in this case, the osxfuse maintainer expects to be paid by Apply because they derived from his work ... what about original FUSE, of which osxfuse is spiritually derived? When is it ethically OK to profit from your derived work?
- romaaeterna 7y agoCan someone explain to me why there are PRs that seem to be opened and merged by other people, but all of the commits show up as bfleischer? I don't quite understand the git history of this project.
- dangus 7y ago> He can do that? > Uh… probably? As I mentioned, most of the code is under BSD-style licenses. The command line utility to actually mount the damn thing is under the Apple Public Source License, which has a “soft copyleft.” But in theory, if no further changes are made to this part of the code, it already meets the requirements for source code distribution. Just a note here, my understanding of the legal status of software licenses is that they don’t supersede your own ownership of copyright. As the nearly-sole contributor, the author can violate his own license for the code he created. Even if the whole thing was GPLv3, I think he could simply remove anyone else’s contributed commits and take the rest as proprietary code. It doesn’t sound like much work was done by other contributors on this project anyway. Now, if he’s closed sourcing and using/changing someone else’s contributions that were licensed to the public in a copyleft license, that’s a different story. (IANAL)
- im3w1l 7y agoIt matters because > FUSE for macOS (or, the kernel extension formerly known as osxfuse) is a project dating back to 2011. It in turn is based on even older projects, such as MacFUSE, the Linux FUSE module, and even some code open sourced by Apple.
- matkoniecz 7y ago> As the nearly-sole contributor, the author can violate his own license for the code he created. To be more specific, it is not in a violation of copyright. I am pretty sure that when I publish my code under any standard* licence it is not an exclusive license. I can still sell access on a more business friendly licence, publish it under CC0 and so on. *is there even serious licence that includes "no dual licencing" exclusivity clause that is binding the author? Is it even possible to do as a licence?
- wongarsu 7y ago> Is it even possible to do as a licence? I guess you could draft it as some kind of exclusivity licence "this work will only ever be available under this licence". You would still own the copyright, just contractually bound not to exercise it. But even that wouldn't be very convincing. If the author republishes under another licence this isn't in violation of copyright or any criminal law, it's more like "I gave written agreement not to do something I have the legal right to do, did it anyway, and nobody can demonstrate any damages. Sue me"
- wildduck 7y ago> I will never ask end users for financial support. FUSE will always be free. However, what I'm asking for is for companies, that are selling FUSE-based products or rebrand FUSE and bundle it with their apps, to re-invest some of the profits in the continued development of FUSE on macOS, if they can afford it. I don't think that is unreasonable. Sounds like he should have released it under GPL type of licensing.
- upofadown 7y agoThe article makes this out to be more complicated than it is. Apple makes it very difficult to use 3rd party kernel modules. That is the whole thing. The open source thing is a complete red herring for everyone except the current maintainer who just happened to use some code that might be open source in a different context. The source for the module that could end up in the Apple kernel was never open to begin with. No one else could actually use the result of compiling the code. So the source was not ever open in a way that made any practical difference. The only moral here is that it is sometimes possible to prevent the use of open source code in some contexts and that Apple sometimes does. We already knew that.
- saagarjha 7y ago> Apple makes it very difficult to use 3rd party kernel modules. That is the whole thing. The open source thing is a complete red herring I would argue that the Apple part is the red herring. It’s boring; it’s common knowledge that they don’t particularly like kernel extensions and it’s somewhat difficult to develop them. > No one else could actually use the result of compiling the code. So the source was not ever open in a way that made any practical difference. Sorry, how did you end up at this conclusion?
- ajnin 7y agoI don't think going closed source is the solution to fight against others leeching off your work. The solution is more stringent GPL-style licenses that are more protective of the open-source community. Overall BSD-style licenses are not protective enough for the open source community, in fact they open it up to predatory behavior by selfish entities with large commercial interests and which don't care about giving back to the community. BSD gives the most freedom to the developers (that includes companies making private use of the code), while GPL gives the most freedom to the user of the software (who can then chose to become a developer). BSD code is often higher in popularity but there's a reason for that. I think GPL is the better choice overall.
- thosakwe 7y agoIf you're an open-source maintainer and either don't have a team, have a niche to small, are receiving zero compensation for the work, or some combination of those things, at this point in my life I believe it's best to either use a strong copy left license like the (A/L)GPL (only use LGPL for libraries, never anything else), or just stay closed source. The problem with permissive licenses is that they do nothing for the people actually developing the software, and makes it extremely likely that others will profit off their back without ever pushing even a line of code upstream. People will try to guilt you into changing licenses so they can use it in a commercial product, but seriously - if that person is going to profit off your code, you should be profiting too.
- jitendrac 7y agoWell, We should respect contributors. It is upto contributor to release their code unless he is redistributing app with viral license like GPL. Here neither big companies nor the sole maintainer is breaching any license clause. If anyone want to get the project mainstream, just find and fork the last open-source code version available, fork it and contribute/maintain/re-license as needed use case. another options is to, hire/contract the sole maintainer to develop needed feature of current version.
- rsync 7y agoSo, so many of the use-cases for osxfuse/macfuse involve people using sshfs to mount SFTP-capable logins into the Finder. All of this could be very simply avoided if Apple just made SFTP a supported protocol under "Connect to Server". I've asked/wished/pleaded for this since 2005. It's one of those Apple deficiencies that makes you wonder just how do people at apple get work done if they don't have this feature ? It's like the multi-year failure of OSX to properly or sanely support 2+ monitor setups ... just what were all those apple employees doing during that time ? How do they not need these things ?
- cr0sh 7y agoI find this to be yet another example of why the GPL (in general) was created, and why licenses like or similar to the BSD license are flawed. The way I see the GPL is that by modifying and publicly releasing the modified version of the binary, the payment for being able to do that is paid, at a minimum, in the code that should be released to accompany those changes. You want to use my code, and not pay me for it with money? Then pay me (or pay it forward) with the code instead. The BSD license and other similar licenses, while seemingly more free - really aren't. They allow for someone or some company to just come in, take the code, then profit off of it in a closed-source manner - provided they give some acknowledgement somewhere that it came from the original BSD based project or whatnot. Now - granted - in neither case would the programmer get paid money - but in the case of the GPL, at the very least the changes, fixes, updates, whatever - get "paid for" in code. It won't put food on the table, but it is the least that someone could do, imho, by benefitting from the rest of the codebase. I note that the above is a very simplified understanding of the GPL, BSD, etc - and of this issue in general. But I still think the basic idea stands; that at its core, the GPL is about "paying for" code with code, so that code nor changes to it will ever "go missing" or become "locked up" into some proprietary version of the code, and ultimately benefiting users less (whether they know or understand it or not).
- donatj 7y agoI honestly didn’t see the need for GPL until a project I had sunk a lot of time into contributing to changed their license from Apache to Proprietary and started charging more than I could possibly afford for a license. I feel tricked and betrayed, it has been a year and I am still upset. The whole thing feels like I got robbed. I donated my time to a project I thought was for the good of the community, turns out I was just doing free work on a proprietary product others stood to make money on. It’ll be a long time before I sign another CLA on something I care about.
- z3t4 7y agoYou can fork the latest Apache version of the project.
- hemancuso 7y agoI think this is fairly overblown, there are a fair number of FUSE for macOS forks out there with signing certificates. I have kext signing certificate for ExpanDrive, Google has one for Google Filestream, I suspect many others have one as well. Rightfully, Apple doesn't hand them out as easily as they do with regular developer certificates, but if you want one and do a reasonable job representing that you're not going to panic end-user systems, you can get one too. FUSE for macOS remains open source, fork it if you want. Benjamin merely decided not to work on it for free anymore and essentially providing bug fixes etc for those who pay for it. Lastly - FUSE of macOS is not going to be around in the current form much longer. Apple has made it abundantly clear that Kernel Extensions are on the way out, and that macOS 10.15 will be the last release to fully support kexts without compromises. Check this slide from WWDC https://imgur.com/a/EAzT6Ch https://imgur.com/a/EAzT6Ch
- khc 7y agoWhat do you think future of fuse on macOS will be like?
- ehutch79 7y agohttps://developer.apple.com/system-extensions/ https://developer.apple.com/system-extensions/
- ehutch79 7y agohttps://developer.apple.com/videos/play/wwdc2019/702/ https://developer.apple.com/videos/play/wwdc2019/702/
- hemancuso 7y agoI have no inside information but assuming they continue to expose the VFS layer they will very likely build a usermode extension framework that is quite like FUSE, but supported by the OS and maintained by Apple.
- whydoyoucare 7y agoHis project, his rules. Period.
- angry_octet 7y agoSee also: https://tidelift.com/ https://tidelift.com/ You pay them to support an open source product. Only a small number of things covered at present, but maybe better than doing it yourself.
- lostgame 7y agoFUSE is a fantastic project that I’ve used since it’s inception. I did notice commercial projects using the source, and if there’s only one dev, I agree he does deserve compensation.
- retroplasma 7y agoBy the way if you are searching for some cross-platform FUSE-like alternative for a project I encourage you to try WebDAV if something else is your bottleneck. It saved me some headaches from bundling an installer for macFUSE or Dokan's blue screens in the past. There are server implementations and also FUSE wrappers on GitHub. It's not perfect but worth a try. And it's supported directly by many OS.
- lilfatbitch 7y agoif you do open source with the intention to make money, don't do open source