14 ms·
I've always thought that the GPLv3 effort was one of the FSF's biggest mistakes. It split the GPL community into GPLv2 and GPLv3, since the two aren't compati
by tytso 6y ago
I've always thought that the GPLv3 effort was one of the FSF's biggest mistakes. It split the GPL community into GPLv2 and GPLv3, since the two aren't compatible. And the GPLv3 was simply far too scary for companies.
It's clear that the Apache license is more friendly toward corporate concerns. But companies were willing to deal with GPLv2, because there were sufficiently large projects (such as the Linux kernel) that added enough value that it overcame their fears over how the GPLv2 restricted how they could monetize their software engineering investments.
Unfortunately, the GPLv3 and even more so, the AGPLv3, was simply a step too far; put simply, in my opinion, the FSF overplayed their hand. Whether a more scaled back GPLv3, or simply sticking with GPLv2, with all of its admitted ambiguities and admitted legal short-comings, would have made enough of a difference at the end of the day is impossible to know. But I think copyleft as a viable open source licensing regime, and the GPL in particular, would have had a much better chance of success if GPLv3 never happened.
- Wowfunhappy 6y agoYou might be right as a practical matter, but I do think the FSF's tivoization concerns are well-founded, especially in light of what we've seen happen in the mobile industry. If the user isn't allowed to actually compile and run their own code, what good is it for that code to be open source?
- tytso 6y agoIf you believe that "software will eat the world", then hardware doesn't matter. Sure, the customers who purchase a locked-down device might not be able to update their device. But the technology will still be out there, so that it can be built upon to improve the next generation of hardware --- perhaps hardware created by a competitor, or using open hardware. This is especially true for consumer-grade devices, which generally become obsolete and replaced within 2-3 years anyway. And if this is something that a sufficiently large segment of the users actually care about, then they will vote with their feet, and purchase hardware where they can update their own code. Maybe this will even result in a software ecosystem where the company selling an open product will be able to take those improvements from the dedicated power users to improve future releases of their product. But this is something which is best enforced by market forces --- if it's really an important right that users find important, they will demand it. This is essentially the debate when the FSF tried to convince the Linux kernel community to relicense to the Linux kernel to the GPLv3. We declined, essentially because we saw the downsides of the anti-Tivo-ization clauses had towards people choosing to use Linux versus some other OS. And we believed that growing the contributor base was in the long term, far more important than the more short-term anti-Tivoization concerns of the FSF. This is why the Linux kernel is GPLv2 and not GPLv3. We didn't give in to the siren call of the FSF position.
- selfhoster11 6y agoRight to Read comes to mind. Software might be eating the world, but IP industry and legislation are eating the hardware. There soon may be no user-controlled hardware, especially with the advent of the internet where "vulnerabilities" that let users run their own code can be patched, and Apple-like certificate checking can be deployed out. GPLv3 might be seen as an effort to counter-act this situation.
- na85 6y ago>hardware doesn't matter >perhaps hardware created by a competitor, or using open hardware I think as the Purism folks are demonstrating with the Librem phone, we live in a world where the barrier to entry to compete in hardware markets is enormous. The "hardware doesn't matter" argument only holds where the hardware to run software is sufficiently commoditized or where it's easy to develop open-source alternatives. For phones and select other segments of the hardware sector this simply isn't the case: consider the yawning chasm that separates the Librem phone from the iPhone.
- AnthonyMouse 6y agoThe way free software is supposed to work is that you buy a device, you want to improve it, so you do. And then you share your improvements with everybody else. If you buy a TiVo and then can't modify it, you don't. So there is nothing to share with everybody else. The entire system is destroyed. It's an existential threat. > And if this is something that a sufficiently large segment of the users actually care about, then they will vote with their feet, and purchase hardware where they can update their own code. But that's the problem. Most of the users aren't (currently) developers, but if the dominant hardware isn't open to developers then there are fewer developers, and the users then can't receive their improvements. It's not obvious that there are always enough developers to justify a production run of open hardware separate from the hardware everybody else uses, even though everyone benefits from its existence. So we need the dominant hardware to be open. > Maybe this will even result in a software ecosystem where the company selling an open product will be able to take those improvements from the dedicated power users to improve future releases of their product. Except that if this becomes popular and the software is open source but can be locked down, proprietary hardware vendors will ship the improvements on locked down hardware. Then anyone who doesn't make modifications themselves, or doesn't anticipate making them even though they might have, buys the locked down hardware and the open hardware has no competitive advantage in the market among non-developers. Even though its existence is a prerequisite to continued community software improvements that everybody wants.
- dTal 6y agoIt always seemed to me that problem with GPLv2 wasn't any shortcoming in the license, as such, but in certain legal opinions that labeled things "compliant" which were clearly against the spirit. TiVo-ization is a violation because GPL software and proprietary software are combined to form a single piece of software, distributed as a single binary firmware image; the fact that there's some notional internal interface between the GPL and non-GPL code within, if you manage to crack the firmware that is, should be legally irrelevant. But engineers are wont to be distracted by concerns such as "kernel space" and "user space", and "dynamically linked" vs "compiled in". Absolutely none of this matters, if I'm getting a big-ass opaque blob with a mixture of GPL and proprietary code in it. The same goes for the average Android handset, for that matter. I think the battle was lost by not pushing the advantage hard enough.
- Wowfunhappy 6y agoI don't think I agree with that. I want to be able to run GPL programs on Windows, for example.
- wizzwizz4 6y agoThere's nothing stopping you. What would be stopping you is if Windows included DRM that stopped you running all GPL programs apart from Microsoft Official Builds™.
- Wowfunhappy 6y agoWell, I wasn't clear that it would still be allowed under the interpretation the GP was advocating for. Perhaps they need to flesh out their position. I'm largely thinking about the current situation with ZFS on Linux. IMO, this benefits no one, and so I'd generally like to see less draconian interpretations of what code is allowed to link together—but more licenses which protect other user freedoms, like the ability to run your own code.
- bronson 6y agoThis is why Apple is so scared of GPL3 on iPhones/iPads.
- deleted 6y ago[deleted]
- ragnese 6y agoI think the truth is that money wins. It doesn't really matter that GPLv3 is stricter than 2. Corporate interests didn't like GPLv2 either. They just dealt with it to use Linux. I think the current state of things was basically inevitable. Corporations love open source because it means they can outsource labor to "the community" and use that labor to profit on their actual cash cows. The free software fight has already lost in spirit. It's not even clear that it ever could have really survived with how complex software has become, anyway. Are any of us really able to customize MS Excel to do something new that we want anyway?
- CJefferson 6y agoVarious companies, Apple most notably, clearly avoid GPLv3. For years Mac OS X has had the last GPLv2 version of bash.
- Twirrim 6y agoAmazon had GPLv3 blacklisted when I worked there. Nothing new by way of legal concerns about GPLv3. No lawyer is going to advise a company to take actions that will likely see the company go to court to explore just how much of a license is legally enforceable, and just what it actually means.
- ragnese 6y agoAnd they also avoided GPLv2. Sure, they had bash, but all of the "coreutils" were the BSD flavors. That an exception was made for one or a couple of things doesn't exactly counter my claim very strongly.
- dwaite 6y agoThey accepted the sister LGPLv2 license as the basis of WebKit, and had other tools like Samba integrated. They may have avoided the GPLv2 when easy, but they outright banned GPLv3 (froze bash and gcc on the last version while working to remove them; wrote their own from-scratch CIFS implementation to drop samba).
- 2Gkashmiri 6y agowhy isnt the said corporation not using any open source licensed software then? why don't they either built their own proprietary software from the ground up or ask the developer to set up a parallel commercial license for their specific purpose?
- tytso 6y agoWhy aren't they building or buying a proprietary software solution instead? Because the open source solution is cheaper, and adds more value to them that the proprietary alternatives. The GPL means that enhancements to Linux generally get contributed back to the core. That has allowed Linux to development faster, have better hardware support, etc., compared to operating systems that have a more permissive licensing scheme, such as BSD, and it's cheaper than a purely proprietary OS where one company has to shoulder the whole cost writing all of the software from scratch. So companies use Linux because it provides a better cost/benefit solution than the alternatives. I will argue that the GPLv2 helps this situation by allowing Linux to get back the software investment made by other companies and merge them back to the core code. So I will be the first to argue that the GPL approach has its benefits. But it also, at the same time, makes companies uncomfortable. So it's simply a matter of nuance. The more value you can provide, the more you can insist that that companies "give back" to the community. I believe the GPLv2, as, for at least some software projects, manage to achieve a balance which works for most of the stakeholders. And I don't consider this to be "the companies are taking advantage of free work from the community", because the companies are paying developers to work on Linux, so their are part of the community, and they are also contributing back to the community. We just need to make sure that the benefit is such that it is worthwhile for companies to continue to contribute to the community. The whole point is that this is not a zero-sum game, but that by enforcing cooperation, everyone wins. But if the GPLv3 is too scary, such that no one wants to even try out the community model, then it's a losing proposition.
- ignoramous 6y agoWe are about to open source our projects too [0], and have been faced with the question of xGPLv3 vs other permissive licenses. Not a big fan of source-available licenses because as Bryan Cantrill argues, one is better off with closed-source in that case [1]. From all that I have read, the Mozilla Public License v2 [2] (file-level copyleft) seems like a good intermediate between GNU family of licenses (strong copyleft) and Apache / MIT / 3-Clause BSD (copyright). The problem with using a permissive license such as Apache is, anyone can fork the project exclusively under xGPLv3. If that fork becomes more popular, there's no way for the Apache-licensed upstream to merge any patches from the xGPLv3d fork back in. With MPLv2, all "files" in the immediate xGPLv3 fork are automatically dual-licensed under both, xGPLv3 and MPLv2. This means MPLv2-licensed upstream is free to merge in changes without worries from immediate forks. MPLv2 additionally bakes in a choice for the original developer (viz. "initial Contributor") to make xGPL forks illegal (using the incompatibility clause), but it isn't the default. The Eclipse Public License v2 [3], which is very similar to MPLv2 in its copyleft aspects, takes this a step further and makes xGPL forks illegal by default. The original developer; however, can explicitly choose to permit xGPLv3 forks. [0] https://www.joelonsoftware.com/2002/06/12/strategy-letter-v/ https://www.joelonsoftware.com/2002/06/12/strategy-letter-v/ [1] http://dtrace.org/blogs/bmc/2018/12/14/open-source-confronts-its-midlife-crisis/ http://dtrace.org/blogs/bmc/2018/12/14/open-source-confronts... [2] https://www.mozilla.org/en-US/MPL/2.0/FAQ/ https://www.mozilla.org/en-US/MPL/2.0/FAQ/ [3] https://www.youtube-nocookie.com/embed/uKKVydoqF_0 https://www.youtube-nocookie.com/embed/uKKVydoqF_0
- LukeEF 6y agoWe thought about the Eclipse Public License in advance of the shift. There is a very persuasive member of our community who argued in its favor. In the end, it is ease of recognition that swayed us to Apache. If you have to forward for approval or read the details of the license before getting started, that is often a bridge too far. Good luck with the open sourcing!
- haberman 6y ago> The problem with using a permissive license such as Apache is, anyone can fork the project exclusively under xGPLv3. If that fork becomes more popular, there's no way for the Apache-licensed upstream to merge any patches from the xGPLv3d fork back in. I'm curious if anyone knows of any cases where this actually happened.
- JoshTriplett 6y ago> And the GPLv3 was simply far too scary for companies. "scary" from a different perspective is "functional". Many companies also push back against even GPLv2 in anything other than the Linux kernel, and as a result, more people use permissive licenses, even when those permissive licenses run counter to their goals. I've directly seen corporate decision-makers ask "how can we prevent our competitors from using this to compete with us" and yet still choose permissive licensing rather than copyleft, for no obvious or stated reason. That's leaving aside many individual projects using permissive licensing; I wonder how many people doing so specifically want permissive licensing for a concrete reason, and how many just aren't sure and so they pick what seems more prevalent/"acceptable"? In many contexts, GPL of any flavor is "that thing that the Linux kernel and a few bits of low-level Linux userspace use, and everything else avoids". GPLv3 didn't cause that; widespread corporate pushback against copyleft caused that.
- endgame 6y agoReading the text of GPLv3 closely, I was disappointed at how little its additional provisions actually protect. It read like it guarded against Tivoisation and not much else, but the world's moved on since then. GPLv3 either went too far, or not far enough (in terms of cost incurred: gaining enough ground that the community split is worthwhile, volume of license text, ...). If I had a time machine, I'd suggest the FSF to try frog-boiling people into software freedom instead.
- JoshTriplett 6y agoI do wonder what would have happened in the counterfactual world in which the FSF put out a new version of the GPL annually, with minor changes in each version, rather than a big revision one time. A slow ratchet, together with the guarantee of forward-compatibility. I also wonder whether many people would have refused to use the GPL if it had had the "or any later version" built in and unremovable, rather than making it part of the license grant.
- frabbit 6y agoEndless FUD is a likely outcome of that. Worse than now, if you can imagine it.
- jillesvangurp 6y agoI think you are absolutely right. Basically don't take my opinion for it and just look at how the corporate world has responded to licenses: 1) GPLv2: a legacy license still dominating e.g. Linux and other projects that simply never switched and leaves enough legal loop holes to not block commercial usage. Huge commercial success and arguably what bootstrapped the OSS world. 2) Apache 2.0. Huge commercial success and together with the MIT & BSD style licenses the no brainer go to license for anyone wanting to release some software under reasonable terms. These licenses dominate the vast majority of Github projects. 3) GPLv3 & AGPL v3. Only used by 1) people with outlier opinions on freedom related topics (trying to be diplomatic here). 2) companies looking to dual license their software under a highly restrictive commercial license or a highly restrictive OSS licenses. Technically free but limiting in practice in what you are actually allowed to do to the point where you probably need to worry about signing a proper deal for a proprietary license. Which is a different way of saying that it is not free at all You are not free to do what you want and you are certainly not free to build a business on top of the software; that requires a non free closed source license. The OSS limitations with respect to any form of commercial applications are kind of the whole point for the companies choosing this license: it practically leaves their users no other choice than their commercial license. Whatever your opinion on this, these licenses are considered problematic by most corporate legal departments and simply not widely used by companies with such departments for this reason.
- rurban 6y agoNot really https://github.com/search?q=license%3Agpl-3.0&type=Repositories&ref=advsearch&l=&l= https://github.com/search?q=license%3Agpl-3.0&type=Repositor... 1,419,692 https://github.com/search?q=license%3Aapache-2.0&type=Repositories&ref=advsearch&l=&l= https://github.com/search?q=license%3Aapache-2.0&type=Reposi... 1,500,312 gpl2 414,348 MIT 5,501,412
- kybernetikos 6y ago> Which is a different way of saying that it is not free at all You are not free to do what you want and you are certainly not free to build a business on top of the software; that requires a non free closed source license. Most freedoms constrain others. The freedoms that the FSF care about are the freedoms of the users. Not the freedoms of the developers, and not the freedoms of the corporations that make the devices that sell to users. If you want to recognise and protect the rights of end users, you will constrain other peoples rights to exploit them in various ways. Which is to say that I think that GPLv3 (dual) licensed software does give genuine freedoms, even if they aren't the freedoms you are most interested in. Your freedom to create a consultancy around the GPLv3 licensed code and to charge for customisations or support are all protected too. Again, I understand that that isn't the kind of business you wanted to build on top of the software, but it's still a real freedom. I actually think a dual license might have been better in the case of terminusDB too.
- voltagex_ 6y agoMeanwhile, there's at least two boxes in my house running Linux that I have absolutely no access to, no chance to upgrade after the manufacturer stops supporting them - on a fast track to e-waste.
- belorn 6y agoGPLv3 effort was made in order to address two main problem. One was that the market dominated manufacturer who held close to 90% of the market was going around and claiming royalties for claimed software patent in free software, and if I remember right against actually members who participated in the drafting of GPLv3. People saw how a dominated party would distribute GPL software and then go and try shake down same people for patent money, and people were really scared at the time. Quality patents like "1-click" were being fought in courts and companies like Microsoft spent billions, with a capital B, of dollars on patent deals. People did not assume Microsoft just did that for laughs and so the drafting process had a distinct goal of addressing this problem. After gplv3 release Microsoft did halt their claims on Linux users, which could naturally be just a major coincidence. The second concern was that millions of devices with Linux in them would be sold for which users could not modify, share or distribute changes for. This happened beyond what anyone could have imagined. FSF fought and lost that fight, but I am not sure I would have called it a mistake. Mobile phones are full with anti-patterns, have zero security, zero privacy, zero control for the user. Their operational lifespan is a small portion of that open platforms and when the developer cuts updates then the device is unfixable. At any time the device can stop working and ransom the user for a subscription in order to regain operation. It is hard to imagine how those devices could get worse in term of user agency, except if the manufacturer join hands with an oppressive regime.
- teddyh 6y ago> the GPLv3 was simply far too scary for companies. The FSF made a huge effort to make GPLv3 not scary. They tried to involve absolutely everyone, and tried to take everyone’s concern into account. The GPLv3 was made to be not scary. The GPLv3 instead became “scary” not because anything scary in it, but because of a huge FUD campaign from large companies who didn’t want people to switch from GPLv2 to GPLv3, since the companies wanted to keep exploiting the loopholes in the old v2. For those old enough to remember, this was mostly the same old FUD campaign against the GPL (any GPL) versus a permissive license, many years before that. But, largely thanks to Linux, the GPL slowly won over that old batch of FUD. With the GPLv3, however, the opportunity was there to start it all up again. The GPLv3 is slowly winning against the FUD this time too, but it hasn’t prevailed yet, and Linux is not here to help this time.
- sneak 6y agoNot everyone agrees that the freedom to start a SaaS business with GPL software is a "loophole".
- hnarn 6y agoI wonder when this idea really started propagating, was it around when AWS came along? Because by a technical definition I don’t understand why this “loophole” wouldn’t also apply to a hypothetical web host back in the late 90s.
- rakoo 6y agoThe GPL has no element saying it can't be used to start any kind of business, and I don't think any of its defenders has ever said the GPL's goal is to suppress that freedom. It seems the FUD is still going strong.
- sneak 6y agoThe same people who made the GPL use the term "ASP loophole" and made the AGPL. Not everyone agrees that the freedom to make a SaaS business with a private GPL fork is a loophole or bug. It seems (from their creation of the AGPL and use of terms like "ASP loophole") that the GPL people do.
- misiti3780 6y agois there anyone good reference online where i could read a simple, summary of the differences between all of these licenses
- boomboomsubban 6y agoThe FSF list is the best I can think of. https://www.gnu.org/licenses/license-list.html https://www.gnu.org/licenses/license-list.html
- rascul 6y agohttps://choosealicense.com/licenses/ https://choosealicense.com/licenses/
- dspillett 6y ago> And the GPLv3 was simply far too scary for companies. I've not got anything out there covered by GPLv3, or any GPL these days, but I remember the same arguments against GPLv3 being given for the older versions too. Much like the answer to "if it doesn't say how much it is, it'll be too much and I move on" is "that is probably the intention, if you move on for that reason then you probably aren't the target audience" - if you are scared of GPLv3 then you probably aren't the target audience of the people using it. (of course if you are the target audience, and they state as much, there is obviously a disconnect somewhere, in both cases) I don't agree that the changes in GPL (AGPL, GPLv3) are the reason for the drop in use of that family of licences, rather that the rise in less restrictive open source options would have happened just as much had GPLv3 never been a thing. That is a mix of many people becoming less ideological in their licence choice overall as the F/OSS developer base increased, and an increase in commercial interest in F/OSS software that has lead to investment (dev & other time & resource, not just money) which has of course gone to less restrictive projects where such exist for obvious alignment-of-interests reasons.
- cyphar 6y agoHonestly the GPLv3 really isn't that radical. It has three major changes along with a bunch of more minor cleanups and improvements: 1. Protections against patent trolls (similar to Apache-2.0, so this is a clear improvement over the GPLv2 which didn't protect users from patent trolls at all). 2. The enforcement provisions were made much less harsh (the GPLv2 immediately terminates your rights upon any violation of the GPLv2) with a curing period so that distributions could rectify honest mistakes without losing their rights. These two are both clearly improvements over the GPLv2 (so much so that many distributions in the Linux community have explicitly promised to only enforce GPLv3-style enforcement for non-compliance of their Linux copyrights[1]). 3. The "tivoisation clause". This one is probably the most controversial change, but honestly it's actually a fairly understandable extension of this clause of the GPLv2 (s3): > For an executable work, complete source code means all the source code for all modules it contains, plus any associated interface definition files, plus the scripts used to control compilation and installation of the executable. In 1991, firmware keys and walled-gardens were unheard of and so I would expect that most people living in 1991 would expect the above line to mean that you should be given everything required to install a program (including if it came with a piece of hardware). You may not personally feel that this is reasonable, but given that the FSF's main goal is complete software freedom, I am surprised people can't see the above clause from their perspective. Today we know that firmware keys aren't part of "the scripts used to control compilation and installation of the executable" and so with the GPLv2 you can still get locked down devices. Hence the "tivoisation clause". [1]: https://www.redhat.com/en/about/gplv3-enforcement-statement https://www.redhat.com/en/about/gplv3-enforcement-statement
- balp 6y agoThe "tivoisation clause" also in many cases makes it against the law to use GPLv3 software in some consumer products, or parts of the products. For example much embedded software that comes under radio transmission laws, much software in safety critical applications such as rail, or automotive use, software that have environmental impact at leat in the automotive industry. At leat in the way that automotive legislator reads the laws at the moment.
- seg_lol 6y agoI am sad your comment is camping at the top of the discussion.