11 ms·
Minio Changes License to AGPL
- slaymaker1907 5y agoIANAL, but this may be illegal. I noticed that they have a large number of contributors yet seem to have no contributor agreement with ownership assignment. This generally means that any license change would need the agreement of every past contributor (as it should). There are good reasons (for the primary author(s)) to enforce copyright assignment for contributions. Besides legal issues, I consider changes like this to be very slimy since you are kind of pulling the rug out from under people. I would expect a huge discussion to take place before doing something like this to try and let people move off of the platform if AGPL does not work for them for whatever reason.
- jcadam 5y agoThe rationale for doing this escapes me. Is minio concerned about one or more cloud providers forking minio and then going closed source with their modifications? I generally only run minio from the official docker image, so I don't reckon this would affect "normal" usage?
- zamalek 5y ago> forking minio and then going closed source with their modifications? Which is somewhat bizarre given that aims to MinIO emulate a closed-source system. Open source businesses usually use AGPL or similar to prevent "Big Cloud" from stealing their business, this is a very strange inverted approach and I can't figure out why.
- the_duke 5y agoThere are many companies that might use and modify a S3 compatible object storage. The world does not run exclusively on AWS, Azure and GC.
- zamalek 5y agoCorrect, but that misses the point I was making entirely. Running S3/Elastic/API-X wherever you'd like is a separate issue to the kind of problem that Elastic faced with AWS. AWS soaked up a huge amount of Elastic's potential market, because they are so big and entrenched. Only AWS, Azure, and GCP are big enough to do that - and I don't see anyone "stealing" a reasonable degree of S3 customers from AWS by using Minio (let alone any business model that Minio might be exploring).
- rytill 5y agoWould it be possible to simply fork an MIT-style license and relicense the new fork as AGPL? The pre-fork version can continue with its old license, but the new fork is AGPL.
- Quekid5 5y agoYou can't really just 'slap a new license on it' AFAIUI. What you can do is fork and license any new derivative work under a new license (which is one-way compatible with the old one). Effectively that means that the fork can only be used under the new license.
- Laremere 5y agoIANAL. The lack of forking isn't the issue here. When someone writes code they (or their company) owns the copyright to it. They then contribute the code to the project using the terms of the project's license. Eg, for GPL, it allows others to modify, build, and run the code. However those modifications must be released to the public under the same license. (skipping over some minor technical details) Unless you get everyone who has contributed code to also release their code under the new license, the old license is the only one which all of the code has. It is possible to start contributing code to a project under a new license (effectively re-licensing the project in the eyes of the community), provided that the new license does not violate the old one. Specifically the Apache license REQUIRES that the code be distributed with a copy of the Apache license. Just removing or changing that license without the copyright holder's permission is in violation of that copyright. A lot of projects avoid potential future issues by having a contributors agreement in addition to the project's distribution license. Essentially, you give an extremely permissive (possibly up full ownership) of the code you write to the project. That is, some legal entity such as a person (the head maintainer) or a foundation. This legal entity then distributes the project to the community using the license of their choice.
- cygx 5y agoYou can't just change the license of code contributed by someone else without approval. But you can relicense your own contributions, which - unless that code can be trivially ripped out - would basically have the same effect as placing the whole thing under the AGPL.
- ChickeNES 5y agoI suppose we'll see a fork this weekend if they don't come to their senses, because it very much appears like there was no discussion about relicensing, nor is there a CLA
- bhickey 5y agoThe AGPLv3 and Apache 2 licenses are compatible. The maintainers are welcome to relicense their own contributions under the AGPLv3 and distribute the whole subject to that license (and the Apache 2 license), but that doesn't magically make contributed source AGPL. Removing the Apache license is suspicious because there are a heap of commits that are still covered by this license and without it the core MinIO devs have no right to use it. This is a full on cluster.
- khuey 5y agoAs is this clearly doesn't satisfy clause 4 of the Apache License for external contributions in the absence of a copyright transferring CLA.
- clarkevans 5y agoGPLv3 is compatible with Apache 2.0. This copyright statement should have addendum which indicates that portions of the code (written by contributors) are under the Apache 2.0 license. This could be addressed. There's no pulling the rug under people here: it's not like the previous releases, under the Apache license, are rescinded. Someone can still fork the project and keep it under the Apache license. If they are using a proprietary license for their commercial offering, they will probably require future community contributions to be donated under the Apache 2.0 license.
- mbreese 5y ago> This could be addressed You’d think they would have thought of this first. The fact that we’re having this conversation isn’t a good sign.
- pipeep 5y agoWhat's more concerning IMO is that despite the fact that I can't find a CLA, their pricing page claims that if you buy their support contract that they'll give you the software under a "Commercial" license: https://min.io/pricing https://min.io/pricing
- deleted 5y ago[deleted]
- seoaeu 5y agoImagine if the only APGL enforcement action on this was by contributors against MinIO. Not exactly the intended outcome of this re-licensing...
- chillfox 5y agoThey might just have figured that none of the people with standing is actually going to sue them. A license is only as strong as the likelihood and severity of consequences.
- khuey 5y agoThey have venture investors. YOLOing IP law like that is not going to pass any sort of due diligence.
- deleted 5y ago[deleted]
- monocasa 5y agoIANAL also, but since Apache is considered compatible with GPL3 and AGPL3, I think they have the ability to, since they can simply relicense their parts of it, and the resulting work is de facto AGPL3 taken as a whole. They might have to drop a 'portions are licensed under the Apache...' blurb somewhere, but the overall idea should be OK.
- deleted 5y ago[deleted]
- bluefox 5y agoI'm not sure it's "illegal"... but according to [0] the Apache license is subsumed by AGPL3, so I think this means they can add AGPL3 code freely and the result still makes sense to lawyers. They may also relicense code fully authored by themselves as AGPL3. Perhaps it may be even possible to relicense contributor code given these specific licenses? I don't know. They can push to that repository, so it's their prerogative to add whatever. Of course, people could use their own forks without these commits, not upgrade, etc. [0] https://www.gnu.org/licenses/license-compatibility.en.html https://www.gnu.org/licenses/license-compatibility.en.html
- sdesol 5y ago> I noticed that they have a large number of contributors yet seem to have no contributor agreement with ownership assignment. I did a quick analysis of the project and there were 41 contributors in the last year that contributed more than 10 lines of code churn to go files. See the following for an analysis: https://public-001.gitsense.com/insights/github/repos?q=file-churn%3A%3E%3D10%2Blangs%3Ago%2Bwindow%3A365&r=github%3Aminio%2Fminio&v=repo https://public-001.gitsense.com/insights/github/repos?q=file... If you switch to the impacts view, you can see that of the 41 contributors, there was 1 frequent contributor, 3 occasional contributors and 37 seldom contributors. I can't tell how many of the contributors are Minio employees, but I'm guessing in the worst case scenario, they could look at re-implementing contributions by non Minio employees, since the vast majority of code changes were by Minio employees. I know re-implementing previous contributions is a strategy that some use when they change their license, but I'm not sure how practical this is for Minio. As a side note, do not install my tool as the docker image has expired license that I need to update.
- koolba 5y agoHow does “reimplement contributions” work in practice? For trivial changes there’s often no alternate implementation (e.g. correcting a typo) and for anything substantial anybody currently involved in the project would be tainted with exposure to the implementation.
- sdesol 5y agoI honestly don't know, but I would have to imagine something like fixing typos would fall under "this is obvious" and you can't claim copyright on it. And likewise, if your algorithm that you contributed was obvious, it would fall under the same rule. Note, I'm just speculating of course, but I do know changing license is something that does happen and I'm sure Minio is probably looking at getting people to sign off on previous contributions. And if they can't get the contributor's consent, will look at re-implementing things or just not use previous contributions, since it is possible that the previous contribution is no longer used.
- Jach 5y ago
- deleted 5y ago[deleted]
- Quekid5 5y agoIs there a CLA or similar? Maybe I missed it, but I couldn't find anything in the CONTRIBUTING.md document. Or did they literally get every past contributor to agree?
- yjftsjthsd-h 5y agoProbably not necessary if they stack the licenses, since Apache 2.0 and AGPL are apparently compatible. That is, they can just add the terms of the AGPL in addition to Apache 2.0. (IANAL)
- Quekid5 5y agoIANAL too, but my understanding is that you cannot just "relicense". You can add your own license to any changes you make and add your own license headers, but absolutely cannot change any existing license headers, etc.
- bobthebuilders 5y agoYet another Rust project sinking to the depths of closed source.
- orra 5y agoThe AGPL is free and open source. It's a strong copyleft licence.
- monocasa 5y agoAlso, this is a go project, not a rust project.
- carlhjerpe 5y agoWhat's the difference between the languages got to do with the license?
- henvic 5y agoNot sure about what he means, but I've written this https://medium.com/@henvic/opensource-and-go-what-license-f6b36c201854 https://medium.com/@henvic/opensource-and-go-what-license-f6... in the past mostly about the impact of permissive vs. non-permissive licenses on Go code (because Go programs are statically linked; not sure about Rust).
- steveklabnik 5y agoRust code is also generally statically linked, and we also have the additional complication of monomorphization for generics.
- the_duke 5y agoNothing, but OP mentioned Rust.
- CaptainOSS 5y agoAGPL is a “weak” copyleft license, not strong. It basically means not all derivatives need to be open sourced. If you modify AGPL code but never distribute it or provide it as a service over a network to users, you don’t have to provide source.
- jabo 5y agoLet's say I use Minio in a SaaS app and allow my end users to upload directly to it. With this AGPL license change, is this now considered to be a form of distribution, that would then require me to open source the rest of my SaaS app?
- throwaway888abc 5y agoSame question for same situation
- rad_gruchalski 5y agoYou only have a problem if you modify anything in the source code of minio that you host.
- enriquto 5y ago> You only have a problem if you modify anything in the source code of minio that you host. And even in that case, you only need to share your modifications of minio, not anything about the rest of your system. Doesn't seem too much of a problem, to begin with.
- rad_gruchalski 5y agoThat’s right.
- jnwatson 5y agoOr put a proxy in front of it.
- rad_gruchalski 5y agoIndeed. I predict that year 2022 will be the year of a sidecar protocol proxy service.
- eloff 5y agoA lot of companies I've worked for had a blanket ban on AGPL. This is not a problem with the license, it's a problem with those companies. But it's still going to be a pain for the people who work there.
- marcinzm 5y agoNo PR and no discussion and no announcement. This will be a fun time bomb for anyone using Minio at a company where legal dislikes AGPL licenses.
- gsich 5y agoJust don't upgrade or don't modify the sourcecode.
- marcinzm 5y agoSee my first sentence. Can't not do something if you don't know the license changed.
- gsich 5y agoNot an issue. If you modify the source you'll notice if you try to keep upstream. If not (as in you don't modify) then it doesn't matter anyway.
- marcinzm 5y agoMany companies have outright internal bans on AGPL or contractual bans imposed by their clients.
- gsich 5y agoAnd? What's the point? That companies can be stupid? If you don't upgrade literally nothing will change. If you have upgraded and noticed the license change - downgrade. Or just use it anyway, if the value of Minio is worth it.
- yjftsjthsd-h 5y ago> If you don't upgrade literally nothing will change. If you have upgraded and noticed the license change - downgrade. And if you upgrade and don't notice the change?
- timmit 5y agopurpose???
- notacoward 5y agoAn interesting side point is that the founder of Minio was also the founder of Gluster, which was also briefly AGPL (just before the Red Hat acquisition IIRC). I think it makes even more sense for Minio, as an install is more likely to be made directly accessible to users. AFAIK nobody ever did that with Gluster - I used to be a maintainer BTW, and thus know a bunch of people who followed AB to Minio - because it would have been insane.
- jchw 5y agoI don’t necessarily think AGPL is the best license, but I am very glad it’s AGPL catching on and not SSPL and friends. I’ve spoken my piece in recent threads already, but I just think this is more friendly to the FOSS community even if it’s not perfect.
- wegs2 5y agoI don't think AGPL is a perfect license, but I do think it's the best. The flaws it has are things like the poorly-written patent clause, verbosity, ambiguity on concepts like linking, and general lack of elegance. It runs into a lot of corner cases around where code looks like data or data looks like code; there isn't a clean separation. GPLv2 was a brilliantly-drafted license. For all those failings, AGPL seems like the right choice for people who want their code feeding into an open ecosystem, rather than coopted by corporate giants.
- hda2 5y ago> The flaws it has are things like the poorly-written patent clause ... Isn't the AGPL based on the GPLv3? I thought the GPLv3 had a very clear stance on patents.
- random5634 5y agoExcept of course the corporate folks who are licensing under AGPL who can and do then take contributors code and make available a commercial version that no one else is allowed to make available. AGPL is a poison pill license that creates a very distorted open source model - better example is "shared source" - you can look but can't really use it in you own ops. The whole AGPLv3 / GPLv3 thing was such a mess - a big move towards trying to tell people how to use the code. I think long term GPLv3 and AGPLv3 die out.
- Benjamin_Dobell 5y agoWhy are most software engineers so terrible at basic comprehension? Licenses are just a set of instructions, how do we consistently fail to follow them? You can't relicense something that is Apache 2.0 as AGPL. You need explicit approval of every single contributor (whose code still exists in the project). You can also attach the AGPL, but it is not a superset of Apache 2.0, which for example contains constraints that require you to clearly indicate each and every time a file is modified. Incidentally, the Apache 2.0 is a terrible license for modern open source, and it probably shouldn't be used. EDIT: To people responding, my advice is to read the licenses. Don't read a dot point summary, read the licenses. Seriously, read the licenses! Sorry, this drives me a little mad. Of course you can include Apache 2.0 code in an AGPL project. The point is contributors contributed their code under the terms of the Apache 2.0 license. To use that code, you must meet the terms of that license. You can slap additional requirements on, you can't remove requirements. In fact, one requirement is the very fact you can't remove the license text itself!
- deleted 5y ago[deleted]
- yjftsjthsd-h 5y ago> Incidentally, the Apache 2.0 is a terrible license for modern open source, and it probably shouldn't be used. It's been a while since I've paid attention; what's wrong with it? It's just a permissive license with some patent stuff added, isn't it?
- Benjamin_Dobell 5y agoPlease see the EDIT.
- yjftsjthsd-h 5y agoAs of 2021-04-24T00:14:57Z, your edits don't appear to answer what problems you have with Apache 2.0? You've only said that people should read it and talked about its interactions with AGPL.
- ddevault 5y agoMinio's development culture has a very self-interested feel to it, like it's their thing moreso than the community's thing. Combine that with the corporate pandering it's designed for, and this was a long time coming. Back in February I remarked on IRC "I feel like minio is always one bad day away from changing to some bullshit proprietary license." I'm glad that it's the AGPL and not one of the nonfree fad licenses going around. For those wondering if they can relicense other people's changes without a CLA, the answer is yes. Apache 2.0 is compatible with the AGPL, so it can be relicensed with it (though the original contributions remain available as Apache 2.0). This does not work backwards, however - this is a one-way change. All of MinIO's code is today and forevermore available under the terms of the AGPL. They've done a pretty shitty job of it, though. No one should have a license change sprung on them like this. Further indicates that Minio does not value their community's input.
- deleted 5y ago[deleted]
- the_duke 5y agoIs sublicensing and relicensing the same thing? Sublicensing to AGPL should definitely be OK, but does that mean they can just relicense all contributed code and remove all mentions of Apache2? Seems doubtful to me. This GNU article [1] explicitly mentions that subsumed licenses still need to be mentioned in the source. [1] https://www.gnu.org/licenses/license-compatibility.en.html https://www.gnu.org/licenses/license-compatibility.en.html
- ddevault 5y agoHm, I'm not a lawyer, but the answer is... kind of. It's a bit complicated. I can understand a valid interpretation for either answer.
- merb 5y agoI'm not sure something like that is legal: - https://github.com/minio/minio/blob/master/pkg/argon2/argon2.go#L38 - https://github.com/golang/crypto/blob/master/argon2/argon2.go > forked from https://golang.org/x/crypto/argon2 > modified to be used with MinIO under GNU Affero General > Public License 3.0 license that can be found in > the LICENSE file. relicense the file based on a small change and also having two licenses on the same file? I'm not so sure, if the go authors are happy about that. they should probably consult a lawyer...
- yjftsjthsd-h 5y agoLooks like the original is under a permissive ("BSD-style") license, in which case they almost certainly can distribute it under any license they want.
- bsder 5y agoThey can distribute it, but this looks like it's changing the license. I thought that only the owner can change the license of the copyrighted file? Now, you can include BSD-style files with GPL ones without issue--that's true. But I thought you can't change the license of a file from BSD to GPL unless you are the original owner.
- yjftsjthsd-h 5y ago(IANAL) BSD-style licenses generally only require that the file and its derivatives retain the original authors copyright notice. Distributing it under a different license still allows you to fill the original requirements, so there's no conflict there. Or from a different angle, what exactly is the difference between including a BSD file in a GPL file vs including a BSD file in an empty file and then licensing the result as GPL? Edit: Does it help if I tell you that more precisely they aren't relicensing the file but merely stacking licenses on the file? The process is purely additive.
- sangnoir 5y agoWhen people say BSD-style licenses are "more permissive" than GPL - this is what they mean. You truly can do whatever you want, as long as you observe the license requirements (i.e. retain the BSD license notice). One can close-source a fork (but keep the notice), or add an additional compatible license like the GPL or AGPL (but keep the BSD notice), or add a license that bars use by cat-lovers (but keep the BSD notice). > I'm not so sure, if the go authors are happy about that. Then they should probably switch to a different license - one that more closely mirrors their intent. The cat's out of the bag for all released versions though.
- hardwaresofton 5y agoRemember, AGPL does not stop you from self-hosting or running a business on the software! It only requires you to share changes if you modify the software, which is a very reasonable requirement. I'm planning on launching a managed S3-alike service later this year and Minio is going to be what I use, it remains to be seen if they'll go to SSPL/BSL or anything else when enough people do this (maybe most wouldn't because of AGPL FUD so that's my uncommon advantage?). On a wider note though, is this going to be the projects/companies now? - Start permissively F/OSS project - Entice the community to contribute/produce content/market - (optional) Sell the project/cash out some how/get acquihired - Change the license of the project - Make all the new stuff source-available but not F/OSS to encourage people to get commercial licenses - ??? - Insert ads/subtle advertisements/banners into the OSS product so people are discouraged from hosting it (this is speculation, I assume this is what comes next) I sure do wish projects would be SSPL/BSL from the beginning, I want the freedom to be able to build a business on my freely obtained immensely valuable software, including hosting it, without worrying about rent seeking activity later. PS: yes, I'm aware of how incredibly selfish that last bit sounds, but I want to be honest about it -- this is what everyone is doing and why F/OSS software won. There's a world where we can build sustainable F/OSS software that runs on something other than donations, and IMO it looks like what Let's Encrypt's managed to do, where organizations that gain immense value from something do revenue-share style deals, but that's a discussion for another time. [EDIT] I just want to soften this -- I am NOT against companies making money from software. IMO AGPL is a great license because it actually maintains that freedom and requires contribution back (or monetary support). I just find that I am increasingly on edge whenever I see projects advertised as "open source" (but not free) and wonder if I'm just walking into a very nice, free-for-me mouse trap. BSL is a very nice license as well, it's straight forward, and IMO a great way to build an open source software company -- no one gets mad at Sentry for their license terms, because it's straight forward and obvious, and still giving a way value for free, just on a time delay. [EDIT2] I could have sworn there was a license that was like BSL but required anyone making over 1MM/year using the software to make some sort of contribution back, licenses like that might be cool too.
- tpxl 5y ago> - Start permissively F/OSS project > - Entice the community to contribute/produce content/market > - Change the license of the project You can't really do that without every contributor agreeing or using a compatible license (unless people sign CLAs, but even then you can only re-license further work).
- MichaelMoser123 5y agothere is the AGPL [1] and the GNU AGPL [2] now the AGPL is designed to block "Application Service Provider" hole. (closed source shops from using modified GPL source code without publishing their changes, as it is only hosted on a single network destination) Can someone please explain the differences between AGPL and GNU AGPL in this respect? Things are now very fragmented in the land of licenses; is there a resource that compares what they all imply? [1] https://en.wikipedia.org/wiki/Affero_General_Public_License https://en.wikipedia.org/wiki/Affero_General_Public_License [2] https://en.wikipedia.org/wiki/GNU_Affero_General_Public_License https://en.wikipedia.org/wiki/GNU_Affero_General_Public_Lice... [3] https://stackoverflow.com/questions/2127246/difference-between-affero-gpl-and-gplv3 https://stackoverflow.com/questions/2127246/difference-betwe...
- tareqak 5y agoFrom your link [1], > Compatibility with the GPL > Both versions of the AGPL, like the corresponding versions of the GNU GPL on which they are based, are strong copyleft licenses. In the Free Software Foundation's judgment, the added requirement in section 2(d) of Affero GPL v1 made it incompatible with the otherwise nearly identical GPLv2. That is to say, one cannot distribute a single work formed by combining components covered by each license. > By contrast, GPLv3 and AGPLv3 each include clauses (in section 13 of each license) that together achieve a form of mutual compatibility for the two licenses. These clauses explicitly allow the "conveying" of a work formed by linking code licensed under the one license against code licensed under the other license,[4] despite the licenses otherwise not allowing relicensing under the terms of each other.[5] > To establish an upgrade path from Affero's original AGPLv1 to the GNU AGPLv3, Affero, Inc. published the Affero General Public License version 2 in November 2007,[6] which is merely a transitional license that allows recipients of software licensed under "AGPLv1 or any later version as published by Affero, Inc." to distribute the software, or derivative works, under the GNU AGPLv3 or any later version.
- MichaelMoser123 5y agothanks! still these are different license, for whatever reasons, so there must be some kind of practical difference (other than the name)