11 ms·
LXD now re-licensed and under a CLA
- ropyeett 3y agoLooks like Canonical also messed up the licensing in their package: https://forum.snapcraft.io/t/incorrect-license-information-for-the-lxd-snap/38121 https://forum.snapcraft.io/t/incorrect-license-information-f...
- CoastalCoder 3y ago[deleted]
- headhasthoughts 3y agoYou, too, are wrong. From Canonical's actual announcement: > Canonical has decided to change the default contributions to the LXD project to AGPLv3 to align with our standard license for server-side code. All Canonical contributions have been relicensed and are now under AGPLv3. Community contributions remain under Apache 2.0.
- CoastalCoder 3y agoThanks for the correction. Seems like the headline was incorrect in a different way.
- tecleandor 3y agoYou're both kinda correct. What Stephane was complaining about is the whole Snap package for lxd has been marked as AGPL, and that's not correct. Check in the store, down, in the license info section: https://snapcraft.io/lxd https://snapcraft.io/lxd Edit: also, from what I see in the commit, it doesn't make much distinction between what's AGPL and what not. https://github.com/canonical/lxd/pull/12663/commits/b8ff449ddb44dee98105b292d531584e34d3a889 https://github.com/canonical/lxd/pull/12663/commits/b8ff449d...
- deleted 3y ago[deleted]
- headhasthoughts 3y agoIt is correct; the binary is AGPL, and Snap is a binary distribution method.
- NewJazz 3y agoNope, the binary is under both licenses. Just because they are compatible doesn't mean you can ignore the terms of one of them.
- notpushkin 3y agoI sometimes “editorialize” license names for Lunni Marketplace, too. [1] I think it’s fine: the binary is under both licenses, but one requires you to publish a notice and the other requires you to publish a notice and all source code for both parts. Since you want to know what “license burden” you’ll have to bear when you’re looking for an app in a distribution platform like this, I think it’s fair to just specify the more restrictive license. (IANAL) [1]: https://lunni.dev/docs/marketplace/ https://lunni.dev/docs/marketplace/
- dang 3y agoThe submitted title was "Canonical re-licenses LXD under AGPLv3, slaps a CLA on top". I've changed it to the article's title, in keeping with HN's rule: "Please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html If the current title isn't accurate, and anyone can suggest a more accurate and neutral one, we can change it again.
- ZiiS 3y agoLxd as a whole is certaily now only available under the AGPLv3 license. Some parts are also available under the Apache 2.0 license. And Canonical are bound by that agreement to tell you such; but it is still factual to say you have to agree to the AGPLv3 to distribute it.
- JonChesterfield 3y agoLinux containers project. Foreshadowing of this move at https://linuxcontainers.org/lxd/ https://linuxcontainers.org/lxd/
- photonbeam 3y agoTime to support the fork
- phatfish 3y agoInteresting, it looks like Incus is the fork (announced in October)? I've really wanted to try LXD but it was infected with Snap and the other Canonical baggage. What i need is straightforward way to run/manage VMs with the ability to have a couple of hosts in a HA setup to failover VMs on an NFS share. libvirt does this just about, but it's pretty painful to use, and the stack needed for Proxmox/oVirt feels too complex. As far as I could tell LXD did what i want.
- 1letterunixname 3y agoAGPL: The radioactive license when you don't want anyone to use your "open" source. (Google, Meta, and more cannot and will not use AGPL code at all.) This change to LXD harms VPSes and any company that uses LXD in SaaS.
- usr1106 3y agoWhen you don't want Amazon, Google etc to earn big money on your work. Actually not even that, they could if they played fair and contributed back all changes they make. But they don't want to play fair.
- jraph 3y agoIs this FUD? [edit: it's not, see the replies - I kept my original comment below because that's what people answered to, but I no longer agree with it] --- The linked announcement says > Going forward, any contribution to LXD will be made under AGPLv3 by default. The author of a change remains the copyright holder of their code (no copyright assignment). Emphasis mine. No copyright assignment. So, Canonical now contributes in AGPLv3. The project is now AGPLv3 as well, with some parts in Apache 2. Contributors may contribute in Apache 2 if they wish but probably won't bother. They still own their code. The author is pissed off because he can't build custom versions without redistributing the modifications and can't sell services to companies afraid of the AGPL anymore.
- ropyeett 3y agohttps://ubuntu.com/legal/contributors/agreement https://ubuntu.com/legal/contributors/agreement for the details. In short, you don't lose your own copyright but you grant them a license to do whatever they want including re-license as they wish without having to ever consult you, allowing for your code to be used within their closed source projects under any license they wish.
- jraph 3y agoAh, right, it's not a copyright assignment, but there is a CLA. Confused the two concepts, rookie mistake. So yeah, not good. I will edit my comment. I would even say that not mentioning the CLA and mentioning the absence of copyright assignment in the announcement is quite dishonest.
- 3y ago
- shp0ngle 3y ago"As a result, Canonical cannot release LXD under the AGPLv3 license and likely never will be able to. LXD is now under a weird mix of Apache2 and AGPLv3 with no clear metadata indicating what file or what part of each file is under one license or the other." IANAL but that's not true? You can take Apache2 and relicense it under AGPL? You can take "less copyleft" license and make it "more copyleft". https://www.gnu.org/licenses/license-list.en.html#apache2 https://www.gnu.org/licenses/license-list.en.html#apache2 It's entirely kosher in my opinion, and the entire thing agpl, with no "weird mix" or whatever
- ropyeett 3y agoThey can freely include Apache2 licensed code in an AGPLv3 project without having to re-license the entire project under Apache2 as it's not a copyleft license. However this doesn't make the code they included AGPLv3, that code remains Apache2 and must be declared as such.
- jraph 3y ago> You can take "less copyleft" license and make it "more copyleft". Only if licenses are compatible. But Apache 2 is AGPL-compatible so > It's entirely kosher in my opinion Yes, I think so too. However, they need to make it clear which parts are under Apache 2.
- type0 3y agoIt is if you own copyright for that code, then you can re-license. It seems Canonical didn't ask the permission of contributors that haven't signed their CLA, so Canonical have no right to change the license for that code > However, they need to make it clear which parts are under Apache 2. The only thing they needed to do is to add the statement that parts of the code that were written before LXD 5.20 remain Apache 2.0
- shp0ngle 3y agowhat IS weird though is the go exosystem thing. in go ecosystem, copyleft is very much not the norm. People might not realise that by just adding copyleft dependency to go.mod, the entire project becomes effectively agpl as it has the code built-in.
- kragen 3y agothe main reason there's a version 2 of the apache license is to ensure that it's clearly legal to incorporate apache-licensed code into gpled systems such as this new version of lxd it is correct that the ubuntu company cannot prohibit people from copying and modifying stephane's code, or indeed the entire previous version of lxd, under the terms of the apache license. but they can certainly keep using his code in new versions of lxd under agpl in fact, apple can use stephane's code in a proprietary lxd derivative if they want to. that's what the apache license is designed to permit if you want to prevent people from using your code in a more-restrictively-licensed fashion, don't use the apache or other bsd-like licenses; use a copyleft license like the agpl. and don't sign a cla
- stgraber 3y agoAnyone is welcome to use my code in a proprietary piece of code, indeed the Apache2 license allows it. What it doesn't allow is for my code to be re-licensed to AGPLv3 nor can they grant themselves a license to do whatever they want (their CLA). So indeed they could keep importing Incus bugfixes and new features into LXD, but that code would need to have an exception carved out in their current contribution requirements as the code would not come from an author that has signed the Canonical CLA nor would it be under the AGPLv3 license. They would also need adequate tracking of this so they don't accidentally assume that the code belongs to them and that they can re-license it as they wish for other projects. Also anyone who stumbles onto that code in the LXD codebase should be properly informed that they can include that code in a non-AGPLv3 project as that bit of code is Apache2, not AGPLv3.
- Macha 3y agoThe reason they need the CLA is to exempt themselves from the burdens of the AGPL license, however. It's not much work to use Apache 2.0 in a proprietary (or AGPLv3) project. Unlike the AGPLv3 it doesn't impose many burdens or the project using it.
- jraph 3y agoI guess you already thought carefully about all this, but wouldn't you actually prevent them from reusing your code (in a closed version) if it were released under (A)GPL? Because if you keep releasing your code under Apache 2, you prevent yourself from taking their code while allowing them to take yours. You could lose at this game. If you released under AGPL, you would reverse the direction. They would not take your code without the CLA but you'd be fine with taking theirs. I know, you mentioned companies disliking AGPL.
- MrStonedOne 3y ago[dead]
- anonymousiam 3y agoSo does this mean that LXD will replace libvirt in the next Ubuntu release? I'm running 23.10 on this machine right now (because the hardware is too new to run anything more stable), and it's still got libvirt.
- tarruda 3y agoLXD is separate from libvirt, I don't think one affects the other. The only thing common between LXD and libvirt is that both use qemu to run virtual machines.
- segmondy 3y agoIt's time for someone else to replace Canonical, that's all I can read from this. We can expect more of this rubbish in the future.
- gpm 3y ago> However, if you were altering LXD in any way, then you will need to familiarize yourself with the AGPLv3 license as unlike Apache2, it does require any changes be made available under the AGPLv3 even if you don’t expose your users to your modified binaries. This is a fascinating argument... You're saying that you cannot add compatibly licensed code into APLv3 software (that you don't also have a more permissive license to modify/own the copyright to) without violating the AGPLv3. I think it also follows that you can't legally modify AGPLv3 software containing bits of compatibly licensed code unless you also have more permissive rights to it or your fully strip out the compatibly licensed code? I have to say, I'm reading the AGPLv3 and it seems like a reasonable conclusion, at least if you also distribute ("convey") it. In particular the clause that says "You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy [...]" would seem to imply this.
- tremon 3y agoI'm not sure what your argument is. "compatibly licensed code" is doing a lot of heavy lifting, and because you don't define that term, your post reads as little more than FUD. Yes, you cannot distribute GPL'ed software if you don't have a license to distribute the source to the whole work. That's not unique to the Affero GPL, that's equally true for GPLv2 and GPLv3. But that's not a problem with respect to "compatibly licensed code" because that wording implies that said code is compatible with the constraints of the GPL.
- gpm 3y agoTo reiterate the argument, one of the constraints on conveying modified versions of AGPLv3 is the text I quoted at the end - that the entire conveyed version be licensed under the AGPLv3. Supposing OPs arguments are correct that third parties don't have the right to relicence apache licensed code... you can't do that? By "compatibly licensed" I meant nothing more or less than "licensed under a license such as Apache 2". I'm not a lawyer though. I'm not saying this interpretation is correct. In fact I'm somewhat dubious of it because it is obviously contrary to the purpose of the AGPLv3, and I believe the people who wrote the license were in fact lawyers. That doesn't mean they couldn't have made a mistake though, and I would describe my current honestly come by opinion of the AGPLv3 as "uncertain and doubtful".
- HankB99 3y agoLXD is container technology, right? I've used Docker for years now (in my home lab.) I took a stab at using Podman a couple times but the friction was too high (and my motivation to switch too low.) How does LXD compare to Docker? Should I be interested in it or just continue with Docker for the handful of containers I'm using (Gitea, Checkmk, MariaDB, Mosquitto.) The license is not interesting to me unless there's a technical advantage. (And for my personal use the license is probably moot anyway.) Host OS would be Debian, if it matters. Thanks!
- forinti 3y agoLXC/LXD is similar to Jails. You have a directory with a whole distribution and a config file with a few details such as network setup and bind mounts. It is much simpler than Docker. I think it's a better starting point if you want to learn about containers. Just last week I tried LXC on Debian, but there was a conflict with iptables. I had more success with Ubuntu.
- CoolCold 3y ago> It is much simpler than Docker Quite a bold statement, very much depends on the task and user's background. For one, running things across your team members, team consisting of mixed Windows, Macos, Linux workstations/laptops, you can't rely on LXD be easily accessible (the same for Jails of course). Running quick tests, one-shot tasks like docker run --rm -v "$(pwd):/sitespeed.io" sitespeedio/sitespeed.io:30.9.0 https://www.mysuperstartup-website.io/ Is easy peasy - friend of mine being SEO guy, could do this. No chances this can be done with LXD (jails of course is even worse for UX/DX - it's requires FreeBSD)
- rcxdude 3y agoLXD is containers but presented much more like a traditional VM, without so much of the Dockerfile type stuff. If you just want VMs but more lightweight, it's great for that and has less footguns and cruft. If you actually want to make use of the docker-type features then it's not really designed for that.
- NewJazz 3y ago
- michaelmrose 3y agoSo you have a file function foo is Apache, bar calls foo. Isn't bar a derivative work of foo? Someone from canonical rewrites foo changing 4 of 7 lines. In this version is foo now canonical's contribution or still the original contributor? A: Is it accurate to say that there is no metadata regarding who owes what because it would take millions and a trial to decide? B: Is it accurate to say that this uncertainty is basically as good as owning the whole thing in this case because it is impossible to use it other than either under the terms of the AGPL or some commercial license from Canonical? You are obviously blameless for using the Apache code. C: Does the inherent confusion mean that if similar features are committed to the mixed proprietary/AGPL branch the inherent complexity of deciding who owns what would make using the open source branch a minefield. EG evilcorp with a substantial budget could simply shut down the open source branch with threats of ruinously expensive lawsuits and false but not obviously false claims of infringement. D: If A B C does this mean that ANY permissively licensed project which is partially owned by a party which presently contributes substantially to the labor could in effect take an open source project proprietary by first making it the path of least resistance to continue with their fork and later the only choice.
- notpushkin 3y ago> bar calls foo. Isn't bar a derivative work of foo? I think it isn’t. Function signatures are fair use (under certain conditions, as established in Google v. Oracle), so just calling a function isn’t enough to declare your code a derivative work. The combined work however is of course a derivative work of foo and is subject to its license terms, so if you want to be able to distribute it, you have to allow abide by them (i.e. release source code for both foo and bar if foo is AGPL, even though bar can be Apache or MIT or something; and you can’t use a more restrictive license that AGPL for bar). If you want you can reimplement foo yourself though – then you can distribute bar together with your implementation under any license you like. (IANAL)
- DannyBee 3y agoShort answer: No in most cases. You can't create confusion and then sue people over the confusion. This is the purpose of copyright notice - you have to make it clear enough who owns rights to avoid various defenses. As for your function question: Copyright was created mostly for books, remember. As such, it gets weird quickly when applied to code. For example - i write a book, and on page 236, it says at the top "the text of this page is copied from the folowing book <some book>" and then copies it inline. This is probably infringement. If i instead write a book, and on page 236, it says at the top "for the text of this page, please see page 194 of the following book <some book>" and does not copy it inline. This is not infringement. Now, could you currently convince a judge how shared library vs static library linking works, and that it matters? Maybe. Moreso than you could a decade ago.
- teleforce 3y agoDear me, I thought CLA is a new type license. Perhaps the title need to also include AGPLv3, the type of license LXD is changing to.