5 ms·
There are uses for CLAs besides rug pulls. For example, if you want to offer software as AGPL, accept community contributions, but be able to _also_ offer a non
by buildfocus 2y ago
There are uses for CLAs besides rug pulls. For example, if you want to offer software as AGPL, accept community contributions, but be able to _also_ offer a non-AGPL option to paying customers (who effectively pay to be allowed to integrate the license without themselves being subject to licensing risk). Quite a few big orgs have a full ban on internal use of AGPL software so this can be very valuable.
That requires a CLA (as I understand it, IANAL) because you're relicensing a contributor's contribution. At the same time though, I wouldn't consider it a rugpull - contributors lose nothing here, and the open source project gains a funding mechanism (a rare thing in open source).
- cogman10 2y agoFunnily, one of the best places for this in practice (IMO) is microsoft. Who is now, again funnily enough, GPLing a lot of their software but have CLAs so they can do long term support for people that want to pay for it. Latest versions stay fully open source while back ported fixes are a paid feature if you don't keep your software up to date. That, to me, is a win win. Oracle is doing the same with the JDK.
- jabl 2y ago> Funnily, one of the best places for this in practice (IMO) is microsoft. Who is now, again funnily enough, GPLing a lot of their software but have CLAs so they can do long term support for people that want to pay for it. Huh, what software is MS releasing under the GPL now?
- cogman10 2y agoNot as much as I thought. MIT is more common it looks like. https://github.com/orgs/microsoft/repositories?q=license%3Agpl https://github.com/orgs/microsoft/repositories?q=license%3Ag...
- int_19h 2y agoMIT is the standard OSS license for Microsoft stuff that is open source. You also see Apache for some projects that predate standardization on MIT, and GPL where there's no way to avoid it (i.e. when you have to build on code that is itself GPL). That said, peak OSS at Microsoft is already past. These days, it's all about advertising products as OSS while quietly close-sourcing parts of it (e.g. just about the only thing in VSCode that's fully open source is JS support, every other language extension is closed to some extent).
- wmf 2y agoThis is abuse of the AGPL and open source in name only.
- piaste 2y agoRichard Stallman, of all people, is not as intransigent as you. > I've considered selling exceptions acceptable since the 1990s, and on occasion I've suggested it to companies. Sometimes this approach has made it possible for important programs to become free software. > [..] [S]elling exceptions permits limited embedding of the code in proprietary software, but the [non-copyleft] X11 license goes even further, permitting unlimited use of the code (and modified versions of it) in proprietary software. If this doesn't make the X11 license unacceptable, it doesn't make selling exceptions unacceptable. > I consider selling exceptions an acceptable thing for a company to do, and I will suggest it where appropriate as a way to get programs freed. https://www.gnu.org/philosophy/selling-exceptions.html https://www.gnu.org/philosophy/selling-exceptions.html
- yencabulator 2y agoThe continuous-rugpull part of demanding CLAs is selling other people's work as proprietary. You'll hear much less complaining if you're selling your own work under a second license.
- piaste 2y agoIt feels unfair to describe it as a "rugpull" when the first bullet point, in bold, reads: > *Grant of copyright license*. You give HashiCorp permission to use your copyrighted work in commercial products. https://www.hashicorp.com/cla https://www.hashicorp.com/cla Unless that text was recently changed, or unless Hashicorp went out of its way to verbally reassure people that they didn't intend to ever exercise that option, I feel very little sympathy for any open source contributor who clicked that link and then was dismayed to find Hashicorp using his work in a commercial product. Read what you sign, and take responsibility.
- pxc 2y agoI think you can do this in a principled way with some extra corporate/bureaucratic machinery, like the Free Qt Foundation, so that it doesn't allow rug pulls.
- barfbagginus 2y agoHmm. Orgs which ban AGPL should be marked and targeted for dismantling. Any way to scope them out, or public registry of them we can build? Orgs banning AGPL should not be allowed to exist at all, or use open source at all. They should all be systematically sabotaged by the OSS community, and if possible acquired/reformed, or destroyed. And it would be very convenient for me to be able to relicense an AGPL contributor's work as if it were mine all along, like an evil genius capitalist, tee hee hee :3 But I would fork a project that tried it, and that is the attitude we should encourage. Those aren't valid reasons for CLAs in my organizations and projects, since they do damage to AGPL as I envision it. I wonder if there are other reasons for a genuine AGPL radical to support a CLA? Seems AGPL is good enough on its own, and most CLAs just weaken it - both technically and in a spiritual and ethical sense. Could we strengthen it instead?
- Arrowmaster 2y agoAmazon bans it's developers from even viewing AGPL code on corporate devices. Good luck on your crusade.
- trueismywork 2y agoThat's a rug pull for a price. I don't think it's a problem because the software is still there. But it's a rug pull.
- GardenLetter27 2y agoEven just stuff like releasing a GPL'd game on Steam or consoles can have the same issue if you need to keep some parts proprietary.
- yencabulator 2y agoThere's no such thing as a "GPL'd game with proprietary parts". GPL was designed to prevent that. You can say "Steam and game consoles only allow publishing software with proprietary components", but don't blame that on GPL.