6 ms·
I feel open source has turned into two worlds
- CaptainFever 1y agoPersonally, the distinction I draw isn't between corporations and cooperation as per the article ("they make money" is kind of an arbitrary difference IMO), but just that in general maintainers have no obligation to do any sort of work for free. So like, regardless of the user of the software, one should understand that there really is no warranty, or promise of quality or support from FOSS. If one (whether it be Debian or Apple) needs a feature, bug fix, or security fix, one can ask for it, but don't expect anything. The best way is to do it themselves, and share their code if they wish to or are obligated to under the GPL. Or commission a programmer or the maintainer to do it. Or buy a support contract from the maintainer. Or encourage it by doing micropatronage and voting for it.
- anewhnaccount2 1y agoI think this is correct and projects like DuckDB are doing a food job at supporting both halves by triaging issues also based on the identity and affiliation of the author (no anonymous issues) and converting them into supporters https://duckdblabs.com/community_support_policy/ https://duckdblabs.com/community_support_policy/ This passive approach of libxml2 where the software remains community only is just fine and totally fair, but corporate users can pay up if there's a clear offering. What they actually get doesn't need to be much, but if it does need to be clear. Of course this does change the project into hybrid community/corperate open source but there can be a spectrum there where a lot of time and resources is carved out for the community approach and the corperate sponsors are given just enough to keep them happy. In a way some more corperate focussed Linux distributions are also an example of a hybrid approach really given the two worlds are very much linked.
- captn3m0 1y agoI don’t see affiliation/no-anon-issues on the DuckDB link, do you have a better link?
- politelemon 1y ago> This policy will probably make some downstream users nervous, but maybe it encourages them to contribute a little more. This is an understated but brilliant framing. Oh I know they won't contribute, users will continue to apply pressure through issue threads saying that their clueless security teams are breathing down their necks. But at least you'd hope this gives pause. The linked issue is worth a read, it's a shame the burden that corporate leeches like apple and google have placed on him. To them this project is simply free labour they have assumed they are entitled to and by extension are subject to their individual security theatrics. https://gitlab.gnome.org/GNOME/libxml2/-/issues/913 https://gitlab.gnome.org/GNOME/libxml2/-/issues/913
- jsnell 1y agoI'd note that the only thing Apple, Google and MS are said to have done is to use the software. The bug has no actual example of them making demands, "leeching" or acting entitled. The security issues would be security issues just the same even if the library was only used by Linux desktops. (And if the library is unfit for use in other operating systems like the author suggests, feels like it probably is equally unfit for use in Gnome.)
- polotics 1y agoIt's high-time for a "reasonable compensation" clause in hobbyists' open-source software licenses I think. Something to the effect of: "if you're using my labour of love to make millions, gimme one of these millions..."
- KingMob 1y agoThe current attitudes and licenses of FOSS, while good in many ways, have also enabled a ton of exploitation and free-riding, and people need to acknowledge that. Nobody should be giving Bezos free work.
- ItCouldBeWorse 1y agoEspecially when Bezos uses that free work,to sabotage the free eco-system wherever he can. Building moats and garden walls, embracing, extending and extincting. And you can tell by the way they move, they do not want to hurt each other- a cartel of toe-owners. Otherwise, what happened to gaming with the steam-deck, could have happened with linux to the desktop world years ago. Especially now, where the owner describing his intent, transfers to scripting glue code.
- GardenLetter27 1y ago> Nobody should be giving Bezos free work. Just use the GPLv3 or AGPL, problem solved.
- ThunderSizzle 1y agoDoes it really? Licensing only means as much as the enforcement that follows infringement, and good luck forcing Amazon to lose on a case like that.
- pabs3 1y agoThe GPLv3 or AGPL still result in free work for corporations, and are easy to comply with for corporations, without paying a cent to maintainers, so do not solve the problem.
- deleted 1y ago[deleted]
- KingMob 1y agoUhhh, neither of those forces Amazon to pay you for your efforts if they use your library. I think you pattern-matched to a different argument.
- notarobot123 1y agoAt this point, why shouldn't the licences change? Sharing the result of collaborative efforts liberally makes sense. Wanting to be able to modify software and redistribute modifications makes sense. Allowing software to evolve in a broader eco-system makes sense. What isn't seeming to make sense is how OSS software is used commercially and the way that skews the culture and priorities of open source projects. What purpose does the lack of commercial restrictions serve? No restrictions on commercial use at all seems naive (and perhaps plain ideological) at this point. I used to think that things were too embedded to change but it does feel like a major shift is fermenting and has been for a while.
- Arainach 1y agoThere's always a tradeoff in use or contribution. If a project is under a more restrictive license the odds of individuals or companies contributing (or for certain licenses even using) drops radically. If your intent is just "I wrote this thing, sharing the code" license as restrictively as you'd like. If your intent is "I want to build (and/or get others to help build) a bigger thing", restrictions scare folks off. It's trivial for me to get approval from my employer to do almost anything in almost any MIT-licensed codebase; we use and contribute to a number of GPLv2 codebases. However GPLv3 is a very rigid line in the sand that I do not expect to ever change.
- pabs3 1y agoWhat is it about GPLv3 that causes a line in the sand? The source distribution, modification and reinstallation requirements are pretty much identical, at least according to the main folks doing Linux kernel GPL enforcement for the last decades. https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-the-gpl-right-to-install/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017/11/Safely-Copylefted-Cars-Reexamining-GPLv3-Installation-Information-Requirements-ALS-Bradley-Kuhn-Behan-Webster-1.pdf https://events19.linuxfoundation.org/wp-content/uploads/2017...
- _vere 1y agoIt's also notable that these companies often dont respect the terms of foss software at all. Anyone worth their salt can tell you that training your LLM on gpl3 code would make it a derivative product, as it is able to reproduce large parts of that code. LLMs that are currently earning Google, Facebook, Openai, etc, billions, while they obviously dont make "their" products available under gpl3.
- GardenLetter27 1y agoI don't mind them training on GPL code, but I wish they had to at least publish their model weights (and maybe also training and inference code, etc.) - same for the other issues re. using copyrighted media in training.
- _vere 1y agoIts not really about if you mind, they create derivative works in direct violation of the gpl.
- karmakaze 1y ago> They're not in open source as a cooperative venture, they are using it to make money > Existing open source licenses, practices, and culture don't draw this distinction I disagree for the most part. Corporations avoid copyleft licenses like the plague. It's the term open-source that includes 'free beer' licensed software that created this confusion.
- MichaelZuo 1y agoIt does seem like a strange claim to make…
- NoGravitas 1y agoLots of companies will draw the line in different places. Some will accept GPLv2 but not GPLv3. Some will accept GPLv3 but not AGPLv3.
- burnt-resistor 1y agoGoogle and Meta have policies against using any AGPL code anywhere.
- pabs3 1y agoI wonder why, it is not like it is hard to comply with.
- burnt-resistor 1y agoLegal absolutism and intransigency, and maybe some ideological retribution. ¯\_(ツ)_/¯ I paid my dues in MAANG. Business culturally, control seemed all-important. They seemed to want source they could use without giving a dime to maintainers, if they so chose. Some support was given, but not enough and not uniformly.
- ndiddy 1y agoI feel bad for the libxml2 maintainer. The project was originally intended for parsing GNOME configuration files, but then a bunch of corporations started using it to parse untrusted data with much higher stakes. I hope that both the decision not to prioritize security issues and the new notice in the README saying it's foolish to use the project to parse untrusted data will encourage corporate users to either switch to a different project or do more to improve its security than dumping security reports onto an unpaid maintainer. I will say that all of the comments saying that open source licenses should change to formally prohibit this behavior are a bit naive. Ever since the Open Source Initiative was founded in the late 90s, its express purpose has been to boost the adoption of free (now "open source") software by pitching it to corporations as a way to cut costs. This means that they'll never approve a license that requires certain users to contribute to the project, monetarily or otherwise. Of course anyone's allowed to license their project any way they see fit, but they'll have to call it something other than open source and accept the limited distribution and userbase they'll see as a result.
- wavemode 1y ago> Of course anyone's allowed to license their project any way they see fit, but they'll have to call it something other than open source and accept the limited distribution and userbase they'll see as a result. This doesn't require abandoning open source. The GPL and AGPL serve precisely the purpose of preventing open-source software from being exploited for closed-source purposes. Obviously hindsight is 20/20, so this doesn't help maintainers who have already chosen a permissive license and don't want to rugpull their users. But to say solving this problem requires adopting a non-open-source license is not correct. Another option is dual-licensing - GPL/AGPL for all, or a permissive license that can be purchased for a fee.
- ndiddy 1y agoI was specifically talking about the people saying that the corporate users should be required by the license to provide compensation or assistance to the project. You're right that licensing as GPLv3 or AGPL generally limits corporate use of open source, and that selling license exemptions is a good way to let everybody win (although it means you'll have to either not accept contributions or make all your contributors sign a CLA).
- phendrenad2 1y ago> You might not want to leave Debian (which is fundamentally people) in the lurch over a security issue, but if a corporation shows up with a security issue, well, you tap the sign. I think that many people have done this, and all of them were deposed and replaced with someone who would "play ball" (I.E., work for free). Go ahead, keep an eye on Libxml2, we'll either see this reversed, or we'll see libxml3 promoted from all angles and libxml2 decried as "deprecated". Note that if that happens, it doesn't mean libxml2 is actually bad, it just means that it no longer fits the needs of the corporate overlords, and they need YOU to believe that it's no longer good so you won't waste their time with support requests.