News: 1633962609

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

.NET Foundation focuses on 'issues with the community' after executive director quits

(2021/10/11)


Analysis .NET Foundation executive director Claire Novotny resigned last week, but board member Shawn Wildermuth said that this did not solve "issues with the community" on which the foundation will now focus.

The phrase "issues with the community" in [1]Wildermuth's post should not be taken to mean that the community has misbehaved. It would be more accurate to call it the community's issues with the .NET Foundation, or perhaps with Microsoft, since the special role of Microsoft is one of those issues.

Both longstanding issues and a few more recent ones have triggered the current crisis. In summary:

Recent

Novotny made a [2]pull request and merged it to a project to which she had not contributed for years.

.NET Foundation projects were forcibly moved from GitHub to the .NET Foundation's GitHub Enterprise without discussion with maintainers and sometimes in what appears to be an [3]underhanded manner , such as for the WiX Toolset – though maintainer Rob Mensching has managed to [4]move it back .

When board member Rodney Littles II [5]resigned , the .NET Foundation implied in a post that this was to do with his "personal life" when in fact it was about frustrations with the .NET Foundation's role and lack of communication with member projects.

Longstanding

Projects have complained that the foundation delivers little of value to them and some have left or expressed interest in leaving. A co-maintainer of the [6]Marten project [7]said last week: "After… two years, we don't see any positive impact, any help from being a member."

The top issue faced by many .NET Foundation projects is their sustainability, but the foundation has concentrated on things like the semi-abandoned [8]Project Maturity , which seems designed to reassure enterprise customers.

The .NET Foundation has done too little to promote .NET to a wider community than Microsoft's own platform.

The .NET Foundation is not fully independent but controlled by Microsoft, which has special "Founder member" status in the organisation's [9]bylaws .

The .NET Foundation is poor at communication with member projects or the wider community and major changes like the proposed removal of the contribution model for projects, later [10]reverted , happen with little explanation. The contribution model allows projects to join the Foundation without assigning their copyright.

Hadi Hariri, VP of Developer Advocacy at JetBrains, [11]noted on Twitter last week: "JetBrains was one of the first to join the foundation when it was announced. However, the broken promises, the approach to how it treats OSS, and the overall lack of value to both JetBrains and the community is the reason we no longer are sponsors."

JetBrains provides the Rider cross-platform .NET IDE and is a natural fit for sponsoring the Foundation.

Opening up

In all this discussion, it is easy to lose sight of the fact that Microsoft made a huge change when it [12]took .NET open source and launched the foundation in 2014. Most of .NET is licensed under the MIT or Apache 2 licences and available on GitHub, and that single fact counts for a lot.

The foundation, although it describes itself as independent, is only partially so. The [13]bylaws grant Microsoft, as Founding Member, a veto on "any vote to materially change the Foundation's Membership Policy, Director Election Policy, Project Governance Policy, or any Intellectual Property-related agreements or policies."

[14]

Further, Microsoft controls the direction of .NET and its core libraries. Corporately, it may simply be unwilling to risk losing control of its core developer platform.

[15]

[16]

What was Project Maturity (and perhaps the Foundation) really about? A [17]2019 tweet by Novotny is a clue. "It's about enabling Microsoft to recommend and take dependencies on libraries not created by them instead of creating new ones that squash projects," she said.

That possibly unguarded comment is a Microsoft-centric view of what third-party, open-source .NET projects are for and the foundation's recent behaviour is in line with that.

[18].NET Foundation boss apologizes for pull request that sparked community row

[19]Microsoft's .NET Foundation under fire as resigning board member questions its role

[20]Feeling saucy? Wave of Microsoft releases includes go-live licence for .NET 6

[21]Faster .NET? Monster post by Microsoft software engineer shows serious improvements

What happens now? Newly elected board member Rob Prouse, who leads the [22]NUnit team, [23]said : "We will be doing our best to address all the concerns that have been raised recently," and referenced a new "maintainers committee."

Prouse also [24]said that "for projects that were moved into GitHub Enterprise and would like to move back, we are working on a plan to do that."

[25]

Further announcements are expected this week.

The relationship between large corporations and open source is often strained. Oracle required a commercial licence for its official Java Development Kit in September 2017 and then [26]made it free again last month. Google donated Kubernetes to the Cloud Native Foundation but chose a [27]controversial path and the formation of a new organisation for its related Istio project. Elastic [28]changed its licensing to restrict commercial usage of its open-source database manager.

It is in Microsoft's interests to have a healthy open-source community around .NET. The foundation, which once seemed part of the strategy for achieving that, now seems to stand in its way unless the company can achieve meaningful reform.

[29]

We have asked both Microsoft and the .NET Foundation for comment on these matters but have so far received no reply. ®

Get our [30]Tech Resources



[1] https://github.com/dotnet-foundation/Home/discussions/40#discussion-3615586

[2] https://github.com/reactiveui/splat/pull/778

[3] https://github.com/dotnet-foundation/Home/discussions/38#discussioncomment-1432691

[4] https://robmensching.com/blog/posts/2021/10/6/how-the-.net-foundation-kerfuffle-became-a-brouhaha/

[5] https://www.theregister.com/2021/10/05/microsoft_net_foundation_under_fire/

[6] https://github.com/JasperFx/marten

[7] https://github.com/dotnet-foundation/Home/discussions/39#discussioncomment-1440602

[8] https://github.com/dotnet-foundation/project-maturity-model

[9] https://dotnetfoundation.org/about/bylaws

[10] https://github.com/dotnet-foundation/projects/pull/118

[11] https://twitter.com/hhariri/status/1445248121915727874

[12] https://www.theregister.com/2014/04/04/microsoft_launches_open_source_net_lovein_with_new_foundation/

[13] https://dotnetfoundation.org/about/bylaws

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWRfvsAzlYozXWwruab@fQAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWRfvsAzlYozXWwruab@fQAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWRfvsAzlYozXWwruab@fQAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://twitter.com/clairernovotny/status/1178372552391102466

[18] https://www.theregister.com/2021/10/07/net_foundation_boss_apologises_for/

[19] https://www.theregister.com/2021/10/05/microsoft_net_foundation_under_fire/

[20] https://www.theregister.com/2021/09/15/dotnet_6_go_live/

[21] https://www.theregister.com/2021/08/18/faster_dotnet_6/

[22] https://nunit.org/

[23] https://github.com/dotnet-foundation/Home/discussions/40#discussioncomment-1450195

[24] https://github.com/dotnet-foundation/Home/discussions/42#discussioncomment-1450522

[25] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWRfvsAzlYozXWwruab@fQAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[26] https://blogs.oracle.com/cloud-infrastructure/post/introducing-free-java-license

[27] https://www.theregister.com/2020/07/09/ibm_oracle_cncf_protest_commons/

[28] https://www.theregister.com/2021/01/18/elastics_doubling_down_on_open/

[29] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWRfvsAzlYozXWwruab@fQAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[30] https://whitepapers.theregister.com/



Helicopter Parents

Will Godfrey

That's what this makes me think of. Never really wanting to let their children go.

Rock and a hard place

chuBb.

Will be interesting if they can square the circle, I don't think they will have much choice but for MS to either loosen the reigns a little or to change the foundations mission.

Look at something like Json.net* which is a dependency for a lot of the official Azure packages, there was quite a lot of hassle caused when the official nuget packages lagged behind a major version of json.net and broke builds if you accidently updated to an incompatible version (and as its such a widely used package you could update to an incompatible version by updating a different package with a dependency on it, such as StackExhange.Redis which you would want to do to fix a memory leak caused by the old v1 connection multiplexor) which led to us having to postpone a reliability fix until the Azure Storage packages were up to date, same with Azure Services lagging 2 or 3 versions behind its deployed azure storage libs and the latest on nuget

In my opinion the quote of

"It's about enabling Microsoft to recommend and take dependencies on libraries not created by them instead of creating new ones that squash projects,"

is mostly right, but really the Foundation should be instructing/co-ordinating MS to keep its packages up to speed with the latest public OSS packages, not making the OSS packages trustworthy. The foundation should be funnelling back into MS the state of play of the foundations projects and making sure MS isn't the ones effecting the trust in the OSS packages. And on that front they are an abject failure as its MS's fault we ended up with a Faustian choice of no more random crashes but have to run production with pre-release (and breaking changes did happen between pre-release and release ready Azure storage packages) or put up with random crashes but working access to storage knowing that the problem is fixed but unsupportable. FWIW I took a middle option and rearchitected the product to separate the storage aspect into its own project and had a separate redis service which then was re-integrated into one service when the dependencies aligned, basically 4 weeks of unnecessary dev work and 3 deployments because MS couldn't keep up with projects it should have been following....

*It might not have been json.net it was a couple of years ago but pretty sure it was something like that

** And before someone says LOL that's what you get for azure, AWS is no better and decisions were made prior to me joining the company

Doctor Syntax

"The relationship between large corporations and open source is often strained."

I think many of them looked on it as a PR move. I made them look trendy, hip, cool or whatever. The fact that it has legal significance for the way software is developed passed them by - and maybe bypassed their legal departments. It doesn't seem to be the prerogative of large corporations either as some startups seem to have done the same.

J.Teodor

It almost feels like this is a publicity campaign before the release of .NET 6. Any publicity is a good publicity....

Your mind understands what you have been taught; your heart, what is true.