News: 1692365588

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

A license to trust: Can you rely on 'open source' companies?

(2023/08/18)


Opinion Company after company has had their start in open source software, and then gone on to dump their open source licenses once they've achieved a measure of success. It's time to stop it.

With a handful of exceptions, everyone uses open source to build their programs. It simply works better. In the last few years, though, one business after another has launched its releases on the backs of open source developers and then dumped their open source license in favor of a semi-proprietary one. It's not fair, and it's not right.

These companies have included Confluent, MongoDB, Elastic, Redis Labs, and most recently [1]HashiCorp . They all have pretty much the same story, the big bad cloud companies come along and deliver their software as a service at scale, and they can't afford to compete.

[2]

I'd feel more sorry for them if it wasn't for the fact that they were wildly successful by most business standards. For example, in its [3]last quarter, HashiCorp reported current non-Generally Accepted Accounting Principles (GAAP) remaining performance obligations of $394.6 million with 29 percent year-over-year growth. On August 11th, after HashiCorp announced its license change from [4]Mozilla Public License (MPL) to the [5]Business Source License (BSL) , the company had a market cap of $5.61 billion.

[6]

[7]

Neither was Elastic unable to compete. When [8]Elastic turned its back on open source, the company was worth almost $14 billion . In 2018, MongoDB dropped the [9]GNU Affero General Public License (AGPL) for its own [10]Server Side Public License (SSPL) and [11]reported a relatively small subscription revenue of $103.8 million, albeit an increase of 56 percent year-over-year, and services revenue of $5.6 million, an increase of 8 percent year-over-year.

They're not hurting. None of these companies were in financial hot water.

[12]

No, the bottom line was that their owners and the venture capital firms behind them wanted more money – a lot more money. In particular, VC firms are in the unicorn-hunting business. You might be happy with hundreds of millions, they want billions, thank you very much.

Other open source developers and companies are unhappy with this trend. Joe Duffy, CEO and founder of [13]Pulumi , a rival open source, Infrastructure as a Service (IaaS) company, pronounced [14]HashiCorp's announcement as "disingenuous. We tried many times to contribute upstream fixes to Terraform providers, but HashiCorp would never accept them. So we've had to maintain forks. They lost their OSS DNA a long time ago, and this move just puts the final nail in the coffin," he opined on the forum.

Amanda Brock, [15]OpenUK 's CEO, which doesn't have a horse in the IaaS race, appeared [16]disappointed with the company's move. "HashiCorp has always been a true open source company, and what Mitchell Hashimoto and Armon Dadgar achieved from a project never intended to be commercialized has been incredible."

[17]

Brock then asks, "Taking it to an IPO and seeing Mitchell have the apparent wisdom to step aside and allow a more experienced individual to run HashiCorp – but has that also led to its downfall as an open source company?" Her answer is yes.

"The statements about BSL are sadly open-washing. It would be wrong to suggest these two ever intended a bait and switch, but they have indeed switched away from open source. The pressure of enabling their competitors with their innovations – an inevitability of open source – did not align with the need to generate shareholder value."

That led her to another, bigger question: How much money is enough? Is a lot of money with others generating a lot of money, too, a reason to stop?" She's left "wondering whether had Mitchell remained CEO, this would have occurred?"

Directing his attention to HashiCorp's business model, Dotan Horovits, principal developer advocate for cloud-native, open source security Logz.io, said: "Companies fail to understand that open source is not a business model. As a result, we see this 'rights ratchet' model, pulled off as a defensive move against competitors, instead of building a sustainable business model. Unfortunately, this means that vendor-owned open source is becoming a business risk to users. relicensing is one-way open source that can 'turn to the dark side.'"

The dark side? Yes. Let's say, for example, you're an open source developer, who's not a stock owner in one of these companies. You may no longer be able to use your code. All too many projects have a [18]CAA (Copyright Assignment Agreement) , which gives copyright ownership to an organization, and/or Contributor License Agreement (CLA), which gives the organization a non-exclusive, perpetual license. Many of these also give the controlling entity the right to change the code's license.

Now, there's nothing wrong with a CLA – CAAs are much dodgier – but you're giving control of how other people can use your code in someone else's hands. For example, the reason we don't have an OpenSolaris today, even though Sun open sourced the code, was it used a CAA. When Oracle took over, they controlled all the copyrights and closed the code. That was it for OpenSolaris, although there is a fork, [19]illumos , and related distros such as [20]OpenIndiana

[21]Add 'writing malware' to the list of things generative AI is not very good at doing

[22]30 years on, Debian is at the heart of the world's most successful Linux distros

[23]Maker of Chrome extension with 300,000+ users tells of constant pressure to sell out

[24]Google opens up Chrome 117 Developer Tools box, drops in a few spanners

That's not what open source is all about. Open source, at its heart, is sharing with other people. These companies and licenses are all about control and profit.

There's nothing wrong with making money. But, I've gotten really tired of projects that use open source for their start and then turn their backs on the philosophy that made them their first hundreds of millions. At the very least, they need to stop pretending they're open source once they've moved to a "Look but don't touch" or "Look but don't profit from it" license. ®

Get our [25]Tech Resources



[1] https://www.theregister.com/2023/08/11/hashicorp_bsl_licence/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZN@VqNjH2hWds0bXTWdNwgAAAZg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://ir.hashicorp.com/static-files/9475fc23-0944-474d-9e99-34f489ff83bd

[4] https://www.mozilla.org/en-US/MPL/

[5] https://www.hashicorp.com/bsl

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN@VqNjH2hWds0bXTWdNwgAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN@VqNjH2hWds0bXTWdNwgAAAZg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.protocol.com/newsletters/protocol-enterprise/elastic-aws-libraries-open-source#toggle-gdpr

[9] https://www.gnu.org/licenses/agpl-3.0.en.html

[10] https://www.mongodb.com/licensing/server-side-public-license

[11] https://investors.mongodb.com/static-files/bce063e8-be64-4ad6-9a81-173085e265c6

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZN@VqNjH2hWds0bXTWdNwgAAAZg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.pulumi.com/

[14] https://news.ycombinator.com/item?id=37082324

[15] https://openuk.uk/

[16] https://www.theregister.com/2023/08/11/hashicorp_bsl_licence/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZN@VqNjH2hWds0bXTWdNwgAAAZg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://wiki.civiccommons.org/Contributor_Agreements/

[19] https://www.illumos.org/

[20] https://www.openindiana.org/

[21] https://www.theregister.com/2023/08/18/ai_malware_truth/

[22] https://www.theregister.com/2023/08/17/debian_turns_30/

[23] https://www.theregister.com/2023/08/11/chrome_extension_developer_pressure/

[24] https://www.theregister.com/2023/08/17/chrome_117_developer_tools/

[25] https://whitepapers.theregister.com/



b0llchit

If your project requires signing a CAA, then you are not soliciting a community but are preying on free labour.

There is nothing more despicable than turning your back on the FLOSS principles when you start out using it high in your banner. These companies deserve to go under and be doomed. You should not touch them and not use any of their products directly or indirectly.

Anonymous Coward

> The dark side? Yes. Let's say, for example, you're an open source developer, who's not a stock owner in one of these companies. You may no longer be able to use your code.

True, but...

Only in the edge case where your contribution was accepted in between the last OSS release and the first non-OSS release.

Not quite as apocalyptic as the article wants to make out.

BUT that said, avoid CAA.

If your code is non-trivial (and so you actually *want* to use it again!) put it in a library and send the project a patch that just invokes that.

This will be really unpopular, but

Anonymous Coward

When these companies turn their coats and "betray the community" they still left their last release, the one you are all currently using, as Open Source.

If there really *is* a community of developers and contributors that are feeling betrayed, then what is stopping you all (aside from giving a flying fuck about it all) from just forking and moving en-masse to that fork?

If your contributions were actually worth anything, then that will be a win. The Bad Guys can go stuff themselves, you are free of them now.

Sure, you aren't making any money of it, but you never were, so nothing has changed there.

I love this article

Pascal Monett

Especially since I said just about the same thing [1]7 days ago , concerning HashiCorp.

Nice to see that I'm not the only one with this opinion.

[1] https://forums.theregister.com/forum/all/2023/08/11/hashicorp_bsl_licence/#c_4710445

Frobnicate, v.:
To manipulate or adjust, to tweak. Derived from FROBNITZ. Usually
abbreviated to FROB. Thus one has the saying "to frob a frob." See TWEAK
and TWIDDLE. Usage: FROB, TWIDDLE, and TWEAK sometimes connote points along
a continuum. FROB connotes aimless manipulation; TWIDDLE connotes gross
manipulation, often a coarse search for a proper setting; TWEAK connotes
fine-tuning. If someone is turning a knob on an oscilloscope, then if he's
carefully adjusting it he is probably tweaking it; if he is just turning it
but looking at the screen he is probably twiddling it; but if he's just
doing it because turning a knob is fun, he's frobbing it.