Do we really need another non-open source available license?
- Reference: 1700825828
- News link: https://www.theregister.co.uk/2023/11/24/opinion_column/
- Source link:
Today, code that's not open source is the rare exception. But that hasn't stopped companies who mistook open source as a business model instead of a development model from trying to combine proprietary methods with "open source" code. The latest is Sentry's [1]Functional Source License (FSL).
Following in the tradition of [2]Server-Side Public License (SSPL), [3]Common Clause , and the [4]Business Source License , the [5]FSL nods at the importance of open source while sneering at its heart by claiming its approach is "Freedom without Free-riding."
[6]
Please.
[7]
[8]
Sentry is a developer-oriented app code monitoring service that began as a short bit of code for Django, the open source, high-level Python web framework. Today, it's still used most for open source code development. Without open source, Sentry doesn't exist.
Neither do any of the companies now using "source-available" or other semi open source licenses. They all began as open source companies, then to maximize profits, they relicense the code they've gotten for free from contributors to lock down the code.
[9]
As Thierry Carrez, vice chair of the Open Source Initiative (OSI) board, told me, "Some companies have built their software by leveraging the body of open source code available to them, without having to ask for permission before using hundreds of open source packages in their dependencies. They built their reputation by publicly committing to the open source principles. But in a short-sighted effort to capture incrementally more value, they later decide to abandon the model that made them successful in the first place." Exactly so.
Sentry, [10]MariaDB , [11]Redis , and [12]HashiCorp , to name a few of the former open source companies, can get away with this thanks to rights-aggressive Contributor License Agreements (CLA)s. These are legal documents that define the terms contributors grant for their code to be used in an open source project. While some CLAs, such as the Apache Software Foundation’s CLA or Linux's Developer Certificate of Origin, are used simply to protect the legal rights of their projects, others are used to grab your code and its copyright, such as MongoDB's contributor agreement. With these CLAs, the companies can then use and relicense your code in any manner they like.
As Drew Devault, the founder and CEO of SourceHut, said about [13]Elasticsearch and its move from open source to source available, "Elasticsearch belongs to its 1,573 contributors, who retain their copyright, and granted Elastic a license to distribute their work without restriction. This is the loophole which Elastic exploited when they decided that Elasticsearch would no longer be open source, a loophole that they introduced with this very intention from the start... Elastic has spit in the face of every single one of 1,573 contributors, and everyone who gave Elastic their trust, loyalty, and patronage."
[14]
Now, here we are with Sentry, and it's the same story with a different license. In all fairness, Sentry has been using a source-available license for a long time. Before the company created and adopted FSL, it had used BSL since 2018. If anyone was still donating code to Sentry, they had to know exactly what they were getting into.
So why make a new license? Sentry head of open source, Chad Whitacre, explained: "BSL has two major flaws. First, the default non-compete time period is four years, which is a really long time in the software world. This can make it feel like the eventual change to Open Source is only a token effort. It almost might as well be 100 years. For Sentry, we chose to tighten it to three years, but even that is probably too long."
[15]Come on, Amazon: If you're going to copy open source code for a new product, at least credit the creator
[16]Fed up with cloud giants ripping off its database, MongoDB forks new 'open source license'
[17]HashiCorp CEO talks license changes and the role of foundations
[18]The battle between open source and 'sort of' open source is as old as software
After that period, the code refers to either the Apache 2.0 or MIT license. But, that's not as generous as it sounds. Under the FSL, you can use its code for "any purpose other than a Competing Use. A Competing Use means use of the Software in or for a commercial product or service that competes with the Software or any other product or service we offer using the Software as of the date we make the Software available."
In other words, you can look but not run the code for a business. For more, you can look at the company FSLed versions of Apache and MIT. As far as I'm concerned, neither is an open source license.
Whitacre added, "The more serious flaw is that BSL has too many parameters: the change date, the change license, and the Additional Use Grant. The Additional Use Grant is the biggest problem. It is a giant fill-in-the-blank that effectively means that every BSL is a different license."
I can't argue with that. Each company's BSL is unique. This also means it makes it hard for customers to know exactly what they're getting legally when they contract with a company using BSL. It's Sentry's hope that the FSL will make its products and services more appealing to its customers.
Maybe it will. But I agree with Carrez, who said: "Releasing yet another license variant that removes developers' self-sovereignty in their technical choices is nothing novel: it is still about removing essential freedoms from the whole software ecosystem to clearly assert ownership over their proprietary software and the use you are allowed to make of it. This is not open source: it is proprietary gatekeeping wrapped in open washed clothing."
Get our [19]Tech Resources
[1] https://www.theregister.com/2023/11/20/sentry_introduces_the_functional_source/
[2] https://www.mongodb.com/licensing/server-side-public-license
[3] https://commonsclause.com/
[4] https://mariadb.com/bsl11/
[5] https://fsl.software/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZWDWtRAMZSvGqjDKBOHZywAAAIM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWDWtRAMZSvGqjDKBOHZywAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWDWtRAMZSvGqjDKBOHZywAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWDWtRAMZSvGqjDKBOHZywAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/05/16/mariadb_growing_pains/
[11] https://www.theregister.com/2019/02/22/redis_labs_changes_license_funding_60m/
[12] https://www.theregister.com/2023/08/11/hashicorp_bsl_licence/
[13] https://www.theregister.com/2021/01/18/elastics_doubling_down_on_open/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWDWtRAMZSvGqjDKBOHZywAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://www.theregister.com/2020/10/16/aws_headless_recorder/
[16] https://www.theregister.com/2018/10/16/mongodb_licensning_change/
[17] https://www.theregister.com/2023/10/19/hashicorp_ceo_license_changes/
[18] https://www.theregister.com/2023/10/27/open_source_vs_sort_of_open_source/
[19] https://whitepapers.theregister.com/
"proprietary gatekeeping wrapped in open washed clothing"
You remember Microsoft's Monkey Boy ? Ballmer. The one who said Open Source was a cancer.
He's metatstased. This is the result.
The only thing is, it's not important. The only ones who will subscribe to this are companies who had no intention of actually respecting Open Source, but are keen on paying lip service to it. For the creds. Before fucking it all over.
Nobody paying attention will run along with this. This is just Big Capital pulling the wool over the unwary.
Unfortunately, there's one born every minute, eh ?
Re: "proprietary gatekeeping wrapped in open washed clothing"
I posted my first "open source" code back to the early days when I was installing ZCPR on S-100 systems and saw the first ZCPR keyboard buffer fail if terminal (I was using a VT-100) was using control-S ... I just fixed if and gave it away. We didn't call it "open source" in the early days, we were just helping other programmers.
Monies
All this overlooks the fact that companies are making millions and billions on the back of unpaid gullible developers who believe in "open source".
It's all great if developer comes from privileged background or still lives in parents' basement living spoon to mouth lifestyle.
But then the reality comes crashing down when they learn the bank won't accept their GitHub stars as a deposit for a flat nor the company that is building yet another space rocket, won't hire them, because why would they if they already got what they wanted for free.
If Only
What the world needs is a license that allows you to do anything with this freely donated code except make it not be free any more.
Oh.
Re: If Only
Yep, but apparently that is seen as "restrictive" by some . . .
Financialisation versus origination
Idea creation and idea exploitation sit uneasily together.
Simple open-source licences are merely reminders that persons using the code - partially, wholly, or derived from - have no proprietorial claims over it, and that it is good manners to acknowledge the source(s) of code until such time as the code is so widely known as to be considered common programming knowledge.
Further complicating the licence stipulation pushes it into the realm of carpetbagging financial concerns, potential litigation, impracticability of 'rights' enforcement, and ambiguities among jurisdictions. As it is being found in different areas where people seek to make ideas (and their expression or application) proprietary, there is increasing pushback from a broadening body of other people demanding that 'content' be shared, and its production financed by patronage instead of a ramshackle body of 'rights' understood solely by specialised lawyers who never once have created anything of value to humanity.
Isn't there an obvious flaw?
" Elastic has spit in the face of every single one of 1,573 contributors, and everyone who gave Elastic their trust, loyalty, and patronage. "
Couldn't somebody take the source just before the licence change when the open licence applied, fork it, and effectively cut Elastic and their nonsense out of the loop?
Re: Isn't there an obvious flaw?
They'd have to know in advance that this was going to happen. This is not likely to be advertised in advance.
Re: Isn't there an obvious flaw?
Not really, that's why we have Git et al.
Who remembers "Shared Source" by Microsoft?