Live data from Hacker News

HashiCorp adopts Business Source License

hashicorp.com

741–750 of 760 posts

Re: HashiCorp adopts Business Source License

#741
post #664

Earlier quoted context omitted.

But it's not just visible... you can submit a PR if you like, and people do.

That's true. I think the taxonomy I'd really endorse is that the dichotomy is between free software and proprietary software, and within each there are a range of restrictions/guarantees (depending on your PoV: user or developer) that licenses might have. The broad distinction we care about within free software is copyleft vs. permissive, and one important one in proprietary software is source-available vs. closed-so…

> The broad distinction we care about within free software is copyleft vs. permissive

You are exactly correct about this.

1. Open-Source is a "Marketing Program for Free-Software". You describe yourself as having the "free-software" world view (which I describe as an anti-developer property worldview).

See: You can find OSI describe itself as a "Marketing Program for Free-Software" in their original FAQ: https://web.archive.org/web/20010406183942/http://opensource...

> The terms get harder because open/closed suggests straightforward opposites that partition all the options.

2. Again, you are exactly correct. By erroneously choosing term that is generic, that was already in use, and that can't be trademarked, the OSI set itself up for a loosing battle as "the universal standard" for what is not "closed-source".

GENERIC/DESCRIPTIVE: "We have discovered that there is virtually no chance that the U.S. Patent and Trademark Office would register the mark “open source”; the mark is too descriptive. Ironically, we were partly a victim of our own success in bringing the “open source” concept into the mainstream. So “Open Source” is not and cannot become a trademark.

https://opensource.org/pressreleases/certified-open-source.p...

ALREADY IN USE: There are many documented uses of "open source" in relation to software that is not closed-source, going all the way back to 1985. https://www.arp242.net/open-source.html#pre-1998-usage

> But I'd characterize licenses like BSL and the Fair Source License as 'generous proprietary licenses with public source availability', but not open-source.

As a person with a self-defined affiliation with free-software, it makes complete sense that you would see it this way, but how many people outside of the free-software group see that? The further someone is from self-affiliation with "free-software" surely the less likely they are to agree with this terminology.

> I have a feeling that the term 'open-source' is more likely to erode than 'free software', in the coming decades. We'll see, I guess.

I 100% agree with you. The OSI postulates a union between the interests of people who release software into the public domain, and the interests of people like yourself who believe in Free-Software.

In my view, there is nothing uniting these two groups and the fracture is 100% inevitable. Even if your preferred term `source-available` were to gain widespread acceptance/use, there is no reason for independent developers to subsidize big business by making their source free to use for those big businesses, unless the developers ideologically agree with the tenants of the free-software movement. However, if the developers agreed with the free-software movement, they would choose a GPL style license, not a MIT/BSD/Apache style public domain license.

Re: HashiCorp adopts Business Source License

#742

It is important to understand that there are two kinds of open-source software: - Software made by startups that are precious to HN. In this case, building a business on top of them is "freeloading" and it's deeply immoral. Examples: Elastic, HashiCorp, Mongo - "Public good software", there's nothing wrong with profiting from it, in fact, it's encouraged. Examples: Linux, Postgres, Nginx, Apache

I think you make a solid distinction between two very different types of software, though I'm not sure I agree with your examples, specifically. If Linux didn't have the wide-spread usage and network of distributions that it currently does, there would be very little difference between it and Elastic, HC or Mongo. When it was originally gaining popularity, the general feeling of the technology world was that it was crazy to give away an operating system.

The "Public good software" you refer to is much better represented by things like Capital One's Cloud Custodian, or the massive number of software libraries in NPM, PYPI, and all over GitHub.

> Software made by startups that are precious to HN. In this case, building a business on top of them is "freeloading" and it's deeply immoral. Examples: Elastic, HashiCorp, Mongo

I don't believe it's nearly as cut and dry as this post claims. The companies who are "freeloading" are usually undertaking massive efforts to be able to run the software in a very different environment than it was originally designed for. Building a hosting solution like AWS, with the high availability solutions they offer, is an incredibly complex problem, and they're adding significant value on top of the original software. Without solutions like DocumentDB and OpenSearch, many companies would not be able to build the solutions that they have built with AWS. Additionally, if we take this stance, are these companies not "freeloading" on the open source contributors' efforts?

One could argue that cloud providers' contributions to upstream could be more significant, but how much of what AWS has developed would be useful to anyone who isn't running at their scale, and using the same solutions for the physical layer?

I see two real problems, here:

    * A lack of foresight on the part of the companies who originally built their businesses based on software with overly permissive license (Elastic is probably a good example, as they decided to pivot to SaaS _after_ they built a company on the premise of open source software). If they wanted to control other peoples' use of the software to the extend that they are complaining about now, they should not have chosen MIT/MPL/BSD/Apache licenses.

    * Changes in leadership which result in a major change in business model which is no-longer in line with the original goals of the companies (I believe HC probably falls in with this bunch). In this case, the new leadership has effectively "bought" something without doing their due diligence. They thought they had all of the keys to the kingdom, but they didn't understand that what they were buying.
In either case, it's not the fault of those who saw an opportunity to build on the work of others. The moral of the story is: don't give away your core intellectual property if your business model depends on monetizing it.

Re: HashiCorp adopts Business Source License

#743

Earlier quoted context omitted.

It's source available. Which is not the same thing as open source.

I don't think anyone is arguing that BSL is capital O Open Source, and even the BSL licence stressses that it is not an Open Source licence. But both "closed source" and "source available" feel like poor descriptors for a project that is developed in the open and takes PRs from outside contributors.

For this case there's already an old good word "proprietary" that covers everything that's not FOSS.

Re: HashiCorp adopts Business Source License

#744
post #342

Earlier quoted context omitted.

>like the AGPL? As I explained in an earlier thread, MongoDB tried using AGPL. AGPL is not a barrier for Amazon, they still will resell your product without contributing. MongoDB ended up using a variant of AGPL that is even stricter (requiring the entire tech stack to be under the same license) but is no longer considered FOSS. Until the attitude changes around what FOSS is, this will keep happening.

AGPL is not a barrier for Amazon, they still will resell your product without contributing. I don't think this is true.

If Amazon don't have a need to change anything in software, they'll just provide it as service without any problems. AGPL permits this.

If they have to change something, then they would likely want want to return hose changes in upstream to lower maintenance burden. Or just publish changes on github of upstream doesn't want to accept them. AGPL is fine with this too.

If Amazon would like create similar offering but with some secret sauce that they don't want to share, then they'll develop in-house solution from scratch and sell it as a service in AWS.

Re: HashiCorp adopts Business Source License

#745

Earlier quoted context omitted.

By any chance are you familiar with Little Free Library ( https://littlefreelibrary.org/ ), those public boxes for people to take or leave books? How would you feel if someone took ALL the books, repeatedly, and then sold them? Would you just shrug and say "well that's totally fine, why is it free in the first place?" This behavior is antisocial, and completely destroys the offering/concept for everyone. I have a boo…

Yes, you chose the wrong license without understanding its implications. > My sense is that adopting AGPL for a brand new product typically causes the product to be dead on arrival. It may hinder adoption (in the corporate world) but not contribution to the source. And if you want to promote the spirit of opensource and make money too, dual licensing with xGPL is the best way to go. MySQL is a successful example of t…

It's pretty telling that you listed only a single example product, and one which was first released twenty-eight years ago, and also one which raised venture capital.

Just because dual-licensing has been successful in a very limited number of exceptional situations, does not mean that it is a reproducible path towards building a sustainable software business.

Also keep in mind:

* MySQL hasn't been an independent business for over 15 years. AFAIK there is no public information on its revenue or profitability.

* Much of Oracle's recent work on the product has been on MySQL Heatwave, which is only available as a managed service.

* Most MySQL Community Edition commits come from Oracle.

* Meanwhile the company behind MariaDB, arguably a more "open" fork of MySQL, is having financial problems and may well end up having its stock de-listed soon.

* The non-open-source Business Source License was originally created by MariaDB for their MaxScale product. The license's existence is fully backed by Monty Widenius, original creator of MySQL.

To be clear, I'm not saying any of the above to criticize Oracle or MariaDB. Rather, just pointing out that a general statement of "dual licensing with xGPL is the best way to go" is not really backed by the facts on the ground.

I must ask, do you run a commercial open source business yourself?

Re: HashiCorp adopts Business Source License

#746

Earlier quoted context omitted.

> Just because nobody has tried yet doesn’t mean that it won’t ever happen. That nobody has tried suggests paranoia at best. > Companies are doing this precisely because companies like Amazon abuse FOSS licenses to stand up their own hosted versions of open source projects. The AGPL exists and already fully addresses that.

I'm thinking that AGPL is, indeed, the Ebola of viral licenses, but it does not cover the case where a large cloud vendor simply takes an AGPL-licensed product and offers it as a cloud service. AGPL does not cover that case. Nothing the cloud vendor does challenges any of the AGPL's terms. The cloud vendor issue is license agnostic. ElasticSearch comes to mind. For the AGPL side, MongoDB and Neo4J come to mind. Recal…

SSPL is much worse than AGPL. At worst AGPL demands you to license your own code under same terms. While SSPL demands you to license third-party code from backup solutions to operating system and firmware. Good luck publishing source code of Linux kernel or even Windows under SSPL.

Re: HashiCorp adopts Business Source License

#747
post #193

Earlier quoted context omitted.

I'm thinking that AGPL is, indeed, the Ebola of viral licenses, but it does not cover the case where a large cloud vendor simply takes an AGPL-licensed product and offers it as a cloud service. AGPL does not cover that case. Nothing the cloud vendor does challenges any of the AGPL's terms. The cloud vendor issue is license agnostic. ElasticSearch comes to mind. For the AGPL side, MongoDB and Neo4J come to mind. Recal…

Cloud providers build a proprietary control plane to deploy copies of the program and it could be argued that such code is a modification of the program itself and thus has to be released. That's why they won't touch AGPL code.

AGPL doesn't infect you code unless you don't link with AGPL-licensed one. Control planes rarely do this. That's why Amazon was absolutely OK with MongoDB being under AGPL.

Re: HashiCorp adopts Business Source License

#748
post #165
post #160

> Why is HashiCorp making this change? > > We strongly believe in the value of openly sharing source code and enabling practitioners to solve their problems, building communities, and creating transparency. HashiCorp provides feature-rich products to the community for free, and that development is made possible by our commercial customers who partner with us. By shifting to this license, HashiCorp can better manage c…

Why, quite clearly: > Organizations providing competitive offerings to HashiCorp will no longer be permitted to use the community edition products free of charge under our BSL license. Commercial licensing terms are available and can enable use cases beyond the BSL limitations. Looks to me very similar to (A)GPL + commercial dual licensing, for instance.

GPL permits this: "Organizations providing competitive offerings to HashiCorp will no longer be permitted to use the community edition products free of charge"

Re: HashiCorp adopts Business Source License

#749
Somebody should point out to them that there's an error in their Parameters:

https://www.hashicorp.com/bsl

The "Licensed Work" parameter should refer to what they are licensing. Right now it reads "The Licensed Work is (c) 2023 HashiCorp, Inc."

I don't see how a corporation itself is copyrightable content to which a license may be granted.

Post reply on HN