We released Sourcegraph under the Fair Source License (https://fair.io/), which we worked with a well-known open-source lawyer to draft.
TLDR is that it lets us create the best product for developers by having a sustainable business.
Full info at https://fair.io:
> Fair Source allows companies to both share a product’s source code and charge for that product. Releasing a product’s source code makes it more valuable to customers by enhancing extensibility and building trust. With open source, releasing the full source code and charging for the product is virtually impossible. Fair Source makes doing both possible.
https://www.schneier.com/blog/archives/2014/05/friday_squid_...
Elaborated briefly on my goal here with an old example:
https://news.ycombinator.com/item?id=10501615
Your license appears to meet many of those requirements. Curious about several things, though, that I figure you could give some straight, English answers to. ;)
How did you come to letting it depend on a user count rather than some other criteria? That's unusual and even reminds me of commercial licenses.
Does the license create a specific amount at that point or allow extortion where locked-in clients are hit with large amounts later?
Is the author able to terminate the project in a way where users are left with a dependency they no longer have access to?
I know you accept modifications under a CLA or something. Let's say, though, you didn't want to distribute some substantial changes. Basically, a fork is in order. How does that work? Do they just assign the whole fork to you where you can optionally offer it to others? Do they keep it onsite? Does it not happen at all? Prior discussions taught me forking is something that should have definitive answers in new OSS licenses.
The ability to make things disappear, get overpriced, or turn to shit arbitrarily are among the largest risks in proprietary OSS projects. So, interested in seeing your company's take on those.
Is there a separate link or some dividing line to the Core source? Or how does one build or access just the core features to abide by the licensing terms if you're a team larger than 15 and want to evaluate Core Sourcegraph?
Sourcegraph Enterprise includes the additional features mentioned in the pricing section on https://sourcegraph.com that are specific to very large companies.
Sorry about the confusion. Anything we can do to make that clearer?
Inside https://src.sourcegraph.com/sourcegraph@master/.tree/LICENSE it has a line that says:
"Use Limitation: 15 users"The LICENSE file starts:
Fair Source License, version 0.9
Copyright (c) 2015 Sourcegraph Inc.
Licensor: Sourcegraph Inc.
Software: Sourcegraph Core
Use Limitation: 15 users
...
But I think "Sourcegraph Core" is described as teams of any size on the website.
The difference being, of course, that one would redistribute the original code under the FSL and so the work as a whole would remain licensed under it.
Strange how much negativity proprietary OSS gets on HN vs cool, proprietary, closed tech.
"Proprietary OSS" is an oxymoron, like "four-sided triangle".
I think you miss that the biggest and most important benefits of open source are tied to the freedom to fork, which is both the source of the greatest security against divergence in interest between the original copyright holder and the user community and the enabler of community-driven innovation.
Put simply, shared-source does not have "OSS-like benefits".
> If they were reacting to that, then it still stands if they don't do similar for cool, closed-source stuff here.
Unlike shared-source stuff like the Fair Source License here, simple closed-source proprietary software generally doesn't try to pretend to be Open Source-like (and, when it does, it is attacked in the same way.)
I agree that's a major benefit. It's why a form of it is on my list. :P
A non-profit maintaining a shared-source software requiring a mere $1 a year wherever it was used would have enough for a full-time developer plus the website by time it hit 20-20k users whether in original or forked form. Plus could take contributions from others while giving them credit and/or a pass on the money. Whereas many OSS projects get used all over the place with about nothing in return and depend on goodwill of occasional volunteers or sponsored developers. So, there's definitely a benefit here with similar innovation, even community driven if a membership fee model.
"Unlike shared-source stuff like the Fair Source License here, simple closed-source proprietary software generally doesn't try to pretend to be Open Source-like (and, when it does, it is attacked in the same way.)"
Nah, shared-source stuff gets attacked more than proprietary or even shoddy OSS when it shows up. I was happy to see some exceptions considering the license a nice evolution in OSS direction from a proprietary angle or just better than most proprietary licenses.
It's made by them as well. It most certainly is not libre/free software. I'm guessing it has minimal legal ability to stand up in court. It is a bastardization of what open source is about... really it's more of a disclosed source setup.
I might go even further, and suggest that if one had to parcel the value created by open source software into two buckets, the one being value created by reason of transparent source code, and the other being value created by reason of no-cost source, the majority of the marginal value creation will have been because of the former, not the latter.
A glance at fair.io shows an interesting attempt to provide OSS under a proprietary model. Many businesses are fine with whatever gets the job done with main benefits of OSS being reviewing, extending, or just fixing things. A proprietary license allowing that has real value.
Curious, do you write comments like this whenever Google, Amazon, deep learning, etc closed-source tech with benefits are mentioned on HN? How they're insanity and not worth further discussion because the whole stack isn't FOSS?
from https://fair.io/:
> We invite the entire coding community to adopt our simple, standardized, proprietary license.
> No. Unlike open source, Fair Source has a Use Limitation built into the license
I contend that open-source has always been a mix of philosophies which originally included commercial variants. The reason those disappeared probably had a lot to due with the greed of the dominant companies in IT. More utilitarian owners or charters might have had different results. However, there's still companies doing proprietary w/ source code and dual-licensing of proprietary + OSS.
This is all wrong. One: Stallman only advocates Free Software, not Open Source, and not "Free and open source". Open Source Software and Free Software are defined very similar in substance (by the OSI and FSF, respectively), what differs most substantially between the respective organization is the philosophy of why they think those definitions are desirable, not the substance of the definition. Virtually all licenses that have been considered by both the FSF and OSI have either been recognized as meeting both definitions, or have been found to be outside of both; there's almost no inconsistency.
"Free and open source software" is a collective term for the common category of software described by the FSF and OSI definitions, typically used by people who are not interested in (when using it) diverting things into a philosophical debate over preferred terminology between "Free Software" and "Open Source".
The license type sometimes described as "viral" espoused by the Stallman and the FSF is copyleft license, which is a kind of Free Software (and/or Open Source) license which has clauses to assure derivative works are licensed under a similar license; the GPL and AGPL are well-known copyleft licenses.
https://news.ycombinator.com/item?id=10623006
Any suggestion for what to call (a) software with source included in general that doesn't meet OSI & FSF definitions or (b) paid software w/ key benefits of OSI?
"Source disclosed" or "Shared source".
> paid software w/ key benefits of OSI?
Since Open Source (and, for that matter, Free -- which means libre, but not necessarily gratis) software can be paid, if paid software actually has the "key benefits" of Open Source, it is probably because it is Open Source.
It's a start.
"if paid software actually has the "key benefits" of Open Source, it is probably because it is Open Source."
You got me thinking on it enough to consult the opensource.org requirements. :) Two jumped out at me immediately:
" Free Redistribution"
"License Must Not Be Specific to a Product"
Many forms of paid software with open-source benefits don't allow this or not for all parties. A license might have to be paid on a per-user, per-product, or per-project basis. Other benefits of OSS can remain. So, it's not traditional definition of OSS but still respects freedoms of paying users to various degrees.
I think most people who believe that open source has benefits would disagree that there is software that provides "open-source benefits" without providing this. What specific examples can you point to of these "many forms" of paid software, and what "open-source benefits" do they provide without these?
To get more specific, you can read the source, you can modify it to suit your needs, you can submit modifications for redistribution by owner, you can fix problems, port to new hardware, often include it in your proprietary software, optional component of OSS software, and optionally fork it as GPL. (optional used to denote some paid, source-shared don't do this) That's really close to OSS software while still being proprietary to support active development and maintenance by full-time people. The dollar amount w/ associated benefits can be as large or small as one likes, even fixed. Provisions can be made for it to go BSD etc if abandoned or unsupported by original owner.
I'm just curious how far a proprietary model can go into increased OSS-style benefits and reduced proprietary-style risks. I'm sure it's way closer than people think with the dual-licensed stuff being most obvious indicators that hybrid models w/ licensing revenue are achievable.
Uh.. I actually often do. I would more, but it generally isn't appreciated and is off topic of the main thread. Here, the software license is a key component of the release seeing as it is a unique component of it.
>Open source is about the source being open plus certain benefits.
It's more than that. The key intent of OSS is the right to study, change, and distribute the software to anyone and for any purpose. The source code is just a prereq for that ability.
I did initially use stallman-esque language, since it's terminology most people are familiar with in this field, but I'll approach it from a different point since I personally have problems with strong copy-left licenses.
The primary thing this license doesn't do is allow distribution in the OSS spirit. This is really just a pervasive license, actually in some ways similar to the Stallman-esque virality except with a corporate intent. It simply masquerades as OSS.
No, the key intent of open-sourcing software is to let one see the source. That's it. Additional intents are added with licensing terms. This goes back to academic and even proprietary (eg Burrough's 1960's MCP) examples that did this. Many models of it formed with examples ranging from permissive BSD to proprietary OSS like LISP machines (esp Genera) letting customers use the source of OS & supporting libs in applications.
So, OSS is a broader thing than you are describing which supports many models. There is no "spirit" so much as many different ideologies competing and pushing their own licensing schemes with various perceived benefits. Now there's one more.
So, your rendering of open-source history is false both in academia and commercial sector. It's always been a mix with proprietary favoring closed source due to financial incentives, especially lock-in. Nothing precluded more paid OSS strategies aside from culture of organizations involved. As dual-licensed projects and proprietary w/ OSS benefits like this one show.
I'd be up for considering a new term to avoid confusion. Paid, non-profit or for-profit, models allow for most benefits of OSS if structured correctly. So, the new phrase must allow for that. I've been calling it "proprietary OSS" or "paid OSS."
You can't just change the meaning of the term and expect everyone to know you mean this alternate definition. "Open Source" is as defined by the OSI, and not whatever loose definition that you use that includes proprietary software.
>I've been calling it "proprietary OSS" or "paid OSS."
"Proprietary OSS" does not make sense given the definition of OSS! The phrase you should be using is "proprietary software."
I've already agreed with you and dragonwriter on that. dragonwriter suggested "shared source" as a start. Might go with that temporarily.
""Proprietary OSS" does not make sense given the definition of OSS! The phrase you should be using is "proprietary software.""
Starting now. Proprietary, shared-source software would make sense and can have most benefits of OSS. Just calling it proprietary software, though, instantly conveys the image of something closed source, for money, not allowing modifications, and with tons of risk. So, I can't just call an OSS-like, but paid, model proprietary due to public perception much like I apparently can't use "proprietary OSS" for same reason.
Hence, need for new terms. Especially one that captures the spirit of OSS with change that distribution/use is paid to some degree in some way, either money or code/doc contributions. Will re-write my old essay, though, as you two got to the bottom of one of its problems.
This illustrates yet another confusion about FOSS. There's nothing in either the Free Software or Open Source definitions that says that a fee cannot be charged for software. You can charge money for free software!
The payment has to be mandatory, done with licensing, and increase with use somehow to maintain few advantages of proprietary software. Open to any models that can leave off one or more of these with consistent effectiveness as my goal is exploration.
Copyleft is not a virus. I'm pretty damn tired of this meme.
The image fits the behavior of the code, though. Hence the meme. More accurate description is like an agreement many parties participate in with copyright used to seal the deal for current and future distributions. So, control-freaks enforcing ideology on improvements to what they create rather than virus. ;)
No, it doesn't.
> This is true even of distributing a large amount of non-free code while someone in organization unknowingly included a tiny amount of copyleft code.
If a single work is distributed that is based on copyleft code (not a mere aggregation that includes copyleft code and other code), then not licensing the resulting work as specified in the copyleft license is a violation of the license of the copyleft code. But the license doesn't attach on its own to the work.
To be clear, your saying that my worry was inaccurate and one person including GPL code into a new, released version of a proprietary app doesn't require the whole, linked source of that app be released under GPL? That happening is very virus-like but if it can't then it wouldn't be virus-like.
If the inclusion suffices to make the app as a whole a derivative work under copyright law (the FSF has a particular opinion on linking, but that opinion is not included in the license), then it would require you to offer the app under the GPL, failure to do so would be a violation of the GPL.
There is nothing "virus-like" here. The license doesn't attach without your knowledge. You may face consequences for the breach if you don't comply with the GPL terms, and releasing the whole work under the GPL may be the most convenient way of dealing with that -- then again, it may not.
It does if one person on a large team did it without others' knowledge. This doesn't occur for most, non-copyleft code. At that point, if it's a derivative work, then your codebase looses its value as it gets GPL'd just because GPL'd code touched it. Preventing that outcome would require both preventative methods and constant vigilance.
Kind of like avoiding getting sick from a virus and spreading it everywhere.
Note: A former Microsoft employee told me in a prior discussion they identified this exact risk and took steps to prevent it. I never knew if it was paranoia or what could legally happen. Interesting to find last year that my hypothetical scenario actually played out to a degree in FOSS's arch-rival of that period.
> It does if one person on a large team did it without others' knowledge.
No, the license never attaches to your code without a positive decision on your part to offer your code under the license.
Now, if someone does something that makes the code legally a derivative work of GPL code without knowledge of the person releasing the code, the obligation to release the code under the GPL or not at all may be created and breached without knowledge of the person doing the release, but the license still has not attached to your code.
When the breach is detected, you may decide that the best way to deal with the breach is to offer the code under the GPL.
> This doesn't occur for most, non-copyleft code.
Any code, under any license with any obligations attached to redistribution of derivative works -- or which simply prohibits redistributing such works -- can create unexpected breaches when someone includes them in a work without knowledge of the person responsible for the release; copyleft licenses are not at all special in this regard.
> At that point, if it's a derivative work, then your codebase looses its value as it gets GPL'd just because GPL'd code touched it.
No, again, your code base only becomes GPL because you choose to offer it under the GPL. IIRC, the few GPL violation cases (in the US, at least) that have gone to court and not been settled have resulted in fines and injunctions on distributing the GPL-dependent software.
> Note: A former Microsoft employee told me in a prior discussion they identified this exact risk and took steps to prevent it. I never knew if it was paranoia or what could legally happen. Interesting to find last year that my hypothetical scenario actually played out to a degree in FOSS's arch-rival of that period.
The description of the GPL as "viral" was central to Microsoft's PR effort against Free Software in general and Linux in particular.
So, its not really surprising to hear that from that source.
This is the specific concern. The name of the license isn't what people call a virus: it's the obligation it attaches to things.
"copyleft licenses are not at all special in this regard."
Damage to most copyright violations is usually a fine/settlement, publishing source of the component (not app), removal, and so on. Not an obligation to loose one's own I.P. entirely. How many common licenses that cut/pasted code or included libraries might be affected by require redistribution of the application's source in full once it gets in a release? I thought it was a non-zero amount that was pretty low for most sources. Whereas, bumbling around on a site with GPL stuff drives it up singificantly specifically due to copyleft.
" the few GPL violation cases (in the US, at least) that have gone to court and not been settled have resulted in fines and injunctions on distributing the GPL-dependent software."
Now we're talking the actual results. The virus metaphor could be dropped if it was clear that this was the worst thing that could happen and that component would just have to be dropped/replaced with non-GPL stuff. Them doing it that way is certainly reassuring. Trick is, could they instead force app using it to go GPL? Guess it hinges on enforceability of that obligation.
"The description of the GPL as "viral" was central to Microsoft's PR effort against Free Software in general and Linux in particular. So, its not really surprising to hear that from that source."
From an ex-employee mocking that source's stance on GPL as paranoid, to be clear. Not surprising, though.
Legal damage from GPL violations is generally fine and injunction against further release of the software with the GPL-bound components; release of application code under the GPL is typically something that happens, if at all, in a settlement, because the copyright owner would rather do that than pay damages and restructure the software not to depend on the GPL-bound component.
Makes me a bit sad in the wake of MS liberating a lot of stuff lately, like Visual Studio.
Of course not many other companies have the benefit of collecting an OS tax on hardware - I still think I'd prefer eg the AGPL to this.
"GNU OSS" is not a thing. GNU is a project of the Free Software Foundation (FSF), which publishes (and applies) the Free Software Definition.
The Open Source Definition is created (and applied) by the Open Source Initiative (OSI). "GNU OSS" is kind of like "Catholic Protestantism".