Relicensing React, Jest, Flow, and Immutable.js
code.facebook.com
code.facebook.com
I get that there's legal uncertainty: I can imagine some companies, especially larger ones, not wanting to give up their patent-suit option just because one random small team in their org is using React. And barriers to adoption aren't a great idea when one of your goals is wide adoption.
Overall, though, I think making it much harder to file patent suits -- at least for software patents -- is a great thing. Facebook's (and others') implementation of it might have left something to be desired, and they're certainly a large company with a lot of resources behind them, so the power dynamic might be a bit lopsided, but...
Well, let's just say I'm a small company or individual who wants to release some open source code. Doing so under a BSD+Patents-style license gives me some protection from any big players who decide to use my software. How is this a bad thing?
I suppose I hold a pretty strong anti-patents stance, though. I'd be happy if (most?) patent protection just went away entirely.
As an aside, note that it looks like FB is going with straight MIT. So they're not even giving users of their software a patent grant at all anymore[1], and reserve the right to sue you later just for using their software, if they happen to have a patent on something in it.
[1] Yes, there are some legal opinions that the MIT license's language includes an implicit patent grant, but I don't believe that's a settled matter.
Using a license that's been in use for a long time, and has the endorsement of major OSS organizations, is pretty much always more comfortable for developers.
I wasn't uncomfortable enough with their licenses to rule out their projects based on the license, but I understand the folks who were. Even if my reading of the license makes me unafraid of it, there was enough uncertainty about how a court, particularly courts that have a history of siding with patent trolls, might interpret the license, for it to make some people nervous.
Also, the belief that the copyrights and patents involved will always belong to a benevolent actor ignores a lot of tech history. See: SCO, Oracle, etc. for examples of a previously decent stakeholder being consumed by a more malevolent and litigious one with a different interpretation of the law and the license. facebook may be a huge, unassailable, force today...can we be certain that in ten years that'll still be true? I'd bet on it, but I also won't be shocked if something dramatic happens. Sun looked pretty unassailable through the 80s and 90s, and then they didn't.
Big companies building big projects have to think about these things if they want to be responsible about the future of their projects. (Again, I agree that in this case, the fear is probably overblown. But, I get where it's coming from.)
As an aside, I realized I read FB's license wrong -- it actually is even better for users of it, and specifically says that the patent termination clause only goes into effect if the user is the aggressor. If FB comes after you for a patent claim, you can counter-sue all you want without losing your license. So FB is actually doing the absolutely correct thing here.
If the license is not one of the standard ones already in use, and it mentions patents, suddenly legal gets involved and it's a disaster. They're very risk-adverse and no one's really sure what will happen when it gets to court. It doesn't have to make sense - after all, most software patents don't make sense, and most software patent lawsuits don't make sense.
Copyright makes some sense - some entity wrote the code and has (or has not) given explicit permission for others to use it, and under common open-source licenses those terms are reasonably well understood. But patents can come out of left-field and be unrelated to the user or the producer of the code. Being aware of patents (which should not cover what you're doing or should not exist) makes punitive damages worse. Again, best to just put your head in the sand and hope the patents don't notice you. Any language about patents adds complications which no one wants to figure out.
But I read in other comments that some some lawyers think MIT implies a patent grant, which could explain why they switched from BSD to MIT.
Ahh, I see. But I think if they were just using BSD instead of BSD+Patents no one would have had any issue with it.
Example: There is a patent in the US on ordering food from a menu online. It's held by a NPE (aka, a patent troll), and they charge a fairly high license fee. Some people who offer online ordering to restaurants pay the license fee; others don't. If you don't pay, then you can afford to charge lower prices than your competitors. If you do pay, then it's in your interests to tell everyone you meet about the patent, because every person you tell is someone who now faces triple damages if they opt to use on your your non-paying competitors.
Let me say that again, because it's so crazy: Some companies actually advertise their high prices, because a potential customer just reading their pricing page can thereafter no longer opt for a lower priced competitor without being subject to increased damages.
That's... sad.
> Being aware of patents ... makes punitive damages worse.
Sure, but that doesn't have anything to do with a BSD+Patents license. The license doesn't say "you also must do extensive patent research when using our software". You have to actually be aware of the patents that you're infringing to be held liable for extra damages.
Also, IANAL, so I may be entirely wrong.
I loved BSD+patent as one of the few potentially successful attacks on the awful software patents regime that we currently live under. This defeat means we are probably stuck with it for the rest of our careers.
BSD + Patents doesn't look like the way we'll get there. Is there a way we can get there without putting "power in the hands of the big players" in the interim?
Apache is an unethical foundation with shitty lawyers? I admire the goal of eradicating software patents, to me BSD+Patents was an unsuccessful way to do it. It hurt OSS projects more than it hurt private projects.
Facebook's patent clause disarms all their opponents, but leaves them free to attack. It's actually a wildly aggressive, offensive weapon, surprisingly - just like how nuclear missile defense is one of the more provocative technologies out there that possibly makes nuclear conflicts more probably.
That's why it's totally unpalatable, at least at the big companies.
"...if Facebook or any of its subsidiaries or corporate affiliates files a lawsuit alleging patent infringement against you in the first instance, and you respond by filing a patent infringement counterclaim in that lawsuit against that party that is unrelated to the Software, the license granted hereunder will not terminate under section (i) of this paragraph due to such counterclaim."
Moreover, nothing is preventing you from informing them of your patent and asking that they stop using it. If they continue to, it's clearly willful infringement.
Patent grant terminated, not license
But on second reading I realize I was wrong (in a good way). Facebook's patent grant specifically says that if they sue you for patent infringement, and you counter-sue with something that is unrelated to the software of FB's that you are using, then your license to use FB's software is NOT terminated. That's actually entirely reasonable and great.
Sure, not everyone is in that situation. Facebook is big enough though that if you have any patents you have to be _very_ careful about that license.
Oracle v. Google?
1. Software patents are a huge, huge, existential crisis facing our industry.
2. So huge, in fact, that nobody wants to deal with it. We can't realistically figure out if the libraries we are using are covered by patents, and given how broken issuance is, they probably are.
3. So the only practical solution is to use MIT licensed libraries, pretend there's no patent issue, and put our heads in the sand.
4. But Facebook's BSD+Patents license made us think about patents. Nobody stopped and said "can we use Angular? Are there patents on core elements of it?". But people did stop and ask that about React, because Facebook was (accidentally) making people think about patents, and the more you think about patents the more you wish you were a plumber and not a dev so all you'd have to deal with is toilets blocked with shit, and not software patents, which are much worse.
5. Now that it's under an MIT license it's just as dangerous to use React (maybe more) but we can pretend it's safe again.
Notice that Wordpress's decision to switch from React (which probably led to this) was quite clear: They were not switching due to patent concerns about React, they were switching because the non-standard license was stirring up FUD and making people ask them uncomfortable questions. (We know this because they explicitly said so, and also because the leading contender for a new library was Preact, which is strictly more dangerous from a patent point of view than React under every possible circumstance, but has a license that lets your pretend everything is okay easier.)
This.
It's the backlash that was led by people who considered it a realistic possibility that they may, some day, want to sue Facebook for infringing on one of their precious patents.
> With MIT nobody knows if you have those grants in the first place because there was never a court precedent. But not our hill to die on
Really? They are doing the minimum possible to prevent an exodus from their stack after a public outcry.
React would have been fine, but to say the big players jumping ship didn't matter is just wrong.
Projects that I work(ed) on that use React have no plans to switch away and aren't represented in that 25%.
25% of sites on the Internet run WordPress. WordPress was rewriting its editor in React, but decided to switch away due to BSD+Patents.
Those were the only two.
But it did matter.
It set a strong precedent.
Some 28.7% of sites use Wordpress.* Curiously, I've seen the 19% number being cited as 19% of all new websites use Wordpress. I'm not sure how 19% becomes 28.7%, but it may just be that sites using WP stick around longer.
* https://w3techs.com/technologies/details/cm-wordpress/all/al...
Even being on the back-foot when having to defend your patents, by refactoring React out of your application, was apparently damning enough for people to migrate.
If you're ok with trusting a direct competitor not to misbehave, then sure, use React under those terms while competing with FB. But large companies consider their patent portfolio to be a significant strategic asset, so it shouldn't be surprising that their legal counsel advises against accepting such a clause.
This Facebook post gives us hope for GraphQL moving away from BSD+, as it is currently in our stack, but without doubt we are considering a move away due to uncertainty.
FWIW, why we prefer Apache 2.0: https://www.cncf.io/blog/2017/02/01/cncf-recommends-aslv2/
Evidently FB saw enough people leaving to prompt this change. No doubt they were also afraid of an exodus of their internal developers on these projects. High-profile developers will move on to companies where they know they'll have greater impact if that's seen to be at risk.
Theorizing, but I suspect FB will begin targeting and picking off IP of apps built entirely on React stacks in a few years.
Please don't go back to them. Just contribute to Vue's ecosystem like crazy. Worst case scenario it'll keep FB in check.
Competing frameworks will now need a new "Reason #1 to use us instead" for their pitch-decks.
That said, this healthy Vue/Angular/React competition has been great for us devs.
In the case of fewer frameworks, you would still have these. Arguably more due to lack of competition.
> evaluating all the various alternatives
Pick one of the "Big 3" above. You'll be fine. Largely due to the previous point.
I think I'm going to dig in my heels this time. React is fine. It's more than fine, I absolutely love working with React, Redux, redux-saga, redux-observable, and a whole bunch of other libraries and patterns that I've finally begun to master after over a year of headaches and frustration. I'm not going to switch to Vue, not even for my next side project.
I didn't personally care about the BSD+Patents license, but you definitely have to keep your eyes and ears open with backlash like this. Even if I think it's a total issue, it might affect my ability to hire employees or even sell my company. So I'm really glad that React is now released under the MIT license.
Seems like an argument against the react ecosystem
It was the same as any other programming language, framework, or ecosystem. Exactly the same as my experience with Ruby on Rails when I first started doing web development.
The comment i made above, that most things going forward will happen in the react eco system, is supported by these statistics. If you have lots and lots of vue users that are still using script tags, and let us - without any data to confirm it - assume that there are less react users doing this, then that would speak volumes about the userbase at large, not the most forward leaning to say the least.
I almost guarantee you none of the devs wanted that weird-ass patent clause in there, but I'm guessing that none of them thought that it was a big deal in the long run, just CYA shit you'd expect from a legal department.
They were proven wrong, and it impacted their market share, they raised a stink about it and they got it changed.
What do you expect them to do, shrug and come back? I doubt anyone who left based on concerns with their stack being owned by Facebook is likely to regret weaning themselves off of it.
I count:
* ReasonML - https://github.com/facebook/reason/blob/master/PATENTS.txt
* GraphQL - https://github.com/graphql/graphql-js/blob/master/PATENTS
* react-native - https://github.com/facebook/react-native/blob/master/PATENTS
* PlanOut - https://github.com/facebook/planout/blob/master/PATENTS
* Flow - https://github.com/facebook/flow/blob/master/PATENTS
* Haxl - https://github.com/facebook/Haxl/blob/master/PATENTS
* Flux - https://github.com/facebook/flux/blob/master/PATENTS
Just a few that I found.. Please reply if you know more project that are still BSD+PATENTS licensed.
https://github.com/facebookincubator/gloo/blob/master/PATENT...
The complicating factor there is Facebook actually has a patent covering the GraphQL specification (along with the fact that they're applying PATENTS to a specification, vs an implementation): https://www.google.com/patents/US9646028
> As our business has become successful, we've become a larger target for meritless patent litigation. This type of litigation can be extremely costly in terms of both resources and attention. It would have been easy for us to stop contributing to open source, or to do what some other large companies do and only release software that isn't used in our most successful products, but we decided to take a different approach.
Never heard Facebook answer: why didn't they just follow Red Hat's model and make a "Patent Promise"[1]?
Then accumulation of software patents would help deter meritless litigation while staying out of the way of FLOSS developers getting their work done.
If I read this right, Red Hat promises to not sue anyone for using/transferring FOSS whether or not such an action infringes on Red Hat's patents - they will only use patents to defend against litigation. (IANAL.)
The "combined" part seems to be saying you can also develop a system that's partly proprietary, as long as the proprietary parts are simple and not using Red Hat's patents.
If they sell a patent, the buyer must agree to the same promise.
The promise won't protect you if you infringe someone else's IP, even if it's related to one of Red Hat's patents.
Isn't that exactly the same as Facebook's license grant?
if Facebook [...] files a lawsuit alleging patent infringement against you
in the first instance, and you respond by filing a patent infringement
counterclaim in that lawsuit against that party that is unrelated to the
Software, the license granted hereunder will not terminateFacebook: You can use our software if we can use your patents.
That's my severely over-simplified interpretation. The most significant difference is that Red Hat's promise extends to FOSS in general, though apparently not proprietary software. Facebook's license applies only to specific Facebook FOSS code, but it can be used in proprietary software.
>Our Promise also does not extend to the actions of a party (including past actions) if at any time the party or its affiliate asserts a patent in proceedings against Red Hat (or its affiliate) or any offering of Red Hat (or its affiliate) (including a cross-claim or counterclaim).
So RedHat can hypothetically use all of your software patents and still sue you for infringement based on their patents if you sue them.
RedHat won't sue you over your FOSS project that infringes any of RedHat patents, but your proprietary software is fair game.
Facebook won't sue you for infringement caused by using one of their libraries in your software (FOSS or not), but your independent project (FOSS or not) that infringes any Facebook patent is fair game.
Red Hat holds patents but promises not to enforce them. This means anyone can use the IP without worrying about being sued for infringement. No one else can claim they own the IP because Red Hat already owns it. They also have a clause saying that if Red Hat sells the IP, the buyer needs to uphold the same promise.
[1]: https://medium.com/@dwalsh.sdlr/react-facebook-and-the-revok...
The four freedoms and free software solve so many of the problems I see around modern tech-infrastructure. No, free software doesn't solve every issue and has some of it's own, for example I think at the code complexity levels we are at the many eyes theory is starting to crumble, but it doesn't change the core truisms about freedom in computing that are important for us to move forward in a free and open society if we actually want to start solving prolems.
Now that we have a concrete example of how picking tooling with bad licensing can bite people in the butt, please take this time to at least consider GPL varients (A/L/GPLv3) for as much of your tooling as you possibly can. (perhaps CC0/CCBY/CCBYSA for content)
In my opinion, MIT/BSD licenses like FB moved to in this case simply aren't good enough to be future-proof, primarily because of the ability of future tivoization of a product that removes freedom from the user (think BSD on playstation).
Remember, either the user controls the program, or the program controls the user.
If the GPL scares you for some reason or you have question about it (commercial sales of gpl software for example), feel free to ask. I've spent enough time wading through just about every license so I think I might be able to cut through some fud.
Heck, they couldn't even put it on the iOS App Store for free...
And even that could hurt their business if somebody used the core to build their own app for the same target market on top of it.
I pretty sure their "core" naming is just another way to promote usage of paid version, but you can still compile it yourself and easily remove all license checks.
Why would they do all these changes if the previous model worked well for making them money?
https://www.reddit.com/r/linux/comments/2fydpm/synergy_gpl_i...
Of course it's not shiny VC funded company with 10000% growth, but I guess it's profitable business. Though it's not that much different from what Red Hat doing by selling support even if it's on small scale.
IANAL.
You don't really require to give the source code unless the purchased person asks for the source. Most people don't care about the source. And you require only to provide source for people who obtained the binary legally. Nobody else can demand for source code.
Say for example, most of the D-Link routers come with a warranty card saying the software is GPL and is available on request. Period.
You can also void the warranty of the software (and hardware) in case the software you sold was replaced with a modified version (afaik, requesting for source can't make the warranty void).
There are a few things to consider: GPL v2 requires you to produce the source code in CD/Floppy (or like media), while GPL v3 allows you to have the source uploaded to net (or sent via email).
I think you're mixing mutually exclusive options. As I understand it, GPL requires you to either provide source code up-front on the same terms as the binaries (I think the relevant phrase in GPLv3 is "equivalent access"), or alternatively provide a written offer to provide the source code to anyone who requests it. The reason the offer must be to anyone is that your customers can distribute that offer with the binaries in lieu of source code. That way, they have the ability to redistribute/"convey" the software in a compliant way even though they don't have source code.
> GPL v2 requires you to produce the source code in CD/Floppy (or like media)
Unless I'm missing something, GPLv2 just says "a medium customarily used for software interchange", not specifying that it must be any sort of disk/tape.
That, plus the fact that if you incorporate any GNU GPLed software in your own software your own derivative software must be licensable under the GNU GPL, or be more liberally licensed, makes for the uncomfortable discussions with lawyers about use of GNU GPLed software in any company.
I have found a person that requested source of BMW i3 car software, and he have uploaded the source online[0].
Really?
https://finance.google.co.uk/finance?q=NYSE:RHT
We actively buy proprietary companies and relicense their software under free software licenses.
Now, about actual software as a product success stories, where you don't sell to companies that need someone to blame (and thus opt for support contracts)?
How do you reconcile that
My own company's lawyers consider the GPLv3 toxic and not allowed at all for company use in any software we create - that's enough for me.
Read the slide in the first few seconds. Does that look familiar to you? https://youtu.be/okEQt-Rla7o?t=863
That is the mental image of your company's lawyers when you ask about GPLv3.
This discussion sometimes feels like like the PHB telling Dilbert to go base the product on Oracle because of an article in CIO Monthly ("written by an EXPERT!") says it's the best database.
Isn't that often because the GPL would require you to release your source code? Which is different from possible patent problems? I can understand why companies don't want to release their source code, but at least it's clear ("release your code and you can't be sued"), right?
I have yet to see a single "professional IP lawyer" who knew more about GPL than an average IT pro. The was majority simply puts forwards claims without doing a minute of actual research on GPL
> My own company's lawyers consider the GPLv3 toxic and not allowed at all for company use in any software we create - that's enough for me.
Don't just blindly defer to lawyers. Yes, including GPL source code in a proprietary product could sink your company's business model. But using a GPL webserver is no threat. Nor using Linux as a set top box to run your local application (Roku). Nor using GCC to compile the program. (Alot of Playstation 1 games used GCC.)
Your own company's lawyers may be very ignorant on the GPL and it's benefits.
They may simply not understand and are relying on other people to inform them. (I believe Microsoft's old attacks against the GPL used the word toxic.)
I knew a contract lawyer who called the GPL 'very restrictive'. I pointed out the Windows EULA. He never really read it to understand it's far more restrictive terms. He never really looked at a EULA through a lawyer's lens and how much his business would suffer if the the terms were actually exercised. Nor that he didn't have to accept the GPL to use GPL software. Only to redistribute it. I doubt he could find that permissiveness in an EULA.
Lawrence Lessig made a few comments that his lawyer friends couldn't understand how Creative Commons licenses worked. People that have never met each other had legally agreed to binding license. This was in the early 2000's.
I'm sorry but Creative Commons themselves declare that their licensing should not be used for software.
https://creativecommons.org/faq/#can-i-apply-a-creative-comm...
content is not software
What are you referring to? Who has been bitten exactly?
Maybe they don't care because in reality its not a problem?
In the sense that it's not a problem people generally have -- not that nobody ever has had it.
A lot of people worry too much about all kinds of BS eventualities and technicalities, and this could be one of them in most cases.
>Now that we have a concrete example of how picking tooling with bad licensing can bite people in the butt
It only bit FB in the butt (in the sense that some developers complained about their license choice) -- not those using the tooling with FB license.
This is a backwards move. Facebook is very good at PR painting this as a win for users.
See http://en.swpat.org/wiki/Patent_clauses_in_software_licences...
an explanation https://opensource.stackexchange.com/a/1890
If you want to blame someone for the litigious culture in the US, blame John Q Public and the corporations he works for.
You're being an asswipe. There is no reason for you to respond this way. The lens upon which you view the world must be pretty god damned shallow to make these kinds of statements. If you want to be a fuckstick and reply like this, please find another community.
The last way we want people to be defending HN, even against perceived assholes, is by being assholes themselves. Would it really have cost you to make your point substantively?
This is very clearly a response to WordPress. Nicely played Matt.
We have considered possible changes carefully, but we won't be changing our
default license or React's license at this time. We recognize that we may lose
some React community members because of this decision. We are sorry for that,
but we need to balance our desire to participate in open source with our desire
to protect ourselves from costly litigation.
Given that they apparently didn't think it was a big enough deal then, and what changed was Wordpress, I don't think it's incorrect to give them some credit.[0] - https://code.facebook.com/posts/112130496157735/explaining-r...
Legal matters at big companies generally take months to resolve and come to consensus over. I can easily imagine their legal team evaluating all such scenarios that a change in license could hurt them (as they should), and that kind of research isn't something done in haste.
Sure, at your typical big public company. But Facebook voting control is firmly in the hands of Mark Zuckerberg, and he doesn't have to wait for approval of a board of directors. Just like when he decided to buy Instagram for $1 billion in a matter of days. If Mark detected developer sentiment shifting, he can move just as fast as he wants to stanch the bleeding.
how is react's popularity at all material to facebook's interests? at best it means you get more outside contributions, but you already have plenty of talent internally.
First, it increases the likelihood that the average programmer already is familiar with the tools they'd use at Facebook. It's useful for them to be able to hire people who already know React, Reason, etc. On occasion, they'll manage to find highly talented developers who either contribute to their projects or build useful related projects, and then they can make those people an offer. Even better, sometimes that's an entire startup they can acquihire.
Second, it increases the prestige of a job at Facebook. Most of the core public functionality of Facebook isn't particularly interesting to me, for example, but the stuff they're doing with OCaml is. The chance of me working there is still essentially nil but it's definitely less nil than it would be if I didn't know about projects like that.
Third, it gives them something really valuable to offer skilled devs -- the ability to become widely known and respected for your contributions to a popular open source project. That's worth a great deal to some people.
I can't pretend to know the exact rationale behind Facebook's decision to open-source React, but there are several things to gain from controlling a major piece of the web infrastructure: influence/clout with browser vendors (decisions that may negatively impact React's performance now threaten a huge percentage of the web, not just Facebook.com), the ability to introduce more and more Facebook-controlled technology with something like React as a shoehorn ("You liked React, try Flow..."), PR benefit/good vibes, and so forth.
Platform control is the real showdown among big software companies. It makes your company downright inextricable. Just ask Microsoft.
If I had to speculate, I'd say they did a ton of research on existing licenses on the route to BSD+Patent, and they already knew what the best alternative would be if it came to that.
You're welcome everybody! And thanks for the assist, Wordpress!
FB: "...we know that many teams went through the process of selecting an alternative library to React. We're sorry for the churn. We don't expect to win these teams back by making this change, but we do want to leave the door open."
This can seem like a response to the community at large, but can also be read as a direct response to Wordpress' comments:
WP: Automattic will also use whatever we choose for Gutenberg to rewrite Calypso — that will take a lot longer, and Automattic still has no issue with the patents clause, but the long-term consistency with core is worth more than a short-term hit to Automattic’s business from a rewrite. Core WordPress updates go out to over a quarter of all websites, having them all inherit the patents clause isn’t something I’m comfortable with.
Now if someone (i.e. an Actual, Impartial Lawyer) can explain if changing to MIT actually changes anything.
EDIT:
As others have pointed out, FB reaffirmed its decision to maintain the patents clause on Aug 18th (33 days ago): We recognize that we may lose some React community members because of this decision. [1] But they change their minds 8 days after the Matt published the On React and Wordpress article.
This pretty much proves that the decision to move to MIT was heavily influenced -- or perhaps in direct response to -- Wordpress' decision to ditch React.
[1]https://code.facebook.com/posts/112130496157735/explaining-r...
I believe the wording you are looking for is "strongly implies", because that's all it is, an implication. There is no proof. (and not even a boat to be seen ;).
1. We like React a lot with or without the license.
2. It's not our job to convince the world React's patent license is fine.
3. We're substantially moving away from React, including large rewrites.
...why are they moving away from React? I'm confused, do they believe using React implicitly supports it? They're already vocally supporting it.
I don't have an opinion or a dog in the race with regards to the React and patent license drama, but I legitimately don't understand why this blog post (or the underlying decisions) was written. In my opinion it feels like a huge deal to decide to rewrite a piece of production software, especially if you like the software already. So what am I missing?
Are they concerned that people won't use WordPress because it has React components? Does React's BSD + Patents license extend downstream like that?
EDIT: Thank you for downvoting me twice for asking an honest question folks...
> I think Facebook’s clause is actually clearer than many other approaches companies could take, and Facebook has been one of the better open source contributors out there. But we have a lot of problems to tackle, and convincing the world that Facebook’s patent clause is fine isn’t ours to take on. It’s their fight.
My interpretation is that due to the negative publicity that Facebook has garnered with their license, they didn't want to scare people away from using/building on top of their platform by using their library even though they themselves did not have a problem with the license.
It's understandable how that might be the final straw for Facebook when even people who don't have a problem with their license won't use their libraries for that reason.
And yes, the Patents part of that extends downstream to anything using it, that's the dangerous part of patents. It applies to everything that does that — even in independent implementations.
Yes, why would it not?
"Core WordPress updates go out to over a quarter of all websites, having them all inherit the patents clause isn’t something I’m comfortable with."
It's one thing to look at the license and guess that it's vanishingly unlikely you'll ever be in an intellectual property fight with FB (and it sounds like the counsel Automattic consulted with came to that conclusion for Automattic).
It's another thing to make that decision for everybody downstream using software that you distribute. Particularly when that's a reaaaally large number of people.
I'm on much less solid ground in speculating about more, but it's often interesting to watch the contents of speech when people are working to assure you of something:
"One nice thing about this apartment is that it's very secure." (That's interesting. Why is it important that this apartment is very secure? Is the neighborhood not so much secure?)
"This guy we're interviewing here is not being interviewed for your position." (That's interesting. Why do I need to know that, manager?)
In the case of this post, between the lines I potentially see something like:
"Hey FB, we don't feel threatened by the license, and you know, he who writes to code makes the rules, like Linus says. You're obviously doing what's right for you, from your point of view, and we're sure you know what's best for you, and if you're doing right by yourself, do you need to even ask if you're doing the right thing?
You do you, bro. And we're sure you won't be mad that we wanna let everybody else be themselves, too."
Not sure it's there, I could be reading more into it than I need to.
https://wptavern.com/wordpress-new-gutenberg-editor-now-avai...
There's also already a theme that uses React: https://themes.redradar.net/foxhound/
With those two things you could build a pretty good web app. The only thing is you'd be in WordPress land and isn't glamorous.
FYI: this shipped in WordPress 4.7 as part of the core software, and is now available on every WordPress site. (e.g. https://www.wired.com/wp-json/)
> The only thing is you'd be in WordPress land and isn't glamorous.
We tried to shield REST API users from much of the nastiness of WordPress' backwards compatibility (inconsistent field naming, date weirdness, etc), but yeah, it's still not perfect.
(I'm the co-lead on the REST API focus, happy to answer any Qs!)
In this instance.
I don't think they should be particularly rewarded for this. I think we should keep in mind what it took to get to this point.
And that, absent such pressure, individual organizations and people, and perhaps our collective society, remain at their... "mercy?"
Remain under their thumb. Whether that thumb presses down this year. Or next. Or... we just don't know.
In other words, I'd remain cautious about whether and how far I move under their umbrella -- tech-wise, or other.
Have you ever worked at a large company with its own legal team? It's not such a large mystery.
Big organizations require more time and people to reach consensus at different hierarchical levels. Probably the legal department was the bottleneck.
Either way, it's a good move.
I'm not sure how changing course from a direction that could have neutralized patents, to one engineered so patent aggressors aren't hurt, is something that can be considered a win for the open source community.
MIT is like a standard when it comes to OS. At big companies, complicated licencies are very hard to get approval of.
No it didn't. Facebook made a nothing-up-the-sleeve showing; you had recourse if they decided to "come after you", because your right to countersue was something that was explicitly protected in the PATENTS grant.
Removing the grant, on the other hand, contributes to a world where everyone else can come after you. That should be scarier, because the set containing entities who aren't Facebook is much larger than the set of entities who are. (And the latter set is much less likely to sue—virtually guaranteed not to sue, even—for the exact reason mentioned above.)
This is why Facebook's move to neutralize patents failed - everyone's suddenly in love with their own patents, even if they agree that the system is broken.
It was a good idea to scrap the clause to prevent the community from fracturing, but there's no triumph here - they failed to convince people that patents were a scourge to be eliminated.
"We grant you a right to use all patents we have covering this work.
[1] If you sue us regarding a patent you claim covers this work, we revoke your right to use all patents we hold covering this work.
[2] If we sue you regarding an unrelated patent, you retain your right to use patents covering this work for purposes of this work.
[3] If you sue us regarding an unrelated patent, you retain your right to use patents covering this work for purposes of this work."
The entire point of people being annoyed about this is that Facebook specifically didn't include the [3] grant. Consequently, this was more about Facebook attempting to use React's popularity to make themselves immune to patent litigation (as anyone relying on React wouldn't have been able to sue Facebook for any patent without losing the React patents grants).
http://www.businessinsider.com/just-so-were-clear-facebook-t...
Be careful. Facebook hasn’t said they’re removing the patents override completely. All they’ve said here is they’re changing their licensing, not what they’ll do. They may end up with BSD+Different patents grant. Make sure you check the changes next week. I doubt it will be straight BSD or they would have said it.
Am I missing something or does this make zero sense?
- Explicit patent license specifies why / how it can be revoked.
- Without an explicit patent license, patent infringement case (by Facebook) against a party that uses Facebook's OSS would be become harder, because one may argue that such grant is implied by Facebook open sourcing the software.
https://www.wilmerhale.com/pages/publicationsandnewsdetail.a...
https://copyleft.org/guide/comprehensive-gpl-guidech7.html
Basically, if you sell or license a product that requires a patent to work, courts have generally held that you grant an implied patent license for any patents that the product might require. If you explicitly reference patents within the license, however, then whatever terms you explicitly write into the license supersede this implied patent license. BSD+patents (and Apache 2) have explicit patent language; paradoxically, this makes them more restrictive than licenses like MIT, BSD, or GPL that don't mention patents at all.
React Patent Grant Version 2: https://github.com/facebook/react/blob/b8ba8c83f318b84e42933...
The license granted hereunder will terminate, automatically and without notice, if you (or any of your subsidiaries, corporate affiliates or agents) initiate directly or indirectly, or take a direct financial interest in, any Patent Assertion: (i) against Facebook or any of its subsidiaries or corporate affiliates, (ii) against any party if such Patent Assertion arises in whole or in part from any software, technology, product or service of Facebook or any of its subsidiaries or corporate affiliates, or (iii) against any party relating to the Software.
Apache 2 Section 3: http://www.apache.org/licenses/LICENSE-2.0
If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
GPL 3 Section 10 (See also Section 11): https://www.gnu.org/licenses/gpl-3.0.en.html
You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License. For example, you may not impose a license fee, royalty, or other charge for exercise of rights granted under this License, and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it.
Edited for spacing
So Facebook's idea works fine if you believe that Patents as a Thing are bad (all patents, not just software patents), and should not be asserted under any circumstances, and it's fine for Facebook to arbitrarily violate any patent of any company who has become dependent on React.
Maybe, maybe not. You suing them over your patent would terminate you patent* license from Facebook, but not your copyright license. Whether that fucks you or not depends on whether or not you actually NEED a patent license from Facebook.
As far as I know, no one has actually found a Facebook patent that covers React.
This would make Reacts PATENTS file a bluff (nothing to grant or revoke). I don't think many companies would be eager to base decisions on that legal theory.
Also, I'm curious. When did React start using the techniques covered in that patent application?
No, if you try to sue them for violating that patent, they can try to sue you for using React - if they actually have valid patents that cover React, that is. I doubt IBM's lawyers are breaking a sweat.
Why do you keep spreading FUD about this stuff even after Facebook withdraws the license?
If implicit patent grants are a thing, why have more modern licenses like Apache 2 and GPL 3 made it a point to include explicit patents grants in the language of the license?
Wouldn’t their legal counsel advise them against it if it was redundant?
Apache 2.0 would have also been acceptable, as it had a better explicit patent grant. I'm actually a little surprised they didn't choose it.
You may be right that this might actually reduce our rights, however, the MIT license is well known and accepted by many in the developer community. It's been around long enough that developers know what they are agreeing to when they use something with an MIT license. With the BSD+Patents license, the biggest concern was not understanding what you were getting into when using React.
Facebook recognized this and conceded despite still believing in the BSD+Patents license to be better. So in that sense, this makes a lot of sense as it:
* alleviates community concerns
* builds up their standing with developers
* generates a lot of good PR
* draws attention away from alternative solutions which were getting a lot of publicity from all of this (Vue.js, Marko, Preact, etc.)
It would be nice though to have a lawyer chime in on the differences between BSD+Patents and MIT.
I'm likely oversimplifying, but that's about as much as I understand on licenses
That combined with the implied licenses means there was a patent clause causing a ton of unecessary hand-wringing.
The reality is every company of FB's size is patenting every developer's latest dump if it can get through the patent office.
> This shift naturally raises questions about the rest of Facebook's open source projects. Many of our popular projects will keep the BSD + Patents license for now. We're evaluating those projects' licenses too, but each project is different and alternative licensing options will depend on a variety of factors.
In what way does re-licensing their most popular packages make it worse? It says they're evaluating. Doesn't say no and as demonstrated here it doesn't mean they wont change their mind later.
The common thread here is that these libraries are often used together - changing React's license wouldn't have helped if they're also using Flow and Jest.
The Open Source Initiative's definition of "open source" doesn't say anything about patents: https://opensource.org/osd
I don't know if Facebook has asked the OSI to validate their "before" license as "open source." Perhaps if they did it would be controversial (or perhaps not), perhaps it would lead to OSI making more restrictions on what it will call 'open source', I dunno.
One version of a "BSD+Patents" license is approved by OSI, but not one involving a "retaliation" clause. https://opensource.org/licenses/BSDplusPatent
Anyway, I don't think you have any grounds to say that license was not "truly open source".
"and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it"
The whole fight here is about patents, not about open source. Perhaps Facebook's solution to nuking patents was too crude, but it had nothing to do with "open source" vs "closed source". The whole issue here is whether you could still use your patents against Facebook, something orthogonal, if not outright hostile to open source.
Well, the implicit assumption behind FB's bsd+patents license is that you should be ok with anyone "infringing" on your software patents, since software patents are mostly bullshit and you only acquired them to be used in defense (i. e. never suing someone first). That license doesn't make any sense if you believe otherwise.
[1] The language I'm thinking of is the part that says that the license terminates if you initiate "any Patent Assertion: (i) against Facebook or any of its subsidiaries or corporate affiliates, (ii) . . . "
They probably left it this way because there is no legal definition of a "software patent" - they cannot differentiate between those and "other patents". It's not like "other patents" are all sunshine and rainbows either - the patent system is fundamentally broken.
It should be noted that there is nothing in the MIT license that actually says it is a copyright license. Here is what it grants you permission to do:
> Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions
It is giving you permission to "deal in the Software". What that means is not defined but it gives several examples that it includes: use, copy, modify, publish, distribute, sublicense, and/or sell copies.
Several of those, including use, copy, sell copies and maybe distribute, are things that require patent permission if the software is patented. The plain language of the license says that you have permission to do those things, and the only way you can have that permission is if you have a patent license, so I don't see how a court could read the license as not including a patent grant if the licensor has patents that cover it.
Apache 2.0 certainly doesn't require you to have patents in order to use it ("applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s)")
Implied patent licenses:
https://www.wilmerhale.com/pages/publicationsandnewsdetail.a....
https://copyleft.org/guide/comprehensive-gpl-guidech7.html
Basically, if you sell or license a product that requires a patent to work, courts have generally held that you grant an implied patent license for any patents that the product might require. If you explicitly reference patents within the license, however, then whatever terms you explicitly write into the license supersede this implied patent license. BSD+patents (and Apache 2) have explicit patent language; paradoxically, this makes them more restrictive than licenses like MIT, BSD, or GPL that don't mention patents at all.
dataloader
draft-js
express-graphql
flux
graphql-js
regenerator
relay
yoga
They'll probably stick with BSD+Patents, unless the pressure is kept on, which is unfortunate.The patents grant was irrevocable except under explicitly described conditions. A license change wasn't one of these conditions.
So:
1) Does the patent grant still apply? i.e. is it now MIT + Patents?
2) If yes/no, what about existing users of React? i.e. if you were a user up to the point of the license change, do you get the grant, but new users don't?
3) Doesn't not having the grant make us worse off? Presumably only the Apache 2 license would be an improvement in this regard?
4) Is this all just PR theater?
(IANAL, but this is how relicensing works basically universally)
I don't think much around patents and software is settled, partly because of the reluctance of big players to use software patents.
The other thing is that there are many projects that are STILL going to be on the BSD+Patent license. These include widely used projects such as React Native and GraphQL.
This behavior is reminiscent of their strategy of invading their users' privacy and then retracting a bit and then doing it again. Wash, rinse, repeat...
...
React switches to MIT...People still FUD. WTF.
Was this release date known before now? I can't find it anywhere else on Google or Twitter. Man, talk about burying the lede.
I'm probably missing something, but: If their BSD+Patents was actually strictly "better" for the user, could they not just dual license under both? Is BSD+Patents ∪ MIT < MIT for some reason?
But I very much agree and am puzzled why everyone seems to think this latest move is such a great thing. Removing the patent grant entirely isn't so great.
Facebook can sue you anyway, no matter what the license is. The grant made it impossible for facebook to sue you unless you sue first. That's gone now.
The issue with the GraphQL spec is that people actually want a patent grant for alternative implementations, but there isn't one.
There's a patent: https://www.google.com/patents/US9646028,
and a recent discussion: https://news.ycombinator.com/item?id=15289676
Another one is tooling, but the recent typescript Compiler can do TSX natively (no webpack config etc required).
The last one is size/performance, but afaik the guy behind inferno is now working on react, this all should union React's "forks" into a single force.
Interesting times we live in, lets hope that facebook does not fail on this.
I would just like to see people evaluate and decide whether to use it based on the actual technology, and not FUD.
I wonder from a more general sense with open source licenses
Interestingly more people seem blatently annoyed that their employer forbids them to use e.g. React and not about what the license actually means.
BSD+Patents would terminate its patent grants if ever yourself and Facebook entered litigation. Implying Facebook would add a patent suit to their defense/offense.
Now they STILL get too! Buuut they look like a good guys. MIT says nothing about Patents. So they can sue _anyone_ using React for patent violations now.
— —
People should keep the pressure up until they license under Apache2. Then the patent issue is solved.
It would be interesting to see the backlash if a company ever tries that one. They would probably lose a lot of their own developers as well.
This is BSD/MIT is consider a _bad_ license if you want to convert patent concerns.
Without restrictions or limitations. As far as I know, it has not been tested in court, but I think it would be suicide among the developer community for a company to try to do that.
Everyone should have patent concerns either way. The ideal solution would be to abolish software patents.
I will still not be using React. It's just too heavy, same order of magnitude as jQuery.
Cause I might consider a move now.
There is no patent clause now. Assuming some FB patent has crept its way in one of their open source, if a company sues FB for patent infringement, FB would be able to counter-sue for copyright infringement due to the suing company's use of FB's open source.
"As long as you don't sue us, we won't sue you" kind of a deal. If the above scenario is true, it seems there is no de facto change beyond the political one.
Anyone with more legal expertise able to disprove this scenario?
the whole point of mit/bsd/etc is copyright grant. fb can only realistically win a suit wrt infringement if they revoke the mit/bsd license first (not sure if this is possible...not sure if it's even been tried before).
But since there is no patent grant with the MIT license, using the open source software is–potentially–open to patent litigation. I don’t think this has been tested in court yet.
But you're right, I don't think it's been exhaustively tested in court, just like most software patent issues.
Here is the scenario without the … emotional baggage:
——
Company X has patent P.
Company X releases open source O which provides implementation of patent P.
There is no patent grant in the license of open source O.
Company Y uses open source O.
——
Can company X sue company Y for infringement of patent P? I think the answer to this is “yes”.
WRT patent grants, there's a few tidbits here and there about implicit patent grants(https://copyleft.org/guide-next/comprehensive-gpl-guidech7.h... and http://en.swpat.org/wiki/Implicit_patent_licence) but hardly any settled case law. At any rate, this is the situation with every MIT license, so I don't know why it's ominous.
They replaced BSD with MIT, because the language used in the MIT license is closer to what constitutes a patent grant: https://en.wikipedia.org/wiki/MIT_License#Comparison_to_othe...
This whole patent/license circus is not really a decent advertisement. The original reasoning already wasn't.
The only proper solution to the whole drama is to end handing patents on software, as it pretty much is pointless.
Case closed. Could not have picked a better license, thank you Facebook. MIT or bust, I try not to use any other types of licenses in products/libraries I choose for work and personal use.
Case not closed, patents still pose a threat. They could (and arguably should) have picked better license, something with explicit permissive patent grant, such as Apache 2.0. This move can barely constitute even as lip service to appease the masses.
So same protection as now.
This is, of course, true of any other OSS and patent holding company.
So I trust implicit grants much less than explicit.
Like, I'd love to live in a world where patent protection wasn't even an issue but we don't. So in this situation we end up with less protection due to compatibility concerns.
Given we do live in a world where software patents are valuable to companies and they won't all want to give blanket irrevocable licenses... there has to be a way for business to do that and protect users of the software.
The patent grant FB did was a (flawed) attempt at that.
Even if you believe the implicit grant to be weak, or Facebook's Patent grant to be better than an implicit grant, the above discussion stands independently of those things.
Edit: It seems like some consider MIT, unlike BSD, to have an implied patent grant based on its wording: https://www.scribd.com/document/46088081/Closing-the-Loophol...
The MIT license gives you the rights to "use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software", and that's not even exhaustive. (See "without restriction" and "without limitation".)
Is there something missing from the second list that you think needs protection from the powers granted to patentholders (the things in the first list)?
Is there somewhere where anyone has elaborated a case as to what those benefits to users would actually be?
Never thought this would happen
As for people who think the exodus out of React was "imaginary" - I wish FB had actually completely dropped the ball and stayed with the old license. That would have forced Automattic to not merely drop React, but also anoint a competitor which would have probably overtaken React in no time.
Why not just go with BSD and drop the problematic patent clauses?
Apache 2.0 has a patent grant from my understanding.
This has all been so tiring.
Like... ok, great, better really hope you never get into legal issues with FB now
If that were true, then why would they write all those blog posts saying that the BSD+Patents was "for their protection". They even repeated it here. It's pretty clear that the patent grant was asymmetric, but not in the direction you're suggesting here.
There's a reason that BSD/MIT is preferred by companies vs Apache 2 (which has been adopted, yes, but much less). It's because - just like here - it preserves all their patent rights.
So yes, you now have less protection but FB has just the same if not more.
Don't get me wrong: the patents grant wasn't a great solution but it solved specific problems and concerns on both sides that BSD by itself doesn't even try to address and alternatives (like Apache 2) only address half of.
For what it's worth, the software that I'm developing at a Big 4 is released under the Apache 2.0 license.
Why would you have preferred the Apache 2.0 license?
But I'll still look for a framework with better separation of view and controller logic. And incremental DOM.