The future of Java and OpenJDK updates without Oracle support
developers.redhat.com
developers.redhat.com
Where can I found Oracle's official statement about this issue?
Here is a pretty good write up on everything that's happening:
https://www.azul.com/eliminating-java-update-confusion/
There was enough concern about all the FUD people are throwing around that Oracle took the step of providing a more visual explanation a long time ago. It's here:
https://www.youtube.com/watch?v=YauqubC8FKM&feature=youtu.be...
I mean, what's wrong with Oracle only supporting every OpenJDK for 6 months?
I'm a Unity user, so no dog in that race really. (Well, we make some game server side stuff with java, but our big stuff is Unity). But it seems completely reasonable to me. I'm probably missing something though, since the internet outrage machine is in high gear. In all honesty though, it sounds perfectly reasonable:
Oracle is basically telling you, "If you want more than 6 months of support, buy a support contract. If you don't want to buy a support contract, then you'll have to download the newest OpenJDK to get those updates and patches."
???
I'm probably missing something here since I'm not a deep java user, but what's the problem with that release model?
- Open JDK has not historically been a production-ready deployment. It was a lower-performance, "reference" implementation, explicitly NOT recommended for production deployments. This changed around JDK 9, but see the next point.
- in spite of Java's attempts at backwards compatibility, migrating non-trivial projects to new major releases of the JDK has always been painful and slow. Many projects are still on (or recently reached) Java 8. For example, Spring Boot released support for Java 9 just 6 months ago.
- many Java applications are large enterprise applications (many dependencies), and enterprises want stability and long-term support of infrastructure components. It's likely that not all dependencies will get migrated to a new JDK within 6 months, even less that the application will be migrated, and that says nothing about rolling it out to production.
- and production is when you really want security updates, etc. And Oracle's plan is that the last scheduled security update would be a couple of months before the next OpenJDK release, so you really only have ~4 months of a supported, updated JDK release.
- there have been various security problems with Java, even with Oracle's support (particularly client-side, which is becoming less relevant)
So Oracle is moving from a slow-moving cost-free model to "hop on a rapid upgrade treadmill on a release we've historically told you not to use".
So the simple answer seems to be "pay oracle for support".
- Then you get into Oracle's [abusive? domineering?] licensing practices, like requiring licenses for every CPU in a VMware cluster.
- Some clients have been told by oracle reps to try enabling feature X, then brought up for license violations because feature X is commercial-only.
- Working with Oracle is problematic enough that clients don't even want to enter into a conversation with them about the consequences of the JDK license change for fear of getting on Oracle's radar.
The community appears to be stepping up, but there's still a lot of concern about whether they will be able to provide production-ready, secure builds, across the many platforms Java supports. (Notably, Solaris support appears to be lacking...)
- OpenJDK and Oracle's JDK have been nearly identical for quite some time, and they are identical as of this week. So whatever differences once were between Oracle/Sun JDK and OpenJDK, OpenJDK now is Oracle JDK. (https://blogs.oracle.com/java-platform-group/oracle-jdk-rele...)
- Enterprises have had to upgrade a JDK every six months for many years, now. But whereas JDK versions used to be named 8, 8u20, 8u40 etc., they are now named 10, 11, 12 etc.. In the past, JDK releases were also not supported more than six months. Some are under the impression that each of those is a major version; this is false. In order to make upgrades easier, Java no longer has major releases (Java 9 was the last), however, all releases now have their version number incremented ("Chrome versioning", if you like). To make this possible, the restrictions of what changes can be done with each 6-month release, so that the transition between, say, 12 and 11 is not quite the same as between 8u20 and 8u40, but it is also not at all like that between 7 and 8 or 8 and 9 (and closer to the former than to the latter). In addition, companies that don't want updates but only security fixes can purchase support from Oracle.
Grails (built on spring boot) won't support anything higher than Java 8 until end of 2018.
Grails 3 is built on Boot but virtually no-one uses it. Websites using Grails have largely remained with version 2 and no-one's starting new projects in version 3, so I doubt the Grails backers will even bother to add Java 9+ support to Grails 3.
The Apache Groovy backers also seem to have given up on releasing a version 3. A few months ago, they pulled preview support for version 3 features from the upcoming Groovy 2.6. Since then, Groovy 3 has been stuck on permanent alpha version, with no-one in their project management committee showing any interest in moving it forward.
Oracle clearly seem interested only in trying to exploit Java developer and users. Why are we still stuck to them?
So, like it or not, this is the reality of open source. A lot of companies are happy to use it freely but less happy to contribute the significant resources necessary to build it.
(I work at Oracle on OpenJDK, but I speak only on behalf of myself)
Because even literally the most used Java library - JUnit is struggling financially, because everyone wants to use great technologies for free and donations and open-source contributions are never considered.
I worked in huge financial institutions once, they heavily relay on some ant plugin. The plugin had a bug, probably like a day of fixing for me. The company decided to stop using the plugin, rewrite the whole configuration in bash, which took almost 4 weeks of 4 people, than contribute to opensource during working hours and fix the bug for everyone.
They've even been involved in getting the open community up and running.
I sincerely can't imagine what more you could want from a corporate steward.
A different business model than suing their customers?
Don't forget many of their customers are pretty dodgy/incompetent also.
https://www.businessinsider.com/oracles-cloud-sales-2015-7
https://www.businessinsider.com/oracle-customer-explains-aud...
Enterprise licensing is extremely complex. Add to that that vendors often play hardball with customers.
If I, as a vendor, want to find you in breach of the licensing agreement. I will.
Source: I worked for a database vendor and was stunned about the dirty tricks pulled in enterprise software sales.
The suit against Google was filed within a month of the Sun acquisition, it was part of their reasoning for buying Sun in the first place: so that they can sue Java users and get tons of money for nothing.
Gosling interview on "Oracle vs Google".
https://www.youtube.com/watch?v=ZYw3X4RZv6Y&feature=youtu.be...
That's the point: they are suing users because they demand those users pay licensing fees.
What other programming language and/or software stack comes with that risk?
Basically any software stack sold with a commercial license.
I know Oracle had sued Google for using Java some 3 years ago, and that amount ran into billions, but I thought that must be some issue exclusive to Big Corps.
https://www.bsa.org/?sc_lang=re-EM
Occasionally they organize surprise audits in collaboration with the respective countries customs police.
Here is an old report (in Portuguese) about 40 000 illegal copies being caught from several businesses.
This is just normal piracy as we know it. They don't appear to be developing anything using FOSS like C, C++?
Am I missing anything here?
That's not what we're talking about Oracle doing here to users of Java.
Any compiler writer that wants to write a conformant implementation needs to buy the ISO document, otherwise there is no guarantee that the compiler is actually ISO compliant.
Additionally most compiler vendors that care about ISO certification need to pay extra to companies that sell ISO validation suits like Dinkumware.
https://github.com/cplusplus/draft
https://www.iso.org/standard/68564.html
See I am even saving you the trouble to search where to buy it.
Express versions were only allowed for education purposes, and only started to be available around Visual Studio 2008.
The original .NET SDK was a bare bones command line SDK without any of the tooling that actually makes development in .NET actually worthwhile.
https://forums.asp.net/t/1204510.aspx?visual+studio+express+...
Can I use Express Editions for commercial use? Yes, there are no licensing restrictions for applications built using Visual Studio Express Editions.
We couldn’t use it in 2008 because we needed to use the Windows Mobile emulator.
Database management - sql server management studio has always been a free tool.
Architecture modeling tools - not required for development.
Directs debugging - how many enterprise developers are doing anything with DirectX?
Share point - you couldn’t pay me enough to do Sharepoint development. That’s not exactly a popular use case these days.
But, until .Net Core, .Net was considered a part of Windows. There was no separate license.
As far as the support lifecycle, you get three years of support for the LTS releases of .Net Core and you don’t pay MS for it.
https://www.microsoft.com/net/platform/support-policy
For .Net Framework, it’s tied to the support lifecycle of the version of Windows it was introduced with.
There is also, of course, projects such as Mono.
I don't recall Mono developers having ever been sued. In fact I recall that the people behind Mono were actually hired and paid a big chunk of cash to work for Microsoft.
I did several ports from .NET to Java as means to have the software run on UNIX platforms.
https://www.geekwire.com/2017/microsoft-just-sued-ip-address...
Same thing, Oracle only sued companies using Java licenses illegally.
Ah, you never used Enterprise frameworks with VS plugins it seems.
The joy of building Sharepoint plugins
.NET applications are for the customers, not for running on our computers.
Before it went open source we surely needed Studio to do any kind of meaningful development and respective production deployments.
They just ended support for VS 2008 in April of this year.
https://blogs.msdn.microsoft.com/visualstudio/2017/04/10/end...
The new commercial JDK is like Microsoft suddenly asking expensive license fees for using .Net "in production" (which they actually do indirectly, and with clear-cut boundaries, through expensive enterprise Windows SKUs)
Every revision since 4.5.2 follows the support lifecycle of the parent OS (which generally is much more than 3 years)
.NET Framework has never had a license fee. An argument could be made that part of the cost of Windows OS is a .NET Framework licensing fee, but the fact is if you're developing for Framework then Windows is already in your purview.
Admittedly, the .NET Framework is not open source. But a good amount of its source code is available for review:
I wouldn’t bet my career on .Net framework or desktop development in general anymore than Webforms.
The last time I was looking for a job, there were companies that offering me architect positions paying $10K - $15K more than the job I accepted to lead projects that were doing ASP.Net MVC, Sql server, etc hosted on IIS using .Net framework.
I saw the writing on the wall, I took a job that was more or less a vertical salary move, and “self demoted” so I could jump on newer tech.
Although Microsoft makes a lot of money on development tools, it seems to think that giving away versions of those tools can help drive demand for Windows. Sun tried the same thing, but then advertised Java as making the operating system and hardware irrelevant, so free JDKs don’t appear to have sold many Solaris systems.
Those free versions of Visual Studio weren't allowed for production when they were called Visual Studio Express.
Visual Studio Community only allows production use for companies up to 5 employees, with a specific yearly revenue. Better read the licenses.
And on the server, majority of .NET Web applications are a typically variation of Sharepoint, SiteCore, Orchard and similar CMS, usually deployed on IIS.
.NET Core might do the circles around HN and Reddit, but it is still largely ignored in the typical .NET shops.
That's news to me, and not only I'm from Europe but also I've actually worked on developing UI applications for laboratory equipment.
I have seen zero instances of WPF being used anywhere at all. Ever.
At this point I'm thoroughly convinced that you're just trolling HN and wasting everyone's time with a constant stream of jibberish.
https://www.zeiss.com/microscopy/int/products/imaging-system...
https://books.google.de/books?id=U5AMFXjNmugC&pg=PA247&lpg=P...
https://www.labmanautomation.com/
As for trolling, I find sad that on a web site created for people starting business, many feel entitled to get their tools for free, unlike every other professionals.
You have to compete with the market as it exists. All of the focus of development and all of the money is going into web and mobile. Every platform vendor except Microsoft is giving away their development environment.
I’m a .Net fan but I can’t imagine living in the hell like landscape of doing WPF development knowing that the industry is passing me by.
If I were going to do desktop development in 2018, it’s going to be working in C/C++ writing really specialized, highly optimized software where I could command a huge premium.
Not everyone does fashion driven consultancy development.
After the comma I have listed other .NET Web platforms.
It looks like today you’re explicitly allowed to use the free Visual Studio for open source work, noncommercial work, academic work, and small commercial work (“small” defined in terms of team size). If that doesn’t cover your project, you have to try to fit in the BizSpark rules for a temporary fee waiver.
> 4. Can I use Express Editions for commercial use?
> Yes, there are no licensing restrictions for applications built using the Express Editions.
Visual Studio Express (and now Community) editions have always allowed for commercial development.
> With Visual C++ 2005 Express you can build both native and managed applications. Using the .NET Framework you can easily create Windows Forms, console, and class library applications. By downloading the Windows Platform SDK (freely available) you can build applications that take full advantage of the Win32 API. Web developers should use Visual Web Developer 2005 Express Edition.
I mean, I'm pretty sure Win Forms, Console apps, and class libraries were all most of us were using .NET for back in 2005 (I wouldn't know for sure as I was in high school still).
Don't get me wrong, there were and are advantages to the non-free versions of Visual Studio. Notably, until 2017 I believe, was extensions. But there's just a lot of misunderstanding in this thread about the general licensing model of .NET and its toolchain.
To generally not try to pull the rug from under you by changing licenses?
I do agree though it isn't a completed product yet, but what's already there is fairly capable depending on what you're working on.
.NET 3.0 will close the gap, but there are lots of .NET Framework features that aren't even on the migration roadmap.
Enterprise stacks are a different animal than plain web sites, where integration between existing platforms plays a major role.
The likes of SAP, Oracle, Rational, Enterprise Architect and similar software are not yet there.
Most of that is so they could wash their hands from the maintenance burden.
> finally the crown jewel the TCK
Can you give me more info here? I heard about EE, but I was not aware the full Java TCK (i.e. the one denied to Apache Harmony) is completely open now.
> I sincerely can't imagine what more you could want from a corporate steward
Simple, don't try to profit from the language itself. Imagine a commercial Go version, or imagine if some AOT parts of the .Net compiler were part of an enterprise edition, or imagine if a test suite for WASM compliance were selectively given only to some, etc.
Oracle are just not giving users of obsolete, deprecated versions of Java free patches anymore. They want everyone to keep up to date with the current version. The likes of Apple, Microsoft and Google just force push updates to achieve the same goal, but Oracle doesn't have that kind of control.
Yet even though Oracle don't want to support old versions anymore, they still offer support contracts for those organizations that truly need it. Which is a completely normal thing in the tech industry. What part of that is exploitation?
IIRC they are also making commercial (non-development) use of Oracle JVMs 11+ something that they will charge for.
I don't think this was true of earlier versions.
From Java 11 onwards the "Oracle JVM" is exactly the same as the "OpenJDK JVM". The only difference is that one has the Oracle name on it and if you buy it, has long term commercial support.
It's actually the other way around to what you think. Earlier versions had proprietary features you had to pay for. Now there are no proprietary features anymore. The only thing you pay for is support.
And that you need to pay for it if you want to deploy the "Oracle" version. It's not optional paid support.
I am aware Oracle produce both, and that the OpenJDK build is every bit as 'official', I have no problem with this.
Please don't call me confused, my original statement is still true - Oracle branded JVMs will no longer be free for production use.
I was confused by the indignation in this thread. A JetBrains blog post [1] seems to say that if you have been coasting on OpenJDK in production, as long as you don't plan to use any OracleJDK-specific features now or in the future, and as long as you use Java 11 in all your implementations, then the license change is not a material difference to you. Not supporting older Java specs for free sounds reasonable to me, is there something wrong with that posture that someone can care to enlighten me upon?
[1] https://blog.jetbrains.com/idea/2018/09/using-java-11-in-pro...
I'm just noting the change in licensing. As I mentioned in the other fork of this thread we're going to move from Oracle 8 to OpenJDK 11 soon, and that's great. No problem at all.
Literally all I've tried to say is that there is a license change on the Oracle branded version, and you need to take note of it if you have been using the Oracle branded version and were going to continue. This is not really a complaint!
I'm not sure why this seems to be controversial.
Simple rule: if it has "Oracle" in the front now, you have to pay to use it in production. If it has "Open" you don't.
Sure, but you could use the Oracle-branded JVM in production, AFAICT, for free before.
Do you use Oracle specific features that are not in OpenJDK?
Please don't mistake my comments for complaints - I'm just noting that things have changed in the licensing terms for Oracle-branded JVMs.
There is an easy and simple way forward, to use OpenJDK, it's important to note the change and act accordingly. That's all.
But we already have OpenJDK. What would be gained by completely cutting ties with Oracle?
Also apparently many have a short memory regarding Sun and IBM's Java business pratices and hating Oracle is fun.
Plus it would be really hard to get adoption for the fork. The Java brand is huge and many of its users are late adopters or even laggards.
I don't see why the uproar about Oracle branded OpenJDK. We can use normal OpenJDK which is almost the same.
Previously, Oracle supplied the engineering resources to develop new features and to maintain old releases.
Now, Oracle provides the first but not the second. The community can step in and do the second. If it is forked, then the community needs to step in and do both.
So getting free of Oracle has a cost, the cost of losing engineering resources for new features. Whether it's worth it would depend on how much value you place on those two things.
Clearly Oracle is trying to steer people toward revenue-generating things. I don't see a problem with that in and of itself, especially if the community can provide a free alternative.
It seems like this could push things either direction. On the one hand, many companies may just pay Oracle for support and that may become a common (and expected) practice. So that would shift some control toward Oracle. On the other hand, Oracle is stimulating the community to get involved in maintenance, and that may build some momentum for community contributions, causing the community a larger role in Java development, which would shift some control away from Oracle.
Why is Oracle obliged to provide long-term binary support and updates for old free software? If you want long-term support for old Java versions, then I think it's reasonable to say: pay for a subscription (or don't complain). RedHad uses a similar business model.
Or keep using the latest versions which will continue to be free, and stay up to date. It seems like a reasonable proposition to me. I don't see what Oracle has done wrong here.
As far as I can tell Hacker News and reddit are overrun with hysterical developers who are desperate to believe Oracle is evil, but whose entire rationale boils down to "but I don't want to read I just want to download whatever I randomly find on the internet", a rationale that is oddly not sympathised with when open source license violations occur.
Oracle JDK doesn't even have any DRM or other controls to ensure license compliance, it's all trust based. And the download page even tells you to go download OpenJDK if you want the GPLd non-commercially-supported version. I'm starting to understand now why companies have to audit their customers. Apparently the world is full of employees who feel it's perfectly legitimate to ignore straightforward, trust based license agreements out of some odd sense of entitlement?
Only free for non-production use. This was on HN yesterday:
https://blog.joda.org/2018/09/do-not-fall-into-oracles-java-...
https://blog.joda.org/2018/09/do-not-fall-into-oracles-java-...
> As well as their commercial JDK, Oracle produce an OpenJDK build. It is $free, zero-cost and GPL licensed (with Classpath exception so safe for commercial use). Download $free Java here: https://jdk.java.net/11/
jdk.java.net/11 in turn says:
> This page provides production-ready open-source builds of the Java Development Kit, version 11, an implementation of the Java SE 11 Platform under the GNU General Public License, version 2, with the Classpath Exception.
"With JDK 11 Oracle has updated the license terms on which we offer the Oracle JDK. The new Oracle Technology Network License Agreement for Oracle Java SE is substantially different from the licenses under which previous versions of the JDK were offered. Please review the new terms carefully before downloading and using this product.
Oracle also offers this software under the GPL License on jdk.java.net/11"
> You may not: use the Programs for any data processing or any commercial, production, or internal business purposes other than developing, testing, prototyping, and demonstrating your Application;
Which seems to suggest that you can use the Oracle JDK to develop, test, prototype, and demonstrate your application, even in a commercial setting. You just can't run Oracle JDK in production without a license. But IANAL.
As for the JRE, I haven't really kept up. I'm not sure if there will be a separate Oracle JRE11 and what its license terms will be. Right now, only JDK11 is posted for download.
> The OpenJDK Vulnerability Group, with members from many organizations, collaborates on critical security issues.
Huh, I'd never heard of that before.
> There is also the question of back-porting important features from later OpenJDK releases ... While new features, particularly performance-related ones, are undoubtedly nice to have, our first priority must be to not break anything: we must remember that we are stewards of a very precious piece of software. ... each proposal will have to be taken on its individual merits, and I don’t think we can have a one-size-fits-all policy for such things.
This is so refreshing to hear. Especially after all the turmoil over the Linux CoC, it's nice to just hear: we'll rely on my human judgment and that if my peers.
All in all I think this is good news and well needed clarity.
Can anyone say which distributions he is alluding to?
Oracle remains the driving organization behind Java and OpenJDK. The change that has everyone up in arms is the cessation of Oracle support for updates to OpenJDK versions 6 months after release (no long-term support/updates of OpenJDK releases)
> Go 2 must also bring along all the existing Go 1 source code. We must not split the Go ecosystem. Mixed programs, in which packages written in Go 2 import packages written in Go 1 and vice versa, must work effortlessly during a transition period of multiple years. We'll have to figure out exactly how to do that; automated tooling like go fix will certainly play a part.
Even if there's 99% compatibility, if upgrading requires anything more than updating the compiler, even if it's just adding a runtime flag and the upgrade effort should be minimal, you're going to see significant resistance from companies with large codebases.
This assumes that Go 2 does have significant breaking changes, which the Go team have explicitly said that they do not want to do. The current view seems to be that they will feed new features into Go 1 releases as opt-ins, in the same ways that modules is an opt-in feature that will become opt-out in some future Go 1 release.
But if you have a greenfield project and some decent Java developers, you'd be surprised what you can do with Java if you're willing to avoid the common pitfalls (J2EE, Spring).
I'm curious how the proposal for generics is "bloated" - especially as compared to something like C# or Rust.
At least with C++, there are several companies involved, and its inventor doesn't work for one software platform in particular (herb sutter works at Microsoft, that I will agree). I don't know how 'iso' Java is, but to me c++ is much more adaptable.
Java requiring a jvm makes things a little complex. Does the jvm offers guarantees like c++ does? I trust c++ more, because once it's compiled, there are much less uncertainties.
This seems backward to me. C++ has a great deal of undefined behaviour, which you don’t get in Java. And Java has had a memory model for years - until recently nobody could argue their parallel code was correct on C++.
If you want guarantees Java seems like the better option.
Oracle (HotSpot) GraalVM (also Oracle) Zing OpenJ9 ExcelsiorJET
Performance was radically different between them, but the answers where the same (ok equivalent as this a whole lot of parallel code).
My co-workers can't even get their C++ compiler to be accepted by two different compilers and it is not just them. Compiler upgrades are feared events where significant effort needs to be put in.
While even the hard upgrade to Java9 from 8 was 3 extra commandline switches on startup. For a project with 168 dependencies and more than 1 million lines of code. Done in one afternoon, with the upgrade to Java 11 taking 3 minutes. (needed to add java mail to the WAR/classpath instead of expecting it to be in the JDK)
Upgrades from 5->6->7->8 where equivalent or simpler. Eleven years in two bugs due to an upgrade. One a compiler bug in 1.7.45 an other not overriding all the methods from abstract list in a list of string implementation that uppercased on retrieval. Trivial compared to C++ upgrades.
I spent close to a week on data corruption that would have never been possible in Java.
C++ is not for the weak of heart. It's like the wild west. I have since moved to the civilisation of Java and quite happy here.
Sun open sourced a lot of software, but they didn’t co-operate with the community. When Oracle bought Sun, I remember thinking that they may have been the only company to have a worse open source background than Sun.
I’ll admit that Microsoft probably isn’t any better as far as actually being open (compared to throwing the source code over the wall on occasion?, but (1) they aren’t any worse, and (2) they never sued Google for using clean-room implementations of their programming language and libraries.
I can't see why you have understand it like that, but I agree with the rest.
Now with .NET Core that is slowly changing, but .NET Core still needs to catch up with many .NET Framework features, specially enterprise frameworks that run on top of .NET.
https://en.m.wikipedia.org/wiki/List_of_compilers#C++_compil...
What many think is ISO C or C++ is actually compiler specific behavior, because they never bothered to read the actual ISO, just some programming book.
Why would you need to? Build your binary, test it, give it to your customers. Why do you have to test every compiler?
For example your carefully written C++ code with gcc, might crash and burn with the TI compiler that is the only way to target a specific SOC.
Or maybe that other customer doing HPC only accepts your code if compiled with Intel or IBM compilers.
Then you build it, test it and deploy it. No clue what you are on about.
Check Boost's codebase as an example of such portability efforts.
JNI >>> Any other interface to C/C++.
Due to Oracle's actions, Java is not free software any longer.