First, Oracle has completely open sourced the JDK, for the first time ever. Instead of a JDK with a complex license, mixing both free and commercial features and containing field-of-use restrictions, Oracle now provides the JDK under a 100% free and open source license, or under a commercial license for those who wish to purchase a support subscription (and fund the development of OpenJDK).
Second, there are no longer major releases, and the new feature releases are similar to the old six-monthly "limited update". JDK 10, 11 and 12 are roughly the same size as 7u2 and 7u4, which also didn't get free security patches after six months. What's changed is the name given to those releases, and to make the updates cheaper and easier, they have been made more gradual, by allowing spec changes in feature releases. Not only do you get security fixes for free forever, but there are no more major upgrades.
So the main point of confusion is that some confuse the new feature releases with the old major releases, when, in fact, they are much closer to the old "limited update" releases. People see a new version number, see that that number is not freely supported beyond six months and panic, when, in fact, the old releases that were similar to the new feature releases were also not supported beyond six months. They themselves were considered "updates" to some major release, but major releases no longer exist, and the "updates" now get a new version number. See here [1] for a more complete explanation.
In addition, there's another new model, that allows organizations that for some reason need a much less gradual upgrade process than the new one -- and even less gradual than the old one -- and that is something that Oracle charges for. But because the JDK is now completely open source, other OpenJDK members have committed to backporting the fixes to provided a similar step-wise upgrade path for free.
(I work on OpenJDK at Oracle, but speak only for myself)
[1]: https://www.reddit.com/r/java/comments/bav1sy/winter_is_comi...
java.com is the website for "consumer-side" Java -- i.e. the desktop JRE. The JRE and "consumer Java" no longer exist (as they've been replaced by jlink), and so the website is out of date and largely irrelevant. I hope someone soon figures out what other use to put it to.
I am aware what OpenJDK is and who develops it, and I can handle the changes to our systems just fine, but I'm an engineer, not a manager. I can assure you that the confusion around Java is very real, as well as IT departments worrying about machines updating to a Java version requiring a commercial license.
EDIT:
I asked about the JRE autoupdater, and got this answer:
Before update, it will offer to change the license to personal use (or to get a commercial one) or remove the software. It will default to remove. You can also choose not to upgrade and not to remove and keep using an out-of-date version. And if you accidentally remove, you can still get the old free versions from the Java archives.
Thank you for asking! It all depends on the warning that is displayed, of course. I still think that our IT has a good point in blocking the update completely.
We have Java installed. As far as I know, we never told the installer if our use was planned to be commercial or personal. But in a few days, personal-use-installations will get a free update and commercial-use-installations will...
A) not get updates, through the updater using heuristics and mind-reading to divine that the installation is not personal?
B) get the update and thus be expensively out of compliance with the license?
C) have the updater present the problem to the end user and expect them to carefully consider the legal situation?
I think many people have assumed that the answer is B and are currently busy uninstalling Java everywhere, but if I understand you right the answer is actually C?
Is there more information on this anywhere? Most importantly, what is the correct official way to tell the updater ahead of time to keep the old version and never update? (We have a legacy application that uses applets.)
There is no longer a parasitic Java installation on my computer.
I've seen exactly zero sign of this. In fact, I think most _knowledgeable_ people are very happy with these changes.
Your IT department is clueless.
There are reasons not to use Java (such as it being legacy tech and the PITA that is using Spring and Maven when those are supposed to make life easier), but historic Java Applet vulnerabilities aren't one of them.
It's been a while that I've been on Windows. All development and ops have been on Linux the last couple years for me.
Thanks for clearing this up.
Anyway, the fact that you're using the updater means you're on Java 8. The five-year-old JDK 8 is past its free updates for commercial use. If you must keep using 8 (and continue getting updates) for commercial uses, you must either: buy support from Oracle (same as before for JDK 7 past its end of free updates), buy support from someone else, get OpenJDK builds from other organizations (like AdoptOpenJDK), or continue using an out-of-date version.
This has always been the case with old JDKs, except now you have a few more options than before. The best option is, of course, to upgrade to the current JDK (12), and keep getting free updates forever.
That option wasn't mentioned by the updater. :)
I don't know if that's true. I know the vulnerability group [1] has members outside Oracle [2], but I know next to nothing about that process. I'm told that nobody gets any advantage on security issues.
> They are also not releasing source for JDKs after 6 months.
What do you mean "after 6 months"? There are no longer major versions. Comparing the update schedule for 7 (a major release) and for 11 (a feature release) makes no sense. JDK 11 is more similar to 7u2 or 7u4, which also got security patches for only six months.
All fixes go into the OpenJDK mainline. What Oracle engineers won't be doing much of is backporting the fixes to old versions, which, again, aren't major versions. They won't be backporting much to 8 (which is a major release) now that it's five-years-old, either, but that's the same as under the old model.
> Therefore, users of non-Oracle supported JDKs will be exposed to a zero day attack between the time of Oracle's CVE disclosure/patch release and the time that their OpenJDK distribution creates, tests, and releases a patch. I would love to see these communities thrive, but the reality is that Oracle is strangling them in the crib by taking control of the most important support functions.
You're talking about users who choose one of the two new release models, and pick the one that's been designed as a paid service. If you're concerned about that, you can pick the other new model, which is not only free but easier overall.
Such altruism; Can they do this for the TCK? Why not? Maybe all of Graal then? That seems to be where many of the dev efforts went after some staff for those now-free, previously-closed components were either repurposed or let go. I don't mind a company trying to make money (granted, not a fan of doing it on the language itself), but we shouldn't pretend they are selfless by treating actions that other languages had long since done as special.
You think that large open source projects developed by hundreds of full-time engineers are meant to be altruistic? Spending ~$100M a year (that's my estimate; I don't have numbers) is not meant as a charitable contribution, and if it were, I'd rather companies contribute this kind of money to worthier causes than software.
> Can they do this for the TCK?
The TCK is provided free of charge to people who produce OpenJDK builds. It is not provided free of charge to people who produce non-OpenJDK JDKs.
> Why not?
Perhaps because this is still seen as another channel to fund all those hundreds of full-time developers who make this open source software. All open source projects of this magnitude -- Chrome, .NET, Android, Swift -- are also funded by various income channels. I don't think any one of those, including OpenJDK, is open for selfless purposes. That's just not how "Big Open Source" generally works. But it is a fact that Oracle open sourced the entire JDK, and many people think that's a very good thing.
Java is deeply engrained in much of enterprise software, which is slow and difficult to change. The licensing change was not given with nearly enough heads up for companies to properly assess their options and migrate to OpenJDK if they choose. From a user perspective, where it’s known that switching JDKs and updating major versions is often not a straightforward task, it sure does seem like this was carefully planned to make it too difficult to move off the JDK that just got a lot more expensive to use.
My company is dropping Oracle JDK entirely and moving to Open JDK, and over time transitioning off of java wherever possible directly due of this change. We are not a small company. It took several months just to figure out the scope of how widely the JDK was in use, we had to cut Oracle a hell of a cheque to avoid licensing issues, and we aren’t doing it again. We have a dedicated team assembled to move off of Oracle JDK now.
The general consensus of the Java leaders in our company is that this is a last ditch effort money grab by Oracle to leech money from Java, which was feared from the day that Sun was acquired.
I don't know what enough would be. This has been discussed and explained for at least a year.
> it sure does seem like this was carefully planned to make it too difficult to move off the JDK that just got a lot more expensive to use.
What? The change was that as of JDK 11, Oracle JDK and OpenJDK are the same software[1]. The same software that used to contain both free and commercial features, and that had field of use restriction is now 100% free and 100% open. If this is making it harder, I don't know what making it easier would be. If free is more expensive, I don't know what less expensive is.
> My company is dropping Oracle JDK entirely and moving to Open JDK, and over time transitioning off of java wherever possible directly due of this change.
Good, because that's what Oracle has been asking you to do[2]. Oracle JDK is now the name given to the same software sold with a commercial support subscription. If you don't want to buy support, don't use the package that includes it.
> The general consensus of the Java leaders in our company is that this is a last ditch effort money grab by Oracle to leech money from Java, which was feared from the day that Sun was acquired.
I am a bit concerned that the Java leaders in your company think that a money grab is taking a commerical offering and making it free. Oracle has now made the JDK 100% open source and free for the first time ever. To fund its development, it is also selling support for those who want it.
[1]: https://blogs.oracle.com/java-platform-group/oracle-jdk-rele...
I say good for oracle looking to want compensation for support. And thanks to oracle for keeping it open source.. and well..your comments on the matter actually feel clearer than some of the information put out by oracle themselves hehe..
Indeed.
I work on enterprise software, and we have to provide Java components for companies that require it. None of our customers want or can use anything past Java 8, and we have no plans on supporting anything past Java 8 until someone squeals.
InputStream in = Main.class.getClassLoader().getResourceAsStream(filename);
try {
OutputStream out = new FileOutputStream(file);
in.transferTo(out); // new in jdk 9!
out.close();
} finally {
in.close();
}Personally, though, I really dislike Java regardless of the version being used. I'm hoping that some day I'll be able to foist this aspect of my job off on someone else -- then I won't have to worry about it!