I get the aesthetic and sentiment, but in practice this doesn't convey the reality. Having a business link or incorporate your open source software project isn't necessarily bad. At the very least, it's a social proof. There could be sponsorships, patches sent back.
There plenty examples of permissively licensed software out there that directly contradict this:
FreeBSD for Nintendo Switch and PS4, FreeNAS
Django, TypeScript, Jupyter. VSCode. Electron. Python. Ruby. CoreCLR. Windows Terminal.
Anyone of these projects, someone could fork it, rename it, repackage it as value added. It doesn't happen since the transaction incentivizes merging contributions upstream - maintaining forked code has passive costs. Pushing it back passes the burden (and also the benefit) of the changes back to the project.
> Go AGPL, they’ll avoid it like the plague.
I feel when we're thinking about gatekeeping who and uses our software and why, we're not really doing open source anymore.
In that case, writing commercial software license from scratch, or based off a permissively licensed project, and not releasing the source is an option.
I don't understand. You're saying “for the benefit of the community”, but then only speak about companies as negative examples. (1) Are companies inherently incapable of being members of the community to you? (2) Are people whose software is more liberally licensed (and may wish to incorporate parts of yours) not part of the community to you?
> never giving back
AGPL allows companies to use the product, while also guaranteeing that they contribute back. And community = entities who contribute back.
The problem is that if you're a big enough monopolist prooviding some online service that people have to use, you can do that in the open. You just comply with the AGPL and reveal all the code that tracks users or discriminates or whatever Bad Stuff. At the end of the day, the code is still running, and vast numbers of users are still logging in.
Basically, the AGPL has no real teeth; it gives the users no real control over the program they are using, only some visibility into it.
Nefarious behavior can be hidden in configurations, not just code. And in other services. Like suppose a server program, at some point in its execution, makes a HTTPS request to another server. The URL, including parameters and an POST data, are driven by data from a configuration database. Oops! Who knows what the heck that is doing? But, hey, if you want to run such a thing on your own machine, here is the source code.
I don’t consider the AGPL to be free software. My freedoms to keep my own code to myself should not change based upon whether or not I am running a web server process on my machine or not.
I think it’s just generic anti-corporate/anti-business sentiment dressed up as egalitarianism. ASPs are a feature, not a bug.
Seems to me that this is the paradox of intolerance... being intolerant of intolerance is a reasonable stance for otherwise tolerant people.
The point of the GPL family of licenses is not to solely make the author's "hard work available to the community". It's to ensure that any modifications which are later provided to other users must be licensed such that those users can make their own modifications.
Private modifications are still permitted under the AGPL. In fact, the FSF explicitly states that licenses which disallow private modifications are not free software.
> Your hard work is still available to the community.
That'd also be true if you used CC-0 or made it public domain. That's not the point of using one of the GPL licences.
> My freedoms to keep my own code to myself should not change based upon whether or not I am running a web server process on my machine or not.
The AGPL doesn't say "if you run apached on your server you must release your code to everyone who asks for it". It says that people who use your software over a network must be given the source code.
And in the context of SaaS and "online-only software" it's pretty clear why such a provision is necessary -- in the nightmare scenario, all software would be only accessible over the internet and you'd have no rights to the source code even if the code was GPL. You might not agree with this measure or the plausibility of such a nightmare scenario (and that's fine), but there is a clear ethical argument for it (and it is consistent with the history of the free software movement).
The code does all sorts of nefarious things in plain view, but you're powerless to change the installations of that code. You can't stop using those services because life depends on it. Hundreds of millions of them continue to use the services, forcing you to do the same. Most of them don't understand the code or your objections to it.
If the fictional character Don Quixote came up with a software license, it would be the AGPL. It's full of nice sentiment, but ineffective and self-defeating.
Free software licenses are mostly about your rights. You can host your own instance with your data. Stallman said on many occasions that it is not possible to exercise software freedom using a service hosted by someone else -- there is a fundamental clash between the freedoms of the users and the freedoms of the administrators. Both groups should be able to exercise their freedom, but unless the users are all administrators (of their own instances) there will always be a mismatch.
> Hundreds of millions of them continue to use the services, forcing you to do the same.
This is a fair point when it comes to social networks, because the AGPL doesn't require interoperability or the ability to federate (such terms would make little sense in a copyright license meant to be applied to all sorts of works). The real-world example would be the "fediverse" -- you could imagine a circumstance where all fediverse servers decide to block instances that don't implement $BadFeature. I would argue that in that nightmare scenario there really isn't a great solution even in theory. If you require interoperability, you've restricted the software freedoms of the other operators and now people can no longer block bad actors. But I would argue the AGPL does make the situation marginally better -- at least you could run your own (isolated) fediverse.
No, you cannot host your own global social network with millions of users, your own search engine with billions of web pages indexed, your own online shopping marketplace, not to mention your own online banking, insurance company, med lab result site, drivers' licensing site, government tax site, ... not even if the original sites run nothing but AGPL-ed software in a fully compliant manner.
The key emphasis was on your data. You can't run your own Facebook clone, but you can run your own version of Google Docs that you use on your own data.
There is simply no licensing solution that could fix the software freedom problems of such services, so it's unsurprising that the AGPL doesn't help...
>A program is “free software” if the program’s users have the four essential freedoms:
>The freedom to run the program as you wish, for any purpose.
>The freedom to study how the program works, and change it so it does your computing as you wish. Access to the source code is a precondition for this.
>The freedom to redistribute copies so you can help your neighbor.
>The freedom to distribute copies of your modified versions to others. By doing this you can give the whole community a chance to benefit from your changes. Access to the source code is a precondition for this.
By running a modified GPL project on a web server without allowing access to the source code to users you are violating all 4 software freedoms at once. Users can't run the same software as you do. Users can't change the program because they have no access to the source code. They can't redistribute modified or unmodified copies.
>My freedoms to keep my own code to myself should not change based upon whether or not I am running a web server process on my machine or not.
The user's freedom should not change based upon whether or not the free software is running a web server process on a machine or not. This is the exact opposite of your argument and it is in line with the four software freedoms. Therefore your argument has nothing to do with free software.
That is nonsense. Firstly, you can't violate freedoms, only exercise them or not.
You're just running the program as you wish, for any purpose, exercising the first freedom. Since you modified it, you obviously had freedom to study how it works and change it how you wish. You haven't exercised your freedom to redistribute the program.
> The user's freedom should not change based upon whether or not the free software is running a web server process on a machine or not.
Yes, it should; the server is my private property.
It is a social problem that people are allowing themselves to become locked to SaaS programs, and those programs are blackboxes whose behavior changes on a whim, and can be nefarious.
That problem can't be solved by turning free software licenses into screwed-up non-free licenses.
Even if you have the exact source code of some SaaS, that still doesn't help you because you don't control the installation.
Users who are stuck with some system that they are pressured by others into using cannot just walk away from it just because they don't like what some piece of code is doing (in plain view, thanks to AGPL compliance).
This is covered in the GNU licenses FAQ [1]:
> Does GPLv3 require that voters be able to modify the software running in a voting machine?
> No. Companies distributing devices that include software under GPLv3 are at most required to provide the source and Installation Information for the software to people who possess a copy of the object code. The voter who uses a voting machine (like any other kiosk) doesn't get possession of it, not even temporarily, so the voter also does not get possession of the binary software in it.
Otherwise, we're all carriers of petty human nature. And few people enjoy thoughts that for time you've torn off from your family, to help some random strangers (and user support is biggest time/effort sync for open-source project, and what makes them popular), risking family problems (re: Reiser and his FS), the eventual benefactor will be some company, making money on the popularity of your project.
Obviously, averaging over counterfactuals is difficult, if not impossible in practice, so people go with intuition. It remains up for debate which way is the better basis for a ethical decision theory.
I wouldn't put it like that. It wants to "bill" people for a grand each, and gave billions to some company. But most importantly, what about the guy who wrote that BSD code - he didn't die unable to buy medicines for cancer? No? Then it's all good.
> The bsd licence gave us the iPhone. Doesn't that benefit mankind?
The BSD license gave Apple a start to build the iPhone; Apple gave us devices that we aren’t given full access to even though we ostensibly own them. No, I’m not sure that’s a net benefit for humanity.
"In some cases, we may have alternative licenses available for AGPL licensed code."
(I still bet _mostly_ open source stuff licensed under AGPL just gets outright ignored by FAANG scale company engineering teams, rather than being embraced and convincing their boss to to go into bat to pay for a commercial license...)
Better examples for FreeBSD are Netflix, Netgate, Netapp, iX (until recently), and Dell. All make significant contributions to FreeBSD despite not being compelled to do so by the license.
The AGPL is the right choice almost all the time when you have user facing projects.
I agree, roughly, but I don’t think it’s really gatekeeping if it’s their choice not to use the software. The AGPL explicitly gives them (and everyone else) the right to use it! They just have to contribute back if they do, which is apparently too unpalatable for them.
By comparison, I’m not in favor of some of the newer licenses that attempt to carve out usage restrictions. I’ll fight the Commons Clause wherever I see it. But just requiring that they contribute back? I think that’s fair.
I exercise my choice not to use Adobe Photoshop; instead I use GIMP.
Is therefore Adobe Photoshop free software?
Certainly not! Adobe Photoshop severely restricts you as the user; for example, you're not permitted to send a copy to a friend, or to fix a bug that's bothering you, or to contribute that fix so others can benefit from it.
GIMP on the other hand is free software because anyone (including Google!) can use it for any purpose, distribute their changes, etc.
As a clarifying point, "free" here (as defined in the Free Software Definition) refers to freedom for the user, not for the developer, hosting provider, etc. A license can impose restrictions on the developer to provide more freedom to the user. For example, if you're hosting a Mastodon instance (AGPL), there's a sense in which you're the user, but to a much greater extent the people using your instance are the users. The AGPL ensures that they have all the freedoms you were given by the developer of the software.
A freely redistributed software whose license requires that it must be used while executing a headstand also ensures that when I pass it on, the next person has all the same freedoms. I'm free to use it, as long as I'm standing on my head; so is the next person.
It's basically a tautology of all licenses that allow copying, which do not distinguish among users, or among first hand versus second hand recipients.
How so?
The occasional rare project does go out of its way to define the demarcation line. For example, the kernel's authors have made it very clear the demarcation line is the user space API, so anything that relies on it is not considered a derived work. I have no doubt that is one of the reasons you find the linux kernel everywhere. But even some top tier GNU projects have similarly clear lines: not only are programs complied with the GCC not considered derived works, programs that statically link the libraries needed by the GCC compiled code are not considered derived either. And so unsurprisingly, using the GCC is not considered dangerous, despite it being GPL.
Personally, I'd like to see an [A]GPLv4, that formally defines what is a "derivative work" is or at least provide a list of choices users could include. It could, for example, exclude programs that use output of another when that output is intended to be readable by humans, and it could exclude header files and similar things that define API's. Doing that would remove a lot of the uncertainty about when the GPL is "viral" and when it isn't. As it stands, Google's blanket ban seems like a reasonable response.
In between ranting at me for about an hour he did give me that useful piece of info. The only thing I asked him.
Quite a character, that guy.