.NET Foundation under fire as resigning board member questions its role
theregister.com
theregister.com
> Concerned friends contacted him, resulting in this post, where he explains some of the background to his resignation and said: "I am fine. No issue in my personal life took me away from the board."
That's a really weird thing to write about someone without clearing it with them.
Anyway, if your point is that it isn't something super crazy to say then you're right. It looks like it was a guess, and it was wrong, and it rubbed the author the wrong way for reasons they detail in TFA.
He failed the interview.
He's the only one who talked about "acqui-hire". Microsoft never talked about acquiring anything. There was nothing to acquire.
I once interviewed a smart guy from a certain UC across the bay. Still undergrad, he played a lot with Python and wished he could have something similar to pip when doing C/C++.
So he wrote himself a "package manager" that could fetch binaries, place header files correctly and add them to his build. Neat little project.
That's basically what this guy did. It reads a YAML file and exec() whatever build instruction is in there. The CS102 guy I hired could do it as well.
Keivan was brought in by Microsoft for an interview and he didn't get the job. He kept talking about how "he could have patented this" or how it was an "acquihire" but there's nothing new to acquire in there!
But hey, he flunked his interview and got a lot of eyes on his startup thanks to some well placed clickbait on HN...
First when a board member resigned from the .NET Foundation:
https://rodneylittlesii.com/posts/topic/foundation-echo-cham...
Then this:
https://www.glennwatson.net/posts/dnf-problems-solutions
Lots of different Twitter threads on this topic since a few days. For example other OSS project maintainers also noticed that their project was moved to a different GitHub org without their knowledge:
https://twitter.com/JeremySkinner/status/1445272800185495555...
This is even worse given that the rights were NEVER assigned to the .NET Foundation in the first place:
https://twitter.com/GeoffreyHuntley/status/14453622296420270...
This whole things is EXTREMELY SKETCHY and very very concerning!
Yeah, by giving the foundation all the power it needs to relicense it however it wants.
> Of having to track down potentially 10's of thousands of contributors that may be hard to find (or even dead) to get their consent?
That's the ideal situation. Make the copyright stuff so hard no one will ever bother trying to take over a project. Linux kernel does this. It will never be licensed as anything other than GPLv2 because it's virtually impossible to obtain the consent of all developers who ever contributed to it. The more Linux grows, the more people contribute to it, the stronger this protection becomes.
Also means if the license ever loses a legal case then the project will always be susceptible to that flaw since it cannot be corrected.
Think of a license as code. It currently works, but tomorrow you may find a serious bug, or, in the case of law, laws change outside the project, making a serious bug.
Now you cannot ever fix it.
And, in common cases, it protects the project from contributors wishing to remove their contribution later, breaking the project.
Linus could get a brain tumor and decide to revoke his contributions to the Linux kernel. Or his heirs could do it, since by law they get his copyrights, including all the code he ever contributed. Guess what that would do. Or any contributor to Linux can do it.
10,000 legal minefields is not a good way to run a project.
Another example: one day the copyright protection of Linux code is going to run out. That'll probably be a very fun day.
> 10,000 legal minefields is not a good way to run a project.
Agreed. Honestly I think these licenses shouldn't even exist to begin with. Copyright needs to be abolished.
DannyBee is an open source lawyer, his comment (https://news.ycombinator.com/item?id=18148727) gives some other advantages of CLAs.
is that https://leastprivilege.com/2020/10/01/the-future-of-identity... ?
Interestingly though, there seemed to be no talk or discussion of finding new maintainers for the .Net Foundation project. Microsoft decided to update their templates for the upcoming .Net 6 to use the new, non FOSS identity server project(despite their being no real need for any identity server in these setups, and despite it no longer being FOSS).
Even more strange(coming from other FOSS platform communities) was how much shilling for Duende IdentityServer, and by Duende, was occurring in this thread discussing the development(buckle up): https://github.com/dotnet/aspnetcore/issues/32494 . Was really strange for a FOSS community to not be discussing the road forward for FOSS, but to be making arguments like "the license isn't that expensive" and etc. All this time the project is still listed as a .Net Foundation project: https://dotnetfoundation.org/projects/identityserver .
I was somewhat surprised when looking into the .Net Foundation rules that they don't require turning over the project in any way to the community or foundation. I'm wondering now if MS was just going along with the easy path to avoid even more drama while the dust settles and they shore up foundation rules to prevent this from happening in the future.
> Assignment and Contribution Models. The .NET Foundation uses either an assignment model or a contribution model for on-boarding new projects. Under the assignment model, a project transfers ownership of the copyright to the .NET Foundation. Under the contribution model, a project retains ownership of the copyright, but grants the .NET Foundation a broad license to the project’s code and other intellectual property. The project also confirms that the project’s submissions to .NET Foundation are its own original work (there are also instructions for any third party materials that might be included).
They accept both models (Contribution and Assignment).
I see all this as something that can be corrected. Not necessarily a sign of anything too sinister. (Maybe I’m too optimistic).
Admittedly I didn’t like the AppGet/WinGet story but there could be a side to that which we don’t hear about. First time I’ve heard about the IdentityServer issue - doesn’t sound great.
But MS have gone too far down the path they’re on for me to any longer dismiss their new found “open source” focus with the same level of cynicism that I once had.
There is a LOT of really good stuff happening here. It can no longer be brushed off as just surface-level pandering, which was what I used to think in the early days of their move to .NET Core and open source.
But that said, I really hope they take the lessons from this and sort out the Foundation.
[1] I exclude Windows 11 from this analysis
Then the radio silence with .NET Native is so typical Silverlight/Managed DirectX/XNA.
Less than a year after launch, just as some devs started writing windows phone apps, “we” decided to deprecate Silverlight and XNA in favor of WinRT for Windows Phone 8.
Devs were just pissed and vowed to never touch Windows Phone after that.
Also, all the customers that bought WP7 phones - they couldn’t upgrade to WP8, because “security”. These were the Microsoft fanboys and early adopters.
I left Microsoft the following year. But it looks like they haven’t improved very much over the years.
nobody moved, instead they had other needs, GO appeared, and people adopted it
what's left? people maintaining Java servers; and when it's time to switch tech, it's GO
politics is what ruined C#, now they are bloating the language with features nobody asked/needed
microsoft have the wrong culture, they are bloat oriented, and they are vendor locking driven
it's either ASP.NET or nothing with C#, that says it all
and you still CAN'T build a AOT statically compiled single file executable, you have to ship your 300 DLLs with you, even that, they couldn't improve, it's 2021, it's a billion dollar company, and yet, it's still "we are working on it", dude no, it's too late, i'll go with GO
for a while they recommended zipping/unzipping at runtime your 300+dll folder as a solution to the "single file problem", so no, you can't come up and say, "we are awesome piece of tech", because that's a pure lie, a billion dollar company
and msbuild, while it has improved, it still a joke compared to what other languages are providing, not worse than gradle or maven, but equally shitty
https://news.ycombinator.com/item?id=28655192 200mb + 300 DLLS for a desktop application, that's the "awesome" dotnet for you, even java don't do that anymore
btw. thats paint.net which comes WITH the runtime. it's not just a "small" desktop application.
now deploy a java desktop application WITH the runtime and look how "big" it is.
The correct way is to use the java linker and distribute jvm.{so, dll} alongside a trimmed runtime.
I published a single file executable just last week, what in the world are you talking about? If there are any native code DLLs you have to include 1 extra line in your .csproj file to get those to be included in the single file, but other than that it works without any issues whatsoever. Literally spits out a .exe and a .pdb file and nothing else.
NGEN, .NET Native, the pseudo extract zip, the pseudo extract zip with mmap execution,.....
https://github.com/dotnet/designs/blob/main/accepted/2020/fo...
Even in .NET 6 it is going to be "almost there, wait a bit more for .NET 7 to cover all use cases".
https://devblogs.microsoft.com/dotnet/announcing-net-6-previ...
If I recall correctly they did at least three surveys asking us what did we mean by AOT compilation.
Apparently they use another dictionary at Redmond, duh.
A lot of times, the folks responsible for welcoming the embrace part of the cycle either move on to actually work at Microsoft or elsewhere, and then the following two steps usually take place after they're gone.
Microsoft has also been really good at seeding standards organizations or pushing out sock puppet companies/representatives to advocate for positions that undermine their competitors.
There's really no long-term good practices. The short term niceties are all just to get the foot in the door to finish their cycle.
Microsoft’s super-political culture still seems to be around.
You see this in the Azure space, where everyone internally within MS seems to be trying to one-up each other.
So I’m not surprised that the .NET Foundation also suffers.
(opinions are my own, naturally)
I lost count how many PMs they had showing us stuff how great everything was going to be, on Channel 9, YouTube and now Microsoft Learn.
When you want to foster a community, you have to focus on the community. Not (only) be the legal guardianship of some (important) stuff.
And all of that I say as a .NET fanboy.
Disagree. There are people at Microsoft that "get" how important it is to look FOSS friendly in order to stay relevant in the developer community and continue to breed C# developers who will deploy to Azure.
They don't get FOSS at all though. They want to control it to their advantage and that's about the extent of which Microsoft is interested in FOSS.
The Foundation failed here in its oversight role and also sustainability wishes from the maintainer perspective. The two maintainers are just overloaded with the project and they had to start earning money with it because no one else was helping. Which again is a community problem which the .NET Foundation fails to address.
No matter. IS4 is a brilliant open source project and should have been one of the highlights of the .NET Foundation and Microsoft's relationship with the OSS community.
It's very disappointing that it's not.
I think the issues with IdentityServer was that it felt like a bait-and-switch in the timing of the commercialization decision more than anything: Microsoft replaced a lot of bespoke OpenID/OpenID Connect/OAuth libraries in ASP.NET with IdentityServer including in out-of-the-box ASP.NET Core templates. Then IdentityServer decided it needed to explore commercialized relicensing.
1. Microsoft could have done better diligence that IdentityServer was financially healthy and in a place to deal with increased maintenance and support needs before baking it into ASP.NET templates.
2. The .NET Foundation could have helped IdentityServer find a commercial licensing regime/path to commercialization that wouldn't have impacted as much all of the users now using it ASP.NET templates.
3. IdentityServer's authors seemed to be in a "take our ball and go home" mood anyway and probably wouldn't have listened to advice from the .NET Foundation had they asked. (And it sounds like they didn't from the article here.)
4. The .NET Foundation sees the root cause problem here that they don't own the projects' copyrights/licenses/CLAs and want to crack down on mandating full ownership now. The article points out this feels almost an unnecessarily rude and authoritarian response. However, as other comments here point out, this is always the harsh learning cycle of Open Source Foundations going back to the OG FSF itself, and including just about everyone (Apache, Software Freedom Conservancy, you name it).
Of those, the .NET Foundation is in the hard place of getting most of the blame that they couldn't stop IdentityServer taking their ball and going home and the rock of now trying to do the hard part that they should have done sooner to prevent this mess in the first place just a little bit too late (and making other projects feel like they are being punished even though they did nothing wrong).
Between Microsoft and IdentityServer there should have been more ways to commercialize the success of the project without relicensing IdentityServer or dropping the project from open source to spite Microsoft trying to rely on it in templates. I don't know who is to blame more there, but I don't envy how much this seems a PR disaster to the .NET Foundation.
Unfortunately, one of the primary functions of the foundation is to facilitate communication around things like this. It's clearly not done that (and issues highlighted in the article indicate more of the same problem).
Frankly, the decision to not update the FOSS project for .Net 6 or accept PRs.. Adds some flavor to the situation: https://github.com/IdentityServer/IdentityServer4/issues/535... .
The word in the GitHub issues discussions is that they are working with their lawyers to clarify, but as of right now the contribution model is an option.
Being a sort of corporate misanthrope seems baked in to Microsoft's DNA, at least from my outsider's perspective. The brief and now-concluding era of tech optimism that was born of "Don't Be Evil" has shown us that corporations gonna do what corporations gonna do.
Never trust Microsoft. You might know Microsoft employees but by and large Microsoft is not your friend.
Your job as an individual is find alignment. An individual, or even a small group, isn't likely to turn a large institution. But you can find those that have aligned missions.
Tell them to give a donation for work and a recurring salary based of continued work on the same project but under "MS Official" and upgrade it's role in the dotnet eco system.
I don't think anyone would say no to a bag of money and continuing their interests.
So "community library developers" complain when "user-developers" default to MS nugets because, hey, it's MS and tested, maintained and supported; and the same (?) "community library developers" also complain when rating system is conceived that'd help "user-developers" choose and use stable/mature 3rd party packages. Well.
I detailed this all at length here prior to defeating the initiative: https://aaronstannard.com/dotnet-foundation-maturity-ladder/
Simple file locking implementation? Why the hell would someone risk importing a nuget when they can implement it themselves in like half a day? (If you know you need a file lock, you know what's needed to implement one, the rest is about finding the docs.)
Library for scalable servers? You don't need one with async, all the other building blocks are already shipped with netcore. (Ya, maybe you won't be able to squeeze the last 5% of performance without enormous amount of work, but 99% of the projects don't need that. Those which do would probably roll their own anyway. BTW, the remaining 5% performance win from some library would easily spoiled by inefficient event handlers.)
Implying that lack of libraries akin to those in Java means that .net developers are doing non-innovative, boring CRUD stuff is extremely condescending. Maybe Java has so many more of such libraries because everything is so much more cumbersome to write from scratch in Java?
(All libraries are a liability. They'd better solve a HARD and/or COMPLEX problem that'd take 1+ months to implement before I vet them into a project. Your examples are not in that class.)
As for customers... there will always be customers for pre-packaged solutions, quality and support. Obviously .net cannot include a framework for $X for every possible X. But that does not mean that non-customers of yours are _not_ doing (approximations, to the degree they need) of X internally.
In your posts, you were complaining about the lack of innovation, yet Akka.NET (I assume that's what you're referring to) does not seem to innovate anything, it's a carbon-copy of Akka for Java and the "raw" actor model.
Project Orleans from MSR on the other hand _does_ innovate. I have a PhD related to distributed systems and I investigated the actor model a lot. Orleans addresses the deficiencies/problems with [1] it that I myself noticed.
[1] Quote from the introduction of https://www.microsoft.com/en-us/research/publication/orleans...: "Actor platforms such as Erlang [3] and Akka [2] are a step forward in simplifying distributed system programming. However, they still burden developers with many distributed system complexities because of the relatively low level of provided abstractions and system services. The key challenges are the need to manage the lifecycle of actors in the application code and deal with inherent distributed races, the responsibility to handle failures and recovery of actors, the placement of actors, and thus distributed resource management. To build a correct solution to such problems in the application, the developer must be a distributed systems expert."
> Akka.NET does not seem to innovate anything
Maybe you should ask for a refund
They can sell you the dream of x but if they feel like it, they will kill that dream faster than you will be able to wake up.
We are creatures of emotion stirred action by said emotions.
... I can't be the only one, can I?
This is a misunderstanding of what open source means. I has zero to do with community. You may think that, but that doesn't make it true. Open source is only about license. It means you, as the copyright owner, give permission for others to use the software royalty free, and you can modify the software as you wish. With permissive license, you don't even have to give us the changes you made. But you do need need to keep the original copyright.
THAT'S ALL IT HAS EVER MEANT.
Now, a lot of open-source is created in a community. But this things about how so-and-so took the source-code and ideas from another projects and reused it, whether that act is done by the big guy or the small guy, or the project you took from ends up getting killed, that's just too bad.
Don't join the game and then complain about the rules later.
You would have a point, but this isn't about open source in general. This is about the .Net Foundation, which has the goal "to improve open-source software development and collaboration around the .NET Framework" and it hardly improves collaboration when the parent organization openly acts like a parasitic ass. Of course since this is Microsoft we are talking about a strongly worded letter wouldn't have achieved anything of note either.