Oracle's JDK 17 – Free Again for Commercial Use
infoq.com
infoq.com
It was a B2B outfit, had maybe 30 customers running a dozen different products that the customers hosted themselves. The product was critical to business and the customers were large and part of critical infrastructure. Even a short outage would have made it into the news. What I'm saying is it wasn't a place where you could just hope for the best while migrating JVMs, everything needed to be tested and re-tested from every imaginable angle.
This was extremely expensive, but in the long run, it was still a lot cheaper than ponying up for oracle licensing costs.
I don't work there anymore, but I doubt they are repeating the process to migrate back, especially given how well OpenJDK works.
this page https://dzone.com/articles/how-much-does-java-cost
gives $28,500 pa for a 200 core runtime
that sounds negligible compared to the engineering investment that was preferred instead.
the logic of a commercially supported license is obviously the engineering depth of the original author's knowledge and in particular being able to refer to the authoritative / canonical answers
were savings the only objective?
if so, what did the savings get? anything better?
I remember reading years ago about the FB vs MySpace fight. MySpace was (I think) .NET on Windows with SQL Server. Every extra machine cost a fortune in licensing. Whereas every FB machine was PHP/MySQL. It matters.
A lot of companies operate with a dozen or so servers, and most startups never need to scale beyond that.
Can you trust Oracle not to raise the pricing in the future, given that they've raised it once already?
No
What did you migrate to? Another build of the OpenJDK? But it's the same code, isn't it? What's the difference that mattered to you?
Right but why? I'm not an expert in the difference but isn't it literally exactly the same code and functionality? What were you doing in that migration time?
Well what do you think the differences in the code are?
For example here's a list of patches that Corretto applies to standard Java 17.
https://docs.aws.amazon.com/corretto/latest/corretto-17-ug/p...
It's uh... empty except they change the brand name!
Some older Java builds do back-port a tiny number of fixes early. But why would you use an old version?
> you test once that it starts up at least, no ?
How does that end up taking a significant amount of time and money?
JDK-8210483 was a regression bug, you pass javac certain Java code which it handled fine in JDK 10 and earlier, in JDK 11 javac would crash with an assertion failure. Oracle fixed this in JDK 12 then backported it to JDK 11; the backport made it in to Oracle JDK 11.0.3, but missed AdoptOpenJDK 11.0.3 and wasn't in AdoptOpenJDK until 11.0.4.
I suppose this is a relatively rare scenario, but due to that bug we could not compile one of our internal apps with AdoptOpenJDK until 11.0.4 came out, whereas Oracle JDK 11.0.3 would compile it fine.
Even though that was a couple of years ago now, I'm still not going to assume that an Oracle JDK build and a third-party JDK build are going to have the exact same set of bugfixes, even if they have the same version number. This is why I think it is important to thoroughly test any migration between different vendor JDK builds before deploying it to production, even if in theory they are supposed to be identical. And even though that testing may be a relatively small amount of work for any given app/microservice/etc, multiply that across dozens or even hundreds of them and it all starts to add up.
In the past, definitely. But aren't all recent Oracle JDKs just OpenJDK builds?
I don't think you would. I was trying to address incompatibility fears as a reason not to move off of it.
haha
Such a surprise, knowing that the two is one and the same..
Furthermore, Oracle JDK still isn't as free as OpenJDK: https://www.linkedin.com/pulse/oracle-java-release-17-now-fr...
The license has a lot of nuances in it. OpenJDK is great and I honestly don't see a real reason to use the Oracle branded version for anything anymore.
Why such big cost? Changing JDK is just replacing some binary installed on server or at client.
"Surveys suggest that Oracle's JDK distributions are not the most popular Java distributions anymore. Developers seem to prefer OpenJDK distributions from AdoptOpenJDK (now Eclipse Temurin), Amazon, Microsoft, Azul, and other vendors. These organizations also provide commercial support for their distributions. In the case of Eclipse Temurin, Azul offers such support."
debconf-set-selections is your friend.
Your monthly bill would be $60k. Presumably you would negotiate some additional discount, but still...ouch.
https://www.oracle.com/us/corporate/pricing/price-lists/java...
I beg to differ. The majority of their products are flawed and outdated. I'm not talking Oracle DB or Java but the vast amount of other apps they sell.
They bought lots of stuff, pull funding from development and redirect it to sales. Then they sell it to fit their vision; but nothing integrates cleanly and you'll be spending massive amounts of money on consultants who understand product A & B and how to connect them.
A java-dev can't do that; you need that A and B knowledge + integration skills. Those consultants are very hard to find and good effective ones nearly non-existent. The fees are enormous regardless of whether you use Oracle consultants, Oracle partners or freelancers. If you do manage to find cheaper consultants (offshoring most likely) be prepared for terrible quality as well.
Ow, and once you're finally comfortable with their stuff after spending all that money, be sure to make a reservation for the unexpected additional license fees they'll slap on you because you failed to remember the fine print.
I had the "pleasure" of working with Oracle BPMS 10 at one point. It was a piece of crap they'd acquired (but apparently a better piece of crap that the other ones available at the time that the team had evaluated). It has pretty much zero code reuse features, and the consultants had taught the team to do stuff like cram all kinds of barely-related stuff into one "screen" so parts could be "reused." Getting support for all the bugs in 10 was extremely painful. It seemed like there was one guy who know what he was doing, and the rest just repeatedly asked for more logs. BPMS 11 was a rewrite with no migration path offered (but by the time that came around I'd noped out of that team).
The team eventually re-implemented everything in Activiti before support for BPMS 10 ended. BPMS 12 might have had a migration path (IIRC, a crappy one), but by then Oracle had burned their bridges.
As someone who has done a bit of Oracle installation I disagree:
It is worse than Windows.
And no, not an Oracle employee, but actually employed by one of the Java main contributors, quite easy to find out which one, although I speak in name of the Java community unable to write proper Java on Android, while ISO C and ISO C++ are fully supported.
Also, java is one of the few languages with complete specifications, instead of saying that here is the reference implementation, what it does is the spec.
But it's not available at any price for independent implementations like Dalvik (I'm sure if it were merely a matter of money Google would've paid up). Most people who built the Java ecosystem were bait-and-switched: we were told the language would be free and the trademarks etc. were just to stop incompatible implementations, but that turned out to be false.
> Also, java is one of the few languages with complete specifications, instead of saying that here is the reference implementation, what it does is the spec.
Allegedly. Given that there are no independent published implementations (various organisations claim to have independent implementations but none of them are readily available), we should be sceptical in practice.
Then how are there plenty of independent JVMs that can legally call themselves Java?
The acquisition made a lot of sense. I was a lowly minion in Oracle when talks between SUN and IBM fell apart, and I told everyone I met "it would be great if we bought them"... After the acquisition, I expected MySQL to die a horrible death and actually it kinda survived (although barely), which I thought was somewhat magnanimous. I was hoping they would just offload some of the stuff that simply didn't make sense (Oracle selling word-processors and chat clients, really...?), but sadly some busybody repackaged them into embarrassing products. And for years they went "business as usual" for Java, actually re-igniting development in a suspiciously proactive manner, which was great... until the day the license changed.
By “that outcome”, I’m of course talking about the hatred of their business practices rather than the OpenJDK.
Worse thing for Oracle than people not paying for their JDK is people moving away from Java altogether.
Unfortunately they migrated from adoptopenjdk to adoptium back in September and have yet to provide repos.
Microsoft however makes it very easy to install their build in linux.
https://docs.microsoft.com/en-us/java/openjdk/download#linux...
It’s just marketing. Adopt spent a lot of money on marketing in the right time.
I've never really considered Azul as I wasn't interested in the GC or JIT complier. Looks like their Zulu (non-prime) builds don't include them anyway.
Is "Oracle OpenJDK" option in IntelliJ safe?
Yes, it always was.
(Oracle JDK != Oracle OpenJDK)
Let's be grateful they haven't done so yet. I'm not convinced there is sufficient talent to carry on OpenJDK without Oracle (contrary to the OpenSolaris→illumos situation).
Why? Wouldn't the community come together and implement any features Oracle tries to lock away in their proprietary version?
Surprised that Java is in the same position.
In 2021, corporate Open Source is often just a response to the market pressure of genuine FOSS. If there's no community-based product, then users are always at the whim of the dominant company, and they can choose to leverage that dominance at any time.
The same people who believe Linux will take over Windows on Desktop for 20 years. I am still surprised human dont learn much from history.
All non-android JVMs depend heavily on OpenJDK.
To put it another way, I'm sure the Kotlin community is big enough to continue developing/maintaining their own JVM implementation (or just use the Android one). I don't think the Java community (that is, people who contribute to open source Java code; not just enterprises that use Java) is big enough to continue development of the Java language.
The only natural candidates I can think of would be Google or Eclipse Foundation. I don’t see Google picking up development as very likely given their legal history with Oracle, and I think Eclipse Foundation would very quickly become stretched unless organisations like IBM are able to lend money and developers.
That being said, I think one of the more exciting futures for Java involves Eclipse taking a leading role in the development of the language and the reference JDK. I view them as the most important non-profit working in the Java ecosystem, and they are already stewards of Jakarta EE.
The "community" is underpinned by corporations. If you look at the top trendy languages they're generally created or heavily supported by large corporations.
It's not all about the music, man.
Unfortunately they do not for the most part. Obviously there are exceptions but they are fairly rare.
Actions speak loudly.
Plus there's GraalVM. Graal and OpenJDK are actually totally separate teams inside Oracle, who compete with each other! They have different licensing, versioning etc models too. And they've written an entire JIT compiler from scratch, which other firms are also developing expertise in (Twitter, Spotify). So even if OpenJDK changed a lot, that wouldn't necessarily imply Graal would change too.
And also thank you, for giving many companies the necessary push for them to realize Oracle's JDK was not the only game in town and many others could deliver a perfectly fine JDK.
There are few things worse in this business than being labeled an "unreliable partner" and Oracle is being seen as just that even at big companies. Oracle's wisdom to pull this kind of bullshit is already legendary, the Open Solaris train-wreck, the MySQL writing on the wall, the OpenOffice implosion, the JDK shoot-in-foot, those samurais at Oracle's board sure know what they're doing..
Maybe KSplice deserves a spot on the list too, it's far from dead but used to be promising and isn't now used much outside Oracle.
The only mystery is Virtualbox, which somehow escaped death and is still useful.
Virtualbox was poisoned to take over the whole VM desktop "business" and then.. it stayed there. Not dead but not much vitality going on.
Poisoned is what Oracle did to it with the plug-in and extension licensing nonsense.
Which are almost all just tiny changes on OpenJDK, developed almost solely by Oracle. So who actually deliver a perfectly fine JDK? Also, what do you even mean by JDK shoot-in-foot?
No thanks to how Oracle eviscerated the JCP (Java Community Process) and reduced to rubber-stamping Oracles roadmap.
My reasons, aside from just licensing concerns? It came with a public long-term support commitment, and was deployed by AWS themselves on internal services before it was released publicly.
Very pleased to see this move as well. It's taken a very very long time, but it's encouraging to see Oracle finally understand the open source ecosystem.
Contrary to their litigious image, they are more than great stewards of the ecosystem and they do undertake open-source.
Without Oracle, there wouldn't exist Java 17, MaximeVM made into GraalVM, J/Rockit JIT cache as OpenJDK DSA, J/Rockit monitoring as Flight Recorder,....
And everyone could enjoy Java 6 with the JIT and GC improvements the FOSS community is known for, when there isn't some big corp sponsoring the work.
A voluntary samaritan committing yet another driver for this IBM entreprise controller, or that Facebook file system?
Linux is "community-of-big-corps"-developed.
The Linux Foundation was intended act as the backstop here, but it is losing that focus, and I'm not confident that it will remain a trusted steward in the future.
For now, and to the point here, the sheer number of meaningful contributors to Linux is what differentiates it from things like Java and .NET. GCC is somewhere in the middle: less resilient than Linux, but more than Java.
However, I don't see any benefit to this latest change in their stance. Everyone already had to wade their way through the confusion from that initial licensing change, and many (most?) spent a lot of time and effort getting to a new stable configuration on a different distro. Why spend more effort, again, to run back to Oracle JDK? I think most organizations have better things to do than deal with all this.
Also, who's to say Oracle won't change their licensing deal once again for Java 21?
Translation, everyone stopped using our stuff in favor of the GPL version, that sucked so we changed the terms on ours to be free for commercial use. I bet they collect data and resell it but that is just a guess.
It's also probably worth financially supporting Oracle if you make substantial money from Java-based software. Oracle is by and large responsible for the platform that you are using.
Mmm... That's an interesting theory, but one does not really know if the money will be spent on tightening down the Java platform and legal attacks or technical improvements[1]. In practice it probably does not matter either way as that company is not cash-constrained in any shape or form.
[1]: https://www.globalnerdy.com/2011/07/03/org-charts-of-the-big...
If you're making Java, you'll have to count up the beans
Oracle is not to be trusted.
Thay did this same thing with OpenOffice.
At the rate things are going, MySQL would also get this in the next 10yrs.
Oracle wants to extra as much resources as possible from any product. And when they realise the tech world has moved on, would try to throw a hinge to the wheel.
Also, it’s really easy, just use OpenJDK (not adopt) packaged by your distro and stick to the latest version, which will continue to get security updates forever, will be much more performant, etc.
In the rare case you need to sit on an older version that is no longer getting security updates, OracleJDK may be preferred as they employ the actual people working on the JDK, and not just backporting commits from the most recent version. So eg. a deprecated feature may not get a security update in time with some other vendors, because it will not have commits from upstream.
* Updates for the life of the distro version support policy.
I seriously doubt it'd be any more performant. They're all just doing a build of JDK from the same central repo.
I'm not sure what that means, exactly. Will the Debian package have unpatched security vulnerabilities for several months at a time?
[1] https://www.debian.org/releases/bullseye/amd64/release-notes...
I guess Debian users should stick to Java 11 then, which is presumably covered by security updates as usual? Is this documented somewhere?
So as with most java vendors, you pay for the support.
If you stay on the latest JDK, then this was never relevant to you. If your company is not nimble enough to do that, then it could pay for the tired dinosaur patches and stay on old JDKs. Since other companies have started contributing to the effort of tired dinosaur patches again, it's no longer necessary for Oracle to charge a fee to produce them.
In other words, Oracle successfully averted a "tragedy of the commons" by asserting property rights long enough to make others behave and stop abusing the system.
They include a bullet list in their release notes for the differences. At this point probably the biggest differences are that usage logging is only available with Oracle's build, and the Oracle build requires 3rd party crypto providers to be signed.
Other than that it's license difference, branding, and the installer does some things differently.
https://www.oracle.com/java/technologies/javase/17-relnote-i...
If you want to make a comparison: Docker is more like Sun. They will have three options:
1. Go bankrupt
2. Get bought
3. Find a way to make money
In docker's case they are on the bankruptcy trajectory so now they have to make choices to change that trajectory (or select option 1 and go bankrupt).
They'll have to boil the kettle much slower, like Microsoft and Apple do.
Also, making the last 1.5 (LTS+1 year into the next LTS) years free probably doesn’t mean a serious profit loss, as those primary come from things running Java 8 for another decade still.
2. They provide images for OpenJDK.
It would be very logical move to just provide Oracle JDK LTS image.
There are plenty of software which would be based on those images. They could use Oracle Linux as a base to somewhat indirectly promote it.
https://container-registry.oracle.com/ords/f?p=113:4:1094175...
Or if you prefer OpenJDK: https://container-registry.oracle.com/ords/f?p=113:4:1094175...
The Oracle v. Google suit was in the end about Google copying the Java APIs (via Apache Harmony). While the case was ongoing Google migrated to the OpenJDK, which Oracle provides under a GPL+Classpath exception. With the case now decided, as long as Google adheres to the license Oracle has provided to them there's no controversy left.
That said, I'm truly curious who's going to buy and resurrect the SCO name next.
[1] https://www.scribd.com/document/521927059/Order-Approving-th...
> [For LTS Oracle JDK versions] security updates will be available for a total of three years. After that period, further use of the Oracle JDK in production requires a commercial license.
Apparently the business model is having commercial customers deploy Oracle JDK and suing them as soon as they forget to upgrade after three years.
They can't sue you for using OpenJDK.
But what is your opinion, everything should be free for big companies to use and then who pays the developers? Even in Linux world you need to pay to get extended LTS support.
The person you replied to didn't say anything against paying for support.
Since when is it grueling? 8->9 was slightly hard, but mostly due to old dependencies doing shit with sun.misc.*, they shouldn’t have and it took time to update them. But even a Java 1.1 class file will run just fine on Java 17, and with the strong encapsulation enabled in recent versions, no hard update will come again (as the internals are not reachable from code, they are free to change)
"This application requires JRE #" -- end-user Googles JRE # and downloads/installs it.
End-user organization gets sued by Oracle lawyers for 10K site licenses for JRE #. Sure, they COULD have downloaded OpenFerretMongrelAsphalt JRE Pi, but yet, here we are...
> OpenFerretMongrelAsphalt
Ignorance is bliss, I guess. Your loss.
To compare I find a licensing situation on mid-size (50+ direct dependencies) or larger project much harder to comprehend - you need to figure out what licenses are used, if they can be used at all due to the requirements and company's policy, if they are compatible with each other and what's required for distribution.
One good example is what is meant by "LTS". You get different answers to that question depending on which JDK it is.[1]
I don't remember another language where it was ever this confusing.
[1] More detail: https://www.javacodegeeks.com/2019/07/long-term-support-mean...
You can hate oracle all you want for some of their other segments, but they are insanely good at managing the Java ecosystem and we should be thankful for that.
You can't run an old version of Python and continue to get security and performance backported fixes. Same thing with GO or Ruby or Swift.
I can't remember what Microsoft does for .Net, but I suspect you also need to always be on the newest CLR to get updates.
I think this is one of the major differences with the JVM, in a way, it has more options and vendors which should be a good thing, but it seems to mostly confuse people.
Dotnet LTS versions have three years of support. LTS versions come out every two years, so there is a year of overlap.
The non-LTS (which they call Current) have 18 months of support.
The distributions that matter here are for the JDK, which simply provides the "full" Java runtime along with developer tools such as javac and jlink.
sudo apt-get install openjdk-8-jre-headless -y on ubuntu. Works fine with UniFi Controller. (what do you think they use on the cloud key?)
The extension pack covers "Support for USB 2.0 and USB 3.0 devices, VirtualBox RDP, disk encryption, NVMe and PXE boot for Intel cards." according to the website.
https://www.theregister.com/2019/10/04/oracle_virtualbox_mer...
Nothing is forcing Oracle to "routinely check log files for downloads of the VirtualBox Extension Pack from nonresidential IP addresses and contact unlicensed users to enforce compliance" (per https://en.wikipedia.org/wiki/VirtualBox#VirtualBox_Extensio...). They could easily just say "this software is free for commercial and non-commercial use."
The choice is not ‘this model or nothing’, Oracle is about the only company this aggressive.
(Apr 2018) - https://old.reddit.com/r/sysadmin/comments/8ffcg3/oracle_is_...
(Sep 2019) - https://old.reddit.com/r/sysadmin/comments/d1ttzp/oracle_is_...
This feature is mostly useful when you want to ship a particularly stripped down version of the JVM for footprint reasons.
For server stuff one points to a matching dockerfile, for distributed stuff one bundles the jre with the tools since java9.