Do we? I do open source work and maintainership, and am happy that this is outside the control and influence of industry.
Must even this that "makes the Internet special" also bow to industry needs?
Do we? I do open source work and maintainership, and am happy that this is outside the control and influence of industry.
Must even this that "makes the Internet special" also bow to industry needs?
If a company is basing their livelihood on your library, they should (in my opinion) be supporting it somehow -- either by paying you, or paying someone to keep an eye on new versions.
The other choice is they are trusting you to fix bugs and not be malicious, which isn't (in my opinion) reasonable, as you get nothing in return.
Anyone can choose this strategy, and I don’t quite understand why more OSS maintainers don’t.
I'm very grateful for OSS projects and maintainers but this is an interesting question: is doing something for free a free pass for false promises (advertising)? If I commit to help someone for free I then have a responsibility to show up. If an OSS developer advertise their projects as production ready then they have a responsibility to honor what is promised. Otherwise it should be stated plainly that the project should not be used in production ("This is a hobby project, use it at your own risks"). Sure it's less attractive and can be incompatible with success and resume building, but it's not possible to have it both way.
Maybe it's important to you and maybe people you support -- but that has nothing to do with your right to make demands against someone who put their work out there for free.
If you need a guaranteed support model, you either do it yourself or hire a company to provide that for you. I've used _supported_ commercial software that's garbage, and I've used FOSS software which has been absolutely rock solid. Also, commercial or not, just because it's supported doesn't mean the problem will be fixed or a feature added.
If you aren't directly paying someone to be there for you, then you're trusting goodwill and/or the community at large to fill that role for you. If you need that assurance, pony up to one of the consultancies like IBM which will support "X" for price "$Y". That support you're referring to is available, at a price -- but doesn't necessarily involve the original contributors.
I've had far better luck with FreeBSD on servers for the past 20 years than I have with Microsoft Windows, but I also understood the deal: "Fix it yourself, or submit a bug report and see if anyone else wants to work on it."
The corporate software method: "Pay us lots of money to look into the bug report, and maybe we'll fix it, maybe we won't -- but you'll need to pay hourly until we determine if its a bug. Then MAYBE we'll refund your money."
The primary difference is that OSS gives you the source and the ability to fix problems on your own, without any involvement from the original contributors/projects. You can also hire any number of other companies to provide support. With a traditional commercial model, you're entirely at the mercy of the company which originated the software, and you likely have no rights to the source or tools which would enable you to fix the problem yourself.
Also tangentially I don’t buy into the binary distinction “it’s free it can be poison I can’t complain / I paid it’s my right to be an entitled asshole”. The cost is irrelevant with the promise for me, the first cent doesn’t have magical entitlement, and its absence is not a free pass to (white) lie.
There is no binary distinction and it isn't about the amount of money per se.
What you're missing is that full extent of what you can expect is spelled out in the license.
Whether it's an open source license or a commercial one, a common one or a custom one. If you don't prefer the terms of the default license, attempt to negotiate a different one. You can always negotiate. If you expect more, expect to pay more.
There is no clause in any license (that I've ever seen) that says if this project is more popular or shows up more often in search results then the license grants the recipients more support. That's not how it works. Read the license, that's what you get, nothing more.
Obviously they should be careful when picking the license, but with any of the standard licenses, they should be fine?
… PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
I think it’s particularly clear, and that part is even in all capitals.
"AS IS"
If you have a specific project in mind, have you read the license under which that project has been made available to you?
If it is under most of the common open source licenses, you will find that it already states very clearly what applicability and support you can expect (none).
You are free to pay for a support contract if you need anything beyond what the free license guarantees you.
Take it or leave it. Which works for the other side complainers too. The worm is available to be used for free by companies, because license said so.
But commercially this is unpopular because it means that companies have to actually account for the cost of maintaining a complex software stack instead of pretending all the open source dependencies maintain themselves.
Long ago at Sun the practice was that all code had to have an internal team maintaining it. If the code was brought in from outside that's fine, but some team internally still had to be where the buck stops for fixes. If all bugs can be fixed by bringing in updated version from open source, that's great. But if not, there's still a customer with a bug and it must be fixed by the internal team if that's what it takes.
Of course, this wasn't too popular with some management, since they wanted to bring in all the free code but offload all the work to unpaid volunteers, instead of budgeting for maintenance.
And I agree with you, that these people as their software ascends in use & importance, need support.
The term professionalization is dangerous to apply here though. There's a lot of baggage & constraint, power/hieraechy dynamics, employer/employee relationships that are no fun, are against the spirit of the thing. To have this vibrant, radical, free spirited altermative, & to turn around & try to consume the spirit of the thing, digest it into the the dun, boring, mundane mediocre shit-show world is a sure & sad way to wreck the thing. Yet these people deserve & need support somehow. Finding innovative ways to support those doing vast social good without binding & restricting them, without entailing them into your projects & curtailing their potential.
That all said, at this point, we just need to start funding these people far far better, step 1. These concerns about whether professionalization see destroys our golden vibrancy are abstract when so few (& only such select industrially useful) projects garner any support at all.
Do you like working for free? Do you like people making unreasonable demands?
How would you like spending the weekend like the log4j people trying to solve a Prio 0 bug?
I don't like doing free tech support for entitled mean people on GitHub, which is what you're really asking about, but I'm perfectly happy to throw code over the fence for the general public to use if they don't bother me about it.
What happens if the log4j developers just... don't fix the bug? Other people who rely on the library fork it, development continues with more funding, the world keeps turning, and maybe a few tens of millions of dollars of additional economic damage are inflicted in a diffuse fashion across the global tech industry.
It's entirely your prerogative to say no.
I’ve always found people are reasonably happy when I send them big reports — though I always either send a fix or, if I can’t figure it out on my own, a test program that demonstrates the problem.
The last time was for some random library I was writing a python wrapper for and the author seemed way too happy to be getting a bug report for the code he based his master’s thesis on. Pretty amusing to be perfectly honest.
Some people still idolized the hell out of me
Contrast that to FOSDEM, which is completely different. This isn't just an offspring of early hacker culture. This is as offspring of how "socialist" european university systems were.
A lot of bigger OSS projects were started during peoples university time and what's so fundamentally different between how universities in Europe were before? You didn't have care about graduating. Some people stayed in University for 10 years, it was free and sometimes even had some benefits, like cheaper healthcare.
Now studying forever subsidized isn't always a good thing, but it has some nice side effects, like being able to work on your side project without having to worry about your livelihood(something that is unthinkable in the US).
The European higher ed systems has gotten more and more close to the US system with the Bologna process[1].
Most Americans immediately think about how to monetize things, and don't get me wrong, being able to live off of your open source project is nice, but it wasn't the focus in the past.
[1] Free Software originated with GNU which was started by Richard Stallman, an American at MIT. Open Source originated in Palo Alto, CA as an alternative (less political, more business friendly) approach to Free Software. There was freely available software prior to the formalization of terminology and licenses from organizations like FSF and OSI, but even then most of it was from developers in the U.S.
[2] Prior to the Internet, most open source projects were heavily concentrated in the U.S. as large scale distributed projects weren't a thing until the 90's with widespread availability of Internet access.
both sides of this odd couple had different motivations and restrictions, but they cooperated in building the network and the software that ran the network. People here have complained, but I claim, TCP/IP was not the only network game in town then, and the massive scaling that you see today was not done yet, and did not work for lots of reasons. Many OSS projects related to the network itself, the signals across the network, and math/science. The media world was largely influenced by commercial print and Hollywood, and was less influential in the early days, as they stuck to the commercial distribution mechanisms. Network media tended to be odd, music-oriented, or sick things, in those early days. Also note that single, massive source code repos were not a thing, so people traded "tarballs" with important releases of whatever.
Which, by the way, took 8 years... typical length for European's who really don't feel like graduating (back in the day).
It's a bit out there, but I do believe there is some truth to op's points.
But open source projects still need a roadmap, focus and maintenance, regardless of how they are funded.
If you just want to share code, that's fine as well, but that's not an OSS project (sure, it can be an open source "project" - but not a project that grows)
Why is sharing code (as long as an OSS license is attached) not open source?
Under what circumstances am I allowed to call things I do open source, under what circumstances not?
outside of a few specific areas; like compilers but that's mainly because hardware is constantly evolving.
If you don't care about control over the downstream of your project, or funding, no one is forcing you to professionalize! I just want that to be available as an option to those who do.
Proprietary and corporate players are equally useless at securing their supply chains; I don't love that (from my perspective) they're now blaming and trying to coerce open source to become more like them to ostensibly fix the same problems they propagate themselves.
I'm not a security nihilist: I think improvement is possible. But in my experience, not many corporate managers or project sponsors ask for removal of features and reduction of attack surface.
Perhaps; some financial statistics that I'd suggest to consider would be:
- As of June 2018, U.S. households in the 0-40% income-level group had $0 median savings[1]
- From the same source: the median savings for a household in the U.S. is approximately $11k. There are approximately 120m households in the U.S. according to the U.S. Government census[2].
- As of 2022, thirteen firms from within the S&P 500 hold a combined $1 trillion in cash-on-reserve[3]
And yep, it'd be sensible to debate whether individuals or companies would be more likely to influence the direction of software; it's a disingenuous comparison to draw in that regard.
But even if we consider only individual citizens, there would still be significant disenfranchisement in dollar-voting ability.
[1] - https://www.cnbc.com/2018/09/27/heres-how-much-money-america...
[2] - https://www.census.gov/quickfacts/fact/table/US/HSD410219
[3] - https://www.investors.com/etfs-and-funds/sectors/sp500-compa...