WEKA Responds to Allegations Made by MinIO Regarding OSS Licensing
weka.io
weka.io
Instead, this is a strong refutation and, if everything WEKA says here is true, it is much less certain that they've done anything wrong and it seems like it's on minIO to prove that they've used minIO software subject to AGPL rather than only to Apache.
Previous HN discussion: https://news.ycombinator.com/item?id=35299665
Just really curious, I've seen that term language lots and never really gave it much thought until now. Surely this must have been fought over before. But I'd have expected a lawyer drafted response by WEKA to cite case law and any governing state/national law. Just saying "see the contract says irrevocable so that's that duh!" feels kinda odd.
--
Edit: Also to be clear, this is all purely dependent on any license terms actually having been broken. If none were then yes that'd be that. It just seemed like WEKA was making an argument that MinIO couldn't revoke no matter what.
MinIO has taken this to other extremes, including believing that your config file for MinIO is subject to AGPL. Even if you assume that an implicit dependence on an API is making the calling code AGPL, MinIO has the least strong claim for their service being infectious, because their API is mostly a reimplementation of S3.
This is like the "are Java APIs copyrightable" case all over again, except the people who are threatening legal action didn't even invent the API.
[1]: https://min.io/compliance
"When MinIO is linked to a larger software stack in any form, including statically, dynamically, pipes, or containerized and invoked remotely, the AGPL v3 applies to your use. What triggers the AGPL v3 obligations is the exchanging data between the larger stack and MinIO."
Their interpretation is so extreme that using a browser would require me to open source the browser. If I used a shell script to test if the service is running, I'd need to make that open source too.
There is also this: "Passing configuration parameters to a MinIO binary instance constitutes making a modified version, as it does not produce an exact binary copy."
How do they know it doesn't produce an exact binary copy? Maybe my x86 computer is quantum based.
I'm pretty sure if I compiled MinIO with a proprietary Golang implementation, MinIO would want me to open source the compiler.
They also include their trademarked logo in the git repo., then try and tack on a supplemental policy about that later. Which you can't do, because the AGPL grants you a license to the logo.
When they wrote it, they set $Company to "Weka". Given the overall interaction and beyond-curious legal interpretations they are making and publishing, I read it with $Company set to "MinIO".
Also what I find interesting is they accepted community contributions without a licensing agreement. So they in fact can't switch to AGPL without written consent from all those contributors.
The FSF has an example of how to comply with the AGPL (specifically the "prominent notice") when using an AGPL licensed proxy that is pretty illuminating. They recommend you just show a landing page with a big reference to the AGPL on the first request. I'd like to see them do that with an API Gateway.
So what we have here is a very detailed description of what they are claiming is a violation, then a refutation that is very strong, but also doesn’t actually address some of the claims in the other blog, as far as I can tell.
There is a blog from minio that says they switched to AGPLv3 in 2021. It’s unclear to me from the screenshots whether the software is later than that or not.
I hope someone takes the time to do an independent analysis, and a more neutral take.
Note that Weka redacted the language from the Apache license that says “subject to the terms and conditions,” which (not a lawyer) seems to allow a copyright holder to deny permission if they’re not meeting the conditions of the license. Whether they are or not is another question.
It's not that detailed; it just says "there is a minio binary, and that's our minio". Okay, but what version is that? This is the crucial part, because Apache vs AGPL license makes a world of difference.
The Apache attribution requirement seems satisfied; perhaps not as prominently as minio would like, but there is no "prominence requirement". It fails to demonstrate any AGPL code is used, although according to some other comments the monio people have a unique and interesting interpretation of relicensing where they think they can retroactively relicense Apache code to AGPL. The claim that backporting any security fixes would trigger the AGPL is also suspect; typically many security fixes are simple in terms of code changed, and tend to be fairly easy to re-implement independently once you know the description of the problem. Either way, "it's likely that [..]" doesn't really demonstrate much of anything and is certainly not "very detailed".
In short, the minio post is vague and full of assumptions; even without this rebuttal I wouldn't put too much stock in it as it seems borderline FUD.
However looking at the warp version in the screenshot, version 3.40 is licensed under AGPL.
[1] https://blog.min.io/new-minio-console/
[2] https://blog.min.io/from-open-source-to-free-and-open-source...
Since the S3 API largely remained the same over the last two years, it might be an option to use the Apache version, if AGPL is not possible. Of course, that would lack security fixes that were done in the meantime.
There is also a discussion [1] about that license change.
[0]: https://github.com/minio/minio/commit/069432566fcfac1f105367...
https://github.com/minio/minio/issues/13308#issuecomment-929...
Lets just say they have a weird take on what constitutes agpl-compliant
Indeed, I don't think that's correct. That depends on the definition of "connecting" but I was under the impression that if you use MinIO on a server, the services that connects to MinIO don't need to be open-source. Only the server component that include MinIO need to be, and only if end users are connecting to that component. But correct me if I'm wrong.
> Combining MinIO software as part of a larger software stack triggers your GNU AGPL v3 obligations.
> The method of combining does not matter. When MinIO is linked to a larger software stack in any form, including statically, dynamically, pipes, or containerized and invoked remotely, the AGPL v3 applies to your use. What triggers the AGPL v3 obligations is the exchanging data between the larger stack and MinIO.
AGPL is true open source.
That's not true, I am in contact with many business using AGPL software. (Not Minio specifically)
Some businesses choose not to touch it, but that's their losses.
You’d be shocked to find out but linux is also run by cloud providers and offered as a service (in the form of VMs).
And unfortunately because of murky water of what constitutes “derivative work” in agpl (case in point - see the title of this thread) most companies won’t ever touch agpl licensed projects
Meanwhile they cannot get their software to work on ext4 and it is apparently ext4s fault[0].
[0] https://github.com/minio/minio/issues/16602#issuecomment-142...
What's really important here is the person who closed the bug did some summarily, with little to no explanation, other than a reference to O_DIRECT not being supported in ext4, and therefore it "loses data" in production. This is an unprofessional comment to close a bug and I'd expect one of the co-founders of MinIO to do a better job. See https://ext4.wiki.kernel.org/index.php/Clarifying_Direct_IO%... for a discussion of the subletly of O_DIRECT. It's also not really required to make a production filesystem reliable, and would only be a tiny part of an overall reliability solution (because drives themselves often buffer and reorder their writes, sometimes even lying about whether data was "commited durably to disk")
https://github.com/minio/minio/discussions/12895
Trying to read and understand.
This eventually surely lead to a lawsuit where this is tested, but in the meantime I would avoid MinIO at all cost. The commercial license to self host it is minimum $1000 per month for 100TB.
> If you distribute, host or create derivative works of the MinIO software over the network, the GNU AGPL v3 license requires that you also distribute the complete, corresponding source code of the combined work under the same GNU AGPL v3 license. This requirement applies whether or not you modified MinIO.
> To "modify" MinIO means to copy from or adapt all or any part of the work in a fashion requiring copyright permission, other than the making of an exact copy. The resulting derivative work is sometimes referred to as a "modified version" or we say that it is "based on" the earlier work. > Passing configuration parameters to a MinIO binary instance constitutes making a modified version, as it does not produce an exact binary copy.
and what derivative works mean:
> Combining MinIO software as part of a larger software stack triggers your GNU AGPL v3 obligations. > The method of combining does not matter. When MinIO is linked to a larger software stack in any form, including statically, dynamically, pipes, or containerized and invoked remotely, the AGPL v3 applies to your use. What triggers the AGPL v3 obligations is the exchanging data between the larger stack and MinIO.
Needless to say that's all completely wrong and just FUD. I think the FSF should get involved they are damaging free software as a whole. Incredibly scummy company.
If you chose a permissive license and then are shocked when people actually take advantage of that, you kind of deserve what you get. If you chose a reciprocal license and someone just ignores it, then I think you still have a license to complain. Pun kind of intended.
(ignoring that they may be wrong about the breaches of the license, I'm sure the lawyers will work that out)
Nobody forces me to choose an open source license. Nobody forces me to use code that is open sourced either. So it’s a curious attitude to take issue with a company that providing software under an open source license as a bad guy for complaining when people don’t follow their license but not the entity that is violating the license that gives them the right to use software in the first place.
> At the end of the business day on Friday, March 24th – without warning, provocation, or even providing WEKA with an opportunity to review and respond to their claims – MinIO issued a public statement that made several false and baseless accusations against WEKA. It was the first time MinIO had made us aware of their concerns.
> Also NOTE: I need to remind you are under AGPLv3 violation here if you are using MinIO with proprietary purposes. Please consult a software lawyer for more information.
Or this: https://github.com/minio/minio/issues/13308#issuecomment-929...
> Also, just want to mention that the AGPL license requires that all software connecting with MinIO be 100% open source for you/your users not to be in violation of the license.
All that AGPL actually requires is that you share the source of your server, if you modify it.
So they would consider my Arq backups to MinIO a license violation? What if I access the GUI from a Windows PC? What about a Linux PC with a proprietary GPU driver?
- MinIO: more trouble than it's worth, as demonstrated here
- Radosgw of Ceph: not really suitable for a single server install
- Garage (https://garagehq.deuxfleurs.fr/): Their writing about the distributed design didn't convince me in 2022.
- https://lakefs.io/ Haven't studied
Neither Weka nor MinIO and definitely not the community.
The way MinIO accusation was worded, felt like this a reaction to someone saying "Boss, they've ripped us off and are earning from it and not attributing us, here's the proof, revoke their licence."
And the way this response is worded, feels like, "Check everything if we're using their stuff, get a lawyer to draft a response, and tell them, this is not the way to handle it."
I hope both parties resolves it soon.
If WEKA is using Apache-licensed software in compliance with the Apache license (as they claim) and is being accused of doing something else by a company with, let's just say, non-mainstream interpretations of license terms, I do have empathy and sympathy for them. (They claim that's what's happening. MinIO claims something else. Several of these claims are pretty much testable facts and I'm sure someone with time and motivation will test them.)