I was wrong about Red Hat's EULA and its enforceability
jeffgeerling.com
jeffgeerling.com
There is a lot of back and forth as to why RedHat is employing this footgun now. It comes down to them feeling, in part, that they are footing the development labor bill while rebuilders (Oracle Linux, Rocky Linux, Alma Linux) reap the rewards and undercut them on support contracts. The other part is enterprises and SMB running thousands of CentOS/non-subscription EL variants and having a token number of RHEL subscriptions to use for support any time they get into trouble.
The real solution to the second problem is to explicitly forbid it within the RHEL support contracts and enforce that. You are either a RHEL shop or you are not. Make it a binary decision. This weird tactic of trying to kill off the customer alternatives is going to just kill off the EL ecosystem in the end. I know I abandoned the EL ecosystem entirely when CentOS Stream became the thing.
They've been, and continue to be, fantastic stewards of the Linux ecosystem. I use many of their inventions today on my Linux workstation and my experience would be decidedly worse without. I am grateful for their continued pledge to OSS: it's so much further ahead of any other big tech company with their revenue, you'd think they were the loonies.
Most companies are doing a mix of OSS and closed source with OSS the core that's dressed up in proprietary services you can't do without. It's the Microsoft strategy, the Docker strategy, the VMware strategy, and on and on and on until most conference showfloors are ghastly apparitions of OSS fun with the real party in their "special sauce".
When Red Hat buys a company's tech stack, they take the time to open source all of its components.
We are truly living in the most insane times of privilege when we blow up in the most petulant outrage for a company saying, "here's the sources, you prep it if you want to sell it".
Rocky and AlmaLinux are not ethical paragons here, in the least.
I think the reason for the initial uproar was this[1]:
Q: Will the source code for Red Hat Enterprise Linux continue to appear on git.centos.org?
A: Yes, the source code for Red Hat Enterprise Linux will continue to be published on git.centos.org. Nothing will change about how the source code is published. This change is only related to the binaries the CentOS Project is building and how they are published.
They struck that answer and replaced it with:
A: June 2023 Update: CentOS Stream is now the location for public RHEL source code, sources will no longer be published to git.centos.org.
The problem is for any downstream users (not just the 'freeloaders' or 'license abusers'), the main reason they remained in the RHEL ecosystem after the great CentOS to Stream migration was because free clones (Rocky and Alma) appeared in the wake of that decision.
Timing is important here. Companies and individuals were working on migration from CentOS 7 to 8 when CentOS 8 was killed off 2 years into a planned 10 year cycle.
Then once companies and individuals started migrating from Rocky/Alma 8 to Rocky/Alma 9, in the middle of the next 10 year support cycle of offering git.centos.org code dumps, Red Hat rugpulled the second time in as many release cycles.
Red Hat is within their rights, but I don't think they are 'in the right' either in the way they announced the change, or in the timing. And IMO in the way they are treating the response ("we do so much good, so it's okay for us to have a EULA which is against the spirit of FOSS/GPL").
Also, the discourse started getting weird when there were implications by Red Hat leadership someone did something so bad to trigger this sudden change, yet nobody will say who it was.
I admittedly don't know much about the Rocky/Alma situation, but it would be great if instead of vague accusations, someone would speak up because right now, for downstream users, it is annoying to have Red Hat imply one of these two orgs (maybe both?) is doing something nefarious, but to not know which one.
No company is gonna open itself up to libel lawsuits by naming a company that did something “bad” when they didn’t even need to state the fact that something bad happened in the first place.
Don’t expect Red Hat to name a company here.
I disagree with this. I view them as one of the main factors in what I see as the ongoing degradation of the Linux ecosystem. But reasonable people can differ -- I suppose your stance probably depends on what you value in Linux.
This is going to be a slow death, they are cutting out people who also contribute to different projects upstream. They don't know how to grow any-more; RH used to do some goodwill, now they think that badwill will work better.
We should expect that "not invented here" syndrome of RH will only get stronger.
You're perfectly free to share the source code. By the way, nice business you have there; shame if something were to happen to it.
I don't know the whole situation, but it sounds like RedHat has created additional licensing terms for their GPL covered software, which would fall foul of 4 above, meaning that RedHat itself may not use any or distribute any of the GPL software it currently distributes?
There is no clause in the GPL that says, “if you get one version of the software, you have the right to all future versions”
The idea that someone can take GPLv2-licensed code, build a platform/product on top of it, then coerce people to not share the source code after becoming a customer through a threat of ending their business relationship... that's what people take issue with.
I do too, though as I said in the OP, I agree it seems they're in the clear, legally-speaking.
FWIW it's arguable whether GPL3 was even needed to close the Tivo loophole, since GPL2 includes "the scripts used to control compilation and installation of the executable". It's unfortunate that none of the major kernel copyright holders are willing to litigate
This whole GPL with contractual restrictions was tried before by Sveasoft (WRT54G firmware). They ended up failing and becoming a footnote in history, but Redhat is obviously much larger and more significant to the overall ecosystem.
As far as I can make out all RH has done is said "we're no longer spending our own money to support downstream projects and forks of our products", and everyone seems to be saying that they should not be allowed to do that. Which seems to be a very clear statement that RedHat should be required to spend time and money writing code to support other projects, whether or not those projects contribute anything, or are well funded.
This bit seems pretty clear cut:
>6. Each time you redistribute the Program (or any work based on the Program), the recipient automatically receives a license from the original licensor to copy, distribute or modify the Program subject to these terms and conditions. You may not impose any further restrictions on the recipients' exercise of the rights granted herein. You are not responsible for enforcing compliance by third parties to this License.
I can only assume that RedHat is saying "This part of the system we wrote entirely ourselves, and so while you are bound by the GPL we are not"?
the loaded words "freeloader" and to a lesser extent "copycats" .. misses an important aspect of the real lifecycle of GNU/Linux software.. maybe you have heard of a book about tech markets called "crossing the chasm".. one part of that book says that there are easily four layers to participation and customers with tech in some markets.. you can imagine those four yourself because there is more than one valid diagram, but basically developers and their employment or income is innermost, their immediate dependencies for inputs, and their most rabid consumers are second, most customers and business relations of varying flavors third, and then "the Chasm" .. a catchy term to say that getting to those outside the regular channels, is very challenging.
So in the RedHat so-called "copycat" case, the immediate downstream fill an important role in getting to the fourth+ layer.. there are more informal, unexpected, temporary or otherwise oddball cases than anyone can imagine. So in a growing and evolving network, the full, paid product from the original brand name source is aided and abetted by these immediate downstream distros. That's not the same as simply counterfeit on black markets. Neither is it low effort, since these two distros Alma and Rocky, show long-term commitment and good skill levels. Those are valuable growth themselves.
What this "squeezeplay on the copycats" does is remove growth at the edges for lots of people, and consolidate revenue in the center, at RedHat. This is common knowledge among MBAs, and they do it all the time.
For my use case, I’d just be interested in the server side stuff, but I don’t know how important desktops are for the RHEL styled distros.
But just in case, I’ve started practicing on Debian 12.
The whole point is to essentially freeload off the money Red Hat is investing instead.
There’s probably a great business to build on a RH fork, but the Rocky Linux one isn’t it.
With bug for bug compatibility, that’s indeed an accusation that will linger.
A fork would arguably re-establish moral high ground.
I for one would enjoy a Debian stable alternative in the rpm/dnf eco-system.