AGPL license is a non-starter for most companies
opencoreventures.com
opencoreventures.com
[1] https://drewdevault.com/2020/07/27/Anti-AGPL-propaganda.html
Whether or not that's true, it's reasonable for Google to warn against using an untested license that has vendors using it who specifically argue that it is completely and totally viral. Interpreting that caution as a psy-op is a bit far fetched.
(This is just me describing reality. My private software is under AGPL to a significant extent, but I understand why my employer's legal dept does not like AGPL.)
I completely understand organizations banning AGPL software. Having an employee mistakenly violate the license is just too great a risk. The majority of AGPL projects seem to be offering the same product on a different commercial license, which is the only way I'd use an AGPL project. E.g. paying for a non-APGL license to use it without the risk.
https://drewdevault.com/2020/07/27/Anti-AGPL-propaganda.html
> You may not deploy it on a network without disclosing the full source code of your own applications under the AGPL license. You must distribute all source code, including your own product and web-based applications.
> It’s a legal violation to use iText Core/Community and our open source add-ons in a non-AGPL environment.
Rather than interpret Google's page[1] as some sort of psy-op, a simpler explanation is that there are many companies who use the AGPL license and want it to be totally viral even over network calls, and since the license has yet to be tested in court it's safest to just assume it has the strongest virality possible.
[0] https://itextpdf.com/how-buy/AGPLv3-license
[1] https://opensource.google/documentation/reference/using/agpl...
This page is just even more nonsensical than TFA. This is not "an interpretation of the AGPL that is as viral as possible", this is just a custom license that tries to masquerade itself as the AGPL. For example, the following term is batshit insane:
> When using iText Core/Community under AGPL, you must prominently mention iText and include the iText copyright and AGPL license in output file metadata, and also retain the producer line in every PDF that is created or manipulated using iText.
Yeah, no. If it was really AGPL, no one would forbid me from just removing all the watermarking code AND THEN publishing the non-watermark version to whoemever I wanted to.
There's a friggin reason 4-clause BSD is considered incompatible with the GPL. The advertising clause doesn't fit into any of the additional requirements that the GPL allows you to exceptionally introduce. A watermark is even a stronger requirement.
But in any case this is like trying to find problems in the GPL from a careful reading of the MS Public License. Sure the Ms-PL is a viral license from one of the "major software vendors of all history", but it is NOT the GPL.
If I write, say, a Java servlet that relies on an AGPL library, then by the same mechanics as effect GPL software, my servlet must now also be AGPL.
Now I host my service and the servlet runs, sending content to whoever made the request. Whoever made that request to the servlet over the network is now entitled to the source code of the servlet. This is what the AGPL does.
That whole effect stems from the original GPL, the AGPL just mucks with the new concept of network access being akin to the GPLs original use of distribution.
If the library was just a GPL library, now even though the servlet is, now too, GPLd, there’s no obligation for source code release because the servlet was not “distributed”. Simply used on site of the servlet developer.
Now if the original request is routed through a proxy, does the AGPL apply? Does the AGPL somehow “infect” the proxy? If not then a proxy is a simple AGPL firewall. If it does, let’s host some AGPL services and start make requests of AWS and Cloudflare for some of their source code.
Which sounds pretty silly.
The handwavey part is - what is "the application"? And they are not going into specifics there - it is, of course, only the application that you build it into. It doesn't virally extend to other things that interface with it over the network, and they're not going to say that part.
You naturally can thus build a minimal "wrapper app" that just provides this library-as-a-service according to some interface, so that you didn't have to release your whole program, but, it is not a misrepresentation that if you use iText core then at least this program will be bound by AGPL and must be distributed.
This is it.
I find it a compelling argument there is tremendous risk to AGPL if Google says so. They not only talk the talk but walk the walk: Google just indemnified AI (C) without limits putting 1.7 trillion dollars behind that statement. The same company said "nah, we are afraid of AGPL".
I would not consider a DB schema or SQL running on a server to be derivative of the AGPL DB server's code. A judge/jury might however. Then all of my SQL and any wrappers calling it become infected.
This same question doesn't come up in a DB server licensed under the GPL, even v3. It's unlikely anyone could successfully argue that client node never publicly distributed could ever be considered distribution and therefore not derivative of the GPL code.
Because there's not much if any legal precedent it's not really propaganda to be concerned by AGPL projects. It doesn't matter what is technically true. It only matters what a judge or jury can be convinced of to ruin a business. The AGPL opens more uncertainty than the GPLv3 which opens more uncertainty than GPLv2 or less viral licenses.
I'm talking, of course, about the Class path exceptions.
Any derivative works of AGPL-licensed software must also use the AGPL.
How a court interprets "derivative" here makes a big difference, that Drew doesn't seem to effectively counter. I'm not sure why his take on what it means will make a difference to what a judge may think it means.Until AGPL is tested over and over in court, and all interpretations converge on Drew's interpretation here, it's not safe to have anywhere in your commercial stack.
There's a license that actually works this way, namely the eupl. If drew is especially interested in having a license that works this way, perhaps he should consider adopting that license instead?
May I ask how you go about it? Dual license?
It's a very simple business model: people pay me money, and in return they get a copy of the software and the complete corresponding source code, and all future updates to the software for 365 days.
Good software, when licensed freely, is more competitively advantageous than an equal proprietary counterpart because it does more for the customer.
Copyleft licenses like AGPL don't. They require the user to share their modifications.
And this is the whole point: that everyone shares in the wealth of free software. And if someone makes a program better, those modifications can be reincorporated into the original work, making it more valuable.
Free software is about computer USER freedom, not DEVELOPER freedom. As a user of software, I want that freedom, and won't settle for anything less. That's why I write free software, because it's the software I want to use.
> Free software is about computer USER freedom, not DEVELOPER freedom.
What are non-developers going to do with source code? Back when FOSS was first conceptualized, all users were developers.
Regardless of anyone's opinions on the issue, the fact of the matter is that AGPL quite specifically don't let people do "anything" with it. The software comes with obligations. That is the entire point of copyleft. Sure, you might think the obligations are good -- that doesn't mean they don't exist.
What do you do when your car is missing a feature that you want? You bring it to a mechanic, and you pay them to add the functionality you want. The GPL means freedom.
And telling someone they need to respect the freedoms that you grant them is not restricting their freedom. It costs nothing to share your source code, and it should be the default state of software development. It's like the silliness around the tolerance paradox. An action that creates more freedom in the world can never be seen as "less free" than one that doesn't.
I agree with this. However, I don't personally believe AGPL does this as equitably as some other licenses.
Except for AGPL, which can require sharing your modifications even if you are not distributing copies of the modified work. Indeed, that was the whole point of AGPL.
> It requires the operator of a network server to provide the source code of the modified version running there to the users of that server.
MIT and BSD have requirements you must fulfil too. You can't just "do whatever you want" with them.
----
I don't normally reach for this level of pedantry, but some takes in this thread just boggle my mind.
Although on that note, I find it somewhat funny to speak about something like the MIT license as conveying "rights", when half of the license's purpose is to take away the licensee's legal rights.
MIT/BSD licences do not take away any rights from the licensee. They merely avoid giving licensees certain rights that would otherwise be understood to be automatic or implicitly granted alongwith the copyright licence.
Like when Anakin was reminded by Mace Windu that his seat on the Jedi Council does not grant him the rank of Master.
It's crazy to me how it is completely normal for engineers in other fields to be held liable for shoddy work, but many software engineers think they're upholding users' rights by giving them software that prohibits users from holding them responsible for their work.
These limitations exist solely out of convenience for the author.
If a company calls you up and says they are uncomfortable with your license, surely that's a tremendous opportunity. You can negotiate whatever you are both comfortable with.
If a company doesn't use your software, makes money some other way; doesn't email you support questions, so they cost you nothing, gosh, isn't that okay too?
I don't see what the big problem is with the AGPL.
If some company like Google doesn't allow AGPL-licensed software, that's fine. I guess it serves its purpose, forbidding leeching?
> While the downloadable version is open, the SaaS version is closed off from open source collaboration, innovation, and competition.
Somehow they critisize that the original author is able to do, what all other companies would do if the author used GPL instead of AGPL.
For example Qualcomm's allegations against ARM last year (that ARM was "preventing 3rd party IP from being in proximity to ARM IP" etc) appear to have been entirely false and untruthful, but people didn't critically consume that and largely worked on the assumption that if QC said it, that it must be true. A year later, has anyone else had problems integrating 3rd party IP into ARM designs? No? That's because it was just Qualcomm going to the tech media with a bullshit story, and they dutifully carried it.
https://news.ycombinator.com/item?id=33419138
https://news.ycombinator.com/item?id=32675376
It's happened over and over even in the tech community: Google and the "pwease open up imessage and use RCS" page (while their proprietary encryption extensions lock everyone else out), MS/sony/epic/facebook/netflix levering open the app store/sideloading, blindly believing the EVGA ceo when he implied that poor lil EVGA barely made any profit during 2020-2021, and that this was also true of the other partners (as they scalped onto ebay, like MSI, or sold at inflated prices through first-party stores, etc) etc. People are not critical thinkers when they are presented these sorts of messages in media, they tend to assume that if it's in media it must be true, or if a company PR spokesperson says it then it must be true.
(and in fact this is a perfect example of a why there is no reason to "assume good faith" when a megacorp is trying to push a particular PR spin, and it is in fact not helpful and usually incorrect (Hanlons' Razor is wrong as a heuristic) in these PR battles. PR messaging of all things does not deserve or benefit from the application of hanlon's razor.)
I touched on all these same themes of media-illiteracy at the time too. These were pretty unbelievable stories at the time and it was very obvious that people were uncritically consuming PR spin. https://news.ycombinator.com/item?id=33822020
Anyway, back to present-day: obviously Google/Amazon/FB would very much prefer a permissive-license model where they can take the fruits of the open source community and privatize the profits (and build proprietary extensions) while contributing nothing back, whether that's apache-licensed code or RISC-V core designs. So it's in their interest to push back against commercial operators who can counter-negotiate and re-internalize those profits, or AGPL that encumbers them from doing this in the first place. But people are so very very credulous about these "pwease be nice to widdle google, we're so helpless and innocent" thinkpieces.
It's just crazy to me that it keeps working over and over, even on the HN crowd. It seems like hanlon's razor has really become a thought-terminating cliche for a lot of people, it is an excuse for credulity and avoidance critical thought. Why bother? Malice doesn't exist, hanlon's razor is always the simplest answer.
I'd guess that even here, probably less than 25% of people are media-literate, in the sense of being able to sniff out a story that doesn't make any sense overall, or identify a source as a PR spin piece. People genuinely assume that if Google puts out an article analyzing a license or something that it must be factual and balanced, or at least not contain any intentional misrepresentations, etc. And as you can see from qualcomm, or google's own RCS article - this is not always the case! Companies do just go and lie, or spread PR that is true "from a certain perspective", etc.
https://arstechnica.com/gadgets/2022/08/new-google-site-begs...
People used to pride themselves on "having a finely-tuned bullshit detector" and we've just replaced that with hanlon's razor. bullshit doesn't exist, hanlon says so. it is a sad state of decline for critical thought. but people love a good thought-terminating cliche.
Isn't that.. the point? If I were to licence something AGPL that is what I want to happen. Folks can use it freely but only I may use it commercially (with the option of licensing to businesses who also want to make some cash off it)
Am I just being dense?
Even that is not true. Of course you can use APGL'd software commercially, you just have to make your own modifications accessible.
Does this mean they've given every one of their employees legal permission to take a copy of the GPL code and its modifications home with them and distribute it as they please?
The legal permissions apply to an employee receiving the code, yeah? After all, the employee is a person and I don't see any special rules about employees in the GPL license?
Google might say that their employment contract supersedes the GPL in some way. But to the extent that their employment contract limits the GPL, to the same extent Google is not in compliance with the GPL license.
It seems to me that any one of the hundreds of Google employees could just walk off with the modifications and sell them or release them however they choose. All legal. It would be an action Google has explicitly given them permission to do in legal writ.
(I am not a lawyer, this is not legal advice. This is just my limited knowledge of the law and a bit of logical thinking.)
Maybe the counter argument is that the employee isn't using the software. The business is.
I've heard people have the legal theory that because there's no explicit copyright reassignment in their contract, they actually own the code they write as employees. Somehow I doubt that'll fly.
And as another reply you got said, GNU also thinks you're wrong.
If you simply 'find' a copy, GPL doesn't necessarily apply. And employees in most circumstances are not legally 'given a copy' - just as if the employer hands them a wrench to work with, that doesn't become the employee's wrench, and that applies to all kinds of copyright issues, any prohibitions to sublicensing don't prevent the product being used by employees because it's never licensed to them, etc.
If you're a Googler working on a personal project and you accept that Google owns it (controversial), then you would just use GPL software the normal way any developer would. If you're a Googler working on a work project, then you compile and link it into your application. If you wanted to modify GPL software, you'd sign the CLA for the project and send them patches.
I did not see anything that would suggest Google was not complying with GPL. We were advised to not make new projects that used GPL, as copyleft and the license are challenging to understand compared to the relatively straightfowrad BSD, MIT, and Apache licenses.
If so, my argument does not apply to Google, but may apply to other big tech companies. I mentioned Google only as an example--a place holder for any big tech company.
It seems any company that hosts modified GPL code can't stop their employees from just walking off with it and selling it.
Not sure why you're so concerned by this use case, it doesn't seem particularly important.
Sure they can, just don't distribute the code. The company holds the copyright to all code the employee wrote, if the employee took the code, they'd be violating their employer's copyright.
See the GNU FAQ on this - https://www.gnu.org/licenses/gpl-faq.en.html#InternalDistrib... - and slightly more elaboration at https://opensource.stackexchange.com/a/10459/
I'll file that under “works as intended.”
Combining both even more so.
Especially copyright assignment, for anyone employed as a programmer. Aka a professional.
So at least for the creators, the license does not seem to have been a rousing success, although that is of course completely anecdotal.
This is why no business will touch AGPL or any other copyright license that has network clause with a ten foot pole.
This is why if you write a book, you can license it to a publisher to print copies of it and sell for profit without them automatically gaining the right to adapt your book into a movie.
Once i have a legal of copy of code, i can do anything i want to it even if the copyright license forbids it as long as i don't distribute the code. I can make as many private copies as i want and deploy it on as many servers as i want without trigger copyright law.
It restricts a whole lot of things. E.g., display, adaptation, performance — hell, even translation.
For example, under US law, a copyright holder is expressly allowed "to determine and decide how, and under what conditions, the work may be marketed, publicly displayed, reproduced, distributed, etc."
And this is just from the list of "Economic rights". Copyright also includes sth it calls "Moral rights" which has nothing to do with copies being made. If you post on Xitter claiming you wrote the LOTR books, you are technically in infringement of the moral rights of J.R.R Tolkien.
----
When you say, "I can do anything I want to it even if the copyright license forbids it as long as I don't distribute the code", you are very conveniently (and illegally) ignoring the copyright holder's exclusive right to control how their work is displayed or performed.
--
If that were the case. Movie rental videos wouldn't exist. Neither would libraries. Like i said you have to make a copy for the a copy right license to come into play.
I'm going to the first company that sell product under AGPL that i think about and check who their client are.
List here: https://www.nexedi.com/success
If you don't want to click, here are the most known:
- EADS (airbus)
- GKR international group
- Sanef (i know it because i worked for them on a fraud detection project, but they're less known than the others)
- Mitsubishi Motors
I think that's okay for a non-starter.
If "venture capital firms" like these complain about not being able to harness libre tools to build their digital serfdoms without giving anything back, it means the AGPL is working.
> it’s unclear what other code may be exposed to the virality of the license. The fear is that a company could be forced into open-sourcing software that was not intended to be open source.
wikipedia says agpl was brought in 2002. so around 21 years of people using this license and no one knows clearly what it does?
>if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network
this is the most important part of the license that everyone just gleans over.
There is no SSPL-like virality in AGPL.
you can use unmodified AGPL code alongside proprietary code, all you have to do is put the license file up there.
IF you modify the code, that modification NEEDS to be shared to customers on demand. That's it.
this means if i use AGPL software in a SAAS environment and i modify 1 character line from a file, all i have to do to comply with the license is to make that DIFF or modification available to customer saying "i used AGPL software ABC, here is the modified version".
that's all there is to it.
edit: > It’s founded on the ethical principle that all software should be free.
Free as in freedom. If you get a readymade code for a software, all this license enforce is that you can't use it to fork it into a proprietary software and not giving your downstream users the same rights you were given.
>Many corporations will forbid end-users from installing any AGPL-licensed code on corporate devices out of an abundance of caution.
this may be a reality but doesnt make it any less bullshit. i recently read an auditor might flag using open source software, like what? Please prove me wrong about AGPL
Not commenting on the rest of the article but “usage” does not equal “understanding”. Plenty of people use computers without an understanding of what they’re doing or capable of. Plenty of people use AI models today without understanding what they’re actually doing. Heck a huge chunk of modern medicine is stuff we have no understanding of how it actually works, we just know that it does and have a small amount of empirical evidence to give use some fuzzy boundaries.
AGPL and GPL do have a linking exception, but only for those two licenses and nothing else. (at least not as I read it - I'm not a lawyer)
One could add that as an extra clause.
It's not easy but one should always recursively check the licenses of every dependency. If one doesn't, one can't even enforce a ban on AGPL software because it might slip into a project deep inside the node_modules directory or the equivalent in that code base.
A simple implementation could be looking for LICENSE files or files containing some keyword. If the file matches the standard licenses you know what they are. If they don't, they could be custom licenses and should be checked.
IMO, it's even somewhat likely. It's entirely unclear why the legal system would care whether something is statically linked or dynamically linked with regards to interpreting derivative works in software, so the question would likely boil down to simply "does linking a library make the application a non-fair use derivative work of the library"? If no, then there is no difference between the LGPL and GPL. If yes, the status quo remains.
> wikipedia says agpl was brought in 2002. so around 21 years of people using this license and no one knows clearly what it does?
The fear referenced here isn't about what the license does. The fear are the unknowns about how it will affect business operations in the future after building a business around a piece of code with that licensing obligation attached to it.
> you can use unmodified AGPL code alongside proprietary code, all you have to do is put the license file up there.
You cannot. AGPL only has one linking exception, and it is for code licensed with GPL.
What companies want is if someone does violate a licesne they can argue it was a rouge employee and so ask the court to just apply a small monetary damage fine as opposed to something large [like opening up all code a AGPL demands]. However in order to argue this in court they need to show the court they made a good faith effort to ensure violations didn't happen in the first place. Those are good enough that most companies won't violate the license in the first place.
For example, the founder of iText feels very strongly about this. As you can imagine, that makes iText almost impossible to use in a commercial setting, if you want their AGPL version. You need to buy their commercially licensed version.
"If user A pushes a button in product X, and by doing a technical effect is triggered that results in an action in (A)GPL library Y, then product X needs to be released under the same license as library Y to user A no matter how product X is technically implemented!"
https://entreprenerd.lowagie.com/chapters/c13.html
https://itextpdf.com/how-buy/AGPLv3-license
https://entreprenerd.lowagie.com/ossurvival/index.html
https://www.slideshare.net/iTextPDF/ianal-what-developers-sh...
Such a situation can persist indefinitely if nobody wants to go to court.
Cry me a river. Start with the fact that I only publicly post software that I'm at least notionally willing to support. If you demonstrate competence and ask nicely, I might have other software to offer just to you. ;-)
On the software that I publicly post I generally use an Apache license. I use the AGPL on a very specific and unique piece of software where I want to maintain architectural control: show me a use case which can't be pushed right or left and we can talk.
In fact, I give away examples for that software in a separate GitHub repository under the Apache license. The principle is simple: if you substantially transform the data separately from my software, you don't need to give your transformational workings away to the data consumer as long as you do it separately from my software. Shift right, shift left; here is effing how.
I would be surprised to see my AGPL product exposed to the internet (even with a proxy in front of it). I don't want it modified and exposed to the internet as a cheap hack by self-serving sociopaths who figure they're justified in "by any means necessary" by their high salary, I would view that as dilution and AGPL is preferable to having to contemplate suing for disparagement when the inevitable shitstorm happens: if you're going to expose it to the public, I want to see the software. Expect me to read it and comment on it publicly.
So internally you shift left / shift right, and the people working on it have access to my source code: what's the problem?
> While the downloadable version is open, the SaaS version is closed off from open source collaboration, innovation, and competition.
This is blatant sociopathic projection where the author's own intent, or that of their owners, is transferred to the Other and then disparaged. In any case if they did a SaaS version it would be closed off from such collaboration.
The author isn't going to spend their own money and is not the decisionmaker so declaring "negotiate a licensing or support contract, or pound sand" is a waste of time.
MIT/BSD are free as in free tech support.