I am not a supplier (2022)
softwaremaxims.com
softwaremaxims.com
To illustrate my point, let us consider the case of Net-SNMP which was one of the projects I had direct experience with back then. We had the entire source code of Net-SNMP checked into our own project repository. From that point on, it was our responsibility to understand/maintain/update/upgrade/patch/customise the code (at least the parts that we relied on). When something didn't work the way it was supposed to, it was one of the employer's developers responsibility to figure out how to make it work. If needed, sometimes we would even engage with the community around the project in their IRC channels or mailing lists, to figure out how to solve our problems and sometimes such engagement might even end up benefitting both the community and us.
But at no point there was the notion of a supplier or "they" or "them". It was always "we". We decided to take this gift called Net-SNMP. We decided to use it develop our software. So it was now our responsibility to keep it in good shape. After all, the employer's developers were getting paid for it.
Now I know in today's world of software engineering, it is no longer possible to tend to every single dependency that is pulled into a project. There are thousands and thousands of them in every project. The way software engineering is done today is vastly different from how it was done a decade or two ago. There has been a Cambrian explosion of programming languages, open source software, frameworks, ecosystems, etc. It is impractical to assume the ownership of the thousands of dependencies that get pulled into every project and I think this is why the notion of "they" or the mythical "supplier" implicitly creeps in. While this rising complexity has resulted in increased speed and agility of software development, we have lost the simplicity and clear sense of ownership of code we rely on, which I believe was more prevalent a decade or so ago.
It is pretty much the way that I look at things. It was also the way that the company that I worked for, did things.
They would never have blindly relied on some outside supply chain. In some cases, we were only given opaque binaries to add (licensing/contract stuff), but we checked that binary into CM, and it was part of our product.
Testing, calibration, accountability, etc., was all on us. If the vendor software failed, it was our failure, and we were Responsible for fixing it (which may have consisted of frantic calls to the vendor).
We also did not add any free software. Indeed, we actually paid a company beaucoup bucks, to scan our software, and let us know of any unlicensed software.
It was really important to establish full provenance of every line of code in our products. We had good lawyers.
What does this really mean? Did you use some paid language/compiler ala Borland? Did you write all your own libraries?
Without huge resources, like an intelligence agency or multinational, I don’t see how it’s possible to not use any free software. Unless these stories take place 30 years ago or something.
We just built an in memory IPC and rpc protocol on top of UDP.
You can just do that. It’s not as easy to use as grpc+protobuf.
Probably not as fast, almost certainly not as correct, but you can do it.
He dreamt up a system which is basically AWS lambdas, but calls to services are abstracted by wrapper classes so it doesn’t _feel_ like you’re making a network call.
Also, I think he just ignores what he doesn’t understand.
I asked what he was thinking about using for our front end and he suggested using wisel, which is a proprietary, mostly unknown, C# to html+css+js package. He said it “paints widgets directly on the page from c#.”
He believes that html+css+js is too complex, so ofc adding C# and a JSON style format that approximates css to the equation will make things simpler.
Probably not appropriate to say “we did not use any free software,” but we knew where it all came from.
I don’t remember the name of the company we hired, but they were expensive. They would periodically scan our codebase, in order to ensure proper licensing of everything.
Our company was a massive patent-holder, and was absolutely anal about licensing.
Sounds big and blue.
Most companies think that they can outsource this to say Tidelift and just keep treating it as a free gift from the global community
But as long as there is not a precise definition of your software stack (I am thinking something like nix plus repeatable software builds) then there is nothing the global community can do (because unless we know your stack precisely who can say what vulnerabilities exist)
I think there is an interesting new industry - software dependency provision - imagine being able to define the complete set of software, where and how it was compiled, probably using something like nix.
While it is definitely unfair to require an independent open sourcing developer to maintain there software free of charge I really like the idea of deferral of not just the knowledge embedded in open source code, but also the maintenance.
The success stories are probably big companies who open source business supporting elements of their stack. Like Meta with React: People can use react and Meta maintains it. On the other hand they benefit from other big companies sharing parts of their stack.
Also for fun, let's assume you're an American company that buys copyright ownership and complete rights of proprietary software originally developed by an Irish company. You immediately re-release the software with a new loading screen logo, "About" dialog, etc changed to your brand name, and a new SBOM is released. Which part of your Double Irish with a Dutch Sandwich corporate structure do you list as "manufacturer", "supplier", "publisher" and "author" fields? Which part of the Irish company (or whatever complex corporate structure may exist) do you list in any of these fields, if any get listed at all? If you did list the Irish company, after 5 years when most code has been rewritten but only a few small bits and pieces remain, does this change whether you mention the Irish company that worked on the software 5 years ago?
That implies that the FOSS code is garbage which we all know it is not.
> I am more than happy to become a supplier[...] which means you are going to have to start to pay me.
I'd love to see large enterprises contribute _something_ to FOSS. In many cases, they forbid their staff from contributing code and they certainly don't contribute in any way financially.
It's astounding, really, that much of our financial system relies on FOSS libraries like OpenSSL, Spring, and Apache and yet they do little to ensure its ongoing health.
That's not quite how I read it. FOSS in general (e.g. public github as a whole) is a "pile" of projects widely ranging in quality, most relatively poor. It's up to all of us to use our "raccoon noses" to find the treasures or "diamonds in the rough".
What do most people (including businesses) want? Free-as-in-beer software, because nobody wants to pay out unless they get an invoice in the mail.
What does FOSS provide? Free-as-in-beer open source software.
Suppose our Raccoon finds a fan in the dumpster. Standard electric consumer grade fan.
It might even be a really nice not-garbage fan. It's just been put out free to take on the condition that there's no liability or guaranteed support.
If the Raccoon uses the fan as expected; For personal cooling purposes. There's no problem. If the fan breaks, the original creator says "WONTFIX", the racoon is a little sad but all is fine in the world.
Suppose instead our Raccoon runs a major aircraft manufacturing company. If it were to take this fan and use the fan blade for a turbojet engine. The fan breaks now, a plane crash-lands and people are injured, the big company insists that it be repaired immediately. The original creator says "WONTFIX", and the company's VP of security is outraged. "Do you not understand how serious this is? The fan is used in a major airplane, you must fix it. It's no longer a hobby, you're part of our supply chain!"
Now obviously, were Raccoon-Boeing to use fan blades from consumer fans put out on the road free-to-take, there'd be mass outrage. Obviously the person who gave away their fan isn't liable for the misuse of the thing they gave away. They owe the company nothing. If anything there'd be riots in the streets about the Racoons being this reckless.
So why do we let software firms get away with this?
My late mother who was an accountant taught me a very important lesson about business:
Nobody's going to pay you until you send them an invoice.
Some would, but most are believing they would get paid for a hobby. Nobody is going to pay for a hobby, in part because it won't solve anything if they did
Once they are paid to be real suppliers, they will not enjoy it at all.
The vast majority of people who have ever tried to turn their hobby into a profession will tell you the same thing - if you want to ruin a hobby, add customers, standards, money, and deadlines.
While, like I said, some will be fine with this, to me the money thing is overall a huge red herring.
Strange, I would not expect any of that from any "enterprise". Most open source projects are much better at these than anything I have seen in enterprise.
Now this second part is … a little naive, but it’s quite feasible for that to become a middle ground industry. The big distributions are fine but as a thought experiment imagine a group of ISVs focused on say python web services. They can provide an immutable nix-like definition of a simplified stack, keep a treadmill of updates and security patches, probably as binaries.
I think there is unlikely to be a way such “focused distros” will ever give up warranties so perhaps we are not making progress.
However until we live in a global socialist utopia, we need to find some way of making the “raccoon in the dumpster” get paid.
Sure the legalese states I owe nothing, but if I’ve shared the code, written some documentation, and encouraged others to use it as I have on a few projects…
… I feel as though I do owe something. I feel like I’ve made a sort of social contract to provide a bit of support on what I’ve, er, “supplied”.
Not really sure why.
With software I actually understand it less. I don't do "cargo add" and then think "just imagine how good chapter 2 will be!"
So I think the analogy is good, but I disagree that the creator ever owes anything to ones benefitting from their initial work.
Objectively, yes, it's entitlement. All you can really do is avoid pop culture entirely and not start a series until the author is done writing, I guess
I believe that maintainer by participating in FOSS getting followers/contributors owes to the community good stewardship so maintenance and at least keeping security fixes and nasty bugs prioritized.
If someone doesn't want the burden then no need to publish stuff or publish it and actively discourage the use, but usually people publish and try to build a community, but when one has built a community, it comes with responsibilities as well.
Seems to me like the main -- or only -- thing you need to fix are your feelings.