Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1164541 > unrolled thread
| Started by | Kentaro HAYASHI <kenhys@xdump.org> |
|---|---|
| First post | 2023-08-18 08:40 +0200 |
| Last post | 2023-08-18 15:40 +0200 |
| Articles | 8 — 5 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1049999: vagrant: the future of packaging vagrant in Debian Kentaro HAYASHI <kenhys@xdump.org> - 2023-08-18 08:40 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Gwili.Stifter@EasyMailer.live - 2023-08-18 11:40 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-18 13:10 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Lucas Nussbaum <lucas@debian.org> - 2023-08-19 07:00 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-22 17:10 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Guillem Jover <guillem@debian.org> - 2023-08-24 02:00 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-24 14:10 +0200
Bug#1049999: vagrant: the future of packaging vagrant in Debian Gwili.Stifter@EasyMailer.live - 2023-08-18 15:40 +0200
| From | Kentaro HAYASHI <kenhys@xdump.org> |
|---|---|
| Date | 2023-08-18 08:40 +0200 |
| Subject | Bug#1049999: vagrant: the future of packaging vagrant in Debian |
| Message-ID | <H41jj-2Fcq-3@gated-at.bofh.it> |
Package: vagrant Version: 2.3.4+dfsg-1 Severity: normal X-Debbugs-Cc: kenhys@xdump.org Dear Maintainer, * What led up to the situation? HashiCorp adopts the BSL. https://ir.hashicorp.com/news-releases/news-release-details/hashicorp-adopts- business-source-license-future-releases-its Currently, vagrant 2.3.4+dfsg-1 was packaged in debian. * What exactly did you do (or not do) that was effective (or ineffective)? Should we keep non-BSL licenced version (A) or drop it (B)? * What was the outcome of this action? Plan A. - Update to 2.3.7 and hold it. (2.3.7 is the last non-BSL licenced version) - Follow a newer version only when BSL limitation expired (4 years). - As a result, we can't use newer feature in timely manner if you stick on packaged vagrant in Debian. Plan B. - Drop vagrant because of that changed licence and no need to keep older vagrant. - No vagrant avaiable in Debian. Just use upstream's package. * What outcome did you expect instead? N/A
[toc] | [next] | [standalone]
| From | Gwili.Stifter@EasyMailer.live |
|---|---|
| Date | 2023-08-18 11:40 +0200 |
| Message-ID | <H447w-2HaX-45@gated-at.bofh.it> |
| In reply to | #1164541 |
Source: vagrant Followup-For: Bug #1049999 Plan C. - Move BSL-licenced versions of vagrant into debian's non-free section.
[toc] | [prev] | [next] | [standalone]
| From | Antonio Terceiro <terceiro@debian.org> |
|---|---|
| Date | 2023-08-18 13:10 +0200 |
| Message-ID | <H45wB-2I8w-3@gated-at.bofh.it> |
| In reply to | #1164559 |
[Multipart message — attachments visible in raw view] — view raw
Hi, FWIW, I have been maintaining vagrant in Debian for several years. Thank you for raising this as I have been too lazy to push this discussion. I am copying the Debian Ruby team plus all the people that I could find listed as maintainer or uploader of vagrant related packages (mostly plugins, vagrant-*, but also other related packages) so that they are aware. TL;DR: I will not be maintaining vagrant anymore. On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote: > Package: vagrant > Version: 2.3.4+dfsg-1 > Severity: normal > X-Debbugs-Cc: kenhys@xdump.org > > Dear Maintainer, > > * What led up to the situation? > > HashiCorp adopts the BSL. > > https://ir.hashicorp.com/news-releases/news-release-details/hashicorp-adopts- > business-source-license-future-releases-its This is the second time a package to which I dedicated extensive amount of my time is made effectively non-free by its corporate upstream. The first time was with Chef: while the license itself was not changed, they started imposing trademark-related requirements that would impose a large amount of busywork to keep something that looks like Chef (Cinc, their "community" fork) in Debian. I decided to just give up, and moved on to using something else. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959981 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=963750 This is now my second time with this, and this time HashiCorp actually made new versions of vagrant non-free. I have used Chef Inc and HashiCorp stuff for free for several years, but I also put in a large amount of work to make their tools available trivially to Debian users by taking care of those packages in the Debian archive. Both Chef Inc and HashiCorp care a lot about having people that use Debian consuming their products, so much so that they provide binary packages for Debian. But they don't care at all about the time of downstream maintainers, and why would they? They are private companies trying to maximize their profit at the expense of whoever is in their way. In this case, HashiCorp is apparently trying to counter other companies who are selling solutions based on their tools that compete with them, they have no incentive to care about the time of a few individuals. I don't see this change as a particularly evil move, but it effectively destroys my motivation to continue working on it. > Currently, vagrant 2.3.4+dfsg-1 was packaged in debian. > > * What exactly did you do (or not do) that was effective (or > ineffective)? > > Should we keep non-BSL licenced version (A) or drop it (B)? > > * What was the outcome of this action? > > Plan A. > > - Update to 2.3.7 and hold it. (2.3.7 is the last non-BSL licenced > version) > - Follow a newer version only when BSL limitation expired (4 years). > - As a result, we can't use newer feature in timely manner if you stick > on packaged vagrant in Debian. I had already looked into this, even before the relicensing being announced, and it turns out that vagrant 2.3.7 has a few extra dependencies that would need to be packaged too (something like 3 or 4 NEW packages), and I wasn't ready to put the necessary work in yet. After the news came out, I gave up on doing it entirely, since after this vagrant would be a dead end. > Plan B. > > - Drop vagrant because of that changed licence and no need to > keep older vagrant. > - No vagrant avaiable in Debian. Just use upstream's package. I think keeping a stale version of vagrant in the archive is worse than telling people to just use upstream packages. As far as my volunteer time is concerned, this is the most likely outcome. I have some private notes on my requirements for a vagrant replacement, and when I reach a conclusion I will most probably pursue this path and just move on. On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote: > Source: vagrant > Followup-For: Bug #1049999 > > Plan C. > > - Move BSL-licenced versions of vagrant into debian's non-free section. I will not maintain any packages in non-free. Hopefully, being burned a second time will teach me to not put my volunteer time in non-copyleft packages provided by a single corporation.
[toc] | [prev] | [next] | [standalone]
| From | Lucas Nussbaum <lucas@debian.org> |
|---|---|
| Date | 2023-08-19 07:00 +0200 |
| Message-ID | <H4me5-2SpY-13@gated-at.bofh.it> |
| In reply to | #1164565 |
[Multipart message — attachments visible in raw view] — view raw
Hi, This license change is so disappointing... On 18/08/23 at 08:07 -0300, Antonio Terceiro wrote: > > Plan B. > > > > - Drop vagrant because of that changed licence and no need to > > keep older vagrant. > > - No vagrant avaiable in Debian. Just use upstream's package. > > I think keeping a stale version of vagrant in the archive is worse than > telling people to just use upstream packages. A follow-up question, especially in the case of Plan B, is: what do we do about Debian Vagrant images provided on Vagrant Cloud (https://app.vagrantup.com/debian/) ? A/ continue to maintain them. But as the main uploader of those images in the recent times, I might not continue to maintain them, especially if I move to another tool for my own uses, so we might need to look for other volunteers. B/ stop maintaining them B.1/ ... and remove existing images from the 'debian' Vagrant Cloud account B.2/ ... and leave the 'debian' Vagrant Cloud account as it is currently I don't think B.2 is a good idea. > Hopefully, being burned a second time will teach me to not put my > volunteer time in non-copyleft packages provided by a single > corporation. Note that the fact that Vagrant was using a non-copyleft license is not entirely relevant. The same relicensing could be achieved by organizations using a copyleft licence with a copyright transfer agreement for external contributions. (I suspect that this is how it was achieved for other Hashicorp products, but I haven't checked). Lucas
[toc] | [prev] | [next] | [standalone]
| From | Antonio Terceiro <terceiro@debian.org> |
|---|---|
| Date | 2023-08-22 17:10 +0200 |
| Message-ID | <H5Bb3-3E62-3@gated-at.bofh.it> |
| In reply to | #1164674 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, Aug 19, 2023 at 06:46:06AM +0200, Lucas Nussbaum wrote: > Hi, > > This license change is so disappointing... > > On 18/08/23 at 08:07 -0300, Antonio Terceiro wrote: > > > Plan B. > > > > > > - Drop vagrant because of that changed licence and no need to > > > keep older vagrant. > > > - No vagrant avaiable in Debian. Just use upstream's package. > > > > I think keeping a stale version of vagrant in the archive is worse than > > telling people to just use upstream packages. > > A follow-up question, especially in the case of Plan B, is: what do we > do about Debian Vagrant images provided on Vagrant Cloud > (https://app.vagrantup.com/debian/) ? > > A/ continue to maintain them. But as the main uploader of those images > in the recent times, I might not continue to maintain them, especially > if I move to another tool for my own uses, so we might need to look > for other volunteers. > B/ stop maintaining them > B.1/ ... and remove existing images from the 'debian' Vagrant Cloud > account > B.2/ ... and leave the 'debian' Vagrant Cloud account as it is > currently > > I don't think B.2 is a good idea. I agree. Just as we provide cloud images for proprietary platforms, I think we as a project want to control what is available as "Debian" for Vagrant users, just like we do with images targetted at proprietary cloud platforms. > > Hopefully, being burned a second time will teach me to not put my > > volunteer time in non-copyleft packages provided by a single > > corporation. > > Note that the fact that Vagrant was using a non-copyleft license is not > entirely relevant. The same relicensing could be achieved by > organizations using a copyleft licence with a copyright transfer > agreement for external contributions. (I suspect that this is how it was > achieved for other Hashicorp products, but I haven't checked). Yes, that's true.
[toc] | [prev] | [next] | [standalone]
| From | Guillem Jover <guillem@debian.org> |
|---|---|
| Date | 2023-08-24 02:00 +0200 |
| Message-ID | <H65Vv-3XqF-9@gated-at.bofh.it> |
| In reply to | #1164565 |
Hi! On Fri, 2023-08-18 at 08:07:44 -0300, Antonio Terceiro wrote: > FWIW, I have been maintaining vagrant in Debian for several years. BTW, thank you for having done that, it's been much appreciated! > TL;DR: I will not be maintaining vagrant anymore. > On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote: > > * What was the outcome of this action? > > Plan A. […] > > Plan B. […] > On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote: > > Plan C. […] There's perhaps a: Plan D. - Package Vagrunt (https://github.com/vaagrunt/vagrunt) a fork of Vagrant, that is stated should remain free software. And as it does not have a CLA, if it gets several contributions it will be increasingly hard to relicense. - Transition from vagrant to vagrunt via a transitional package. (We use Vagrant at work, and I'm not planning on relying on a non-free tool, so a fork would do, otherwise I'd have to look into alternatives for us to switch to.) > Hopefully, being burned a second time will teach me to not put my > volunteer time in non-copyleft packages provided by a single > corporation. While it's certainly true that contributing into a project with single-corp-control + non-copyleft has uncertain odds to take, at least everyone is on the same footing. I think, as Lucas has mentioned, the most problematic aspect in this kind of cases is where there are both single-corp-control and a CLA, as that's what grants the possibility of a relicense and this asymmetrical relationship, which could have happened here as well even with a copyleft license. (Out of principle I never sign CLAs for my volunteer work, with the exception of the one for the FSF due to its nature and its assurances, but which I supposedly rescinded some time ago anyway.) Thanks, Guillem
[toc] | [prev] | [next] | [standalone]
| From | Antonio Terceiro <terceiro@debian.org> |
|---|---|
| Date | 2023-08-24 14:10 +0200 |
| Message-ID | <H6hjX-44JU-9@gated-at.bofh.it> |
| In reply to | #1165299 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Aug 24, 2023 at 01:46:11AM +0200, Guillem Jover wrote: > Hi! > > On Fri, 2023-08-18 at 08:07:44 -0300, Antonio Terceiro wrote: > > FWIW, I have been maintaining vagrant in Debian for several years. > > BTW, thank you for having done that, it's been much appreciated! > > > TL;DR: I will not be maintaining vagrant anymore. > > > On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote: > > > * What was the outcome of this action? > > > > Plan A. > […] > > > > Plan B. > […] > > > On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote: > > > Plan C. > […] > > There's perhaps a: > > Plan D. > > - Package Vagrunt (https://github.com/vaagrunt/vagrunt) a fork of > Vagrant, that is stated should remain free software. And as it does > not have a CLA, if it gets several contributions it will be > increasingly hard to relicense. > - Transition from vagrant to vagrunt via a transitional package. > > (We use Vagrant at work, and I'm not planning on relying on a non-free > tool, so a fork would do, otherwise I'd have to look into alternatives > for us to switch to.) I have seen this a couple of days ago. So far vagrunt is vaporware. The GitHub user which created has -- as far as I looked, i.e. on GitHub itself -- 0 contributions to Ruby projects. I'm also not confident that it will be easy to keep up with e.g. new VirtualBox versions without effectively infringing on HashiCorp copyrights. I will love to be proven wrong, but I'm not holding my breath here.
[toc] | [prev] | [next] | [standalone]
| From | Gwili.Stifter@EasyMailer.live |
|---|---|
| Date | 2023-08-18 15:40 +0200 |
| Message-ID | <H47RM-2JrD-9@gated-at.bofh.it> |
| In reply to | #1164541 |
Source: vagrant Followup-For: Bug #1049999 Please consider officially orphaning the package if realistically you are the only maintainer of this package. This should help increase the visibility of the problem and make users think more about whether using vagrant from debian is the right solution to whatever they may be trying to achieve.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web