Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1164541 > unrolled thread

Bug#1049999: vagrant: the future of packaging vagrant in Debian

Started byKentaro HAYASHI <kenhys@xdump.org>
First post2023-08-18 08:40 +0200
Last post2023-08-18 15:40 +0200
Articles 8 — 5 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1049999: vagrant: the future of packaging vagrant in Debian Kentaro HAYASHI <kenhys@xdump.org> - 2023-08-18 08:40 +0200
    Bug#1049999: vagrant: the future of packaging vagrant in Debian Gwili.Stifter@EasyMailer.live - 2023-08-18 11:40 +0200
      Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-18 13:10 +0200
        Bug#1049999: vagrant: the future of packaging vagrant in Debian Lucas Nussbaum <lucas@debian.org> - 2023-08-19 07:00 +0200
          Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-22 17:10 +0200
        Bug#1049999: vagrant: the future of packaging vagrant in Debian Guillem Jover <guillem@debian.org> - 2023-08-24 02:00 +0200
          Bug#1049999: vagrant: the future of packaging vagrant in Debian Antonio Terceiro <terceiro@debian.org> - 2023-08-24 14:10 +0200
    Bug#1049999: vagrant: the future of packaging vagrant in Debian Gwili.Stifter@EasyMailer.live - 2023-08-18 15:40 +0200

#1164541 — Bug#1049999: vagrant: the future of packaging vagrant in Debian

FromKentaro HAYASHI <kenhys@xdump.org>
Date2023-08-18 08:40 +0200
SubjectBug#1049999: vagrant: the future of packaging vagrant in Debian
Message-ID<H41jj-2Fcq-3@gated-at.bofh.it>
Package: vagrant
Version: 2.3.4+dfsg-1
Severity: normal
X-Debbugs-Cc: kenhys@xdump.org

Dear Maintainer,

* What led up to the situation?

HashiCorp adopts the BSL.

https://ir.hashicorp.com/news-releases/news-release-details/hashicorp-adopts-
business-source-license-future-releases-its

Currently, vagrant 2.3.4+dfsg-1 was packaged in debian.

* What exactly did you do (or not do) that was effective (or
  ineffective)?

Should we keep non-BSL licenced version (A) or drop it (B)?

* What was the outcome of this action?

Plan A.

- Update to 2.3.7 and hold it. (2.3.7 is the last non-BSL licenced
  version)
- Follow a newer version only when BSL limitation expired (4 years).
- As a result, we can't use newer feature in timely manner if you stick
  on packaged vagrant in Debian.

Plan B.

- Drop vagrant because of that changed licence and no need to
  keep older vagrant.
- No vagrant avaiable in Debian. Just use upstream's package.

* What outcome did you expect instead?

N/A

[toc] | [next] | [standalone]


#1164559

FromGwili.Stifter@EasyMailer.live
Date2023-08-18 11:40 +0200
Message-ID<H447w-2HaX-45@gated-at.bofh.it>
In reply to#1164541
Source: vagrant
Followup-For: Bug #1049999

Plan C.

- Move BSL-licenced versions of vagrant into debian's non-free section.

[toc] | [prev] | [next] | [standalone]


#1164565

FromAntonio Terceiro <terceiro@debian.org>
Date2023-08-18 13:10 +0200
Message-ID<H45wB-2I8w-3@gated-at.bofh.it>
In reply to#1164559

[Multipart message — attachments visible in raw view] — view raw

Hi,

FWIW, I have been maintaining vagrant in Debian for several years. Thank
you for raising this as I have been too lazy to push this discussion.

I am copying the Debian Ruby team plus all the people that I could find
listed as maintainer or uploader of vagrant related packages (mostly
plugins, vagrant-*, but also other related packages) so that they are
aware.

TL;DR: I will not be maintaining vagrant anymore.

On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote:
> Package: vagrant
> Version: 2.3.4+dfsg-1
> Severity: normal
> X-Debbugs-Cc: kenhys@xdump.org
> 
> Dear Maintainer,
> 
> * What led up to the situation?
> 
> HashiCorp adopts the BSL.
> 
> https://ir.hashicorp.com/news-releases/news-release-details/hashicorp-adopts-
> business-source-license-future-releases-its

This is the second time a package to which I dedicated extensive amount
of my time is made effectively non-free by its corporate upstream.

The first time was with Chef: while the license itself was not changed,
they started imposing trademark-related requirements that would impose a
large amount of busywork to keep something that looks like Chef (Cinc,
their "community" fork) in Debian. I decided to just give up, and moved
on to using something else.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959981
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=963750

This is now my second time with this, and this time HashiCorp actually
made new versions of vagrant non-free.

I have used Chef Inc and HashiCorp stuff for free for several years, but
I also put in a large amount of work to make their tools available
trivially to Debian users by taking care of those packages in the Debian
archive.

Both Chef Inc and HashiCorp care a lot about having people that use
Debian consuming their products, so much so that they provide binary
packages for Debian. But they don't care at all about the time of
downstream maintainers, and why would they? They are private companies
trying to maximize their profit at the expense of whoever is in their
way. In this case, HashiCorp is apparently trying to counter other
companies who are selling solutions based on their tools that compete
with them, they have no incentive to care about the time of a few
individuals.

I don't see this change as a particularly evil move, but it effectively
destroys my motivation to continue working on it.

> Currently, vagrant 2.3.4+dfsg-1 was packaged in debian.
> 
> * What exactly did you do (or not do) that was effective (or
>   ineffective)?
> 
> Should we keep non-BSL licenced version (A) or drop it (B)?
> 
> * What was the outcome of this action?
> 
> Plan A.
> 
> - Update to 2.3.7 and hold it. (2.3.7 is the last non-BSL licenced
>   version)
> - Follow a newer version only when BSL limitation expired (4 years).
> - As a result, we can't use newer feature in timely manner if you stick
>   on packaged vagrant in Debian.

I had already looked into this, even before the relicensing being
announced, and it turns out that vagrant 2.3.7 has a few extra
dependencies that would need to be packaged too (something like 3 or 4
NEW packages), and I wasn't ready to put the necessary work in yet.

After the news came out, I gave up on doing it entirely, since after
this vagrant would be a dead end.

> Plan B.
> 
> - Drop vagrant because of that changed licence and no need to
>   keep older vagrant.
> - No vagrant avaiable in Debian. Just use upstream's package.

I think keeping a stale version of vagrant in the archive is worse than
telling people to just use upstream packages.

As far as my volunteer time is concerned, this is the most likely
outcome. I have some private notes on my requirements for a vagrant
replacement, and when I reach a conclusion I will most probably pursue
this path and just move on.

On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote:
> Source: vagrant
> Followup-For: Bug #1049999
> 
> Plan C.
> 
> - Move BSL-licenced versions of vagrant into debian's non-free section.

I will not maintain any packages in non-free.

Hopefully, being burned a second time will teach me to not put my
volunteer time in non-copyleft packages provided by a single
corporation.

[toc] | [prev] | [next] | [standalone]


#1164674

FromLucas Nussbaum <lucas@debian.org>
Date2023-08-19 07:00 +0200
Message-ID<H4me5-2SpY-13@gated-at.bofh.it>
In reply to#1164565

[Multipart message — attachments visible in raw view] — view raw

Hi,

This license change is so disappointing...

On 18/08/23 at 08:07 -0300, Antonio Terceiro wrote:
> > Plan B.
> > 
> > - Drop vagrant because of that changed licence and no need to
> >   keep older vagrant.
> > - No vagrant avaiable in Debian. Just use upstream's package.
> 
> I think keeping a stale version of vagrant in the archive is worse than
> telling people to just use upstream packages.

A follow-up question, especially in the case of Plan B, is: what do we
do about Debian Vagrant images provided on Vagrant Cloud
(https://app.vagrantup.com/debian/) ?

A/ continue to maintain them. But as the main uploader of those images
   in the recent times, I might not continue to maintain them, especially
   if I move to another tool for my own uses, so we might need to look
   for other volunteers.
B/ stop maintaining them
   B.1/ ... and remove existing images from the 'debian' Vagrant Cloud
   account
   B.2/ ... and leave the 'debian' Vagrant Cloud account as it is
   currently

I don't think B.2 is a good idea.

> Hopefully, being burned a second time will teach me to not put my
> volunteer time in non-copyleft packages provided by a single
> corporation.

Note that the fact that Vagrant was using a non-copyleft license is not
entirely relevant. The same relicensing could be achieved by
organizations using a copyleft licence with a copyright transfer
agreement for external contributions. (I suspect that this is how it was
achieved for other Hashicorp products, but I haven't checked).

Lucas

[toc] | [prev] | [next] | [standalone]


#1165096

FromAntonio Terceiro <terceiro@debian.org>
Date2023-08-22 17:10 +0200
Message-ID<H5Bb3-3E62-3@gated-at.bofh.it>
In reply to#1164674

[Multipart message — attachments visible in raw view] — view raw

On Sat, Aug 19, 2023 at 06:46:06AM +0200, Lucas Nussbaum wrote:
> Hi,
> 
> This license change is so disappointing...
> 
> On 18/08/23 at 08:07 -0300, Antonio Terceiro wrote:
> > > Plan B.
> > > 
> > > - Drop vagrant because of that changed licence and no need to
> > >   keep older vagrant.
> > > - No vagrant avaiable in Debian. Just use upstream's package.
> > 
> > I think keeping a stale version of vagrant in the archive is worse than
> > telling people to just use upstream packages.
> 
> A follow-up question, especially in the case of Plan B, is: what do we
> do about Debian Vagrant images provided on Vagrant Cloud
> (https://app.vagrantup.com/debian/) ?
> 
> A/ continue to maintain them. But as the main uploader of those images
>    in the recent times, I might not continue to maintain them, especially
>    if I move to another tool for my own uses, so we might need to look
>    for other volunteers.
> B/ stop maintaining them
>    B.1/ ... and remove existing images from the 'debian' Vagrant Cloud
>    account
>    B.2/ ... and leave the 'debian' Vagrant Cloud account as it is
>    currently
> 
> I don't think B.2 is a good idea.

I agree. Just as we provide cloud images for proprietary platforms, I
think we as a project want to control what is available as "Debian" for
Vagrant users, just like we do with images targetted at proprietary
cloud platforms.

> > Hopefully, being burned a second time will teach me to not put my
> > volunteer time in non-copyleft packages provided by a single
> > corporation.
> 
> Note that the fact that Vagrant was using a non-copyleft license is not
> entirely relevant. The same relicensing could be achieved by
> organizations using a copyleft licence with a copyright transfer
> agreement for external contributions. (I suspect that this is how it was
> achieved for other Hashicorp products, but I haven't checked).

Yes, that's true.

[toc] | [prev] | [next] | [standalone]


#1165299

FromGuillem Jover <guillem@debian.org>
Date2023-08-24 02:00 +0200
Message-ID<H65Vv-3XqF-9@gated-at.bofh.it>
In reply to#1164565
Hi!

On Fri, 2023-08-18 at 08:07:44 -0300, Antonio Terceiro wrote:
> FWIW, I have been maintaining vagrant in Debian for several years.

BTW, thank you for having done that, it's been much appreciated!

> TL;DR: I will not be maintaining vagrant anymore.

> On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote:
> > * What was the outcome of this action?

> > Plan A.
[…]

> > Plan B.
[…]

> On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote:
> > Plan C.
[…]

There's perhaps a:

Plan D.

- Package Vagrunt (https://github.com/vaagrunt/vagrunt) a fork of
  Vagrant, that is stated should remain free software. And as it does
  not have a CLA, if it gets several contributions it will be
  increasingly hard to relicense.
- Transition from vagrant to vagrunt via a transitional package.

(We use Vagrant at work, and I'm not planning on relying on a non-free
tool, so a fork would do, otherwise I'd have to look into alternatives
for us to switch to.)

> Hopefully, being burned a second time will teach me to not put my
> volunteer time in non-copyleft packages provided by a single
> corporation.

While it's certainly true that contributing into a project with
single-corp-control + non-copyleft has uncertain odds to take, at
least everyone is on the same footing. I think, as Lucas has mentioned,
the most problematic aspect in this kind of cases is where there are
both single-corp-control and a CLA, as that's what grants the possibility
of a relicense and this asymmetrical relationship, which could have
happened here as well even with a copyleft license. (Out of principle
I never sign CLAs for my volunteer work, with the exception of the one
for the FSF due to its nature and its assurances, but which I supposedly
rescinded some time ago anyway.)

Thanks,
Guillem

[toc] | [prev] | [next] | [standalone]


#1165358

FromAntonio Terceiro <terceiro@debian.org>
Date2023-08-24 14:10 +0200
Message-ID<H6hjX-44JU-9@gated-at.bofh.it>
In reply to#1165299

[Multipart message — attachments visible in raw view] — view raw

On Thu, Aug 24, 2023 at 01:46:11AM +0200, Guillem Jover wrote:
> Hi!
> 
> On Fri, 2023-08-18 at 08:07:44 -0300, Antonio Terceiro wrote:
> > FWIW, I have been maintaining vagrant in Debian for several years.
> 
> BTW, thank you for having done that, it's been much appreciated!
> 
> > TL;DR: I will not be maintaining vagrant anymore.
> 
> > On Fri, Aug 18, 2023 at 02:56:28PM +0900, Kentaro HAYASHI wrote:
> > > * What was the outcome of this action?
> 
> > > Plan A.
> […]
> 
> > > Plan B.
> […]
> 
> > On Fri, Aug 18, 2023 at 09:37:54AM +0000, Gwili.Stifter@EasyMailer.live wrote:
> > > Plan C.
> […]
> 
> There's perhaps a:
> 
> Plan D.
> 
> - Package Vagrunt (https://github.com/vaagrunt/vagrunt) a fork of
>   Vagrant, that is stated should remain free software. And as it does
>   not have a CLA, if it gets several contributions it will be
>   increasingly hard to relicense.
> - Transition from vagrant to vagrunt via a transitional package.
> 
> (We use Vagrant at work, and I'm not planning on relying on a non-free
> tool, so a fork would do, otherwise I'd have to look into alternatives
> for us to switch to.)

I have seen this a couple of days ago.

So far vagrunt is vaporware. The GitHub user which created has -- as far
as I looked, i.e. on GitHub itself -- 0 contributions to Ruby projects.
I'm also not confident that it will be easy to keep up with e.g. new
VirtualBox versions without effectively infringing on HashiCorp
copyrights.

I will love to be proven wrong, but I'm not holding my breath here.

[toc] | [prev] | [next] | [standalone]


#1164593

FromGwili.Stifter@EasyMailer.live
Date2023-08-18 15:40 +0200
Message-ID<H47RM-2JrD-9@gated-at.bofh.it>
In reply to#1164541
Source: vagrant
Followup-For: Bug #1049999

Please consider officially orphaning the package if realistically you are the only maintainer of this package. This should help increase the visibility of the problem and make users think more about whether using vagrant from debian is the right solution to whatever they may be trying to achieve.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web