Vivian Voss

Decisions You Did Not Make

open source licensing defaults freedom

IT Philosophy ■ a thesis, with the strongest case against it

Type umask into a shell on the machine you are reading this on and it will answer 0022. Three digits, sitting in one line of a configuration file you have never opened, and what they decide is who may read every file you create from now on. At 022 the answer is everybody with an account on that machine, because a new file arrives as -rw-r--r-- and stays that way unless somebody intervenes.

You did not choose that. Nor, in all likelihood, did whoever set the machine up: the value was already in the file when the system was installed, and the reasoning behind it is older than most of the people relying on it. It is also, as it happens, perfectly sensible. Somebody thought about it carefully a long time ago, and the argument still holds.

That is a default, and there is nothing wrong with it. A working day contains a few dozen decisions worth actually making, and several thousand that would swallow the whole day in a fine administrative kerfuffle if you insisted on making them yourself. Every one of those thousands has been made for you by somebody who will never meet you, and the overwhelming majority of them are sound. Far from being a conspiracy against your autonomy, defaults are the reason you got anything done this morning.

So the objection is not that you inherit decisions. You inherit almost all of them, and so does everybody else, and the alternative is a career spent reading configuration files.

The objection begins one step later, at the moment you want to change your mind.

The moment of taking it back

Try it and you will find the inherited decisions sort themselves into three quite different kinds, which had looked identical right up until you touched them.

Three kinds that look identical until you touch them THE RIGHT THE ABILITY IT SURVIVES First kind a value in a text file yes yes yes 20 seconds Second kind a setting in somebody else's store yes no no no export Third kind the licence on the code itself no yes no an afternoon Only the third kind is settled by permission rather than by capability.

The first kind you simply change. The number is in a file, the file is a text file, you edit it, and the system does what you now say. Nobody has to agree, nobody has to be asked, and the entire transaction takes twenty seconds and leaves a line in a diff.

The second kind you may change, in that no rule forbids it, except that the change cannot survive. The setting lives in a database you do not control, behind a console with no export worth the name, or in a format one program understands and no other, and getting at it is a faff of a particular and familiar kind. You are permitted to want something different, and you are not equipped to have it.

The third kind is the interesting one, and it is the rarest. You have the file. You have the source. You are entirely capable of making the change, in an afternoon, with no help from anybody. And you are not allowed to.

The one that cannot be undone

The GNU General Public Licence gives you a remarkable set of permissions, and they should be stated plainly before anything else is said. You may read the whole of it. You may change any line, any behaviour, any setting, any default the authors chose. You may run the result in production, sell it, rip out the parts you dislike and replace them with your own, and nobody may ask you for a penny or a reason. In terms of what you may do to the software in your possession, it is about as free as a document can make it.

There is exactly one thing you may not alter, and that is the licence.

The condition travels with the code origin fork derivative in-house build Every node carries the same condition. No node anywhere in the tree may remove it, and the tree continues past the edge of this picture.

Every other inherited decision in the system is yours to revisit. That one is not, and no oversight put it there. The condition is the entire mechanism, working exactly as designed, and it works by travelling: the condition attaches to the code and goes wherever the code goes, into every copy, every fork, every derivative, for as long as any of it survives. You may take back every decision the authors made except the one they made about your right to take decisions back.

There is a word for an arrangement that fixes one rule beyond the reach of those it governs, and it is not usually a compliment when applied to anything other than software.

The word on the tin is freedom. A freedom that arrives as a condition, and that may not be set aside by those who receive it, has stopped being a freedom somewhere along the way and become an order. That is what the words mean, and no amount of goodwill towards the intention changes them.

But nobody would give anything back

Here is the objection, and it is the only one that matters, so it deserves the strongest form anybody has ever given it.

Remove the condition and people take. They take the work of volunteers, build a business on it, improve it privately behind closed doors, return nothing whatever, and the next generation of volunteers watches all this and quietly stops volunteering. The condition exists because the behaviour is expected, which is what conditions are for. And the behaviour is real: whole industries sit on permissively licensed code and return a fraction of what they took. Anyone arguing the other side who pretends otherwise is not arguing honestly.

Now look at what the objection actually claims. It claims that without compulsion, giving does not happen.

Netflix put kernel TLS into FreeBSD, along with asynchronous sendfile, unmapped mbufs, the CAM scheduler and two congestion control algorithms, over roughly five years, under a licence that could not have compelled a single line of it. Sony has shipped FreeBSD inside the PlayStation 4 and again inside the PlayStation 5, the first on a kernel derived from FreeBSD 9 and the second from FreeBSD 11, and returns little to that tree; the same company has upstreamed more than three hundred PlayStation-related commits into LLVM and paid FreeBSD developers to work on the compiler side. Juniper has built its operating system on FreeBSD since the late nineties and has said openly that the licence was part of the appeal.

Read that middle case slowly, because it is the one that decides the argument. Sony gave back where it saw a reason and did not give back where it did not, and the two are different projects with different relationships to its product. A condition cannot make that distinction. It can only demand everything from everybody, and it will get compliance, which is a different substance entirely from what Netflix did and cannot be told apart from it afterwards.

Compulsion does not merely fail to produce generosity. It destroys the evidence that generosity was ever there, because once the giving is required, nobody can tell any more who would have given anyway.

The limit

The position has edges, and they are best stated by the person holding it.

The price is real and it is paid. Give without conditions and some recipients will take the thing, improve it quietly at home, and return nothing at all, and no amount of argument about the nature of freedom will get those improvements back. Nothing hypothetical about it either, since that is the ordinary case at several of the largest houses in the industry, and anybody choosing the permissive route should do so with the loss fully in view rather than in a warm glow.

The right to change your mind is worth nothing without the ability. A licence that permits you to rebuild the system is a piece of paper if nobody in the building can rebuild the system, and that is true of the freest licence ever written. Capability is the harder half, and it is bought with people rather than with words.

Some decisions ought to be irreversible, and being settled is often precisely their value. A deletion after a subject access request must be final. A key that has been exposed is replaced rather than reconsidered. And the counter-argument for the licence itself is genuinely serious: the condition protects the freedom of everybody downstream rather than that of whoever holds the code today, which is an entirely coherent thing to want. Whether an arrangement that binds itself against its own repeal is closer to a constitution than to an order is a question I am not going to settle in a Thursday column, and anyone who tells you it is obvious in either direction is selling something.

And the largest edge of all: a great deal of what this industry stands on was built under exactly the licence being argued against here. Whatever one thinks of the mechanism, the ecosystem it produced is not a thought experiment, and an argument that ignores that is arguing with a strawman.

The point

The three kinds of inherited decision are worth keeping in mind next time a tool is chosen, because the difference between them never appears in the comparison table. Which of these can I change with an editor. Which can I change if I am prepared to do some work. And which am I simply not permitted to change, however capable I become.

Most of what you run consists of decisions taken by strangers. That is fine, and it will go on being fine. The question worth asking about any of them has nothing to do with whether they were good decisions.

It is whether the door back is yours to open, or somebody else's to keep shut on your behalf, for your own good.