On April 3rd, we received a Cease and Desist letter from HashiCorp regarding our implementation of the “removed” block in OpenTofu, claiming copyright infringement on the part of one of our core developers. We were also made aware of an article posted that same day with the same accusations. We have investigated these claims and are publishing the C&D letter, our response and the source code origin document resulting from our investigation.

The OpenTofu team vehemently disagrees with any suggestion that it misappropriated, mis-sourced, or otherwise misused HashiCorp’s BSL code. All such statements have zero basis in facts.

HashiCorp has made claims of copyright infringement in a cease & desist letter. These claims are completely unsubstantiated.

The code in question can be clearly shown to have been copied from older code under the MPL-2.0 license. HashiCorp seems to have copied the same code itself when they implemented their version of this feature. All of this is easily visible in our detailed SCO analysis, as well as their own comments which indicate this.

Documents

To prevent further harassment of individual people, we have redacted any personal information from these documents.

Conclusion

Despite these events, we have managed to carry out significant development on OpenTofu 1.7, including state encryption, “for_each” implementation for “import” blocks, as well as the all-new provider-defined functions supported by the recently released provider plugin protocol.

On that note, we will be releasing a new pre-release version next week, and we are eager to gather feedback from the community.

— The OpenTofu Team


The image in this blog post contains code licensed under the BUSL-1.1 by HashiCorp. However, for the purposes of this post we are making non-commercial, transformative fair use under 17 U.S. Code § 107. You can read more about fair use on the website of the US Copyright Office.

  • Saganaki@lemmy.one
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    This is unrelated to this topic exactly, but I don’t know what OpenTofu is nor what it is for, so I looked at the FAQ.

    What is OpenTofu?

    OpenTofu is a Terraform fork, created as an initiative of Gruntwork, Spacelift, Harness, Env0, Scalr, and others, in response to HashiCorp’s switch from an open-source license to the BUSL. The initiative has many supporters, all of whom are listed here.

    This is practically a meme…I have no idea what all of these are (coming from my area of expertise).

    • hydroptic@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      7 months ago

      I’ve run into this problem with many open source projects. It’s sometimes really hard to find out what the hell something actually does based on just the project’s own pages. It took a while for eg. join-lemmy.org to actually describe what Lemmy is, for example, instead of just going on about it being open source and secure and federated and blah.

      • deweydecibel@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        7 months ago

        That’s just a classic issue with most tech people: they either forget or don’t know how to adjust their speech for a different audience than themselves. Often they don’t even comprehend just how much “common knowledge” isn’t actually common outside their social spaces.

        Then there’s some that are deliberately refusing to help uninformed people understand, or are even outright hostile to them.

        • hydroptic@sopuli.xyz
          link
          fedilink
          arrow-up
          0
          arrow-down
          1
          ·
          7 months ago

          Yeah I really don’t know where hostility against newbies (actual or perceived) comes from in nerd circles. It’s been like this for as long as I can remember, and I’ve been eg. using Linux from the late 90’s and fucking around on the Internet for over 30 years now. At least things are way better than they used to be, but it’s still sometimes a bit of a bumpy ride

  • Deebster@programming.dev
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    Pretty shitty attempt on Hashicorp’s part. Come to think of it, are Hashicorp themselves in the legal clear for grabbing code from an incompatible licence?

    • dariusj18@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      7 months ago

      Well, I’m sure they are worried about their new deal with IBM that they’ve obviously been working on for a while.

      • deweydecibel@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 months ago

        Yep, the timing lines up. As part of the buyout offer, they probably had to demonstrate an effort to cripple the open source fork of the thing IBM wants to buy.