My blog has moved!

You should be automatically redirected in 4 seconds. If not, visit
http://chrisjhorn.wordpress.com
and update your bookmarks.

Showing posts with label open source. Show all posts
Showing posts with label open source. Show all posts

Tuesday 9 June 2009

Boxing above your weight

I reproduce below an invited keynote talk which I gave this morning at a seminar organised the Alimentary Pharmabiotic Centre in University College Cork, on the general topic of entrepreneurship and start-ups.

---

Exactly twenty years ago, American Airlines and Hewlett-Packard Corporation took an initiative in the global software industry to interconnect distributed software applications. The initiative rapidly gained momentum, with all major software suppliers - with the sole exception of Microsoft - quickly joining. Yet by 1996, a small company from Ireland, IONA Technologies, was a widely recognised world leading supplier of products to interconnect distributed software applications, ahead of such major vendors as IBM, Oracle, HP, Microsoft, Digital and Sun. As a result, IONA had major customer contracts with companies such as Motorola, Boeing, Goldman Sachs, Lufthansa and Hong Kong Telecom. How can a relatively small player punch way above its weight ?


Thursday 18 September 2008

Building Cathedrals from Bazaars

I wrote this as part of my work for Cloudsmith. It is a follow up of my earlier posting a few weeks ago.

In summary, Cloudsmith lets you browse and find useful bundles of software components which work together – software playlists – and then download ones of interest. Each one can contain components from different software repositories, and Cloudsmith knows where to go, and how to get to them.


--


Eric S. Raymond wrote a seminal paper in 1997, The Cathedral and the Bazaar, contrasting how Linux emerged from a loosely structured, highly collaborative community or "bazaar" with the traditional approach to developing software (open source or proprietary), in which a select group of cathedral-builders controlled every aspect of design and technology.


Most engineers strive to build at least one great “building” during their career, a monument, a shrine, and a testament to their skill. Today, even "cathedrals" are made from parts found at the bazaars - a huge and growing marketplace for open source components, in which thousands of developers promote parts that many other developers combine into new products. The output of many bazaars -- projects and communities such as the Eclipse Foundation, the Apache Foundation, Google Code, SourceForge, etc. - support and publish the efforts of component development teams. Popular components turn up in multiple bazaars, sometimes as identical copies, other times with subtle variations.

Among the challenges development teams, and their co-worker product management and product marketing teams, face when operating within this new ecosystem are:

* What range of components is currently available? Which bazaars have them; what is their status and quality; how popular are they; where can updates and fixes be found; and so on.

* What works with what? What components, and combinations of components, are available? How do the pieces all fit together, and which bazaars have them?

* How popular is this combination of components compared to that alternative one? How do we know when and if we should update a selection of components, as new versions of the constituent parts emerge?

* How can we build playlists which combine components we built ourselves, with components found in public bazaars and that change in ways we don't control? How can we move to the new version of a public component without breaking what we already have? And how can we keep what we found in the bazaar from getting so intertwined with what we built that we can no longer separate them? What is the best strategy to manage change, when your organisation and your team are increasingly mixing public software components with your proprietary assets?

* Who is going to support us when we use some unique combination which we assembled from public bazaars? Is there anyone out there doing something similar we can learn from?

* We fix and extend components we find in the bazaar, and sometimes create entirely new component playlists of our own. How do we share our work with other developers in our organisation or (assuming our corporate policy allows it) contribute things back to the bazaar for the public good? And assuming we've shared it, how do we know who is using it, and for what?

It is, of course, no longer just an issue of providing a stable, managed foundation on which you and your colleagues can build. There is heightened corporate awareness reaching all the way to the audit committees of publicly quoted companies, due to the multiplicity of software licensing policies. The issue of knowing if, when and how public software assets are being used inside a corporation has become a high concern.

The ability to tailor software should be its value rather than its risk. But in todays world, isn't software componentisation paradoxically slower than it could be, precisely due to the changes, improvements and proliferation offered by the community?

Eric Raymond describes how extremely useful software can result from open collaboration, despite the absence of a clear lead architect directing the project. Today’s software repositories illustrate this principle on a grand scale - they are collections of really good and useful components developed, published, maintained and extended, sometimes by individuals and sometimes by organized teams of collaborators, in a process that can seem almost anarchic compared to conventional internal development.

As bazaars of developed, and contributed, software components have matured, the complexity of fitting together appropriate combinations have increased, as has ensuring that things do not break as each component is maintained.

One example is Eclipse, which is a common integration platform for many components. The recent Ganymede release lists nine application frameworks, six toolsets for embedded and device development, six toolsets for enterprise development, five language IDEs, and five aspects of its rich client platform. All of these elements, in principle, can be used in any combination of choice, although there are seven different official Ganymede packages are listed. Forty-five additional different project downloads are listed. And nine different distributions from member organisations are promoted. It shows an impressive level of community momentum and collective activity, but which of all of the alternatives do you really need for your particular project?

Actually, it is even more complex, because each bazaar stacks up components from its own shelves with components it finds in other bazaars. And you are often building not just one cathedral, but several based on a common set of blueprints. Perhaps you want to develop using Seam rich client Java toolkit? Then you might need a playlist of the Eclipse Classic IDE, JBoss Tools, Seam Core, JBoss AS, and PostgreSQL (with thanks to Stefan Daume for suggesting this particular playlist). But to do so, you may need to visit the Eclipse, JBoss, Seam and Postgres bazaars to put this all together -- unless you can happen to find somebody else who has already done this for you. If you want to build an email spam filter, then maybe a playlist of MySQL, qpsmtpd, my qpsmtpd custom modules, php pages (status), and open flash chart run-time files might be just the job (with thanks to Bjorn Freeman-Benson for this playlist).

Finding out what software components are available is a modest challenge: you can use raw Google, or Google CodeSearch, or Koders, or Krugle, or Codase, or something similar. The more significant challenge is finding out what works with what else to form a useful playlist; then how to get hold of the right version of each these pieces from each of the right bazaars concerned; how popular is this specific playlist of components; and how to get notified if any of the pieces are subsequently changed. If you want to be civic-minded, you might also want to find out how best to contribute original or derivative works back to the remainder of your organisation or community at large.

Our industry is maturing: we really soon should reach the equivalent levels of professional practice as our colleagues in other engineering disciplines, such as electronics hardware and civil engineering. There now is - perhaps at long last - a substantial number of re-usable, well-engineered, components available to all of us, being extended and improved on a daily basis. We should all be able to build cathedrals, and other artifacts, from the components we find. But the vast range of components, coupled with the fluidity of material - software - with which to work, has presented our industry with some new challenges,and which are not as apparent in other engineering disciplines.

Saturday 10 November 2007

Open Source, China and Microsoft

Confucius was born in the state of Lu. When he received news that the powerful state of Qi was preparing to attack his homeland, he sent his gifted disciple Zi Gong to talk to the rulers of the surrounding states. Zi Gong went first to the state of Qi and observed to the military generals the flaws in a strategy to attack Lu. He succeeded in persuading the generals to first attack the state of Wu instead. Zi Gong subsequently went to Wu and instigated the king of Wu to attack Qi…Thus, Confucius saved Lu.

From ninth chapter of Chang Duan Jing.


At first sight, it would appear that there should be an excellent cultural fit between the open source movement in the West, and Chinese values. Open source emphasizes collective knowledge and sharing of competence. In China, the loyalty to the group is strong; communist philosophy emphasizes sharing, and Confucian teaching emphasizes the latent potential of the individual to attain skilled judgment from the experience of others.

The use of the web is growing fast in China – exceeding the US and growing much faster than the US - as reported in Forbes. Open source collaboration uses the web as a collaboration platform, so you would also expect this to add to the momentum of open source in China.

The Economic Intelligence Unit recently reported a ratio of 100 jobs for every computer science graduate in China, with this number expected to sky-rocket; and Duke University reported 60,000 computer science graduates from 4-year degree programmes in China in 2004, and 292,000 from 3-year programmes. This huge domestic demand, and huge output, of software developers might lead you to expect further momentum for open source in China.

A recent Eclipse Members meeting noted that China has the most number of the downloads globally (over a recent 18 month period) at 21%, followed by the US at 18%, and both Germany and Japan at 8% each.

So: what is the status of open source in China ?

Well, there are a small number of open source projects in China, but apparently not as many as you might expect. XOOPS (a content management framework) is quite well known and Stephen Walli’s blog contains an interesting presentation by Tiaiwen Jiang, the community leader in China, on the project from the Chinese perspective. Huihoo is a leading open source middleware project including a J2EE implementation, JFox. Qianqian at Harvard Medical School initiated, in 2004, a collaborative project Wen Quan Yi to develop an open source font set for the 70,000 Han characters encoded by Unicode.

An interesting development is the merger of ObjectWeb in France and Orientware in China at the end of 2006, to form OW2. They are sharing open source contributions in a variety of middleware technologies and their deliberations are documented in their Board of Directors minutes...

But, perhaps predictably, the main interest in open source in China is Linux: just google ‘china open source’ and you’ll see! In 2003, China enacted the Software Government Procurement Regulation (SGPR) which excluded foreign companies from the federal software market. As recently as the end of 2005, CIO Magazine was discussing China’s federal commitment to Linux – for multiple reasons at the time, including suspicions of US intelligence agencies “trojan horses” in US proprietary code (remember the B-767 government jet delivered in 2002 to Beijing, but with eavesdropping devices discovered on delivery ?); overcoming WTO IP concerns by promoting open source; localization to the Chinese market; and kick-starting a strong domestic software industry.

But then things changed in 2005, despite CIO Magazine’s analysis above: in trade talks, China laid aside the SGPR in favour of concessions on industries such as textile and colour television.

So now, according to Lou Shouqun of the China OSS Promotion Unit (a non-government organisation) in a recent presentation, the Linux revenues in all China last year (2006) were about 218M RMB (20MЄ), with a market share (by revenue) of just 3%. Other UNIX systems were 52% - the financial services and telecommunications industries in China have heavily used Solaris, AIX and HP/UX, amongst others. Windows was 42%. While the overall market is growing about 10% per annum, Shouqun believes Linux in China is growing faster than the market, albeit from a low base.

Things have changed even more significantly since the 2005 abandonment of the SGPR directive: Microsoft seem to have successfully found favour with the federal authorities. Fortune magazine documented Bill Gates recent summer visit to China; the history of Microsoft in China, and how Microsoft has very successfully wooed the Chinese policy makers creating an apparent “win-win” situation. It is a fascinating article, and I recommend it to you if you haven’t already read it.

So, why are there few committers in China, and apparently meek participation in the global open source, particularly when the number of software professionals in China is rising so rapidly ? Why is it that Windows is far more successful in China than Linux, and is Microsoft’s new strategy truly a “win-win” ?

The urgency to make money is IMHO a national obsession in China. Consumerism, and chasing Western fashions and brands are all-consuming. You must remember that, within the life times of those of us in our 40s or more, very many Chinese were incredibly impoverished to appallingly abysmal standards of life. It really is only in the last twenty years or so that national living standards have consistently dramatically improved – while admitting of course that there remain many challenges and disparities today across the huge country. In my own experience, making money is far more important to many Chinese than political discourse.

If your parents and grandparents have supported you, a single child, through your professional education as a software developer, their expectations (and needs in their senior age) will be that you will support them. Your partner’s parents and grandparents will have similar expectations. An engineer, including a software engineer, is considered a respected professional: many policy makers, senior business managers, and senior party members also have engineering backgrounds. As a software engineer, your own, your family’s, and society’s expectations are all that you will be financially successful.

Can you be truly financially successful in China if you are an open source developer ?

In the West, much of the open source activity in fact is carried out within companies, including Intel, Novell, IBM, Sun and Oracle, amongst others. Foreign companies in China with recognized global brands – such as Microsoft, with its very wealthy founder – are highly attractive as employers, since they not only in general pay well by local standards but also potentially open the possibility of international travel.

But, which foreign companies have so far established software development laboratories in China which contribute to open source development ? IBM have a Linux technology centre in Beijing. Intel announced in 2004 development centres in Beijing, Xi’an, and Guandong to help Chinese companies develop desktop applications for Linux. Oracle promotes its products on Linux in China, including via the Oracle technology centre in Beijing. But these centers appear, on the surface, to be solution centers which promote Linux based application solutions perhaps as a response to the apparent promotion of Linux by the Chinese authorities and prior to the SGPR retraction; rather than development centers actively contributing to globally available open source. I of course am very open to correction, but it would appear that to date only Novell has opened an R&D centre in China specifically for Linux system development. It is also noteworthy that IONA (of which I’m Vice-Chairman) has Chinese committers from its Beijing R&D centre on the Eclipse STP and Apache CXF open source projects.

For domestic Chinese activity, the largest player in open source Linux is Red Flag. It is ambitious to develop into an international player in Asian Linux, and has recently announced a specific initiative. However its current sales revenue is still relatively small, even by Chinese national standards, at just 40M RMB (3.6MЄ).

To the extent that open source development is being conducted in China by foreign companies, with Chinese committers, then arguably these initiatives need to be more openly promoted and publicized to the Chinese software development community. The open source movement in China needs major foreign brand name companies to visibly invest and recruit in China for development of open source.

Well, then how about Chinese open source start-ups ? Are there any budding MySQL ABs, SugarCRMs, or xTuples ? Yes, and I mentioned Huihoo and Red Flag earlier, as examples. But IMHO the open source industry in China is currently fragile and considered so both by potential employees (ie software developers) and, as importantly, Chinese corporate customers. It is frankly easier – and perhaps more socially acceptable with one’s parents – to work for an established organization, particularly if it is a foreign brand.


Let’s now look at that second question I posed above: why is Microsoft now being much more successful in China ? Microsoft seems to have overcome concerns by Chinese policy makers by pro-actively taking a number of steps. The “trojan horse” threat has been overcome by allowing access (and hence inspection) under appropriate conditions to Microsoft source code, and China now has a federal laboratory to do exactly so. Microsoft has been very actively investing in the education sector, including rural classrooms and software engineering universities, and so aligning its investments with the federal desire to strengthen software skills nationwide – Microsoft is training 1,000 instructors and 20,000 software engineers, and offering online courses to another 50,000 engineers. It has worked with the federal authorities in the context of WTO obligations to ensure that more Chinese PCs have legally licensed pre-installed copies of Windows. In turn this is overcoming piracy issues since the pre-installed versions are more current, have less bugs and more features than older copies of Windows. It has also dramatically dropped the price of Windows in China. In summary, President Hu Jintao on a visit to Microsoft said that Bill Gates is a friend to China and the Chinese people: in China, this is an incredible endorsement, and it is difficult to find any analogy in the West for such an important and powerful public ratification.

It would appear that Microsoft is on a roll in China. It is very interesting to reflect on the Microsoft strategy and their execution of it within China, and contrast that to the open source industry and initiatives in China. Of which open source project or company will the President of China publicly endorse as a friend of China and of the Chinese people ? If the open source industry globally is to benefit from China’s rapid development, it is clear that investment – perhaps akin to Microsoft’s commitment to China – will be needed.

It is also very interesting to ponder to what extent the prices Windows customers in the West are paying are being used to subsidise Windows customers in the East. Cross-subsidies are of course not at all a new idea in any industry: I find the Microsoft case interesting because it is part of a much broader initiative.


Let me finish by a hypothesis for policy from the Chinese Government perspective. The war is not about whether Windows or Linux will ultimately win. Both are sufficiently low cost here in China to be usable. Microsoft is generously up-skilling the national software engineering talent pool, and the open source industry is also helping by publishing its source code and inner workings. The war is rather about building a vibrant software industry in China, capable not only of satisfying national needs, but also exporting and becoming a world leader.

The main requirement is excellent application development, on whatever foundation systems and middleware technology are de facto in the global industry (it doesn’t matter which, as long as they are low cost in China). Open source by the Chinese industry – and for the Chinese industry - could play a very significant role indeed. By fostering a national repository of re-useable Chinese application components – with documentation and test suites – written by Chinese developers (in Chinese first, and then maybe English), with a framework put in place and re-enforced by Government policy and investment, then the national industry could be rapidly enhanced.


“Therefore the Master concerns himself with the depths and not the surface, with the fruit and not the flower….When his work is done, the people say ‘Amazing: we did it, all by ourselves!’’”

The Tao Te Ching, by Lao Tzu


This was the basis for an invited keynote I was to give at the OS Summit in Hong Kong at the end of this month: but the conference has now been postponed until sometime in 2008.

Monday 5 November 2007

Think Liquidity.

Professional investors understand liquidity. They understand asset backed securities, and they understand the risks when assets subsequently emerge to be poorer quality than they were represented to be. Sub-prime assets can be embarrassingly illiquid and career changing.

In the world of enterprise IT investments, customers have likewise yearned for liquidity. Lock-in to assets available solely from any single vendor implies significant risk to the purchaser. Bad investment decisions into IT assets which subsequently emerge to be poorer quality than they were represented to be, can be embarrassing and career changing – particularly if the assets are illiquid and difficult to replace.

Financial markets have been driven by liquidity. However by contrast, purchasers of IT assets have found it challenging to be able to subsequently replace and substitute alternatives when desirable.

Until now.

Today, I believe that the software and hardware industries are fundamentally changing in favour of liquidity. Software is increasingly componentized. Software has increasingly recognized industry standards which facilitates substitution of alternatives. Open source provides liquidity through lowering the cost of change.

Enterprise software vendors should be trusted partners in providing and maintaining tailored solutions. The ability to successfully integrate a variety of components from a variety of sources to an enterprise level of service is valued. The ability to scalably manage multiple configurations, and evolve them dynamically over time, is valued. Tailorable, personalized solutions for specific customers, partners and staff, but all as part as of the holistic enterprise, are valued. Dynamic systems enable liquidity amongst software assets – no matter from which particular vendors specific assets are obtained.

New, and sustainable, business models are emerging from software vendors who deeply understand technology liquidity.

Single, monolithic, vertically integrated silos of software stacks is thinking from the last century. Integrated stacks are illiquid if any specific components or layers cannot be readily substituted by better alternatives on the market today, or which may emerge tomorrow, from any vendor.

It does not take an oracle to foresee what will happen if BEAS are purchased by ORCL. Overlapping products – portal servers, application servers, service busses, Java development platforms, whatever – will be culled: “synergies” throughout the two organizations will be executed. ORCL will attempt to cross sell its own offerings into the BEAS client base and migrate them away to ORCL alternatives.

Professional investors understand liquidity. Even if they are new to investing in IT equities, they therefore should have little difficulty in understanding that enterprise IT customers likewise yearn for liquidity of technology assets. In the past, enterprise vendors have been slow to offer liquidity. Now, the IT industry is changing fast, and the potential upside for investors in IT is vendors who understand and are executing on technology liquidity: vertically integrated illiquid stacks are from a former and sub-prime era.

Think liquidity.

Monday 10 September 2007

Sharing the best and most valuable: Software Hot Rodding

Like some other teenagers of my generation in the seventies, one of my hobbies at the time was faithfully constructing scale models from plastic kits from Airfix, Revell, Historex etc. As I developed my skills and interest, I took great pride in adding extra levels of detail – particularly for ship kits. Eventually I converted particular kits so as to model an aircraft, ship or vehicle not directly available as a standard kit, by moulding balsa, crafting acetate sheet and so on – for example building a twin engine, triple tail fin Avro Manchester from the Airfix kit of the successor four engine Lancaster. The monthly Airfix Magazine was a great source of designs and examples, and I still have a shelf full of back copies here in my office at home.

When I was an engineering student, I took a similar interest in building my own, albeit fairly simple, analogue electronic circuits – the usual things such as oscillators, radios, fire/smoke detectors, etc. Of course, as with converting plastic kits, having a good stock of spare parts - scavenged from broken electronic circuits – was useful. I used to keep them sorted into empty margarine tubs on my shelves.

In more recent years, I became more and more involved in computers, from the digital gates and circuits up to microcode, assembler, compiler/interpreter systems and finally full systems and applications. I was fascinated when they became affordable as home systems, and played around adding extension cards and interfaces to my first PC. I was initially really impressed by Dell when I saw their range of alternative pre-configured systems for direct order across the internet. Dell used to have a plant in Bray just a few miles away from my home, and I have bought many systems over the years from them for home, school and charitable use.

But I’ve often thought there must be quite a few people out there like me who aren’t quite happy with a specific system they buy from Dell (or indeed any other supplier). Although I carefully chose a configuration before buying, still afterwards I frequently tailor my purchase further with additional cards, expansions and options. I also wonder whether somebody out there has already built the perfect system for creative digital photography, or multi-screen home media management, or whatever. Or whether anyone would be interested if I could publish my own designs and configurations. Or whether any configurations would be commercially interesting, for example for specialist systems such as creative digital media design.

Reflecting on my fads above, the common aspects are a desire to build interesting variations of basic designs; from additional parts either built myself, or stock-piled somewhere (not necessarily in margarine tubs!), or purchased elsewhere; to look at designs published by others, and perhaps even to publish my own.

Well, that’s what Cloudsmith is doing for the world of software. One way to think of Cloudsmith is as a derivation of Dell’s world, for software. You can browse an online catalogue at Cloudsmith and see what “distros” – configurations - of software components are available. If you want to chose any particular one, you click it and it “materializes” – ie downloads its parts, and then automatically assembles them together – onto your machine. And like getting a system from Dell, the different components of your configuration will usually come from different “repos” (repositories - think Dell sub-suppliers) around the world. So rather than just a single download of a binary file, a materialization will usually automatically fetch multiple files, from multiple places, and assemble them automatically for you on your machine as a complete system. The distro is thus “virtual”: it is not monolithic (like an old download) and its parts are not hosted at Cloudsmith (any internet repo can contribute).

If you like what you find, you can send others the “Cloudlink” you used. When they click it, the same components will materialize from the cloud of components available in multiple repos across the internet, and assemble and install on their machine too. So, you can materialize something specific without having to yourself connect to the Cloudsmith site and without having to search the online catalogue for it – just get the Cloudlink for it from someone else via an email or blog or whatever, and the magic will happen when you click.

Whats kinda nice about the Redhats of this world is that they pre-assemble a large collection of software components for you as a full Linux system. Whats nice about Cloudsmith is that if you build your own interesting set of software components, then you can publish that configuration at Cloudsmith, and reliably make it available for other people to use. It need not of course be as complex as a full operating system: just a nice application or tool or subsystem for a particular use which you have put together, using your own design or as an interesting derivation from somebody else's published distro. You can publish novel and interesting things that you’ve done, for others to take a look at and possibly use – no longer are you or they tied just to the pre-assembled varieties which the software equivalents of Dell provide. And if you have components from a new repo which Cloudsmith does not yet know about, you yourself can simply add that repo to Cloudsmith’s map of the world – it is the Cloudsmith software equivalent to introducing Dell to a new sub-supplier.

Why hasn’t a service like Cloudsmith existed up to now ? One reason is that although there has been a proliferation of useful re-useable software components developed and published around the world in many online repos, there has equally been a proliferation of software version control, make and build systems. It is difficult to justify re-engineering everything globally to use the same version control and build technology. IMHO it is impossible to impose one build or version control technology, or one IDE, on everyone: and it is short-sighted to expect everyone else to use the one that you happen to think is best. However, with some thought and help, it is possible for systems like Cloudsmith to automatically, on the fly, interpret the meta-information in all these version control and build system technologies, and thus automatically derive a global perspective and capability across many different repos.

But how do you know that somebody else’s published configuration is any good, and trustworthy? Well how does a plastic modeler or an electronics hobbyist know that somebody else’s design is any good ? Part of the answer is the popularity of the design – how many others are using it, and what do they say about it – and part of it is the reputation of the designer. Social community sites on the internet in general work because most people are ethical, and many people can watch, observe, comment and mend where necessary information which is incorrect.

Assembling and publishing new configurations of components is fun. Is it however just for hobbyists and software hot-rodding ? I believe that many commercial organizations will find interest in discovering and contributing to software configurations and assemblies that add real value in their business domains. I think enterprise managers will find reassurance not only in the popularity of certain distros, but also because they can be reassured that precisely the same distro (and bill of materials) is reliably installed on every machine under their control, and because component updates can be notified and controlled. I think vendor product managers and technology strategists will find interest in the concept of being able to build their own private “cloudspaces” for their licensed customer communities, to manage and distribute software in a controllable way.

Now, let me put my hand up and confess that all of this isn’t yet as smooth as we would like at Cloudsmith just right at the moment: it is an alpha version for the community to experiment with and give us feedback on. The materialization wizard, the wizard to build a cloudlink are IMHO both pretty good and straightforward to use. Private and public cloudspaces are ready to use. But today, the publishing wizard and the wizard to register a new repo are IMHO a bit clunky: we’re improving them right now and we expect better versions within a couple of weeks. Our online documentation is being improved. However, if you’re interested, contact us and we’ll talk you through online and get you involved in the Cloudsmith community.

Monday 20 August 2007

Cloudsmith goes live!

As some of you may know, I regularly holiday just outside Roundstone in Connemara. I’ve just come back to Dublin yesterday after some time there again.

If you haven’t yet been to the west of Ireland, I think one of the most striking things is the web of small stone walls that embrace the fields, pastures, meadows, boglands and tracts. Each is made by hand, and almost always as dry stone walls without mortar. They usually are as a result of clearing granite stones and rubble from the fields, and are economic: not requiring mortar, they do not suffer from frost attack, and so little maintenance is needed. At first sight, they all appear similar, but in fact there are different construction styles, with single, double and combination walls as the basic classification. They are malleable: walls can be easily moved and re-configured – gates are not strictly necessary since a few stones can easily be removed and put back again to, for example, let cattle through. Patrick McAfee’s book and website are a very readable commentary.

From ground level, the profusion of little stone walls can appear as a complex pattern, perhaps even fractal-like. But viewed from a high point, perspective reveals the logic of the landscape and the paths – the boreens – lined with walls either side, gently meandering to distant places.

I came back to Dublin last night, and this morning read Martin Banks’, of Reg Developer, excellent overview of Buckminster. Since I first wrote about Buckminster, the team has considerably improved the tool, including the documentation kit. Martin’s article makes use of a bricklaying analogy, and I guess I hinted in my own blog entry that if you are to build structures from re-usable bricks, then it might be useful to have a web site somewhere at which various designs could be published found and compared…

Well, also while I was away in Connemara, www.cloudsmith.com went live. Many of those on the Buckminster team have collaborated to put the site together, and the initial incarnation of the site certainly turned out to have richer functionality than I myself expected in a first iteration. There is a fairly detailed overview on the About Cloudsmith page, but in summary:

  • Cloudsmith keeps meta-data about assemblies of software components.
  • Software components can be sourced from any number of public and private repositories worldwide. Of course, components from private repositories are only available to those duly authorized to use them.
  • Cloudsmith does not store the components themselves: but it knows where they are worldwide and how it can access them in the appropriate repository formats.
  • A software publisher – an individual, project, or company – can register one or more specific software component assemblies with Cloudsmith.
  • A software consumer – an individual, project, or company – can search and browse for available assemblies; and can readily download and install any particular one – “materialize” in Cloudsmith-speak – onto his local machine (or indeed another machine if appropriately authorized).

In effect, Cloudsmith is building a global map of software components (in various forms: source, binary, versioned, and optionally with test suites, documentation and license agreements). Professional software developers - individually or in a community project or working on a commercial offering – can publish interesting new assemblies of components, sourced across one or more repositories.

One of the neatest capabilities of Cloudsmith is a Cloudlink. A Cloudlink is simply a URL: it can be sent in an email, or given in a blog or whatever. When a Cloudlink is clicked, the software assembly which it denotes is then materialized without further intervention, onto the local machine. This gives a very simple download mechanism: publish a Cloudlink, and anyone clicking on it within a recent-vintage web browser can download your software. In practice, when a Cloudlink is clicked, behind the scenes the Cloudsmith site is contacted, and it resolves the differences between the assembly of software components identified by the Cloudlink, and those already available on the local machine, and then fetches (as appropriate from various repositories worldwide) and downloads the missing components.

Cloudlinking in turn enables “virtual distributions”. A software publisher can create a virtual distro, whose components reside across multiple (eg open source) projects and repositories: materializing a virtual distro requires nothing more than a web browser.

If your project is looking for a simple way to make its software available to the worldwide community; if your project is itself using software from multiple sources and multiple projects; if you want to keep your community regularly updated with patches and extensions; if you want to manage installation and distribution processes; then Cloudsmith should be worth taking a look.

Software components, and configurations and assemblies of them, are very malleable. It is relatively easy to define new interesting configurations, as well as new components. Looking at the world wide activity, and the multitude of repositories and projects, it is easy to become overwhelmed. It is possible to detect patterns, and different styles of construction, but sometimes it can be very confusing to see overall themes, to understand how other people are using configurations, and what changes have occurred.

I’m reminded of Connemara’s dry stone walls. They are numerous, wonderful, simple, easily changed, easily re-built, easily maintained, and as a result have lasted for decades. But in the landscape and up close, they are confusing to absorb and see the overall picture. The perspective of height gives clarity.

Cloudsmith is giving clarity to the construction of assemblies of software components.

Thursday 21 June 2007

Software Patents: why should we have them ?

What should be the justification for software patents ?

Software patents are now emerging as a major influence on open source software. In 2003, there was SCO’s threatened litigation on Linux. Last November, Novell and Microsoft signed a major agreement in which Microsoft undertook not to dispute use of Microsoft’s patents in Novell’s SUSE Linux technology. More recently, Microsoft has claimed that Linux and open source technologies infringe 235 of its patents.

Major open source organisations like Eclipse and Apache scrutinise contributed source code to try and ensure there are no patent infringements. Furthermore, under some contribution agreements, an individual contributor may become personally liable if (s)he successfully inserts infringing code into such collaborations.

IMHO, software patents are sometimes granted by national patent offices with insufficient scrutiny regarding their originality. A patent should pass the “obviousness” test: the principles claimed in a patent should not be immediately obvious to normally skilled practitioners in the field at the time that those claims are made. Having said that, it is clear that many software patents do pass this test, and are sufficiently original.

It is also illuminating to note that even when a patent is subsequently over-turned by a national patent office, as being “obvious”, a litigant may still be successful. I understand that Research In Motion (who brought the Blackberry to market) settled their purported patent infringement case with NTP for over half a billion dollars, even after many of the patents were overturned by the patent office concerned: the Judge involved would not reconsider his judgement in the light of the overturning of the patents by the patent office.

While thinking about these issues, I was interested to see developments in the use of patents in the global pharmaceutical industry, in a recent Economist article, and wondered about parallels in the software industry.

Recently, the Government of Thailand invoked the compulsory licensing mechanism of the Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS), negotiated globally as part of the Uruguay round of the World Trade Organisation.

Under TRIPS, a government can invoke compulsory licensing (see article 31 “Other Use”) in the interests of national emergency or extreme urgency, such as arising from national health concerns, and if efforts to negotiate with the patent owner (for example a pharmaceutical multinational) fail. As a result, a generic drug replacement for a patented drug can either be manufactured domestically, or imported from a third country.

A quick aside, just in case you are unfamiliar with generic drugs. A generic drug contains the same active chemical ingredients as its patented original, but is distributed without a brand name. It is bio-equivalent to the original. A drug patent publishes a chemical structure, which then readily copied as a generic: alternatively, a patented drug can be fairly easily reverse-engineered to produce a generic. Of course, normally a generic drug can only be legally produced once the patent for its original expires, or in territories where the patent does not apply. Compulsory licensing under the TRIPS protocol yields a further way of legalising the use of a generic drug within a specific country.

In general, bringing a new drug successfully to market requires extensive trials, under a rigorous procedure closely supervised by a national drug regulator. This is both time consuming and costly for the inventor, and hence patents are valuable in enabling their owners recoup not only the research and development costs involved, but also the costs of the clinical trials and regulatory procedures. Correspondingly, because a generic drug is bio-equivalent to its patented original, a generic can quickly gain regulatory approval, and therefore its cost is significantly lower.

The trade-off in invoking the TRIPS compulsory licensing mechanism is between a short term gain to obtain a beneficial treatment at lower cost, and a medium to long term disincentive for the industry to invest in research and development for new drugs, particularly for diseases more prevalent in the third world and emerging economies. Equally, the full costs of bringing a new drug to market will be even more met by those countries which do not invoke compulsory licensing: in practice, by the markets of the more wealthy nations.

It is also significant that a middle income country like Thailand – rather than an impoverished country – has invoked compulsory licensing. It is rumoured that other such countries – for example Brazil, India, and Malaysia – are also considering the mechanism. Some of these countries – in particular India – have their own blossoming drugs industries, including investment in research into new drugs: it will be very interesting to observe how a strengthening domestic industry in such a country can be reconciled with compulsory licensing.

Back to the software industry. I found it interesting to consider what if compulsory licensing under TRIPS were to be used in the software industry as well as the pharmaceutical industry ?

If this were the case, a national government might invoke TRIPS compulsory licensing of one or more software patents, in the national interest. This would probably be primarily as a result of economic and/or social, rather than health, concerns. Compulsory licensing might be seen as a legitimate response by a government to punitive action threatened by an aggrieved patent holder against users of a patented technology, whether those users be in nationally strategic industries, the civil service itself and/or the national education system.

The technical consequence of compulsory licensing of a software patent is clearly not equivalent to compulsory licensing of a pharmaceutical drug. As I noted above, a generic drug can quickly be derived as a bio-equivalent of a patented drug. It is not nearly as easy to produce a software program which is equivalent in all respects to another program which is built using one or more patents, assuming that the source code of the patented work is unavailable. That is, there is no direct software analogy of generic drugs. Nevertheless, compulsory licensing of a software patent would remove the ability of the patent holder to impose punitive licensing terms on infringing software, including in particular infringing open source software.

If there were no intellectual property protection, would there be innovation ? Some open source protagonists would claim ‘absolutely, of course there can be’. I personally think that although there can be innovation in software without intellectual property, nevertheless so far, innovative and intellectual property free open source software is unfortunately rare. More frequently, open source software is a replacement for well established main stream technology: Linux, JBOSS and MySQL are all examples.

So, if there were compulsory licensing of software, would commercial software organisations become disenchanted with investing in innovation ? I started this blog entry by musing what should be the justification for software patents ? In my view, the pharmaceutical industry points the way for us in the software industry.

Consider. In the pharmaceutical industry, a new drug has to be extensively proven in trials, before the national regulator will permit that drug be sold. The resultant product is thus reasonably expected to be safe and to address the medical problem for which it is claimed. In return for this investment and careful procedure, the drug inventor can be awarded a patent.

By analogy then, should therefore a software patent only be awarded once the software products which exploit it, are carefully proven to be safe and effective, via documented testing and trial use ? Should there be national Software Administration Agencies, to which a prospective software patent holder should apply, providing extensive evidence of testing and trials under an auditable procedure to verify that use of the technology described by the prospective patent is effective and safe ?

As I think about testing software, I recall a comment to me by Andrew O’Sullivan (the VP at IONA responsible for professional services) last week. The willingness of enterprise customers to accept even a single bug in a software product today is substantially less than during the late 90s and the frantic dotcom era. Today, software is fully expected to work first time, and every time: any bug which comes to light seriously adversely reflects on the vendor concerned.

So: maybe software patents should only be awarded to verified high quality software, in the same way in which patented drugs have to first prove themselves in trials.

If this situation were ever put in place, what of the role of compulsory licensing ? Could a software patent be overturned by a compulsory license issued by a national government for national social and economic reasons, despite the investment made by the patent holder in proving that the software concerned was safe ?

In the pharmaceutical world, the equivalent is happening today to patented drugs. However in the software world, we would not obtain the same result. If a software patent is compulsory licensed, the associated software program(s) exploiting the software patent would not in general be as readily reverse engineered as is a patented drug to a generic drug. Instead, compulsory licensing would inhibit litigation potentially taken by a software patent holder against alleged infringements by other software programs (including open source). But these other software programs would not be identical in effect as the patent protected works – unlike a generic drug which is bio-equivalent to its patented original. In particular, these other software programs would not, by virtue of the compulsory licensing alone, be implicitly as verifiably safe as the regulated products directly using the patents.

In summary, there are some interesting similarities but critical differences between software and pharmaceuticals. It appears to me that there is merit in only awarding software patents to verifiably tested, safe and effective cases. It also appears that there could be an argument for compulsory licensing of software patents. Unlike the pharmaceutical industry and generic drugs, a compulsory licensed software patent would not enable an exact equivalent to be produced. Thus compulsory licensing would simply remove the threat of litigation against infringements. The patented software would be verifiably “safe”: the infringing software would not necessarily be “safe” since it would not necessarily have been subject to the full rigor of regulation. In my view, the outcome would be that commercial enterprises would remain incented, perhaps even more so, to produce patented products, and to ensure that these are safe and fault-free.

Monday 28 May 2007

Self-Service Software As (And?) A Service

It is an interesting time for the world of “Software As A Service”.

At some sort of cerebral level, Dell has been an inspiration for those contemplating a SaaS go-to-market strategy. Dell was renowned in the PC industry for largely avoiding the cost of enterprise sales and retail distribution channels, by instead connecting directly to end purchasers – whether domestic, small/medium business, or enterprise – as much as possible. It is very interesting thus that last week Dell announced, for the first time in 15 years, a retail deal: this time, with Wal-Mart to put some of its low end products directly onto the retailer’s shelves, as its “first step” into a retail channel. Dell apparently needs a distribution platform – and a retailer which 90% of American shoppers use is more attractive than most other retailers – through which to advertise some of its products.

Also this week, Ray Ozzie of Microsoft has stated that it is no longer about “Software As A Service” but “Software And A Service”! He was speaking at the Mix07 developers conference, and primarily promoting the Silverlight technology for Rich Internet Applications. Silverlight will be a runtime for .NET in various browsers – IE, Firefox and Safari – and compete with Flash, AJAX and Javascript to – in Microsoft’s view – provide a much richer video and interactive graphics experience for end users. Ozzie noted that (“fat”) client software not only supports offline usage, but also offers “privacy, empowerment, anonymity and freedom” compared to the “monitoring, auditing and creepy behaviour” of some online services. I guess this was a swipe in particular at Eric Schmidt at Google who is currently promoting substantially enhanced search experiences for end-users, albeit with the consequence of maintaining (private) information about each user.

An interesting part of Ozzie’s presentation was his announcement that Microsoft Live is offering a Silverlight Streaming service providing 4Gbytes of free storage per Silverlight developer, so as to encourage the development and hosting of Silverlight applications. So, if you are a S(as/and)aS developer or independent software vendor (ISV), Microsoft is potentially offering you a rapid way to scale up to address a massive online audience, based on MSN and now not just IE but other browsers as well: up to 1 million unique end users can access your application for free (above that, its 25c per unique user). It will be interesting to see how Google responds..

IMHO we will continue to see a mix of pure software-as-a-service applications (with thin clients); online services with companion client applications (including rich internet access), and fat clients accessing remote services from time to time. There will continue to be a spectrum of configurations.

Regardless, I believe that a critical aspect of S(as/and)aS applications is the ability to scale self-service. Whether you use Silverlight Streaming, Google, Salesforce.com’s Apex or even Wal-Mart (as Dell is doing) to reach a potential audience of millions, I believe that a S(as/and)aS application will be unsuccessful if scaling of its adoption requires manual intervention for every transaction.

Self-service is key to S(as/and)aS – whilst at the same time ensuring that the customer’s experience is happy and helpful. Dell’s appearance in Wal-Mart may in part be due to reports of poor customer service with a purely online self-service store.

One example of online software self-service is of course the open source community. What could be more self-service than downloading source code, and playing and building it yourself ? A common open source business model is to extend self-service with technical support and training. But in turn, this customer support will best be implemented by at least some degree of self-service: witness IONA’s various support offerings for its Celtix family of open source products, including a self-service knowledge base alongside telephone and email support.

LeCayla’s self-service philosophy goes further. In providing SaaS metering and billing, LeCayla’s technology has to address two audiences. The first is end-users of SaaS offerings: LeCayla measures usage, and generates bills and invoices according to actual usage, and in accordance with specific business rules defined by a particular SaaS ISV or application software provider. Naturally, it is desirable that each end-user may use a self-service interface: eg to check her usage, or to change billing information such as a credit card number.

The second audience for LeCayla is the ISVs who want to use LeCayla to meter and bill for use of their software products. Each such ISV registers business rules (eg pricing information, usage tiers, etc) into LeCayla. Furthermore, each such ISV may wish to subsequently change its own business rules at any time – for example for a pricing promotion of a particular product within a particular geography. Naturally it is desirable that not only should end-users have self service to their own usage and billing information; but also that each ISV should also likewise have self-service to its own business rules, as well as to its market adoption metrics and usage information.

For Cloudsmith – the third software company in which I am involved – self-service is also key. As I noted in a previous posting, sometimes creative developers have different configurations that they seek, or want to define, share and publish to the world. Can interesting new virtual distributions be rapidly defined, communicated and materialized ?”. Cloudsmith will enable developers to self-service find and use interesting software configurations, each frequently materialised from different software repositories (and sometimes using widely different repository technologies and build/make systems). Equally, publishing a new configuration, either to the entire world or to a private community of collaborating developers, will be a self-service activity.

Self-service seems to be intrinsic to scaling software services offered over the internet. Self-serviced services must naturally be scaleable: poor customer support and dissatisfaction will otherwise result. In a self-service, service oriented world, multiple business models are IMHO possible: for example, free access with optional paid-for support and consultancy (IONA’s approach with Celtix as per above); metered usage (LeCayla’s approach); or community based (Cloudsmith’s). I believe that scalable self-service underpins any viable service oriented business model.

Not all S(and/as)aS transactions should be self-service. But unless your S(and/as)aS business model facilitates self-service, then you may be scaleably challenged!