A successful fork of a popular open source project is easier said than done
The other day I wrote about some drama playing out in the open source Nagios community. As a result of that article, I have been contacted by parties on both side of this dispute and have a keener insight into what I think really went down here. I will give you my interpretation of what happened in a moment. In a nutshell though, when money and egos are involved, even the best of intentions can wind up lining the road to perdition. The lesson though is that the whoever owns the copyright generally calls the shot. Yes you can fork any open source project pursuant to its license, but having a successful fork is easier said than done.
I myself have seen this happen a few times in my own experience in the security industry. The very popular open source Nessus vulnerability scanner came under the control of Tenable Network Security when the owner of the Nessus copyright helped found Tenable. Shortly thereafter, Tenable started asserting some of its legal rights as the copyright owner of the program. Eventually, new versions of the Nessus scanner were released under a non-open source license. Some in the community (including me) cried foul. After all it was “against the spirit” of open source. There were many who contributed to the code besides the Tenable folks (it turned out there really wasn’t. As in most open source projects there was a small cadre of people who contributed the lions share of code), people yelled fork, fork. Ron Gula, the Tenable CEO said go ahead and fork, you are certainly allowed to. Some tried and there even some still around I believe. But all in all the furor died down and people still use Nessus. They don’t care about whether it is open, but care more about is it free (as in beer) and does it work.
A similar story surrounds the open source IDS Snort. When Marty Roesch first started Sourcefire there were many who had doubts about whether Snort would remain open source. There were calls for forks and alternatives. That story is still playing out today. Have a listen to my podcast with Matt Jonkman if you are interested. The bottom line and the lesson to be learned from both of these examples is that the people who “own” the project copyright have a legal advantage that is difficult to overcome. In essence they can take their ball and play without you. While you have the legal right to fork, there is more to a fork than just taking the code and giving it a good name. It is the rare fork that becomes more successful than the original project. A lesson perhaps for the OpenLibre and SkySQL folks.
In the case of Nagios it looks like the folks over in Europe had been “contributing” to the community in their own way for some time. They had set up sites for plug in extensions to Nagios and other community related resources. The Netways company did evidently even register a Nagios trademark in Germany, to “protect the Nagios name” there. Whether that was the reason or not, who knows, but that is his story. The bottom line is no one really gave a hoot here until Nagios Enterprises was founded in 2007 and a commercial model began to develop for Nagios.
Many on the other side of this argument began to feel that this was a betrayal of the community and what Nagios stood for. They took it upon themselves to protect the open source Nagios project. Unfortunately for them, it wasn’t theirs to protect. At the end of the day despite their perhaps best intentions the rightful owner of the brand has a right to it. That is what happened here. Whether people like it or not Ethan Galstad is in control of Nagios. When he exerted his rights, feelings may be bruised or hurt, but he is well within his rights to do so.
So politics of this case aside. If you are involved in an open source project learn from the history here. Because you know those that don’t learn from it are destined to repeat the same mistakes again.




