Repository navigation
RFC: Beyond donations (not working, whatever reason) - make users pay for maintained open source firmware #2195
Description
Activity
- changed the title
[-]RFC: Beyound donations (not working, whatever reason) - make users pay for maintained open sourcefirmware[/-][+]RFC: Beyound donations (not working, whatever reason) - make users pay for maintained open source firmware[/+]on Aug 26, 2026 You don't want to pay? why?
Would you rather instead
- pay per feature
- pay per update
- pay per fix
- pay for everything flat fee/subscriptions ?
Free as free beer doens't exist sorry. Woould you do your 9-5 free? Why would I? Because you don't know me? Well. I might as well just disappear then what?
- changed the title
[-]RFC: Beyound donations (not working, whatever reason) - make users pay for maintained open source firmware[/-][+]RFC: Beyond donations (not working, whatever reason) - make users pay for maintained open source firmware[/+]on Aug 26, 2026 @tlaurion I think you should start tracking where your time goes. From my perspective, a large amount of your time goes to answering questions that are already answered in the wiki from people who need their hand held through the process. However, that may not be where most of your time goes and therefore I do not know what to suggest.
Other than that, I think you should also consider consultation fees.
Reacted by Thierry LaurionHi @tlaurion
I only run open source software. I do donate to projects I rely on. I have only only recently started using Heads, I'm not sure whether I will use it long term, so I haven't donated.This post worries me.
I do understand your need to make a living, but if you think about gating updates or fixes it would make me reconsider using your software in the first place.I'm ok with paid features. I think it's fair to offer a more featureful proprietary version. I won't buy it, but I'm ok with you offering it.
In my opinion Heads is too niche. You need special equipment to even run it. I assume your user base is simply too small to sustain you on donations.
Since Heads support is tied to hardware I think I would be willing to pay for hardware supporting it. I don't know whether you make money by partnering with laptop companies but I would be willing to pay $50 to $100 more for Heads support and you should profit off of that.
Otherwise I would advise you to look for another job and adjust your time on Heads maintenance to what seems appropriate according to the donations coming in.
Reacted by Thierry LaurionReacted by Thierry LaurionHi @tlaurion
I only run open source software. I do donate to projects I rely on. I have only only recently started using Heads, I'm not sure whether I will use it long term, so I haven't donated.This post worries me.
I do understand your need to make a living, but if you think about gating updates or fixes it would make me reconsider using your software in the first place.Same here. I'm wondering if for the sake of security and reproducibility, I made it a bit too easy for people to not realize the quantity of engineering and work done to have each commit produce roms people can flash without even having to build it themselves through Circleci?
I'm ok with paid features. I think it's fair to offer a more featureful proprietary version. I won't buy it, but I'm ok with you offering it.
Paid services would be firmware as service, which had pushback from downstream relying on Heads (qubesos, partners etc) not wanting network in firmware
Other then that, not sure how to monetize firmware as services.
My take was https://youtu.be/It13u9UASs4?si=gz8epqzS4vK1gTzz
In my opinion Heads is too niche. You need special equipment to even run it. I assume your user base is simply too small to sustain you on donations.
Hard to tell how many users.
Since Heads support is tied to hardware I think I would be willing to pay for hardware supporting it. I don't know whether you make money by partnering with laptop companies but I would be willing to pay $50 to $100 more for Heads support and you should profit off of that.
http://osresearch.net/Vendors/
I receive small proportion of each dasharo+heads subscription sold by partners.
Otherwise I would advise you to look for another job and adjust your time on Heads maintenance to what seems appropriate according to the donations coming in.
That is what I'm considering right now after having dedicated professional work on Heads since 2017.
Hi @tlaurion
I only run open source software. I do donate to projects I rely on. I have only only recently started using Heads, I'm not sure whether I will use it long term, so I haven't donated.This post worries me.
I do understand your need to make a living, but if you think about gating updates or fixes it would make me reconsider using your software in the first place.Same here. I'm wondering if for the sake or security and reproducibility, I made it a bit too easy for people to not realize the quantity of engineering and work done to have each commit produce roms people can flash without even having to build it themselves through Circleci?
I'm ok with paid features. I think it's fair to offer a more featureful proprietary version. I won't buy it, but I'm ok with you offering it.
Paid services would be firmware as service, which had pushback from downstream relying on Heads (qubesos, partners etc) not wanting network in firmware
Other then that, not sure how to monetize firmware as services.
My take was https://youtu.be/It13u9UASs4?si=gz8epqzS4vK1gTzz
In my opinion Heads is too niche. You need special equipment to even run it. I assume your user base is simply too small to sustain you on donations.
Hard to tell how many users.
Since Heads support is tied to hardware I think I would be willing to pay for hardware supporting it. I don't know whether you make money by partnering with laptop companies but I would be willing to pay $50 to $100 more for Heads support and you should profit off of that.
http://osresearch.net/Vendors/
I receive small proportion of each dasharo+heads subscription sold by partners.
Otherwise I would advise you to look for another job and adjust your time on Heads maintenance to what seems appropriate according to the donations coming in.
That is what I'm considering right now after having dedicated professional work on Heads since 2017.
@goetschp Thank you for your feedback.
Modified with proper link to conf.
@tlaurion of course you need a job. you have a life and we all are thankful for what you and others do here. @goetschp is right with heads being a niche product. A lot of people i know don't even know what a bios/uefi is....
So yes i think getting a job for having a secured income is the way that anybody will understand, you did a lot for the project over the years.
My ideas for givingblock and techccult i have commented on another issue.
Maybe sell something like the pro package for other boards e.g. T480 or some modern desktops boards while also have an wiki entry for the people who want to build the firmware by themselves.
Also offering customisation with eg background colors, bootlogo, systeminfo etc for small companys selling coreboot laptops?
AND maybe let those building the firmware by themselves pay a consultation fee for answering questions by you or direct them in the wiki to matrix community channel.
I'd definitely pay for a tested firmware binary built from open source code.
(For example here's a great open source project that monetizes a bit via its binary downloads: https://ardour.org/)However the issue right now is that tons of boards are untested, i.e. I'm less of a customer and more of a tester.
Also, I guess the number of boards supported by heads is too low to reach any meaningful market share unless modern boards are supported (dasharo seems to focus on that).
Taking my thoughts from the Matrix channel.
It isn't too clear where to donate, and using GitHub sponsorships requires I use a VAT ID, which is a business related thing. Maybe the README, or repo descriptor? It may be worth making it a bit more prominent.Also I don't know how many dozens of people use heads, but I would imagine not too many.
I'd definitely pay for a tested firmware binary built from open source code. (For example here's a great open source project that monetizes a bit via its binary downloads: https://ardour.org/)
Well, for right now they're available through CircleCI. I think its a good idea though.
However the issue right now is that tons of boards are untested, i.e. I'm less of a customer and more of a tester.
Also, I guess the number of boards supported by heads is too low to reach any meaningful market share unless modern boards are supported (dasharo seems to focus on that).
To be fair, boards with Coreboot should be able to run Heads fine, though Heads uses an older version by default. NitroKey do sell 12th gen laptops. Not sure if the decision is to use newer coreboot versions, or to backport support (and that's not my call to make). I think Heads is keeping with Dasharo.
There's just not enough people using Heads on such a variety of hardware to be making said ports.
To be fair, boards with Coreboot should be able to run Heads fine, though Heads uses an older version by default. NitroKey do sell 12th gen laptops. Not sure if the decision is to use newer coreboot versions, or to backport support (and that's not my call to make). I think Heads is keeping with Dasharo.
There's just not enough people using Heads on such a variety of hardware to be making said ports.
Agreed, this is where contributions like the t480/t480s/m900/chromebooks and all others
- past ports https://github.com/linuxboot/heads/pulls?q=is%3Apr+label%3Aport+is%3Aclosed
- new ports https://github.com/linuxboot/heads/pulls?q=is%3Apr+label%3Aport+is%3Aopen
Chromebooks would change that landscape. New vendors would change that landscape. "Firmware as services" too. Not the current status quo.
Are all ports I consider investing time for some ROI. Otherwise having contractual $ contribution/code contribution agreements with
To be fair, the reaility of bootguard fused keys on newer platforms sold by vendors IS the reason not so much platforms either get a coreboot port, and those who gets it need to be prefixed EOL because they are from a supported CPU vendor perspective.
As for donations, @NobodyNo0ne @Thrilleratplay please check
Please check https://github.com/linuxboot/heads-wiki/pull/237/changesThis doesn't solve #2166, but
Proven way forward is to make users pay for open source.
Are still proven research, showing that donations are not enough to make open source projects self-subsisting.
I'd definitely pay for a tested firmware binary built from open source code. (For example here's a great open source project that monetizes a bit via its binary downloads: https://ardour.org/)
Thanks @3hhh
However the issue right now is that tons of boards are untested, i.e. I'm less of a customer and more of a tester.
cat doc/BOARDS_AND_TESTERS.md | grep 3hh - [ ] t530 (xx30): @fhvyhjriur @3hhh (See: https://github.com/linuxboot/heads/issues/1682)Sorry if I missed something, but the t530 is yet marked as untested because not a lot of users claimed ownership of that platform and tested it on 25.12 :(
One issue to open to say its tested, better, flip it in PR to tested and it will be marked as such: the naming is there to prevent newcomers to flash and expect it working on an untested board. I haven't came with a better solution; and it should not be hard for people to test, even less when there is other boards in the same family that were reported as working; yet in the past there were regression os s3, usb and other expected to work things that worked on one board and yet not on another.
Also, I guess the number of boards supported by heads is too low to reach any meaningful market share unless modern boards are supported (dasharo seems to focus on that).
Yes. Because people are less and less interested in testing EOL boards, which coreboot ports tend to support. Yet again, that depends on the use case, and https://tlaurion.github.io/heads-wiki/Heads-threat-model/#per-board-protection-status.... Again there, newer boards need to be made/built in bulk without bootguard keys fused to be https://osresearch.net/Vendors/
And yet again, all those ports need someone to make them, someone to guide/help them to become free/maintained, and tested by some. Not sure what to do better here, but happy to listen.
To be fair, boards with Coreboot should be able to run Heads fine, though Heads uses an older version by default. NitroKey do sell 12th gen laptops. Not sure if the decision is to use newer coreboot versions, or to backport support (and that's not my call to make). I think Heads is keeping with Dasharo.
There's just not enough people using Heads on such a variety of hardware to be making said ports.
Agreed, this is where contributions like the t480/t480s/m900/chromebooks and all others
* past ports https://github.com/linuxboot/heads/pulls?q=is%3Apr+label%3Aport+is%3Aclosed * new ports https://github.com/linuxboot/heads/pulls?q=is%3Apr+label%3Aport+is%3AopenChromebooks would change that landscape. New vendors would change that landscape. "Firmware as services" too. Not the current status quo.
I think coreboot upstream has support for chromebooks. The NitroKey laptops are also EXPENSIVE (I assume as R&D for making sure things work), which is why I did not want NovaCustom/NitroKey, or other such device, and stuck with an X280. I should have mentioned that in my previous comment. So there is a bar of entry there. I have never had/never liked chromebooks though
Are all ports I consider investing time for some ROI. Otherwise having contractual $ contribution/code contribution agreements with
* https://osresearch.net/Vendors/To be fair, the reaility of bootguard fused keys on newer platforms sold by vendors IS the reason not so much platforms either get a coreboot port, and those who gets it need to be prefixed EOL because they are from a supported CPU vendor perspective.
As for donations, @NobodyNo0ne @Thrilleratplay please check Please check https://github.com/linuxboot/heads-wiki/pull/237/changes
This doesn't solve #2166, but
Proven way forward is to make users pay for open source.
Are still proven research, showing that donations are not enough to make open source projects self-subsisting.
It would help to have a clearer path to donate though, but not end-all-be-all
I'd definitely pay for a tested firmware binary built from open source code. (For example here's a great open source project that monetizes a bit via its binary downloads: https://ardour.org/)
^ Is a nice idea. I did not want to put it forward because of how CircleCI/reproducibility is handled for now.
Also, I guess the number of boards supported by heads is too low to reach any meaningful market share unless modern boards are supported (dasharo seems to focus on that).
Yes. Because people are less and less interested in testing EOL boards, which coreboot ports tend to support. Yet again, that depends on the use case, and https://tlaurion.github.io/heads-wiki/Heads-threat-model/#per-board-protection-status.... Again there, newer boards need to be made/built in bulk without bootguard keys fused to be https://osresearch.net/Vendors/
I think OpenSIL is coming to laptops, and Framework seems to be working on that. Given Intel will probably stay averse to firmware modifications, I hope OpenSIL offers that modern hardware.
And yet again, all those ports need someone to make them, someone to guide/help them to become free/maintained, and tested by some. Not sure what to do better here, but happy to listen.
I might be able to get some ports/guides in passing, but I won't be able to maintain them unless I want to end up keeping about a hundred laptops or so... I'm not too sure, since most people would gravitate to the T480/s specifically if they are able to, or some alderlake (like novacustom) to avoid EOL (far more expensive).
This is turning into a long comment
From Matrix room
Donation for europe (Qubes Project uses this):
https://techcultivation.org/Crypto maybe (signal messenger using it):
https://thegivingblock.com/Hellotux (Qubes Project):
https://www.hellotux.comGerman Sovereign Tech Fund (cURL, Arch Linux, FreeBSD, etc):
https://www.sovereign.tech/programs/fundMaybe there is something useful for supporting heads
Proven way forward is to make users pay for open source.
links recommended by @pietrushnic to change my free tier mindset; arriving to the point I cannot dismiss/deny/live in another multiverse.
Against/amends #2166 #2027 if not probable (not usage of word probable, proven in history and posterity see https://opencollective.com/insurgo/transactions
Interesting input of this thread: