summaryrefslogtreecommitdiffstats
path: root/packaging/build
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-05 08:59:06 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-05 09:20:38 +0200
commitcce8a911553597ada33e275bc9b29fd34121074d (patch)
tree58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packaging/build
parentbacab81915a9ab640437b7d674bf9e29e701b1f1 (diff)
downloadmeshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packaging/build')
-rwxr-xr-xpackaging/build/build-common.sh5
-rwxr-xr-xpackaging/build/build-packages.sh35
2 files changed, 40 insertions, 0 deletions
diff --git a/packaging/build/build-common.sh b/packaging/build/build-common.sh
index 3045689..5f119c6 100755
--- a/packaging/build/build-common.sh
+++ b/packaging/build/build-common.sh
@@ -44,6 +44,11 @@ echo " installing all packages + dependencies"
--find-links "$WHEEL_DIR" \
meshbay-common meshbay-hub meshbay-node 2>&1 | tail -3
+# --- Third-party notices: every package the venv ships, with its licence -------
+echo " writing THIRD-PARTY-NOTICES.txt"
+"$VENV_BUILD/bin/python" "$REPO/packaging/third_party_notices.py" \
+ -o "$ROOT/opt/meshbay-common/THIRD-PARTY-NOTICES.txt" meshbay-hub meshbay-node
+
# --- Strip build tools from the venv (not needed at runtime) ---------------
echo " stripping build tools"
"$VENV_BUILD/bin/pip" uninstall -y pip setuptools wheel 2>&1 | tail -1
diff --git a/packaging/build/build-packages.sh b/packaging/build/build-packages.sh
index ccacb81..8ca0e23 100755
--- a/packaging/build/build-packages.sh
+++ b/packaging/build/build-packages.sh
@@ -84,6 +84,38 @@ echo ""
echo "--- Packaging ($FORMAT) ---"
if [ "$FORMAT" = "deb" ]; then
+ # Debian policy: /usr/share/doc/<pkg>/copyright, machine-readable. The LGPL
+ # is in /usr/share/common-licenses and is referred to; the AGPL is not, so
+ # its full text goes in, as a DEP-5 licence paragraph (indented, "." for a
+ # blank line).
+ install_copyright() {
+ local pkg="$1" root="$2"
+ local doc="$root/usr/share/doc/$pkg"
+ mkdir -p "$doc"
+ {
+ echo "Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/"
+ echo "Upstream-Name: MeshBay"
+ echo "Source: https://git.meshbay.org/"
+ echo ""
+ echo "Files: *"
+ echo "Copyright: MeshBay contributors"
+ if [ "$pkg" = "meshbay-common" ]; then
+ echo "License: LGPL-3.0-or-later"
+ echo " On Debian systems, the full text of the GNU Lesser General Public"
+ echo " License version 3 is in /usr/share/common-licenses/LGPL-3, and the"
+ echo " GNU General Public License it builds on in /usr/share/common-licenses/GPL-3."
+ echo " ."
+ echo " The venv under /opt/meshbay-common carries the Python packages MeshBay"
+ echo " depends on, each under its own licence; they are listed, with their"
+ echo " licence texts, in /opt/meshbay-common/THIRD-PARTY-NOTICES.txt."
+ else
+ echo "License: AGPL-3.0-or-later"
+ sed -e 's/^$/./' -e 's/^/ /' "$REPO/LICENSE"
+ fi
+ } > "$doc/copyright"
+ chmod 644 "$doc/copyright"
+ }
+
build_deb() {
local pkg="$1"
local root="$STAGING/${pkg}-root"
@@ -102,6 +134,8 @@ if [ "$FORMAT" = "deb" ]; then
[ -f "$deb_dir/control" ] && chmod 644 "$deb_dir/control"
[ -f "$deb_dir/conffiles" ] && chmod 644 "$deb_dir/conffiles"
+ install_copyright "$pkg" "$root"
+
dpkg-deb --build --root-owner-group "$root" "$OUT/${pkg}_${VERSION}_${ARCH}.deb"
echo " -> $OUT/${pkg}_${VERSION}_${ARCH}.deb"
}
@@ -127,6 +161,7 @@ elif [ "$FORMAT" = "rpm" ]; then
rpmbuild \
--define "_topdir $RPMBUILD_DIR" \
--define "_staging_root $root" \
+ --define "_repo_root $REPO" \
-bb "$RPMBUILD_DIR/SPECS/${pkg}.spec" 2>&1 | tail -5
local rpm_file