diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-05 08:59:06 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-05 09:20:38 +0200 |
| commit | cce8a911553597ada33e275bc9b29fd34121074d (patch) | |
| tree | 58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packaging/build | |
| parent | bacab81915a9ab640437b7d674bf9e29e701b1f1 (diff) | |
| download | meshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz | |
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so
any client may use it whatever its own licence: meshbay-common, and the files
marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js,
transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop;
Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is
AGPL-3.0-or-later, which the RPM specs and package.json already declared
without a licence file to back them.
Two AGPL section 7 permissions:
- group applications may be under any licence when they use the interface
only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt);
the reference application is 0BSD so that copying it brings no AGPL code;
- the Android application may be conveyed linked with Google Play services.
Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from
what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and
the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its
BSD licence does not mention — and the vendored browser libraries get their
licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata,
RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt.
test_licensing.py holds the line: the LGPL layer imports nothing under the
AGPL, the reference application nothing outside the application interface,
and every SPDX line is one of the known ones.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packaging/build')
| -rwxr-xr-x | packaging/build/build-common.sh | 5 | ||||
| -rwxr-xr-x | packaging/build/build-packages.sh | 35 |
2 files changed, 40 insertions, 0 deletions
diff --git a/packaging/build/build-common.sh b/packaging/build/build-common.sh index 3045689..5f119c6 100755 --- a/packaging/build/build-common.sh +++ b/packaging/build/build-common.sh @@ -44,6 +44,11 @@ echo " installing all packages + dependencies" --find-links "$WHEEL_DIR" \ meshbay-common meshbay-hub meshbay-node 2>&1 | tail -3 +# --- Third-party notices: every package the venv ships, with its licence ------- +echo " writing THIRD-PARTY-NOTICES.txt" +"$VENV_BUILD/bin/python" "$REPO/packaging/third_party_notices.py" \ + -o "$ROOT/opt/meshbay-common/THIRD-PARTY-NOTICES.txt" meshbay-hub meshbay-node + # --- Strip build tools from the venv (not needed at runtime) --------------- echo " stripping build tools" "$VENV_BUILD/bin/pip" uninstall -y pip setuptools wheel 2>&1 | tail -1 diff --git a/packaging/build/build-packages.sh b/packaging/build/build-packages.sh index ccacb81..8ca0e23 100755 --- a/packaging/build/build-packages.sh +++ b/packaging/build/build-packages.sh @@ -84,6 +84,38 @@ echo "" echo "--- Packaging ($FORMAT) ---" if [ "$FORMAT" = "deb" ]; then + # Debian policy: /usr/share/doc/<pkg>/copyright, machine-readable. The LGPL + # is in /usr/share/common-licenses and is referred to; the AGPL is not, so + # its full text goes in, as a DEP-5 licence paragraph (indented, "." for a + # blank line). + install_copyright() { + local pkg="$1" root="$2" + local doc="$root/usr/share/doc/$pkg" + mkdir -p "$doc" + { + echo "Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/" + echo "Upstream-Name: MeshBay" + echo "Source: https://git.meshbay.org/" + echo "" + echo "Files: *" + echo "Copyright: MeshBay contributors" + if [ "$pkg" = "meshbay-common" ]; then + echo "License: LGPL-3.0-or-later" + echo " On Debian systems, the full text of the GNU Lesser General Public" + echo " License version 3 is in /usr/share/common-licenses/LGPL-3, and the" + echo " GNU General Public License it builds on in /usr/share/common-licenses/GPL-3." + echo " ." + echo " The venv under /opt/meshbay-common carries the Python packages MeshBay" + echo " depends on, each under its own licence; they are listed, with their" + echo " licence texts, in /opt/meshbay-common/THIRD-PARTY-NOTICES.txt." + else + echo "License: AGPL-3.0-or-later" + sed -e 's/^$/./' -e 's/^/ /' "$REPO/LICENSE" + fi + } > "$doc/copyright" + chmod 644 "$doc/copyright" + } + build_deb() { local pkg="$1" local root="$STAGING/${pkg}-root" @@ -102,6 +134,8 @@ if [ "$FORMAT" = "deb" ]; then [ -f "$deb_dir/control" ] && chmod 644 "$deb_dir/control" [ -f "$deb_dir/conffiles" ] && chmod 644 "$deb_dir/conffiles" + install_copyright "$pkg" "$root" + dpkg-deb --build --root-owner-group "$root" "$OUT/${pkg}_${VERSION}_${ARCH}.deb" echo " -> $OUT/${pkg}_${VERSION}_${ARCH}.deb" } @@ -127,6 +161,7 @@ elif [ "$FORMAT" = "rpm" ]; then rpmbuild \ --define "_topdir $RPMBUILD_DIR" \ --define "_staging_root $root" \ + --define "_repo_root $REPO" \ -bb "$RPMBUILD_DIR/SPECS/${pkg}.spec" 2>&1 | tail -5 local rpm_file |