diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-05 08:59:06 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-05 09:20:38 +0200 |
| commit | cce8a911553597ada33e275bc9b29fd34121074d (patch) | |
| tree | 58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packaging/rpm/meshbay-common.spec | |
| parent | bacab81915a9ab640437b7d674bf9e29e701b1f1 (diff) | |
| download | meshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz | |
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so
any client may use it whatever its own licence: meshbay-common, and the files
marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js,
transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop;
Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is
AGPL-3.0-or-later, which the RPM specs and package.json already declared
without a licence file to back them.
Two AGPL section 7 permissions:
- group applications may be under any licence when they use the interface
only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt);
the reference application is 0BSD so that copying it brings no AGPL code;
- the Android application may be conveyed linked with Google Play services.
Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from
what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and
the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its
BSD licence does not mention — and the vendored browser libraries get their
licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata,
RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt.
test_licensing.py holds the line: the LGPL layer imports nothing under the
AGPL, the reference application nothing outside the application interface,
and every SPDX line is one of the known ones.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packaging/rpm/meshbay-common.spec')
| -rw-r--r-- | packaging/rpm/meshbay-common.spec | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/packaging/rpm/meshbay-common.spec b/packaging/rpm/meshbay-common.spec index 147dc17..cad00b7 100644 --- a/packaging/rpm/meshbay-common.spec +++ b/packaging/rpm/meshbay-common.spec @@ -2,7 +2,9 @@ Name: meshbay-common Version: __VERSION__ Release: 1%{?dist} Summary: MeshBay shared Python runtime and libraries -License: AGPLv3+ +# The venv carries every Python dependency, each under its own licence: +# /opt/meshbay-common/THIRD-PARTY-NOTICES.txt lists them. +License: LGPL-3.0-or-later URL: https://meshbay.org AutoReqProv: no @@ -16,6 +18,9 @@ Installs to /opt/meshbay-common/venv/. %install cp -a %{_staging_root}/* %{buildroot}/ +install -Dm644 -t %{buildroot}%{_licensedir}/%{name} \ + %{_repo_root}/packages/meshbay-common/COPYING \ + %{_repo_root}/packages/meshbay-common/COPYING.LESSER # Bytecode written at run time into __pycache__ is not the package's, and would # keep rpm from removing a directory the new version no longer ships. @@ -32,6 +37,7 @@ if [ "$1" -eq 0 ]; then fi %files +%license %{_licensedir}/%{name} /opt/meshbay-common %changelog |