summaryrefslogtreecommitdiffstats
path: root/packaging/win
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-05 08:59:06 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-05 09:20:38 +0200
commitcce8a911553597ada33e275bc9b29fd34121074d (patch)
tree58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packaging/win
parentbacab81915a9ab640437b7d674bf9e29e701b1f1 (diff)
downloadmeshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packaging/win')
-rw-r--r--packaging/win/build-node-runtime.ps116
-rw-r--r--packaging/win/electron-builder.light.yml4
-rw-r--r--packaging/win/electron-builder.msix.yml4
3 files changed, 24 insertions, 0 deletions
diff --git a/packaging/win/build-node-runtime.ps1 b/packaging/win/build-node-runtime.ps1
index 371311b..1171146 100644
--- a/packaging/win/build-node-runtime.ps1
+++ b/packaging/win/build-node-runtime.ps1
@@ -109,6 +109,22 @@ if (-not (Test-Path (Join-Path $frozen "meshbay-node.exe"))) {
throw "PyInstaller did not produce meshbay-node.exe at $frozen"
}
+# --- 3b. licences ----------------------------------------------------
+# The frozen tree is a distribution of every package in it, so each one's
+# licence goes with it: MeshBay's own (AGPL for the node, LGPL for the common
+# library it embeds) and THIRD-PARTY-NOTICES.txt, generated from the build
+# venv's own metadata -- PyAV's wheel, for one, grafts in a GPL FFmpeg build
+# (libx264, libx265) that its BSD licence does not mention. PyInstaller's
+# bootloader and the interpreter ship too, without being a requirement.
+Step "writing licence notices"
+Copy-Item (Join-Path $Repo "LICENSE") (Join-Path $frozen "LICENSE.txt")
+Copy-Item (Join-Path $Repo "packages\meshbay-common\COPYING.LESSER") (Join-Path $frozen "LICENSE-meshbay-common.txt")
+Copy-Item (Join-Path $Repo "packages\meshbay-common\COPYING") (Join-Path $frozen "LICENSE-GPL-3.0.txt")
+& $Python (Join-Path $Repo "packaging\third_party_notices.py") `
+ -o (Join-Path $frozen "THIRD-PARTY-NOTICES.txt") `
+ meshbay-node tzdata --extra pyinstaller --with-python
+if ($LASTEXITCODE -ne 0) { throw "third_party_notices.py failed" }
+
# --- 4. ffmpeg (bundled by default) -----------------------------------
if ($SkipFfmpeg -or $env:MESHBAY_SKIP_FFMPEG -eq "1") {
Write-Host " !! ffmpeg not bundled (-SkipFfmpeg) -- the node will look for it on PATH, and streaming needs it installed separately" -ForegroundColor Yellow
diff --git a/packaging/win/electron-builder.light.yml b/packaging/win/electron-builder.light.yml
index 502a3c5..6cd2b0d 100644
--- a/packaging/win/electron-builder.light.yml
+++ b/packaging/win/electron-builder.light.yml
@@ -36,6 +36,10 @@ win:
# ICE + the 2 LAN-casting rules) and logs the node rule as skipped.
- from: ../../packaging/win/firewall.ps1
to: firewall.ps1
+ # The application's own licence, beside the app (Electron's LICENSE and
+ # LICENSES.chromium.html are put next to the exe by electron-builder).
+ - from: ../../LICENSE
+ to: LICENSE.txt
nsis:
oneClick: false
diff --git a/packaging/win/electron-builder.msix.yml b/packaging/win/electron-builder.msix.yml
index 5460267..d3adad6 100644
--- a/packaging/win/electron-builder.msix.yml
+++ b/packaging/win/electron-builder.msix.yml
@@ -69,6 +69,10 @@ win:
# anticipated in the original plan).
- from: ../../packaging/win/ensure-node-path.ps1
to: ensure-node-path.ps1
+ # The application's own licence, beside the app (Electron's LICENSE and
+ # LICENSES.chromium.html are put next to the exe by electron-builder).
+ - from: ../../LICENSE
+ to: LICENSE.txt
appx:
# --- Real values, from Partner Center's "App identity" page (App