From cce8a911553597ada33e275bc9b29fd34121074d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 5 Oct 2026 08:59:06 +0200 Subject: chore: license MeshBay — LGPL protocol layer, AGPL for the rest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 --- README.md | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) (limited to 'README.md') diff --git a/README.md b/README.md index a3d0f06..ebbc1a3 100644 --- a/README.md +++ b/README.md @@ -57,6 +57,44 @@ pip install -e "packages/meshbay-common[dev]" -e "packages/meshbay-hub[dev]" \ .venv/bin/pytest ``` +## Licence + +MeshBay is free software. + +| Component | Licence | +|---|---| +| `packages/meshbay-common/` — the protocol and its cryptography, in Python | [LGPL-3.0-or-later](packages/meshbay-common/COPYING.LESSER) (with the [GPL-3.0](packages/meshbay-common/COPYING) it builds on) | +| The same layer in the clients: the files marked `SPDX-License-Identifier: LGPL-3.0-or-later` — in the interface, `keyderive.js`, `crypto.js`, `playlist-crypto.js`, `transport.js` and `transport-*.js`; on the desktop, `keyring.js`, `transcripts.js` and `argon2-wasm.js`; on Android, `keys/Kdf.kt`, `keys/Keyring.kt` and `keys/Transcripts.kt` | LGPL-3.0-or-later | +| Everything else — hub, node, the rest of the interface, the desktop and Android shells | [AGPL-3.0-or-later](LICENSE) | + +The line is the protocol. Whatever a program needs to speak to a hub and a node — +key derivation, the identity bundle, sealing and opening, what is signed, the +wire codec and the transport — is under the Lesser GPL, in every language it +exists in, so a client may use it whatever its own licence; changes to those +files themselves stay under the LGPL. A file without an SPDX line has its +package's licence. Talking to a hub or a node over the network needs none of +this code and carries no condition at all. The rest is under the Affero GPL: +whoever runs a modified hub or node for other people must offer them its +source. The licence texts travel with the interface, in `static/licenses/`. + +Group applications — the application store — may be under any licence, free +or not: the interface grants them that in an additional permission, +[`static/licenses/APPLICATION-EXCEPTION.txt`](packages/meshbay-hub/src/meshbay_hub/static/licenses/APPLICATION-EXCEPTION.txt), +as long as they use it only through the documented application interface +(`docs/MESHBAY_DESIGN.md` §9.2–9.4 and the modules the permission names). The +reference application, `helloworld-app.js` and its settings pane, is under 0BSD: +copy it to start one. + +The Android application adds one permission to the AGPL, for the Google Play +services libraries the cast to a television goes through: +[`packages/meshbay-android/LICENSE-EXCEPTION.txt`](packages/meshbay-android/LICENSE-EXCEPTION.txt). + +Third-party code keeps its own licence: the vendored browser libraries are +listed in [`static/vendor/PROVENANCE.md`](packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md) +with their texts in `LICENSES.txt` beside it, and every package build carries a +`THIRD-PARTY-NOTICES.txt` generated from what it actually ships +([`packaging/third_party_notices.py`](packaging/third_party_notices.py)). + ## Source The repository is published read-only at , and can be -- cgit v1.2.3