From cce8a911553597ada33e275bc9b29fd34121074d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 5 Oct 2026 08:59:06 +0200 Subject: chore: license MeshBay — LGPL protocol layer, AGPL for the rest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-android/LICENSE-EXCEPTION.txt | 24 ++++++++++++++++++++++ .../src/main/kotlin/org/meshbay/client/keys/Kdf.kt | 2 ++ .../main/kotlin/org/meshbay/client/keys/Keyring.kt | 2 ++ .../kotlin/org/meshbay/client/keys/Transcripts.kt | 2 ++ 4 files changed, 30 insertions(+) create mode 100644 packages/meshbay-android/LICENSE-EXCEPTION.txt (limited to 'packages/meshbay-android') diff --git a/packages/meshbay-android/LICENSE-EXCEPTION.txt b/packages/meshbay-android/LICENSE-EXCEPTION.txt new file mode 100644 index 0000000..bd526f6 --- /dev/null +++ b/packages/meshbay-android/LICENSE-EXCEPTION.txt @@ -0,0 +1,24 @@ +MeshBay for Android — additional permission under GNU AGPL version 3, section 7 +============================================================================== + +The MeshBay Android application is free software under the GNU Affero General +Public License, version 3 or (at your option) any later version — see LICENSE +at the root of the repository — with the following additional permission. +(Its protocol files, those marked SPDX-License-Identifier: LGPL-3.0-or-later, +are under the GNU Lesser GPL instead, which needs no such permission.) + + If you modify this Program, or any covered work, by linking or combining + it with the Google Play services client libraries (the Maven group + com.google.android.gms, or a modified version of those libraries), + containing parts covered by the terms of the licence under which Google + distributes them, the licensors of this Program grant you additional + permission to convey the resulting work. Corresponding Source for a + non-source form of such a combination shall not include the source code + for the parts of those libraries used as well as that of the covered work. + +Why: casting to a television goes through Google's cast sender SDK, which is +not free software and is linked into the application. Without this permission, +nobody but the copyright holders could lawfully distribute the application as +it is built, including from a fork. The permission covers those libraries only; +nothing else in the application is exempt from the AGPL, and anybody who +distributes a modified version may remove it (section 7). diff --git a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Kdf.kt b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Kdf.kt index 30f094e..404efcb 100644 --- a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Kdf.kt +++ b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Kdf.kt @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. package org.meshbay.client.keys import org.bouncycastle.crypto.digests.SHA256Digest diff --git a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Keyring.kt b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Keyring.kt index fa8ff71..9a7dd9f 100644 --- a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Keyring.kt +++ b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Keyring.kt @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. package org.meshbay.client.keys import org.bouncycastle.crypto.agreement.X25519Agreement diff --git a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Transcripts.kt b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Transcripts.kt index 4d183f7..cf20a0b 100644 --- a/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Transcripts.kt +++ b/packages/meshbay-android/app/src/main/kotlin/org/meshbay/client/keys/Transcripts.kt @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. package org.meshbay.client.keys import org.json.JSONObject -- cgit v1.2.3