From cce8a911553597ada33e275bc9b29fd34121074d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 5 Oct 2026 08:59:06 +0200 Subject: chore: license MeshBay — LGPL protocol layer, AGPL for the rest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-client/package.json | 4 ++++ packages/meshbay-client/src/argon2-wasm.js | 2 ++ packages/meshbay-client/src/keyring.js | 2 ++ packages/meshbay-client/src/transcripts.js | 2 ++ 4 files changed, 10 insertions(+) (limited to 'packages/meshbay-client') diff --git a/packages/meshbay-client/package.json b/packages/meshbay-client/package.json index 8a1fec7..a13c0ab 100644 --- a/packages/meshbay-client/package.json +++ b/packages/meshbay-client/package.json @@ -53,6 +53,10 @@ { "from": "../../packaging/win/ensure-node-path.ps1", "to": "ensure-node-path.ps1" + }, + { + "from": "../../LICENSE", + "to": "LICENSE.txt" } ] }, diff --git a/packages/meshbay-client/src/argon2-wasm.js b/packages/meshbay-client/src/argon2-wasm.js index c68e994..4660414 100644 --- a/packages/meshbay-client/src/argon2-wasm.js +++ b/packages/meshbay-client/src/argon2-wasm.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. /** * Argon2id for the main process, from the page's own WebAssembly build. * diff --git a/packages/meshbay-client/src/keyring.js b/packages/meshbay-client/src/keyring.js index ec37fd4..c9997aa 100644 --- a/packages/meshbay-client/src/keyring.js +++ b/packages/meshbay-client/src/keyring.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. /** * The account's keys in the desktop application: the bundle master key `M` and * the identity on every node, held here and never handed to the page. diff --git a/packages/meshbay-client/src/transcripts.js b/packages/meshbay-client/src/transcripts.js index 8b0f6ef..a58cb24 100644 --- a/packages/meshbay-client/src/transcripts.js +++ b/packages/meshbay-client/src/transcripts.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: LGPL-3.0-or-later +// Part of MeshBay's protocol layer, under the LGPL so that any client may use it. /** * What a node identity signs, built here from named fields — never bytes the * page chose. -- cgit v1.2.3