Skip to content

Actually ship the license texts NOTICE.md said we ship - #58

Merged
MakerViking merged 1 commit into
mainfrom
bundle-license-texts
Sep 24, 2026
Merged

MakerViking merged 1 commit into
mainfrom
bundle-license-texts

Conversation

@MakerViking

Copy link
Copy Markdown
Owner

NOTICE.md says the full license texts are bundled under LICENSES/ in distributed builds. No build did that, so every release so far went out without the texts LGPL-2.1 §6 and LGPL-2.0 require.

scripts/collect-licenses.mjs builds src-tauri/LICENSES/ from the artefacts that actually ship (node_modules, the sidecar runtime's site-packages, vendored Rust), plus the two texts no dependency provides (OCCT LGPL-2.1 and the Open CASCADE Exception, checked in under licenses/). tauri.bundle.conf.json bundles the directory.

It is a gate: if a required text is missing, the build fails.

Verified on Linux: 61 texts written, exit 0. With the OCCT exception text removed it exits 1, and restored it exits 0. Windows and macOS are NOT verified locally. That is what this PR's CI run is for.

NOTICE.md opened with "Full license texts are bundled under `LICENSES/` in
distributed builds". Nothing did that. There was no LICENSES directory,
nothing created one, tauri.bundle.conf.json listed no such resource, and a
repo-wide search for the string returned exactly one hit: the sentence
making the claim. So every build since the beta shipped without the texts
LGPL-2.1 §6 and LGPL-2.0 require to accompany a distribution, while a
public compliance file said otherwise.

Found while checking whether FreeCAD's PlaneGCS was credited properly for a
Reddit answer. The credit itself was fine: NOTICE names PlaneGCS, attributes
it to FreeCAD, gives LGPL-2.0-or-later (matching what the package declares)
and links both upstream sources. It was the bundling claim that was false.

`scripts/collect-licenses.mjs` assembles src-tauri/LICENSES/ from the
artefacts that actually ship -- node_modules, the built sidecar runtime's
site-packages, and the vendored Rust under third_party. Taking each text
from the thing it covers is the point: a curated copy drifts, a copied one
cannot. Node rather than bash because CI bundles on three platforms and the
Windows leg has no bash step; vendor-planegcs.mjs already set that
precedent. No new dependency.

**It is a gate.** The bug was a promise with nothing enforcing it, so a
missing required text exits non-zero and fails the build rather than
producing a quietly incomplete directory. Verified by removing the OCCT
exception text and confirming exit code 1, then restoring and confirming 0.

Two texts no dependency ships at all, so they are checked in under
licenses/: OCCT's LGPL-2.1 and the Open CASCADE Exception. The
cadquery-ocp-novtk wheel carries NO license file -- its METADATA declares
Apache-2.0, which covers the Python wrapper and says nothing about the
compiled OCCT object code inside it, which is the LGPL part. Both texts
fetched from the OCCT repo at V7_9_3, the tag NOTICE already names.
The collector reports that wheel and its proxy as shipping no text, so the
gap stays visible rather than being silently patched over.

Verified against a real artefact rather than the config: built the deb,
extracted it, and confirmed /usr/lib/SindriCAD/LICENSES holds 62 texts with
the load-bearing ones intact -- OCCT LGPL-2.1 (26434 bytes), the exception
(663), PlaneGCS LGPL-2.1 (26526), opencascade-rs, certifi's MPL notice, and
our own AGPL-3.0.

NOTICE.md now describes what happens and says plainly that it previously
did not, because the next person to read that paragraph should know it was
once untrue.
@MakerViking
MakerViking merged commit aeeea65 into main Sep 24, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant