Repository navigation
Actually ship the license texts NOTICE.md said we ship - #58
Merged
Merged
Conversation
NOTICE.md opened with "Full license texts are bundled under `LICENSES/` in distributed builds". Nothing did that. There was no LICENSES directory, nothing created one, tauri.bundle.conf.json listed no such resource, and a repo-wide search for the string returned exactly one hit: the sentence making the claim. So every build since the beta shipped without the texts LGPL-2.1 §6 and LGPL-2.0 require to accompany a distribution, while a public compliance file said otherwise. Found while checking whether FreeCAD's PlaneGCS was credited properly for a Reddit answer. The credit itself was fine: NOTICE names PlaneGCS, attributes it to FreeCAD, gives LGPL-2.0-or-later (matching what the package declares) and links both upstream sources. It was the bundling claim that was false. `scripts/collect-licenses.mjs` assembles src-tauri/LICENSES/ from the artefacts that actually ship -- node_modules, the built sidecar runtime's site-packages, and the vendored Rust under third_party. Taking each text from the thing it covers is the point: a curated copy drifts, a copied one cannot. Node rather than bash because CI bundles on three platforms and the Windows leg has no bash step; vendor-planegcs.mjs already set that precedent. No new dependency. **It is a gate.** The bug was a promise with nothing enforcing it, so a missing required text exits non-zero and fails the build rather than producing a quietly incomplete directory. Verified by removing the OCCT exception text and confirming exit code 1, then restoring and confirming 0. Two texts no dependency ships at all, so they are checked in under licenses/: OCCT's LGPL-2.1 and the Open CASCADE Exception. The cadquery-ocp-novtk wheel carries NO license file -- its METADATA declares Apache-2.0, which covers the Python wrapper and says nothing about the compiled OCCT object code inside it, which is the LGPL part. Both texts fetched from the OCCT repo at V7_9_3, the tag NOTICE already names. The collector reports that wheel and its proxy as shipping no text, so the gap stays visible rather than being silently patched over. Verified against a real artefact rather than the config: built the deb, extracted it, and confirmed /usr/lib/SindriCAD/LICENSES holds 62 texts with the load-bearing ones intact -- OCCT LGPL-2.1 (26434 bytes), the exception (663), PlaneGCS LGPL-2.1 (26526), opencascade-rs, certifi's MPL notice, and our own AGPL-3.0. NOTICE.md now describes what happens and says plainly that it previously did not, because the next person to read that paragraph should know it was once untrue.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
NOTICE.md says the full license texts are bundled under
LICENSES/in distributed builds. No build did that, so every release so far went out without the texts LGPL-2.1 §6 and LGPL-2.0 require.scripts/collect-licenses.mjsbuildssrc-tauri/LICENSES/from the artefacts that actually ship (node_modules, the sidecar runtime's site-packages, vendored Rust), plus the two texts no dependency provides (OCCT LGPL-2.1 and the Open CASCADE Exception, checked in underlicenses/).tauri.bundle.conf.jsonbundles the directory.It is a gate: if a required text is missing, the build fails.
Verified on Linux: 61 texts written, exit 0. With the OCCT exception text removed it exits 1, and restored it exits 0. Windows and macOS are NOT verified locally. That is what this PR's CI run is for.