initial commit
This commit is contained in:
@@ -0,0 +1,73 @@
|
||||
# Third-party material in the Linux development package
|
||||
|
||||
DocView's public license has not been selected. These notices do not grant a
|
||||
license to DocView, declare a license choice for a dependency, or authorize a
|
||||
public release.
|
||||
|
||||
`cmake --install` includes the independently distributed PDFium binary's
|
||||
`LICENSE` and `licenses/` directory, plus the locally verified qpdf license text.
|
||||
The Linux install also includes `pdfium-supplemental/`'s full libc++ and
|
||||
libc++abi notices. The provider's collection script omits these names, while
|
||||
the fixed build settings and inspected library identify their use. The
|
||||
supplement's `sources.json` binds each text to its exact upstream revision and
|
||||
hash, and to the inspected PDFium library hash. Configure and packaging reject
|
||||
a changed PDFium version, source pin, binary or notice pending a new review.
|
||||
This adds two texts to the provider's 15; it does not prove all component
|
||||
attribution is complete.
|
||||
`tools/package_linux_development.py` additionally creates
|
||||
`share/doc/docview/third-party/NOTICE.txt`, `dependency-manifest.json`, and a
|
||||
`licenses/` tree from the actual Arch Linux packages on the packaging host.
|
||||
Every copied text has a source path or resource attribution and SHA-256 in the manifest. Package license
|
||||
labels are recorded verbatim; a list of alternatives is not a selected license.
|
||||
|
||||
For the current e2fsprogs 1.47.4, libidn2 2.3.8 and opencore-amr 0.1.6 packages,
|
||||
the installed package has no specific license-text directory. The
|
||||
`linux-supplemental/` tree supplies top-level notice/license texts from the
|
||||
versioned upstream sources. `sources.json` records the URLs, downloaded-object
|
||||
hashes and each text's hash. Packaging rejects a changed upstream version or
|
||||
modified text until this supplement is reviewed. Downloaded source archives
|
||||
were used only to obtain these texts and are not included as corresponding
|
||||
source. This does not establish complete component-specific attribution.
|
||||
|
||||
The package contains DocView's three executables and the independent PDFium
|
||||
shared library. Qt, Qt Quick, Qt WebEngine, libqpdf, libzip, toml++, libseccomp,
|
||||
Fontconfig and their resolved system libraries remain system dependencies.
|
||||
Compiled-in toml++ code is also recorded. Copying a system dependency's notice
|
||||
does not mean that its runtime binary is bundled.
|
||||
|
||||
The manifest separates pinned PDFium source/binary provenance from Arch package
|
||||
version, upstream home and packaging-repository pointers. Corresponding source
|
||||
trees and complete build materials are **not included in this package**.
|
||||
Separate repository evidence records selected exact Arch recipes/patches,
|
||||
PDFium provider metadata and fixed-source notice comparisons. That bounded
|
||||
collection is not a complete corresponding-source archive. A source URL or an
|
||||
installed license text does not complete source-delivery requirements.
|
||||
Each component therefore retains `source.status = not-collected` for the
|
||||
package's complete-source collection.
|
||||
|
||||
Qt WebEngine includes Chromium components whose terms are separate from the Qt
|
||||
module's terms. The installed Arch `LICENSE.chromium` is copied, but it is a
|
||||
top-level license, not the complete build-specific Chromium attribution set.
|
||||
The Linux packager also copies the seven complete notice comments in
|
||||
`qt-embedded-notices/`, extracted from 13 inspected QtWebEngine DataPack entries.
|
||||
The reviewed `sources.json` binds the texts and exact resource spans to Qt
|
||||
6.11.2, Arch qt6-webengine 6.11.2-1, the two DataPack paths/hashes and the
|
||||
extraction evidence. Packaging checks the fixed metadata digest, Qt/package
|
||||
versions, actual system-file inventory, and every notice's size/hash. A changed
|
||||
variant or missing/modified text fails packaging pending a new review.
|
||||
Only the texts and source metadata are copied; Qt's runtime/resources remain
|
||||
system dependencies. These seven texts do not complete Chromium attribution
|
||||
or corresponding sources. That collection and review remain open. See the
|
||||
[Qt WebEngine licensing documentation](https://doc.qt.io/qt-6/qtwebengine-licensing.html).
|
||||
|
||||
The bounded inventory includes the executables' ELF closure, Qt WebEngine helper
|
||||
and resources, selected QML modules, and candidate styles/platform/image plugins.
|
||||
It records system files without copying them into the runtime. It is not a
|
||||
dynamic-load trace or an inventory of every optional IME, GPU, theme or system
|
||||
font provider. No system font files are bundled.
|
||||
|
||||
The generated package is for local development on the recorded Arch Linux ABI.
|
||||
It does not satisfy the clean Ubuntu/Windows distribution gate. Before public
|
||||
distribution, settle the application license and target packaging policy,
|
||||
resolve all actual bundled-component conditions, complete required notices and
|
||||
source arrangements, and test the resulting target-OS package.
|
||||
Reference in New Issue
Block a user