74 lines
4.7 KiB
Markdown
74 lines
4.7 KiB
Markdown
# Third-party material in the Linux development package
|
|
|
|
DocView's public license has not been selected. These notices do not grant a
|
|
license to DocView, declare a license choice for a dependency, or authorize a
|
|
public release.
|
|
|
|
`cmake --install` includes the independently distributed PDFium binary's
|
|
`LICENSE` and `licenses/` directory, plus the locally verified qpdf license text.
|
|
The Linux install also includes `pdfium-supplemental/`'s full libc++ and
|
|
libc++abi notices. The provider's collection script omits these names, while
|
|
the fixed build settings and inspected library identify their use. The
|
|
supplement's `sources.json` binds each text to its exact upstream revision and
|
|
hash, and to the inspected PDFium library hash. Configure and packaging reject
|
|
a changed PDFium version, source pin, binary or notice pending a new review.
|
|
This adds two texts to the provider's 15; it does not prove all component
|
|
attribution is complete.
|
|
`tools/package_linux_development.py` additionally creates
|
|
`share/doc/docview/third-party/NOTICE.txt`, `dependency-manifest.json`, and a
|
|
`licenses/` tree from the actual Arch Linux packages on the packaging host.
|
|
Every copied text has a source path or resource attribution and SHA-256 in the manifest. Package license
|
|
labels are recorded verbatim; a list of alternatives is not a selected license.
|
|
|
|
For the current e2fsprogs 1.47.4, libidn2 2.3.8 and opencore-amr 0.1.6 packages,
|
|
the installed package has no specific license-text directory. The
|
|
`linux-supplemental/` tree supplies top-level notice/license texts from the
|
|
versioned upstream sources. `sources.json` records the URLs, downloaded-object
|
|
hashes and each text's hash. Packaging rejects a changed upstream version or
|
|
modified text until this supplement is reviewed. Downloaded source archives
|
|
were used only to obtain these texts and are not included as corresponding
|
|
source. This does not establish complete component-specific attribution.
|
|
|
|
The package contains DocView's three executables and the independent PDFium
|
|
shared library. Qt, Qt Quick, Qt WebEngine, libqpdf, libzip, toml++, libseccomp,
|
|
Fontconfig and their resolved system libraries remain system dependencies.
|
|
Compiled-in toml++ code is also recorded. Copying a system dependency's notice
|
|
does not mean that its runtime binary is bundled.
|
|
|
|
The manifest separates pinned PDFium source/binary provenance from Arch package
|
|
version, upstream home and packaging-repository pointers. Corresponding source
|
|
trees and complete build materials are **not included in this package**.
|
|
Separate repository evidence records selected exact Arch recipes/patches,
|
|
PDFium provider metadata and fixed-source notice comparisons. That bounded
|
|
collection is not a complete corresponding-source archive. A source URL or an
|
|
installed license text does not complete source-delivery requirements.
|
|
Each component therefore retains `source.status = not-collected` for the
|
|
package's complete-source collection.
|
|
|
|
Qt WebEngine includes Chromium components whose terms are separate from the Qt
|
|
module's terms. The installed Arch `LICENSE.chromium` is copied, but it is a
|
|
top-level license, not the complete build-specific Chromium attribution set.
|
|
The Linux packager also copies the seven complete notice comments in
|
|
`qt-embedded-notices/`, extracted from 13 inspected QtWebEngine DataPack entries.
|
|
The reviewed `sources.json` binds the texts and exact resource spans to Qt
|
|
6.11.2, Arch qt6-webengine 6.11.2-1, the two DataPack paths/hashes and the
|
|
extraction evidence. Packaging checks the fixed metadata digest, Qt/package
|
|
versions, actual system-file inventory, and every notice's size/hash. A changed
|
|
variant or missing/modified text fails packaging pending a new review.
|
|
Only the texts and source metadata are copied; Qt's runtime/resources remain
|
|
system dependencies. These seven texts do not complete Chromium attribution
|
|
or corresponding sources. That collection and review remain open. See the
|
|
[Qt WebEngine licensing documentation](https://doc.qt.io/qt-6/qtwebengine-licensing.html).
|
|
|
|
The bounded inventory includes the executables' ELF closure, Qt WebEngine helper
|
|
and resources, selected QML modules, and candidate styles/platform/image plugins.
|
|
It records system files without copying them into the runtime. It is not a
|
|
dynamic-load trace or an inventory of every optional IME, GPU, theme or system
|
|
font provider. No system font files are bundled.
|
|
|
|
The generated package is for local development on the recorded Arch Linux ABI.
|
|
It does not satisfy the clean Ubuntu/Windows distribution gate. Before public
|
|
distribution, settle the application license and target packaging policy,
|
|
resolve all actual bundled-component conditions, complete required notices and
|
|
source arrangements, and test the resulting target-OS package.
|