Repository navigation
build: ship licence texts and third-party notices with releases and the image - #165
Conversation
…he image Release binaries and the Docker image carried no licence material at all: .dockerignore excluded LICENSE* and nothing reproduced the notices that the linked Go modules, the embedded Swagger UI and the bundled web packages require (MIT, BSD, ISC and Apache-2.0 all ask for this in binary redistribution). The binary also statically links go-ethereum library code under the GNU LGPL v3, which has to be identified, with the licence texts and a pointer to its source. scripts/notices (standard library only) lists the modules linked into ./cmd/indelible for each release target with `go list -deps` and CGO disabled, as the release build does, and writes THIRD-PARTY-NOTICES.txt with every module's licence and notice files (including NOTICE files and licences kept in subdirectories), the Go standard library licence, the Swagger UI notices from third_party/swagger-ui and the web UI notices. When go-ethereum is linked it adds a section naming it, its version, where its exact source is available, and how to rebuild this Indelible commit against a modified copy. It records the commit built and the antd release bundled alongside. It fails when a linked module ships no licence file (antd-go, published from a subdirectory of the MIT/Apache ant-sdk repository, is the one listed exception) or when any module other than go-ethereum carries GNU GPL-family text. A small Vite plugin records which npm packages the production build actually bundles, and web/scripts/third-party-notices.mjs reproduces their licence files plus those of the build tools whose output is in the bundle, failing when one is missing. CI runs both generators on every code change. The release workflow uploads THIRD-PARTY-NOTICES.txt, LICENSE-MIT and LICENSE-APACHE as release assets. The Docker image installs the same three files under /usr/share/doc/indelible/. The README licence section now points at the real licence files instead of a missing LICENSE, and `make notices` generates the file locally.
|
Reviewed as part of the V2-1385 sweep (V2-1395). Of all eleven PRs in this sweep, this is the one doing real licence-compliance reasoning rather than paperwork, and writing a purpose-built Go tool instead of reusing the Python generator was the right call for a Go project. The go-ethereum handling is genuinely well done: a dedicated LGPL section, the LGPL-3.0 and GPL-3.0 texts reproduced in full, a source URL pinned to the exact module version, and step-by-step Requesting one change: the notices don't travel with the thing they cover.
Compare the sibling PRs: ant-node and ant-client both put the licence files and notices inside each archive, and both added a line to the release body pointing at them. The release body here is unchanged. What I'd like, either of:
The Docker image is already correct — Happy to approve once either is in. |
…ices The licence files and third-party notices were published as separate release assets beside bare binaries, so anyone who downloaded a single binary, the usual way to install, received no notice at all. The release job now packs each indelible binary into indelible-<os>-<arch>.tar.gz (indelible-windows-amd64.zip on Windows) together with LICENSE-MIT, LICENSE-APACHE and THIRD-PARTY-NOTICES.txt, and publishes those archives in place of the bare binaries. The binary inside is named indelible (indelible.exe) and is set to mode 0755 in the tarballs, since workflow artifacts drop file modes. The job fails if any of the three files is missing. One notices file still covers all four targets, so it is generated once and copied into every archive. The bundled antd-* binaries stay separate assets, republished unchanged from the ant-sdk release named in the release body, which now also says what each archive contains. The release asset names change accordingly. Nothing in the WithAutonomi organisation downloads the old names, and the version check reads only the release tag and URL. The download walkthrough in FEATURES.md now fetches the archive from the GitHub release instead of a releases.autonomi.com host that does not resolve, and the README says the notices ship inside every release binary archive.
Publishing only archives renamed every indelible release asset, which would break any download URL or script that fetches the bare binaries. Every asset name a release has today now stays published with the same content: the bare indelible-<os>-<arch> binaries, the bundled antd-* binaries and SHA256SUMS, so releases/download/<tag>/<name> and releases/latest/download/<name> keep working. The archives are published alongside them: indelible-<os>-<arch>.tar.gz (indelible-windows-amd64.zip on Windows) holds a copy of the binary with LICENSE-MIT, LICENSE-APACHE and THIRD-PARTY-NOTICES.txt. The three files also stay loose release assets, so someone who downloads a bare binary finds them in the same release, and SHA256SUMS covers every asset. The release body now says what the archives contain, that the loose files apply to the bare binaries, and that the antd-* binaries are the named ant-sdk release redistributed unchanged. The FEATURES.md walkthrough goes back to the bare binary, now at its GitHub release URL, which resolves today. The README describes what the release workflow publishes.
dirvine
left a comment
There was a problem hiding this comment.
Re-review — archive and download-compatibility request addressed
Reviewed 03caeb075f82a89bb251ae0d420b97121b058a21.
The revised release workflow adds per-platform archives containing the binary, LICENSE-MIT, LICENSE-APACHE and THIRD-PARTY-NOTICES.txt, while preserving the existing bare asset names. The release body also identifies which notices apply. This satisfies both alternatives in the earlier packaging comment.
I executed the actual archive step using explicit synthetic binary fixtures plus the real notice/licence files: all three Unix archives and the Windows ZIP had the expected contents; Unix binary mode was 0755; legacy bare fixtures remained. This verifies packaging logic, not a new production release build. The specialist reviewer also exercised the Go/web notices generators; applicable CI, including Docker build/smoke, is green.
Recommendation: no introduced blocker identified for the requested revision. Keep inherited distribution debt separate: copying the antd binary from its source image does not copy its notice directory; the added cross-reference is not the full daemon notices bundle. That needs its own checked distribution path before declaring the complete product's licence work finished.
The go-ethereum texts/source links/relink instructions are useful engineering evidence, not a blanket legal opinion that all LGPL obligations are satisfied. Advisory review only; no approval or merge performed.
Panel result: the repository specialist, independent GLM-5.2 reviewer, and both adversarial reviewers agree there is no introduced blocker in this revision. Coordinator verification supports that engineering recommendation, with the limitations above.
dirvine
left a comment
There was a problem hiding this comment.
Follow-up engineering review
Exact head: 03caeb075f82a89bb251ae0d420b97121b058a21.
No introduced blocker found. Head is identical to the previous six-seat review; this revalidation reuses that packaging evidence rather than claiming repeated builds. Current applicable CI checks pass, including Docker build and smoke test.
Archives include licence texts and notices; existing bare download names/URLs remain unchanged. Bundled antd notice distribution remains pre-existing follow-up work. Notice files and LGPL relink instructions are engineering evidence, not a legal compliance certification. Completed follow-up panel supports the prior recommendation.
Advisory COMMENT review only; no formal approval, merge, release dispatch or legal certification. Browser SDK PR #3 excluded as requested.
dirvine
left a comment
There was a problem hiding this comment.
Formal review — APPROVE
Reviewed exact head 03caeb075f82a89bb251ae0d420b97121b058a21.
The previous distribution request is satisfied: each new platform archive includes its binary, both licence texts and third-party notices; the release body also identifies the notices applicable to the retained bare binaries. The completed six-seat panel, including independent GLM-5.2 review, found no actionable blocker after coordinator verification.
Fresh verification: frontend build and web notices generation passed. The Go notices generator passed for all four default release targets under official Go 1.25.13, including LGPL/GPL texts, the nested metrics licence and exact source SHA. Homebrew Go lacked its standard-library LICENSE file; that local toolchain packaging failure did not recur with official Go. The actual archive step passed with explicitly synthetic binary/notice fixtures for three Unix archives and Windows ZIP; Unix executable mode is 0755. Those fixtures test packaging, not production binaries. Exact-head hosted Docker build/smoke CI passes; Docker was not rebuilt locally.
Inherited antd notice-directory distribution remains separate follow-up work. The source links and relink instructions are engineering evidence, not a legal compliance certification. No merge or release performed.
What this changes
Indelible's release binaries and Docker image ship no licence material today.
.dockerignoredropsLICENSE*, so the image does not even carry Indelible's own licence. Nothing reproduces the licence and notice files that the bundled third-party code requires. MIT, BSD, ISC and Apache-2.0 all require those notices when the code is redistributed as a binary.The binary also statically links 22 go-ethereum library packages, which are licensed under the GNU LGPL v3 or later. Shipping them requires a prominent notice, the LGPL and GPL texts, and a pointer to the corresponding source.
After this PR every release and every image ships
THIRD-PARTY-NOTICES.txtnext toLICENSE-MITandLICENSE-APACHE:SHA256SUMS./usr/share/doc/indelible/, which is where Debian keeps licence files.How the notices are built
scripts/notices(Go, standard library only) lists the modules linked into./cmd/indeliblefor each release target, usinggo list -depswithCGO_ENABLED=0exactly as the release build does. It writes each module's licence and notice files into the output, including NOTICE files (go-oidc, grpc, yaml.v2), licences kept in subdirectories (go-ethereum'smetrics/LICENSE) and modernc'sLICENSE-3RD-PARTY.md. It also adds:go-ethereum section: when go-ethereum is linked, the file opens with a section that:
go mod edit -replace,CGO_ENABLED=0 go build).The LGPL v3 and GPL v3 texts come from go-ethereum's own
COPYING.LESSERandCOPYING.Failure checks: the tool fails if a linked module ships no licence file, or if any module other than go-ethereum carries GNU GPL-family text. A dependency bump therefore cannot silently leave the notices incomplete.
Web UI: a small Vite plugin (
web/vite.config.ts) records which npm packages the production build actually bundles.web/scripts/third-party-notices.mjsthen reproduces their licence files.third_party/swagger-ui/NOTICES.txtcovers the Swagger UI 4.11.0 bundle thatgithubproxy.fjygbaifeng.eu.org/swaggo/filesembeds. That module carries only its own MIT licence. This file supplies the Apache-2.0 licence and SmartBear NOTICE of Swagger UI, plus the licences of the 76 npm packages bundled into it.swaggo/filesis upgraded.CI: both generators run on every code change, the Go one in the lint job and the web one in the frontend job.
README: the licence section now links the real licence files instead of a missing
LICENSE.Makefile:
make noticesgenerates the file locally.Verification
Everything below ran locally with Go 1.25.13 and Node 22.
go vet ./...is clean.golangci-lintv1.64.8 on./scripts/...is clean.CGO_ENABLED=0 go build ./cmd/indeliblesucceeds.npm run build(includingvue-tsc) succeeds, andnpm run test:unitpasses 45 of 45.tsc --noEmit -p tsconfig.node.jsonpasses for the new Vite plugin, whichvue-tscdoes not type-check.COPYING,COPYING.LESSERandmetrics/LICENSE.NOTICE.txt, the go-oidc and yaml.v2NOTICEs, the GoLICENSEandPATENTS, the Swagger UI section and the 21 web packages.-targets linux/amd64lists 64 modules.Known limits and out of scope
Closes V2-1395