diff --git a/licenses/BSL-1.0.txt b/licenses/BSL-1.0.txt
new file mode 100644
index 00000000..2d87ab1a
--- /dev/null
+++ b/licenses/BSL-1.0.txt
@@ -0,0 +1,7 @@
+Boost Software License - Version 1.0 - August 17th, 2003
+
+Permission is hereby granted, free of charge, to any person or organization obtaining a copy of the software and accompanying documentation covered by this license (the "Software") to use, reproduce, display, distribute, execute, and transmit the Software, and to prepare derivative works of the Software, and to permit third-parties to whom the Software is furnished to do so, all subject to the following:
+
+The copyright notices in the Software and this entire statement, including the above license grant, this restriction and the following disclaimer, must be included in all copies of the Software, in whole or in part, and all derivative works of the Software, unless such copies or derivative works are solely in the form of machine-executable object code generated by a source language processor.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR ANYONE DISTRIBUTING THE SOFTWARE BE LIABLE FOR ANY DAMAGES OR OTHER LIABILITY, WHETHER IN CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
diff --git a/licenses/GCC-exception-3.1.txt b/licenses/GCC-exception-3.1.txt
new file mode 100644
index 00000000..3d8345be
--- /dev/null
+++ b/licenses/GCC-exception-3.1.txt
@@ -0,0 +1,33 @@
+GCC RUNTIME LIBRARY EXCEPTION
+
+Version 3.1, 31 March 2009
+
+General information: http://www.gnu.org/licenses/gcc-exception.html
+Copyright (C) 2009 Free Software Foundation, Inc.
+
+Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
+This GCC Runtime Library Exception ("Exception") is an additional permission under section 7 of the GNU General Public License, version 3 ("GPLv3"). It applies to a given file (the "Runtime Library") that bears a notice placed by the copyright holder of the file stating that the file is governed by GPLv3 along with this Exception.
+
+When you use GCC to compile a program, GCC may combine portions of certain GCC header files and runtime libraries with the compiled program. The purpose of this Exception is to allow compilation of non-GPL (including proprietary) programs to use, in this way, the header files and runtime libraries covered by this Exception.
+
+0. Definitions.
+
+A file is an "Independent Module" if it either requires the Runtime Library for execution after a Compilation Process, or makes use of an interface provided by the Runtime Library, but is not otherwise based on the Runtime Library.
+
+"GCC" means a version of the GNU Compiler Collection, with or without modifications, governed by version 3 (or a specified later version) of the GNU General Public License (GPL) with the option of using any subsequent versions published by the FSF.
+
+"GPL-compatible Software" is software whose conditions of propagation, modification and use would permit combination with GCC in accord with the license of GCC.
+
+"Target Code" refers to output from any compiler for a real or virtual target processor architecture, in executable form or suitable for input to an assembler, loader, linker and/or execution phase. Notwithstanding that, Target Code does not include data in any format that is used as a compiler intermediate representation, or used for producing a compiler intermediate representation.
+
+The "Compilation Process" transforms code entirely represented in non-intermediate languages designed for human-written code, and/or in Java Virtual Machine byte code, into Target Code. Thus, for example, use of source code generators and preprocessors need not be considered part of the Compilation Process, since the Compilation Process can be understood as starting with the output of the generators or preprocessors.
+
+A Compilation Process is "Eligible" if it is done using GCC, alone or with other GPL-compatible software, or if it is done without using any work based on GCC. For example, using non-GPL-compatible Software to optimize any GCC intermediate representations would not qualify as an Eligible Compilation Process.
+
+1. Grant of Additional Permission.
+
+You have permission to propagate a work of Target Code formed by combining the Runtime Library with Independent Modules, even if such propagation would otherwise violate the terms of GPLv3, provided that all Target Code was generated by Eligible Compilation Processes. You may then convey such a combination under terms of your choice, consistent with the licensing of the Independent Modules.
+
+2. No Weakening of GCC Copyleft.
+
+The availability of this Exception does not imply any general presumption that third-party software is unaffected by the copyleft requirements of the license of GCC.
diff --git a/licenses/LicenseRef-duplicacy-no-libre.txt b/licenses/LicenseRef-duplicacy-no-libre.txt
new file mode 100644
index 00000000..d46ef970
--- /dev/null
+++ b/licenses/LicenseRef-duplicacy-no-libre.txt
@@ -0,0 +1,7 @@
+Copyright © 2017 Acrosync LLC
+
+* Free for personal use or commercial trial
+* Non-trial commercial use requires per-computer CLI licenses available from [duplicacy.com](https://duplicacy.com/buy.html) at a cost of $50 per year
+* The computer with a valid commercial license for the GUI version may run the CLI version without a CLI license
+* CLI licenses are not required to restore or manage backups; only the backup command requires valid CLI licenses
+* Modification and redistribution are permitted, but commercial use of derivative works is subject to the same requirements of this license
diff --git a/licenses/LicenseRef-lsof.txt b/licenses/LicenseRef-lsof.txt
new file mode 100644
index 00000000..279721a9
--- /dev/null
+++ b/licenses/LicenseRef-lsof.txt
@@ -0,0 +1,26 @@
+Copyright 2002 Purdue Research Foundation, West Lafayette,
+Indiana 47907. All rights reserved.
+
+Written by Victor A. Abell
+
+This software is not subject to any license of the American
+Telephone and Telegraph Company or the Regents of the
+University of California.
+
+Permission is granted to anyone to use this software for
+any purpose on any computer system, and to alter it and
+redistribute it freely, subject to the following
+restrictions:
+
+1. Neither the authors nor Purdue University are responsible
+ for any consequences of the use of this software.
+
+2. The origin of this software must not be misrepresented,
+ either by explicit claim or by omission. Credit to the
+ authors and Purdue University must appear in documentation
+ and sources.
+
+3. Altered versions must be plainly marked as such, and must
+ not be misrepresented as being the original software.
+
+4. This notice may not be removed or altered.
diff --git a/licenses/LicenseRef-openssh.txt b/licenses/LicenseRef-openssh.txt
new file mode 100644
index 00000000..aeb3017e
--- /dev/null
+++ b/licenses/LicenseRef-openssh.txt
@@ -0,0 +1,412 @@
+This file is part of the OpenSSH software.
+
+The licences which components of this software fall under are as
+follows. First, we will summarize and say that all components
+are under a BSD licence, or a licence more free than that.
+
+OpenSSH contains no GPL code.
+
+1)
+ * Copyright (c) 1995 Tatu Ylonen , Espoo, Finland
+ * All rights reserved
+ *
+ * As far as I am concerned, the code I have written for this software
+ * can be used freely for any purpose. Any derived versions of this
+ * software must be clearly marked as such, and if the derived work is
+ * incompatible with the protocol description in the RFC file, it must be
+ * called by a name other than "ssh" or "Secure Shell".
+
+ [Tatu continues]
+ * However, I am not implying to give any licenses to any patents or
+ * copyrights held by third parties, and the software includes parts that
+ * are not under my direct control. As far as I know, all included
+ * source code is used in accordance with the relevant license agreements
+ * and can be used freely for any purpose (the GNU license being the most
+ * restrictive); see below for details.
+
+ [However, none of that term is relevant at this point in time. All of
+ these restrictively licenced software components which he talks about
+ have been removed from OpenSSH, i.e.,
+
+ - RSA is no longer included, found in the OpenSSL library
+ - IDEA is no longer included, its use is deprecated
+ - DES is now external, in the OpenSSL library
+ - GMP is no longer used, and instead we call BN code from OpenSSL
+ - Zlib is now external, in a library
+ - The make-ssh-known-hosts script is no longer included
+ - TSS has been removed
+ - MD5 is now external, in the OpenSSL library
+ - RC4 support has been replaced with ARC4 support from OpenSSL
+ - Blowfish is now external, in the OpenSSL library
+
+ [The licence continues]
+
+ Note that any information and cryptographic algorithms used in this
+ software are publicly available on the Internet and at any major
+ bookstore, scientific library, and patent office worldwide. More
+ information can be found e.g. at "http://www.cs.hut.fi/crypto".
+
+ The legal status of this program is some combination of all these
+ permissions and restrictions. Use only at your own responsibility.
+ You will be responsible for any legal consequences yourself; I am not
+ making any claims whether possessing or using this is legal or not in
+ your country, and I am not taking any responsibility on your behalf.
+
+
+ NO WARRANTY
+
+ BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
+ FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
+ OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
+ PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
+ OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
+ MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS
+ TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE
+ PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
+ REPAIR OR CORRECTION.
+
+ IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
+ WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
+ REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
+ INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
+ OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
+ TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
+ YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
+ PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
+ POSSIBILITY OF SUCH DAMAGES.
+
+3)
+ ssh-keyscan was contributed by David Mazieres under a BSD-style
+ license.
+
+ * Copyright 1995, 1996 by David Mazieres .
+ *
+ * Modification and redistribution in source and binary forms is
+ * permitted provided that due credit is given to the author and the
+ * OpenBSD project by leaving this copyright notice intact.
+
+4)
+ The Rijndael implementation by Vincent Rijmen, Antoon Bosselaers
+ and Paulo Barreto is in the public domain and distributed
+ with the following license:
+
+ * @version 3.0 (December 2000)
+ *
+ * Optimised ANSI C code for the Rijndael cipher (now AES)
+ *
+ * @author Vincent Rijmen
+ * @author Antoon Bosselaers
+ * @author Paulo Barreto
+ *
+ * This code is hereby placed in the public domain.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHORS ''AS IS'' AND ANY EXPRESS
+ * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
+ * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
+ * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
+ * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
+ * OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE,
+ * EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+
+5)
+ One component of the ssh source code is under a 3-clause BSD license,
+ held by the University of California, since we pulled these parts from
+ original Berkeley code.
+
+ * Copyright (c) 1983, 1990, 1992, 1993, 1995
+ * The Regents of the University of California. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ * 3. Neither the name of the University nor the names of its contributors
+ * may be used to endorse or promote products derived from this software
+ * without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
+ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
+ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
+ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
+ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
+ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ * SUCH DAMAGE.
+
+6)
+ Remaining components of the software are provided under a standard
+ 2-term BSD licence with the following names as copyright holders:
+
+ Markus Friedl
+ Theo de Raadt
+ Niels Provos
+ Dug Song
+ Aaron Campbell
+ Damien Miller
+ Kevin Steves
+ Daniel Kouril
+ Wesley Griffin
+ Per Allansson
+ Nils Nordman
+ Simon Wilkinson
+
+ Portable OpenSSH additionally includes code from the following copyright
+ holders, also under the 2-term BSD license:
+
+ Ben Lindstrom
+ Tim Rice
+ Andre Lucas
+ Chris Adams
+ Corinna Vinschen
+ Cray Inc.
+ Denis Parker
+ Gert Doering
+ Jakob Schlyter
+ Jason Downs
+ Juha Yrjölä
+ Michael Stone
+ Networks Associates Technology, Inc.
+ Solar Designer
+ Todd C. Miller
+ Wayne Schroeder
+ William Jones
+ Darren Tucker
+ Sun Microsystems
+ The SCO Group
+ Daniel Walsh
+ Red Hat, Inc
+ Simon Vallet / Genoscope
+
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
+ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
+ * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
+ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
+ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
+ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+
+8) Portable OpenSSH contains the following additional licenses:
+
+ a) snprintf replacement
+
+ * Copyright Patrick Powell 1995
+ * This code is based on code written by Patrick Powell
+ * (papowell@astart.com) It may be used for any purpose as long as this
+ * notice remains intact on all source code distributions
+
+ b) Compatibility code (openbsd-compat)
+
+ Apart from the previously mentioned licenses, various pieces of code
+ in the openbsd-compat/ subdirectory are licensed as follows:
+
+ Some code is licensed under a 3-term BSD license, to the following
+ copyright holders:
+
+ Todd C. Miller
+ Theo de Raadt
+ Damien Miller
+ Eric P. Allman
+ The Regents of the University of California
+ Constantin S. Svintsoff
+ Kungliga Tekniska Högskolan
+
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ * 3. Neither the name of the University nor the names of its contributors
+ * may be used to endorse or promote products derived from this software
+ * without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
+ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
+ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
+ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
+ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
+ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ * SUCH DAMAGE.
+
+ Some code is licensed under an ISC-style license, to the following
+ copyright holders:
+
+ Internet Software Consortium.
+ Todd C. Miller
+ Reyk Floeter
+ Chad Mynhier
+
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND TODD C. MILLER DISCLAIMS ALL
+ * WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL TODD C. MILLER BE LIABLE
+ * FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
+ * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
+ * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+
+ Some code is licensed under a MIT-style license to the following
+ copyright holders:
+
+ Free Software Foundation, Inc.
+
+ * Permission is hereby granted, free of charge, to any person obtaining a *
+ * copy of this software and associated documentation files (the *
+ * "Software"), to deal in the Software without restriction, including *
+ * without limitation the rights to use, copy, modify, merge, publish, *
+ * distribute, distribute with modifications, sublicense, and/or sell *
+ * copies of the Software, and to permit persons to whom the Software is *
+ * furnished to do so, subject to the following conditions: *
+ * *
+ * The above copyright notice and this permission notice shall be included *
+ * in all copies or substantial portions of the Software. *
+ * *
+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS *
+ * OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF *
+ * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. *
+ * IN NO EVENT SHALL THE ABOVE COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, *
+ * DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR *
+ * OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR *
+ * THE USE OR OTHER DEALINGS IN THE SOFTWARE. *
+ * *
+ * Except as contained in this notice, the name(s) of the above copyright *
+ * holders shall not be used in advertising or otherwise to promote the *
+ * sale, use or other dealings in this Software without prior written *
+ * authorization. *
+ ****************************************************************************/
+
+ The Blowfish cipher implementation is licensed by Niels Provos under
+ a 3-clause BSD license:
+
+ * Blowfish - a fast block cipher designed by Bruce Schneier
+ *
+ * Copyright 1997 Niels Provos
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ * 3. The name of the author may not be used to endorse or promote products
+ * derived from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
+ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
+ * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
+ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
+ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
+ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+
+ Some replacement code is licensed by the NetBSD foundation under a
+ 2-clause BSD license:
+
+ * Copyright (c) 2001 The NetBSD Foundation, Inc.
+ * All rights reserved.
+ *
+ * This code is derived from software contributed to The NetBSD Foundation
+ * by Todd Vierling.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
+ * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
+ * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
+ * POSSIBILITY OF SUCH DAMAGE.
+
+ The replacement base64 implementation has the following MIT-style
+ licenses:
+
+ * Copyright (c) 1996 by Internet Software Consortium.
+ *
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS
+ * ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE
+ * CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
+ * DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
+ * PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
+ * ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
+ * SOFTWARE.
+
+ * Portions Copyright (c) 1995 by International Business Machines, Inc.
+ *
+ * International Business Machines, Inc. (hereinafter called IBM) grants
+ * permission under its copyrights to use, copy, modify, and distribute this
+ * Software with or without fee, provided that the above copyright notice and
+ * all paragraphs of this notice appear in all copies, and that the name of IBM
+ * not be used in connection with the marketing of any product incorporating
+ * the Software or modifications thereof, without specific, written prior
+ * permission.
+ *
+ * To the extent it has a right to do so, IBM grants an immunity from suit
+ * under its patents, if any, for the use, sale or manufacture of products to
+ * the extent that such products are used for performing Domain Name System
+ * dynamic updates in TCP/IP networks by means of the Software. No immunity is
+ * granted for any product per se or for any other function of any product.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS", AND IBM DISCLAIMS ALL WARRANTIES,
+ * INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ * PARTICULAR PURPOSE. IN NO EVENT SHALL IBM BE LIABLE FOR ANY SPECIAL,
+ * DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER ARISING
+ * OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE, EVEN
+ * IF IBM IS APPRISED OF THE POSSIBILITY OF SUCH DAMAGES.
+
+------
+$OpenBSD: LICENCE,v 1.20 2017/04/30 23:26:16 djm Exp $
diff --git a/licenses/LicenseRef-qorpa-ajena-no-enumerable.txt b/licenses/LicenseRef-qorpa-ajena-no-enumerable.txt
new file mode 100644
index 00000000..2a8b343f
--- /dev/null
+++ b/licenses/LicenseRef-qorpa-ajena-no-enumerable.txt
@@ -0,0 +1,20 @@
+IMAGEN AJENA — TÉRMINOS NO ENUMERABLES
+======================================
+
+Este identificador NO es una licencia: marca un artefacto que NO construimos
+nosotros desde fuente, sino un rootfs de otra distribución que se trae pineado
+por sha256 y corre enjaulado (ADR 0015, «imágenes ajenas» / qorpa).
+
+POR QUÉ NO SE ENUMERA. Adentro hay cientos de paquetes de terceros, cada uno
+con sus propios términos. Afirmar una licencia única sobre ese conjunto sería
+inventarla, y dejar el campo vacío se leería como «todavía no lo poblamos».
+
+QUIÉN PONE LOS TÉRMINOS. Quien publica la imagen, que no somos nosotros. La
+relación de licencia es entre el usuario y esa distribución, cuyo material se
+trae por URL + sha256.
+
+ALCANCE. Estos artefactos van con `foreign = true`, el grafo los clasifica
+`ajeno` y quedan FUERA del catálogo publicable y del reporte de licencias
+(docs/20-catalogo-publicable-y-completa.md). Replicarlos a nuestras propias
+máquinas (`hammer mirror push`) es una cosa; PUBLICARLOS a terceros pide mirar
+licencia y marca antes, y eso no es una pregunta técnica.
diff --git a/licenses/LicenseRef-sin-licencia-declarada.txt b/licenses/LicenseRef-sin-licencia-declarada.txt
new file mode 100644
index 00000000..ca9eb74a
--- /dev/null
+++ b/licenses/LicenseRef-sin-licencia-declarada.txt
@@ -0,0 +1,19 @@
+SIN LICENCIA DECLARADA
+======================
+
+Este identificador NO es una licencia: es la constancia de que el proyecto de
+origen NO declara ninguna en el commit que la receta pinea. No hay LICENSE ni
+COPYING en el árbol, y el README no menciona términos de uso.
+
+QUÉ SIGNIFICA. Sin una concesión expresa del autor, el derecho de autor por
+defecto reserva todos los derechos: no hay permiso para redistribuir el
+programa ni sus binarios. Que el código esté publicado en una forja NO es una
+licencia.
+
+POR QUÉ ESTÁ ESCRITO Y NO VACÍO. Un campo `license` vacío se lee como «todavía
+no lo poblamos» y pasa desapercibido; escrito, el guardián de licencias
+(scripts/licencias-rootfs.sh) lo ve y el paquete queda marcado en el manifiesto
+de cualquier imagen que lo incluya.
+
+QUÉ HAY QUE HACER antes de publicar una imagen que lo contenga: pedirle al
+autor que declare una licencia, o sacar el paquete de esa imagen.
diff --git a/licenses/LicenseRef-tz-public-domain.txt b/licenses/LicenseRef-tz-public-domain.txt
new file mode 100644
index 00000000..8ba4399c
--- /dev/null
+++ b/licenses/LicenseRef-tz-public-domain.txt
@@ -0,0 +1,5 @@
+Unless specified below, all files in the tz code and data (including
+this LICENSE file) are in the public domain.
+
+If the files date.c, newstrftime.3, and strftime.c are present, they
+contain material derived from BSD and use the BSD 3-clause license.
diff --git a/recipes/amp.toml b/recipes/amp.toml
index 60e71fd6..33a12c4c 100644
--- a/recipes/amp.toml
+++ b/recipes/amp.toml
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "amp"
version = "0.7.1"
+# licencia: LICENSE del repo en el commit pineado: «GNU General Public License … either version 3 … or (at your option) any later version»
+license = "GPL-3.0-or-later"
[source]
repo = "https://github.com/jmacdonald/amp"
diff --git a/recipes/cargo-audit.toml b/recipes/cargo-audit.toml
index fa82df50..7ace3488 100644
--- a/recipes/cargo-audit.toml
+++ b/recipes/cargo-audit.toml
@@ -6,6 +6,8 @@
# - deps.build=["zlib"]: git2/openssl-sys enlazan -lz.
name = "cargo-audit"
version = "0.22.1"
+# licencia: campo `license` del Cargo.toml de cargo-audit/ dentro del tarball pineado
+license = "Apache-2.0 OR MIT"
[source]
tarball = "https://github.com/RustSec/cargo-audit/archive/cargo-audit/v0.22.1.tar.gz"
diff --git a/recipes/cargo-binstall.toml b/recipes/cargo-binstall.toml
index 54b11947..ae52520b 100644
--- a/recipes/cargo-binstall.toml
+++ b/recipes/cargo-binstall.toml
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "cargo-binstall"
version = "1.20.0"
+# licencia: campo `license` de crates/bin/Cargo.toml —el binario que construimos— en el commit pineado. El workspace no declara licencia; la declara el crate
+license = "GPL-3.0-only"
[source]
repo = "https://github.com/cargo-bins/cargo-binstall"
diff --git a/recipes/duplicacy.toml b/recipes/duplicacy.toml
index da275ea8..57bb6e12 100644
--- a/recipes/duplicacy.toml
+++ b/recipes/duplicacy.toml
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "duplicacy"
version = "3.2.5"
+# licencia: ⚠ NO ES SOFTWARE LIBRE. LICENSE.md del commit pineado: «Free for personal use or commercial trial; Non-trial commercial use requires per-computer CLI licenses … $50 per year». Se declara con LicenseRef porque no hay identificador SPDX, y el texto va en licenses/ para que quien reciba una imagen lo lea
+license = "LicenseRef-duplicacy-no-libre"
[source]
repo = "https://github.com/gilbertchen/duplicacy"
diff --git a/recipes/fuse3.toml b/recipes/fuse3.toml
index d15df467..a19a0730 100644
--- a/recipes/fuse3.toml
+++ b/recipes/fuse3.toml
@@ -34,6 +34,8 @@
# lo que quisimos y sellar lo que había.
name = "fuse3"
version = "3.18.2"
+# licencia: LICENSE del tarball pineado: include/ y lib/ bajo LGPL v2.1, «all other files» bajo GPL v2. Ninguno dice «or later»
+license = "LGPL-2.1-only AND GPL-2.0-only"
[source]
tarball = "https://github.com/libfuse/libfuse/archive/fuse-3.18.2/libfuse-fuse-3.18.2.tar.gz"
diff --git a/recipes/gmp.toml b/recipes/gmp.toml
index bea06d46..7aa7f8ee 100644
--- a/recipes/gmp.toml
+++ b/recipes/gmp.toml
@@ -31,6 +31,8 @@
# (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch).
name = "gmp"
version = "6.3.0"
+# licencia: README del tarball pineado (sha256 verificado al bajarlo): LGPLv3+ o GPLv2+, «or both in parallel»
+license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source]
tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz"
diff --git a/recipes/hwdata.toml b/recipes/hwdata.toml
index 64f446d9..5f180401 100644
--- a/recipes/hwdata.toml
+++ b/recipes/hwdata.toml
@@ -14,6 +14,12 @@
# `configure` es un script shell propio (no autoconf); no compila nada.
name = "hwdata"
version = "0.393"
+# licencia: LICENSE del tarball pineado: «This data is licenced under 2 different licenses … can be used freely under either license»
+# ⚠ XFree86-1.0 se queda SIN texto en licenses/: SPDX no publica ese identificador (sólo
+# XFree86-1.1, que es OTRA licencia) y el tarball de hwdata lo nombra sin incluirlo. El
+# guardián avisa y no veta, que es lo correcto: la rama del OR que SÍ podemos entregar es
+# la GPL, y su texto ya está en licenses/.
+license = "GPL-2.0-or-later OR XFree86-1.0"
[source]
tarball = "https://github.com/vcrhonek/hwdata/archive/refs/tags/v0.393.tar.gz"
diff --git a/recipes/incoming-cosmic/gmp.toml b/recipes/incoming-cosmic/gmp.toml
index 02518c97..ecf2240a 100644
--- a/recipes/incoming-cosmic/gmp.toml
+++ b/recipes/incoming-cosmic/gmp.toml
@@ -37,6 +37,8 @@
# la alternativa realista tampoco era «assembly sí».
name = "gmp"
version = "6.3.0"
+# licencia: README del tarball pineado — mismo sha256 que recipes/gmp.toml
+license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source]
tarball = "https://gmplib.org/download/gmp/gmp-6.3.0.tar.xz"
diff --git a/recipes/incoming-gnome/gi-foreign-girs.toml b/recipes/incoming-gnome/gi-foreign-girs.toml
index 7ee89281..eca0f121 100644
--- a/recipes/incoming-gnome/gi-foreign-girs.toml
+++ b/recipes/incoming-gnome/gi-foreign-girs.toml
@@ -7,6 +7,8 @@
# Ver [[gnome-introspection-dinamica]].
name = "gi-foreign-girs"
version = "1.84.0"
+# licencia: los .gir foráneos no traen cabecera propia (verificado en gir/fontconfig-2.0.gir del tarball), así que rige el COPYING de gobject-introspection: girepository/ es LGPLv2+ y «the remaining code … consists of a mix of GPLv2+, LGPLv2+ and MIT»
+license = "GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT"
[source]
tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz"
diff --git a/recipes/incoming-gnome/gi-foreign-typelibs.toml b/recipes/incoming-gnome/gi-foreign-typelibs.toml
index 06445c6a..9c5e80b8 100644
--- a/recipes/incoming-gnome/gi-foreign-typelibs.toml
+++ b/recipes/incoming-gnome/gi-foreign-typelibs.toml
@@ -55,6 +55,8 @@
# resuelva los includes de un .gir contra los otros .gir del sistema.
name = "gi-foreign-typelibs"
version = "1.84.0"
+# licencia: mismo tarball y mismos ficheros que gi-foreign-girs, compilados a typelib: rige el COPYING de gobject-introspection
+license = "GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT"
[source]
# El mismo tarball que gi-foreign-girs: los .gir salen de ahí. No se compila nada del proyecto.
diff --git a/recipes/incoming-gnome/gi-girepository-typelib.toml b/recipes/incoming-gnome/gi-girepository-typelib.toml
index 5e51c85b..4b321984 100644
--- a/recipes/incoming-gnome/gi-girepository-typelib.toml
+++ b/recipes/incoming-gnome/gi-girepository-typelib.toml
@@ -38,6 +38,8 @@
# dice el nombre del header. Upstream nunca lo escanea; el glob fue el error.
name = "gi-girepository-typelib"
version = "1.84.0"
+# licencia: el COPYING de gobject-introspection es explícito: «The typelib libraries (girepository/) are licensed under the LGPLv2+». Esta receta instala GIRepository-2.0.typelib y nada más
+license = "LGPL-2.1-or-later"
[source]
tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz"
diff --git a/recipes/incoming-gnome/gsd-schemas.toml b/recipes/incoming-gnome/gsd-schemas.toml
index 1283d337..ca2a8c56 100644
--- a/recipes/incoming-gnome/gsd-schemas.toml
+++ b/recipes/incoming-gnome/gsd-schemas.toml
@@ -43,6 +43,8 @@
# corriendo no aplica esas preferencias igual, así que falsearlas sólo escondería que el demonio falta.
name = "gsd-schemas"
version = "48.1"
+# licencia: COPYING del tarball de gnome-settings-daemon: GPL v2 «either version 2 … or (at your option) any later version»
+license = "GPL-2.0-or-later"
[source]
tarball = "https://download.gnome.org/sources/gnome-settings-daemon/48/gnome-settings-daemon-48.1.tar.xz"
diff --git a/recipes/incoming-gnome/libgdm.toml b/recipes/incoming-gnome/libgdm.toml
index 7be82d0c..ad828cf7 100644
--- a/recipes/incoming-gnome/libgdm.toml
+++ b/recipes/incoming-gnome/libgdm.toml
@@ -52,6 +52,8 @@
# dlopea la `.so` que el typelib nombra. Ver [[gnome-introspection-dinamica]].
name = "libgdm"
version = "48.0"
+# licencia: COPYING del tarball de gdm y la cabecera de libgdm/gdm-client.c —la librería que esta receta construye— dicen GPL v2 «or (at your option) any later version». Ojo: es GPL, no LGPL, aunque sea la librería cliente
+license = "GPL-2.0-or-later"
[source]
tarball = "https://download.gnome.org/sources/gdm/48/gdm-48.0.tar.xz"
diff --git a/recipes/incoming-gnome/libical.toml b/recipes/incoming-gnome/libical.toml
index 0ec04c8f..5b1610db 100644
--- a/recipes/incoming-gnome/libical.toml
+++ b/recipes/incoming-gnome/libical.toml
@@ -33,6 +33,8 @@
# arrastra ICalGLib; sin .so real no hay typelib. Ver [[gnome-introspection-dinamica]].
name = "libical"
version = "3.0.20"
+# licencia: LICENSE del tarball: «distributed under two licenses. You may choose the terms of either: MPL v2.0 or LGPL v2.1». El fichero no dice «or later» en ningún sitio
+license = "MPL-2.0 OR LGPL-2.1-only"
[source]
tarball = "https://github.com/libical/libical/releases/download/v3.0.20/libical-3.0.20.tar.gz"
diff --git a/recipes/incoming-kde/boost.toml b/recipes/incoming-kde/boost.toml
index 4980a519..44c09f96 100644
--- a/recipes/incoming-kde/boost.toml
+++ b/recipes/incoming-kde/boost.toml
@@ -2,6 +2,8 @@
# Boost_INCLUDE_DIR. No compilamos las libs de boost (b2): copiamos el árbol `boost/` a /usr/include.
name = "boost"
version = "1.86.0"
+# licencia: LICENSE_1_0.txt en la raíz del tarball pineado: Boost Software License 1.0
+license = "BSL-1.0"
[source]
tarball = "https://archives.boost.io/release/1.86.0/source/boost_1_86_0.tar.bz2"
diff --git a/recipes/incoming-kde/gmp.toml b/recipes/incoming-kde/gmp.toml
index bea06d46..5345f081 100644
--- a/recipes/incoming-kde/gmp.toml
+++ b/recipes/incoming-kde/gmp.toml
@@ -31,6 +31,8 @@
# (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch).
name = "gmp"
version = "6.3.0"
+# licencia: README del tarball pineado — mismo sha256 que recipes/gmp.toml
+license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source]
tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz"
diff --git a/recipes/incoming-kde/leptonica.toml b/recipes/incoming-kde/leptonica.toml
index 1e8be313..d5ba26c8 100644
--- a/recipes/incoming-kde/leptonica.toml
+++ b/recipes/incoming-kde/leptonica.toml
@@ -7,6 +7,8 @@
# lee imágenes vía leptonica, y PNG/JPEG cubre el caso de spectacle (OCR sobre una captura de pantalla).
name = "leptonica"
version = "1.85.0"
+# licencia: leptonica-license.txt del tarball pineado (sha256 verificado al bajarlo): dos condiciones, retener el aviso en fuente y reproducirlo en binario
+license = "BSD-2-Clause"
[source]
tarball = "https://github.com/DanBloomberg/leptonica/releases/download/1.85.0/leptonica-1.85.0.tar.gz"
diff --git a/recipes/incoming-kde/libcanberra.toml b/recipes/incoming-kde/libcanberra.toml
index ebfd0f5d..8b0a8a13 100644
--- a/recipes/incoming-kde/libcanberra.toml
+++ b/recipes/incoming-kde/libcanberra.toml
@@ -4,6 +4,8 @@
# (deuda Capa 0 audio). find_package(Canberra) usa FindCanberra.cmake (pkg-config libcanberra.pc → target).
name = "libcanberra"
version = "0.30"
+# licencia: el tarball no trae COPYING, trae el texto en LGPL y las cabeceras (src/canberra.h) dicen «either version 2.1 … or (at your option) any later version»
+license = "LGPL-2.1-or-later"
[source]
# 0pointer.de (upstream original) murió ~2026-07. Mirror BLFS/OSUOSL = MISMO tarball byte a byte
# (sha256 verificado idéntico, 318960 bytes). Es el archivo canónico de tarballs viejos, muy estable.
diff --git a/recipes/lsof.toml b/recipes/lsof.toml
index 28518672..a6967ce6 100644
--- a/recipes/lsof.toml
+++ b/recipes/lsof.toml
@@ -3,6 +3,8 @@
# sha256 del tarball (el wrapper lo calcula), y adaptar build/install del shell de abuild.
name = "lsof"
version = "4.99.7"
+# licencia: COPYING del tarball pineado: licencia propia de Purdue Research Foundation, sin identificador SPDX. Era uno de los DOS que vetaban las imágenes base y cli (docs/20-catalogo-publicable-y-completa.md)
+license = "LicenseRef-lsof"
[source]
tarball = "https://github.com/lsof-org/lsof/archive/4.99.7/lsof-4.99.7.tar.gz"
diff --git a/recipes/openssh.toml b/recipes/openssh.toml
index f3b196a1..297afb88 100644
--- a/recipes/openssh.toml
+++ b/recipes/openssh.toml
@@ -35,6 +35,8 @@
name = "openssh"
version = "10.3p1"
+# licencia: LICENCE del tarball pineado. Es una MEZCLA que el propio fichero enumera —BSD-2/3-Clause, ISC, MIT y dominio público— con el resumen «all components are under a BSD licence, or a licence more free than that». Se entrega el fichero entero en vez de una expresión compuesta: la enumeración de upstream no necesita interpretación nuestra
+license = "LicenseRef-openssh"
[source]
tarball = "https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-10.3p1.tar.gz"
diff --git a/recipes/pigz.toml b/recipes/pigz.toml
index d989fa78..09ef55fa 100644
--- a/recipes/pigz.toml
+++ b/recipes/pigz.toml
@@ -4,6 +4,8 @@
# matar-gcc contaba `compiler = "gcc"` y no miraba las fases, así que pigz no figuraba como deuda.
name = "pigz"
version = "2.8"
+# licencia: el bloque de licencia de pigz.c en el tarball pineado es el texto de la licencia zlib palabra por palabra (Mark Adler)
+license = "Zlib"
[source]
tarball = "https://zlib.net/pigz/pigz-2.8.tar.gz"
sha256 = "eb872b4f0e1f0ebe59c9f7bd8c506c4204893ba6a8492de31df416f0d5170fd0"
diff --git a/recipes/sqlite-shared.toml b/recipes/sqlite-shared.toml
index 40c3e6a3..154f48c3 100644
--- a/recipes/sqlite-shared.toml
+++ b/recipes/sqlite-shared.toml
@@ -28,6 +28,8 @@
# corpus, así que no se abre un skew de versiones entre el mundo estático y el dinámico.
name = "sqlite-shared"
version = "3.46.1"
+# licencia: MISMO sha256 de tarball que recipes/sqlite.toml, que ya declara `blessing` (la bendición del dominio público de SQLite)
+license = "blessing"
[source]
tarball = "https://sqlite.org/2024/sqlite-autoconf-3460100.tar.gz"
diff --git a/recipes/tzdata.toml b/recipes/tzdata.toml
index ef26932e..f5006cc4 100644
--- a/recipes/tzdata.toml
+++ b/recipes/tzdata.toml
@@ -11,6 +11,8 @@
# de `posixtz` (no lo construimos).
name = "tzdata"
version = "2026b"
+# licencia: LICENSE del commit pineado: «all files in the tz code and data … are in the public domain», salvo date.c/newstrftime.3/strftime.c, que son BSD-3-Clause y esta receta NO instala — sólo compila zic y deja /usr/share/zoneinfo. Era el otro de los DOS que vetaban base y cli
+license = "LicenseRef-tz-public-domain"
[source]
repo = "https://github.com/eggert/tz"
diff --git a/recipes/vulkan-headers.toml b/recipes/vulkan-headers.toml
index 40b0f7b8..77cf3d34 100644
--- a/recipes/vulkan-headers.toml
+++ b/recipes/vulkan-headers.toml
@@ -18,6 +18,8 @@
# vulkan-loader. Tests y el módulo C++20 (Vulkan-Hpp) apagados.
name = "vulkan-headers"
version = "1.4.350.1"
+# licencia: LICENSE.md del tarball pineado: «SPDX-License-Identifier: Apache-2.0 OR MIT»
+license = "Apache-2.0 OR MIT"
[source]
tarball = "https://github.com/KhronosGroup/Vulkan-Headers/archive/refs/tags/vulkan-sdk-1.4.350.1.tar.gz"
diff --git a/recipes/waybackurls.toml b/recipes/waybackurls.toml
index d08cb33a..9ed9e60b 100644
--- a/recipes/waybackurls.toml
+++ b/recipes/waybackurls.toml
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "waybackurls"
version = "0.1.0"
+# licencia: ⚠ EL REPO NO DECLARA LICENCIA en el commit pineado: la raíz del árbol es .gitignore, README.mkd, go.mod, main.go y script/ — sin LICENSE ni COPYING, y el README no la menciona. Sin concesión expresa, el derecho de autor por defecto es «todos los derechos reservados» ⇒ NO se puede redistribuir en una imagen. Se declara para que el veto lo VEA en vez de que el campo vacío se lea como «falta poblarlo»
+license = "LicenseRef-sin-licencia-declarada"
[source]
repo = "https://github.com/tomnomnom/waybackurls"
diff --git a/recipes/xz-shared.toml b/recipes/xz-shared.toml
index 783f20bd..3f03e7ab 100644
--- a/recipes/xz-shared.toml
+++ b/recipes/xz-shared.toml
@@ -5,6 +5,8 @@
# liblzma.so con autotools --enable-shared (PIC nativo). Nombre distinto para no colisionar con el canónico.
name = "xz-shared"
version = "5.8.3"
+# licencia: MISMO sha256 de tarball que recipes/xz.toml, que ya declara 0BSD; el COPYING confirma que liblzma —lo que esta variante publica— es 0BSD (lo GPLv2+ son los scripts xzgrep/xzdiff, que no se instalan)
+license = "0BSD"
[source]
tarball = "https://github.com/tukaani-project/xz/releases/download/v5.8.3/xz-5.8.3.tar.xz"
diff --git a/scripts/licencias-rootfs.sh b/scripts/licencias-rootfs.sh
index b227dba8..6a5dc980 100755
--- a/scripts/licencias-rootfs.sh
+++ b/scripts/licencias-rootfs.sh
@@ -40,11 +40,40 @@ elif [ ! -t 0 ]; then cat > /tmp/.lic-pkgs
else echo "!! sin lista de paquetes (pasala por argumento o stdin)"; exit 2; fi
sort -u /tmp/.lic-pkgs | grep -v '^$' > /tmp/.lic-pkgs2 && mv /tmp/.lic-pkgs2 /tmp/.lic-pkgs
+# ⚠ SE RESUELVE POR EL CAMPO `name`, NO POR EL NOMBRE DE FICHERO (2026-09-09).
+# Antes esto hacía `ls recipes/$1.toml` y nada más, y el paquete se llama por su campo `name`, que
+# en 34 recetas del corpus NO coincide con el fichero (recipes/nu.toml → `nushell`, dust.toml →
+# `du-dust`, incoming-kde/qtbase.toml → `qt6-qtbase`…). Medido: **14 paquetes que SÍ declaran
+# licencia salían como «licencia desconocida»** y el guardián vetaba una imagen perfectamente
+# publicable. Un falso veto se nota; el hermano silencioso no: si el fichero .toml existe pero
+# pertenece a OTRO paquete, la versión vieja reportaba la licencia EQUIVOCADA sin decir nada. Hoy no
+# pasa (medido: 0 casos), pero el índice por `name` lo hace imposible en vez de improbable.
+# El índice se arma UNA vez: 1128 recetas, no una por paquete.
+IDX=$(mktemp)
+for f in recipes/*.toml recipes/incoming-*/*.toml; do
+ [ -f "$f" ] || continue
+ awk -F'"' -v ARCH="$f" -v BASE="$(basename "$f" .toml)" '
+ /^\[/{exit}
+ /^[[:space:]]*name[[:space:]]*=/ {if(!n) n=$2}
+ /^[[:space:]]*license[[:space:]]*=/{if(!l) l=$2}
+ END{if(n) printf "%s\t%s\t%s\t%s\n", n, l, ARCH, BASE}' "$f"
+done > "$IDX"
+trap 'rm -f "$IDX"' EXIT
+# Precedencia: la receta canónica (recipes/*.toml) antes que una cola incoming-*, igual que antes.
+# Comprobado que no cambia nada hoy: de los 34 nombres duplicados, CERO declaran licencias distintas.
+# Se busca por `name` y, si no aparece, por nombre de FICHERO: los dos llamadores existen y usan
+# claves distintas — el grafo de estado nombra sus nodos por el fichero (`dust`) y el artefacto del
+# store por el campo `name` (`du-dust`). Resolver sólo por uno rompe al otro; medido en los dos
+# sentidos sobre el perfil base+cli y sobre el corpus entero.
licencia_de_receta() {
- f=$(ls "recipes/$1.toml" 2>/dev/null | head -1)
- [ -z "$f" ] && f=$(ls recipes/incoming-*/"$1.toml" 2>/dev/null | head -1)
- [ -z "$f" ] && return 1
- awk -F'"' '/^\[/{exit} /^[[:space:]]*license[[:space:]]*=/{print $2; exit}' "$f"
+ lic=$(awk -F'\t' -v p="$1" '
+ $1==p && $2!="" {if ($3 !~ /^recipes\/incoming-/) {print $2; exit} else if (!c) c=$2}
+ END{if (c) print c}' "$IDX")
+ [ -n "$lic" ] || lic=$(awk -F'\t' -v p="$1" '
+ $4==p && $2!="" {if ($3 !~ /^recipes\/incoming-/) {print $2; exit} else if (!c) c=$2}
+ END{if (c) print c}' "$IDX")
+ [ -n "$lic" ] || return 1
+ printf '%s\n' "$lic"
}
DESTDIR="$PREFIX/usr/share/licenses"