licencias: las 26 que faltaban, y el guardián que las contaba mal

CAMPAÑA CERRADA: 1166/1166 recetas declaran `license`. Ninguna adivinada — cada una sale del
fichero de licencia de su fuente PINEADA (tarball del sha256 de la receta, o el commit exacto en
la forja), y la cita queda como comentario en la propia receta.

⚠ Y EL GUARDIÁN ESTABA MAL, que es el hallazgo que vale más que las 26. `licencias-rootfs.sh`
resolvía la receta por NOMBRE DE FICHERO (`ls recipes/$pkg.toml`), y el paquete se llama por su
campo `name`, que en 34 recetas NO coincide: nu.toml→`nushell`, dust.toml→`du-dust`,
incoming-kde/qtbase.toml→`qt6-qtbase`… Medido: **14 paquetes que SÍ declaran licencia salían como
«licencia desconocida»** y el guardián vetaba una imagen perfectamente publicable.
El falso veto se nota; el hermano silencioso NO: si existe un `<pkg>.toml` que pertenece a OTRO
paquete, la versión vieja reportaba la licencia EQUIVOCADA sin decir nada. Hoy no pasa —medido,
0 casos, y de los 34 nombres duplicados CERO declaran licencias distintas—, pero ahora es
imposible en vez de improbable.

El arreglo tuvo que ser por LOS DOS lados, y el primer intento rompió el otro: el grafo de estado
nombra sus nodos por el fichero (`dust`) y el artefacto del store por `name` (`du-dust`), así que
resolver sólo por `name` dejaba a `dust` sin licencia. Ahora busca por `name` y cae al fichero.
Medido en los dos sentidos: corpus entero 1128/1128, perfil base+cli 81/81, cero sin licencia.

Y probado CON ROTURA A PROPÓSITO además del control, que es lo único que distingue a un guardián
que sirve de uno que nunca salta:
  paquete inexistente en la lista               → exit 1 y «ESTA IMAGEN NO SE PUEDE PUBLICAR»
  control (zlib nushell qt6-qtbase lsof tzdata) → exit 0, y escribe los textos
(⚠ ojo al medir: `script | tail` devuelve el exit de `tail`. La primera corrida dijo exit=0 sobre
la rotura y no era el guardián, era el pipe.)

SE LEVANTA EL VETO QUE SDD 20 DEJÓ ESCRITO. Decía que `base` y `cli` iban con 2 paquetes cada una
con binarios y licencia desconocida: `lsof` y `tzdata`, «que necesitan la vía LicenseRef- y siguen
vetando a propósito». Hechos los dos, con su texto real en licenses/:
  lsof    → LicenseRef-lsof (licencia propia de Purdue, sin identificador SPDX)
  tzdata  → LicenseRef-tz-public-domain (su LICENSE: «all files in the tz code and data … are in
            the public domain»; los tres ficheros BSD-3-Clause que menciona NO se instalan — la
            receta sólo compila zic y deja /usr/share/zoneinfo)

⚠ DOS QUE NO SE PUEDEN REDISTRIBUIR, y ahora el veto los ve:
  duplicacy    NO ES LIBRE. Su LICENSE.md: «Free for personal use or commercial trial; non-trial
               commercial use requires per-computer CLI licenses … $50 per year»
  waybackurls  NO DECLARA LICENCIA: en el commit pineado la raíz es .gitignore, README.mkd,
               go.mod, main.go y script/ — sin LICENSE ni COPYING, y el README no la menciona. Sin
               concesión expresa, el defecto es «todos los derechos reservados»
Los dos con LicenseRef y un texto en licenses/ que explica qué hay, en vez de dejar el campo vacío,
que se lee como «todavía no lo poblamos». Ninguno está hoy en un perfil de imagen; si alguien los
mete, el guardián corta.

De paso queda escrito el texto de `LicenseRef-qorpa-ajena-no-enumerable`, que ya se usaba en
steam-runtime-sniper y no tenía fichero; y `licencias-textos.sh` bajó los canónicos nuevos
(BSL-1.0 para boost, GCC-exception-3.1 que ya hacía falta).

Hueco conocido y anotado en la receta: `XFree86-1.0` (rama del OR de hwdata) se queda sin texto —
SPDX no publica ese identificador, sólo XFree86-1.1, que es otra licencia, y el tarball lo nombra
sin incluirlo. El guardián avisa y no veta, que es correcto: la otra rama del OR es la GPL y su
texto sí está.

NADA SE RE-HASHEA: `license` está fuera de `hash_inputs`. Verificado, no supuesto — `hammer hash`
sobre pigz, lsof y boost después de editarlas devuelve el hash cuyo artefacto YA está en el store.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LCt3ettR4Z7b6wPCBmbvEV
This commit is contained in:
Sergio
2026-09-09 17:47:16 +00:00
co-authored by Claude Opus 5
parent d8f1280ae9
commit 3379a1f170
35 changed files with 618 additions and 4 deletions
+7
View File
@@ -0,0 +1,7 @@
Boost Software License - Version 1.0 - August 17th, 2003
Permission is hereby granted, free of charge, to any person or organization obtaining a copy of the software and accompanying documentation covered by this license (the "Software") to use, reproduce, display, distribute, execute, and transmit the Software, and to prepare derivative works of the Software, and to permit third-parties to whom the Software is furnished to do so, all subject to the following:
The copyright notices in the Software and this entire statement, including the above license grant, this restriction and the following disclaimer, must be included in all copies of the Software, in whole or in part, and all derivative works of the Software, unless such copies or derivative works are solely in the form of machine-executable object code generated by a source language processor.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR ANYONE DISTRIBUTING THE SOFTWARE BE LIABLE FOR ANY DAMAGES OR OTHER LIABILITY, WHETHER IN CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+33
View File
@@ -0,0 +1,33 @@
GCC RUNTIME LIBRARY EXCEPTION
Version 3.1, 31 March 2009
General information: http://www.gnu.org/licenses/gcc-exception.html
Copyright (C) 2009 Free Software Foundation, Inc. <http://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
This GCC Runtime Library Exception ("Exception") is an additional permission under section 7 of the GNU General Public License, version 3 ("GPLv3"). It applies to a given file (the "Runtime Library") that bears a notice placed by the copyright holder of the file stating that the file is governed by GPLv3 along with this Exception.
When you use GCC to compile a program, GCC may combine portions of certain GCC header files and runtime libraries with the compiled program. The purpose of this Exception is to allow compilation of non-GPL (including proprietary) programs to use, in this way, the header files and runtime libraries covered by this Exception.
0. Definitions.
A file is an "Independent Module" if it either requires the Runtime Library for execution after a Compilation Process, or makes use of an interface provided by the Runtime Library, but is not otherwise based on the Runtime Library.
"GCC" means a version of the GNU Compiler Collection, with or without modifications, governed by version 3 (or a specified later version) of the GNU General Public License (GPL) with the option of using any subsequent versions published by the FSF.
"GPL-compatible Software" is software whose conditions of propagation, modification and use would permit combination with GCC in accord with the license of GCC.
"Target Code" refers to output from any compiler for a real or virtual target processor architecture, in executable form or suitable for input to an assembler, loader, linker and/or execution phase. Notwithstanding that, Target Code does not include data in any format that is used as a compiler intermediate representation, or used for producing a compiler intermediate representation.
The "Compilation Process" transforms code entirely represented in non-intermediate languages designed for human-written code, and/or in Java Virtual Machine byte code, into Target Code. Thus, for example, use of source code generators and preprocessors need not be considered part of the Compilation Process, since the Compilation Process can be understood as starting with the output of the generators or preprocessors.
A Compilation Process is "Eligible" if it is done using GCC, alone or with other GPL-compatible software, or if it is done without using any work based on GCC. For example, using non-GPL-compatible Software to optimize any GCC intermediate representations would not qualify as an Eligible Compilation Process.
1. Grant of Additional Permission.
You have permission to propagate a work of Target Code formed by combining the Runtime Library with Independent Modules, even if such propagation would otherwise violate the terms of GPLv3, provided that all Target Code was generated by Eligible Compilation Processes. You may then convey such a combination under terms of your choice, consistent with the licensing of the Independent Modules.
2. No Weakening of GCC Copyleft.
The availability of this Exception does not imply any general presumption that third-party software is unaffected by the copyleft requirements of the license of GCC.
@@ -0,0 +1,7 @@
Copyright © 2017 Acrosync LLC
* Free for personal use or commercial trial
* Non-trial commercial use requires per-computer CLI licenses available from [duplicacy.com](https://duplicacy.com/buy.html) at a cost of $50 per year
* The computer with a valid commercial license for the GUI version may run the CLI version without a CLI license
* CLI licenses are not required to restore or manage backups; only the backup command requires valid CLI licenses
* Modification and redistribution are permitted, but commercial use of derivative works is subject to the same requirements of this license
+26
View File
@@ -0,0 +1,26 @@
Copyright 2002 Purdue Research Foundation, West Lafayette,
Indiana 47907. All rights reserved.
Written by Victor A. Abell
This software is not subject to any license of the American
Telephone and Telegraph Company or the Regents of the
University of California.
Permission is granted to anyone to use this software for
any purpose on any computer system, and to alter it and
redistribute it freely, subject to the following
restrictions:
1. Neither the authors nor Purdue University are responsible
for any consequences of the use of this software.
2. The origin of this software must not be misrepresented,
either by explicit claim or by omission. Credit to the
authors and Purdue University must appear in documentation
and sources.
3. Altered versions must be plainly marked as such, and must
not be misrepresented as being the original software.
4. This notice may not be removed or altered.
+412
View File
@@ -0,0 +1,412 @@
This file is part of the OpenSSH software.
The licences which components of this software fall under are as
follows. First, we will summarize and say that all components
are under a BSD licence, or a licence more free than that.
OpenSSH contains no GPL code.
1)
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
* All rights reserved
*
* As far as I am concerned, the code I have written for this software
* can be used freely for any purpose. Any derived versions of this
* software must be clearly marked as such, and if the derived work is
* incompatible with the protocol description in the RFC file, it must be
* called by a name other than "ssh" or "Secure Shell".
[Tatu continues]
* However, I am not implying to give any licenses to any patents or
* copyrights held by third parties, and the software includes parts that
* are not under my direct control. As far as I know, all included
* source code is used in accordance with the relevant license agreements
* and can be used freely for any purpose (the GNU license being the most
* restrictive); see below for details.
[However, none of that term is relevant at this point in time. All of
these restrictively licenced software components which he talks about
have been removed from OpenSSH, i.e.,
- RSA is no longer included, found in the OpenSSL library
- IDEA is no longer included, its use is deprecated
- DES is now external, in the OpenSSL library
- GMP is no longer used, and instead we call BN code from OpenSSL
- Zlib is now external, in a library
- The make-ssh-known-hosts script is no longer included
- TSS has been removed
- MD5 is now external, in the OpenSSL library
- RC4 support has been replaced with ARC4 support from OpenSSL
- Blowfish is now external, in the OpenSSL library
[The licence continues]
Note that any information and cryptographic algorithms used in this
software are publicly available on the Internet and at any major
bookstore, scientific library, and patent office worldwide. More
information can be found e.g. at "http://www.cs.hut.fi/crypto".
The legal status of this program is some combination of all these
permissions and restrictions. Use only at your own responsibility.
You will be responsible for any legal consequences yourself; I am not
making any claims whether possessing or using this is legal or not in
your country, and I am not taking any responsibility on your behalf.
NO WARRANTY
BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS
TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
REPAIR OR CORRECTION.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES.
3)
ssh-keyscan was contributed by David Mazieres under a BSD-style
license.
* Copyright 1995, 1996 by David Mazieres <dm@lcs.mit.edu>.
*
* Modification and redistribution in source and binary forms is
* permitted provided that due credit is given to the author and the
* OpenBSD project by leaving this copyright notice intact.
4)
The Rijndael implementation by Vincent Rijmen, Antoon Bosselaers
and Paulo Barreto is in the public domain and distributed
with the following license:
* @version 3.0 (December 2000)
*
* Optimised ANSI C code for the Rijndael cipher (now AES)
*
* @author Vincent Rijmen <vincent.rijmen@esat.kuleuven.ac.be>
* @author Antoon Bosselaers <antoon.bosselaers@esat.kuleuven.ac.be>
* @author Paulo Barreto <paulo.barreto@terra.com.br>
*
* This code is hereby placed in the public domain.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHORS ''AS IS'' AND ANY EXPRESS
* OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
* WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
* BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
* WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
* OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE,
* EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
5)
One component of the ssh source code is under a 3-clause BSD license,
held by the University of California, since we pulled these parts from
original Berkeley code.
* Copyright (c) 1983, 1990, 1992, 1993, 1995
* The Regents of the University of California. All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. Neither the name of the University nor the names of its contributors
* may be used to endorse or promote products derived from this software
* without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
6)
Remaining components of the software are provided under a standard
2-term BSD licence with the following names as copyright holders:
Markus Friedl
Theo de Raadt
Niels Provos
Dug Song
Aaron Campbell
Damien Miller
Kevin Steves
Daniel Kouril
Wesley Griffin
Per Allansson
Nils Nordman
Simon Wilkinson
Portable OpenSSH additionally includes code from the following copyright
holders, also under the 2-term BSD license:
Ben Lindstrom
Tim Rice
Andre Lucas
Chris Adams
Corinna Vinschen
Cray Inc.
Denis Parker
Gert Doering
Jakob Schlyter
Jason Downs
Juha Yrjölä
Michael Stone
Networks Associates Technology, Inc.
Solar Designer
Todd C. Miller
Wayne Schroeder
William Jones
Darren Tucker
Sun Microsystems
The SCO Group
Daniel Walsh
Red Hat, Inc
Simon Vallet / Genoscope
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
8) Portable OpenSSH contains the following additional licenses:
a) snprintf replacement
* Copyright Patrick Powell 1995
* This code is based on code written by Patrick Powell
* (papowell@astart.com) It may be used for any purpose as long as this
* notice remains intact on all source code distributions
b) Compatibility code (openbsd-compat)
Apart from the previously mentioned licenses, various pieces of code
in the openbsd-compat/ subdirectory are licensed as follows:
Some code is licensed under a 3-term BSD license, to the following
copyright holders:
Todd C. Miller
Theo de Raadt
Damien Miller
Eric P. Allman
The Regents of the University of California
Constantin S. Svintsoff
Kungliga Tekniska Högskolan
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. Neither the name of the University nor the names of its contributors
* may be used to endorse or promote products derived from this software
* without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
Some code is licensed under an ISC-style license, to the following
copyright holders:
Internet Software Consortium.
Todd C. Miller
Reyk Floeter
Chad Mynhier
* Permission to use, copy, modify, and distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* copyright notice and this permission notice appear in all copies.
*
* THE SOFTWARE IS PROVIDED "AS IS" AND TODD C. MILLER DISCLAIMS ALL
* WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL TODD C. MILLER BE LIABLE
* FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
Some code is licensed under a MIT-style license to the following
copyright holders:
Free Software Foundation, Inc.
* Permission is hereby granted, free of charge, to any person obtaining a *
* copy of this software and associated documentation files (the *
* "Software"), to deal in the Software without restriction, including *
* without limitation the rights to use, copy, modify, merge, publish, *
* distribute, distribute with modifications, sublicense, and/or sell *
* copies of the Software, and to permit persons to whom the Software is *
* furnished to do so, subject to the following conditions: *
* *
* The above copyright notice and this permission notice shall be included *
* in all copies or substantial portions of the Software. *
* *
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS *
* OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF *
* MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. *
* IN NO EVENT SHALL THE ABOVE COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, *
* DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR *
* OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR *
* THE USE OR OTHER DEALINGS IN THE SOFTWARE. *
* *
* Except as contained in this notice, the name(s) of the above copyright *
* holders shall not be used in advertising or otherwise to promote the *
* sale, use or other dealings in this Software without prior written *
* authorization. *
****************************************************************************/
The Blowfish cipher implementation is licensed by Niels Provos under
a 3-clause BSD license:
* Blowfish - a fast block cipher designed by Bruce Schneier
*
* Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de>
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. The name of the author may not be used to endorse or promote products
* derived from this software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Some replacement code is licensed by the NetBSD foundation under a
2-clause BSD license:
* Copyright (c) 2001 The NetBSD Foundation, Inc.
* All rights reserved.
*
* This code is derived from software contributed to The NetBSD Foundation
* by Todd Vierling.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
* ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
* TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
* BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
* POSSIBILITY OF SUCH DAMAGE.
The replacement base64 implementation has the following MIT-style
licenses:
* Copyright (c) 1996 by Internet Software Consortium.
*
* Permission to use, copy, modify, and distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
* copyright notice and this permission notice appear in all copies.
*
* THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS
* ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE
* CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
* DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
* PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
* ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
* SOFTWARE.
* Portions Copyright (c) 1995 by International Business Machines, Inc.
*
* International Business Machines, Inc. (hereinafter called IBM) grants
* permission under its copyrights to use, copy, modify, and distribute this
* Software with or without fee, provided that the above copyright notice and
* all paragraphs of this notice appear in all copies, and that the name of IBM
* not be used in connection with the marketing of any product incorporating
* the Software or modifications thereof, without specific, written prior
* permission.
*
* To the extent it has a right to do so, IBM grants an immunity from suit
* under its patents, if any, for the use, sale or manufacture of products to
* the extent that such products are used for performing Domain Name System
* dynamic updates in TCP/IP networks by means of the Software. No immunity is
* granted for any product per se or for any other function of any product.
*
* THE SOFTWARE IS PROVIDED "AS IS", AND IBM DISCLAIMS ALL WARRANTIES,
* INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
* PARTICULAR PURPOSE. IN NO EVENT SHALL IBM BE LIABLE FOR ANY SPECIAL,
* DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER ARISING
* OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE, EVEN
* IF IBM IS APPRISED OF THE POSSIBILITY OF SUCH DAMAGES.
------
$OpenBSD: LICENCE,v 1.20 2017/04/30 23:26:16 djm Exp $
@@ -0,0 +1,20 @@
IMAGEN AJENA — TÉRMINOS NO ENUMERABLES
======================================
Este identificador NO es una licencia: marca un artefacto que NO construimos
nosotros desde fuente, sino un rootfs de otra distribución que se trae pineado
por sha256 y corre enjaulado (ADR 0015, «imágenes ajenas» / qorpa).
POR QUÉ NO SE ENUMERA. Adentro hay cientos de paquetes de terceros, cada uno
con sus propios términos. Afirmar una licencia única sobre ese conjunto sería
inventarla, y dejar el campo vacío se leería como «todavía no lo poblamos».
QUIÉN PONE LOS TÉRMINOS. Quien publica la imagen, que no somos nosotros. La
relación de licencia es entre el usuario y esa distribución, cuyo material se
trae por URL + sha256.
ALCANCE. Estos artefactos van con `foreign = true`, el grafo los clasifica
`ajeno` y quedan FUERA del catálogo publicable y del reporte de licencias
(docs/20-catalogo-publicable-y-completa.md). Replicarlos a nuestras propias
máquinas (`hammer mirror push`) es una cosa; PUBLICARLOS a terceros pide mirar
licencia y marca antes, y eso no es una pregunta técnica.
@@ -0,0 +1,19 @@
SIN LICENCIA DECLARADA
======================
Este identificador NO es una licencia: es la constancia de que el proyecto de
origen NO declara ninguna en el commit que la receta pinea. No hay LICENSE ni
COPYING en el árbol, y el README no menciona términos de uso.
QUÉ SIGNIFICA. Sin una concesión expresa del autor, el derecho de autor por
defecto reserva todos los derechos: no hay permiso para redistribuir el
programa ni sus binarios. Que el código esté publicado en una forja NO es una
licencia.
POR QUÉ ESTÁ ESCRITO Y NO VACÍO. Un campo `license` vacío se lee como «todavía
no lo poblamos» y pasa desapercibido; escrito, el guardián de licencias
(scripts/licencias-rootfs.sh) lo ve y el paquete queda marcado en el manifiesto
de cualquier imagen que lo incluya.
QUÉ HAY QUE HACER antes de publicar una imagen que lo contenga: pedirle al
autor que declare una licencia, o sacar el paquete de esa imagen.
+5
View File
@@ -0,0 +1,5 @@
Unless specified below, all files in the tz code and data (including
this LICENSE file) are in the public domain.
If the files date.c, newstrftime.3, and strftime.c are present, they
contain material derived from BSD and use the BSD 3-clause license.
+2
View File
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren. # - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "amp" name = "amp"
version = "0.7.1" version = "0.7.1"
# licencia: LICENSE del repo en el commit pineado: «GNU General Public License … either version 3 … or (at your option) any later version»
license = "GPL-3.0-or-later"
[source] [source]
repo = "https://github.com/jmacdonald/amp" repo = "https://github.com/jmacdonald/amp"
+2
View File
@@ -6,6 +6,8 @@
# - deps.build=["zlib"]: git2/openssl-sys enlazan -lz. # - deps.build=["zlib"]: git2/openssl-sys enlazan -lz.
name = "cargo-audit" name = "cargo-audit"
version = "0.22.1" version = "0.22.1"
# licencia: campo `license` del Cargo.toml de cargo-audit/ dentro del tarball pineado
license = "Apache-2.0 OR MIT"
[source] [source]
tarball = "https://github.com/RustSec/cargo-audit/archive/cargo-audit/v0.22.1.tar.gz" tarball = "https://github.com/RustSec/cargo-audit/archive/cargo-audit/v0.22.1.tar.gz"
+2
View File
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren. # - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "cargo-binstall" name = "cargo-binstall"
version = "1.20.0" version = "1.20.0"
# licencia: campo `license` de crates/bin/Cargo.toml —el binario que construimos— en el commit pineado. El workspace no declara licencia; la declara el crate
license = "GPL-3.0-only"
[source] [source]
repo = "https://github.com/cargo-bins/cargo-binstall" repo = "https://github.com/cargo-bins/cargo-binstall"
+2
View File
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren. # - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "duplicacy" name = "duplicacy"
version = "3.2.5" version = "3.2.5"
# licencia: ⚠ NO ES SOFTWARE LIBRE. LICENSE.md del commit pineado: «Free for personal use or commercial trial; Non-trial commercial use requires per-computer CLI licenses … $50 per year». Se declara con LicenseRef porque no hay identificador SPDX, y el texto va en licenses/ para que quien reciba una imagen lo lea
license = "LicenseRef-duplicacy-no-libre"
[source] [source]
repo = "https://github.com/gilbertchen/duplicacy" repo = "https://github.com/gilbertchen/duplicacy"
+2
View File
@@ -34,6 +34,8 @@
# lo que quisimos y sellar lo que había. # lo que quisimos y sellar lo que había.
name = "fuse3" name = "fuse3"
version = "3.18.2" version = "3.18.2"
# licencia: LICENSE del tarball pineado: include/ y lib/ bajo LGPL v2.1, «all other files» bajo GPL v2. Ninguno dice «or later»
license = "LGPL-2.1-only AND GPL-2.0-only"
[source] [source]
tarball = "https://github.com/libfuse/libfuse/archive/fuse-3.18.2/libfuse-fuse-3.18.2.tar.gz" tarball = "https://github.com/libfuse/libfuse/archive/fuse-3.18.2/libfuse-fuse-3.18.2.tar.gz"
+2
View File
@@ -31,6 +31,8 @@
# (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch). # (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch).
name = "gmp" name = "gmp"
version = "6.3.0" version = "6.3.0"
# licencia: README del tarball pineado (sha256 verificado al bajarlo): LGPLv3+ o GPLv2+, «or both in parallel»
license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source] [source]
tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz" tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz"
+6
View File
@@ -14,6 +14,12 @@
# `configure` es un script shell propio (no autoconf); no compila nada. # `configure` es un script shell propio (no autoconf); no compila nada.
name = "hwdata" name = "hwdata"
version = "0.393" version = "0.393"
# licencia: LICENSE del tarball pineado: «This data is licenced under 2 different licenses … can be used freely under either license»
# ⚠ XFree86-1.0 se queda SIN texto en licenses/: SPDX no publica ese identificador (sólo
# XFree86-1.1, que es OTRA licencia) y el tarball de hwdata lo nombra sin incluirlo. El
# guardián avisa y no veta, que es lo correcto: la rama del OR que SÍ podemos entregar es
# la GPL, y su texto ya está en licenses/.
license = "GPL-2.0-or-later OR XFree86-1.0"
[source] [source]
tarball = "https://github.com/vcrhonek/hwdata/archive/refs/tags/v0.393.tar.gz" tarball = "https://github.com/vcrhonek/hwdata/archive/refs/tags/v0.393.tar.gz"
+2
View File
@@ -37,6 +37,8 @@
# la alternativa realista tampoco era «assembly sí». # la alternativa realista tampoco era «assembly sí».
name = "gmp" name = "gmp"
version = "6.3.0" version = "6.3.0"
# licencia: README del tarball pineado — mismo sha256 que recipes/gmp.toml
license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source] [source]
tarball = "https://gmplib.org/download/gmp/gmp-6.3.0.tar.xz" tarball = "https://gmplib.org/download/gmp/gmp-6.3.0.tar.xz"
@@ -7,6 +7,8 @@
# Ver [[gnome-introspection-dinamica]]. # Ver [[gnome-introspection-dinamica]].
name = "gi-foreign-girs" name = "gi-foreign-girs"
version = "1.84.0" version = "1.84.0"
# licencia: los .gir foráneos no traen cabecera propia (verificado en gir/fontconfig-2.0.gir del tarball), así que rige el COPYING de gobject-introspection: girepository/ es LGPLv2+ y «the remaining code … consists of a mix of GPLv2+, LGPLv2+ and MIT»
license = "GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT"
[source] [source]
tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz" tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz"
@@ -55,6 +55,8 @@
# resuelva los includes de un .gir contra los otros .gir del sistema. # resuelva los includes de un .gir contra los otros .gir del sistema.
name = "gi-foreign-typelibs" name = "gi-foreign-typelibs"
version = "1.84.0" version = "1.84.0"
# licencia: mismo tarball y mismos ficheros que gi-foreign-girs, compilados a typelib: rige el COPYING de gobject-introspection
license = "GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT"
[source] [source]
# El mismo tarball que gi-foreign-girs: los .gir salen de ahí. No se compila nada del proyecto. # El mismo tarball que gi-foreign-girs: los .gir salen de ahí. No se compila nada del proyecto.
@@ -38,6 +38,8 @@
# dice el nombre del header. Upstream nunca lo escanea; el glob fue el error. # dice el nombre del header. Upstream nunca lo escanea; el glob fue el error.
name = "gi-girepository-typelib" name = "gi-girepository-typelib"
version = "1.84.0" version = "1.84.0"
# licencia: el COPYING de gobject-introspection es explícito: «The typelib libraries (girepository/) are licensed under the LGPLv2+». Esta receta instala GIRepository-2.0.typelib y nada más
license = "LGPL-2.1-or-later"
[source] [source]
tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz" tarball = "https://download.gnome.org/sources/gobject-introspection/1.84/gobject-introspection-1.84.0.tar.xz"
+2
View File
@@ -43,6 +43,8 @@
# corriendo no aplica esas preferencias igual, así que falsearlas sólo escondería que el demonio falta. # corriendo no aplica esas preferencias igual, así que falsearlas sólo escondería que el demonio falta.
name = "gsd-schemas" name = "gsd-schemas"
version = "48.1" version = "48.1"
# licencia: COPYING del tarball de gnome-settings-daemon: GPL v2 «either version 2 … or (at your option) any later version»
license = "GPL-2.0-or-later"
[source] [source]
tarball = "https://download.gnome.org/sources/gnome-settings-daemon/48/gnome-settings-daemon-48.1.tar.xz" tarball = "https://download.gnome.org/sources/gnome-settings-daemon/48/gnome-settings-daemon-48.1.tar.xz"
+2
View File
@@ -52,6 +52,8 @@
# dlopea la `.so` que el typelib nombra. Ver [[gnome-introspection-dinamica]]. # dlopea la `.so` que el typelib nombra. Ver [[gnome-introspection-dinamica]].
name = "libgdm" name = "libgdm"
version = "48.0" version = "48.0"
# licencia: COPYING del tarball de gdm y la cabecera de libgdm/gdm-client.c —la librería que esta receta construye— dicen GPL v2 «or (at your option) any later version». Ojo: es GPL, no LGPL, aunque sea la librería cliente
license = "GPL-2.0-or-later"
[source] [source]
tarball = "https://download.gnome.org/sources/gdm/48/gdm-48.0.tar.xz" tarball = "https://download.gnome.org/sources/gdm/48/gdm-48.0.tar.xz"
+2
View File
@@ -33,6 +33,8 @@
# arrastra ICalGLib; sin .so real no hay typelib. Ver [[gnome-introspection-dinamica]]. # arrastra ICalGLib; sin .so real no hay typelib. Ver [[gnome-introspection-dinamica]].
name = "libical" name = "libical"
version = "3.0.20" version = "3.0.20"
# licencia: LICENSE del tarball: «distributed under two licenses. You may choose the terms of either: MPL v2.0 or LGPL v2.1». El fichero no dice «or later» en ningún sitio
license = "MPL-2.0 OR LGPL-2.1-only"
[source] [source]
tarball = "https://github.com/libical/libical/releases/download/v3.0.20/libical-3.0.20.tar.gz" tarball = "https://github.com/libical/libical/releases/download/v3.0.20/libical-3.0.20.tar.gz"
+2
View File
@@ -2,6 +2,8 @@
# Boost_INCLUDE_DIR. No compilamos las libs de boost (b2): copiamos el árbol `boost/` a /usr/include. # Boost_INCLUDE_DIR. No compilamos las libs de boost (b2): copiamos el árbol `boost/` a /usr/include.
name = "boost" name = "boost"
version = "1.86.0" version = "1.86.0"
# licencia: LICENSE_1_0.txt en la raíz del tarball pineado: Boost Software License 1.0
license = "BSL-1.0"
[source] [source]
tarball = "https://archives.boost.io/release/1.86.0/source/boost_1_86_0.tar.bz2" tarball = "https://archives.boost.io/release/1.86.0/source/boost_1_86_0.tar.bz2"
+2
View File
@@ -31,6 +31,8 @@
# (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch). # (gmpxx.h que libqalculate exige). La descarga es del mirror GNU (gmplib.org cuelga en TLS con hammer-fetch).
name = "gmp" name = "gmp"
version = "6.3.0" version = "6.3.0"
# licencia: README del tarball pineado — mismo sha256 que recipes/gmp.toml
license = "LGPL-3.0-or-later OR GPL-2.0-or-later"
[source] [source]
tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz" tarball = "https://ftp.gnu.org/gnu/gmp/gmp-6.3.0.tar.xz"
+2
View File
@@ -7,6 +7,8 @@
# lee imágenes vía leptonica, y PNG/JPEG cubre el caso de spectacle (OCR sobre una captura de pantalla). # lee imágenes vía leptonica, y PNG/JPEG cubre el caso de spectacle (OCR sobre una captura de pantalla).
name = "leptonica" name = "leptonica"
version = "1.85.0" version = "1.85.0"
# licencia: leptonica-license.txt del tarball pineado (sha256 verificado al bajarlo): dos condiciones, retener el aviso en fuente y reproducirlo en binario
license = "BSD-2-Clause"
[source] [source]
tarball = "https://github.com/DanBloomberg/leptonica/releases/download/1.85.0/leptonica-1.85.0.tar.gz" tarball = "https://github.com/DanBloomberg/leptonica/releases/download/1.85.0/leptonica-1.85.0.tar.gz"
+2
View File
@@ -4,6 +4,8 @@
# (deuda Capa 0 audio). find_package(Canberra) usa FindCanberra.cmake (pkg-config libcanberra.pc → target). # (deuda Capa 0 audio). find_package(Canberra) usa FindCanberra.cmake (pkg-config libcanberra.pc → target).
name = "libcanberra" name = "libcanberra"
version = "0.30" version = "0.30"
# licencia: el tarball no trae COPYING, trae el texto en LGPL y las cabeceras (src/canberra.h) dicen «either version 2.1 … or (at your option) any later version»
license = "LGPL-2.1-or-later"
[source] [source]
# 0pointer.de (upstream original) murió ~2026-07. Mirror BLFS/OSUOSL = MISMO tarball byte a byte # 0pointer.de (upstream original) murió ~2026-07. Mirror BLFS/OSUOSL = MISMO tarball byte a byte
# (sha256 verificado idéntico, 318960 bytes). Es el archivo canónico de tarballs viejos, muy estable. # (sha256 verificado idéntico, 318960 bytes). Es el archivo canónico de tarballs viejos, muy estable.
+2
View File
@@ -3,6 +3,8 @@
# sha256 del tarball (el wrapper lo calcula), y adaptar build/install del shell de abuild. # sha256 del tarball (el wrapper lo calcula), y adaptar build/install del shell de abuild.
name = "lsof" name = "lsof"
version = "4.99.7" version = "4.99.7"
# licencia: COPYING del tarball pineado: licencia propia de Purdue Research Foundation, sin identificador SPDX. Era uno de los DOS que vetaban las imágenes base y cli (docs/20-catalogo-publicable-y-completa.md)
license = "LicenseRef-lsof"
[source] [source]
tarball = "https://github.com/lsof-org/lsof/archive/4.99.7/lsof-4.99.7.tar.gz" tarball = "https://github.com/lsof-org/lsof/archive/4.99.7/lsof-4.99.7.tar.gz"
+2
View File
@@ -35,6 +35,8 @@
name = "openssh" name = "openssh"
version = "10.3p1" version = "10.3p1"
# licencia: LICENCE del tarball pineado. Es una MEZCLA que el propio fichero enumera —BSD-2/3-Clause, ISC, MIT y dominio público— con el resumen «all components are under a BSD licence, or a licence more free than that». Se entrega el fichero entero en vez de una expresión compuesta: la enumeración de upstream no necesita interpretación nuestra
license = "LicenseRef-openssh"
[source] [source]
tarball = "https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-10.3p1.tar.gz" tarball = "https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-10.3p1.tar.gz"
+2
View File
@@ -4,6 +4,8 @@
# matar-gcc contaba `compiler = "gcc"` y no miraba las fases, así que pigz no figuraba como deuda. # matar-gcc contaba `compiler = "gcc"` y no miraba las fases, así que pigz no figuraba como deuda.
name = "pigz" name = "pigz"
version = "2.8" version = "2.8"
# licencia: el bloque de licencia de pigz.c en el tarball pineado es el texto de la licencia zlib palabra por palabra (Mark Adler)
license = "Zlib"
[source] [source]
tarball = "https://zlib.net/pigz/pigz-2.8.tar.gz" tarball = "https://zlib.net/pigz/pigz-2.8.tar.gz"
sha256 = "eb872b4f0e1f0ebe59c9f7bd8c506c4204893ba6a8492de31df416f0d5170fd0" sha256 = "eb872b4f0e1f0ebe59c9f7bd8c506c4204893ba6a8492de31df416f0d5170fd0"
+2
View File
@@ -28,6 +28,8 @@
# corpus, así que no se abre un skew de versiones entre el mundo estático y el dinámico. # corpus, así que no se abre un skew de versiones entre el mundo estático y el dinámico.
name = "sqlite-shared" name = "sqlite-shared"
version = "3.46.1" version = "3.46.1"
# licencia: MISMO sha256 de tarball que recipes/sqlite.toml, que ya declara `blessing` (la bendición del dominio público de SQLite)
license = "blessing"
[source] [source]
tarball = "https://sqlite.org/2024/sqlite-autoconf-3460100.tar.gz" tarball = "https://sqlite.org/2024/sqlite-autoconf-3460100.tar.gz"
+2
View File
@@ -11,6 +11,8 @@
# de `posixtz` (no lo construimos). # de `posixtz` (no lo construimos).
name = "tzdata" name = "tzdata"
version = "2026b" version = "2026b"
# licencia: LICENSE del commit pineado: «all files in the tz code and data … are in the public domain», salvo date.c/newstrftime.3/strftime.c, que son BSD-3-Clause y esta receta NO instala — sólo compila zic y deja /usr/share/zoneinfo. Era el otro de los DOS que vetaban base y cli
license = "LicenseRef-tz-public-domain"
[source] [source]
repo = "https://github.com/eggert/tz" repo = "https://github.com/eggert/tz"
+2
View File
@@ -18,6 +18,8 @@
# vulkan-loader. Tests y el módulo C++20 (Vulkan-Hpp) apagados. # vulkan-loader. Tests y el módulo C++20 (Vulkan-Hpp) apagados.
name = "vulkan-headers" name = "vulkan-headers"
version = "1.4.350.1" version = "1.4.350.1"
# licencia: LICENSE.md del tarball pineado: «SPDX-License-Identifier: Apache-2.0 OR MIT»
license = "Apache-2.0 OR MIT"
[source] [source]
tarball = "https://github.com/KhronosGroup/Vulkan-Headers/archive/refs/tags/vulkan-sdk-1.4.350.1.tar.gz" tarball = "https://github.com/KhronosGroup/Vulkan-Headers/archive/refs/tags/vulkan-sdk-1.4.350.1.tar.gz"
+2
View File
@@ -4,6 +4,8 @@
# - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren. # - las deps van con su nombre NIX; remapealas a las recetas del corpus si difieren.
name = "waybackurls" name = "waybackurls"
version = "0.1.0" version = "0.1.0"
# licencia: ⚠ EL REPO NO DECLARA LICENCIA en el commit pineado: la raíz del árbol es .gitignore, README.mkd, go.mod, main.go y script/ — sin LICENSE ni COPYING, y el README no la menciona. Sin concesión expresa, el derecho de autor por defecto es «todos los derechos reservados» ⇒ NO se puede redistribuir en una imagen. Se declara para que el veto lo VEA en vez de que el campo vacío se lea como «falta poblarlo»
license = "LicenseRef-sin-licencia-declarada"
[source] [source]
repo = "https://github.com/tomnomnom/waybackurls" repo = "https://github.com/tomnomnom/waybackurls"
+2
View File
@@ -5,6 +5,8 @@
# liblzma.so con autotools --enable-shared (PIC nativo). Nombre distinto para no colisionar con el canónico. # liblzma.so con autotools --enable-shared (PIC nativo). Nombre distinto para no colisionar con el canónico.
name = "xz-shared" name = "xz-shared"
version = "5.8.3" version = "5.8.3"
# licencia: MISMO sha256 de tarball que recipes/xz.toml, que ya declara 0BSD; el COPYING confirma que liblzma —lo que esta variante publica— es 0BSD (lo GPLv2+ son los scripts xzgrep/xzdiff, que no se instalan)
license = "0BSD"
[source] [source]
tarball = "https://github.com/tukaani-project/xz/releases/download/v5.8.3/xz-5.8.3.tar.xz" tarball = "https://github.com/tukaani-project/xz/releases/download/v5.8.3/xz-5.8.3.tar.xz"
+33 -4
View File
@@ -40,11 +40,40 @@ elif [ ! -t 0 ]; then cat > /tmp/.lic-pkgs
else echo "!! sin lista de paquetes (pasala por argumento o stdin)"; exit 2; fi else echo "!! sin lista de paquetes (pasala por argumento o stdin)"; exit 2; fi
sort -u /tmp/.lic-pkgs | grep -v '^$' > /tmp/.lic-pkgs2 && mv /tmp/.lic-pkgs2 /tmp/.lic-pkgs sort -u /tmp/.lic-pkgs | grep -v '^$' > /tmp/.lic-pkgs2 && mv /tmp/.lic-pkgs2 /tmp/.lic-pkgs
# ⚠ SE RESUELVE POR EL CAMPO `name`, NO POR EL NOMBRE DE FICHERO (2026-09-09).
# Antes esto hacía `ls recipes/$1.toml` y nada más, y el paquete se llama por su campo `name`, que
# en 34 recetas del corpus NO coincide con el fichero (recipes/nu.toml → `nushell`, dust.toml →
# `du-dust`, incoming-kde/qtbase.toml → `qt6-qtbase`…). Medido: **14 paquetes que SÍ declaran
# licencia salían como «licencia desconocida»** y el guardián vetaba una imagen perfectamente
# publicable. Un falso veto se nota; el hermano silencioso no: si el fichero <pkg>.toml existe pero
# pertenece a OTRO paquete, la versión vieja reportaba la licencia EQUIVOCADA sin decir nada. Hoy no
# pasa (medido: 0 casos), pero el índice por `name` lo hace imposible en vez de improbable.
# El índice se arma UNA vez: 1128 recetas, no una por paquete.
IDX=$(mktemp)
for f in recipes/*.toml recipes/incoming-*/*.toml; do
[ -f "$f" ] || continue
awk -F'"' -v ARCH="$f" -v BASE="$(basename "$f" .toml)" '
/^\[/{exit}
/^[[:space:]]*name[[:space:]]*=/ {if(!n) n=$2}
/^[[:space:]]*license[[:space:]]*=/{if(!l) l=$2}
END{if(n) printf "%s\t%s\t%s\t%s\n", n, l, ARCH, BASE}' "$f"
done > "$IDX"
trap 'rm -f "$IDX"' EXIT
# Precedencia: la receta canónica (recipes/*.toml) antes que una cola incoming-*, igual que antes.
# Comprobado que no cambia nada hoy: de los 34 nombres duplicados, CERO declaran licencias distintas.
# Se busca por `name` y, si no aparece, por nombre de FICHERO: los dos llamadores existen y usan
# claves distintas — el grafo de estado nombra sus nodos por el fichero (`dust`) y el artefacto del
# store por el campo `name` (`du-dust`). Resolver sólo por uno rompe al otro; medido en los dos
# sentidos sobre el perfil base+cli y sobre el corpus entero.
licencia_de_receta() { licencia_de_receta() {
f=$(ls "recipes/$1.toml" 2>/dev/null | head -1) lic=$(awk -F'\t' -v p="$1" '
[ -z "$f" ] && f=$(ls recipes/incoming-*/"$1.toml" 2>/dev/null | head -1) $1==p && $2!="" {if ($3 !~ /^recipes\/incoming-/) {print $2; exit} else if (!c) c=$2}
[ -z "$f" ] && return 1 END{if (c) print c}' "$IDX")
awk -F'"' '/^\[/{exit} /^[[:space:]]*license[[:space:]]*=/{print $2; exit}' "$f" [ -n "$lic" ] || lic=$(awk -F'\t' -v p="$1" '
$4==p && $2!="" {if ($3 !~ /^recipes\/incoming-/) {print $2; exit} else if (!c) c=$2}
END{if (c) print c}' "$IDX")
[ -n "$lic" ] || return 1
printf '%s\n' "$lic"
} }
DESTDIR="$PREFIX/usr/share/licenses" DESTDIR="$PREFIX/usr/share/licenses"