diff --git a/.github/scripts/build-codex-package-archive.sh b/.github/scripts/build-codex-package-archive.sh index a0ed4a5f34..86eb9d1fc6 100644 --- a/.github/scripts/build-codex-package-archive.sh +++ b/.github/scripts/build-codex-package-archive.sh @@ -15,6 +15,7 @@ Usage: build-codex-package-archive.sh \ [--zsh-manifest ] \ [--codex-command-runner-bin ] \ [--codex-windows-sandbox-setup-bin ] \ + [--voice-signed-dir --release-version ] \ [--target-suffixed-entrypoint] EOF } @@ -29,6 +30,8 @@ bwrap_bin_provided="false" code_mode_host_bin_provided="false" command_runner_bin_provided="false" sandbox_setup_bin_provided="false" +voice_signed_dir="" +release_version="" while [[ $# -gt 0 ]]; do case "$1" in @@ -90,6 +93,14 @@ while [[ $# -gt 0 ]]; do target_suffixed_entrypoint="true" shift ;; + --voice-signed-dir) + voice_signed_dir="${2:?--voice-signed-dir requires a value}" + shift 2 + ;; + --release-version) + release_version="${2:?--release-version requires a value}" + shift 2 + ;; -h|--help) usage exit 0 @@ -106,6 +117,10 @@ if [[ -z "$target" || -z "$bundle" || -z "$entrypoint_dir" || -z "$archive_dir" usage >&2 exit 1 fi +if [[ ( -n "$voice_signed_dir" || -n "$release_version" ) && ( -z "$voice_signed_dir" || -z "$release_version" || "$bundle" != "primary" || "$target" != *-apple-darwin ) ]]; then + echo "Signed voice resources require a primary macOS release package version" >&2 + exit 1 +fi case "$bundle" in primary) @@ -188,12 +203,36 @@ python_args=( --entrypoint-bin "${entrypoint_dir%/}/${entrypoint_name}${exe_suffix}" --cargo-profile release --package-dir "$package_dir" - --archive-output "$gzip_archive_path" - --archive-output "$zstd_archive_path" ) +if [[ -z "$voice_signed_dir" ]]; then + python_args+=(--archive-output "$gzip_archive_path" --archive-output "$zstd_archive_path") +fi if ((${#resource_args[@]} > 0)); then python_args+=("${resource_args[@]}") fi python_args+=(--force) "$python_bin" "${python_args[@]}" + +if [[ -n "$voice_signed_dir" ]]; then + voice_package="${RUNNER_TEMP:-/tmp}/${archive_stem}-voice-${target}" + rm -rf "$voice_package" + "$python_bin" "${repo_root}/third_party/voice/assemble_package.py" \ + --package "$package_dir" \ + --helper "${voice_signed_dir%/}/codex-voice-host" \ + --runtime "${voice_signed_dir%/}/runtime" \ + --voice-target "$target" \ + --build-commit "$(git -C "$repo_root" rev-parse HEAD)" \ + --release-version "$release_version" \ + --output "$voice_package" + PYTHONPATH="${repo_root}/public/scripts" "$python_bin" - \ + "$voice_package" "$gzip_archive_path" "$zstd_archive_path" <<'PY' +import sys +from pathlib import Path +from codex_package.archive import write_archive + +package = Path(sys.argv[1]) +for archive in sys.argv[2:]: + write_archive(package, Path(archive), force=True) +PY +fi diff --git a/.github/scripts/macos-signing/codex-voice-host.entitlements.plist b/.github/scripts/macos-signing/codex-voice-host.entitlements.plist new file mode 100644 index 0000000000..b572d9c04e --- /dev/null +++ b/.github/scripts/macos-signing/codex-voice-host.entitlements.plist @@ -0,0 +1,8 @@ + + + + + com.apple.security.device.audio-input + + + diff --git a/.github/workflows/rust-release.yml b/.github/workflows/rust-release.yml index a3dd6c834b..7bc27ec0cb 100644 --- a/.github/workflows/rust-release.yml +++ b/.github/workflows/rust-release.yml @@ -480,8 +480,61 @@ jobs: path: | codex-rs/dist/${{ matrix.target }}/* + build-macos-voice: + needs: tag-check + name: Build voice runtime - ${{ matrix.target }} + runs-on: ${{ matrix.runner }} + timeout-minutes: 120 + permissions: + contents: read + strategy: + fail-fast: false + matrix: + include: + - target: aarch64-apple-darwin + runner: macos-15 + prefix: macos_aarch64 + - target: x86_64-apple-darwin + runner: macos-15-intel + prefix: macos_x86_64 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + with: + python-version: "3.12" + - uses: bazel-contrib/setup-bazel@c5acdfb288317d0b5c0bbd7a396a3dc868bb0f86 # 0.19.0 + with: + bazelisk-version: 1.28.1 + - name: Build matching helper and native runtime + shell: bash + env: + TARGET: ${{ matrix.target }} + PREFIX: ${{ matrix.prefix }} + run: | + set -euo pipefail + bazel build //codex-rs/voice-host:codex-voice-host //third_party/voice:native_runtime + runtime="bazel-bin/third_party/voice/native_runtime_${PREFIX}" + PYTHONPATH=third_party/voice python3 - "$runtime" "$TARGET" <<'PY' + from pathlib import Path + import sys + from package_runtime import runtime_files + runtime_files(Path(sys.argv[1]), sys.argv[2]) + PY + mkdir -p "voice-unsigned/${TARGET}" + cp -R "$runtime" "voice-unsigned/${TARGET}/runtime" + cp bazel-bin/codex-rs/voice-host/codex-voice-host "voice-unsigned/${TARGET}/codex-voice-host" + tar -C "voice-unsigned/${TARGET}" -czf "voice-unsigned-${TARGET}.tar.gz" runtime codex-voice-host + - uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 + with: + name: voice-${{ matrix.target }}-unsigned + path: voice-unsigned-${{ matrix.target }}.tar.gz + if-no-files-found: error + sign-macos-binaries: - needs: build + needs: [build, build-macos-voice] + if: ${{ always() && needs.build.result == 'success' && needs.build-macos-voice.result == 'success' }} name: Sign macOS binaries - ${{ matrix.target }} - ${{ matrix.bundle }} runs-on: ubuntu-latest timeout-minutes: 45 @@ -524,6 +577,13 @@ jobs: name: ${{ matrix.artifact_name }}-unsigned path: ${{ runner.temp }}/unsigned-macos + - name: Download unsigned voice runtime + if: ${{ matrix.bundle == 'primary' }} + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: voice-${{ matrix.target }}-unsigned + path: ${{ runner.temp }}/unsigned-voice + - name: Set up AKV PKCS11 macOS signing uses: ./.github/actions/setup-akv-pkcs11-codesigning with: @@ -647,6 +707,57 @@ jobs: --report-dir "$report_dir" done + - name: Sign and notarize voice runtime + if: ${{ matrix.bundle == 'primary' }} + shell: bash + env: + TARGET: ${{ matrix.target }} + APPLE_NOTARIZATION_AKV_KEY_NAME: ${{ secrets.AKV_NOTARIZATION_KEY_NAME }} + APPLE_NOTARIZATION_AKV_KEY_VERSION: ${{ secrets.AKV_NOTARIZATION_KEY_VERSION }} + run: | + set -euo pipefail + unsigned="${RUNNER_TEMP}/unsigned-voice/extracted" + signed="${GITHUB_WORKSPACE}/signed-voice/${TARGET}" + mkdir -p "$unsigned" "$signed" + tar -xzf "${RUNNER_TEMP}/unsigned-voice/voice-unsigned-${TARGET}.tar.gz" -C "$unsigned" + python3 third_party/voice/release_runtime.py stage \ + --target "$TARGET" --source "$unsigned/runtime" --output "$signed/runtime" + cp "$unsigned/codex-voice-host" "$signed/codex-voice-host" + chmod 0755 "$signed/codex-voice-host" + + while IFS= read -r -d '' library; do + name="$(basename "$library")" + .github/scripts/macos-signing/sign_macos_code.sh \ + --target "$library" --identity unused --deep false \ + --identifier "com.openai.codex.voice.${name}" \ + --options runtime --timestamp true + done < <(find "$signed/runtime" -name '*.dylib' -type f -print0) + .github/scripts/macos-signing/sign_macos_code.sh \ + --target "$signed/codex-voice-host" --identity unused --deep false \ + --identifier com.openai.codex.voice-host --options runtime --timestamp true \ + --entitlements .github/scripts/macos-signing/codex-voice-host.entitlements.plist + + # Notarize the actual signed closure together, then hash those bytes. + (cd "$signed" && zip -qr "${RUNNER_TEMP}/voice-${TARGET}.zip" runtime codex-voice-host) + report_dir="${GITHUB_WORKSPACE}/macos-binary-signing-verification/${TARGET}/voice" + mkdir -p "$report_dir" + python3 .github/scripts/macos-signing/notarize_with_akv.py \ + --file "${RUNNER_TEMP}/voice-${TARGET}.zip" \ + --report-log "${report_dir}/notarization.json" \ + --max-wait-seconds 600 + python3 third_party/voice/release_runtime.py seal \ + --target "$TARGET" --output "$signed/runtime" + tar -C "$signed" -czf "${GITHUB_WORKSPACE}/signed-voice-${TARGET}.tar.gz" \ + runtime codex-voice-host + + - name: Upload signed voice runtime + if: ${{ matrix.bundle == 'primary' }} + uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 + with: + name: voice-${{ matrix.target }}-signed + path: signed-voice-${{ matrix.target }}.tar.gz + if-no-files-found: error + - name: Upload signed macOS binaries uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: @@ -723,6 +834,41 @@ jobs: name: ${{ matrix.target }}-signed-resources path: codex-rs/signed-resources/${{ matrix.target }} + - name: Download signed voice runtime + if: ${{ matrix.bundle == 'primary' }} + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: voice-${{ matrix.target }}-signed + path: ${{ runner.temp }}/signed-voice + + - name: Verify signed voice runtime + if: ${{ matrix.bundle == 'primary' }} + shell: bash + env: + TARGET: ${{ matrix.target }} + run: | + set -euo pipefail + root="${RUNNER_TEMP}/signed-voice/${TARGET}" + mkdir -p "$root" + tar -xzf "${RUNNER_TEMP}/signed-voice/signed-voice-${TARGET}.tar.gz" -C "$root" + case "$TARGET" in + aarch64-apple-darwin) arch=arm64 ;; + x86_64-apple-darwin) arch=x86_64 ;; + *) exit 1 ;; + esac + PYTHONPATH="${GITHUB_WORKSPACE}/third_party/voice" python3 - "$root/runtime" "$TARGET" <<'PY' + from pathlib import Path + import sys + from package_runtime import runtime_files + runtime_files(Path(sys.argv[1]), sys.argv[2], public_release=True) + PY + while IFS= read -r -d '' binary; do + lipo "$binary" -verify_arch "$arch" + codesign --verify --strict --verbose=2 "$binary" + done < <(find "$root/runtime" -name '*.dylib' -type f -print0) + lipo "$root/codex-voice-host" -verify_arch "$arch" + codesign --verify --strict --verbose=2 "$root/codex-voice-host" + - name: Verify signed macOS binaries shell: bash run: | @@ -739,6 +885,43 @@ jobs: codesign --verify --strict --verbose=2 "$resource_path" done + - name: Stage macOS artifacts + shell: bash + run: | + set -euo pipefail + dest="dist/${{ matrix.target }}" + mkdir -p "$dest" + + for binary in ${{ matrix.binaries }}; do + # Both variants package the host, but only the primary bundle publishes + # standalone binary archives to avoid duplicate release asset names. + if [[ "${{ matrix.bundle }}" == "app-server" && "$binary" == "codex-code-mode-host" ]]; then + continue + fi + cp "target/${{ matrix.target }}/release/${binary}" "$dest/${binary}-${{ matrix.target }}" + done + + - name: Build Codex package archive + shell: bash + env: + TARGET: ${{ matrix.target }} + BUNDLE: ${{ matrix.bundle }} + run: | + set -euo pipefail + voice_args=() + if [[ "$BUNDLE" == "primary" ]]; then + voice_args+=(--voice-signed-dir "${RUNNER_TEMP}/signed-voice/${TARGET}") + voice_args+=(--release-version "${GITHUB_REF_NAME#rust-v}") + fi + bash "${GITHUB_WORKSPACE}/.github/scripts/build-codex-package-archive.sh" \ + --target "$TARGET" \ + --bundle "$BUNDLE" \ + --entrypoint-dir "target/${TARGET}/release" \ + --archive-dir "dist/${TARGET}" \ + --rg-bin "signed-resources/${TARGET}/rg" \ + --zsh-bin "signed-resources/${TARGET}/zsh" \ + "${voice_args[@]}" + - name: Build unsigned macOS DMG if: ${{ matrix.build_dmg == 'true' }} shell: bash @@ -763,6 +946,15 @@ jobs: ditto "$binary_path" "${dmg_root}/${binary}" done + if [[ "${{ matrix.bundle }}" == "primary" ]]; then + # Keep the root-level invocation, but resolve it into the canonical + # package layout so InstallContext finds its adjacent voice runtime. + package="${RUNNER_TEMP}/codex-package-voice-${target}" + ditto "$package" "$dmg_root" + rm "${dmg_root}/codex" + ln -s bin/codex "${dmg_root}/codex" + fi + rm -f "$dmg_path" hdiutil create \ -volname "$volname" \ @@ -784,37 +976,6 @@ jobs: path: codex-rs/target/${{ matrix.target }}/release/codex-${{ matrix.target }}.dmg if-no-files-found: error - - name: Stage macOS artifacts - shell: bash - run: | - set -euo pipefail - dest="dist/${{ matrix.target }}" - mkdir -p "$dest" - - for binary in ${{ matrix.binaries }}; do - # Both variants package the host, but only the primary bundle publishes - # standalone binary archives to avoid duplicate release asset names. - if [[ "${{ matrix.bundle }}" == "app-server" && "$binary" == "codex-code-mode-host" ]]; then - continue - fi - cp "target/${{ matrix.target }}/release/${binary}" "$dest/${binary}-${{ matrix.target }}" - done - - - name: Build Codex package archive - shell: bash - env: - TARGET: ${{ matrix.target }} - BUNDLE: ${{ matrix.bundle }} - run: | - set -euo pipefail - bash "${GITHUB_WORKSPACE}/.github/scripts/build-codex-package-archive.sh" \ - --target "$TARGET" \ - --bundle "$BUNDLE" \ - --entrypoint-dir "target/${TARGET}/release" \ - --archive-dir "dist/${TARGET}" \ - --rg-bin "signed-resources/${TARGET}/rg" \ - --zsh-bin "signed-resources/${TARGET}/zsh" - - name: Build Python runtime wheel if: ${{ matrix.bundle == 'primary' }} shell: bash @@ -837,13 +998,32 @@ jobs: python3 -m venv "${RUNNER_TEMP}/python-runtime-build-venv" "${RUNNER_TEMP}/python-runtime-build-venv/bin/python" -m pip install build + # The wheel keeps its macOS 10.9/11 tags. The native voice build + # currently targets macOS 14, so keep it in the release archives and + # DMG but leave this older-OS-compatible wheel unchanged. + wheel_archives="${RUNNER_TEMP}/voice-free-wheel/${{ matrix.target }}" + bash "${GITHUB_WORKSPACE}/.github/scripts/build-codex-package-archive.sh" \ + --target "${{ matrix.target }}" \ + --bundle primary \ + --entrypoint-dir "target/${{ matrix.target }}/release" \ + --archive-dir "$wheel_archives" \ + --rg-bin "signed-resources/${{ matrix.target }}/rg" \ + --zsh-bin "signed-resources/${{ matrix.target }}/zsh" + wheel_archive="${wheel_archives}/codex-package-${{ matrix.target }}.tar.gz" + python3 - "$wheel_archive" <<'PY' + import sys + import tarfile + with tarfile.open(sys.argv[1]) as archive: + assert not any("codex-resources/voice/" in item.name for item in archive) + PY + stage_dir="${RUNNER_TEMP}/openai-codex-cli-bin-${{ matrix.target }}" wheel_dir="${GITHUB_WORKSPACE}/python-runtime-dist/${{ matrix.target }}" python3 \ "${GITHUB_WORKSPACE}/sdk/python/scripts/update_sdk_artifacts.py" \ stage-runtime \ "$stage_dir" \ - "dist/${{ matrix.target }}/codex-package-${{ matrix.target }}.tar.gz" \ + "$wheel_archive" \ --codex-version "${GITHUB_REF_NAME}" \ --platform-tag "$platform_tag" "${RUNNER_TEMP}/python-runtime-build-venv/bin/python" -m build --wheel --outdir "$wheel_dir" "$stage_dir" @@ -1135,6 +1315,33 @@ jobs: rm -f "$entitlements" done + if [[ "${{ matrix.bundle }}" == "primary" ]]; then + voice="${package_dir}/codex-resources/voice" + [[ -f "${voice}/lib/libgstreamer-1.0.0.dylib" ]] + export VOICE_BUILD_COMMIT="$(git rev-parse HEAD)" + PYTHONPATH="${GITHUB_WORKSPACE}/third_party/voice" python3 - "$voice" "$target" "$package_dir" <<'PY' + import json + import sys + from pathlib import Path + from package_runtime import runtime_files + from runtime import digest + + voice, target, package = map(Path, sys.argv[1:]) + runtime_files(voice, str(target), public_release=True) + manifest = json.loads((voice / "manifest.json").read_text()) + assert manifest["buildCommit"] == __import__("os").environ["VOICE_BUILD_COMMIT"] + for relative, expected in manifest["sha256"].items(): + assert digest(package / relative) == expected, relative + PY + helper="${voice}/bin/codex-voice-host" + [[ "$("$helper" --build-commit)" == "$VOICE_BUILD_COMMIT" ]] + while IFS= read -r -d '' library; do + lipo "$library" -verify_arch "$expected_arch" + codesign --verify --strict --verbose=2 "$library" + done < <(find "$voice" -name '*.dylib' -type f -print0) + verify_signed_binary "$helper" "codex-voice-host" + fi + if [[ "${{ matrix.verify_dmg }}" != "true" ]]; then exit 0 fi @@ -1162,6 +1369,15 @@ jobs: verify_signed_binary "${mount_dir}/${binary}" "$binary" done + if [[ "${{ matrix.bundle }}" == "primary" ]]; then + [[ "$(readlink "${mount_dir}/codex")" == "bin/codex" ]] + cmp "${mount_dir}/codex-package.json" "${package_dir}/codex-package.json" + cmp "${mount_dir}/codex-resources/voice/manifest.json" \ + "${package_dir}/codex-resources/voice/manifest.json" + cmp "${mount_dir}/codex-resources/voice/bin/codex-voice-host" \ + "${package_dir}/codex-resources/voice/bin/codex-voice-host" + fi + cleanup_mount trap - EXIT cp "$dmg_path" "dist/${target}/codex-${target}.dmg" diff --git a/third_party/voice/NOTICE.md b/third_party/voice/NOTICE.md new file mode 100644 index 0000000000..b6557717f7 --- /dev/null +++ b/third_party/voice/NOTICE.md @@ -0,0 +1,17 @@ +# Native voice libraries in Codex releases + +The macOS Codex release package includes dynamically linked GStreamer and GLib +libraries and selected plugins, plus their native library dependencies. These +components have their own copyrights and licenses. Their notices accompany +this file in `licenses/`: `LGPL-2.1.txt` for GStreamer and GLib, +`proxy-libintl.txt` for libintl, `libffi.txt`, `PCRE2.md` and `sljit.txt` +for PCRE2, `Opus.txt`, and `zlib.txt`. GVDB is included with GLib under LGPL. + +The exact upstream versions, source archive URLs and SHA-256 digests are in +`sources.json` alongside this notice. The corresponding build, runtime +projection and package scripts are in the public Codex source tree under +`third_party/voice/`. The source commit for this package is recorded in +`manifest.json`. The native libraries remain separate dynamic libraries in +`lib/` and `plugins/`; replacing them requires compatible binaries and valid +macOS code signatures. Build tools listed in `sources.json` are build inputs, +not bundled runtime libraries. diff --git a/third_party/voice/assemble_package.py b/third_party/voice/assemble_package.py index c54c1aa4a3..af6cc8ca00 100644 --- a/third_party/voice/assemble_package.py +++ b/third_party/voice/assemble_package.py @@ -22,6 +22,7 @@ def assemble( output: Path, *, runtime: Path, + release_version: str | None = None, ): package, helper = package.resolve(strict=True), helper.resolve(strict=True) output = output.absolute() @@ -60,8 +61,17 @@ def assemble( } if any(metadata.get(key) != value for key, value in expected.items()): raise ValueError("input is not a canonical Codex package") - if not metadata["version"].endswith(f"+{commit}"): - raise ValueError("package version does not match the declared build") + if release_version is None: + if not metadata["version"].endswith(f"+{commit}"): + raise ValueError("package version does not match the declared build") + elif ( + not re.fullmatch( + r"[0-9]+\.[0-9]+\.[0-9]+(?:-alpha(?:\.[0-9]+){0,2}|-beta(?:\.[0-9]+)?)?", + release_version, + ) + or metadata["version"] != release_version + ): + raise ValueError("package version does not match the release") if (package / "codex-resources/voice").exists(): raise ValueError("input already contains voice resources") for path in package.rglob("*"): @@ -79,7 +89,13 @@ def assemble( for parent in output.resolve().parents ): raise ValueError("output must be outside the runtime input") - inputs = runtime_files(runtime, voice_target) + inputs = runtime_files( + runtime, voice_target, public_release=release_version is not None + ) + if release_version is not None: + receipt = json.loads((runtime / "runtime.json").read_text(encoding="utf-8")) + if receipt["sourceCommit"] != commit: + raise ValueError("release runtime source does not match the app build") output.mkdir() # Exclusive creation: never clean or overwrite a pre-existing output. try: shutil.copytree(package, output, dirs_exist_ok=True) @@ -93,6 +109,23 @@ def assemble( shutil.copy2(runtime / relative, copied) if digest(copied) != expected_digest: raise ValueError("runtime file changed during copying") + if release_version is not None: + source_dir = Path(__file__).resolve().parent + for relative in ( + "NOTICE.md", + "sources.json", + "licenses/LGPL-2.1.txt", + "licenses/Opus.txt", + "licenses/PCRE2.md", + "licenses/libffi.txt", + "licenses/proxy-libintl.txt", + "licenses/sljit.txt", + "licenses/zlib.txt", + ): + destination_file = destination.parent.parent / relative + destination_file.parent.mkdir(parents=True, exist_ok=True) + shutil.copy2(source_dir / relative, destination_file) + inputs[relative] = digest(destination_file) digests = {} for relative in (entrypoint, relative_helper): with (output / relative).open("rb") as source: @@ -122,12 +155,15 @@ if __name__ == "__main__": parser.add_argument("--helper", type=Path, required=True) parser.add_argument("--voice-target", required=True) parser.add_argument("--build-commit", required=True) + parser.add_argument( + "--release-version", help="exact version of a public release package" + ) parser.add_argument("--output", type=Path, required=True) parser.add_argument( "--runtime", type=Path, required=True, - help="prepared development runtime required by the helper", + help="prepared runtime required by the helper", ) args = parser.parse_args() assemble( @@ -137,4 +173,5 @@ if __name__ == "__main__": args.build_commit, args.output, runtime=args.runtime, + release_version=args.release_version, ) diff --git a/third_party/voice/licenses/LGPL-2.1.txt b/third_party/voice/licenses/LGPL-2.1.txt new file mode 100644 index 0000000000..efce2a87c3 --- /dev/null +++ b/third_party/voice/licenses/LGPL-2.1.txt @@ -0,0 +1,503 @@ + GNU LESSER GENERAL PUBLIC LICENSE + Version 2.1, February 1999 + + Copyright (C) 1991, 1999 Free Software Foundation, Inc. + 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + +[This is the first released version of the Lesser GPL. It also counts + as the successor of the GNU Library Public License, version 2, hence + the version number 2.1.] + + Preamble + + The licenses for most software are designed to take away your +freedom to share and change it. By contrast, the GNU General Public +Licenses are intended to guarantee your freedom to share and change +free software--to make sure the software is free for all its users. + + This license, the Lesser General Public License, applies to some +specially designated software packages--typically libraries--of the +Free Software Foundation and other authors who decide to use it. You +can use it too, but we suggest you first think carefully about whether +this license or the ordinary General Public License is the better +strategy to use in any particular case, based on the explanations below. + + When we speak of free software, we are referring to freedom of use, +not price. Our General Public Licenses are designed to make sure that +you have the freedom to distribute copies of free software (and charge +for this service if you wish); that you receive source code or can get +it if you want it; that you can change the software and use pieces of +it in new free programs; and that you are informed that you can do +these things. + + To protect your rights, we need to make restrictions that forbid +distributors to deny you these rights or to ask you to surrender these +rights. These restrictions translate to certain responsibilities for +you if you distribute copies of the library or if you modify it. + + For example, if you distribute copies of the library, whether gratis +or for a fee, you must give the recipients all the rights that we gave +you. You must make sure that they, too, receive or can get the source +code. If you link other code with the library, you must provide +complete object files to the recipients, so that they can relink them +with the library after making changes to the library and recompiling +it. And you must show them these terms so they know their rights. + + We protect your rights with a two-step method: (1) we copyright the +library, and (2) we offer you this license, which gives you legal +permission to copy, distribute and/or modify the library. + + To protect each distributor, we want to make it very clear that +there is no warranty for the free library. Also, if the library is +modified by someone else and passed on, the recipients should know +that what they have is not the original version, so that the original +author's reputation will not be affected by problems that might be +introduced by others. + + Finally, software patents pose a constant threat to the existence of +any free program. We wish to make sure that a company cannot +effectively restrict the users of a free program by obtaining a +restrictive license from a patent holder. Therefore, we insist that +any patent license obtained for a version of the library must be +consistent with the full freedom of use specified in this license. + + Most GNU software, including some libraries, is covered by the +ordinary GNU General Public License. This license, the GNU Lesser +General Public License, applies to certain designated libraries, and +is quite different from the ordinary General Public License. We use +this license for certain libraries in order to permit linking those +libraries into non-free programs. + + When a program is linked with a library, whether statically or using +a shared library, the combination of the two is legally speaking a +combined work, a derivative of the original library. The ordinary +General Public License therefore permits such linking only if the +entire combination fits its criteria of freedom. The Lesser General +Public License permits more lax criteria for linking other code with +the library. + + We call this license the "Lesser" General Public License because it +does Less to protect the user's freedom than the ordinary General +Public License. It also provides other free software developers Less +of an advantage over competing non-free programs. These disadvantages +are the reason we use the ordinary General Public License for many +libraries. However, the Lesser license provides advantages in certain +special circumstances. + + For example, on rare occasions, there may be a special need to +encourage the widest possible use of a certain library, so that it becomes +a de-facto standard. To achieve this, non-free programs must be +allowed to use the library. A more frequent case is that a free +library does the same job as widely used non-free libraries. In this +case, there is little to gain by limiting the free library to free +software only, so we use the Lesser General Public License. + + In other cases, permission to use a particular library in non-free +programs enables a greater number of people to use a large body of +free software. For example, permission to use the GNU C Library in +non-free programs enables many more people to use the whole GNU +operating system, as well as its variant, the GNU/Linux operating +system. + + Although the Lesser General Public License is Less protective of the +users' freedom, it does ensure that the user of a program that is +linked with the Library has the freedom and the wherewithal to run +that program using a modified version of the Library. + + The precise terms and conditions for copying, distribution and +modification follow. Pay close attention to the difference between a +"work based on the library" and a "work that uses the library". The +former contains code derived from the library, whereas the latter must +be combined with the library in order to run. + + GNU LESSER GENERAL PUBLIC LICENSE + TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION + + 0. This License Agreement applies to any software library or other +program which contains a notice placed by the copyright holder or +other authorized party saying it may be distributed under the terms of +this Lesser General Public License (also called "this License"). +Each licensee is addressed as "you". + + A "library" means a collection of software functions and/or data +prepared so as to be conveniently linked with application programs +(which use some of those functions and data) to form executables. + + The "Library", below, refers to any such software library or work +which has been distributed under these terms. A "work based on the +Library" means either the Library or any derivative work under +copyright law: that is to say, a work containing the Library or a +portion of it, either verbatim or with modifications and/or translated +straightforwardly into another language. (Hereinafter, translation is +included without limitation in the term "modification".) + + "Source code" for a work means the preferred form of the work for +making modifications to it. For a library, complete source code means +all the source code for all modules it contains, plus any associated +interface definition files, plus the scripts used to control compilation +and installation of the library. + + Activities other than copying, distribution and modification are not +covered by this License; they are outside its scope. The act of +running a program using the Library is not restricted, and output from +such a program is covered only if its contents constitute a work based +on the Library (independent of the use of the Library in a tool for +writing it). Whether that is true depends on what the Library does +and what the program that uses the Library does. + + 1. You may copy and distribute verbatim copies of the Library's +complete source code as you receive it, in any medium, provided that +you conspicuously and appropriately publish on each copy an +appropriate copyright notice and disclaimer of warranty; keep intact +all the notices that refer to this License and to the absence of any +warranty; and distribute a copy of this License along with the +Library. + + You may charge a fee for the physical act of transferring a copy, +and you may at your option offer warranty protection in exchange for a +fee. + + 2. You may modify your copy or copies of the Library or any portion +of it, thus forming a work based on the Library, and copy and +distribute such modifications or work under the terms of Section 1 +above, provided that you also meet all of these conditions: + + a) The modified work must itself be a software library. + + b) You must cause the files modified to carry prominent notices + stating that you changed the files and the date of any change. + + c) You must cause the whole of the work to be licensed at no + charge to all third parties under the terms of this License. + + d) If a facility in the modified Library refers to a function or a + table of data to be supplied by an application program that uses + the facility, other than as an argument passed when the facility + is invoked, then you must make a good faith effort to ensure that, + in the event an application does not supply such function or + table, the facility still operates, and performs whatever part of + its purpose remains meaningful. + + (For example, a function in a library to compute square roots has + a purpose that is entirely well-defined independent of the + application. Therefore, Subsection 2d requires that any + application-supplied function or table used by this function must + be optional: if the application does not supply it, the square + root function must still compute square roots.) + +These requirements apply to the modified work as a whole. If +identifiable sections of that work are not derived from the Library, +and can be reasonably considered independent and separate works in +themselves, then this License, and its terms, do not apply to those +sections when you distribute them as separate works. But when you +distribute the same sections as part of a whole which is a work based +on the Library, the distribution of the whole must be on the terms of +this License, whose permissions for other licensees extend to the +entire whole, and thus to each and every part regardless of who wrote +it. + +Thus, it is not the intent of this section to claim rights or contest +your rights to work written entirely by you; rather, the intent is to +exercise the right to control the distribution of derivative or +collective works based on the Library. + +In addition, mere aggregation of another work not based on the Library +with the Library (or with a work based on the Library) on a volume of +a storage or distribution medium does not bring the other work under +the scope of this License. + + 3. You may opt to apply the terms of the ordinary GNU General Public +License instead of this License to a given copy of the Library. To do +this, you must alter all the notices that refer to this License, so +that they refer to the ordinary GNU General Public License, version 2, +instead of to this License. (If a newer version than version 2 of the +ordinary GNU General Public License has appeared, then you can specify +that version instead if you wish.) Do not make any other change in +these notices. + + Once this change is made in a given copy, it is irreversible for +that copy, so the ordinary GNU General Public License applies to all +subsequent copies and derivative works made from that copy. + + This option is useful when you wish to copy part of the code of +the Library into a program that is not a library. + + 4. You may copy and distribute the Library (or a portion or +derivative of it, under Section 2) in object code or executable form +under the terms of Sections 1 and 2 above provided that you accompany +it with the complete corresponding machine-readable source code, which +must be distributed under the terms of Sections 1 and 2 above on a +medium customarily used for software interchange. + + If distribution of object code is made by offering access to copy +from a designated place, then offering equivalent access to copy the +source code from the same place satisfies the requirement to +distribute the source code, even though third parties are not +compelled to copy the source along with the object code. + + 5. A program that contains no derivative of any portion of the +Library, but is designed to work with the Library by being compiled or +linked with it, is called a "work that uses the Library". Such a +work, in isolation, is not a derivative work of the Library, and +therefore falls outside the scope of this License. + + However, linking a "work that uses the Library" with the Library +creates an executable that is a derivative of the Library (because it +contains portions of the Library), rather than a "work that uses the +library". The executable is therefore covered by this License. +Section 6 states terms for distribution of such executables. + + When a "work that uses the Library" uses material from a header file +that is part of the Library, the object code for the work may be a +derivative work of the Library even though the source code is not. +Whether this is true is especially significant if the work can be +linked without the Library, or if the work is itself a library. The +threshold for this to be true is not precisely defined by law. + + If such an object file uses only numerical parameters, data +structure layouts and accessors, and small macros and small inline +functions (ten lines or less in length), then the use of the object +file is unrestricted, regardless of whether it is legally a derivative +work. (Executables containing this object code plus portions of the +Library will still fall under Section 6.) + + Otherwise, if the work is a derivative of the Library, you may +distribute the object code for the work under the terms of Section 6. +Any executables containing that work also fall under Section 6, +whether or not they are linked directly with the Library itself. + + 6. As an exception to the Sections above, you may also combine or +link a "work that uses the Library" with the Library to produce a +work containing portions of the Library, and distribute that work +under terms of your choice, provided that the terms permit +modification of the work for the customer's own use and reverse +engineering for debugging such modifications. + + You must give prominent notice with each copy of the work that the +Library is used in it and that the Library and its use are covered by +this License. You must supply a copy of this License. If the work +during execution displays copyright notices, you must include the +copyright notice for the Library among them, as well as a reference +directing the user to the copy of this License. Also, you must do one +of these things: + + a) Accompany the work with the complete corresponding + machine-readable source code for the Library including whatever + changes were used in the work (which must be distributed under + Sections 1 and 2 above); and, if the work is an executable linked + with the Library, with the complete machine-readable "work that + uses the Library", as object code and/or source code, so that the + user can modify the Library and then relink to produce a modified + executable containing the modified Library. (It is understood + that the user who changes the contents of definitions files in the + Library will not necessarily be able to recompile the application + to use the modified definitions.) + + b) Use a suitable shared library mechanism for linking with the + Library. A suitable mechanism is one that (1) uses at run time a + copy of the library already present on the user's computer system, + rather than copying library functions into the executable, and (2) + will operate properly with a modified version of the library, if + the user installs one, as long as the modified version is + interface-compatible with the version that the work was made with. + + c) Accompany the work with a written offer, valid for at + least three years, to give the same user the materials + specified in Subsection 6a, above, for a charge no more + than the cost of performing this distribution. + + d) If distribution of the work is made by offering access to copy + from a designated place, offer equivalent access to copy the above + specified materials from the same place. + + e) Verify that the user has already received a copy of these + materials or that you have already sent this user a copy. + + For an executable, the required form of the "work that uses the +Library" must include any data and utility programs needed for +reproducing the executable from it. However, as a special exception, +the materials to be distributed need not include anything that is +normally distributed (in either source or binary form) with the major +components (compiler, kernel, and so on) of the operating system on +which the executable runs, unless that component itself accompanies +the executable. + + It may happen that this requirement contradicts the license +restrictions of other proprietary libraries that do not normally +accompany the operating system. Such a contradiction means you cannot +use both them and the Library together in an executable that you +distribute. + + 7. You may place library facilities that are a work based on the +Library side-by-side in a single library together with other library +facilities not covered by this License, and distribute such a combined +library, provided that the separate distribution of the work based on +the Library and of the other library facilities is otherwise +permitted, and provided that you do these two things: + + a) Accompany the combined library with a copy of the same work + based on the Library, uncombined with any other library + facilities. This must be distributed under the terms of the + Sections above. + + b) Give prominent notice with the combined library of the fact + that part of it is a work based on the Library, and explaining + where to find the accompanying uncombined form of the same work. + + 8. You may not copy, modify, sublicense, link with, or distribute +the Library except as expressly provided under this License. Any +attempt otherwise to copy, modify, sublicense, link with, or +distribute the Library is void, and will automatically terminate your +rights under this License. However, parties who have received copies, +or rights, from you under this License will not have their licenses +terminated so long as such parties remain in full compliance. + + 9. You are not required to accept this License, since you have not +signed it. However, nothing else grants you permission to modify or +distribute the Library or its derivative works. These actions are +prohibited by law if you do not accept this License. Therefore, by +modifying or distributing the Library (or any work based on the +Library), you indicate your acceptance of this License to do so, and +all its terms and conditions for copying, distributing or modifying +the Library or works based on it. + + 10. Each time you redistribute the Library (or any work based on the +Library), the recipient automatically receives a license from the +original licensor to copy, distribute, link with or modify the Library +subject to these terms and conditions. You may not impose any further +restrictions on the recipients' exercise of the rights granted herein. +You are not responsible for enforcing compliance by third parties with +this License. + + 11. If, as a consequence of a court judgment or allegation of patent +infringement or for any other reason (not limited to patent issues), +conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot +distribute so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you +may not distribute the Library at all. For example, if a patent +license would not permit royalty-free redistribution of the Library by +all those who receive copies directly or indirectly through you, then +the only way you could satisfy both it and this License would be to +refrain entirely from distribution of the Library. + +If any portion of this section is held invalid or unenforceable under any +particular circumstance, the balance of the section is intended to apply, +and the section as a whole is intended to apply in other circumstances. + +It is not the purpose of this section to induce you to infringe any +patents or other property right claims or to contest validity of any +such claims; this section has the sole purpose of protecting the +integrity of the free software distribution system which is +implemented by public license practices. Many people have made +generous contributions to the wide range of software distributed +through that system in reliance on consistent application of that +system; it is up to the author/donor to decide if he or she is willing +to distribute software through any other system and a licensee cannot +impose that choice. + +This section is intended to make thoroughly clear what is believed to +be a consequence of the rest of this License. + + 12. If the distribution and/or use of the Library is restricted in +certain countries either by patents or by copyrighted interfaces, the +original copyright holder who places the Library under this License may add +an explicit geographical distribution limitation excluding those countries, +so that distribution is permitted only in or among countries not thus +excluded. In such case, this License incorporates the limitation as if +written in the body of this License. + + 13. The Free Software Foundation may publish revised and/or new +versions of the Lesser General Public License from time to time. +Such new versions will be similar in spirit to the present version, +but may differ in detail to address new problems or concerns. + +Each version is given a distinguishing version number. If the Library +specifies a version number of this License which applies to it and +"any later version", you have the option of following the terms and +conditions either of that version or of any later version published by +the Free Software Foundation. If the Library does not specify a +license version number, you may choose any version ever published by +the Free Software Foundation. + + 14. If you wish to incorporate parts of the Library into other free +programs whose distribution conditions are incompatible with these, +write to the author to ask for permission. For software which is +copyrighted by the Free Software Foundation, write to the Free +Software Foundation; we sometimes make exceptions for this. Our +decision will be guided by the two goals of preserving the free status +of all derivatives of our free software and of promoting the sharing +and reuse of software generally. + + NO WARRANTY + + 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO +WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW. +EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR +OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY +KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE +LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME +THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + + 16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN +WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY +AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU +FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR +CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE +LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING +RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A +FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF +SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH +DAMAGES. + + END OF TERMS AND CONDITIONS + + How to Apply These Terms to Your New Libraries + + If you develop a new library, and you want it to be of the greatest +possible use to the public, we recommend making it free software that +everyone can redistribute and change. You can do so by permitting +redistribution under these terms (or, alternatively, under the terms of the +ordinary General Public License). + + To apply these terms, attach the following notices to the library. It is +safest to attach them to the start of each source file to most effectively +convey the exclusion of warranty; and each file should have at least the +"copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + + This library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with this library; if not, write to the Free Software + Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA + +Also add information on how to contact you by electronic and paper mail. + +You should also get your employer (if you work as a programmer) or your +school, if any, to sign a "copyright disclaimer" for the library, if +necessary. Here is a sample; alter the names: + + Yoyodyne, Inc., hereby disclaims all copyright interest in the + library `Frob' (a library for tweaking knobs) written by James Random Hacker. + + , 1 April 1990 + Ty Coon, President of Vice + +That's all there is to it! + diff --git a/third_party/voice/licenses/Opus.txt b/third_party/voice/licenses/Opus.txt new file mode 100644 index 0000000000..75711467a3 --- /dev/null +++ b/third_party/voice/licenses/Opus.txt @@ -0,0 +1,44 @@ +Copyright 2001-2023 Xiph.Org, Skype Limited, Octasic, + Jean-Marc Valin, Timothy B. Terriberry, + CSIRO, Gregory Maxwell, Mark Borgerding, + Erik de Castro Lopo, Mozilla, Amazon + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: + +- Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. + +- Redistributions in binary form must reproduce the above copyright +notice, this list of conditions and the following disclaimer in the +documentation and/or other materials provided with the distribution. + +- Neither the name of Internet Society, IETF or IETF Trust, nor the +names of specific contributors, may be used to endorse or promote +products derived from this software without specific prior written +permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER +OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, +EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, +PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR +PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF +LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING +NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +Opus is subject to the royalty-free patent licenses which are +specified at: + +Xiph.Org Foundation: +https://datatracker.ietf.org/ipr/1524/ + +Microsoft Corporation: +https://datatracker.ietf.org/ipr/1914/ + +Broadcom Corporation: +https://datatracker.ietf.org/ipr/1526/ diff --git a/third_party/voice/licenses/PCRE2.md b/third_party/voice/licenses/PCRE2.md new file mode 100644 index 0000000000..f6fba35db2 --- /dev/null +++ b/third_party/voice/licenses/PCRE2.md @@ -0,0 +1,104 @@ +PCRE2 Licence +============= + +| SPDX-License-Identifier: | BSD-3-Clause WITH PCRE2-exception | +|---------|-------| + +PCRE2 is a library of functions to support regular expressions whose syntax +and semantics are as close as possible to those of the Perl 5 language. + +Releases 10.00 and above of PCRE2 are distributed under the terms of the "BSD" +licence, as specified below, with one exemption for certain binary +redistributions. The documentation for PCRE2, supplied in the "doc" directory, +is distributed under the same terms as the software itself. The data in the +testdata directory is not copyrighted and is in the public domain. + +The basic library functions are written in C and are freestanding. Also +included in the distribution is a just-in-time compiler that can be used to +optimize pattern matching. This is an optional feature that can be omitted when +the library is built. The just-in-time compiler is separately licensed under the +"2-clause BSD" licence. + + +COPYRIGHT +--------- + +### The basic library functions + + Written by: Philip Hazel + Email local part: Philip.Hazel + Email domain: gmail.com + + Retired from University of Cambridge Computing Service, + Cambridge, England. + + Copyright (c) 1997-2007 University of Cambridge + Copyright (c) 2007-2024 Philip Hazel + All rights reserved. + +### PCRE2 Just-In-Time compilation support + + Written by: Zoltan Herczeg + Email local part: hzmester + Email domain: freemail.hu + + Copyright (c) 2010-2024 Zoltan Herczeg + All rights reserved. + +### Stack-less Just-In-Time compiler + + Written by: Zoltan Herczeg + Email local part: hzmester + Email domain: freemail.hu + + Copyright (c) 2009-2024 Zoltan Herczeg + All rights reserved. + +The code in the `deps/sljit` directory has its own LICENSE file. + +### All other contributions + +Many other contributors have participated in the authorship of PCRE2. As PCRE2 +has never required a Contributor Licensing Agreement, or other copyright +assignment agreement, all contributions have copyright retained by each +original contributor or their employer. + + +THE "BSD" LICENCE +----------------- + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +* Redistributions of source code must retain the above copyright notices, + this list of conditions and the following disclaimer. + +* Redistributions in binary form must reproduce the above copyright + notices, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +* Neither the name of the University of Cambridge nor the names of any + contributors may be used to endorse or promote products derived from this + software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + + +EXEMPTION FOR BINARY LIBRARY-LIKE PACKAGES +------------------------------------------ + +The second condition in the BSD licence (covering binary redistributions) does +not apply all the way down a chain of software. If binary package A includes +PCRE2, it must respect the condition, but if package B is software that +includes package A, the condition is not imposed on package B unless it uses +PCRE2 independently. diff --git a/third_party/voice/licenses/libffi.txt b/third_party/voice/licenses/libffi.txt new file mode 100644 index 0000000000..90a8b23028 --- /dev/null +++ b/third_party/voice/licenses/libffi.txt @@ -0,0 +1,21 @@ +libffi - Copyright (c) 1996-2026 Anthony Green, Red Hat, Inc and others. +See source files for details. + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +``Software''), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED ``AS IS'', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/third_party/voice/licenses/proxy-libintl.txt b/third_party/voice/licenses/proxy-libintl.txt new file mode 100644 index 0000000000..bf50f20de6 --- /dev/null +++ b/third_party/voice/licenses/proxy-libintl.txt @@ -0,0 +1,482 @@ + GNU LIBRARY GENERAL PUBLIC LICENSE + Version 2, June 1991 + + Copyright (C) 1991 Free Software Foundation, Inc. + 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + +[This is the first released version of the library GPL. It is + numbered 2 because it goes with version 2 of the ordinary GPL.] + + Preamble + + The licenses for most software are designed to take away your +freedom to share and change it. By contrast, the GNU General Public +Licenses are intended to guarantee your freedom to share and change +free software--to make sure the software is free for all its users. + + This license, the Library General Public License, applies to some +specially designated Free Software Foundation software, and to any +other libraries whose authors decide to use it. You can use it for +your libraries, too. + + When we speak of free software, we are referring to freedom, not +price. Our General Public Licenses are designed to make sure that you +have the freedom to distribute copies of free software (and charge for +this service if you wish), that you receive source code or can get it +if you want it, that you can change the software or use pieces of it +in new free programs; and that you know you can do these things. + + To protect your rights, we need to make restrictions that forbid +anyone to deny you these rights or to ask you to surrender the rights. +These restrictions translate to certain responsibilities for you if +you distribute copies of the library, or if you modify it. + + For example, if you distribute copies of the library, whether gratis +or for a fee, you must give the recipients all the rights that we gave +you. You must make sure that they, too, receive or can get the source +code. If you link a program with the library, you must provide +complete object files to the recipients so that they can relink them +with the library, after making changes to the library and recompiling +it. And you must show them these terms so they know their rights. + + Our method of protecting your rights has two steps: (1) copyright +the library, and (2) offer you this license which gives you legal +permission to copy, distribute and/or modify the library. + + Also, for each distributor's protection, we want to make certain +that everyone understands that there is no warranty for this free +library. If the library is modified by someone else and passed on, we +want its recipients to know that what they have is not the original +version, so that any problems introduced by others will not reflect on +the original authors' reputations. + + Finally, any free program is threatened constantly by software +patents. We wish to avoid the danger that companies distributing free +software will individually obtain patent licenses, thus in effect +transforming the program into proprietary software. To prevent this, +we have made it clear that any patent must be licensed for everyone's +free use or not licensed at all. + + Most GNU software, including some libraries, is covered by the ordinary +GNU General Public License, which was designed for utility programs. This +license, the GNU Library General Public License, applies to certain +designated libraries. This license is quite different from the ordinary +one; be sure to read it in full, and don't assume that anything in it is +the same as in the ordinary license. + + The reason we have a separate public license for some libraries is that +they blur the distinction we usually make between modifying or adding to a +program and simply using it. Linking a program with a library, without +changing the library, is in some sense simply using the library, and is +analogous to running a utility program or application program. However, in +a textual and legal sense, the linked executable is a combined work, a +derivative of the original library, and the ordinary General Public License +treats it as such. + + Because of this blurred distinction, using the ordinary General +Public License for libraries did not effectively promote software +sharing, because most developers did not use the libraries. We +concluded that weaker conditions might promote sharing better. + + However, unrestricted linking of non-free programs would deprive the +users of those programs of all benefit from the free status of the +libraries themselves. This Library General Public License is intended to +permit developers of non-free programs to use free libraries, while +preserving your freedom as a user of such programs to change the free +libraries that are incorporated in them. (We have not seen how to achieve +this as regards changes in header files, but we have achieved it as regards +changes in the actual functions of the Library.) The hope is that this +will lead to faster development of free libraries. + + The precise terms and conditions for copying, distribution and +modification follow. Pay close attention to the difference between a +"work based on the library" and a "work that uses the library". The +former contains code derived from the library, while the latter only +works together with the library. + + Note that it is possible for a library to be covered by the ordinary +General Public License rather than by this special one. + + GNU LIBRARY GENERAL PUBLIC LICENSE + TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION + + 0. This License Agreement applies to any software library which +contains a notice placed by the copyright holder or other authorized +party saying it may be distributed under the terms of this Library +General Public License (also called "this License"). Each licensee is +addressed as "you". + + A "library" means a collection of software functions and/or data +prepared so as to be conveniently linked with application programs +(which use some of those functions and data) to form executables. + + The "Library", below, refers to any such software library or work +which has been distributed under these terms. A "work based on the +Library" means either the Library or any derivative work under +copyright law: that is to say, a work containing the Library or a +portion of it, either verbatim or with modifications and/or translated +straightforwardly into another language. (Hereinafter, translation is +included without limitation in the term "modification".) + + "Source code" for a work means the preferred form of the work for +making modifications to it. For a library, complete source code means +all the source code for all modules it contains, plus any associated +interface definition files, plus the scripts used to control compilation +and installation of the library. + + Activities other than copying, distribution and modification are not +covered by this License; they are outside its scope. The act of +running a program using the Library is not restricted, and output from +such a program is covered only if its contents constitute a work based +on the Library (independent of the use of the Library in a tool for +writing it). Whether that is true depends on what the Library does +and what the program that uses the Library does. + + 1. You may copy and distribute verbatim copies of the Library's +complete source code as you receive it, in any medium, provided that +you conspicuously and appropriately publish on each copy an +appropriate copyright notice and disclaimer of warranty; keep intact +all the notices that refer to this License and to the absence of any +warranty; and distribute a copy of this License along with the +Library. + + You may charge a fee for the physical act of transferring a copy, +and you may at your option offer warranty protection in exchange for a +fee. + + 2. You may modify your copy or copies of the Library or any portion +of it, thus forming a work based on the Library, and copy and +distribute such modifications or work under the terms of Section 1 +above, provided that you also meet all of these conditions: + + a) The modified work must itself be a software library. + + b) You must cause the files modified to carry prominent notices + stating that you changed the files and the date of any change. + + c) You must cause the whole of the work to be licensed at no + charge to all third parties under the terms of this License. + + d) If a facility in the modified Library refers to a function or a + table of data to be supplied by an application program that uses + the facility, other than as an argument passed when the facility + is invoked, then you must make a good faith effort to ensure that, + in the event an application does not supply such function or + table, the facility still operates, and performs whatever part of + its purpose remains meaningful. + + (For example, a function in a library to compute square roots has + a purpose that is entirely well-defined independent of the + application. Therefore, Subsection 2d requires that any + application-supplied function or table used by this function must + be optional: if the application does not supply it, the square + root function must still compute square roots.) + +These requirements apply to the modified work as a whole. If +identifiable sections of that work are not derived from the Library, +and can be reasonably considered independent and separate works in +themselves, then this License, and its terms, do not apply to those +sections when you distribute them as separate works. But when you +distribute the same sections as part of a whole which is a work based +on the Library, the distribution of the whole must be on the terms of +this License, whose permissions for other licensees extend to the +entire whole, and thus to each and every part regardless of who wrote +it. + +Thus, it is not the intent of this section to claim rights or contest +your rights to work written entirely by you; rather, the intent is to +exercise the right to control the distribution of derivative or +collective works based on the Library. + +In addition, mere aggregation of another work not based on the Library +with the Library (or with a work based on the Library) on a volume of +a storage or distribution medium does not bring the other work under +the scope of this License. + + 3. You may opt to apply the terms of the ordinary GNU General Public +License instead of this License to a given copy of the Library. To do +this, you must alter all the notices that refer to this License, so +that they refer to the ordinary GNU General Public License, version 2, +instead of to this License. (If a newer version than version 2 of the +ordinary GNU General Public License has appeared, then you can specify +that version instead if you wish.) Do not make any other change in +these notices. + + Once this change is made in a given copy, it is irreversible for +that copy, so the ordinary GNU General Public License applies to all +subsequent copies and derivative works made from that copy. + + This option is useful when you wish to copy part of the code of +the Library into a program that is not a library. + + 4. You may copy and distribute the Library (or a portion or +derivative of it, under Section 2) in object code or executable form +under the terms of Sections 1 and 2 above provided that you accompany +it with the complete corresponding machine-readable source code, which +must be distributed under the terms of Sections 1 and 2 above on a +medium customarily used for software interchange. + + If distribution of object code is made by offering access to copy +from a designated place, then offering equivalent access to copy the +source code from the same place satisfies the requirement to +distribute the source code, even though third parties are not +compelled to copy the source along with the object code. + + 5. A program that contains no derivative of any portion of the +Library, but is designed to work with the Library by being compiled or +linked with it, is called a "work that uses the Library". Such a +work, in isolation, is not a derivative work of the Library, and +therefore falls outside the scope of this License. + + However, linking a "work that uses the Library" with the Library +creates an executable that is a derivative of the Library (because it +contains portions of the Library), rather than a "work that uses the +library". The executable is therefore covered by this License. +Section 6 states terms for distribution of such executables. + + When a "work that uses the Library" uses material from a header file +that is part of the Library, the object code for the work may be a +derivative work of the Library even though the source code is not. +Whether this is true is especially significant if the work can be +linked without the Library, or if the work is itself a library. The +threshold for this to be true is not precisely defined by law. + + If such an object file uses only numerical parameters, data +structure layouts and accessors, and small macros and small inline +functions (ten lines or less in length), then the use of the object +file is unrestricted, regardless of whether it is legally a derivative +work. (Executables containing this object code plus portions of the +Library will still fall under Section 6.) + + Otherwise, if the work is a derivative of the Library, you may +distribute the object code for the work under the terms of Section 6. +Any executables containing that work also fall under Section 6, +whether or not they are linked directly with the Library itself. + + 6. As an exception to the Sections above, you may also compile or +link a "work that uses the Library" with the Library to produce a +work containing portions of the Library, and distribute that work +under terms of your choice, provided that the terms permit +modification of the work for the customer's own use and reverse +engineering for debugging such modifications. + + You must give prominent notice with each copy of the work that the +Library is used in it and that the Library and its use are covered by +this License. You must supply a copy of this License. If the work +during execution displays copyright notices, you must include the +copyright notice for the Library among them, as well as a reference +directing the user to the copy of this License. Also, you must do one +of these things: + + a) Accompany the work with the complete corresponding + machine-readable source code for the Library including whatever + changes were used in the work (which must be distributed under + Sections 1 and 2 above); and, if the work is an executable linked + with the Library, with the complete machine-readable "work that + uses the Library", as object code and/or source code, so that the + user can modify the Library and then relink to produce a modified + executable containing the modified Library. (It is understood + that the user who changes the contents of definitions files in the + Library will not necessarily be able to recompile the application + to use the modified definitions.) + + b) Accompany the work with a written offer, valid for at + least three years, to give the same user the materials + specified in Subsection 6a, above, for a charge no more + than the cost of performing this distribution. + + c) If distribution of the work is made by offering access to copy + from a designated place, offer equivalent access to copy the above + specified materials from the same place. + + d) Verify that the user has already received a copy of these + materials or that you have already sent this user a copy. + + For an executable, the required form of the "work that uses the +Library" must include any data and utility programs needed for +reproducing the executable from it. However, as a special exception, +the source code distributed need not include anything that is normally +distributed (in either source or binary form) with the major +components (compiler, kernel, and so on) of the operating system on +which the executable runs, unless that component itself accompanies +the executable. + + It may happen that this requirement contradicts the license +restrictions of other proprietary libraries that do not normally +accompany the operating system. Such a contradiction means you cannot +use both them and the Library together in an executable that you +distribute. + + 7. You may place library facilities that are a work based on the +Library side-by-side in a single library together with other library +facilities not covered by this License, and distribute such a combined +library, provided that the separate distribution of the work based on +the Library and of the other library facilities is otherwise +permitted, and provided that you do these two things: + + a) Accompany the combined library with a copy of the same work + based on the Library, uncombined with any other library + facilities. This must be distributed under the terms of the + Sections above. + + b) Give prominent notice with the combined library of the fact + that part of it is a work based on the Library, and explaining + where to find the accompanying uncombined form of the same work. + + 8. You may not copy, modify, sublicense, link with, or distribute +the Library except as expressly provided under this License. Any +attempt otherwise to copy, modify, sublicense, link with, or +distribute the Library is void, and will automatically terminate your +rights under this License. However, parties who have received copies, +or rights, from you under this License will not have their licenses +terminated so long as such parties remain in full compliance. + + 9. You are not required to accept this License, since you have not +signed it. However, nothing else grants you permission to modify or +distribute the Library or its derivative works. These actions are +prohibited by law if you do not accept this License. Therefore, by +modifying or distributing the Library (or any work based on the +Library), you indicate your acceptance of this License to do so, and +all its terms and conditions for copying, distributing or modifying +the Library or works based on it. + + 10. Each time you redistribute the Library (or any work based on the +Library), the recipient automatically receives a license from the +original licensor to copy, distribute, link with or modify the Library +subject to these terms and conditions. You may not impose any further +restrictions on the recipients' exercise of the rights granted herein. +You are not responsible for enforcing compliance by third parties to +this License. + + 11. If, as a consequence of a court judgment or allegation of patent +infringement or for any other reason (not limited to patent issues), +conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot +distribute so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you +may not distribute the Library at all. For example, if a patent +license would not permit royalty-free redistribution of the Library by +all those who receive copies directly or indirectly through you, then +the only way you could satisfy both it and this License would be to +refrain entirely from distribution of the Library. + +If any portion of this section is held invalid or unenforceable under any +particular circumstance, the balance of the section is intended to apply, +and the section as a whole is intended to apply in other circumstances. + +It is not the purpose of this section to induce you to infringe any +patents or other property right claims or to contest validity of any +such claims; this section has the sole purpose of protecting the +integrity of the free software distribution system which is +implemented by public license practices. Many people have made +generous contributions to the wide range of software distributed +through that system in reliance on consistent application of that +system; it is up to the author/donor to decide if he or she is willing +to distribute software through any other system and a licensee cannot +impose that choice. + +This section is intended to make thoroughly clear what is believed to +be a consequence of the rest of this License. + + 12. If the distribution and/or use of the Library is restricted in +certain countries either by patents or by copyrighted interfaces, the +original copyright holder who places the Library under this License may add +an explicit geographical distribution limitation excluding those countries, +so that distribution is permitted only in or among countries not thus +excluded. In such case, this License incorporates the limitation as if +written in the body of this License. + + 13. The Free Software Foundation may publish revised and/or new +versions of the Library General Public License from time to time. +Such new versions will be similar in spirit to the present version, +but may differ in detail to address new problems or concerns. + +Each version is given a distinguishing version number. If the Library +specifies a version number of this License which applies to it and +"any later version", you have the option of following the terms and +conditions either of that version or of any later version published by +the Free Software Foundation. If the Library does not specify a +license version number, you may choose any version ever published by +the Free Software Foundation. + + 14. If you wish to incorporate parts of the Library into other free +programs whose distribution conditions are incompatible with these, +write to the author to ask for permission. For software which is +copyrighted by the Free Software Foundation, write to the Free +Software Foundation; we sometimes make exceptions for this. Our +decision will be guided by the two goals of preserving the free status +of all derivatives of our free software and of promoting the sharing +and reuse of software generally. + + NO WARRANTY + + 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO +WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW. +EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR +OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY +KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE +LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME +THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + + 16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN +WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY +AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU +FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR +CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE +LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING +RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A +FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF +SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH +DAMAGES. + + END OF TERMS AND CONDITIONS + + How to Apply These Terms to Your New Libraries + + If you develop a new library, and you want it to be of the greatest +possible use to the public, we recommend making it free software that +everyone can redistribute and change. You can do so by permitting +redistribution under these terms (or, alternatively, under the terms of the +ordinary General Public License). + + To apply these terms, attach the following notices to the library. It is +safest to attach them to the start of each source file to most effectively +convey the exclusion of warranty; and each file should have at least the +"copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + + This library is free software; you can redistribute it and/or + modify it under the terms of the GNU Library General Public + License as published by the Free Software Foundation; either + version 2 of the License, or (at your option) any later version. + + This library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Library General Public License for more details. + + You should have received a copy of the GNU Library General Public + License along with this library; if not, write to the + Free Software Foundation, Inc., 59 Temple Place - Suite 330, + Boston, MA 02111-1307 USA. + +Also add information on how to contact you by electronic and paper mail. + +You should also get your employer (if you work as a programmer) or your +school, if any, to sign a "copyright disclaimer" for the library, if +necessary. Here is a sample; alter the names: + + Yoyodyne, Inc., hereby disclaims all copyright interest in the + library `Frob' (a library for tweaking knobs) written by James Random Hacker. + + , 1 April 1990 + Ty Coon, President of Vice + +That's all there is to it! diff --git a/third_party/voice/licenses/sljit.txt b/third_party/voice/licenses/sljit.txt new file mode 100644 index 0000000000..0aaecaaa28 --- /dev/null +++ b/third_party/voice/licenses/sljit.txt @@ -0,0 +1,25 @@ +/* + * Stack-less Just-In-Time compiler + * + * Copyright Zoltan Herczeg (hzmester@freemail.hu). All rights reserved. + * + * Redistribution and use in source and binary forms, with or without modification, are + * permitted provided that the following conditions are met: + * + * 1. Redistributions of source code must retain the above copyright notice, this list of + * conditions and the following disclaimer. + * + * 2. Redistributions in binary form must reproduce the above copyright notice, this list + * of conditions and the following disclaimer in the documentation and/or other materials + * provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDER(S) AND CONTRIBUTORS ``AS IS'' AND ANY + * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT + * SHALL THE COPYRIGHT HOLDER(S) OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED + * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN + * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ diff --git a/third_party/voice/licenses/zlib.txt b/third_party/voice/licenses/zlib.txt new file mode 100644 index 0000000000..b7a69d058e --- /dev/null +++ b/third_party/voice/licenses/zlib.txt @@ -0,0 +1,22 @@ +Copyright notice: + + (C) 1995-2026 Jean-loup Gailly and Mark Adler + + This software is provided 'as-is', without any express or implied + warranty. In no event will the authors be held liable for any damages + arising from the use of this software. + + Permission is granted to anyone to use this software for any purpose, + including commercial applications, and to alter it and redistribute it + freely, subject to the following restrictions: + + 1. The origin of this software must not be misrepresented; you must not + claim that you wrote the original software. If you use this software + in a product, an acknowledgment in the product documentation would be + appreciated but is not required. + 2. Altered source versions must be plainly marked as such, and must not be + misrepresented as being the original software. + 3. This notice may not be removed or altered from any source distribution. + + Jean-loup Gailly Mark Adler + jloup@gzip.org madler@alumni.caltech.edu diff --git a/third_party/voice/package_runtime.py b/third_party/voice/package_runtime.py index c70a4711eb..ca213eb611 100644 --- a/third_party/voice/package_runtime.py +++ b/third_party/voice/package_runtime.py @@ -12,7 +12,9 @@ import re from runtime import PLUGINS, digest, required_library_paths -def runtime_files(root: Path, target: str) -> dict[str, str]: +def runtime_files( + root: Path, target: str, *, public_release: bool = False +) -> dict[str, str]: manifest_path = root / "runtime.json" if manifest_path.is_symlink() or not manifest_path.is_file(): raise ValueError("runtime manifest must be a regular file") @@ -23,7 +25,8 @@ def runtime_files(root: Path, target: str) -> dict[str, str]: manifest = json.loads(data) if ( manifest.get("schemaVersion") != 1 - or manifest.get("developmentOnly") is not True + or manifest.get("developmentOnly") is not (not public_release) + or (public_release and manifest.get("distribution") != "publicRelease") or manifest.get("target") != target or manifest.get("sourceManifestSha256") != digest(Path(__file__).with_name("sources.json")) diff --git a/third_party/voice/release_runtime.py b/third_party/voice/release_runtime.py new file mode 100644 index 0000000000..cdcd9989e0 --- /dev/null +++ b/third_party/voice/release_runtime.py @@ -0,0 +1,56 @@ +"""Stage verified macOS voice libraries and seal their post-signing release receipt.""" + +import argparse +import json +from pathlib import Path +import shutil + +from package_runtime import runtime_files +from runtime import digest + + +def stage(source: Path, destination: Path, target: str) -> None: + if target not in {"aarch64-apple-darwin", "x86_64-apple-darwin"}: + raise ValueError("public voice runtime requires a macOS target") + source = source.resolve(strict=True) + files = runtime_files(source, target) + destination.mkdir() + try: + for relative, expected in files.items(): + copied = destination / relative + copied.parent.mkdir(parents=True, exist_ok=True) + shutil.copy2(source / relative, copied) + if digest(copied) != expected: + raise ValueError("runtime changed while staging release inputs") + except BaseException: + shutil.rmtree(destination) + raise + + +def seal(root: Path, target: str) -> None: + root = root.resolve(strict=True) + manifest_path = root / "runtime.json" + manifest = json.loads(manifest_path.read_text(encoding="utf-8")) + if manifest.get("developmentOnly") is not True or manifest.get("target") != target: + raise ValueError("expected an unsealed development receipt for this target") + for record in manifest["libraries"]: + record["sha256"] = digest(root / record["path"]) + manifest["developmentOnly"] = False + manifest["distribution"] = "publicRelease" + manifest_path.write_text(json.dumps(manifest, indent=2) + "\n", encoding="utf-8") + runtime_files(root, target, public_release=True) + + +if __name__ == "__main__": + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument("operation", choices=("stage", "seal")) + parser.add_argument("--target", required=True) + parser.add_argument("--source", type=Path) + parser.add_argument("--output", type=Path, required=True) + args = parser.parse_args() + if args.operation == "stage": + if args.source is None: + parser.error("stage requires --source") + stage(args.source, args.output, args.target) + else: + seal(args.output, args.target) diff --git a/third_party/voice/test_assemble_package.py b/third_party/voice/test_assemble_package.py index 79f929ab5e..2eb4999671 100644 --- a/third_party/voice/test_assemble_package.py +++ b/third_party/voice/test_assemble_package.py @@ -13,6 +13,8 @@ from unittest.mock import patch from assemble_package import assemble from package_runtime import runtime_files +from release_runtime import seal +from release_runtime import stage from runtime import PLUGINS, digest, required_library_paths @@ -160,6 +162,120 @@ class AssembleTests(unittest.TestCase): with self.assertRaisesRegex(ValueError, "required libraries"): runtime_files(root.resolve(), target) + def test_alpha_package_preserves_release_version_and_matching_build(self): + self.commit = "b" * 40 + target = "aarch64-apple-darwin" + runtime, _ = self.make_runtime(target, "plugins/libgst{}.dylib") + staged = self.root / "staged" + stage(runtime, staged, target) + signed_library = staged / "lib/libgio-2.0.0.dylib" + signed_library.write_bytes(signed_library.read_bytes() + b"signed") + seal(staged, target) + self.metadata["version"] = "0.154.0-alpha.8" + self.metadata["target"] = target + (self.package / "codex-package.json").write_text(json.dumps(self.metadata)) + assemble( + self.package, + self.helper, + target, + self.commit, + self.output, + runtime=staged, + release_version="0.154.0-alpha.8", + ) + manifest = json.loads( + (self.output / "codex-resources/voice/manifest.json").read_text() + ) + self.assertEqual(manifest["appVersion"], "0.154.0-alpha.8") + self.assertEqual(manifest["buildCommit"], self.commit) + notice_root = self.output / "codex-resources/voice" + for source in (Path(__file__).with_name("licenses")).iterdir(): + relative = f"codex-resources/voice/licenses/{source.name}" + self.assertEqual( + (notice_root / "licenses" / source.name).read_bytes(), + source.read_bytes(), + ) + self.assertEqual(manifest["sha256"][relative], digest(source)) + self.assertEqual( + (self.output / "codex-resources/voice/lib/libgio-2.0.0.dylib").read_bytes(), + signed_library.read_bytes(), + ) + + self.output.rename(self.root / "previous output") + with self.assertRaisesRegex(ValueError, "package version"): + assemble( + self.package, + self.helper, + target, + self.commit, + self.output, + runtime=staged, + release_version="0.154.0-alpha.7", + ) + + with self.assertRaisesRegex(ValueError, "runtime receipt"): + assemble( + self.package, + self.helper, + target, + self.commit, + self.output, + runtime=runtime, + release_version="0.154.0-alpha.8", + ) + + def test_alpha_receipt_requires_matching_signed_hashes(self): + target = "x86_64-apple-darwin" + runtime, _ = self.make_runtime(target, "plugins/libgst{}.dylib") + secret = self.root / "outside-secret" + secret.write_bytes(b"must not enter signing artifacts") + (runtime / "unlisted-file").write_bytes(b"unlisted") + try: + (runtime / "unlisted-secret").symlink_to(secret) + except OSError: + # Windows runners may not grant symlink creation to this process. + pass + staged = self.root / "staged" + stage(runtime, staged, target) + self.assertFalse((staged / "unlisted-file").exists()) + self.assertFalse((staged / "unlisted-secret").exists()) + seal(staged, target) + self.assertTrue(runtime_files(staged.resolve(), target, public_release=True)) + with self.assertRaisesRegex(ValueError, "runtime receipt"): + runtime_files(staged.resolve(), target) + (staged / "lib/libgio-2.0.0.dylib").write_bytes(b"tampered") + with self.assertRaisesRegex(ValueError, "digest mismatch"): + runtime_files(staged.resolve(), target, public_release=True) + + def test_beta_and_stable_release_versions_package_the_same_runtime(self): + self.commit = "b" * 40 + target = "aarch64-apple-darwin" + runtime, _ = self.make_runtime(target, "plugins/libgst{}.dylib") + staged = self.root / "staged" + stage(runtime, staged, target) + seal(staged, target) + self.metadata["target"] = target + for version in ("0.154.0-beta.2", "0.154.0"): + with self.subTest(version=version): + self.metadata["version"] = version + (self.package / "codex-package.json").write_text( + json.dumps(self.metadata) + ) + output = self.root / f"package-{version}" + assemble( + self.package, + self.helper, + target, + self.commit, + output, + runtime=staged, + release_version=version, + ) + manifest = json.loads( + (output / "codex-resources/voice/manifest.json").read_text() + ) + self.assertEqual(manifest["appVersion"], version) + def test_rejects_invalid_runtime_receipts_before_creating_package(self): runtime, original = self.make_runtime() changes = [