docs(license): add LICENSE.md, audit third-party licenses (Python/native/tauri), flag pedalboard GPL-3.0

This commit is contained in:
2026-08-16 21:08:13 +07:00
parent 4f6e2bc049
commit e2c0564982
2 changed files with 139 additions and 5 deletions
+102
View File
@@ -0,0 +1,102 @@
# LICENSE — SonicForgeStudio
## 1. Mã nguồn dự án
MIT License
Copyright (c) 2026 SonicForge Studio contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
File văn bản MIT đầy đủ: `LICENSE`.
## 2. Thành phần bên thứ ba
Kiểm tra ngày 2026-08-15 (verify từ PyPI/GitHub/wheel). Các thành phần giữ
license gốc; chi tiết + attribution: `THIRD_PARTY_LICENSES.md`.
### 2.1. npm (`package.json`)
| Thành phần | License |
|---|---|
| react / react-dom 19.x | MIT |
| @babel/cli, @babel/core, @babel/preset-react | MIT |
| jsdom | MIT |
| @tauri-apps/cli 2.x (desktop shell) | Apache-2.0 OR MIT |
### 2.2. Python (`requirements.txt`)
| Thành phần | License |
|---|---|
| fastapi | MIT |
| uvicorn | BSD-3-Clause |
| celery | BSD-3-Clause |
| redis | MIT |
| python-multipart | Apache-2.0 |
| librosa | ISC |
| pydub | MIT |
| numpy | BSD-3-Clause (kèm code nhúng: 0BSD, MIT, Zlib, CC0-1.0) |
| scipy | BSD-3-Clause (kèm OpenBLAS BSD-3, GCC runtime GPL-3.0-with-exception) |
| soundfile | BSD-3-Clause |
| jinja2 | BSD-3-Clause |
| httpx | BSD-3-Clause |
| jsonschema | MIT |
| mido | MIT |
| pyfluidsynth | MIT (wrapper — link FluidSynth **LGPL-2.1+**) |
| sf2utils 1.0.0 | **LGPL-3.0+** (LICENSE.txt trong wheel; metadata PyPI ghi nhầm "GPLv3+") |
| pedalboard 0.9.19 | **GPL-3.0** ⚠️ — xem mục 3 |
### 2.3. Native bridge (`native_bridge/`, C++)
| Thành phần | License |
|---|---|
| fluidsynth (vcpkg) | LGPL-2.1+ |
| vst3sdk (git submodule, `native_bridge/vst3sdk`) | MIT (© 2026 Steinberg Media Technologies GmbH) |
| vestige (dự kiến thêm khi implement VST2, xem `DESIGN_VST2_BACKWARD_COMPAT.md`) | header mã nguồn mở — xác nhận lại file license gốc khi thêm vào repo |
### 2.4. Nhúng (`app/static`)
| Thành phần | License |
|---|---|
| `css/tailwind.min.css` | MIT |
| Lucide icons | ISC |
| `js/vendor/libfluidsynth-2.3.0-sf3.js` + `.wasm` (FluidSynth Emscripten) | **LGPL-2.1+** |
| `js/services/spessasynth_processor.min.js` | MIT — file chết, không include trong `index.html` |
### 2.5. Nội dung âm thanh (`app/storage`)
| Thành phần | License | Trạng thái |
|---|---|---|
| "General MIDI SoundFont v3.0" — © 2006-2010 Rich "Weeds" Nagel | "Some rights reserved" (không rõ điều kiện) | ⚠️ cần attribution hoặc thay SF2 license rõ |
| SGM-V2.01 | Freeware — hạn chế redistribution | ⚠️ không nhúng vào bản phân phối |
## 3. Lưu ý pháp lý khi phân phối
1. **pedalboard (GPL-3.0)** — dùng runtime ở server (`app/core/render_engine.py`,
`app/core/vst_engine.py`, `app/api/v1/plugins.py`) cho render VST3.
GPL-3.0 copyleft → phân phối bản server gộp pedalboard có thể kéo toàn bộ
phần combined theo GPL. Cần: tách pedalboard ra subprocess/plugin riêng
(không import trong process MIT chính) hoặc thay thế bằng host khác.
2. **sf2utils (LGPL-3.0+)** — dùng runtime (`app/core/soundfont_inspector.py`).
LGPL cho phép app MIT dùng nếu giữ notice + (khi phân phối binary) cung cấp
khả năng relink/object tương ứng.
3. **FluidSynth (LGPL-2.1+)** — vừa nhúng Emscripten (`app/static`) vừa link
tĩnh qua vcpkg (`native_bridge`). Bắt buộc: giữ license notice, cung cấp
link/object relinkable khi phân phối bản build.
4. **vst3sdk (MIT)** — tương thích hoàn toàn với dự án MIT.
5. **VST2 SDK của Steinberg** — discontinued, license không cấp mới → hướng
dùng **vestige** (header mã nguồn mở) theo `DESIGN_VST2_BACKWARD_COMPAT.md`,
không nhúng VST2 SDK chính hãng.
6. **SoundFont** — SGM-V2.01 không đưa vào bản phân phối; SF2 Rich Nagel cần
attribution hoặc thay thế.
+37 -5
View File
@@ -1,6 +1,7 @@
# THIRD-PARTY LICENSES — SonicForgeStudio
Kiểm tra ngày 2026-08-07. Danh sách thành phần bên thứ ba + license.
Kiểm tra ngày 2026-08-15 (verify từ PyPI/GitHub/LICENSE.txt trong wheel).
Danh sách thành phần bên thứ ba + license. Bản tổng hợp: `LICENSE.md`.
## 1. Dependencies (npm — package.json)
| Thành phần | License | Ghi chú |
@@ -8,6 +9,35 @@ Kiểm tra ngày 2026-08-07. Danh sách thành phần bên thứ ba + license.
| react / react-dom 19.x | MIT | OK |
| @babel/cli, @babel/core, @babel/preset-react | MIT | Chỉ build-time |
| jsdom | MIT | Chỉ build-time/test |
| @tauri-apps/cli 2.x | Apache-2.0 OR MIT | Desktop shell (src-tauri) — build-time |
## 1b. Dependencies (Python — requirements.txt)
| Thành phần | License | Ghi chú |
|---|---|---|
| fastapi | MIT | OK |
| uvicorn | BSD-3-Clause | OK |
| celery | BSD-3-Clause | OK |
| redis | MIT | OK |
| python-multipart | Apache-2.0 | OK |
| librosa | ISC | OK |
| pydub | MIT | OK |
| numpy | BSD-3-Clause (kèm 0BSD, MIT, Zlib, CC0-1.0) | OK |
| scipy | BSD-3-Clause (kèm OpenBLAS BSD-3, GCC runtime GPL-3.0-with-exception) | OK — exception cho phép dùng |
| soundfile | BSD-3-Clause | OK (libsndfile core là LGPL-2.1+) |
| jinja2 | BSD-3-Clause | OK |
| httpx | BSD-3-Clause | OK |
| jsonschema | MIT | OK |
| mido | MIT | OK |
| pyfluidsynth | MIT (wrapper) | OK — link FluidSynth LGPL-2.1+ |
| sf2utils 1.0.0 | **LGPL-3.0+** | ⚠️ LICENSE.txt trong wheel là LGPLv3 (metadata PyPI ghi nhầm "GPLv3+"). Dùng runtime `soundfont_inspector.py` — giữ notice + relinkable khi phân phối binary |
| pedalboard 0.9.19 | **GPL-3.0** | ⚠️ RỦI RO — dùng runtime render VST3 (render_engine/vst_engine/plugins). Copyleft mạnh → tách subprocess hoặc thay thế trước khi phân phối server |
## 1c. Native bridge (native_bridge/, C++)
| Thành phần | License | Ghi chú |
|---|---|---|
| fluidsynth (vcpkg) | LGPL-2.1+ | Link tĩnh qua vcpkg — bắt buộc notice + relinkable object |
| vst3sdk (git submodule) | MIT | © 2026 Steinberg Media Technologies GmbH — tương thích MIT project |
| vestige (dự kiến cho VST2) | mã nguồn mở | Chưa thêm vào repo — xác nhận license gốc khi implement |
## 2. Thư viện nhúng (app/static)
| File | Nguồn | License | Trạng thái |
@@ -31,7 +61,9 @@ Kiểm tra ngày 2026-08-07. Danh sách thành phần bên thứ ba + license.
## KẾT LUẬN
- **Không phát hiện vi phạm bản quyền rõ ràng** (không có code GPL bị nhúng vào project MIT; LGPL của FluidSynth tương thích nếu giữ notice).
- **3 điểm cần xử lý trước khi phân phối công khai:**
1. Bổ sung `LICENSE` text (MIT + LGPL-2.1) + attribution cho SpessaSynth (MIT notice) và Tailwind.
2. Ghi attribution SF2 Rich Nagel ("General MIDI SoundFont v3.0 — © 2006-2010 Rich 'Weeds' Nagel — Some rights reserved") hoặc thay soundfont khác license rõ.
3. Không nhúng SGM-V2.01 vào bản phân phối (hạn chế redistribution).
- **Cần xử lý trước khi phân phối công khai:**
1. **pedalboard (GPL-3.0)** — dependency runtime server render VST3 → rủi ro copyleft cao nhất. Tách subprocess/plugin hoặc thay thế.
2. **sf2utils (LGPL-3.0+)** — giữ notice + relinkable object khi phân phối binary.
3. Bổ sung `LICENSE` text (MIT + LGPL-2.1) + attribution cho SpessaSynth (MIT notice) và Tailwind.
4. Ghi attribution SF2 Rich Nagel ("General MIDI SoundFont v3.0 — © 2006-2010 Rich 'Weeds' Nagel — Some rights reserved") hoặc thay soundfont khác license rõ.
5. Không nhúng SGM-V2.01 vào bản phân phối (hạn chế redistribution).