Files
SonicForgeStudio/THIRD_PARTY_LICENSES.md
admin dc331f39d8 phase5: mặc định RENDER_ENGINE=bridge, gỡ pedalboard khỏi requirements/source/LICENSE
- config.py: SF_RENDER_ENGINE default 'bridge' (pedalboard GPL-3.0 đã gỡ)
- requirements.txt: bỏ pedalboard==0.9.19
- vst_engine.py: bỏ HAS_PEDALBOARD/check_pedalboard_safe/load_vst/import pedalboard;
  midi_events_to_messages giữ làm utility thuần (không gate pedalboard)
- render_engine.py: bỏ nhánh elif vst and HAS_PEDALBOARD + import thừa
- plugins.py: preview/midi-render chỉ qua native_bridge; guard SF_RENDER_ENGINE=bridge
- runtime.py: _vst_render_available() check bridge exe (SF_BRIDGE_PATH/install/) thay find_spec('pedalboard')
- LICENSE.md/THIRD_PARTY_LICENSES.md: bỏ cảnh báo GPL-3.0 pedalboard, đánh số lại
- tests: bỏ test golden so pedalboard + test requires_pedalboard; 114 passed 0 skip
2026-08-17 12:58:51 +07:00

4.8 KiB

THIRD-PARTY LICENSES — SonicForgeStudio

Kiểm tra ngày 2026-08-15 (verify từ PyPI/GitHub/LICENSE.txt trong wheel). Danh sách thành phần bên thứ ba + license. Bản tổng hợp: LICENSE.md.

1. Dependencies (npm — package.json)

Thành phần License Ghi chú
react / react-dom 19.x MIT OK
@babel/cli, @babel/core, @babel/preset-react MIT Chỉ build-time
jsdom MIT Chỉ build-time/test
@tauri-apps/cli 2.x Apache-2.0 OR MIT Desktop shell (src-tauri) — build-time

1b. Dependencies (Python — requirements.txt)

Thành phần License Ghi chú
fastapi MIT OK
uvicorn BSD-3-Clause OK
celery BSD-3-Clause OK
redis MIT OK
python-multipart Apache-2.0 OK
librosa ISC OK
pydub MIT OK
numpy BSD-3-Clause (kèm 0BSD, MIT, Zlib, CC0-1.0) OK
scipy BSD-3-Clause (kèm OpenBLAS BSD-3, GCC runtime GPL-3.0-with-exception) OK — exception cho phép dùng
soundfile BSD-3-Clause OK (libsndfile core là LGPL-2.1+)
jinja2 BSD-3-Clause OK
httpx BSD-3-Clause OK
jsonschema MIT OK
mido MIT OK
pyfluidsynth MIT (wrapper) OK — link FluidSynth LGPL-2.1+
sf2utils 1.0.0 LGPL-3.0+ ⚠️ LICENSE.txt trong wheel là LGPLv3 (metadata PyPI ghi nhầm "GPLv3+"). Dùng runtime soundfont_inspector.py — giữ notice + relinkable khi phân phối binary

1c. Native bridge (native_bridge/, C++)

Thành phần License Ghi chú
fluidsynth (vcpkg) LGPL-2.1+ Link tĩnh qua vcpkg — bắt buộc notice + relinkable object
vst3sdk (git submodule) MIT © 2026 Steinberg Media Technologies GmbH — tương thích MIT project
vestige (dự kiến cho VST2) mã nguồn mở Chưa thêm vào repo — xác nhận license gốc khi implement

2. Thư viện nhúng (app/static)

File Nguồn License Trạng thái
css/tailwind.min.css Tailwind CSS MIT OK — nên giữ attribution
js/services/spessasynth_processor.min.js SpessaSynth (KHÔNG còn dùng — không được include trong index.html — chỉ FluidSynth) MIT ✅ KHÔNG có code nào gọi (chỉ còn comment cũ app.jsx:14276 + file chết) — có thể xóa file
js/vendor/libfluidsynth-2.3.0-sf3.js + .wasm FluidSynth 2.3.0 (Emscripten) LGPL-2.1+ ⚠️ Bắt buộc giữ license notice + attribution + (nếu phân phối bản build) cung cấp link/tài liệu LGPL
js/services/fluidsynthLoader.js, worklets/fluidsynth-bridge.js Bản tự viết (bọc FluidSynth) Dự án OK
Lucide icons (inline data-lucide) Lucide ISC (MIT-compatible) OK

3. Nội dung âm thanh (app/storage)

File Nguồn License Trạng thái
soundfonts/518e850f-...sf2 "General MIDI SoundFont v3.0" — © 2006-2010 Rich "Weeds" Nagel — "Some rights reserved" Không có text đầy đủ trong file (chỉ ICOP ngắn). Tuyên bố: "created from various commercial, custom, and freeware soundfonts and samples" ⚠️ RỦI RO: (a) điều kiện "some rights reserved" không rõ ràng (thường là CC-BY — cần ghi attribution; có thể hạn chế thương mại); (b) samples gốc có nguồn commercial — quyền tái phân phối phụ thuộc tuyên bố tác giả. Khuyến nghị: thay bằng SF2 license rõ (FluidR3_GM — MIT/GPL-2; GeneralUser GS — CC-BY-SA; Arachno — public domain) HOẶC giữ + ghi attribution đầy đủ.
uploads/user_anonymous_*.mp3 File người dùng upload Thuộc người dùng OK — không phải thành phần phân phối
SGM-V2.01 (xuất hiện trong log sfId: SGM-V2.01) SGM-V2.01 Freeware — tác giả cho phép dùng nhưng hạn chế redistribution (cần permission) ⚠️ Nếu vẫn dùng để phân phối bản build — cần permission từ tác giả; không nhúng vào sản phẩm

4. Assets

  • templates/favicon.svg, images/SonicForgeUI.png — nội bộ (tự tạo) — OK.
  • Code trong app/static/js/services/*, app/static/js/components/*, app.jsx — tự viết — thuộc dự án.

KẾT LUẬN

  • Không phát hiện vi phạm bản quyền rõ ràng (không có code GPL bị nhúng vào project MIT; LGPL của FluidSynth tương thích nếu giữ notice).
  • Cần xử lý trước khi phân phối công khai:
    1. sf2utils (LGPL-3.0+) — giữ notice + relinkable object khi phân phối binary.
    2. Bổ sung LICENSE text (MIT + LGPL-2.1) + attribution cho SpessaSynth (MIT notice) và Tailwind.
    3. Ghi attribution SF2 Rich Nagel ("General MIDI SoundFont v3.0" — © 2006-2010 Rich 'Weeds' Nagel — Some rights reserved) hoặc thay soundfont khác license rõ.
    4. Không nhúng SGM-V2.01 vào bản phân phối (hạn chế redistribution).