From 3323496a346d83f6a024f44199cbee464eb0c23d Mon Sep 17 00:00:00 2001 From: PJ Date: Wed, 12 Aug 2026 21:30:13 +0530 Subject: [PATCH] License under MIT No licence file meant nobody had permission to redistribute this, which is a strange position for a public repo with an AUR package pointing at it. The PKGBUILD said license=('custom') because there was nothing truthful to put there. MIT is not one of the licences Arch keeps in /usr/share/licenses/common, so the package now fetches the licence from its own tag and installs a copy. The release workflow checksums that copy from the tag it checked out, rather than trusting whatever main has drifted to. Declared in package.json and Cargo.toml too, so the manifests and the package agree on the answer. --- .github/workflows/release.yml | 12 ++++++++++-- LICENSE | 21 +++++++++++++++++++++ package.json | 1 + packaging/aur/PKGBUILD.in | 11 ++++++++--- src-tauri/Cargo.toml | 1 + 5 files changed, 41 insertions(+), 5 deletions(-) create mode 100644 LICENSE diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2f785eb..512380c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -188,7 +188,10 @@ jobs: needs: [prepare, publish] runs-on: ubuntu-latest steps: + # The tag, not main, so the template and the licence are the ones this release shipped. - uses: actions/checkout@v7 + with: + ref: ${{ needs.prepare.outputs.tag }} - name: Render the PKGBUILD for this release env: @@ -199,8 +202,13 @@ jobs: # From the published asset, so the checksum is of the artifact users will actually fetch. curl -fsSL --retry 3 -o package.deb "$URL" SHA=$(sha256sum package.deb | cut -d' ' -f1) - sed -e "s/@VERSION@/$VERSION/g" -e "s/@SHA256@/$SHA/g" packaging/aur/PKGBUILD.in > PKGBUILD - echo "pkgver $VERSION, sha256 $SHA" + # The PKGBUILD fetches the licence from the tag, so checksum the copy at that same tag. + LICENSE_SHA=$(sha256sum LICENSE | cut -d' ' -f1) + sed -e "s/@VERSION@/$VERSION/g" \ + -e "s/@SHA256@/$SHA/g" \ + -e "s/@LICENSE_SHA256@/$LICENSE_SHA/g" \ + packaging/aur/PKGBUILD.in > PKGBUILD + echo "pkgver $VERSION, deb $SHA, licence $LICENSE_SHA" - name: Generate .SRCINFO # makepkg is Arch-only and refuses to run as root, hence the container and the throwaway diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..80d92ee --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 Priyanshu Jain + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/package.json b/package.json index aa1bd38..5365f6a 100644 --- a/package.json +++ b/package.json @@ -2,6 +2,7 @@ "name": "margin-calendar", "private": true, "version": "0.0.1", + "license": "MIT", "type": "module", "scripts": { "dev": "vite", diff --git a/packaging/aur/PKGBUILD.in b/packaging/aur/PKGBUILD.in index 12de25a..f7ea777 100644 --- a/packaging/aur/PKGBUILD.in +++ b/packaging/aur/PKGBUILD.in @@ -13,15 +13,17 @@ pkgrel=1 pkgdesc="A calendar for Google Calendar, where the grid owns the window and the day fits without scrolling" arch=('x86_64') url="https://github.com/priyanshujain/margin-calendar" -license=('custom') +license=('MIT') depends=('webkit2gtk-4.1' 'gtk3') provides=('margin-calendar') conflicts=('margin-calendar') # Prebuilt and already linked: stripping it again buys nothing and risks the binary. options=('!strip' '!debug') -source=("${pkgname}-${pkgver}.deb::${url}/releases/download/v${pkgver}/Margin.Calendar_${pkgver}_amd64.deb") +source=("${pkgname}-${pkgver}.deb::${url}/releases/download/v${pkgver}/Margin.Calendar_${pkgver}_amd64.deb" + "LICENSE-${pkgver}::https://raw.githubusercontent.com/priyanshujain/margin-calendar/v${pkgver}/LICENSE") noextract=("${pkgname}-${pkgver}.deb") -sha256sums=('@SHA256@') +sha256sums=('@SHA256@' + '@LICENSE_SHA256@') package() { bsdtar -xOf "${pkgname}-${pkgver}.deb" data.tar.gz | bsdtar -xf - -C "${pkgdir}" @@ -29,4 +31,7 @@ package() { # copes with that, and nothing that reads it enjoys it. mv "${pkgdir}/usr/share/applications/Margin Calendar.desktop" \ "${pkgdir}/usr/share/applications/margin-calendar.desktop" + # MIT is not one of the licences Arch keeps in /usr/share/licenses/common, so every package + # under it has to carry its own copy. + install -Dm644 "LICENSE-${pkgver}" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE" } diff --git a/src-tauri/Cargo.toml b/src-tauri/Cargo.toml index 8f6f8c6..efdb30c 100644 --- a/src-tauri/Cargo.toml +++ b/src-tauri/Cargo.toml @@ -4,6 +4,7 @@ version = "0.0.1" description = "A calendar for Google Calendar" authors = ["Margin"] edition = "2021" +license = "MIT" [lib] name = "margin_calendar_lib"