e0bc4785e9
Flashes the diskOS custom UI onto the FiiO Snowsky Disc over Ingenic mask-ROM USB, building the image from your own stock firmware. Runs from source via install.sh.
136 lines
9.1 KiB
Markdown
136 lines
9.1 KiB
Markdown
# diskOS installer - third-party components & licenses
|
|
|
|
The diskOS installer ships the third-party programs and libraries below. Each is invoked as a
|
|
separate program or loaded as a library; this document provides the required attribution and points
|
|
to the corresponding source that ships alongside the binaries. The full verbatim license texts are in
|
|
[`licenses/`](licenses/); this file is the component-to-license index.
|
|
|
|
## Bundled native programs (called as subprocesses - mere aggregation)
|
|
|
|
| Component | Purpose | License | Source |
|
|
|---|---|---|---|
|
|
| **usbboot** | Ingenic X2000 mask-ROM USB loader (the flasher front-end) | **GPL-2.0-or-later** - © 2021 Aidan MacDonald, © 2015 Amaury Pouly | included: `src/usbboot/` (built from this) |
|
|
| **mksquashfs / unsquashfs** (squashfs-tools **4.6.1**) | build/extract the rootfs image | **GPL-2.0** | https://github.com/plougher/squashfs-tools (v4.6.1) |
|
|
| **dropbearmulti** (Dropbear SSH **2022.83**) | embedded in the diskOS image; started by the opt-in Debug Mode for SSH-over-WiFi | **MIT-style** (© 2002-2020 Matt Johnston; components under MIT/BSD/public-domain) - text in `licenses/LICENSE-dropbear.txt` | https://matt.ucc.asn.au/dropbear/dropbear.html (v2022.83; **predates the CVE-2023-48795 "Terrapin" Strict-KEX mitigation - an update is planned**. Debug Mode SSH is opt-in and short-lived, and Dropbear's Terrapin exposure is limited.) |
|
|
|
|
`usbboot` and squashfs-tools are **GPL-2.0**, so anyone redistributing them must make their
|
|
corresponding source available and include the GPL-2.0 license text. (`dropbearmulti` is MIT-style -
|
|
no source-availability obligation, only its license text as noted above.) **The complete
|
|
corresponding source ships in-tree and in every release tarball**, so it travels from the same place
|
|
as the binaries (GPL-2.0 §3(a), plus the "same place" provision in §3's final paragraph):
|
|
`usbboot`'s own source is `src/usbboot/usbboot.c`;
|
|
**squashfs-tools 4.6.1** source is `corresponding-source/squashfs-tools_4.6.1*`. Both are rebuilt by
|
|
`build/build-usbboot-static.sh` / `build/build-squashfs-static.sh`.
|
|
|
|
**Static linking (Linux):** the prebuilt Linux `usbboot`, `mksquashfs`, and `unsquashfs` are shipped
|
|
**fully statically linked** (built with `gcc -static` on a glibc host). They therefore statically
|
|
incorporate:
|
|
- **libusb-1.0.27 (LGPL-2.1)** - in `usbboot`
|
|
- **liblzo2 2.10 (GPL-2.0-or-later)**, **zlib**, **liblzma** (permissive) - in squashfs-tools
|
|
- the **GNU C Library (glibc, LGPL-2.1-or-later)** - the host's system C runtime, in all three
|
|
|
|
Because liblzo2 is GPL, the resulting `mksquashfs`/`unsquashfs` binaries are effectively GPL-2.0. The
|
|
corresponding source for the statically-linked **GPL/LGPL** libraries is provided so their §3/§6
|
|
obligations are met:
|
|
- **liblzo2** (`corresponding-source/lzo2_2.10*`) and **libusb-1.0** (`corresponding-source/libusb-1.0_1.0.27*`)
|
|
ship in-tree.
|
|
- **glibc** (statically linked, so it travels inside the binary): the **complete corresponding source**
|
|
is vendored in `corresponding-source/glibc_2.39*` (the exact version the shipped binaries were built
|
|
against). Because it is statically linked it does not qualify for the "system library" exception, so
|
|
its source ships alongside the binaries like the others.
|
|
|
|
**Relink path (satisfies LGPL-2.1 §6 for libusb *and* glibc):** we ship the **complete source** of
|
|
`usbboot` (`src/usbboot/usbboot.c`) and squashfs-tools (`corresponding-source/squashfs-tools_4.6.1*`)
|
|
plus the exact build recipes (`build/build-usbboot-static.sh`, `build/build-squashfs-static.sh`). A
|
|
user can therefore rebuild and relink these tools against a **modified** libusb, liblzo2, **or glibc**
|
|
of their choosing - the freedom §6 exists to protect. See
|
|
[`corresponding-source/README.md`](corresponding-source/README.md).
|
|
|
|
**Python runtime + libraries - NOT redistributed by this project.** The installer runs **from
|
|
source** with **your own Python**. The two Python dependencies (`pyusb`, `pycryptodome`) are fetched
|
|
from PyPI by *your* `pip` into a local `.venv` (created by `./install.sh`); CPython, `tkinter`, and
|
|
their transitive native libraries (OpenSSL, Tk/Tcl, the X11 stack, freetype, fontconfig, zlib, etc.)
|
|
all come from **your system's Python** - this project ships none of them, so their redistribution
|
|
notices are not our obligation. Their license texts (for reference) are still listed in
|
|
[`licenses/README.md`](licenses/README.md).
|
|
|
|
> If you instead build a self-contained PyInstaller onefile yourself (`build/build.sh`), *that*
|
|
> binary embeds CPython + ~90 native libraries and you become the redistributor of them - see
|
|
> [`licenses/THIRD_PARTY_BUNDLED.md`](licenses/THIRD_PARTY_BUNDLED.md) for the enumeration and
|
|
> obligations. The **published release does not do this**; it distributes source + the native flash
|
|
> tools below.
|
|
|
|
## Bundled device blobs
|
|
|
|
| Component | Purpose | Notes |
|
|
|---|---|---|
|
|
| **my_write5_dram.bin** | the bad-block-aware DRAM NAND writer run on-device | diskOS project code - source: `flash/my_write5.c` |
|
|
| **disc_spl_lpddr3.bin** | Ingenic X2000 USB stage-1 SPL (DRAM init) | **GPL-2.0** - built from source: Ingenic-community/uboot-xburst `1060b516` + our LPDDR3 patches. Corresponding source in `spl-src/`; see `SPL_SOURCE.md`. (No vendor/USBCloner binary is redistributed.) |
|
|
|
|
## Python dependencies (fetched by your pip, not redistributed by us)
|
|
|
|
`./install.sh` installs these from PyPI into a local `.venv`; **CPython** comes from your own system
|
|
Python. This project does not ship any of them, so their license texts are listed here only for
|
|
reference. (**PyInstaller** is used *only* if you build the optional onefile yourself; it is not
|
|
involved in the source release.)
|
|
|
|
| Component | License |
|
|
|---|---|
|
|
| **pyusb** (USB device detection) | BSD-3-Clause |
|
|
| **pycryptodome** (AES-decrypt of FiiO OTA chunks) | BSD-2-Clause + public-domain (Unlicense) |
|
|
| **CPython** (your system's) | Python Software Foundation License |
|
|
| **PyInstaller** runtime bootloader (only for a self-built onefile) | GPL-2.0 **with a bootloader exception** permitting distribution of the packaged app under any license |
|
|
|
|
## Bundled shared libraries (macOS build)
|
|
|
|
| Component | License |
|
|
|---|---|
|
|
| **libusb-1.0** (bundled next to usbboot on macOS) | LGPL-2.1 |
|
|
|
|
## diskOS's own code
|
|
|
|
- **The Python installer, build scripts, and docs** in this repo are licensed **MIT** -
|
|
`Copyright (c) 2026 diskOS contributors`. See `LICENSE`.
|
|
- **The diskOS UI (`payload/mq_ui`)** ships as a **binary-only** component (static-musl, MIPS): its
|
|
source is not yet published and it is **not** covered by the MIT license above.
|
|
|
|
**diskOS UI Binary License:** *You may use and redistribute the `mq_ui` binary verbatim - on its own
|
|
or as part of the diskOS installer - free of charge. It is provided **AS IS, without warranty of any
|
|
kind**. Its source is not published, and no right to modify, decompile, or reverse-engineer it is
|
|
granted. The embedded third-party components below retain their own licenses.* © 2026 the diskOS
|
|
author (alias **b0hemia**).
|
|
|
|
It statically incorporates these third-party components, whose licenses apply to the shipped binary:
|
|
|
|
| Embedded in `mq_ui` | License | Text / source |
|
|
|---|---|---|
|
|
| **musl libc** (static C runtime) | MIT | `licenses/MIT-musl.txt`; source: https://musl.libc.org/ |
|
|
| **LVGL** (UI toolkit) | MIT | `licenses/MIT-LVGL.txt` |
|
|
| **JSMN** (JSON parser) | MIT | `licenses/MIT-JSMN.txt` |
|
|
| **SQLite** (amalgamation) | Public domain | https://sqlite.org/copyright.html |
|
|
| **MD5** (Peslyak/Solar Designer) | Public domain | in the (unpublished) UI source |
|
|
| **QR Code generator** (Nayuki `qrcodegen`) | MIT | `licenses/MIT-qrcodegen.txt` |
|
|
| **TJpgDec** (tiny JPEG decoder, via LVGL) | BSD-style (ChaN) | `licenses/LICENSE-TJpgDec.txt` |
|
|
| **Montserrat** font (via LVGL built-in fonts) | SIL OFL 1.1 | `licenses/OFL-1.1-Montserrat.txt` |
|
|
| **Source Han Sans SC** (CJK fallback font, subset) | SIL OFL 1.1 | `licenses/OFL-1.1-SourceHanSans.txt` |
|
|
| **Font Awesome Free** glyphs (via LVGL `LV_SYMBOL_*`) | OFL 1.1 (fonts) + CC-BY 4.0 (icons) | `licenses/OFL-1.1-FontAwesome.txt`, `licenses/CC-BY-4.0.txt` |
|
|
|
|
## NOT distributed by this installer
|
|
|
|
- **FiiO's stock rootfs** - you supply your own official firmware; the installer only reads it locally
|
|
and never redistributes it.
|
|
- **ffmpeg** - used at runtime for album-art decoding, but it is part of FiiO's stock firmware already
|
|
on the device (`/usr/bin/ffmpeg`); the installer does **not** ship it.
|
|
|
|
---
|
|
|
|
### Compliance checklist (done)
|
|
- ✅ Full license texts shipped in [`licenses/`](licenses/) (GPL-2.0, LGPL-2.1, BSD, PSF, LVGL-MIT,
|
|
dropbear, Font Awesome OFL/CC-BY) - see [`licenses/README.md`](licenses/README.md).
|
|
- ✅ diskOS installer license stated: **MIT** (`LICENSE`). The `mq_ui` binary is documented as
|
|
binary-only (source unpublished, not MIT) with its embedded LVGL/JSMN/Font Awesome notices shipped.
|
|
- ✅ Exact upstream versions pinned and their **complete corresponding source shipped in-tree** for the
|
|
GPL/LGPL native binaries: squashfs-tools 4.6.1, liblzo2 2.10, libusb-1.0 1.0.27, the SPL, and
|
|
usbboot - in [`corresponding-source/`](corresponding-source/) and [`spl-src/`](spl-src/). Source
|
|
travels from the same place as the binaries; no separate written offer is needed.
|