From 1a970eef918d3fb7a9be25d5bcdf5114ded66fba Mon Sep 17 00:00:00 2001 From: Filip Leonarski Date: Wed, 7 Oct 2026 21:21:18 +0200 Subject: [PATCH] docs: regenerate THIRD_PARTY_NOTICES.md (Mbed TLS replaces curl, XDS plugin note) Generated from the root file by the update_version.sh step, which otherwise runs only on a version bump; the published copy still listed libcurl. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/THIRD_PARTY_NOTICES.md | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/docs/THIRD_PARTY_NOTICES.md b/docs/THIRD_PARTY_NOTICES.md index e1d49fb17..39536b178 100644 --- a/docs/THIRD_PARTY_NOTICES.md +++ b/docs/THIRD_PARTY_NOTICES.md @@ -35,21 +35,20 @@ linked into the Jungfraujoch executables. | [Abseil](https://github.com/abseil/abseil-cpp) | 20250127 (required by Ceres) | Google Inc. | Apache-2.0 | [abseil.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/abseil.txt) | | [fast-feedback-indexer](https://github.com/paulscherrerinstitute/fast-feedback-indexer) | (pinned) | PSI | BSD-3-Clause | [fast-feedback-indexer.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/fast-feedback-indexer.txt) | | [libjpeg-turbo](https://github.com/libjpeg-turbo/libjpeg-turbo) | 3.2.0 | D. R. Commander and others; IJG | IJG + BSD-3-Clause + Zlib | [libjpeg-turbo.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/libjpeg-turbo.txt) | -| [curl](https://github.com/curl/curl) | 8.22.0 | Daniel Stenberg and contributors | curl (MIT-like) | [curl.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/curl.txt) | +| [Mbed TLS](https://github.com/Mbed-TLS/mbedtls) (with TF-PSA-Crypto) | 4.2.0 | The Mbed TLS Contributors | Apache-2.0 OR GPL-2.0-or-later (used under Apache-2.0) | [mbedtls.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/mbedtls.txt), [tf-psa-crypto.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/tf-psa-crypto.txt) | | [Catch2](https://github.com/catchorg/Catch2) | 3.16.0 | Catch2 Authors | BSL-1.0 | [catch2.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/catch2.txt) | | [zlib-ng](https://github.com/zlib-ng/zlib-ng) | 2.3.3 | Jean-loup Gailly and Mark Adler; the zlib-ng contributors | Zlib | [zlib.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/zlib.txt) | | [Eigen](https://gitlab.com/libeigen/eigen) | 3.4.1 | Benoit Jacob, Gael Guennebaud and contributors | MPL-2.0 (+ BSD parts) | [eigen.txt](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/eigen.txt), [README](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/licenses/eigen-README.txt) | -libcurl is fetched and statically linked only for viewer builds (`JFJOCH_VIEWER_BUILD` / -`JFJOCH_VIEWER_ONLY`), where it is `jfjoch_viewer`'s HTTP client; the broker and writer never link -it. Its TLS and Kerberos backends are the OS-native ones (Schannel/SSPI on Windows, OpenSSL and -system krb5 on Linux), so no TLS stack is vendored with it. +Mbed TLS is fetched and statically linked only for viewer builds (`JFJOCH_VIEWER_BUILD` / +`JFJOCH_VIEWER_ONLY`), where it is the TLS backend of `jfjoch_viewer`'s cpp-httplib client; the +broker and writer never link it. Catch2 is used only to build the test binary (`jfjoch_test`) and is not part of any shipped artifact; it is listed here for completeness. zlib is supplied by zlib-ng built in its zlib-compatible mode (same `zlib.h`, same API and symbol -names), so it is the zlib that HDF5, libtiff, cpp-httplib, libcurl and GEMMI all link. It is +names), so it is the zlib that HDF5, libtiff, cpp-httplib and GEMMI all link. It is built during the configure rather than added as a subproject; the licence is the zlib licence either way. Eigen is header-only: only its headers reach the binaries, and no Eigen CMake runs. @@ -118,6 +117,11 @@ served frontend, so the shipped web UI carries its own attribution. sphere manifold for the crystal refinement, following its source. Both files name the origin at the top and are covered by `licenses/ceres-solver.txt`. * **FFTW** is GPL-2.0-or-later — compatible with, and absorbed by, this project's GPL-3.0 license. + It is never linked into the XDS plugin, which `LICENSE` allows to be linked with the closed-source + XDS only while it holds no third-party GPL code. +* **XDS plugin**: ships as an archive of its own, with only the notices of what it links (HDF5, + zlib-ng, Zstandard, LZ4, Bitshuffle, Bitshuffle h-perf) — see + [`xds-plugin/THIRD_PARTY_NOTICES.md`](https://gitea.psi.ch/mx/jungfraujoch/src/branch/main/xds-plugin/THIRD_PARTY_NOTICES.md). * **Apache-2.0** components: where upstream ships a `NOTICE` file, it is reproduced in the corresponding `licenses/` text. * **Qt (LGPL-3.0)** and **NVIDIA CUDA (EULA)** carry redistribution conditions beyond a copyright