Include firmware notices with the public v0.1.6 release #102

Merged
ams-tech merged 1 commit from codex/raspberry-pi-firmware-notices into main 2026-10-03 16:38:49 -04:00
ams-tech commented 2026-10-02 22:25:41 -04:00 (Migrated from github.com)

The public v0.1.6 release distributes four Raspberry Pi EEPROM/recovery firmware binaries without accompanying upstream licensing material. Add the exact rpi-eeprom LICENSE, a per-file origin/hash map, and a link from the release README. Copy the notices into the operational payload beside its manifest and include them in the release SHA256 inventory.

Firmware bytes, signed inputs, the operational manifest, and canonical RPIBOOT directory contents are unchanged. The custom firmware license grants redistribution "without modification"; the notice index records the unresolved permission question for configured/signed variants and does not claim that attribution resolves it.

Validation:

  • Built the operational payload offline with the pinned Nixpkgs source; existing inventory and bundle hash checks passed.
  • Verified all 15 SHA256SUMS entries and byte-compared the built license, EEPROM image, and manifest with the checked-in inputs.
  • Matched the included license to upstream Git blob cdeafb462d; retained upstream whitespace verbatim.
  • nixfmt check passed for nix/packages.nix.
The public v0.1.6 release distributes four Raspberry Pi EEPROM/recovery firmware binaries without accompanying upstream licensing material. Add the exact rpi-eeprom LICENSE, a per-file origin/hash map, and a link from the release README. Copy the notices into the operational payload beside its manifest and include them in the release SHA256 inventory. Firmware bytes, signed inputs, the operational manifest, and canonical RPIBOOT directory contents are unchanged. The custom firmware license grants redistribution "without modification"; the notice index records the unresolved permission question for configured/signed variants and does not claim that attribution resolves it. Validation: - Built the operational payload offline with the pinned Nixpkgs source; existing inventory and bundle hash checks passed. - Verified all 15 SHA256SUMS entries and byte-compared the built license, EEPROM image, and manifest with the checked-in inputs. - Matched the included license to upstream Git blob cdeafb462db4ac43aade488dd8f0c6f4442b6139; retained upstream whitespace verbatim. - nixfmt check passed for nix/packages.nix.
Sign in to join this conversation.
No description provided.