Retain vendor notices in Raspberry Pi firmware build outputs #103

Merged
ams-tech merged 1 commit from codex/retain-firmware-build-notices into main 2026-10-03 16:42:41 -04:00
ams-tech commented 2026-10-02 22:32:04 -04:00 (Migrated from github.com)

The EEPROM release and probe-bundle recipes copy Raspberry Pi firmware into new outputs without retaining its vendor licensing materials. Add adjacent notices directories containing the complete upstream texts and a component-to-file map, and expose the probe notices in the provisioning package.

Verify that the frozen probe bootcode is byte-identical to the EEPROM submodule's recovery firmware before assigning its custom firmware terms. Keep Apache-2.0 material separate for usbboot, including a hash-pinned license from the exact revision supplying update-pieeprom.sh. Preserve the original firmware bytes, EEPROM release manifests, and the probe bundle's two-file layout and digest format.

Validation:

  • Built the current 2026-09-12 and historical 2026-05-26 EEPROM release outputs and the probe bundle using the pinned Nixpkgs source.
  • Passed the existing EEPROM release and probe integrity Nix contracts, extended to compare retained license files byte-for-byte and check the provisioning package's notice link.
  • nixfmt and git diff --check passed for all changed files.
  • The published Git tree matches the tested local tree exactly.

The vendor's "without modification" grant still needs clarification before redistributing configured/signed variants. This change retains notices; it does not resolve that permission question. Public v0.1.6 release notices and operational payload retention are handled independently in #102.

The EEPROM release and probe-bundle recipes copy Raspberry Pi firmware into new outputs without retaining its vendor licensing materials. Add adjacent notices directories containing the complete upstream texts and a component-to-file map, and expose the probe notices in the provisioning package. Verify that the frozen probe bootcode is byte-identical to the EEPROM submodule's recovery firmware before assigning its custom firmware terms. Keep Apache-2.0 material separate for usbboot, including a hash-pinned license from the exact revision supplying update-pieeprom.sh. Preserve the original firmware bytes, EEPROM release manifests, and the probe bundle's two-file layout and digest format. Validation: - Built the current 2026-09-12 and historical 2026-05-26 EEPROM release outputs and the probe bundle using the pinned Nixpkgs source. - Passed the existing EEPROM release and probe integrity Nix contracts, extended to compare retained license files byte-for-byte and check the provisioning package's notice link. - nixfmt and git diff --check passed for all changed files. - The published Git tree matches the tested local tree exactly. The vendor's "without modification" grant still needs clarification before redistributing configured/signed variants. This change retains notices; it does not resolve that permission question. Public v0.1.6 release notices and operational payload retention are handled independently in #102.
Sign in to join this conversation.
No description provided.