Files
kernalix7--winpodx/THIRD_PARTY_LICENSES.md
T
wehub-resource-sync 3e779be6f3
CI / lint (push) Failing after 13m4s
CI / test (3.11, ubuntu-latest) (push) Failing after 2m4s
CI / test (3.13, ubuntu-latest) (push) Successful in 13m30s
CI / test (3.14, ubuntu-latest) (push) Successful in 17m21s
CI / test (3.12, ubuntu-latest) (push) Successful in 17m55s
CI / discover-apps-ps (push) Successful in 1m56s
CI / test (3.9, ubuntu-latest) (push) Successful in 13m17s
CI / test (3.10, ubuntu-latest) (push) Successful in 26m21s
CI / audit (push) Successful in 13m38s
Deploy site / deploy (push) Has been cancelled
CI / test (3.14, ubuntu-24.04-arm) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:32:37 +08:00

6.6 KiB

Third-Party Licenses

WinPodX is MIT-licensed (see LICENSE). This document lists the third-party components redistributed inside the source tree or pulled in as runtime/optional dependencies, together with their upstream licenses.

Bundled binaries

rdprrap

  • Upstream: https://github.com/kernalix7/rdprrap
  • Version: 0.3.0 (pinned by config/oem/rdprrap_version.txt, SHA256-verified)
  • License: MIT
  • Bundled as: config/oem/rdprrap-0.3.0-windows-x64.zip
  • Role: enables multi-session RDP on the Windows guest during first-boot OEM install. Same copyright holder as WinPodX.

rdprrap's own source tree ports code from three upstream projects whose licenses require attribution / license-text redistribution. The bundled ZIP therefore ships:

  • LICENSE — rdprrap's own MIT terms.
  • NOTICE — names each upstream project and lists the rdprrap source files derived from it: stascorp/rdpwrap (Apache-2.0), llccd/TermWrap (MIT), llccd/RDPWrapOffsetFinder (MIT).
  • vendor/licenses/ — verbatim copies of the three upstream license texts.
  • THIRD_PARTY_LICENSES.txt — compiled Rust-dependency attributions, auto-generated from the crate graph.

WinPodX redistributes the ZIP unmodified. All four attribution files are extracted into the Windows guest at first-boot install time (C:\Program Files\RDP Wrapper\ and C:\winpodx\rdprrap\), which is where the binaries live and is the redistribution surface that the upstream licenses govern.

Historical note. WinPodX 0.1.6 bundled rdprrap 0.1.0, which upstream later withdrew because the 0.1.0 / 0.1.1 ZIPs were missing NOTICE and vendor/licenses/. 0.1.7 onward bundles 0.1.3 and is the first license-compliant WinPodX release for this component. WinPodX 0.8.0 bumps the bundled component to rdprrap 0.3.0 (same MIT terms, same copyright holder; 0.3.0 derives the termsrv.dll patch sites dynamically).

rcedit

  • Upstream: https://github.com/electron/rcedit
  • License: MIT (Copyright (c) 2013 GitHub Inc.)
  • Bundled as: config/oem/reverse-open/shim/bin/rcedit.exe
  • Role: patches PE metadata on the per-app reverse-open shim during OEM install. LICENSE-rcedit.txt ships beside the binary in the same directory.

winpodx-reverse-open-shim

  • Own code (config/oem/reverse-open/shim/, Cargo.toml declares MIT).
  • License: MIT (same as WinPodX).
  • Bundled as: config/oem/reverse-open/shim/bin/winpodx-reverse-open-shim.exe
  • Role: stub Windows Explorer invokes from "Open with" to relay a file-open request back to the host's reverse-open listener.

Runtime dependency (always required)

Package License When Notes
tomli MIT Python 3.9 / 3.10 only Back-fills stdlib tomllib (3.11+). Pure Python.

Optional dependencies (only installed with matching extras)

Package License Extra Linkage
PySide6 LGPL-3.0-or-later (with Qt for Python FAQ exceptions) winpodx[gui] Dynamic — imported at runtime. Not redistributed by WinPodX.
docker (docker-py) Apache-2.0 winpodx[docker] Dynamic — imported at runtime.
pyxdg LGPL-2.0-or-later (none — soft optional) Dynamic — try-imported at runtime by core/reverse_open/mime.py for the long-tail MIME→extension fallback when a type isn't in the curated 86-entry table. WinPodX works without it (fallback simply returns the curated entry only). Not vendored.

LGPL compliance: WinPodX does not statically link, vendor, or redistribute the PySide6 binaries. Users install them from PyPI (or their distro) at their own discretion; the LGPL reverse-engineering / replacement rights are preserved because the libraries remain swappable at the Python import level.

Development-only dependencies (winpodx[dev])

Package License
pytest MIT
ruff MIT
pip-audit Apache-2.0
hatchling (build backend) MIT

Dev dependencies are not shipped in the wheel / sdist / distro packages.

Fat AppImage release artifact (DOES redistribute the components below)

The source tree, wheel, .deb, and .rpm do not vendor FreeRDP / Podman / Qt / Python — they are runtime dependencies the host provides (see the next section). The fat AppImage release artifact is the exception: since v0.5.8, winpodx-fat-x86_64.AppImage bundles, for self-contained operation on immutable distros:

  • Python 3.11 (astral-sh python-build-standalone) — PSF
  • PySide6 / Qt6 — LGPL-3.0 (dynamically loaded; the AppImage SquashFS is user-extractable via --appimage-extract, satisfying LGPL relinking)
  • Pillow (HPND), cairosvg (LGPL-3.0), pyxdg (LGPL-2.0)
  • FreeRDP (xfreerdp / wlfreerdp / sdl-freerdp) — Apache-2.0
  • Podman, conmon, crun, netavark, slirp4netns, passt — Apache-2.0
  • podman-compose — GPL-2.0, invoked by WinPodX as a separate executable via subprocess (mere aggregation under GPLv2 §2 — WinPodX itself stays MIT; the GPL does not reach across the exec boundary)

Each bundled component's license + NOTICE text is shipped inside the AppImage at usr/share/doc/winpodx/third-party/, alongside WinPodX's own LICENSE and this file at usr/share/doc/winpodx/. A GPL-2.0 source offer for podman-compose is included there too. The CI build step that collects these is in .github/workflows/appimage-publish.yml.

Runtime system dependencies (not vendored)

Installed by install.sh via the host's package manager, or by the user (this is the default for the wheel / .deb / .rpm / curl install — only the fat AppImage above bundles them):

  • FreeRDP 3+ — Apache-2.0
  • Podman / Docker — Apache-2.0 / Apache-2.0
  • Microsoft Windows — EULA-governed; the user supplies their own license via the dockur/windows image, which WinPodX pulls at setup time.
  • dockur/windows container image — MIT (https://github.com/dockur/windows). WinPodX orchestrates but does not redistribute this image.

Reference projects (inspiration only, no code redistributed)

  • winapps (https://github.com/winapps-org/winapps) — independent predecessor that also wraps FreeRDP RemoteApp. WinPodX's CLI shape and .cproc tracking concepts are compatible with winapps configuration conventions for migration, but WinPodX does not copy winapps source code.
  • LinOffice — concept reference only; no source derivation.

If you find any attribution gap, please open an issue.