renest 0.1.15

Concepts

Source code offer.

The Renest floor image contains other people's software, some of it under the GPL, LGPL or MPL. For at least three years from the date an image version is published, we will give anyone who asks the complete corresponding source for any copyleft component in it. This page says how to request it, how to get it yourself, and what we are not claiming.

The offer

The Renest floor image is a container image we publish so you can restore a nest on a clean machine. It contains an Ubuntu base system and other third-party binaries. A number of those are licensed under the GNU General Public License (GPL), the GNU Lesser General Public License (LGPL), or the Mozilla Public License 2.0. Publishing the image makes us a distributor of those binaries, and a distributor owes you the corresponding source.

So, plainly: for at least three years from the date an image version is published, we will give anyone who asks the complete corresponding source code for any copyleft component in it, on a medium customarily used for software interchange, for no more than what it actually costs us to hand it over. This applies whether you got the image from us or from someone else.

To request it, email support@notify.renest.ai and name the image version — the date tag or the sha256: digest you pulled. Both are recorded in /opt/renest/versions.env inside the image.

What it covers, exactly

The exact set of packages depends on the image version, so we do not hand-write a list here that would go stale. Every published image carries its own inventory, generated from the image itself:

  • /usr/share/doc/renest-floor/licenses/ubuntu/gpl-packages.txt — package name and version for every installed package whose copyright file references the GPL or LGPL
  • /usr/share/doc/renest-floor/licenses/ubuntu/packages.txt — every installed package and version
  • /usr/share/doc/renest-floor/licenses/gpl/ — the full GPL and LGPL texts
  • /usr/share/doc/renest-floor/licenses/python-deps/index.txt — the Python packages in the Renest CLI's own isolated environment, with their declared licences
  • /usr/share/doc/renest-floor/NOTICE — the full component inventory

That GPL list is deliberately over-inclusive: it is produced by matching the text of each package's copyright file, so a package that merely mentions the GPL is listed too. We would rather offer source for more than we owe than miss something. Each published image also ships an SPDX software bill of materials alongside it. If the two ever disagree, treat the union as covered and tell us.

You do not have to wait for us

The packages come from the Ubuntu archive, which publishes the corresponding source for everything it ships:

  • https://archive.ubuntu.com/ubuntu/
  • https://ports.ubuntu.com/ubuntu-ports/

For a package named in gpl-packages.txt, the source is the matching entry in the archive's Sources index for Ubuntu 22.04 (jammy), including the -updates and -security pockets, at the exact version recorded in that file. With the archive configured, apt-get source <package>=<version> fetches it.

Pointing you at the archive is a convenience, not a substitute for the offer above. Upstream archives reorganise and drop old versions; the offer is ours to honour either way.

What this page is not

It is not a claim that the floor image is open-source software — the genuinely open parts of Renest are the format specification and the escape hatch, and this image is neither of those. The image is a mixture of licences with no single one describing it, so its metadata records org.opencontainers.image.licenses = NOASSERTION — meaning "no single licence expression describes this artifact", not "no licence applies".

The Renest command-line tool itself is source-available, not open source: you can read it and redistribute it, but it is not licensed for building a competing hosted service on, and this offer does not cover it. Its terms travel with it at /usr/share/doc/renest-floor/licenses/renest-cli/.

The genuinely open-source parts of Renest are the archive format specification and the escape-hatch restore script. Those are Apache-2.0 and always will be — they are the evidence behind the claim that you are not locked in.

These docs describe renest 0.1.15, the latest release.

Open format

The docs describe a format you own.

Everything here is written against the open nest format. Every nest ships a plain restore.sh that brings back its files and dependencies with zero Renest code.