# Source code offer.

> The Renest floor image contains other people's software, some of it under the GPL, LGPL or MPL. For at least three years from the date an image version is published, we will give anyone who asks the complete corresponding source for any copyleft component in it. This page says how to request it, how to get it yourself, and what we are not claiming.

Canonical page: https://renest.ai/docs-source-offer.html

<h2 id="offer">The offer</h2>

<p>The Renest floor image is a container image we publish so you can restore a nest on a
clean machine. It contains an Ubuntu base system and other third-party binaries. A
number of those are licensed under the <strong>GNU General Public License (GPL)</strong>,
the <strong>GNU Lesser General Public License (LGPL)</strong>, or the
<strong>Mozilla Public License 2.0</strong>. Publishing the image makes us a distributor
of those binaries, and a distributor owes you the corresponding source.</p>

<p>So, plainly: <strong>for at least three years from the date an image version is
published, we will give anyone who asks the complete corresponding source code for any
copyleft component in it</strong>, on a medium customarily used for software interchange,
for no more than what it actually costs us to hand it over. This applies whether you got
the image from us or from someone else.</p>

<p>To request it, email <a href="mailto:support@notify.renest.ai">support@notify.renest.ai</a> and name the
image version — the date tag or the <code>sha256:</code> digest you pulled. Both are
recorded in <code>/opt/renest/versions.env</code> inside the image.</p>

<h2 id="covered">What it covers, exactly</h2>

<p>The exact set of packages depends on the image version, so we do not hand-write a list
here that would go stale. Every published image carries its own inventory, generated from
the image itself:</p>

<ul>
  <li><code>/usr/share/doc/renest-floor/licenses/ubuntu/gpl-packages.txt</code> — package name and version for every
      installed package whose copyright file references the GPL or LGPL</li>
  <li><code>/usr/share/doc/renest-floor/licenses/ubuntu/packages.txt</code> — every installed package and version</li>
  <li><code>/usr/share/doc/renest-floor/licenses/gpl/</code> — the full GPL and LGPL texts</li>
  <li><code>/usr/share/doc/renest-floor/licenses/python-deps/index.txt</code> — the Python packages in the Renest
      CLI's own isolated environment, with their declared licences</li>
  <li><code>/usr/share/doc/renest-floor/NOTICE</code> — the full component inventory</li>
</ul>

<p>That GPL list is deliberately over-inclusive: it is produced by matching the text of
each package's copyright file, so a package that merely mentions the GPL is listed too.
We would rather offer source for more than we owe than miss something. Each published
image also ships an SPDX software bill of materials alongside it. If the two ever
disagree, treat the union as covered and tell us.</p>

<h2 id="yourself">You do not have to wait for us</h2>

<p>The packages come from the Ubuntu archive, which publishes the corresponding source for
everything it ships:</p>

<ul>
  <li><code>https://archive.ubuntu.com/ubuntu/</code></li>
  <li><code>https://ports.ubuntu.com/ubuntu-ports/</code></li>
</ul>

<p>For a package named in <code>gpl-packages.txt</code>, the source is the matching entry
in the archive's Sources index for Ubuntu 22.04 (jammy), including the
<code>-updates</code> and <code>-security</code> pockets, at the exact version recorded in
that file. With the archive configured,
<code>apt-get source &lt;package&gt;=&lt;version&gt;</code> fetches it.</p>

<p>Pointing you at the archive is a convenience, not a substitute for the offer above.
Upstream archives reorganise and drop old versions; the offer is ours to honour either
way.</p>

<h2 id="notopen">What this page is not</h2>

<p>It is not a claim that the floor image is open-source software — the genuinely open parts of Renest are the format specification and the escape hatch, and this image is neither of those. The image is a mixture
of licences with no single one describing it, so its metadata records
<code>org.opencontainers.image.licenses = NOASSERTION</code> — meaning "no single licence
expression describes this artifact", not "no licence applies".</p>

<p>The Renest command-line tool itself is <strong>source-available, not open source</strong>:
you can read it and redistribute it, but it is not licensed for building a competing
hosted service on, and this offer does not cover it. Its terms travel with it at
<code>/usr/share/doc/renest-floor/licenses/renest-cli/</code>.</p>

<p>The genuinely open-source parts of Renest are the archive format specification and the
escape-hatch restore script. Those are Apache-2.0 and always will be — they are the
evidence behind the claim that you are not locked in.</p>
