# Third-party notices for the Mac test build

Prepared 2026-10-04 for REQ-0068. This file records observed dependencies and
the included notice texts. It is not a declaration that public redistribution
of the complete product has been cleared.

## Product and release boundary

The gateway itself retains its separate `Gateway-LICENSE` / source
`docs/LICENSE`. Its personal-learning / reserved-rights terms are not replaced
by the permissive licences below. Obtain the gateway rightsholder's permission
before publishing a download. The supplied Python runtime's complete build
provenance also remains to be confirmed before a public release.

The application adds a native launcher and a frozen Python supervisor around
the gateway. This project has not edited CPython or the third-party library
source code. PyInstaller collects runtime files and adjusts binary loading
paths; this is not an assertion about changes made by the original runtime
supplier. No endorsement by dependency authors is implied.

## Components and evidence

| Component | Observed version / basis | Included text |
| --- | --- | --- |
| CPython | Bundled interpreter reports 3.12.14; licence copied from its own `lib/python3.12/LICENSE.txt` | `Python-LICENSE.txt` |
| CPython incorporated components | Supplemental notices from the official CPython 3.12 branch; not a binary-matched bill of materials | `CPython-Third-Party-Licenses.rst` |
| OpenSSL | Runtime `ssl.OPENSSL_VERSION` reports 3.5.8 | `OpenSSL-LICENSE.txt` (Apache 2.0, official 3.5.8 tag) |
| SQLite | Runtime `sqlite3.sqlite_version` reports 3.53.1 | `SQLite-LICENSE.md` (official repository's public-domain explanation) |
| Expat | Runtime `pyexpat.EXPAT_VERSION` reports 2.8.3 | `Expat-COPYING.txt` (official R_2_8_3 tag) |
| mpdecimal | Runtime `decimal.__libmpdec_version__` reports 4.0.0 | `mpdecimal-COPYRIGHT.txt` |
| bzip2 / libbzip2 | `_bz2` is built in; binary contains `1.0.8, 13-Jul-2019` | `bzip2-LICENSE.txt` (official 1.0.8 source archive) |
| XZ / liblzma | `_lzma` is built in; binary contains `5.8.3`, a version inference rather than complete build evidence | `XZ-COPYING.txt`, `XZ-COPYING.0BSD.txt` (official v5.8.3 tag) |
| libffi | `_ctypes` is built in; no external libffi appears in the binary's dynamic dependencies; exact version unconfirmed | `libffi-LICENSE.txt` (current official licence, not a verified version match) |
| Go runtime / standard library | Gateway built with the project's verified Go 1.27.1 toolchain | `Go-LICENSE.txt`, `Go-PATENTS.txt` (copied from that toolchain) |

The separate generated application notice directory also includes licences
for PyInstaller (including its bootloader exception), certifi, and the
recorded packaging tools. Their presence does not mean every build-time tool
is shipped as executable code. Preserve those notices with this directory.

macOS `otool -L` identifies system-provided zlib, libedit, ncurses, panel,
libSystem, CoreFoundation and SystemConfiguration dependencies. This build
references Apple's system copies rather than redistributing those dylibs.
The CPython supplementary notice contains a zlib attribution as well.
This software includes code from XZ Utils <https://tukaani.org/xz/>.

## Source locations

- CPython supplemental notices: <https://github.com/python/cpython/blob/3.12/Doc/license.rst>, section “Licenses and Acknowledgements for Incorporated Software”. The upstream describes this list as incomplete; it is retained as a supplement, not as a replacement for build-specific notices.
- OpenSSL: <https://github.com/openssl/openssl/blob/openssl-3.5.8/LICENSE.txt>. The root `NOTICE` lookup returned 404 for this tag; this does not audit every source subdirectory.
- Expat: <https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/COPYING>.
- XZ: <https://github.com/tukaani-project/xz/blob/v5.8.3/COPYING> and <https://github.com/tukaani-project/xz/blob/v5.8.3/COPYING.0BSD>.
- libffi: <https://github.com/libffi/libffi/blob/master/LICENSE>, retrieved 2026-10-04. Runtime version and exact matching revision remain unknown.
- bzip2: <https://sourceware.org/pub/bzip2/bzip2-1.0.8.tar.gz>, member `bzip2-1.0.8/LICENSE`.
- mpdecimal: <https://www.bytereef.org/software/mpdecimal/releases/mpdecimal-4.0.0.tar.gz>, member `mpdecimal-4.0.0/COPYRIGHT.txt`. The complete licence member was returned, but the overall archive transfer subsequently timed out. The archive itself was not retained or integrity-verified; obtain the original runtime's build manifest or re-fetch the archive before claiming complete provenance.
- SQLite: <https://github.com/sqlite/sqlite/blob/master/LICENSE.md> and <https://www.sqlite.org/copyright.html>. This explains the upstream library's public-domain status, not the gateway's terms.
- Go: <https://go.dev/LICENSE> and <https://go.dev/PATENTS>; included copies come from the actual local toolchain.

## Still unconfirmed / publication gate

The installed Python runtime has no complete dependency manifest or source
archive in its distribution directory. Version strings and dynamic-link
inspection do not prove the exact source revision, all static objects,
compiler patches, or full licence coverage. In particular, confirm libffi,
liblzma and any additional incorporated CPython components against the
runtime supplier's bill of materials, and retain their applicable notices.
If that evidence cannot be obtained, rebuild the runtime from pinned,
documented source dependencies before public distribution. Do not relabel this
test candidate as fully audited, signed/notarized, or commercially cleared.
