Licensing — technical audit for 1.0
LICENSING DECISION REQUIRED BEFORE PUBLIC v1.0.0 RELEASE.
This page records what a Nazm release and a program it compiles contain, and under which terms each part reaches its recipient, as facts a person can check. It draws no legal conclusion. The repository’s policy does not yet settle whether Apache-2.0, as it stands, is intended for the runtime and standard-library code that ends up inside every compiled program; a human decides that, and the questions are listed at the end. Audited in Gate 1 of the v1 programme, 2026-10-07, at the tree that declares toolchain 1.0.0.
What the repository says
| Fact | Where |
|---|---|
| The licence is the full, unmodified Apache License 2.0 text | LICENSE (202 lines) |
Its appendix’s copyright line is the unfilled template, Copyright [yyyy] [name of copyright owner]; no project copyright line exists elsewhere | LICENSE |
There is no NOTICE file | repository root |
Every workspace crate declares license = "Apache-2.0" through license.workspace = true; publish = false | Cargo.toml, crates/*/Cargo.toml, xtask/Cargo.toml |
fuzz/Cargo.toml declares no licence | fuzz/Cargo.toml |
| No source file carries a copyright or SPDX header — compiler, runtime generator, standard library or templates | crates/, library/, crates/nazm-cli/templates/ |
| Contributions have no stated terms: no DCO, CLA, sign-off or inbound-equals-outbound clause | CONTRIBUTING.md |
| The open question is stated, and called a Phase 1 decision | README.md (Licence), deny.toml |
What a compiled program contains
| Part | How it reaches the program | Source |
|---|---|---|
| The runtime | LLVM IR text generated by the Rust crate nazm-runtime (core.rs, entry.rs, os.rs, switch.rs, board.rs, wasm.rs) and compiled into every native executable by nazm build, together with per-target entry and errno units; or a prebuilt libnazmrt.a from nazm runtime build. The Rust crate itself is not linked into user programs | project code, Apache-2.0 |
| Third-party code in the runtime | none: nazm-runtime’s one dependency, blake3, computes the runtime’s digest at build time and emits nothing into the IR | — |
| The core prelude | library/core/prelude.nz, compiled into every program (include_str! in the compiler) | project code, Apache-2.0 |
| The standard library | each library/std/*.nz module a program imports with use "@std/…", compiled into it | project code, Apache-2.0 |
| Generated glue | WebAssembly imports, EVM and account-contract scaffolding for the experimental targets; no licence header in any generated output | project code |
| Project templates | nazm init copies crates/nazm-cli/templates/{cli,library,server,embedded,wasm,contract} into the user’s directory, with no licence header | project code |
nazm bindgen output | declarations derived from the user’s own C header | the user’s |
What the toolchain contains
bin/nazm statically links about 238 third-party crates. Their licence expressions, read from
each crate’s manifest for the 261 crates of the R1 SBOM (nazm.sbom/1, which itself records no
licence field):
| Licence expression | Crates |
|---|---|
| MIT OR Apache-2.0 (with its spelling variants) | 157 |
| MIT | 37 |
| Apache-2.0 WITH LLVM-exception (Cranelift and its family) | 17 |
| Unlicense OR MIT | 7 |
| triple, including Apache-2.0 WITH LLVM-exception | 5 |
Apache-2.0 only (esaxx-rs, rmcp, spm_precompiled, tokenizers) | 4 |
| Apache-2.0 OR MIT OR Zlib | 2 |
BSD-2-Clause OR Apache-2.0 OR MIT (zerocopy) | 2 |
Zlib (foldhash) | 1 |
Apache-2.0 OR BSL-1.0 (ryu) | 1 |
CC0-1.0 alternatives (blake3, constant_time_eq) | 2 |
(MIT OR Apache-2.0) AND Unicode-3.0 (unicode-ident) | 1 |
| workspace crates (this repository) | 23 |
Copyleft: only r-efi (5.3.0 and 6.0.0), as MIT OR Apache-2.0 OR LGPL-2.1-or-later — one
option of three. No GPL, AGPL or MPL, and no unknown licence. deny.toml’s allow-list names
Apache-2.0 (with and without the LLVM exception), MIT, BSD-2/3-Clause, ISC, Unicode-3.0 and Zlib;
Unlicense, BSL-1.0, CC0-1.0 and MIT-0 appear only as alternatives beside one of those. The
tokenizer data nazm-tokens records (two MIT, two Apache-2.0) is not embedded in the binary.
What a release archive contains
scripts/release-candidate.sh copies README.md, LICENSE, SECURITY.md and
CONTRIBUTING.md beside bin/nazm, bin/nazmc-selfhosted, the documentation, schemas,
examples, the compiler written in Nazm, the benchmark and scripts. It contains no third-party
licence texts, attribution file, NOTICE or SBOM; the SBOM is in the separate evidence bundle.
What a human must decide
- The runtime and standard library in user programs. Whether to add an exception — for
example Apache-2.0 WITH LLVM-exception, or a clause of the kind Swift’s runtime carries — so
that the generated runtime,
libnazmrt.a, the prelude, the standard-library modules and thenazm inittemplates impose nothing on a compiled program; or to state that Apache-2.0 as it stands is intended for them. - The copyright holder. Fill the copyright line, and decide whether a
NOTICEfile is wanted. - Contributor terms. DCO, CLA, or inbound-equals-outbound, written into
CONTRIBUTING.md. - Third-party notices in the release. Whether the archive carries the licence texts and
notices of the crates linked into
bin/nazm— in particular the Apache-2.0-only ones and any with aNOTICEof its own — and licence data in the SBOM. - The policy gate. Whether
deny.tomlnames the alternatives it now admits only implicitly, and whetherfuzz/Cargo.tomland headers inlibrary/and generated output are wanted.
Until these are decided, no public 1.0.0 release is made (docs/stability.md,
docs/releases/).