Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Licensing — technical audit for 1.0

LICENSING DECISION REQUIRED BEFORE PUBLIC v1.0.0 RELEASE.

This page records what a Nazm release and a program it compiles contain, and under which terms each part reaches its recipient, as facts a person can check. It draws no legal conclusion. The repository’s policy does not yet settle whether Apache-2.0, as it stands, is intended for the runtime and standard-library code that ends up inside every compiled program; a human decides that, and the questions are listed at the end. Audited in Gate 1 of the v1 programme, 2026-10-07, at the tree that declares toolchain 1.0.0.

What the repository says

FactWhere
The licence is the full, unmodified Apache License 2.0 textLICENSE (202 lines)
Its appendix’s copyright line is the unfilled template, Copyright [yyyy] [name of copyright owner]; no project copyright line exists elsewhereLICENSE
There is no NOTICE filerepository root
Every workspace crate declares license = "Apache-2.0" through license.workspace = true; publish = falseCargo.toml, crates/*/Cargo.toml, xtask/Cargo.toml
fuzz/Cargo.toml declares no licencefuzz/Cargo.toml
No source file carries a copyright or SPDX header — compiler, runtime generator, standard library or templatescrates/, library/, crates/nazm-cli/templates/
Contributions have no stated terms: no DCO, CLA, sign-off or inbound-equals-outbound clauseCONTRIBUTING.md
The open question is stated, and called a Phase 1 decisionREADME.md (Licence), deny.toml

What a compiled program contains

PartHow it reaches the programSource
The runtimeLLVM IR text generated by the Rust crate nazm-runtime (core.rs, entry.rs, os.rs, switch.rs, board.rs, wasm.rs) and compiled into every native executable by nazm build, together with per-target entry and errno units; or a prebuilt libnazmrt.a from nazm runtime build. The Rust crate itself is not linked into user programsproject code, Apache-2.0
Third-party code in the runtimenone: nazm-runtime’s one dependency, blake3, computes the runtime’s digest at build time and emits nothing into the IR—
The core preludelibrary/core/prelude.nz, compiled into every program (include_str! in the compiler)project code, Apache-2.0
The standard libraryeach library/std/*.nz module a program imports with use "@std/…", compiled into itproject code, Apache-2.0
Generated glueWebAssembly imports, EVM and account-contract scaffolding for the experimental targets; no licence header in any generated outputproject code
Project templatesnazm init copies crates/nazm-cli/templates/{cli,library,server,embedded,wasm,contract} into the user’s directory, with no licence headerproject code
nazm bindgen outputdeclarations derived from the user’s own C headerthe user’s

What the toolchain contains

bin/nazm statically links about 238 third-party crates. Their licence expressions, read from each crate’s manifest for the 261 crates of the R1 SBOM (nazm.sbom/1, which itself records no licence field):

Licence expressionCrates
MIT OR Apache-2.0 (with its spelling variants)157
MIT37
Apache-2.0 WITH LLVM-exception (Cranelift and its family)17
Unlicense OR MIT7
triple, including Apache-2.0 WITH LLVM-exception5
Apache-2.0 only (esaxx-rs, rmcp, spm_precompiled, tokenizers)4
Apache-2.0 OR MIT OR Zlib2
BSD-2-Clause OR Apache-2.0 OR MIT (zerocopy)2
Zlib (foldhash)1
Apache-2.0 OR BSL-1.0 (ryu)1
CC0-1.0 alternatives (blake3, constant_time_eq)2
(MIT OR Apache-2.0) AND Unicode-3.0 (unicode-ident)1
workspace crates (this repository)23

Copyleft: only r-efi (5.3.0 and 6.0.0), as MIT OR Apache-2.0 OR LGPL-2.1-or-later — one option of three. No GPL, AGPL or MPL, and no unknown licence. deny.toml’s allow-list names Apache-2.0 (with and without the LLVM exception), MIT, BSD-2/3-Clause, ISC, Unicode-3.0 and Zlib; Unlicense, BSL-1.0, CC0-1.0 and MIT-0 appear only as alternatives beside one of those. The tokenizer data nazm-tokens records (two MIT, two Apache-2.0) is not embedded in the binary.

What a release archive contains

scripts/release-candidate.sh copies README.md, LICENSE, SECURITY.md and CONTRIBUTING.md beside bin/nazm, bin/nazmc-selfhosted, the documentation, schemas, examples, the compiler written in Nazm, the benchmark and scripts. It contains no third-party licence texts, attribution file, NOTICE or SBOM; the SBOM is in the separate evidence bundle.

What a human must decide

  1. The runtime and standard library in user programs. Whether to add an exception — for example Apache-2.0 WITH LLVM-exception, or a clause of the kind Swift’s runtime carries — so that the generated runtime, libnazmrt.a, the prelude, the standard-library modules and the nazm init templates impose nothing on a compiled program; or to state that Apache-2.0 as it stands is intended for them.
  2. The copyright holder. Fill the copyright line, and decide whether a NOTICE file is wanted.
  3. Contributor terms. DCO, CLA, or inbound-equals-outbound, written into CONTRIBUTING.md.
  4. Third-party notices in the release. Whether the archive carries the licence texts and notices of the crates linked into bin/nazm — in particular the Apache-2.0-only ones and any with a NOTICE of its own — and licence data in the SBOM.
  5. The policy gate. Whether deny.toml names the alternatives it now admits only implicitly, and whether fuzz/Cargo.toml and headers in library/ and generated output are wanted.

Until these are decided, no public 1.0.0 release is made (docs/stability.md, docs/releases/).