Third-Party Notices
===================

This project vendors a minimal set of third-party source files under
`third_party/` to provide the ZIP, RAR and 7z extraction features (the
`/api/extract` endpoint). Their full license texts are included
alongside the sources.

1. minizip-ng
   -----------
   Version : 4.2.2
   Source  : https://github.com/zlib-ng/minizip-ng
   License : zlib (see third_party/minizip-ng/LICENSE)
   Files   : third_party/minizip-ng/** (vendored subset, compiled with
             relaxed warnings into the final binary)

2. zlib
   ------
   Version : 1.3.1
   Source  : https://www.zlib.net/
   License : zlib (see third_party/zlib/LICENSE)
   Files   : third_party/zlib/** (vendored subset, compiled with relaxed
             warnings into the final binary)

3. unrar (rarlab UnRAR source, v7.20.1)
   -------------------------------------
   Version : 7.20.1 (RAR 7.23-free source snapshot, 2025-10-28)
   Source  : https://www.rarlab.com/rar_add.htm — mirrored by
             https://github.com/opello/unrar (commit 97e1780)
   License : UnRAR freeware license (see third_party/unrar7/license.txt)
   Files   : third_party/unrar7/** (RARDLL source set compiled with
             relaxed warnings; unrar_c_api.h is project-authored and
             carries the project's license)

4. LZMA SDK (7z decoder)
   ----------------------
   Version : 26.03 (2026-09-03)
   Source  : https://www.7-zip.org/sdk.html — release `lzma2603.7z` from
             https://github.com/ip7z/7zip/releases
   License : Public domain ("LZMA SDK is written and placed in the public
             domain by Igor Pavlov", see third_party/7z/DOC/lzma-sdk.txt)
   Files   : third_party/7z/** (decoder-only subset, compiled with relaxed
             warnings; see third_party/7z/README.md for the file list)

The LZMA SDK is the engine behind `src/sevenz_extract.c` (the v1.9.x 7z
support: LZMA/LZMA2/PPMd/Copy plus the BCJ, BCJ2 and Delta filters). Only the
C implementation is used — it builds with the plain PS5 C toolchain and does
not pull in the C++ runtime. The encoder half of the SDK is not vendored.

unrar is the engine behind `src/rar_extract.c` (the v1.9 RAR support: RAR4,
RAR5 including WinRAR 6/7 "v6" compression, and multi-volume archives; the
engine can also decrypt via RARSetPassword once a password channel is wired
up). The UnRAR source may be used in any software to handle RAR archives,
but may not be used to develop a RAR-compatible *archiver* or to re-create
the RAR compression algorithm, which is proprietary.

(The v1.8 engine, DrMcCoy/dmc_unrar 1.7.0 under GPL-2.0-or-later, was
replaced by the rarlab UnRAR source in v1.9; see git history under
`third_party/unrar/` for its notice.)

Libraries in sections 1 and 2 are distributed under the zlib license, which
permits redistribution in source and binary form provided the copyright
notice and this list of conditions are retained. unrar is distributed under
its own freeware terms. The LZMA SDK (section 4) is in the public domain and
carries no conditions. See the individual LICENSE / license.txt files in
each `third_party/` subdirectory for the complete terms.


Reference-only projects (NOT vendored)
--------------------------------------

The README Credits section lists a second class of project: ones this payload
was *written with reference to*, whose code is not present in this repository
and which therefore impose no obligations here. Keeping the two classes apart
matters, because one of them is licence-incompatible with this codebase:

  * websrv, ftpsrv, ps5-payload-manager, ps5-payload-dev/sdk, etaHEN  (GPL-3.0 / 3.0+)
  * zftpd                                                           (MIT)
  * libmicrohttpd                                                   (LGPL; linked as the SDK-provided static library)
  * ezremote                                                        (GPL-2.0-only)

For ezremote specifically: GPL-2.0-only cannot be combined with this project's
GPL-3.0, so it matters that no code was taken from it. The PKG-preview code in
`src/pkg_info.c` is an independent implementation -- the two share only the
on-disk SFO format facts, which no implementation can avoid. Line-by-line
comparison and reasoning: `docs/REWRITE-FEASIBILITY.md` section 2.2.

`owendswang/ps5-web-file-manager` (GPL-3.0) is not a mere reference: it is the
fork this project descends from, and the web UI, the task model and the PS5
packaging all originate there.
