Package metadata and unfree policy research¶
Reviewed: 2026-09-08. Scope: all 39 public nixpkgs-personal outputs and their
consumer interfaces. Nixpkgs reference:
801bef6abd86b91e51083066b83fb354a11fc640,
the revision in flake.lock. This extends the earlier
package design research with license-policy
behavior and package-specific metadata evidence.
Answer¶
Declare the license of the installed payload and let the consuming Nixpkgs instance enforce its policy. Source availability, payment, redistribution, and Nix build provenance describe different properties. A downloaded free application can contain vendor-built native code. A source-built package can remain unfree.
The review found incorrect blanket Apache declarations on both vendor skill catalogs, an outdated LibreOffice license declaration, and an unfree fetcher name that defeated the documented Windows-font allowlist. Other metadata needs verification against the actual outputs, including inherited metadata on font and desktop variants. The findings below identify the evidence and the intended package behavior; the package audit records implementation and validation.
Configuration belongs to the consumer¶
Nixpkgs rejects unfree licenses during evaluation, including evaluated build
dependencies. allowUnfreePredicate allows selected package names while keeping
the default rejection. Flakes require an explicit config when importing
Nixpkgs; ordinary user configuration files do not control that import.
Nixpkgs configuration reference
At this pin, config.allowUnfreePackages also accepts a list of package names
and composes additively with the predicate. allowUnfree = true admits all
unfree packages and therefore bypasses either narrower selector. Names use
lib.getName, which prefers pname and otherwise parses name.
Configuration options,
policy implementation
The collection deliberately uses two interfaces. Its direct flake
imports Nixpkgs with allowUnfree = true. Its ordinary import
and overlay instantiate against the caller's package set, preserving that
caller's policy. Consenting metadata discovery for the overlay does not replace
the incoming package scope. Keep this distinction explicit in examples.
Before the correction, allowing only ttf-ms-win11-auto still rejected its ISO
fetcher. The URL-derived source name parsed as 26200.6584.250915, so the
package and its restricted input had different allowlist names. Give the
fetcher a stable package-related name. Composite packages such as apple-fonts
also evaluate their constituent unfree font derivations; selective consent must
cover those names. Preserve the restrictive source license metadata.
Windows font recipe,
Apple font composition
Do not set meta.unfree manually to control installation. Nixpkgs derives it
from meta.license. Prefer license attributes over strings: the pinned
implementation explicitly documents a string-license detection defect.
checkMeta = true enables metadata type validation, but type validation cannot
establish that the declared license matches the payload.
Metadata checking implementation
Licenses and redistribution¶
Use a specific lib.licenses value when available. A license list describes
differently licensed components, rather than automatically offering a choice
between licenses. unfreeRedistributable describes permission to redistribute
the derivation output. An accessible download does not establish that permission.
Metadata license reference
Both unfree and unfreeRedistributable have free = false. The latter also
sets redistributable = true; it still requires unfree consent. Noncommercial
licenses such as cc-by-nc-sa-40 are also unfree, even when they permit sharing
under their stated conditions. Retain that precise license for
mutant-standard-emoji instead of replacing it with a generic label.
Pinned license definitions
preferLocalBuild changes build placement. allowSubstitutes = false disables
normal substitution, subject to Nix's override setting. Neither attribute
prevents someone from uploading a store path. They are scheduling controls,
not a license enforcement mechanism. Preserve the existing restricted-font
settings, but do not add them universally to packages merely because those
packages are unfree. Cache publication requires a separate policy.
Nix 2.35 derivation attributes
Provenance and metadata fields¶
Use binaryNativeCode for downloaded desktop application or CLI binaries.
Use fromSource for the compiled Swift/C utilities and source-rendered cursor
artwork. The available source types distinguish native code, interpreter
bytecode, firmware, and obfuscated code. Their isSource flags support a policy
separate from license freedom.
Source type definitions
The pinned upstream Google Fonts recipe classifies downloaded fonts as
binaryBytecode. Retain this convention for prebuilt font files and inherited
font variants. A font generated locally from the supplied source artwork can
use fromSource. Missing provenance implies no known non-source component;
explicit provenance makes this collection easier to audit. It does not certify
every transitive dependency.
Upstream Google Fonts recipe
allowNonSource = false rejects a package whose provenance contains a type
with isSource = false, unless its corresponding predicate allows the package.
This means accurately marked fonts and free vendor-built applications can be
rejected independently of allowUnfree.
Provenance policy implementation
| Field | Policy for this collection |
|---|---|
description, homepage |
Supply factual package information and the upstream project URL |
platforms, badPlatforms |
Describe supported targets and actual exclusions |
mainProgram |
Name an installed executable in bin; omit for data and library outputs |
maintainers |
Identify people who maintain this expression; do not invent ownership |
hydraPlatforms |
Set only when Hydra scheduling needs a narrower platform list |
broken, knownVulnerabilities |
Record demonstrated failures or known issues; do not add speculative values |
changelog, downloadPage, identifiers |
Add accurate useful values; omit guesses |
These fields describe different contracts. Metadata changes alone do not rebuild the package. Metadata reference
Hydra uses hydraPlatforms when present, otherwise the package platforms minus
bad platforms. An inherited Linux-only Hydra list can become stale when a
variant broadens supported systems. Review inherited maintainers, changelogs,
program names and build flags whenever a variant changes their meaning. Keep
valid upstream licenses and provenance rather than recreating them without
evidence.
Hydra platform selection,
local font override
Build settings¶
Keep strictDeps = true, native tools in nativeBuildInputs, and target
libraries in buildInputs. Disabling an irrelevant configure or build phase
is appropriate for copied data. dontFixup skips the entire fixup phase;
dontStrip skips stripping only. Choose the narrow setting needed by the
package. Preserve phase hooks in custom phases. Enable doCheck or
doInstallCheck when the corresponding tests exist; merely declaring a phase
does not enable it. Target-execution checks need a compatible build platform.
Standard environment reference
For signed macOS vendor bundles, preserve the bundle bytes through installation and skip generic fixup that would modify them. Locally modified or compiled bundles need signing after their final mutations, as explained in the existing build standard and Apple signing documentation.
passthru.tests are separate derivations; ordinary package builds do not
automatically run them. Keep CI explicitly connected to those tests. Do not
force a GUI launch into a sandbox merely to populate doCheck.
Passthru test documentation
Package-specific license evidence¶
- The full
anthropic-skillscatalog includes document skills whose pinned notices contain custom copying, modification and distribution restrictions. A blanket Apache-2.0 declaration cannot describe that installed catalog. Preserve those notices and account for the restricted components in its license metadata. Pinned document-skill notice Its canvas-design directory also includes 54 prebuilt fonts with OFL notices. Record bothfromSourceandbinaryBytecode, and include OFL in the license list. Pinned canvas assets The implemented default now selects 14 reviewed free examples. Document skills anddoc-coauthoring, which lacks an explicit license, need a restricted selection. Metadata follows the selected contents; see the package README. openai-skillsincludes Figma skills governed by Figma Developer Terms. Other per-skill licenses remain applicable. Its repository name does not make the entire catalog Apache-2.0. Pinned Figma skill notice Four Notion skills andvercel-deployuse MIT. Include it in the aggregate metadata. Pinned Notion notice, pinned Vercel notice- LibreOffice identifies MPL-2.0 as its distribution license and points to the installed LICENSE for its mixed third-party components. Retain the complete vendor notices and replace the old LGPL-only declaration with MPL-2.0. LibreOffice license statement
- Bibata's pinned README expressly permits GPLv3 or later.
gpl3Plusis accurate. The source has no standalone LICENSE file, so retain its upstream README attribution and license statement in the output. Pinned Bibata README - Vorssaint's pinned README identifies GPL-3.0-or-later. Keep
gpl3Plusand the installed license notice. Pinned Vorssaint README - Bitwarden's repository includes GPL and commercial code, but this release's desktop build selects the OSS entrypoint. Retain GPL-3.0-only for this desktop package; do not infer its classification from the server or browser modules. Release license scope, desktop build configuration
- The reviewed T3 Code, LinearMouse and remindctl releases use MIT. Their vendor
binaries still need
binaryNativeCode. The remindctl ZIP contains only the executable, so packaging must obtain its notice separately. T3 Code notice, LinearMouse notice, remindctl notice
Validation and limits¶
Research inspected the pinned Nixpkgs implementation, all package recipe
metadata, existing package standards, and the linked upstream statements.
On x86_64-linux, evaluating the original Windows-font package with a predicate
allowing only ttf-ms-win11-auto reproduced a rejected unfree ISO dependency.
Reading its metadata alone succeeded, showing why a successful metadata query
does not establish that the full derivation can instantiate.
This research did not build the desktop system or launch GUI applications. Evaluation cannot establish native behavior, complete copyright ownership, or redistribution permission beyond the upstream statements reviewed here. Use the package audit for the completed package checks and their platform limits.