diff --git a/docs/requirements.md b/docs/requirements.md index 6ea69d1..7651671 100644 --- a/docs/requirements.md +++ b/docs/requirements.md @@ -2009,7 +2009,27 @@ desktop window, not as a second interface. --- -### D13 — face inference runtime and model licensing · **RUNTIME ANSWERED, LICENSING OPEN** +### D13 — face inference runtime and model licensing · **RUNTIME ANSWERED · LICENSING POSITION RECORDED 2026-09-19** + +> **Position, 2026-09-19.** DarkRoom is non-commercial software, built and installed by its +> author for personal libraries, and it uses the InsightFace SCRFD detectors and ArcFace embedder +> under their **non-commercial research grant** as such. That is the position, and it is taken +> with the risks written down rather than around them: +> +> - The grant is a **use** restriction and binds every user of the app, not only the project. It +> is not GPL-compatible and cannot become so; D8's licence covers this codebase and not those +> weights, which `models/face/README.md` says in as many words. +> - It is incompatible with **every public channel** — Flathub, F-Droid, Play. NFR-COMPAT-2's +> channels are therefore all self-distribution (a CI-built APK, a Flatpak and an Arch package +> installed by hand, an NSIS installer), and nothing is published to a store or a catalogue +> while these weights are in the tree. Publishing is the event that reopens this decision, and +> S14's licence search is what would close it: the OCEC eye-state weights showed a clean chain is +> possible, and a clean detector and embedder are what is missing. +> - The about screen names the models and their grant (NFR-SEC-5), so the person running the app +> can read the restriction they are under. +> +> The runtime half is unchanged below. + > **Updated 2026-08-21.** The runtime half of this decision is settled, and by a route the table > below does not contain. `ort` 2.0's `alternative-backend` feature *disables its linking entirely*