license: SDK 改用 MIT —— 让第三方插件不被 AGPL 传染

原 LICENSE 是 2026-09-12(93ab794)引入的 AGPL-3.0-only 全文,README 据此
声明「插件静态链接 SDK,故必须以相同许可发布,闭源只能另取商业授权」。
这堵死了闭源插件,与第三方插件生态的目标相反。

## 为什么 MIT 才自洽

SDK 会随插件一起静态链接(源码进入插件二进制)。用传染许可,插件作者就被
强制开源;用 MIT,插件作者可自由选择许可(闭源 / 商业 / 私有均可),无需
回馈、无需任何例外或商业授权。这是刻意的宽松,也是插件生态安全的基础。

MIT 在这里**不会与任何许可冲突**:SDK 完全自包含 —— go.mod 零外部依赖,
sdk/ 只 import Go 标准库(sync),不引用核心仓任何代码(已实测确认)。

## 改动

- LICENSE:AGPL-3.0-only 全文(661 行)→ MIT 正文(21 行,版权人 JianFeeeee)
- README.md / README_EN.md:许可章节重写,把「必须同许可」改为「可自选许可」,
  并写明自包含这一前提

内核仓仍为 AGPL-3.0-only(其 README 的对应论述与本提交同批更新)。

验证:go build ./sdk/... ./meta/... 通过。
This commit is contained in:
JianFeeeee
2026-09-24 10:55:17 +08:00
parent 5af2a86816
commit e97cafc8de
3 changed files with 40 additions and 673 deletions

View File

@ -849,14 +849,18 @@ Or upload via the WebUI plugin management page, or manually place the `.hmap` in
## License
The SDK is released under **AGPL-3.0-only** — see [LICENSE](LICENSE).
The SDK is released under the **MIT license** — see [LICENSE](LICENSE).
**This is a substantive constraint for plugin developers**: the SDK is **statically linked** into
your plugin (its source ends up in the plugin binary), so the plugin is a derivative work of
this SDK and **must be released under the same license**. Because AGPL §13 covers network
interaction, a plugin that serves users over HTTP/WebSocket must also offer them the source.
If you need a closed-source plugin, the only compliant route is a separate exception/commercial
license from this project — none is offered today.
**This permissiveness is deliberate**: the SDK is **statically linked** into your plugin
(its source ends up in the plugin binary). Under a copyleft license such as AGPL that would
force plugin authors to open-source their work; MIT exists precisely so that plugin authors
can **pick their own license** — closed-source, commercial or private — with no obligation to
contribute back and no need for any exception or commercial grant. The safety and vitality of
the third-party plugin ecosystem rest on this.
This is sound because the SDK is **fully self-contained**: `go.mod` has zero external
dependencies and `sdk/` imports only the Go standard library (`sync`), never any code from the
core repository — so the MIT grant conflicts with nothing.
Third-party components (Go dependencies: go-sqlite3, gojieba, bubbletea, … — MIT / BSD-3 /
Apache-2.0) keep their own licenses. The platform-side model and inference runtime