This document fixes how plugin binaries may be distributed. It complements THIRD_PARTY_NOTICES.md, which records what is included, and section 12 of the design policy.
It describes engineering obligations, not legal advice. A qualified reviewer confirms the interpretation before the first public binary release.
| Component | License | Distributed as |
|---|---|---|
Project code (libs/, plugins/) |
Apache-2.0 | Source and binaries |
laz-perf 2.0.0 |
LGPL-2.1 | Vendored source, compiled into pointcloud-laz and pointcloud-copc |
| OpenUSD | Apache-2.0 (per distribution) | Not vendored; runtime dependency |
| Test corpus | Per-dataset terms | Not shipped in plugin bundles |
pointcloud-las contains no laz-perf code. pointcloud-laz and
pointcloud-copc are affected by LGPL-2.1.
The build compiles the upstream sources under third_party/laz-perf/cpp/lazperf
directly into the static library usdLaz, which is then linked into the
pointcloud-laz plugin shared library.
third_party/laz-perf/cpp/lazperf/*.cpp
-> usdLaz (STATIC)
-> pointcloud-laz and pointcloud-copc plugins (SHARED)
Consequences:
- The shipped
pointcloud-lazandpointcloud-copcbinaries are combined works that contain LGPL-2.1 object code, so LGPL-2.1 section 6 applies to their distribution. - laz-perf headers are not exposed through the public
usdLazinclude path, and no laz-perf type appears in a public API. - The upstream source under
cpp/lazperfis unmodified. Omitted upstream components are listed in VENDORING.md.
If the vendored source is ever modified, the change must be marked in the
files, described in VENDORING.md, and reflected in
THIRD_PARTY_NOTICES.md.
Every distribution that includes pointcloud-laz or pointcloud-copc binaries provides:
- The complete LGPL-2.1 text (
third_party/laz-perf/COPYING). LICENSEandNOTICEfor the project code.THIRD_PARTY_NOTICES.md, naming laz-perf, its version, its commit, and its license.- A prominent statement that the plugin uses laz-perf and that laz-perf is covered by LGPL-2.1.
- The complete corresponding source for laz-perf, matching the exact version built.
- A means for the recipient to relink
pointcloud-lazandpointcloud-copcagainst a modified laz-perf.
Requirement 6 is what static linking adds. It is satisfied by publishing, in
the same release, the complete source archive of this repository together with
build instructions that reproduce the shipped binary, so a recipient can
rebuild pointcloud-laz and pointcloud-copc with their own laz-perf. Shipping the intermediate object
files or the static usdLaz archive is the fallback if a build from source
ever stops being reproducible.
Switching pointcloud-laz to link laz-perf as a separate shared library would move
the obligation from section 6(a) to the simpler shared-library case. That
change is a candidate but is not in effect today, and this document must be
updated before any statement to the contrary is published.
A published release contains, per platform:
| Artifact | Purpose |
|---|---|
| Plugin product bundle | pointcloud-las, pointcloud-laz, and pointcloud-copc libraries and plugInfo.json |
*.manifest.json |
Bundle manifest emitted by ost plugin package |
*.sbom.spdx.json |
SBOM for the packaged bundle |
| Source archive | Corresponding source for the tag, including laz-perf |
LICENSE, NOTICE |
Project license and attribution |
THIRD_PARTY_NOTICES.md |
Third-party components and their terms |
COPYING (laz-perf) |
LGPL-2.1 text |
CAPABILITY_MATRIX.md |
The format and attribute matrix for the release |
OPENUSD.md |
OpenUSD and OpenStrata compatibility statement |
INSTALL.md |
Plugin discovery and installation instructions |
SHA256SUMS |
SHA-256 for every artifact |
The release workflow publishes the plugin products, manifests, SBOMs, the
source archive, release notes, SHA256SUMS, and the license, notice,
capability, compatibility, and installation documents listed above. The
workflow stages these documents before checksums are generated, so they are
covered by the published checksum file.
- The tag matches
VERSION. -
THIRD_PARTY_NOTICES.mdmatches the vendored laz-perf commit. -
VENDORING.mdmatches the vendored tree, including any modification. - LGPL-2.1 text is present in the assets.
- The source archive builds
pointcloud-lazandpointcloud-copcon every published platform. - Checksums verify.
- A qualified reviewer has confirmed the licensing statement.