CSPlay browser-runtime source package
====================================

This directory stages source and verbatim license notices for the exact local
compiled browser candidate. It does not upload, deploy, copy user game content,
contact a rights holder, or establish commercial distribution permission.

From the CSPlay repository:
  python infra/cs16-runtime/release/package_source.py

The script accepts --runtime-root for a prepared private runtime and --output
for a new private staging directory below .local. It checks all 27 source pins,
reviewed patches, compiler artifact hashes and the selected runtime manifest.
It reads Waf and Ninja dependency records and rejects exclusions affecting
recorded compiler sources. The original upstream Git blobs remain the base;
only patches composed against the pinned blobs replace source contents. Later
checkout changes cannot enter the package. Every file
and excluded upstream asset is recorded in source-manifest.json.

Staged public/ files:
  licenses.html                 Human-readable source and notices entry point
  NOTICE.txt                    Concatenated original notice bytes
  source-manifest.json           Pins, inputs, hashes, exclusions and limitations
  csplay-browser-source.tar.gz   Source, applied patches, build tools and notices

This source tar contains the modified engine/client source, the original local
build driver, reviewed patch files, the exact selected launcher source,
Emscripten system/JavaScript library source, SDL 2.32.0 source and notices.
The installed compiler/SDK binaries are not bundled. Original upstream commit
metadata is retained solely to reproduce build-version metadata offline.
MODIFICATIONS.txt prominently records the four applied patches and their date.
The original standalone CSPlay launcher/browser transport is GPL-3.0-or-later;
the exact narrow scope is in CSPLAY-RUNTIME-LICENSE.txt and launcher/LICENSE.txt.
This grant does not extend to the parent CSPlay platform or game/branding assets.

Rebuild after extracting the source tar into a NEW directory:
  cd csplay-browser-source
  python build/release/rebuild_source.py
  python build/release/rebuild_source.py --build --sdk ABSOLUTE_EMSDK_PATH --cmake ABSOLUTE_CMAKE_EXECUTABLE

Requirements: Python 3.12+, Git, Ninja, CMake 3.31.6 and an installed/activated
Emscripten SDK 4.0.11. The local original SDK pin is in source-lock.json. Install
these tools from their official upstream distributions. The build consumes two
jobs and writes logs plus rebuild-receipt.json below build-output. Run each
attempt from a fresh extraction. The first command only verifies source hashes.

The distributed source already has the reviewed patches applied. Do not apply
them a second time. Original build-source.py is retained as provenance; it is
for the complete repository checkout. rebuild_source.py uses this extracted
source package and builds only the seven shipped code artifacts, never extras.

Source matching is checked. Identical output hashes across machines are not
promised: generated build dates, compiler installation and paths can differ.
The package records a local toolchain source snapshot, not a hermetic toolchain
attestation. A fresh extracted-source build receipt is separate evidence.

SDK terms and corrected upstream notice
--------------------------------------
The exact pinned CS16Client LICENSE includes GPL terms, a Valve linking
exception and SDK terms limiting free distribution and directing commercial
use inquiries to Valve. No commercial grant has been established here. The
intended browser game is free and uses each player's local game files.

The pinned downstream text names third_party_licenses.txt, which is absent from
the recovered source trees. Valve's own issue 2101 documents that historical
Source SDK wording error. The official Half-Life 1 SDK LICENSE correction at
commit e8c4d541164ed56e78de2bb2bffdb6e8089cdb97 requires LICENSE and does not
name that missing file. The package preserves the pinned downstream license
and supplements it with the exact corrected Valve license and provenance;
it does not fabricate a third-party notice or alter upstream source terms.
See upstream/valve-license-provenance.json in this directory and the package's
notices/supplemental directory.

Optional upstream extras, game maps, models, textures, sounds, fonts and
prebuilt binaries are omitted when they are not compiler inputs. Their notices
are preserved. No Valve user content or extras.pk3 is served. Original source
file copyright/license headers remain unchanged. Packaging and reproducible
source verification do not themselves establish a commercial grant.
