Legal & licensing¶
Not legal advice
This page summarises the project's licensing decisions in plain English. It is not legal advice. The authoritative text is DESIGN.md §2. Parts of it (the Apple toolkit import, the LGPL source procedure and the project name) are scheduled for review by a lawyer before version 1.0.
Licences at a glance¶
| Part | Licence | What that means for you |
|---|---|---|
Mallow's own code: the Mallow app, the mallow CLI, the MallowKit library, the test tools and the repository scripts |
0BSD | Use it for anything, commercial use included. Change it, sell it and redistribute it. No attribution required. |
| Documentation, including this website | 0BSD | The same, so doc snippets and code snippets can move freely between each other. |
Wine patches in runtime/patches/ |
LGPL-2.1-or-later | They change Wine, so they carry Wine's licence. |
| The Mallow Runtime (Wine 11.0 plus our patches and bundled libraries) | LGPL-2.1-or-later for Wine. Each bundled library keeps its own licence | Downloaded separately from the app. Its complete source is published with every release (see below). |
Recipes (recipes/) and JSON Schemas (schemas/) |
CC0-1.0 | Public domain dedication. Other tools can adopt the formats and data freely. |
| DXMT, DXVK-macOS, MoltenVK | Their own licences (DXMT: MIT up to v0.80, LGPL-2.1-or-later after that; DXVK: zlib; MoltenVK: Apache-2.0) | Delivered as separate signed downloads or inside the runtime, with their licence texts. |
| swift-argument-parser; later Sparkle (planned for v0.8) | Apache-2.0; MIT with bundled notices | Linked into the CLI (argument parser) and the app (Sparkle). Their notices ship in THIRD_PARTY_LICENSES.md. |
| D3DMetal (Apple Game Porting Toolkit) | Apple proprietary | Never distributed by Mallow. You import it from your own copy (see below). |
| Steam, Microsoft redistributables and fonts | Their vendors' terms | Downloaded only when you ask, with the terms and the real download host shown first. Never hosted or mirrored by us. |
Copyright © 2026 Mixutin and the Mallow contributors. Mallow's own files carry an SPDX licence identifier at the top, for example SPDX-License-Identifier: 0BSD.
Why the app and the runtime have different licences¶
The Mallow app and CLI start Wine as a separate program. They never link Wine's code into themselves. That makes the two a "mere aggregation": separate programs that are distributed side by side. The LGPL covers the runtime and doesn't extend to the 0BSD frontend. This is the usual Free Software Foundation reading of the licence.
For the same reason, the frontend must never contain copyleft code. GPL or LGPL code copied into the app would change its licence. See the clean-room rule below.
Getting the runtime's source code¶
The Mallow Runtime contains LGPL software, so its source must be available to everyone who gets the binary. The plan (DESIGN.md §2.3):
- Every runtime release on GitHub Releases carries its source beside it, as two archives:
mallow-runtime-<version>-source.tar.xz: the exact Wine source used (from CodeWeavers' published LGPL source release), our patches, our build scripts at the tagged commit, and the pinned input list.mallow-deps-<hash>-sources.tar.xz: the upstream source of every bundled library, every patch we apply to them, and our scripts that build them.
- Inside every runtime, a
licenses/folder holds Wine's licence and authors list, the licence of every bundled library, andSOURCE.mdwith the exact source URLs. These files are generated by a script, and CI refuses to release a runtime with a missing notice. - No binary without its source. No runtime, library or backend binary is ever served from a host that doesn't also serve the matching source.
- Source stays available for as long as we offer the binary. For the LGPL-3 components, we keep it for at least three more years after that.
- You can swap libraries. The runtime is signed without library validation, so you can replace its LGPL libraries with your own builds, as the LGPL requires.
- Easy to find. The planned Runtimes window shows a "Source code" link for each runtime and backend, and
mallow licensesprints the licence notices and source URLs.
Graphics backends follow the same procedure.
D3DMetal (Apple Game Porting Toolkit)¶
D3DMetal is Apple's proprietary Direct3D-to-Metal translator, part of the Game Porting Toolkit (GPTK). Apple's licence allows use for developing, testing and evaluating games, allows distribution only for non-commercial purposes, and forbids modifying it or reverse engineering it. Mallow's policy (DESIGN.md §2.4):
- We never download, bundle, mirror or host D3DMetal. The catalog has no entry for it, and CI rejects any archive that contains it.
- You import it yourself (planned for v0.5), from Apple's "Evaluation environment for Windows games" disk image that you downloaded with your own Apple ID, or from a folder with the same layout.
- You accept Apple's licence yourself. Mallow shows the licence file from your own copy and needs an explicit "I accept" before copying anything. It records when you accepted, and a hash of the licence file.
- The files are copied unchanged and their Apple signatures are checked. Mallow never modifies or re-signs them. They are never uploaded and never included in diagnostics bundles.
- No back doors. Other import paths (runtimes, Standard Wine builds, bottles from other tools) refuse or quarantine D3DMetal files, so the only way in is the import with the licence screen.
- Your decision. Whether your use fits Apple's licence is between you and Apple. Read it before you accept.
Other downloads¶
- Every recipe says where its downloads come from. Before anything is downloaded, Mallow shows the licence terms and every host a download may come from. Recipes that use a third-party mirror (for example, the Microsoft core fonts come from a GitHub mirror) are labelled as such.
- Microsoft's .NET Framework is not a one-click install, because its terms allow its use only by people licensed to use Windows. Mallow still lets you install it through winetricks, after showing that warning.
- Winetricks runs unattended, which would accept installers' licences without showing them. So Mallow shows the terms itself before starting winetricks.
- Rosetta 2. Installing it means accepting Apple's software licence. Mallow never accepts it without your recorded consent.
- Steam is downloaded from Valve's servers after you ask for it. We never host or mirror it.
Trademarks¶
- CrossOver and CodeWeavers are trademarks of CodeWeavers, Inc. Mallow is an open-source alternative to CrossOver, but it is not affiliated with or endorsed by CodeWeavers. We use these names only to describe the project and where our Wine sources come from. They never appear in Mallow's product names, runtime IDs, bundle identifiers, interface labels or marketing.
- Apple, Mac, macOS and Metal are trademarks of Apple Inc. Mallow is not affiliated with or endorsed by Apple.
- Windows, DirectX and Direct3D are trademarks of Microsoft Corporation.
- Steam is a trademark of Valve Corporation.
- Wine is used descriptively, to refer to the Wine project and its software.
- Mallow is the project's provisional name. Formal trademark searches are part of the first milestone (Gate G0), and the name may change if they turn up a conflict.
The Mallow Runtime's crash dialog, and every support link in Mallow, will point to Mallow's own issue tracker, so that nobody sends Mallow support requests to CodeWeavers or WineHQ by mistake.
The clean-room rule¶
Mallow is open and permissively licensed, and we want to keep it that way. So we are strict about where code and knowledge come from (DESIGN.md §2.7):
Never used, by anyone, for anything:
- Anything inside CodeWeavers' commercial CrossOver app beyond its licence texts and version strings: its launcher logic and defaults, bottle templates, compatibility database, configuration comments, interface assets and strings, its copy of D3DMetal, and the names or headers of its binaries.
Ideas only, never code:
- GPL-licensed frontends such as Whisky, Heroic, Bottles and Mythic. Studying how they behave is fine, and we credit them in NOTICE. Copying their code into the 0BSD frontend is not. A contributor who has just read a GPL implementation of the same function says so in their pull request, and a second maintainer reviews it.
- Winetricks (LGPL). Its download URLs, hashes and registry keys are facts and may appear in CC0 recipes, but its script logic is never transcribed.
- Code without a licence. It may be read for ideas, never copied.
Allowed:
- Permissively licensed code (0BSD, MIT, BSD, ISC, Apache-2.0, zlib, CC0) in the frontend, under its licence, with its original headers kept and the reuse recorded.
- Upstream Wine, CodeWeavers' published LGPL Wine sources and other LGPL-compatible code, only in the separately distributed runtime.
- Public vendor documentation, and our own experiments.
The provenance rule. Every environment variable, registry key or DLL rule that Mallow sets must cite an open source (upstream code, public documentation or our own test) in a code comment. Anything whose only source is a look inside a proprietary product is not implemented.
Sign-off. Every contribution carries a Developer Certificate of Origin sign-off (git commit -s). With it, you certify that you have the right to submit your work under the project's licences. See Contributing.
Contact¶
Questions about licensing are welcome in GitHub Discussions. For security issues and takedown or abuse requests, see SECURITY.md.