Rand Stats

KeyNub::LicDongle

zef:ab-tools

KeyNub License Dongle — Raku Distribution

use KeyNub::LicDongle;

my $secret = KeyNub::LicDongle::open(-> $d {  # first dongle, or open('serial', -> $d { ... })
    $d.verify-genuine;                         # dies unless genuine
    $d.session({                               # closed on every exit path
        $d.app-decrypt($sealed)                # <- build the licence check on this
    })
});

Nothing compiled. The distribution calls the SDK's flat companion API through NativeCall, which loads the native library at run time, so there is no extension to build and nothing sits in the path of the check that a customer could substitute. No dependencies beyond Rakudo itself (NativeCall is part of it); Raku 6.d, on Windows, Linux and macOS.

Setup

zef install KeyNub::LicDongle

The distribution does not carry the native library. In a clone of the SDK repository it finds keynub_licdongle_flat for your platform in natives/<platform>/ on its own, from the program's folder and the working directory upwards, so the samples run with nothing set. Elsewhere, take the library from the SDK's natives folder and put it in natives/<platform>/ beside your program, where the operating system finds libraries (PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH), or name it before the first call:

KeyNub::LicDongle::library-path('/opt/keynub/libkeynub_licdongle_flat.so');

KEYNUB_LICDONGLE_FLAT_LIBRARY in the environment does the same. A process loads the library once; KeyNub::LicDongle::loaded-library-path() tells which, and library-path with a different file after that dies. On Linux, install the udev rule described in NATIVES.md so the dongle is accessible without root.

Notes

Read docs/integration-security.md before writing the check. exit 1 unless $d.genuine is one conditional branch, and editing one of those in a script is no effort at all. Route something the program needs through app-encrypt and app-decrypt, so removing the check removes the data.

Tests

zef test bindings/raku runs the tests of the distribution, which need neither the native library nor a dongle. raku -I bindings/raku/lib bindings/raku/test/standin_test.raku runs without a dongle: it compiles a stand-in for the flat C API (bindings/flat/licd_flat.c over bindings/julia/test/stub/licd_stub.c) with the C compiler on the path and exercises every call against it. KEYNUB_SDK_ROOT names the SDK sources when the distribution is not inside a clone; KEYNUB_LICDONGLE_FLAT_LIBRARY names a compiled stand-in instead. The samples are under samples/raku (raku samples/raku/verify-and-read.raku).