Tcl reaches the dongle through the SDK’s flat C API with cffi, which loads the native library at run time, so the package is pure Tcl with no extension to compile and nothing sits in the path of the check that a customer could substitute for something more agreeable. Tcl 8.6 or later with cffi 2.0 or later, on Windows, Linux and macOS; the Magicsplat Tcl distribution for Windows and BAWT ship cffi.
The Public Tcl Package Repository has the package as a zip that includes the native library for every platform: unpacked into a folder on auto_path, it is found by package require keynub_licdongle. From a clone of the SDK repository instead:
lappend auto_path <clone of the SDK repository>/bindings/tcl
package require keynub_licdongleCode language: Tcl (tcl)
Reading a License
package require keynub_licdongle
set license [keynub::licdongle with_dongle d { ;# first dongle, or with_dongle d <serial> {...}
keynub::licdongle verify_genuine $d ;# raises unless genuine
keynub::licdongle with_session $d { ;# closed on every exit path
keynub::licdongle read_record $d license
}
}]Code language: Tcl (tcl)
What You Are Protecting
Tcl software that is sold is often the logic inside a larger product: an EDA flow, a test system, an instrument controller, a configuration tool. It ships as scripts or as a starkit, and a check that returns a boolean is one if in a file anyone can open.
So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.
# Weak: one edited line.
if {![keynub::licdongle is_genuine $d]} exit
# Strong: the parameters only exist with the dongle present.
set parameters [keynub::licdongle with_session $d {
decode_parameters [keynub::licdongle app_decrypt $d $sealed_blob_shipped_with_your_program]
}]Code language: Tcl (tcl)
Every failed call raises an error whose -errorcode is {KEYNUB <STATUS> <code> <operation>}, so try ... trap {KEYNUB NOT_GENUINE} catches one status; is_genuine fails closed. with_dongle and with_session release the dongle and the session on every exit path. The package calls the SDK’s flat companion API, the one designed for foreign function interfaces: integer handles and buffers, no hand-written structure layouts.
Shipping the Native Library with a Tcl Application
The keynub_licdongle package is pure Tcl: cffi resolves the SDK’s flat API by name from the library it loads at run time, so there is no extension to compile. A script, a starkit or a starpack takes the package folder and keynub_licdongle_flat for its platform, found in natives/<platform>/ above the package, on the search path, or named with keynub::licdongle library_path or KEYNUB_LICDONGLE_FLAT_LIBRARY. cffi comes with the Magicsplat distribution and BAWT, and builds from its sources elsewhere.
The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.
Questions Tcl Developers Ask
Which Tcl Versions Does the Package Support?
Tcl 8.6 and later, Tcl 9 included, with cffi 2.0 or later, on Windows, Linux and macOS.
Does the Tcl Package Need a C Compiler?
No. It is pure Tcl over cffi, which is itself a prebuilt extension in the common Tcl distributions; the native library ships prebuilt for every platform.
Does a Tcl Application Need Administrator Rights to Talk to the Dongle?
No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.
Does a Tcl License Check Need an Internet Connection?
No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.
Who Can Read the License Records on a Dongle?
Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.
Can a License Written from Tcl Be Read by a Program in Another Language?
Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.
Code
Runnable sample: tcl/verify_and_read.tcl. Binding source: bindings/tcl. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.
All supported languages · All industries · Buy a KeyNub · Ask us something