P0 licensing boundary: one authority, the artifacts, and the history - #12
Merged
Merged
Conversation
A release-integrity lane before the tag. PUBLIC HISTORY AUDIT. 454 blobs across all 29 reachable public commits, inspected by CONTENT and not only by path. Zero PDF, XLSX, DOCX, CSV or archive has ever existed publicly. Every framework marker found is a clean-room prohibition, the README's NOT YET CLAIMED list, or an injection's own synthetic string. ONE MACHINE-READABLE AUTHORITY. public_licensing_policy.json replaces licensing assumptions scattered across scripts. check-licensing was EXTENDED, not duplicated, and now reads every text surface with claim CONTEXT (a provider token alone is not a finding — "do not copy from CIS" names a provider in order to forbid it), restricted document formats, symlinks leaving the repository, MPL application, and THE BUILT ARTIFACTS and SBOMs rather than the templates that produced them. TWO DEFECTS FOUND BY IT. The .deb declared no licence anywhere machine-readable: the RPM carried License: MPL-2.0 while Debian's mechanism, a DEP-5 file at /usr/share/doc/<pkg>/copyright, was simply absent. A licence the packaging format cannot express is one a package manager cannot report. And the privacy gate caught a private filesystem path written into public files — a public file does not get to describe a private filesystem. FALSE-POSITIVE QUALITY. 16 legitimate lines produce zero findings; 6 real claims are all caught. Noise is a defect. HARNESS BLIND SPOT. _tree_digest used find -type f, which excludes symlinks entirely — a blind spot precisely where it matters, since a symlink is one of the ways restricted content reaches an artifact without being committed to it. REPORTING CORRECTED. Executed detections are no longer added to declared skips, and the DEB reproducibility claim is narrowed to what was demonstrated. Gates 18. Injections 84, all executed and detected. Implements: D-84, D-90, D-111, GOV-001, GOV-002 Assisted-by: Claude (licensing audit, gate extension, defect injection)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release-integrity lane before the tag.
Public history audited — 454 blobs across all 29 reachable commits, by content not path. No restricted provider content has ever been committed publicly.
One machine-readable authority replaces scattered assumptions.
check-licensingextended (not duplicated) to read every text surface with claim context, restricted document formats, symlinks leaving the repository, MPL application, and the built artifacts and SBOMs rather than the templates.Two defects it found: the
.debdeclared no licence anywhere machine-readable (DEP-5copyrightadded), and a private filesystem path had been written into public files.16 legitimate lines produce zero false positives. 84 injections, all executed and detected.