feat(legal): land cargo-about + cargo-deny + Flutter license inventory
Closes engineering deliverables 1–3 from the open-work table in `docs/governance/legal-review-readiness.md` so the DEC-012 legal review can actually run. With this commit, the only remaining engineering item blocking sign-off is signed Windows / macOS / iOS build artefacts, deferrable per the DEC-002 staged release plan. Tooling ------- * `about.toml` + `about.hbs` + `about-md.hbs` configure cargo-about with the DEC-020 license posture and the five-target matrix (Linux, Android, Windows, macOS, iOS). One per-crate clarification for `allo-isolate` (`flutter_rust_bridge` transitive that ships Apache-2.0 via `license-file` rather than an SPDX `license` field). `cargo about generate` runs with zero warnings. * `deny.toml` mirrors the cargo-about allow-list and adds minimal bans / sources / advisories config. `cargo deny check` reports `advisories ok, bans ok, licenses ok, sources ok` for the workspace; multiple-versions of `windows_x86_64_msvc` produce advisory `warn` (no fail) because three windows-targets versions reach the graph via `jni`, `cpal`, and `keyring` respectively. * `tools/dump_flutter_licenses.sh` + `tools/dump_flutter_licenses.dart` walk `apps/chanora_flutter/pubspec.lock`, resolve each dependency to its local pub-cache directory, read the LICENSE file, and emit `docs/security/flutter-license-inventory.md`. SDK-sourced packages (`flutter`, `flutter_localizations`, `flutter_test`, `flutter_web_plugins`, `sky_engine`) resolve to the Flutter framework BSD-3-Clause LICENSE under `$FLUTTER_ROOT` (or `$HOME/sdks/flutter`). Artefacts --------- * `docs/security/license-inventory.md` — 364 transitive Rust crates with full license texts. Apache-2.0 (276), MIT (55), Unicode-3.0 (19), BSD-3-Clause (7), ISC (7). Zero copyleft. * `docs/security/license-inventory.html` — same data rendered as styled HTML for reviewer convenience. * `docs/security/flutter-license-inventory.md` — 94 Dart / Flutter packages with their LICENSE texts. Zero packages without a resolvable LICENSE in this RC. CI -- * New `supply-chain` job runs `cargo deny check --workspace --all-features` via `EmbarkStudios/cargo-deny-action@v2`. Fails the build on any GPL / LGPL / AGPL / commercial-source license surfacing transitively. * New `license-inventory` job installs `cargo-about --features cli` and regenerates `docs/security/license-inventory.md`; diffs against the committed copy and fails on drift. Forces contributors who touch the Cargo.lock to refresh the inventory. * New `flutter-license-inventory` job runs `tools/dump_flutter_licenses.sh` against the just-resolved pub cache; same diff-on-drift semantics. Governance ---------- * `docs/governance/legal-review-readiness.md` §5 cross-links the three new artefacts in a "Reviewer artefacts" subsection. * The open-work table at the bottom of the doc is rewritten as a status grid: items 1–3 now read **Done**; item 4 (signed iOS / macOS builds) remains the only open engineering blocker, with a pointer back to `staged-release-plan.md`. Verification ------------ * `CHANORA_DISABLE_KEYRING=1 cargo test --workspace`: all 49 unit + integration tests green (unchanged from v1.0.0-rc.1). * `cargo deny check`: advisories ok, bans ok, licenses ok, sources ok. * `cargo about generate --output-file …`: zero warnings. * `tools/dump_flutter_licenses.sh`: 94 packages, 0 without LICENSE. * `flutter analyze`: clean. No code changes touch the runtime; this is governance-tooling only.
This commit is contained in:
@@ -94,11 +94,22 @@ several places where we describe interoperability (e.g.
|
||||
* Each direct dependency is permissively licensed
|
||||
(`MIT`, `Apache-2.0`, `MIT OR Apache-2.0`, `BSD-3-Clause`).
|
||||
No GPL / LGPL / AGPL surfaces in the direct set.
|
||||
* **Reviewer artefacts** checked into the repository:
|
||||
- `docs/security/license-inventory.md` and
|
||||
`docs/security/license-inventory.html` — full transitive Rust
|
||||
inventory generated by `cargo about generate` from
|
||||
`about.toml`. Covers 364 crates across the workspace.
|
||||
- `docs/security/flutter-license-inventory.md` — Flutter / Dart
|
||||
inventory generated by `tools/dump_flutter_licenses.sh`.
|
||||
Covers 94 packages including the Flutter SDK BSD-3-Clause
|
||||
text.
|
||||
- `deny.toml` — `cargo deny` configuration enforcing the
|
||||
DEC-020 license posture as a CI guardrail. The `supply-chain`
|
||||
job in `.github/workflows/ci.yml` runs `cargo deny check` on
|
||||
every push and PR.
|
||||
* **Reviewer action**:
|
||||
- Confirm the `NOTICE` enumeration matches what the build tooling
|
||||
actually links (the audit must be repeated against a `cargo
|
||||
about generate --workspace` output and a Flutter
|
||||
`LicenseRegistry` dump as of the release build).
|
||||
actually links by spot-checking against the inventories above.
|
||||
- Confirm each direct dependency's attribution obligations are
|
||||
satisfied (Apache-2.0 requires a copy of the license text, the
|
||||
NOTICE entry, and a list of changes in any modified copies).
|
||||
@@ -171,14 +182,12 @@ These are concrete items that engineering must close before the
|
||||
reviewer's work can complete. They do **not** require legal input
|
||||
themselves — they are listed here so the reviewer's scope is clear.
|
||||
|
||||
1. Produce a `cargo about generate --workspace` output checked into
|
||||
`docs/security/`.
|
||||
2. Produce a Flutter `LicenseRegistry` dump for the release build
|
||||
checked into the same path.
|
||||
3. Wire `cargo deny check licenses` into CI with a deny-list of
|
||||
GPL / LGPL / AGPL / commercial source licenses.
|
||||
4. Confirm iOS and macOS build artefacts can ship (DEC-002 staged
|
||||
release allows deferring these; today neither has a live build).
|
||||
| # | Item | Status |
|
||||
|---|------|--------|
|
||||
| 1 | `cargo about generate --workspace` output checked into `docs/security/license-inventory.{md,html}` | **Done** (v1.0.0-rc.2 candidate) — generated from `about.toml`. 364 transitive crates enumerated; CI fails on staleness. |
|
||||
| 2 | Flutter `LicenseRegistry` dump checked into `docs/security/flutter-license-inventory.md` | **Done** (v1.0.0-rc.2 candidate) — generated by `tools/dump_flutter_licenses.sh`; 94 packages enumerated; CI fails on staleness. |
|
||||
| 3 | `cargo deny check licenses` (with allow-list mirroring DEC-020) | **Done** (v1.0.0-rc.2 candidate) — config at `deny.toml`, CI job `supply-chain` runs `cargo deny check` on every push. |
|
||||
| 4 | Live iOS and macOS build artefacts | **Open** — DEC-002 staged release allows deferring; today neither has a live build. See `staged-release-plan.md`. |
|
||||
|
||||
## Out-of-scope
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user