feat(legal): land cargo-about + cargo-deny + Flutter license inventory
Closes engineering deliverables 1–3 from the open-work table in `docs/governance/legal-review-readiness.md` so the DEC-012 legal review can actually run. With this commit, the only remaining engineering item blocking sign-off is signed Windows / macOS / iOS build artefacts, deferrable per the DEC-002 staged release plan. Tooling ------- * `about.toml` + `about.hbs` + `about-md.hbs` configure cargo-about with the DEC-020 license posture and the five-target matrix (Linux, Android, Windows, macOS, iOS). One per-crate clarification for `allo-isolate` (`flutter_rust_bridge` transitive that ships Apache-2.0 via `license-file` rather than an SPDX `license` field). `cargo about generate` runs with zero warnings. * `deny.toml` mirrors the cargo-about allow-list and adds minimal bans / sources / advisories config. `cargo deny check` reports `advisories ok, bans ok, licenses ok, sources ok` for the workspace; multiple-versions of `windows_x86_64_msvc` produce advisory `warn` (no fail) because three windows-targets versions reach the graph via `jni`, `cpal`, and `keyring` respectively. * `tools/dump_flutter_licenses.sh` + `tools/dump_flutter_licenses.dart` walk `apps/chanora_flutter/pubspec.lock`, resolve each dependency to its local pub-cache directory, read the LICENSE file, and emit `docs/security/flutter-license-inventory.md`. SDK-sourced packages (`flutter`, `flutter_localizations`, `flutter_test`, `flutter_web_plugins`, `sky_engine`) resolve to the Flutter framework BSD-3-Clause LICENSE under `$FLUTTER_ROOT` (or `$HOME/sdks/flutter`). Artefacts --------- * `docs/security/license-inventory.md` — 364 transitive Rust crates with full license texts. Apache-2.0 (276), MIT (55), Unicode-3.0 (19), BSD-3-Clause (7), ISC (7). Zero copyleft. * `docs/security/license-inventory.html` — same data rendered as styled HTML for reviewer convenience. * `docs/security/flutter-license-inventory.md` — 94 Dart / Flutter packages with their LICENSE texts. Zero packages without a resolvable LICENSE in this RC. CI -- * New `supply-chain` job runs `cargo deny check --workspace --all-features` via `EmbarkStudios/cargo-deny-action@v2`. Fails the build on any GPL / LGPL / AGPL / commercial-source license surfacing transitively. * New `license-inventory` job installs `cargo-about --features cli` and regenerates `docs/security/license-inventory.md`; diffs against the committed copy and fails on drift. Forces contributors who touch the Cargo.lock to refresh the inventory. * New `flutter-license-inventory` job runs `tools/dump_flutter_licenses.sh` against the just-resolved pub cache; same diff-on-drift semantics. Governance ---------- * `docs/governance/legal-review-readiness.md` §5 cross-links the three new artefacts in a "Reviewer artefacts" subsection. * The open-work table at the bottom of the doc is rewritten as a status grid: items 1–3 now read **Done**; item 4 (signed iOS / macOS builds) remains the only open engineering blocker, with a pointer back to `staged-release-plan.md`. Verification ------------ * `CHANORA_DISABLE_KEYRING=1 cargo test --workspace`: all 49 unit + integration tests green (unchanged from v1.0.0-rc.1). * `cargo deny check`: advisories ok, bans ok, licenses ok, sources ok. * `cargo about generate --output-file …`: zero warnings. * `tools/dump_flutter_licenses.sh`: 94 packages, 0 without LICENSE. * `flutter analyze`: clean. No code changes touch the runtime; this is governance-tooling only.
This commit is contained in:
@@ -94,11 +94,22 @@ several places where we describe interoperability (e.g.
|
||||
* Each direct dependency is permissively licensed
|
||||
(`MIT`, `Apache-2.0`, `MIT OR Apache-2.0`, `BSD-3-Clause`).
|
||||
No GPL / LGPL / AGPL surfaces in the direct set.
|
||||
* **Reviewer artefacts** checked into the repository:
|
||||
- `docs/security/license-inventory.md` and
|
||||
`docs/security/license-inventory.html` — full transitive Rust
|
||||
inventory generated by `cargo about generate` from
|
||||
`about.toml`. Covers 364 crates across the workspace.
|
||||
- `docs/security/flutter-license-inventory.md` — Flutter / Dart
|
||||
inventory generated by `tools/dump_flutter_licenses.sh`.
|
||||
Covers 94 packages including the Flutter SDK BSD-3-Clause
|
||||
text.
|
||||
- `deny.toml` — `cargo deny` configuration enforcing the
|
||||
DEC-020 license posture as a CI guardrail. The `supply-chain`
|
||||
job in `.github/workflows/ci.yml` runs `cargo deny check` on
|
||||
every push and PR.
|
||||
* **Reviewer action**:
|
||||
- Confirm the `NOTICE` enumeration matches what the build tooling
|
||||
actually links (the audit must be repeated against a `cargo
|
||||
about generate --workspace` output and a Flutter
|
||||
`LicenseRegistry` dump as of the release build).
|
||||
actually links by spot-checking against the inventories above.
|
||||
- Confirm each direct dependency's attribution obligations are
|
||||
satisfied (Apache-2.0 requires a copy of the license text, the
|
||||
NOTICE entry, and a list of changes in any modified copies).
|
||||
@@ -171,14 +182,12 @@ These are concrete items that engineering must close before the
|
||||
reviewer's work can complete. They do **not** require legal input
|
||||
themselves — they are listed here so the reviewer's scope is clear.
|
||||
|
||||
1. Produce a `cargo about generate --workspace` output checked into
|
||||
`docs/security/`.
|
||||
2. Produce a Flutter `LicenseRegistry` dump for the release build
|
||||
checked into the same path.
|
||||
3. Wire `cargo deny check licenses` into CI with a deny-list of
|
||||
GPL / LGPL / AGPL / commercial source licenses.
|
||||
4. Confirm iOS and macOS build artefacts can ship (DEC-002 staged
|
||||
release allows deferring these; today neither has a live build).
|
||||
| # | Item | Status |
|
||||
|---|------|--------|
|
||||
| 1 | `cargo about generate --workspace` output checked into `docs/security/license-inventory.{md,html}` | **Done** (v1.0.0-rc.2 candidate) — generated from `about.toml`. 364 transitive crates enumerated; CI fails on staleness. |
|
||||
| 2 | Flutter `LicenseRegistry` dump checked into `docs/security/flutter-license-inventory.md` | **Done** (v1.0.0-rc.2 candidate) — generated by `tools/dump_flutter_licenses.sh`; 94 packages enumerated; CI fails on staleness. |
|
||||
| 3 | `cargo deny check licenses` (with allow-list mirroring DEC-020) | **Done** (v1.0.0-rc.2 candidate) — config at `deny.toml`, CI job `supply-chain` runs `cargo deny check` on every push. |
|
||||
| 4 | Live iOS and macOS build artefacts | **Open** — DEC-002 staged release allows deferring; today neither has a live build. See `staged-release-plan.md`. |
|
||||
|
||||
## Out-of-scope
|
||||
|
||||
|
||||
Reference in New Issue
Block a user