Closes engineering deliverables 1–3 from the open-work table in
`docs/governance/legal-review-readiness.md` so the DEC-012 legal
review can actually run. With this commit, the only remaining
engineering item blocking sign-off is signed Windows / macOS / iOS
build artefacts, deferrable per the DEC-002 staged release plan.
Tooling
-------
* `about.toml` + `about.hbs` + `about-md.hbs` configure cargo-about
with the DEC-020 license posture and the five-target matrix
(Linux, Android, Windows, macOS, iOS). One per-crate clarification
for `allo-isolate` (`flutter_rust_bridge` transitive that ships
Apache-2.0 via `license-file` rather than an SPDX `license`
field). `cargo about generate` runs with zero warnings.
* `deny.toml` mirrors the cargo-about allow-list and adds minimal
bans / sources / advisories config. `cargo deny check` reports
`advisories ok, bans ok, licenses ok, sources ok` for the
workspace; multiple-versions of `windows_x86_64_msvc` produce
advisory `warn` (no fail) because three windows-targets versions
reach the graph via `jni`, `cpal`, and `keyring` respectively.
* `tools/dump_flutter_licenses.sh` + `tools/dump_flutter_licenses.dart`
walk `apps/chanora_flutter/pubspec.lock`, resolve each dependency
to its local pub-cache directory, read the LICENSE file, and emit
`docs/security/flutter-license-inventory.md`. SDK-sourced
packages (`flutter`, `flutter_localizations`, `flutter_test`,
`flutter_web_plugins`, `sky_engine`) resolve to the Flutter
framework BSD-3-Clause LICENSE under `$FLUTTER_ROOT` (or
`$HOME/sdks/flutter`).
Artefacts
---------
* `docs/security/license-inventory.md` — 364 transitive Rust
crates with full license texts. Apache-2.0 (276), MIT (55),
Unicode-3.0 (19), BSD-3-Clause (7), ISC (7). Zero copyleft.
* `docs/security/license-inventory.html` — same data rendered as
styled HTML for reviewer convenience.
* `docs/security/flutter-license-inventory.md` — 94 Dart / Flutter
packages with their LICENSE texts. Zero packages without a
resolvable LICENSE in this RC.
CI
--
* New `supply-chain` job runs `cargo deny check --workspace
--all-features` via `EmbarkStudios/cargo-deny-action@v2`. Fails
the build on any GPL / LGPL / AGPL / commercial-source license
surfacing transitively.
* New `license-inventory` job installs `cargo-about --features cli`
and regenerates `docs/security/license-inventory.md`; diffs
against the committed copy and fails on drift. Forces
contributors who touch the Cargo.lock to refresh the inventory.
* New `flutter-license-inventory` job runs
`tools/dump_flutter_licenses.sh` against the just-resolved pub
cache; same diff-on-drift semantics.
Governance
----------
* `docs/governance/legal-review-readiness.md` §5 cross-links the
three new artefacts in a "Reviewer artefacts" subsection.
* The open-work table at the bottom of the doc is rewritten as a
status grid: items 1–3 now read **Done**; item 4 (signed iOS /
macOS builds) remains the only open engineering blocker, with a
pointer back to `staged-release-plan.md`.
Verification
------------
* `CHANORA_DISABLE_KEYRING=1 cargo test --workspace`: all 49 unit
+ integration tests green (unchanged from v1.0.0-rc.1).
* `cargo deny check`: advisories ok, bans ok, licenses ok,
sources ok.
* `cargo about generate --output-file …`: zero warnings.
* `tools/dump_flutter_licenses.sh`: 94 packages, 0 without LICENSE.
* `flutter analyze`: clean.
No code changes touch the runtime; this is governance-tooling only.