Licence the code GPLv3 and contributed manifests CC0 #2

Merged
dtourolle merged 3 commits from licence/cc0-manifests into master 2026-09-05 11:51:05 +00:00
3 Commits
Author SHA1 Message Date
dtourolle 7eb5c175af docs: tag the untagged verifications, and record the UR-007 conflict
CI / fmt, clippy, test (pull_request) Failing after 54s
CI / static musl binary (pull_request) Skipped
CI / advisories and licences (pull_request) Successful in 39s
Five tests and the schema constant implemented requirements without
carrying a tag, so those requirements read as uncovered when they were
not. No behaviour changes here — every edit is a comment.

Also documents `static` as a real tier rather than an exemption: it is
already in `ci_executable_tiers` and its checks run in CI, and it exists
because DR-007's single binary and DR-012's licence policy are properties
of the build that a unit test could only assert as theatre.

The UR-007 note records a cross-repo status conflict rather than
resolving it. `jRay` JR-025 is `Done` and claims UR-007, but the fetch
path that would exercise it (`jRay` JR-031) is still `Planned`. Either
JR-025 is scoped to selection alone or it over-claims; until that is
settled neither register should be trusted for UR-007 coverage.

The gate reports 0 orphan tags and 19/19 UR coverage.

TRACES: DR-001, DR-014, UR-015, UR-016, UR-018 | SR-003, SR-004
2026-07-31 16:26:10 +02:00
dtourolleandClaude Opus 5 4afa36e7a2 feat(licence): contributed manifests are CC0 1.0
Contributed manifests were in no declared condition at all, which left §9a
replication with no grant flowing through it: peers mirror each other's
catalogues wholesale, and every hop of that was unlicensed.

CC0 rather than a share-alike licence, because a share-alike works by asserting
a right in the data and then conditioning its use. The position in
docs/legal-posture.md §3 is that presence timings are facts rather than
protectable expression — asserting copyright in them in order to license them
would contradict that argument in the same repository, and that contradiction is
worth more to an opponent than the licence is worth to us. CC0 also waives the
sui generis database right by name, closing the EU-specific residual exposure
from the contributor's side.

The grant is taken at token issuance, and that is not incidental. There are no
accounts, so there is no sign-up to attach terms to, and a manifest arrives over
POST /manifests with no channel to negotiate over. Acquiring the contribute
capability is the only moment a grant can be made, so POST /tokens now returns
the licence and its terms alongside the token — a licence the server publishes
but never delivers is one no contributor agreed to.

The test pins the scope limit as well as the identifier. Bounding the grant to
the manifest is the half that can fail silently: a reworded term reading onto
the underlying work would purport to grant what no contributor can.

Also records the settled code-licence position across all four repositories in
the legal posture, correcting an earlier claim there that the plugin and
extraction repos declared nothing. Both already carried LICENSE files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

TRACES: UR-019 | PR-006
2026-07-31 10:43:43 +02:00
dtourolleandClaude Opus 5 d5dd8113ef chore: add the GPLv3 LICENSE file Cargo.toml already declared
`license = "GPL-3.0-or-later"` has been in the manifest since the start, and
cargo-deny's allow-list carries it annotated "This crate's own licence" — but
no LICENSE file existed, so the declaration pointed at nothing.

Text copied from the jRay plugin's LICENSE after verifying it is byte-identical
to the FSF's canonical gpl-3.0.txt, rather than transcribed. 674 lines where a
single altered word changes the terms is not a file to write by hand.

No requirement trailer: this serves none, it completes an existing declaration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-31 10:43:32 +02:00