From cab92e6e1bf2374455e17cc70defd9530eca6e60 Mon Sep 17 00:00:00 2001 From: Jintao Date: Sun, 26 Jul 2026 23:54:09 +0800 Subject: [PATCH] Pin BusyBox ping notices --- CHANGELOG.en.md | 10 +-- CHANGELOG.md | 8 +-- Compliance/RootFS/v0.3.3/EVIDENCE.json | 6 +- .../RootFS/v0.3.3/LICENSE-INVENTORY.json | 6 +- .../v0.3.3/LICENSE-NOTICE-CANDIDATES.json | 6 +- .../v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json | 11 ++-- .../RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json | 10 ++- Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json | 14 ++++ Compliance/RootFS/v0.3.3/NOTICE.md | 6 +- Compliance/RootFS/v0.3.3/README.md | 66 +++++++++++++------ Compliance/RootFS/v0.3.3/SHA256SUMS | 14 ++-- Docs/ReleaseCompliance.md | 10 +-- Docs/Roadmap.md | 2 +- Docs/RootFS.md | 8 +-- Docs/en/ReleaseCompliance.md | 10 +-- Docs/en/Roadmap.md | 2 +- Docs/en/RootFS.md | 8 +-- README.md | 2 +- Scripts/rootfs-license-notice-candidates.rb | 2 +- .../rootfs-license-notice-review-results.rb | 2 +- .../RootFSLicenseNoticeCandidatesTests.rb | 45 ++++++++++++- .../RootFSLicenseNoticeReviewResultsTests.rb | 34 ++++++++-- .../RootFSLicenseReviewResultsTests.rb | 2 +- 23 files changed, 199 insertions(+), 85 deletions(-) diff --git a/CHANGELOG.en.md b/CHANGELOG.en.md index 8d61a9c..ac00df1 100644 --- a/CHANGELOG.en.md +++ b/CHANGELOG.en.md @@ -32,17 +32,17 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit declared-license/attribution inventories, and default `apk`, repository, and DNS configuration; complete LICENSE/NOTICE and corresponding-source bundles remain distribution blockers. -- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 26 +- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 27 pinned RootFS license/NOTICE candidates have engineering review results; eight source origins retain package-level open items, and legal and redistribution gates remain closed. - A checksum-bound `LICENSE-NOTICE-CANDIDATES.json`, strict validator, and outside-repository atomic materializer for the eight remaining RootFS source origins. It indexes 13 remote license/attribution payloads, 47 aports files, - and the 26 existing evidence files for complete re-verification without + and the 27 existing evidence files for complete re-verification without committing payloads or opening engineering, legal, or redistribution gates. - `LICENSE-NOTICE-REVIEW-RESULTS.json` and a strict external payload-tree - verifier. All 86 candidate payloads now have checksum-bound engineering + verifier. All 87 candidate payloads now have checksum-bound engineering review. The pinned upstream `alpine-keys` GPL-to-MIT license-decision commit is included while its package-level copyright notice remains open. The `ca-certificates` generator is byte-identical to curl commit `3fdc4bdb`, and @@ -52,8 +52,8 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit `shell/math.c`, which retains complete MIT and BSD-3-Clause notices, and confirms that the installed `env`, `echo`, `logger`, and `cal` applets link `coreutils/env.c`, `coreutils/echo.c`, `sysklogd/logger.c`, and - `util-linux/cal.c`, - respectively, with complete BSD notices; other inline third-party notices + `util-linux/cal.c`, respectively, while `ping` and `ping6` share + `networking/ping.c`; each retains complete BSD notices. Other inline notices stay open; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, five origins still need diff --git a/CHANGELOG.md b/CHANGELOG.md index b6fbf1b..1c8c03c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -30,15 +30,15 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 10 个 source origin、SPDX 2.3 JSON SBOM、许可证声明/attribution inventory 和 `apk`、repository、DNS 默认配置快照;完整 LICENSE/NOTICE 与对应源码 bundle 仍保持发行阻塞。 -- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;26/26 个固定 +- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;27/27 个固定 RootFS license/NOTICE 候选已完成工程复核,8 个 source origin 仍有包级未决项, 法律与再分发门禁保持关闭。 - 为剩余 8 个 RootFS source origin 加入 checksum-bound `LICENSE-NOTICE-CANDIDATES.json`、严格验证器和仓库外原子 materializer;索引 - 13 份远端许可证/attribution 材料、47 份 aports 文件与 26 份既有证据,支持完整 + 13 份远端许可证/attribution 材料、47 份 aports 文件与 27 份既有证据,支持完整 复验,但不提交 payload,也不解除工程、法律或再分发门禁。 - 加入 `LICENSE-NOTICE-REVIEW-RESULTS.json` 和严格外置 payload-tree 复验器; - 86/86 个候选 payload 已完成 checksum-bound 工程复核;新增固定 + 87/87 个候选 payload 已完成 checksum-bound 工程复核;新增固定 `alpine-keys` GPL→MIT 上游许可判定提交,但仍保留包级版权声明缺口; `ca-certificates` 生成脚本与 curl 提交 `3fdc4bdb` 字节一致并固定该精确 revision 的 curl 授权文本,trust-store 审查仍保持未决; @@ -46,7 +46,7 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 链入保留完整 MIT 与 BSD-3-Clause notices 的 `shell/math.c`,并确认已安装的 `env`、`echo`、`logger` 与 `cal` applet 分别链入保留完整 BSD notice 的 `coreutils/env.c`、`coreutils/echo.c`、`sysklogd/logger.c` 与 - `util-linux/cal.c`;其他内联第三方 + `util-linux/cal.c`,`ping` 与 `ping6` 则共同链入 `networking/ping.c`;其他内联第三方 notices 继续保持未决; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项关闭,另外 5 个 origin 仍需补逐包材料,法律和再分发门禁保持关闭。 diff --git a/Compliance/RootFS/v0.3.3/EVIDENCE.json b/Compliance/RootFS/v0.3.3/EVIDENCE.json index c2a67c3..16b5ced 100644 --- a/Compliance/RootFS/v0.3.3/EVIDENCE.json +++ b/Compliance/RootFS/v0.3.3/EVIDENCE.json @@ -39,13 +39,13 @@ "sourceOrigins": 10, "declaredLicenseExpressions": 7, "licenseOrNoticeFilesInGuestTemplate": 0, - "indexedExternalLicenseReviewCandidates": 26, - "engineeringReviewedLicenseCandidates": 26, + "indexedExternalLicenseReviewCandidates": 27, + "engineeringReviewedLicenseCandidates": 27, "sourceOriginsWithRemainingLicenseReviewItems": 8, "indexedLicenseNoticeCandidateOrigins": 8, "pinnedRemoteLicenseNoticePayloads": 13, "supplementalAportsCandidateFiles": 47, - "engineeringReviewedLicenseNoticeCandidatePayloads": 86, + "engineeringReviewedLicenseNoticeCandidatePayloads": 87, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5 }, "engineeringStatus": { diff --git a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json index 4b20862..c58dbef 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json @@ -26,14 +26,14 @@ "licenseOrNoticeFilesFoundInGuestTemplate": [ ], - "indexedExternalReviewCandidates": 26, - "engineeringReviewedCandidates": 26, + "indexedExternalReviewCandidates": 27, + "engineeringReviewedCandidates": 27, "sourceOriginsWithOpenReviewItems": 10, "sourceOriginsWithRemainingReviewItems": 8, "indexedOpenSourceOrigins": 8, "pinnedRemoteReferencePayloads": 13, "supplementalAportsFiles": 47, - "engineeringReviewedCandidatePayloads": 86, + "engineeringReviewedCandidatePayloads": 87, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5, "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json index 07bbae7..30c6526 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewResultsSha256": "2b27048cd9f39dedd2f03f2e5eb9b644aaea315629dc117878aaa770dc79c2a2", + "licenseReviewResultsSha256": "584bd14ea70fae4fcc39f87fe4b1205518673daf9b46bff8ac1afa58c463d19b", "status": "candidate-bundle-indexed-engineering-review-required", "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, @@ -250,7 +250,8 @@ "evidence/busybox/coreutils-env.c", "evidence/busybox/coreutils-echo.c", "evidence/busybox/sysklogd-logger.c", - "evidence/busybox/util-linux-cal.c" + "evidence/busybox/util-linux-cal.c", + "evidence/busybox/networking-ping.c" ], "referenceLicensePaths": [ "licenses/GPL-2.0.txt" @@ -302,6 +303,7 @@ "confirm-enabled-echo-license-and-attribution-coverage", "confirm-enabled-logger-license-and-attribution-coverage", "confirm-enabled-cal-license-and-attribution-coverage", + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ], diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json index 8d6872b..1b57b70 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "candidateManifestSha256": "7bc5063de74731ffdc3e234bf1b9a11fc16d0aca050e5139dc7bbc127149b5f8", + "candidateManifestSha256": "dae069cd0728343e9b50a2192c2881d53e6e5ddfc85f1ee47ed2c5ebdfdd931f", "status": "candidate-payloads-engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allIndexedCandidatePayloadsReviewed": true, @@ -13,8 +13,8 @@ "legalReviewApproved": false, "redistributionApproved": false, "candidatePayloadTreeFormat": "sha256-path-lines-v1", - "candidatePayloadTreeSha256": "f7268359cc93790f37787fb028dd85a5dc18e60ecd487ff0634ee6533a0ea61b", - "reviewedPayloadFileCount": 86, + "candidatePayloadTreeSha256": "1f6207b917d1805f56f28c29007a3a18830d59347e455d5ec5479ab58fff9ae0", + "reviewedPayloadFileCount": 87, "reviewedClosedOriginEvidenceCount": 4, "sourceOriginsWithRemainingReviewItems": 5, "sources": [ @@ -82,7 +82,7 @@ "reviewState": "candidate-payloads-engineering-reviewed-legal-review-open", "licenseTextCoverage": "partial", "attributionCoverage": "partial", - "reviewedExistingEvidenceCount": 8, + "reviewedExistingEvidenceCount": 9, "reviewedReferenceLicenseCount": 1, "reviewedSupplementalAportsCount": 37, "reviewedRemoteEvidenceCount": 0, @@ -93,7 +93,8 @@ "confirm-enabled-env-license-and-attribution-coverage", "confirm-enabled-echo-license-and-attribution-coverage", "confirm-enabled-logger-license-and-attribution-coverage", - "confirm-enabled-cal-license-and-attribution-coverage" + "confirm-enabled-cal-license-and-attribution-coverage", + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage" ], "remainingReviewItems": [ "review-other-bundled-third-party-license-and-attribution-coverage" diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json index 5b978c3..f0d6b91 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json @@ -4,11 +4,11 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewManifestSha256": "1edf1106bdcd2cded016b1bb584baacfa7f92bd66ccda17844e80d93f02026b2", + "licenseReviewManifestSha256": "bf2502a04fbfba77547b0728d8ca0a2b3665b4e7539ad32aa1df3e919b7f3eff", "status": "engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allCandidateDigestsVerified": true, - "reviewedCandidateCount": 26, + "reviewedCandidateCount": 27, "sourceOriginsWithRemainingReviewItems": 8, "completeLicenseTextBundlePresent": false, "completePackageNoticeSetPresent": false, @@ -129,6 +129,11 @@ "outputPath": "evidence/busybox/util-linux-cal.c", "sha256": "39798fa68229dcb25817d906ac1990cc147fd84065918a1404b56263d7a6e311", "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/networking-ping.c", + "sha256": "f5500d03eb8c681589cd99a861ce57bec208bfdded726b5529c61967e738a205", + "conclusion": "inline-license-and-attribution-notice" } ], "resolvedReviewItems": [], @@ -139,6 +144,7 @@ "confirm-enabled-echo-license-and-attribution-coverage", "confirm-enabled-logger-license-and-attribution-coverage", "confirm-enabled-cal-license-and-attribution-coverage", + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ] diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json index ce13726..cdcedcc 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json @@ -217,6 +217,19 @@ "attribution" ], "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/networking/ping.c", + "outputPath": "evidence/busybox/networking-ping.c", + "byteCount": 31080, + "sha256": "f5500d03eb8c681589cd99a861ce57bec208bfdded726b5529c61967e738a205", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" } ], "openReviewItems": [ @@ -226,6 +239,7 @@ "confirm-enabled-echo-license-and-attribution-coverage", "confirm-enabled-logger-license-and-attribution-coverage", "confirm-enabled-cal-license-and-attribution-coverage", + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ] diff --git a/Compliance/RootFS/v0.3.3/NOTICE.md b/Compliance/RootFS/v0.3.3/NOTICE.md index b6dde1f..000a66c 100644 --- a/Compliance/RootFS/v0.3.3/NOTICE.md +++ b/Compliance/RootFS/v0.3.3/NOTICE.md @@ -33,12 +33,12 @@ Generated from the exact `v0.3.3` archive with SHA-256 No file whose path identifies it as LICENSE, COPYING, NOTICE, or a license-directory member was found in the guest template. Declared identifiers and expressions are recorded in -`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 26 +`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 27 candidate license, attribution, declaration, and inline-notice files across all 10 source origins. The external review tool extracts and verifies those candidates from the pinned source-review bundle. `LICENSE-REVIEW-RESULTS.json` records the checksum-bound engineering review -of all 26 candidates. All indexed review items are resolved +of all 27 candidates. All indexed review items are resolved for `libc-dev`, `zlib`. 8 source origins still have package-specific open items, so this is not a complete or legally approved license/NOTICE bundle. @@ -49,7 +49,7 @@ reference/attribution payloads and files, together with all checksum-bound reviewed evidence. The repository tool can materialize and re-verify that bundle outside the repository. `LICENSE-NOTICE-REVIEW-RESULTS.json` records checksum-bound engineering -review of all 86 indexed +review of all 87 indexed payload files. 3 origins have no remaining candidate-material engineering items; 5 origins still require package-specific material. Legal review and redistribution diff --git a/Compliance/RootFS/v0.3.3/README.md b/Compliance/RootFS/v0.3.3/README.md index 38d33c8..2fd5d03 100644 --- a/Compliance/RootFS/v0.3.3/README.md +++ b/Compliance/RootFS/v0.3.3/README.md @@ -16,14 +16,14 @@ pinned RootFS archive. It does not store the RootFS payload. SHA-256; - `LICENSE-INVENTORY.json`:声明的许可证表达式、标识符和 archive 内 license/notice 文件检查结果; -- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 26 个候选许可证文本、 +- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 27 个候选许可证文本、 attribution、声明与内联 notice 的路径、大小、SHA-256 和逐包未决审查项; -- `LICENSE-REVIEW-RESULTS.json`:对全部 26 个候选的 checksum-bound 工程复核 +- `LICENSE-REVIEW-RESULTS.json`:对全部 27 个候选的 checksum-bound 工程复核 结论、coverage 和未决项处置;不表示法律或再分发批准; - `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 13 份远端 - 许可证/attribution 材料、47 份 aports 补充文件及现有 26 份复核证据的外置候选包; + 许可证/attribution 材料、47 份 aports 补充文件及现有 27 份复核证据的外置候选包; payload 不提交,工程、法律和再分发门禁保持关闭; -- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 86 个 payload 文件树的 +- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 87 个 payload 文件树的 工程复核结果;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,法律和 再分发门禁保持关闭; - `RUNTIME-CONFIGURATION.json`:guest、`apk`、repository、world 和 DNS 默认配置; @@ -34,15 +34,15 @@ pinned RootFS archive. It does not store the RootFS payload. `SOURCE-ACQUISITION.json` pins the aports snapshots and upstream distfiles needed to assemble an external source-review directory. It is an acquisition manifest, not a committed source archive or redistribution grant. -`LICENSE-REVIEW.json` pins 26 unreviewed candidate evidence files across all +`LICENSE-REVIEW.json` pins 27 unreviewed candidate evidence files across all 10 source origins; it is an engineering review index, not legal approval. -`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 26 pinned +`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 27 pinned candidates. Two source origins have no remaining indexed review items; eight still have package-specific open items. `LICENSE-NOTICE-CANDIDATES.json` indexes an external candidate bundle for those eight origins: 13 pinned remote license/attribution payloads, 47 supplemental aports files, and the existing -26 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the -engineering review to the exact 86-file payload tree. Three origins have no +27 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the +engineering review to the exact 87-file payload tree. Three origins have no remaining candidate-material engineering items; five still require package-specific material. Legal and redistribution approval remain open. @@ -79,12 +79,15 @@ change. `CONFIG_FEATURE_BZIP2_DECOMPRESS=y`,也启用了 `CONFIG_ASH=y`、 `CONFIG_FEATURE_SH_MATH=y`、`CONFIG_FEATURE_SH_MATH_64=y` 和 `CONFIG_ENV=y`、`CONFIG_ECHO=y`、`CONFIG_FEATURE_FANCY_ECHO=y`、 -`CONFIG_LOGGER=y` 和 `CONFIG_CAL=y`;BusyBox +`CONFIG_LOGGER=y`、`CONFIG_CAL=y`、`CONFIG_PING=y`、`CONFIG_PING6=y` 和 +`CONFIG_FEATURE_FANCY_PING=y`;BusyBox `shell/Kbuild.src` 在该配置下把 `math.o` 链入构建,`coreutils/env.c` 与 `coreutils/echo.c` 则分别通过 `lib-$(CONFIG_ENV) += env.o` 和 `lib-$(CONFIG_ECHO) += echo.o` 链入,`sysklogd/logger.c` 通过 `lib-$(CONFIG_LOGGER) += syslogd_and_logger.o` 链入,`util-linux/cal.c` -通过 `lib-$(CONFIG_CAL) += cal.o` 链入。外置候选树现同时绑定该 +通过 `lib-$(CONFIG_CAL) += cal.o` 链入,`networking/ping.c` 则同时通过 +`lib-$(CONFIG_PING) += ping.o` 与 `lib-$(CONFIG_PING6) += ping.o` +链入。外置候选树现同时绑定该 配置与固定 BusyBox 1.36.1 源包中的 1,999 字节 `archival/libarchive/bz/LICENSE`(SHA-256 @@ -114,7 +117,16 @@ RootFS 中 `/usr/bin/logger` 的目标为 `/bin/busybox`,因此在工程层关 `39798fa68229dcb25817d906ac1990cc147fd84065918a1404b56263d7a6e311`), 其中保留完整 Berkeley BSD-3-Clause 版权及许可通知。固定 RootFS 中 `/usr/bin/cal` 的目标为 `/bin/busybox`,因此在工程层关闭 -`confirm-enabled-cal-license-and-attribution-coverage`。BusyBox 其他已启用 +`confirm-enabled-cal-license-and-attribution-coverage`;同时绑定 31,080 字节 +`networking/ping.c`(SHA-256 +`f5500d03eb8c681589cd99a861ce57bec208bfdded726b5529c61967e738a205`), +其中保留 Berkeley 版权、再分发条件与免责声明,并明确记录 advertising clause +已依据 1999 年许可变更移除。固定 aports 的 +`0016-ping-make-ping-work-without-root-privileges.patch` 也已包含在同一外置 +payload 树中;它只修改 socket/runtime 代码,不触及文件头或文件尾的许可通知。 +固定 RootFS 主树与 guest 模板树中的 `/bin/ping` +和 `/bin/ping6` 均指向 `/bin/busybox`,因此在工程层关闭 +`confirm-enabled-ping-and-ping6-license-and-attribution-coverage`。BusyBox 其他已启用 组件的内联第三方 notice 尚未形成完整集合,因此 license-text 与 attribution coverage 均保持 partial, `review-other-bundled-third-party-license-and-attribution-coverage` 保持未决, @@ -126,14 +138,17 @@ The `busyboxconfig` at pinned aports commit It explicitly enables `CONFIG_BZIP2=y`, `CONFIG_BZIP2_SMALL=8`, `CONFIG_FEATURE_BZIP2_DECOMPRESS=y`, `CONFIG_ASH=y`, `CONFIG_FEATURE_SH_MATH=y`, `CONFIG_FEATURE_SH_MATH_64=y`, `CONFIG_ENV=y`, -`CONFIG_ECHO=y`, `CONFIG_FEATURE_FANCY_ECHO=y`, `CONFIG_LOGGER=y`, and -`CONFIG_CAL=y`; BusyBox +`CONFIG_ECHO=y`, `CONFIG_FEATURE_FANCY_ECHO=y`, `CONFIG_LOGGER=y`, +`CONFIG_CAL=y`, `CONFIG_PING=y`, `CONFIG_PING6=y`, and +`CONFIG_FEATURE_FANCY_PING=y`; BusyBox `shell/Kbuild.src` links `math.o` under that configuration, while `coreutils/env.c` and `coreutils/echo.c` are linked by `lib-$(CONFIG_ENV) += env.o` and `lib-$(CONFIG_ECHO) += echo.o`, respectively, `sysklogd/logger.c` is linked through `lib-$(CONFIG_LOGGER) += syslogd_and_logger.o`, and `util-linux/cal.c` is -linked through `lib-$(CONFIG_CAL) += cal.o`. The external candidate tree +linked through `lib-$(CONFIG_CAL) += cal.o`; `networking/ping.c` is linked +through both `lib-$(CONFIG_PING) += ping.o` and +`lib-$(CONFIG_PING6) += ping.o`. The external candidate tree now binds that configuration to the 1,999-byte `archival/libarchive/bz/LICENSE` in the pinned BusyBox 1.36.1 source archive, @@ -167,6 +182,17 @@ level. It also binds the 10,951-byte `util-linux/cal.c`, whose SHA-256 is the file retains its complete Berkeley BSD-3-Clause copyright and license notice. The pinned RootFS maps `/usr/bin/cal` to `/bin/busybox`, closing `confirm-enabled-cal-license-and-attribution-coverage` at the engineering +level. It also binds the 31,080-byte `networking/ping.c`, whose SHA-256 is +`f5500d03eb8c681589cd99a861ce57bec208bfdded726b5529c61967e738a205`; +the file retains Berkeley copyright, redistribution conditions, and +disclaimer while explicitly recording removal of the advertising clause +under the 1999 licensing change. The pinned aports +`0016-ping-make-ping-work-without-root-privileges.patch` is also included in +the same external payload tree; it changes socket/runtime code without +touching the header or trailing license notice. Both the main and +guest-template RootFS trees +map `/bin/ping` and `/bin/ping6` to `/bin/busybox`, closing +`confirm-enabled-ping-and-ping6-license-and-attribution-coverage` at the engineering level. A complete set of inline third-party notices for BusyBox's other enabled components is still missing, so license-text and attribution coverage remain partial, @@ -346,13 +372,13 @@ ruby Scripts/rootfs-license-review-results.rb ``` 工具只提取 `LICENSE-REVIEW.json` 固定的候选文件,并再次核对大小、SHA-256、 -路径全集、无符号链接/特殊节点边界。结果清单证明 26 个候选已完成工程复核; +路径全集、无符号链接/特殊节点边界。结果清单证明 27 个候选已完成工程复核; 外置输出仍不是可直接随产品发行的 NOTICE bundle。 The tool extracts only candidates pinned by `LICENSE-REVIEW.json`, then rechecks byte counts, SHA-256 digests, the exact path set, and the no-symlink/ special-node boundary. The results manifest proves engineering review of all -26 candidates; the external output is still not a product-ready NOTICE bundle. +27 candidates; the external output is still not a product-ready NOTICE bundle. 剩余 8 个 source origin 的材料可继续组装为外置候选包。先校验清单;实际物化 必须同时提供已经通过 `--verify` 的 source-review 和 license-review 目录,以及 @@ -396,8 +422,8 @@ advice, or redistribution approval. 这些文件不构成完整第三方 LICENSE/NOTICE bundle、经审查的 copyleft corresponding-source 交付、法律意见或再分发授权。源码获取清单已完整覆盖固定 -inventory,26 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 -8 个 source origin 的 86 个新候选 payload 已完成 checksum-bound 工程复核; +inventory,27 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 +8 个 source origin 的 87 个新候选 payload 已完成 checksum-bound 工程复核; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、源码提供方式、法律 审查、App Store 2.5.2 产品策略和负责人批准仍是发行阻塞项。 @@ -405,8 +431,8 @@ origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、 These files are not a complete third-party LICENSE/NOTICE bundle, reviewed copyleft corresponding-source delivery, legal advice, or redistribution approval. The acquisition manifest completely covers the pinned inventory and -all 26 indexed candidates have engineering review results. `libc-dev` and -`zlib` have no remaining indexed items. All 86 newly indexed payloads have a +all 27 indexed candidates have engineering review results. `libc-dev` and +`zlib` have no remaining indexed items. All 87 newly indexed payloads have a checksum-bound engineering review; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, while five origins still need package-specific copyright/notice material. Modification, build diff --git a/Compliance/RootFS/v0.3.3/SHA256SUMS b/Compliance/RootFS/v0.3.3/SHA256SUMS index 82a5ebd..d3fa785 100644 --- a/Compliance/RootFS/v0.3.3/SHA256SUMS +++ b/Compliance/RootFS/v0.3.3/SHA256SUMS @@ -1,10 +1,10 @@ -9e87f19971b10b0dc68a4ef828fd909ad5ab8ba8b7ce53ec23869d7b6e32b4a1 EVIDENCE.json -8ae1ab5b2c5afbf524faa609e620fccfd6143d5556b627b231f1d1c6f6966158 LICENSE-INVENTORY.json -7bc5063de74731ffdc3e234bf1b9a11fc16d0aca050e5139dc7bbc127149b5f8 LICENSE-NOTICE-CANDIDATES.json -1c182a223cbbaa814e2e1c9f068a8f5149d3148329744d520b1179f56b8d5bdb LICENSE-NOTICE-REVIEW-RESULTS.json -2b27048cd9f39dedd2f03f2e5eb9b644aaea315629dc117878aaa770dc79c2a2 LICENSE-REVIEW-RESULTS.json -1edf1106bdcd2cded016b1bb584baacfa7f92bd66ccda17844e80d93f02026b2 LICENSE-REVIEW.json -07f49681978d01c14f799f55f58cf00881458b42064e2c24d98c3a8842a79473 NOTICE.md +49e128ef20c2edab48ce400f9eac9928a5711caa3a1e513213e96fa77818cee7 EVIDENCE.json +ae34396664969e747754496b39bd2aa2ebe1e4e918851acfda6eef6e05edbc10 LICENSE-INVENTORY.json +dae069cd0728343e9b50a2192c2881d53e6e5ddfc85f1ee47ed2c5ebdfdd931f LICENSE-NOTICE-CANDIDATES.json +256bf447f85b494baa7334b177a2d1072bf3cd553cf98ad380b8c062964131c7 LICENSE-NOTICE-REVIEW-RESULTS.json +584bd14ea70fae4fcc39f87fe4b1205518673daf9b46bff8ac1afa58c463d19b LICENSE-REVIEW-RESULTS.json +bf2502a04fbfba77547b0728d8ca0a2b3665b4e7539ad32aa1df3e919b7f3eff LICENSE-REVIEW.json +dba379d94654346937c91d040f1be01ab76a99c926597d8a6e29bbdea55c59de NOTICE.md 4f7f7626f3d0891a29717e4b7932c36004ecc9aac25a4aa104c300aae979e3e1 PACKAGE-INVENTORY.tsv dbca9b285015a0d8b1d339a894b4594c9e335cbc2d7f9d5212a41095ae4bd1e1 RUNTIME-CONFIGURATION.json 8e021cb8c4160c934a0202609691d7a94526cd016f4394a47da6e7a5ab41d0ea SBOM.spdx.json diff --git a/Docs/ReleaseCompliance.md b/Docs/ReleaseCompliance.md index 7d1c429..4c2738d 100644 --- a/Docs/ReleaseCompliance.md +++ b/Docs/ReleaseCompliance.md @@ -72,12 +72,12 @@ machine-readable SBOM。仓库现在从固定 archive 可复现生成 15 个已 `apk`、repository、DNS 默认配置快照。archive 内没有发现可识别的 LICENSE/COPYING/NOTICE 文件。仓库另有与 inventory 一一对应、固定 checksum 的 aports snapshot/upstream distfile 获取清单和仓库外 materializer,并固定了覆盖 -全部 10 个 source origin 的 26 个 license、attribution、声明与内联 notice 候选。 +全部 10 个 source origin 的 27 个 license、attribution、声明与内联 notice 候选。 第二个仓库外工具从已验证 source-review 目录提取这些候选;固定结果清单记录 -26/26 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source +27/27 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:13 份远端 许可证/attribution 材料、47 份 aports 补充文件和全部既有复核证据;工具可在 -仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 86 文件 payload +仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 87 文件 payload tree;`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成, 不能视为完整 NOTICE 或已批准的对应源码交付。 @@ -176,10 +176,10 @@ Alpine `apk` 可以下载、安装和执行新增代码。即使初始 RootFS - [x] 从固定 APK database 生成完整 package inventory。 - [x] 生成并通过 SPDX 2.3 JSON schema 校验的 machine-readable SBOM。 -- [x] 对固定的 26 个 license/NOTICE 候选完成 checksum-bound 工程复核。 +- [x] 对固定的 27 个 license/NOTICE 候选完成 checksum-bound 工程复核。 - [x] 为剩余 8 个 source origin 建立 checksum-bound 外置候选包索引与可复验 materializer;payload 不提交且批准门禁保持关闭。 -- [x] 对外置候选包的 86 个 payload 完成 checksum-bound 工程复核并固定结果; +- [x] 对外置候选包的 87 个 payload 完成 checksum-bound 工程复核并固定结果; 3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料。 - [ ] 收集 license text 和 NOTICE。 - [ ] 建立 copyleft corresponding source bundle。 diff --git a/Docs/Roadmap.md b/Docs/Roadmap.md index df15a72..5ddc057 100644 --- a/Docs/Roadmap.md +++ b/Docs/Roadmap.md @@ -103,7 +103,7 @@ | 最低 Xcode 16 原生兼容 | 已通过 | Xcode 16.0 / iOS 18.0 SDK 完成 RootFS install、Simulator/device final-link 和 17 项 native smoke | | App lifecycle 与内存 | 进行中 | Simulator 与 Jack iPhone 均有 256 MiB `ru_maxrss` 门禁;真机 process suspend/resume、UIKit foreground/background、强制终止后数据恢复和有界 App delegate memory-warning 回调恢复已通过;补真实 memory pressure/jetsam | | RootFS ENOSPC/掉电 | 进行中 | 峰值空间预检、全 ENOSPC、七点持久化屏障、确定性掉电切点和 Jack iPhone 受限容量/ENOSPC 清理恢复已覆盖;补真实 storage pressure/强制断电 | -| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、26/26 初始候选和 86/86 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | +| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、27/27 初始候选和 87/87 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | | App Store 2.5.2 | 阻塞 | guest download/execute policy 有书面结论 | ### 后续 runtime 执行顺序 diff --git a/Docs/RootFS.md b/Docs/RootFS.md index 97136df..85ddddb 100644 --- a/Docs/RootFS.md +++ b/Docs/RootFS.md @@ -5,7 +5,7 @@ RootFS 是 PocketRoot 的外部供应链输入,不是普通测试 fixture。仓库提交的是不可变清单、校验和安全安装代码,不提交、镜像或默认打包 RootFS 二进制。 > [!WARNING] -> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 26 个初始候选和 86 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 +> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 27 个初始候选和 87 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 ## 1. 固定清单 @@ -118,7 +118,7 @@ receipt schema v2 强制包含该模式。旧 v1 source-review 的传输来源 规范化 aports 目录身份覆盖条目类型、路径、普通文件权限位和内容摘要;物化时会保留 这些权限位,`--verify` 会再次校验。 -在 source-review 目录验证通过后,可把固定的 26 个候选许可证/attribution 文件 +在 source-review 目录验证通过后,可把固定的 27 个候选许可证/attribution 文件 提取到另一个仓库外目录: ```bash @@ -139,7 +139,7 @@ ruby Scripts/rootfs-license-review-results.rb `APKBUILD`;`--verify` 会复核普通文件摘要、目录集合和符号链接目标。脚本不向 App、 Git 或 CI artifact 自动添加输出。这完成的是可复现的工程获取流程。archive 内没有 随附可识别的 LICENSE/COPYING/NOTICE 文件。候选工具会核对提取文件的大小、 -SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 26/26 个候选均已 +SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 27/27 个候选均已 工程复核,其中 `libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有 未决项;输出不能直接视为完整 NOTICE 或对应源码交付材料。 @@ -167,7 +167,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ ``` 工具对远端材料强制 HTTPS、重定向次数、响应大小、固定字节数与 SHA-256,并原子 -创建输出。结果清单把工程复核绑定到精确的 86 文件 payload tree;复验器拒绝路径 +创建输出。结果清单把工程复核绑定到精确的 87 文件 payload tree;复验器拒绝路径 漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools`、 `openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包 材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 diff --git a/Docs/en/ReleaseCompliance.md b/Docs/en/ReleaseCompliance.md index d3b6efc..48a66fd 100644 --- a/Docs/en/ReleaseCompliance.md +++ b/Docs/en/ReleaseCompliance.md @@ -36,15 +36,15 @@ the default `apk`, repository, and DNS snapshot. No identifiable LICENSE/COPYING/NOTICE file was found in the archive. A checksum-pinned aports-snapshot/upstream-distfile manifest covers the inventory, and an outside-repository materializer creates reproducible review inputs. A second -outside-repository tool pins, extracts, and verifies 26 license, attribution, +outside-repository tool pins, extracts, and verifies 27 license, attribution, declaration, and inline-notice candidates across all 10 source origins. -A pinned result manifest records engineering review of all 26 candidates. +A pinned result manifest records engineering review of all 27 candidates. `libc-dev` and `zlib` have no remaining indexed items; eight source origins still have package-level follow-up. The repository now pins an external candidate bundle for those origins: 13 remote license/attribution payloads, 47 supplemental aports files, and all existing reviewed evidence. The tool can atomically materialize and re-verify it outside the repository. A pinned -results manifest binds engineering review to the exact 86-file payload tree. +results manifest binds engineering review to the exact 87-file payload tree. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. Modification, build-completeness, source-offer, and legal reviews remain unresolved, so the @@ -117,12 +117,12 @@ The current code does not provide a complete product-level privacy policy. - [x] Generate a complete inventory from the pinned APK database. - [x] Generate a machine-readable SBOM validated against the SPDX 2.3 JSON schema. -- [x] Complete checksum-bound engineering review of all 26 pinned +- [x] Complete checksum-bound engineering review of all 27 pinned license/NOTICE candidates. - [x] Index a checksum-bound external candidate bundle and reproducible materializer for the eight remaining origins; payloads stay uncommitted and approval gates stay closed. -- [x] Complete checksum-bound engineering review of all 86 external candidate +- [x] Complete checksum-bound engineering review of all 87 external candidate payloads; three origins have no remaining candidate-material engineering items and five still need package-specific material. - [ ] Collect license texts and NOTICE files. diff --git a/Docs/en/Roadmap.md b/Docs/en/Roadmap.md index 703b6a6..56f76ae 100644 --- a/Docs/en/Roadmap.md +++ b/Docs/en/Roadmap.md @@ -98,7 +98,7 @@ This establishes the current Simulator, minimum-Xcode 16, and single-iPhone one- | Minimum Xcode 16 native | Passed | Xcode 16.0 / iOS 18.0 SDK completed RootFS install, Simulator/device final links, and the 17-check native smoke | | App lifecycle and memory | In progress | Simulator and Jack iPhone have 256 MiB `ru_maxrss` gates; physical process suspend/resume, UIKit foreground/background, post-termination data recovery, and bounded App-delegate memory-warning recovery passed; add real memory-pressure/jetsam evidence | | RootFS ENOSPC/power faults | In progress | Peak-space preflight, full ENOSPC, seven persistence barriers, deterministic power-loss cuts, and bounded capacity/ENOSPC cleanup recovery on Jack iPhone are covered; add real storage-pressure/power-cut evidence | -| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 26 initial candidates, and all 86 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | +| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 27 initial candidates, and all 87 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | | App Store 2.5.2 | Blocked | Written guest download/execute policy decision | ### Next runtime sequence diff --git a/Docs/en/RootFS.md b/Docs/en/RootFS.md index 7b79715..74d482f 100644 --- a/Docs/en/RootFS.md +++ b/Docs/en/RootFS.md @@ -5,7 +5,7 @@ A RootFS is an external supply-chain input, not a normal fixture. PocketRoot commits immutable metadata and secure install code, not the payload. > [!WARNING] -> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 26 initial candidates and all 86 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. +> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 27 initial candidates and all 87 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. ## Pinned manifest @@ -95,7 +95,7 @@ Receipt schema v2 requires that explicit mode. A legacy v1 source-review directory has ambiguous transport provenance and is no longer accepted by `--verify`; pass it to `--download-cache` to regenerate a verifiable v2 bundle. -After that source-review directory verifies, extract the 26 pinned +After that source-review directory verifies, extract the 27 pinned license/attribution candidates into another directory outside the repository: ```bash @@ -122,7 +122,7 @@ engineering acquisition workflow, not legal review. The RootFS archive contains no identifiable LICENSE/COPYING/NOTICE files. The candidate tool rechecks extracted byte counts, SHA-256 digests, the exact path set, and the no-link/special-node boundary. The pinned results record engineering review of -all 26 candidates: `libc-dev` and `zlib` have no remaining indexed items, while +all 27 candidates: `libc-dev` and `zlib` have no remaining indexed items, while eight source origins still require follow-up. The output is not a completed NOTICE or corresponding-source delivery bundle. @@ -152,7 +152,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ The tool enforces HTTPS, redirect and response-size bounds, pinned byte counts and SHA-256 digests, and atomic output creation. The results bind engineering -review to the exact 86-file payload tree; the verifier rejects path drift, +review to the exact 87-file payload tree; the verifier rejects path drift, links, special nodes, known-digest drift, and tree-digest drift. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. The candidate NOTICE diff --git a/README.md b/README.md index eab848c..41b7bfb 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ print("stderr:", result.stderr) - 展开大小:`18,838,016` 字节 - SHA-256:`be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4` -固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 26 个初始候选及 86 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 +固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 27 个初始候选及 87 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 ## 验证命令 diff --git a/Scripts/rootfs-license-notice-candidates.rb b/Scripts/rootfs-license-notice-candidates.rb index 7a5abad..b44c23b 100644 --- a/Scripts/rootfs-license-notice-candidates.rb +++ b/Scripts/rootfs-license-notice-candidates.rb @@ -20,7 +20,7 @@ module RootFSLicenseNoticeCandidates alpine-baselayout alpine-keys apk-tools busybox ca-certificates musl openssl pax-utils ].freeze - EXPECTED_EXISTING_EVIDENCE_FILES = 26 + EXPECTED_EXISTING_EVIDENCE_FILES = 27 EXPECTED_REMOTE_PAYLOAD_FILES = 13 EXPECTED_APORTS_FILES = 47 PAYLOAD_KINDS = %w[package-attribution spdx-license-text].freeze diff --git a/Scripts/rootfs-license-notice-review-results.rb b/Scripts/rootfs-license-notice-review-results.rb index dc99960..6593631 100644 --- a/Scripts/rootfs-license-notice-review-results.rb +++ b/Scripts/rootfs-license-notice-review-results.rb @@ -22,7 +22,7 @@ module RootFSLicenseNoticeReviewResults COVERAGE = %w[complete partial reference-only].freeze SHA256_PATTERN = /\A[0-9a-f]{64}\z/ CANDIDATE_PAYLOAD_TREE_FORMAT = "sha256-path-lines-v1" - EXPECTED_REVIEWED_PAYLOAD_FILES = 86 + EXPECTED_REVIEWED_PAYLOAD_FILES = 87 MAX_REVIEWED_PAYLOAD_BYTES = 8 * 1_024 * 1_024 TOP_LEVEL_KEYS = %w[ allIndexedCandidatePayloadsReviewed archive candidateManifestSha256 diff --git a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb index d4074b9..69f164d 100644 --- a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb @@ -29,7 +29,7 @@ def test_validates_complete_open_origin_candidate_index assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length - assert_equal 26, validated.fetch(:existing_evidence_paths).length + assert_equal 27, validated.fetch(:existing_evidence_paths).length assert_equal 47, validated.fetch(:aports_paths).length end @@ -399,6 +399,49 @@ def test_pins_enabled_busybox_cal_inline_notice ) end + def test_pins_enabled_busybox_ping_and_ping6_inline_notice + source = @candidate.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + review_source = @review.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + evidence = review_source.fetch("candidateEvidence").find do |candidate| + candidate.fetch("outputPath") == "evidence/busybox/networking-ping.c" + end + + assert_includes( + source.fetch("existingEvidencePaths"), + "evidence/busybox/networking-ping.c" + ) + assert_includes( + source.fetch("supplementalAportsPaths"), + "aports/busybox/busyboxconfig" + ) + assert_includes( + source.fetch("supplementalAportsPaths"), + "aports/busybox/0016-ping-make-ping-work-without-root-privileges.patch" + ) + assert_includes( + source.fetch("remainingReviewItems"), + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage" + ) + assert_includes( + source.fetch("remainingReviewItems"), + "review-other-bundled-third-party-license-and-attribution-coverage" + ) + assert_equal "busybox-1.36.1/networking/ping.c", evidence.fetch("member") + assert_equal 31_080, evidence.fetch("byteCount") + assert_equal( + "f5500d03eb8c681589cd99a861ce57bec208bfdded726b5529c61967e738a205", + evidence.fetch("sha256") + ) + assert_equal( + %w[inline-license-notice attribution], + evidence.fetch("evidenceKinds") + ) + end + def test_rejects_overlapping_materialized_output_paths payloads = @candidate.fetch("remotePayloads") payloads.fetch(0)["outputPath"] = "licenses/collision" diff --git a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb index 51906b2..a67a665 100644 --- a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb @@ -47,7 +47,7 @@ def test_validates_pinned_candidate_review_results assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length assert_equal 47, validated.fetch(:aports_paths).length - assert_equal 86, @results.fetch("reviewedPayloadFileCount") + assert_equal 87, @results.fetch("reviewedPayloadFileCount") assert_equal 5, @results.fetch("sourceOriginsWithRemainingReviewItems") assert_equal %w[apk-tools openssl pax-utils], @@ -136,7 +136,7 @@ def test_binds_enabled_busybox_ash_math_to_inline_notices assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 8, source.fetch("reviewedExistingEvidenceCount") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-ash-math-license-and-attribution-coverage" @@ -158,7 +158,7 @@ def test_binds_enabled_busybox_env_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 8, source.fetch("reviewedExistingEvidenceCount") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-env-license-and-attribution-coverage" @@ -180,7 +180,7 @@ def test_binds_enabled_busybox_echo_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 8, source.fetch("reviewedExistingEvidenceCount") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-echo-license-and-attribution-coverage" @@ -202,7 +202,7 @@ def test_binds_enabled_busybox_logger_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 8, source.fetch("reviewedExistingEvidenceCount") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-logger-license-and-attribution-coverage" @@ -224,7 +224,7 @@ def test_binds_enabled_busybox_cal_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 8, source.fetch("reviewedExistingEvidenceCount") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-cal-license-and-attribution-coverage" @@ -239,6 +239,28 @@ def test_binds_enabled_busybox_cal_to_inline_notice ) end + def test_binds_enabled_busybox_ping_and_ping6_to_inline_notice + source = @results.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + + assert_equal "partial", source.fetch("licenseTextCoverage") + assert_equal "partial", source.fetch("attributionCoverage") + assert_equal 9, source.fetch("reviewedExistingEvidenceCount") + assert_includes( + source.fetch("resolvedReviewItems"), + "confirm-enabled-ping-and-ping6-license-and-attribution-coverage" + ) + assert_equal( + ["review-other-bundled-third-party-license-and-attribution-coverage"], + source.fetch("remainingReviewItems") + ) + assert_equal( + "additional-package-material-required", + source.fetch("engineeringConclusion") + ) + end + def test_rejects_candidate_manifest_digest_drift @candidates["status"] = "changed" diff --git a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb index 45bde8b..b13803f 100644 --- a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb @@ -39,7 +39,7 @@ def test_validates_pinned_engineering_review_results sources = validate assert_equal 10, sources.length - assert_equal 26, + assert_equal 27, sources.sum { |entry| entry.fetch("candidateResults").length } assert_equal 8, sources.count { |entry| !entry.fetch("remainingReviewItems").empty? }