diff --git a/CHANGELOG.en.md b/CHANGELOG.en.md index 52852b1..f0c273c 100644 --- a/CHANGELOG.en.md +++ b/CHANGELOG.en.md @@ -32,17 +32,17 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit declared-license/attribution inventories, and default `apk`, repository, and DNS configuration; complete LICENSE/NOTICE and corresponding-source bundles remain distribution blockers. -- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 32 +- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 34 pinned RootFS license/NOTICE candidates have engineering review results; eight source origins retain package-level open items, and legal and redistribution gates remain closed. - A checksum-bound `LICENSE-NOTICE-CANDIDATES.json`, strict validator, and outside-repository atomic materializer for the eight remaining RootFS source origins. It indexes 13 remote license/attribution payloads, 47 aports files, - and the 32 existing evidence files for complete re-verification without + and the 34 existing evidence files for complete re-verification without committing payloads or opening engineering, legal, or redistribution gates. - `LICENSE-NOTICE-REVIEW-RESULTS.json` and a strict external payload-tree - verifier. All 92 candidate payloads now have checksum-bound engineering + verifier. All 94 candidate payloads now have checksum-bound engineering review. The pinned upstream `alpine-keys` GPL-to-MIT license-decision commit is included while its package-level copyright notice remains open. The `ca-certificates` generator is byte-identical to curl commit `3fdc4bdb`, and @@ -58,7 +58,10 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit the original BSD/LBL notice for traceroute. The desktop `od` build includes `coreutils/od.c` and `coreutils/od_bloaty.c`, while `hexdump` and `hd` share `util-linux/hexdump.c` and use `libbb/dump.c`, covering the complete Regents - BSD terms, FSF attribution, and GPL declarations. Other inline notices stay open; + BSD terms, FSF attribution, and GPL declarations. `expand` and `unexpand` + share `coreutils/expand.c`, while `fold` links `coreutils/fold.c`; both + sources retain FSF copyright, GPLv2-or-later declarations, and BusyBox port + attribution. Other inline notices stay open; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, five origins still need package-specific material, and diff --git a/CHANGELOG.md b/CHANGELOG.md index bf61738..9f089d9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -30,15 +30,15 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 10 个 source origin、SPDX 2.3 JSON SBOM、许可证声明/attribution inventory 和 `apk`、repository、DNS 默认配置快照;完整 LICENSE/NOTICE 与对应源码 bundle 仍保持发行阻塞。 -- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;32/32 个固定 +- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;34/34 个固定 RootFS license/NOTICE 候选已完成工程复核,8 个 source origin 仍有包级未决项, 法律与再分发门禁保持关闭。 - 为剩余 8 个 RootFS source origin 加入 checksum-bound `LICENSE-NOTICE-CANDIDATES.json`、严格验证器和仓库外原子 materializer;索引 - 13 份远端许可证/attribution 材料、47 份 aports 文件与 32 份既有证据,支持完整 + 13 份远端许可证/attribution 材料、47 份 aports 文件与 34 份既有证据,支持完整 复验,但不提交 payload,也不解除工程、法律或再分发门禁。 - 加入 `LICENSE-NOTICE-REVIEW-RESULTS.json` 和严格外置 payload-tree 复验器; - 92/92 个候选 payload 已完成 checksum-bound 工程复核;新增固定 + 94/94 个候选 payload 已完成 checksum-bound 工程复核;新增固定 `alpine-keys` GPL→MIT 上游许可判定提交,但仍保留包级版权声明缺口; `ca-certificates` 生成脚本与 curl 提交 `3fdc4bdb` 字节一致并固定该精确 revision 的 curl 授权文本,trust-store 审查仍保持未决; @@ -51,7 +51,9 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se `networking/traceroute.c`;`od` 的 desktop 构建链入 `coreutils/od.c` 与 `coreutils/od_bloaty.c`,`hexdump`/`hd` 共同链入 `util-linux/hexdump.c` 并使用 `libbb/dump.c`,覆盖完整 Regents BSD 条款、FSF attribution 与 GPL - 声明;其他内联第三方 notices 继续保持未决; + 声明;`expand`/`unexpand` 共同链入 `coreutils/expand.c`,`fold` 链入 + `coreutils/fold.c`,两份源码均保留 FSF 版权、GPLv2-or-later 声明与 BusyBox + 改写署名;其他内联第三方 notices 继续保持未决; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项关闭,另外 5 个 origin 仍需补逐包材料,法律和再分发门禁保持关闭。 - RootFS source-review materializer 新增严格仓库外下载缓存输入;缓存只替代网络 diff --git a/Compliance/RootFS/v0.3.3/EVIDENCE.json b/Compliance/RootFS/v0.3.3/EVIDENCE.json index 184c1db..1da9fb6 100644 --- a/Compliance/RootFS/v0.3.3/EVIDENCE.json +++ b/Compliance/RootFS/v0.3.3/EVIDENCE.json @@ -39,13 +39,13 @@ "sourceOrigins": 10, "declaredLicenseExpressions": 7, "licenseOrNoticeFilesInGuestTemplate": 0, - "indexedExternalLicenseReviewCandidates": 32, - "engineeringReviewedLicenseCandidates": 32, + "indexedExternalLicenseReviewCandidates": 34, + "engineeringReviewedLicenseCandidates": 34, "sourceOriginsWithRemainingLicenseReviewItems": 8, "indexedLicenseNoticeCandidateOrigins": 8, "pinnedRemoteLicenseNoticePayloads": 13, "supplementalAportsCandidateFiles": 47, - "engineeringReviewedLicenseNoticeCandidatePayloads": 92, + "engineeringReviewedLicenseNoticeCandidatePayloads": 94, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5 }, "engineeringStatus": { diff --git a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json index e886667..33966a4 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json @@ -26,14 +26,14 @@ "licenseOrNoticeFilesFoundInGuestTemplate": [ ], - "indexedExternalReviewCandidates": 32, - "engineeringReviewedCandidates": 32, + "indexedExternalReviewCandidates": 34, + "engineeringReviewedCandidates": 34, "sourceOriginsWithOpenReviewItems": 10, "sourceOriginsWithRemainingReviewItems": 8, "indexedOpenSourceOrigins": 8, "pinnedRemoteReferencePayloads": 13, "supplementalAportsFiles": 47, - "engineeringReviewedCandidatePayloads": 92, + "engineeringReviewedCandidatePayloads": 94, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5, "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json index aeebb53..519fd6d 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewResultsSha256": "e3ad43e944b822f46cfe74a6769b5bd70ea774d2010bb4b3be85d567e63f590e", + "licenseReviewResultsSha256": "631538681cc635632ac0dc953cab8d2bb142b91dfdbf51fd2ad0edd33d8d5eaa", "status": "candidate-bundle-indexed-engineering-review-required", "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, @@ -256,7 +256,9 @@ "evidence/busybox/coreutils-od.c", "evidence/busybox/coreutils-od_bloaty.c", "evidence/busybox/util-linux-hexdump.c", - "evidence/busybox/libbb-dump.c" + "evidence/busybox/libbb-dump.c", + "evidence/busybox/coreutils-expand.c", + "evidence/busybox/coreutils-fold.c" ], "referenceLicensePaths": [ "licenses/GPL-2.0.txt" @@ -311,6 +313,7 @@ "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage", "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage", + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ], diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json index b666fec..1979389 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "candidateManifestSha256": "7fd00f5f3e980fc8590100ee27ed122c65fec0dd1102d0f18268cfe27ccc852b", + "candidateManifestSha256": "056043693f154ac9d9df31c3a65e8ed5b546b24c7d0bec0683a24da9fb83e987", "status": "candidate-payloads-engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allIndexedCandidatePayloadsReviewed": true, @@ -13,8 +13,8 @@ "legalReviewApproved": false, "redistributionApproved": false, "candidatePayloadTreeFormat": "sha256-path-lines-v1", - "candidatePayloadTreeSha256": "80c88a9327ce6df178fb3d9dc0c6def2b80a27b270b83c93b2861bd13cb558e5", - "reviewedPayloadFileCount": 92, + "candidatePayloadTreeSha256": "56419961808ba864deabd901620bd59eee9d551b2b1db0a3ed7b1188bd20f69d", + "reviewedPayloadFileCount": 94, "reviewedClosedOriginEvidenceCount": 4, "sourceOriginsWithRemainingReviewItems": 5, "sources": [ @@ -82,7 +82,7 @@ "reviewState": "candidate-payloads-engineering-reviewed-legal-review-open", "licenseTextCoverage": "partial", "attributionCoverage": "partial", - "reviewedExistingEvidenceCount": 14, + "reviewedExistingEvidenceCount": 16, "reviewedReferenceLicenseCount": 1, "reviewedSupplementalAportsCount": 37, "reviewedRemoteEvidenceCount": 0, @@ -96,7 +96,8 @@ "confirm-enabled-cal-license-and-attribution-coverage", "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage", - "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage" + "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage", + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage" ], "remainingReviewItems": [ "review-other-bundled-third-party-license-and-attribution-coverage" diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json index 5fdeb21..e5ef2be 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json @@ -4,11 +4,11 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewManifestSha256": "bf7ddbfae242c3a5fc5de1dfc735ef8a0cf732f251fa63aabd6c9ebc8be35547", + "licenseReviewManifestSha256": "45e86e2945da28137723aab628141939fc8979945abf9467173fec085467907f", "status": "engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allCandidateDigestsVerified": true, - "reviewedCandidateCount": 32, + "reviewedCandidateCount": 34, "sourceOriginsWithRemainingReviewItems": 8, "completeLicenseTextBundlePresent": false, "completePackageNoticeSetPresent": false, @@ -159,6 +159,16 @@ "outputPath": "evidence/busybox/libbb-dump.c", "sha256": "a1c705a48bd6eb43b4cb9cfb74d61f47f8500b601ebd9d3502906093f7c8ddfe", "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/coreutils-expand.c", + "sha256": "66296875f04016bba0721d4fa80393317ffca014e4b4722ed8e7e7fb1c882802", + "conclusion": "license-header-and-attribution" + }, + { + "outputPath": "evidence/busybox/coreutils-fold.c", + "sha256": "db291cf01ee9a90244607c88a5d88ddf7d2600237eca6f2d7a6894815928cdef", + "conclusion": "license-header-and-attribution" } ], "resolvedReviewItems": [], @@ -172,6 +182,7 @@ "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage", "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage", + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ] diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json index f146d6c..6154a87 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json @@ -295,6 +295,32 @@ "attribution" ], "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/expand.c", + "outputPath": "evidence/busybox/coreutils-expand.c", + "byteCount": 6393, + "sha256": "66296875f04016bba0721d4fa80393317ffca014e4b4722ed8e7e7fb1c882802", + "evidenceKinds": [ + "license-declaration", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/fold.c", + "outputPath": "evidence/busybox/coreutils-fold.c", + "byteCount": 5018, + "sha256": "db291cf01ee9a90244607c88a5d88ddf7d2600237eca6f2d7a6894815928cdef", + "evidenceKinds": [ + "license-declaration", + "attribution" + ], + "reviewState": "unreviewed-candidate" } ], "openReviewItems": [ @@ -307,6 +333,7 @@ "confirm-enabled-ping-and-ping6-license-and-attribution-coverage", "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage", "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage", + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage", "review-other-bundled-third-party-license-and-attribution-coverage", "confirm-aports-patch-notices" ] diff --git a/Compliance/RootFS/v0.3.3/NOTICE.md b/Compliance/RootFS/v0.3.3/NOTICE.md index d799ea6..6abc5dd 100644 --- a/Compliance/RootFS/v0.3.3/NOTICE.md +++ b/Compliance/RootFS/v0.3.3/NOTICE.md @@ -33,12 +33,12 @@ Generated from the exact `v0.3.3` archive with SHA-256 No file whose path identifies it as LICENSE, COPYING, NOTICE, or a license-directory member was found in the guest template. Declared identifiers and expressions are recorded in -`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 32 +`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 34 candidate license, attribution, declaration, and inline-notice files across all 10 source origins. The external review tool extracts and verifies those candidates from the pinned source-review bundle. `LICENSE-REVIEW-RESULTS.json` records the checksum-bound engineering review -of all 32 candidates. All indexed review items are resolved +of all 34 candidates. All indexed review items are resolved for `libc-dev`, `zlib`. 8 source origins still have package-specific open items, so this is not a complete or legally approved license/NOTICE bundle. @@ -49,7 +49,7 @@ reference/attribution payloads and files, together with all checksum-bound reviewed evidence. The repository tool can materialize and re-verify that bundle outside the repository. `LICENSE-NOTICE-REVIEW-RESULTS.json` records checksum-bound engineering -review of all 92 indexed +review of all 94 indexed payload files. 3 origins have no remaining candidate-material engineering items; 5 origins still require package-specific material. Legal review and redistribution diff --git a/Compliance/RootFS/v0.3.3/README.md b/Compliance/RootFS/v0.3.3/README.md index dfe1ba3..91178a5 100644 --- a/Compliance/RootFS/v0.3.3/README.md +++ b/Compliance/RootFS/v0.3.3/README.md @@ -16,14 +16,14 @@ pinned RootFS archive. It does not store the RootFS payload. SHA-256; - `LICENSE-INVENTORY.json`:声明的许可证表达式、标识符和 archive 内 license/notice 文件检查结果; -- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 32 个候选许可证文本、 +- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 34 个候选许可证文本、 attribution、声明与内联 notice 的路径、大小、SHA-256 和逐包未决审查项; -- `LICENSE-REVIEW-RESULTS.json`:对全部 32 个候选的 checksum-bound 工程复核 +- `LICENSE-REVIEW-RESULTS.json`:对全部 34 个候选的 checksum-bound 工程复核 结论、coverage 和未决项处置;不表示法律或再分发批准; - `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 13 份远端 - 许可证/attribution 材料、47 份 aports 补充文件及现有 32 份复核证据的外置候选包; + 许可证/attribution 材料、47 份 aports 补充文件及现有 34 份复核证据的外置候选包; payload 不提交,工程、法律和再分发门禁保持关闭; -- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 92 个 payload 文件树的 +- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 94 个 payload 文件树的 工程复核结果;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,法律和 再分发门禁保持关闭; - `RUNTIME-CONFIGURATION.json`:guest、`apk`、repository、world 和 DNS 默认配置; @@ -34,15 +34,15 @@ pinned RootFS archive. It does not store the RootFS payload. `SOURCE-ACQUISITION.json` pins the aports snapshots and upstream distfiles needed to assemble an external source-review directory. It is an acquisition manifest, not a committed source archive or redistribution grant. -`LICENSE-REVIEW.json` pins 32 unreviewed candidate evidence files across all +`LICENSE-REVIEW.json` pins 34 unreviewed candidate evidence files across all 10 source origins; it is an engineering review index, not legal approval. -`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 32 pinned +`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 34 pinned candidates. Two source origins have no remaining indexed review items; eight still have package-specific open items. `LICENSE-NOTICE-CANDIDATES.json` indexes an external candidate bundle for those eight origins: 13 pinned remote license/attribution payloads, 47 supplemental aports files, and the existing -32 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the -engineering review to the exact 92-file payload tree. Three origins have no +34 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the +engineering review to the exact 94-file payload tree. Three origins have no remaining candidate-material engineering items; five still require package-specific material. Legal and redistribution approval remain open. @@ -83,7 +83,8 @@ change. `CONFIG_FEATURE_FANCY_PING=y`、`CONFIG_TRACEROUTE=y`、 `CONFIG_TRACEROUTE6=y`、`CONFIG_FEATURE_TRACEROUTE_VERBOSE=y` 和 `CONFIG_FEATURE_TRACEROUTE_USE_ICMP=y`,以及 `CONFIG_DESKTOP=y`、 -`CONFIG_OD=y`、`CONFIG_HEXDUMP=y` 和 `CONFIG_HD=y`;BusyBox +`CONFIG_OD=y`、`CONFIG_HEXDUMP=y`、`CONFIG_HD=y`、`CONFIG_EXPAND=y`、 +`CONFIG_UNEXPAND=y` 和 `CONFIG_FOLD=y`;BusyBox `shell/Kbuild.src` 在该配置下把 `math.o` 链入构建,`coreutils/env.c` 与 `coreutils/echo.c` 则分别通过 `lib-$(CONFIG_ENV) += env.o` 和 `lib-$(CONFIG_ECHO) += echo.o` 链入,`sysklogd/logger.c` 通过 @@ -96,7 +97,10 @@ change. 链入;`coreutils/od.c` 通过 `lib-$(CONFIG_OD) += od.o` 链入,并在 `ENABLE_DESKTOP` 分支直接包含 `coreutils/od_bloaty.c`; `util-linux/hexdump.c` 通过 `CONFIG_HEXDUMP` 与 `CONFIG_HD` 两条规则链入, -并调用由 `libbb/Kbuild.src` 的 `lib-y += dump.o` 提供的 `libbb/dump.c`。 +并调用由 `libbb/Kbuild.src` 的 `lib-y += dump.o` 提供的 `libbb/dump.c`; +`coreutils/expand.c` 同时通过 `lib-$(CONFIG_EXPAND) += expand.o` 与 +`lib-$(CONFIG_UNEXPAND) += expand.o` 链入,`coreutils/fold.c` 通过 +`lib-$(CONFIG_FOLD) += fold.o` 链入。 外置候选树现同时绑定该 配置与固定 BusyBox 1.36.1 源包中的 1,999 字节 @@ -163,6 +167,19 @@ payload 树中;它只修改 socket/runtime 代码,不触及文件头或文 `confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage`。 这只确认精确源码与 notice 证据完整,不判断 GPL 版本选择、组合或发行方案的 法律兼容性。 +同时绑定 6,393 字节 `coreutils/expand.c`(SHA-256 +`66296875f04016bba0721d4fa80393317ffca014e4b4722ed8e7e7fb1c882802`)与 +5,018 字节 `coreutils/fold.c`(SHA-256 +`db291cf01ee9a90244607c88a5d88ddf7d2600237eca6f2d7a6894815928cdef`)。 +`expand.c` 保留 FSF 版权、GPLv2-or-later 声明、David MacKenzie attribution +与 Tito Ragusa 的 BusyBox 改写署名;`fold.c` 保留 FSF 版权、 +GPLv2-or-later 声明、David MacKenzie attribution 与 Glenn McGrath 的 BusyBox +改写署名。固定 aports 补丁集没有修改这两个文件;固定 RootFS 主树与 guest +模板树中的 `/usr/bin/expand`、`/usr/bin/unexpand` 和 `/usr/bin/fold` 均指向 +`/bin/busybox`,因此在工程层关闭 +`confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage`。 +这只确认精确源码与声明/署名证据完整,不判断 GPL 版本选择、组合或发行方案的 +法律兼容性。 BusyBox 其他已启用 组件的内联第三方 notice 尚未形成完整集合,因此 license-text 与 attribution coverage 均保持 partial, @@ -180,7 +197,8 @@ It explicitly enables `CONFIG_BZIP2=y`, `CONFIG_BZIP2_SMALL=8`, `CONFIG_FEATURE_FANCY_PING=y`, `CONFIG_TRACEROUTE=y`, `CONFIG_TRACEROUTE6=y`, `CONFIG_FEATURE_TRACEROUTE_VERBOSE=y`, and `CONFIG_FEATURE_TRACEROUTE_USE_ICMP=y`, plus `CONFIG_DESKTOP=y`, -`CONFIG_OD=y`, `CONFIG_HEXDUMP=y`, and `CONFIG_HD=y`; BusyBox +`CONFIG_OD=y`, `CONFIG_HEXDUMP=y`, `CONFIG_HD=y`, `CONFIG_EXPAND=y`, +`CONFIG_UNEXPAND=y`, and `CONFIG_FOLD=y`; BusyBox `shell/Kbuild.src` links `math.o` under that configuration, while `coreutils/env.c` and `coreutils/echo.c` are linked by `lib-$(CONFIG_ENV) += env.o` and `lib-$(CONFIG_ECHO) += echo.o`, @@ -194,7 +212,10 @@ both `lib-$(CONFIG_TRACEROUTE) += traceroute.o` and `lib-$(CONFIG_OD) += od.o` and directly includes `coreutils/od_bloaty.c` under `ENABLE_DESKTOP`; `util-linux/hexdump.c` is linked by both `CONFIG_HEXDUMP` and `CONFIG_HD` and calls the `libbb/dump.c` implementation supplied by -`lib-y += dump.o` in `libbb/Kbuild.src`. The external candidate tree +`lib-y += dump.o` in `libbb/Kbuild.src`; `coreutils/expand.c` is linked by +both `lib-$(CONFIG_EXPAND) += expand.o` and +`lib-$(CONFIG_UNEXPAND) += expand.o`, while `coreutils/fold.c` is linked by +`lib-$(CONFIG_FOLD) += fold.o`. The external candidate tree now binds that configuration to the 1,999-byte `archival/libarchive/bz/LICENSE` in the pinned BusyBox 1.36.1 source archive, @@ -267,7 +288,23 @@ both the main and guest-template RootFS trees map `/usr/bin/od`, `confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage` at the engineering level. This confirms exact source and notice evidence only; it does not determine the legal compatibility of GPL version selection, -combination, or the distribution plan. A complete set of inline third-party notices for BusyBox's other +combination, or the distribution plan. It also binds the 6,393-byte +`coreutils/expand.c` with SHA-256 +`66296875f04016bba0721d4fa80393317ffca014e4b4722ed8e7e7fb1c882802` and +the 5,018-byte `coreutils/fold.c` with SHA-256 +`db291cf01ee9a90244607c88a5d88ddf7d2600237eca6f2d7a6894815928cdef`. +`expand.c` retains the FSF copyright, GPLv2-or-later declaration, David +MacKenzie attribution, and Tito Ragusa's BusyBox port attribution; `fold.c` +retains the FSF copyright, GPLv2-or-later declaration, David MacKenzie +attribution, and Glenn McGrath's BusyBox port attribution. The pinned aports +patch set does not modify either file, and both the main and guest-template +RootFS trees map `/usr/bin/expand`, `/usr/bin/unexpand`, and `/usr/bin/fold` +to `/bin/busybox`, closing +`confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage` +at the engineering level. This confirms exact source, declaration, and +attribution evidence only; it does not determine the legal compatibility of +GPL version selection, combination, or the distribution plan. A complete set +of inline third-party notices for BusyBox's other enabled components is still missing, so license-text and attribution coverage remain partial, `review-other-bundled-third-party-license-and-attribution-coverage` remains @@ -446,13 +483,13 @@ ruby Scripts/rootfs-license-review-results.rb ``` 工具只提取 `LICENSE-REVIEW.json` 固定的候选文件,并再次核对大小、SHA-256、 -路径全集、无符号链接/特殊节点边界。结果清单证明 32 个候选已完成工程复核; +路径全集、无符号链接/特殊节点边界。结果清单证明 34 个候选已完成工程复核; 外置输出仍不是可直接随产品发行的 NOTICE bundle。 The tool extracts only candidates pinned by `LICENSE-REVIEW.json`, then rechecks byte counts, SHA-256 digests, the exact path set, and the no-symlink/ special-node boundary. The results manifest proves engineering review of all -32 candidates; the external output is still not a product-ready NOTICE bundle. +34 candidates; the external output is still not a product-ready NOTICE bundle. 剩余 8 个 source origin 的材料可继续组装为外置候选包。先校验清单;实际物化 必须同时提供已经通过 `--verify` 的 source-review 和 license-review 目录,以及 @@ -496,8 +533,8 @@ advice, or redistribution approval. 这些文件不构成完整第三方 LICENSE/NOTICE bundle、经审查的 copyleft corresponding-source 交付、法律意见或再分发授权。源码获取清单已完整覆盖固定 -inventory,32 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 -8 个 source origin 的 92 个新候选 payload 已完成 checksum-bound 工程复核; +inventory,34 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 +8 个 source origin 的 94 个新候选 payload 已完成 checksum-bound 工程复核; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、源码提供方式、法律 审查、App Store 2.5.2 产品策略和负责人批准仍是发行阻塞项。 @@ -505,8 +542,8 @@ origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、 These files are not a complete third-party LICENSE/NOTICE bundle, reviewed copyleft corresponding-source delivery, legal advice, or redistribution approval. The acquisition manifest completely covers the pinned inventory and -all 32 indexed candidates have engineering review results. `libc-dev` and -`zlib` have no remaining indexed items. All 92 newly indexed payloads have a +all 34 indexed candidates have engineering review results. `libc-dev` and +`zlib` have no remaining indexed items. All 94 newly indexed payloads have a checksum-bound engineering review; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, while five origins still need package-specific copyright/notice material. Modification, build diff --git a/Compliance/RootFS/v0.3.3/SHA256SUMS b/Compliance/RootFS/v0.3.3/SHA256SUMS index 9f29395..56226b0 100644 --- a/Compliance/RootFS/v0.3.3/SHA256SUMS +++ b/Compliance/RootFS/v0.3.3/SHA256SUMS @@ -1,10 +1,10 @@ -29db1a51a7971e98ba3c4f14552eadcd5b1ef14e5b57234d2a315f8604ec25d4 EVIDENCE.json -49d5db8a83e90b71cc3458a16967c89ae6551c9215f07d37f317c45be9068565 LICENSE-INVENTORY.json -7fd00f5f3e980fc8590100ee27ed122c65fec0dd1102d0f18268cfe27ccc852b LICENSE-NOTICE-CANDIDATES.json -095fcfb99e1083c64922f04f98286223363d0f33566cf284abae7c6ae2a484ac LICENSE-NOTICE-REVIEW-RESULTS.json -e3ad43e944b822f46cfe74a6769b5bd70ea774d2010bb4b3be85d567e63f590e LICENSE-REVIEW-RESULTS.json -bf7ddbfae242c3a5fc5de1dfc735ef8a0cf732f251fa63aabd6c9ebc8be35547 LICENSE-REVIEW.json -6211466dab0490f3b9ee7d3c4703fe0dfca7eac33c5628df2d330c0c09a92a29 NOTICE.md +d485445792976d10ca81a4939d0ac9bff87db5001e0ecf8b68308f9f97c1b712 EVIDENCE.json +488b452f517b78dbd0952a3d0cb83f75fae0f0c72129a15036911a7583971e3f LICENSE-INVENTORY.json +056043693f154ac9d9df31c3a65e8ed5b546b24c7d0bec0683a24da9fb83e987 LICENSE-NOTICE-CANDIDATES.json +4e5159dd97cbbeafc69fdb582dda16d9e0b8c1b6318f0ec57469bc84c27acea8 LICENSE-NOTICE-REVIEW-RESULTS.json +631538681cc635632ac0dc953cab8d2bb142b91dfdbf51fd2ad0edd33d8d5eaa LICENSE-REVIEW-RESULTS.json +45e86e2945da28137723aab628141939fc8979945abf9467173fec085467907f LICENSE-REVIEW.json +60e2b327424a0985803ecd8a7ee92affd6946bb0250be90aeda6ab4879b70c7a NOTICE.md 4f7f7626f3d0891a29717e4b7932c36004ecc9aac25a4aa104c300aae979e3e1 PACKAGE-INVENTORY.tsv dbca9b285015a0d8b1d339a894b4594c9e335cbc2d7f9d5212a41095ae4bd1e1 RUNTIME-CONFIGURATION.json 8e021cb8c4160c934a0202609691d7a94526cd016f4394a47da6e7a5ab41d0ea SBOM.spdx.json diff --git a/Docs/ReleaseCompliance.md b/Docs/ReleaseCompliance.md index 61451ec..197827f 100644 --- a/Docs/ReleaseCompliance.md +++ b/Docs/ReleaseCompliance.md @@ -72,12 +72,12 @@ machine-readable SBOM。仓库现在从固定 archive 可复现生成 15 个已 `apk`、repository、DNS 默认配置快照。archive 内没有发现可识别的 LICENSE/COPYING/NOTICE 文件。仓库另有与 inventory 一一对应、固定 checksum 的 aports snapshot/upstream distfile 获取清单和仓库外 materializer,并固定了覆盖 -全部 10 个 source origin 的 32 个 license、attribution、声明与内联 notice 候选。 +全部 10 个 source origin 的 34 个 license、attribution、声明与内联 notice 候选。 第二个仓库外工具从已验证 source-review 目录提取这些候选;固定结果清单记录 -32/32 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source +34/34 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:13 份远端 许可证/attribution 材料、47 份 aports 补充文件和全部既有复核证据;工具可在 -仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 92 文件 payload +仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 94 文件 payload tree;`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成, 不能视为完整 NOTICE 或已批准的对应源码交付。 @@ -176,10 +176,10 @@ Alpine `apk` 可以下载、安装和执行新增代码。即使初始 RootFS - [x] 从固定 APK database 生成完整 package inventory。 - [x] 生成并通过 SPDX 2.3 JSON schema 校验的 machine-readable SBOM。 -- [x] 对固定的 32 个 license/NOTICE 候选完成 checksum-bound 工程复核。 +- [x] 对固定的 34 个 license/NOTICE 候选完成 checksum-bound 工程复核。 - [x] 为剩余 8 个 source origin 建立 checksum-bound 外置候选包索引与可复验 materializer;payload 不提交且批准门禁保持关闭。 -- [x] 对外置候选包的 92 个 payload 完成 checksum-bound 工程复核并固定结果; +- [x] 对外置候选包的 94 个 payload 完成 checksum-bound 工程复核并固定结果; 3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料。 - [ ] 收集 license text 和 NOTICE。 - [ ] 建立 copyleft corresponding source bundle。 diff --git a/Docs/Roadmap.md b/Docs/Roadmap.md index ddf7838..f121c03 100644 --- a/Docs/Roadmap.md +++ b/Docs/Roadmap.md @@ -103,7 +103,7 @@ | 最低 Xcode 16 原生兼容 | 已通过 | Xcode 16.0 / iOS 18.0 SDK 完成 RootFS install、Simulator/device final-link 和 17 项 native smoke | | App lifecycle 与内存 | 进行中 | Simulator 与 Jack iPhone 均有 256 MiB `ru_maxrss` 门禁;真机 process suspend/resume、UIKit foreground/background、强制终止后数据恢复和有界 App delegate memory-warning 回调恢复已通过;补真实 memory pressure/jetsam | | RootFS ENOSPC/掉电 | 进行中 | 峰值空间预检、全 ENOSPC、七点持久化屏障、确定性掉电切点和 Jack iPhone 受限容量/ENOSPC 清理恢复已覆盖;补真实 storage pressure/强制断电 | -| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、32/32 初始候选和 92/92 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | +| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、34/34 初始候选和 94/94 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | | App Store 2.5.2 | 阻塞 | guest download/execute policy 有书面结论 | ### 后续 runtime 执行顺序 diff --git a/Docs/RootFS.md b/Docs/RootFS.md index ba1921a..a61de4a 100644 --- a/Docs/RootFS.md +++ b/Docs/RootFS.md @@ -5,7 +5,7 @@ RootFS 是 PocketRoot 的外部供应链输入,不是普通测试 fixture。仓库提交的是不可变清单、校验和安全安装代码,不提交、镜像或默认打包 RootFS 二进制。 > [!WARNING] -> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 32 个初始候选和 92 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 +> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 34 个初始候选和 94 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 ## 1. 固定清单 @@ -118,7 +118,7 @@ receipt schema v2 强制包含该模式。旧 v1 source-review 的传输来源 规范化 aports 目录身份覆盖条目类型、路径、普通文件权限位和内容摘要;物化时会保留 这些权限位,`--verify` 会再次校验。 -在 source-review 目录验证通过后,可把固定的 32 个候选许可证/attribution 文件 +在 source-review 目录验证通过后,可把固定的 34 个候选许可证/attribution 文件 提取到另一个仓库外目录: ```bash @@ -139,7 +139,7 @@ ruby Scripts/rootfs-license-review-results.rb `APKBUILD`;`--verify` 会复核普通文件摘要、目录集合和符号链接目标。脚本不向 App、 Git 或 CI artifact 自动添加输出。这完成的是可复现的工程获取流程。archive 内没有 随附可识别的 LICENSE/COPYING/NOTICE 文件。候选工具会核对提取文件的大小、 -SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 32/32 个候选均已 +SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 34/34 个候选均已 工程复核,其中 `libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有 未决项;输出不能直接视为完整 NOTICE 或对应源码交付材料。 @@ -167,7 +167,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ ``` 工具对远端材料强制 HTTPS、重定向次数、响应大小、固定字节数与 SHA-256,并原子 -创建输出。结果清单把工程复核绑定到精确的 92 文件 payload tree;复验器拒绝路径 +创建输出。结果清单把工程复核绑定到精确的 94 文件 payload tree;复验器拒绝路径 漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools`、 `openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包 材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 diff --git a/Docs/en/ReleaseCompliance.md b/Docs/en/ReleaseCompliance.md index 8f7cc33..80e7474 100644 --- a/Docs/en/ReleaseCompliance.md +++ b/Docs/en/ReleaseCompliance.md @@ -36,15 +36,15 @@ the default `apk`, repository, and DNS snapshot. No identifiable LICENSE/COPYING/NOTICE file was found in the archive. A checksum-pinned aports-snapshot/upstream-distfile manifest covers the inventory, and an outside-repository materializer creates reproducible review inputs. A second -outside-repository tool pins, extracts, and verifies 32 license, attribution, +outside-repository tool pins, extracts, and verifies 34 license, attribution, declaration, and inline-notice candidates across all 10 source origins. -A pinned result manifest records engineering review of all 32 candidates. +A pinned result manifest records engineering review of all 34 candidates. `libc-dev` and `zlib` have no remaining indexed items; eight source origins still have package-level follow-up. The repository now pins an external candidate bundle for those origins: 13 remote license/attribution payloads, 47 supplemental aports files, and all existing reviewed evidence. The tool can atomically materialize and re-verify it outside the repository. A pinned -results manifest binds engineering review to the exact 92-file payload tree. +results manifest binds engineering review to the exact 94-file payload tree. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. Modification, build-completeness, source-offer, and legal reviews remain unresolved, so the @@ -117,12 +117,12 @@ The current code does not provide a complete product-level privacy policy. - [x] Generate a complete inventory from the pinned APK database. - [x] Generate a machine-readable SBOM validated against the SPDX 2.3 JSON schema. -- [x] Complete checksum-bound engineering review of all 32 pinned +- [x] Complete checksum-bound engineering review of all 34 pinned license/NOTICE candidates. - [x] Index a checksum-bound external candidate bundle and reproducible materializer for the eight remaining origins; payloads stay uncommitted and approval gates stay closed. -- [x] Complete checksum-bound engineering review of all 92 external candidate +- [x] Complete checksum-bound engineering review of all 94 external candidate payloads; three origins have no remaining candidate-material engineering items and five still need package-specific material. - [ ] Collect license texts and NOTICE files. diff --git a/Docs/en/Roadmap.md b/Docs/en/Roadmap.md index dc9d03e..9631f7f 100644 --- a/Docs/en/Roadmap.md +++ b/Docs/en/Roadmap.md @@ -98,7 +98,7 @@ This establishes the current Simulator, minimum-Xcode 16, and single-iPhone one- | Minimum Xcode 16 native | Passed | Xcode 16.0 / iOS 18.0 SDK completed RootFS install, Simulator/device final links, and the 17-check native smoke | | App lifecycle and memory | In progress | Simulator and Jack iPhone have 256 MiB `ru_maxrss` gates; physical process suspend/resume, UIKit foreground/background, post-termination data recovery, and bounded App-delegate memory-warning recovery passed; add real memory-pressure/jetsam evidence | | RootFS ENOSPC/power faults | In progress | Peak-space preflight, full ENOSPC, seven persistence barriers, deterministic power-loss cuts, and bounded capacity/ENOSPC cleanup recovery on Jack iPhone are covered; add real storage-pressure/power-cut evidence | -| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 32 initial candidates, and all 92 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | +| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 34 initial candidates, and all 94 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | | App Store 2.5.2 | Blocked | Written guest download/execute policy decision | ### Next runtime sequence diff --git a/Docs/en/RootFS.md b/Docs/en/RootFS.md index 7e06628..a80729a 100644 --- a/Docs/en/RootFS.md +++ b/Docs/en/RootFS.md @@ -5,7 +5,7 @@ A RootFS is an external supply-chain input, not a normal fixture. PocketRoot commits immutable metadata and secure install code, not the payload. > [!WARNING] -> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 32 initial candidates and all 92 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. +> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 34 initial candidates and all 94 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. ## Pinned manifest @@ -95,7 +95,7 @@ Receipt schema v2 requires that explicit mode. A legacy v1 source-review directory has ambiguous transport provenance and is no longer accepted by `--verify`; pass it to `--download-cache` to regenerate a verifiable v2 bundle. -After that source-review directory verifies, extract the 32 pinned +After that source-review directory verifies, extract the 34 pinned license/attribution candidates into another directory outside the repository: ```bash @@ -122,7 +122,7 @@ engineering acquisition workflow, not legal review. The RootFS archive contains no identifiable LICENSE/COPYING/NOTICE files. The candidate tool rechecks extracted byte counts, SHA-256 digests, the exact path set, and the no-link/special-node boundary. The pinned results record engineering review of -all 32 candidates: `libc-dev` and `zlib` have no remaining indexed items, while +all 34 candidates: `libc-dev` and `zlib` have no remaining indexed items, while eight source origins still require follow-up. The output is not a completed NOTICE or corresponding-source delivery bundle. @@ -152,7 +152,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ The tool enforces HTTPS, redirect and response-size bounds, pinned byte counts and SHA-256 digests, and atomic output creation. The results bind engineering -review to the exact 92-file payload tree; the verifier rejects path drift, +review to the exact 94-file payload tree; the verifier rejects path drift, links, special nodes, known-digest drift, and tree-digest drift. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. The candidate NOTICE diff --git a/README.md b/README.md index fb4ce2b..fa2cc4c 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ print("stderr:", result.stderr) - 展开大小:`18,838,016` 字节 - SHA-256:`be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4` -固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 32 个初始候选及 92 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 +固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 34 个初始候选及 94 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 ## 验证命令 diff --git a/Scripts/rootfs-license-notice-candidates.rb b/Scripts/rootfs-license-notice-candidates.rb index dca7918..f210503 100644 --- a/Scripts/rootfs-license-notice-candidates.rb +++ b/Scripts/rootfs-license-notice-candidates.rb @@ -20,7 +20,7 @@ module RootFSLicenseNoticeCandidates alpine-baselayout alpine-keys apk-tools busybox ca-certificates musl openssl pax-utils ].freeze - EXPECTED_EXISTING_EVIDENCE_FILES = 32 + EXPECTED_EXISTING_EVIDENCE_FILES = 34 EXPECTED_REMOTE_PAYLOAD_FILES = 13 EXPECTED_APORTS_FILES = 47 PAYLOAD_KINDS = %w[package-attribution spdx-license-text].freeze diff --git a/Scripts/rootfs-license-notice-review-results.rb b/Scripts/rootfs-license-notice-review-results.rb index bb18781..d0206a9 100644 --- a/Scripts/rootfs-license-notice-review-results.rb +++ b/Scripts/rootfs-license-notice-review-results.rb @@ -22,7 +22,7 @@ module RootFSLicenseNoticeReviewResults COVERAGE = %w[complete partial reference-only].freeze SHA256_PATTERN = /\A[0-9a-f]{64}\z/ CANDIDATE_PAYLOAD_TREE_FORMAT = "sha256-path-lines-v1" - EXPECTED_REVIEWED_PAYLOAD_FILES = 92 + EXPECTED_REVIEWED_PAYLOAD_FILES = 94 MAX_REVIEWED_PAYLOAD_BYTES = 8 * 1_024 * 1_024 TOP_LEVEL_KEYS = %w[ allIndexedCandidatePayloadsReviewed archive candidateManifestSha256 diff --git a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb index 2808c58..8bbe5f4 100644 --- a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb @@ -29,7 +29,7 @@ def test_validates_complete_open_origin_candidate_index assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length - assert_equal 32, validated.fetch(:existing_evidence_paths).length + assert_equal 34, validated.fetch(:existing_evidence_paths).length assert_equal 47, validated.fetch(:aports_paths).length end @@ -544,6 +544,54 @@ def test_pins_enabled_busybox_od_hexdump_and_hd_notices ) end + def test_pins_enabled_busybox_expand_unexpand_and_fold_notices + source = @candidate.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + review_source = @review.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + expected = { + "evidence/busybox/coreutils-expand.c" => { + member: "busybox-1.36.1/coreutils/expand.c", + bytes: 6_393, + sha256: "66296875f04016bba0721d4fa80393317ffca014e4b4722ed8e7e7fb1c882802" + }, + "evidence/busybox/coreutils-fold.c" => { + member: "busybox-1.36.1/coreutils/fold.c", + bytes: 5_018, + sha256: "db291cf01ee9a90244607c88a5d88ddf7d2600237eca6f2d7a6894815928cdef" + } + } + + expected.each do |output_path, values| + evidence = review_source.fetch("candidateEvidence").find do |candidate| + candidate.fetch("outputPath") == output_path + end + + assert_includes source.fetch("existingEvidencePaths"), output_path + assert_equal values.fetch(:member), evidence.fetch("member") + assert_equal values.fetch(:bytes), evidence.fetch("byteCount") + assert_equal values.fetch(:sha256), evidence.fetch("sha256") + assert_equal( + %w[license-declaration attribution], + evidence.fetch("evidenceKinds") + ) + end + assert_includes( + source.fetch("supplementalAportsPaths"), + "aports/busybox/busyboxconfig" + ) + assert_includes( + source.fetch("remainingReviewItems"), + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage" + ) + assert_includes( + source.fetch("remainingReviewItems"), + "review-other-bundled-third-party-license-and-attribution-coverage" + ) + end + def test_rejects_overlapping_materialized_output_paths payloads = @candidate.fetch("remotePayloads") payloads.fetch(0)["outputPath"] = "licenses/collision" diff --git a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb index a08435b..546b9c0 100644 --- a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb @@ -47,7 +47,7 @@ def test_validates_pinned_candidate_review_results assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length assert_equal 47, validated.fetch(:aports_paths).length - assert_equal 92, @results.fetch("reviewedPayloadFileCount") + assert_equal 94, @results.fetch("reviewedPayloadFileCount") assert_equal 5, @results.fetch("sourceOriginsWithRemainingReviewItems") assert_equal %w[apk-tools openssl pax-utils], @@ -136,7 +136,7 @@ def test_binds_enabled_busybox_ash_math_to_inline_notices assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-ash-math-license-and-attribution-coverage" @@ -158,7 +158,7 @@ def test_binds_enabled_busybox_env_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-env-license-and-attribution-coverage" @@ -180,7 +180,7 @@ def test_binds_enabled_busybox_echo_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-echo-license-and-attribution-coverage" @@ -202,7 +202,7 @@ def test_binds_enabled_busybox_logger_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-logger-license-and-attribution-coverage" @@ -224,7 +224,7 @@ def test_binds_enabled_busybox_cal_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-cal-license-and-attribution-coverage" @@ -246,7 +246,7 @@ def test_binds_enabled_busybox_ping_and_ping6_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-ping-and-ping6-license-and-attribution-coverage" @@ -268,7 +268,7 @@ def test_binds_enabled_busybox_traceroute_and_traceroute6_to_inline_notice assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage" @@ -290,7 +290,7 @@ def test_binds_enabled_busybox_od_hexdump_and_hd_to_inline_notices assert_equal "partial", source.fetch("licenseTextCoverage") assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 14, source.fetch("reviewedExistingEvidenceCount") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage" @@ -305,6 +305,28 @@ def test_binds_enabled_busybox_od_hexdump_and_hd_to_inline_notices ) end + def test_binds_enabled_busybox_expand_unexpand_and_fold_to_license_headers + source = @results.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + + assert_equal "partial", source.fetch("licenseTextCoverage") + assert_equal "partial", source.fetch("attributionCoverage") + assert_equal 16, source.fetch("reviewedExistingEvidenceCount") + assert_includes( + source.fetch("resolvedReviewItems"), + "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage" + ) + assert_equal( + ["review-other-bundled-third-party-license-and-attribution-coverage"], + source.fetch("remainingReviewItems") + ) + assert_equal( + "additional-package-material-required", + source.fetch("engineeringConclusion") + ) + end + def test_rejects_candidate_manifest_digest_drift @candidates["status"] = "changed" diff --git a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb index 9d2e068..5c23d67 100644 --- a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb @@ -39,7 +39,7 @@ def test_validates_pinned_engineering_review_results sources = validate assert_equal 10, sources.length - assert_equal 32, + assert_equal 34, sources.sum { |entry| entry.fetch("candidateResults").length } assert_equal 8, sources.count { |entry| !entry.fetch("remainingReviewItems").empty? }