From a06effd8b47ef6afe3cff56c3537f079ab49174e Mon Sep 17 00:00:00 2001 From: Jintao Date: Mon, 27 Jul 2026 12:57:18 +0800 Subject: [PATCH] Close remaining BusyBox notice review --- CHANGELOG.en.md | 19 +- CHANGELOG.md | 14 +- Compliance/RootFS/v0.3.3/EVIDENCE.json | 8 +- .../RootFS/v0.3.3/LICENSE-INVENTORY.json | 8 +- .../v0.3.3/LICENSE-NOTICE-CANDIDATES.json | 73 ++- .../v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json | 41 +- .../RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json | 249 +++++++- Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json | 533 ++++++++++++++++++ Compliance/RootFS/v0.3.3/NOTICE.md | 10 +- Compliance/RootFS/v0.3.3/README.md | 94 ++- Compliance/RootFS/v0.3.3/SHA256SUMS | 14 +- Docs/ReleaseCompliance.md | 14 +- Docs/Roadmap.md | 2 +- Docs/RootFS.md | 18 +- Docs/en/ReleaseCompliance.md | 19 +- Docs/en/Roadmap.md | 2 +- Docs/en/RootFS.md | 24 +- README.md | 2 +- Scripts/rootfs-license-notice-candidates.rb | 2 +- .../rootfs-license-notice-review-results.rb | 2 +- .../RootFSLicenseNoticeCandidatesTests.rb | 82 ++- .../RootFSLicenseNoticeReviewResultsTests.rb | 162 +++--- .../RootFSLicenseReviewResultsTests.rb | 42 +- 23 files changed, 1210 insertions(+), 224 deletions(-) diff --git a/CHANGELOG.en.md b/CHANGELOG.en.md index cb8cd2f..4a68d7a 100644 --- a/CHANGELOG.en.md +++ b/CHANGELOG.en.md @@ -32,17 +32,17 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit declared-license/attribution inventories, and default `apk`, repository, and DNS configuration; complete LICENSE/NOTICE and corresponding-source bundles remain distribution blockers. -- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 37 +- A checksum-bound `LICENSE-REVIEW-RESULTS.json` and strict validator. All 78 pinned RootFS license/NOTICE candidates have engineering review results; eight source origins retain package-level open items, and legal and redistribution gates remain closed. - A checksum-bound `LICENSE-NOTICE-CANDIDATES.json`, strict validator, and outside-repository atomic materializer for the eight remaining RootFS source origins. It indexes 13 remote license/attribution payloads, 47 aports files, - and the 37 existing evidence files for complete re-verification without + and the 78 existing evidence files for complete re-verification without committing payloads or opening engineering, legal, or redistribution gates. - `LICENSE-NOTICE-REVIEW-RESULTS.json` and a strict external payload-tree - verifier. All 97 candidate payloads now have checksum-bound engineering + verifier. All 138 candidate payloads now have checksum-bound engineering review. The pinned upstream `alpine-keys` GPL-to-MIT license-decision commit is included while its package-level copyright notice remains open. The `ca-certificates` generator is byte-identical to curl commit `3fdc4bdb`, and @@ -63,11 +63,14 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit sources retain FSF copyright, GPLv2-or-later declarations, and BusyBox port attribution. `cut`, `sort`, and `uniq` link their corresponding `coreutils` sources, each retaining its GPLv2-or-later declaration and original - attribution. Other inline notices stay open; - `apk-tools`, `openssl`, and `pax-utils` have no remaining - candidate-material engineering items, five origins still need - package-specific material, and - legal and redistribution gates remain closed. + attribution. The remaining BusyBox review applies the 33 pinned aports + patches and configuration to derive 487 compilation units and a 562-file + include closure, then pins the 41 files retaining independent third-party + terms or provenance. BusyBox evidence increases to 60 files and its broad + engineering item closes. `apk-tools`, `busybox`, `openssl`, and `pax-utils` + have no remaining candidate-material engineering items, four origins still + need package-specific material, and legal and redistribution gates remain + closed. - Strict external download-cache input for the RootFS source-review materializer. A cache replaces network transport only: inputs remain size-bounded and symlink/overlap-rejected, with pinned SHA-512 and canonical diff --git a/CHANGELOG.md b/CHANGELOG.md index 6a4d5e4..2c7b6b6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -30,15 +30,15 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 10 个 source origin、SPDX 2.3 JSON SBOM、许可证声明/attribution inventory 和 `apk`、repository、DNS 默认配置快照;完整 LICENSE/NOTICE 与对应源码 bundle 仍保持发行阻塞。 -- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;37/37 个固定 +- 加入 checksum-bound `LICENSE-REVIEW-RESULTS.json` 和严格验证器;78/78 个固定 RootFS license/NOTICE 候选已完成工程复核,8 个 source origin 仍有包级未决项, 法律与再分发门禁保持关闭。 - 为剩余 8 个 RootFS source origin 加入 checksum-bound `LICENSE-NOTICE-CANDIDATES.json`、严格验证器和仓库外原子 materializer;索引 - 13 份远端许可证/attribution 材料、47 份 aports 文件与 37 份既有证据,支持完整 + 13 份远端许可证/attribution 材料、47 份 aports 文件与 78 份既有证据,支持完整 复验,但不提交 payload,也不解除工程、法律或再分发门禁。 - 加入 `LICENSE-NOTICE-REVIEW-RESULTS.json` 和严格外置 payload-tree 复验器; - 97/97 个候选 payload 已完成 checksum-bound 工程复核;新增固定 + 138/138 个候选 payload 已完成 checksum-bound 工程复核;新增固定 `alpine-keys` GPL→MIT 上游许可判定提交,但仍保留包级版权声明缺口; `ca-certificates` 生成脚本与 curl 提交 `3fdc4bdb` 字节一致并固定该精确 revision 的 curl 授权文本,trust-store 审查仍保持未决; @@ -54,9 +54,11 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 声明;`expand`/`unexpand` 共同链入 `coreutils/expand.c`,`fold` 链入 `coreutils/fold.c`,两份源码均保留 FSF 版权、GPLv2-or-later 声明与 BusyBox 改写署名;`cut`、`sort`、`uniq` 分别链入对应 `coreutils` 源码,三份源码均 - 保留 GPLv2-or-later 声明与原作者署名;其他内联第三方 notices 继续保持未决; - `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项关闭,另外 5 个 origin - 仍需补逐包材料,法律和再分发门禁保持关闭。 + 保留 GPLv2-or-later 声明与原作者署名。其余 BusyBox 审查按固定 33 个 aports + 补丁和配置生成 487 个编译单元、562 文件 include 闭包,并固定其中 41 份仍含 + 独立第三方条款或 provenance 的源码;BusyBox 证据增至 60 份,总括工程项关闭。 + `apk-tools`、`busybox`、`openssl`、`pax-utils` 的候选材料工程项关闭,另外 + 4 个 origin 仍需补逐包材料,法律和再分发门禁保持关闭。 - RootFS source-review materializer 新增严格仓库外下载缓存输入;缓存只替代网络 传输,仍逐项限制大小、拒绝 symlink/重叠路径、核对固定 SHA-512,并重新验证 解包后的 canonical aports tree;v2 receipt 会明确区分网络与缓存获取,不伪造 diff --git a/Compliance/RootFS/v0.3.3/EVIDENCE.json b/Compliance/RootFS/v0.3.3/EVIDENCE.json index baa6c7f..e81668c 100644 --- a/Compliance/RootFS/v0.3.3/EVIDENCE.json +++ b/Compliance/RootFS/v0.3.3/EVIDENCE.json @@ -39,14 +39,14 @@ "sourceOrigins": 10, "declaredLicenseExpressions": 7, "licenseOrNoticeFilesInGuestTemplate": 0, - "indexedExternalLicenseReviewCandidates": 37, - "engineeringReviewedLicenseCandidates": 37, + "indexedExternalLicenseReviewCandidates": 78, + "engineeringReviewedLicenseCandidates": 78, "sourceOriginsWithRemainingLicenseReviewItems": 8, "indexedLicenseNoticeCandidateOrigins": 8, "pinnedRemoteLicenseNoticePayloads": 13, "supplementalAportsCandidateFiles": 47, - "engineeringReviewedLicenseNoticeCandidatePayloads": 97, - "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5 + "engineeringReviewedLicenseNoticeCandidatePayloads": 138, + "sourceOriginsWithRemainingCandidatePayloadReviewItems": 4 }, "engineeringStatus": { "completeInstalledPackageInventory": true, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json index 0a85a00..332f86c 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json @@ -26,15 +26,15 @@ "licenseOrNoticeFilesFoundInGuestTemplate": [ ], - "indexedExternalReviewCandidates": 37, - "engineeringReviewedCandidates": 37, + "indexedExternalReviewCandidates": 78, + "engineeringReviewedCandidates": 78, "sourceOriginsWithOpenReviewItems": 10, "sourceOriginsWithRemainingReviewItems": 8, "indexedOpenSourceOrigins": 8, "pinnedRemoteReferencePayloads": 13, "supplementalAportsFiles": 47, - "engineeringReviewedCandidatePayloads": 97, - "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5, + "engineeringReviewedCandidatePayloads": 138, + "sourceOriginsWithRemainingCandidatePayloadReviewItems": 4, "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, "engineeringReviewCompleted": true, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json index 9e94dff..4b05e34 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewResultsSha256": "fe473ffd86d0d1ca7b1ad2594373311b8cc6181ee36865089780e1cf885fc0de", + "licenseReviewResultsSha256": "810f047bd36867c3a34318fef8535dcb87cc263f6a59df88b1abee56472e35ce", "status": "candidate-bundle-indexed-engineering-review-required", "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, @@ -185,7 +185,9 @@ "referenceLicensePaths": [ "licenses/GPL-2.0.txt" ], - "supplementalAportsPaths": [], + "supplementalAportsPaths": [ + + ], "remoteEvidencePaths": [ "supplemental/alpine-baselayout/netbase-6.4-copyright" ], @@ -206,7 +208,9 @@ "referenceLicensePaths": [ "licenses/MIT-reference.txt" ], - "supplementalAportsPaths": [], + "supplementalAportsPaths": [ + + ], "remoteEvidencePaths": [ "supplemental/alpine-keys/license-decision.patch" ], @@ -231,7 +235,9 @@ "aports/apk-tools/fix-recursive-solve-1.patch", "aports/apk-tools/fix-recursive-solve-2.patch" ], - "remoteEvidencePaths": [], + "remoteEvidencePaths": [ + + ], "remainingReviewItems": [ "confirm-package-specific-attribution-and-aports-patch-notices" ], @@ -261,7 +267,48 @@ "evidence/busybox/coreutils-fold.c", "evidence/busybox/coreutils-cut.c", "evidence/busybox/coreutils-sort.c", - "evidence/busybox/coreutils-uniq.c" + "evidence/busybox/coreutils-uniq.c", + "evidence/busybox/build-closure-archival-bbunzip.c", + "evidence/busybox/build-closure-archival-libarchive-decompress_gunzip.c", + "evidence/busybox/build-closure-archival-libarchive-liblzo.h", + "evidence/busybox/build-closure-archival-libarchive-lzo1x_1.c", + "evidence/busybox/build-closure-archival-libarchive-lzo1x_1o.c", + "evidence/busybox/build-closure-archival-libarchive-lzo1x_c.c", + "evidence/busybox/build-closure-archival-libarchive-lzo1x_d.c", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz.h", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_config.h", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_bcj.c", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_lzma2.c", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_stream.c", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_lzma2.h", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_private.h", + "evidence/busybox/build-closure-archival-libarchive-unxz-xz_stream.h", + "evidence/busybox/build-closure-archival-lzop.c", + "evidence/busybox/build-closure-coreutils-dos2unix.c", + "evidence/busybox/build-closure-coreutils-sync.c", + "evidence/busybox/build-closure-coreutils-test.c", + "evidence/busybox/build-closure-coreutils-tr.c", + "evidence/busybox/build-closure-include-liblzo_interface.h", + "evidence/busybox/build-closure-libbb-change_identity.c", + "evidence/busybox/build-closure-libbb-correct_password.c", + "evidence/busybox/build-closure-libbb-hash_md5_sha.c", + "evidence/busybox/build-closure-libbb-procps.c", + "evidence/busybox/build-closure-libbb-progress.c", + "evidence/busybox/build-closure-libbb-pw_encrypt_des.c", + "evidence/busybox/build-closure-libbb-pw_encrypt_sha.c", + "evidence/busybox/build-closure-libbb-run_shell.c", + "evidence/busybox/build-closure-libbb-setup_environment.c", + "evidence/busybox/build-closure-libbb-vfork_daemon_rexec.c", + "evidence/busybox/build-closure-libpwdgrp-uidgid_get.c", + "evidence/busybox/build-closure-loginutils-add-remove-shell.c", + "evidence/busybox/build-closure-miscutils-bbconfig.c", + "evidence/busybox/build-closure-networking-nc_bloaty.c", + "evidence/busybox/build-closure-procps-pmap.c", + "evidence/busybox/build-closure-shell-ash.c", + "evidence/busybox/build-closure-shell-shell_common.c", + "evidence/busybox/build-closure-shell-shell_common.h", + "evidence/busybox/build-closure-util-linux-fdisk_osf.c", + "evidence/busybox/build-closure-util-linux-setsid.c" ], "referenceLicensePaths": [ "licenses/GPL-2.0.txt" @@ -305,7 +352,9 @@ "aports/busybox/dad.if-up", "aports/busybox/default.script" ], - "remoteEvidencePaths": [], + "remoteEvidencePaths": [ + + ], "remainingReviewItems": [ "confirm-enabled-bzip2-license-and-attribution-coverage", "confirm-enabled-ash-math-license-and-attribution-coverage", @@ -336,7 +385,9 @@ "licenses/MIT-reference.txt", "licenses/MPL-2.0.txt" ], - "supplementalAportsPaths": [], + "supplementalAportsPaths": [ + + ], "remoteEvidencePaths": [ "supplemental/ca-certificates/curl-mk-ca-bundle.pl", "supplemental/ca-certificates/curl-COPYING" @@ -371,7 +422,9 @@ "aports/musl/handle-aux-at_base.patch", "aports/musl/remove-dns-63-records-limit.patch" ], - "remoteEvidencePaths": [], + "remoteEvidencePaths": [ + + ], "remainingReviewItems": [ "confirm-third-party-musl-files-and-aports-helper-notice-coverage" ], @@ -417,7 +470,9 @@ "referenceLicensePaths": [ "licenses/GPL-2.0.txt" ], - "supplementalAportsPaths": [], + "supplementalAportsPaths": [ + + ], "remoteEvidencePaths": [ "supplemental/pax-utils/README.md" ], diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json index e7c757f..d549700 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "candidateManifestSha256": "537646fc1fe8bb81322d74a434227d83495ffbc4bff5a61f123a47e9effcd999", + "candidateManifestSha256": "534c12f8b9268a36cff13af3123bebbacf61d85b667fafce6d7649cae47c7e65", "status": "candidate-payloads-engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allIndexedCandidatePayloadsReviewed": true, @@ -13,10 +13,10 @@ "legalReviewApproved": false, "redistributionApproved": false, "candidatePayloadTreeFormat": "sha256-path-lines-v1", - "candidatePayloadTreeSha256": "e4d8eef692cba9ed38052e2b8067b5e9c46acbd6d0dd46b9158fd876d7a4ec40", - "reviewedPayloadFileCount": 97, + "candidatePayloadTreeSha256": "cc9aacfeb345129ea9df24834cdcf381dfb67c8393b11d4c1d4249855238d281", + "reviewedPayloadFileCount": 138, "reviewedClosedOriginEvidenceCount": 4, - "sourceOriginsWithRemainingReviewItems": 5, + "sourceOriginsWithRemainingReviewItems": 4, "sources": [ { "sourceOrigin": "alpine-baselayout", @@ -50,7 +50,9 @@ "reviewedReferenceLicenseCount": 1, "reviewedSupplementalAportsCount": 0, "reviewedRemoteEvidenceCount": 1, - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "collect-mit-license-grant-and-copyright-notice" ], @@ -71,7 +73,9 @@ "resolvedReviewItems": [ "confirm-package-specific-attribution-and-aports-patch-notices" ], - "remainingReviewItems": [], + "remainingReviewItems": [ + + ], "engineeringConclusion": "candidate-material-complete-engineering-only" }, { @@ -80,9 +84,9 @@ "GPL-2.0-only" ], "reviewState": "candidate-payloads-engineering-reviewed-legal-review-open", - "licenseTextCoverage": "partial", - "attributionCoverage": "partial", - "reviewedExistingEvidenceCount": 19, + "licenseTextCoverage": "complete", + "attributionCoverage": "complete", + "reviewedExistingEvidenceCount": 60, "reviewedReferenceLicenseCount": 1, "reviewedSupplementalAportsCount": 37, "reviewedRemoteEvidenceCount": 0, @@ -98,12 +102,13 @@ "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage", "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage", "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage", - "confirm-enabled-cut-sort-and-uniq-license-and-attribution-coverage" + "confirm-enabled-cut-sort-and-uniq-license-and-attribution-coverage", + "review-other-bundled-third-party-license-and-attribution-coverage" ], "remainingReviewItems": [ - "review-other-bundled-third-party-license-and-attribution-coverage" + ], - "engineeringConclusion": "additional-package-material-required" + "engineeringConclusion": "candidate-material-complete-engineering-only" }, { "sourceOrigin": "ca-certificates", @@ -139,7 +144,9 @@ "reviewedReferenceLicenseCount": 3, "reviewedSupplementalAportsCount": 3, "reviewedRemoteEvidenceCount": 0, - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-third-party-musl-files-and-aports-helper-notice-coverage" ], @@ -160,7 +167,9 @@ "resolvedReviewItems": [ "confirm-required-apache-notice-and-attribution-material" ], - "remainingReviewItems": [], + "remainingReviewItems": [ + + ], "engineeringConclusion": "candidate-material-complete-engineering-only" }, { @@ -178,7 +187,9 @@ "resolvedReviewItems": [ "confirm-package-specific-copyright-and-aports-patch-notices" ], - "remainingReviewItems": [], + "remainingReviewItems": [ + + ], "engineeringConclusion": "candidate-material-complete-engineering-only" } ] diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json index 2b7d728..75911c1 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW-RESULTS.json @@ -4,11 +4,11 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "licenseReviewManifestSha256": "60dd3aa2d8b73f49813e081b722caa65d60580ef767ad6df4e7cf906b7baa59d", + "licenseReviewManifestSha256": "5c6f0971c156275869c0e5c0390cb1ce2f3acb3b55d19657d902e264cbe2ef08", "status": "engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allCandidateDigestsVerified": true, - "reviewedCandidateCount": 37, + "reviewedCandidateCount": 78, "sourceOriginsWithRemainingReviewItems": 8, "completeLicenseTextBundlePresent": false, "completePackageNoticeSetPresent": false, @@ -30,7 +30,9 @@ "conclusion": "license-declaration" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "collect-complete-gpl-2.0-license-text", "identify-package-specific-copyright-and-notice" @@ -51,7 +53,9 @@ "conclusion": "license-declaration" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "collect-mit-license-grant-and-copyright-notice" ] @@ -76,7 +80,9 @@ "conclusion": "attribution-list" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-package-specific-attribution-and-aports-patch-notices" ] @@ -184,9 +190,216 @@ "outputPath": "evidence/busybox/coreutils-uniq.c", "sha256": "09c15b3e70e0b5ac2e65b42b1e556f9b25199b846b2ac75dc730d18650d14f7d", "conclusion": "license-header-and-attribution" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-bbunzip.c", + "sha256": "c8a5db572c48f33b4554841e5157b7fbe41764b2e8db114201b3dfdfef5ea7e5", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-decompress_gunzip.c", + "sha256": "2346dd2b227d6305bbe580b50e077e52da9441881c674ad2a6a2960a1f75fa8b", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-liblzo.h", + "sha256": "2a544181ad8ab8386d5cd8df85758286d429fe7dadbfd3f173f91f8aac7f2389", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_1.c", + "sha256": "eba89167022a816fef6a8cf1e296588a1cf0de84ceadfee1b688ebb8b46a833a", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_1o.c", + "sha256": "255b49a7a81ebd826e23c2635574f5d36e43c286985595ca34772ac1befde940", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_c.c", + "sha256": "a05ba174e8dc9509d70f28cacaf704e201f131dd02b7cccb509dd4c70543deae", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_d.c", + "sha256": "a63a1d20e33650fe04afe12c7ad5c09b09bbd0a040e857aba8d695f30c85875c", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz.h", + "sha256": "db6edcf8424001930a8b5ff513eafd67d89f69efd5f46feab9c9f390b644d0b4", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_config.h", + "sha256": "4f44266f23eee08aa32f424c07701b0fd7ebc90f676eecfd79afbf2705c3c981", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_bcj.c", + "sha256": "42ead75122607fa392579eaae003b7b5921dfb636f4d9e912818790228a2fc95", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_lzma2.c", + "sha256": "8b8f8854a4b3c11288d693bde95d346468cfc9aa9e59babcf734d59652e27c79", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_stream.c", + "sha256": "ec66858910c88b773e65c37dfabdab6018555773d379a8cd20a9d13a2aa102c2", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_lzma2.h", + "sha256": "ef38ebe621800cf4960575136ea167171648c9e8e0d8ed3b98be6651d1651981", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_private.h", + "sha256": "d0d05b876173512ec45fd5ac89163dbdd89cd95a0a1759e9f4473872d3393d37", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_stream.h", + "sha256": "a30849b8acaafdb9613fa5fc7704b89f97050ccf9847fb6f5182487012df26aa", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-archival-lzop.c", + "sha256": "2ce2f015b7378d083929a58017af6177afa223091b2fde7e464fa7e2ec56dd44", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-coreutils-dos2unix.c", + "sha256": "594bed730a26ed7622e34b7c5774a3737b777ce9dd07023a567b6f8baaacb8f9", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-coreutils-sync.c", + "sha256": "655760926c4e2d4959a56710452fbefcfac1d75ed5fea320c55a4985b20c5a9d", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-coreutils-test.c", + "sha256": "7fa39b5204486d13765f63cbeab0b4a482b89c6c85868553857df299d792375d", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-coreutils-tr.c", + "sha256": "5e0e51da2636151b97f5bd905716c484a9759b055b90b27488437c945d4be6e3", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-include-liblzo_interface.h", + "sha256": "ece65419355194234d31b78f59d3378581cc53cb959651bc613ba781f3b65cc3", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-change_identity.c", + "sha256": "c8aef5e372ff6b742f18f8cfa9355e3d28d436d4be279fae5730706370e0c807", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-correct_password.c", + "sha256": "7f119ea757548393aed188e783fa58dbc240a35fc598acdc727295fea6290e9d", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-hash_md5_sha.c", + "sha256": "65dba16216f7f72b562b229c30efe3ffaa6a8d6ff8ae96044394b25adaef0217", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-procps.c", + "sha256": "070633eba0b4dfe7f9ee29f02dd1ace6f368acdbe5802c7b1ea570aa2873e70c", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-progress.c", + "sha256": "fc3db3f961b24eeed7413ca219de4d4520d041507485628e1a103f234ff03072", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-pw_encrypt_des.c", + "sha256": "00470df43c2ec79b76ebbdcf1ad51d14df14db4bc59142e4c8bd10d07e7f5885", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-pw_encrypt_sha.c", + "sha256": "1a14c5841a4ad4c8ec4de51c3f7c658dbf772f52120f2a5c9429cd69eb8b3c7d", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-run_shell.c", + "sha256": "f551208951ef58f131fe2a49425d51b191b6ac25b7b95905125b63eb2e8d0bce", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-setup_environment.c", + "sha256": "4e2f6100a44e922c5c7b154e3044c656b7edfae966b2f83c8845248674551bde", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libbb-vfork_daemon_rexec.c", + "sha256": "a754155eab527a4bb038722218234371837e013f5092e77631e57ee12df1398c", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-libpwdgrp-uidgid_get.c", + "sha256": "bfff92a736909142e425694f80b9e85ea390a3b68b9f14896a19a90ca65f15e0", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-loginutils-add-remove-shell.c", + "sha256": "9250de6bdc412422d26ef4baf1ecb49cbaef759360088be49295caf263d24173", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-miscutils-bbconfig.c", + "sha256": "e4b817b538e139d17c57cefcd3e382a6dde4458ed42c262c762a89829acea464", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-networking-nc_bloaty.c", + "sha256": "c58ac147a37d8e928ccdf0948fa06d164ac41ed6ce74c5ed128012a2fd6d2362", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-procps-pmap.c", + "sha256": "224a941febb696871ff10ffa3a4adb8199c701ccd373098ba5c4c1b41fde494b", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-shell-ash.c", + "sha256": "ca769312d3c0bf0592c6bc5a810d3328b6d95bdb82fbe2fc7542b0936c4ce7ec", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-shell-shell_common.c", + "sha256": "090601269e1bc01a1558a56a4192a92bc133ab374bf9096fc930c2a6eeca3948", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-shell-shell_common.h", + "sha256": "6d0589523721f9a41f9db5d0d88035bccb086f5055b8709b22c9310004530745", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-util-linux-fdisk_osf.c", + "sha256": "d66020e2f68456ad1f7fda40458ee37126dea42c8e0057970d3fcdb591dafdfc", + "conclusion": "inline-license-and-attribution-notice" + }, + { + "outputPath": "evidence/busybox/build-closure-util-linux-setsid.c", + "sha256": "29c8bb684db0c174c94f2e509832e62d8a116e864a9bf19fc9844a91452fb8dd", + "conclusion": "inline-license-and-attribution-notice" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-enabled-bzip2-license-and-attribution-coverage", "confirm-enabled-ash-math-license-and-attribution-coverage", @@ -223,7 +436,9 @@ "conclusion": "license-reference-and-attribution" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "collect-complete-mpl-2.0-license-text", "confirm-certificate-attribution-and-trust-store-requirements", @@ -259,7 +474,9 @@ "confirm-empty-libc-utils-subpackage-license-obligations", "confirm-bsd-2-clause-and-bsd-3-clause-notice-coverage" ], - "remainingReviewItems": [] + "remainingReviewItems": [ + + ] }, { "sourceOrigin": "musl", @@ -297,7 +514,9 @@ "conclusion": "license-header-and-attribution" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-third-party-musl-files-and-aports-helper-notice-coverage" ] @@ -322,7 +541,9 @@ "conclusion": "attribution-list" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-required-apache-notice-and-attribution-material" ] @@ -342,7 +563,9 @@ "conclusion": "complete-license-text" } ], - "resolvedReviewItems": [], + "resolvedReviewItems": [ + + ], "remainingReviewItems": [ "confirm-package-specific-copyright-and-aports-patch-notices" ] @@ -365,7 +588,9 @@ "resolvedReviewItems": [ "confirm-package-specific-attribution-material" ], - "remainingReviewItems": [] + "remainingReviewItems": [ + + ] } ] } diff --git a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json index 5d21b2c..e03dadd 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-REVIEW.json @@ -360,6 +360,539 @@ "attribution" ], "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/bbunzip.c", + "outputPath": "evidence/busybox/build-closure-archival-bbunzip.c", + "byteCount": 19163, + "sha256": "c8a5db572c48f33b4554841e5157b7fbe41764b2e8db114201b3dfdfef5ea7e5", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/decompress_gunzip.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-decompress_gunzip.c", + "byteCount": 37689, + "sha256": "2346dd2b227d6305bbe580b50e077e52da9441881c674ad2a6a2960a1f75fa8b", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/liblzo.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-liblzo.h", + "byteCount": 3464, + "sha256": "2a544181ad8ab8386d5cd8df85758286d429fe7dadbfd3f173f91f8aac7f2389", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/lzo1x_1.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_1.c", + "byteCount": 1292, + "sha256": "eba89167022a816fef6a8cf1e296588a1cf0de84ceadfee1b688ebb8b46a833a", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/lzo1x_1o.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_1o.c", + "byteCount": 1299, + "sha256": "255b49a7a81ebd826e23c2635574f5d36e43c286985595ca34772ac1befde940", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/lzo1x_c.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_c.c", + "byteCount": 7045, + "sha256": "a05ba174e8dc9509d70f28cacaf704e201f131dd02b7cccb509dd4c70543deae", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/lzo1x_d.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-lzo1x_d.c", + "byteCount": 9309, + "sha256": "a63a1d20e33650fe04afe12c7ad5c09b09bbd0a040e857aba8d695f30c85875c", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz.h", + "byteCount": 11673, + "sha256": "db6edcf8424001930a8b5ff513eafd67d89f69efd5f46feab9c9f390b644d0b4", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_config.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_config.h", + "byteCount": 3178, + "sha256": "4f44266f23eee08aa32f424c07701b0fd7ebc90f676eecfd79afbf2705c3c981", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_dec_bcj.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_bcj.c", + "byteCount": 14107, + "sha256": "42ead75122607fa392579eaae003b7b5921dfb636f4d9e912818790228a2fc95", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_dec_lzma2.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_lzma2.c", + "byteCount": 29287, + "sha256": "8b8f8854a4b3c11288d693bde95d346468cfc9aa9e59babcf734d59652e27c79", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_dec_stream.c", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_dec_stream.c", + "byteCount": 19848, + "sha256": "ec66858910c88b773e65c37dfabdab6018555773d379a8cd20a9d13a2aa102c2", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_lzma2.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_lzma2.h", + "byteCount": 6160, + "sha256": "ef38ebe621800cf4960575136ea167171648c9e8e0d8ed3b98be6651d1651981", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_private.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_private.h", + "byteCount": 4679, + "sha256": "d0d05b876173512ec45fd5ac89163dbdd89cd95a0a1759e9f4473872d3393d37", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/libarchive/unxz/xz_stream.h", + "outputPath": "evidence/busybox/build-closure-archival-libarchive-unxz-xz_stream.h", + "byteCount": 1471, + "sha256": "a30849b8acaafdb9613fa5fc7704b89f97050ccf9847fb6f5182487012df26aa", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/archival/lzop.c", + "outputPath": "evidence/busybox/build-closure-archival-lzop.c", + "byteCount": 30948, + "sha256": "2ce2f015b7378d083929a58017af6177afa223091b2fde7e464fa7e2ec56dd44", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/dos2unix.c", + "outputPath": "evidence/busybox/build-closure-coreutils-dos2unix.c", + "byteCount": 3625, + "sha256": "594bed730a26ed7622e34b7c5774a3737b777ce9dd07023a567b6f8baaacb8f9", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/sync.c", + "outputPath": "evidence/busybox/build-closure-coreutils-sync.c", + "byteCount": 3797, + "sha256": "655760926c4e2d4959a56710452fbefcfac1d75ed5fea320c55a4985b20c5a9d", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/test.c", + "outputPath": "evidence/busybox/build-closure-coreutils-test.c", + "byteCount": 23678, + "sha256": "7fa39b5204486d13765f63cbeab0b4a482b89c6c85868553857df299d792375d", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/coreutils/tr.c", + "outputPath": "evidence/busybox/build-closure-coreutils-tr.c", + "byteCount": 9766, + "sha256": "5e0e51da2636151b97f5bd905716c484a9759b055b90b27488437c945d4be6e3", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/include/liblzo_interface.h", + "outputPath": "evidence/busybox/build-closure-include-liblzo_interface.h", + "byteCount": 2457, + "sha256": "ece65419355194234d31b78f59d3378581cc53cb959651bc613ba781f3b65cc3", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/change_identity.c", + "outputPath": "evidence/busybox/build-closure-libbb-change_identity.c", + "byteCount": 2411, + "sha256": "c8aef5e372ff6b742f18f8cfa9355e3d28d436d4be279fae5730706370e0c807", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/correct_password.c", + "outputPath": "evidence/busybox/build-closure-libbb-correct_password.c", + "byteCount": 4217, + "sha256": "7f119ea757548393aed188e783fa58dbc240a35fc598acdc727295fea6290e9d", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/hash_md5_sha.c", + "outputPath": "evidence/busybox/build-closure-libbb-hash_md5_sha.c", + "byteCount": 57050, + "sha256": "65dba16216f7f72b562b229c30efe3ffaa6a8d6ff8ae96044394b25adaef0217", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/procps.c", + "outputPath": "evidence/busybox/build-closure-libbb-procps.c", + "byteCount": 17018, + "sha256": "070633eba0b4dfe7f9ee29f02dd1ace6f368acdbe5802c7b1ea570aa2873e70c", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/progress.c", + "outputPath": "evidence/busybox/build-closure-libbb-progress.c", + "byteCount": 7150, + "sha256": "fc3db3f961b24eeed7413ca219de4d4520d041507485628e1a103f234ff03072", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/pw_encrypt_des.c", + "outputPath": "evidence/busybox/build-closure-libbb-pw_encrypt_des.c", + "byteCount": 23942, + "sha256": "00470df43c2ec79b76ebbdcf1ad51d14df14db4bc59142e4c8bd10d07e7f5885", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/pw_encrypt_sha.c", + "outputPath": "evidence/busybox/build-closure-libbb-pw_encrypt_sha.c", + "byteCount": 9442, + "sha256": "1a14c5841a4ad4c8ec4de51c3f7c658dbf772f52120f2a5c9429cd69eb8b3c7d", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/run_shell.c", + "outputPath": "evidence/busybox/build-closure-libbb-run_shell.c", + "byteCount": 3335, + "sha256": "f551208951ef58f131fe2a49425d51b191b6ac25b7b95905125b63eb2e8d0bce", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/setup_environment.c", + "outputPath": "evidence/busybox/build-closure-libbb-setup_environment.c", + "byteCount": 2952, + "sha256": "4e2f6100a44e922c5c7b154e3044c656b7edfae966b2f83c8845248674551bde", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libbb/vfork_daemon_rexec.c", + "outputPath": "evidence/busybox/build-closure-libbb-vfork_daemon_rexec.c", + "byteCount": 9146, + "sha256": "a754155eab527a4bb038722218234371837e013f5092e77631e57ee12df1398c", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/libpwdgrp/uidgid_get.c", + "outputPath": "evidence/busybox/build-closure-libpwdgrp-uidgid_get.c", + "byteCount": 3821, + "sha256": "bfff92a736909142e425694f80b9e85ea390a3b68b9f14896a19a90ca65f15e0", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/loginutils/add-remove-shell.c", + "outputPath": "evidence/busybox/build-closure-loginutils-add-remove-shell.c", + "byteCount": 3706, + "sha256": "9250de6bdc412422d26ef4baf1ecb49cbaef759360088be49295caf263d24173", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/miscutils/bbconfig.c", + "outputPath": "evidence/busybox/build-closure-miscutils-bbconfig.c", + "byteCount": 1704, + "sha256": "e4b817b538e139d17c57cefcd3e382a6dde4458ed42c262c762a89829acea464", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/networking/nc_bloaty.c", + "outputPath": "evidence/busybox/build-closure-networking-nc_bloaty.c", + "byteCount": 31172, + "sha256": "c58ac147a37d8e928ccdf0948fa06d164ac41ed6ce74c5ed128012a2fd6d2362", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/procps/pmap.c", + "outputPath": "evidence/busybox/build-closure-procps-pmap.c", + "byteCount": 2499, + "sha256": "224a941febb696871ff10ffa3a4adb8199c701ccd373098ba5c4c1b41fde494b", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/shell/ash.c", + "outputPath": "evidence/busybox/build-closure-shell-ash.c", + "byteCount": 340996, + "sha256": "ca769312d3c0bf0592c6bc5a810d3328b6d95bdb82fbe2fc7542b0936c4ce7ec", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/shell/shell_common.c", + "outputPath": "evidence/busybox/build-closure-shell-shell_common.c", + "byteCount": 16946, + "sha256": "090601269e1bc01a1558a56a4192a92bc133ab374bf9096fc930c2a6eeca3948", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/shell/shell_common.h", + "outputPath": "evidence/busybox/build-closure-shell-shell_common.h", + "byteCount": 1507, + "sha256": "6d0589523721f9a41f9db5d0d88035bccb086f5055b8709b22c9310004530745", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/util-linux/fdisk_osf.c", + "outputPath": "evidence/busybox/build-closure-util-linux-fdisk_osf.c", + "byteCount": 29910, + "sha256": "d66020e2f68456ad1f7fda40458ee37126dea42c8e0057970d3fcdb591dafdfc", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" + }, + { + "sourceKind": "distfile-member", + "distfile": "busybox-1.36.1.tar.bz2", + "member": "busybox-1.36.1/util-linux/setsid.c", + "outputPath": "evidence/busybox/build-closure-util-linux-setsid.c", + "byteCount": 2391, + "sha256": "29c8bb684db0c174c94f2e509832e62d8a116e864a9bf19fc9844a91452fb8dd", + "evidenceKinds": [ + "inline-license-notice", + "attribution" + ], + "reviewState": "unreviewed-candidate" } ], "openReviewItems": [ diff --git a/Compliance/RootFS/v0.3.3/NOTICE.md b/Compliance/RootFS/v0.3.3/NOTICE.md index df0c26e..ed8bb68 100644 --- a/Compliance/RootFS/v0.3.3/NOTICE.md +++ b/Compliance/RootFS/v0.3.3/NOTICE.md @@ -33,12 +33,12 @@ Generated from the exact `v0.3.3` archive with SHA-256 No file whose path identifies it as LICENSE, COPYING, NOTICE, or a license-directory member was found in the guest template. Declared identifiers and expressions are recorded in -`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 37 +`LICENSE-INVENTORY.json`. `LICENSE-REVIEW.json` pins 78 candidate license, attribution, declaration, and inline-notice files across all 10 source origins. The external review tool extracts and verifies those candidates from the pinned source-review bundle. `LICENSE-REVIEW-RESULTS.json` records the checksum-bound engineering review -of all 37 candidates. All indexed review items are resolved +of all 78 candidates. All indexed review items are resolved for `libc-dev`, `zlib`. 8 source origins still have package-specific open items, so this is not a complete or legally approved license/NOTICE bundle. @@ -49,9 +49,9 @@ reference/attribution payloads and files, together with all checksum-bound reviewed evidence. The repository tool can materialize and re-verify that bundle outside the repository. `LICENSE-NOTICE-REVIEW-RESULTS.json` records checksum-bound engineering -review of all 97 indexed -payload files. 3 origins have no remaining -candidate-material engineering items; 5 origins +review of all 138 indexed +payload files. 4 origins have no remaining +candidate-material engineering items; 4 origins still require package-specific material. Legal review and redistribution approval remain open. diff --git a/Compliance/RootFS/v0.3.3/README.md b/Compliance/RootFS/v0.3.3/README.md index 1f6251f..138173c 100644 --- a/Compliance/RootFS/v0.3.3/README.md +++ b/Compliance/RootFS/v0.3.3/README.md @@ -16,15 +16,15 @@ pinned RootFS archive. It does not store the RootFS payload. SHA-256; - `LICENSE-INVENTORY.json`:声明的许可证表达式、标识符和 archive 内 license/notice 文件检查结果; -- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 37 个候选许可证文本、 +- `LICENSE-REVIEW.json`:覆盖 10 个 source origin 的 78 个候选许可证文本、 attribution、声明与内联 notice 的路径、大小、SHA-256 和逐包未决审查项; -- `LICENSE-REVIEW-RESULTS.json`:对全部 37 个候选的 checksum-bound 工程复核 +- `LICENSE-REVIEW-RESULTS.json`:对全部 78 个候选的 checksum-bound 工程复核 结论、coverage 和未决项处置;不表示法律或再分发批准; - `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 13 份远端 - 许可证/attribution 材料、47 份 aports 补充文件及现有 37 份复核证据的外置候选包; + 许可证/attribution 材料、47 份 aports 补充文件及现有 78 份复核证据的外置候选包; payload 不提交,工程、法律和再分发门禁保持关闭; -- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 97 个 payload 文件树的 - 工程复核结果;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,法律和 +- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 138 个 payload 文件树的 + 工程复核结果;4 个 origin 的候选材料工程项关闭,4 个仍需补逐包材料,法律和 再分发门禁保持关闭; - `RUNTIME-CONFIGURATION.json`:guest、`apk`、repository、world 和 DNS 默认配置; - `NOTICE.md`:可复现 attribution inventory 与尚未完成事项; @@ -34,16 +34,16 @@ pinned RootFS archive. It does not store the RootFS payload. `SOURCE-ACQUISITION.json` pins the aports snapshots and upstream distfiles needed to assemble an external source-review directory. It is an acquisition manifest, not a committed source archive or redistribution grant. -`LICENSE-REVIEW.json` pins 37 unreviewed candidate evidence files across all +`LICENSE-REVIEW.json` pins 78 unreviewed candidate evidence files across all 10 source origins; it is an engineering review index, not legal approval. -`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 37 pinned +`LICENSE-REVIEW-RESULTS.json` records the engineering review of all 78 pinned candidates. Two source origins have no remaining indexed review items; eight still have package-specific open items. `LICENSE-NOTICE-CANDIDATES.json` indexes an external candidate bundle for those eight origins: 13 pinned remote license/attribution payloads, 47 supplemental aports files, and the existing -37 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the -engineering review to the exact 97-file payload tree. Three origins have no -remaining candidate-material engineering items; five still require +78 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the +engineering review to the exact 138-file payload tree. Four origins have no +remaining candidate-material engineering items; four still require package-specific material. Legal and redistribution approval remain open. `alpine-keys` 的 MIT 声明现同时绑定当前固定 aports `APKBUILD` 与上游不可变提交 @@ -198,11 +198,25 @@ Mark Whitley,`sort.c` 署名 Rob Landley,`uniq.c` 署名 Manuel Novoa III。 `confirm-enabled-cut-sort-and-uniq-license-and-attribution-coverage`。 这只确认精确源码与声明/署名证据完整,不判断 GPL 版本选择、组合或发行方案的 法律兼容性。 -BusyBox 其他已启用 -组件的内联第三方 notice 尚未形成完整集合,因此 license-text 与 attribution -coverage 均保持 partial, -`review-other-bundled-third-party-license-and-attribution-coverage` 保持未决, -法律与再分发门禁不变。 +为收口其余已启用组件,工程审查从固定 `busybox-1.36.1.tar.bz2` 开始,按 +`APKBUILD` 顺序应用全部 33 个固定 aports 补丁,再加载固定 `busyboxconfig`。 +补丁后 `oldconfig` 与固定配置只差生成时间戳;生成的 dry-run 构建图包含 487 +个编译单元,递归解析本地 `#include` 后得到 562 个源码/头文件闭包。审查从该 +闭包中选出仍含独立 BSD/MIT/public-domain、LZO/XZ provenance、原作者版权或 +再分发条款的 41 份文件,并把各自的原始 distfile member、大小和 SHA-256 +加入候选。新增材料覆盖 gzip/unzip 的公共领域来源、LZO、XZ Embedded、 +`dos2unix`/`sync`/`test`/`tr`、shadow-derived `libbb` 代码、密码散列来源、 +进度条、`uidgid_get`、`nc_bloaty`、`ash`/shell common、OSF fdisk 与 `setsid` +等实际构建闭包。 + +固定补丁仅修改其中的 `libbb/hash_md5_sha.c` 和 `shell/ash.c`;相应 5 份补丁 +已经作为 supplemental aports payload 单独固定,修改 hunks 不删除或改写本轮 +依赖的 notice。Alpine 的 `0009-properly-fix-wget-https-support.patch` 使固定 +动态配置继续保持 `CONFIG_TLS` 未启用,因此未把仅由未打补丁上游默认值引入的 +TLS 源码误计入闭包。BusyBox 现有证据由 19 份增至 60 份,license-text 与 +attribution coverage 均在候选材料工程层记为 complete,并关闭 +`review-other-bundled-third-party-license-and-attribution-coverage`。这仍不是 +法律兼容性、对应源码完整性或再分发批准,相关发行门禁保持关闭。 The `busyboxconfig` at pinned aports commit `d1b6f274f29076967826e0ecf6ebcaa5d360272f` is 31,529 bytes with SHA-256 @@ -341,12 +355,32 @@ closing `confirm-enabled-cut-sort-and-uniq-license-and-attribution-coverage` at the engineering level. This confirms exact source, declaration, and attribution evidence only; it does not determine the legal compatibility of GPL version -selection, combination, or the distribution plan. A complete set -of inline third-party notices for BusyBox's other -enabled components is still missing, so license-text and attribution coverage -remain partial, -`review-other-bundled-third-party-license-and-attribution-coverage` remains -open, and the legal and redistribution gates do not change. +selection, combination, or the distribution plan. To close the remaining +enabled-component review, the engineering audit starts from the pinned +`busybox-1.36.1.tar.bz2`, applies all 33 pinned aports patches in `APKBUILD` +order, and loads the pinned `busyboxconfig`. The post-patch `oldconfig` differs +from the pinned configuration only by its generated timestamp. The resulting +dry-run build graph contains 487 compilation units and a 562-file recursive +local-include closure. From that closure, the audit selects 41 files that +retain independent BSD/MIT/public-domain terms, LZO/XZ provenance, original +copyright, or redistribution notices, and pins each original distfile member, +byte count, and SHA-256. The added evidence covers public-domain gzip/unzip +origins, LZO, XZ Embedded, `dos2unix`/`sync`/`test`/`tr`, shadow-derived +`libbb` code, password-hash origins, the progress meter, `uidgid_get`, +`nc_bloaty`, `ash`/shell common, OSF fdisk, and `setsid`. + +Only `libbb/hash_md5_sha.c` and `shell/ash.c` among those files are modified by +the pinned patch set. The five relevant patches are already pinned as +supplemental aports payloads, and their hunks do not remove or rewrite the +notices used here. Alpine patch +`0009-properly-fix-wget-https-support.patch` keeps `CONFIG_TLS` disabled in +the fixed dynamic configuration, so TLS sources introduced only by the +unpatched upstream default are excluded. BusyBox existing evidence increases +from 19 to 60 files; license-text and attribution coverage are complete at the +candidate-material engineering level, closing +`review-other-bundled-third-party-license-and-attribution-coverage`. This is +still not a legal-compatibility conclusion, corresponding-source completeness +determination, or redistribution approval; all release gates remain closed. `ca-certificates-20230506.tar.bz2` 中的 `mk-ca-bundle.pl`(20,863 字节, SHA-256 `9d828d97053868907ce6229d132132f0f26772393405dadd037b6f85a5c5b219`) @@ -521,13 +555,13 @@ ruby Scripts/rootfs-license-review-results.rb ``` 工具只提取 `LICENSE-REVIEW.json` 固定的候选文件,并再次核对大小、SHA-256、 -路径全集、无符号链接/特殊节点边界。结果清单证明 37 个候选已完成工程复核; +路径全集、无符号链接/特殊节点边界。结果清单证明 78 个候选已完成工程复核; 外置输出仍不是可直接随产品发行的 NOTICE bundle。 The tool extracts only candidates pinned by `LICENSE-REVIEW.json`, then rechecks byte counts, SHA-256 digests, the exact path set, and the no-symlink/ special-node boundary. The results manifest proves engineering review of all -37 candidates; the external output is still not a product-ready NOTICE bundle. +78 candidates; the external output is still not a product-ready NOTICE bundle. 剩余 8 个 source origin 的材料可继续组装为外置候选包。先校验清单;实际物化 必须同时提供已经通过 `--verify` 的 source-review 和 license-review 目录,以及 @@ -571,19 +605,19 @@ advice, or redistribution approval. 这些文件不构成完整第三方 LICENSE/NOTICE bundle、经审查的 copyleft corresponding-source 交付、法律意见或再分发授权。源码获取清单已完整覆盖固定 -inventory,37 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 -8 个 source origin 的 97 个新候选 payload 已完成 checksum-bound 工程复核; -`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 +inventory,78 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 +8 个 source origin 的 138 个新候选 payload 已完成 checksum-bound 工程复核; +`apk-tools`、`busybox`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 4 个 origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、源码提供方式、法律 审查、App Store 2.5.2 产品策略和负责人批准仍是发行阻塞项。 These files are not a complete third-party LICENSE/NOTICE bundle, reviewed copyleft corresponding-source delivery, legal advice, or redistribution approval. The acquisition manifest completely covers the pinned inventory and -all 37 indexed candidates have engineering review results. `libc-dev` and -`zlib` have no remaining indexed items. All 97 newly indexed payloads have a -checksum-bound engineering review; `apk-tools`, `openssl`, and `pax-utils` -have no remaining candidate-material engineering items, while five origins +all 78 indexed candidates have engineering review results. `libc-dev` and +`zlib` have no remaining indexed items. All 138 newly indexed payloads have a +checksum-bound engineering review; `apk-tools`, `busybox`, `openssl`, and +`pax-utils` have no remaining candidate-material engineering items, while four origins still need package-specific copyright/notice material. Modification, build completeness, source-offer mechanics, legal review, App Store 2.5.2 product policy, and authorized approval remain distribution blockers. diff --git a/Compliance/RootFS/v0.3.3/SHA256SUMS b/Compliance/RootFS/v0.3.3/SHA256SUMS index bf33117..a1a343a 100644 --- a/Compliance/RootFS/v0.3.3/SHA256SUMS +++ b/Compliance/RootFS/v0.3.3/SHA256SUMS @@ -1,10 +1,10 @@ -089cffca5b2f65ff50e9a0dd6bf0b3b0bc586806b22009a155e308f2f4603584 EVIDENCE.json -5b65dab7a2933ad2324538d03c55b024524e7900dd9d87a1f1cac732c88e6d81 LICENSE-INVENTORY.json -537646fc1fe8bb81322d74a434227d83495ffbc4bff5a61f123a47e9effcd999 LICENSE-NOTICE-CANDIDATES.json -b894db5aea4637d523d4b144ccbfe03890baac83bebad4dc0b63e0604415bd58 LICENSE-NOTICE-REVIEW-RESULTS.json -fe473ffd86d0d1ca7b1ad2594373311b8cc6181ee36865089780e1cf885fc0de LICENSE-REVIEW-RESULTS.json -60dd3aa2d8b73f49813e081b722caa65d60580ef767ad6df4e7cf906b7baa59d LICENSE-REVIEW.json -c00334eed179c19e3c1257e280655ef698ddf35d27d0ccd9fc978579eff90230 NOTICE.md +9135d47129268d88874763486ad682b3e2b50cf58a5fd368d839831c5c32eb7e EVIDENCE.json +72766d0a381e1fbe2a14072713414d26734946f2ff0328b4c9426efc6f850934 LICENSE-INVENTORY.json +534c12f8b9268a36cff13af3123bebbacf61d85b667fafce6d7649cae47c7e65 LICENSE-NOTICE-CANDIDATES.json +f5363bd54ea3fc0d772989085d9abc49320fa88843739e0725f76bd5a48cc8fc LICENSE-NOTICE-REVIEW-RESULTS.json +810f047bd36867c3a34318fef8535dcb87cc263f6a59df88b1abee56472e35ce LICENSE-REVIEW-RESULTS.json +5c6f0971c156275869c0e5c0390cb1ce2f3acb3b55d19657d902e264cbe2ef08 LICENSE-REVIEW.json +05f31ff6f7f31d7e9c65ba7965fdd00da783884e9baa3a5e9b21a677c3814ef2 NOTICE.md 4f7f7626f3d0891a29717e4b7932c36004ecc9aac25a4aa104c300aae979e3e1 PACKAGE-INVENTORY.tsv dbca9b285015a0d8b1d339a894b4594c9e335cbc2d7f9d5212a41095ae4bd1e1 RUNTIME-CONFIGURATION.json 8e021cb8c4160c934a0202609691d7a94526cd016f4394a47da6e7a5ab41d0ea SBOM.spdx.json diff --git a/Docs/ReleaseCompliance.md b/Docs/ReleaseCompliance.md index 428992d..d78d681 100644 --- a/Docs/ReleaseCompliance.md +++ b/Docs/ReleaseCompliance.md @@ -72,13 +72,13 @@ machine-readable SBOM。仓库现在从固定 archive 可复现生成 15 个已 `apk`、repository、DNS 默认配置快照。archive 内没有发现可识别的 LICENSE/COPYING/NOTICE 文件。仓库另有与 inventory 一一对应、固定 checksum 的 aports snapshot/upstream distfile 获取清单和仓库外 materializer,并固定了覆盖 -全部 10 个 source origin 的 37 个 license、attribution、声明与内联 notice 候选。 +全部 10 个 source origin 的 78 个 license、attribution、声明与内联 notice 候选。 第二个仓库外工具从已验证 source-review 目录提取这些候选;固定结果清单记录 -37/37 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source +78/78 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:13 份远端 许可证/attribution 材料、47 份 aports 补充文件和全部既有复核证据;工具可在 -仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 97 文件 payload -tree;`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 +仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 138 文件 payload +tree;`apk-tools`、`busybox`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 4 个 origin 仍需补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成, 不能视为完整 NOTICE 或已批准的对应源码交付。 @@ -176,11 +176,11 @@ Alpine `apk` 可以下载、安装和执行新增代码。即使初始 RootFS - [x] 从固定 APK database 生成完整 package inventory。 - [x] 生成并通过 SPDX 2.3 JSON schema 校验的 machine-readable SBOM。 -- [x] 对固定的 37 个 license/NOTICE 候选完成 checksum-bound 工程复核。 +- [x] 对固定的 78 个 license/NOTICE 候选完成 checksum-bound 工程复核。 - [x] 为剩余 8 个 source origin 建立 checksum-bound 外置候选包索引与可复验 materializer;payload 不提交且批准门禁保持关闭。 -- [x] 对外置候选包的 97 个 payload 完成 checksum-bound 工程复核并固定结果; - 3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料。 +- [x] 对外置候选包的 138 个 payload 完成 checksum-bound 工程复核并固定结果; + BusyBox 构建闭包审查已收口,4 个 origin 的候选材料工程项关闭,4 个仍需补逐包材料。 - [ ] 收集 license text 和 NOTICE。 - [ ] 建立 copyleft corresponding source bundle。 - [x] 固定 DNS、repository 和 package-manager 默认配置事实。 diff --git a/Docs/Roadmap.md b/Docs/Roadmap.md index 3e75cc7..d794208 100644 --- a/Docs/Roadmap.md +++ b/Docs/Roadmap.md @@ -103,7 +103,7 @@ | 最低 Xcode 16 原生兼容 | 已通过 | Xcode 16.0 / iOS 18.0 SDK 完成 RootFS install、Simulator/device final-link 和 17 项 native smoke | | App lifecycle 与内存 | 进行中 | Simulator 与 Jack iPhone 均有 256 MiB `ru_maxrss` 门禁;真机 process suspend/resume、UIKit foreground/background、强制终止后数据恢复和有界 App delegate memory-warning 回调恢复已通过;补真实 memory pressure/jetsam | | RootFS ENOSPC/掉电 | 进行中 | 峰值空间预检、全 ENOSPC、七点持久化屏障、确定性掉电切点和 Jack iPhone 受限容量/ENOSPC 清理恢复已覆盖;补真实 storage pressure/强制断电 | -| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、37/37 初始候选和 97/97 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | +| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、78/78 初始候选和 138/138 外置 payload 工程复核已完成;BusyBox 构建闭包审查已收口,4 个 origin 的候选材料工程项关闭,4 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | | App Store 2.5.2 | 阻塞 | guest download/execute policy 有书面结论 | ### 后续 runtime 执行顺序 diff --git a/Docs/RootFS.md b/Docs/RootFS.md index d1baf70..a2a39f0 100644 --- a/Docs/RootFS.md +++ b/Docs/RootFS.md @@ -5,7 +5,7 @@ RootFS 是 PocketRoot 的外部供应链输入,不是普通测试 fixture。仓库提交的是不可变清单、校验和安全安装代码,不提交、镜像或默认打包 RootFS 二进制。 > [!WARNING] -> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 37 个初始候选和 97 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 +> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 78 个初始候选和 138 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;BusyBox 构建闭包审查已收口,4 个 origin 的候选材料工程项已关闭,4 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 ## 1. 固定清单 @@ -118,7 +118,7 @@ receipt schema v2 强制包含该模式。旧 v1 source-review 的传输来源 规范化 aports 目录身份覆盖条目类型、路径、普通文件权限位和内容摘要;物化时会保留 这些权限位,`--verify` 会再次校验。 -在 source-review 目录验证通过后,可把固定的 37 个候选许可证/attribution 文件 +在 source-review 目录验证通过后,可把固定的 78 个候选许可证/attribution 文件 提取到另一个仓库外目录: ```bash @@ -139,10 +139,16 @@ ruby Scripts/rootfs-license-review-results.rb `APKBUILD`;`--verify` 会复核普通文件摘要、目录集合和符号链接目标。脚本不向 App、 Git 或 CI artifact 自动添加输出。这完成的是可复现的工程获取流程。archive 内没有 随附可识别的 LICENSE/COPYING/NOTICE 文件。候选工具会核对提取文件的大小、 -SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 37/37 个候选均已 +SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单记录 78/78 个候选均已 工程复核,其中 `libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有 未决项;输出不能直接视为完整 NOTICE 或对应源码交付材料。 +BusyBox 的最后一批候选由固定 distfile、按 `APKBUILD` 顺序应用的 33 个补丁和 +固定配置共同确定。补丁后配置只发生时间戳变化;dry-run 构建图包含 487 个编译 +单元和 562 文件递归 include 闭包,并从中固定 41 份仍含独立第三方条款或 +provenance 的文件。连同已有材料,BusyBox 现有 60 份 checksum-bound 证据; +这关闭候选材料工程项,但不解除法律、对应源码或发行门禁。 + 剩余 8 个 origin 的外置 LICENSE/NOTICE 候选包清单还固定了 13 份远端许可证/ attribution 材料与 47 份 aports 补充文件。清单可独立校验;实际物化和复验必须 同时提供上面已经验证的两个仓库外目录: @@ -167,10 +173,10 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ ``` 工具对远端材料强制 HTTPS、重定向次数、响应大小、固定字节数与 SHA-256,并原子 -创建输出。结果清单把工程复核绑定到精确的 97 文件 payload tree;复验器拒绝路径 +创建输出。结果清单把工程复核绑定到精确的 138 文件 payload tree;复验器拒绝路径 漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools`、 -`openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包 -材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 +`busybox`、`openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 4 个 origin +仍需补逐包材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 不要把归档放入 `Sources/PocketRootResources/Resources`、Demo resources 或 Git LFS。合规完成前,`PocketRootBundledRootFSProvider` 的资源查找预期返回 `nil`。 diff --git a/Docs/en/ReleaseCompliance.md b/Docs/en/ReleaseCompliance.md index 5afde15..1b4552a 100644 --- a/Docs/en/ReleaseCompliance.md +++ b/Docs/en/ReleaseCompliance.md @@ -36,17 +36,17 @@ the default `apk`, repository, and DNS snapshot. No identifiable LICENSE/COPYING/NOTICE file was found in the archive. A checksum-pinned aports-snapshot/upstream-distfile manifest covers the inventory, and an outside-repository materializer creates reproducible review inputs. A second -outside-repository tool pins, extracts, and verifies 37 license, attribution, +outside-repository tool pins, extracts, and verifies 78 license, attribution, declaration, and inline-notice candidates across all 10 source origins. -A pinned result manifest records engineering review of all 37 candidates. +A pinned result manifest records engineering review of all 78 candidates. `libc-dev` and `zlib` have no remaining indexed items; eight source origins still have package-level follow-up. The repository now pins an external candidate bundle for those origins: 13 remote license/attribution payloads, 47 supplemental aports files, and all existing reviewed evidence. The tool can atomically materialize and re-verify it outside the repository. A pinned -results manifest binds engineering review to the exact 97-file payload tree. -`apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material -engineering items; five origins still need package-specific material. Modification, +results manifest binds engineering review to the exact 138-file payload tree. +`apk-tools`, `busybox`, `openssl`, and `pax-utils` have no remaining +candidate-material engineering items; four origins still need package-specific material. Modification, build-completeness, source-offer, and legal reviews remain unresolved, so the output is neither a complete NOTICE set nor approved corresponding-source delivery. @@ -117,14 +117,15 @@ The current code does not provide a complete product-level privacy policy. - [x] Generate a complete inventory from the pinned APK database. - [x] Generate a machine-readable SBOM validated against the SPDX 2.3 JSON schema. -- [x] Complete checksum-bound engineering review of all 37 pinned +- [x] Complete checksum-bound engineering review of all 78 pinned license/NOTICE candidates. - [x] Index a checksum-bound external candidate bundle and reproducible materializer for the eight remaining origins; payloads stay uncommitted and approval gates stay closed. -- [x] Complete checksum-bound engineering review of all 97 external candidate - payloads; three origins have no remaining candidate-material engineering - items and five still need package-specific material. +- [x] Complete checksum-bound engineering review of all 138 external candidate + payloads; the BusyBox build-closure review is closed, four origins have no + remaining candidate-material engineering items, and four still need + package-specific material. - [ ] Collect license texts and NOTICE files. - [ ] Establish a corresponding-source bundle for copyleft components. - [x] Record default DNS, repository, and package-manager facts. diff --git a/Docs/en/Roadmap.md b/Docs/en/Roadmap.md index 4f6c8a7..7e48058 100644 --- a/Docs/en/Roadmap.md +++ b/Docs/en/Roadmap.md @@ -98,7 +98,7 @@ This establishes the current Simulator, minimum-Xcode 16, and single-iPhone one- | Minimum Xcode 16 native | Passed | Xcode 16.0 / iOS 18.0 SDK completed RootFS install, Simulator/device final links, and the 17-check native smoke | | App lifecycle and memory | In progress | Simulator and Jack iPhone have 256 MiB `ru_maxrss` gates; physical process suspend/resume, UIKit foreground/background, post-termination data recovery, and bounded App-delegate memory-warning recovery passed; add real memory-pressure/jetsam evidence | | RootFS ENOSPC/power faults | In progress | Peak-space preflight, full ENOSPC, seven persistence barriers, deterministic power-loss cuts, and bounded capacity/ENOSPC cleanup recovery on Jack iPhone are covered; add real storage-pressure/power-cut evidence | -| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 37 initial candidates, and all 97 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | +| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 78 initial candidates, and all 138 external payloads have checksum-bound engineering review; the BusyBox build-closure review is closed, four origins have no remaining candidate-material engineering items, four still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | | App Store 2.5.2 | Blocked | Written guest download/execute policy decision | ### Next runtime sequence diff --git a/Docs/en/RootFS.md b/Docs/en/RootFS.md index 5f882e1..6d5542a 100644 --- a/Docs/en/RootFS.md +++ b/Docs/en/RootFS.md @@ -5,7 +5,7 @@ A RootFS is an external supply-chain input, not a normal fixture. PocketRoot commits immutable metadata and secure install code, not the payload. > [!WARNING] -> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 37 initial candidates and all 97 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. +> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 78 initial candidates and all 138 external LICENSE/NOTICE payloads. The BusyBox build-closure review is closed; four origins have no remaining candidate-material engineering items and four still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. ## Pinned manifest @@ -95,7 +95,7 @@ Receipt schema v2 requires that explicit mode. A legacy v1 source-review directory has ambiguous transport provenance and is no longer accepted by `--verify`; pass it to `--download-cache` to regenerate a verifiable v2 bundle. -After that source-review directory verifies, extract the 37 pinned +After that source-review directory verifies, extract the 78 pinned license/attribution candidates into another directory outside the repository: ```bash @@ -122,10 +122,19 @@ engineering acquisition workflow, not legal review. The RootFS archive contains no identifiable LICENSE/COPYING/NOTICE files. The candidate tool rechecks extracted byte counts, SHA-256 digests, the exact path set, and the no-link/special-node boundary. The pinned results record engineering review of -all 37 candidates: `libc-dev` and `zlib` have no remaining indexed items, while +all 78 candidates: `libc-dev` and `zlib` have no remaining indexed items, while eight source origins still require follow-up. The output is not a completed NOTICE or corresponding-source delivery bundle. +The final BusyBox candidate set is derived from the pinned distfile, all 33 +patches applied in `APKBUILD` order, and the pinned configuration. After +patching, only the generated timestamp changes in the configuration. The +dry-run build graph contains 487 compilation units and a 562-file recursive +include closure, from which 41 files retaining independent third-party terms +or provenance are pinned. Together with prior material, BusyBox now has 60 +checksum-bound evidence files. This closes its candidate-material engineering +item without opening legal, corresponding-source, or distribution gates. + The external LICENSE/NOTICE candidate manifest for those eight origins also pins 13 remote license/attribution payloads and 47 supplemental aports files. Validate it independently, or materialize and re-verify it using both external @@ -152,11 +161,12 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ The tool enforces HTTPS, redirect and response-size bounds, pinned byte counts and SHA-256 digests, and atomic output creation. The results bind engineering -review to the exact 97-file payload tree; the verifier rejects path drift, +review to the exact 138-file payload tree; the verifier rejects path drift, links, special nodes, known-digest drift, and tree-digest drift. `apk-tools`, -`openssl`, and `pax-utils` have no remaining candidate-material engineering -items; five origins still need package-specific material. The candidate NOTICE -and receipt do not represent legal review or distribution approval. +`busybox`, `openssl`, and `pax-utils` have no remaining candidate-material +engineering items; four origins still need package-specific material. The +candidate NOTICE and receipt do not represent legal review or distribution +approval. Do not put it in package resources, Demo resources, Git, or Git LFS. diff --git a/README.md b/README.md index 7294f21..72fa902 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ print("stderr:", result.stderr) - 展开大小:`18,838,016` 字节 - SHA-256:`be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4` -固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 37 个初始候选及 97 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 +固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 78 个初始候选及 138 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;BusyBox 候选材料工程项已关闭,4 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 ## 验证命令 diff --git a/Scripts/rootfs-license-notice-candidates.rb b/Scripts/rootfs-license-notice-candidates.rb index 7392ed6..d4c3cd4 100644 --- a/Scripts/rootfs-license-notice-candidates.rb +++ b/Scripts/rootfs-license-notice-candidates.rb @@ -20,7 +20,7 @@ module RootFSLicenseNoticeCandidates alpine-baselayout alpine-keys apk-tools busybox ca-certificates musl openssl pax-utils ].freeze - EXPECTED_EXISTING_EVIDENCE_FILES = 37 + EXPECTED_EXISTING_EVIDENCE_FILES = 78 EXPECTED_REMOTE_PAYLOAD_FILES = 13 EXPECTED_APORTS_FILES = 47 PAYLOAD_KINDS = %w[package-attribution spdx-license-text].freeze diff --git a/Scripts/rootfs-license-notice-review-results.rb b/Scripts/rootfs-license-notice-review-results.rb index 0439d76..578294f 100644 --- a/Scripts/rootfs-license-notice-review-results.rb +++ b/Scripts/rootfs-license-notice-review-results.rb @@ -22,7 +22,7 @@ module RootFSLicenseNoticeReviewResults COVERAGE = %w[complete partial reference-only].freeze SHA256_PATTERN = /\A[0-9a-f]{64}\z/ CANDIDATE_PAYLOAD_TREE_FORMAT = "sha256-path-lines-v1" - EXPECTED_REVIEWED_PAYLOAD_FILES = 97 + EXPECTED_REVIEWED_PAYLOAD_FILES = 138 MAX_REVIEWED_PAYLOAD_BYTES = 8 * 1_024 * 1_024 TOP_LEVEL_KEYS = %w[ allIndexedCandidatePayloadsReviewed archive candidateManifestSha256 diff --git a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb index beac3d6..c645720 100644 --- a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb @@ -29,7 +29,7 @@ def test_validates_complete_open_origin_candidate_index assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length - assert_equal 37, validated.fetch(:existing_evidence_paths).length + assert_equal 78, validated.fetch(:existing_evidence_paths).length assert_equal 47, validated.fetch(:aports_paths).length end @@ -645,6 +645,86 @@ def test_pins_enabled_busybox_cut_sort_and_uniq_notices ) end + def test_pins_remaining_busybox_build_closure_notices + source = @candidate.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + review_source = @review.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + relative_paths = %w[ + archival/bbunzip.c + archival/libarchive/decompress_gunzip.c + archival/libarchive/liblzo.h + archival/libarchive/lzo1x_1.c + archival/libarchive/lzo1x_1o.c + archival/libarchive/lzo1x_c.c + archival/libarchive/lzo1x_d.c + archival/libarchive/unxz/xz.h + archival/libarchive/unxz/xz_config.h + archival/libarchive/unxz/xz_dec_bcj.c + archival/libarchive/unxz/xz_dec_lzma2.c + archival/libarchive/unxz/xz_dec_stream.c + archival/libarchive/unxz/xz_lzma2.h + archival/libarchive/unxz/xz_private.h + archival/libarchive/unxz/xz_stream.h + archival/lzop.c + coreutils/dos2unix.c + coreutils/sync.c + coreutils/test.c + coreutils/tr.c + include/liblzo_interface.h + libbb/change_identity.c + libbb/correct_password.c + libbb/hash_md5_sha.c + libbb/procps.c + libbb/progress.c + libbb/pw_encrypt_des.c + libbb/pw_encrypt_sha.c + libbb/run_shell.c + libbb/setup_environment.c + libbb/vfork_daemon_rexec.c + libpwdgrp/uidgid_get.c + loginutils/add-remove-shell.c + miscutils/bbconfig.c + networking/nc_bloaty.c + procps/pmap.c + shell/ash.c + shell/shell_common.c + shell/shell_common.h + util-linux/fdisk_osf.c + util-linux/setsid.c + ] + evidence = review_source.fetch("candidateEvidence").select do |candidate| + candidate.fetch("outputPath").start_with?( + "evidence/busybox/build-closure-" + ) + end + + assert_equal 41, evidence.length + assert_equal( + relative_paths.map { |path| "busybox-1.36.1/#{path}" }, + evidence.map { |candidate| candidate.fetch("member") } + ) + evidence.zip(relative_paths).each do |candidate, relative_path| + expected_output = + "evidence/busybox/build-closure-#{relative_path.tr("/", "-")}" + + assert_equal expected_output, candidate.fetch("outputPath") + assert_operator candidate.fetch("byteCount"), :>, 0 + assert_match(/\A[0-9a-f]{64}\z/, candidate.fetch("sha256")) + assert_equal( + %w[inline-license-notice attribution], + candidate.fetch("evidenceKinds") + ) + assert_includes source.fetch("existingEvidencePaths"), expected_output + end + assert_includes( + source.fetch("remainingReviewItems"), + "review-other-bundled-third-party-license-and-attribution-coverage" + ) + end + def test_rejects_overlapping_materialized_output_paths payloads = @candidate.fetch("remotePayloads") payloads.fetch(0)["outputPath"] = "licenses/collision" diff --git a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb index 9db21da..ea99276 100644 --- a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb @@ -47,10 +47,10 @@ def test_validates_pinned_candidate_review_results assert_equal 8, validated.fetch(:sources).length assert_equal 13, validated.fetch(:remote_payloads).length assert_equal 47, validated.fetch(:aports_paths).length - assert_equal 97, @results.fetch("reviewedPayloadFileCount") - assert_equal 5, + assert_equal 138, @results.fetch("reviewedPayloadFileCount") + assert_equal 4, @results.fetch("sourceOriginsWithRemainingReviewItems") - assert_equal %w[apk-tools openssl pax-utils], + assert_equal %w[apk-tools busybox openssl pax-utils], @results.fetch("sources") .select { |source| source.fetch("remainingReviewItems").empty? } .map { |source| source.fetch("sourceOrigin") } @@ -112,19 +112,16 @@ def test_binds_enabled_busybox_bzip2_to_its_exact_license candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") assert_equal 37, source.fetch("reviewedSupplementalAportsCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-bzip2-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -134,19 +131,16 @@ def test_binds_enabled_busybox_ash_math_to_inline_notices candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-ash-math-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -156,19 +150,16 @@ def test_binds_enabled_busybox_env_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-env-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -178,19 +169,16 @@ def test_binds_enabled_busybox_echo_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-echo-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -200,19 +188,16 @@ def test_binds_enabled_busybox_logger_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-logger-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -222,19 +207,16 @@ def test_binds_enabled_busybox_cal_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-cal-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -244,19 +226,16 @@ def test_binds_enabled_busybox_ping_and_ping6_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-ping-and-ping6-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -266,19 +245,16 @@ def test_binds_enabled_busybox_traceroute_and_traceroute6_to_inline_notice candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-traceroute-and-traceroute6-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -288,19 +264,16 @@ def test_binds_enabled_busybox_od_hexdump_and_hd_to_inline_notices candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-od-hexdump-and-hd-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -310,19 +283,16 @@ def test_binds_enabled_busybox_expand_unexpand_and_fold_to_license_headers candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-expand-unexpand-and-fold-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") - ) - assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end @@ -332,19 +302,35 @@ def test_binds_enabled_busybox_cut_sort_and_uniq_to_license_headers candidate.fetch("sourceOrigin") == "busybox" end - assert_equal "partial", source.fetch("licenseTextCoverage") - assert_equal "partial", source.fetch("attributionCoverage") - assert_equal 19, source.fetch("reviewedExistingEvidenceCount") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") assert_includes( source.fetch("resolvedReviewItems"), "confirm-enabled-cut-sort-and-uniq-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") assert_equal( - ["review-other-bundled-third-party-license-and-attribution-coverage"], - source.fetch("remainingReviewItems") + "candidate-material-complete-engineering-only", + source.fetch("engineeringConclusion") + ) + end + + def test_closes_remaining_busybox_build_closure_review_item + source = @results.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "busybox" + end + + assert_equal 60, source.fetch("reviewedExistingEvidenceCount") + assert_includes( + source.fetch("resolvedReviewItems"), + "review-other-bundled-third-party-license-and-attribution-coverage" ) + assert_empty source.fetch("remainingReviewItems") + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "complete", source.fetch("attributionCoverage") assert_equal( - "additional-package-material-required", + "candidate-material-complete-engineering-only", source.fetch("engineeringConclusion") ) end diff --git a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb index 21fc26c..a1871f6 100644 --- a/Tests/Scripts/RootFSLicenseReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseReviewResultsTests.rb @@ -39,7 +39,7 @@ def test_validates_pinned_engineering_review_results sources = validate assert_equal 10, sources.length - assert_equal 37, + assert_equal 78, sources.sum { |entry| entry.fetch("candidateResults").length } assert_equal 8, sources.count { |entry| !entry.fetch("remainingReviewItems").empty? } @@ -49,6 +49,46 @@ def test_validates_pinned_engineering_review_results .map { |entry| entry.fetch("sourceOrigin") } end + def test_reviews_remaining_busybox_build_closure_candidates + sources = validate + result = sources.find do |entry| + entry.fetch("sourceOrigin") == "busybox" + end + review = @review.fetch("sources").find do |entry| + entry.fetch("sourceOrigin") == "busybox" + end + candidate_results = result.fetch("candidateResults").select do |candidate| + candidate.fetch("outputPath").start_with?( + "evidence/busybox/build-closure-" + ) + end + candidate_evidence = review.fetch("candidateEvidence").select do |candidate| + candidate.fetch("outputPath").start_with?( + "evidence/busybox/build-closure-" + ) + end + + assert_equal 41, candidate_results.length + assert_equal( + candidate_evidence.map do |candidate| + [candidate.fetch("outputPath"), candidate.fetch("sha256")] + end, + candidate_results.map do |candidate| + [candidate.fetch("outputPath"), candidate.fetch("sha256")] + end + ) + assert( + candidate_results.all? do |candidate| + candidate.fetch("conclusion") == + "inline-license-and-attribution-notice" + end + ) + assert_includes( + result.fetch("remainingReviewItems"), + "review-other-bundled-third-party-license-and-attribution-coverage" + ) + end + def test_rejects_legal_or_redistribution_approval @results["legalReviewApproved"] = true