Add Phase 9 validation and advisory review

Record the finite dependency search, Wi-Fi maintenance blocker, and
pinned
icon provenance. Add bounded host orchestration and fixture coverage,
and
update release documentation with current evidence.
This commit is contained in:
2026-09-16 16:26:46 +02:00
parent 51f835c22f
commit cdc4d4a8df
31 changed files with 1748 additions and 45 deletions
+19 -10
View File
@@ -25,8 +25,8 @@ contents. Versions: ESP-IDF 5.5.0 / package 3.50500.0, Xtensa package
TinyUSB 0.21.0~1, wolfSSL 5.8.2~1, wolfSSH 1.4.20.
The scoped inventory covers the six managed packages, the SDK/runtime groups
in `docs/dependency_licenses.md`, two xterm packages, and the recorded icon
summary. It retains configured-but-not-observed-linked groups too; inclusion
in `docs/dependency_licenses.md`, two xterm packages, and the two verified icon
SVG sources with pinned upstream metadata and full Apache-2.0 text. It retains configured-but-not-observed-linked groups too; inclusion
is not a claim that each contributes to a release image. Full SDK/toolchain
redistribution needs a broader review, including nested/test/tool licenses.
No recursive license discovery is performed by the tool. Newly added files or
@@ -68,13 +68,21 @@ license grant or independent upstream authentication is claimed by assembly.
## Icons and browser notices
The existing Pictogrammers summary is retained unchanged. Full Apache-2.0 text
is supplied as `inputs/sdk/LICENSE`, the exact installed SDK copy; this is
license text, **not proof of the individual icons' provenance or grant**.
The project records Material Design Icons 7.4.47 and adapted USB/Wi-Fi masks.
Exact two-icon origin/version/licensing and any applicable upstream NOTICE
still need verification before distribution. No icon or web asset was changed
or regenerated, and no upstream icon provenance was authenticated here.
The existing Pictogrammers summary is retained unchanged. Both retained SVGs
are byte-identical to official `@mdi/svg` 7.4.47 sources at commit
`9e04201d4557e729822fb57f62a316c3dea1d4a8`. The bundle now includes those SVGs,
unmodified upstream originals/license/package metadata, full author metadata,
unsigned tag and complete tree evidence, separately fetched full Apache-2.0
text, and `inputs/project/docs/icon_provenance.md`. Metadata credits USB to
Google and Wi-Fi to Simran; the package declares Apache-2.0. No NOTICE-named
path occurs in the pinned non-truncated distribution tree; none is invented.
See the included provenance record for exact coordinates and mockup transforms.
The USB mockup path matches; its Wi-Fi path differs. Firmware masks remain
manual adaptations with **no verified exact rasterization recipe**. Identity of
the preferred SVG sources is resolved, not the historical/mechanical derivation
of every adaptation. No existing icon, firmware or web asset was changed or
regenerated. Full license text alone is not provenance or release clearance.
Both xterm MIT notices and `web_assets/SOURCES.md` are retained. This does not
embed or serve notices in browser responses, authenticate preferred sources,
@@ -105,5 +113,6 @@ proof of delivery.
Installation Information, and validate recipient access and source offers.
Do not publish keys, passwords, Wi-Fi secrets, tickets, verifiers, NVS/flash
images, credential backups, or secret-bearing build configurations.
5. Resolve wolfSSH packaging and icon provenance questions above. Do not use a
5. Resolve wolfSSH packaging and the remaining manual-derivative provenance
limits above. Do not use a
successful hash check as legal sign-off or whole-Phase-9 acceptance.