Files
ESP32_Serial_Swiss_Army_Knife/third_party/release-notices/README.md
T
Commander1024 cdc4d4a8df Add Phase 9 validation and advisory review
Record the finite dependency search, Wi-Fi maintenance blocker, and
pinned
icon provenance. Add bounded host orchestration and fixture coverage,
and
update release documentation with current evidence.
2026-09-16 16:26:46 +02:00

7.3 KiB
Raw Blame History

Scoped release notice inputs and unresolved obligations

Reviewed local notice snapshot: 2026-09-16. This is engineering evidence, not legal advice, legal clearance, a complete SBOM, or corresponding source. The bundle preserves separate files, not a single inferred umbrella license.

Provenance and scope

inputs.json is the explicit, reviewed input policy for tools/release_notices.py. It records logical root/path, full-file size and SHA-256, optional zero-based half-open byte range, output SHA-256, and purpose. A null range means the entire original file is retained. Ranges select opening source notice comments verbatim, not source implementations. Even excerpts require the exact hash of the whole installed source file. Absolute machine paths, collection time, build artifacts and configuration are omitted. The manifest in each successful bundle repeats this evidence and identifies the catalog by hash. The catalog is trusted project policy, not a signed SBOM.

Roots identify the project checkout, installed ESP-IDF package, and installed Xtensa toolchain. Managed manifests and package metadata are retained as provenance, not as substitutes for licenses. Hashes identify the reviewed local bytes; they do not authenticate upstream authorship or validate all package contents. Versions: ESP-IDF 5.5.0 / package 3.50500.0, Xtensa package 14.2.0+20241119, esp_tinyusb 2.2.1, led_strip 3.0.3, mDNS 1.12.0, TinyUSB 0.21.01, wolfSSL 5.8.21, wolfSSH 1.4.20.

The scoped inventory covers the six managed packages, the SDK/runtime groups in docs/dependency_licenses.md, two xterm packages, and the two verified icon SVG sources with pinned upstream metadata and full Apache-2.0 text. It retains configured-but-not-observed-linked groups too; inclusion is not a claim that each contributes to a release image. Full SDK/toolchain redistribution needs a broader review, including nested/test/tool licenses. No recursive license discovery is performed by the tool. Newly added files or NOTICEs outside the explicit list are not detected: review the catalog again when dependencies, selected objects, or distribution scope change.

Grants and evidence that must not be collapsed

  • Project: GPL-3.0-only; dependencies retain their own grants.
  • wolfSSL: preserve package LICENSE and README; GPLv3 option selected here.
  • wolfSSH packaging discrepancy remains unresolved: installed LICENSE and README describe wolfSSL/wolfCrypt and GPLv2-or-later; wolfSSH source headers explicitly grant GPL-3.0-or-later. Both evidence sets are included unchanged. GPLv3 is selected for this integration, not GPL-2.0-only. Seek upstream packaging clarification; this bundle does not silently repair vendor files.
  • Mbed TLS: preserve the whole dual-license document (Apache-2.0 OR GPL-2.0-or-later); Apache-2.0 is the selection for this integration.
  • Preserve all argtable3 aggregate notices and both SDK and toolchain Newlib texts. Neither aggregate is reduced to one guessed SPDX label.
  • GCC: preserve GPLv3 and the actual GCC Runtime Library Exception 3.1; COPYING3.LIB is not a substitute. Eligibility/per-object review remains.
  • wpa_supplicant: retain COPYING and README containing the full BSD grant; COPYING's historical GPL option discussion is not a current GPLv2-only grant.
  • Xtensa HAL and FatFs: retain complete opening permission/disclaimer comments.
  • TinyUSB's nested Espressif LED-strip license is retained separately; it is not a seventh managed package.

TLSF full-text assembly

TLSF-BSD-3-Clause.txt is a project-assembled rendering, not a claimed verbatim upstream LICENSE. Copyright holder and years come from the installed IDF 5.5.0 files components/heap/tlsf/include/tlsf.h and components/heap/tlsf/tlsf_block_functions.h: both identify 20062016 Matthew Conte and BSD-3-Clause. The three conditions and disclaimer render that SPDX license, with this holder, rather than another project's copyright. The original SPDX comments are retained as separately hash-pinned excerpts; components/heap/tlsf/README.md also records the 2016 switch to BSD. No new license grant or independent upstream authentication is claimed by assembly.

Icons and browser notices

The existing Pictogrammers summary is retained unchanged. Both retained SVGs are byte-identical to official @mdi/svg 7.4.47 sources at commit 9e04201d4557e729822fb57f62a316c3dea1d4a8. The bundle now includes those SVGs, unmodified upstream originals/license/package metadata, full author metadata, unsigned tag and complete tree evidence, separately fetched full Apache-2.0 text, and inputs/project/docs/icon_provenance.md. Metadata credits USB to Google and Wi-Fi to Simran; the package declares Apache-2.0. No NOTICE-named path occurs in the pinned non-truncated distribution tree; none is invented.

See the included provenance record for exact coordinates and mockup transforms. The USB mockup path matches; its Wi-Fi path differs. Firmware masks remain manual adaptations with no verified exact rasterization recipe. Identity of the preferred SVG sources is resolved, not the historical/mechanical derivation of every adaptation. No existing icon, firmware or web asset was changed or regenerated. Full license text alone is not provenance or release clearance.

Both xterm MIT notices and web_assets/SOURCES.md are retained. This does not embed or serve notices in browser responses, authenticate preferred sources, or independently establish project-logo authorship. Arrange and verify actual firmware/device/browser recipient notice delivery; Git presence alone is not proof of delivery.

Remaining release gates — bundle success does not close these

  1. Radio blobs: establish required corresponding source or a defensible System Library/other exception for actual linked content. The three local Apache radio license files permit redistribution on their terms; they do not settle GPL corresponding-source compatibility. No clearance or blanket prohibition is asserted.
  2. Review final application and bootloader maps, runtime objects, ROM, mixed/aggregate and nested package attributions. The catalog is bounded, not an exhaustive selected-object audit or all-upstream-NOTICE inventory.
  3. Deliver exact preferred corresponding source through an appropriate GPLv3 method. Include application and required dependency sources, safe build inputs, editable generators/patches, original hash-matching overlay inputs, tools/security_overrides.py, cmake/security_overrides.cmake, root CMake integration, cmake/wolf_crypto_policy.{cmake,h}, and all tools/wolfssh_order/ delta/patch/provenance inputs. Retain upstream grants and generated modification/date notices (2026-09-15 baseline and 2026-09-16 wolfSSH ordering). There are eight generated C sources and one PUBLIC forced header. This notice tool does not package those sources.
  4. Supply required asset preferred sources/build inputs, assess User Product Installation Information, and validate recipient access and source offers. Do not publish keys, passwords, Wi-Fi secrets, tickets, verifiers, NVS/flash images, credential backups, or secret-bearing build configurations.
  5. Resolve wolfSSH packaging and the remaining manual-derivative provenance limits above. Do not use a successful hash check as legal sign-off or whole-Phase-9 acceptance.