Record the finite dependency search, Wi-Fi maintenance blocker, and pinned icon provenance. Add bounded host orchestration and fixture coverage, and update release documentation with current evidence.
Scoped release notice inputs and unresolved obligations
Reviewed local notice snapshot: 2026-09-16. This is engineering evidence, not legal advice, legal clearance, a complete SBOM, or corresponding source. The bundle preserves separate files, not a single inferred umbrella license.
Provenance and scope
inputs.json is the explicit, reviewed input policy for
tools/release_notices.py. It records logical root/path, full-file size and
SHA-256, optional zero-based half-open byte range, output SHA-256, and purpose.
A null range means the entire original file is retained. Ranges select
opening source notice comments verbatim, not source implementations. Even
excerpts require the exact hash of the whole installed source file. Absolute
machine paths, collection time, build artifacts and configuration are omitted.
The manifest in each successful bundle repeats this evidence and identifies
the catalog by hash. The catalog is trusted project policy, not a signed SBOM.
Roots identify the project checkout, installed ESP-IDF package, and installed
Xtensa toolchain. Managed manifests and package metadata are retained as
provenance, not as substitutes for licenses. Hashes identify the reviewed local
bytes; they do not authenticate upstream authorship or validate all package
contents. Versions: ESP-IDF 5.5.0 / package 3.50500.0, Xtensa package
14.2.0+20241119, esp_tinyusb 2.2.1, led_strip 3.0.3, mDNS 1.12.0,
TinyUSB 0.21.01, wolfSSL 5.8.21, wolfSSH 1.4.20.
The scoped inventory covers the six managed packages, the SDK/runtime groups
in docs/dependency_licenses.md, two xterm packages, and the two verified icon
SVG sources with pinned upstream metadata and full Apache-2.0 text. It retains configured-but-not-observed-linked groups too; inclusion
is not a claim that each contributes to a release image. Full SDK/toolchain
redistribution needs a broader review, including nested/test/tool licenses.
No recursive license discovery is performed by the tool. Newly added files or
NOTICEs outside the explicit list are not detected: review the catalog again
when dependencies, selected objects, or distribution scope change.
Grants and evidence that must not be collapsed
- Project: GPL-3.0-only; dependencies retain their own grants.
- wolfSSL: preserve package LICENSE and README; GPLv3 option selected here.
- wolfSSH packaging discrepancy remains unresolved: installed LICENSE and README describe wolfSSL/wolfCrypt and GPLv2-or-later; wolfSSH source headers explicitly grant GPL-3.0-or-later. Both evidence sets are included unchanged. GPLv3 is selected for this integration, not GPL-2.0-only. Seek upstream packaging clarification; this bundle does not silently repair vendor files.
- Mbed TLS: preserve the whole dual-license document (Apache-2.0 OR GPL-2.0-or-later); Apache-2.0 is the selection for this integration.
- Preserve all argtable3 aggregate notices and both SDK and toolchain Newlib texts. Neither aggregate is reduced to one guessed SPDX label.
- GCC: preserve GPLv3 and the actual GCC Runtime Library Exception 3.1; COPYING3.LIB is not a substitute. Eligibility/per-object review remains.
- wpa_supplicant: retain COPYING and README containing the full BSD grant; COPYING's historical GPL option discussion is not a current GPLv2-only grant.
- Xtensa HAL and FatFs: retain complete opening permission/disclaimer comments.
- TinyUSB's nested Espressif LED-strip license is retained separately; it is not a seventh managed package.
TLSF full-text assembly
TLSF-BSD-3-Clause.txt is a project-assembled rendering, not a claimed
verbatim upstream LICENSE. Copyright holder and years come from the installed
IDF 5.5.0 files components/heap/tlsf/include/tlsf.h and
components/heap/tlsf/tlsf_block_functions.h: both identify 2006–2016 Matthew
Conte and BSD-3-Clause. The three conditions and disclaimer render that
SPDX license, with this holder, rather than another project's copyright.
The original SPDX comments are retained as separately hash-pinned excerpts;
components/heap/tlsf/README.md also records the 2016 switch to BSD. No new
license grant or independent upstream authentication is claimed by assembly.
Icons and browser notices
The existing Pictogrammers summary is retained unchanged. Both retained SVGs
are byte-identical to official @mdi/svg 7.4.47 sources at commit
9e04201d4557e729822fb57f62a316c3dea1d4a8. The bundle now includes those SVGs,
unmodified upstream originals/license/package metadata, full author metadata,
unsigned tag and complete tree evidence, separately fetched full Apache-2.0
text, and inputs/project/docs/icon_provenance.md. Metadata credits USB to
Google and Wi-Fi to Simran; the package declares Apache-2.0. No NOTICE-named
path occurs in the pinned non-truncated distribution tree; none is invented.
See the included provenance record for exact coordinates and mockup transforms. The USB mockup path matches; its Wi-Fi path differs. Firmware masks remain manual adaptations with no verified exact rasterization recipe. Identity of the preferred SVG sources is resolved, not the historical/mechanical derivation of every adaptation. No existing icon, firmware or web asset was changed or regenerated. Full license text alone is not provenance or release clearance.
Both xterm MIT notices and web_assets/SOURCES.md are retained. This does not
embed or serve notices in browser responses, authenticate preferred sources,
or independently establish project-logo authorship. Arrange and verify actual
firmware/device/browser recipient notice delivery; Git presence alone is not
proof of delivery.
Remaining release gates — bundle success does not close these
- Radio blobs: establish required corresponding source or a defensible System Library/other exception for actual linked content. The three local Apache radio license files permit redistribution on their terms; they do not settle GPL corresponding-source compatibility. No clearance or blanket prohibition is asserted.
- Review final application and bootloader maps, runtime objects, ROM, mixed/aggregate and nested package attributions. The catalog is bounded, not an exhaustive selected-object audit or all-upstream-NOTICE inventory.
- Deliver exact preferred corresponding source through an appropriate GPLv3
method. Include application and required dependency sources, safe build
inputs, editable generators/patches, original hash-matching overlay inputs,
tools/security_overrides.py,cmake/security_overrides.cmake, root CMake integration,cmake/wolf_crypto_policy.{cmake,h}, and alltools/wolfssh_order/delta/patch/provenance inputs. Retain upstream grants and generated modification/date notices (2026-09-15 baseline and 2026-09-16 wolfSSH ordering). There are eight generated C sources and one PUBLIC forced header. This notice tool does not package those sources. - Supply required asset preferred sources/build inputs, assess User Product Installation Information, and validate recipient access and source offers. Do not publish keys, passwords, Wi-Fi secrets, tickets, verifiers, NVS/flash images, credential backups, or secret-bearing build configurations.
- Resolve wolfSSH packaging and the remaining manual-derivative provenance limits above. Do not use a successful hash check as legal sign-off or whole-Phase-9 acceptance.