From 61bab72b541d18dd927a755653becdc036c693f9 Mon Sep 17 00:00:00 2001 From: Jintao Date: Sun, 26 Jul 2026 13:12:53 +0800 Subject: [PATCH] Close OpenSSL notice engineering review --- CHANGELOG.en.md | 9 +-- CHANGELOG.md | 8 +-- Compliance/RootFS/v0.3.3/EVIDENCE.json | 6 +- .../RootFS/v0.3.3/LICENSE-INVENTORY.json | 6 +- .../v0.3.3/LICENSE-NOTICE-CANDIDATES.json | 26 +++++++- .../v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json | 18 +++--- Compliance/RootFS/v0.3.3/NOTICE.md | 8 +-- Compliance/RootFS/v0.3.3/README.md | 63 ++++++++++++++----- Compliance/RootFS/v0.3.3/SHA256SUMS | 10 +-- Docs/ReleaseCompliance.md | 14 ++--- Docs/Roadmap.md | 2 +- Docs/RootFS.md | 12 ++-- Docs/en/ReleaseCompliance.md | 14 ++--- Docs/en/Roadmap.md | 2 +- Docs/en/RootFS.md | 14 ++--- README.md | 2 +- Scripts/rootfs-license-notice-candidates.rb | 2 +- .../rootfs-license-notice-review-results.rb | 2 +- .../RootFSLicenseNoticeCandidatesTests.rb | 2 +- .../RootFSLicenseNoticeReviewResultsTests.rb | 10 +-- 20 files changed, 143 insertions(+), 87 deletions(-) diff --git a/CHANGELOG.en.md b/CHANGELOG.en.md index 29c6c89..c9de28c 100644 --- a/CHANGELOG.en.md +++ b/CHANGELOG.en.md @@ -38,13 +38,14 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit redistribution gates remain closed. - A checksum-bound `LICENSE-NOTICE-CANDIDATES.json`, strict validator, and outside-repository atomic materializer for the eight remaining RootFS source - origins. It indexes 8 remote license/attribution payloads, 46 aports files, + origins. It indexes 10 remote license/attribution payloads, 46 aports files, and the 21 existing evidence files for complete re-verification without committing payloads or opening engineering, legal, or redistribution gates. - `LICENSE-NOTICE-REVIEW-RESULTS.json` and a strict external payload-tree - verifier. All 75 candidate payloads now have checksum-bound engineering - review; `apk-tools` and `pax-utils` have no remaining candidate-material - engineering items, six origins still need package-specific material, and + verifier. All 77 candidate payloads now have checksum-bound engineering + review; `apk-tools`, `openssl`, and `pax-utils` have no remaining + candidate-material engineering items, five origins still need + package-specific material, and legal and redistribution gates remain closed. - Strict external download-cache input for the RootFS source-review materializer. A cache replaces network transport only: inputs remain diff --git a/CHANGELOG.md b/CHANGELOG.md index 3a10824..bd214b0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -35,12 +35,12 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 法律与再分发门禁保持关闭。 - 为剩余 8 个 RootFS source origin 加入 checksum-bound `LICENSE-NOTICE-CANDIDATES.json`、严格验证器和仓库外原子 materializer;索引 - 8 份远端许可证/attribution 材料、46 份 aports 文件与 21 份既有证据,支持完整 + 10 份远端许可证/attribution 材料、46 份 aports 文件与 21 份既有证据,支持完整 复验,但不提交 payload,也不解除工程、法律或再分发门禁。 - 加入 `LICENSE-NOTICE-REVIEW-RESULTS.json` 和严格外置 payload-tree 复验器; - 75/75 个候选 payload 已完成 checksum-bound 工程复核,`apk-tools`、 - `pax-utils` 的候选材料工程项关闭,另外 6 个 origin 仍需补逐包材料,法律和 - 再分发门禁保持关闭。 + 77/77 个候选 payload 已完成 checksum-bound 工程复核,`apk-tools`、 + `openssl`、`pax-utils` 的候选材料工程项关闭,另外 5 个 origin 仍需补逐包 + 材料,法律和再分发门禁保持关闭。 - RootFS source-review materializer 新增严格仓库外下载缓存输入;缓存只替代网络 传输,仍逐项限制大小、拒绝 symlink/重叠路径、核对固定 SHA-512,并重新验证 解包后的 canonical aports tree;v2 receipt 会明确区分网络与缓存获取,不伪造 diff --git a/Compliance/RootFS/v0.3.3/EVIDENCE.json b/Compliance/RootFS/v0.3.3/EVIDENCE.json index c8ff941..845cd4c 100644 --- a/Compliance/RootFS/v0.3.3/EVIDENCE.json +++ b/Compliance/RootFS/v0.3.3/EVIDENCE.json @@ -43,10 +43,10 @@ "engineeringReviewedLicenseCandidates": 21, "sourceOriginsWithRemainingLicenseReviewItems": 8, "indexedLicenseNoticeCandidateOrigins": 8, - "pinnedRemoteLicenseNoticePayloads": 8, + "pinnedRemoteLicenseNoticePayloads": 10, "supplementalAportsCandidateFiles": 46, - "engineeringReviewedLicenseNoticeCandidatePayloads": 75, - "sourceOriginsWithRemainingCandidatePayloadReviewItems": 6 + "engineeringReviewedLicenseNoticeCandidatePayloads": 77, + "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5 }, "engineeringStatus": { "completeInstalledPackageInventory": true, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json index a2d59be..82f7944 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json @@ -31,10 +31,10 @@ "sourceOriginsWithOpenReviewItems": 10, "sourceOriginsWithRemainingReviewItems": 8, "indexedOpenSourceOrigins": 8, - "pinnedRemoteReferencePayloads": 8, + "pinnedRemoteReferencePayloads": 10, "supplementalAportsFiles": 46, - "engineeringReviewedCandidatePayloads": 75, - "sourceOriginsWithRemainingCandidatePayloadReviewItems": 6, + "engineeringReviewedCandidatePayloads": 77, + "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5, "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, "engineeringReviewCompleted": true, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json index 59c2665..cf74eef 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json @@ -106,6 +106,28 @@ "byteCount": 6635, "sha256": "b226dd8531c618ff85a96a185c22c803168afbda1d8e4d8c13552c455b29b044" }, + { + "kind": "package-attribution", + "sourceOrigin": "openssl", + "retrievalURLs": [ + "https://raw.githubusercontent.com/openssl/openssl/01d5e2318405362b4de5e670c90d9b40a351d053/apps/CA.pl.in" + ], + "cacheKey": "openssl-3.1.4-CA.pl.in", + "outputPath": "supplemental/openssl/CA.pl.in", + "byteCount": 8041, + "sha256": "eac0e1059a78f7eb5b17ac90fbc3de5f1345c54dd890674aa36c9b4788b0c92a" + }, + { + "kind": "package-attribution", + "sourceOrigin": "openssl", + "retrievalURLs": [ + "https://raw.githubusercontent.com/openssl/openssl/01d5e2318405362b4de5e670c90d9b40a351d053/apps/tsget.in" + ], + "cacheKey": "openssl-3.1.4-tsget.in", + "outputPath": "supplemental/openssl/tsget.in", + "byteCount": 6778, + "sha256": "36239180730dd8fd7a3c448981a7e71bd5f7a93576865949d865fabee4fc2188" + }, { "kind": "package-attribution", "sourceOrigin": "pax-utils", @@ -309,7 +331,9 @@ "aports/openssl/man-section.patch" ], "remoteEvidencePaths": [ - "supplemental/openssl/README.md" + "supplemental/openssl/README.md", + "supplemental/openssl/CA.pl.in", + "supplemental/openssl/tsget.in" ], "remainingReviewItems": [ "confirm-required-apache-notice-and-attribution-material" diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json index 4ecbc0a..3cb4810 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "candidateManifestSha256": "55e13487c9c0b0ad0160e91c440120b6faa1ef75b0cf467676c67834ca1083cb", + "candidateManifestSha256": "82eb3905dd0314cbced81075d78cf6940833d8908feac87a9d0c4a49f30e1e44", "status": "candidate-payloads-engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allIndexedCandidatePayloadsReviewed": true, @@ -13,10 +13,10 @@ "legalReviewApproved": false, "redistributionApproved": false, "candidatePayloadTreeFormat": "sha256-path-lines-v1", - "candidatePayloadTreeSha256": "a54935ff29aa4f9784a74f26733bd915f8e6750e8487138af3f17a9389b93d30", - "reviewedPayloadFileCount": 75, + "candidatePayloadTreeSha256": "c79e6ac9edad292582e0fca75871a240463870e9384b8048ad674007f23b9aaf", + "reviewedPayloadFileCount": 77, "reviewedClosedOriginEvidenceCount": 4, - "sourceOriginsWithRemainingReviewItems": 6, + "sourceOriginsWithRemainingReviewItems": 5, "sources": [ { "sourceOrigin": "alpine-baselayout", @@ -141,16 +141,16 @@ ], "reviewState": "candidate-payloads-engineering-reviewed-legal-review-open", "licenseTextCoverage": "complete", - "attributionCoverage": "partial", + "attributionCoverage": "complete", "reviewedExistingEvidenceCount": 2, "reviewedReferenceLicenseCount": 1, "reviewedSupplementalAportsCount": 5, - "reviewedRemoteEvidenceCount": 1, - "resolvedReviewItems": [], - "remainingReviewItems": [ + "reviewedRemoteEvidenceCount": 3, + "resolvedReviewItems": [ "confirm-required-apache-notice-and-attribution-material" ], - "engineeringConclusion": "additional-package-material-required" + "remainingReviewItems": [], + "engineeringConclusion": "candidate-material-complete-engineering-only" }, { "sourceOrigin": "pax-utils", diff --git a/Compliance/RootFS/v0.3.3/NOTICE.md b/Compliance/RootFS/v0.3.3/NOTICE.md index 5f48f41..2d68cb4 100644 --- a/Compliance/RootFS/v0.3.3/NOTICE.md +++ b/Compliance/RootFS/v0.3.3/NOTICE.md @@ -43,15 +43,15 @@ for `libc-dev`, `zlib`. 8 source origins still have package-specific open items, so this is not a complete or legally approved license/NOTICE bundle. `LICENSE-NOTICE-CANDIDATES.json` now pins an external candidate bundle for -those open origins: 8 remote +those open origins: 10 remote reference/attribution payloads and 46 supplemental aports files, together with all checksum-bound reviewed evidence. The repository tool can materialize and re-verify that bundle outside the repository. `LICENSE-NOTICE-REVIEW-RESULTS.json` records checksum-bound engineering -review of all 75 indexed -payload files. 2 origins have no remaining -candidate-material engineering items; 6 origins +review of all 77 indexed +payload files. 3 origins have no remaining +candidate-material engineering items; 5 origins still require package-specific material. Legal review and redistribution approval remain open. diff --git a/Compliance/RootFS/v0.3.3/README.md b/Compliance/RootFS/v0.3.3/README.md index 5f84494..ec1b4c0 100644 --- a/Compliance/RootFS/v0.3.3/README.md +++ b/Compliance/RootFS/v0.3.3/README.md @@ -20,11 +20,11 @@ pinned RootFS archive. It does not store the RootFS payload. attribution、声明与内联 notice 的路径、大小、SHA-256 和逐包未决审查项; - `LICENSE-REVIEW-RESULTS.json`:对全部 21 个候选的 checksum-bound 工程复核 结论、coverage 和未决项处置;不表示法律或再分发批准; -- `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 8 份远端 +- `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 10 份远端 许可证/attribution 材料、46 份 aports 补充文件及现有 21 份复核证据的外置候选包; payload 不提交,工程、法律和再分发门禁保持关闭; -- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 75 个 payload 文件树的 - 工程复核结果;2 个 origin 的候选材料工程项关闭,6 个仍需补逐包材料,法律和 +- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 77 个 payload 文件树的 + 工程复核结果;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,法律和 再分发门禁保持关闭; - `RUNTIME-CONFIGURATION.json`:guest、`apk`、repository、world 和 DNS 默认配置; - `NOTICE.md`:可复现 attribution inventory 与尚未完成事项; @@ -39,13 +39,44 @@ manifest, not a committed source archive or redistribution grant. `LICENSE-REVIEW-RESULTS.json` records the engineering review of all 21 pinned candidates. Two source origins have no remaining indexed review items; eight still have package-specific open items. `LICENSE-NOTICE-CANDIDATES.json` -indexes an external candidate bundle for those eight origins: 8 pinned remote +indexes an external candidate bundle for those eight origins: 10 pinned remote license/attribution payloads, 46 supplemental aports files, and the existing 21 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the -engineering review to the exact 75-file payload tree. Two origins have no -remaining candidate-material engineering items; six still require +engineering review to the exact 77-file payload tree. Three origins have no +remaining candidate-material engineering items; five still require package-specific material. Legal and redistribution approval remain open. +OpenSSL 的工程结论绑定固定 `openssl-3.1.4.tar.gz`:源包根目录没有 +`NOTICE` 文件;固定 RootFS 的 APK database 将 guest 路径 +`/etc/ssl/misc/CA.pl` 与 `/etc/ssl/misc/tsget.pl` 归属到 inventory 中的 +`libcrypto3`。归档内 canonical guest-template 文件分别为 8,062 字节、 +SHA-256 `35a85ebe05ac4ee42a0efe544c02ad2c70bf374c4dcd8bf5aaf403b7c1b6cdd8` +和 6,746 字节、SHA-256 +`1c303a261c93d09a04dbb5b4167e93553607a8d06e968bd1cf06325933c147bc`。 +候选包中的 `LICENSE.txt`、`AUTHORS.md`、`README.md`、`CA.pl.in` 和 +`tsget.in` 与固定源包字节一致;两个源码模板的 license/attribution 头部与上述 +生成后的安装文件一致,覆盖 OpenSSL Project、OpenTSA Project 及 Eric A. +Young/Tim J. Hudson 版权归属。因此 +`confirm-required-apache-notice-and-attribution-material` 已在工程层关闭; +这不表示法律审查或再分发批准。 + +The OpenSSL engineering conclusion is bound to the pinned +`openssl-3.1.4.tar.gz`: its source root contains no `NOTICE` file. The pinned +RootFS APK database assigns guest paths `/etc/ssl/misc/CA.pl` and +`/etc/ssl/misc/tsget.pl` to the inventoried `libcrypto3` package. Their +canonical guest-template files are 8,062 bytes with SHA-256 +`35a85ebe05ac4ee42a0efe544c02ad2c70bf374c4dcd8bf5aaf403b7c1b6cdd8` +and 6,746 bytes with SHA-256 +`1c303a261c93d09a04dbb5b4167e93553607a8d06e968bd1cf06325933c147bc`, +respectively. The candidate `LICENSE.txt`, `AUTHORS.md`, `README.md`, +`CA.pl.in`, and `tsget.in` are byte-identical to the pinned source; the two +source-template license/attribution headers match the generated installed +files and cover the OpenSSL Project, OpenTSA Project, and Eric A. Young/Tim J. +Hudson copyright attributions. The +`confirm-required-apache-notice-and-attribution-material` item is therefore +closed at the engineering level only; this is not legal review or +redistribution approval. + ## 重新生成 / Regenerate 先把经授权使用的固定 archive 放在仓库外,再运行: @@ -212,18 +243,18 @@ advice, or redistribution approval. 这些文件不构成完整第三方 LICENSE/NOTICE bundle、经审查的 copyleft corresponding-source 交付、法律意见或再分发授权。源码获取清单已完整覆盖固定 inventory,21 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 -8 个 source origin 的 75 个新候选 payload 已完成 checksum-bound 工程复核; -`apk-tools`、`pax-utils` 的候选材料工程项已关闭,另外 6 个 origin 仍需补逐包 -版权/notice 材料。修改说明、构建完整性、源码提供方式、法律审查、App Store -2.5.2 产品策略和负责人批准仍是发行阻塞项。 +8 个 source origin 的 77 个新候选 payload 已完成 checksum-bound 工程复核; +`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 +origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、源码提供方式、法律 +审查、App Store 2.5.2 产品策略和负责人批准仍是发行阻塞项。 These files are not a complete third-party LICENSE/NOTICE bundle, reviewed copyleft corresponding-source delivery, legal advice, or redistribution approval. The acquisition manifest completely covers the pinned inventory and all 21 indexed candidates have engineering review results. `libc-dev` and -`zlib` have no remaining indexed items. All 75 newly indexed payloads have a -checksum-bound engineering review; `apk-tools` and `pax-utils` have no -remaining candidate-material engineering items, while six origins still need -package-specific copyright/notice material. Modification, build completeness, -source-offer mechanics, legal review, App Store 2.5.2 product policy, and -authorized approval remain distribution blockers. +`zlib` have no remaining indexed items. All 77 newly indexed payloads have a +checksum-bound engineering review; `apk-tools`, `openssl`, and `pax-utils` +have no remaining candidate-material engineering items, while five origins +still need package-specific copyright/notice material. Modification, build +completeness, source-offer mechanics, legal review, App Store 2.5.2 product +policy, and authorized approval remain distribution blockers. diff --git a/Compliance/RootFS/v0.3.3/SHA256SUMS b/Compliance/RootFS/v0.3.3/SHA256SUMS index 20fad9f..df136d5 100644 --- a/Compliance/RootFS/v0.3.3/SHA256SUMS +++ b/Compliance/RootFS/v0.3.3/SHA256SUMS @@ -1,10 +1,10 @@ -69fc3496bb4832d109942f72e81009a4d1774d459f372422263903802c5d3019 EVIDENCE.json -c12f1bf7d6a83b8e4e549dee0cafe28162d9b7f0ab210af5370503fe72f195ec LICENSE-INVENTORY.json -55e13487c9c0b0ad0160e91c440120b6faa1ef75b0cf467676c67834ca1083cb LICENSE-NOTICE-CANDIDATES.json -faee5c5c91c7be648ff7772c69167be3056bbb3501e52a7057d208d8fbfa621c LICENSE-NOTICE-REVIEW-RESULTS.json +47e96d72ae690bf941bdf05bdc0eb9b1fb8f24e320d927109a6c3425d51abe7a EVIDENCE.json +2fa98989f7725bed0e82db2f5350d74893b732395227974d77a9ca55147da842 LICENSE-INVENTORY.json +82eb3905dd0314cbced81075d78cf6940833d8908feac87a9d0c4a49f30e1e44 LICENSE-NOTICE-CANDIDATES.json +0ae4a280c5c418bd54b00ae9e7a2dec16122d2d0cf61b34fd1e338598600cdfc LICENSE-NOTICE-REVIEW-RESULTS.json 3c7f786d9551d716c2a8b374d8cc63d11a46d67827be2fa0cea73b51b6b92eda LICENSE-REVIEW-RESULTS.json 3d483714a09cb2194e1b4af9aef5dfec2fbcfd44c70d521899398a3893f1908a LICENSE-REVIEW.json -39dff7ed584e32bb46559d29ffcff7cef4dc88278de1957383616fd412732a64 NOTICE.md +b0fd80c51c7276c65d4122e65c628f2ef3cb67a5170fb6577f5399a93c848938 NOTICE.md 4f7f7626f3d0891a29717e4b7932c36004ecc9aac25a4aa104c300aae979e3e1 PACKAGE-INVENTORY.tsv dbca9b285015a0d8b1d339a894b4594c9e335cbc2d7f9d5212a41095ae4bd1e1 RUNTIME-CONFIGURATION.json 8e021cb8c4160c934a0202609691d7a94526cd016f4394a47da6e7a5ab41d0ea SBOM.spdx.json diff --git a/Docs/ReleaseCompliance.md b/Docs/ReleaseCompliance.md index b3713b0..43d4867 100644 --- a/Docs/ReleaseCompliance.md +++ b/Docs/ReleaseCompliance.md @@ -75,12 +75,12 @@ aports snapshot/upstream distfile 获取清单和仓库外 materializer,并固 全部 10 个 source origin 的 21 个 license、attribution、声明与内联 notice 候选。 第二个仓库外工具从已验证 source-review 目录提取这些候选;固定结果清单记录 21/21 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source -origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:8 份远端 +origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:10 份远端 许可证/attribution 材料、46 份 aports 补充文件和全部既有复核证据;工具可在 -仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 75 文件 payload -tree;`apk-tools`、`pax-utils` 的候选材料工程项已关闭,另外 6 个 origin 仍需 -补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成,不能视为完整 -NOTICE 或已批准的对应源码交付。 +仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 77 文件 payload +tree;`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 +origin 仍需补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成, +不能视为完整 NOTICE 或已批准的对应源码交付。 ## 当前仓库保护 @@ -179,8 +179,8 @@ Alpine `apk` 可以下载、安装和执行新增代码。即使初始 RootFS - [x] 对固定的 21 个 license/NOTICE 候选完成 checksum-bound 工程复核。 - [x] 为剩余 8 个 source origin 建立 checksum-bound 外置候选包索引与可复验 materializer;payload 不提交且批准门禁保持关闭。 -- [x] 对外置候选包的 75 个 payload 完成 checksum-bound 工程复核并固定结果; - 2 个 origin 的候选材料工程项关闭,6 个仍需补逐包材料。 +- [x] 对外置候选包的 77 个 payload 完成 checksum-bound 工程复核并固定结果; + 3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料。 - [ ] 收集 license text 和 NOTICE。 - [ ] 建立 copyleft corresponding source bundle。 - [x] 固定 DNS、repository 和 package-manager 默认配置事实。 diff --git a/Docs/Roadmap.md b/Docs/Roadmap.md index 72a3d43..fbb4505 100644 --- a/Docs/Roadmap.md +++ b/Docs/Roadmap.md @@ -103,7 +103,7 @@ | 最低 Xcode 16 原生兼容 | 已通过 | Xcode 16.0 / iOS 18.0 SDK 完成 RootFS install、Simulator/device final-link 和 17 项 native smoke | | App lifecycle 与内存 | 进行中 | Simulator 与 Jack iPhone 均有 256 MiB `ru_maxrss` 门禁;真机 process suspend/resume、UIKit foreground/background、强制终止后数据恢复和有界 App delegate memory-warning 回调恢复已通过;补真实 memory pressure/jetsam | | RootFS ENOSPC/掉电 | 进行中 | 峰值空间预检、全 ENOSPC、七点持久化屏障、确定性掉电切点和 Jack iPhone 受限容量/ENOSPC 清理恢复已覆盖;补真实 storage pressure/强制断电 | -| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、21/21 初始候选和 75/75 外置 payload 工程复核已完成;2 个 origin 的候选材料工程项关闭,6 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | +| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、21/21 初始候选和 77/77 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | | App Store 2.5.2 | 阻塞 | guest download/execute policy 有书面结论 | ### 后续 runtime 执行顺序 diff --git a/Docs/RootFS.md b/Docs/RootFS.md index fd883e8..a5710c0 100644 --- a/Docs/RootFS.md +++ b/Docs/RootFS.md @@ -5,7 +5,7 @@ RootFS 是 PocketRoot 的外部供应链输入,不是普通测试 fixture。仓库提交的是不可变清单、校验和安全安装代码,不提交、镜像或默认打包 RootFS 二进制。 > [!WARNING] -> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 21 个初始候选和 75 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;2 个 origin 的候选材料工程项已关闭,6 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 +> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 21 个初始候选和 77 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 ## 1. 固定清单 @@ -143,7 +143,7 @@ SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单 工程复核,其中 `libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有 未决项;输出不能直接视为完整 NOTICE 或对应源码交付材料。 -剩余 8 个 origin 的外置 LICENSE/NOTICE 候选包清单还固定了 8 份远端许可证/ +剩余 8 个 origin 的外置 LICENSE/NOTICE 候选包清单还固定了 10 份远端许可证/ attribution 材料与 46 份 aports 补充文件。清单可独立校验;实际物化和复验必须 同时提供上面已经验证的两个仓库外目录: @@ -167,10 +167,10 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ ``` 工具对远端材料强制 HTTPS、重定向次数、响应大小、固定字节数与 SHA-256,并原子 -创建输出。结果清单把工程复核绑定到精确的 75 文件 payload tree;复验器拒绝路径 -漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools` 与 -`pax-utils` 的候选材料工程项已关闭,另外 6 个 origin 仍需补逐包材料;候选 NOTICE -和 receipt 不代表法律审查或发行批准。 +创建输出。结果清单把工程复核绑定到精确的 77 文件 payload tree;复验器拒绝路径 +漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools`、 +`openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包 +材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 不要把归档放入 `Sources/PocketRootResources/Resources`、Demo resources 或 Git LFS。合规完成前,`PocketRootBundledRootFSProvider` 的资源查找预期返回 `nil`。 diff --git a/Docs/en/ReleaseCompliance.md b/Docs/en/ReleaseCompliance.md index 6b9da2c..5251d2a 100644 --- a/Docs/en/ReleaseCompliance.md +++ b/Docs/en/ReleaseCompliance.md @@ -41,12 +41,12 @@ declaration, and inline-notice candidates across all 10 source origins. A pinned result manifest records engineering review of all 21 candidates. `libc-dev` and `zlib` have no remaining indexed items; eight source origins still have package-level follow-up. The repository now pins an external -candidate bundle for those origins: 8 remote license/attribution payloads, +candidate bundle for those origins: 10 remote license/attribution payloads, 46 supplemental aports files, and all existing reviewed evidence. The tool can atomically materialize and re-verify it outside the repository. A pinned -results manifest binds engineering review to the exact 75-file payload tree. -`apk-tools` and `pax-utils` have no remaining candidate-material engineering -items; six origins still need package-specific material. Modification, +results manifest binds engineering review to the exact 77-file payload tree. +`apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material +engineering items; five origins still need package-specific material. Modification, build-completeness, source-offer, and legal reviews remain unresolved, so the output is neither a complete NOTICE set nor approved corresponding-source delivery. @@ -122,9 +122,9 @@ The current code does not provide a complete product-level privacy policy. - [x] Index a checksum-bound external candidate bundle and reproducible materializer for the eight remaining origins; payloads stay uncommitted and approval gates stay closed. -- [x] Complete checksum-bound engineering review of all 75 external candidate - payloads; two origins have no remaining candidate-material engineering items - and six still need package-specific material. +- [x] Complete checksum-bound engineering review of all 77 external candidate + payloads; three origins have no remaining candidate-material engineering + items and five still need package-specific material. - [ ] Collect license texts and NOTICE files. - [ ] Establish a corresponding-source bundle for copyleft components. - [x] Record default DNS, repository, and package-manager facts. diff --git a/Docs/en/Roadmap.md b/Docs/en/Roadmap.md index 6b7da72..1f114ca 100644 --- a/Docs/en/Roadmap.md +++ b/Docs/en/Roadmap.md @@ -98,7 +98,7 @@ This establishes the current Simulator, minimum-Xcode 16, and single-iPhone one- | Minimum Xcode 16 native | Passed | Xcode 16.0 / iOS 18.0 SDK completed RootFS install, Simulator/device final links, and the 17-check native smoke | | App lifecycle and memory | In progress | Simulator and Jack iPhone have 256 MiB `ru_maxrss` gates; physical process suspend/resume, UIKit foreground/background, post-termination data recovery, and bounded App-delegate memory-warning recovery passed; add real memory-pressure/jetsam evidence | | RootFS ENOSPC/power faults | In progress | Peak-space preflight, full ENOSPC, seven persistence barriers, deterministic power-loss cuts, and bounded capacity/ENOSPC cleanup recovery on Jack iPhone are covered; add real storage-pressure/power-cut evidence | -| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 21 initial candidates, and all 75 external payloads have checksum-bound engineering review; two origins have no remaining candidate-material engineering items, six still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | +| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 21 initial candidates, and all 77 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | | App Store 2.5.2 | Blocked | Written guest download/execute policy decision | ### Next runtime sequence diff --git a/Docs/en/RootFS.md b/Docs/en/RootFS.md index 33d6c24..8316183 100644 --- a/Docs/en/RootFS.md +++ b/Docs/en/RootFS.md @@ -5,7 +5,7 @@ A RootFS is an external supply-chain input, not a normal fixture. PocketRoot commits immutable metadata and secure install code, not the payload. > [!WARNING] -> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 21 initial candidates and all 75 external LICENSE/NOTICE payloads. Two origins have no remaining candidate-material engineering items; six still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. +> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 21 initial candidates and all 77 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. ## Pinned manifest @@ -127,7 +127,7 @@ eight source origins still require follow-up. The output is not a completed NOTICE or corresponding-source delivery bundle. The external LICENSE/NOTICE candidate manifest for those eight origins also -pins 8 remote license/attribution payloads and 46 supplemental aports files. +pins 10 remote license/attribution payloads and 46 supplemental aports files. Validate it independently, or materialize and re-verify it using both external directories verified above: @@ -152,11 +152,11 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ The tool enforces HTTPS, redirect and response-size bounds, pinned byte counts and SHA-256 digests, and atomic output creation. The results bind engineering -review to the exact 75-file payload tree; the verifier rejects path drift, -links, special nodes, known-digest drift, and tree-digest drift. `apk-tools` -and `pax-utils` have no remaining candidate-material engineering items; six -origins still need package-specific material. The candidate NOTICE and receipt -do not represent legal review or distribution approval. +review to the exact 77-file payload tree; the verifier rejects path drift, +links, special nodes, known-digest drift, and tree-digest drift. `apk-tools`, +`openssl`, and `pax-utils` have no remaining candidate-material engineering +items; five origins still need package-specific material. The candidate NOTICE +and receipt do not represent legal review or distribution approval. Do not put it in package resources, Demo resources, Git, or Git LFS. diff --git a/README.md b/README.md index e6e7e79..be4e6a6 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ print("stderr:", result.stderr) - 展开大小:`18,838,016` 字节 - SHA-256:`be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4` -固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 21 个初始候选及 75 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;6 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 +固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 21 个初始候选及 77 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 ## 验证命令 diff --git a/Scripts/rootfs-license-notice-candidates.rb b/Scripts/rootfs-license-notice-candidates.rb index b4674d2..5b1db37 100644 --- a/Scripts/rootfs-license-notice-candidates.rb +++ b/Scripts/rootfs-license-notice-candidates.rb @@ -21,7 +21,7 @@ module RootFSLicenseNoticeCandidates openssl pax-utils ].freeze EXPECTED_EXISTING_EVIDENCE_FILES = 21 - EXPECTED_REMOTE_PAYLOAD_FILES = 8 + EXPECTED_REMOTE_PAYLOAD_FILES = 10 EXPECTED_APORTS_FILES = 46 PAYLOAD_KINDS = %w[package-attribution spdx-license-text].freeze TOP_LEVEL_KEYS = %w[ diff --git a/Scripts/rootfs-license-notice-review-results.rb b/Scripts/rootfs-license-notice-review-results.rb index 8ebd0de..7feae3c 100644 --- a/Scripts/rootfs-license-notice-review-results.rb +++ b/Scripts/rootfs-license-notice-review-results.rb @@ -22,7 +22,7 @@ module RootFSLicenseNoticeReviewResults COVERAGE = %w[complete partial reference-only].freeze SHA256_PATTERN = /\A[0-9a-f]{64}\z/ CANDIDATE_PAYLOAD_TREE_FORMAT = "sha256-path-lines-v1" - EXPECTED_REVIEWED_PAYLOAD_FILES = 75 + EXPECTED_REVIEWED_PAYLOAD_FILES = 77 MAX_REVIEWED_PAYLOAD_BYTES = 8 * 1_024 * 1_024 TOP_LEVEL_KEYS = %w[ allIndexedCandidatePayloadsReviewed archive candidateManifestSha256 diff --git a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb index 30e5654..09e7c50 100644 --- a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb @@ -28,7 +28,7 @@ def test_validates_complete_open_origin_candidate_index validated = validate assert_equal 8, validated.fetch(:sources).length - assert_equal 8, validated.fetch(:remote_payloads).length + assert_equal 10, validated.fetch(:remote_payloads).length assert_equal 21, validated.fetch(:existing_evidence_paths).length assert_equal 46, validated.fetch(:aports_paths).length end diff --git a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb index 4042ac8..5e3d1cb 100644 --- a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb @@ -45,12 +45,12 @@ def test_validates_pinned_candidate_review_results validated = validate assert_equal 8, validated.fetch(:sources).length - assert_equal 8, validated.fetch(:remote_payloads).length + assert_equal 10, validated.fetch(:remote_payloads).length assert_equal 46, validated.fetch(:aports_paths).length - assert_equal 75, @results.fetch("reviewedPayloadFileCount") - assert_equal 6, + assert_equal 77, @results.fetch("reviewedPayloadFileCount") + assert_equal 5, @results.fetch("sourceOriginsWithRemainingReviewItems") - assert_equal %w[apk-tools pax-utils], + assert_equal %w[apk-tools openssl pax-utils], @results.fetch("sources") .select { |source| source.fetch("remainingReviewItems").empty? } .map { |source| source.fetch("sourceOrigin") } @@ -98,7 +98,7 @@ def test_rejects_conclusion_that_does_not_match_open_items end def test_rejects_payload_count_drift - @results["reviewedPayloadFileCount"] = 74 + @results["reviewedPayloadFileCount"] = 76 error = assert_raises( RootFSLicenseNoticeReviewResults::ValidationError