From 04329839866cdb8937b6cac542d454464118e988 Mon Sep 17 00:00:00 2001 From: Jintao Date: Sun, 26 Jul 2026 15:20:20 +0800 Subject: [PATCH] Pin ca-certificates curl license provenance --- CHANGELOG.en.md | 9 ++-- CHANGELOG.md | 6 ++- Compliance/RootFS/v0.3.3/EVIDENCE.json | 4 +- .../RootFS/v0.3.3/LICENSE-INVENTORY.json | 4 +- .../v0.3.3/LICENSE-NOTICE-CANDIDATES.json | 27 +++++++++++- .../v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json | 8 ++-- Compliance/RootFS/v0.3.3/NOTICE.md | 4 +- Compliance/RootFS/v0.3.3/README.md | 39 +++++++++++++++--- Compliance/RootFS/v0.3.3/SHA256SUMS | 10 ++--- Docs/ReleaseCompliance.md | 6 +-- Docs/Roadmap.md | 2 +- Docs/RootFS.md | 6 +-- Docs/en/ReleaseCompliance.md | 6 +-- Docs/en/Roadmap.md | 2 +- Docs/en/RootFS.md | 6 +-- README.md | 2 +- Scripts/rootfs-license-notice-candidates.rb | 2 +- .../rootfs-license-notice-review-results.rb | 2 +- .../RootFSLicenseNoticeCandidatesTests.rb | 41 ++++++++++++++++++- .../RootFSLicenseNoticeReviewResultsTests.rb | 26 +++++++++++- 20 files changed, 165 insertions(+), 47 deletions(-) diff --git a/CHANGELOG.en.md b/CHANGELOG.en.md index 4c938dd..d0ddced 100644 --- a/CHANGELOG.en.md +++ b/CHANGELOG.en.md @@ -38,13 +38,16 @@ All notable PocketRoot changes are recorded here. Semantic Versioning begins wit redistribution gates remain closed. - A checksum-bound `LICENSE-NOTICE-CANDIDATES.json`, strict validator, and outside-repository atomic materializer for the eight remaining RootFS source - origins. It indexes 11 remote license/attribution payloads, 46 aports files, + origins. It indexes 13 remote license/attribution payloads, 46 aports files, and the 21 existing evidence files for complete re-verification without committing payloads or opening engineering, legal, or redistribution gates. - `LICENSE-NOTICE-REVIEW-RESULTS.json` and a strict external payload-tree - verifier. All 78 candidate payloads now have checksum-bound engineering + verifier. All 80 candidate payloads now have checksum-bound engineering review. The pinned upstream `alpine-keys` GPL-to-MIT license-decision commit - is included while its package-level copyright notice remains open; + is included while its package-level copyright notice remains open. The + `ca-certificates` generator is byte-identical to curl commit `3fdc4bdb`, and + that exact revision's curl license is pinned while trust-store review stays + open; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, five origins still need package-specific material, and diff --git a/CHANGELOG.md b/CHANGELOG.md index 4b9d915..3c67382 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -35,11 +35,13 @@ PocketRoot 的重要变化记录在这里。首个公开版本发布后遵循 Se 法律与再分发门禁保持关闭。 - 为剩余 8 个 RootFS source origin 加入 checksum-bound `LICENSE-NOTICE-CANDIDATES.json`、严格验证器和仓库外原子 materializer;索引 - 11 份远端许可证/attribution 材料、46 份 aports 文件与 21 份既有证据,支持完整 + 13 份远端许可证/attribution 材料、46 份 aports 文件与 21 份既有证据,支持完整 复验,但不提交 payload,也不解除工程、法律或再分发门禁。 - 加入 `LICENSE-NOTICE-REVIEW-RESULTS.json` 和严格外置 payload-tree 复验器; - 78/78 个候选 payload 已完成 checksum-bound 工程复核;新增固定 + 80/80 个候选 payload 已完成 checksum-bound 工程复核;新增固定 `alpine-keys` GPL→MIT 上游许可判定提交,但仍保留包级版权声明缺口; + `ca-certificates` 生成脚本与 curl 提交 `3fdc4bdb` 字节一致并固定该精确 + revision 的 curl 授权文本,trust-store 审查仍保持未决; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项关闭,另外 5 个 origin 仍需补逐包材料,法律和再分发门禁保持关闭。 - RootFS source-review materializer 新增严格仓库外下载缓存输入;缓存只替代网络 diff --git a/Compliance/RootFS/v0.3.3/EVIDENCE.json b/Compliance/RootFS/v0.3.3/EVIDENCE.json index 61f3a32..b14285e 100644 --- a/Compliance/RootFS/v0.3.3/EVIDENCE.json +++ b/Compliance/RootFS/v0.3.3/EVIDENCE.json @@ -43,9 +43,9 @@ "engineeringReviewedLicenseCandidates": 21, "sourceOriginsWithRemainingLicenseReviewItems": 8, "indexedLicenseNoticeCandidateOrigins": 8, - "pinnedRemoteLicenseNoticePayloads": 11, + "pinnedRemoteLicenseNoticePayloads": 13, "supplementalAportsCandidateFiles": 46, - "engineeringReviewedLicenseNoticeCandidatePayloads": 78, + "engineeringReviewedLicenseNoticeCandidatePayloads": 80, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5 }, "engineeringStatus": { diff --git a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json index 8afc6b6..db0e82f 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-INVENTORY.json @@ -31,9 +31,9 @@ "sourceOriginsWithOpenReviewItems": 10, "sourceOriginsWithRemainingReviewItems": 8, "indexedOpenSourceOrigins": 8, - "pinnedRemoteReferencePayloads": 11, + "pinnedRemoteReferencePayloads": 13, "supplementalAportsFiles": 46, - "engineeringReviewedCandidatePayloads": 78, + "engineeringReviewedCandidatePayloads": 80, "sourceOriginsWithRemainingCandidatePayloadReviewItems": 5, "candidateBundleIndexComplete": true, "candidatePayloadCommitted": false, diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json index 6ea45bd..82fee3b 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-CANDIDATES.json @@ -106,6 +106,28 @@ "byteCount": 772, "sha256": "a939e8baa52febea02d5bcfcc306822827eac3fd979a637c7723c84af3487e3e" }, + { + "kind": "package-attribution", + "sourceOrigin": "ca-certificates", + "retrievalURLs": [ + "https://raw.githubusercontent.com/curl/curl/3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477/lib/mk-ca-bundle.pl" + ], + "cacheKey": "ca-certificates-curl-3fdc4bdb-mk-ca-bundle.pl", + "outputPath": "supplemental/ca-certificates/curl-mk-ca-bundle.pl", + "byteCount": 20863, + "sha256": "9d828d97053868907ce6229d132132f0f26772393405dadd037b6f85a5c5b219" + }, + { + "kind": "package-attribution", + "sourceOrigin": "ca-certificates", + "retrievalURLs": [ + "https://raw.githubusercontent.com/curl/curl/3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477/COPYING" + ], + "cacheKey": "ca-certificates-curl-3fdc4bdb-COPYING", + "outputPath": "supplemental/ca-certificates/curl-COPYING", + "byteCount": 1088, + "sha256": "db3c4a3b3695a0f317a0c5176acd2f656d18abc45b3ee78e50935a78eb1e132e" + }, { "kind": "package-attribution", "sourceOrigin": "openssl", @@ -287,7 +309,10 @@ "licenses/MPL-2.0.txt" ], "supplementalAportsPaths": [], - "remoteEvidencePaths": [], + "remoteEvidencePaths": [ + "supplemental/ca-certificates/curl-mk-ca-bundle.pl", + "supplemental/ca-certificates/curl-COPYING" + ], "remainingReviewItems": [ "collect-complete-mpl-2.0-license-text", "confirm-certificate-attribution-and-trust-store-requirements", diff --git a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json index c7cf5d5..2e722c0 100644 --- a/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json +++ b/Compliance/RootFS/v0.3.3/LICENSE-NOTICE-REVIEW-RESULTS.json @@ -4,7 +4,7 @@ "version": "v0.3.3", "sha256": "be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4" }, - "candidateManifestSha256": "65b61668f3535149c949ed45e166934d9d0353d73835dc2d39ee9ba31be751b2", + "candidateManifestSha256": "7df6c1d6dee4e95775fd21112a6b074d584eb2661ac019b7309f3e6f1e4c1584", "status": "candidate-payloads-engineering-reviewed-open-release-gates", "engineeringReviewCompleted": true, "allIndexedCandidatePayloadsReviewed": true, @@ -13,8 +13,8 @@ "legalReviewApproved": false, "redistributionApproved": false, "candidatePayloadTreeFormat": "sha256-path-lines-v1", - "candidatePayloadTreeSha256": "1291b4df5e9a7b4375afbf31de492d832b3ca693bf390a1c2619652ee0739418", - "reviewedPayloadFileCount": 78, + "candidatePayloadTreeSha256": "98efff580466a00ba3f265f21c4cadab97f704551b61b1bcaae8c25ff27864d0", + "reviewedPayloadFileCount": 80, "reviewedClosedOriginEvidenceCount": 4, "sourceOriginsWithRemainingReviewItems": 5, "sources": [ @@ -105,7 +105,7 @@ "reviewedExistingEvidenceCount": 2, "reviewedReferenceLicenseCount": 2, "reviewedSupplementalAportsCount": 0, - "reviewedRemoteEvidenceCount": 0, + "reviewedRemoteEvidenceCount": 2, "resolvedReviewItems": [ "collect-complete-mpl-2.0-license-text", "confirm-mit-script-notices-relevant-to-shipped-bundle" diff --git a/Compliance/RootFS/v0.3.3/NOTICE.md b/Compliance/RootFS/v0.3.3/NOTICE.md index 17b163a..1c84fe0 100644 --- a/Compliance/RootFS/v0.3.3/NOTICE.md +++ b/Compliance/RootFS/v0.3.3/NOTICE.md @@ -43,13 +43,13 @@ for `libc-dev`, `zlib`. 8 source origins still have package-specific open items, so this is not a complete or legally approved license/NOTICE bundle. `LICENSE-NOTICE-CANDIDATES.json` now pins an external candidate bundle for -those open origins: 11 remote +those open origins: 13 remote reference/attribution payloads and 46 supplemental aports files, together with all checksum-bound reviewed evidence. The repository tool can materialize and re-verify that bundle outside the repository. `LICENSE-NOTICE-REVIEW-RESULTS.json` records checksum-bound engineering -review of all 78 indexed +review of all 80 indexed payload files. 3 origins have no remaining candidate-material engineering items; 5 origins still require package-specific material. Legal review and redistribution diff --git a/Compliance/RootFS/v0.3.3/README.md b/Compliance/RootFS/v0.3.3/README.md index 962817c..25f9d4e 100644 --- a/Compliance/RootFS/v0.3.3/README.md +++ b/Compliance/RootFS/v0.3.3/README.md @@ -20,10 +20,10 @@ pinned RootFS archive. It does not store the RootFS payload. attribution、声明与内联 notice 的路径、大小、SHA-256 和逐包未决审查项; - `LICENSE-REVIEW-RESULTS.json`:对全部 21 个候选的 checksum-bound 工程复核 结论、coverage 和未决项处置;不表示法律或再分发批准; -- `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 11 份远端 +- `LICENSE-NOTICE-CANDIDATES.json`:为剩余 8 个 source origin 固定 13 份远端 许可证/attribution 材料、46 份 aports 补充文件及现有 21 份复核证据的外置候选包; payload 不提交,工程、法律和再分发门禁保持关闭; -- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 78 个 payload 文件树的 +- `LICENSE-NOTICE-REVIEW-RESULTS.json`:绑定候选清单与 80 个 payload 文件树的 工程复核结果;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,法律和 再分发门禁保持关闭; - `RUNTIME-CONFIGURATION.json`:guest、`apk`、repository、world 和 DNS 默认配置; @@ -39,10 +39,10 @@ manifest, not a committed source archive or redistribution grant. `LICENSE-REVIEW-RESULTS.json` records the engineering review of all 21 pinned candidates. Two source origins have no remaining indexed review items; eight still have package-specific open items. `LICENSE-NOTICE-CANDIDATES.json` -indexes an external candidate bundle for those eight origins: 11 pinned remote +indexes an external candidate bundle for those eight origins: 13 pinned remote license/attribution payloads, 46 supplemental aports files, and the existing 21 reviewed evidence files. `LICENSE-NOTICE-REVIEW-RESULTS.json` binds the -engineering review to the exact 78-file payload tree. Three origins have no +engineering review to the exact 80-file payload tree. Three origins have no remaining candidate-material engineering items; five still require package-specific material. Legal and redistribution approval remain open. @@ -72,6 +72,33 @@ reference-only, coverage remains partial, and the legal and redistribution gates do not change. +`ca-certificates-20230506.tar.bz2` 中的 `mk-ca-bundle.pl`(20,863 字节, +SHA-256 `9d828d97053868907ce6229d132132f0f26772393405dadd037b6f85a5c5b219`) +与 curl 提交 `3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477` 的 +`lib/mk-ca-bundle.pl` 字节一致。外置候选包同时固定该脚本和同一提交的 +1,088 字节 `COPYING`;后者 SHA-256 为 +`db3c4a3b3695a0f317a0c5176acd2f656d18abc45b3ee78e50935a78eb1e132e`, +补齐脚本头部所引用的精确 curl 授权,而不是把通用 SPDX MIT 文本当作替代。 +因此 `confirm-mit-script-notices-relevant-to-shipped-bundle` 的既有工程结论有了 +精确 provenance;`confirm-certificate-attribution-and-trust-store-requirements` +仍未决,attribution coverage 仍为 partial,法律与再分发门禁不变。 + +The `mk-ca-bundle.pl` in `ca-certificates-20230506.tar.bz2` is 20,863 bytes +with SHA-256 +`9d828d97053868907ce6229d132132f0f26772393405dadd037b6f85a5c5b219` +and is byte-identical to `lib/mk-ca-bundle.pl` at curl commit +`3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477`. The external candidate bundle +pins both that script and the 1,088-byte `COPYING` from the same commit; the +license has SHA-256 +`db3c4a3b3695a0f317a0c5176acd2f656d18abc45b3ee78e50935a78eb1e132e`. +This supplies the exact curl grant referenced by the script header instead +of treating a generic SPDX MIT text as a substitute. The existing engineering +disposition of +`confirm-mit-script-notices-relevant-to-shipped-bundle` is therefore bound to +exact provenance. `confirm-certificate-attribution-and-trust-store-requirements` +remains open, attribution coverage remains partial, and the legal and +redistribution gates do not change. + OpenSSL 的工程结论绑定固定 `openssl-3.1.4.tar.gz`:源包根目录没有 `NOTICE` 文件;固定 RootFS 的 APK database 将 guest 路径 `/etc/ssl/misc/CA.pl` 与 `/etc/ssl/misc/tsget.pl` 归属到 inventory 中的 @@ -269,7 +296,7 @@ advice, or redistribution approval. 这些文件不构成完整第三方 LICENSE/NOTICE bundle、经审查的 copyleft corresponding-source 交付、法律意见或再分发授权。源码获取清单已完整覆盖固定 inventory,21 个候选也都有工程复核结果;`libc-dev`、`zlib` 已关闭索引项,另外 -8 个 source origin 的 78 个新候选 payload 已完成 checksum-bound 工程复核; +8 个 source origin 的 80 个新候选 payload 已完成 checksum-bound 工程复核; `apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包版权/notice 材料。修改说明、构建完整性、源码提供方式、法律 审查、App Store 2.5.2 产品策略和负责人批准仍是发行阻塞项。 @@ -278,7 +305,7 @@ These files are not a complete third-party LICENSE/NOTICE bundle, reviewed copyleft corresponding-source delivery, legal advice, or redistribution approval. The acquisition manifest completely covers the pinned inventory and all 21 indexed candidates have engineering review results. `libc-dev` and -`zlib` have no remaining indexed items. All 78 newly indexed payloads have a +`zlib` have no remaining indexed items. All 80 newly indexed payloads have a checksum-bound engineering review; `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items, while five origins still need package-specific copyright/notice material. Modification, build diff --git a/Compliance/RootFS/v0.3.3/SHA256SUMS b/Compliance/RootFS/v0.3.3/SHA256SUMS index 42f1236..84fca78 100644 --- a/Compliance/RootFS/v0.3.3/SHA256SUMS +++ b/Compliance/RootFS/v0.3.3/SHA256SUMS @@ -1,10 +1,10 @@ -372abe76057ea5573999c38db5ca92a180a99c0b1d10b61342a6cccc1a1dff09 EVIDENCE.json -8d82477fb7076d2f5582a1b8a29675e3d4ec029bf54c7ed01fb4dd8fb47deb0f LICENSE-INVENTORY.json -65b61668f3535149c949ed45e166934d9d0353d73835dc2d39ee9ba31be751b2 LICENSE-NOTICE-CANDIDATES.json -d6d1ec6f3a487d9d9f048486e7ad05a698caf6f25ca2bf6bb7e0d45aec03fbc6 LICENSE-NOTICE-REVIEW-RESULTS.json +d10ce04e007c10aea2112c8e654e41fbde6099ea18d96ae11dea434e4f5f708d EVIDENCE.json +f5a8d7fbd5b5a1664bf95c4e5dd3611994f03adff20ab77f378cdbc15900afdd LICENSE-INVENTORY.json +7df6c1d6dee4e95775fd21112a6b074d584eb2661ac019b7309f3e6f1e4c1584 LICENSE-NOTICE-CANDIDATES.json +391ab116ec79ae5fd30b126384564a562fa857070b0276c711fb4e0ff4cf3d69 LICENSE-NOTICE-REVIEW-RESULTS.json 3c7f786d9551d716c2a8b374d8cc63d11a46d67827be2fa0cea73b51b6b92eda LICENSE-REVIEW-RESULTS.json 3d483714a09cb2194e1b4af9aef5dfec2fbcfd44c70d521899398a3893f1908a LICENSE-REVIEW.json -4573a70b9fded20bd65d72ae4d63908a9c13e5c2f5ac6c95a1f926fb068ab1f6 NOTICE.md +710bb926e90d10572b6d4b07a59090ce480e1159e2ed4a774722a30272d4539e NOTICE.md 4f7f7626f3d0891a29717e4b7932c36004ecc9aac25a4aa104c300aae979e3e1 PACKAGE-INVENTORY.tsv dbca9b285015a0d8b1d339a894b4594c9e335cbc2d7f9d5212a41095ae4bd1e1 RUNTIME-CONFIGURATION.json 8e021cb8c4160c934a0202609691d7a94526cd016f4394a47da6e7a5ab41d0ea SBOM.spdx.json diff --git a/Docs/ReleaseCompliance.md b/Docs/ReleaseCompliance.md index e90a5a9..e1eb65c 100644 --- a/Docs/ReleaseCompliance.md +++ b/Docs/ReleaseCompliance.md @@ -75,9 +75,9 @@ aports snapshot/upstream distfile 获取清单和仓库外 materializer,并固 全部 10 个 source origin 的 21 个 license、attribution、声明与内联 notice 候选。 第二个仓库外工具从已验证 source-review 目录提取这些候选;固定结果清单记录 21/21 个候选均已工程复核,`libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source -origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:11 份远端 +origin 仍有逐包未决项。仓库现已为这 8 个 origin 固定外置候选包:13 份远端 许可证/attribution 材料、46 份 aports 补充文件和全部既有复核证据;工具可在 -仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 78 文件 payload +仓库外原子生成并复验。固定结果清单把工程复核绑定到精确的 80 文件 payload tree;`apk-tools`、`openssl`、`pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包材料。修改与构建完整性、源码提供方式和法律审查仍未完成, 不能视为完整 NOTICE 或已批准的对应源码交付。 @@ -179,7 +179,7 @@ Alpine `apk` 可以下载、安装和执行新增代码。即使初始 RootFS - [x] 对固定的 21 个 license/NOTICE 候选完成 checksum-bound 工程复核。 - [x] 为剩余 8 个 source origin 建立 checksum-bound 外置候选包索引与可复验 materializer;payload 不提交且批准门禁保持关闭。 -- [x] 对外置候选包的 78 个 payload 完成 checksum-bound 工程复核并固定结果; +- [x] 对外置候选包的 80 个 payload 完成 checksum-bound 工程复核并固定结果; 3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料。 - [ ] 收集 license text 和 NOTICE。 - [ ] 建立 copyleft corresponding source bundle。 diff --git a/Docs/Roadmap.md b/Docs/Roadmap.md index 6b5191e..fd69e84 100644 --- a/Docs/Roadmap.md +++ b/Docs/Roadmap.md @@ -103,7 +103,7 @@ | 最低 Xcode 16 原生兼容 | 已通过 | Xcode 16.0 / iOS 18.0 SDK 完成 RootFS install、Simulator/device final-link 和 17 项 native smoke | | App lifecycle 与内存 | 进行中 | Simulator 与 Jack iPhone 均有 256 MiB `ru_maxrss` 门禁;真机 process suspend/resume、UIKit foreground/background、强制终止后数据恢复和有界 App delegate memory-warning 回调恢复已通过;补真实 memory pressure/jetsam | | RootFS ENOSPC/掉电 | 进行中 | 峰值空间预检、全 ENOSPC、七点持久化屏障、确定性掉电切点和 Jack iPhone 受限容量/ENOSPC 清理恢复已覆盖;补真实 storage pressure/强制断电 | -| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、21/21 初始候选和 78/78 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | +| License-reviewed RootFS | 阻塞 | 15 包 inventory、10 source origin、SPDX SBOM、默认配置证据、外置源码获取流程、21/21 初始候选和 80/80 外置 payload 工程复核已完成;3 个 origin 的候选材料工程项关闭,5 个仍需补逐包材料,之后完成法律复核、对应源码交付审查与负责人批准 | | App Store 2.5.2 | 阻塞 | guest download/execute policy 有书面结论 | ### 后续 runtime 执行顺序 diff --git a/Docs/RootFS.md b/Docs/RootFS.md index 0f19795..49bb3d4 100644 --- a/Docs/RootFS.md +++ b/Docs/RootFS.md @@ -5,7 +5,7 @@ RootFS 是 PocketRoot 的外部供应链输入,不是普通测试 fixture。仓库提交的是不可变清单、校验和安全安装代码,不提交、镜像或默认打包 RootFS 二进制。 > [!WARNING] -> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 21 个初始候选和 78 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 +> 固定 v0.3.3 归档已有可复现 package inventory、SPDX SBOM、默认配置证据、完整覆盖 inventory 的源码获取清单,以及 21 个初始候选和 80 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核结果;3 个 origin 的候选材料工程项已关闭,5 个仍需补逐包材料。完整 NOTICE、法律复核、对应源码交付审查与发行批准尚未闭环。以下 URL 与命令用于审计和本地开发,不构成公开再分发授权。应用必须先完成自己的法律与发行审查。 ## 1. 固定清单 @@ -143,7 +143,7 @@ SHA-256、精确路径集合与无链接/特殊节点边界。固定结果清单 工程复核,其中 `libc-dev`、`zlib` 的索引项已关闭,另外 8 个 source origin 仍有 未决项;输出不能直接视为完整 NOTICE 或对应源码交付材料。 -剩余 8 个 origin 的外置 LICENSE/NOTICE 候选包清单还固定了 11 份远端许可证/ +剩余 8 个 origin 的外置 LICENSE/NOTICE 候选包清单还固定了 13 份远端许可证/ attribution 材料与 46 份 aports 补充文件。清单可独立校验;实际物化和复验必须 同时提供上面已经验证的两个仓库外目录: @@ -167,7 +167,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ ``` 工具对远端材料强制 HTTPS、重定向次数、响应大小、固定字节数与 SHA-256,并原子 -创建输出。结果清单把工程复核绑定到精确的 78 文件 payload tree;复验器拒绝路径 +创建输出。结果清单把工程复核绑定到精确的 80 文件 payload tree;复验器拒绝路径 漂移、符号链接、特殊节点、已知摘要漂移和 tree digest 漂移。`apk-tools`、 `openssl` 与 `pax-utils` 的候选材料工程项已关闭,另外 5 个 origin 仍需补逐包 材料;候选 NOTICE 和 receipt 不代表法律审查或发行批准。 diff --git a/Docs/en/ReleaseCompliance.md b/Docs/en/ReleaseCompliance.md index 2721e51..4abe6c2 100644 --- a/Docs/en/ReleaseCompliance.md +++ b/Docs/en/ReleaseCompliance.md @@ -41,10 +41,10 @@ declaration, and inline-notice candidates across all 10 source origins. A pinned result manifest records engineering review of all 21 candidates. `libc-dev` and `zlib` have no remaining indexed items; eight source origins still have package-level follow-up. The repository now pins an external -candidate bundle for those origins: 11 remote license/attribution payloads, +candidate bundle for those origins: 13 remote license/attribution payloads, 46 supplemental aports files, and all existing reviewed evidence. The tool can atomically materialize and re-verify it outside the repository. A pinned -results manifest binds engineering review to the exact 78-file payload tree. +results manifest binds engineering review to the exact 80-file payload tree. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. Modification, build-completeness, source-offer, and legal reviews remain unresolved, so the @@ -122,7 +122,7 @@ The current code does not provide a complete product-level privacy policy. - [x] Index a checksum-bound external candidate bundle and reproducible materializer for the eight remaining origins; payloads stay uncommitted and approval gates stay closed. -- [x] Complete checksum-bound engineering review of all 78 external candidate +- [x] Complete checksum-bound engineering review of all 80 external candidate payloads; three origins have no remaining candidate-material engineering items and five still need package-specific material. - [ ] Collect license texts and NOTICE files. diff --git a/Docs/en/Roadmap.md b/Docs/en/Roadmap.md index 56281fe..9baf7c9 100644 --- a/Docs/en/Roadmap.md +++ b/Docs/en/Roadmap.md @@ -98,7 +98,7 @@ This establishes the current Simulator, minimum-Xcode 16, and single-iPhone one- | Minimum Xcode 16 native | Passed | Xcode 16.0 / iOS 18.0 SDK completed RootFS install, Simulator/device final links, and the 17-check native smoke | | App lifecycle and memory | In progress | Simulator and Jack iPhone have 256 MiB `ru_maxrss` gates; physical process suspend/resume, UIKit foreground/background, post-termination data recovery, and bounded App-delegate memory-warning recovery passed; add real memory-pressure/jetsam evidence | | RootFS ENOSPC/power faults | In progress | Peak-space preflight, full ENOSPC, seven persistence barriers, deterministic power-loss cuts, and bounded capacity/ENOSPC cleanup recovery on Jack iPhone are covered; add real storage-pressure/power-cut evidence | -| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 21 initial candidates, and all 78 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | +| License-reviewed RootFS | Blocked | The 15-package/10-origin evidence, all 21 initial candidates, and all 80 external payloads have checksum-bound engineering review; three origins have no remaining candidate-material engineering items, five still need package-specific material, followed by legal review, corresponding-source delivery review, and authorized approval | | App Store 2.5.2 | Blocked | Written guest download/execute policy decision | ### Next runtime sequence diff --git a/Docs/en/RootFS.md b/Docs/en/RootFS.md index f1b3c56..8e95e57 100644 --- a/Docs/en/RootFS.md +++ b/Docs/en/RootFS.md @@ -5,7 +5,7 @@ A RootFS is an external supply-chain input, not a normal fixture. PocketRoot commits immutable metadata and secure install code, not the payload. > [!WARNING] -> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 21 initial candidates and all 78 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. +> The pinned v0.3.3 archive now has a reproducible package inventory, SPDX SBOM, default-configuration evidence, a source-acquisition manifest covering the complete inventory, and checksum-bound engineering review of all 21 initial candidates and all 80 external LICENSE/NOTICE payloads. Three origins have no remaining candidate-material engineering items; five still need package-specific material. The complete NOTICE set, legal review, corresponding-source delivery review, and distribution approval remain open. The URL and commands below support audit and local development; they do not grant redistribution rights. ## Pinned manifest @@ -127,7 +127,7 @@ eight source origins still require follow-up. The output is not a completed NOTICE or corresponding-source delivery bundle. The external LICENSE/NOTICE candidate manifest for those eight origins also -pins 11 remote license/attribution payloads and 46 supplemental aports files. +pins 13 remote license/attribution payloads and 46 supplemental aports files. Validate it independently, or materialize and re-verify it using both external directories verified above: @@ -152,7 +152,7 @@ ruby Scripts/rootfs-license-notice-review-results.rb \ The tool enforces HTTPS, redirect and response-size bounds, pinned byte counts and SHA-256 digests, and atomic output creation. The results bind engineering -review to the exact 78-file payload tree; the verifier rejects path drift, +review to the exact 80-file payload tree; the verifier rejects path drift, links, special nodes, known-digest drift, and tree-digest drift. `apk-tools`, `openssl`, and `pax-utils` have no remaining candidate-material engineering items; five origins still need package-specific material. The candidate NOTICE diff --git a/README.md b/README.md index 736d423..2adb1a2 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ print("stderr:", result.stderr) - 展开大小:`18,838,016` 字节 - SHA-256:`be0f3c133f78f28b023288459b33dc28fa253a6ef29f7123bc5f3892edf90ad4` -固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 21 个初始候选及 78 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 +固定 URL 只是清单元数据,不代表库会自动下载。仓库已从固定归档生成 RootFS 包清单与 SPDX SBOM,并完成 21 个初始候选及 80 个外置 LICENSE/NOTICE payload 的 checksum-bound 工程复核;5 个 source origin 仍需补逐包材料。许可证/NOTICE 法律复核、对应源码和完整发行物 SBOM 未完成前,不得把该 RootFS 加入 Package、App bundle 或公开发行物。 ## 验证命令 diff --git a/Scripts/rootfs-license-notice-candidates.rb b/Scripts/rootfs-license-notice-candidates.rb index 495e0ba..3d2cf21 100644 --- a/Scripts/rootfs-license-notice-candidates.rb +++ b/Scripts/rootfs-license-notice-candidates.rb @@ -21,7 +21,7 @@ module RootFSLicenseNoticeCandidates openssl pax-utils ].freeze EXPECTED_EXISTING_EVIDENCE_FILES = 21 - EXPECTED_REMOTE_PAYLOAD_FILES = 11 + EXPECTED_REMOTE_PAYLOAD_FILES = 13 EXPECTED_APORTS_FILES = 46 PAYLOAD_KINDS = %w[package-attribution spdx-license-text].freeze TOP_LEVEL_KEYS = %w[ diff --git a/Scripts/rootfs-license-notice-review-results.rb b/Scripts/rootfs-license-notice-review-results.rb index a5e37c3..89e4a94 100644 --- a/Scripts/rootfs-license-notice-review-results.rb +++ b/Scripts/rootfs-license-notice-review-results.rb @@ -22,7 +22,7 @@ module RootFSLicenseNoticeReviewResults COVERAGE = %w[complete partial reference-only].freeze SHA256_PATTERN = /\A[0-9a-f]{64}\z/ CANDIDATE_PAYLOAD_TREE_FORMAT = "sha256-path-lines-v1" - EXPECTED_REVIEWED_PAYLOAD_FILES = 78 + EXPECTED_REVIEWED_PAYLOAD_FILES = 80 MAX_REVIEWED_PAYLOAD_BYTES = 8 * 1_024 * 1_024 TOP_LEVEL_KEYS = %w[ allIndexedCandidatePayloadsReviewed archive candidateManifestSha256 diff --git a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb index ac1551e..75998f3 100644 --- a/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeCandidatesTests.rb @@ -28,7 +28,7 @@ def test_validates_complete_open_origin_candidate_index validated = validate assert_equal 8, validated.fetch(:sources).length - assert_equal 11, validated.fetch(:remote_payloads).length + assert_equal 13, validated.fetch(:remote_payloads).length assert_equal 21, validated.fetch(:existing_evidence_paths).length assert_equal 46, validated.fetch(:aports_paths).length end @@ -142,6 +142,45 @@ def test_pins_alpine_keys_license_decision_evidence ) end + def test_pins_exact_curl_license_for_ca_bundle_generator + payloads = @candidate.fetch("remotePayloads").select do |candidate| + candidate["sourceOrigin"] == "ca-certificates" + end + source = @candidate.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "ca-certificates" + end + reviewed_script = @review.fetch("sources") + .find { |candidate| candidate.fetch("sourceOrigin") == "ca-certificates" } + .fetch("candidateEvidence") + .find { |evidence| evidence.fetch("outputPath").end_with?("mk-ca-bundle.pl") } + + assert_equal 2, payloads.length + assert_equal( + [ + "https://raw.githubusercontent.com/curl/curl/" \ + "3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477/lib/mk-ca-bundle.pl", + "https://raw.githubusercontent.com/curl/curl/" \ + "3fdc4bdb5b00835a1d04cf160cd61fe7f8feb477/COPYING" + ], + payloads.flat_map { |payload| payload.fetch("retrievalURLs") } + ) + assert_equal [20_863, 1_088], + payloads.map { |payload| payload.fetch("byteCount") } + assert_equal reviewed_script.fetch("sha256"), + payloads.first.fetch("sha256") + assert_equal( + "db3c4a3b3695a0f317a0c5176acd2f656d18abc45b3ee78e50935a78eb1e132e", + payloads.last.fetch("sha256") + ) + assert_equal( + %w[ + supplemental/ca-certificates/curl-mk-ca-bundle.pl + supplemental/ca-certificates/curl-COPYING + ], + source.fetch("remoteEvidencePaths") + ) + end + def test_rejects_overlapping_materialized_output_paths payloads = @candidate.fetch("remotePayloads") payloads.fetch(0)["outputPath"] = "licenses/collision" diff --git a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb index 0d18e11..7ab5a2f 100644 --- a/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb +++ b/Tests/Scripts/RootFSLicenseNoticeReviewResultsTests.rb @@ -45,9 +45,9 @@ def test_validates_pinned_candidate_review_results validated = validate assert_equal 8, validated.fetch(:sources).length - assert_equal 11, validated.fetch(:remote_payloads).length + assert_equal 13, validated.fetch(:remote_payloads).length assert_equal 46, validated.fetch(:aports_paths).length - assert_equal 78, @results.fetch("reviewedPayloadFileCount") + assert_equal 80, @results.fetch("reviewedPayloadFileCount") assert_equal 5, @results.fetch("sourceOriginsWithRemainingReviewItems") assert_equal %w[apk-tools openssl pax-utils], @@ -85,6 +85,28 @@ def test_keeps_alpine_keys_copyright_notice_gate_open ) end + def test_binds_ca_bundle_generator_to_exact_curl_license + source = @results.fetch("sources").find do |candidate| + candidate.fetch("sourceOrigin") == "ca-certificates" + end + + assert_equal "complete", source.fetch("licenseTextCoverage") + assert_equal "partial", source.fetch("attributionCoverage") + assert_equal 2, source.fetch("reviewedRemoteEvidenceCount") + assert_includes( + source.fetch("resolvedReviewItems"), + "confirm-mit-script-notices-relevant-to-shipped-bundle" + ) + assert_equal( + ["confirm-certificate-attribution-and-trust-store-requirements"], + source.fetch("remainingReviewItems") + ) + assert_equal( + "additional-package-material-required", + source.fetch("engineeringConclusion") + ) + end + def test_rejects_candidate_manifest_digest_drift @candidates["status"] = "changed"