Offer the core under MIT OR Apache-2.0, and reverse the set that follows [#303] - #307
Merged
Conversation
…ows [#303] Entry 1 of #1 was answered twice and the second answer stands: MIT OR Apache-2.0, because a core whose purpose is to be linked by clients this organisation does not write cannot be copyleft in any strength. The tree published the first answer in four places at once - Cargo.toml, README.md, the root LICENSE and the provider's own listing - so a client author following the decision to the artefact found the opposite of what was decided, on the one fact they check before writing a line against this core. docs/decisions/0303-the-licence-the-core-is-offered-under.md carries the answer that stands, names the 2026-08-24 answer it supersedes and the reason given for the one that replaces it, and supersedes 0103 rather than editing it: the outbound licence is the premise 0103 derives its licence set from, and under MIT OR Apache-2.0 the one-way compatibility runs the other way. The whole copyleft column moves to the refused half, on two grounds kept apart because only the first is a compatibility fact - GPL, AGPL and LGPL impose conditions on the combined work that a client offering their own client permissively cannot meet, and MPL-2.0 is satisfiable but carries a source-availability obligation into eleven client repositories that MIT OR Apache-2.0 does not name. The worth test, the five outright behaviours with 0243's narrowing written into the fourth, the clause for a standing requirement, the test-tree split and the removal rule are carried forward unchanged. 0268 is re-read there rather than superseded. Its conjunction rule stands untouched, and Unicode-3.0 stays admitted on the second of the two grounds it gave - the admitted half already carries a notice condition and a name-use bar, so no obligation class arrives with the term. The first ground mapped that term's conditions onto the supplementary terms AGPL-3.0-or-later enumerates, and that mapping reads a licence this work no longer carries. The root now carries LICENSE-MIT and LICENSE-APACHE and no longer carries the AGPL text; Cargo.toml, README.md and NOTICE.md state the pair. A copy already received under AGPL-3.0-or-later keeps those terms, and README.md says so rather than leaving a reader to wonder what happened to the licence they had. Nothing in the resolved graph is admitted only by the clause that moves. The sixteen packages and the expression each one carries are read into the record under "The graph as it stands, read against this set", with the command that produced the listing beside it, so the shrinking set costs this graph nothing and that is measured rather than supposed. Closes #303 Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The issue this belongs to
Closes #303
What changed
The core is offered under
MIT OR Apache-2.0from this commit, and thedependency rule that derived its licence set from the earlier answer moves with
it.
docs/decisions/0303-the-licence-the-core-is-offered-under.mdcarries theanswer that stands, names the
AGPL-3.0-or-lateranswer of 2026-08-24 that itsupersedes and the reason given for the one that replaced it, and supersedes
0103rather than editing it. The outbound licence is the premise0103derives its licence set from, so under the answer that stands the one-way
compatibility runs the other way: every strength of copyleft moves to the
refused half, on two grounds the record keeps apart because only the first is a
compatibility fact.
GPL,AGPLandLGPLimpose conditions on the combinedwork that a client offering their own client on their own terms cannot meet.
MPL-2.0is satisfiable and is refused anyway, as a choice stated as one: itcarries a source-availability obligation into eleven client repositories that
MIT OR Apache-2.0does not name, and accepting that obligation outbound whilerefusing it inbound is a position that cannot be argued.
Everything in
0103that does not rest on the outbound licence is carriedforward unchanged rather than dropped: the worth test, the five outright
behaviours with
0243's narrowing of the fourth written into it, the clause fora requirement a landed record already states, the test-tree and shipping-tree
split, the removal rule and where the line beside a manifest entry lives.
0268is re-read there rather than superseded. Its conjunction rule standsuntouched and is restated in the set.
Unicode-3.0stays in the admitted halfon the second of the two grounds that record gave -
MITalready carries thenotice condition and the disclaimer,
BSD-3-Clausealready carries thename-use bar, so no obligation class arrives with the term. The first ground
mapped those three conditions onto the supplementary terms
AGPL-3.0-or-laterenumerates, quoting this repository's own licence file, and that mapping reads a
licence this work no longer carries.
The root carries
LICENSE-MITandLICENSE-APACHEand no longer carries theAGPL text.
Cargo.toml,README.mdandNOTICE.mdstate the pair.README.mdalso says what a copy already received under
AGPL-3.0-or-laterkeeps, becausea licence is a grant to a recipient rather than a property of a repository and a
reader who had one should not have to work that out.
Pointers were added to three landed records and nothing in them was reworded:
0011and0091each read the superseded answer out of the provider's listing,and
0268's first ground reads the superseded licence file. Each gains onesentence naming
0303, which is the pointer edit0001permits - remove any ofthe three and the record says exactly what it said before.
0103gains only thesuperseded byhalf of itsStatus:line, which is the second permitted edit.What failure it prevents
A client author checking the licence before writing a line against this core
found the answer that had been superseded, in four places at once. That has
already happened rather than being expected, and it is what #303 was opened
with:
The second failure is the dependency rule lagging behind the licence. A rule
whose stated ground is a licence the work is no longer offered under gets
applied in the permissive direction: a reader working from
0103's set admits acopyleft node, the node lands, and a licence obligation is the one class of
mistake here that deleting the dependency later does not repair. Taking it today
costs nothing in the graph, which the reading below measures.
Evidence
The answer that stands, read out of the issue that holds it rather than from
this branch:
The resolved graph, read at the commit being pushed. Nothing in it is admitted
only by the clause that moves:
Sixteen packages, each a single admitted term or a dual offer both of whose
members are admitted.
LICENSE-APACHEis the canonical text and not a retyped one. Byte-identical towhat apache.org serves, at the commit being pushed:
LICENSE-MITis the SPDX text with the copyright line filled in and theparagraphs wrapped; it is not byte-identical to any upstream file, and that is a
claim about a text a reader can compare rather than a measurement:
The two commands
CONTRIBUTING.mdnames, run on this branch:587, 2, 5, 5, 3, 11, 28, 5, 125 and 1 passing across the ten targets, none
failed, none ignored, none filtered out.
The gate legs that read what this change touches, run here:
What this does not cover
No guard was added or edited, so there is nothing here to watch bite. Nothing
in this repository reads a licence expression, which
0103already said ofitself and
0303repeats: the set is applied by the review and by the linebeside a manifest entry. This change does not alter that and adds no check.
The two dependency entries in
Cargo.tomlstill cite0103by number. Theyare not rewritten here. Every statement they make about a licence is still true
under the successor - both members of
MIT OR Apache-2.0are in the admittedhalf and
ureq-proto's graph reaches no conjunction - so what is stale is thenumber and not the judgement.
0303names that residual in its own text under"Where the line lives" rather than leaving a reader to find it.
What the provider's listing will report is not measured and is not claimed.
gh api repos/Flowfin/core --jq '.license.spdx_id'reads a state on GitHubrather than a byte in this tree, that state is computed after the merge, and a
repository carrying two licence files may well come back as
NOASSERTIONratherthan as either member. #303's last condition asks that it stop reporting what
was superseded; whether it names something useful instead is GitHub's detector's
answer and not this change's. The reading will be taken on the issue after the
merge and written there whatever it says.
Whether the licence analysis is right is a judgement and no run here makes
one. The two grounds for the refused half, the reading of
MPL-2.0's thirdsection, and the re-reading of
Unicode-3.0against the new premise arearguments in the record, written to be argued with. Nothing in this tree
evaluates them, and no lawyer has read them.
Nothing was run for a target other than this machine's. The
targetsandcross-toolchainlegs were not run here; this change compiles no code andtouches one manifest field, so nothing about a triple moves, but that is a claim
rather than a measurement.
cargo test --lockeddoes not reach two targets, which isCargo.toml'sown
test = falseonneeds_a_real_server_or_real_hardwareanda_race_the_detector_must_catch. Neither was run here and neither is touched.Who has read it
Nobody other than the author. There is no second reader on this board tonight,
and the evidence above stands in place of one.