Skip to content

legal: adversarial and attorney review of rc3 for rc4 #31

Description

@zackees

Note

Meta issue for paralegal research and open-source counsel review. It does not approve the license, apply it to FastLED software, or replace attorney judgment.

Context

PR #29 publishes FastLED Reciprocal License 1.0-rc3 as the immutable policy snapshot produced by the completed interview and research pass. The operative rc3 content is pinned at 8a92a8739f337c5a47e2ca8409b602d41c8c3d6e, with its SHA-256 and Git blob recorded in PROVENANCE.md.

Rc3 intentionally makes several material departures from MPL 2.0: a broad modifier-controlled Monetization Event; educational, research, media, and unrestricted-funding exemptions; upstream-first permanent public return of the covered delta; default GPL-family Secondary License compatibility; verbatim-only canonical license text; adopter-selected version pinning; and a bespoke termination/cure rule.

Before a final 1.0 candidate, these choices need a consolidated adversarial and attorney review that produces either a justified rc4 revision or an explicit decision to retain each rc3 term.

Proposal

Run an rc4 review across these lanes:

  1. Copyright nexus and contract fallback ? test internal production, SaaS/network use, development tools used before launch, and other Monetization Events against exclusive-right nexus, formation, assent, preemption, and enforceable-remedy limits.
  2. GPL-family election ? verify GPLv2-or-later, LGPLv2.1-or-later, and AGPLv3-or-later compatibility; confirm that incompatible monetization restrictions fall away after election; determine which FastLED, provenance, and AI-notice obligations can remain as reasonable notices.
  3. Trigger and exemption boundaries ? adversarially test Materially Enables, $1/no-threshold events, ad-supported media, tuition and sponsored education, publisher/university transactions, grants, contractors, resellers, and attempted token or sham structures.
  4. Covered source and confidentiality ? validate the file-level boundary, build/reconstruction materials, secrets and unlicensable dependencies, mixed proprietary files, upstream-first mechanics, complete PR records, partial merges, host disappearance, and continuing availability.
  5. Version and text governance ? verify verbatim-copy permission, copyrightability limits, independent-license rights, exact commit pinning, only versus or later, prior-release irrevocability, and the separation between text stewardship and adopter software rights.
  6. Termination, cure, and remedies ? resolve legal: review repeat and willful violation reinstatement for rc4 #30, preserve prospective-versus-historical liability, and ensure the text does not promise compelled source disclosure or a forced separate license.
  7. Baseline MPL provisions ? review patent grant/retaliation, warranty, liability, defendant-principal-place law/venue, severability, and contributor-by-contributor enforcement for unintended interaction with Section 11.
  8. Operational consistency ? keep Exhibit C identical to the generic AI notice; align SPDX LicenseRef, notice templates, machine-readable policy, artifact hashes, legal-review record, and immutable provenance.

Acceptance criteria

  • Each lane has a proposition-level research update using current primary authority, exact license versions, procedural posture, and jurisdiction-specific weight.
  • Every discovered contradiction, loophole, or material ambiguity is either fixed in rc4 or retained with a written policy and counsel rationale.
  • Strategy: project-agnostic GPL/free-software compatibility exception #10's GPL strategy is reconciled with the actual rc3 Secondary License election and closed or rewritten accordingly.
  • legal: review repeat and willful violation reinstatement for rc4 #30's cure/reinstatement severity review is resolved before rc4 is published.
  • The review expressly states that GPL terms win after a valid Secondary License election and identifies which notices may lawfully remain.
  • The review does not infer ownership of adopter software from maintenance of the canonical license-text repository.
  • Any rc4 implementation includes focused RED -> GREEN consistency tests for the changed clauses, identifiers, Exhibit C equality, notice fields, and artifact manifest.
  • Rc3 remains available at its immutable content commit and rc4 receives a new identifier, content digest, Git blob, and immutable source reference.
  • LEGAL-REVIEW.md remains PENDING unless a named attorney records approval, date, reviewed commit, and required changes.

Decisions

  • Treat rc4 as a legal hardening pass, not a reopening of the mission: the objective remains returning private covered improvements to the official project upon non-exempt monetization.
  • Preserve rc3 unchanged as the interview-derived snapshot; accepted changes receive the rc4 identifier rather than rewriting rc3 history.
  • Make GPL conflict priority non-negotiable for compatible adoptions, while allowing an adopter to attach Exhibit B and opt out before distribution.
  • Keep FastLED software adoption, source ownership, and source-file migration outside this generic license-text review.
  • Require explicit decisions rather than silently equating lack of case law with enforceability or unenforceability.

Open questions

  • Should rc4 retain every named Secondary License or narrow version combinations after exact compatibility analysis?
  • Should an adopting project be required to provide both an Upstream Repository and Official Reporting Location when either exists?
  • Should continuing availability use a defined archival backstop in addition to the 30-day replacement rule?

Related issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions