diff --git a/AGENTS.md b/AGENTS.md index c5e7a11..aaf8031 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -9,13 +9,14 @@ licensing decision. Treat this repository like a repository of reusable license text. It does not need a universal software owner. A maintainer or steward of the canonical text controls text publication and versioning only; that role does not by itself -make the person a copyright owner, licensor, commercial licensor, beneficiary, -or enforcement claimant for software placed under the license. +make the person a copyright owner, licensor, separate-permission grantor, +beneficiary, or enforcement claimant for software placed under the license. For every adoption or enforcement question, identify the applicable software -Contributor or rights holder separately. A commercial-license exception can -come only from the applicable Contributors or someone independently authorized -by them. Do not investigate the ownership, contribution history, or source-file +Contributor or rightsholder separately. Separate written permission can come +only from all rightsholders whose authorization is necessary or from someone +independently authorized by them; do not assume anyone must offer it. Do not +investigate the ownership, contribution history, or source-file headers of the FastLED codebase merely because the license is named FastLED. Those facts are relevant only when the question specifically concerns FastLED adoption, FastLED rights, or enforcement involving FastLED software. diff --git a/ARTIFACTS.sha256 b/ARTIFACTS.sha256 index 0b561b0..a7ece5d 100644 --- a/ARTIFACTS.sha256 +++ b/ARTIFACTS.sha256 @@ -1,10 +1,10 @@ -a42aa7bb2925ba62054e14d6f4b32b2d1358270f0ac61cd7ec753a1ac00db7eb LICENSE +c46471504fd976d1e3693506d13b1d8c3bc25dca94c333736cb431b647692d67 LICENSE 452bf527cba6c1635f7c8d4a756c06ae3d2cbb50e020e612ac40cdee0233781f MPL-2.0.txt -07b4400299f67dad4bf49de5f3e2ee5c19daf2d95fc0800e0e07987993c66a13 LICENSE-AI-AGENT-INSTRUCTIONS.md +51a0ef022d3ade2ff0b7412aff9db9d33adc954d9dbfb0402c11037ad6bf7603 LICENSE-AI-AGENT-INSTRUCTIONS.md 4358d4c37f1305b43a3117a6a12780f666bf285538de0b28991613c0ccacecd8 LICENSE-MIT-LEGACY -4cc93f53cd775a8ed98c46e7658ce8ebce1c7fc764ddfc56224d7c8c582ae4c4 NOTICE-TEMPLATE.txt -8975b7bc9e8a11b7d4769efcbafab0a239c03a29cec027bd8a1140fe8f43b12d NOTICE-TEMPLATE-MIT-LEGACY.txt -b86c86db6b0a405f5c3933c1ed7e2495e2b889c8b01550b9bf2a5830b82136ba ai-policy.toml -965ec1ba8ff569db31e5f366909ae387b152f174ab3404154919b989e95dea23 header-policy.toml +90540d0496d5dc41c748de8c1942d6f9a259a1131f8ff5b3751251b37bd304ed NOTICE-TEMPLATE.txt +1e26b89ad86ef267672a20638ee747f3563452cf97c3c3676d699dfae49fd2df NOTICE-TEMPLATE-MIT-LEGACY.txt +f8c037026a86a1d313950dc6ef9ba03fd5e48dd65dd35c161b7a78659e1dc852 ai-policy.toml +53c035e6ff53f5d1e516f5a375266b71eb7da4baf1035c1a2fac944da33d80ba header-policy.toml 46a58ea084f12a001709c9b59a05d24be7180f82da52a12f646b18bd22125826 header-policy.schema.json b9ea8bd9ef4d6eff9729d914db7927216ba2b49f4b800a89ea55906f155b1963 tools/license_headers.py diff --git a/LEGAL-REVIEW.md b/LEGAL-REVIEW.md index 1190cee..c206fc8 100644 --- a/LEGAL-REVIEW.md +++ b/LEGAL-REVIEW.md @@ -17,19 +17,21 @@ approval. An AI multi-agent first-pass review of rc1 was filed as GitHub issues #2-#8 on 2026-08-24. The license was restructured in response. Rc2 then separated -the reusable license text from the rights, repositories, and commercial -licensing decisions of any particular adopting project. That work is input -to, not a substitute for, attorney review. +the reusable license text from the rights, repositories, and licensing +decisions of any particular adopting project. Rc3 records the subsequent +policy interview concerning monetization-triggered public return, upstream- +first submission, immutable versions, and GPL-family compatibility. That work +is input to, not a substitute for, attorney review. ## Decisions applied pending attorney ratification 1. **Reusable-text architecture.** The FastLED Reciprocal License may be applied to software from any project. The canonical repository and its maintainers publish and version the text only. They do not become the - owner, commercial licensor, beneficiary, or enforcement claimant for an + owner, separate-permission grantor, beneficiary, or enforcement claimant for an adopter's software. Each Contributor grants rights only in its - Contributions. Any separate commercial license must come from the - applicable Contributors or someone independently authorized by them. + Contributions. Any separate written permission must come from all necessary + rightsholders or someone independently authorized by them. Confirm Sections 10.1 and 11.3(g). 2. **Single-instrument construction.** The license is one self-contained document: a modified MPL 2.0 renamed under its Section 10.3, with Mozilla @@ -40,19 +42,24 @@ to, not a substitute for, attorney review. 2.7 does not condition the Contributor patent grant in Section 2.1(b) on the public-availability rule or required AI-notice inclusion. Confirm this allocation. -4. **Exhibit B closes Secondary-License distribution.** Sections 1.5, 3.3, - and 11.6 make the license deliberately GPL-incompatible in exchange for - making Section 11.3 non-bypassable. Confirm this trade-off before - recommending adoption. -5. **Zero-day timing is intentional and per version.** The development period - before a commercial Triggering Transfer is the compliance window. - Publication after the transfer restores rights only prospectively under - Sections 5.1 and 11.3(f). Confirm the condition-versus-covenant framing and - remedy consequences. -6. **The Triggering Transfer is recurring and modifier-bound.** It includes - the free-software-with-paid-product scenario and excludes specified - intra-group, manufacturing, lease, reseller, and network-only conduct. - Confirm each boundary and the interaction with applicable exhaustion law. +4. **GPL-family compatibility is the default.** Sections 3.3 and 11.6 use an + MPL-style Secondary License election for GPL 2.0 or later, LGPL 2.1 or + later, and AGPL 3.0 or later. The elected license controls conflicts and + incompatible reciprocal restrictions do not survive the election. Exhibit + B lets an adopter opt out. Confirm version-specific compatibility, + preservation of reasonable notices, and the deliberate GPL path around the + monetization trigger. +5. **Zero-day timing is intentional and per version.** Private non-monetized + development is allowed, but the period before the first Monetization Event + is the compliance window. Later publication restores rights only + prospectively under Sections 5.1 and 11.3(f). Confirm the condition-versus- + covenant framing and remedy consequences. +6. **The Monetization Event is broad and modifier-controlled.** It covers + transfers, hosted/network services, internal production, and later products + materially enabled by a modified tool. It has no revenue threshold and + exempts the activity categories stated in Section 11.1. Confirm the + copyright nexus, contract formation, preemption, causation, exhaustion, + education/media boundaries, and downstream-reseller treatment. 7. **The AI Coding Agent Notice is generic and mandatory.** Exhibit C and `LICENSE-AI-AGENT-INSTRUCTIONS.md` contain the same project-agnostic notice. Section 11.7(a) requires every adopter and source distributor to include a @@ -60,20 +67,33 @@ to, not a substitute for, attorney review. states that an automated agent is not made a contracting party or enforcement target and that its operating guidance adds no further condition. Confirm that distinction and every distribution path. -8. **Release-candidate status is explicit.** The current identifier is - `LicenseRef-FastLED-Reciprocal-1.0-rc2`; the final identifier remains gated. +8. **Release-candidate status and immutable versions are explicit.** The + current identifier is `LicenseRef-FastLED-Reciprocal-1.0-rc3`; the final + identifier remains gated. Section 10 permits verbatim copies only, defaults + adoption to the pinned version, and allows an adopter to opt into later + canonical versions. +9. **Upstream return is the operational objective.** Section 11.3 requires a + public pull request, public fork, or complete patch in the official project + mechanism when one is available. Complete Compliance Source covers only + the covered portion and its reconstruction/build material. Confirm the + continuing-availability rule, third-party-interference window, and + treatment of confidential or unlicensable material. ## Attorney checklist - the Section 10 distinction between canonical text publication and each - adopter's software ownership, licensing authority, and standing; + adopter's software ownership, licensing authority, standing, immutable + version selection, and verbatim-copy rule; - the Section 11.1 definitions of optional Upstream Repository, Modified - Covered Software, Triggering Transfer, and Publicly Available; + Covered Software, Compliance Source, Materially Enables, Monetization Event, + Official Reporting Location, and Publicly Available; - the Section 11.3 condition, duration, third-party-interference safe harbor, - prospective-only model, and project-specific separate-license valve; + upstream-first mechanisms, prospective-only model, and project-specific + separate-permission valve; - Section 2.7 condition scope and the *Jacobsen*/*MDY* condition-versus-covenant framing; -- the Exhibit B and GPL-incompatibility decision; +- the default Secondary-License compatibility rule, Exhibit B opt-out, and + GPL-conflict priority; - the modified Sections 1.4, 1.5, 1.8, 3.1, 3.3, 3.4, 4, 9, and 10 against MPL 2.0, including compliance with MPL Section 10.3; - Contributor copyright and patent grants and the requirement that each @@ -87,5 +107,5 @@ to, not a substitute for, attorney review. - Whether to modify Section 8's defendant-principal-place litigation rule. - Whether to add a BUSL/FSL-style sunset or reversion clause. - Whether unmodified MPL 2.0 plus a nonbinding upstreaming norm and - project-specific commercial licensing would better meet adopter goals than + project-specific separate permissions would better meet adopter goals than this bespoke instrument. diff --git a/LICENSE b/LICENSE index 9c4623d..785e0c7 100644 --- a/LICENSE +++ b/LICENSE @@ -28,7 +28,7 @@ __/\\\__________________________________________________________________________ _\///////////////__\///_____\////////____\//////////__\///____\///__\//////////____\//////////________________\///__\///_____\///////_____ ``` -FastLED Reciprocal License, Version 1.0-rc2 +FastLED Reciprocal License, Version 1.0-rc3 =========================================== This License is a modified version of the Mozilla Public License, Version @@ -45,14 +45,14 @@ Every adopting project must include a copy as described in Section 11.7. This License is reusable license text. A person with sufficient rights may apply it to any software by attaching the notice in Exhibit A. Publishing, maintaining, or copying this License does not itself make anyone a copyright -owner, licensor, commercial licensor, or enforcement claimant for software +owner, licensor, separate-permission grantor, or enforcement claimant for software that an adopting project places under it. The SPDX license identifier for this version is: - LicenseRef-FastLED-Reciprocal-1.0-rc2 + LicenseRef-FastLED-Reciprocal-1.0-rc3 -The "-rc2" suffix marks this text as a release candidate. The identifier +The "-rc3" suffix marks this text as a release candidate. The identifier without an "-rc" suffix is reserved for the reviewed and adopted text; see LEGAL-REVIEW.md in the license repository. @@ -66,27 +66,40 @@ and Exhibits control. * This License charges no fee for either commercial or non-commercial use. Distribution requirements still apply when You give copies to others. -* If your use is commercial, You may use Covered Software under this License - if: +* Unmodified Covered Software may be used commercially. The special public- + return condition in Section 11.3 applies only to Modified Covered Software. - * You make no Modifications. The special publication condition in Section - 11.3 does not apply to unmodified Covered Software, although the ordinary source - and notice requirements in Section 3 still apply when You distribute it; - or +* You may develop and evaluate Modified Covered Software privately before a + Monetization Event. On or before the first Monetization Event for each + modified version, You must return the complete Compliance Source for the + covered portion through the official upstream project as a public pull + request, public fork, or complete reproducible patch, as detailed in Section + 11.3. + +* Bona fide teaching, learning, scholarship, academic research, software + discussion, and media or social-media presentation are exempt as described + in Section 11.1. Selling usable Modified Covered Software or a product, + service, or deliverable materially enabled by it is not exempt merely + because the customer is an educational institution. - * You make Modifications and, on or before the first Triggering Transfer of - each modified version, publish the complete Modified Covered Software in a - public repository or publish a complete reproducible patch as a public - bug report, as detailed in Section 11.3. +* Unless an adopter attaches Exhibit B, Covered Software may be combined with + the named GPL-family Secondary Licenses under Section 3.3. A recipient who + elects a Secondary License follows that license where its terms conflict + with this License, while preserving applicable license and provenance + notices. -* A separate commercial license, waiver, or settlement can come only from the - applicable software rights holders or their authorized representative. The - repository that publishes this License text does not supply that authority. +* Separate written permission can come only from the applicable software + rightsholders or their authorized representative. No rightsholder is + required to offer it, and the repository that publishes this License text + does not supply that authority. -When an adopting project identifies an Upstream Repository: +When an adopting project identifies an Upstream Repository and Official +Reporting Location: * Fork that Upstream Repository. * Make Your Covered Software changes in that public fork. +* Submit the complete covered delta through the designated public project + mechanism no later than the first Monetization Event. 1. Definitions -------------- @@ -219,7 +232,8 @@ addressed in Section 11.5. No Contributor makes additional grants as a result of Your choice to distribute the Covered Software under a subsequent version of this -License (see Section 10.2). +License, if the initial Contributor has permitted that choice under +Section 10.2. 2.5. Representation @@ -273,10 +287,14 @@ If You distribute Covered Software in Executable Form then: You may create and distribute a Larger Work under terms of Your choice, provided that You also comply with the requirements of this License for -the Covered Software. The Covered Software is Incompatible With -Secondary Licenses (see Sections 1.5 and 11.6), and this License does -not permit You to distribute the Covered Software under the terms of any -Secondary License. +the Covered Software. If the Larger Work is a combination of Covered +Software with a work governed by one or more Secondary Licenses, and the +Covered Software is not Incompatible With Secondary Licenses, this License +permits You to additionally distribute such Covered Software under the terms +of such Secondary License or Licenses, so that a recipient of the Larger Work +may, at its option, further distribute the Covered Software under the terms of +either this License or such Secondary License or Licenses. Section 11.6 +controls conflicts following that election. 3.4. Notices @@ -320,25 +338,25 @@ regulation, such description must be sufficiently detailed for a recipient of ordinary skill to be able to understand it. A private contractual obligation of confidentiality is not a statute, judicial order, or regulation for the purposes of this Section; see Section -11.3(g) for the separate-license alternative. +11.3(g) for the separate-permission alternative. 5. Termination -------------- -5.1. The rights granted under this License will terminate automatically -if You fail to comply with any of its terms. However, if You become -compliant, then the rights granted under this License from a particular -Contributor are reinstated (a) provisionally, unless and until such -Contributor explicitly and finally terminates Your grants, and (b) on an -ongoing basis, if such Contributor fails to notify You of the -non-compliance by some reasonable means prior to 60 days after You have -come back into compliance. Moreover, Your grants from a particular -Contributor are reinstated on an ongoing basis if such Contributor -notifies You of the non-compliance by some reasonable means, this is the -first time You have received notice of non-compliance with this License -from such Contributor, and You become compliant prior to 30 days after -Your receipt of the notice. Reinstatement under this Section is -prospective only; see Section 11.3(f). +5.1. The rights granted under this License will terminate automatically if You +fail to comply with any of its terms. For a first, non-willful non-compliance +with respect to a particular Contributor, Your rights from that Contributor +are reinstated provisionally when You become compliant. That reinstatement +becomes ongoing if (a) the Contributor does not notify You of the non- +compliance by reasonable means within sixty (60) days after You become +compliant, or (b) the Contributor notifies You and You become compliant within +thirty (30) days after receiving the notice. If You were already compliant +when notice arrived, the thirty-day requirement is satisfied. After a repeat +violation following such notice, or after a willful violation, Your rights +remain terminated unless the affected Contributor expressly reinstates them +in writing. Reinstatement is prospective only and does not release liability +or remedies for acts that occurred while Your rights were terminated; see +Section 11.3(f). 5.2. If You initiate litigation against any entity by asserting a patent infringement claim (excluding declaratory judgment actions, @@ -428,25 +446,32 @@ repository at https://github.com/FastLED/license. Each version will be given a distinguishing version number. The maintainers of that repository perform a text-publication and versioning role only. That role does not, by itself, make any maintainer a Contributor, copyright owner, licensor, -commercial licensor, beneficiary, or enforcement claimant for Covered +separate-permission grantor, beneficiary, or enforcement claimant for Covered Software. An adopting project need not identify an owner of this License text. 10.2. Effect of New Versions -You may distribute the Covered Software under the terms of the version -of the License under which You originally received the Covered Software, -or under the terms of any subsequent canonical version published in the -license-text repository identified in Section 10.1. +The initial Contributor must state, in or with the Exhibit A notice, whether +the Covered Software is offered under this version only or under this version +or any later canonical version. If the statement is omitted, the offer is +under this version only. If the initial Contributor permits later versions, +You may distribute the Covered Software under the terms of the version under +which You originally received it or any subsequent canonical version +published in the license-text repository identified in Section 10.1. A later +version does not retroactively alter a grant already made under an earlier +version. 10.3. Modified Versions -If you create software not governed by this License, and you want to -create a new license for such software, you may create and use a -modified version of this License if you rename the license and remove -references that could imply that the modified text is a canonical FastLED -Reciprocal License or is published by the repository identified in Section -10.1 (except to note that the modified license differs from this License). +Permission is granted to copy and distribute verbatim copies of this License. +Changing this License document is not permitted under this License. Separately +authored terms must use a different name and must not state or imply that they +are a canonical FastLED Reciprocal License or were published by the repository +identified in Section 10.1. This restriction does not prevent anyone from +using the unmodified Mozilla Public License under its terms, independently +drafting another license, or using ideas and other material not protected by +copyright. 10.4. Distributing Source Code Form that is Incompatible With Secondary Licenses @@ -470,6 +495,13 @@ identify a successor location in that repository. This definition does not give the repository maintainers any ownership, licensing, or enforcement authority they do not otherwise possess. +"Official Reporting Location" means the public pull-request or issue-reporting +location, if any, that the initial Contributor identifies in or with the +Exhibit A notice for submission of Modifications. An adopting project may +identify a successor location through the Upstream Repository. This definition +does not give the location or its maintainers any ownership, licensing, or +enforcement authority they do not otherwise possess. + "Modified Covered Software" means Covered Software containing Modifications as defined in Section 1.10. It does not include separate files of a Larger Work that do not contain or derive from Covered Software. @@ -477,37 +509,70 @@ Each distinct version or state is a separate body of Modified Covered Software for the purposes of Section 11.3; publication of one version does not satisfy Section 11.3 for another version. -"Triggering Transfer" means any transfer to a third party, for monetary -or other valuable consideration, of a version of Modified Covered Software, -or of software, firmware, or hardware embodying that version, where the -transfer is made by, or with the authorization of, the person that -created or commissioned the Modifications in that version. A Triggering -Transfer also occurs when a version of Modified Covered Software is made -available at no charge in connection with a product, device, or service -for which the person that created or commissioned the Modifications, or -its licensee, receives monetary or other valuable consideration. The -following are not Triggering Transfers: - -(a) a transfer between entities that together constitute "You" under - Section 1.14; - -(b) a transfer by a manufacturer or assembler acting on the instruction - of, and delivering exclusively to, the person that commissioned the - Modifications; - -(c) a lease or rental of a device that does not convey a copy of the - Modified Covered Software Source Code Form or Executable Form to the lessee - beyond the copy embedded in the device, where the lessor retains - ownership of the device; and - -(d) a subsequent sale, resale, or other transfer by a distributor, - retailer, reseller, or other person who neither created nor - commissioned the Modifications; such a person incurs no obligation - under Section 11.3 by reason of that transfer alone. - -Use of Modified Covered Software to provide a service over a network, without a -transfer of a copy, is not a Triggering Transfer; Sections 3.1 and 3.2 -continue to apply to any distribution that does occur. +"Compliance Source" means the complete Source Code Form of Modified Covered +Software, together with the scripts, configuration templates, build +instructions, and identities and versions of dependencies reasonably necessary +to reconstruct and build the covered portion. Compliance Source does not +include independent files of a Larger Work, credentials, private keys, +personal data, security secrets, or third-party material that You do not have +the right to publish. An exclusion does not permit omission or redaction of +Covered Software. Excluded dependencies must still be accurately identified, +and confidential or separately licensed material must be separated from +Covered Software or separately authorized. + +"Materially Enables" means that Modified Covered Software performs a +substantial and non-incidental role in developing, producing, operating, or +delivering a product, device, software offering, service, access arrangement, +or contracted deliverable. It includes a modified tool used to develop or +produce a later monetized offering even if use of the tool stops before the +offering is sold. It excludes trivial administrative, background, or merely +incidental use. + +"Monetization Event" means an event in which You, or a person acting under +Your authority, receive or become entitled to monetary or other valuable +consideration from any of the following involving a version of Modified +Covered Software that You created, commissioned, or control: + +(a) selling, licensing, leasing, renting, or otherwise transferring that + version or a product, device, software offering, or other deliverable + embodying that version; + +(b) providing a paid, sponsored, advertising-supported, customer-facing, + hosted, or network service that the version Materially Enables, whether or + not a copy is transferred to a customer; + +(c) using the version privately or internally where it Materially Enables the + development, production, operation, or delivery of a monetized product, + device, service, or deliverable; or + +(d) receiving funding tied to a specific product, service, deliverable, or + access arrangement that the version Materially Enables. + +The amount of consideration does not matter. The following are not +Monetization Events: + +(i) private, non-monetized development, experimentation, or internal + evaluation; + +(ii) bona fide teaching, learning, scholarship, academic research, + classroom demonstration, or public discussion, review, or depiction of + the software in social media or other media, even when an institution + charges tuition, participants receive salaries, or the activity receives + general sponsorship or advertising revenue, provided the activity does + not sell or provide for consideration usable Modified Covered Software, + access to it, or a non-educational commercial product, service, or + deliverable that it Materially Enables; and + +(iii) unrestricted donations, scholarships, or general grants that are not + tied to a specific product, service, deliverable, or access arrangement. + +A transfer between entities that together constitute You under Section 1.14, +or to a contractor acting exclusively on Your behalf, is not by itself a +Monetization Event, but the later monetized activity it supports may be. A +downstream resale by a distributor, retailer, or reseller that neither +created, commissioned, nor controls the Modifications does not create a new +Section 11.3 obligation by itself; Sections 3.1 and 3.2 continue to govern any +distribution that occurs. "Publicly Available" means accessible at a stable URL, without payment, login, invitation, allow-listing, approval step, or any other special @@ -531,82 +596,96 @@ Software under Section 1.4. 11.3. Public Availability Condition -(a) Condition. You may reproduce and distribute a version of Modified - Covered Software only if, on or before the date of the earliest Triggering - Transfer of that version (measured in the time zone of Your - principal place of business), the complete Source Code Form of that - version is Publicly Available through at least one of the mechanisms - in Section 11.3(c). This condition applies separately to each - version. The development period before a Triggering Transfer is the - time in which to establish compliance; there is no compliance - period after a Triggering Transfer, and Section 11.3(f) governs the - consequences of a Triggering Transfer that precedes publication. +(a) Condition. You may use, reproduce, modify, or distribute a version of + Modified Covered Software in connection with a Monetization Event only if, + on or before the date of the earliest Monetization Event for that version + (measured in the time zone of Your principal place of business), its + complete Compliance Source is Publicly Available through a mechanism in + Section 11.3(c). This is a condition of the copyright permission granted + for those acts, applies separately to each version involved in a + Monetization Event, and does not claim an exclusive copyright right over + conduct that applicable law permits without a license. The private, + non-monetized development period is the time in which to establish + compliance. Section 11.3(f) governs a Monetization Event that precedes + publication. (b) Standing compliance. If You develop Modified Covered Software in a repository that is Publicly Available at all times from the start of - development through the date of a Triggering Transfer, and that + development through the date of a Monetization Event, and that repository identifies the exact upstream source, commit, or release from which the work is derived, You satisfy this Section for every - version contained in that repository as of that date, with nothing - further required. - -(c) Mechanisms. The Source Code Form is made Publicly Available by: - - (i) Public repository. Publishing the complete Source Code Form of - the version in a Publicly Available Git repository that - identifies the exact upstream source, commit, or release from which - it was derived. A public fork of the Upstream Repository, if one is - identified, is a preferred location; any equivalent Publicly - Available Git repository is sufficient. - - (ii) Public patch. Publishing a report that identifies the exact - upstream source version or commit identifier used as the base and - contains a complete patch or unified diff against that base, - together with a short description of the modification. The base and - patch must be sufficient to reconstruct the complete Source Code - Form of the version deterministically. A public issue in the - Upstream Repository or another reporting location identified with - the Covered Software is a preferred location; a Publicly Available - location under Your control is equally sufficient. - -(d) Duration. Source Code Form published under this Section must remain - Publicly Available for at least three (3) years after the last - Triggering Transfer of that version, and in any event for as long as - You distribute the Executable Form of that version. - -(e) Third-party interference. If a submission made under Section - 11.3(c)(ii) to the Upstream Repository or another project-designated - location is rejected, blocked, removed, or rendered inaccessible by a - person other than You, or if that location or its hosting platform is - unavailable to You for reasons outside Your control, You remain - compliant if You republish the same material in a Publicly Available - location under Your control within thirty (30) days of becoming - aware of the interference or unavailability. No act or omission of the - license-text repository, an Upstream Repository, or their maintainers - places You in breach of this Section by itself. + version whose complete Compliance Source is contained in that repository + as of that date, subject to the upstream-first rule in Section 11.3(c). + +(c) Upstream-first mechanisms. If a usable Upstream Repository or Official + Reporting Location has been identified, You must use at least one of the + following official-project mechanisms: + + (i) Public pull request. Submitting a public pull request to the Upstream + Repository that independently preserves the complete Compliance + Source or a complete reconstructable delta against an exact upstream + commit. + + (ii) Public fork. Publishing the complete Compliance Source in a Publicly + Available fork of the Upstream Repository that identifies the exact + upstream commit or release from which it was derived. + + (iii) Public patch report. Publishing at the Official Reporting Location a + public report that identifies the exact upstream commit or release + used as the base and contains a complete patch or unified diff, + together with a short description of the Modifications. The base and + patch must reconstruct the complete Compliance Source deterministically. + + If no usable Upstream Repository or Official Reporting Location is + available, You may instead publish the same material at another Publicly + Available location. Convenience alone does not permit bypassing an + available official-project mechanism. + +(d) Continuing availability. You must not intentionally withdraw, delete, or + render inaccessible Compliance Source published under this Section. The + obligation is satisfied while the complete material remains Publicly + Available in an official upstream commit, pull request, or report, whether + the pull request or report is open or closed. You may remove a public fork + after submitting a pull request only if the pull request independently + preserves the complete reconstructable material. You may also remove a + fork after all Modifications are merged into the Upstream Repository. If + only part of the Modifications is merged, the unmerged delta must remain + Publicly Available through another compliant mechanism. + +(e) Third-party interference. If a submission made under Section 11.3(c) is + blocked, removed, or rendered inaccessible by a person other than You, is + rejected in a manner that prevents the complete material from remaining + Publicly Available, or if the official location or its hosting platform + becomes unavailable for reasons outside Your control, You remain compliant + if You republish the same complete material at another Publicly Available + location within thirty (30) days after becoming aware of the interference + or unavailability. Rejection or closure does not require republication + while the complete material remains Publicly Available. There is no breach + during that outside-control window. No act or omission of the license-text + repository, an Upstream Repository, an Official Reporting Location, or + their maintainers places You in breach by itself. (f) Timing and consequences. Section 5.1 applies to any failure to - satisfy this Section. Publication after the date of a Triggering - Transfer does not retroactively authorize any reproduction or - distribution that occurred before publication: copies of the version - reproduced or transferred while this Section was unsatisfied were - not licensed under Section 2.1(a) when made or transferred, and - later publication does not change that. Publication does restore - Your rights prospectively, subject to Section 5.1. - -(g) Separate license. This Section does not apply to acts separately - authorized by a written license from every Contributor whose permission - is necessary for those acts, or from a person authorized to license those - Contributions. Publishing or maintaining this License text supplies no - such authority. + satisfy this Section. Publication after the date of a Monetization Event + does not retroactively authorize any licensed act that occurred in + connection with that event while this Section was unsatisfied. Later + publication restores rights only prospectively, subject to Section 5.1; + it does not release claims or remedies for earlier unlicensed acts. + +(g) Separate permission. This Section does not apply to acts separately + authorized in writing by every rightsholder whose permission is necessary + for those acts, or by a person or entity authorized to grant that + permission. No rightsholder is required to offer separate permission, and + publishing or maintaining this License text supplies no such authority. (h) Relationship to Sections 3.1 and 3.2. This Section is in addition to, and does not replace, Your obligations under Sections 3.1 and 3.2. Publication under Section 11.3(c)(i) satisfies Section 3.2(a) - with respect to the Modified Covered Software if You inform recipients of the - Executable Form of the location of the published Source Code Form. - Publication under Section 11.3(c)(ii) does not by itself satisfy - Section 3.2(a). + with respect to Modified Covered Software only if the pull request + provides the Source Code Form required by Section 3.2(a) and You inform + recipients of its location. A public fork or patch satisfies Section + 3.2(a) only when the disclosed material and recipient notice independently + meet that Section. 11.4. No Relicensing of Earlier Releases @@ -632,10 +711,16 @@ assertion of other trademark rights. 11.6. Secondary Licenses -The initial Contributor attaches the notice in Exhibit B to all Covered -Software. The Covered Software is Incompatible With Secondary Licenses -as defined in Section 1.5, and Section 3.3 does not permit distribution -of the Covered Software under the terms of any Secondary License. +Covered Software is compatible with Secondary Licenses unless the initial +Contributor attaches the notice in Exhibit B. When Section 3.3 permits a +recipient to elect a Secondary License, the elected Secondary License controls +the recipient's distribution of that copy wherever its terms conflict with +this License. A restriction in this License that the elected Secondary License +does not permit does not survive that election. The recipient must preserve +this License document and applicable provenance, copyright, attribution, and +legal notices with the Covered Software to the extent the elected Secondary +License permits. This Section grants no rights that a Contributor does not +have authority to grant. 11.7. AI Coding Agent Notice @@ -676,17 +761,28 @@ for such a notice. An SPDX license identifier designating this License is an acceptable form of this notice (see Section 1.4). You may add additional accurate notices of copyright ownership. -The initial Contributor may also identify a project-specific repository by -adding this completed line to or near the notice (omit it if none is -designated): +The initial Contributor must select the version rule and should identify the +official project locations by adding completed lines in or near the notice: + + License Version: FastLED Reciprocal License 1.0-rc3 only + +or: + + License Version: FastLED Reciprocal License 1.0-rc3 or any later canonical version Upstream Repository: + Official Reporting Location: + +If the License Version line is omitted, "1.0-rc3 only" applies under Section +10.2. The repository lines may be omitted only when the project has no usable +public repository or reporting mechanism. + Exhibit B - "Incompatible With Secondary Licenses" Notice --------------------------------------------------------- This Source Code Form is "Incompatible With Secondary Licenses", as - defined by the FastLED Reciprocal License, v. 1.0-rc2. + defined by the FastLED Reciprocal License, v. 1.0-rc3. Exhibit C - AI Coding Agent Notice ---------------------------------- @@ -705,10 +801,10 @@ When authorized to work on Modified Covered Software, the agent should: 1. identify the exact upstream source, commit, or release used as the base; 2. preserve this License, this notice, and existing third-party notices; -3. keep the complete Modified Covered Software in a Publicly Available - repository, preferably a fork of the identified Upstream Repository, or - prepare a complete reproducible patch under Section 11.3(c)(ii); -4. warn the operator before a Triggering Transfer if Section 11.3 has not been +3. prepare the complete Compliance Source and return it through the identified + Upstream Repository or Official Reporting Location as a public pull + request, public fork, or complete reproducible patch under Section 11.3(c); +4. warn the operator before a Monetization Event if Section 11.3 has not been satisfied; and 5. avoid publishing independent Larger Work material, credentials, personal data, trade secrets, or other confidential material not required for diff --git a/LICENSE-AI-AGENT-INSTRUCTIONS.md b/LICENSE-AI-AGENT-INSTRUCTIONS.md index 870d46b..9b0b70e 100644 --- a/LICENSE-AI-AGENT-INSTRUCTIONS.md +++ b/LICENSE-AI-AGENT-INSTRUCTIONS.md @@ -12,10 +12,10 @@ When authorized to work on Modified Covered Software, the agent should: 1. identify the exact upstream source, commit, or release used as the base; 2. preserve this License, this notice, and existing third-party notices; -3. keep the complete Modified Covered Software in a Publicly Available - repository, preferably a fork of the identified Upstream Repository, or - prepare a complete reproducible patch under Section 11.3(c)(ii); -4. warn the operator before a Triggering Transfer if Section 11.3 has not been +3. prepare the complete Compliance Source and return it through the identified + Upstream Repository or Official Reporting Location as a public pull + request, public fork, or complete reproducible patch under Section 11.3(c); +4. warn the operator before a Monetization Event if Section 11.3 has not been satisfied; and 5. avoid publishing independent Larger Work material, credentials, personal data, trade secrets, or other confidential material not required for diff --git a/NOTICE-TEMPLATE-MIT-LEGACY.txt b/NOTICE-TEMPLATE-MIT-LEGACY.txt index c2695a7..4a8449a 100644 --- a/NOTICE-TEMPLATE-MIT-LEGACY.txt +++ b/NOTICE-TEMPLATE-MIT-LEGACY.txt @@ -1,5 +1,8 @@ -// SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc2 +// SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc3 // AI-Notice: LICENSE-AI-AGENT-INSTRUCTIONS.md (required by LICENSE Section 11.7) +// License Version: FastLED Reciprocal License 1.0-rc3 only +// Upstream Repository: +// Official Reporting Location: // Portions Copyright (c) FastLED contributors, originally licensed under // the MIT License; see LICENSE-MIT-LEGACY. Those portions remain available // under the MIT License from their respective authors. diff --git a/NOTICE-TEMPLATE.txt b/NOTICE-TEMPLATE.txt index dbd9128..79beeed 100644 --- a/NOTICE-TEMPLATE.txt +++ b/NOTICE-TEMPLATE.txt @@ -1,2 +1,5 @@ -// SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc2 +// SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc3 // AI-Notice: LICENSE-AI-AGENT-INSTRUCTIONS.md (required by LICENSE Section 11.7) +// License Version: FastLED Reciprocal License 1.0-rc3 only +// Upstream Repository: +// Official Reporting Location: diff --git a/PROVENANCE.md b/PROVENANCE.md index 58ec7ea..f81bb0f 100644 --- a/PROVENANCE.md +++ b/PROVENANCE.md @@ -11,9 +11,12 @@ `LICENSE` is a **modified version** of this text, created under the permission in MPL 2.0 Section 10.3. It is renamed, adds the Reciprocal Terms as Section 11, and adapts Sections 1.4, 1.5, 1.8, 2.3, 2.4, 2.7, 3.1, 3.3, -3.4, 3.5, 4, 5.1, 9, 10.1-10.3, and all three Exhibits. `MPL-2.0.txt` is retained -solely so reviewers can diff the modified instrument against the unmodified -base; it is not part of the license and is not incorporated by reference. +3.4, 3.5, 4, 5.1, 9, 10.1-10.3, and all three Exhibits. `MPL-2.0.txt` is +retained solely so reviewers can diff the modified instrument against the +unmodified base; it is not part of the license and is not incorporated by +reference. FastLED Reciprocal License 1.0-rc3 permits verbatim copying of its +canonical text but does not grant permission to publish altered text as a +FastLED Reciprocal License. The canonical repository publishes reusable text. Its maintainers do not gain ownership or licensing authority over software merely by maintaining this @@ -27,7 +30,8 @@ research records must cite an immutable commit rather than `main`. | Version | Immutable source | SHA-256 of `LICENSE` | Git blob | |---|---|---|---| | 1.0-rc1 | [`40ee7108f4b46b6b8fb1976f5c8b3cd996bdfb42`](https://github.com/FastLED/license/blob/40ee7108f4b46b6b8fb1976f5c8b3cd996bdfb42/LICENSE) | `796cef1d065c002d315c54396554eb7ec8370508a8e8603eb854d565f439739f` | `01e0e8f0586888866bed9e83419e6135129fa248` | -| 1.0-rc2 | Current working draft; record the merged commit and digest before treating it as an immutable authority | pending | pending | +| 1.0-rc2 | [`e994509b79e1daf6c8ed268f0482cc1709b4043b`](https://github.com/FastLED/license/blob/e994509b79e1daf6c8ed268f0482cc1709b4043b/LICENSE) | `a42aa7bb2925ba62054e14d6f4b32b2d1358270f0ac61cd7ec753a1ac00db7eb` | `9c4623d9a3dec259f265f9f52d0fd00fca04cb88` | +| 1.0-rc3 | [`8a92a8739f337c5a47e2ca8409b602d41c8c3d6e`](https://github.com/FastLED/license/blob/8a92a8739f337c5a47e2ca8409b602d41c8c3d6e/LICENSE) | `c46471504fd976d1e3693506d13b1d8c3bc25dca94c333736cb431b647692d67` | `785e0c70502ab45127cdb892332c910099b1678a` | ## Ripgrep diff --git a/README.md b/README.md index 2fb95ac..aaa0537 100644 --- a/README.md +++ b/README.md @@ -6,8 +6,8 @@ general-purpose instrument that may be applied to software from any project. It is not limited to the FastLED codebase. > [!IMPORTANT] -> The current text is release candidate `1.0-rc2`, identified as -> `LicenseRef-FastLED-Reciprocal-1.0-rc2`. It is preliminary legal drafting, +> The current text is release candidate `1.0-rc3`, identified as +> `LicenseRef-FastLED-Reciprocal-1.0-rc3`. It is preliminary legal drafting, > is not OSI-approved, and has not completed the attorney gate in > `LEGAL-REVIEW.md`. The identifier without an `-rc` suffix is reserved for a > reviewed release. @@ -17,7 +17,7 @@ It is not limited to the FastLED codebase. The license does not require a universal "owner." Zachary Vorhies currently maintains the canonical license-text repository and its version history. That text-maintenance role does not make Zach, FastLED, or this repository the -owner, commercial licensor, or enforcement claimant for software that another +owner, separate-permission grantor, or enforcement claimant for software that another project places under the license. The roles are intentionally separate: @@ -26,7 +26,7 @@ The roles are intentionally separate: |---|---| | Canonical text maintainer | Publishes and versions the reusable license text | | Adopting rights holder or Contributor | Applies the license and grants rights in its Contributions | -| Commercial licensor | Grants a separate license only when independently authorized for the relevant software | +| Separate-permission grantor | Grants separate written permission only when independently authorized for the relevant software | | Enforcement claimant | Enforces only rights or promises for which it has the required ownership, authorization, or standing | Publishing or copying `LICENSE` does not transfer software copyrights or @@ -35,22 +35,44 @@ appoint the text maintainer to enforce an adopter's code. ## Design The license is one self-contained instrument derived from Mozilla Public -License 2.0 under MPL Section 10.3. It preserves a file-level Covered Software -boundary and adds a commercial-transfer condition: when a person commercially -transfers a modified version, the complete Modified Covered Software must -already be publicly available through a repository or reproducible patch. -Independent files in a Larger Work may remain proprietary under Section 11.2. - -An adopting project may identify its own optional **Upstream Repository** in -or with the Exhibit A notice. That project-specific designation does not alter -the canonical license text and does not make the repository maintainer a -rights holder. - -A separate commercial license is optional and project-specific. Section -11.3(g) recognizes only written authorization from the Contributors whose -permission is needed, or from someone independently authorized to license -their Contributions. The canonical license repository cannot sell exceptions -for third-party software merely because it publishes this text. +License 2.0 under MPL Section 10.3. It is a monetization-triggered reciprocal +open-source license that is not OSI-approved. It preserves a file-level +Covered Software boundary: independent files in a Larger Work may remain +proprietary under Section 11.2. + +The license's mission is to return privately maintained improvements to the +official source project when those improvements materially enable non-exempt +monetization. Before the first Monetization Event for each modified version, +the modifier must publish the Compliance Source for the covered portion +through the official upstream project as a public pull request, public fork, +or complete reproducible patch. Genuine educational, scholarly, media, and +unrestricted-donation activities are exempt under the exact boundaries in +Section 11.1. + +An adopting project identifies its **Upstream Repository** and **Official +Reporting Location** in or with the Exhibit A notice. Those project-specific +designations do not alter the canonical license text and do not make either +repository's maintainer a rights holder. + +Separate written permission is optional and project-specific. Section 11.3(g) +recognizes only written authorization from all necessary software +rightsholders or their authorized licensing entity. No one is required to +offer that permission, and the canonical license repository cannot grant +exceptions for third-party software merely because it publishes this text. + +GPL-family compatibility is enabled by default through the MPL-style +Secondary License mechanism. If a recipient validly elects GPL 2.0 or later, +LGPL 2.1 or later, or AGPL 3.0 or later, the elected license controls where its +terms conflict with this license. The FastLED license and applicable provenance +notices travel with the covered code to the extent the elected license permits. +An adopter may instead attach Exhibit B to opt out of Secondary Licenses. + +Each canonical version is immutable. Verbatim copying is permitted, but the +license text may not be altered and still presented as the FastLED Reciprocal +License. An adopter selects either the pinned version only or that version or +later; omission defaults to the pinned version only. A software rightsholder +who wants different terms publishes a separately licensed release or fork +without changing grants already made for earlier releases. The generic `LICENSE-AI-AGENT-INSTRUCTIONS.md` notice is part of the license and must be included by every adopting project under Section 11.7(a). The @@ -83,15 +105,16 @@ party or independently subject to damages. the license have sufficient rights in the software they are offering. 2. Copy an immutable reviewed license release into the adopting repository. 3. Attach the Exhibit A notice or the corresponding SPDX identifier to the - Covered Software. The optional Upstream Repository line may point to that - project's own public repository. + Covered Software. Record whether the adoption is this version only or this + version or later, plus the project's Upstream Repository and Official + Reporting Location. 4. Include `LICENSE-AI-AGENT-INSTRUCTIONS.md` as the complete generic Exhibit C notice. It is required for every adopting project, whether or not that project expects AI-assisted development. 5. Preserve third-party notices and licenses. Do not overwrite separately licensed or generated material with a project-wide header. -6. If the project offers commercial licenses, publish its own contact and - authorization process separately from the canonical license text. +6. If the project offers separate written permissions, publish its own contact + and authorization process separately from the canonical license text. No change to the FastLED software repository is necessary to draft, publish, study, or use this license text. FastLED remains under its existing license diff --git a/ai-policy.toml b/ai-policy.toml index b1e1c17..2651ba4 100644 --- a/ai-policy.toml +++ b/ai-policy.toml @@ -16,22 +16,31 @@ agent_guidance_adds_license_conditions = false authorization_required_before_publication = true [upstream_report] -repository_source = "Exhibit A Upstream Repository, when identified" -mechanisms = ["public-repository", "public-reproducible-patch"] +repository_source = "Exhibit A Upstream Repository and Official Reporting Location" +mechanisms = ["public-pull-request", "public-fork", "public-reproducible-patch"] patch_format = "complete-patch-against-exact-base" required_fields = [ "base_source_or_commit", - "complete_patch_or_source", + "complete_compliance_source_or_patch", "description", ] optional_fields = ["target_platform", "reproduction", "tests"] +[monetization] +trigger = "monetization-event-involving-modified-covered-software" +disclosure_deadline = "on-or-before-first-event-for-each-version" +upstream_first = true +revenue_threshold = "none" +private_nonmonetized_development_allowed = true + [scope] applies_to = "modified-covered-software" excluded = [ "independent-larger-work-files", "credentials", + "private-keys", "personal-data", - "trade-secrets", + "security-secrets", + "unlicensable-third-party-material", "confidential-material-not-required-for-compliance", ] diff --git a/header-policy.toml b/header-policy.toml index 3af137d..363bb6c 100644 --- a/header-policy.toml +++ b/header-policy.toml @@ -2,13 +2,14 @@ schema_version = 1 old_license_ids = [ "LicenseRef-FastLED-Reciprocal-1.0", "LicenseRef-FastLED-Reciprocal-1.0-rc1", + "LicenseRef-FastLED-Reciprocal-1.0-rc2", ] [license] -id = "LicenseRef-FastLED-Reciprocal-1.0-rc2" -header_version = 3 +id = "LicenseRef-FastLED-Reciprocal-1.0-rc3" +header_version = 4 ai_document = "LICENSE-AI-AGENT-INSTRUCTIONS.md" -ai_document_sha256 = "07b4400299f67dad4bf49de5f3e2ee5c19daf2d95fc0800e0e07987993c66a13" +ai_document_sha256 = "51a0ef022d3ade2ff0b7412aff9db9d33adc954d9dbfb0402c11037ad6bf7603" [profiles.release] roots = ["src"] diff --git a/tests/test_license_headers.py b/tests/test_license_headers.py index fa741ae..393440d 100644 --- a/tests/test_license_headers.py +++ b/tests/test_license_headers.py @@ -15,7 +15,7 @@ def write_policy( root: Path, *, old_ids: tuple[str, ...] = (), - license_id: str = "LicenseRef-FastLED-Reciprocal-1.0-rc2", + license_id: str = "LicenseRef-FastLED-Reciprocal-1.0-rc3", ai_document: str = "LICENSE-AI-AGENT-INSTRUCTIONS.md", ) -> subject.Policy: policy_path = root / "header-policy.toml" @@ -73,7 +73,7 @@ def test_bom_shebang_encoding_and_mode_are_preserved(tmp_path: Path) -> None: assert subject.update_file(subject.classify(source, policy), policy) updated = source.read_bytes() assert updated.startswith(subject.UTF8_BOM + b"#!/usr/bin/env python3\n# coding: utf-8\n") - assert b"# SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc2" in updated + assert b"# SPDX-License-Identifier: LicenseRef-FastLED-Reciprocal-1.0-rc3" in updated if os.name != "nt": assert stat.S_IMODE(source.stat().st_mode) == 0o744 @@ -281,15 +281,26 @@ def test_artifact_manifest_matches_files() -> None: assert hashlib.sha256((root / relative).read_bytes()).hexdigest() == expected -def test_rc2_identifiers_and_agent_notice_are_consistent() -> None: +def test_rc3_identifiers_and_agent_notice_are_consistent() -> None: root = Path(__file__).parents[1] license_text = (root / "LICENSE").read_text(encoding="utf-8") - license_id = "LicenseRef-FastLED-Reciprocal-1.0-rc2" - assert "FastLED Reciprocal License, Version 1.0-rc2" in license_text + license_id = "LicenseRef-FastLED-Reciprocal-1.0-rc3" + assert "FastLED Reciprocal License, Version 1.0-rc3" in license_text assert license_id in license_text - assert 'defined by the FastLED Reciprocal License, v. 1.0-rc2.' in license_text + assert 'defined by the FastLED Reciprocal License, v. 1.0-rc3.' in license_text + assert '"Monetization Event" means' in license_text + assert "Triggering Transfer" not in license_text + assert "Public pull request." in license_text + assert "Public fork." in license_text + assert "Public patch report." in license_text + assert "A restriction in this License that the elected Secondary License" in license_text + assert "Changing this License document is not permitted under this License" in license_text for name in ("NOTICE-TEMPLATE.txt", "NOTICE-TEMPLATE-MIT-LEGACY.txt"): - assert license_id in (root / name).read_text(encoding="utf-8") + template = (root / name).read_text(encoding="utf-8") + assert license_id in template + assert "License Version: FastLED Reciprocal License 1.0-rc3 only" in template + assert "Upstream Repository: " in template + assert "Official Reporting Location: " in template policy = subject.load_policy(root / "header-policy.toml", "release") assert policy.license_id == license_id