Skip to content

fix(supply-chain): separate MIT and bundled-font licenses - #270

Draft
seonghobae wants to merge 14 commits into
codex/fix-python-boundary-coveragefrom
fix/license-detection-269
Draft

seonghobae wants to merge 14 commits into
codex/fix-python-boundary-coveragefrom
fix/license-detection-269

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Current exact-head integration update

This section supersedes mutable head/check statements from earlier branch snapshots.

  • Current exact Draft head: face112af438c023ff256600e04c26afd6a175ea.
  • This Draft is stacked on proposed prerequisite feat: prepare TipTap 3 migration and restore Python matrix #402 at exact parent f1906d5c97915f522742c4cfa4b69fb8900a27a1, not on an unprotected copy of owner code.
  • The branch preserves the complete prior fix(supply-chain): separate MIT and bundled-font licenses #270 history plus current feat: prepare TipTap 3 migration and restore Python matrix #402 ancestry. The review repair is an ordinary fast-forward child of 846c6d318dbf4ccaab0c8707a36a698f679e7ee5; no force update or destructive rebase was used.
  • Relative to that exact parent, this head is ahead 14 / behind 0 with the parent as merge base. The effective child delta remains exactly two paths: root LICENSE and src/licenseBoundary.test.ts.
  • Root LICENSE is exact canonical MIT text. Existing Noto Sans attribution and complete OFL-1.1 terms remain separately in src/fonts/NOTICE and src/fonts/OFL.txt. The npm manifest remains license: MIT and packages both root LICENSE and src/fonts. This does not change or invent rights.
  • The real npm tarball test now extracts and compares the packed MIT LICENSE, font NOTICE, and OFL bytes against their authoritative source files. The complete source and packed OFL are independently pinned to canonical SHA-256 eb7f35eae6a733ac55711f933739502c635f98eb19fa7788af92ed83dc3e10f5, so a header-only or truncated license fails closed.
  • npm pack, tar listing, and each tar extraction have direct 30-second subprocess timeouts with SIGKILL; the outer test ceiling is 65 seconds so stalled synchronous children fail before the test runner ceiling.
  • Fresh exact-tree evidence: focused license tests passed 4/4. The full suite passed 157 files / 894 tests with exactly 100% statements (2329/2329), branches (1539/1539), functions (453/453), and lines (2147/2147). TypeScript and every production bundle built; all independent packed-consumer verifiers passed; pnpm audit --audit-level=moderate reported no known vulnerabilities; git diff --check passed.
  • The temporary first package-verifier attempt failed because the isolated worktree's node_modules was a relative symlink. Replacing that test-environment shortcut with a frozen-lockfile offline installation made the unchanged independent-consumer verifier pass. No product or verifier weakening was used.
  • Both prior-head Codex findings (complete emitted OFL validation and direct child-process timeout) are repaired and their threads resolved. Codex reviewed exact current head face112af438c023ff256600e04c26afd6a175ea and reported no major issues. CodeRabbit's exact-head re-review was rate-limited. Current unresolved inline threads: 0.
  • Exact-head CI 36802695795 is skipped because the PR remains Draft. Other exact-head hosted suites and a qualifying independent approval are absent. Skipped, absent, stale, predecessor, model-only, or status-only evidence is non-passing. Draft is not merge authorization.

Product boundary

This Draft separates the Inkspan software license from bundled-font license evidence without changing either license. It is machine-readable supply-chain evidence and license-file separation, not legal advice.

Test-first lineage

  1. Test-only 961597fe6431452a8ba89d513b6ae236abcc2e9f established the intended root/software and bundled-font separation and produced the expected RED result.
  2. c3ce70a527e19c06e41b7d82d369ee8fd5fa402d removed only the appended font prose from root LICENSE.
  3. Later commits strengthened manifest, packlist, and emitted-tarball evidence while successively synchronizing protected-main ancestry.
  4. 210284bb30661294a86f413581c26731c25d4b8a removed unrelated Office edits so their canonical writer remained separate.
  5. 846c6d318dbf4ccaab0c8707a36a698f679e7ee5 preserved that history, inherited feat: prepare TipTap 3 migration and restore Python matrix #402, and repaired the observed full-suite timeout without weakening artifact inspection.
  6. Current head face112af438c023ff256600e04c26afd6a175ea adds exact packed-byte evidence and enforceable subprocess timeouts in response to exact-head review.

Integration boundary

Keep Draft and unmerged until #402 is integrated or remains the valid live base, all exact-head hosted checks are terminal green, all review threads are resolved, and a qualifying independent approval exists under the live rules. Protected main alone defines shipped behavior. After ordinary protected integration, verify GitHub identifies the repository software license as MIT and the packed/published npm artifact retains both MIT and OFL evidence.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 34 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: aa858c2c-4735-4a6e-aaf4-3daf1b9469f1

📥 Commits

Reviewing files that changed from the base of the PR and between f1906d5 and face112.

📒 Files selected for processing (2)
  • LICENSE
  • src/licenseBoundary.test.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Exact-current-head read-only review request for b2c6b6eb7b9638051688939b722a1094c97da013 against frozen protected base main@a430b1c153702de3b6439def801732d7453b4940.

Direct exact-head gates are complete: CI 31590591645, Security Scan 31590591555, and SAST Semgrep 31590591516 all succeeded; current unresolved inline threads and formal reviews are zero. Review the narrow license-evidence separation only: exact canonical MIT root text, retained Noto/OFL attribution and complete terms, npm license: MIT, package inclusion of LICENSE and src/fonts, and absence of unintended runtime/version/dependency/export changes.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review only. Do not mutate the branch, dispatch repair writers, reuse predecessor/stale/synthetic evidence, or synthesize author approval. Bind findings and verdicts to this exact unchanged head.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='b2c6b6eb7b9638051688939b722a1094c97da013'
base='a430b1c153702de3b6439def801732d7453b4940'

echo '== Revision identities =='
git rev-parse HEAD
git cat-file -t "$head"
git cat-file -t "$base"
git merge-base --is-ancestor "$base" "$head" && echo 'base-is-ancestor=yes' || echo 'base-is-ancestor=no'

echo '== Changed paths and diff summary =='
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"
git diff -- "$base" "$head" -- LICENSE package.json src/fonts/NOTICE src/fonts/OFL.txt 2>/dev/null || true

echo '== Root LICENSE canonical MIT comparison =='
expected="$(mktemp)"
cat > "$expected" <<'EOF'
MIT License

Copyright (c) 2026 Inkspan Contributors

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
EOF
if diff -u "$expected" LICENSE; then
  echo 'root-license-canonical-mit=yes'
else
  echo 'root-license-canonical-mit=no'
fi
rm -f "$expected"

echo '== Font-license evidence =='
printf 'NOTICE Noto occurrences: '
rg -n -i 'Noto(\s+Sans)?' src/fonts/NOTICE || true
printf 'OFL reserved-font-name occurrences: '
rg -n 'Reserved Font Name|Noto Sans' src/fonts/OFL.txt || true
printf 'OFL version markers: '
rg -n 'SIL OPEN FONT LICENSE|Version 1\.1|PREAMBLE|TERMS AND CONDITIONS' src/fonts/OFL.txt || true
wc -l src/fonts/NOTICE src/fonts/OFL.txt

echo '== npm manifest evidence =='
jq '{license, files, version, dependencies, devDependencies, exports, main, module, types}' package.json
echo '== Package-related changed manifest fields =='
git diff -U0 "$base" "$head" -- package.json

echo '== Non-scope changes excluding license evidence =='
git diff --name-only "$base" "$head" -- . ':!LICENSE' ':!package.json' ':!src/fonts/NOTICE' ':!src/fonts/OFL.txt'

Length of output: 8196


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='b2c6b6eb7b9638051688939b722a1094c97da013'
base='a430b1c153702de3b6439def801732d7453b4940'

echo '== Test structure =='
ast-grep outline src/licenseBoundary.test.ts --items all

echo '== Added test content =='
cat -n src/licenseBoundary.test.ts

echo '== License content at base and head =='
echo '-- base LICENSE --'
git show "${base}:LICENSE" | cat -n
echo '-- head LICENSE --'
git show "${head}:LICENSE" | cat -n

echo '== Corrected canonical MIT comparison =='
expected="$(mktemp)"
cat > "$expected" <<'EOF'
MIT License

Copyright (c) 2026 ContextualWisdomLab

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
EOF
diff -u "$expected" LICENSE && echo 'root-license-canonical-mit=yes'
rm -f "$expected"

echo '== Exact package contract comparison =='
for key in version license dependencies devDependencies peerDependencies optionalDependencies exports main module types files; do
  before="$(git show "${base}:package.json" | jq -c --arg key "$key" '.[$key]')"
  after="$(git show "${head}:package.json" | jq -c --arg key "$key" '.[$key]')"
  if [ "$before" = "$after" ]; then
    printf '%s=unchanged\n' "$key"
  else
    printf '%s=CHANGED\n' "$key"
  fi
done

echo '== Test references to requested evidence =='
rg -n -C 2 'LICENSE|MIT|NOTICE|OFL|Noto|package\.json|license|files|src/fonts' src/licenseBoundary.test.ts

Length of output: 10800


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/inkspan'
head='b2c6b6eb7b9638051688939b722a1094c97da013'

echo '== Exact-head GitHub Actions runs =='
for run_id in 31590591645 31590591555 31590591516; do
  gh api "repos/${repo}/actions/runs/${run_id}" \
    --jq '[.id, .name, .head_sha, .status, .conclusion] | `@tsv`'
done

echo '== Retained OFL text has no changes from the protected base =='
git diff --quiet a430b1c153702de3b6439def801732d7453b4940 "$head" -- src/fonts/OFL.txt \
  && echo 'ofl-unchanged-from-base=yes' \
  || echo 'ofl-unchanged-from-base=no'

Length of output: 1082


🤖 web_search executed:

Official SIL Open Font License Version 1.1 full text plain text

Length of output: 10588


🏁 Script executed:

#!/bin/bash
set -euo pipefail

reference="$(mktemp)"
repository_terms="$(mktemp)"
reference_terms="$(mktemp)"
trap 'rm -f "$reference" "$repository_terms" "$reference_terms"' EXIT

curl --fail --silent --show-error --location \
  'https://openfontlicense.org/open-font-license-official-text/OFL.txt' \
  -o "$reference"

echo '== Official reference identity =='
sed -n '1,20p' "$reference"

echo '== Compare standard OFL-1.1 terms =='
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
  src/fonts/OFL.txt > "$repository_terms"
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
  "$reference" > "$reference_terms"

if diff -u "$reference_terms" "$repository_terms"; then
  echo 'ofl-standard-terms-exact=yes'
else
  echo 'ofl-standard-terms-exact=no'
fi

Length of output: 1154


🏁 Script executed:

#!/bin/bash
set -euo pipefail

page="$(mktemp)"
trap 'rm -f "$page"' EXIT

curl --fail --silent --show-error --location \
  --user-agent 'Mozilla/5.0 (compatible; CodeRabbit review)' \
  'https://openfontlicense.org/open-font-license-official-text/' \
  -o "$page"

echo '== Official OFL page title and text-download candidates =='
rg -n -i -C 1 '<title>|OFL\.txt|plaintext|plain text|download' "$page" | head -n 120

Length of output: 6977


🏁 Script executed:

#!/bin/bash
set -euo pipefail

reference="$(mktemp)"
repository_terms="$(mktemp)"
reference_terms="$(mktemp)"
trap 'rm -f "$reference" "$repository_terms" "$reference_terms"' EXIT

curl --fail --silent --show-error --location \
  --user-agent 'Mozilla/5.0 (compatible; CodeRabbit review)' \
  'https://openfontlicense.org/documents/OFL.txt' \
  -o "$reference"

sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
  src/fonts/OFL.txt > "$repository_terms"
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
  "$reference" > "$reference_terms"

echo '== Official reference header =='
sed -n '1,16p' "$reference"
echo '== Exact standard-terms comparison =='
if diff -u "$reference_terms" "$repository_terms"; then
  echo 'ofl-standard-terms-exact=yes'
else
  echo 'ofl-standard-terms-exact=no'
fi

Length of output: 2344


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Trailing whitespace in bundled OFL text =='
rg -n '[ \t]+$' src/fonts/OFL.txt || true

Length of output: 379


@seonghobae No findings from this exact-head review.

I reviewed b2c6b6eb7b9638051688939b722a1094c97da013 against main@a430b1c153702de3b6439def801732d7453b4940.

  • LICENSE is exact canonical MIT text with the existing ContextualWisdomLab copyright.
  • Noto attribution remains in src/fonts/NOTICE.
  • The complete OFL-1.1 terms remain in src/fonts/OFL.txt. The file is unchanged from the base. It has one pre-existing trailing space on Line 25, but the terms are complete.
  • package.json remains license: "MIT". Its files contract includes both LICENSE and src/fonts.
  • Versions, dependencies, exports, and package entry points are unchanged.
  • Only the root license and the license-boundary test changed.
  • CI 31590591645, Security Scan 31590591555, and SAST Semgrep 31590591516 each completed successfully on this exact head.

I kept this review distinct from protected-main verification and approval authority, as required by the repository guidance.


🧠 Learnings used
Learnt from: CR
Repo: ContextualWisdomLab/inkspan PR: 0
File: CLAUDE.md:0-0
Timestamp: 2026-08-12T02:30:49.287Z
Learning: Formal review, automated review, repository checks, host authorization, and release evidence remain distinct authorities.

Learnt from: CR
Repo: ContextualWisdomLab/inkspan PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-12T02:31:03.922Z
Learning: Do not infer shipped behavior from conversation history, PR bodies, model output, or predecessor-head evidence. Keep Proposed/Active-PR behavior distinct from implementation on Protected `main`, preserve fail-closed security and deterministic conversion boundaries, and update the smallest affected canonical documents plus tests when a durable contract changes.
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@opencode-agent opencode-agent Bot added priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior labels Aug 22, 2026
@seonghobae

Copy link
Copy Markdown
Contributor Author

Restacked onto current protected main and retained the two-file license evidence boundary.

Validation at 60f98e3fe9cb8166597aade5658a8f6d48f432d4:

  • focused license artifact and exact-head tests: 14 passed
  • typecheck passed
  • full root suite: 157 files / 885 tests, 100% coverage
  • production build and packed-package verification passed

The real emitted npm tarball contains canonical root MIT text plus separate bundled-font NOTICE and OFL evidence; no license terms or runtime behavior changed. @codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Remove the duplicated Python support contract changes from this license branch. PR #405 remains the single writer while this branch keeps its repository license correction.

Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com>

Commit-Message-Assisted-by: Claude (via Claude Code)
@seonghobae
seonghobae changed the base branch from main to codex/fix-python-boundary-coverage October 1, 2026 01:34

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 846c6d318dbf4ccaab0c8707a36a698f679e7ee5, including the two-file effective delta and emitted-package license evidence.

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 846c6d318dbf4ccaab0c8707a36a698f679e7ee5. Focus on license/provenance accuracy, emitted npm tarball evidence, the 30-second I/O-test timeout, and the stacked boundary on #402.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T01:50:51.803762Z face112 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 846c6d318d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/licenseBoundary.test.ts Outdated
Comment thread src/licenseBoundary.test.ts Outdated

Copy link
Copy Markdown
Contributor Author

Exact-current-head read-only review request for face112af438c023ff256600e04c26afd6a175ea against stacked base f1906d5c97915f522742c4cfa4b69fb8900a27a1.

Review only the two-path effective delta (LICENSE, src/licenseBoundary.test.ts) and bind any finding to this exact unchanged head. Verify canonical MIT root text, retained Noto/OFL obligations, exact source-and-packed OFL digest/byte checks, packed MIT/NOTICE byte checks, enforceable subprocess timeouts, and absence of dependency/runtime/export changes. Do not mutate the branch or synthesize approval.

@codex review
@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: face112af4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(supply-chain): separate root MIT license from bundled font notices

1 participant