Clarify MPL release placement obligations

This commit is contained in:
axiomlogicnexus 2026-05-25 02:46:06 +02:00
parent 574ecb49b1
commit 42c6b266b2
5 changed files with 226 additions and 0 deletions

View file

@ -201,6 +201,8 @@ This file now also preserves the current truth that future models must not lose:
- restrictive live lanes: `5`
- the dedicated current doctrine note for `MPL`-side non-`GPL` usage is:
- [HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md:1)
- the dedicated release-placement checklist for that route is:
- [HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md:1)
The twenty-three permissive live lanes are:

View file

@ -41,6 +41,9 @@ Current verified product-side reality is:
code license
- the dedicated current doctrine note for `MPL`-side non-`GPL` usage is:
- [HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md:1)
- the dedicated release-placement checklist for selling or externally
distributing builds that include those `MPL` lanes is:
- [HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md:1)
- the closed `0R-E` packet still retains these non-live benchmark, oracle, or
clean-room-later rows:
- `cs0x7f/cstimer`

View file

@ -32,10 +32,15 @@ The current HyperTwist live-lane rollups remain:
- [REPO_LICENSE_TRACKING.md](C:/HyperTwist/docs/REPO_LICENSE_TRACKING.md:1)
- [ROADMAP.md](C:/HyperTwist/docs/v6_5_deep_manual_pack/HyperTwist/ROADMAP.md:1)
- [HYPERTWIST_IMPLEMENTATION_PHASE_1_KICKOFF.md](C:/HyperTwist/docs/ops/HYPERTWIST_IMPLEMENTATION_PHASE_1_KICKOFF.md:1)
- [HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md:1)
This note does not replace those files. It clarifies the `MPL` route that
those files already authorize.
For exact release-placement instructions, use the dedicated checklist:
- [HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md:1)
## Non-advice boundary
This file is a HyperTwist engineering and compliance doctrine note.

View file

@ -0,0 +1,214 @@
# HyperTwist MPL Distribution Placement Checklist
Created on `2026-05-25`.
## Purpose
This file answers one narrow operational question for HyperTwist:
- where `MPL-2.0` notices, license text, and source-availability instructions
must be placed when HyperTwist uses `MPL`-covered code from
`cubing/cubing.js` and `coqui-ai/TTS`
This file does not replace the live-lane licensing doctrine. It is the
release-placement checklist for that doctrine.
Primary authority surfaces for this checklist are:
- [HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md:1)
- [REPO_LICENSE_TRACKING.md](C:/HyperTwist/docs/REPO_LICENSE_TRACKING.md:1)
- the official `MPL-2.0` text: <https://www.mozilla.org/en-US/MPL/2.0/>
- the official Mozilla `MPL-2.0` FAQ: <https://www.mozilla.org/en-US/MPL/2.0/FAQ/>
## One-line rule
If HyperTwist distributes a build or browser bundle containing `MPL`-covered
code, docs alone are not enough. The distributed product and its public
distribution surfaces must tell recipients:
- that `MPL`-covered code is present
- where to read the `MPL-2.0` license
- where to obtain the corresponding `MPL`-covered source
## What HyperTwist is relying on today
For the current live lanes:
- `cubing/cubing.js`
- HyperTwist relies on the accepted `MPL` route
- HyperTwist does not rely on `GPL` permission for the current landed lane
- HyperTwist must not copy `GPL`-only material into that lane without a new
legal review
- `coqui-ai/TTS`
- HyperTwist relies on the `MPL-2.0` code-side route for package code
- model, voice, and payload artifacts remain separate per-artifact review
- model or payload approval is not created by the package-code notice alone
## Scenario matrix
### 1. Internal-only use inside the organization
If HyperTwist is only used internally and is not distributed externally:
- external release-placement obligations do not activate in the same way
- keep internal compliance records anyway
- keep the doctrine note and this checklist available to release engineering
### 2. Downloadable desktop app or packaged native software
If HyperTwist is sold or distributed as a downloadable desktop product, put the
`MPL` materials in all of these places:
1. shipped artifact contents
- `ThirdPartyNotices.txt` or equivalent
- `licenses/MPL-2.0.txt` or another included full `MPL-2.0` text
- a source-availability statement that tells recipients where the
corresponding `MPL`-covered source can be obtained
2. installed app UI
- `Open Source Notices`, `Legal`, or `About > Licenses`
3. public download or distribution page
- link to the open-source notices
- link to the corresponding source location
- separate payload-license page if `coqui-ai/TTS` models or payloads are
shipped
4. corresponding source location
- host the exact corresponding `MPL`-covered source snapshot used by the
release
- if HyperTwist modified `MPL`-covered files directly, publish those
modified files under `MPL`
### 3. Public website or SaaS with server-side code only
If the product is a hosted service and users do not receive the `MPL`-covered
code in the browser or as a download:
- server-side use alone is not the same as distributing the code to users
- a public website legal page is not required solely for that server-side use
- keep internal release records anyway
### 4. Public website that delivers client-side JavaScript or other browser code
If HyperTwist delivers browser code that includes `MPL`-covered files or a
bundle containing them:
1. the website should have a public `Legal`, `Open Source Notices`, or
equivalent page
2. that page should identify the `MPL`-covered component
3. that page should include or link the full `MPL-2.0` text
4. that page should include a source-availability link for the corresponding
`MPL`-covered source
5. the bundled asset or release notes should not hide the fact that the code is
present
### 5. Source repo only, without distributed build
If HyperTwist only keeps the code in source control and does not yet distribute
it:
- preserve upstream notices
- keep the `MPL` doctrine note and this checklist
- prepare a release-ready notices surface before external shipment
## Exact HyperTwist placement checklist
Before selling or externally distributing HyperTwist in a form that includes
`MPL`-covered code, ship all of the following:
### Required release-file surfaces
- a root `ThirdPartyNotices.txt` or equivalent bundled notices file
- a bundled `licenses/MPL-2.0.txt` or another full-copy location for the
`MPL-2.0` license text
- a source-availability statement naming where the corresponding
`MPL`-covered source can be obtained
### Required product UI surfaces
- `Help > About > Open Source Notices`
- or another stable in-product `Legal` / `Licenses` surface that users can
reach after installation
### Required public distribution surfaces for downloadable releases
- the release page or store page should reference the open-source notices
- the release page or store page should reference the corresponding source
location
- if `coqui-ai/TTS` models, voices, or payloads are shipped, the distribution
materials should link to their separate artifact-license page
### Required public distribution surfaces for browser-delivered bundles
- the website should have a public open-source notices page
- that page should expose the `MPL-2.0` license text or a stable link to it
- that page should expose the source-availability location for the
corresponding `MPL`-covered source
## Component-specific notes
### `cubing/cubing.js`
HyperTwist should state all of the following in release materials:
- `cubing/cubing.js` is used through the accepted `MPL` route
- HyperTwist is not relying on `GPL` permission for the landed lane
- the `MPL-2.0` text is available in the shipped notices materials
- the corresponding `MPL`-covered source location is available to recipients
If HyperTwist later modifies `MPL`-covered upstream files directly, release
engineering must publish those modified files under `MPL` with the shipped
release.
### `coqui-ai/TTS`
HyperTwist should state all of the following in release materials:
- `coqui-ai/TTS` package code is used through the `MPL-2.0` code-side route
- the `MPL-2.0` text is available in the shipped notices materials
- the corresponding `MPL`-covered package-code source location is available to
recipients
- any shipped model, voice, or payload artifact is licensed and disclosed
separately from the package-code notice
## What the website must and must not do
If the public website is only marketing the product:
- it does not need a special `MPL` page solely because the product exists
- it is still cleaner to link to the downloadable product's legal/notices page
If the public website delivers browser code containing `MPL`-covered material:
- it should have a public legal or open-source notices page
- it should identify the component
- it should provide the `MPL-2.0` text or a stable link to it
- it should provide the corresponding source location
## Minimum safe HyperTwist release package
The minimum safe package for a distributed HyperTwist release that includes
these lanes is:
- `ThirdPartyNotices.txt`
- `licenses/MPL-2.0.txt`
- an in-product `Open Source Notices` or `Licenses` screen
- release-page notice links
- a stable source URL for the corresponding `MPL`-covered files
- separate artifact-level notice handling for any shipped `coqui-ai/TTS`
models, voices, or payloads
## Trigger for immediate re-review
Stop and re-review the lane immediately if any of these become true:
- HyperTwist copies `GPL`-only material into the `cubing/cubing.js` lane
- HyperTwist modifies upstream `MPL`-covered files but has no plan to publish
those modified files on distribution
- HyperTwist ships `coqui-ai/TTS` models or payloads without separate
artifact-level license review
- HyperTwist serves browser bundles with `MPL`-covered code but no public
notices page or source-availability link
## Non-advice boundary
This is a HyperTwist engineering compliance checklist. It is not legal advice.
If release posture changes materially, escalate to formal counsel review.

View file

@ -209,6 +209,8 @@ Donor-strength rule:
- `coqui-ai/TTS` is live as a bounded `MPL` code-side lane, while model and payload review remains separate from the code-license judgment; that separation is not a clean-room requirement for the package code
- the dedicated current doctrine note for this route is:
- [HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_BOUNDARY_AND_NON_GPL_USAGE_DOCTRINE_2026-05-25.md:1)
- the dedicated release-placement checklist for this route is:
- [HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md](C:/HyperTwist/docs/ops/HYPERTWIST_MPL_DISTRIBUTION_PLACEMENT_CHECKLIST_2026-05-25.md:1)
- `Phase 0R` is now closed for the remaining `47` non-live rows
- `Phase 1R` is now closed as the retained-set contract and handoff overhaul
- `Phase 2R` is now closed as the retained-set ownership and acceptance packet sequence