From bf7ce02c15851bf0c5b0d83c70ae9520381c085f Mon Sep 17 00:00:00 2001 From: Sumer Johal Date: Wed, 26 Aug 2026 20:57:19 -0700 Subject: [PATCH] Adopt EUPL-1.2 for the node: canonical LICENSE, SPDX headers, CI gate The previous LICENSE was the first 134 lines of MPL-2.0, cut mid-sentence in section 2.4 -- the copyleft core (section 3) and Exhibits were absent, and GitHub reported the repo as NOASSERTION. Beyond the truncation, MPL and GPL both trigger only on distribution; AR2 nodes are operated as services, so a closed modified fork run as a service owed nothing. EUPL-1.2 defines Distribution/Communication to include "providing access to its essential functionalities", so the copyleft binds hosted forks too, and the license carries equal force in 23 EU languages -- the operating environment of the node network (EUDR, EUDI, dataspaces). Mechanized per the lessons ledger: scripts/license_check.sh pins LICENSE to the canonical text by sha256 and requires the SPDX header on every tracked Python file; ci.yml gates on it. Lesson recorded under license-posture-unchecked. Co-authored-by: Cursor --- .github/workflows/ci.yml | 7 + .stomata/lessons.json | 14 + LICENSE | 371 ++++++++++++------ app/auth.py | 4 + app/database.py | 4 + app/geoid_v2.py | 4 + app/grant_verifier.py | 4 + app/main.py | 4 + app/meal_logger.py | 4 + app/merkle.py | 4 + app/models/__init__.py | 4 + app/models/geo_id_model.py | 4 + app/routers/analytics_and_maintenance_apis.py | 4 + app/routers/fetch_field.py | 4 + app/routers/field_registration.py | 4 + app/routers/point_registration.py | 4 + app/routers/traceforward.py | 4 + app/s2_services.py | 4 + app/schemas.py | 4 + app/tests/conftest.py | 4 + app/tests/test_api.py | 4 + app/tests/test_fsma204_traceability.py | 4 + app/tests/test_geoid_v2.py | 4 + app/tests/test_geoid_v2_iou.py | 4 + app/tests/test_geoid_v2_live.py | 4 + app/tests/test_geoid_v2_properties.py | 4 + app/tests/test_traceforward.py | 4 + .../mint_test_authority_credentials.py | 4 + app/utils.py | 4 + migration/__init__.py | 3 + migration/db_repo.py | 4 + migration/geoid_v2.py | 4 + migration/models.py | 4 + migration/pipeline.py | 4 + migration/repo.py | 4 + migration/resolve.py | 4 + migration/run.py | 4 + migration/sample.py | 4 + migration/sources.py | 4 + migration/tests/__init__.py | 3 + migration/tests/test_db_repo.py | 4 + .../tests/test_limit_invalidates_joins.py | 4 + migration/tests/test_pipeline.py | 4 + migration/tests/test_points_are_importable.py | 4 + migration/tests/test_primitive.py | 4 + migration/tests/test_report_arithmetic.py | 4 + migration/tests/test_sample.py | 4 + migration/tests/test_schema_drift.py | 4 + scripts/license_check.sh | 31 ++ 49 files changed, 491 insertions(+), 110 deletions(-) create mode 100755 scripts/license_check.sh diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a00d80a..2d2ca2f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -3,6 +3,13 @@ name: AR2 CI on: [push, pull_request] jobs: + license: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: License posture (canonical EUPL-1.2 + SPDX headers) + run: bash scripts/license_check.sh + lint: runs-on: ubuntu-latest steps: diff --git a/.stomata/lessons.json b/.stomata/lessons.json index 8480e25..e8e1be9 100644 --- a/.stomata/lessons.json +++ b/.stomata/lessons.json @@ -104,6 +104,20 @@ {"date": "2026-08-14", "what": "The same document predicted that a check which becomes noise 'gets waived, then gets deleted'. Two checks became noise and were ignored for days by the author who wrote that sentence.", "where": "workplan/2026-08/rajat_ar2_closeout_20260814.md:418"} ] }, + { + "recurrence_key": "license-posture-unchecked", + "trigger": "You are adding, editing or citing a LICENSE file, a license declaration in prose, or a per-file license header.", + "directive": "Pin the license file to the canonical text by hash and check every source file for its header in CI. A license is a control that binds outsiders, and it fails silently: a truncated file or a prose-only declaration looks licensed to everyone who does not read it end to end.", + "kind": "mechanized", + "enforced_by": [ + "scripts/license_check.sh", + ".github/workflows/ci.yml" + ], + "occurrences": [ + {"date": "2026-08-26", "what": "LICENSE in ar2 and ar2-hub was the first 134 lines of MPL-2.0, cut mid-sentence in section 2.4 -- the copyleft core and exhibits were absent, and GitHub reported NOASSERTION. Nothing had ever checked it.", "where": "workplan/2026-08/core_license_posture_20260826.md"}, + {"date": "2026-08-26", "what": "pancake had no LICENSE file at all while GOVERNANCE.md line 5 declared Apache 2.0 in prose, a permissive license contradicting the copyleft intent.", "where": "workplan/2026-08/core_license_posture_20260826.md"} + ] + }, { "recurrence_key": "run-record-not-at-the-reviewed-commit", "trigger": "You are reading a run record, CI result or packet to decide whether a branch is sound.", diff --git a/LICENSE b/LICENSE index 8cb4a62..4153cd3 100644 --- a/LICENSE +++ b/LICENSE @@ -1,136 +1,287 @@ -Mozilla Public License Version 2.0 -================================== + EUROPEAN UNION PUBLIC LICENCE v. 1.2 + EUPL © the European Union 2007, 2016 -1. Definitions --------------- - -1.1. "Contributor" - means each individual or legal entity that creates, contributes to - the creation of, or owns Covered Software. - -1.2. "Contributor Version" - means the combination of the Contributions of others (if any) used - by a Contributor and that particular Contributor's Contribution. - -1.3. "Contribution" - means Covered Software of a particular Contributor. - -1.4. "Covered Software" - means Source Code Form to which the initial Contributor has attached - the notice in Exhibit A, the Executable Form of such Source Code - Form, and Modifications of such Source Code Form, in each case - including portions thereof. - -1.5. "Incompatible With Secondary Licenses" - means +This European Union Public Licence (the ‘EUPL’) applies to the Work (as defined +below) which is provided under the terms of this Licence. Any use of the Work, +other than as authorised under this Licence is prohibited (to the extent such +use is covered by a right of the copyright holder of the Work). - (a) that the initial Contributor has attached the notice described - in Exhibit B to the Covered Software; or +The Work is provided under the terms of this Licence when the Licensor (as +defined below) has placed the following notice immediately following the +copyright notice for the Work: - (b) that the Covered Software was made available under the terms of - version 1.1 or earlier of the License, but not also under the - terms of a Secondary License. + Licensed under the EUPL -1.6. "Executable Form" - means any form of the work other than Source Code Form. +or has expressed by any other means his willingness to license under the EUPL. -1.7. "Larger Work" - means a work that combines Covered Software with other material, in - a separate file or files, that is not Covered Software. - -1.8. "License" - means this document. - -1.9. "Licensable" - means having the right to grant, to the maximum extent possible, - whether at the time of the initial grant or subsequently, any and - all of the rights conveyed by this License. - -1.10. "Modifications" - means any of the following: - - (a) any file in Source Code Form that results from an addition to, - deletion from, or modification of the contents of Covered - Software; or +1. Definitions - (b) any new file in Source Code Form that contains any Covered - Software. +In this Licence, the following terms have the following meaning: -1.11. "Patent Claims" of a Contributor - means any patent claim(s), including without limitation, method, - process, and apparatus claims, in any patent Licensable by such - Contributor that would be infringed, but for the grant of the - License, by the making, using, selling, offering for sale, having - made, import, or transfer of either its Contributions or its - Contributor Version. +- ‘The Licence’: this Licence. -1.12. "Secondary License" - means either the GNU General Public License, Version 2.0, the GNU - Lesser General Public License, Version 2.1, the GNU Affero General - Public License, Version 3.0, or any later versions of those - licenses. +- ‘The Original Work’: the work or software distributed or communicated by the + Licensor under this Licence, available as Source Code and also as Executable + Code as the case may be. + +- ‘Derivative Works’: the works or software that could be created by the + Licensee, based upon the Original Work or modifications thereof. This Licence + does not define the extent of modification or dependence on the Original Work + required in order to classify a work as a Derivative Work; this extent is + determined by copyright law applicable in the country mentioned in Article 15. + +- ‘The Work’: the Original Work or its Derivative Works. + +- ‘The Source Code’: the human-readable form of the Work which is the most + convenient for people to study and modify. + +- ‘The Executable Code’: any code which has generally been compiled and which is + meant to be interpreted by a computer as a program. -1.13. "Source Code Form" - means the form of the work preferred for making modifications. +- ‘The Licensor’: the natural or legal person that distributes or communicates + the Work under the Licence. + +- ‘Contributor(s)’: any natural or legal person who modifies the Work under the + Licence, or otherwise contributes to the creation of a Derivative Work. + +- ‘The Licensee’ or ‘You’: any natural or legal person who makes any usage of + the Work under the terms of the Licence. + +- ‘Distribution’ or ‘Communication’: any act of selling, giving, lending, + renting, distributing, communicating, transmitting, or otherwise making + available, online or offline, copies of the Work or providing access to its + essential functionalities at the disposal of any other natural or legal + person. -1.14. "You" (or "Your") - means an individual or a legal entity exercising rights under this - License. For legal entities, "You" includes any entity that - controls, is controlled by, or is under common control with You. For - purposes of this definition, "control" means (a) the power, direct - or indirect, to cause the direction or management of such entity, - whether by contract or otherwise, or (b) ownership of more than - fifty percent (50%) of the outstanding shares or beneficial - ownership of such entity. +2. Scope of the rights granted by the Licence + +The Licensor hereby grants You a worldwide, royalty-free, non-exclusive, +sublicensable licence to do the following, for the duration of copyright vested +in the Original Work: + +- use the Work in any circumstance and for all usage, +- reproduce the Work, +- modify the Work, and make Derivative Works based upon the Work, +- communicate to the public, including the right to make available or display + the Work or copies thereof to the public and perform publicly, as the case may + be, the Work, +- distribute the Work or copies thereof, +- lend and rent the Work or copies thereof, +- sublicense rights in the Work or copies thereof. -2. License Grants and Conditions --------------------------------- +Those rights can be exercised on any media, supports and formats, whether now +known or later invented, as far as the applicable law permits so. + +In the countries where moral rights apply, the Licensor waives his right to +exercise his moral right to the extent allowed by law in order to make effective +the licence of the economic rights here above listed. + +The Licensor grants to the Licensee royalty-free, non-exclusive usage rights to +any patents held by the Licensor, to the extent necessary to make use of the +rights granted on the Work under this Licence. + +3. Communication of the Source Code + +The Licensor may provide the Work either in its Source Code form, or as +Executable Code. If the Work is provided as Executable Code, the Licensor +provides in addition a machine-readable copy of the Source Code of the Work +along with each copy of the Work that the Licensor distributes or indicates, in +a notice following the copyright notice attached to the Work, a repository where +the Source Code is easily and freely accessible for as long as the Licensor +continues to distribute or communicate the Work. + +4. Limitations on copyright + +Nothing in this Licence is intended to deprive the Licensee of the benefits from +any exception or limitation to the exclusive rights of the rights owners in the +Work, of the exhaustion of those rights or of other applicable limitations +thereto. + +5. Obligations of the Licensee + +The grant of the rights mentioned above is subject to some restrictions and +obligations imposed on the Licensee. Those obligations are the following: + +Attribution right: The Licensee shall keep intact all copyright, patent or +trademarks notices and all notices that refer to the Licence and to the +disclaimer of warranties. The Licensee must include a copy of such notices and a +copy of the Licence with every copy of the Work he/she distributes or +communicates. The Licensee must cause any Derivative Work to carry prominent +notices stating that the Work has been modified and the date of modification. + +Copyleft clause: If the Licensee distributes or communicates copies of the +Original Works or Derivative Works, this Distribution or Communication will be +done under the terms of this Licence or of a later version of this Licence +unless the Original Work is expressly distributed only under this version of the +Licence — for example by communicating ‘EUPL v. 1.2 only’. The Licensee +(becoming Licensor) cannot offer or impose any additional terms or conditions on +the Work or Derivative Work that alter or restrict the terms of the Licence. + +Compatibility clause: If the Licensee Distributes or Communicates Derivative +Works or copies thereof based upon both the Work and another work licensed under +a Compatible Licence, this Distribution or Communication can be done under the +terms of this Compatible Licence. For the sake of this clause, ‘Compatible +Licence’ refers to the licences listed in the appendix attached to this Licence. +Should the Licensee's obligations under the Compatible Licence conflict with +his/her obligations under this Licence, the obligations of the Compatible +Licence shall prevail. + +Provision of Source Code: When distributing or communicating copies of the Work, +the Licensee will provide a machine-readable copy of the Source Code or indicate +a repository where this Source will be easily and freely available for as long +as the Licensee continues to distribute or communicate the Work. + +Legal Protection: This Licence does not grant permission to use the trade names, +trademarks, service marks, or names of the Licensor, except as required for +reasonable and customary use in describing the origin of the Work and +reproducing the content of the copyright notice. + +6. Chain of Authorship + +The original Licensor warrants that the copyright in the Original Work granted +hereunder is owned by him/her or licensed to him/her and that he/she has the +power and authority to grant the Licence. + +Each Contributor warrants that the copyright in the modifications he/she brings +to the Work are owned by him/her or licensed to him/her and that he/she has the +power and authority to grant the Licence. + +Each time You accept the Licence, the original Licensor and subsequent +Contributors grant You a licence to their contributions to the Work, under the +terms of this Licence. + +7. Disclaimer of Warranty + +The Work is a work in progress, which is continuously improved by numerous +Contributors. It is not a finished work and may therefore contain defects or +‘bugs’ inherent to this type of development. + +For the above reason, the Work is provided under the Licence on an ‘as is’ basis +and without warranties of any kind concerning the Work, including without +limitation merchantability, fitness for a particular purpose, absence of defects +or errors, accuracy, non-infringement of intellectual property rights other than +copyright as stated in Article 6 of this Licence. + +This disclaimer of warranty is an essential part of the Licence and a condition +for the grant of any rights to the Work. -2.1. Grants +8. Disclaimer of Liability -Each Contributor hereby grants You a world-wide, royalty-free, -non-exclusive license: +Except in the cases of wilful misconduct or damages directly caused to natural +persons, the Licensor will in no event be liable for any direct or indirect, +material or moral, damages of any kind, arising out of the Licence or of the use +of the Work, including without limitation, damages for loss of goodwill, work +stoppage, computer failure or malfunction, loss of data or any commercial +damage, even if the Licensor has been advised of the possibility of such damage. +However, the Licensor will be liable under statutory product liability laws as +far such laws apply to the Work. + +9. Additional agreements + +While distributing the Work, You may choose to conclude an additional agreement, +defining obligations or services consistent with this Licence. However, if +accepting obligations, You may act only on your own behalf and on your sole +responsibility, not on behalf of the original Licensor or any other Contributor, +and only if You agree to indemnify, defend, and hold each Contributor harmless +for any liability incurred by, or claims asserted against such Contributor by +the fact You have accepted any warranty or additional liability. + +10. Acceptance of the Licence + +The provisions of this Licence can be accepted by clicking on an icon ‘I agree’ +placed under the bottom of a window displaying the text of this Licence or by +affirming consent in any other similar way, in accordance with the rules of +applicable law. Clicking on that icon indicates your clear and irrevocable +acceptance of this Licence and all of its terms and conditions. + +Similarly, you irrevocably accept this Licence and all of its terms and +conditions by exercising any rights granted to You by Article 2 of this Licence, +such as the use of the Work, the creation by You of a Derivative Work or the +Distribution or Communication by You of the Work or copies thereof. + +11. Information to the public + +In case of any Distribution or Communication of the Work by means of electronic +communication by You (for example, by offering to download the Work from a +remote location) the distribution channel or media (for example, a website) must +at least provide to the public the information requested by the applicable law +regarding the Licensor, the Licence and the way it may be accessible, concluded, +stored and reproduced by the Licensee. + +12. Termination of the Licence + +The Licence and the rights granted hereunder will terminate automatically upon +any breach by the Licensee of the terms of the Licence. + +Such a termination will not terminate the licences of any person who has +received the Work from the Licensee under the Licence, provided such persons +remain in full compliance with the Licence. + +13. Miscellaneous + +Without prejudice of Article 9 above, the Licence represents the complete +agreement between the Parties as to the Work. + +If any provision of the Licence is invalid or unenforceable under applicable +law, this will not affect the validity or enforceability of the Licence as a +whole. Such provision will be construed or reformed so as necessary to make it +valid and enforceable. -(a) under intellectual property rights (other than patent or trademark) - Licensable by such Contributor to use, reproduce, make available, - modify, display, perform, distribute, and otherwise exploit its - Contributions, either on an unmodified basis, with Modifications, or - as part of a Larger Work; and +The European Commission may publish other linguistic versions or new versions of +this Licence or updated versions of the Appendix, so far this is required and +reasonable, without reducing the scope of the rights granted by the Licence. New +versions of the Licence will be published with a unique version number. -(b) under Patent Claims of such Contributor to make, use, sell, offer - for sale, have made, import, and otherwise transfer either its - Contributions or its Contributor Version. +All linguistic versions of this Licence, approved by the European Commission, +have identical value. Parties can take advantage of the linguistic version of +their choice. -2.2. Effective Date +14. Jurisdiction -The licenses granted in Section 2.1 with respect to any Contribution -become effective for each Contribution on the date the Contributor first -distributes such Contribution. +Without prejudice to specific agreement between parties, -2.3. Limitations on Grant Scope +- any litigation resulting from the interpretation of this License, arising + between the European Union institutions, bodies, offices or agencies, as a + Licensor, and any Licensee, will be subject to the jurisdiction of the Court + of Justice of the European Union, as laid down in article 272 of the Treaty on + the Functioning of the European Union, -The licenses granted in this Section 2 are the only rights granted under -this License. No additional rights or licenses will be implied from the -distribution or licensing of Covered Software under this License. -Notwithstanding Section 2.1(b) above, no patent license is granted by a -Contributor: +- any litigation arising between other parties and resulting from the + interpretation of this License, will be subject to the exclusive jurisdiction + of the competent court where the Licensor resides or conducts its primary + business. -(a) for any code that a Contributor has removed from Covered Software; - or +15. Applicable Law + +Without prejudice to specific agreement between parties, -(b) for infringements caused by: (i) Your and any other third party's - modifications of Covered Software, or (ii) the combination of its - Contributions with other software (except as part of its Contributor - Version); or +- this Licence shall be governed by the law of the European Union Member State + where the Licensor has his seat, resides or has his registered office, + +- this licence shall be governed by Belgian law if the Licensor has no seat, + residence or registered office inside a European Union Member State. -(c) under Patent Claims infringed by Covered Software in the absence of - its Contributions. +Appendix -This License does not grant any rights in the trademarks, service marks, -or logos of any Contributor (except as may be necessary to comply with -the notice requirements in Section 3.4). +‘Compatible Licences’ according to Article 5 EUPL are: -2.4. Subsequent Licenses +- GNU General Public License (GPL) v. 2, v. 3 +- GNU Affero General Public License (AGPL) v. 3 +- Open Software License (OSL) v. 2.1, v. 3.0 +- Eclipse Public License (EPL) v. 1.0 +- CeCILL v. 2.0, v. 2.1 +- Mozilla Public Licence (MPL) v. 2 +- GNU Lesser General Public Licence (LGPL) v. 2.1, v. 3 +- Creative Commons Attribution-ShareAlike v. 3.0 Unported (CC BY-SA 3.0) for + works other than software +- European Union Public Licence (EUPL) v. 1.1, v. 1.2 +- Québec Free and Open-Source Licence — Reciprocity (LiLiQ-R) or Strong + Reciprocity (LiLiQ-R+). -No Contributor makes additional +The European Commission may update this Appendix to later versions of the above +licences without producing a new version of the EUPL, as long as they provide +the rights granted in Article 2 of this Licence and protect the covered Source +Code from exclusive appropriation. +All other changes or additions to this Appendix require the production of a new +EUPL version. diff --git a/app/auth.py b/app/auth.py index ae00bff..9d51a33 100644 --- a/app/auth.py +++ b/app/auth.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/database.py b/app/database.py index fb9656a..60f0c81 100644 --- a/app/database.py +++ b/app/database.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/geoid_v2.py b/app/geoid_v2.py index de8e343..e73088f 100644 --- a/app/geoid_v2.py +++ b/app/geoid_v2.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """GeoID v2: content-derived field identity, and area-exact comparison of covers. The regime, per doc/current/dpi_architecture_20260812.md S10: diff --git a/app/grant_verifier.py b/app/grant_verifier.py index b5b94d6..93d9ff2 100644 --- a/app/grant_verifier.py +++ b/app/grant_verifier.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/main.py b/app/main.py index a50c3db..8f4cabe 100644 --- a/app/main.py +++ b/app/main.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/meal_logger.py b/app/meal_logger.py index b94d5c9..69a5590 100644 --- a/app/meal_logger.py +++ b/app/meal_logger.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + import os import httpx diff --git a/app/merkle.py b/app/merkle.py index 62fe6e6..e753f29 100644 --- a/app/merkle.py +++ b/app/merkle.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + from __future__ import annotations import hashlib diff --git a/app/models/__init__.py b/app/models/__init__.py index 1f31b33..23ca341 100644 --- a/app/models/__init__.py +++ b/app/models/__init__.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/models/geo_id_model.py b/app/models/geo_id_model.py index 3d75128..2b0af7d 100644 --- a/app/models/geo_id_model.py +++ b/app/models/geo_id_model.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/routers/analytics_and_maintenance_apis.py b/app/routers/analytics_and_maintenance_apis.py index a375450..8d9a2b6 100644 --- a/app/routers/analytics_and_maintenance_apis.py +++ b/app/routers/analytics_and_maintenance_apis.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/routers/fetch_field.py b/app/routers/fetch_field.py index 3fa9c85..48d8074 100644 --- a/app/routers/fetch_field.py +++ b/app/routers/fetch_field.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/routers/field_registration.py b/app/routers/field_registration.py index 0ed4e41..1654851 100644 --- a/app/routers/field_registration.py +++ b/app/routers/field_registration.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/routers/point_registration.py b/app/routers/point_registration.py index 2e6a91d..0ea38b2 100644 --- a/app/routers/point_registration.py +++ b/app/routers/point_registration.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/routers/traceforward.py b/app/routers/traceforward.py index 34eaa29..c5396c0 100644 --- a/app/routers/traceforward.py +++ b/app/routers/traceforward.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + import hashlib import os diff --git a/app/s2_services.py b/app/s2_services.py index 994ad68..fe5a1d0 100644 --- a/app/s2_services.py +++ b/app/s2_services.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/schemas.py b/app/schemas.py index f712b41..da7293a 100644 --- a/app/schemas.py +++ b/app/schemas.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/app/tests/conftest.py b/app/tests/conftest.py index c39985b..9cf7fa3 100644 --- a/app/tests/conftest.py +++ b/app/tests/conftest.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + from pathlib import Path import pytest diff --git a/app/tests/test_api.py b/app/tests/test_api.py index 1548fa4..c9ba5db 100644 --- a/app/tests/test_api.py +++ b/app/tests/test_api.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + import os import pytest diff --git a/app/tests/test_fsma204_traceability.py b/app/tests/test_fsma204_traceability.py index 7e7b358..edce764 100644 --- a/app/tests/test_fsma204_traceability.py +++ b/app/tests/test_fsma204_traceability.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """FSMA 204 end-to-end traceability scenario: romaine lettuce, field to retail. This file does two jobs. It is a regression harness for the trace-back and diff --git a/app/tests/test_geoid_v2.py b/app/tests/test_geoid_v2.py index e35f7f1..cca00de 100644 --- a/app/tests/test_geoid_v2.py +++ b/app/tests/test_geoid_v2.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + import json import os diff --git a/app/tests/test_geoid_v2_iou.py b/app/tests/test_geoid_v2_iou.py index ecd1be2..d5dfa7d 100644 --- a/app/tests/test_geoid_v2_iou.py +++ b/app/tests/test_geoid_v2_iou.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + from shapely.wkt import loads from app.utils import Utils diff --git a/app/tests/test_geoid_v2_live.py b/app/tests/test_geoid_v2_live.py index 5553d03..c6757b6 100644 --- a/app/tests/test_geoid_v2_live.py +++ b/app/tests/test_geoid_v2_live.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """GeoID v2 in the live registration path, and the exact cover comparison. Three changes are pinned here. diff --git a/app/tests/test_geoid_v2_properties.py b/app/tests/test_geoid_v2_properties.py index c9de5db..51a1421 100644 --- a/app/tests/test_geoid_v2_properties.py +++ b/app/tests/test_geoid_v2_properties.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + from app.utils import Utils diff --git a/app/tests/test_traceforward.py b/app/tests/test_traceforward.py index 190a6be..e800bca 100644 --- a/app/tests/test_traceforward.py +++ b/app/tests/test_traceforward.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + import json import os import uuid diff --git a/app/tests/testkit/mint_test_authority_credentials.py b/app/tests/testkit/mint_test_authority_credentials.py index eda059e..12b7a96 100644 --- a/app/tests/testkit/mint_test_authority_credentials.py +++ b/app/tests/testkit/mint_test_authority_credentials.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """Mint test Authority credentials (vct: agstack.org/credentials/traceforward-authority/v1). Usage: diff --git a/app/utils.py b/app/utils.py index 5553d2f..b84b082 100644 --- a/app/utils.py +++ b/app/utils.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at https://mozilla.org/MPL/2.0/. diff --git a/migration/__init__.py b/migration/__init__.py index e69de29..2b47ab2 100644 --- a/migration/__init__.py +++ b/migration/__init__.py @@ -0,0 +1,3 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. diff --git a/migration/db_repo.py b/migration/db_repo.py index da57fff..db45ce8 100644 --- a/migration/db_repo.py +++ b/migration/db_repo.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ SQLAlchemy-backed TargetRepo. diff --git a/migration/geoid_v2.py b/migration/geoid_v2.py index 1fdc8e8..768f99b 100644 --- a/migration/geoid_v2.py +++ b/migration/geoid_v2.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ GeoID v2 — content-derived field identity. diff --git a/migration/models.py b/migration/models.py index 86330c7..d439c7d 100644 --- a/migration/models.py +++ b/migration/models.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ SQLAlchemy models for the import's target tables. diff --git a/migration/pipeline.py b/migration/pipeline.py index b44d781..50041ea 100644 --- a/migration/pipeline.py +++ b/migration/pipeline.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ The import: AR 1.0 polygons -> AR2, TerraPipe profiles -> Hub + Pancake. diff --git a/migration/repo.py b/migration/repo.py index b6f8f89..6cfe86c 100644 --- a/migration/repo.py +++ b/migration/repo.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Target-side repository: AR2 registry, Hub accounts, Pancake profiles. diff --git a/migration/resolve.py b/migration/resolve.py index 08cfae5..32fd166 100644 --- a/migration/resolve.py +++ b/migration/resolve.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Area-exact IoU and containment over S2 token covers. diff --git a/migration/run.py b/migration/run.py index 44c4ebc..2f82cee 100644 --- a/migration/run.py +++ b/migration/run.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Import rehearsal runner. diff --git a/migration/sample.py b/migration/sample.py index 157672b..a42e922 100644 --- a/migration/sample.py +++ b/migration/sample.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Adversarial stratified sampling (M2). diff --git a/migration/sources.py b/migration/sources.py index bb14560..2bff7ce 100644 --- a/migration/sources.py +++ b/migration/sources.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Legacy source adapters — AR 1.0 (polygons) and TerraPipe (profiles). diff --git a/migration/tests/__init__.py b/migration/tests/__init__.py index e69de29..2b47ab2 100644 --- a/migration/tests/__init__.py +++ b/migration/tests/__init__.py @@ -0,0 +1,3 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. diff --git a/migration/tests/test_db_repo.py b/migration/tests/test_db_repo.py index da9916c..07e1e2a 100644 --- a/migration/tests/test_db_repo.py +++ b/migration/tests/test_db_repo.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Tests for the SQLAlchemy repository against real databases (SQLite here, Postgres in the rehearsal). diff --git a/migration/tests/test_limit_invalidates_joins.py b/migration/tests/test_limit_invalidates_joins.py index 8b1f4ea..10c8074 100644 --- a/migration/tests/test_limit_invalidates_joins.py +++ b/migration/tests/test_limit_invalidates_joins.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """--limit truncates fields only, so every join figure it produces is an artifact. `run.py` passes `--limit` to `import_fields` but not to `import_profiles`. Every diff --git a/migration/tests/test_pipeline.py b/migration/tests/test_pipeline.py index e245d61..f5af779 100644 --- a/migration/tests/test_pipeline.py +++ b/migration/tests/test_pipeline.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """End-to-end import rehearsal on synthetic AR1 + TerraPipe fixtures. Run: python -m pytest migration/tests/test_pipeline.py -v diff --git a/migration/tests/test_points_are_importable.py b/migration/tests/test_points_are_importable.py index c0128f3..dc71969 100644 --- a/migration/tests/test_points_are_importable.py +++ b/migration/tests/test_points_are_importable.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """Pins must import, not quarantine. The first full run against the live AR 1.0 registry quarantined 14,594 of 28,282 diff --git a/migration/tests/test_primitive.py b/migration/tests/test_primitive.py index cf08761..8ae7ce7 100644 --- a/migration/tests/test_primitive.py +++ b/migration/tests/test_primitive.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """Verification of the v2 primitive and the resolution arithmetic. Run: python -m pytest migration/tests/test_primitive.py -v diff --git a/migration/tests/test_report_arithmetic.py b/migration/tests/test_report_arithmetic.py index 233ed54..7bb0d69 100644 --- a/migration/tests/test_report_arithmetic.py +++ b/migration/tests/test_report_arithmetic.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """The report's categories must add up, and must not overlap. THE INCIDENT. On 2026-08-19 an import run reported 268 fields quarantined and 268 diff --git a/migration/tests/test_sample.py b/migration/tests/test_sample.py index 22b5979..8a772b9 100644 --- a/migration/tests/test_sample.py +++ b/migration/tests/test_sample.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Tests for adversarial sampling (M2). diff --git a/migration/tests/test_schema_drift.py b/migration/tests/test_schema_drift.py index 3b9f2d4..3b3a55c 100644 --- a/migration/tests/test_schema_drift.py +++ b/migration/tests/test_schema_drift.py @@ -1,3 +1,7 @@ +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 AgStack project contributors. +# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text. + """ Drift guard: models.py mirrors the shipped schemas rather than importing them, so something has to notice when the real ones change. diff --git a/scripts/license_check.sh b/scripts/license_check.sh new file mode 100755 index 0000000..cf57611 --- /dev/null +++ b/scripts/license_check.sh @@ -0,0 +1,31 @@ +#!/usr/bin/env bash +# Fail if the license posture regresses. +# +# Two invariants, both mechanical: +# 1. LICENSE is the canonical EUPL-1.2 English text, byte for byte. +# (Its predecessor here was a silently truncated license file that GitHub +# reported as NOASSERTION -- a hash comparison cannot fail that quietly.) +# 2. Every git-tracked Python file carries the SPDX EUPL-1.2 header. +set -euo pipefail + +# sha256 of https://joinup.ec.europa.eu/sites/default/files/custom-page/attachment/2020-03/EUPL-1.2%20EN.txt +# computed 2026-08-26 (287 lines). +want="6fc9e709ccbfe0d77fbffa2427a983282be2eb88e47b1cdb49f21a83b4d1e665" +got=$(shasum -a 256 LICENSE | cut -d' ' -f1) +if [ "$got" != "$want" ]; then + echo "FAIL: LICENSE is not the canonical EUPL-1.2 text (sha256 $got)" + exit 1 +fi + +fail=0 +while IFS= read -r f; do + if ! head -5 "$f" | grep -q "SPDX-License-Identifier: EUPL-1.2"; then + echo "FAIL: missing SPDX EUPL-1.2 header: $f" + fail=1 + fi +done < <(git ls-files '*.py') + +if [ "$fail" -eq 0 ]; then + echo "license posture OK: canonical EUPL-1.2 + headers on all tracked .py files" +fi +exit "$fail"