Skip to content

Fix the scaffold that propagates 'License: PMPL-1.0-or-later' (runbook §7a source fix) #645

Description

@hyperpolymath

docs/migrations/pmpl-to-mpl-sweep-runbook.adoc §7a already prescribes the fix; this issue exists to track doing it at the source.

The runbook's instruction, verbatim

Strategy — fix at the source, not 236 times. Locate the scaffold generator (rsr-template-repo / scaffoldia / the llm-warmup-* template) and flip the template's licence line to the correct per-category value, THEN re-propagate. Doing 236 manual edits invites immediate re-drift on the next scaffold run.

Measured in standards today, 2026-08-26

54 files still carry a PMPL declaration. By filename, the template origin is obvious:

File Count
humans.txt 12
REUSE dep5 12
README.adoc 11
trust.txt 5
everything else 1 each

Many still carry unfilled {{AUTHOR}} / {{OWNER}} / {{CURRENT_DATE}} placeholders — proof they are scaffold output, not authored text. Note the SPDX header on these files is already correct (MPL-2.0); only the body License: line is wrong, so the legally operative licence is right and this is metadata hygiene rather than a licence defect.

Must NOT be touched

  • LICENSES/PMPL-1.0-or-later.txt — the licence exhibit text (runbook §1 says "Leave")
  • docs/migrations/pmpl-to-mpl-sweep-runbook.adoc — documents the migration
  • rhodium-standard-repositories/satellites/rsr-certifier/PALIMPSEST.adoc
  • scripts/tests/spdx-header-block-test.sh — a test that asserts on these strings; editing it would break the check rather than fix anything

What to do

  1. Find which scaffold emits humans.txt / trust.txt / dep5 / README.adoc carrying License: PMPL-1.0-or-later — candidates per the runbook are rsr-template-repo, scaffoldia, and the llm-warmup-* templates
  2. Fix the template's licence line per category (code → MPL-2.0, prose → CC-BY-SA-4.0)
  3. Re-propagate, excluding the Rule 2 carve-outs, 007, son-shared repos, and vendored forks — exactly as §1/§3 specify
  4. Only then clean the residue

Why this is filed rather than done

I found these 54 files and was about to correct them directly. The runbook explicitly forbids that, and is right to: they are the output of a generator that will reproduce them on the next scaffold run. Recording the measurement here so the source fix has a denominator to verify against.

Related: standards#643 (removed the PMPL preference comments — a different, non-templated surface, already done).

Activity

  1. added
    scope:estateAffects many or all repos across the estate
    tech-debtKnown shortcut, drift, or hygiene owed - includes cleanup
    on Aug 26, 2026
  2. hyperpolymath commented on Aug 26, 2026

    @hyperpolymath
    OwnerAuthor

    ✅ Source located — and it was already fixed three months ago

    Traced per the runbook's §7a instruction. The generator is not the problem.

    rsr-template-repo/.well-known/humans.txt now emits:

    License: MPL-2.0 (code) / CC-BY-SA-4.0 (docs)
    

    and its history shows exactly when that happened:

    2026-05-22  chore: migrate license from PMPL-1.0-or-later to MPL-2.0
    2026-06-26  chore(template): doc-link fixes, MPL-2.0/CC-BY-SA-4.0 licence cleanup
    

    Its dep5 is likewise clean (License: MPL-2.0 throughout).

    This changes the disposition

    The runbook is dated 2026-06-27 — the day after the final template fix — and warned:

    Doing 236 manual edits invites immediate re-drift on the next scaffold run.

    That risk no longer exists. The scaffold has emitted the correct line since May, so
    there is nothing left to re-drift from. The 54 files in standards are stale residue
    that predates the fix
    , not live output of a broken generator.

    So the residue is now safely cleanable, and the runbook's step 4 ("only then clean the
    residue") is the step we are actually at — steps 1–3 are done.

    One loose end at the source

    scaffoldia/.well-known/humans.txt reads:

    License: MPL-2.0 (Palimpsest MPL)
    

    The licence identifier is correct; the (Palimpsest MPL) parenthetical is a leftover that
    contradicts it, since MPL-2.0 is not Palimpsest MPL. Worth correcting so scaffoldia's
    output does not reintroduce the confusion the template already removed.

    Revised scope

    • Fix the generator — already done, 2026-05-22
    • Fix scaffoldia's stray parenthetical — small
    • Clean the 54 stale files in standards — now safe, was not before
    • Note the SPDX headers on all 54 are already MPL-2.0, so the legally operative licence
      has been correct throughout
      ; this is metadata hygiene, not a licence defect

    Correcting my own earlier note on this issue, which treated the residue as unsafe to touch.
    It was — until I checked when the source was fixed.

  3. hyperpolymath commented on Aug 27, 2026

    @hyperpolymath
    OwnerAuthor

    Next step (re-verified 2026-08-27, and the answer the issue was asking for): the scaffold source is scaffoldia, not rsr-template-repo — 6 templates under machine-readable-design/harvested-registry/ emit the defect verbatim (ecosystem/reposystem-tool.ncl:150, elixir/phoenix-service.ncl:468, gitbot/fleet-bot.ncl:439, plus haskell/julia/rescript ones), as the README badge line where the badge URL already says MPL-2.0 and only the alt text says PMPL. Meanwhile PR #648 already cleared most of standards' residue: live count is 12 files, 10 of them inside directories #479 is evicting.

    → Six one-line edits in scaffoldia, then re-propagate per the runbook §1/§3. Small, and now precisely located. (Adjacent, not this issue: 497 files in standards still carry unfilled {{AUTHOR}}/{{OWNER}}/{{CURRENT_DATE}} placeholders.)

  4. hyperpolymath commented on Aug 31, 2026

    @hyperpolymath
    OwnerAuthor

    Re-measured 2026-08-31 — confirmed, and larger than the last estimate. The generator source is still defective on scaffoldia main: 6 of 7 harvested-registry templates, 28 PMPL lines total (not "six one-line edits") — every affected template carries license = "PMPL-1.0-or-later" metadata at line 10 plus the mixed badge MPL--2.0-blue.svg[License: PMPL-1.0]; rescript/deno-app.ncl additionally has three SPDX PMPL headers (lines 1/89/126) and a badge URL that is itself PMPL. rust/library.ncl is the only clean one. scaffoldia's .well-known/humans.txt line 12 still reads License: MPL-2.0 (Palimpsest MPL); rsr-template-repo's is clean.

    Downstream propagation re-confirmed on remote default branches: 5 repos carry the emitted badge line — ambientops (traffic-conditioner/README.adoc), ViableSystems.jl, ShellIntegration.jl, SiliconCore.jl, SoftwareSovereign.jl. standards' own residue by this issue's declaration metric (License: PMPL, excluding the 4 sanctioned carve-outs): 17 files.

    Stays open as REAL WORK. Fix order: templates → humans.txt → regenerate/patch the 5 consumers → standards residue.

  5. hyperpolymath commented on Sep 17, 2026

    @hyperpolymath
    OwnerAuthor

    Template-arm landed: PR #835 MERGED (482c1feb) — 1-formats/templates/STATE.a2ml.template:46 now teaches the per-category default and the palimpsest carve-out, and the §7a runbook carries the source-status note (follow-up PR riding). Issue stays open by design: the survivors are the owner-run re-propagation/residue clean and the AI-MANIFEST lines as #643-residue candidates.

  6. hyperpolymath commented on Sep 21, 2026

    @hyperpolymath
    OwnerAuthor

    Clarification from the adjacent factory, 2026-09-21: iseriser is not the §7a source. iseriser generates the -iser family (29 repos) and emitted live PMPL licence text until hyperpolymath/iseriser#106 (now MPL-2.0). The §7a surface is body-text License: lines in humans.txt / trust.txt / REUSE dep5 / README.adoc from the rsr template family. The runbook's candidate sources (rsr-template-repo, scaffoldia, llm-warmup-*) remain the right hunt.
    One observation for whoever takes this: iseriser's template tokens were fixed by pairing the generator fix with a contractile.just grep-gate, which catches re-drift at build time — the same gate pattern travels well if you want a ratchet on the §7a fix.

  7. hyperpolymath commented on Sep 21, 2026

    @hyperpolymath
    OwnerAuthor

    Source located (2026-09-21) — and the fix is open: hyperpolymath/developer-ecosystem#215

    Authenticated code-search locator pass over the issue's three candidates:

    • rsr-template-repo — clean: no carrier files remain.
    • scaffoldia — not the emitter: the six PMPL-bearing files under machine-readable-design/harvested-registry/ are harvest data, and that directory's README already records the caveat: "flagged not fixed (no automated licence edits — ever)" with "owner review needed before any consumer uses it". Per that standing directive I did not flip them. Carriers for the owner's per-file review: julia/package.ncl (named in the README), haskell/stack-library.ncl, elixir/phoenix-service.ncl, gitbot/fleet-bot.ncl, ecosystem/reposystem-tool.ncl, plus rescript/deno-app.ncl (banned-language legacy, harvest-only).
    • developer-ecosystem — the emitter. The PR above flips the six source/template lines (llm-warmup-dev/user.adoc, QUICKSTART-MAINTAINER.adoc, ABI-FFI-README.adoc, stapeln.toml, www/.well-known/humans.txt) to the canonical Rule-1 form, exactly per §7a's "fix at the source, THEN re-propagate".

    Per the runbook's ordering, the re-propagation (template-sync machinery) and residue cleanup — including the ~139 body-text matches inside developer-ecosystem's own vendored subtrees, which are instances not sources — follow the source merge, with §1/§3 carve-outs excluded. That follow-on is tracked here; the locator question this issue filed is answered by the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p2Normal - queue itscope:estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked uptech-debtKnown shortcut, drift, or hygiene owed - includes cleanup

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions