Skip to content

legal: close incoming IP provenance for the first Apache release #3268

Description

@M4n5ter
English

Part of #2974 — G1: incoming IP and provenance.

Outcome

Establish that the code intended for the first Apache Maka release has the
required provenance and incoming-IP coverage, with the remaining human and ASF
determinations recorded explicitly.

Exit criteria

  • A human contributor of record reviews the final evidence and conclusions
    in docs: close code origin audit #2907. docs: close code origin audit #2907 was reviewed by a non-author committer and merged on
    2026-08-22.
  • The bootstrap contributor confirmations listed in docs: close code origin audit #2907 are complete, or
    the affected facts and dependent code are independently replaced.
  • Initial committer ICLAs and the applicable SGA coverage are confirmed
    through the appropriate ASF process.
  • Material non-initial contributors are triaged and any required ICLA, SGA,
    CCLA, or other action is resolved.
  • Mentors, the IPMC, or ASF Legal Affairs provide the required determination
    for the retained code and evidence.
  • The public podling status is updated when the corresponding rights items
    are complete.

Existing work

Do not use Closes on #2907 until every exit criterion above is satisfied. The
PR can land as evidence before the wider gate is closed.

Out of scope

  • ASF source headers and RAT configuration.
  • Artifact-specific LICENSE and NOTICE changes.
  • Release-candidate construction and voting.

References

Ownership

The assignee coordinates this gate because they own the direct audit PR. Legal
and release approval remain with the appropriate human contributors, PPMC,
mentors, IPMC, and ASF Legal Affairs.

简体中文

#2974 的一部分——G1:代码来源与知识产权输入。

目标结果

确认第一次 Apache Maka 发版所含代码具备所需的来源和知识产权输入覆盖,并明确记录
剩余的人工及 ASF 判断。

完成条件

  • 人工贡献负责人审查 docs: close code origin audit #2907 中最终的证据和结论。docs: close code origin audit #2907 已由非作者 committer 审查,
    并于 2026-08-22 合并。
  • 完成 docs: close code origin audit #2907 所列的初始代码贡献者确认,或者独立替换受影响的事实及依赖代码。
  • 通过适当的 ASF 流程确认初始 committer 的 ICLA 和适用的 SGA 覆盖。
  • 完成对非初始 committer 的实质性贡献者审查,并解决所需的 ICLA、SGA、CCLA
    或其他措施。
  • Mentors、IPMC 或 ASF Legal Affairs 对保留的代码与证据给出所需判断。
  • 相应权利事项完成后更新公开的 podling 状态。

已有工作

在上述全部完成条件满足前,不要让 #2907 使用 Closes。该 PR 可以先作为证据合并,
而更大的 gate 继续保持开放。

不在范围内

  • ASF 源码 headers 和 RAT 配置。
  • 针对具体 artifact 的 LICENSE 和 NOTICE 修改。
  • RC 构建与投票。

参考资料

负责人边界

Assignee 因直接负责审计 PR 而协调这一 gate。法律和发版批准仍由相应人工贡献者、
PPMC、mentors、IPMC 和 ASF Legal Affairs 负责。

Activity

  1. Astro-Han commented on Aug 20, 2026

    @Astro-Han
    Contributor

    #3293 tracks the independent-replacement path for the Computer Use cursor values, so this gate no longer depends on a determination that they may stay. The alternative exit remains open until that work lands.

    简体中文

    #3293 跟踪 Computer Use 光标数值的独立替换路径,因此这一 gate 不再依赖"这些数值可以保留"的判断。在该工作完成前,另一条出口仍然保留。

  2. Astro-Han commented on Aug 21, 2026

    @Astro-Han
    Contributor

    Contributor triage for the fourth exit criterion

    Three facts, submitted for the mentors' judgement rather than as a proposed action. The fifth exit criterion reserves that judgement, and nothing below assumes an outcome.

    1. The seven initial committers map cleanly to git identities. Cross-referencing the repository's push-capable collaborators against the podling status page, and removing ASF infrastructure accounts and the mentors and champion, leaves exactly seven: jackwener (Jie Wen), Astro-Han (Yuhan Lei), likun666661 (Kun Li), YayoiNanoka (Zhanghan Gao), hqhq1025 (Haoqing Wang), MicroGery (Yuhang Chang), M4n5ter (Yongtao Wang). Their coverage is the third exit criterion, not this one.

    2. The repository carried no license notice for its first two months. The first commit is 2026-05-19. LICENSE and the package.json license field were both added on 2026-07-25 by #1484; CONTRIBUTING.md's "By contributing you agree that your contributions are licensed under the Apache License 2.0" followed on 2026-08-08 in #2508. GitHub's Terms of Service §D.6 conditions inbound=outbound on adding content "to a repository containing notice of a license," so it does not reach contributions made before 2026-07-25.

    By git blame -w -M -C over the 2,661 tracked source files (excluding generated files, lockfiles, notice artifacts, and binaries), 311,400 of 860,845 surviving lines — 36% — were introduced before that date.

    For comparison, OpenDAL carried LICENSE from its first commit on 2022-02-14, so its chain was unbroken. We are raising this because that difference may or may not matter to how the third criterion's paperwork is scoped, and that is not ours to decide.

    3. Four non-initial contributors are large enough to be worth naming. Surviving lines introduced before 2026-07-25:

    Contributor Lines Area
    UncertaintyDeterminesYou4ndMe 27,449 foreign session store, backend and CLI test suites
    zhiiw 10,088 Git workspace service, SQLite runtime store
    Mingqwqqaq 8,441 desktop localization, Linux sandbox worker
    ACMerJuyu 3,884 Deep Research

    Below these the next contributor is at 2,657 lines and the tail falls away quickly; we read the remainder as small contributions in the sense of Apache-2.0 §5 and are not proposing action on them. All four accounts are active, so contacting them is possible if the mentors decide it is needed.

    简体中文

    第四条完成条件的贡献者审查

    以下三点是提交给 mentors 判断的事实,而非提议的行动。第五条完成条件保留了这一判断权,下文不预设任何结论。

    1. 七位 initial committer 与 git 身份可以准确对应。 将仓库中具有 push 权限的协作者与 podling 状态页交叉比对,去掉 ASF 基础设施账号以及 mentors 和 champion 后,恰好剩下七人:jackwener(Jie Wen)、Astro-Han(Yuhan Lei)、likun666661(Kun Li)、YayoiNanoka(Zhanghan Gao)、hqhq1025(Haoqing Wang)、MicroGery(Yuhang Chang)、M4n5ter(Yongtao Wang)。他们的覆盖属于第三条完成条件,不属于本条。

    2. 仓库最初两个月没有任何 license 声明。 首个 commit 为 2026-05-19。LICENSE 与 package.json 的 license 字段都是在 2026-07-25 由 #1484 一并加入;CONTRIBUTING.md 中「By contributing you agree that your contributions are licensed under the Apache License 2.0」这句则更晚,于 2026-08-08 在 #2508 加入。GitHub 服务条款 §D.6 将 inbound=outbound 的前提限定为向「containing notice of a license」的仓库添加内容,因此它无法覆盖 2026-07-25 之前的贡献。

    对 2,661 个纳入统计的源文件(排除生成文件、lockfile、notice 产物和二进制)执行 git blame -w -M -C,当前存活的 860,845 行中有 311,400 行(36%)是在该日期之前引入的。

    作为对照,OpenDAL 自 2022-02-14 首个 commit 起就带有 LICENSE,其链条未曾中断。我们提出这一点,是因为这一差异可能影响、也可能不影响第三条完成条件的文书范围,而这不是我们能决定的。

    3. 有四位非 initial committer 的贡献量足以单独列出。 2026-07-25 之前引入且当前仍存活的行数:

    贡献者 行数 涉及范围
    UncertaintyDeterminesYou4ndMe 27,449 foreign session store、backend 与 CLI 测试套件
    zhiiw 10,088 Git workspace service、SQLite runtime store
    Mingqwqqaq 8,441 桌面端本地化、Linux sandbox worker
    ACMerJuyu 3,884 Deep Research

    再往下一位是 2,657 行,此后迅速衰减;我们将其余部分理解为 Apache-2.0 §5 意义上的小额贡献,不就其提出任何行动建议。上述四个账号目前均活跃,若 mentors 认为有必要联系,是可以联系到的。

  3. added
    enhancementNew feature or request
    and removed
    enhancementNew feature or request
    on Aug 23, 2026
  4. added theissue type on Aug 29, 2026
  5. Astro-Han commented on Sep 1, 2026

    @Astro-Han
    Contributor
    English

    Proposing closure: the substantive criteria are met, and the rest are not release gates

    This gate was written as if incoming IP clearance were a pre-vote checklist item. Comparing it against how ASF projects actually run a source release, that framing does not hold. Below is the evidence for each remaining criterion. Mentors and the IPMC own the final determination and can reopen this if they read any item differently.

    Initial committer ICLAs are on file — verifiable in public LDAP

    All seven initial committers hold live ASF accounts. An Apache ID is only created after the Secretary records an ICLA, so this criterion is already satisfied and independently checkable:

    Apache ID Name Account created
    jakevin Jie Wen 2022-08-29
    wyt Yongtao Wang 2026-08-14
    astrohan Yuhan Lei 2026-08-16
    kunli Kun Li 2026-08-16
    yayoinanoka Zhanghan Gao 2026-08-16
    haoqing Haoqing Wang 2026-08-16
    microg Yuhang Chang 2026-08-16

    Source: https://whimsy.apache.org/public/public_ldap_projects.json (projects.maka) cross-referenced with https://whimsy.apache.org/public/public_ldap_people.json.

    The SGA is an incubation setup item, not a release item

    The software grant is tracked on the podling status page under Copyright and is handled by the Incubator and the Secretary. It is not a step in any ASF release process, and no release checklist asks a Release Manager to confirm it.

    Non-initial contributors do not need individual ICLAs

    Per LEGAL-704 and the current ASF contributor agreements guidance, ordinary contributions submitted through pull requests are licensed to the ASF under Apache-2.0 Clause 5. This issue's own earlier triage comments already cite that guidance.

    Updating the podling status page is mentor documentation upkeep

    The Copyright and contributor-agreement rows on https://incubator.apache.org/projects/maka.html are still blank. That is a record-keeping lag, not an outstanding rights problem, and most podlings cut their first release with those rows unticked. Worth asking a mentor to update, but it does not gate a candidate.

    The engineering work closed two weeks ago

    What actually checks this at release time

    The one IP-related property an ASF release vote does check is that the source package contains no unaccounted or incompatible third-party material and no unexpected binary files. That is verified against the exact candidate by every voter, and it is now recorded in #2974 as part of the verification checklist carried in the vote email.

    For comparison, Apache OpenDAL's release runbook — 595 lines covering the complete process — contains no ICLA, SGA, IP-clearance, or provenance step. Its entire "Preparation" section asks the Release Manager to set up a GPG key. The legal properties are checked inside the vote, by the voters.

    Proposal

    Close this issue. #2974 now carries the pre-vote readiness checklist and the in-vote verification checklist that replace it. If a mentor or IPMC member reads any criterion above as still outstanding, please say so on this issue and we will reopen it rather than proceed.

    简体中文

    提议关闭:实质条件已满足,其余几条不是发布门槛

    这个 gate 当初是按「投票前的 IP 清理检查表」写的。对照 ASF 项目实际执行源码发布的方式,这个定位站不住。下面逐条给出证据。最终判定权在导师和 IPMC,如果有任何一条读法不同,可以重开。

    初始 committer 的 ICLA 已在案——公开 LDAP 可直接验证

    7 位初始 committer 全部持有活跃 ASF 账号。Apache ID 只有在秘书处登记 ICLA 之后才会创建,因此这一条已经满足,且可独立核验:

    Apache ID 姓名 账号创建时间
    jakevin Jie Wen 2022-08-29
    wyt Yongtao Wang 2026-08-14
    astrohan Yuhan Lei 2026-08-16
    kunli Kun Li 2026-08-16
    yayoinanoka Zhanghan Gao 2026-08-16
    haoqing Haoqing Wang 2026-08-16
    microg Yuhang Chang 2026-08-16

    来源:https://whimsy.apache.org/public/public_ldap_projects.json(projects.maka)与 https://whimsy.apache.org/public/public_ldap_people.json 交叉核对。

    SGA 是入孵事项,不是发布事项

    软件授权书记录在孵化状态页的 Copyright 栏,由孵化器和秘书处办理。它不是任何 ASF 发布流程中的步骤,也没有任何发布检查表要求 Release Manager 确认它。

    非初始贡献者不需要单独的 ICLA

    依据 LEGAL-704 和当前的 ASF 贡献者协议指南,通过 pull request 提交的普通贡献已按 Apache-2.0 第 5 条授权给 ASF。本 issue 早前的分类评论已经引用过这条指南。

    更新孵化状态页属于导师的文档维护

    https://incubator.apache.org/projects/maka.html 上 Copyright 和贡献者协议两栏仍是空白。那是记录滞后,不是尚未解决的权利问题;绝大多数 podling 发布第一个版本时那些框都还没勾。值得请导师更新,但它不构成候选版本的门槛。

    工程部分两周前就已完成

    发布时真正检查这件事的地方

    ASF 发布投票确实会检查的、与 IP 相关的性质只有一条:源码包中不含来源不明或不兼容的第三方材料,也没有意外的二进制文件。这一条由每位投票人针对确切候选包核验,现已记入 #2974 中随投票邮件下发的验证清单。

    作为对照,Apache OpenDAL 的发布手册——595 行,覆盖完整流程——没有任何 ICLA、SGA、IP clearance 或 provenance 步骤。它整个「Preparation」章节只要求 Release Manager 配置好 GPG 密钥。法务性质由投票人在投票过程中检查。

    提议

    关闭本 issue。#2974 已经承接了取代它的投票前就绪清单和投票内验证清单。如果导师或 IPMC 成员认为上述任何一条仍未了结,请在本 issue 说明,我们会重开而不是继续推进。


    Drafted with help from Claude Code. I reviewed the final text and take responsibility for posting it.

  6. Astro-Han commented on Sep 20, 2026

    @Astro-Han
    Contributor

    Hi @Xuanwo, thanks again for talking this through with me.

    I’ve tried to contact @Mingqwqqaq and @ACMerJuyu about ICLAs but haven’t been able to reach them. Their contributions are still in the source tree.

    From our conversation, I understood that I could proceed with the first release with those contributions included under the existing licensing. Did I understand that correctly? A brief explanation here would help me answer Justin’s question on the release vote.

    Thanks!

  7. github-actions commented on Sep 20, 2026

    @github-actions
    No description provided.
  8. Astro-Han commented on Sep 22, 2026

    @Astro-Han
    Contributor

    Hi @Xuanwo, a quick update: I’ve now reached @Mingqwqqaq, and the ASF Secretary team has confirmed that his ICLA is filed.

    I also removed the Deep Research implementation in #5554. Six generic type/JSX lines attributable to @ACMerJuyu remain, so I’m not claiming that all of his contributions have been removed.

    This updates my earlier comment that I hadn’t been able to reach either contributor. I’ve opened #5583 to correct the outdated disclaimer and will explain the initial-code authorization basis in the RC2 vote, alongside the RC1 fixes.

    Thanks again for your help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions