From dad74f0ad95deae9156f451a40f2932cedf2c747 Mon Sep 17 00:00:00 2001 From: BootIntel Agent Date: Wed, 7 Oct 2026 10:59:38 +0000 Subject: [PATCH] Ship the licence in release tarballs The packaging steps copied `../LICENSE`, which points outside the checkout: the step runs at the repo root, where the file is `LICENSE`. The path never matched, and `2>/dev/null || echo "LICENSE not found at repo root; skipping"` turned that into a log line nobody reads. The Windows step had the same path wrapped in a `Test-Path` guard, which hid it the same way. So every release has shipped with no licence file while this workflow's own header claims it "bundles each binary with LICENSE + README". Verified against the published 0.13.0 x86_64-linux tarball: `./`, `./README.md`, `./bootintel` and nothing else. The repo is Apache-2.0, and section 4(a) requires giving recipients a copy of the licence with the work, so this is a distribution defect rather than a tidiness one. Found while verifying the 0.14.0 draft before publishing it. The draft is being rebuilt on this fix rather than published as-is. Both copies are now unguarded. A missing licence should fail the release, since tolerating the miss is what kept it invisible for six releases. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/cli-release.yml | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/.github/workflows/cli-release.yml b/.github/workflows/cli-release.yml index 36e8927..5d5c5dc 100644 --- a/.github/workflows/cli-release.yml +++ b/.github/workflows/cli-release.yml @@ -166,7 +166,16 @@ jobs: mkdir -p dist cp target/${{ matrix.target }}/release/bootintel dist/ cp README.md dist/ - cp ../LICENSE dist/ 2>/dev/null || echo "LICENSE not found at repo root; skipping" + # LICENSE, not ../LICENSE. The step runs at the repo root, so the old + # path pointed outside the checkout, never matched, and the + # `2>/dev/null || echo skipping` turned that into a log line nobody + # read. Every release from here back shipped with no licence file + # while this workflow's header claimed it bundled one, and Apache 2.0 + # section 4(a) requires giving recipients a copy with the work. + # + # No fallback now: if the licence is missing the release should fail, + # because a silent skip is what hid this. + cp LICENSE dist/ tar -czf ${{ matrix.asset_name }} -C dist . - name: Package (Windows) @@ -177,7 +186,10 @@ jobs: New-Item -ItemType Directory -Force -Path dist | Out-Null Copy-Item "target\${{ matrix.target }}\release\bootintel.exe" -Destination "dist\" Copy-Item README.md -Destination "dist\" - if (Test-Path "..\LICENSE") { Copy-Item "..\LICENSE" -Destination "dist\" } + # Same bug, same reason: ..\LICENSE is outside the checkout, and the + # Test-Path guard made the miss invisible. Unguarded now so a missing + # licence fails the build. + Copy-Item LICENSE -Destination "dist\" Compress-Archive -Path "dist\*" -DestinationPath ${{ matrix.asset_name }} - name: Compute SHA256