Files
ConformalLabpp/doc/reviewer/dependency-license-audit-2026-05-31.md
Tarik Moussa 74d41e99a8 docs(reviewer): update audit status + add finding-orchestration plan
Session 1 (2026-05-31) resolved 26 findings across Sonnet/Haiku/Opus; 298/298
CGAL tests green.  Bring the audit docs in line with reality:

- README.md: G0 banner now records that the original authors were contacted by
  email about porting/relicensing rights (awaiting reply); headline-status cells
  updated per finding; new "Session 1 — implemented" record; link to the plan.
- Per-audit resolution banners (api-performance, numerical-stability,
  input-validation, test-coverage, math-citation, thread-safety) + G0-blocked
  banners (cgal-submission, dependency-license).
- NEW finding-orchestration.md: the meta-plan mapping every finding to a session,
  an implementing model (Haiku/Sonnet/Opus by the "how much must be understood"
  rule), and an Opus review gate after each implementation session.  Records S1
  (done) and lays out S2–S6 so the next session can be picked up cold.

Docs only — no code change.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-31 19:44:50 +02:00

174 lines
7.9 KiB
Markdown

# Dependency & License-Compatibility Audit — ConformalLabpp
**Date:** 2026-05-31
**Auditor:** External reviewer (Claude Opus 4.8)
**Scope:** Vendored/auto-fetched dependencies, their license compatibility, and the
provenance/license of bundled **data assets** (test meshes).
**Focus:** Is the dependency + data licensing coherent — especially in light of the
unresolved provenance/license blocker (CGAL audit **G0/G1**)?
Status legend: 🔴 Critical · 🟡 Important · 🔵 Polish
> **🔄 Status (2026-05-31):** **D1/D2 blocked by G0** — the dependency/licensing
> matrix rests on the MIT premise that G0 (porting rights) undermines. The
> original authors have been **contacted by email**; no licensing action until
> their reply. Scheduled **S6** (after G0/G1) in
> [`finding-orchestration.md`](finding-orchestration.md).
> **Good news up front:** a `code/deps/THIRD-PARTY-LICENSES.md` already exists and is
> a genuinely good per-dependency compatibility matrix (CGAL, Eigen, libigl, GLFW,
> nlohmann/json). This audit does **not** redo that work. It flags two things that
> matrix cannot see: (D1) it is built on the MIT premise that G0 undermines, and
> (D2) the bundled **test meshes have no provenance or license at all**.
---
## Summary table
| ID | Sev | Title | Location |
|----|-----|-------|----------|
| D1 | 🔴 | The dependency-license matrix is predicated on "conformallab++ is MIT" — a premise CGAL-audit G0 shows is unfounded; the whole compatibility conclusion is conditional on the unresolved license decision | `code/deps/THIRD-PARTY-LICENSES.md` |
| D2 | 🔴 | Bundled test meshes (`cathead.obj`, `brezel*.obj`, torus OFFs) have **no provenance and no license** — likely third-party / Varylab-origin, redistributed without attribution | `code/data/` |
| D3 | 🟡 | No per-dependency license *files* under most vendored trees (only GLFW ships one); the matrix is the only record | `code/deps/*/` |
| D4 | 🔵 | Vendored-tarball integrity is asserted ("bit-for-bit identical") but not checksum-verified in-repo | `code/deps/tarballs/` |
---
## D1 — 🔴 License matrix is conditional on the unresolved MIT premise
### Evidence
`code/deps/THIRD-PARTY-LICENSES.md` opens its analysis with:
> *"## conformallab++ itself … **MIT** … Every C++ source file carries
> `SPDX-License-Identifier: MIT`"*
and every dependency row evaluates "**Compatibility with MIT distribution**".
### Problem
The matrix's central column — and therefore its conclusion that everything is
distributable — assumes conformallab++ *is* MIT-licensed and *may* be distributed as
MIT. CGAL-audit **G0** establishes that this premise is unfounded: the code is a
documented port (derivative work) of the unlicensed Varylab/TU-Berlin project, so the
MIT grant itself is on shaky ground. Two consequences cascade:
1. If porting rights are **not** granted, there is no valid MIT (or any) license to
be "compatible with" — the matrix evaluates compatibility against a license the
project may not be entitled to use.
2. If the project relicenses to **GPLv3+** for CGAL submission (G1), the entire
"compatible with MIT distribution" analysis must be **redone against GPLv3+**
(e.g. the CGAL LGPL/GPL split, Eigen's MPL-2.0, libigl's MPL-2.0 are all
GPL-compatible — but that needs stating, not assuming).
### Fix
- Resolve G0/G1 first (owner-level).
- Then re-run the matrix against the *actual* outbound license. Add a column
"compatibility with GPLv3+ distribution" if the CGAL path is taken.
- Until resolved, annotate `THIRD-PARTY-LICENSES.md` with a banner that its
conclusions are conditional on the pending G0/G1 decision.
### Acceptance criteria
- The matrix's outbound-license assumption matches the resolved G0/G1 outcome and is
re-evaluated against it.
---
## D2 — 🔴 Bundled test meshes have no provenance or license
### Evidence
```
code/data/obj: brezel.obj brezel2.obj cathead.obj tetraflat.obj
code/data/off: simple_cupe.off torus_4x4.off torus_8x8.off torus_hex_6x6.off torus_skewed_4x4.off
```
`find code/data -iname '*readme*' -o -iname '*licen*' -o -iname '*source*'`**nothing.**
### Problem
These meshes are committed and redistributed with the project, used by the smoke and
parity tests (`test_scalability_smoke.cpp`, `test_geometry_utils.cpp` references
`brezel2.obj`, etc.). But:
- `cathead.obj` is a **well-known third-party mesh** that circulates in graphics
courses/datasets — it is almost certainly not original to this project and carries
whoever's terms.
- `brezel.obj` / `brezel2.obj` ("Brezel" = pretzel; genus-1/genus-2) are the exact
example surfaces used in the **Varylab/TU-Berlin** discrete-conformal work — i.e.
likely the *same* upstream as the G0 code-provenance problem.
Redistributing third-party data assets without attribution or a license is the same
class of issue as the code port (G0), and CGAL submission would flag it: CGAL example
data must have clear redistribution rights.
### Fix
- Establish each mesh's origin and license. For `cathead.obj`, identify the standard
source and its terms. For the `brezel*` meshes, this is part of the **same
conversation with the Varylab/TU-Berlin authors** as G0.
- Add `code/data/PROVENANCE.md` listing each file: source, author, license, URL.
- Replace any mesh whose redistribution rights cannot be confirmed with a
cleanly-licensed or self-generated equivalent (the torus OFFs look procedurally
generated — confirm and document that, which would make them safe).
### Acceptance criteria
- Every file under `code/data/` has documented provenance + redistribution rights;
unconfirmed assets are replaced.
---
## D3 — 🟡 Most vendored trees ship no license file
### Evidence
```
eigen-3.4.0: NONE FOUND CGAL-6.1.1: NONE FOUND
libigl-2.6.0: NONE FOUND glfw-3.4: LICENSE.md ✓
```
Only GLFW retains its upstream license file; the others rely solely on the central
`THIRD-PARTY-LICENSES.md`.
### Problem
When vendoring source trees, the upstream LICENSE/COPYING file should travel with the
code (it is usually a license *requirement* — MPL-2.0 and LGPL both require preserving
license notices). A central summary is good practice but does not substitute for the
upstream notice files inside each tree.
### Fix
Restore each upstream license file into its vendored tree (`eigen-3.4.0/COPYING.*`,
`CGAL-6.1.1/LICENSE*`, `libigl-2.6.0/LICENSE*`). They were likely stripped during
trimming of the vendored copies.
### Acceptance criteria
- Each vendored dependency tree contains its upstream license notice file.
---
## D4 — 🔵 Vendored tarball integrity not checksum-verified
### Evidence
`THIRD-PARTY-LICENSES.md` states the cached tarballs are "bit-for-bit identical to the
upstream releases", but no checksum manifest is committed.
### Problem
The reproducibility claim (the stated rationale for vendoring) rests on an unverified
assertion. A corrupted or substituted tarball would not be detected.
### Fix
Commit a `code/deps/tarballs/SHA256SUMS` and verify it in the extraction step of the
CMake/deps logic.
---
## What is already good
- `THIRD-PARTY-LICENSES.md` is a thorough, honest per-dependency matrix with real
compatibility reasoning (the CGAL LGPL/GPL split, Eigen's NonMPL2 gating, the
viewer-only scope of libigl/GLFW) — excellent practice, just built on a premise
(D1) that G0 destabilizes.
- The dependency choices themselves are clean: Eigen (MPL-2.0), libigl (MPL-2.0),
GLFW (zlib), nlohmann/json (MIT) are all permissive; only CGAL carries copyleft, and
its header-only LGPL consumption is correctly reasoned.
- Vendoring at fixed versions for build reproducibility is a defensible choice and is
documented.
## Suggested order
1. **D2** (data provenance) — couple with the G0 conversation; CGAL-blocking and the
most clearly missing piece.
2. **D1** (re-base the matrix on the resolved license) — after G0/G1.
3. **D3** (restore upstream license files) — quick, and likely a license requirement.
4. **D4** (checksum manifest) — polish.