Skip to content

docs(license): add MPL-2.0 LICENSE for TIWCG software - #7

Merged
erinepshovel-code merged 3 commits into
mainfrom
repair/license-mpl-software
Sep 27, 2026
Merged

erinepshovel-code merged 3 commits into
mainfrom
repair/license-mpl-software

Conversation

@erinepshovel-code

@erinepshovel-code erinepshovel-code commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

What was wrong

tiwcg has never had a LICENSE, so by default all rights are reserved. Erin's 2026-09-26 rights audit of the org's repos found no license grant in tiwcg's history. The target is MPL-2.0 for the software (engine/, render/, mobile/) and, in a later step, a Creative Commons share-alike license for the rules text. The software license comes first. Rules text and card data wait.

What changed

  • LICENSES/MPL-2.0.txt (new): canonical MPL-2.0 text from https://www.mozilla.org/media/MPL/2.0/index.txt, in the REUSE layout. (Second follow-up) The root LICENSE this PR first added was removed on review, so this is now the only copy of the text.
  • REUSE.toml (new, follow-up): the scope from README in machine-readable form, per REUSE Specification 3.x [[annotations]], with no per-file headers:
    • MPL-2.0, SPDX-FileCopyrightText = "2026 Erin Spencer": engine/**, render/**, mobile/**, scared-sacred_msdmd.ts, .github/**, .gitignore, REUSE.toml;
    • MPL-2.0: .agents/** (skill copies from The-Interdependency/skill-lib).
  • README.md ## License: states the scope, points to LICENSES/MPL-2.0.txt and REUSE.toml, and lists every path that is still unlicensed: canon/, base-game/ (rules text and *.json card data), expansions/, funding/, PLAN.md, docs/ (icon artwork) and README.md.
  • Choice made: .github/ and .gitignore are MPL-2.0 (tooling). README.md is left unlicensed because it carries game content (the L1–L3 layer descriptions and The Litany) alongside the licensing map, and the README scoping keeps game content out of MPL.
  • No third-party code found. No manifest carries a license field (mobile/android/*.gradle.kts has none).

Verification

  • cmp LICENSES/MPL-2.0.txt <(curl -sL https://www.mozilla.org/media/MPL/2.0/index.txt): identical.
  • Removing the root LICENSE left reuse lint output byte-for-byte unchanged (diff of the before/after output is empty), because REUSE ignores root LICENSE files.
  • reuse lint (reuse 6.2.0): 46/146 files carry license and copyright information. The 100 files it reports as missing are exactly base-game/ (93), canon/ (2), expansions/ (1), funding/ (1), PLAN.md, README.md and docs/icon.svg, as intended. No missing, unused or invalid licenses. The overall result is "not compliant" on purpose until the rules-text license is chosen.
  • Same gates as .github/workflows/test.yml, re-run on head b6e871d: python -m compileall -q engine render OK. engine: 50 tests OK (includes test_plan_contract.py, which reads README.md). render: 4 tests OK.
  • CI on head b6e871d: test and CodeQL all green.

License detection

licensee detect . (licensee 10.1.0) on this branch's checkout (head b6e871d):

License:        MPL-2.0
Matched files:  LICENSES/MPL-2.0.txt, README.md
LICENSES/MPL-2.0.txt:
  Confidence:    100.00%
  Matcher:       Licensee::Matchers::Exact
  License:       MPL-2.0
README.md:
  Confidence:    90.00%
  Matcher:       Licensee::Matchers::Reference
  License:       MPL-2.0

On main, gh api repos/The-Interdependency/tiwcg/license currently returns 404. Detection updates only after merge to main.

hmmm

  • Licensing for rules text and card data (base-game/*.json, 88 files) is undecided and needs Erin's decision. When it is made, adding a [[annotations]] block for those paths in REUSE.toml, plus the license text under LICENSES/, will make reuse lint pass.
  • REUSE.toml records a 2026 Erin Spencer copyright on the software. AI-assisted commits (Claude, Codex) are part of the history, and their copyright status is a separate question.
  • Third-party referential exemplars in game content (PLAN.md: "not a license determination for commercial use") remain open.
  • This is licensing hygiene, not legal advice.

RIGHTS-AUDIT Phase 1.4: tiwcg never had a LICENSE. Add the canonical
MPL-2.0 text and a README License section scoping it to the software
(engine/, render/, mobile/). Rules text and card data stay hmmm
pending the Phase 2 rules-text license split.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T06:36:23.760578Z b6e871d New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1de370d560

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md Outdated
Comment on lines +35 to +36
`MPL-2.0`). The full text is in [`LICENSE`](LICENSE). "Software" here means
`engine/`, `render/`, `mobile/` and `scared-sacred_msdmd.ts`. The skills under

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Exclude the card-data source from the software grant

Licensing all of engine/ also licenses the card data that this section says is still pending: engine/weimar_data.py declares itself the set's executable-data source, and engine/cards_export.py copies those dictionaries into base-game/**/*.json nearly verbatim. Once this grant is distributed, that content has already been made available under MPL-2.0 even if the generated JSON directory is nominally excluded, defeating the intended licensing split; carve the data-bearing engine modules out of this grant or move the data outside the licensed software boundary first.

Useful? React with 👍 / 👎.

Comment thread README.md Outdated
Comment on lines +45 to +46
Usage: when you reuse TIWCG code, keep the MPL-2.0 notice and publish your
changes to MPL-covered files under MPL-2.0. This section is a licensing map,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Limit the source-sharing instruction to distribution

For users who only modify or use the code privately, this instruction incorrectly says they must publish their changes. MPL-2.0 Sections 3.1–3.2 impose source-availability requirements when covered software is distributed, and even then the source may be supplied to recipients rather than published publicly; qualify this guidance accordingly so it does not materially overstate users' obligations.

Useful? React with 👍 / 👎.

Review follow-up: REUSE.toml (REUSE spec 3.x, no per-file headers) marks
engine/, render/, mobile/, scared-sacred_msdmd.ts, .github/, .gitignore
and .agents/ as MPL-2.0, and LICENSES/MPL-2.0.txt provides the REUSE copy.
README lists the remaining unlicensed paths (rules text, card data,
docs/, PLAN.md, README.md).
Review nit: the MPL-2.0 text now lives only at LICENSES/MPL-2.0.txt
(REUSE layout). README points there. licensee still detects MPL-2.0
and reuse lint output is unchanged.
@erinepshovel-code
erinepshovel-code merged commit c213739 into main Sep 27, 2026
5 checks passed
erinepshovel-code added a commit that referenced this pull request Sep 27, 2026
The final commit of #7 dropped the root LICENSE and kept only
LICENSES/MPL-2.0.txt. GitHub's license detection reads only the repo
root, so tiwcg showed no license. Add a root LICENSE byte-identical to
LICENSES/MPL-2.0.txt (the official MPL-2.0 text).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant