cncf / cncf/foundation

[License Exception Request] [OpenShell] [Unicode-3.0 build dependency]

Open
#1,518 2 comments 0 reactions 3 assignees Claimed by @krook View on GitHub
licensing needs-review
Dominant language
Rich Text Format
Stars
695
Forks
861
Avg merge
12h 19m
Merged PRs (30d)
23

Description

### For which CNCF project are you requesting exceptions?

OpenShell

### Are you an official maintainer of this project?

Yes

### List of components requiring an exception

| Component | Upstream URL | Project Usage URL | License(s) | Purpose |
|-----------|--------------|-------------------|------------|---------|
| unicode-ident 1.0.24 | https://github.com/dtolnay/unicode-ident | https://github.com/NVIDIA/OpenShell/blob/main/Cargo.lock | (MIT OR Apache-2.0) AND Unicode-3.0 | Build-time dependency of proc-macro2 and Rust procedural macros, providing Unicode identifier classification required when compiling OpenShell. |

### Distribution and integration model

- [ ] **CNCF-Distributed**: The CNCF project will distribute the dependency or the resulting combined artifacts to users.
- [x] **User-Fetched Dependency**: The CNCF project code will cause the user's system to automatically retrieve the dependency from an upstream source at build, install, or runtime.
- [ ] **System Component**: The CNCF project expects that the dependency will either already be present on the user's system or will be installed independently by the user.
- [ ] **Not Distributed + Not Needed by End User (Internal Project Tooling)**: ALL of the following are true:

### Distribution and integration model — explanation

Users building OpenShell from source retrieve unicode-ident from crates.io through Cargo. It is used while compiling Rust procedural macros and is not included as a runtime library in OpenShell release binaries.

### Modification status

- [ ] **Modified Upstream**: The CNCF project will patch, alter, or otherwise modify the source code of the dependency and contribute upstream.
- [ ] **Modified Downstream**: The CNCF project will patch, alter, or otherwise modify the source code of the dependency and maintain a downstream fork or local copy.
- [x] **Unmodified**: The CNCF project will use the dependency exactly as provided by the upstream maintainers without any changes to its source code.

### Modification status — explanation

OpenShell uses the published upstream crate without modification. It is retrieved from crates.io and is not vendored or copied into OpenShell source.

### Structural separation

- [x] **Separated Component**: The dependency's code will either be (a) kept in a distinct directory or module clearly separated from CNCF project code, or (b) retrieved at build/installation time from a third-party repository and never stored in the CNCF project repository.
- [ ] **Intermingled Code**: The dependency's code will be "mixed in" with CNCF source files, copied into existing project files, or will otherwise lose its distinct directory/module boundary.

### Structural separation — explanation

OpenShell uses the published upstream crate without modification. It is retrieved from crates.io and is not vendored or copied into OpenShell source.

### Communication mechanism

- [x] **Static Linking**: The dependency and the CNCF project code will be combined into a single binary or similar type of artifact during the build process.
- [ ] **Dynamic Linking**: The CNCF project code will interact with the dependency by loading it into the shared address space (memory) at run-time. This includes traditional shared objects compiled into a separate binary, as well as runtime module loading in interpreted or JIT-compiled languages.
- [ ] **Separate Process**: The dependency and the CNCF project code will run as distinct executables and communicate via Inter-Process Communication (e.g., pipes, sockets, or shared files)
- [ ] **Network Interaction**: The dependency and the CNCF project code will be logically and physically separated by a network boundary, with the CNCF project's code acting as a client or consumer of the remote service and interacting with the dependency exclusively via standardized network protocols.

### Communication mechanism — explanation

unicode-ident is statically linked into build-time Rust procedural-macro tooling executed by the compiler. It is not loaded into OpenShell at runtime.

### Data exchange

- [x] **Tightly Coupled**: The upstream dependency and CNCF project code will exchange complex internal data structures such as shared pointers, class instances, or private memory offsets that require extensive knowledge of the other component's internal memory layout.
- [ ] **Arms-Length Only**: The communication between the dependency and the CNCF project code will be limited to standard serialized data (e.g., JSON, XML, or Protobuf) where data is "flattened" for transport and neither component accesses the other's internal memory structures.

### Data exchange — explanation

The crate is called through in-process Rust APIs by proc-macro2 and related build-time procedural macros.

### Additional information — explanation

unicode-ident is a ubiquitous transitive dependency in the Rust procedural-macro ecosystem. Its implementation is offered under MIT or Apache-2.0, but its Unicode-derived tables additionally carry Unicode-3.0. OpenShell uses the unmodified upstream package solely through the normal Cargo build process.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.