Skip to content

docs(charter): replace CLA with DCO; plugin exception becomes the module-boundary mechanism (HT-21) - #19

Merged
zaridan merged 1 commit into
mainfrom
docs/ht-21-dco-charter-amendment
Jul 11, 2026
Merged

docs(charter): replace CLA with DCO; plugin exception becomes the module-boundary mechanism (HT-21)#19
zaridan merged 1 commit into
mainfrom
docs/ht-21-dco-charter-amendment

Conversation

@zaridan

@zaridan zaridan commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

What

Charter §3/§7 amendment (HT-21). Contributions move from CLA/consolidated-copyright to DCO-only inbound — contributors keep their copyright, permanently. The commercial-module model now rests where it always legally rested: on the plugin exception (AGPL-3.0 §7 additional permission), not on core ownership.

  • CHARTER.md §3 — DCO replaces the CLA; a "Given up, deliberately" record prices the trade honestly (dual-licensing, the CLA's patent grant/warranties/employer sign-offs); module boundary section names the exception as the sole legal mechanism (repo separation does no legal work for npm-bundled modules), makes it symmetric and §13-covering, and moves its counsel deadline to before the first external contribution — under DCO the text cannot be broadened afterward without every contributor's consent; forks inherit the exception, so name/marks + npm org + marketplace are the commercial assets (trademark policy added to pre-launch counsel work); Resonant IQ is bound by the core's license like any licensee.
  • CHARTER.md §7 — governance line: CLA → DCO sign-off.
  • CONTRIBUTING.md — PRs stay closed, but the gating item is now the exception text, not a CLA; future requirement will be git commit -s and nothing else.
  • CLAUDE.md — human-review rationale no longer cites dual-licensability (that option is being given up); ownership phrasing aligned.

Why

The old §3 claimed consolidated copyright "is what makes it lawful to also sell first-party commercial modules." That claim is wrong — verified 2026-07-10 against primary sources (vendor LICENSE/CONTRIBUTING files, FSF texts, §7 mechanics; e.g. Element's CLA exists solely to sell AGPL exceptions on its core). Meanwhile a single-vendor CLA is the exact trust signal the self-hosted audience screens against (HashiCorp 2023; Cal.com went fully closed via its CLA in April 2026). Exception-sale revenue is ~nil for an operator-run helpdesk, so the CLA's only real value was an option this project doesn't want to hold.

Full research basis and the counsel-work rescope are in HT-21 and the comment on HT-5.

Notes for review

  • Honest-accounting check: §3's "Given up, deliberately" paragraph is the decision record — if anything there reads over- or under-stated, that's the paragraph to push on.
  • The amendment is charter-level only; the exception drafting itself is HT-5 counsel work and deliberately not attempted here.
  • Text went through an adversarial 3-lens review (internal consistency, legal accuracy vs. research + AGPL text, restraint/voice); all surviving findings applied.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Updated licensing guidance to adopt a DCO-based contribution model and clarify the plugin exception.
    • Revised governance language to reflect updated licensing and trademark-policy requirements.
    • Clarified product ownership wording and human-review expectations for substantive changes.
    • Updated contribution instructions to explain the AGPL-3.0 core model and current contribution status.
    • Refined guidance on when contributions may be accepted and what legal documentation must be finalized first.

…ule-boundary mechanism (HT-21)

Charter §3/§7 amendment. Contributions move from CLA/consolidated
copyright to DCO-only inbound — contributors keep their copyright.
The consolidated-copyright rationale was incorrect: the plugin
exception (AGPL-3.0 §7 additional permission), not core ownership,
is what makes first-party commercial modules lawful.

Consequences recorded in §3: dual-licensing the core is deliberately
given up (worth little for an operator-run end application); the
exception's counsel deadline moves from marketplace-open to before
the first external contribution (under DCO its text cannot be
broadened afterward without every contributor's consent); the
exception is symmetric and travels with forks, so the name/marks,
npm org, and marketplace are the commercial assets — trademark
policy added to pre-launch counsel work. Resonant IQ is bound by
the core's license like any licensee (AGPL §13 applies to its own
hosted offerings).

CONTRIBUTING.md: gating item changes from "CLA not finalized" to
"exception text not counsel-final"; future requirement is a DCO
sign-off only. CLAUDE.md: human-review rationale no longer cites
dual-licensability.

Basis: adversarial research pass 2026-07-10 (primary sources:
vendor LICENSE/CONTRIBUTING files, FSF texts, GPLv3 §7 mechanics);
findings summarized in HT-21 and the HT-5 rescope comment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jul 11, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 6ef64744-1fed-4c4a-b281-5859aec2e205

📥 Commits

Reviewing files that changed from the base of the PR and between 2f90bc6 and 5f2f3ef.

📒 Files selected for processing (3)
  • CHARTER.md
  • CLAUDE.md
  • CONTRIBUTING.md

📝 Walkthrough

Walkthrough

The documentation updates establish DCO-only contributions, revise the commercial plugin exception and governance status, adjust contribution timing guidance, and update Helpthread’s ownership and human-review wording.

Changes

Licensing and governance

Layer / File(s) Summary
Charter licensing and governance terms
CHARTER.md
The charter replaces the CLA/consolidated-copyright model with DCO-only contributions, defines the plugin exception, removes dual-licensing language, and updates governance and counsel timing.
Contribution and project guidance
CONTRIBUTING.md, CLAUDE.md
Contribution guidance reflects the AGPL-3.0 core and future DCO sign-off, while project ownership and human-review wording are revised.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly reflects the main documentation changes: replacing CLA with DCO and elevating the plugin exception as the module-boundary mechanism.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/ht-21-dco-charter-amendment

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant