From 4652d82b2f5e4393397ad5e5498a08ebd3bbb3ed Mon Sep 17 00:00:00 2001 From: michalharakal Date: Mon, 21 Sep 2026 08:43:31 +0200 Subject: [PATCH] fix(spec): Moonshine license facts; tutorial clone URL Per the publisher README (moonshine-ai/moonshine, License), Moonshine models are MIT in every language and size; only the legacy non-streaming models for languages other than English stay under the non-commercial Moonshine Community License. The spec applied that license to all non-English models -- so it wrongly said a German streaming cartridge needs a separate license (moonshine-ai/moonshine-streaming-tiny-de is MIT). Corrected in the licensing table, OQ10, the roadmap, the example descriptor, blueprints.adoc and SKEEP-007; ADR-004 gets a dated correction note, its decision is unaffected. blueprints.adoc now states the rule behind the mistake: a license is a fact about a pinned checkpoint, stated by its publisher, never inferred from the model family. Tutorial clones the real repository name. --- .../asr-moonshine-ort-cpu.descriptor.json | 2 +- .../adr/adr-004-license-composition.adoc | 5 ++++- docs/modules/ROOT/pages/blueprints.adoc | 12 +++++++---- docs/modules/ROOT/pages/index.adoc | 21 ++++++++++++------- docs/modules/ROOT/pages/roadmap.adoc | 4 ++-- .../pages/skeep/007-cartridge-blueprints.adoc | 6 +++--- .../build-cartridge-from-blueprint.adoc | 4 ++-- 7 files changed, 33 insertions(+), 21 deletions(-) diff --git a/docs/modules/ROOT/examples/asr-moonshine-ort-cpu.descriptor.json b/docs/modules/ROOT/examples/asr-moonshine-ort-cpu.descriptor.json index 27d91a4..e4cd6fe 100644 --- a/docs/modules/ROOT/examples/asr-moonshine-ort-cpu.descriptor.json +++ b/docs/modules/ROOT/examples/asr-moonshine-ort-cpu.descriptor.json @@ -11,7 +11,7 @@ "checkpoint": "usefulsensors/moonshine-tiny-streaming", "upstream": { "source": "https://github.com/moonshine-ai/moonshine", - "license": "MIT (English models; non-English models are Moonshine AI Community License — revenue-capped, enterprise license required above USD $1M/yr — see ADR-004)" + "license": "MIT (per the publisher, Moonshine models are MIT in every language and size; only the legacy non-streaming non-English models stay under the non-commercial Moonshine Community License — see ADR-004)" } }, "modality": "audio", diff --git a/docs/modules/ROOT/pages/adr/adr-004-license-composition.adoc b/docs/modules/ROOT/pages/adr/adr-004-license-composition.adoc index f308509..551e5d0 100644 --- a/docs/modules/ROOT/pages/adr/adr-004-license-composition.adoc +++ b/docs/modules/ROOT/pages/adr/adr-004-license-composition.adoc @@ -8,7 +8,10 @@ unattributed Whisper-derived (MIT) weights, vendor Apache-2.0 NPU sample code mo modification notices — while being publicly described as "Apache-2.0". Moonshine adds a sharper case: English models MIT, non-English models revenue-capped (Community License, $1M/yr) with a display duty — a *product-blocking* constraint invisible in a single top-level -license string. + +license string. _Correction (2026-09-21): that scope was too broad. Per the publisher's README, +Moonshine models are MIT in every language and size; only the *legacy non-streaming* models for +languages other than English stay under the (non-commercial) Community License. The decision +below is unaffected — the case still exists, for fewer models._ + *Decision:* The manifest records `license` and `derived_from` *per artifact*; the descriptor's `license` is the *effective* license and MUST be satisfiable given all upstream obligations. `NOASSERTION` marks unremediated packages and is treated as a failure by conformance tooling. diff --git a/docs/modules/ROOT/pages/blueprints.adoc b/docs/modules/ROOT/pages/blueprints.adoc index 7240ae5..ea7dcca 100644 --- a/docs/modules/ROOT/pages/blueprints.adoc +++ b/docs/modules/ROOT/pages/blueprints.adoc @@ -226,10 +226,14 @@ checkpoint), plus every supplied input. the cartridge may be passed on under the computed license; `restricted` — only under conditions the materializer must check for itself (a revenue cap, a display duty, a field of use); `acceptance-required` — access itself is conditional, and the result inherits the terms. -* The worked constraint on the concept page is the model case: Moonshine's English checkpoints - are MIT, its non-English ones are under a revenue-capped community license. A Moonshine - blueprint therefore marks the German flavor's source `restricted`, and a materialization that - selects that flavor carries the obligation into its manifest — visibly, instead of nowhere. +* Licenses are facts about a *specific checkpoint at a specific revision*, stated by its + publisher — never inferred from the model family. Moonshine is the worked case: its streaming + checkpoints are MIT in every language (a German streaming flavor's source is `allowed`), while + its legacy non-streaming models for languages other than English stay under a non-commercial + community license (a blueprint using one marks that source `restricted`, and a + materialization selecting it carries the obligation into its manifest — visibly, instead of + nowhere). A blueprint author checks the publisher's statement for the pinned revision and + records `license_url`; a materializer re-checks it. [#provenance] === Provenance diff --git a/docs/modules/ROOT/pages/index.adoc b/docs/modules/ROOT/pages/index.adoc index 347ad40..3037b43 100644 --- a/docs/modules/ROOT/pages/index.adoc +++ b/docs/modules/ROOT/pages/index.adoc @@ -179,12 +179,16 @@ Worked reality checks from the existing cartridges: carries `license: NOASSERTION`. | `asr-moonshine-ort-cpu` -| The bundled `tiny-streaming-en` model is MIT (Moonshine AI licenses its *English* models - MIT). Its *non-English* models fall under the Moonshine AI Community License: commercial use - only below USD $1M annual revenue, mandatory notice and "Powered by Moonshine AI" display — - i.e. any *German* Moonshine cartridge for this ecosystem requires an enterprise license - before it can exist. Exactly the kind of constraint the manifest must carry and a build gate - must surface (OQ10's worked case). +| The bundled `tiny-streaming-en` model is MIT. Per the publisher + (https://github.com/moonshine-ai/moonshine#license[moonshine-ai/moonshine, License]), Moonshine + models are MIT "in every language and at every size" — the *streaming* checkpoints included, + so a German streaming cartridge (`moonshine-ai/moonshine-streaming-tiny-de`, model card: + `license: mit`) is MIT too. The one exception is the *legacy non-streaming* models for + languages other than English, which stay under the non-commercial Moonshine Community + License. A cartridge built on one of *those* needs a separate agreement before it can ship — + exactly the kind of constraint the manifest must carry and a build gate must surface (OQ10's + worked case). _Corrected 2026-09-21: earlier text applied the community license to all + non-English models._ |=== The descriptor's `license` field states the *effective* license: an SPDX id for open weights; @@ -699,8 +703,9 @@ be promoted the same way. declared; tolerance = which attributes the host marks *required*. Remaining: a sensible default required-set per task profile. * *OQ10 — Commercial licensing field(s).* Formalize the closed/commercial shape of `license` + - entitlement pointers. v0.2 adds the concrete worked case (Moonshine Community License: - revenue-capped commercial use, display duty) that the field structure must be able to carry. + entitlement pointers. v0.2 adds the concrete worked case (the Moonshine Community License on + the publisher's legacy non-streaming non-English models: a non-commercial license next to MIT + siblings of the same family) that the field structure must be able to carry. * *OQ11 — Reproducible builds.* Whether the NPU builder / an ORT export / an IREE compile can be made bit-for-bit deterministic — prerequisite for the Mode-B trust path to mean anything beyond "I trust my own laptop." v0.4 supplies the other prerequisite: a xref:blueprints.adoc[blueprint] diff --git a/docs/modules/ROOT/pages/roadmap.adoc b/docs/modules/ROOT/pages/roadmap.adoc index eb3f793..2094b12 100644 --- a/docs/modules/ROOT/pages/roadmap.adoc +++ b/docs/modules/ROOT/pages/roadmap.adoc @@ -47,8 +47,8 @@ maturity tags, ADR log; Runtime ABI v0.1 (`cartridge-abi/include/cartridge_abi.h `requirements.driver` + `ctg_preflight`. Descriptor v0.2 with measured WER. * *ORT Moonshine cartridge (`asr-moonshine-ort-cpu`)*: ABI wrapper over `moonshine-c-api.h`; descriptor v0.2 (`execution_mode: eager`, `family`, `endpointing: signal`, honest per-ABI RTF); LICENSE + - NOTICE (MIT English models; the non-English Community-License constraint documented as the - OQ10 worked case); Silero-blob artifact granularity decided (extract to file vs. accept + NOTICE (MIT models; the Community-License constraint on the publisher's legacy non-streaming + non-English models documented as the OQ10 worked case); Silero-blob artifact granularity decided (extract to file vs. accept whole-binary granularity, per the granularity rule in xref:index.adoc#integrity[]). * *Adapters onto `asr/v1`*: both of the first app's ASR adapters implement the profile; the duplicated session/channel/PCM plumbing (~250–300 LOC each) hoists into a shared support diff --git a/docs/modules/ROOT/pages/skeep/007-cartridge-blueprints.adoc b/docs/modules/ROOT/pages/skeep/007-cartridge-blueprints.adoc index 0bfa65f..e40040f 100644 --- a/docs/modules/ROOT/pages/skeep/007-cartridge-blueprints.adoc +++ b/docs/modules/ROOT/pages/skeep/007-cartridge-blueprints.adoc @@ -25,9 +25,9 @@ xref:blueprints.adoc[Blueprints]. Spec v0.4; additive. * *The first cartridges cannot be published as they are.* The Moonshine v2 streaming ASR and FunctionGemma NLU cartridges exist and work, but their repositories either contain hundreds of megabytes of compiled modules and parameter archives, or reference them out of band. Neither - shape is publishable: the weights have a publisher and terms (MIT for Moonshine's English - checkpoints, a revenue-capped community license for its other languages, Gemma's Terms of Use - for FunctionGemma), and re-hosting them drops those terms on the floor. + shape is publishable: the weights have a publisher and terms (MIT for Moonshine's streaming + checkpoints, a non-commercial community license for its legacy non-English models, Gemma's + Terms of Use for FunctionGemma), and re-hosting them drops those terms on the floor. * *The build loop is unrecorded.* "Developing a cartridge" is eight lines of prose. Which upstream revision, which files, how they were converted and quantized, which exporter and compiler versions — known to whoever built it, written down nowhere a reviewer or a machine can diff --git a/docs/modules/ROOT/pages/tutorials/build-cartridge-from-blueprint.adoc b/docs/modules/ROOT/pages/tutorials/build-cartridge-from-blueprint.adoc index 7bf5f13..52f462c 100644 --- a/docs/modules/ROOT/pages/tutorials/build-cartridge-from-blueprint.adoc +++ b/docs/modules/ROOT/pages/tutorials/build-cartridge-from-blueprint.adoc @@ -50,8 +50,8 @@ build/cartridge/nlu-functiongemma-270m-iree-vulkan-arm64/ [source,bash] ---- -git clone https://github.com/SKaiNET-developers/skainet-cartridge-blueprints.git -cd skainet-cartridge-blueprints/blueprints/nlu-functiongemma-270m-iree +git clone https://github.com/SKaiNET-developers/SKaiNET-cartridge-blueprints.git +cd SKaiNET-cartridge-blueprints/blueprints/nlu-functiongemma-270m-iree ---- Open `blueprint.json`. Three parts are worth reading before you run anything: