Skip to content

[ternary-f32] Final gate: licensing, REUSE & OSS-compliance close-out for the vendored NeoGPU/BitNet work #1166

Description

@michalharakal

Final gate of #1136 — runs after all other sub-issues close, and is the last one to close. Nothing in the ternary effort is "done" until the licensing, attribution, and OSS-compliance story of the vendored code is verifiably in order — in the repo and in the shipped artifacts.

Why a dedicated issue

This effort introduced the repo's first vendored third-party source (hs_ml_ternary_neon.c from anjaustin/neogpu, MIT) and code written against a second MIT upstream (BitNet.cpp, vendored in NeoGPU's tree) for the I2_S wire format (#1140). MIT is permissive but not obligation-free: the copyright notice and license text must accompany "copies or substantial portions" — which includes compiled copies inside our published jars, klibs, and AARs, not just the source tree.

Repo-level compliance

  • reuse lint passes on the repo (REUSE.toml precedence = "closest" + the .license sidecar under native/src/vendor/neogpu/); wire it into CI so it stays passing
  • Vendored file still byte-identical to the recorded upstream commit — re-verify the SHA-256 in native/src/vendor/neogpu/README.md against anjaustin/neogpu@0846b24, and that "Local modifications: none" is still true
  • LICENSES/ holds every license the tree now references; drop or justify the currently-unreferenced entries (Apache-2.0.txt, CC0-1.0.txt) so the directory reflects reality
  • I2_S format knowledge ([ternary-f32] Phase 4: GGUF I2_S (type 36) import with group→sequential repack, keep-packed BITNET_B1_58 #1140): add an interpretation note crediting BitNet.cpp (MIT, microsoft/BitNet) in I2sRepack.kt / Constants.kt, following the existing llama.cpp precedent in the GGUF constants header — the layout rule was reimplemented against their sources
  • Docs cross-check: the ternary tutorial and vendor README attribute NeoGPU consistently (name, license, upstream link, agreement in Porting the ternary LUT kernel into SKaiNET (Kotlin Multiplatform ML runtime) — a few questions anjaustin/neogpu#1)

Artifact-level compliance (the part reuse lint cannot see)

  • skainet-backend-native-cpu (jar with bundled libskainet_kernels.*, klibs embedding the static archive) and skainet-backend-jni-cpu (AAR with both .so variants) ship compiled NeoGPU code → each published artifact must carry the NeoGPU MIT notice: a META-INF/ third-party notices file (or equivalent for AAR), listing NeoGPU (and BitNet.cpp if any of its code lands beyond format knowledge)
  • Maven POM <licenses> of the affected artifacts reviewed — SKaiNET's own MIT stays, third-party notices travel with the artifact, not just the repo
  • BOM / release notes: mention the vendored component and its license in the release that first ships it

Upstream courtesies (agreed in anjaustin/neogpu#1)

Close-out

Definition of done: a third party auditing a shipped SKaiNET release can trace every vendored byte to its upstream, license, and copyright holder without asking us.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentation (DARC: D)enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions