Caught by our own licence gate the minute the anchor went up, which is the only
reason this is a same-day correction rather than something a reader finds first.
Two separate requirements, both real:
- section 4(b): the twenty upstream files this overlay modifies must carry a
prominent notice that we changed them. They did not. They do now, placed after
the upstream copyright header rather than over it, because 4(c) requires that
header to survive untouched. It does: eighteen still read "Copyright ConsenSys
AG.", two "Copyright contributors to Besu."
- section 4(d): NOTICE must carry the attribution notices of the work this
derives from. It named Hyperledger Besu only, while the files themselves carry
three distinct notices. All three are now reproduced. Naming one of three was a
smaller truth than the files tell.
The patch is regenerated from the corrected files and re-verified end to end, not
assumed: git apply --check and git apply both 0 on a pristine d2032017 checkout,
the resulting tree byte-identical to anchor/ (75 files compared, 0 differences),
and 605 tests with 0 failures across consensus:common and consensus:qbft.
This repository argues, in its own README, that a patch against a named upstream
commit is the honest way to publish a contribution to a million-line project: the
diff is the contribution, the reader fetches the rest from upstream, and a patch
fails loudly when upstream moves while a whole file overwrites in silence.
The anchor was published as whole files only, which contradicted that argument.
It is now both: patches/0003 to apply, anchor/ to read.
Verified on a pristine d2032017 checkout rather than assumed:
- git apply --check and git apply both returned 0
- the resulting tree is byte-identical to anchor/: 75 files compared, 0 differences
- :consensus:common:test and :consensus:qbft:test returned 605 tests, 0 failures,
the same count class by class as the same tree built from the files
The README also said "no build file changes are required" in a place that now
reads as if it covered all three patches. It covered the first two. Patch 0003
changes one build file by one line, and that line is named.
- Apache 2.0 section 4(b): the patches modify files that are the work of
Hyperledger Besu and now say so, with the notice inside the modified files,
which is what the licence asks for and what applying the patch produces.
- patches/ and precompiles/ now carry the staged versions rather than an older
export. The two had drifted in both directions; the only thing the published
copy had that the staged one lacked was the word "audited" in front of Bouncy
Castle, which we cannot evidence and which the staged version had dropped.
- the brand was spelled two ways in the same repository, 62 times one way and 23
the other. It is Aere Network; AERE is the ticker. The 96 AERE_* code
identifiers are untouched.
Aere Network public source. Everything here can be checked against the live
chain (chain id 2800, https://rpc.aere.network).
Scope note, stated up front rather than buried: consensus on chain 2800 is
classical secp256k1 ECDSA QBFT. The post-quantum work in this repository is at
the signature, precompile, account and transport layers. Nothing here makes the
consensus post-quantum, and no document in it should be read as claiming so.