Skip to content

META: AI first-pass legal review of FastLED Reciprocal License 1.0 RC — triage, findings & prior-art survey #8

Description

@zackees

Note

AI-generated first-pass legal review — not legal advice. This meta issue coordinates a multi-agent review produced by Claude on 2026-08-24 against HEAD of main. It is input material for the human attorney review gated by LEGAL-REVIEW.md, not a substitute for it.

Scope reviewed: LICENSE (MPL-2.0 + FastLED Additional Terms), LICENSE-AI-AGENT-INSTRUCTIONS.md, NOTICE-TEMPLATE.txt, LEGAL-REVIEW.md, PROVENANCE.md, README.md, header-policy.toml.

Method: A coordinating agent generated the lawyer question list below, triaged each question by difficulty, and fanned out 8 agents: 2× Opus for the hard legal-analysis clusters, 2× Sonnet for drafting/ecosystem clusters, 4× Sonnet web-research agents for prior art on frontier licenses aimed at LLM-compelled ethics upstreaming.

Child issues

# Issue Cluster Model
#2 License architecture & MPL-2.0 interaction Hard analysis Opus
#3 First Sale trigger, remedies, MIT relicensing & AI-agent instructions Hard analysis Opus
#4 Drafting & definitional gaps Medium analysis Sonnet
#5 SPDX, registries, scanners & OSD/DFSG ecosystem impact Easy/medium analysis Sonnet
#6 Prior art: commercial-trigger/reciprocity & ethical-source lineages Research Sonnet
#7 Prior art: RAIL-family AI licenses & machine-directed instruction files Research Sonnet

Question triage

Hard → Opus (architecture, #2): MPL §10.3 rename/steward compliance; whether the Additional Terms run with the code ("this License" ambiguity, Exhibit A/Covered-Software gap, §2.7 closed condition list, §9 integration clause); determinacy of the minimum-extent conflict clause and the §5.1 cure-window interaction; the §3.3 Secondary-License escape hatch and GPL compatibility; source-availability duration and the third-party issue-tracker dependency; patent-grant interaction.

Hard → Opus (trigger & AI file, #3): "First Sale" vs. 17 U.S.C. §109 exhaustion; condition-vs-covenant (Jacobsen/MDY nexus) and the real remedy for a missed same-day publication; trigger scope gaps (SaaS, gratis distribution, intra-corporate, contract manufacturing, lease, wrong-party incidence); MIT relicensing feasibility without CLAs and the enforcement footprint; AI-instruction enforceability, disclaimer effectiveness, GitHub ToS/trade-secret-inducement, prompt-injection framing; RC-status estoppel risk.

Medium → Sonnet (drafting, #4): undefined "official FastLED repository"; third-party-hostage compliance in §2.3(b) with no cure; vague operative terms; RC label inside the operative instrument; two-file instrument integrity; trademark silence; "includes Modified FastLED" de-minimis/innocent-seller reach; AI-file internal contradictions and scanner-misparse risk.

Easy/medium → Sonnet (ecosystem, #5): SPDX LicenseRef mechanics and SBOM resolution; Arduino Library Manager/PlatformIO policies; scanner classification (Licensee, FOSSA, Black Duck, ScanCode) and corporate default-deny; OSD/FSF/DFSG analysis and distro fallout; MIT→custom migration playbooks and the header-notice approach; GitHub license-detection UX.

Research fan-out (#6, #7): reciprocity/commercial-trigger licenses (Parity, RPL-1.5, CAL, SSPL, Commons Clause, ELv2, BUSL, FSL, PolyForm, Prosperity, CDDL, Watcom, OSL, AGPL); ethical-source lineage (Hippocratic 3.0, Do No Harm, ACSL, Anti-996, JSON license, OES ethical stack, OSI/FSF/Mitchell critiques, Post-Open); RAIL family (OpenRAIL-M variants, Llama, Gemma, AI2 ImpACT, OSAID); machine-directed instructions (robots.txt, llms.txt, noai, Do-Not-Train, EU DSM Art. 4, AGENTS.md, attribution.md, Assisted-by trailers, agency-law scholarship, prompt-injection research).

Consolidated top findings

CRITICAL — structural

  1. The Additional Terms probably do not run with the code as conditions (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q2). MPL §1.8 defines "License" as the MPL document itself; §2.7 is a closed list of conditions that excludes FastLED §2.3; §9 is an integration clause; and the Exhibit A / Covered Software definition gap means the SPDX-only notice arguably makes nothing Covered Software. Single most important fix: a merged single-file license amending §1.8, §1.4/Exhibit A, §2.7, §9, and §3.1 — and renumbering the Additional Terms to §11 to end the §2.3-vs-§2.3 section-number collision.
  2. The Secondary License escape hatch is wide open (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q4). Without Exhibit B, MPL §3.3 lets any licensee add one GPL file and redistribute Modified FastLED under GPLv2 — which has no public-disclosure duty — deleting §2.3 in one hop. Closing it (Exhibit B) makes the license GPL-incompatible; leaving it open makes §2.3 optional. There is no drafting that gets both; this is a client business decision to record in LEGAL-REVIEW.md.
  3. "First Sale" reads as a one-time-ever trigger (AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q1). "Modified FastLED" is a class, not a version: publish one trivial diff on day one and no later sale of any later fork is ever "the first sale" again. Rename to a per-version, recurring "Triggering Transfer."
  4. The obligation lands on the wrong party (AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q3d). The seller (distributor, retailer, contract manufacturer) triggers §2.3, not the modifier — a party that may not have the source, is exhaustion-protected, never assented, and cannot cure, while the modifier who never sold walks. Bind the modifier.
  5. "Official FastLED repository" is undefined (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 A3, AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Add.1, AI legal review — drafting & definitional gaps (Sonnet cluster) #4 Q1) — the anchor for the definition of "FastLED" itself and for the §2.3(b) compliance mechanism. Define by URL + successor clause + git-ancestry tiebreaker.
  6. §2.3(b) compliance is hostage to a third party with no cure (AI legal review — drafting & definitional gaps (Sonnet cluster) #4 Q2, AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q5), and "There is no post-sale grace period" is legally inert against MPL §5.1's cure/reinstatement machinery anyway (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q3). Decide the cure question deliberately; add a licensor-caused-impossibility safe harbor and a duration term; consider deleting mechanism (b) entirely.
  7. OSD feat: publish reciprocal license and compliance toolchain #1 / DFSG exposure comes from the timing, not the copyleft (AI legal review — SPDX, registries, scanners & OSD/DFSG ecosystem impact (Sonnet cluster) #5 Q4). Zero-grace, pre-sale publication is stricter than any OSI-approved analogue and is the least-precedented parameter in the whole design (Prior art survey — commercial-trigger/reciprocity licenses & ethical-source lineage #6 synthesis: RPL gives 1 month; nothing surveyed requires same-day). A bounded post-sale cure window removes most of the friction while preserving intent.

HIGH — operational

  1. MIT history limits enforcement and endangers the header rewrite (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 A1, AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q4). Anyone can fork the last MIT commit; the enforceable surface is thin for 12–24 months. Sharper: bulk header replacement risks breaching the MIT notice condition that the sublicensing authority depends on — run a per-file ownership audit before apply, use additive headers, institute DCO/inbound=outbound now.
  2. The AI-instruction lines are backdoored into condition-like status by MPL §3.4 (AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q5a): they sit inside the license-notice block, so stripping them is arguably a notice-integrity breach that terminates the license — contradicting the non-remedial intent. Move to one severable URI line / declarative manifest.
  3. The AI file's publish-first ordering induces trade-secret destruction (AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q5c): an agent on a private corporate branch following §2 as written publishes the employer's unreleased code. Reorder authorization-first — the highest-value single change in the AI cluster. Also: internal "behaviorally mandatory"-vs-"no remedy" contradiction (AI legal review — drafting & definitional gaps (Sonnet cluster) #4 Q8), prompt-injection shape (~84% README-injection success rates in CSA research, Prior art survey — RAIL-family AI licenses & machine-directed instruction files #7), and the issue-tracker firehose (route to a dedicated upstream-reports repo).
  4. Scanner/SCA fallout (AI legal review — SPDX, registries, scanners & OSD/DFSG ecosystem impact (Sonnet cluster) #5 Q3): GitHub shows "Other," FOSSA/Black Duck default to Unknown→deny; the relicense converts FastLED from "always auto-approved" (MIT) to "always manually queued." WLED already dropped FastLED (AI legal review — SPDX, registries, scanners & OSD/DFSG ecosystem impact (Sonnet cluster) #5 Q4). Mitigations: SPDX List submission (BUSL-1.1 precedent shows non-OSI is not disqualifying), ScanCode/FOSSA/Black Duck database submissions, canonical hosted license URL.
  5. Two-file instrument breaks downstream (AI legal review — drafting & definitional gaps (Sonnet cluster) #4 Q5, AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q1): ship one merged self-contained file; also resolves the §10.1/§10.2 Mozilla-steward contradiction that currently lets licensees argue for upgrade to a future Mozilla MPL 3.0 without §2.3.
  6. RC status inside the operative text (AI legal review — drafting & definitional gaps (Sonnet cluster) #4 Q4, AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 Q6): remove §4 from LICENSE; use an -rc1 SPDX id until review; make the LEGAL-REVIEW.md gate technical (CI refuses apply/release while Status: PENDING).

Prior-art conclusions (#6, #7)

  • The sale-triggered same-day publication duty is genuinely unprecedented. Nearest kin: RPL-1.5 (deployment-triggered publication + public notification, 1-month window), Commons Clause ("Sell" trigger vocabulary), CDDL (MPL rename-and-extend construction), AI2 ImpACT (affirmative pre-release disclosure + naming-and-shaming enforcement), Perens' Post-Open (revenue-triggered obligation). FastLED = RPL's mechanism + Commons Clause's trigger + CDDL's construction method, a combination not previously attempted.
  • Disclosure duties have empirically low backlash; prohibitions fork projects (Redis/Commons Clause, Elastic/SSPL→OpenSearch, HashiCorp/BUSL→OpenTofu — the Terraform MPL-2.0→BUSL episode is nearly a dry run of this relicense's risk profile). Lead announcements with "you may sell freely; you must simply have already published."
  • The AI-agent instruction file appears first-of-kind: nothing else combines (a) addressed-to-the-agent, (b) behaviorally mandatory yet expressly non-remedial, (c) affirmative labor-bearing upstreaming duty. Nearest analogue is attribution.md (a "social tip jar"). The OES ethical stack (non-binding Contributor Covenant vastly out-adopting the binding Hippocratic License) is the best evidence the non-remedial choice is the strong play, not a hedge — but the JSON-license history ("Good, not Evil" → Apache Category-X ban, Google rewrite) shows even admittedly-unenforceable clauses cause enterprise-legal chill unless the disclaimer is airtight and co-located.
  • Compliance with machine-addressed affirmative asks has no honor-system precedent — robots.txt-style norms only ever achieved compliance for prohibitive asks backed by platform/legal leverage. Practical uptake likely depends on agent-vendor adoption (the llms.txt/Mintlify path), not organic adherence.

The strategic question both Opus agents converge on

Given the thin marginal delta of §2.3 over MPL's own §3.2 (public-by-one-hop anyway), the MIT-fork bypass, the destroyed GPL compatibility, and the SCA friction: counsel should be asked to price the alternative of shipping unmodified MPL-2.0 (OSI-approved, SPDX-standard, zero scanner friction) plus the AI-policy manifest as a norm, plus a commercial license for NDA/export-control-bound users. That combination captures most of §2.3's practical value at a fraction of its ecosystem cost. If the maintainers still want the same-day condition after seeing that comparison, the fixes in #2#4 make it defensible — but the comparison should be made deliberately, and the decision recorded in LEGAL-REVIEW.md.

Suggested next steps

  1. Decide the three recorded business choices: Exhibit B / GPL trade-off (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q4), patent conditioning (AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 Q6), and MPL-2.0-plus-norms vs. bespoke license (above).
  2. Apply the mechanical fixes that are safe regardless of those choices: single merged license file, §11 renumbering, "Triggering Transfer" per-version rename, modifier-binding, repo definition, authorization-first AI-file reorder, header AI-lines → one URI line, -rc1 identifier + CI gate.
  3. Take this packet to the open-source licensing attorney per LEGAL-REVIEW.md, with AI legal review — license architecture & MPL-2.0 interaction (Opus cluster) #2 and AI legal review — First Sale trigger, remedies, MIT relicensing & AI-agent instructions (Opus cluster) #3 as the agenda.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions