@@ -156,45 +156,32 @@ sentinel with `REPLACE-WITH-*`); `spdx-policy-guard.yml` hard-fails it
156156as a real SPDX value (and surfaces A3 variants as non-failing
157157warnings). Evidence: `LICENCE-DEBT-LEDGER-2026-05-18`.
158158
159- === A6 — Named hard-exclusions (enforced, not docs-only)
160-
161- Two repos are permanently excluded from the SPDX policy guard
162- (owner-ruled 2026-05-19). This is *enforced* in
163- `rsr-template-repo/.github/workflows/spdx-policy-guard.yml` (a
164- repo-name early-exit), not merely documented here:
165-
166- * **`palimpsest-license`** — it *defines* the PMPL / PLMP / PMLP
167- identifiers; its spec and legal text legitimately contain many SPDX
168- strings, so scanning it produces guaranteed false positives and
169- could corrupt the licence specification.
170- * **`repos-monorepo`** — a 297-submodule aggregate superproject that
171- only mirrors the standalone source repos (and harbours `007`, see
172- A1). Every hit duplicates a source repo; licence fixes belong in the
173- source repos only, never here.
174-
175- === A7 — Known multi-SPDX false positives (ignore-list)
176-
177- A small, named set of files legitimately carry more than one SPDX
178- *string* without being a licence contradiction — the extra strings are
179- documentation-fenced examples, UI string-literals, or codegen-emitted
180- headers. These are owner-ruled false positives (2026-05-19, ledger §A +
181- §C C1–C3) and the guard reports them as a non-failing `::notice`:
182-
183- [cols="2,2,3"]
184- |===
185- | File (repo-relative) | Repo | Why it is not a contradiction
186-
187- | `PALIMPSEST.adoc` | standards | SPDX ids appear inside doc example blocks
188- | `README.adoc` | llm-grace | PMPL references are explanatory prose, not a header
189- | `…/App.res` | ephapax | the second id (EUPL-1.2) is a UI string-literal
190- | `…/state-utils.scm`| wp-resurrect | the second id (AGPL) is a codegen-emitted header
191- | `CONTRIBUTING.md` | flatracoon | extra SPDX ids are fenced documentation examples
192- |===
193-
194- These remain *visible* (`::notice`, not silenced) so the list can be
195- audited and tightened. Genuine contradiction §C-C4 (zotero-voyant-export
196- `ECHIDNA_ARCHITECTURE_UPDATE_3LANG.md`) is **not** on this list — it is
197- a real defect tracked for an owner-directed single-file fix.
159+ === A8 — Explicit owner-sanctioned scoped carve-outs (2026-05-19)
160+
161+ A2 forbids *automated/bulk* SPDX change as a standing default. The
162+ owner has issued the following **explicit, scoped, per-file-verified
163+ carve-outs** to discharge known licence debt. These are owner-directed
164+ remediation (A2's "manual, per-file, by the owner" — executed under
165+ explicit owner ruling, enumerated and verified, never a blind sweep),
166+ NOT a relaxation of A2's default:
167+
168+ . *Suffix normalisation* — `PMPL-1.0` → `PMPL-1.0-or-later`. This is
169+ *not a relicence* (identical licence; only the SPDX expression's
170+ `-or-later` suffix is corrected — exactly the A3 debt). Authorised
171+ estate-wide, per-repo PRs, owner-merged, diff = SPDX-value-only.
172+ . *Repo licence correction* — `idaptik` is wholly the owner's son's
173+ work → `AGPL-3.0-or-later` (Rule 3); ledger ruling #1, ring-fenced by
174+ `idaptik/SON-WORK.boundary`.
175+ . *Archive relicence* — `hyperpolymath-archive` files bearing `MPL-2.0`
176+ that are verified 100% the owner's own authored content (no
177+ third-party, no vendored, no licence-text) → `PMPL-1.0-or-later`.
178+ Verified by read-only fan-out 2026-05-19. Genuine third-party /
179+ vendored / licence-text files are never rewritten.
180+
181+ Every carve-out PR is per-file enumerated, SPDX-only, draft for owner
182+ merge, and references `LICENCE-DEBT-LEDGER-2026-05-18`. Scaffold
183+ placeholder/variant leaks (A5) remain fixed by *regeneration*, not by
184+ these carve-outs.
198185
199186== See Also
200187
0 commit comments