Pre-publish privacy audit: scrub the simulator serial, harden the sdist, add licences
Audited the package against the two-stage procedure before a first PyPI publish. The sdist and wheel were already tight, but three things needed fixing and the controls needed to become real rather than documented. The simulator volunteered high="PI04" as its product serial, which is the real Bebop 2 serial prefix. Nothing unique to one aircraft, but a realistic prefix invites being quoted into a bug report as a specimen, so it now reads "N0TAREAL" / "0000000SIM" with a comment saying why it is nonsense on purpose. The low half and the 500.0 no-fix GPS sentinel were already fake. Hardened [tool.uv.build-backend] source-exclude well past the directories that exist today: captures at any depth, log dumps, recorded media by extension, caches, and anything credential-shaped. .gitignore governs git and source-exclude governs the sdist; a capture can sit in one and not the other, which is how this kind of data reaches an immutable index. Verified the broad patterns do not over-reach: arsdk-xml/ with PROVENANCE.md and tools/logs.py both still ship. Added LICENSE (MIT) and LICENSE-arsdk-xml (Parrot SA's BSD-3-Clause), and corrected the declared licence to "MIT AND BSD-3-Clause". The vendored XML ships in both artifacts because nothing here decodes a command without it, so MIT alone understated what is in the box. Both texts now appear in the artifacts and in the metadata. test_packaging.py grows privacy guards that fail on a serial prefix, a P7 CPU id, any MAC, a high-precision coordinate, an absolute home path, or any private address other than the drone's own documented 192.168.42.0/24. Each pattern was checked against the real identifiers to confirm it bites, since a guard that passes on an empty tree proves nothing. Example address in test_arsdk_session.py moved to RFC 5737 space. 504 tests pass, ruff clean.
This commit is contained in:
@@ -84,7 +84,12 @@ uvx mcbebop
|
||||
claude mcp add mcbebop -- uvx mcbebop
|
||||
```
|
||||
|
||||
## Credits
|
||||
## Licence
|
||||
|
||||
`arsdk-xml/` is Parrot SA's own protocol definition, BSD-3-Clause. See
|
||||
`arsdk-xml/PROVENANCE.md`.
|
||||
This package is MIT (`LICENSE`), and it vendors one third-party component:
|
||||
`src/mcbebop/arsdk-xml/` is Parrot SA's own protocol definition, BSD-3-Clause
|
||||
(`LICENSE-arsdk-xml`). It ships in both the sdist and the wheel because nothing
|
||||
here can decode a single command without it. What that snapshot is and how it
|
||||
differs from upstream is recorded in `arsdk-xml/PROVENANCE.md`.
|
||||
|
||||
So the distribution as a whole is `MIT AND BSD-3-Clause`.
|
||||
|
||||
Reference in New Issue
Block a user