Skip to content

Latest commit

 

History

History
108 lines (80 loc) · 4.71 KB

File metadata and controls

108 lines (80 loc) · 4.71 KB

Contributing to MARSHAL

Contributions should preserve the project's evidence-first engineering model and remain small enough to review and revert independently.

Before starting

  1. Read TEAM.md, TORVALDS.md, and the relevant role and protocol contracts.
  2. Search existing issues and pull requests before duplicating work.
  3. For non-trivial work, state the requirement, affected contracts, invariants, and verification plan before editing.
  4. Report vulnerabilities privately according to SECURITY.md.
  5. Review IP Contributor Requirements: Material external contributions require an executed Contributor Assignment Agreement before merge (see Contributor Assignment Workflow below).

Workflow

Fork the repository or create a branch from the appropriate base. Preferred branch names are:

feat/<short-name>
fix/<short-name>
docs/<short-name>

Keep one active implementation task with one owner, branch, and worktree. Use tests first for behavior changes. Do not mix unrelated cleanup, formatting, dependency updates, or refactors into the patch.

Use Conventional Commit-style messages, for example:

feat(runtime): add bounded worker shutdown
fix(policy): reject expired approval
docs: clarify adapter status

Verification

Run the checks relevant to your change. The baseline repository suite is:

python conformance/runner.py validate-pack
python -m unittest discover -s conformance/tests -v
python -m unittest discover -s tools/tests -v
python -m unittest discover -s tools/tests_v6 -v
go test ./...
go vet ./...

Concurrency-sensitive runtime changes should also run:

go test -race ./...

Before committing, inspect git diff --check, the complete diff, and the exact staged file list. Never claim a check passed unless you ran it on the reported commit.

Contributor Assignment Workflow

Important

Material external contributions are not accepted for merge until the required contributor assignment process is completed.

To preserve a clean chain-of-title and support the project's dual-licensing architecture (AGPL-3.0-only community + commercial), MARSHAL requires external contributors to execute a Copyright Assignment Agreement prior to merging material code changes.

                     Pull Request Opened
                             │
            Contributor Identity Resolution
                             │
     ┌───────────────────────┴───────────────────────┐
     │                                               │
Individual Contributor                    Corporate Contributor
     │                                               │
Individual Agreement (ICAA)             Corporate Agreement (CCAA)
     │                                               │
     └───────────────────────┬───────────────────────┘
                             │
               Assignment Registry Check (CI Gate)
                             │
                  IP Provenance & Technical Review
                             │
                           Merge

Contributor Agreement Types

For step-by-step onboarding, see docs/legal/CONTRIBUTOR-ONBOARDING.md.

Warning

Simply opening a Pull Request, checking a PR template checkbox, including a Signed-off-by line, or declaring DCO compliance does NOT automatically transfer copyright or replace an executed assignment agreement.

Third-Party & AI-Generated Material

Licensing

MARSHAL Community Edition is licensed under AGPL-3.0-only. Alternative Commercial Licensing is available for organizations requiring non-AGPL terms. See LICENSING.md and COMMERCIAL-LICENSING.md.

By participating, you agree to follow the Code of Conduct.