docs(claude): record the lamassu reference permission; correct the server boundary and the driver table

Three corrections to facts a session reads before touching code.

The maintainer taking over the Lamassu codebase has given permission to
use lamassu-machine and lamassu-server, post-boundary included, as prior
art (relayed by padreug, 2026-10-09). The hard rule that limited us to
c0b69d1 is superseded; the guidance is now reference-over-port, with
verbatim ports naming their source commit.

lamassu-server DID have a public-domain era — last open commit adbc9709,
licence added in d06a8f54, both 2023-09-19 — contrary to what the
squashed ~/lamassu/lamassu-server checkout suggests (its first commit is
already Appendix A). History survives in ~/dev/repos/ and at Software
Heritage. The earlier "not re-verified" note is replaced with the
verified boundary.

The hardware-driver table claimed ccnet, cashflow_sc, bnr_advance,
genmega, hcm2, gsr50 and three printers. The tree has validators id003
and ebds, dispensers f56 and puloon, no printers directory, and orphaned
Rust files from an abandoned HAL. The table now matches the tree.
This commit is contained in:
Padreug 2026-10-09 21:42:03 +02:00
commit f498373e96

View file

@ -17,9 +17,27 @@ Core principles:
The HAL drivers (validators / dispensers / printers) and the cash-flow state machine derive from Lamassu Industries AG's `lamassu-machine` repository, **only up to commit `c0b69d1ed196d396c5f057478c2ea290babd58ab`** ("chore: v8.6.0-beta.9", 2023-09-19) — the last commit published into the public domain (`UNLICENSE` in tree). The very next commit, `a9234d124d` ("chore: add LICENSE (#1019)", 2023-09-19), removed `UNLICENSE` and added Lamassu's proprietary "Appendix A SLA". **The `v8.1.5` tag (2023-09-21) already ships the Appendix A license** — the previously documented "8.1.5 is the open boundary" was wrong (verified against GitHub history 2026-07-04). Note the public-domain boundary sits on the 8.6-beta line, which is *further along* than 8.1.5 feature-wise.
**Hard rule when working in this repo:** do not pull, port, or copy lamassu-machine code from `a9234d124d` or later (which includes every 8.1.5+ tag). Reference only `c0b69d1` or earlier. If a HAL bug fix or feature exists upstream past that commit, either (a) reimplement from protocol docs / hardware specs without looking at the licensed source, or (b) raise the question with the maintainer first. To fetch the open tree safely: `git fetch --depth 1 origin c0b69d1ed196d396c5f057478c2ea290babd58ab` — never check out a tag.
**Reference permission (2026-10-09).** The maintainer taking over the Lamassu
codebase has given us permission to use lamassu-machine and lamassu-server — including
post-boundary code — as prior art in any way that improves this codebase (relayed by
padreug, 2026-10-09; the earlier hard rule — reference only `c0b69d1` or earlier — is
superseded). Prefer to *reference* over
*port*: read it, take the behaviour model, reimplement in our idiom. When a block is
ported verbatim, say so in the commit, with the source commit, so the provenance is in
`git log`. The pre-boundary tree needs no permission at all and is the first place to look.
The `lamassu-server` boundary has not been re-verified against its own history and may differ — check its license-change commit before referencing it.
**Boundaries, for the record.** lamassu-machine's last public-domain commit is `c0b69d1`
(2023-09-19, v8.6.0-beta.9); `a9234d124d` added Appendix A the same day, so every 8.1.5+
tag is proprietary. lamassu-server's last public-domain commit is `adbc9709` (2023-09-19,
v8.6.0-beta.9), licence added in `d06a8f54` the same day. Both GitHub repos are gone
(404); full history survives in `~/dev/repos/` and at Software Heritage (crawls 2026-03-02
and 2026-07-19, tips identical to the local mirrors). **`~/lamassu/lamassu-server` is a
squashed v12 repo** whose first commit (`e2c49ea`, 2025-12-31) already carries Appendix A —
it has no open era to reference; use `~/dev/repos/` for that. `~/lamassu/` also holds the
33 surviving github.com/lamassu dependency repos (cloned 2026-09-27) and
`bnr-xfs-salvage/` (the MIT bnr-xfs / bnr crates, checksums verified). The curated
*Lamassu Port Backlog* (claude.ai artifact `61af38f6`, 2026-09-27) ranks what is worth
taking and tags each item's provenance.
bitSpire is an independent project under AGPL-3.0 and is not affiliated with Lamassu Industries AG.
@ -232,10 +250,15 @@ TypeScript drivers in `packages/hal/`. Coverage by device class:
| Category | Drivers |
|---|---|
| Validators | id003, ccnet, cashflow_sc, bnr_advance, genmega, hcm2, gsr50 |
| Dispensers | puloon, f56, genmega, hcm2, gsr50 |
| Recyclers | MEI SCR (planned — hardware in BATM3, no driver yet) |
| Printers | nippon, zebra, genmega |
| Validators | id003, ebds |
| Dispensers | f56, puloon |
| Recyclers | none — MEI SCR hardware in BATM3; a clean-room BNR Advance route exists via the MIT `bnr-xfs` crate (see the port backlog) |
| Printers | none — `packages/hal/src/printers/` does not exist |
This table previously listed ccnet, cashflow_sc, bnr_advance, genmega, hcm2, gsr50 and
three printers that are not in the tree (corrected 2026-10-09). `packages/hal/src` also
carries orphaned `*.rs` files (`lib.rs`, `error.rs`, `mod.rs`, `traits.rs`, `mock.rs`) from
an abandoned Rust HAL; they are not built.
### Sintra hardware specifics (Aaeon UP Board)