Skip to content

feat(legal): the enforcement process numbers, the Thai 7-day clause switch, and the future-tense model release - #31

Merged
HetCreep merged 9 commits into
mainfrom
lwk2-1008c
Oct 8, 2026
Merged

HetCreep merged 9 commits into
mainfrom
lwk2-1008c

Conversation

@HetCreep

@HetCreep HetCreep commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Three changes, one PR. Everything in TERMS.md stays under the pending-legal-review marker.

1. The planned model release in the future tense. README, LICENSE, py/LICENSE and SECURITY say plainly that no model has been released, no date is set and nothing is on sale; each release will carry its own license, and the base-model attribution is stated as planned.

2. The enforcement process numbers in TERMS.md, with a Thai version. 14 business days to answer a notice, a written decision 7 business days after the answer, 30 business days to file the one appeal through appeals@kolwen.com, an answer within 14 business days, the key's clock stopped for the whole case, a 90-calendar-day ceiling, and the missed-deadline rules (a missed Kolwen deadline lifts the suspension; a lapsed customer deadline lets the case proceed). The support spec's appeal deadline matches.

3. The legal-state record and the build-time switch for the Thai 7-day clause. legal/legal-state.json holds state only (fixed keys, null or a real date, the seller type), so no identifier, number or revenue figure can be stored here. The clause lives in legal/thai-7day-clause.md; TERMS.md carries one marked block, empty while no trigger is met. scripts/legal-state.mjs --write renders it and --check refuses a disagreement; surface-check rule 19 holds the record, the markers and the rendering. legal/README.md writes the revenue trigger down as a design; no billing code exists. Cancellation goes through support@kolwen.com.

Also: a declared reason at the head of scripts/surface-check.mjs, which is over the room's 800-line review signal.

Tests: scripts/legal-state.test.mjs (10, red first, 10 mutants killed) is in the CI roster; surface-check, the secret tests and the rest of the roster pass locally.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Updated the acceptable-use process with response, decision, and appeal deadlines, plus a 90-day case limit. Added a Thai-language version and clarified when access is restored if Kolwen misses a deadline.
    • Clarified that Kolwen model weights have not been released and no release date is set; any future release will include its own license.
    • Documented the Thai 7-day cancellation terms, which appear in the Terms only when a specified legal trigger is recorded. The clause is currently inactive.
  • Tests
    • Added checks to verify that the cancellation clause shown in the Terms matches its legal status.

HetCreep and others added 8 commits October 8, 2026 16:18
README, LICENSE, py/LICENSE and SECURITY now say plainly that no model
has been released, no date is set and nothing is on sale, and that each
release will carry its own license. The base-model attribution is stated
as planned. No claim is made about quality or performance, and nothing
was removed. No test or gate held the old wording. The CHANGELOG records
the change.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…n channel, with a Thai version

TERMS.md's enforcement process now states its numbers: 14 business days
to answer a notice, a written decision 7 business days after the answer,
30 business days to file the one appeal through the appeals role address,
an answer within 14 business days, the key's clock stopped for the whole
case, a 90-calendar-day ceiling from the notice, and a missed Kolwen
deadline lifting the suspension while a lapsed customer deadline lets the
case proceed. A business day is a normal working day in Thailand without
the Royal Gazette public holidays. A Thai version follows the English.
The dormant Thai 7-day clause names the support role address in both
languages. Everything stays under the pending-legal-review marker, and
the support spec's appeal deadline now matches.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… Thai 7-day clause

The Thai 7-day cancellation clause is in TERMS.md only while legal/legal-state.json says a
trigger has been met (incorporation, direct-marketing registration, or a revenue crossing
that stands). The record holds state only: fixed keys whose values are null or a real
calendar date, plus the seller type, so a registration number, a tax identification number,
a revenue figure or any owner identifier cannot be stored in this public repository; the
validator refuses any other key or kind of value. The clause text moves to
legal/thai-7day-clause.md (English and Thai, with a placeholder for the date it takes
effect), and TERMS.md carries one marked block that is empty while no trigger is met and
holds the dated clause once one is. scripts/legal-state.mjs --write renders the block from
the record and --check refuses a disagreement; the block is never edited by hand. The
mechanism is a marked block plus a script because TERMS.md is a tracked document and the
site has no build step; its limit is that a person can still edit the block, which the
check (and the next commit) refuses rather than prevents. legal/README.md writes the
revenue trigger down as a design (settled statements net of refunds in baht, a crossing
date that arms the clause at once, a 14-calendar-day veto for a measurement error only, a
one-way latch, git history as the audit log); no billing code exists.

Red first against a stub that reports nothing: 9 of 10 tests failed (the tenth was
tightened to name what it checked); with the script, all 10 pass, and each of 10 mutants
(an inactive switch, a veto ignored, an always-rendered clause, the key allowlist, the date
shape, the veto window, the marker count, the sync compare, the company check, the nested
key check) is killed by a named test. The tests are in the CI roster.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…MS.md

The surface check now reads legal/legal-state.json, legal/thai-7day-clause.md and TERMS.md
through the same library as the switch script and refuses: a record of the wrong shape
(an unknown key, a value that is not null or a real date, a company trigger on a natural
person, a veto outside its 14 days) or a missing file; a TERMS.md without exactly one pair
of markers; and a block that is not the rendering of the record and the clause file (a
clause showing while no trigger is met, or missing once one is). Rule 10 now also reads the
clause file, so its counsel-pending gap keeps its marker. The stated limits (the one-way
latch and the veto timing need git history, the trigger date is the owner's commit, revenue
has no meter yet) are in the rule's comment.

Red first on a throwaway copy: against the gate without rule 19, all 12 refusal fixtures
passed; with it all are refused, the two no-false-refusal rows (an active record with a
rendered block, a vetoed crossing with an empty block) pass, and each of the three clauses
removed lets its own fixture through.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The record validator already refused an incorporation date on a natural
person; the reverse was accepted. A company with incorporated.on unset was
a valid record, so the incorporation trigger never armed the clause and
nothing reported it. The validator now refuses it, and the "record must agree
with itself" test holds the case (red against the old validator, killed by
a mutant that removes the check).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…hai, and tighten the 7-day clause wording

The CHANGELOG now says the Thai 7-day clause lives in legal/ and appears
in TERMS.md only when the legal-state record says a trigger has been met,
and has a bullet for the record, the clause file, the marked block, the
script and rule 19. The Thai enforcement section gains the lead-in that
the list of prohibited conduct is not written yet and the chargeback
track, so it says what the English says. policies.md names rule 19 and
CONTRIBUTING lists the new test and the script that flips the clause.
In the clause itself, the trial before payment is stated as an offer to
make rather than a present fact, and the Thai says whose receipt of the
cancellation notice starts the 15 days. It stays under the pending-legal-
review marker.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…0-line signal

The file is 895 lines, over the room's 800-line review signal. Its head comment
now carries the declared reason: every rule reads one tracked-file list, one set
of scope predicates and one failure list, and the file is the list of record
that docs/TRUST.md and governance/policies.md name, so a split would leave two
lists of record. No code change.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…, N2)

The declared reason for the 895-line file now reads as plain prose: no
session-mode label and no pinned line count. It claims only what the file
shows: one failure list, scope predicates defined once, and the numbered
rules as the list of record named by docs/TRUST.md and governance/policies.md.
Comment-only.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 9e92c866-08cd-4a98-9953-0fb8c224a31d
📥 Commits

Reviewing files that changed from the base of the PR and between 9e60a55 and 442285b.

📒 Files selected for processing (3)
  • governance/policies.md
  • scripts/legal-state.mjs
  • scripts/legal-state.test.mjs
🚧 Files skipped from review as they are similar to previous changes (2)
  • scripts/legal-state.test.mjs
  • scripts/legal-state.mjs

Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: analyze (javascript)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Workers Builds: kolwen
🧰 Additional context used
📓 Path-based instructions (3)
ISO/IEC 27001:2022 and 42001:2023 control-family records that state what is TRUE today; they are not a certification.

⚙️ CodeRabbit configuration file

Files:

  • governance/policies.md
House style is the UNSPACED em dash, an owner ruling, so do not suggest spaced dashes.

⚙️ CodeRabbit configuration file

Files:

  • governance/policies.md
Context for every file.

⚙️ CodeRabbit configuration file

Files:

  • governance/policies.md
🔇 Additional comments (1)
governance/policies.md (1)

24-24: LGTM!


📝 Walkthrough

Walkthrough

The change adds a record-controlled Thai 7-day cancellation clause, revises acceptable-use enforcement deadlines, and updates model release and licensing statements. Scripts validate and render the clause in TERMS.md. Tests and the surface checker cover the legal-state workflow.

Changes

Record-controlled Thai cancellation clause

Layer / File(s) Summary
State and clause inputs
legal/legal-state.json, legal/thai-7day-clause.md, legal/README.md, TERMS.md
Adds an initial state record and English and Thai clause text. The documentation describes triggers, state fields, and legal-review questions. Removes the prior dormant-clause description from TERMS.md.
Validation and rendering
scripts/lib/legal-state.mjs, scripts/legal-state.mjs, scripts/legal-state.test.mjs
Validates the state record and clause markers, derives the active trigger date, and checks or writes the marked TERMS.md block. Tests cover trigger dates, vetoes, invalid records, markers, CLI outcomes, and idempotent writes.
Surface checks and project wiring
scripts/surface-check.mjs, governance/policies.md, .github/workflows/ci.yml, CONTRIBUTING.md, CHANGELOG.md
Adds the state-to-terms consistency check to the surface checker and adds the tests and check command to project instructions and CI. The changelog describes the workflow.

Acceptable-use enforcement process

Layer / File(s) Summary
Enforcement deadlines and process
TERMS.md, docs/SUPPORT-AGENT-SPEC.md, CHANGELOG.md
Specifies response, decision, and appeal deadlines; business-day rules; a 90-calendar-day case limit; key-clock handling; and outcomes for missed deadlines. Adds the Thai-language process and updates the support-agent deadline.

Model release and license statements

Layer / File(s) Summary
Planned weights and licensing statements
README.md, LICENSE, py/LICENSE, SECURITY.md, CHANGELOG.md
Describes weights as unreleased, with no release date set. Updates statements about future Qwen use, attribution, and per-release licensing.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Sequence Diagram(s)

sequenceDiagram
  participant Maintainer
  participant legal-state.mjs
  participant legal-state helper
  participant TERMS.md
  participant surface-check.mjs
  Maintainer->>legal-state.mjs: Run --write or --check
  legal-state.mjs->>legal-state helper: Validate record and derive clause block
  legal-state helper-->>legal-state.mjs: Return findings and rendered block
  legal-state.mjs->>TERMS.md: Write block when --write is valid
  surface-check.mjs->>legal-state helper: Check record and block consistency
Loading

Merge Risk: 🟡 Moderate · up to 44228

The enforcement terms leave unanswered cases without a decision deadline and make the appeal remedy unclear after termination. Resolve these process gaps before merging the updated terms.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://lwk2-1008c-kolwen.hetcreep.workers.dev (commit 442285b)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://5484894a-kolwen.hetcreep.workers.dev 442285b 2026-10-08T14:38:28.148Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://36896c44-kolwen.hetcreep.workers.dev 9e60a55 2026-10-08T14:21:19.904Z Visit the dashboard ↗

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 358b06ab-17a4-48fc-91fc-07012e8538e8
📥 Commits

Reviewing files that changed from the base of the PR and between b90ad0f and 9e60a55.

📒 Files selected for processing (17)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • CONTRIBUTING.md
  • LICENSE
  • README.md
  • SECURITY.md
  • TERMS.md
  • docs/SUPPORT-AGENT-SPEC.md
  • governance/policies.md
  • legal/README.md
  • legal/legal-state.json
  • legal/thai-7day-clause.md
  • py/LICENSE
  • scripts/legal-state.mjs
  • scripts/legal-state.test.mjs
  • scripts/lib/legal-state.mjs
  • scripts/surface-check.mjs

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.

📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: all-green
  • GitHub Check: analyze (javascript)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (python)
  • GitHub Check: Workers Builds: kolwen
🧰 Additional context used
📓 Path-based instructions (11)
A claim about behaviour must match what the code actually does, and any data shown (a version, a model ID, a benchmark figure, a count) must match its authoritative source verbatim.

⚙️ CodeRabbit configuration file

Files:

  • SECURITY.md
  • CONTRIBUTING.md
  • README.md
  • TERMS.md
Kolwen's PyPI name-reservation package: Python inside an otherwise Node organisation.

⚙️ CodeRabbit configuration file

Files:

  • py/LICENSE
Every action is pinned to a 40-character commit SHA with a version comment, and the organisation refuses unpinned actions, so never suggest a tag pin.

⚙️ CodeRabbit configuration file

Files:

  • .github/workflows/ci.yml
Tests use node:test only, run from an explicit file list that fails on an unlisted or missing file.

⚙️ CodeRabbit configuration file

Files:

  • scripts/legal-state.test.mjs
Keep a Changelog.

⚙️ CodeRabbit configuration file

Files:

  • CHANGELOG.md
Library modules, and some ship to users.

⚙️ CodeRabbit configuration file

Files:

  • scripts/lib/legal-state.mjs
ISO/IEC 27001:2022 and 42001:2023 control-family records that state what is TRUE today; they are not a certification.

⚙️ CodeRabbit configuration file

Files:

  • governance/policies.md
Licence files.

⚙️ CodeRabbit configuration file

Files:

  • LICENSE
  • py/LICENSE
Repo gates and CLIs.

⚙️ CodeRabbit configuration file

Files:

  • scripts/surface-check.mjs
  • scripts/legal-state.mjs
  • scripts/legal-state.test.mjs
  • scripts/lib/legal-state.mjs
House style is the UNSPACED em dash, an owner ruling, so do not suggest spaced dashes.

⚙️ CodeRabbit configuration file

Files:

  • docs/SUPPORT-AGENT-SPEC.md
  • SECURITY.md
  • legal/thai-7day-clause.md
  • governance/policies.md
  • legal/README.md
  • CONTRIBUTING.md
  • README.md
  • CHANGELOG.md
  • TERMS.md
Context for every file.

⚙️ CodeRabbit configuration file

Files:

  • docs/SUPPORT-AGENT-SPEC.md
  • SECURITY.md
  • legal/legal-state.json
  • scripts/surface-check.mjs
  • legal/thai-7day-clause.md
  • governance/policies.md
  • legal/README.md
  • CONTRIBUTING.md
  • scripts/legal-state.mjs
  • README.md
  • LICENSE
  • scripts/legal-state.test.mjs
  • py/LICENSE
  • scripts/lib/legal-state.mjs
  • CHANGELOG.md
  • TERMS.md
🪛 GitHub Check: lint
README.md

[failure] 14-14: Line length
brand/README.md:14:81 MD013/line-length Line length [Expected: 80; Actual: 92] https://github.com/DavidAnson/markdownlint/blob/v0.41.1/doc/md013.md

🔇 Additional comments (5)
docs/SUPPORT-AGENT-SPEC.md (1)

68-68: LGTM!

README.md (1)

14-14: LGTM!

Also applies to: 27-28, 39-39

LICENSE (1)

12-15: LGTM!

Also applies to: 21-23

py/LICENSE (1)

12-15: LGTM!

Also applies to: 21-23

SECURITY.md (1)

46-48: LGTM!

Comment thread governance/policies.md Outdated
Comment thread scripts/legal-state.mjs Outdated
Comment thread scripts/legal-state.mjs
writeFileSync(join(dir, 'TERMS.md'), terms);
return dir;
}
const run = (dir, args = []) => spawnSync(process.execPath, ['--max-old-space-size=2048', SCRIPT, ...args], { cwd: dir, encoding: 'utf8', timeout: 30000 });

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Sandbox the spawned CLI’s HOME and TEMP.

spawnSync() changes the working directory but inherits the runner’s real HOME and temporary-directory settings. Give each fixture private home and temp directories, then pass those paths through env. This also isolates runs that use LEGAL_STATE_SCRIPT to select a mutant. As per path instructions, “A test that spawns a hook or a CLI sandboxes HOME and TEMP and must never write the real ~/.claude.”

Source: Path instructions

Comment thread TERMS.md
Comment thread TERMS.md
…arse, and rule 10's list in policies (review)

Three review threads on the legal-state work.

- scripts/legal-state.mjs runs in main() and sets process.exitCode instead of
  calling process.exit; the exit codes are unchanged (0, 1, 2).
- A leading byte-order mark on the record is stripped once at read, so
  validation and parsing see the same text. Before, a record that passed
  validation threw an uncaught SyntaxError in --write. The character is built
  from its code point. One test covers a BOM-led active record.
- governance/policies.md rule 10 now lists legal/thai-7day-clause.md among the
  legal drafts, as the check runs it.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@HetCreep
HetCreep merged commit cf7ca5e into main Oct 8, 2026
14 checks passed
@HetCreep
HetCreep deleted the lwk2-1008c branch October 8, 2026 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant