build(site): [SITE-07] distribute verified console package and embedded notices

This commit is contained in:
Harvey Zhao committed 2026-09-15 07:21:02 +08:00
1 parent 63e4e8ad92
commit 199021c8a9
55 files changed
+1918 -14

No files matched your search

@@ -0,0 +1,41 @@
{
"schemaVersion": 1,
"task": "SITE-07",
"notices": [
{
"archive": "console-feed-3.2.2",
"member": "package/lib/Component/devtools-parser/string-utils.js",
"start": "// Copyright 2014 The Chromium Authors.",
"end": "// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n",
"memberSha256": "1daafcdb9cdeab609e5c4561903d821acd46b6edac8a84bbaf93fc710ce3e99d",
"sourceSha256": "1daafcdb9cdeab609e5c4561903d821acd46b6edac8a84bbaf93fc710ce3e99d",
"source": "refactor/baselines/site-vendor/console-embedded/chromium-string-utils-LICENSE.txt",
"sha256": "7a209dd1b94cabdb5ea9c6f9164b9546ffa5daaa671e7767d49510db055f5c51"
},
{
"archive": "styled-components-5.3.3",
"member": "package/dist/styled-components.browser.esm.js.map",
"mapSource": "../src/utils/stylisPluginInsertRule.js",
"start": "/**\n * MIT License",
"end": " */\n",
"memberSha256": "582683de52b70c913c6265acf7ade913a53a69d569216f951990c220db28ed44",
"sourceSha256": "76ff20854b816d05778c864647dfb9b300d8f5fc4f1df5f4d774ffa47a340871",
"source": "refactor/baselines/site-vendor/console-embedded/stylis-rule-sheet-LICENSE.txt",
"sha256": "99a75da65634b772687781c054ffe679569c1770c398f96427677899fe0ca8d7"
}
],
"review": {
"status": "partial",
"confirmed": [
"Chromium copyright and full BSD conditions in console-feed source",
"Sultan Tarimo MIT header in styled-components embedded rule-sheet source"
],
"pending": [
"console-feed replicator upstream attribution",
"linkifyjs simple-html-tokenizer attribution",
"Emotion stylis/hash and cache rule-sheet attribution",
"react-inspector embedded Babel/regenerator source and notices",
"console-feed Component Stack Overflow attribution and any additional embedded sources"
]
}
}
@@ -0,0 +1,86 @@
{
"schemaVersion": 1,
"task": "SITE-07",
"status": "checkpoint-incomplete",
"recordedAt": "2026-09-14T23:20:00.640Z",
"baseCommit": "63e4e8ad9206049c48bd2e2aee05166c05bed8d7",
"node": "v24.21.0",
"sourceFingerprint": {
"manifestSha256": "ba103e8ec004b5670dec9ee096edaa84d7b72da08b97e2807eac87dcc911420e",
"embeddedRecordSha256": "f11b0c4e903b448cacef60493c4991f79679ad67d68e9a2dcd18d0545c7fa150",
"consoleSha256": "5644af7bb35bb6d0bcfa7eeae9a21b406ac4fc1b499a6c797a6534c7d33f0678"
},
"unit": {
"command": "node --test test/site-console.test.js test/site-notices.test.js",
"passed": 20,
"failed": 0,
"log": "refactor/.cache/console-notices-tests.log"
},
"reproduction": {
"exactModules": 100,
"embeddedNotices": 2,
"licenseClosure": false,
"log": "refactor/.cache/console-notices-reproduce.log"
},
"browser": {
"command": "node node_modules/@playwright/test/cli.js test test/browser/site-vendor.spec.js --workers=1",
"report": "refactor/.cache/browser/report.json",
"sha256": "9a3c46a1b5c40514f4ba8a6733249d3b8d771c1cdaac1634b676b9d24cd7619d",
"tests": [
{
"project": "chromium",
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"status": "passed",
"retry": 0,
"browser": "153.0.8010.12",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [
{
"url": "http://127.0.0.1:8084/test/pattern.mp4",
"resourceType": "media",
"failure": {
"errorText": "net::ERR_ABORTED"
}
}
]
},
{
"project": "firefox",
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"status": "passed",
"retry": 0,
"browser": "155.0",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": []
},
{
"project": "webkit",
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"status": "passed",
"retry": 0,
"browser": "26.6",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": []
}
],
"noticeFilesPerEngine": 53
},
"checks": [
"docs-tools strict TypeScript",
"scoped ESLint after three style corrections",
"build-site-notices --check",
"build-console --check"
],
"limits": [
"Embedded attribution review remains incomplete; see console-embedded-notices.json",
"HTTPS integrations fulfilled by fixture; only local real pages and playback verified",
"Windows desktop engines are not physical mobile device evidence",
"No runtime, lockfile, push, deployment or publication change"
]
}
@@ -0,0 +1,27 @@
// Copyright 2014 The Chromium Authors. All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions are
// met:
//
// * Redistributions of source code must retain the above copyright
// notice, this list of conditions and the following disclaimer.
// * Redistributions in binary form must reproduce the above
// copyright notice, this list of conditions and the following disclaimer
// in the documentation and/or other materials provided with the
// distribution.
// * Neither the name of Google Inc. nor the names of its
// contributors may be used to endorse or promote products derived from
// this software without specific prior written permission.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
@@ -0,0 +1,20 @@
/**
* MIT License
*
* Copyright (c) 2016 Sultan Tarimo
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"),
* to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
* sell copies of the Software and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
* OR IMPLIED INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
* WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR
* IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*/
@@ -0,0 +1,48 @@
# SITE-07 控制台许可分发检查点
以 63e4e8ad9206049c48bd2e2aee05166c05bed8d7 为修改前 HEAD,继续同一任务。
100 个模块及 Parcel 来源复现已通过;本次补齐已核实许可的实际站点分发。
## 实现与来源
站点 manifest 新增 console 组,把 32 个运行时包、Parcel 加载器的完整许可
接入现有 notices 生成器。styled-components 继续使用上一批已固定的上游文本。
原包许可不自动覆盖内嵌代码:console-feed 的 string-utils 明确保留 Chromium
2014 年 BSD 许可;styled-components 5.3.3 的 browser ESM source map 中,
stylisPluginInsertRule.js 保留 Sultan Tarimo 2016 年 MIT 全文。两段完整注释
分别保留,记录归档、成员、映射源路径和三层 SHA-256,不删注释符或改写原文。
新增 embedded-notices.ts 负责精确抽取和验证,reproduce.ts 纳入离线复核。
站点 CLI 保护三个组、原10组件及控制台35组件/35许可数量,避免清单意外缩小。
生成 docs/licenses/console/ 下35文件及公共总索引;所有许可输出共53文件,
加总索引为54输出。Git 属性保留原字节,后续修改从来源/manifest 更新再生成。
## 验证
- Node 24.21.0,Yarn 1.22.22 配置不变,未新增依赖或锁文件修改。
- 控制台与 notices 单元20/20;包括缺映射源、重复源、缺正文、篡改/截短许可、
删除包或独立署名时在写出前失败的反例。
- 完整离线复现100/100、Parcel及跨包边通过,新增两段许可抽取精确匹配。
- docs-tools 严格 TS 通过;首次 lint 发现 includes 写法与 import 排序问题,
修复后相关 lint 通过;console 与 notices 只读生成检查通过。
- 三引擎实际本地页面3/3,无重试或跳过。每个引擎请求并逐字节比较全部53份
许可,校验公共索引、Codicons 字体,且运行移动页日志、原生播放与销毁。
具体浏览器版本、报告哈希及诊断见[验证记录](../baselines/console-notices-validation.json)。
外部 HTTPS 被测试夹具隔离;这是 Windows 本地页面证据,不代表手机或远端发布。
Chromium 诊断记录一次 pattern.mp4 的 ERR_ABORTED;播放断言及销毁通过,
没有未处理页面错误/console error。现有诊断没有请求失败时间,故不将其断言
为特定销毁时刻的取消;许可 HTTP 请求全部成功且字节一致。
## 剩余范围与回退
这不是完整许可审查结论。需继续核对 console-feed 的 replicator 与 Component
内 Stack Overflow 引用、linkifyjs 的 simple-html-tokenizer、Emotion 中的
stylis/hash/cache rule-sheet,以及 react-inspector 源码映射显示的 Babel/
regenerator 内嵌代码。已发现链接或映射源并不等于已确认其版本/许可要求;
详见 console-embedded-notices.json 的 pending 项。VENDOR-08 保持 open,
SITE-07 保持 doing,仍199/265完成;Monaco/字体/媒体的其他范围继续待审。
无站点运行时 JS、旧 API、包版本或入口变化。上一批控制台运行时测试仍对应
相同源码产物,本轮补测实际许可交付。回退移除 console notice 组/新增输出及
抽取器,恢复原生成器检查,不改变已交付的控制台生命周期修复。
本地独立检查点提交,无推送、部署或发布。
+1 -1
View File
@@ -653,7 +653,7 @@
- SITE-AI-DOCS-01: [记录](changes/2026-09-14-SITE-AI-DOCS-01-documentation-pipeline.md) [记录](baselines/documentation-pipeline-validation.json)
- SITE-BUILD-01: [记录](changes/2026-09-14-SITE-BUILD-01-staged-builds.md) [记录](baselines/site-build-validation.json)
- SITE-03: [记录](changes/2026-09-14-SITE-03-desktop-editor.md) [记录](baselines/site-editor-validation.json)
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md)
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md) [记录](baselines/console-embedded-notices.json) [记录](baselines/console-notices-validation.json) [记录](changes/2026-09-15-SITE-07-console-notices.md)
- EX-01: [记录](changes/2026-09-14-EX-01-react-consumer.md) [记录](baselines/react-consumer-validation.json) [记录](scripts/react-consumer.mjs)
- EX-02: [记录](changes/2026-09-14-EX-02-vue-consumer.md) [记录](baselines/vue-consumer-validation.json) [记录](scripts/vue-consumer.mjs)
- MOD-01: [记录](changes/2026-09-15-MOD-01-bun-evaluation.md) [记录](baselines/bun-install-validation.json) [记录](bun-evaluation.md)
+7
View File
@@ -1,5 +1,12 @@
# 进度与证据
## SITE-07 控制台许可实际分发
32个包与Parcel许可、Chromium及Stylis两份内嵌完整许可已接入生成流程,新增35份
站点文件。单元20/20、离线复现100/100、三引擎HTTP逐字节及移动播放3/3通过。
见[记录](changes/2026-09-15-SITE-07-console-notices.md)。继续核查其他内嵌来源,
VENDOR-08 open、SITE-07 doing,仍199/265。运行时与锁未变,无推送/发布。
## SITE-07 控制台 100/100 源码与 Parcel 加载器匹配
最后27模块使用固定归档与分阶段 Babel 转换精确重建,全部100模块、跨包边与
+7 -2
View File
@@ -690,11 +690,16 @@
"refactor/changes/2026-09-15-SITE-07-console-commonjs.md",
"refactor/baselines/console-esm-provenance.json",
"refactor/changes/2026-09-15-SITE-07-console-esm.md",
"scripts/site-vendor/console/reconstruction.ts"
"scripts/site-vendor/console/reconstruction.ts",
"refactor/baselines/console-embedded-notices.json",
"refactor/baselines/console-notices-validation.json",
"refactor/changes/2026-09-15-SITE-07-console-notices.md",
"scripts/site-vendor/console/embedded-notices.ts",
"docs/THIRD_PARTY_NOTICES.md"
],
"compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.",
"closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。",
"workspaceState": "All 100 vendor module bodies and the Parcel prelude/invocation exactly reproduce from fixed official archives; all cross-package import edges verified. Original full lockfile is not recovered. Complete embedded attribution and public notices remain open; runtime unchanged."
"workspaceState": "All 100 vendor module bodies and Parcel loader exactly reproduce from fixed archives. Public notices now deliver 32 package licenses, the Parcel license, and exact Chromium/Sultan Tarimo embedded headers; all 53 site notice files passed byte-for-byte HTTP checks in three engines. Remaining embedded attribution is explicitly tracked in console-embedded-notices.json. Original full lockfile is not recovered; runtime unchanged."
},
{
"id": "SDK-01",
+4 -1
View File
@@ -4494,7 +4494,10 @@
"baselines/console-commonjs-provenance.json",
"changes/2026-09-15-SITE-07-console-commonjs.md",
"baselines/console-esm-provenance.json",
"changes/2026-09-15-SITE-07-console-esm.md"
"changes/2026-09-15-SITE-07-console-esm.md",
"baselines/console-embedded-notices.json",
"baselines/console-notices-validation.json",
"changes/2026-09-15-SITE-07-console-notices.md"
]
},
{