build(site): [SITE-07] distribute verified console package and embedded notices

This commit is contained in:
Harvey Zhao committed 2026-09-15 07:21:02 +08:00
1 parent 63e4e8ad92
commit 199021c8a9
55 files changed
+1918 -14

No files matched your search

+3
View File
@@ -29,6 +29,9 @@ test('mobile vConsole shows logs and upstream site notice texts are served uncha
const index = await request.get('/THIRD_PARTY_NOTICES.md')
expect(index.status()).toBe(200)
expect(await index.text()).toContain('Included component: @vscode/codicons 0.0.26')
expect(await index.text()).toContain('Included component: console-feed 3.2.2')
expect(await index.text()).toContain('Included component: chromium-string-utils')
expect(await index.text()).toContain('Embedded attribution review is still incomplete')
await page.evaluate(() => {
window.vConsole.destroy()
window.art.destroy()
+21
View File
@@ -7,12 +7,33 @@ import process from 'node:process'
import test from 'node:test'
import ts from 'typescript'
import { generateConsole, moduleRanges, obsoleteMap, upstreamSha256 } from '../scripts/site-vendor/console/build.ts'
import { extractNotice } from '../scripts/site-vendor/console/embedded-notices.ts'
import { hash, parcelModules, verifyArchive, verifyModules, verifyPackageEdges } from '../scripts/site-vendor/console/provenance.ts'
import { reconstructModule, verifyPrelude } from '../scripts/site-vendor/console/reconstruction.ts'
import { errorArgument } from '../scripts/site-vendor/console/runtime/errors.ts'
import { css } from '../scripts/site-vendor/console/runtime/style.ts'
import { createSubscriptions } from '../scripts/site-vendor/console/runtime/subscriptions.ts'
test('Embedded notices retain exact headers and reject missing or changed mapped sources', () => {
const source = '// Copyright owner\n// Full permission and disclaimer.\nconst value = 1;'
const text = '// Copyright owner\n// Full permission and disclaimer.\n'
const bytes = Buffer.from(source)
const notice = { archive: 'fixture', member: 'index.js', memberSha256: hash(bytes), sourceSha256: hash(source), start: '// Copyright owner', end: '// Full permission and disclaimer.\n', source: 'LICENSE', sha256: hash(text) }
assert.equal(extractNotice(bytes, notice), text)
assert.throws(() => extractNotice(Buffer.from(`${source}\n`), notice), /archive member changed/)
assert.throws(() => extractNotice(bytes, { ...notice, end: 'absent' }), /Missing notice end/)
assert.throws(() => extractNotice(bytes, { ...notice, sha256: hash('shortened') }), /excerpt changed/)
const map = { sources: ['../src/plugin.js'], sourcesContent: [source] }
const mapped = Buffer.from(JSON.stringify(map))
const mappedNotice = { ...notice, mapSource: map.sources[0], memberSha256: hash(mapped) }
assert.equal(extractNotice(mapped, mappedNotice), text)
assert.throws(() => extractNotice(mapped, { ...mappedNotice, mapSource: 'missing.js' }), /map source/)
for (const changed of [{ ...map, sourcesContent: [null] }, { sources: [...map.sources, ...map.sources], sourcesContent: [source, source] }, { ...map, sourcesContent: ['changed'] }]) {
const changedBytes = Buffer.from(JSON.stringify(changed))
assert.throws(() => extractNotice(changedBytes, { ...mappedNotice, memberSha256: hash(changedBytes) }), /source content|map source|source changed/)
}
})
function fixture() {
const jobs = new Map()
let id = 0
+23
View File
@@ -105,3 +105,26 @@ test('Site notice CLI rejects omitted reviewed components and supplemental vCons
assert(!fs.existsSync(path.join(root, 'docs')))
}
})
test('Console notice CLI rejects omitted package or embedded attribution before writing', (t) => {
const { root } = fixture(t)
const manifestPath = path.join(root, 'scripts/site-vendor/manifest.json')
fs.mkdirSync(path.dirname(manifestPath), { recursive: true })
const original = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
for (const name of ['console-feed', 'parcel-bundler', 'styled-components', 'chromium-string-utils', 'stylis-rule-sheet']) {
for (const field of ['components', 'notices']) {
const manifest = structuredClone(original)
const group = manifest.groups.find(group => group.name === 'console')
const component = group.components.find(component => component.name === name)
if (field === 'components')
group.components = group.components.filter(item => item !== component)
else
group.notices = group.notices.filter(notice => !component.notices.includes(notice.target))
fs.writeFileSync(manifestPath, JSON.stringify(manifest))
const result = spawnSync(process.execPath, [path.resolve('scripts/build-site-notices.mjs')], { cwd: root, encoding: 'utf8' })
assert.equal(result.status, 1)
assert.match(result.stderr, field === 'components' ? /Do not silently drop verified console/ : /Missing reviewed console notice/)
assert(!fs.existsSync(path.join(root, 'docs')))
}
}
})