docs(site): [SITE-07] ship selected font notice references

This commit is contained in:
Harvey Zhao committed 2026-09-15 20:37:46 +08:00
1 parent 01f3d00e4c
commit 4545c43679
29 files changed
+3508 -12

No files matched your search

+4 -2
View File
@@ -2,6 +2,7 @@ import assert from 'node:assert/strict'
import fs from 'node:fs'
import process from 'node:process'
import { verifyConsoleNoticeSources } from './site-vendor/console/notices.ts'
import { verifyFontNotices } from './site-vendor/fonts/notices.ts'
import { verifyMonacoCoreNotices } from './site-vendor/monaco/core-origins.ts'
import { verifyMonacoDomNotices } from './site-vendor/monaco/dom-origins.ts'
import { verifyMonacoPathNotices } from './site-vendor/monaco/node-path.ts'
@@ -12,8 +13,8 @@ import { writeOrCheckNotices } from './site-vendor/notices.ts'
assert(process.argv.slice(2).every(arg => arg === '--check'), 'Use yarn build:site-notices [--check]')
/** @type {import('./site-vendor/notices.ts').VendorManifest} */
const manifest = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
assert.deepEqual(manifest.groups.map(group => group.name).sort(), ['console', 'monaco-editor', 'vconsole'], 'Do not silently drop a verified site component')
assert.deepEqual(manifest.groups.filter(group => group.name !== 'console').flatMap(group => (group.components || []).map(component => component.name)).sort(), [
assert.deepEqual(manifest.groups.map(group => group.name).sort(), ['console', 'jassub-fonts', 'monaco-editor', 'vconsole'], 'Do not silently drop a verified site component')
assert.deepEqual(manifest.groups.filter(group => ['monaco-editor', 'vconsole'].includes(group.name)).flatMap(group => (group.components || []).map(component => component.name)).sort(), [
'@babel/runtime',
'@vscode/codicons',
'Unicode data (Monaco core)',
@@ -94,6 +95,7 @@ assert.deepEqual(typeScriptNotices?.map(target => target.split('/').pop()).sort(
for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md'])
assert(vconsoleNotices?.includes(`docs/licenses/vconsole/${name}`), `Missing vConsole notice: ${name}`)
verifyConsoleNoticeSources(process.cwd(), manifest)
verifyFontNotices(process.cwd(), manifest)
verifyMonacoCoreNotices(process.cwd(), manifest)
verifyMonacoDomNotices(process.cwd(), manifest)
verifyMonacoUnicodeNotices(process.cwd(), manifest)
+8
View File
@@ -69,6 +69,14 @@ Follow-up: finish Monaco's broader bundled-component notice audit and remaining
fonts/media. Do not upgrade these assets
without verifying globals, AMD/worker paths, CSS, consoleLog and user interaction.
The notice inventory also includes four selected JASSUB font families at their
five unchanged URLs. CHAWP matches the author font exactly; Liberation, Averia
Sans and Lato have explicitly recorded reference-table differences. Full upstream
terms and embedded copyright are delivered together. Averia Serif Simple and six
other font permissions remain unresolved; this is not font redistribution clearance.
See [font reference maintenance](fonts/README.md). The generator now preserves all
four top-level groups and validates the font-to-notice bindings before writing.
Monaco's actual TypeScript 4.4.4 worker now has a separate source proof and notice
supplement; its original notice's 2.7.2 label is retained and explained. See
[Monaco maintenance](monaco/README.md) for the fixed six source adaptations,
+53
View File
@@ -0,0 +1,53 @@
# Selected font notice references
`notices.ts` binds the selected JASSUB font bytes, complete upstream terms and
attribution to `site-font-notices-provenance.json`. Ordinary notice generation is
offline and checks every binding before writing. Five font paths represent four
families: Liberation Sans (two existing default copies), Averia Sans Libre Light,
Lato Regular and CHAWP. No font, subtitle style, family name or URL is replaced.
CHAWP is byte-identical to the pinned author repository. The other three are
references with documented font-table differences: outlines, character mapping
and horizontal metrics match, but this does not recover the original conversion
recipe or prove that the files were never modified. Lato's reference OFL header
and its embedded copyright use different year ranges; both are preserved.
The complete notices and the bounded attribution ship in `docs/licenses/jassub-fonts/`.
Averia Serif Simple Light remains unresolved: the Serif Libre reference has a
different encoded `g` glyph. It cannot be silently treated as the same font.
Allison, Architext, Arial, Franklin Gothic, Garamond and Slate Pro are also outside
this group pending redistribution evidence or a reviewed replacement. VENDOR-05,
BASE-MEDIA-01 and SITE-07 remain open; publishing an OFL reference does not itself
close font provenance or release review.
## Reproduce the comparison
The provenance record pins exact Git commits, file paths, SHA-256 and Git blob
identity for the reference fonts. Retrieve GitHub files through the contents API
at that exact `ref`, decode its base64 content to bytes and verify both hashes.
The Liberation reference comes from the recorded release attachment: verify the
archive SHA-256 before reading its exact font/LICENSE members to memory with tar.
Do not pipe binary fonts through PowerShell text redirection or substitute newer
font versions. The Serif negative reference uses the separate fixed URL and hash.
Save these reference files as `liberation.ttf`, `averia-sans.ttf`, `lato.ttf`,
`chawp.otf` and `averia-serif.ttf` in an ignored directory. Use Python 3.12 with
fonttools 4.60.1 and brotli 1.1.0 (the pre-existing isolated font inspector tools),
then run:
```sh
python refactor/scripts/site-font-comparison.py <reference-directory> --check
```
The read-only script verifies input hashes before parsing, compares every SFNT
table, all glyph outlines/order, character mapping and horizontal metrics, and
checks the full result against the recorded observations, including the negative
case. It never changes font files or writes a replacement baseline. Ordinary CI
does not need Python or these archived references; it validates local font/notice
fingerprints and runs the binding tests.
Run `yarn build:site-notices`, `yarn check:site-notices`,
`node --test test/site-notices.test.js`, and
`yarn test:browser site-vendor.spec.js --workers=1`. The browser checks original
font HTTP bytes, native FontFace loading and ink, notice bytes/links and real
mobile playback. They are not a complete libass subtitle shaping comparison.
+28
View File
@@ -0,0 +1,28 @@
import type { VendorManifest } from '../notices.ts'
import assert from 'node:assert/strict'
import { createHash } from 'node:crypto'
import fs from 'node:fs'
import path from 'node:path'
interface FontRecord {
group: VendorManifest['groups'][number]
unresolved: string[]
}
export function verifyFontNotices(root: string, manifest: VendorManifest) {
const record = JSON.parse(fs.readFileSync(path.join(root, 'refactor/baselines/site-font-notices-provenance.json'), 'utf8')) as FontRecord
assert.deepEqual(record.group.components?.map(component => component.name).sort(), ['Averia Sans Libre Light', 'CHAWP', 'Lato Regular', 'Liberation Sans'], 'Incomplete reviewed font roster')
assert.equal(record.group.files.length, 5, 'Keep both default font copies and the three selected demo fonts')
assert.equal(record.group.notices.length, 5, 'Keep four full font licenses and attribution')
const group = manifest.groups.filter(group => group.name === 'jassub-fonts')
assert.deepEqual(group, [record.group], 'Font notice/source binding changed')
for (const file of record.group.files) {
assert(!record.unresolved.includes(file.path), 'Unresolved font cannot be promoted by a notice binding')
const bytes = fs.readFileSync(path.join(root, file.path))
assert.equal(createHash('sha256').update(bytes).digest('hex'), file.sha256, `Font bytes changed: ${file.path}`)
}
for (const notice of record.group.notices) {
const bytes = fs.readFileSync(path.join(root, notice.source))
assert.equal(createHash('sha256').update(bytes).digest('hex'), notice.sha256, `Font notice changed: ${notice.source}`)
}
}
+119 -1
View File
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"scope": "Frozen source identities and verbatim upstream notice texts for Monaco, vConsole and the legacy console bundle. Embedded component attribution, fonts, media and other site provenance gates remain open; this inventory is not publication clearance.",
"scope": "Frozen source identities and complete upstream notice texts for selected site components and font references. Unresolved font/media and embedded provenance gates remain open; this inventory is not publication clearance.",
"groups": [
{
"name": "vconsole",
@@ -2006,6 +2006,124 @@
]
}
]
},
{
"name": "jassub-fonts",
"version": "selected historical references",
"tarball": "https://github.com/ThaUnknown/jassub/tree/25d1ea7ca1f827dbed2c8ea539c9bc917ccbfab1",
"review": "Four selected font families only. CHAWP matches author bytes; other full notice references have explicit font-table differences. Other fonts and complete redistribution provenance remain open under SITE-07/VENDOR-05.",
"roots": [
"docs/assets/jassub/default.woff2",
"docs/assets/jassub/fonts/default.woff2",
"docs/assets/jassub/fonts/Averia Sans Libre Light.ttf",
"docs/assets/jassub/fonts/Lato-Regular.ttf",
"docs/assets/jassub/fonts/chawp.otf"
],
"files": [
{
"path": "docs/assets/jassub/default.woff2",
"sha256": "886929903707c5bb28b07cd2eed69921b3d5ef5c49c73a0dd1e187ebf6546a4c",
"mode": "binary"
},
{
"path": "docs/assets/jassub/fonts/default.woff2",
"sha256": "886929903707c5bb28b07cd2eed69921b3d5ef5c49c73a0dd1e187ebf6546a4c",
"mode": "binary"
},
{
"path": "docs/assets/jassub/fonts/Averia Sans Libre Light.ttf",
"sha256": "df4ca526f9a941afda1f9c5a275695beb066a531f5b008c1e28ddc2c5f6e4390",
"mode": "binary"
},
{
"path": "docs/assets/jassub/fonts/Lato-Regular.ttf",
"sha256": "6f6940be0835c3ddec9199e5fc42be4cbc61ebcfd58c623fdf719366253f1780",
"mode": "binary"
},
{
"path": "docs/assets/jassub/fonts/chawp.otf",
"sha256": "9107241585a4328ce1438dfeabbfb1a8d0cd513dab6902be9a1a5774eab607c6",
"mode": "binary"
}
],
"components": [
{
"name": "Liberation Sans",
"version": "2.00.5 reference",
"tarball": "https://github.com/liberationfonts/liberation-fonts/files/2926169/liberation-fonts-ttf-2.00.5.tar.gz",
"assets": [
"docs/assets/jassub/default.woff2",
"docs/assets/jassub/fonts/default.woff2"
],
"notices": [
"docs/licenses/jassub-fonts/liberation/OFL.txt",
"docs/licenses/jassub-fonts/ATTRIBUTION.md"
]
},
{
"name": "Averia Sans Libre Light",
"version": "1.002 reference",
"tarball": "https://github.com/google/fonts/blob/0f81bc90462b862dbfe3d16403ff284a68473833/ofl/averiasanslibre/AveriaSansLibre-Light.ttf",
"assets": [
"docs/assets/jassub/fonts/Averia Sans Libre Light.ttf"
],
"notices": [
"docs/licenses/jassub-fonts/averia-sans/OFL.txt",
"docs/licenses/jassub-fonts/ATTRIBUTION.md"
]
},
{
"name": "Lato Regular",
"version": "2.015 reference",
"tarball": "https://github.com/google/fonts/blob/f3b885d5590e307e02542f1a724cec55d567fdaa/ofl/lato/Lato-Regular.ttf",
"assets": [
"docs/assets/jassub/fonts/Lato-Regular.ttf"
],
"notices": [
"docs/licenses/jassub-fonts/lato/OFL.txt",
"docs/licenses/jassub-fonts/ATTRIBUTION.md"
]
},
{
"name": "CHAWP",
"version": "1.000 exact bytes",
"tarball": "https://github.com/awp/chawp/blob/3c4f6317bebd6783c8d0db3bc9206aa62d602f90/chawp.otf",
"assets": [
"docs/assets/jassub/fonts/chawp.otf"
],
"notices": [
"docs/licenses/jassub-fonts/chawp/OFL.txt",
"docs/licenses/jassub-fonts/ATTRIBUTION.md"
]
}
],
"notices": [
{
"source": "refactor/baselines/site-vendor/jassub-fonts/liberation-OFL.txt",
"target": "docs/licenses/jassub-fonts/liberation/OFL.txt",
"sha256": "93fed46019c38bbe566b479d22148e2e8a1e85ada614accb0211c37b2c61c19b"
},
{
"source": "refactor/baselines/site-vendor/jassub-fonts/averia-sans-OFL.txt",
"target": "docs/licenses/jassub-fonts/averia-sans/OFL.txt",
"sha256": "46239ba6485d28553fd944da4ad32a00d9c403aa1c3e111676b0b96fe458d1d4"
},
{
"source": "refactor/baselines/site-vendor/jassub-fonts/lato-OFL.txt",
"target": "docs/licenses/jassub-fonts/lato/OFL.txt",
"sha256": "74ba064d03f1f1c4a952da936c3eb71866c34404916734de3cae73b34357e59e"
},
{
"source": "refactor/baselines/site-vendor/jassub-fonts/chawp-OFL.txt",
"target": "docs/licenses/jassub-fonts/chawp/OFL.txt",
"sha256": "fa786a37ddd70be650bc53d476cc0a1ec5a6284c6f28a32943e941021b2397b8"
},
{
"source": "refactor/baselines/site-vendor/jassub-fonts/ATTRIBUTION.txt",
"target": "docs/licenses/jassub-fonts/ATTRIBUTION.md",
"sha256": "b9485c05b07bbfca2407f4336247d2bb19eba05458fe9bced8f68c81c158504d"
}
]
}
]
}