mirror of
https://github.com/zhw2590582/ArtPlayer.git
synced 2026-10-08 19:06:15 -08:00
build(site): [SITE-07] verify vConsole sources and complete notices
This commit is contained in:
1 parent
bf432ed62a
commit
d2f4261aa7
41 files changed
+2206
-22
No files matched your search
@@ -7,6 +7,20 @@ assert(process.argv.slice(2).every(arg => arg === '--check'), 'Use yarn build:si
|
||||
/** @type {import('./site-vendor/notices.ts').VendorManifest} */
|
||||
const manifest = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
|
||||
assert.deepEqual(manifest.groups.map(group => group.name).sort(), ['monaco-editor', 'vconsole'], 'Do not silently drop a verified site component')
|
||||
assert.deepEqual(manifest.groups.flatMap(group => (group.components || []).map(component => component.name)), ['@vscode/codicons'], 'Do not silently drop the verified Codicons attribution')
|
||||
assert.deepEqual(manifest.groups.flatMap(group => (group.components || []).map(component => component.name)).sort(), [
|
||||
'@babel/runtime',
|
||||
'@vscode/codicons',
|
||||
'copy-text-to-clipboard',
|
||||
'core-js',
|
||||
'css-loader',
|
||||
'mutation-observer',
|
||||
'regenerator-runtime',
|
||||
'style-loader',
|
||||
'svelte',
|
||||
'webpack',
|
||||
], 'Do not silently drop verified bundled component attribution')
|
||||
const vconsoleNotices = manifest.groups.find(group => group.name === 'vconsole')?.notices.map(notice => notice.target)
|
||||
for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md'])
|
||||
assert(vconsoleNotices?.includes(`docs/licenses/vconsole/${name}`), `Missing vConsole notice: ${name}`)
|
||||
const count = writeOrCheckNotices(process.cwd(), manifest, process.argv.includes('--check'))
|
||||
console.log(`Verified site notices: ${count} outputs; Monaco/vConsole only, other provenance gates remain open.`)
|
||||
@@ -3,8 +3,10 @@
|
||||
`manifest.json` pins the already-identified Monaco 0.30.1 and vConsole 3.15.0
|
||||
archives, corresponding files and upstream notice texts. It does not clear other
|
||||
site dependencies or grant rights to samples/fonts. The vConsole LICENSE is
|
||||
preserved verbatim but is incomplete: it promises an MIT copy that is absent.
|
||||
Its completion and bundled dependency notices remain open under SITE-07.
|
||||
preserved verbatim. A separately identified MIT text supplies the body referenced
|
||||
by the original bundle, alongside the full notices for eight bundled dependencies
|
||||
and webpack's generated bootstrap. Fixed-source reconstruction verifies their
|
||||
identity; see `vconsole/README.md` and `vconsole/reproduce.ts`.
|
||||
Monaco's supplied notices lack a Codicons entry. The bundled font now has an
|
||||
exact byte match to the official `@vscode/codicons@0.0.26` archive. Its historical
|
||||
README, CC BY 4.0 content license and MIT code license are preserved, alongside
|
||||
@@ -20,7 +22,8 @@ files retain their exact upstream bytes, including final blank lines.
|
||||
`../build-site-notices.mjs` provides `yarn build:site-notices` and read-only
|
||||
`yarn check:site-notices`. The write command cannot bless altered vendor assets;
|
||||
review the new archive and license evidence before changing the manifest. The
|
||||
CLI prevents accidentally dropping either verified group or the Codicons component.
|
||||
CLI prevents accidentally dropping either verified group, the ten reviewed nested
|
||||
components, or vConsole's original license, supplemental MIT body and attribution.
|
||||
Component references require their runtime assets and every notice before writing.
|
||||
Source notices
|
||||
live in `refactor/baselines/site-vendor/`; generated delivery files live under
|
||||
@@ -52,6 +55,6 @@ members as Buffers. Compare `package/dist/codicon.ttf` directly with `fontPath`,
|
||||
and each non-null notice member with its frozen `source`. Do not pipe binary font
|
||||
output through PowerShell text redirection. No dependency installation is needed.
|
||||
|
||||
Follow-up: finish the broader bundled-component notice audit, then recover the
|
||||
Follow-up: finish Monaco's broader bundled-component notice audit, then recover the
|
||||
console.js build and resolve remaining fonts/media. Do not upgrade these assets
|
||||
without verifying globals, AMD/worker paths, CSS, consoleLog and user interaction.
|
||||
@@ -26,9 +26,165 @@
|
||||
"source": "refactor/baselines/site-vendor/vconsole-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/LICENSE",
|
||||
"sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/babel-runtime/LICENSE",
|
||||
"sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/core-js/LICENSE",
|
||||
"sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/copy-text-to-clipboard/LICENSE",
|
||||
"sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/mutation-observer/LICENSE",
|
||||
"sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/svelte/LICENSE",
|
||||
"sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/regenerator-runtime/LICENSE",
|
||||
"sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/style-loader/LICENSE",
|
||||
"sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/css-loader/LICENSE",
|
||||
"sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt",
|
||||
"target": "docs/licenses/vconsole/webpack/LICENSE",
|
||||
"sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE",
|
||||
"target": "docs/licenses/vconsole/MIT-LICENSE",
|
||||
"sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217"
|
||||
},
|
||||
{
|
||||
"source": "refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt",
|
||||
"target": "docs/licenses/vconsole/ATTRIBUTION.md",
|
||||
"sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3"
|
||||
}
|
||||
],
|
||||
"review": "The 3.15.0 upstream LICENSE declares MIT but omits the promised full license text. The copied file preserves this upstream evidence; completeness and bundled dependency notices remain under review. ArtPlayer applies a reproducible local lifecycle patch to log frame cancellation and delayed panel ownership; the upstream bundle is frozen in scripts/site-vendor/vconsole/upstream.js and generated by yarn build:vconsole. Public asset URL and UMD/CSS contracts are retained."
|
||||
"review": "The original 3.15.0 LICENSE is preserved unchanged; its missing MIT body is supplemented separately using the MIT text explicitly referenced by upstream. Exact reconstruction from the pinned source and lockfile establishes eight bundled package dependencies and webpack bootstrap; their complete notices and attribution are distributed below. ArtPlayer retains its reproducible lifecycle patch and the original script URL/UMD/CSS contracts.",
|
||||
"components": [
|
||||
{
|
||||
"name": "@babel/runtime",
|
||||
"version": "7.17.9",
|
||||
"tarball": "https://registry.npmjs.org/@babel/runtime/-/runtime-7.17.9.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/babel-runtime/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "core-js",
|
||||
"version": "3.21.1",
|
||||
"tarball": "https://registry.npmjs.org/core-js/-/core-js-3.21.1.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/core-js/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "copy-text-to-clipboard",
|
||||
"version": "3.0.1",
|
||||
"tarball": "https://registry.npmjs.org/copy-text-to-clipboard/-/copy-text-to-clipboard-3.0.1.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/copy-text-to-clipboard/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "mutation-observer",
|
||||
"version": "1.0.3",
|
||||
"tarball": "https://registry.npmjs.org/mutation-observer/-/mutation-observer-1.0.3.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/mutation-observer/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "svelte",
|
||||
"version": "3.47.0",
|
||||
"tarball": "https://registry.npmjs.org/svelte/-/svelte-3.47.0.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/svelte/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "regenerator-runtime",
|
||||
"version": "0.13.9",
|
||||
"tarball": "https://registry.npmjs.org/regenerator-runtime/-/regenerator-runtime-0.13.9.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/regenerator-runtime/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "style-loader",
|
||||
"version": "3.3.1",
|
||||
"tarball": "https://registry.npmjs.org/style-loader/-/style-loader-3.3.1.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/style-loader/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "css-loader",
|
||||
"version": "6.7.1",
|
||||
"tarball": "https://registry.npmjs.org/css-loader/-/css-loader-6.7.1.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/css-loader/LICENSE"
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "webpack",
|
||||
"version": "5.72.0",
|
||||
"tarball": "https://registry.npmjs.org/webpack/-/webpack-5.72.0.tgz",
|
||||
"assets": [
|
||||
"docs/assets/js/vconsole.min.js"
|
||||
],
|
||||
"notices": [
|
||||
"docs/licenses/vconsole/webpack/LICENSE"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"name": "monaco-editor",
|
||||
|
||||
@@ -50,8 +50,49 @@ test to reproduce failures; normal CI serves the candidate and expects no errors
|
||||
The scroller case holds zero-delay timers to force the late continuation while
|
||||
using native rendering, ResizeObserver and RAF; this is explicit fault injection.
|
||||
|
||||
This patch does not claim complete upstream lifecycle coverage, device coverage,
|
||||
or permission clearance. The upstream LICENSE is distributed verbatim, but its
|
||||
missing MIT body and bundled dependency notices remain open in VENDOR-07/SITE-07.
|
||||
Do not replace or upgrade the bundle to resolve these issues without separately
|
||||
checking entrypoints, logging, CSS and the full dependency notices.
|
||||
This patch does not claim complete upstream lifecycle or device coverage. The
|
||||
notice set now preserves the original LICENSE, supplies its missing MIT body in a
|
||||
separate file, and includes the complete licenses of the verified bundled runtime
|
||||
components. Do not upgrade the bundle without reviewing entrypoints, logging,
|
||||
CSS and the new dependency notices.
|
||||
|
||||
## Historical bundle reconstruction and notices
|
||||
|
||||
`refactor/baselines/vconsole-notices-provenance.json` pins 81 original source/config
|
||||
files from the commit above, the upstream lockfile, nine notice-bearing component
|
||||
archives and the observed runtime resource paths. The original npm bundle was
|
||||
reproduced byte for byte using Node 24.21.0 and the frozen upstream npm lockfile.
|
||||
No upstream install scripts ran. This is an isolated historical reconstruction;
|
||||
ArtPlayer remains on Yarn Classic with its root yarn.lock.
|
||||
|
||||
Prepare a checkout of the exact upstream commit inside `refactor/.cache/`, then
|
||||
run `npm ci --ignore-scripts --no-audit --no-fund` there. The 81 source/config files
|
||||
can also be fetched from fixed raw GitHub URLs using the recorded Git blob IDs
|
||||
and SHA-256 values when the source archive host is unavailable. Return to the
|
||||
ArtPlayer root and run:
|
||||
|
||||
```powershell
|
||||
yarn verify:vconsole-source refactor/.cache/<upstream-checkout>
|
||||
```
|
||||
|
||||
The helper checks every pinned input and dependency version before loading the
|
||||
upstream build configuration. It builds only in the ignored checkout, requires
|
||||
the exact npm bundle SHA-256, rejects hidden/truncated module statistics, and
|
||||
compares all dependency resources and webpack bootstrap modules to the reviewed
|
||||
notice set. It never copies the rebuilt bundle over ArtPlayer's patched asset.
|
||||
Upstream size warnings and its old Browserslist dataset remain visible; do not
|
||||
update the lockfile or dataset to silence them during historical reconstruction.
|
||||
|
||||
The eight runtime packages are @babel/runtime, copy-text-to-clipboard, core-js,
|
||||
css-loader, mutation-observer, regenerator-runtime, style-loader and svelte.
|
||||
Only actual resource paths count: less-loader's appearance in a loader chain does
|
||||
not make it a runtime dependency. Webpack's four generated bootstrap modules also
|
||||
have a license entry. Mutation-observer's two BSD notices are both retained.
|
||||
Other packages' MIT licenses retain their own copyright holders.
|
||||
|
||||
The published vConsole header explicitly links the MIT license. The upstream
|
||||
LICENSE omits its promised body, so ArtPlayer supplies `MIT-LICENSE` with that
|
||||
body and the original Tencent copyright, without pretending it came verbatim
|
||||
from the archive. `ATTRIBUTION.md` identifies this assembly, original sources and
|
||||
the local lifecycle modifications. These files and all dependency licenses are
|
||||
generated into `docs/licenses/vconsole/`; never edit the outputs by hand.
|
||||
@@ -0,0 +1,79 @@
|
||||
import assert from 'node:assert/strict'
|
||||
import { createHash } from 'node:crypto'
|
||||
import fs from 'node:fs'
|
||||
import { createRequire } from 'node:module'
|
||||
import path from 'node:path'
|
||||
import process from 'node:process'
|
||||
import { fileURLToPath } from 'node:url'
|
||||
|
||||
interface Module {
|
||||
name?: string
|
||||
nameForCondition?: string
|
||||
moduleType?: string
|
||||
filteredChildren?: number
|
||||
modules?: Module[]
|
||||
}
|
||||
interface Stats {
|
||||
hasErrors: () => boolean
|
||||
toJson: (options: Record<string, unknown>) => { modules: Module[], errors: unknown[], warnings: unknown[] }
|
||||
}
|
||||
interface Provenance {
|
||||
upstream: { bundleSha256: string }
|
||||
reconstruction: { sources: { path: string, sha256: string }[] }
|
||||
dependencies: { name: string, version: string, runtimeResources: string[] }[]
|
||||
}
|
||||
|
||||
const repository = fileURLToPath(new URL('../../../', import.meta.url))
|
||||
const cache = fs.realpathSync(path.join(repository, 'refactor/.cache'))
|
||||
assert.equal(process.argv.length, 3, 'Pass a prepared upstream checkout inside refactor/.cache')
|
||||
const checkout = fs.realpathSync(process.argv[2]!)
|
||||
assert(checkout.startsWith(`${cache}${path.sep}`), 'Reconstruction must stay inside the ignored cache')
|
||||
const provenance: Provenance = JSON.parse(fs.readFileSync(path.join(repository, 'refactor/baselines/vconsole-notices-provenance.json'), 'utf8'))
|
||||
const hash = (bytes: Uint8Array) => createHash('sha256').update(bytes).digest('hex')
|
||||
for (const source of provenance.reconstruction.sources) {
|
||||
const filename = fs.realpathSync(path.join(checkout, source.path))
|
||||
assert(filename.startsWith(`${checkout}${path.sep}`), 'Source must stay in the prepared checkout')
|
||||
assert.equal(hash(fs.readFileSync(filename)), source.sha256, `Frozen source changed: ${source.path}`)
|
||||
}
|
||||
for (const dependency of provenance.dependencies) {
|
||||
const manifest = JSON.parse(fs.readFileSync(path.join(checkout, 'node_modules', dependency.name, 'package.json'), 'utf8'))
|
||||
assert.equal(manifest.version, dependency.version, `Installed version changed: ${dependency.name}`)
|
||||
}
|
||||
|
||||
// The verified upstream config resolves aliases and compiler targets from cwd.
|
||||
process.chdir(checkout)
|
||||
const require = createRequire(path.join(checkout, 'package.json'))
|
||||
const config = require('./webpack.config.js')({ target: 'web' }, { mode: 'production' })
|
||||
|
||||
const stats = await new Promise<Stats>((resolve, reject) => {
|
||||
require('webpack')(config, (error: Error | null, result: Stats) => error ? reject(error) : resolve(result))
|
||||
})
|
||||
const report = stats.toJson({
|
||||
all: true,
|
||||
groupModulesByAttributes: false,
|
||||
groupModulesByType: false,
|
||||
groupModulesByPath: false,
|
||||
groupModulesByCacheStatus: false,
|
||||
groupModulesByExtension: false,
|
||||
groupModulesByLayer: false,
|
||||
modulesSpace: Infinity,
|
||||
nestedModulesSpace: Infinity,
|
||||
chunkModulesSpace: Infinity,
|
||||
})
|
||||
assert(!stats.hasErrors(), JSON.stringify(report.errors))
|
||||
assert.equal(hash(fs.readFileSync('dist/vconsole.min.js')), provenance.upstream.bundleSha256, 'Rebuilt bundle differs from the frozen npm bundle')
|
||||
const resources = new Set<string>()
|
||||
function visit(module: Module) {
|
||||
assert(!module.filteredChildren, 'Webpack hid modules; this is incomplete provenance')
|
||||
const resource = module.nameForCondition?.replaceAll('\\', '/')
|
||||
if (resource?.includes('/node_modules/'))
|
||||
resources.add(`node_modules/${resource.split('/node_modules/').pop()}`)
|
||||
if (module.moduleType === 'runtime') {
|
||||
assert(module.name)
|
||||
resources.add(module.name)
|
||||
}
|
||||
module.modules?.forEach(visit)
|
||||
}
|
||||
report.modules.forEach(visit)
|
||||
assert.deepEqual([...resources].sort(), [...new Set(provenance.dependencies.flatMap(dependency => dependency.runtimeResources))].sort(), 'Bundled component resources differ from the reviewed notice set')
|
||||
console.log(JSON.stringify({ exactBundle: true, sha256: provenance.upstream.bundleSha256, resources: resources.size, notices: provenance.dependencies.length, warnings: report.warnings }))
|
||||
Reference in new issue
Block a user