Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
26dbe21c37 |
@@ -0,0 +1,39 @@
|
||||
# Speedometer 3.1 offline pack: packaging decision
|
||||
|
||||
## Answer
|
||||
|
||||
**Do not redistribute an unchanged Speedometer 3.1 pack from commit `1386415be8fef2f6b6bbdbe1828872471c5d802a` yet.** The pinned archive is a conservative, precisely inventoried source candidate, but its full redistribution rights are not established. The companion [per-file source inventory](speedometer-license-manifest.tsv) contains all 1,118 archive files, each with byte count and SHA-256 (61,022,359 bytes total; inventory SHA-256 `78edcd45649128fbd4c8659c1d054a2b9bb76a184b58ce59b37895c19f2bdfb6`). It identifies review groups, **not** individual license clearance or a minimal runtime set. The [prior license audit](speedometer-license-audit.md) documents the evidence and gaps. Source: [pinned WebKit/Speedometer tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a).
|
||||
|
||||
The acquisition decision is concrete: obtain a verifiable grant and required notices for every unresolved work in the selected pack, or replace those works and rebuild/validate the affected assets. If either route cannot clear every **default** suite, do not call a reduced suite set the unchanged official Speedometer 3.1 workload. Select a different browser workload or explicitly specify a derivative suite and scoring identity. The [pinned suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs) enables NewsSite Next/Nuxt, both Charts suites, both Editor suites, and complex TodoMVC variants by default, so simply deleting those assets changes the measured workload. No permission or replacement is established by this report.
|
||||
|
||||
## Asset and notice boundary
|
||||
|
||||
The [runner](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/benchmark-runner.mjs) loads `resources/${suite.url}`; the [suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs) declares 32 suite entries, 20 enabled by default. All declared entry files exist in the pinned archive. Previous static inspection found 194 landing-page and default-entry HTML asset references, all local and present, but did not resolve dynamic imports, CSS URLs, route requests, or interactions. Source: [prior offline-pack research](speedometer-offline-pack.md), [pinned archive](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a). No exact smaller **runtime** file set has therefore been proved. Use the full archive as the conservative candidate until a dependency trace and offline gate justify exclusions.
|
||||
|
||||
| Asset group in candidate archive | Evidence and obligation or gap |
|
||||
| --- | --- |
|
||||
| Speedometer-authored files | [Root BSD-style license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/LICENSE): retain its copyright, conditions, and disclaimer in source copies; reproduce them in documentation or other binary-distribution materials. Its terms do not establish rights to embedded third-party works. |
|
||||
| TodoMVC implementations and generated framework bundles | [TodoMVC license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/license.md) says MIT unless otherwise specified. Keep that text, matching generated-bundle notices, and inline notices; match bundled component versions to source/lockfiles. [Angular notice](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/architecture-examples/angular/dist/3rdpartylicenses.txt) includes MIT, Apache-2.0, and CC-BY-4.0 entries. |
|
||||
| NewsSite Next/Nuxt, template, CSS, imagery | Both [Next](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-next/README.md) and [Nuxt](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-nuxt/README.md) credit the [source template](https://github.com/flashdesignory/news-site-template), whose repository exposes no license file or package license. No grant for adapted template content is established. [Pinned CSS package metadata](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-site-css/package.json) says ISC, but the matching license text and rights for bundled images still need confirmation. |
|
||||
| Charts code and data | [Dataset README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/charts/datasets/README) identifies copied CSVs without source rights. The archive also contains generated chart bundles, including data embedded in `resources/charts/dist/assets/flights-airports-9a9e6422.js`; the [manifest](speedometer-license-manifest.tsv) records their hashes. Trace dataset grants or replace with cleared equivalent data, rebuild, then recheck the result. |
|
||||
| Complex TodoMVC Adobe shell | [Big DOM README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/big-dom-generator/README.md) names Adobe `@spectrum-css`; the archive has `Smock_*.svg` icons. Exact package versions, rights, and built-copy notices remain unresolved. |
|
||||
| Editor fixtures and bundles | [`longtext.html`](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/editors/assets/longtext.html) identifies Project Gutenberg eBook 2650 and contains its license. [Project Gutenberg's terms](https://www.gutenberg.org/policy/license) attach redistribution and trademark conditions while its marks remain; geographic rights need checking. Replace with independently cleared text of comparable workload shape if those conditions are unsuitable. Editor bundles also need component/notice mapping. |
|
||||
| React Stockcharts and Perf Dashboard | [Stockcharts README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/README.md) cites MIT; [generated bundle notice](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/build/static/js/2.8e539c84.chunk.js.LICENSE.txt) lists components. Keep notices and verify component versions. Audit generated dashboard JavaScript and imagery against their source rights. |
|
||||
|
||||
The candidate archive has nine separate notice files: root `LICENSE`; `resources/todomvc/license.md`; one React Stockcharts `*.LICENSE.txt`; two Angular `3rdpartylicenses.txt`; and four React-family `app.bundle.js.LICENSE.txt`. Their exact paths and hashes are in the [source inventory](speedometer-license-manifest.tsv). Preserve applicable files and inline headers. A top-level notice index must map each shipped component or asset to origin, copyright holder, license/permission evidence, required notice, and fulfillment location. A notice file alone does not cure an absent grant. Source: [pinned tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a), [license audit](speedometer-license-audit.md).
|
||||
|
||||
## Offline fetch boundary
|
||||
|
||||
The built pack can be served over loopback HTTP without installing its development dependencies; the [about page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/about.html) says suites are static applications without server infrastructure. The [main page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/index.html) loads local runner assets. The Perf Dashboard [static page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/index.html) overrides `RemoteAPI.sendHttpRequest`, prefetches 13 local JSON fixtures, and reports unexpected paths. Those 13 paths exist in the archive; an unmocked [remote API implementation](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/remote.js) also exists, so packaging must retain the override and verify it executes. Static source inspection has **not** established closure for all dynamic requests, imports, CSS fonts/images, redirects, workers, or navigation. Source: [prior offline-pack research](speedometer-offline-pack.md).
|
||||
|
||||
Prepared native automation is outside the asset pack. The pinned [Selenium harness](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/tests/run.mjs) starts a server and connects to an installed browser/driver; [Testing.md](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/Testing.md) states those installation requirements for upstream tests. Odin's browser binary, driver, profile, window state, headed/headless mode, and automation adapter belong to the **run environment record**, not the frozen workload pack. Upstream [instructions](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/instructions.html) require a focused browser page. The [parameters](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/params.mjs) default the suite iframe to 800 × 600; the [landing page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/index.html) warns below an 850 × 650 visible viewport. Record both sizes; keep headed and headless measurements separate unless equivalence is demonstrated.
|
||||
|
||||
## Final manifest and acceptance gate
|
||||
|
||||
After rights are cleared and the exact shipped file set is selected, create a canonical, content-addressed manifest **for that set**. Include schema version; upstream URL/full commit; Speedometer display version; immutable suite names, entry URLs, enabled state, and runner parameters; every normalized relative path with byte length and SHA-256; provenance and license evidence identifiers; notice paths and fulfillment mapping; and all replacements/build inputs. Sort paths by UTF-8 bytes, use one specified JSON serialization, exclude the manifest's own digest from hashed content, and publish the SHA-256 of those bytes as pack identity. Reject duplicate or traversal paths, symlinks, missing/extra files, and hash mismatches before serving. Any altered asset, suite list, or notice changes pack identity. This is an Odin packaging proposal; upstream provides no such manifest. Source for source identity and suite paths: [pinned tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a), [suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs).
|
||||
|
||||
Run a separate **non-benchmark** acceptance gate before any scored use: verify the manifest; serve read-only files on loopback; start a disposable browser profile with outbound network blocked; open the landing page and each enabled suite entry without starting `Start Test`; capture all page/frame/worker requests and response status, redirects, console errors, and service-worker activity; inspect dynamic imports, CSS images/fonts, and the Perf Dashboard fixture requests. If a suite needs interaction to reveal a resource, use an unscored smoke action outside the runner and record it. Fail on any outside request, missing local resource, unexpected remote API path, or console error that affects loading. This tests reachability and fetch closure, **not** benchmark behavior or timing. A full workload execution later remains a separate validation before results are trusted. Source for runner behavior: [runner](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/benchmark-runner.mjs), [dashboard mock](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/index.html).
|
||||
|
||||
## State of evidence
|
||||
|
||||
No browser was installed, no benchmark was run, and no host setting was changed for this research. No pack has passed the legal or offline gate. The exact runtime subset, component-to-file rights matrix, successful fetch closure, and permission or replacement choices remain to be established before redistribution.
|
||||
Reference in New Issue
Block a user