Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
26dbe21c37 | ||
|
|
151505b4f7 |
@@ -0,0 +1,38 @@
|
||||
# Speedometer 3.1 pinned pack: redistribution audit
|
||||
|
||||
## Decision
|
||||
|
||||
**Do not redistribute the complete pinned archive yet.** The top-level BSD-style license permits redistribution of Speedometer's own work when its notice, conditions, and disclaimer travel with it. It does not establish rights for every embedded work. The pinned archive contains identifiable third-party material whose grant or compliance path is not yet established. This is a source audit, not a legal opinion or a benchmark run.
|
||||
|
||||
Source: [WebKit/Speedometer commit `1386415be8fef2f6b6bbdbe1828872471c5d802a`](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a), [root license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/LICENSE).
|
||||
|
||||
## Exact inventory
|
||||
|
||||
The companion [per-file manifest](speedometer-license-manifest.tsv) records every relative path, byte count, SHA-256, and **review group** in the full GitHub commit archive: **1,118 files; 61,022,359 uncompressed bytes**. Its SHA-256 is `78edcd45649128fbd4c8659c1d054a2b9bb76a184b58ce59b37895c19f2bdfb6`. The archive download SHA-256 was `cfefa818d7789ed2f2b9f3f1bf608cc35e4e8241489eef47049296ce92791313`. Review groups flag provenance work; they are **not license determinations**. The complete source archive is a conservative candidate pack, not a selected minimum runtime file set.
|
||||
|
||||
Reproduce the manifest from that commit's GitHub `.tar.gz`: strip its single leading directory; sort regular-file paths by UTF-8 path; for each file write `path`, decimal byte count, lowercase SHA-256, and review group as tab-separated fields. Group rules: exact notice names and `*.LICENSE.txt`/`3rdpartylicenses.txt` first; then Gutenberg HTML, chart datasets, all news-site files, Adobe icon SVGs, then TodoMVC, React Stockcharts, charts, editors, and remainder in that order. The manifest itself is not an upstream artifact.
|
||||
|
||||
Nine separate notice files appear in the archive: `LICENSE`; `resources/todomvc/license.md`; `resources/react-stockcharts/build/static/js/2.8e539c84.chunk.js.LICENSE.txt`; Angular and Angular Complex `dist/3rdpartylicenses.txt`; and React, React Complex, React Redux, React Redux Complex `dist/app.bundle.js.LICENSE.txt`. Exact paths and hashes are in the manifest. Inline notices in JavaScript, CSS, HTML, SVG, and source maps also need preservation. A filename scan cannot prove all component notices were extracted.
|
||||
|
||||
## Established obligations and specific gaps
|
||||
|
||||
| Material | Evidence and current finding | Required action before shipping |
|
||||
| --- | --- | --- |
|
||||
| Speedometer-owned source | [Root license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/LICENSE) requires retention of copyright, conditions, and disclaimer for source; reproduction in documentation or other materials for binary form. | Include root `LICENSE` in pack and distribution materials; keep original headers. |
|
||||
| TodoMVC implementations | [TodoMVC subtree license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/license.md) says MIT **unless otherwise specified**. Generated React and Angular notices identify further components. | Carry subtree license and all bundled notices. Audit each runtime bundle against its dependency versions; fill missing texts/attributions. |
|
||||
| Angular bundles | Both [`3rdpartylicenses.txt` files](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/architecture-examples/angular/dist/3rdpartylicenses.txt) include MIT, Apache-2.0, and CC-BY-4.0 material. | Keep both files with their matching bundles; map each named component to bundle; satisfy Apache notice/change rules and CC attribution requirements as applicable. |
|
||||
| React Stockcharts | Its [README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/README.md) claims MIT and points to upstream; [bundle notice](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/build/static/js/2.8e539c84.chunk.js.LICENSE.txt) lists dependencies. | Include upstream MIT text plus bundled notice; verify the actual bundled versions. |
|
||||
| News-site template and CSS | Both [Next README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-next/README.md) and [Nuxt README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-nuxt/README.md) credit [`flashdesignory/news-site-template`](https://github.com/flashdesignory/news-site-template). Its repository has no visible license file, and [its package metadata](https://github.com/flashdesignory/news-site-template/blob/main/package.json) declares none. Pinned [news-site-css metadata](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-site-css/package.json) says ISC but does not provide that license text. The source and exported `dist` include adapted template material. **No redistribution grant established for the template.** | Get written permission or a verifiable applicable license from its rights holder, or remove/replace the NewsSite suites and all dependent files. Obtain and carry correct ISC text/notice for news-site-css. Reassess suite set and scoring if suites removed. |
|
||||
| Chart datasets | [Dataset README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/charts/datasets/README) identifies two CSVs copied from an older D3 path. It does not state their data source or rights. `airports.csv`, `flights-airports.csv`, and the README are the three manifest paths. Generated `resources/charts/dist/assets/flights-airports-9a9e6422.js` embeds data. | Trace dataset origin and grant, then include required attribution. Otherwise replace with licensed/synthetic data and rebuild the affected chart assets, or omit that workload. |
|
||||
| Adobe Spectrum icons and CSS | [Big DOM README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/big-dom-generator/README.md) says static shell uses Adobe `@spectrum-css`. Its source contains 22 `Smock_*.svg` icons plus three other SVGs, with no per-file notice. Generated `dist` and complex TodoMVC pages may embed this material. TodoMVC's MIT default alone cannot establish rights over Adobe assets. | Identify exact Adobe package/source and applicable icon/CSS license, preserve its notice, and verify built copies. If unavailable, replace assets and rebuild/verify affected pages. |
|
||||
| Editor text | [`longtext.html`](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/editors/assets/longtext.html) is Project Gutenberg eBook 2650 per [asset README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/editors/assets/README.md). It includes Gutenberg branding and full license. [Gutenberg terms](https://www.gutenberg.org/policy/license) impose access, notice, format, fee, and territorial conditions while branding remains. | Preserve full embedded license and prominent notice; assess distribution geography and price. Simpler path: replace with separately cleared text of equivalent workload shape. |
|
||||
| Other generated bundles and imagery | Charts, Editors, NewsSite, TodoMVC, React Stockcharts, images, maps, and CSS are generated or embedded works. Package lock entries identify dependencies but do not themselves provide all license texts; absence of a notice file is not proof of permission. | Build a component-to-file bill of materials from pinned locks/source maps and licenses. Review all shipped binaries/images individually; acquire missing grants or exclude/rebuild. |
|
||||
|
||||
## Pack gate
|
||||
|
||||
1. Define exact runtime file set; leave development files out only after proving every enabled suite resolves locally. Record each shipped file in a final manifest, with source commit and byte hash. The full-archive manifest here remains comparison baseline.
|
||||
2. Map every final file to originating project or generated bundle components. Record SPDX identifier, copyright holder, evidence URL, required notice text, and fulfillment location. Mark unknown explicitly; no implicit root-license inheritance for third-party work.
|
||||
3. Resolve the specific gaps above. Carry all nine existing notice files when their associated files ship; carry missing upstream notices and keep inline notices. Build a top-level `THIRD_PARTY_NOTICES` index with bundled texts or direct accompanying files.
|
||||
4. Recheck after any exclusion, replacement, or rebuild. Any changed byte needs a new manifest digest and runtime validation. License clearance and offline functional validation are separate gates.
|
||||
|
||||
The earlier [offline pack research](speedometer-offline-pack.md) established static-path plausibility and proposed blocked-network validation; it did not clear redistribution rights. No benchmark, browser installation, or host change was made here.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,39 @@
|
||||
# Speedometer 3.1 offline pack: packaging decision
|
||||
|
||||
## Answer
|
||||
|
||||
**Do not redistribute an unchanged Speedometer 3.1 pack from commit `1386415be8fef2f6b6bbdbe1828872471c5d802a` yet.** The pinned archive is a conservative, precisely inventoried source candidate, but its full redistribution rights are not established. The companion [per-file source inventory](speedometer-license-manifest.tsv) contains all 1,118 archive files, each with byte count and SHA-256 (61,022,359 bytes total; inventory SHA-256 `78edcd45649128fbd4c8659c1d054a2b9bb76a184b58ce59b37895c19f2bdfb6`). It identifies review groups, **not** individual license clearance or a minimal runtime set. The [prior license audit](speedometer-license-audit.md) documents the evidence and gaps. Source: [pinned WebKit/Speedometer tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a).
|
||||
|
||||
The acquisition decision is concrete: obtain a verifiable grant and required notices for every unresolved work in the selected pack, or replace those works and rebuild/validate the affected assets. If either route cannot clear every **default** suite, do not call a reduced suite set the unchanged official Speedometer 3.1 workload. Select a different browser workload or explicitly specify a derivative suite and scoring identity. The [pinned suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs) enables NewsSite Next/Nuxt, both Charts suites, both Editor suites, and complex TodoMVC variants by default, so simply deleting those assets changes the measured workload. No permission or replacement is established by this report.
|
||||
|
||||
## Asset and notice boundary
|
||||
|
||||
The [runner](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/benchmark-runner.mjs) loads `resources/${suite.url}`; the [suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs) declares 32 suite entries, 20 enabled by default. All declared entry files exist in the pinned archive. Previous static inspection found 194 landing-page and default-entry HTML asset references, all local and present, but did not resolve dynamic imports, CSS URLs, route requests, or interactions. Source: [prior offline-pack research](speedometer-offline-pack.md), [pinned archive](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a). No exact smaller **runtime** file set has therefore been proved. Use the full archive as the conservative candidate until a dependency trace and offline gate justify exclusions.
|
||||
|
||||
| Asset group in candidate archive | Evidence and obligation or gap |
|
||||
| --- | --- |
|
||||
| Speedometer-authored files | [Root BSD-style license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/LICENSE): retain its copyright, conditions, and disclaimer in source copies; reproduce them in documentation or other binary-distribution materials. Its terms do not establish rights to embedded third-party works. |
|
||||
| TodoMVC implementations and generated framework bundles | [TodoMVC license](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/license.md) says MIT unless otherwise specified. Keep that text, matching generated-bundle notices, and inline notices; match bundled component versions to source/lockfiles. [Angular notice](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/architecture-examples/angular/dist/3rdpartylicenses.txt) includes MIT, Apache-2.0, and CC-BY-4.0 entries. |
|
||||
| NewsSite Next/Nuxt, template, CSS, imagery | Both [Next](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-next/README.md) and [Nuxt](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-nuxt/README.md) credit the [source template](https://github.com/flashdesignory/news-site-template), whose repository exposes no license file or package license. No grant for adapted template content is established. [Pinned CSS package metadata](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/newssite/news-site-css/package.json) says ISC, but the matching license text and rights for bundled images still need confirmation. |
|
||||
| Charts code and data | [Dataset README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/charts/datasets/README) identifies copied CSVs without source rights. The archive also contains generated chart bundles, including data embedded in `resources/charts/dist/assets/flights-airports-9a9e6422.js`; the [manifest](speedometer-license-manifest.tsv) records their hashes. Trace dataset grants or replace with cleared equivalent data, rebuild, then recheck the result. |
|
||||
| Complex TodoMVC Adobe shell | [Big DOM README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/todomvc/big-dom-generator/README.md) names Adobe `@spectrum-css`; the archive has `Smock_*.svg` icons. Exact package versions, rights, and built-copy notices remain unresolved. |
|
||||
| Editor fixtures and bundles | [`longtext.html`](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/editors/assets/longtext.html) identifies Project Gutenberg eBook 2650 and contains its license. [Project Gutenberg's terms](https://www.gutenberg.org/policy/license) attach redistribution and trademark conditions while its marks remain; geographic rights need checking. Replace with independently cleared text of comparable workload shape if those conditions are unsuitable. Editor bundles also need component/notice mapping. |
|
||||
| React Stockcharts and Perf Dashboard | [Stockcharts README](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/README.md) cites MIT; [generated bundle notice](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/react-stockcharts/build/static/js/2.8e539c84.chunk.js.LICENSE.txt) lists components. Keep notices and verify component versions. Audit generated dashboard JavaScript and imagery against their source rights. |
|
||||
|
||||
The candidate archive has nine separate notice files: root `LICENSE`; `resources/todomvc/license.md`; one React Stockcharts `*.LICENSE.txt`; two Angular `3rdpartylicenses.txt`; and four React-family `app.bundle.js.LICENSE.txt`. Their exact paths and hashes are in the [source inventory](speedometer-license-manifest.tsv). Preserve applicable files and inline headers. A top-level notice index must map each shipped component or asset to origin, copyright holder, license/permission evidence, required notice, and fulfillment location. A notice file alone does not cure an absent grant. Source: [pinned tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a), [license audit](speedometer-license-audit.md).
|
||||
|
||||
## Offline fetch boundary
|
||||
|
||||
The built pack can be served over loopback HTTP without installing its development dependencies; the [about page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/about.html) says suites are static applications without server infrastructure. The [main page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/index.html) loads local runner assets. The Perf Dashboard [static page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/index.html) overrides `RemoteAPI.sendHttpRequest`, prefetches 13 local JSON fixtures, and reports unexpected paths. Those 13 paths exist in the archive; an unmocked [remote API implementation](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/remote.js) also exists, so packaging must retain the override and verify it executes. Static source inspection has **not** established closure for all dynamic requests, imports, CSS fonts/images, redirects, workers, or navigation. Source: [prior offline-pack research](speedometer-offline-pack.md).
|
||||
|
||||
Prepared native automation is outside the asset pack. The pinned [Selenium harness](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/tests/run.mjs) starts a server and connects to an installed browser/driver; [Testing.md](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/Testing.md) states those installation requirements for upstream tests. Odin's browser binary, driver, profile, window state, headed/headless mode, and automation adapter belong to the **run environment record**, not the frozen workload pack. Upstream [instructions](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/instructions.html) require a focused browser page. The [parameters](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/params.mjs) default the suite iframe to 800 × 600; the [landing page](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/index.html) warns below an 850 × 650 visible viewport. Record both sizes; keep headed and headless measurements separate unless equivalence is demonstrated.
|
||||
|
||||
## Final manifest and acceptance gate
|
||||
|
||||
After rights are cleared and the exact shipped file set is selected, create a canonical, content-addressed manifest **for that set**. Include schema version; upstream URL/full commit; Speedometer display version; immutable suite names, entry URLs, enabled state, and runner parameters; every normalized relative path with byte length and SHA-256; provenance and license evidence identifiers; notice paths and fulfillment mapping; and all replacements/build inputs. Sort paths by UTF-8 bytes, use one specified JSON serialization, exclude the manifest's own digest from hashed content, and publish the SHA-256 of those bytes as pack identity. Reject duplicate or traversal paths, symlinks, missing/extra files, and hash mismatches before serving. Any altered asset, suite list, or notice changes pack identity. This is an Odin packaging proposal; upstream provides no such manifest. Source for source identity and suite paths: [pinned tree](https://github.com/WebKit/Speedometer/tree/1386415be8fef2f6b6bbdbe1828872471c5d802a), [suite list](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/tests.mjs).
|
||||
|
||||
Run a separate **non-benchmark** acceptance gate before any scored use: verify the manifest; serve read-only files on loopback; start a disposable browser profile with outbound network blocked; open the landing page and each enabled suite entry without starting `Start Test`; capture all page/frame/worker requests and response status, redirects, console errors, and service-worker activity; inspect dynamic imports, CSS images/fonts, and the Perf Dashboard fixture requests. If a suite needs interaction to reveal a resource, use an unscored smoke action outside the runner and record it. Fail on any outside request, missing local resource, unexpected remote API path, or console error that affects loading. This tests reachability and fetch closure, **not** benchmark behavior or timing. A full workload execution later remains a separate validation before results are trusted. Source for runner behavior: [runner](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/benchmark-runner.mjs), [dashboard mock](https://github.com/WebKit/Speedometer/blob/1386415be8fef2f6b6bbdbe1828872471c5d802a/resources/perf.webkit.org/public/v3/index.html).
|
||||
|
||||
## State of evidence
|
||||
|
||||
No browser was installed, no benchmark was run, and no host setting was changed for this research. No pack has passed the legal or offline gate. The exact runtime subset, component-to-file rights matrix, successful fetch closure, and permission or replacement choices remain to be established before redistribution.
|
||||
Reference in New Issue
Block a user