Files
odin/docs/research/speedometer-pack-decision.md
T

12 KiB
Raw Blame History

Speedometer 3.1 offline pack: packaging decision

Answer

Do not redistribute an unchanged Speedometer 3.1 pack from commit 1386415be8fef2f6b6bbdbe1828872471c5d802a yet. The pinned archive is a conservative, precisely inventoried source candidate, but its full redistribution rights are not established. The companion per-file source inventory contains all 1,118 archive files, each with byte count and SHA-256 (61,022,359 bytes total; inventory SHA-256 78edcd45649128fbd4c8659c1d054a2b9bb76a184b58ce59b37895c19f2bdfb6). It identifies review groups, not individual license clearance or a minimal runtime set. The prior license audit documents the evidence and gaps. Source: pinned WebKit/Speedometer tree.

The acquisition decision is concrete: obtain a verifiable grant and required notices for every unresolved work in the selected pack, or replace those works and rebuild/validate the affected assets. If either route cannot clear every default suite, do not call a reduced suite set the unchanged official Speedometer 3.1 workload. Select a different browser workload or explicitly specify a derivative suite and scoring identity. The pinned suite list enables NewsSite Next/Nuxt, both Charts suites, both Editor suites, and complex TodoMVC variants by default, so simply deleting those assets changes the measured workload. No permission or replacement is established by this report.

Asset and notice boundary

The runner loads resources/${suite.url}; the suite list declares 32 suite entries, 20 enabled by default. All declared entry files exist in the pinned archive. Previous static inspection found 194 landing-page and default-entry HTML asset references, all local and present, but did not resolve dynamic imports, CSS URLs, route requests, or interactions. Source: prior offline-pack research, pinned archive. No exact smaller runtime file set has therefore been proved. Use the full archive as the conservative candidate until a dependency trace and offline gate justify exclusions.

Asset group in candidate archive Evidence and obligation or gap
Speedometer-authored files Root BSD-style license: retain its copyright, conditions, and disclaimer in source copies; reproduce them in documentation or other binary-distribution materials. Its terms do not establish rights to embedded third-party works.
TodoMVC implementations and generated framework bundles TodoMVC license says MIT unless otherwise specified. Keep that text, matching generated-bundle notices, and inline notices; match bundled component versions to source/lockfiles. Angular notice includes MIT, Apache-2.0, and CC-BY-4.0 entries.
NewsSite Next/Nuxt, template, CSS, imagery Both Next and Nuxt credit the source template, whose repository exposes no license file or package license. No grant for adapted template content is established. Pinned CSS package metadata says ISC, but the matching license text and rights for bundled images still need confirmation.
Charts code and data Dataset README identifies copied CSVs without source rights. The archive also contains generated chart bundles, including data embedded in resources/charts/dist/assets/flights-airports-9a9e6422.js; the manifest records their hashes. Trace dataset grants or replace with cleared equivalent data, rebuild, then recheck the result.
Complex TodoMVC Adobe shell Big DOM README names Adobe @spectrum-css; the archive has Smock_*.svg icons. Exact package versions, rights, and built-copy notices remain unresolved.
Editor fixtures and bundles longtext.html identifies Project Gutenberg eBook 2650 and contains its license. Project Gutenberg's terms attach redistribution and trademark conditions while its marks remain; geographic rights need checking. Replace with independently cleared text of comparable workload shape if those conditions are unsuitable. Editor bundles also need component/notice mapping.
React Stockcharts and Perf Dashboard Stockcharts README cites MIT; generated bundle notice lists components. Keep notices and verify component versions. Audit generated dashboard JavaScript and imagery against their source rights.

The candidate archive has nine separate notice files: root LICENSE; resources/todomvc/license.md; one React Stockcharts *.LICENSE.txt; two Angular 3rdpartylicenses.txt; and four React-family app.bundle.js.LICENSE.txt. Their exact paths and hashes are in the source inventory. Preserve applicable files and inline headers. A top-level notice index must map each shipped component or asset to origin, copyright holder, license/permission evidence, required notice, and fulfillment location. A notice file alone does not cure an absent grant. Source: pinned tree, license audit.

Offline fetch boundary

The built pack can be served over loopback HTTP without installing its development dependencies; the about page says suites are static applications without server infrastructure. The main page loads local runner assets. The Perf Dashboard static page overrides RemoteAPI.sendHttpRequest, prefetches 13 local JSON fixtures, and reports unexpected paths. Those 13 paths exist in the archive; an unmocked remote API implementation also exists, so packaging must retain the override and verify it executes. Static source inspection has not established closure for all dynamic requests, imports, CSS fonts/images, redirects, workers, or navigation. Source: prior offline-pack research.

Prepared native automation is outside the asset pack. The pinned Selenium harness starts a server and connects to an installed browser/driver; Testing.md states those installation requirements for upstream tests. Odin's browser binary, driver, profile, window state, headed/headless mode, and automation adapter belong to the run environment record, not the frozen workload pack. Upstream instructions require a focused browser page. The parameters default the suite iframe to 800 × 600; the landing page warns below an 850 × 650 visible viewport. Record both sizes; keep headed and headless measurements separate unless equivalence is demonstrated.

Final manifest and acceptance gate

After rights are cleared and the exact shipped file set is selected, create a canonical, content-addressed manifest for that set. Include schema version; upstream URL/full commit; Speedometer display version; immutable suite names, entry URLs, enabled state, and runner parameters; every normalized relative path with byte length and SHA-256; provenance and license evidence identifiers; notice paths and fulfillment mapping; and all replacements/build inputs. Sort paths by UTF-8 bytes, use one specified JSON serialization, exclude the manifest's own digest from hashed content, and publish the SHA-256 of those bytes as pack identity. Reject duplicate or traversal paths, symlinks, missing/extra files, and hash mismatches before serving. Any altered asset, suite list, or notice changes pack identity. This is an Odin packaging proposal; upstream provides no such manifest. Source for source identity and suite paths: pinned tree, suite list.

Run a separate non-benchmark acceptance gate before any scored use: verify the manifest; serve read-only files on loopback; start a disposable browser profile with outbound network blocked; open the landing page and each enabled suite entry without starting Start Test; capture all page/frame/worker requests and response status, redirects, console errors, and service-worker activity; inspect dynamic imports, CSS images/fonts, and the Perf Dashboard fixture requests. If a suite needs interaction to reveal a resource, use an unscored smoke action outside the runner and record it. Fail on any outside request, missing local resource, unexpected remote API path, or console error that affects loading. This tests reachability and fetch closure, not benchmark behavior or timing. A full workload execution later remains a separate validation before results are trusted. Source for runner behavior: runner, dashboard mock.

State of evidence

No browser was installed, no benchmark was run, and no host setting was changed for this research. No pack has passed the legal or offline gate. The exact runtime subset, component-to-file rights matrix, successful fetch closure, and permission or replacement choices remain to be established before redistribution.