# 固定版ソースアーカイブの取得・照合 Qt 6.11.2とtoml++ 3.4.0の公開ソースを取得し、固定した公開hashと照合する。ダウンロードしたビルドスクリプトは実行しない。Qtでは通常ファイルを専用の新規treeへ保存し、path、件数、単体・総容量に上限を設ける。リンクを辿らず、元アーカイブのpath・mode・全通常ファイルのSHA-256をJSONLへ記録する。ファイルの実行属性は設定しないため、抽出treeをそのままビルド可能なcheckoutとは呼ばない。 ```sh python3 tests/source_archives/fetch.py \ --output tests/results/source-archives/new-download \ --cache .deps/new-source-archives python3 tests/source_archives/inspect_qt.py \ --archive .deps/new-source-archives/qt-everywhere-src-6.11.2.tar.xz \ --tree .deps/new-qt-regular-files \ --output tests/results/source-archives/new-qt-inspection python3 tests/source_archives/verify_toml.py \ --output tests/results/source-archives/new-toml-check python3 tests/source_archives/check_arch_patches.py \ --output tests/results/source-archives/new-patch-check ``` 各出力先は新規にする。`verify_toml.py`は既定の`.deps/source-archives`を、patch確認は保存済み`qt-inspection/report.json`のtreeを読む。既存の資料を更新する場合は、対応するpinと参照箇所を明示的に変更する。 Qtのpinは[公式mirror metadata](https://download.qt.io/archive/qt/6.11/6.11.2/single/qt-everywhere-src-6.11.2.tar.xz.mirrorlist)、toml++は保存済みの使用版Arch recipeによる。Qtのmirrorページには要求元IPが含まれることがあるため、全文は保存せず、応答hashと一致した公開checksumを記録する。 [今回の実行結果](../results/source-archives/README.md)。ソース取得、使用版との部分的な照合、実ビルド構成に対する告知の完全性、具体的配布条件の判定は区別する。 ## PDFiumの固定Gitソース 保存済みDEPSの固定値からLinux / Windows x64 minimalのGit取得対象を選び、PDFium本体と27依存を取得する。3並列、fetch上限900秒、Git hookとcredential helper無効で、DEPSや取得ソースのコードは実行しない。Git objectを検査してから通常ファイル・リンクの全blobをアーカイブ化し、読み戻して照合する。アーカイブに保存したリンクはファイルシステムへ展開しない。 ```sh python3 tests/source_archives/collect_pdfium.py \ --output tests/results/source-archives/new-pdfium-git \ --cache .deps/new-pdfium-git python3 tests/source_archives/check_pdfium.py \ --collection tests/results/source-archives/new-pdfium-git \ --output tests/results/source-archives/new-pdfium-check python3 tests/source_archives/collect_pdfium_gitlink.py \ --output tests/results/source-archives/new-pdfium-gitlink \ --cache .deps/new-pdfium-gitlink ``` 出力先とアーカイブのcacheは新規にする。rootのbare repositoryのみ、存在すれば最初の取得確認用cacheを再利用して固定commit・treeを再検査する。gitlink補足スクリプトは今回の既定`pdfium-git/report.json`と固定したFreeType参照を読み、未確認の追加参照があれば停止する。 checkスクリプトはproviderのパッチを出力先内の専用コピーへ適用する。Linux3件とWindows4件の差分、既存Linux配布物の全24公開ヘッダー・15告知を比較し、本体・ワーカーを変更しない。[PDFiumの実行結果と範囲](../results/source-archives/PDFIUM.md) ## Ubuntu用Qt SDKの告知 `collect_qt_sdk_notices.py --output <新規directory>`は、保存済みの公式Qt SDK archive、Ubuntu実行時台帳とSDK SBOM、検証済みQt sourceからChromiumの告知本文を抽出する。全archiveをストリームで検査し、SBOMの67ファイル・既存実行時台帳の83ファイル・告知129entryを照合する。元SBOMの参照ID不整合や本文のない項目、生成器のskipを保持し、網羅性の判定とは分ける。[実行結果](../results/source-archives/QT-SDK-NOTICES.md)