Files
2026-09-21 13:41:40 +09:00

48 lines
4.1 KiB
Markdown

# 固定版ソースアーカイブの取得・照合
Qt 6.11.2とtoml++ 3.4.0の公開ソースを取得し、固定した公開hashと照合する。ダウンロードしたビルドスクリプトは実行しない。Qtでは通常ファイルを専用の新規treeへ保存し、path、件数、単体・総容量に上限を設ける。リンクを辿らず、元アーカイブのpath・mode・全通常ファイルのSHA-256をJSONLへ記録する。ファイルの実行属性は設定しないため、抽出treeをそのままビルド可能なcheckoutとは呼ばない。
```sh
python3 tests/source_archives/fetch.py \
--output tests/results/source-archives/new-download \
--cache .deps/new-source-archives
python3 tests/source_archives/inspect_qt.py \
--archive .deps/new-source-archives/qt-everywhere-src-6.11.2.tar.xz \
--tree .deps/new-qt-regular-files \
--output tests/results/source-archives/new-qt-inspection
python3 tests/source_archives/verify_toml.py \
--output tests/results/source-archives/new-toml-check
python3 tests/source_archives/check_arch_patches.py \
--output tests/results/source-archives/new-patch-check
```
各出力先は新規にする。`verify_toml.py`は既定の`.deps/source-archives`を、patch確認は保存済み`qt-inspection/report.json`のtreeを読む。既存の資料を更新する場合は、対応するpinと参照箇所を明示的に変更する。
Qtのpinは[公式mirror metadata](https://download.qt.io/archive/qt/6.11/6.11.2/single/qt-everywhere-src-6.11.2.tar.xz.mirrorlist)、toml++は保存済みの使用版Arch recipeによる。Qtのmirrorページには要求元IPが含まれることがあるため、全文は保存せず、応答hashと一致した公開checksumを記録する。
[今回の実行結果](../results/source-archives/README.md)。ソース取得、使用版との部分的な照合、実ビルド構成に対する告知の完全性、具体的配布条件の判定は区別する。
## PDFiumの固定Gitソース
保存済みDEPSの固定値からLinux / Windows x64 minimalのGit取得対象を選び、PDFium本体と27依存を取得する。3並列、fetch上限900秒、Git hookとcredential helper無効で、DEPSや取得ソースのコードは実行しない。Git objectを検査してから通常ファイル・リンクの全blobをアーカイブ化し、読み戻して照合する。アーカイブに保存したリンクはファイルシステムへ展開しない。
```sh
python3 tests/source_archives/collect_pdfium.py \
--output tests/results/source-archives/new-pdfium-git \
--cache .deps/new-pdfium-git
python3 tests/source_archives/check_pdfium.py \
--collection tests/results/source-archives/new-pdfium-git \
--output tests/results/source-archives/new-pdfium-check
python3 tests/source_archives/collect_pdfium_gitlink.py \
--output tests/results/source-archives/new-pdfium-gitlink \
--cache .deps/new-pdfium-gitlink
```
出力先とアーカイブのcacheは新規にする。rootのbare repositoryのみ、存在すれば最初の取得確認用cacheを再利用して固定commit・treeを再検査する。gitlink補足スクリプトは今回の既定`pdfium-git/report.json`と固定したFreeType参照を読み、未確認の追加参照があれば停止する。
checkスクリプトはproviderのパッチを出力先内の専用コピーへ適用する。Linux3件とWindows4件の差分、既存Linux配布物の全24公開ヘッダー・15告知を比較し、本体・ワーカーを変更しない。[PDFiumの実行結果と範囲](../results/source-archives/PDFIUM.md)
## Ubuntu用Qt SDKの告知
`collect_qt_sdk_notices.py --output <新規directory>`は、保存済みの公式Qt SDK archive、Ubuntu実行時台帳とSDK SBOM、検証済みQt sourceからChromiumの告知本文を抽出する。全archiveをストリームで検査し、SBOMの67ファイル・既存実行時台帳の83ファイル・告知129entryを照合する。元SBOMの参照ID不整合や本文のない項目、生成器のskipを保持し、網羅性の判定とは分ける。[実行結果](../results/source-archives/QT-SDK-NOTICES.md)