返回 CodeWhale
README.md
1 # Compiled-host runtime inputs
2
3 This is a release preparation contract, not runtime authority or a publication
4 approval. The runtime remains optional and Node remains the Core default.
5
6 The exact local Bun observed during this packet is **1.4.0+34cbb9a40**, executable
7 SHA-256 `539598c775882420b9d8deb7dc14d845f20f7d26f5600c50ab067dde6ac3f3bf`. Its
8 full source revision is `34cbb9a40b4bd1bd767d134a7065e66c2432a676`, with WebKit
9 revision `0f966e81b78c84bb23213e391bc679c4ef83e56b`. This is one observed macOS
10 ARM64 binary, not qualification for other architectures or libc families.
11
12 The [matching Bun license](https://raw.githubusercontent.com/oven-sh/bun/34cbb9a40b4bd1bd767d134a7065e66c2432a676/LICENSE.md)
13 identifies statically linked JavaScriptCore/WebCore under LGPL2 and TinyCC under
14 LGPL2.1. It provides the Bun/WebKit source rebuild path. Delivery must retain
15 the corresponding copyright/license texts and provide the exact matching
16 source, patches, build/relink recipe and application object/source inputs
17 needed to modify and relink the LGPL components. URLs or a single MIT label do
18 not constitute that payload.
19
20 `stage-compiled-host.mjs` requires a reviewed JSON closure file with schema1,
21 exact `runtime_version`, full `runtime_revision`, `runtime_sha256`, full
22 `webkit_revision`, actual `libc` (`glibc`, `musl`, or `none`), current
23 `bundle_sha256` and `source_commit`; `notices`, `notices_sha256`, `relink_source`,
24 `source_sha256`; `license_closure: "complete"` and
25 `corresponding_source: "complete"`. Every named component must have an actual
26 `notice_components[name]: {file, sha256}` text included byte-for-byte in the
27 combined notices, including linked libraries, embedded polyfills and Rust
28 dependencies. Paths resolve only from this explicitly supplied local closure
29 file. The required notice inventory is enforced in the stager; the complete
30 per-platform component inventory must also be reviewed.
31
32 The source `.tar.gz` must include `source_inputs` entries for `bun`, `webkit`,
33 `tinycc`, and `relink-recipe`, each naming its contained `root`; Bun and WebKit
34 entries also carry the exact corresponding revision. This inventory and hash
35 check detects missing/mixed inputs. Review of the complete reproduction and
36 relink recipe remains necessary: flags and archive member names alone do not
37 prove source sufficiency. Do not mark incomplete inputs complete.
38
39 Exact corresponding Bun and TinyCC source archives are available from the
40 [matching Bun commit](https://codeload.github.com/oven-sh/bun/tar.gz/34cbb9a40b4bd1bd767d134a7065e66c2432a676)
41 and [matching TinyCC fork commit](https://codeload.github.com/oven-sh/tinycc/tar.gz/05f0fafaa3be31e31d7b4b5c17dc60f62c991171).
42 The Bun archive includes its exact TinyCC patch and build scripts. Matching
43 libwebp notice texts are available from Google's primary
44 [exact commit](https://chromium.googlesource.com/webm/libwebp/+/b7e29b9d75bd31422b00c2a446d49d7af06c328d/COPYING).
45 Earlier GitHub mirror 404 observations do not establish a source/notice absence.
46
47 The matching WebKit release is
48 [`autobuild-0f966…`](https://github.com/oven-sh/WebKit/releases/tag/autobuild-0f966e81b78c84bb23213e391bc679c4ef83e56b).
49 Its 42 observed assets are ABI-specific prebuilts according to the pinned build
50 contract; no full source/relink archive was found among them. The generated
51 exact-source archive request returned HTTP 422 during the takeover. A full exact
52 fork source snapshot, generated-header/build inputs, complete copyright/license
53 texts for embedded components/polyfills/Rust dependencies, and a reviewed
54 rebuild/relink recipe are still required. API tree results were truncated and
55 must not be labeled a complete source inventory. No delivery-qualified closure
56 has been produced by these downloads.
57
58 The exact build source also includes static SQLite on Linux/Windows, while macOS
59 loads system SQLite. Its in-tree source/public-domain dedication must be
60 accounted for in a complete per-platform component inventory. The stager's
61 required notice list is a minimum guard; full inventory and source sufficiency
62 remain reviewed input obligations, never conclusions from flags alone.
63
64 The release workflow is explicitly opt-in and fails when those local reviewed
65 inputs or exact-source Native proof are absent. The compiled image is copied
66 from the already tested CI artifact, never rebuilt after Native containment
67 proof. Five direct-image protocol cases apply on every supported OS; macOS
68 adds a sixth reexec/jetsam case. These cases require zero failures and zero
69 skips and cannot substitute for the same exact compiled image's actual Rust
70 Native containment and memory enforcement or license/source closure.
71
72 The official Bun 1.4.0 release has Android and musl runtime assets. Android is
73 **not a qualified Codewhale compiled-host delivery target** in this contract;
74 that is an evidence boundary, not a claim that upstream has no Android binary.
75 The existing static musl CLI remains available, while a musl runtime needs its
76 own exact-image Native receipt and complete source/notice closure. GNU runner
77 proof does not transfer. No additional delivery targets are enabled here.
78
79 Delivery probes the actual selected Bun process and the actual compiled image
80 for platform/architecture. Both must equal the native runner and the exact-image
81 Native receipt; an emulated x64 Bun on ARM cannot be labeled ARM. Windows now
82 requires all nine current Native cases, including compiled-image containment
83 and memory enforcement plus seven LPAC cases. Linux/macOS require their two
84 compiled-image Rust cases, independently of the direct-image protocol cases.
85 This does not claim any of those remote cases ran locally.
86
86 lines MARKDOWN