# CAD Viewer source access and release packaging

Revision 0 · 2026-10-10 · Codex

This release uses **immediate source availability alongside the browser build**. This file is an index and publishing procedure, not a promise to supply missing code later or an assertion that publication has happened. The site operator must deploy the source files and keep their links working for the served release.

## Files to publish with this revision

The public release has an [application source ZIP](CAD_Viewer_Rev0_Application_Source.zip) and separately downloadable pinned upstream source archives. Use the [source download index](source-downloads.html) to obtain both. The application ZIP contains the HTML entry point, tested browser assets, readable application/build/test sources, public synthetic fixtures and notices; it excludes `source-archives/`, whose exact files are served separately on the same website. `DEPLOYMENT_MANIFEST.json` records every deployed file hash and `APPLICATION_SOURCE_SHA256.txt` records the application ZIP hash. This split keeps every asset below Cloudflare Pages' 25 MiB limit. The original combined development ZIP is not a public download.

Keep the HTML entry point, `assets/`, `src/`, `scripts/`, `tests/`, `package.json`, `pnpm-lock.yaml`, `pnpm-workspace.yaml`, `licenses/`, `source-archives/`, `THIRD_PARTY_NOTICES.md`, this file, and the tool's documentation together in the release. Do not publish `node_modules/`, temporary files, internal/private drawing files or unrelated company folders. Project CAD files selected by users are not part of the viewer source distribution.

Provide a visible **Source and licenses** link beside the viewer's download/about information. Link this page and offer the application archive plus the listed upstream archives, providing direct access to every source component. Keep the exact release available; do not replace its source with a newer source revision while continuing to serve an older binary. Confirm the website serves `.tar.gz`, `.tgz`, `.json`, `.js`, `.map`, `.md` and license text as downloadable files and does not rewrite source requests to the viewer HTML. No login or payment should be required for the accompanying source download.

This release's new application source is declared GPL-3.0-or-later in package.json and README, with the full text in LICENSE.txt. Individual MIT/Apache/ISC/0BSD notices remain intact. This source pack does not license unrelated website code or company drawings. If a closed-source release is needed later, replace the GPL DWG path with appropriately licensed code and rebuild; do not merely remove these notices.

## Upstream source supplied locally

| Purpose | Exact supplied archive | Revision |
|---|---|---|
| Viewer and Three renderer | [cad-viewer source](source-archives/cad-viewer-17cf21a4195ce77a41cc983bc9a22c9e20c14b06-source.tar.gz) | v1.7.4, `17cf21a4195ce77a41cc983bc9a22c9e20c14b06` |
| DWG converter, CAD model and common modules | [realdwg-web source](source-archives/realdwg-web-9f0b3382a9c201c4826a09dd76c2df3ce7067b6d-source.tar.gz) | v1.15.1, converter package 3.15.1, `9f0b3382a9c201c4826a09dd76c2df3ce7067b6d` |
| Deployed worker's matching LibreDWG C/WASM tree | [libredwg-web v0.7.14 source](source-archives/libredwg-web-1dd682f46339f37b67c5ff1085d10d04a8c16d7e-source.tar.gz) | `1dd682f46339f37b67c5ff1085d10d04a8c16d7e` |
| Installed libredwg-web JavaScript dependency | [libredwg-web v0.7.17 source](source-archives/libredwg-web-2654a724bce3d5f588a0d16b6426a23e3f0fef46-source.tar.gz) | `2654a724bce3d5f588a0d16b6426a23e3f0fef46` |
| LibreDWG's omitted git submodule | [jsmn source](source-archives/jsmn-85695f3d5903b1cd5b4030efe50db3b4f5f3c928-source.tar.gz) | `85695f3d5903b1cd5b4030efe50db3b4f5f3c928` |

The main npm package archives are retained too, with their original registry integrity metadata. They supply the exact distributed JavaScript, worker and WASM for comparison; compiled npm packages are not presented as substitutes for the preferred GPL source code above. Additional package versions 0.7.15/0.7.16 are retained as audit evidence for the identical WASM binary.

## Build or modify the application

1. Use Node.js and pnpm to install the versions in the supplied lockfile: `pnpm install --frozen-lockfile`.
2. Modify the readable application files under `src/` and the supplied HTML/CSS assets.
3. Run `pnpm test`, then `pnpm build`. `scripts/build.mjs` bundles the app and copies the exact converter worker/WASM as a pair.
4. Serve the folder over local HTTP using `pnpm serve` or the supplied launcher; browser worker restrictions mean a `file://` double-click is not equivalent to HTTP hosting.
5. Re-run the browser checks in the tool's review log and regenerate the release archive/source index after changes.

## Build or modify LibreDWG and its adapter

The GPL archives include upstream build instructions, rather than an invented replacement build. To prepare the v0.7.14 source tree, extract that archive, extract the separately supplied jsmn source into its empty `jsmn/` subdirectory, and read `bindings/javascript/README.md` and `bindings/javascript/package.json`. The documented sequence is:

```sh
# From the extracted libredwg-web root, with Emscripten environment active:
./autogen.sh
cd bindings/javascript
pnpm install --frozen-lockfile
pnpm build:prepare
pnpm build:obj
pnpm build:wasm
pnpm copy
pnpm build
```

The upstream package requires Emscripten, automake/autoconf and normal native build tools. Its scripts specify compiler/linker flags and source inputs, but do not pin the original Emscripten compiler version. The published CI packages a checked-in prebuilt WASM rather than rebuilding C in that job. Consequently, **a bit-for-bit C-to-WASM rebuild has not been established by this task**. The checked-in binary itself was verified equal to the deployed binary. These are distinct facts.

The converter source is `packages/libredwg-converter/` in the retained realdwg-web tree. That package includes its TypeScript, Vite worker/main configuration and verification scripts. When changing the low-level WASM/bindings, rebuild the converter worker against the matching bindings; deploy the worker and WASM together and retest DWG samples. Never replace only one of those files based on a semver range.

## Verify the retained evidence

Run `python source-archives/audit_sources.py`. It verifies retained npm archives against published SHA-512 integrity values, checks the exact jsmn gitlink, compares the source-tree WASM with the converter/runtime WASM, compares the runtime worker with the converter tarball and generates [`MANIFEST.json`](source-archives/MANIFEST.json) and [`SHA256SUMS.txt`](source-archives/SHA256SUMS.txt).

Source tags and decoded npm build attestations agree on the recorded commits. The attestation signature chain was not independently cryptographically verified. No external GPL compliance certification, clean-room audit, or original C toolchain reproduction was performed. A future release should preserve this distinction in its history instead of converting these checks into a blanket compliance claim.

## Remaining publication work

- Publish the application archive and separate pinned source archives with the matching compiled assets and keep the [full license](licenses/GPL-3.0.txt) accessible. Regenerate the archive after any change.
- Verify the live source-download links after deployment; this local task does not establish that those links work on the public website.
- Include any additional dependencies/assets introduced after this audit in the source/license manifest.

The concrete source pack is supplied now. These remaining items concern final release packaging and hosting, not a plan to locate the GPL source later.
