Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
183 commits
Select commit Hold shift + click to select a range
e5bf81c
feat(agent): add experimental local document assistant
chaxus Oct 6, 2026
d089949
fix(agent): propagate cancellation to in-flight tools
chaxus Oct 7, 2026
7282c17
test(agent): freeze Gemma task-message fidelity comparison
chaxus Oct 7, 2026
8e73aec
test(agent): retain native Gemma summary fidelity results
chaxus Oct 7, 2026
38a6bd0
test(agent): record Gemma message fidelity comparison
chaxus Oct 7, 2026
a824cbc
test(agent): verify current offline Word save and reopen
chaxus Oct 7, 2026
25b44a8
test(agent): verify offline PPT save and process restart
chaxus Oct 7, 2026
63d14d1
test(agent): freeze model-recommended sampling contrast
chaxus Oct 7, 2026
9a0e3aa
test(agent): retain model-recommended sampling results
chaxus Oct 7, 2026
20743d3
test(agent): freeze seven-language sampling transfer screen
chaxus Oct 7, 2026
10643b0
docs(agent): reconcile sampling diagnosis and transfer scope
chaxus Oct 7, 2026
78457e9
style(agent): format application sources and regression tests
chaxus Oct 7, 2026
3ae3764
docs(agent): bind current progress and remaining acceptance gaps
chaxus Oct 7, 2026
4c84486
test(agent): gate Korean source readiness before writing
chaxus Oct 7, 2026
eb3a9c6
test(agent): retain failed multilingual sampling transfer
chaxus Oct 7, 2026
58b3d3d
test(agent): retain corrected Korean sampling results
chaxus Oct 7, 2026
ef71c47
test(agent): observe actual CPU inference thread configuration
chaxus Oct 7, 2026
7b95d63
test(agent): freeze Gemma thinking-mode feasibility contrast
chaxus Oct 7, 2026
357c505
test(agent): retain thinking-mode timeout and evidence limits
chaxus Oct 7, 2026
f0c8998
test(agent): freeze current Excel offline lifecycle check
chaxus Oct 7, 2026
648393f
test(agent): verify Excel offline save and process reopen
chaxus Oct 7, 2026
ae70bce
test(agent): freeze actual WebGPU backend date contrast
chaxus Oct 7, 2026
8bd76d0
test(agent): retain backend reproduction and software timeout
chaxus Oct 7, 2026
f6c25b5
test(agent): freeze cold and reset chat-state date contrast
chaxus Oct 7, 2026
0b76a54
test(agent): reject chat reset as known date-copy repair
chaxus Oct 7, 2026
35f388a
test(agent): freeze pinned compiled-library date contrast
chaxus Oct 7, 2026
06902cd
test(agent): retain subgroup library contrast failure
chaxus Oct 7, 2026
0b160e6
test(agent): freeze independent multilingual instruct candidate screen
chaxus Oct 7, 2026
493cc57
test(agent): align source-language fixture fields before inference
chaxus Oct 7, 2026
ef97ba8
test(agent): check instruct screen request and history integrity
chaxus Oct 7, 2026
c544737
test(agent): freeze original writing policy placement contrast
chaxus Oct 7, 2026
95f0544
test(agent): validate unchanged policy placement evidence
chaxus Oct 7, 2026
a4170fd
docs(agent): preserve first seventeen instruct screen judgments
chaxus Oct 7, 2026
ff6d1bf
docs(agent): archive complete instruct seven-language screen
chaxus Oct 7, 2026
f05742a
docs(agent): record limited writing policy placement improvement
chaxus Oct 7, 2026
91e2471
test(agent): freeze compound spreadsheet offline lifecycle
chaxus Oct 7, 2026
31e56ff
docs(agent): verify compound spreadsheet offline save and reopen
chaxus Oct 7, 2026
b31836d
test(agent): pin official seven-billion CPU writing screen
chaxus Oct 7, 2026
b0d7225
test(agent): freeze official shard native writing requests
chaxus Oct 7, 2026
a37a36d
test(agent): retain CPU screen failure snapshots and identity checks
chaxus Oct 7, 2026
9096aad
docs(agent): verify official model shard download integrity
chaxus Oct 7, 2026
f5ce09d
docs(agent): preserve CPU allocation failure before inference
chaxus Oct 7, 2026
64c1899
fix(agent): verify native CPU readiness before reporting load success
chaxus Oct 7, 2026
0a50fcd
docs(agent): identify fixed CPU linear-memory ceiling
chaxus Oct 7, 2026
4d2814b
test(agent): pin higher-precision writing diagnosis
chaxus Oct 7, 2026
7e4c87f
test(agent): freeze current-build Q4 and Q6 native contrast
chaxus Oct 7, 2026
af611ec
test(agent): require native readiness for precision contrast
chaxus Oct 7, 2026
701209e
docs(agent): preserve truncated candidate download and range checks
chaxus Oct 7, 2026
4e24ab5
docs(agent): verify complete higher-precision model download
chaxus Oct 7, 2026
7631f26
docs(agent): compare pinned quantization metadata identities
chaxus Oct 7, 2026
17e7c78
docs(agent): reproduce synthetic signed URL settings persistence
chaxus Oct 7, 2026
1a642ac
docs(agent): preserve synthetic token persistence in cache names
chaxus Oct 7, 2026
4ec70a2
docs(agent): preserve completed quantization contrast failures
chaxus Oct 7, 2026
175cee0
test(agent): verify native CPU readiness in desktop WebKit
chaxus Oct 7, 2026
3dc6e6b
test(agent): expose compound spreadsheet write-sequence gap
chaxus Oct 7, 2026
7a32927
test(agent): preserve offline sort sum history and stale-cache scope
chaxus Oct 7, 2026
3434e53
test(agent): bind offline spreadsheet regression to current editor
chaxus Oct 7, 2026
006708b
test(agent): pin larger GPU candidate feasibility inputs
chaxus Oct 7, 2026
bfd5b9b
test(agent): freeze pinned GPU loading and writing diagnostic
chaxus Oct 7, 2026
472113b
test(agent): validate pinned GPU diagnostic receipt mechanics
chaxus Oct 7, 2026
f573b56
test(agent): bind GPU screen to original writing instructions
chaxus Oct 7, 2026
5867a28
docs(agent): preserve completed larger GPU writing screen
chaxus Oct 7, 2026
151cf73
test(agent): freeze native larger GPU seven-language screen
chaxus Oct 7, 2026
7e4be39
test(agent): check native larger GPU writing receipt mechanics
chaxus Oct 7, 2026
e571658
fix(agent): keep generic model failure recovery guidance accurate
chaxus Oct 7, 2026
e04b352
docs(agent): preserve native larger GPU fidelity failures
chaxus Oct 7, 2026
4ae8bdc
test(agent): verify model failure copy and same-panel recovery
chaxus Oct 7, 2026
447770f
test(agent): freeze larger GPU policy-placement follow-up
chaxus Oct 7, 2026
1704ed7
test(agent): verify original-policy contrast identity
chaxus Oct 7, 2026
07a2310
docs(agent): preserve policy contrast failures and cached library evi…
chaxus Oct 7, 2026
042a14a
test(agent): freeze larger GPU fixed-example rewrite contrast
chaxus Oct 7, 2026
0ce21fb
test(agent): verify fixed-example rewrite contrast identity
chaxus Oct 7, 2026
79c0cb4
test(agent): isolate diagnostic worker response header failure
chaxus Oct 7, 2026
e4f9e04
docs(agent): retain fixed-example diagnostic startup timeout
chaxus Oct 7, 2026
26139ab
test(agent): preserve worker headers in fixed-example diagnostic
chaxus Oct 7, 2026
796cfc1
test(agent): verify header-preserving rewrite contrast mechanics
chaxus Oct 7, 2026
1b83998
docs(agent): record observed rewrite contrast regressions
chaxus Oct 7, 2026
4c380b0
docs(agent): contrast Japanese actor loss and Korean recovery
chaxus Oct 7, 2026
71866d1
docs(agent): archive complete larger GPU rewrite contrast
chaxus Oct 7, 2026
f147b7e
test(agent): audit pinned larger GPU cached weight bytes
chaxus Oct 7, 2026
5eb2f1f
test(agent): verify full larger GPU shard audit coverage
chaxus Oct 7, 2026
c2b3914
docs(agent): confirm complete pinned larger GPU cache audit
chaxus Oct 7, 2026
d76e1cf
test(agent): probe actual GPU device loss during native chat
chaxus Oct 7, 2026
2328f0f
test(agent): target actual streaming chat row for device loss
chaxus Oct 7, 2026
de74e5d
test(agent): include explicit reload after actual GPU loss
chaxus Oct 7, 2026
7bae569
docs(agent): preserve initial GPU fault probe setup failure
chaxus Oct 7, 2026
fbddcdb
docs(agent): preserve actual GPU loss recovery and stale status defect
chaxus Oct 7, 2026
448a9ad
fix(agent): refresh model feedback after late GPU failure
chaxus Oct 7, 2026
235a5b5
test(agent): verify current production GPU loss feedback recovery
chaxus Oct 7, 2026
ab22fba
test(agent): confirm native GPU loss feedback and explicit recovery
chaxus Oct 7, 2026
a83298f
test(agent): probe idle GPU loss and unexpected worker replay
chaxus Oct 7, 2026
886914b
test(agent): confirm idle GPU loss feedback without automatic replay
chaxus Oct 7, 2026
75365f0
docs(agent): assess larger model runtime feasibility before download
chaxus Oct 7, 2026
080cd24
test(agent): probe default GPU loss and explicit CPU fallback retry
chaxus Oct 7, 2026
f881422
test(agent): require worker diagnostic startup before default GPU fault
chaxus Oct 7, 2026
8aef1dc
test(agent): isolate existing service worker from native fault probe
chaxus Oct 7, 2026
fe9f8b1
test(agent): confirm default GPU loss and explicit real CPU recovery
chaxus Oct 7, 2026
ec93dc8
test(agent): restore owned profile registration after fault isolation
chaxus Oct 7, 2026
9bb17a7
test(agent): probe current default CPU offline process restart
chaxus Oct 7, 2026
9de6f35
test(agent): verify current cached default CPU offline chat
chaxus Oct 7, 2026
509085d
docs(agent): verify isolated model compiler dependency availability
chaxus Oct 7, 2026
c2a287f
docs(agent): record native compiler dependency incompatibility
chaxus Oct 7, 2026
f12596d
docs(agent): pin matched compiler source revisions
chaxus Oct 7, 2026
01e97f4
docs(agent): verify matched source and LLVM build prerequisites
chaxus Oct 7, 2026
c5561d9
docs(agent): record Wasm runtime link failure and partial outputs
chaxus Oct 7, 2026
e428178
docs(agent): prepare pinned model compile controls and native build
chaxus Oct 7, 2026
317809a
docs(agent): distinguish expected Wasm frontend callback imports
chaxus Oct 7, 2026
e653514
docs(agent): verify C++ linked Wasm runtime build
chaxus Oct 7, 2026
9643e62
docs(agent): verify native module build and paired TVM requirement
chaxus Oct 7, 2026
cd3eb30
docs(agent): record diagnostic model linker correction
chaxus Oct 7, 2026
1d656c5
docs(agent): verify paired compiler and start Qwen control build
chaxus Oct 7, 2026
c4fdcf3
docs(agent): verify locally compiled Qwen library in WebGPU
chaxus Oct 7, 2026
092d58e
docs(agent): verify Qwen14 compiler tensor contract
chaxus Oct 7, 2026
64f1373
docs(agent): compile matched Qwen14 WebGPU library and prepare load p…
chaxus Oct 7, 2026
b490b82
docs(agent): verify Qwen14 WebGPU load and generation
chaxus Oct 7, 2026
82a859b
docs(agent): preserve Qwen14 native structured generation timeout
chaxus Oct 7, 2026
8c42bab
docs(agent): verify bounded Qwen14 request and preserve date fidelity…
chaxus Oct 7, 2026
537902a
docs(agent): reproduce Qwen14 default structured request timeout
chaxus Oct 7, 2026
54ca95e
docs(agent): isolate Qwen14 context-dependent generation timeout
chaxus Oct 7, 2026
2f89260
docs(agent): review Qwen14 Chinese native writing triplet
chaxus Oct 7, 2026
a8ee0f6
docs(agent): review additional Qwen14 native writing cases
chaxus Oct 7, 2026
d6b28ab
docs(agent): record Qwen14 German writing quality failures
chaxus Oct 7, 2026
b7f8745
docs(agent): reconcile Qwen14 interim model decision evidence
chaxus Oct 7, 2026
265d39d
docs(agent): preserve untranslated Qwen14 document heading
chaxus Oct 7, 2026
c8e3cbb
docs(agent): review Qwen14 Spanish native rewrite
chaxus Oct 7, 2026
b686163
docs(agent): review Qwen14 Spanish summary and translation
chaxus Oct 7, 2026
19f0c11
docs(agent): complete bounded Qwen14 native writing review
chaxus Oct 7, 2026
2ccb61c
docs(agent): freeze Qwen14 policy placement contrast
chaxus Oct 7, 2026
71704b1
docs(agent): preserve unobserved Qwen14 contrast launch failure
chaxus Oct 7, 2026
8732823
docs(agent): correct Qwen14 contrast observation path error
chaxus Oct 7, 2026
497ed29
docs(agent): verify Qwen14 policy placement repeats actor omission
chaxus Oct 7, 2026
b340d38
docs(agent): review Qwen14 policy placement local effects
chaxus Oct 7, 2026
a58d99a
docs(agent): preserve Qwen14 placement failures and runtime gate
chaxus Oct 7, 2026
db94d11
docs(agent): bind authenticated model source privacy gap
chaxus Oct 7, 2026
80bf95e
docs(agent): reproduce authenticated source URL persistence
chaxus Oct 7, 2026
7efecfc
docs(agent): clarify session-only model cache feasibility
chaxus Oct 7, 2026
fbdd814
docs(agent): trace SDK artifact caches and signed directory gap
chaxus Oct 7, 2026
07b3c62
docs(agent): verify directory authentication query is not propagated
chaxus Oct 7, 2026
d79daf7
docs(agent): verify fixed WebKit offline navigation controls
chaxus Oct 7, 2026
1775722
docs(agent): bind fixed WebKit product offline-page protocol
chaxus Oct 7, 2026
3828232
docs(agent): preserve fixed WebKit natural CPU startup failure
chaxus Oct 7, 2026
74dcfba
docs(agent): isolate WebKit27 default URL startup failure
chaxus Oct 7, 2026
5c5429e
docs(agent): locate WebKit27 URL model Blob read failure
chaxus Oct 7, 2026
3ab0d44
docs(agent): bind WebKit27 large Blob slice read failure
chaxus Oct 7, 2026
024b891
fix(agent): bound cached model Blob reads for WebKit
chaxus Oct 7, 2026
c1f5ff4
docs(agent): bind WebKit offline native edit protocol
chaxus Oct 7, 2026
30879be
docs(agent): preserve unproven WebKit offline insertion outcome
chaxus Oct 7, 2026
e2ea9ff
docs(agent): correct WebKit offline tool observation scope
chaxus Oct 7, 2026
3c44702
docs(agent): verify WebKit offline insertion and native history
chaxus Oct 7, 2026
95927bb
docs(agent): record WebKit offline reopen resource failure
chaxus Oct 7, 2026
5b1ccce
fix(offline): precache font menu sprites for saved-file reopen
chaxus Oct 7, 2026
8146680
docs(agent): freeze two-stage writing diagnostic protocol
chaxus Oct 7, 2026
08c21cf
docs(agent): record two-stage writing fidelity limits
chaxus Oct 7, 2026
38efed9
docs(agent): index fact-ledger diagnostic without adoption
chaxus Oct 7, 2026
50db005
docs(agent): freeze rendition prompt-only writing contrast
chaxus Oct 7, 2026
2f6a7f6
docs(agent): isolate prompt-only writing improvements and failures
chaxus Oct 7, 2026
dc77570
docs(agent): freeze protected-date writing experiment
chaxus Oct 7, 2026
bac6315
docs(agent): record protected-date actor retention regression
chaxus Oct 7, 2026
8af6cfb
docs(agent): freeze WebKit offline browser restart protocol
chaxus Oct 7, 2026
e1b871a
docs(agent): verify cached WebKit offline browser restart
chaxus Oct 7, 2026
e42f604
docs(agent): freeze per-sentence writing diagnostic
chaxus Oct 7, 2026
928c6cf
docs(agent): record segmented writing fidelity and assembly limits
chaxus Oct 7, 2026
52bd5bb
docs(agent): freeze seven-language segmented writing transfer
chaxus Oct 7, 2026
cf05989
fix(editor): allow embedded-image byte reads under CSP
chaxus Oct 7, 2026
eb8594b
docs(agent): record seven-language segmented writing transfer limits
chaxus Oct 7, 2026
aac79f2
fix(ci): preserve evaluation evidence with integrity checks
chaxus Oct 7, 2026
95fb6ec
test(pwa): retry version probes across automatic reloads
chaxus Oct 7, 2026
d82e51f
test(theme): wait for vendor theme API readiness
chaxus Oct 7, 2026
0f6dca4
docs(agent): freeze independent writing revision screen
chaxus Oct 7, 2026
f1aa44b
docs(agent): freeze specialized CPU translation screen
chaxus Oct 7, 2026
7fc6698
docs(agent): record revision and specialized translation limits
chaxus Oct 7, 2026
8a02034
fix(pwa): release worker version request resources
chaxus Oct 7, 2026
ea3c368
docs(pwa): record timing-sensitive worker activation observations
chaxus Oct 7, 2026
6573144
docs(pwa): retain failed stable-cache diagnostic control
chaxus Oct 7, 2026
372e444
docs(agent): freeze protected-literal translation comparison
chaxus Oct 7, 2026
9033dbd
docs(agent): freeze WebKit offline spreadsheet and presentation checks
chaxus Oct 7, 2026
f241701
docs(agent): retain literal protection and offline cell failures
chaxus Oct 7, 2026
1613b60
docs(agent): freeze offline cell plan boundary diagnostic
chaxus Oct 7, 2026
fde9a25
docs(agent): locate offline leading-zero loss at plan dispatch
chaxus Oct 7, 2026
5892436
fix(agent): preserve text type for quoted cell assignments
chaxus Oct 7, 2026
e3a8044
docs(agent): verify offline WebKit cell text and slide persistence
chaxus Oct 7, 2026
fe8c0cc
docs(agent): freeze typed numeric translation comparison
chaxus Oct 7, 2026
645ebe8
docs(agent): retain typed translation semantic failures
chaxus Oct 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
18 changes: 18 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,17 @@ playwright-report-docker/
test-results/
public/fonts/__fallback__/

# Local AI/browser probes: downloaded documents, profiles, logs and audit artifacts.
# Keep reproducible probe scripts and evaluation reports in docs/evaluations/.
/.scratch/

# Default Emscripten outputs from local compilation experiments.
/a.out.js
/a.out.wasm

# Python bytecode caches generated when running evaluation and verification scripts.
__pycache__/

# Nightly public corpus checkout (never committed)
corpus/
corpus-src/
Expand Down Expand Up @@ -220,3 +231,10 @@ public/pt/help.html
public/pt/changelog.html
public/pt/help/embed-api.html
public/pt/index.html

# Generated copies of the root legal notices for static hosting.
/public/LICENSE
/public/NOTICE

# Locally mirrored model artifacts (deploy separately, keep out of Git).
/public/models/
3 changes: 2 additions & 1 deletion .oxlintrc.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,8 @@
"public/help/**",
"public/changelog/**",
"public/convert/**",
"public/document_editor_service_worker.js"
"public/document_editor_service_worker.js",
"packages/agent-core/vendor/wllama-count/**"
],
"rules": {
"no-debugger": "error",
Expand Down
3 changes: 3 additions & 0 deletions .prettierignore
Original file line number Diff line number Diff line change
Expand Up @@ -187,3 +187,6 @@ public/pt/help.html
public/pt/changelog.html
public/pt/help/embed-api.html
public/pt/index.html

# Hash-pinned generated CPU runtime and upstream source patches.
packages/agent-core/vendor/wllama-count/
33 changes: 25 additions & 8 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,14 +70,31 @@ notes. Entries describe what users experience, not internal refactors.
the session on them, so a laptop keeps a recovery point about every 30
seconds while a phone under load backs off instead of competing with the
document you are editing.
- **The ONLYOFFICE logo is back in the editor header, and the About pane with
it.** Both had been switched off as interface clutter. They are not: this
editor is a modified version of ONLYOFFICE, and the license it is published
under requires the product logo to stay. The About pane now also says that
this build is not an official ONLYOFFICE product and links to the source it
was built from. Every page of the site carries the same trademark notice in
its footer, and the repository has a NOTICE file with the full terms and the
list of changes made to the vendor build.
- **Neutral presentation with legal attribution retained.** Product logos
and ecosystem promotion are removed. A neutral document icon supplies PWA and browser icons. The editor's About pane stays
available with the upstream copyright and version, a modified-version notice,
license and source links. NOTICE explains the logo decision with reference to
the FSF's interpretation of AGPLv3; it does not claim a court ruling. Offline caching remains available.

### Fixed

- Browser icons, theme-color and native controls now follow the effective light
or dark theme, including manual choices opposite to the OS preference.
Universal PWA / touch icons remain stable. The editor's existing theme
follow behavior is covered by light/dark browser tests.

- Save messages are accepted only from the same-origin editor frame. Embedded
commands are accepted only from the direct parent, with a fixed origin.
Exported document bytes no longer bypass the host API by going straight to
the top-level ancestor.
- Service Worker cache eviction stays within its `waitUntil` lifetime, removes
excess entries in a batch and tolerates storage failures.
- Editor title updates preserve the filename and unsaved marker without
restoring a product-name suffix. Language controls include the visible
language in their accessible names.
- Image-export tests use the current neutral icon. All README translations
distinguish local editing from optional cloud AI, qualify offline resource
availability and state the seven supported site languages.

### Known issues

Expand Down
1 change: 1 addition & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ RUN corepack enable && \
# Scripts are skipped here because the packages' prepare (tsc) builds need
# their sources, which are only copied in the next layer.
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
COPY patches/ ./patches/
COPY packages/shared/package.json ./packages/shared/
COPY packages/converter/package.json ./packages/converter/
COPY packages/agent-core/package.json ./packages/agent-core/
Expand Down
80 changes: 65 additions & 15 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,10 @@ This product is a derivative work of ONLYOFFICE.
The site (https://edit.chaxus.com/, https://github.com/ranuts/document) is
licensed under the GNU Affero General Public License version 3 -- see LICENSE.
It embeds the ONLYOFFICE document editors, which are distributed under the same
license with the additional terms permitted by Section 7 of the GNU AGPL. Those
terms are reproduced verbatim below and apply to this work as well.
license with the additional terms permitted by Section 7 of the GNU AGPL. The
received upstream notice is reproduced verbatim below for provenance. Valid
additional terms remain applicable; the logo-retention term is addressed
separately below rather than adopted as a downstream requirement.


1. ONLYOFFICE editors (sdkjs, web-apps)
Expand Down Expand Up @@ -57,17 +59,41 @@ The notice carried by the upstream source files, reproduced in full:
terms at http://creativecommons.org/licenses/by-sa/4.0/legalcode


How this work complies with those terms
---------------------------------------

Section 7(b) -- product logo. The ONLYOFFICE logo is shown in the editor
header, and the About pane (product logo, version, Ascensio System SIA
copyright, onlyoffice.com link) is reachable from the left rail. Neither is
suppressed. lib/onlyoffice/guards/chrome.ts hides only the current-user and
co-users widgets, which describe a collaboration session this serverless build
cannot have, and lib/onlyoffice-editor.ts leaves `customization.about` at its
default. test/unit/branding-notice.test.ts and
test/e2e/vendor-branding.spec.ts keep both from being "cleaned up" again.
Neutral presentation and retained legal notices (2026-09-26)
-----------------------------------------------------------

The interface uses descriptive functional names without project or upstream
product logos, promotional branding, or ecosystem advertising. The editor's
About pane stays reachable, retains the upstream version and publisher, and
adds copyright attribution, a modified-version notice, the warranty disclaimer,
license and source links. Site footers retain the trademark attribution and
non-affiliation notice. Source copyright headers are not removed.

The upstream notice reproduced above requires retention of the original product
logo. In its statement of 15 April 2026, the Free Software Foundation identified
that requirement as an AGPLv3-incompatible further restriction removable under
Section 7:
https://www.fsf.org/blogs/licensing/agpl-is-not-a-tool-for-taking-freedom-away

This project relies on that interpretation in omitting product-logo displays.
The quoted upstream notice is kept as a record of the terms received, not an
assertion that logo retention is a valid obligation for downstream recipients.
ONLYOFFICE has asserted a different interpretation; its position is available at:
https://www.onlyoffice.com/license-faq

The FSF statement is a license interpretation, not a court judgment. This
branding decision does not claim that the dispute is judicially resolved or
that removing logos alone satisfies all copyright, source-distribution or
trademark obligations. Other valid additional terms and third-party licenses
remain unaffected, including the GUI material's CC BY-SA 4.0 license.

lib/onlyoffice/guards/chrome.ts hides the header and About product marks,
independently of the legal text. Vendor entry HTML has matching styles to avoid
showing those marks during startup, neutral titles and no branded favicon.
lib/onlyoffice-editor.ts keeps About enabled, and
lib/onlyoffice/guards/about-source.ts provides the legal and source links.
test/unit/branding-notice.test.ts and test/e2e/vendor-branding.spec.ts verify
neutral presentation alongside accessible legal attribution.

Section 7(e) -- trademarks. ONLYOFFICE and the ONLYOFFICE logo are trademarks
of Ascensio System SIA. No rights under trademark law are granted by the
Expand All @@ -85,7 +111,9 @@ The changes made to it are:
well as in the editor frame (it branches on `typeof document` in three
places), so conversion happens in a realm whose memory can be handed
back. See docs/changelogs/2026-08-20-issue-144-memory-and-delivery.md and
docs/explorations/2026-09-12-x2t-in-a-worker.md.
docs/explorations/2026-09-12-x2t-in-a-worker.md. Modified 2026-09-26 to
send exported file bytes only to the immediate parent; outer ancestors
no longer receive an unsolicited copy.
* public/sdkjs/common/wasm/x2t/x2t.worker.js -- added by this project. It
loads the file above and drives it; no vendor code is reimplemented in it.
* public/sdkjs/common/wasm/x2t/x2t.wasm -- published brotli-compressed only
Expand All @@ -103,6 +131,11 @@ The changes made to it are:
keys returned `undefined` and crashed the tooltip renderer. Values only;
no key is removed.
* public/web-apps help content trimmed from the shipped tree.
* public/web-apps/apps/{common,*/main}/index*.html -- entry shells with
branded titles now use neutral titles and an empty favicon. An inline
stylesheet suppresses header and About product marks before the
iframe paints. Copyright, publisher and version information remain.
Changed 2026-09-26.
* public/fonts/ -- the font catalog's proprietary font files were replaced
with redistributable open-source families (see docs/font-licenses.md and
docs/changelogs/2026-08-22-font-licensing.md).
Expand All @@ -112,7 +145,8 @@ The changes made to it are:
still resolves, and nine families were added for scripts the remaining set
did not cover.

Nothing else in public/sdkjs/ or public/web-apps/ is edited. The behavioural
Other than the changes listed above, public/sdkjs/ and public/web-apps/
are not edited. The behavioural
patches this site needs are applied at runtime from lib/onlyoffice/guards/,
which leaves the rest of the vendor files byte-identical to the build they
came from.
Expand Down Expand Up @@ -140,3 +174,19 @@ third-party project https://github.com/cryptpad/onlyoffice-x2t-wasm.
Other trademarks named in this repository and on the site (Microsoft Word,
Excel, PowerPoint, and others) are the property of their respective owners and
are used only to describe the file formats this editor reads and writes.

The application icon is an independently drawn, neutral document illustration.
It contains no upstream product logo, trademark or project initials.

4. Optional local AI runtime
----------------------------

wllama 3.6.1 (https://github.com/ngxson/wllama), Copyright (c) 2024
Xuan Son NGUYEN, is distributed under the MIT license. Its WASM runtime
includes llama.cpp. License copies are shipped in public/licenses/.
Model weights are not bundled; their licenses are independent of the runtime.
The matching optional @wllama/wllama-compat 3.6.1 package is also MIT licensed.
The local pnpm patch modifies wllama's memory64 capability detection and
propagates fatal worker errors and explicit termination to pending and
subsequent tasks; see
patches/@wllama__wllama@3.6.1.patch.
43 changes: 43 additions & 0 deletions bin/archive-quality.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
import { readFileSync, rmSync, writeFileSync } from 'node:fs';
import { join } from 'node:path';
import { spawnSync } from 'node:child_process';
import { fileURLToPath } from 'node:url';
import { verifyArchive } from './evaluation-archive.mjs';

const mode = process.argv[2];
if (!['format', 'format:check', 'lint'].includes(mode)) throw new Error('Expected format, format:check or lint');
const root = fileURLToPath(new URL('../', import.meta.url));
const manifest = JSON.parse(readFileSync(join(root, 'docs/evaluations/archive-integrity.json'), 'utf8'));
console.log(`Verified ${verifyArchive(root, manifest)} immutable evaluation artifacts.`);
// Ignore patterns resolve relative to the ignore file, so it must live at
// the repository root. Exclusive creation avoids overwriting another run.
const ignore = join(root, `.archive-quality-${process.pid}.ignore`);
try {
const existing = mode === 'lint' ? '' : readFileSync(join(root, '.prettierignore'), 'utf8');
writeFileSync(ignore, `${existing}\n${manifest.files.map(({ path }) => `/${path}`).join('\n')}\n`, { flag: 'wx' });
const args =
mode === 'lint'
? [
'exec',
'oxlint',
'--deny-warnings',
...manifest.files
.filter(({ path }) => path.endsWith('.mjs'))
.flatMap(({ path }) => ['--ignore-pattern', path]),
]
: [
'exec',
'prettier',
mode === 'format' ? '--write' : '--check',
'.',
'--ignore-path',
'.gitignore',
'--ignore-path',
ignore,
];
const result = spawnSync('pnpm', args, { cwd: root, stdio: 'inherit' });
if (result.error) throw result.error;
process.exitCode = result.status ?? 1;
} finally {
rmSync(ignore, { force: true });
}
22 changes: 22 additions & 0 deletions bin/build-app-icons.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
/** Rasterize the checked-in SVG sources without adding a runtime dependency.
* npm install --prefix /tmp/document-icon-tools --no-audit --no-fund @resvg/resvg-js@2.6.2
* node bin/build-app-icons.mjs /tmp/document-icon-tools/package.json
*/
import { createRequire } from 'node:module';
import { readFileSync, writeFileSync } from 'node:fs';
import { resolve } from 'node:path';

if (!process.argv[2]) throw new Error('Pass the package.json path of an installation of @resvg/resvg-js.');
const { Resvg } = createRequire(resolve(process.argv[2]))('@resvg/resvg-js');
for (const [name, sizes] of [
['document', [32, 180, 192, 512]],
['document-maskable', [512]],
['document-light', [32]],
['document-dark', [32]],
]) {
const source = new URL(`../public/icons/${name}.svg`, import.meta.url);
for (const size of sizes) {
const png = new Resvg(readFileSync(source), { fitTo: { mode: 'width', value: size } }).render().asPng();
writeFileSync(new URL(`../public/icons/${name}-${size}.png`, import.meta.url), png);
}
}
10 changes: 10 additions & 0 deletions bin/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,10 @@ VITE_MODE_ARGS=""

echo "Starting build process (publicDir: $PUBLIC_DIR, outDir: $DIST_DIR)..."

# Workspace exports resolve to dist, so rebuild them before Vite reads those
# files. Installation-time prepare alone leaves later source edits stale.
pnpm --recursive --filter '@ranuts/*' build

# Keep the vendored ranui design-token layer in sync (the landing hero consumes
# its --ran-* variables via $PUBLIC_DIR/ran-tokens.css). Regenerate on every build
# so it never drifts from the installed ranui version, prepending a provenance
Expand Down Expand Up @@ -66,6 +70,10 @@ node bin/locale-fill.mjs

pnpm vite build $VITE_MODE_ARGS

# Hash exact inline bootstrap bytes after Vite transforms the editor entry.
# The meta policy travels with the cached shell on every static host.
node bin/editor-csp.mjs "$DIST_DIR"

# Fingerprint the vendored design tokens.
#
# The file's *name* was stable while its *content* changed every deploy — the one combination
Expand Down Expand Up @@ -106,6 +114,8 @@ else
echo "Warning: $TOKENS_DIST not found, skipping token fingerprint."
fi

node ./bin/offline-assets.mjs "$DIST_DIR"

# Inject the version stamps into sw.js.
#
# Two of them, and the difference is the point. The build stamp names the core
Expand Down
2 changes: 2 additions & 0 deletions bin/editor-csp.d.mts
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
export function secureEditorHtml(html: string): string;
export function stampEditorCsp(directory: string): Promise<void>;
38 changes: 38 additions & 0 deletions bin/editor-csp.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
import { createHash } from 'node:crypto';
import { readFile, writeFile } from 'node:fs/promises';
import { join } from 'node:path';

/** Final HTML bytes define the allowed bootstrap; never permit arbitrary inline scripts. */
export function secureEditorHtml(html) {
if (/http-equiv\s*=\s*["']Content-Security-Policy["']/i.test(html)) throw new Error('Editor CSP already exists');
if (!/<head\b[^>]*>/i.test(html)) throw new Error('Editor HTML needs a head insertion point');
const hashes = [...html.matchAll(/<script\b([^>]*)>([\s\S]*?)<\/script>/gi)]
.filter((match) => !/\bsrc\s*=/i.test(match[1]) && match[2].trim())
.map((match) => `'sha256-${createHash('sha256').update(match[2]).digest('base64')}'`);
const policy = [
"default-src 'self'",
`script-src 'self' 'wasm-unsafe-eval' ${[...new Set(hashes)].join(' ')}`,
"script-src-attr 'none'",
"style-src 'self' 'unsafe-inline'",
"img-src 'self' data: blob:",
"font-src 'self' data:",
"worker-src 'self' blob:",
"frame-src 'self' blob:",
// The editor supports user-supplied remote document and artifact URLs.
// Fetch permission does not grant those hosts permission to execute scripts.
// Embedded editor images are read with fetch(data:) before decoding.
"connect-src 'self' https: http: blob: data:",
"object-src 'none'",
"base-uri 'self'",
"form-action 'self'",
].join('; ');
return html.replace(
/<head\b[^>]*>/i,
(head) => `${head}\n<meta http-equiv="Content-Security-Policy" content="${policy}">`,
);
}
export async function stampEditorCsp(directory) {
const path = join(directory, 'editor.html');
await writeFile(path, secureEditorHtml(await readFile(path, 'utf8')));
}
if (process.argv[1]?.endsWith('/editor-csp.mjs')) await stampEditorCsp(process.argv[2] ?? 'dist');
30 changes: 30 additions & 0 deletions bin/evaluate-local-writing.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
/** Browser-side smoke evaluation. Import from the local Vite server. */
export async function evaluateLocalWriting(provider, samples, buildWritingMessages, onResult = () => {}, signal) {
const results = [];
await provider.preload();
for (const [locale, text] of samples) {
signal?.throwIfAborted();
const started = performance.now();
let firstMs;
const response = await provider.chatStream(
buildWritingMessages({ task: 'rewrite', text }),
[],
() => {
firstMs ??= performance.now() - started;
},
signal,
);
const result = {
locale,
text,
output: response.text,
firstMs,
totalMs: performance.now() - started,
// Literal checks are not semantic quality scores or language detection.
literalsPreserved: ['1,250', 'EUR', '2026-10-08', 'Alex'].every((value) => response.text.includes(value)),
};
results.push(result);
onResult(result);
}
return results;
}
5 changes: 5 additions & 0 deletions bin/evaluation-archive.d.mts
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
export function verifyArchive(
root: string,
manifest: { version: number; files: { path: string; sha256: string }[] },
options?: { syntax?: boolean },
): number;
Loading
Loading