Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
third_party/UO_Model3D_v13/model/*.blend filter=lfs diff=lfs merge=lfs -text
third_party/UO_Model3D_v13/model/*.fbx filter=lfs diff=lfs merge=lfs -text
third_party/UO_Model3D_v13/model/*.glb filter=lfs diff=lfs merge=lfs -text
12 changes: 10 additions & 2 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
# Third-party notices

SpriteMotion's own code, schemas, documentation and annotations are under the
MIT license in [LICENSE](LICENSE). The repository does not bundle any
third-party software or content. The items below are dependencies you install
MIT license in [LICENSE](LICENSE). The one exception is the UO_Model3D v13 body
described below; apart from it the repository does not bundle third-party
software or content. The items below are dependencies you install
yourself, or software the tools talk to.

## Contributed code
Expand All @@ -14,6 +15,13 @@ scripts in `games/ultima-online/outfit-lab/` (`atlas_to_vd.py`,
`uo_vd_writer.py`, `vd.py`) and `tools/vd/` were contributed by Levy and are
included with his permission.

## UO_Model3D v13

`third_party/UO_Model3D_v13/` holds UO_Model3D v13 by Levy, shared with the
artist's permission (the model, its fitting pipeline and `vdtool`). It is not
under the MIT license. It contains no data extracted from the Ultima Online
client; see its [NOTICE](third_party/UO_Model3D_v13/NOTICE.md).
Comment on lines +20 to +23

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update onboarding to use the bundled model

Update the primary README now that this model is included. Its “Start with Content Studio” section still says users need a separately obtained UO_Model3D folder, and “What you download” explicitly says the canonical body scene is not included. A fresh user following those instructions will overlook this bundled, audited source instead of running git lfs pull and passing third_party/UO_Model3D_v13 to the existing setup command.

Useful? React with 👍 / 👎.


## Runtime dependencies (installed by pip)

| Package | Use | License |
Expand Down
10 changes: 10 additions & 0 deletions tests/integration/test_repository.py
Original file line number Diff line number Diff line change
Expand Up @@ -49,14 +49,24 @@ def test_no_game_assets_or_local_paths_are_published():
files = tracked_files()
starter = REPO / 'examples/cc0-starter'
approved = json.loads((starter / 'provenance.json').read_text())['files']
model = REPO / 'third_party/UO_Model3D_v13'
model_approved = json.loads((model / 'provenance.json').read_text())['files']
for path in files:
rel = path.relative_to(REPO).as_posix()
assert not rel.startswith("workspace/") or rel == "workspace/README.md", rel
if path.parent == starter and path.name in approved:
assert path.suffix == '.glb'
assert hashlib.sha256(path.read_bytes()).hexdigest() == approved[path.name]['sha256'], rel
elif rel.startswith('third_party/UO_Model3D_v13/') and rel.removeprefix('third_party/UO_Model3D_v13/') in model_approved:
data = path.read_bytes() # a git-lfs pointer carries the sha256 of the real file
pointer = re.search(rb'^oid sha256:([0-9a-f]{64})$', data, re.MULTILINE) if data.startswith(b'version https://git-lfs') else None
digest = pointer.group(1).decode() if pointer else hashlib.sha256(data).hexdigest()
assert digest == model_approved[rel.removeprefix('third_party/UO_Model3D_v13/')], rel
Comment on lines +60 to +64

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require provenance for every bundled binary asset

Add the newly bundled PNG and NPZ assets to the provenance allowlist and reject unapproved binaries in this subtree. Currently only the three LFS model paths enter this hash check; replacing one of the six albedo PNGs—or adding another PNG/NPZ containing client-derived data—falls through to the permissive branch, and the later checks reject neither extension unless an exact client/extract directory component is present. Thus the privacy guard can pass content it claims to exclude.

AGENTS.md reference: AGENTS.md:L3-L6

Useful? React with 👍 / 👎.

else:
assert path.suffix.lower() not in {".mul", ".uop", ".idx", ".blend", ".fbx", ".glb"}, rel
if rel.startswith('third_party/UO_Model3D_v13/'):
assert path.suffix.lower() not in {".vd", ".mul", ".uop", ".idx", ".pkl"}, f"client-derived or unsafe file: {rel}"
assert not {'client', 'extract'} & set(path.parts), rel
if rel.startswith("games/") and path.suffix.lower() in {".png", ".bmp", ".gif"}:
pytest.fail(f"image under games/ (game art must never be committed): {rel}")
if path.suffix.lower() in {".py", ".gd", ".json", ".md", ".bat", ".toml", ".cfg", ".godot", ".tscn",
Expand Down
32 changes: 32 additions & 0 deletions third_party/UO_Model3D_v13/NOTICE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# UO_Model3D v13

UO_Model3D v13 by Levy, shared with the artist's permission.

A rigged 3D rebuild of the Ultima Online male body (body 0x190) with its fitting pipeline. SpriteMotion uses it as the
canonical body (rig `UO_Rig`, 112 bones after the 2026-10 weapon-bone update). Start with `README_EN.md` (English) or
`README.md` (Polish).

## What is here

`model/` (`.blend`, `.fbx`, `.glb`, albedo PNGs), `pipeline/`, `vdtool/`, and the two READMEs. The three model files are
stored with git LFS (`git lfs pull` after cloning).

## What is deliberately not here

Everything extracted from the Ultima Online client is EA data and is not published:

- `client/` (original body and horse frames, extraction output).
- All `.vd` files (`body400.vd`, `horse200.vd`, `pipeline/body13/mul/`, the example shirt layer), the original-frame atlas
(`UO_Original_Atlas.png`, `uo_original_frames.json`), the compare GIFs and shirt preview, and fit targets built from
original silhouettes (`views_*.npz`, `horse.npz`).
- All `*.pkl` result caches (also unsafe to load from a stranger).
- The packed original-frame atlas inside the `.blend`: `model/UO_Body_0x190.blend` is the stripped copy.

The READMEs still describe those files and the "exact modes" that need them. To use them, supply your own client:
copy your `anim1_0x0190.vd` to `pipeline/body400.vd`, then run `build_originals.py` and `pack_originals.py` as the
README says. The scripts that rebuild them stay in `pipeline/`.

## License

Shared with permission of the artist (Levy). `pipeline/body13/mh/` holds MakeHuman base data, which the MakeHuman
project publishes under CC0.
Loading
Loading