Chapter 22: third-party-notices, every licence the binaries carry

The extension links 136 crates from crates.io into postjevsql.so (the sidecar CLI, 65), and most of their licences say the same thing: if you distribute this, include the notice. So a shipped binary owes a file listing every crate inside it, its licence, and the licence's full text. Written by hand, that file is wrong by the next cargo update.

This tool writes it from the source of truth: the crate archives buck actually fetched. For each shipped artifact, buck's query_outputs hands it the extracted archive of every crate in that artifact's target dependencies (so build scripts, proc-macros and test crates, which never ship, are left out). From each it reads the name, version and license from its Cargo.toml, and every LICENSE, LICENCE, COPYING and NOTICE file, and writes them out with identical texts printed once.

flowchart LR
  A["//crates/postjevsql:postjevsql's target deps"] --> Q["query_outputs: their extracted archives"]
  B["//crates/postjevsql-sidecar:cli's target deps"] --> Q
  X["texts/ (for crates that ship none)"] --> N
  Q --> N["third-party-notices generate"]
  N --> T1["THIRD-PARTY"]
  N --> T2["THIRD-PARTY-sidecar"]

Two artifacts, two files: THIRD-PARTY for the extension and THIRD-PARTY-sidecar for the sidecar CLI, which links no pgrx and a different set (tokio, tokio-postgres, toml). Each package installs only its own. Both come from one run, because one texts/ folder serves both.

Aside: four crates with nothing to say. pgrx, pgrx-pg-sys, pgrx-sql-entity-graph and seahash ship no licence text in their crate archives. A missing text fails the build, so their texts are in texts/, one folder per <name>-<version>, each fetched from upstream at that version with a SOURCE file naming where. seahash's SOURCE even tells the story of where its licence went.

Try it. Open THIRD-PARTY at the repository root: a list of every crate, its version and its SPDX licence, then the texts. nix develop -c buck2 test //tools/third-party-notices:drift checks it is current.

For the people who maintain it

PathWhat
src/The tool. Chapter 23.
texts/Upstream licence texts for crates whose archives ship none: <name>-<version>/LICENSE and SOURCE. Not a chapter: these are other people's words, fetched, with nothing to explain beyond this paragraph.
BUCK:notices (both files from one run, with ARCHIVES as the query_outputs over each artifact's target deps), :drift and :update.
drift.rsFails when either committed file differs from the generated one.
Cargo.tomlGenerated by tools/cargo-gen (chapter 20).

← Previous: Chapter 21, cargo-gen/src/ · Up: tools · Next: Chapter 23, third-party-notices/src/ →