Chapter 22: third-party-notices, every licence the binaries carry
The extension links 136 crates from crates.io into postjevsql.so (the
sidecar CLI, 65), and most of their licences say the same thing: if you
distribute this, include the notice. So a shipped binary owes a file listing
every crate inside it, its licence, and the licence's full text. Written by
hand, that file is wrong by the next cargo update.
This tool writes it from the source of truth: the crate archives buck
actually fetched. For each shipped artifact, buck's query_outputs hands it
the extracted archive of every crate in that artifact's target
dependencies (so build scripts, proc-macros and test crates, which never
ship, are left out). From each it reads the name, version and license
from its Cargo.toml, and every LICENSE, LICENCE, COPYING and NOTICE
file, and writes them out with identical texts printed once.
flowchart LR A["//crates/postjevsql:postjevsql's target deps"] --> Q["query_outputs: their extracted archives"] B["//crates/postjevsql-sidecar:cli's target deps"] --> Q X["texts/ (for crates that ship none)"] --> N Q --> N["third-party-notices generate"] N --> T1["THIRD-PARTY"] N --> T2["THIRD-PARTY-sidecar"]
Two artifacts, two files: THIRD-PARTY for the extension and
THIRD-PARTY-sidecar for the sidecar CLI, which links no pgrx and a
different set (tokio, tokio-postgres, toml). Each package installs only its
own. Both come from one run, because one texts/ folder serves both.
Aside: four crates with nothing to say. pgrx, pgrx-pg-sys, pgrx-sql-entity-graph and seahash ship no licence text in their crate archives. A missing text fails the build, so their texts are in
texts/, one folder per<name>-<version>, each fetched from upstream at that version with aSOURCEfile naming where. seahash'sSOURCEeven tells the story of where its licence went.
Try it. Open THIRD-PARTY at the repository root: a list of every crate, its version and its SPDX licence, then the texts.
nix develop -c buck2 test //tools/third-party-notices:driftchecks it is current.
For the people who maintain it
| Path | What |
|---|---|
| src/ | The tool. Chapter 23. |
| texts/ | Upstream licence texts for crates whose archives ship none: <name>-<version>/LICENSE and SOURCE. Not a chapter: these are other people's words, fetched, with nothing to explain beyond this paragraph. |
| BUCK | :notices (both files from one run, with ARCHIVES as the query_outputs over each artifact's target deps), :drift and :update. |
| drift.rs | Fails when either committed file differs from the generated one. |
| Cargo.toml | Generated by tools/cargo-gen (chapter 20). |
← Previous: Chapter 21, cargo-gen/src/ · Up: tools · Next: Chapter 23, third-party-notices/src/ →