1# Chapter 22: third-party-notices, every licence the binaries carry
2
3The extension links 136 crates from crates.io into `postjevsql.so` (the
4sidecar CLI, 65), and most of their licences say the same thing: if you
5distribute this, include the notice. So a shipped binary owes a file listing
6every crate inside it, its licence, and the licence's full text. Written by
7hand, that file is wrong by the next `cargo update`.
8
9This tool writes it from the source of truth: the crate archives buck
10actually fetched. For each shipped artifact, buck's `query_outputs` hands it
11the extracted archive of every crate in that artifact's *target*
12dependencies (so build scripts, proc-macros and test crates, which never
13ship, are left out). From each it reads the name, version and `license`
14from its `Cargo.toml`, and every `LICENSE`, `LICENCE`, `COPYING` and `NOTICE`
15file, and writes them out with identical texts printed once.
16
17```mermaid
18flowchart LR
19  A["//crates/postjevsql:postjevsql's target deps"] --> Q["query_outputs: their extracted archives"]
20  B["//crates/postjevsql-sidecar:cli's target deps"] --> Q
21  X["texts/ (for crates that ship none)"] --> N
22  Q --> N["third-party-notices generate"]
23  N --> T1["THIRD-PARTY"]
24  N --> T2["THIRD-PARTY-sidecar"]
25```
26
27Two artifacts, two files: `THIRD-PARTY` for the extension and
28`THIRD-PARTY-sidecar` for the sidecar CLI, which links no pgrx and a
29different set (tokio, tokio-postgres, toml). Each package installs only its
30own. Both come from one run, because one `texts/` folder serves both.
31
32> **Aside: four crates with nothing to say.** pgrx, pgrx-pg-sys,
33> pgrx-sql-entity-graph and seahash ship no licence text in their crate
34> archives. A missing text fails the build, so their texts are in `texts/`,
35> one folder per `<name>-<version>`, each fetched from upstream at that
36> version with a `SOURCE` file naming where. seahash's `SOURCE` even tells
37> the story of where its licence went.
38
39> **Try it.** Open [THIRD-PARTY](../../THIRD-PARTY) at the repository root:
40> a list of every crate, its version and its SPDX licence, then the texts.
41> `nix develop -c buck2 test //tools/third-party-notices:drift` checks it is
42> current.
43
44## For the people who maintain it
45
46| Path | What |
47| --- | --- |
48| [src/](src/) | The tool. Chapter 23. |
49| [texts/](texts/) | Upstream licence texts for crates whose archives ship none: `<name>-<version>/LICENSE` and `SOURCE`. Not a chapter: these are other people's words, fetched, with nothing to explain beyond this paragraph. |
50| [BUCK](BUCK) | `:notices` (both files from one run, with `ARCHIVES` as the `query_outputs` over each artifact's target deps), `:drift` and `:update`. |
51| [drift.rs](drift.rs) | Fails when either committed file differs from the generated one. |
52| [Cargo.toml](Cargo.toml) | Generated by `tools/cargo-gen` (chapter 20). |
53
54← Previous: [Chapter 21, cargo-gen/src/](../cargo-gen/src/) · Up: [tools](../) · Next: [Chapter 23, third-party-notices/src/](src/) →