1# Chapter 22: third-party-notices, every licence the binaries carry 2 3The extension links 136 crates from crates.io into `postjevsql.so` (the 4sidecar CLI, 65), and most of their licences say the same thing: if you 5distribute this, include the notice. So a shipped binary owes a file listing 6every crate inside it, its licence, and the licence's full text. Written by 7hand, that file is wrong by the next `cargo update`. 8 9This tool writes it from the source of truth: the crate archives buck 10actually fetched. For each shipped artifact, buck's `query_outputs` hands it 11the extracted archive of every crate in that artifact's *target* 12dependencies (so build scripts, proc-macros and test crates, which never 13ship, are left out). From each it reads the name, version and `license` 14from its `Cargo.toml`, and every `LICENSE`, `LICENCE`, `COPYING` and `NOTICE` 15file, and writes them out with identical texts printed once. 16 17```mermaid 18flowchart LR 19 A["//crates/postjevsql:postjevsql's target deps"] --> Q["query_outputs: their extracted archives"] 20 B["//crates/postjevsql-sidecar:cli's target deps"] --> Q 21 X["texts/ (for crates that ship none)"] --> N 22 Q --> N["third-party-notices generate"] 23 N --> T1["THIRD-PARTY"] 24 N --> T2["THIRD-PARTY-sidecar"] 25``` 26 27Two artifacts, two files: `THIRD-PARTY` for the extension and 28`THIRD-PARTY-sidecar` for the sidecar CLI, which links no pgrx and a 29different set (tokio, tokio-postgres, toml). Each package installs only its 30own. Both come from one run, because one `texts/` folder serves both. 31 32> **Aside: four crates with nothing to say.** pgrx, pgrx-pg-sys, 33> pgrx-sql-entity-graph and seahash ship no licence text in their crate 34> archives. A missing text fails the build, so their texts are in `texts/`, 35> one folder per `<name>-<version>`, each fetched from upstream at that 36> version with a `SOURCE` file naming where. seahash's `SOURCE` even tells 37> the story of where its licence went. 38 39> **Try it.** Open [THIRD-PARTY](../../THIRD-PARTY) at the repository root: 40> a list of every crate, its version and its SPDX licence, then the texts. 41> `nix develop -c buck2 test //tools/third-party-notices:drift` checks it is 42> current. 43 44## For the people who maintain it 45 46| Path | What | 47| --- | --- | 48| [src/](src/) | The tool. Chapter 23. | 49| [texts/](texts/) | Upstream licence texts for crates whose archives ship none: `<name>-<version>/LICENSE` and `SOURCE`. Not a chapter: these are other people's words, fetched, with nothing to explain beyond this paragraph. | 50| [BUCK](BUCK) | `:notices` (both files from one run, with `ARCHIVES` as the `query_outputs` over each artifact's target deps), `:drift` and `:update`. | 51| [drift.rs](drift.rs) | Fails when either committed file differs from the generated one. | 52| [Cargo.toml](Cargo.toml) | Generated by `tools/cargo-gen` (chapter 20). | 53 54← Previous: [Chapter 21, cargo-gen/src/](../cargo-gen/src/) · Up: [tools](../) · Next: [Chapter 23, third-party-notices/src/](src/) →