ci(release): ship licence texts and third-party notices with the ant CLI - #213
Conversation
08f8007 to
edbaa5f
Compare
The `ant` archives and the npm platform packages contained only the binary and bootstrap_peers.toml. The binary statically links several hundred third-party crates, OpenSSL (vendored and linked statically on Linux and macOS) and other bundled C code, whose licences (MIT, BSD, ISC, Apache-2.0, MPL-2.0 and others) require their copyright and licence notices to accompany binary redistribution, and the archives did not carry the project's own licence files either. scripts/third_party_notices/generate.py builds THIRD-PARTY-NOTICES.txt from Cargo.lock for `ant` and one or more targets. It takes the packages `cargo tree` resolves (normal and build dependencies, so build tools such as openssl-src are listed too), matches each to exactly one `cargo metadata` package, and for each: - reproduces, unaltered, every licence, copyright, notice, authors, patents, credits and third-party file the crate ships at any depth, printing identical texts once, and names the crate's exact crates.io source archive, which is also how source is offered where a licence requires it (MPL-2.0, and GPL-3.0 for self_encryption); - checks the declared licence against the policy in config.toml and records the licence it is redistributed under, which must be allowed and whose text must be identified in one of the crate's own licence files (those of bundled components do not count); - when a crate ships no such files, or none with that licence's text, takes them from its repository at the commit recorded in the crate (or Cargo's checkout, for a git dependency), and failing that from a reviewed, version-pinned config entry with a checksummed canonical text (saorsa-pqc and siphasher today); - requires a reviewed config entry for any crate that may contain native code: one that ships C, C++, Objective-C, CUDA or assembly sources or prebuilt libraries, builds with cc/cmake/nasm, declares `links`, or is a `*-src` crate (OpenSSL, zstd, bzip2, XZ Utils, AWS-LC, ring, BLAKE3, and a few build tools and test fixtures). self_encryption 0.36.0 is GPL-3.0 with a linking exception; a version-pinned exception records that, its LICENSE, including the exception, is reproduced, and its exact source is linked. Any other gap fails generation. For the statically linked Linux builds it also appends musl's COPYRIGHT for the musl release the building rustc uses: the version is read from Rust's own build scripts at that rustc's commit, and the text from that musl release tarball. Each release build job generates the notices for its own target and puts them in the archive with LICENSE-MIT, LICENSE-APACHE and RUST-STD-COPYRIGHT.html, the Rust standard library's notices copied from the toolchain that built the binary. The signed Windows archive is repackaged with the same files, and npm/build-packages.sh copies all four into each platform package (and the licence files into the meta package), failing if an archive lacks any of them. `ant update`, install.sh and install.ps1 pick files from the archive by name, so the extra entries do not affect them. CI generates the notices for all release targets on every pull request.
edbaa5f to
e8ed13c
Compare
|
Reviewed as part of the V2-1385 sweep (V2-1392). Covers everything the issue asked for, including the two easy things to miss:
The packaging is consistent across all three distribution channels — the tar/zip archives, each npm platform package ( The Same two cross-cutting notes as ant-node, neither blocking: Approving. |
jacderida
left a comment
There was a problem hiding this comment.
Covers the vendored OpenSSL and MPL-2.0 as the issue asked; packaging is consistent across archives, npm and the signed Windows build.
Linear issue
Closes V2-1392
Risk tier
Release packaging and CI only; the
antbinary is unchanged.Compatibility
LICENSE-MIT,LICENSE-APACHE,THIRD-PARTY-NOTICES.txtandRUST-STD-COPYRIGHT.html; the npm meta package gains the two licence files.ant update(ant-core/src/update.rs), the node installer (ant-core/src/node/binary.rs),install.shandinstall.ps1pick entries from the archive by name, so the extra files do not affect them.Semver impact
Test evidence
The
antarchives and npm packages held only the binary andbootstrap_peers.toml, whileantstatically links several hundred third-party crates, OpenSSL 3 (vendored and linked statically on Linux and macOS throughopenssl-src, which Cargo lists as a build dependency) and other bundled C code, whose licences require their notices in binary redistribution.scripts/third_party_notices/generate.pyis the same standard-library Python generator as in the companion ant-node pull request (ci(release): ship licence texts and third-party notices; link self_encryption only with test-utils ant-node#243, where it went through several review rounds). It buildsTHIRD-PARTY-NOTICES.txtfromCargo.lockforantand a target: every packagecargo treeresolves (normal and build dependencies, soopenssl-srcand other build tools are listed), each matched to exactly onecargo metadatapackage; every licence, copyright, notice, authors, patents, credits and third-party file each crate ships is reproduced unaltered, identical texts once, with the crate's exact crates.io source archive as its Source link, which is also how source is offered where a licence requires it.config.toml): the notice records the licence each crate is redistributed under, which must be allowed and identified in the crate's own licence files; gaps fail generation (missing texts, unreviewed licences, ambiguous packages, or crates that may contain native code without a reviewed entry). Reviewed entries cover OpenSSL, zstd, bzip2, XZ Utils, AWS-LC, ring and BLAKE3 plus a few build tools and fixtures; saorsa-pqc 0.5.2 and siphasher 1.0.3 publish no text of their licence anywhere, so a checksummed canonical text is supplied, version-pinned.rustcuses (version read from rust-lang/rust'smusl.shat that rustc's commit, text from that musl release tarball). Each archive also carriesRUST-STD-COPYRIGHT.html, the Rust standard library's notices copied from the toolchain that built the binary.npm/build-packages.shcopies all four files into each platform package and the licence files into the meta package, and fails if an archive lacks any of them. CI generates the notices for all five targets on every pull request.Copyrightline in every crate's licence files against the output found none missing on any target.npm/build-packages.shdry run with five staged archives produced packages containing the new files (npm pack --dry-runlists them). Workflow YAML parses. The release workflow itself only runs on a tag.New dependency
none (the generator is a standard-library Python script run in CI;
actions/setup-pythonpins Python 3.12 in the release build jobs)ADR
n/a
Mitigation / rollback
Revert the commit; the binary is untouched and the archives return to their previous contents.