Skip to content

ci(release): ship licence texts and third-party notices with the ant CLI - #213

Merged
jacderida merged 1 commit into
WithAutonomi:mainfrom
grumbach:ci/release-third-party-notices
Oct 2, 2026
Merged

jacderida merged 1 commit into
WithAutonomi:mainfrom
grumbach:ci/release-third-party-notices

Conversation

@grumbach

@grumbach grumbach commented Oct 1, 2026

Copy link
Copy Markdown
Member

Linear issue

Closes V2-1392

Risk tier

  • T0 — docs / tooling / CI / pure UX-output. Repo CI only.
  • T1 — client-only, no network-facing behavior change. CI + prod compat smoke.
  • T2 — node/client logic with behavioral surface, no protocol/format/economics change. Dev testnet + ADR.
  • T3 — protocol / storage format / payments / routing. T2 evidence + adversarial testing.

Release packaging and CI only; the ant binary is unchanged.

Compatibility

  • Wire: none
  • Storage: none
  • API: none. Release archives and npm platform packages gain LICENSE-MIT, LICENSE-APACHE, THIRD-PARTY-NOTICES.txt and RUST-STD-COPYRIGHT.html; the npm meta package gains the two licence files. ant update (ant-core/src/update.rs), the node installer (ant-core/src/node/binary.rs), install.sh and install.ps1 pick entries from the archive by name, so the extra files do not affect them.

Semver impact

  • breaking
  • feature
  • fix

Test evidence

The ant archives and npm packages held only the binary and bootstrap_peers.toml, while ant statically links several hundred third-party crates, OpenSSL 3 (vendored and linked statically on Linux and macOS through openssl-src, which Cargo lists as a build dependency) and other bundled C code, whose licences require their notices in binary redistribution.

  • scripts/third_party_notices/generate.py is the same standard-library Python generator as in the companion ant-node pull request (ci(release): ship licence texts and third-party notices; link self_encryption only with test-utils ant-node#243, where it went through several review rounds). It builds THIRD-PARTY-NOTICES.txt from Cargo.lock for ant and a target: every package cargo tree resolves (normal and build dependencies, so openssl-src and other build tools are listed), each matched to exactly one cargo metadata package; every licence, copyright, notice, authors, patents, credits and third-party file each crate ships is reproduced unaltered, identical texts once, with the crate's exact crates.io source archive as its Source link, which is also how source is offered where a licence requires it.
  • Policy (config.toml): the notice records the licence each crate is redistributed under, which must be allowed and identified in the crate's own licence files; gaps fail generation (missing texts, unreviewed licences, ambiguous packages, or crates that may contain native code without a reviewed entry). Reviewed entries cover OpenSSL, zstd, bzip2, XZ Utils, AWS-LC, ring and BLAKE3 plus a few build tools and fixtures; saorsa-pqc 0.5.2 and siphasher 1.0.3 publish no text of their licence anywhere, so a checksummed canonical text is supplied, version-pinned.
  • self_encryption 0.36.0 is GPL-3.0 with a linking exception. A version-pinned exception records it: its LICENSE, including the exception, is reproduced in full and its exact source is linked. Whether the exception leaves any further duty for the library itself is a question for counsel; moving ant-core to a self_encryption release published under MIT OR Apache-2.0 removes the entry.
  • For the musl Linux builds the notices append musl's COPYRIGHT for the release the building rustc uses (version read from rust-lang/rust's musl.sh at that rustc's commit, text from that musl release tarball). Each archive also carries RUST-STD-COPYRIGHT.html, the Rust standard library's notices copied from the toolchain that built the binary.
  • Release workflow: each build job generates the notices for its own target before building and packs them with the licence files; the Windows signing job repackages them (failing if any is missing). npm/build-packages.sh copies all four files into each platform package and the licence files into the meta package, and fails if an archive lacks any of them. CI generates the notices for all five targets on every pull request.
  • Local runs: linux-musl x64 442 crates / 324 texts, linux-musl arm64 440 / 323, macOS x64 447 / 327, macOS arm64 445 / 326, Windows 458 / 316; a cross-check comparing every Copyright line in every crate's licence files against the output found none missing on any target. npm/build-packages.sh dry run with five staged archives produced packages containing the new files (npm pack --dry-run lists them). Workflow YAML parses. The release workflow itself only runs on a tag.

New dependency

none (the generator is a standard-library Python script run in CI; actions/setup-python pins Python 3.12 in the release build jobs)

ADR

n/a

Mitigation / rollback

Revert the commit; the binary is untouched and the archives return to their previous contents.

@grumbach
grumbach force-pushed the ci/release-third-party-notices branch from 08f8007 to edbaa5f Compare October 1, 2026 07:31
The `ant` archives and the npm platform packages contained only the binary
and bootstrap_peers.toml. The binary statically links several hundred
third-party crates, OpenSSL (vendored and linked statically on Linux and
macOS) and other bundled C code, whose licences (MIT, BSD, ISC, Apache-2.0,
MPL-2.0 and others) require their copyright and licence notices to
accompany binary redistribution, and the archives did not carry the
project's own licence files either.

scripts/third_party_notices/generate.py builds THIRD-PARTY-NOTICES.txt from
Cargo.lock for `ant` and one or more targets. It takes the packages
`cargo tree` resolves (normal and build dependencies, so build tools such as
openssl-src are listed too), matches each to exactly one `cargo metadata`
package, and for each:

- reproduces, unaltered, every licence, copyright, notice, authors, patents,
  credits and third-party file the crate ships at any depth, printing
  identical texts once, and names the crate's exact crates.io source archive,
  which is also how source is offered where a licence requires it (MPL-2.0,
  and GPL-3.0 for self_encryption);
- checks the declared licence against the policy in config.toml and records
  the licence it is redistributed under, which must be allowed and whose
  text must be identified in one of the crate's own licence files (those of
  bundled components do not count);
- when a crate ships no such files, or none with that licence's text, takes
  them from its repository at the commit recorded in the crate (or Cargo's
  checkout, for a git dependency), and failing that from a reviewed,
  version-pinned config entry with a checksummed canonical text
  (saorsa-pqc and siphasher today);
- requires a reviewed config entry for any crate that may contain native
  code: one that ships C, C++, Objective-C, CUDA or assembly sources or
  prebuilt libraries, builds with cc/cmake/nasm, declares `links`, or is a
  `*-src` crate (OpenSSL, zstd, bzip2, XZ Utils, AWS-LC, ring, BLAKE3, and a
  few build tools and test fixtures).

self_encryption 0.36.0 is GPL-3.0 with a linking exception; a version-pinned
exception records that, its LICENSE, including the exception, is reproduced,
and its exact source is linked. Any other gap fails generation. For the
statically linked Linux builds it also appends musl's COPYRIGHT for the musl
release the building rustc uses: the version is read from Rust's own build
scripts at that rustc's commit, and the text from that musl release tarball.

Each release build job generates the notices for its own target and puts
them in the archive with LICENSE-MIT, LICENSE-APACHE and
RUST-STD-COPYRIGHT.html, the Rust standard library's notices copied from the
toolchain that built the binary. The signed Windows archive is repackaged
with the same files, and npm/build-packages.sh copies all four into each
platform package (and the licence files into the meta package), failing if
an archive lacks any of them. `ant update`, install.sh and install.ps1 pick
files from the archive by name, so the extra entries do not affect them. CI
generates the notices for all release targets on every pull request.
@grumbach
grumbach force-pushed the ci/release-third-party-notices branch from edbaa5f to e8ed13c Compare October 1, 2026 08:29
@jacderida

Copy link
Copy Markdown
Member

Reviewed as part of the V2-1385 sweep (V2-1392).

Covers everything the issue asked for, including the two easy things to miss:

  • Vendored OpenSSL. [native.openssl-src] and [native.openssl-sys] are reviewed entries, with the note correctly distinguishing the OpenSSL that openssl-src builds and statically links on Linux and macOS from the small C shim openssl-sys compiles itself. Cargo calls this a build dependency; it ends up in the binary, and the notices now say so.
  • MPL-2.0 is in allowed, and the generated header carries the source-availability statement MPL-2.0 §3.2 wants.

The packaging is consistent across all three distribution channels — the tar/zip archives, each npm platform package (files updated so they actually publish), and the signed Windows archive, which hard-fails if a file is missing. build-packages.sh dies rather than producing a package without notices. Shipping only LICENSE-MIT/LICENSE-APACHE in the ant meta package is the right call since it contains no binary.

The npm/README.md dry-run instructions were also corrected to build for an explicit target, which they needed anyway.

Same two cross-cutting notes as ant-node, neither blocking: generate.py is byte-identical across five repositories and should be extracted, and notices generation now puts the GitHub API and musl.libc.org in the release path.

Approving.

@jacderida jacderida left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Covers the vendored OpenSSL and MPL-2.0 as the issue asked; packaging is consistent across archives, npm and the signed Windows build.

@jacderida
jacderida merged commit 681d48f into WithAutonomi:main Oct 2, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants