← All tasks
cppshader-slang/slang #13023Not a task: not reproduced

Third-party license notices missing for statically-linked MIT/Apache deps (miniz, mimalloc, unordered_dense, spirv-tools; follow-up to #12302)

envgap__shader-slang__slang-13023

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
a90dfa31129508f1beefe956c3b1933fa67cf21e
Manifest
CMakeLists.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

shader-slang/slang #13023 · read the original issue
### Third-party license attribution — same-family gap for statically-linked MIT / Apache dependencies

Follow-up to #12302 (fixed by #13021, which shipped the **BSD** trio's notices — `cmark`, `lz4`, `glslang` — into `third-party-notices/`). The same binary-redistribution notice obligation applies to the statically-linked **MIT** and **Apache** dependencies, and their specific notices are likewise not reproduced in the redistributed package: the generic `LICENSES/MIT.txt` and `LICENSES/Apache-2.0.txt` are license *bodies*, not the per-holder copyright/NOTICE text those licenses require to accompany binary distributions.

This was **deliberately kept out of #13021** so that PR stays scoped to the BSD trio + README as approved; this issue tracks the remainder.

#### Confirmed statically-linked & shipped (MIT — notice not reproduced)
- **`miniz`** (MIT, © 2013-2014 RAD Game Tools and Valve Software) — `LINK_WITH_PRIVATE miniz` into `core` (`source/core/CMakeLists.txt:7`).
- **`mimalloc`** (MIT, © 2018-2021 Microsoft Corporation, Daan Leijen) — linked into `core` by default on Windows MSVC shared builds (`SLANG_ENABLE_MIMALLOC_DEFAULT`, `CMakeLists.txt:366-374`).
- **`ankerl::unordered_dense`** (MIT) — `LINK_WITH_PUBLIC unordered_dense::unordered_dense` into `core` (`source/core/CMakeLists.txt:8`).

#### Confirmed statically-linked & shipped (Apache-2.0 — additional NOTICE/attribution requirement)
- **`spirv-tools`** (Apache-2.0) — `LINK_WITH_PRIVATE ... SPIRV-Tools-opt SPIRV-Tools-link` into `slang-glslang` (`source/slang-glslang/CMakeLists.txt:10`), and used on the SPIR-V emission path. Apache-2.0 §4 requires carrying any upstream `NOTICE` file and retaining attribution — distinct from the MIT case.

#### To verify (header-only — redistribution-scope determination)
- **`fast_float`** (Apache 2.0 / MIT / Boost) — header-only float parsing; compiled into the binary.
- **`spirv-headers`** (Modified MIT) — headers only.

For header-only libraries the compiled binary still contains "substantial portions," so the MIT/Apache notice clauses plausibly apply; a maintainer/legal determination on scope (which deps, and whether header-only inclusion triggers the clause) is the open question here.

#### Proposed fix
Extend the same mechanism #13021 established — ship each affected dependency's own `LICENSE`/`NOTICE` file into the package's `third-party-notices/` (via the CPack `metadata` component; and, for the hand-assembled WASM packages, the same `cp` treatment) — or provide one aggregated `THIRD-PARTY-NOTICES` file. Keep `reuse lint` green (do **not** add bare `LICENSES/*.txt` templates for submodule-only licenses; the compliance CI checks out without submodules and would flag them unused, as noted in #12302).

*Confirmed by static inspection of `master`; not GPU/runtime-dependent. Classification: legal/compliance, same family as #12302.*

> <sub>🤖 Generated by an automated Slang coworker — may be inaccurate. A human maintainer should verify.</sub>
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]