Third-party license notices missing for statically-linked MIT/Apache deps (miniz, mimalloc, unordered_dense, spirv-tools; follow-up to #12302)
envgap__shader-slang__slang-13023
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
a90dfa31129508f1beefe956c3b1933fa67cf21e- Manifest
CMakeLists.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
shader-slang/slang #13023 · read the original issue
### Third-party license attribution — same-family gap for statically-linked MIT / Apache dependencies Follow-up to #12302 (fixed by #13021, which shipped the **BSD** trio's notices — `cmark`, `lz4`, `glslang` — into `third-party-notices/`). The same binary-redistribution notice obligation applies to the statically-linked **MIT** and **Apache** dependencies, and their specific notices are likewise not reproduced in the redistributed package: the generic `LICENSES/MIT.txt` and `LICENSES/Apache-2.0.txt` are license *bodies*, not the per-holder copyright/NOTICE text those licenses require to accompany binary distributions. This was **deliberately kept out of #13021** so that PR stays scoped to the BSD trio + README as approved; this issue tracks the remainder. #### Confirmed statically-linked & shipped (MIT — notice not reproduced) - **`miniz`** (MIT, © 2013-2014 RAD Game Tools and Valve Software) — `LINK_WITH_PRIVATE miniz` into `core` (`source/core/CMakeLists.txt:7`). - **`mimalloc`** (MIT, © 2018-2021 Microsoft Corporation, Daan Leijen) — linked into `core` by default on Windows MSVC shared builds (`SLANG_ENABLE_MIMALLOC_DEFAULT`, `CMakeLists.txt:366-374`). - **`ankerl::unordered_dense`** (MIT) — `LINK_WITH_PUBLIC unordered_dense::unordered_dense` into `core` (`source/core/CMakeLists.txt:8`). #### Confirmed statically-linked & shipped (Apache-2.0 — additional NOTICE/attribution requirement) - **`spirv-tools`** (Apache-2.0) — `LINK_WITH_PRIVATE ... SPIRV-Tools-opt SPIRV-Tools-link` into `slang-glslang` (`source/slang-glslang/CMakeLists.txt:10`), and used on the SPIR-V emission path. Apache-2.0 §4 requires carrying any upstream `NOTICE` file and retaining attribution — distinct from the MIT case. #### To verify (header-only — redistribution-scope determination) - **`fast_float`** (Apache 2.0 / MIT / Boost) — header-only float parsing; compiled into the binary. - **`spirv-headers`** (Modified MIT) — headers only. For header-only libraries the compiled binary still contains "substantial portions," so the MIT/Apache notice clauses plausibly apply; a maintainer/legal determination on scope (which deps, and whether header-only inclusion triggers the clause) is the open question here. #### Proposed fix Extend the same mechanism #13021 established — ship each affected dependency's own `LICENSE`/`NOTICE` file into the package's `third-party-notices/` (via the CPack `metadata` component; and, for the hand-assembled WASM packages, the same `cp` treatment) — or provide one aggregated `THIRD-PARTY-NOTICES` file. Keep `reuse lint` green (do **not** add bare `LICENSES/*.txt` templates for submodule-only licenses; the compliance CI checks out without submodules and would flag them unused, as noted in #12302). *Confirmed by static inspection of `master`; not GPU/runtime-dependent. Classification: legal/compliance, same family as #12302.* > <sub>🤖 Generated by an automated Slang coworker — may be inaccurate. A human maintainer should verify.</sub>
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]