From 5040ffd83598bb954667204cf9832dc6dbfb5e5a Mon Sep 17 00:00:00 2001 From: Abrar Shivani Date: Thu, 27 Aug 2026 11:06:22 -0700 Subject: [PATCH 1/3] Add version and verified upstream license links to the notices THIRD_PARTY_NOTICES.md now carries a Version and a Location column instead of the Dependency column. Location links to the license file in the dependency's own upstream repository, pinned to the version we redistribute: | Package | Version | License | Location | |---------|---------|---------|----------| | `github.com/NVIDIA/go-nvml/pkg` | v0.13.3-1 | Apache-2.0 | [LICENSE](https://github.com/NVIDIA/go-nvml/blob/v0.13.3-1/LICENSE) | Version was dropped in b911681d on the grounds that the notices identify dependencies and their licenses, not an exact build. That is reversed here: a notices file that does not say which version it describes cannot be matched to a release, and a link into upstream needs a ref to point at. The churn per bump is one index row and two bullets. Every URL was verified by fetching it and comparing its sha256 against the copy under vendor/. A URL that does not match is never written, so no link is dead and none points at the wrong license. 47 URLs across 41 modules. vendor/ gives the module, the version and the license file names for free, but not the upstream repository: cyphar.com/go-pathrs lives at github.com/cyphar/go-pathrs, sigs.k8s.io/yaml at github.com/kubernetes-sigs/yaml. Two committed maps carry that instead, both machine-generated. hack/module-repos.tsv maps module to repository, resolved from the Go module proxy's Origin, then the go-import meta tag that go get itself uses, then the github.com// path shape. It is keyed by module and not by version, so a bump does not invalidate it. hack/license-urls.tsv maps module, version and license path to a verified URL. A row is written only when the bytes at that URL hash identically to the vendored copy. Probing for a 200 is not enough: it cannot tell a correct link from one that returns 200 for the wrong license. Both are produced out of band by 'make third-party-notices-repos' and 'make third-party-notices-urls', which need network. 'make third-party-notices' reads them offline, so 'make check-third-party-notices' stays hermetic. License files are now enumerated from vendor/ rather than from the go-licenses save output, because that output keeps only the one file it classifies as the license per package and drops the rest. That recovers five files, including the three golang.org/x PATENTS files and the LICENSE.libyaml that sigs.k8s.io/yaml/goyaml.v2 ships alongside its Apache-2.0 LICENSE. hack/license-overrides.tsv corrects the License column where go-licenses under-reports it. Two packages ship a license document holding more than one license, so they read Apache-2.0 / MIT from the override. It is curated by hand rather than detected, because scanning license text cannot tell BSD-2-Clause from BSD-3-Clause and a wrong addition is worse than an omission. Generation fails if an override names a package no longer in the index, so it cannot rot unnoticed. third-party-notices-links.yaml re-verifies every URL weekly. Links are proven correct when written, but upstream can retag or archive a repository afterwards and no offline gate can see that. A version change now needs two commands, because a verified URL contains the version: make third-party-notices-urls # network make third-party-notices # offline Dependabot cannot do the first on its own; its bump job needs wiring, or a human runs it. That is the direct cost of requiring every link to be verified rather than derived. 'make test-tools' runs the new bash suites, 67 assertions across two files, and is part of CHECK_TARGETS so it runs in CI. Transient failures fetching a license blob are retried. go.googlesource.com returns 503 and 429 under the per-file loop this drives, and the fail-closed gate would otherwise treat a rate-limited response as link rot; the weekly link check drives the same loop. A 404 still fails on the first request, so a real miss costs one request per candidate. fetch_retry moves into license-url-lib.sh as http_fetch_to_file so both resolvers share one retry and status policy, and it writes to a file because command substitution strips the trailing newline that a license file's sha256 depends on. Signed-off-by: Abrar Shivani --- .../workflows/third-party-notices-check.yaml | 7 + .../workflows/third-party-notices-links.yaml | 60 +++ Makefile | 19 +- THIRD_PARTY_NOTICES.md | 369 ++++++++++++++---- hack/generate-third-party-notices.sh | 222 ++++++++--- hack/generate-third-party-notices_test.sh | 194 +++++++++ hack/license-overrides.tsv | 15 + hack/license-url-lib.sh | 199 ++++++++++ hack/license-url-lib_test.sh | 172 ++++++++ hack/license-urls.tsv | 52 +++ hack/module-repos.tsv | 45 +++ hack/resolve-module-repos.sh | 177 +++++++++ hack/test-helpers.sh | 45 +++ hack/verify-license-urls.sh | 241 ++++++++++++ 14 files changed, 1698 insertions(+), 119 deletions(-) create mode 100644 .github/workflows/third-party-notices-links.yaml create mode 100755 hack/generate-third-party-notices_test.sh create mode 100644 hack/license-overrides.tsv create mode 100755 hack/license-url-lib.sh create mode 100755 hack/license-url-lib_test.sh create mode 100644 hack/license-urls.tsv create mode 100644 hack/module-repos.tsv create mode 100755 hack/resolve-module-repos.sh create mode 100755 hack/test-helpers.sh create mode 100755 hack/verify-license-urls.sh diff --git a/.github/workflows/third-party-notices-check.yaml b/.github/workflows/third-party-notices-check.yaml index 4f46f56fd..5b1f45353 100644 --- a/.github/workflows/third-party-notices-check.yaml +++ b/.github/workflows/third-party-notices-check.yaml @@ -12,6 +12,13 @@ # See the License for the specific language governing permissions and # limitations under the License. +# Regenerates THIRD_PARTY_NOTICES.md and fails if it differs from the committed +# copy, so a dependency change cannot land without refreshed attribution. The +# generator also fails when a license file has no verified URL in +# hack/license-urls.tsv, which catches a bump that skipped +# 'make third-party-notices-urls'. Link rot is caught separately by +# third-party-notices-links.yaml. + name: Third-Party Notices on: diff --git a/.github/workflows/third-party-notices-links.yaml b/.github/workflows/third-party-notices-links.yaml new file mode 100644 index 000000000..255917831 --- /dev/null +++ b/.github/workflows/third-party-notices-links.yaml @@ -0,0 +1,60 @@ +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# Re-verifies every license URL against the vendored bytes. Links are proven +# correct when written, but upstream can retag, rename or archive a repository +# afterwards, and no offline gate can see that. This runs on a schedule rather +# than per pull request so link rot does not block unrelated work. + +name: Third-Party Notices Link Check + +on: + schedule: + - cron: '0 6 * * 1' + workflow_dispatch: + +permissions: + contents: read + +jobs: + verify-links: + name: Re-verify license URLs against upstream + runs-on: ubuntu-latest + timeout-minutes: 45 + steps: + - uses: actions/checkout@v6 + name: Check out code + + - name: Get Golang version + id: vars + run: | + echo "GOLANG_VERSION=$(./hack/golang-version.sh)" >> "$GITHUB_ENV" + + - name: Install Go + uses: actions/setup-go@v7 + with: + go-version: ${{ env.GOLANG_VERSION }} + + - name: Re-verify every license URL + env: + URLS_OUTPUT: /tmp/license-urls-fresh.tsv + run: make bin/go-licenses && bash hack/verify-license-urls.sh + + - name: Compare against the committed map + run: | + if ! diff -u <(LC_ALL=C grep -v '^#' hack/license-urls.tsv) \ + <(LC_ALL=C grep -v '^#' /tmp/license-urls-fresh.tsv); then + echo "::error::A license URL no longer serves the vendored bytes. Upstream may have retagged or moved." + exit 1 + fi diff --git a/Makefile b/Makefile index f5781ca09..5b08be528 100644 --- a/Makefile +++ b/Makefile @@ -38,8 +38,8 @@ EXAMPLE_TARGETS := $(patsubst %,example-%, $(EXAMPLES)) CMDS := $(patsubst ./cmd/%/,%,$(sort $(dir $(wildcard ./cmd/*/)))) CMD_TARGETS := $(patsubst %,cmd-%, $(CMDS)) -CHECK_TARGETS := lint -MAKE_TARGETS := binaries build check fmt test examples cmds coverage generate licenses third-party-notices check-third-party-notices vendor check-vendor $(CHECK_TARGETS) +CHECK_TARGETS := lint test-tools +MAKE_TARGETS := binaries build check fmt test examples cmds coverage generate licenses third-party-notices check-third-party-notices third-party-notices-repos third-party-notices-urls vendor check-vendor $(CHECK_TARGETS) TARGETS := $(MAKE_TARGETS) $(EXAMPLE_TARGETS) $(CMD_TARGETS) @@ -135,6 +135,21 @@ check-third-party-notices: third-party-notices @git diff --exit-code HEAD -- THIRD_PARTY_NOTICES.md \ || { echo "ERROR: THIRD_PARTY_NOTICES.md is stale. Run 'make third-party-notices' and commit the change."; exit 1; } +# Needs network. Rarely run: keyed by module, so a version bump does not +# invalidate it. Only a new dependency does. +third-party-notices-repos: + @bash hack/resolve-module-repos.sh + +# Needs network. Every URL is content-verified against the vendored copy before +# it is written, so re-run this whenever a dependency version changes. +third-party-notices-urls: bin/go-licenses third-party-notices-repos + @bash hack/verify-license-urls.sh + +test-tools: + @for t in hack/*_test.sh; do \ + bash "$$t" || exit 1; \ + done + COVERAGE_FILE := coverage.out test: build cmds go test -coverprofile=$(COVERAGE_FILE).with-mocks $(MODULE)/... diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md index 5cdb06420..22321c59a 100644 --- a/THIRD_PARTY_NOTICES.md +++ b/THIRD_PARTY_NOTICES.md @@ -12,6 +12,13 @@ and `nvidia-cdi-hook` commands ship in the deb and rpm packages. The Go standard library packages are excluded; they are covered by the license of the Go distribution itself. +Each dependency is listed with the version redistributed and a link to the +license file in that version's upstream source. Every link was verified by +fetching it and comparing its contents against the copy vendored here, so each +one resolves to the same license text reproduced below. Modules that no command +under `cmd/` links are not listed; those are vendored only for this module's own +tests and build tooling. + The `container-toolkit` image uses `nvcr.io/nvidia/distroless/go` as a base image. All of the OSS packages and source included in this image can be found at https://developer.nvidia.com/w/distroless-oss/index.html. A statically compiled @@ -19,51 +26,53 @@ busybox binary is added to the image, which is licensed under GPLv2. ## Go Module Index -| Package | License | Dependency | -|---------|---------|------------| -| `github.com/Masterminds/semver/v3` | MIT | `github.com/Masterminds/semver/v3` | -| `github.com/NVIDIA/go-nvlib/pkg` | Apache-2.0 | `github.com/NVIDIA/go-nvlib` | -| `github.com/NVIDIA/go-nvml/pkg` | Apache-2.0 | `github.com/NVIDIA/go-nvml` | -| `github.com/containerd/log` | Apache-2.0 | `github.com/containerd/log` | -| `github.com/containerd/nri/pkg` | Apache-2.0 | `github.com/containerd/nri` | -| `github.com/containerd/ttrpc` | Apache-2.0 | `github.com/containerd/ttrpc` | -| `github.com/cyphar/filepath-securejoin` | BSD-3-Clause / MPL-2.0 | `github.com/cyphar/filepath-securejoin` | -| `github.com/fsnotify/fsnotify` | BSD-3-Clause | `github.com/fsnotify/fsnotify` | -| `github.com/google/uuid` | BSD-3-Clause | `github.com/google/uuid` | -| `github.com/knqyf263/go-plugin/wasm` | MIT | `github.com/knqyf263/go-plugin` | -| `github.com/moby/sys/capability` | BSD-2-Clause | `github.com/moby/sys/capability` | -| `github.com/moby/sys/mountinfo` | Apache-2.0 | `github.com/moby/sys/mountinfo` | -| `github.com/moby/sys/reexec` | Apache-2.0 | `github.com/moby/sys/reexec` | -| `github.com/opencontainers/cgroups/devices/config` | Apache-2.0 | `github.com/opencontainers/cgroups` | -| `github.com/opencontainers/runc` | Apache-2.0 | `github.com/opencontainers/runc` | -| `github.com/opencontainers/runtime-spec/specs-go` | Apache-2.0 | `github.com/opencontainers/runtime-spec` | -| `github.com/opencontainers/runtime-tools` | Apache-2.0 | `github.com/opencontainers/runtime-tools` | -| `github.com/pelletier/go-toml` | Apache-2.0 / MIT | `github.com/pelletier/go-toml` | -| `github.com/prometheus/procfs` | Apache-2.0 | `github.com/prometheus/procfs` | -| `github.com/sirupsen/logrus` | MIT | `github.com/sirupsen/logrus` | -| `github.com/tetratelabs/wazero` | Apache-2.0 | `github.com/tetratelabs/wazero` | -| `github.com/urfave/cli-altsrc/v3` | MIT | `github.com/urfave/cli-altsrc/v3` | -| `github.com/urfave/cli/v3` | MIT | `github.com/urfave/cli/v3` | -| `golang.org/x/mod/semver` | BSD-3-Clause | `golang.org/x/mod` | -| `golang.org/x/sys` | BSD-3-Clause | `golang.org/x/sys` | -| `google.golang.org/genproto/googleapis/rpc/status` | Apache-2.0 | `google.golang.org/genproto/googleapis/rpc` | -| `google.golang.org/grpc` | Apache-2.0 | `google.golang.org/grpc` | -| `google.golang.org/protobuf` | BSD-3-Clause | `google.golang.org/protobuf` | -| `gopkg.in/yaml.v3` | MIT | `gopkg.in/yaml.v3` | -| `sigs.k8s.io/yaml` | Apache-2.0 / BSD-3-Clause / MIT | `sigs.k8s.io/yaml` | -| `sigs.k8s.io/yaml/goyaml.v2` | Apache-2.0 | `sigs.k8s.io/yaml` | -| `tags.cncf.io/container-device-interface` | Apache-2.0 | `tags.cncf.io/container-device-interface` | -| `tags.cncf.io/container-device-interface/specs-go` | Apache-2.0 | `tags.cncf.io/container-device-interface/specs-go` | +| Package | Version | License | Location | +|---------|---------|---------|----------| +| `github.com/Masterminds/semver/v3` | v3.5.0 | MIT | [LICENSE.txt](https://github.com/Masterminds/semver/blob/v3.5.0/LICENSE.txt) | +| `github.com/NVIDIA/go-nvlib/pkg` | v0.12.0 | Apache-2.0 | [LICENSE](https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/LICENSE) / [NOTICE](https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/NOTICE) | +| `github.com/NVIDIA/go-nvml/pkg` | v0.13.3-1 | Apache-2.0 | [LICENSE](https://github.com/NVIDIA/go-nvml/blob/v0.13.3-1/LICENSE) | +| `github.com/containerd/log` | v0.1.0 | Apache-2.0 | [LICENSE](https://github.com/containerd/log/blob/v0.1.0/LICENSE) | +| `github.com/containerd/nri/pkg` | v0.12.1 | Apache-2.0 | [LICENSE](https://github.com/containerd/nri/blob/v0.12.1/LICENSE) | +| `github.com/containerd/ttrpc` | v1.2.7 | Apache-2.0 | [LICENSE](https://github.com/containerd/ttrpc/blob/v1.2.7/LICENSE) | +| `github.com/cyphar/filepath-securejoin` | v0.7.0 | BSD-3-Clause / MPL-2.0 | [COPYING.md](https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/COPYING.md) / [LICENSE.BSD](https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/LICENSE.BSD) / [LICENSE.MPL-2.0](https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/LICENSE.MPL-2.0) | +| `github.com/fsnotify/fsnotify` | v1.7.0 | BSD-3-Clause | [LICENSE](https://github.com/fsnotify/fsnotify/blob/v1.7.0/LICENSE) | +| `github.com/google/uuid` | v1.6.0 | BSD-3-Clause | [LICENSE](https://github.com/google/uuid/blob/v1.6.0/LICENSE) | +| `github.com/knqyf263/go-plugin/wasm` | v0.9.0 | MIT | [LICENSE](https://github.com/knqyf263/go-plugin/blob/v0.9.0/LICENSE) | +| `github.com/moby/sys/capability` | v0.4.0 | BSD-2-Clause | [LICENSE](https://github.com/moby/sys/blob/capability/v0.4.0/capability/LICENSE) | +| `github.com/moby/sys/mountinfo` | v0.7.2 | Apache-2.0 | [LICENSE](https://github.com/moby/sys/blob/mountinfo/v0.7.2/LICENSE) | +| `github.com/moby/sys/reexec` | v0.1.0 | Apache-2.0 | [LICENSE](https://github.com/moby/sys/blob/reexec/v0.1.0/LICENSE) | +| `github.com/opencontainers/cgroups/devices/config` | v0.0.7 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/cgroups/blob/v0.0.7/LICENSE) | +| `github.com/opencontainers/runc` | v1.4.3 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runc/blob/v1.4.3/LICENSE) / [NOTICE](https://github.com/opencontainers/runc/blob/v1.4.3/NOTICE) | +| `github.com/opencontainers/runtime-spec/specs-go` | v1.3.0 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runtime-spec/blob/v1.3.0/LICENSE) | +| `github.com/opencontainers/runtime-tools` | v0.9.1-0.20251114084447-edf4cb3d2116 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runtime-tools/blob/edf4cb3d2116/LICENSE) | +| `github.com/pelletier/go-toml` | v1.9.5 | Apache-2.0 / MIT | [LICENSE](https://github.com/pelletier/go-toml/blob/v1.9.5/LICENSE) | +| `github.com/prometheus/procfs` | v0.21.1 | Apache-2.0 | [LICENSE](https://github.com/prometheus/procfs/blob/v0.21.1/LICENSE) / [NOTICE](https://github.com/prometheus/procfs/blob/v0.21.1/NOTICE) | +| `github.com/sirupsen/logrus` | v1.9.4 | MIT | [LICENSE](https://github.com/sirupsen/logrus/blob/v1.9.4/LICENSE) | +| `github.com/tetratelabs/wazero` | v1.11.0 | Apache-2.0 | [LICENSE](https://github.com/tetratelabs/wazero/blob/v1.11.0/LICENSE) / [NOTICE](https://github.com/tetratelabs/wazero/blob/v1.11.0/NOTICE) | +| `github.com/urfave/cli-altsrc/v3` | v3.1.0 | MIT | [LICENSE](https://github.com/urfave/cli-altsrc/blob/v3.1.0/LICENSE) | +| `github.com/urfave/cli/v3` | v3.10.1 | MIT | [LICENSE](https://github.com/urfave/cli/blob/v3.10.1/LICENSE) | +| `golang.org/x/mod/semver` | v0.38.0 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/mod/+/refs/tags/v0.38.0/LICENSE) / [PATENTS](https://go.googlesource.com/mod/+/refs/tags/v0.38.0/PATENTS) | +| `golang.org/x/sys` | v0.47.0 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE) / [PATENTS](https://go.googlesource.com/sys/+/refs/tags/v0.47.0/PATENTS) | +| `google.golang.org/genproto/googleapis/rpc/status` | v0.0.0-20260414002931-afd174a4e478 | Apache-2.0 | [LICENSE](https://github.com/googleapis/go-genproto/blob/afd174a4e478/LICENSE) | +| `google.golang.org/grpc` | v1.82.1 | Apache-2.0 | [AUTHORS](https://github.com/grpc/grpc-go/blob/v1.82.1/AUTHORS) / [LICENSE](https://github.com/grpc/grpc-go/blob/v1.82.1/LICENSE) / [NOTICE.txt](https://github.com/grpc/grpc-go/blob/v1.82.1/NOTICE.txt) | +| `google.golang.org/protobuf` | v1.36.11 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/LICENSE) / [PATENTS](https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/PATENTS) | +| `gopkg.in/yaml.v3` | v3.0.1 | Apache-2.0 / MIT | [LICENSE](https://github.com/go-yaml/yaml/blob/v3.0.1/LICENSE) / [NOTICE](https://github.com/go-yaml/yaml/blob/v3.0.1/NOTICE) | +| `sigs.k8s.io/yaml` | v1.4.0 | Apache-2.0 / BSD-3-Clause / MIT | [LICENSE](https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/LICENSE) | +| `sigs.k8s.io/yaml/goyaml.v2` | v1.4.0 | Apache-2.0 / MIT | [LICENSE](https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/LICENSE) / [LICENSE.libyaml](https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/LICENSE.libyaml) / [NOTICE](https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/NOTICE) | +| `tags.cncf.io/container-device-interface` | v1.1.0 | Apache-2.0 | [LICENSE](https://github.com/cncf-tags/container-device-interface/blob/v1.1.0/LICENSE) | +| `tags.cncf.io/container-device-interface/specs-go` | v1.1.0 | Apache-2.0 | [LICENSE](https://github.com/cncf-tags/container-device-interface/blob/specs-go/v1.1.0/LICENSE) | ## Go Module License Texts ### github.com/Masterminds/semver/v3 +* Version: v3.5.0 * License: MIT -* Module: github.com/Masterminds/semver/v3 #### LICENSE.txt + + ```text Copyright (C) 2014-2019, Matt Butcher and Matt Farina @@ -90,11 +99,13 @@ THE SOFTWARE. ### github.com/NVIDIA/go-nvlib/pkg +* Version: v0.12.0 * License: Apache-2.0 -* Module: github.com/NVIDIA/go-nvlib #### LICENSE + + ```text Apache License @@ -303,6 +314,8 @@ THE SOFTWARE. #### NOTICE + + ```text The file pkg/pciids/default_pci.ids is distributed under the 3-clause BSD License. Maintained by Albert Pool, Martin Mares, and other volunteers from @@ -314,11 +327,13 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ### github.com/NVIDIA/go-nvml/pkg +* Version: v0.13.3-1 * License: Apache-2.0 -* Module: github.com/NVIDIA/go-nvml #### LICENSE + + ```text Apache License @@ -528,11 +543,13 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ### github.com/containerd/log +* Version: v0.1.0 * License: Apache-2.0 -* Module: github.com/containerd/log #### LICENSE + + ```text Apache License @@ -731,11 +748,13 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ### github.com/containerd/nri/pkg +* Version: v0.12.1 * License: Apache-2.0 -* Module: github.com/containerd/nri #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -944,11 +963,13 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ### github.com/containerd/ttrpc +* Version: v1.2.7 * License: Apache-2.0 -* Module: github.com/containerd/ttrpc #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -1157,11 +1178,13 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ### github.com/cyphar/filepath-securejoin +* Version: v0.7.0 * License: BSD-3-Clause / MPL-2.0 -* Module: github.com/cyphar/filepath-securejoin #### COPYING.md + + ````text ## COPYING ## @@ -1615,6 +1638,8 @@ Exhibit B - "Incompatible With Secondary Licenses" Notice #### LICENSE.BSD + + ```text Copyright (C) 2014-2015 Docker Inc & Go Authors. All rights reserved. Copyright (C) 2017-2024 SUSE LLC. All rights reserved. @@ -1649,6 +1674,8 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. #### LICENSE.MPL-2.0 + + ```text Mozilla Public License Version 2.0 ================================== @@ -2029,11 +2056,13 @@ Exhibit B - "Incompatible With Secondary Licenses" Notice ### github.com/fsnotify/fsnotify +* Version: v1.7.0 * License: BSD-3-Clause -* Module: github.com/fsnotify/fsnotify #### LICENSE + + ```text Copyright © 2012 The Go Authors. All rights reserved. Copyright © fsnotify Authors. All rights reserved. @@ -2066,11 +2095,13 @@ SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/google/uuid +* Version: v1.6.0 * License: BSD-3-Clause -* Module: github.com/google/uuid #### LICENSE + + ```text Copyright (c) 2009,2014 Google Inc. All rights reserved. @@ -2105,11 +2136,13 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/knqyf263/go-plugin/wasm +* Version: v0.9.0 * License: MIT -* Module: github.com/knqyf263/go-plugin #### LICENSE + + ```text MIT License @@ -2138,11 +2171,13 @@ SOFTWARE. ### github.com/moby/sys/capability +* Version: v0.4.0 * License: BSD-2-Clause -* Module: github.com/moby/sys/capability #### LICENSE + + ```text Copyright 2023 The Capability Authors. Copyright 2013 Suryandaru Triandana @@ -2175,11 +2210,13 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/moby/sys/mountinfo +* Version: v0.7.2 * License: Apache-2.0 -* Module: github.com/moby/sys/mountinfo #### LICENSE + + ```text Apache License @@ -2389,11 +2426,13 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/moby/sys/reexec +* Version: v0.1.0 * License: Apache-2.0 -* Module: github.com/moby/sys/reexec #### LICENSE + + ```text Apache License @@ -2603,11 +2642,13 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/opencontainers/cgroups/devices/config +* Version: v0.0.7 * License: Apache-2.0 -* Module: github.com/opencontainers/cgroups #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -2816,11 +2857,13 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### github.com/opencontainers/runc +* Version: v1.4.3 * License: Apache-2.0 -* Module: github.com/opencontainers/runc #### LICENSE + + ```text Apache License @@ -3018,6 +3061,8 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. #### NOTICE + + ```text runc @@ -3042,11 +3087,13 @@ See also http://www.apache.org/dev/crypto.html and/or seek legal counsel. ### github.com/opencontainers/runtime-spec/specs-go +* Version: v1.3.0 * License: Apache-2.0 -* Module: github.com/opencontainers/runtime-spec #### LICENSE + + ```text Apache License @@ -3245,11 +3292,13 @@ See also http://www.apache.org/dev/crypto.html and/or seek legal counsel. ### github.com/opencontainers/runtime-tools +* Version: v0.9.1-0.20251114084447-edf4cb3d2116 * License: Apache-2.0 -* Module: github.com/opencontainers/runtime-tools #### LICENSE + + ```text Apache License @@ -3448,11 +3497,13 @@ See also http://www.apache.org/dev/crypto.html and/or seek legal counsel. ### github.com/pelletier/go-toml +* Version: v1.9.5 * License: Apache-2.0 / MIT -* Module: github.com/pelletier/go-toml #### LICENSE + + ```text The bulk of github.com/pelletier/go-toml is distributed under the MIT license (see below), with the exception of localtime.go and localtime.test.go. @@ -3707,11 +3758,13 @@ License: ### github.com/prometheus/procfs +* Version: v0.21.1 * License: Apache-2.0 -* Module: github.com/prometheus/procfs #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -3919,6 +3972,8 @@ License: #### NOTICE + + ```text procfs provides functions to retrieve system, kernel and process metrics from the pseudo-filesystem proc. @@ -3933,11 +3988,13 @@ SoundCloud Ltd. (http://soundcloud.com/). ### github.com/sirupsen/logrus +* Version: v1.9.4 * License: MIT -* Module: github.com/sirupsen/logrus #### LICENSE + + ```text The MIT License (MIT) @@ -3966,11 +4023,13 @@ THE SOFTWARE. ### github.com/tetratelabs/wazero +* Version: v1.11.0 * License: Apache-2.0 -* Module: github.com/tetratelabs/wazero #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -4178,6 +4237,8 @@ THE SOFTWARE. #### NOTICE + + ```text wazero Copyright 2020-2023 wazero authors @@ -4187,11 +4248,13 @@ Copyright 2020-2023 wazero authors ### github.com/urfave/cli-altsrc/v3 +* Version: v3.1.0 * License: MIT -* Module: github.com/urfave/cli-altsrc/v3 #### LICENSE + + ```text MIT License @@ -4220,11 +4283,13 @@ SOFTWARE. ### github.com/urfave/cli/v3 +* Version: v3.10.1 * License: MIT -* Module: github.com/urfave/cli/v3 #### LICENSE + + ```text MIT License @@ -4253,11 +4318,13 @@ SOFTWARE. ### golang.org/x/mod/semver +* Version: v0.38.0 * License: BSD-3-Clause -* Module: golang.org/x/mod #### LICENSE + + ```text Copyright 2009 The Go Authors. @@ -4289,14 +4356,46 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ``` +#### PATENTS + + + +```text +Additional IP Rights Grant (Patents) + +"This implementation" means the copyrightable works distributed by +Google as part of the Go project. + +Google hereby grants to You a perpetual, worldwide, non-exclusive, +no-charge, royalty-free, irrevocable (except as stated in this section) +patent license to make, have made, use, offer to sell, sell, import, +transfer and otherwise run, modify and propagate the contents of this +implementation of Go, where such license applies only to those patent +claims, both currently owned or controlled by Google and acquired in +the future, licensable by Google that are necessarily infringed by this +implementation of Go. This grant does not include claims that would be +infringed only as a consequence of further modification of this +implementation. If you or your agent or exclusive licensee institute or +order or agree to the institution of patent litigation against any +entity (including a cross-claim or counterclaim in a lawsuit) alleging +that this implementation of Go or any code incorporated within this +implementation of Go constitutes direct or contributory patent +infringement, or inducement of patent infringement, then any patent +rights granted to you under this License for this implementation of Go +shall terminate as of the date such litigation is filed. + +``` + ### golang.org/x/sys +* Version: v0.47.0 * License: BSD-3-Clause -* Module: golang.org/x/sys #### LICENSE + + ```text Copyright 2009 The Go Authors. @@ -4328,14 +4427,46 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ``` +#### PATENTS + + + +```text +Additional IP Rights Grant (Patents) + +"This implementation" means the copyrightable works distributed by +Google as part of the Go project. + +Google hereby grants to You a perpetual, worldwide, non-exclusive, +no-charge, royalty-free, irrevocable (except as stated in this section) +patent license to make, have made, use, offer to sell, sell, import, +transfer and otherwise run, modify and propagate the contents of this +implementation of Go, where such license applies only to those patent +claims, both currently owned or controlled by Google and acquired in +the future, licensable by Google that are necessarily infringed by this +implementation of Go. This grant does not include claims that would be +infringed only as a consequence of further modification of this +implementation. If you or your agent or exclusive licensee institute or +order or agree to the institution of patent litigation against any +entity (including a cross-claim or counterclaim in a lawsuit) alleging +that this implementation of Go or any code incorporated within this +implementation of Go constitutes direct or contributory patent +infringement, or inducement of patent infringement, then any patent +rights granted to you under this License for this implementation of Go +shall terminate as of the date such litigation is filed. + +``` + ### google.golang.org/genproto/googleapis/rpc/status +* Version: v0.0.0-20260414002931-afd174a4e478 * License: Apache-2.0 -* Module: google.golang.org/genproto/googleapis/rpc #### LICENSE + + ```text Apache License @@ -4545,11 +4676,22 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ### google.golang.org/grpc +* Version: v1.82.1 * License: Apache-2.0 -* Module: google.golang.org/grpc + +#### AUTHORS + + + +```text +Google Inc. + +``` #### LICENSE + + ```text Apache License @@ -4758,6 +4900,8 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. #### NOTICE.txt + + ```text Copyright 2014 gRPC authors. @@ -4778,11 +4922,13 @@ limitations under the License. ### google.golang.org/protobuf +* Version: v1.36.11 * License: BSD-3-Clause -* Module: google.golang.org/protobuf #### LICENSE + + ```text Copyright (c) 2018 The Go Authors. All rights reserved. @@ -4814,14 +4960,46 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ``` +#### PATENTS + + + +```text +Additional IP Rights Grant (Patents) + +"This implementation" means the copyrightable works distributed by +Google as part of the Go project. + +Google hereby grants to You a perpetual, worldwide, non-exclusive, +no-charge, royalty-free, irrevocable (except as stated in this section) +patent license to make, have made, use, offer to sell, sell, import, +transfer and otherwise run, modify and propagate the contents of this +implementation of Go, where such license applies only to those patent +claims, both currently owned or controlled by Google and acquired in +the future, licensable by Google that are necessarily infringed by this +implementation of Go. This grant does not include claims that would be +infringed only as a consequence of further modification of this +implementation. If you or your agent or exclusive licensee institute or +order or agree to the institution of patent litigation against any +entity (including a cross-claim or counterclaim in a lawsuit) alleging +that this implementation of Go or any code incorporated within this +implementation of Go constitutes direct or contributory patent +infringement, or inducement of patent infringement, then any patent +rights granted to you under this License for this implementation of Go +shall terminate as of the date such litigation is filed. + +``` + ### gopkg.in/yaml.v3 -* License: MIT -* Module: gopkg.in/yaml.v3 +* Version: v3.0.1 +* License: Apache-2.0 / MIT #### LICENSE + + ```text This project is covered by two different licenses: MIT and Apache. @@ -4878,6 +5056,8 @@ limitations under the License. #### NOTICE + + ```text Copyright 2011-2016 Canonical Ltd. @@ -4898,11 +5078,13 @@ limitations under the License. ### sigs.k8s.io/yaml +* Version: v1.4.0 * License: Apache-2.0 / BSD-3-Clause / MIT -* Module: sigs.k8s.io/yaml #### LICENSE + + ```text The MIT License (MIT) @@ -5216,11 +5398,13 @@ Apache license: ### sigs.k8s.io/yaml/goyaml.v2 -* License: Apache-2.0 -* Module: sigs.k8s.io/yaml +* Version: v1.4.0 +* License: Apache-2.0 / MIT #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -5426,8 +5610,49 @@ Apache license: ``` +#### LICENSE.libyaml + + + +```text +The following files were ported to Go from C files of libyaml, and thus +are still covered by their original copyright and license: + + apic.go + emitterc.go + parserc.go + readerc.go + scannerc.go + writerc.go + yamlh.go + yamlprivateh.go + +Copyright (c) 2006 Kirill Simonov + +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies +of the Software, and to permit persons to whom the Software is furnished to do +so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +``` + #### NOTICE + + ```text Copyright 2011-2016 Canonical Ltd. @@ -5448,11 +5673,13 @@ limitations under the License. ### tags.cncf.io/container-device-interface +* Version: v1.1.0 * License: Apache-2.0 -* Module: tags.cncf.io/container-device-interface #### LICENSE + + ```text Apache License Version 2.0, January 2004 @@ -5661,11 +5888,13 @@ limitations under the License. ### tags.cncf.io/container-device-interface/specs-go +* Version: v1.1.0 * License: Apache-2.0 -* Module: tags.cncf.io/container-device-interface/specs-go #### LICENSE + + ```text Apache License Version 2.0, January 2004 diff --git a/hack/generate-third-party-notices.sh b/hack/generate-third-party-notices.sh index 9b5ddb809..7d4a74bcd 100755 --- a/hack/generate-third-party-notices.sh +++ b/hack/generate-third-party-notices.sh @@ -52,14 +52,14 @@ log() { # Licenses that are themselves Markdown close a fixed ``` fence early and invert # every block after it, so open with one backtick more than the file's longest run. fence_for() { - local file="$1" longest width + local file="$1" longest_backtick_run fence_width # -a: a license containing a NUL byte is otherwise treated as binary and # grep prints "Binary file ... matches" rather than the matches themselves. - longest=$(LC_ALL=C grep -oaE '`+' "${file}" 2>/dev/null \ - | awk '{ if (length($0) > m) m = length($0) } END { print m+0 }') - width=$(( longest + 1 )) - (( width < 3 )) && width=3 - printf '%*s' "${width}" '' | tr ' ' '`' + longest_backtick_run=$(LC_ALL=C grep -oaE '`+' "${file}" 2>/dev/null \ + | awk '{ if (length($0) > m) m = length($0) } END { print m+0 }' || true) + fence_width=$(( longest_backtick_run + 1 )) + (( fence_width < 3 )) && fence_width=3 + printf '%*s' "${fence_width}" '' | tr ' ' '`' } check_prerequisites() { @@ -75,9 +75,10 @@ check_prerequisites() { die "go-licenses is not installed." "Install it with 'make bin/go-licenses'." fi - local f - for f in "${MULTI_ARCH_MK}" "${MODULES_TXT}"; do - [[ -f "${f}" ]] || die "${f} not found — run 'make third-party-notices' from the repo root." + local required_file + for required_file in "${MULTI_ARCH_MK}" "${MODULES_TXT}" "${LICENSE_OVERRIDES}"; do + [[ -f "${required_file}" ]] \ + || die "${required_file} not found — run 'make third-party-notices' from the repo root." done LOCAL_MODULE=$(go list -m 2>/dev/null || true) @@ -115,10 +116,10 @@ prepare_workspace() { rm -rf "${LICENSES_DIR}" mkdir -p "${LICENSES_DIR}" - local t="${TMPDIR:-/tmp}/nvidia-container-toolkit-notices" - SAVE_ROOT="$(mktemp -d "${t}.XXXXXX")" - COMBINED_CSV="$(mktemp "${t}-csv.XXXXXX")" - INDEX_FILE="$(mktemp "${t}-idx.XXXXXX")" + local workspace_template="${TMPDIR:-/tmp}/nvidia-container-toolkit-notices" + SAVE_ROOT="$(mktemp -d "${workspace_template}.XXXXXX")" + COMBINED_CSV="$(mktemp "${workspace_template}-csv.XXXXXX")" + INDEX_FILE="$(mktemp "${workspace_template}-idx.XXXXXX")" # Composed next to OUTPUT, not in TMPDIR, so the publish below is a rename. local out_dir @@ -181,10 +182,10 @@ collapse_index() { ' } -# Rows carry module names, not a URL: in vendor mode go-licenses points into -# this repo at HEAD, which stops describing released content once main moves. -# Versions are intentionally omitted because the notices identify dependencies -# and their licenses, not an exact build. Longest-prefix match, because a +# Rows carry the module path and version, not a URL: in vendor mode go-licenses +# points into this repo at HEAD, which stops describing released content once +# main moves and names our copy rather than upstream. The verified upstream +# location comes from hack/license-urls.tsv. Longest-prefix match, because a # license may sit below the module root. annotate_modules() { awk -v modfile="${MODULES_TXT}" ' @@ -205,9 +206,11 @@ annotate_modules() { } mods[++m] = f[2] disp[f[2]] = f[r] + ver[f[2]] = f[r + 1] } else { mods[++m] = f[2] disp[f[2]] = f[2] + ver[f[2]] = f[3] } } close(modfile) @@ -223,7 +226,7 @@ annotate_modules() { mp = mods[i] if (($1 == mp || index($1, mp "/") == 1) && length(mp) > length(best)) best = mp } - print $0, (best == "" ? "unknown" : disp[best]) + print $0, (best == "" ? "unknown" : disp[best]), (best == "" ? "unknown" : ver[best]) } ' } @@ -240,63 +243,176 @@ build_indexes() { "Re-run 'make vendor' first; if it persists, fix annotate_modules in hack/generate-third-party-notices.sh." fi + if cut -d, -f5 "${INDEX_FILE}" | LC_ALL=C grep -qx 'unknown'; then + die "some runtime packages could not be matched to a version in ${MODULES_TXT}." \ + "Re-run 'make vendor' first; if it persists, fix annotate_modules in hack/generate-third-party-notices.sh." + fi + # An unclassifiable license is reported as "Unknown" with a zero exit, so # without this an entry that attributes nothing would ship. if cut -d, -f3 "${INDEX_FILE}" | LC_ALL=C grep -qE '(^| / )Unknown( / |$)'; then die "go-licenses could not identify a license for some dependencies." \ "Check the entries reported as Unknown before committing the file." fi + + check_override_coverage "${INDEX_FILE}" +} + +# A dropped dependency would otherwise leave its row in LICENSE_OVERRIDES +# silently asserting a license for a package no longer shipped. +check_override_coverage() { + local index="$1" override_package + while IFS=$'\t' read -r override_package _ _; do + case "${override_package}" in + ''|'#'*) continue ;; + esac + LC_ALL=C cut -d, -f1 "${index}" | LC_ALL=C grep -qFx "${override_package}" \ + || die "${LICENSE_OVERRIDES} has a row for ${override_package}, which is not in the generated index." \ + "Remove that row from ${LICENSE_OVERRIDES} — the dependency was likely dropped." + done < "${LICENSE_OVERRIDES}" } # Filter by name: for restricted licenses 'go-licenses save' copies the whole # module source. license_files_for() { - local dir="$1" f - [[ -d "${dir}" ]] || return 0 - while IFS= read -r -d '' f; do - if printf '%s' "$(basename "${f}")" \ + local search_dir="$1" license_file file_basename + [[ -d "${search_dir}" ]] || return 0 + while IFS= read -r -d '' license_file; do + file_basename="$(basename "${license_file}")" + # Exclude source files: the name pattern below also matches source files + # that merely open with a license-shaped header, e.g. a Go file named + # license.go beginning "// Copyright ...". + case "${file_basename}" in + *.go|*.c|*.h|*.s|*.py|*.sh|*.java|*.ts|*.js) continue ;; + esac + if printf '%s' "${file_basename}" \ | LC_ALL=C grep -qiE '^(licen[cs]e|notice|copying|copyright|authors|patents)([-._].*)?$'; then - printf '%s\n' "${f}" + printf '%s\n' "${license_file}" fi - done < <(find "${dir}" -maxdepth 1 -type f -print0 2>/dev/null | LC_ALL=C sort -z) + done < <(find "${search_dir}" -maxdepth 1 -type f -print0 2>/dev/null | LC_ALL=C sort -z) } -emit_index_table() { - local index="$1" pkg _url license module - printf '| Package | License | Dependency |\n' - printf '|---------|---------|------------|\n' +LICENSE_URLS="${LICENSE_URLS:-hack/license-urls.tsv}" +LICENSE_OVERRIDES="${LICENSE_OVERRIDES:-hack/license-overrides.tsv}" +VENDOR_DIR="${VENDOR_DIR:-vendor}" + +# Separate from check_prerequisites: hack/verify-license-urls.sh reuses the +# collection stages to discover which license files the document will link, and +# it is the command that produces this map, so it must run without it. +require_url_map() { + [[ -f "${LICENSE_URLS}" ]] \ + || die "${LICENSE_URLS} not found." \ + "Run 'make third-party-notices-urls' (needs network) and commit the result." +} - while IFS=, read -r pkg _url license module; do - [[ -z "${pkg}" ]] && continue +# A single license file can bundle more than one license, which go-licenses +# reports as whichever one it scores highest; LICENSE_OVERRIDES corrects the +# identifier by hand without touching the license text, which is unaffected. +license_identifier_for() { + local package="$1" default_identifier="$2" override_identifier + override_identifier="$(LC_ALL=C awk -F'\t' -v pkg="${package}" \ + '$1 == pkg { print $2; exit }' "${LICENSE_OVERRIDES}")" + printf '%s' "${override_identifier:-${default_identifier}}" +} + +# The first enclosing directory holding a license file wins, which is how +# go-licenses attributes them. +license_dir_within_module() { + local module="$2" dir="$1" relative + while :; do + if [[ -n "$(license_files_for "${VENDOR_DIR}/${dir}")" ]]; then + relative="${dir#"${module}"}" + printf '%s' "${relative#/}" + return 0 + fi + [[ "${dir}" == "${module}" ]] && return 1 + [[ "${dir}" != */* ]] && return 1 + dir="${dir%/*}" + done +} + +location_for() { + local url + url="$(LC_ALL=C awk -F'\t' -v m="$1" -v v="$2" -v p="$3" \ + '$1 == m && $2 == v && $3 == p { print $4; found = 1; exit } + END { exit !found }' "${LICENSE_URLS}")" || return 1 + [[ -n "${url}" ]] || return 1 + printf '%s' "${url}" +} + +# Mirrors how the License column joins identifiers. +location_cell() { + local package="$1" module="$2" version="$3" + local relative_license_dir license_file_name license_path url cell="" license_file governing_dir + relative_license_dir="$(license_dir_within_module "${package}" "${module}")" \ + || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." \ + "Run 'make vendor' and re-run." + governing_dir="${VENDOR_DIR}/${module}${relative_license_dir:+/${relative_license_dir}}" + while IFS= read -r license_file; do + [[ -z "${license_file}" ]] && continue + license_file_name="$(basename "${license_file}")" + license_path="${relative_license_dir:+${relative_license_dir}/}${license_file_name}" + url="$(location_for "${module}" "${version}" "${license_path}")" \ + || die "${LICENSE_URLS} has no verified URL for ${module}@${version} ${license_path}." \ + "Run 'make third-party-notices-urls' (needs network) and commit the result." + cell="${cell:+${cell} / }[${license_file_name}](${url})" + done < <(license_files_for "${governing_dir}") + [[ -n "${cell}" ]] || die "no license file for ${package} under ${governing_dir}." \ + "Run 'make vendor' and re-run." + printf '%s' "${cell}" +} + +emit_index_table() { + local index="$1" package _url license module version location license_identifier + printf '| Package | Version | License | Location |\n' + printf '|---------|---------|---------|----------|\n' + + while IFS=, read -r package _url license module version; do + [[ -z "${package}" ]] && continue + location="$(location_cell "${package}" "${module}" "${version}")" + license_identifier="$(license_identifier_for "${package}" "${license:-Unknown}")" # shellcheck disable=SC2016 # backticks are literal markdown here. - printf '| `%s` | %s | `%s` |\n' "${pkg}" "${license:-Unknown}" "${module:-unknown}" + printf '| `%s` | %s | %s | %s |\n' \ + "${package}" "${version:-unknown}" \ + "${license_identifier}" "${location}" done < "${index}" } emit_sections() { - local index="$1" root="$2" - local pkg _url license module files lf fence + local index="$1" + local package _url license module version files license_file fence relative_license_dir license_file_name url governing_dir license_identifier - while IFS=, read -r pkg _url license module; do - [[ -z "${pkg}" ]] && continue + while IFS=, read -r package _url license module version; do + [[ -z "${package}" ]] && continue - printf '### %s\n\n' "${pkg}" - printf '* License: %s\n' "${license:-Unknown}" - printf '* Module: %s\n\n' "${module:-unknown}" + license_identifier="$(license_identifier_for "${package}" "${license:-Unknown}")" + printf '### %s\n\n' "${package}" + printf '* Version: %s\n' "${version:-unknown}" + printf '* License: %s\n\n' "${license_identifier}" + + relative_license_dir="$(license_dir_within_module "${package}" "${module}")" \ + || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." \ + "Run 'make vendor' and re-run." + governing_dir="${VENDOR_DIR}/${module}${relative_license_dir:+/${relative_license_dir}}" files=() - while IFS= read -r lf; do - [[ -n "${lf}" ]] && files+=("${lf}") - done < <(license_files_for "${root}/${pkg}") + while IFS= read -r license_file; do + [[ -n "${license_file}" ]] && files+=("${license_file}") + done < <(license_files_for "${governing_dir}") if (( ${#files[@]} == 0 )); then printf 'License text unavailable. See upstream source for the full license.\n' else - for lf in "${files[@]}"; do - fence="$(fence_for "${lf}")" - printf '#### %s\n\n' "$(basename "${lf}")" + for license_file in "${files[@]}"; do + license_file_name="$(basename "${license_file}")" + url="$(location_for "${module}" "${version}" "${relative_license_dir:+${relative_license_dir}/}${license_file_name}")" \ + || die "${LICENSE_URLS} has no verified URL for ${module}@${version} ${relative_license_dir:+${relative_license_dir}/}${license_file_name}." \ + "Run 'make third-party-notices-urls' (needs network) and commit the result." + fence="$(fence_for "${license_file}")" + printf '#### %s\n\n' "${license_file_name}" + printf '<%s>\n\n' "${url}" printf '%stext\n' "${fence}" - cat "${lf}" + cat "${license_file}" echo printf '%s\n' "${fence}" echo @@ -307,6 +423,7 @@ emit_sections() { } compose_document() { + require_url_map log "Composing ${OUTPUT}..." { cat <<'EOF' @@ -324,6 +441,13 @@ and `nvidia-cdi-hook` commands ship in the deb and rpm packages. The Go standard library packages are excluded; they are covered by the license of the Go distribution itself. +Each dependency is listed with the version redistributed and a link to the +license file in that version's upstream source. Every link was verified by +fetching it and comparing its contents against the copy vendored here, so each +one resolves to the same license text reproduced below. Modules that no command +under `cmd/` links are not listed; those are vendored only for this module's own +tests and build tooling. + The `container-toolkit` image uses `nvcr.io/nvidia/distroless/go` as a base image. All of the OSS packages and source included in this image can be found at https://developer.nvidia.com/w/distroless-oss/index.html. A statically compiled @@ -339,7 +463,7 @@ EOF ## Go Module License Texts EOF - emit_sections "${INDEX_FILE}" "${LICENSES_DIR}" + emit_sections "${INDEX_FILE}" } > "${OUT_TMP}" # mv, not cp: OUT_TMP is in OUTPUT's directory, so this is a rename(2) and @@ -362,4 +486,8 @@ main() { log "Wrote ${OUTPUT} (${runtime_count} Go packages)" } -main "$@" +# Sourced by the tests and by hack/verify-license-urls.sh, which reuse these +# functions without the side effects of a full run. +if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then + main "$@" +fi diff --git a/hack/generate-third-party-notices_test.sh b/hack/generate-third-party-notices_test.sh new file mode 100755 index 000000000..3e958881b --- /dev/null +++ b/hack/generate-third-party-notices_test.sh @@ -0,0 +1,194 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +set -uo pipefail + +HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +# shellcheck source=hack/test-helpers.sh disable=SC1091 +source "${HERE}/test-helpers.sh" + +# If the guard ever regresses, sourcing must not overwrite the committed +# notices file. OUTPUT is honoured by compose_document. +OUTPUT="$(mktemp)" +export OUTPUT + +# shellcheck source=hack/generate-third-party-notices.sh disable=SC1091 +source "${HERE}/generate-third-party-notices.sh" + +# If the guard is missing, sourcing runs the generator and exits before here. +assert_eq "sourced" "sourced" "sourcing the generator does not execute main" + +# Environment-independent: proves the guard is present rather than relying on +# main failing fast, which it only does on a host without go-licenses. +assert_eq "1" \ + "$(LC_ALL=C grep -c 'BASH_SOURCE\[0\]' "${HERE}/generate-third-party-notices.sh")" \ + "the generator guards main against running on source" + +fixture="$(mktemp)" +trap 'rm -f "${fixture}"' EXIT +printf 'plain text, no backticks\n' > "${fixture}" +assert_eq '```' "$(fence_for "${fixture}")" "fence_for: minimum width is three" +printf 'a ```` b\n' > "${fixture}" +assert_eq '`````' "$(fence_for "${fixture}")" "fence_for: one wider than the longest run" + +modules_fixture="$(mktemp)" +cat > "${modules_fixture}" <<'MODULES' +# sigs.k8s.io/yaml v1.4.0 +## explicit +# gopkg.in/yaml.v3 v3.0.1 +MODULES + +index_input="$(mktemp)" +cat > "${index_input}" <<'ROWS' +sigs.k8s.io/yaml,ignored,Apache-2.0 +sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0 +gopkg.in/yaml.v3,ignored,MIT +ROWS + +assert_eq "sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v1.4.0" \ + "$(MODULES_TXT="${modules_fixture}" annotate_modules < "${index_input}" | sed -n 2p)" \ + "annotate_modules appends module and version" +assert_eq "gopkg.in/yaml.v3,ignored,MIT,gopkg.in/yaml.v3,v3.0.1" \ + "$(MODULES_TXT="${modules_fixture}" annotate_modules < "${index_input}" | sed -n 3p)" \ + "annotate_modules resolves a root module" + +urls_fixture="$(mktemp)" +{ + printf 'sigs.k8s.io/yaml\tv1.4.0\tLICENSE\thttps://example.invalid/yaml\n' + printf 'sigs.k8s.io/yaml\tv1.4.0\tgoyaml.v2/LICENSE\thttps://example.invalid/goyaml-license\n' + printf 'sigs.k8s.io/yaml\tv1.4.0\tgoyaml.v2/LICENSE.libyaml\thttps://example.invalid/goyaml-libyaml\n' + printf 'gopkg.in/yaml.v3\tv3.0.1\tLICENSE\thttps://example.invalid/yaml-v3\n' +} > "${urls_fixture}" + +# No rows: exercises license_identifier_for's not-found path so the fixtures +# below that do not care about overrides are unaffected by them, without +# depending on the LICENSE_OVERRIDES default resolving from the test's cwd. +empty_overrides_fixture="$(mktemp)" +printf '# no overrides\n' > "${empty_overrides_fixture}" + +assert_eq "https://example.invalid/goyaml-license" \ + "$(LICENSE_URLS="${urls_fixture}" location_for \ + sigs.k8s.io/yaml v1.4.0 goyaml.v2/LICENSE)" \ + "location_for finds a nested license path" +# $1 is expanded by the child bash -c, not here. +# shellcheck disable=SC2016 +assert_fails "location_for fails closed on a miss" \ + env LICENSE_URLS="${urls_fixture}" bash -c \ + 'source "$1"; location_for github.com/nope v1.0.0 LICENSE' \ + _ "${HERE}/generate-third-party-notices.sh" + +license_files_fixture="$(mktemp -d)" +touch "${license_files_fixture}/LICENSE" "${license_files_fixture}/LICENSE.md" "${license_files_fixture}/license.go" +assert_eq "$(printf '%s/LICENSE\n%s/LICENSE.md' "${license_files_fixture}" "${license_files_fixture}")" \ + "$(license_files_for "${license_files_fixture}")" \ + "license_files_for excludes a Go source file even when its name matches" +rm -rf "${license_files_fixture}" + +vendor_fixture="$(mktemp -d)" +mkdir -p "${vendor_fixture}/sigs.k8s.io/yaml/goyaml.v2" +mkdir -p "${vendor_fixture}/gopkg.in/yaml.v3" +touch "${vendor_fixture}/sigs.k8s.io/yaml/LICENSE" +touch "${vendor_fixture}/sigs.k8s.io/yaml/goyaml.v2/LICENSE" +touch "${vendor_fixture}/sigs.k8s.io/yaml/goyaml.v2/LICENSE.libyaml" +touch "${vendor_fixture}/gopkg.in/yaml.v3/LICENSE" +assert_eq "goyaml.v2" \ + "$(VENDOR_DIR="${vendor_fixture}" license_dir_within_module \ + sigs.k8s.io/yaml/goyaml.v2 sigs.k8s.io/yaml)" \ + "license_dir_within_module finds the nearest enclosing license" +assert_eq "" \ + "$(VENDOR_DIR="${vendor_fixture}" license_dir_within_module \ + sigs.k8s.io/yaml sigs.k8s.io/yaml)" \ + "license_dir_within_module is empty at the module root" +# $1 is expanded by the child bash -c, not here. +# shellcheck disable=SC2016 +assert_fails "license_dir_within_module fails when no license exists" \ + env VENDOR_DIR="${vendor_fixture}" bash -c \ + 'source "$1"; license_dir_within_module github.com/absent/mod github.com/absent/mod' \ + _ "${HERE}/generate-third-party-notices.sh" + +render="$(mktemp -d)" +mkdir -p "${render}/cache/sigs.k8s.io/yaml/goyaml.v2" +printf 'Apache text\n' > "${render}/cache/sigs.k8s.io/yaml/goyaml.v2/LICENSE" +cat > "${render}/index.csv" <<'IDX' +sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v1.4.0 +gopkg.in/yaml.v3,ignored,MIT,gopkg.in/yaml.v3,v3.0.1 +IDX + +assert_eq '| Package | Version | License | Location |' \ + "$(LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ + LICENSE_OVERRIDES="${empty_overrides_fixture}" emit_index_table "${render}/index.csv" | sed -n 1p)" \ + "index header has four columns" +# Expected literal Markdown, not shell expansion. +# shellcheck disable=SC2016 +assert_eq '| `sigs.k8s.io/yaml/goyaml.v2` | v1.4.0 | Apache-2.0 | [LICENSE](https://example.invalid/goyaml-license) / [LICENSE.libyaml](https://example.invalid/goyaml-libyaml) |' \ + "$(LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ + LICENSE_OVERRIDES="${empty_overrides_fixture}" emit_index_table "${render}/index.csv" | sed -n 3p)" \ + "index row labels the link by filename" + +# Regression: a package whose module/version pair has no entry in the URL map +# must abort the whole table, not render with a blank Location cell. +mismatch_index="${render}/mismatch-index.csv" +cat > "${mismatch_index}" <<'IDX' +sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v9.9.9 +IDX +# $1/$2 are expanded by the child bash -c, not here. +# shellcheck disable=SC2016 +assert_fails "emit_index_table fails closed when the URL map has no entry for a row" \ + env LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ + LICENSE_OVERRIDES="${empty_overrides_fixture}" \ + bash -c 'source "$1"; emit_index_table "$2"' _ "${HERE}/generate-third-party-notices.sh" "${mismatch_index}" + +section="$(LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ + LICENSE_OVERRIDES="${empty_overrides_fixture}" emit_sections "${render}/index.csv" "${render}/cache")" +assert_eq "* Version: v1.4.0" "$(printf '%s' "${section}" | sed -n 3p)" "section names the version" +assert_eq "* License: Apache-2.0" "$(printf '%s' "${section}" | sed -n 4p)" "section names the license" +assert_eq "0" "$(printf '%s' "${section}" | LC_ALL=C grep -c '^\* Module: ')" "section no longer names the module" +assert_eq "" \ + "$(printf '%s' "${section}" | LC_ALL=C grep -m1 '^ "${overrides_fixture}" <<'OVERRIDES' +# package license reason +sigs.k8s.io/yaml/goyaml.v2 Apache-2.0 / MIT test fixture +gopkg.in/yaml.v3 Apache-2.0 / MIT test fixture +OVERRIDES + +assert_eq "Apache-2.0 / MIT" \ + "$(LICENSE_OVERRIDES="${overrides_fixture}" license_identifier_for sigs.k8s.io/yaml/goyaml.v2 Apache-2.0)" \ + "license_identifier_for returns the override for a package that has one" +assert_eq "BSD-3-Clause" \ + "$(LICENSE_OVERRIDES="${overrides_fixture}" license_identifier_for sigs.k8s.io/yaml BSD-3-Clause)" \ + "license_identifier_for returns the passed-in default for a package without an override" + +# Expected literal Markdown, not shell expansion. +# shellcheck disable=SC2016 +assert_eq '| `gopkg.in/yaml.v3` | v3.0.1 | Apache-2.0 / MIT | [LICENSE](https://example.invalid/yaml-v3) |' \ + "$(LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ + LICENSE_OVERRIDES="${overrides_fixture}" emit_index_table "${render}/index.csv" | sed -n 4p)" \ + "emit_index_table renders the overridden identifier in the License column" + +stale_overrides="$(mktemp)" +printf 'github.com/absent/package\tApache-2.0 / MIT\ttest fixture\n' > "${stale_overrides}" +# $1/$2 are expanded by the child bash -c, not here. +# shellcheck disable=SC2016 +assert_fails "check_override_coverage fails when an override names a package absent from the index" \ + env LICENSE_OVERRIDES="${stale_overrides}" bash -c \ + 'source "$1"; check_override_coverage "$2"' _ "${HERE}/generate-third-party-notices.sh" "${render}/index.csv" + +rm -rf "${vendor_fixture}" "${render}" +rm -f "${modules_fixture}" "${index_input}" "${urls_fixture}" "${empty_overrides_fixture}" "${overrides_fixture}" "${stale_overrides}" + +finish diff --git a/hack/license-overrides.tsv b/hack/license-overrides.tsv new file mode 100644 index 000000000..44197903f --- /dev/null +++ b/hack/license-overrides.tsv @@ -0,0 +1,15 @@ +# Curated license identifiers for packages whose license file bundles more +# than one license as a single document. go-licenses classifies such a file +# as whichever license it scores highest and reports only that one, so the +# reported identifier understates the terms even though the license text +# reproduced in THIRD_PARTY_NOTICES.md already carries every license in full. +# +# Add a row here only when you have read the vendored license file yourself +# and confirmed by eye which licenses it actually contains — do not derive +# an entry by grepping license text for phrases, which cannot reliably tell +# similar licenses apart (e.g. BSD-2-Clause vs BSD-3-Clause) and risks adding +# a wrong claim to a legal document. +# +# package license reason +sigs.k8s.io/yaml/goyaml.v2 Apache-2.0 / MIT ships LICENSE (Apache-2.0) and LICENSE.libyaml (MIT) as two files; go-licenses reports only the Apache-2.0 LICENSE +gopkg.in/yaml.v3 Apache-2.0 / MIT single LICENSE file has a full-text MIT section plus a short-form Apache-2.0 grant; go-licenses reports only MIT diff --git a/hack/license-url-lib.sh b/hack/license-url-lib.sh new file mode 100755 index 000000000..f7c4f30aa --- /dev/null +++ b/hack/license-url-lib.sh @@ -0,0 +1,199 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +# Shared by the resolvers and the notices generator, in two parts. +# +# Everything below http_fetch_to_file is a pure string transform: no network +# and (except base64_decode, which reads stdin) no I/O, so every rule is +# testable offline. http_fetch_to_file itself is the one HTTP fetch both +# resolvers use, kept here so there is a single retry and status policy. + +# The single HTTP fetch for both resolvers. Writes bytes to a file rather than +# returning them: command substitution strips trailing newlines, which would +# change the sha256 of every license file that ends in one. +# +# curl -f is deliberately not used here. It reports every failure as exit 22, +# which cannot distinguish a retryable 503 from a permanent 404 -- and retrying +# a genuine miss matters, because this drives a loop over several candidate +# refs and paths per license file. +HTTP_FETCH_ATTEMPTS="${HTTP_FETCH_ATTEMPTS:-3}" + +# Successive requests to one host are what trips a rate limiter, so pause +# between them. go.googlesource.com returns 503 and 429 under the tight +# per-file loop this drives; both were observed against golang.org/x and +# google.golang.org/protobuf, and both succeeded on a later attempt. +HTTP_FETCH_THROTTLE_SECONDS="${HTTP_FETCH_THROTTLE_SECONDS:-0.2}" +HTTP_FETCH_LAST_HOST="" + +http_fetch_to_file() { + local url="$1" destination="$2" attempt status host + + host="${url#*://}" + host="${host%%/*}" + [[ "${host}" == "${HTTP_FETCH_LAST_HOST}" ]] && sleep "${HTTP_FETCH_THROTTLE_SECONDS}" + HTTP_FETCH_LAST_HOST="${host}" + + for (( attempt = 1; attempt <= HTTP_FETCH_ATTEMPTS; attempt++ )); do + status="$(curl -sL --max-time 30 --output "${destination}" \ + --write-out '%{http_code}' "${url}" 2>/dev/null)" || status="000" + case "${status}" in + 2*) return 0 ;; + # 000 is curl's own transport failure; the rest are server-side and + # temporary. Anything else (404, 401, 410) is a permanent answer. + ""|000|408|429|5*) ;; + *) return 1 ;; + esac + (( attempt < HTTP_FETCH_ATTEMPTS )) && sleep $(( attempt * 2 )) + done + return 1 +} + +# The module proxy case-encodes an uppercase letter as '!' plus its lowercase +# form: github.com/NVIDIA -> github.com/!n!v!i!d!i!a. This MUST NOT be done with +# sed: 's/\([A-Z]\)/!\l\1/g' yields '!lN!lV...' on BSD sed, which the proxy +# rejects as an invalid escaped module path. +proxy_escape() { + printf '%s' "$1" | awk '{ + n = split($0, chars, "") + out = "" + for (i = 1; i <= n; i++) { + c = chars[i] + out = out (c ~ /[A-Z]/ ? "!" tolower(c) : c) + } + print out + }' +} + +strip_major_suffix() { + if [[ "$1" =~ ^(.*)/v[0-9]+$ ]]; then + printf '%s' "${BASH_REMATCH[1]}" + else + printf '%s' "$1" + fi +} + +normalize_version() { + printf '%s' "${1%+incompatible}" +} + +# A pseudo-version ends in <14-digit UTC timestamp>-<12-hex commit>. That +# trailing hash is the only ref such a module has; there is no tag. +# Pre-release versions have an optional 0. prefix before the timestamp. +pseudo_version_hash() { + if [[ "$1" =~ -[0-9.]*[0-9]{14}-([0-9a-f]{12})$ ]]; then + printf '%s' "${BASH_REMATCH[1]}" + fi +} + +normalize_repo_url() { + local url="${1%/}" + printf '%s' "${url%.git}" +} + +github_repo_from_path() { + local module rest org repo + module="$(strip_major_suffix "$1")" + case "${module}" in github.com/*) ;; *) return 0 ;; esac + rest="${module#github.com/}" + org="${rest%%/*}" + rest="${rest#*/}" + repo="${rest%%/*}" + [[ -n "${org}" && -n "${repo}" && "${org}" != "${module}" ]] || return 0 + printf 'https://github.com/%s/%s' "${org}" "${repo}" +} + +# The module's directory inside a github repository, derived from the path +# alone. GitHub serves no go-import meta, so when the proxy has no Origin this +# is the only source of the submodule tag prefix; without it a module such as +# github.com/Mellanox/maintenance-operator/api loses its 'api/' tag and no +# candidate URL can match. +github_subdir_from_path() { + local module rest + module="$(strip_major_suffix "$1")" + case "${module}" in github.com/*) ;; *) return 0 ;; esac + rest="${module#github.com/}" + [[ "${rest}" == */* ]] || return 0 + rest="${rest#*/}" # drop org + [[ "${rest}" == */* ]] || return 0 + printf '%s' "${rest#*/}" # drop repo +} + +# gopkg.in publishes a go-import pointing at itself, which serves no blobs. +# Its documented convention maps onto GitHub. +gopkg_in_repo() { + local rest user pkg + case "$1" in gopkg.in/*) ;; *) return 0 ;; esac + rest="${1#gopkg.in/}" + if [[ "${rest}" == */* ]]; then + user="${rest%%/*}" + pkg="${rest#*/}" + printf 'https://github.com/%s/%s' "${user}" "${pkg%.v*}" + else + pkg="${rest%.v*}" + printf 'https://github.com/go-%s/%s' "${pkg}" "${pkg}" + fi +} + +derived_subdir() { + local module prefix + module="$(strip_major_suffix "$1")" + prefix="$(strip_major_suffix "$2")" + [[ "${module}" == "${prefix}" ]] && return 0 + [[ "${module}" == "${prefix}/"* ]] || return 0 + printf '%s' "${module#"${prefix}/"}" +} + +# Gerrit serves blobs under /+//, not /blob//. +blob_url() { + local repo="$1" ref="$2" path="$3" + case "${repo}" in + https://go.googlesource.com/*) printf '%s/+/%s/%s' "${repo}" "${ref}" "${path}" ;; + *) printf '%s/blob/%s/%s' "${repo}" "${ref}" "${path}" ;; + esac +} + +raw_url_for() { + local blob="$1" rest owner repo + case "${blob}" in + https://github.com/*) + rest="${blob#https://github.com/}" + owner="${rest%%/*}"; rest="${rest#*/}" + repo="${rest%%/*}"; rest="${rest#*/}" + rest="${rest#blob/}" + printf 'https://raw.githubusercontent.com/%s/%s/%s' "${owner}" "${repo}" "${rest}" + ;; + https://go.googlesource.com/*) + printf '%s?format=TEXT' "${blob}" + ;; + esac +} + +raw_is_base64() { + case "$1" in https://go.googlesource.com/*) return 0 ;; *) return 1 ;; esac +} + +# GNU coreutils spells the decode flag -d; BSD documents -D. Probe once rather +# than assuming, or every Gerrit-hosted module fails to hash on a strict BSD. +base64_decode() { + if [[ -z "${BASE64_DECODE_FLAG:-}" ]]; then + if printf '' | base64 -d >/dev/null 2>&1; then + BASE64_DECODE_FLAG="-d" + else + BASE64_DECODE_FLAG="-D" + fi + fi + base64 "${BASE64_DECODE_FLAG}" +} diff --git a/hack/license-url-lib_test.sh b/hack/license-url-lib_test.sh new file mode 100755 index 000000000..5c325994e --- /dev/null +++ b/hack/license-url-lib_test.sh @@ -0,0 +1,172 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +set -uo pipefail +HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +# shellcheck source=hack/test-helpers.sh disable=SC1091 +source "${HERE}/test-helpers.sh" +# shellcheck source=hack/license-url-lib.sh disable=SC1091 +source "${HERE}/license-url-lib.sh" + +# The bug that silently broke proxy resolution for all three uppercase modules. +assert_eq "github.com/!n!v!i!d!i!a/go-nvml" \ + "$(proxy_escape github.com/NVIDIA/go-nvml)" "proxy_escape lowercases with a bang" +assert_eq "github.com/!n!v!i!d!i!a/nvidia-container-toolkit" \ + "$(proxy_escape github.com/NVIDIA/nvidia-container-toolkit)" \ + "proxy_escape leaves an identically spelled lowercase segment alone" +assert_eq "tags.cncf.io/container-device-interface" \ + "$(proxy_escape tags.cncf.io/container-device-interface)" "proxy_escape leaves lowercase alone" + +assert_eq "github.com/urfave/cli" \ + "$(strip_major_suffix github.com/urfave/cli/v3)" "strip /v3" +assert_eq "github.com/Masterminds/semver" \ + "$(strip_major_suffix github.com/Masterminds/semver/v3)" "strip /v3 below an uppercase org" +assert_eq "gopkg.in/yaml.v3" \ + "$(strip_major_suffix gopkg.in/yaml.v3)" "gopkg.in .vN is not a /vN suffix" + +assert_eq "v2.0.1" "$(normalize_version 'v2.0.1+incompatible')" "strip +incompatible" +assert_eq "afd174a4e478" \ + "$(pseudo_version_hash v0.0.0-20260414002931-afd174a4e478)" "pseudo-version hash" +assert_eq "edf4cb3d2116" \ + "$(pseudo_version_hash v0.9.1-0.20251114084447-edf4cb3d2116)" "pre-release pseudo-version" +assert_eq "" "$(pseudo_version_hash v1.9.4)" "a tagged version has no hash" + +assert_eq "https://github.com/sirupsen/logrus" \ + "$(github_repo_from_path github.com/sirupsen/logrus)" "github root module" +assert_eq "https://github.com/moby/sys" \ + "$(github_repo_from_path github.com/moby/sys/capability)" "github submodule" +assert_eq "" "$(github_repo_from_path tags.cncf.io/container-device-interface)" "non-github yields empty" + +# Without this the github fallback loses the submodule tag prefix entirely. +assert_eq "capability" \ + "$(github_subdir_from_path github.com/moby/sys/capability)" "github subdir" +assert_eq "internal/spew" \ + "$(github_subdir_from_path github.com/stretchr/testify/internal/spew)" \ + "multi-segment github subdir" +assert_eq "" "$(github_subdir_from_path github.com/urfave/cli/v3)" "/vN is not a subdir" +assert_eq "" "$(github_subdir_from_path github.com/sirupsen/logrus)" "root module has no subdir" + +assert_eq "https://github.com/go-yaml/yaml" \ + "$(gopkg_in_repo gopkg.in/yaml.v3)" "gopkg.in single segment" +# The only gopkg.in module vendored here is gopkg.in/yaml.v3. The remaining two +# forms resolve differently, so they are covered with upstream module names. +assert_eq "https://github.com/go-inf/inf" \ + "$(gopkg_in_repo gopkg.in/inf.v0)" "gopkg.in single segment, no dash in repo" +assert_eq "https://github.com/evanphx/json-patch" \ + "$(gopkg_in_repo gopkg.in/evanphx/json-patch.v4)" "gopkg.in user/pkg" +assert_eq "" "$(gopkg_in_repo github.com/foo/bar)" "non-gopkg.in yields empty" + +assert_eq "https://github.com/cyphar/go-pathrs" \ + "$(normalize_repo_url 'https://github.com/cyphar/go-pathrs.git')" "strip .git" +assert_eq "https://github.com/foo/bar" \ + "$(normalize_repo_url 'https://github.com/foo/bar/')" "strip trailing slash" + +assert_eq "specs-go" \ + "$(derived_subdir tags.cncf.io/container-device-interface/specs-go tags.cncf.io/container-device-interface)" \ + "subdir from prefix" +assert_eq "" "$(derived_subdir github.com/sirupsen/logrus github.com/sirupsen/logrus)" "root module" + +assert_eq "https://github.com/sirupsen/logrus/blob/v1.9.4/LICENSE" \ + "$(blob_url https://github.com/sirupsen/logrus v1.9.4 LICENSE)" "github blob template" +assert_eq "https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE" \ + "$(blob_url https://go.googlesource.com/sys refs/tags/v0.47.0 LICENSE)" "gerrit blob template" + +assert_eq "https://raw.githubusercontent.com/stretchr/testify/v1.11.1/internal/spew/LICENSE" \ + "$(raw_url_for https://github.com/stretchr/testify/blob/v1.11.1/internal/spew/LICENSE)" \ + "github raw URL" +assert_eq "https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE?format=TEXT" \ + "$(raw_url_for https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE)" "gerrit raw URL" +assert_fails "github raw is not base64" raw_is_base64 https://github.com/a/b/blob/v1/LICENSE + +assert_eq "hello" "$(printf 'aGVsbG8=' | base64_decode)" "base64_decode works on this host" + +# http_fetch_to_file's retry policy. curl and sleep are shadowed by shell +# functions, so this exercises the real policy with no network and no delay. +# The distinction under test is the load-bearing one: a 503 is retried, a 404 +# is a real miss and must cost exactly one request per candidate. +# +# The stub keeps its call count and status sequence in files, not variables: +# http_fetch_to_file reads curl's output through command substitution, so the +# stub runs in a subshell and any variable it set would be discarded. +CURL_CALLS_FILE="$(mktemp)" +CURL_SEQUENCE_FILE="$(mktemp)" +FETCH_DESTINATION="$(mktemp)" +trap 'rm -f "${CURL_CALLS_FILE}" "${CURL_SEQUENCE_FILE}" "${FETCH_DESTINATION}"' EXIT + +curl() { + local destination="" + while (( $# )); do + case "$1" in + --output) destination="$2"; shift 2 ;; + *) shift ;; + esac + done + + printf '%s' "$(( $(cat "${CURL_CALLS_FILE}") + 1 ))" > "${CURL_CALLS_FILE}" + + local sequence status + sequence="$(cat "${CURL_SEQUENCE_FILE}")" + status="${sequence%% *}" + case "${sequence}" in + *' '*) printf '%s' "${sequence#* }" > "${CURL_SEQUENCE_FILE}" ;; + esac + + [[ -n "${destination}" ]] && printf 'stub-body' > "${destination}" + printf '%s' "${status}" + [[ "${status}" == "000" ]] && return 7 + return 0 +} + +sleep() { :; } + +fetch_status=0 +fetch_case() { + printf '%s' "$1" > "${CURL_SEQUENCE_FILE}" + printf '0' > "${CURL_CALLS_FILE}" + HTTP_FETCH_LAST_HOST="" + fetch_status=0 + http_fetch_to_file "https://example.test/LICENSE" "${FETCH_DESTINATION}" || fetch_status=$? +} +curl_calls() { cat "${CURL_CALLS_FILE}"; } + +fetch_case "200" +assert_eq "0" "${fetch_status}" "200 succeeds" +assert_eq "1" "$(curl_calls)" "200 costs one request" +assert_eq "stub-body" "$(cat "${FETCH_DESTINATION}")" "200 writes the body to the destination" + +fetch_case "404" +assert_eq "1" "${fetch_status}" "404 fails" +assert_eq "1" "$(curl_calls)" "404 is not retried" + +fetch_case "503 200" +assert_eq "0" "${fetch_status}" "503 then 200 succeeds" +assert_eq "2" "$(curl_calls)" "503 is retried" + +fetch_case "429 200" +assert_eq "0" "${fetch_status}" "429 then 200 succeeds" +assert_eq "2" "$(curl_calls)" "429 is retried" + +fetch_case "000 200" +assert_eq "0" "${fetch_status}" "transport failure then 200 succeeds" +assert_eq "2" "$(curl_calls)" "transport failure is retried" + +fetch_case "503 503 503" +assert_eq "1" "${fetch_status}" "persistent 503 fails" +assert_eq "3" "$(curl_calls)" "persistent 503 stops at HTTP_FETCH_ATTEMPTS" + +unset -f curl sleep + +finish diff --git a/hack/license-urls.tsv b/hack/license-urls.tsv new file mode 100644 index 000000000..ddeb6fd3b --- /dev/null +++ b/hack/license-urls.tsv @@ -0,0 +1,52 @@ +# Verified upstream URL for every license file the notices document links. +# Generated by hack/verify-license-urls.sh. Each URL was fetched and its +# sha256 matched against the vendored copy, so no entry is a dead or wrong link. +# Covers the shipped set only: build- and test-only dependencies are excluded. +# module version license-path url +github.com/Masterminds/semver/v3 v3.5.0 LICENSE.txt https://github.com/Masterminds/semver/blob/v3.5.0/LICENSE.txt +github.com/NVIDIA/go-nvlib v0.12.0 LICENSE https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/LICENSE +github.com/NVIDIA/go-nvlib v0.12.0 NOTICE https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/NOTICE +github.com/NVIDIA/go-nvml v0.13.3-1 LICENSE https://github.com/NVIDIA/go-nvml/blob/v0.13.3-1/LICENSE +github.com/containerd/log v0.1.0 LICENSE https://github.com/containerd/log/blob/v0.1.0/LICENSE +github.com/containerd/nri v0.12.1 LICENSE https://github.com/containerd/nri/blob/v0.12.1/LICENSE +github.com/containerd/ttrpc v1.2.7 LICENSE https://github.com/containerd/ttrpc/blob/v1.2.7/LICENSE +github.com/cyphar/filepath-securejoin v0.7.0 COPYING.md https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/COPYING.md +github.com/cyphar/filepath-securejoin v0.7.0 LICENSE.BSD https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/LICENSE.BSD +github.com/cyphar/filepath-securejoin v0.7.0 LICENSE.MPL-2.0 https://github.com/cyphar/filepath-securejoin/blob/v0.7.0/LICENSE.MPL-2.0 +github.com/fsnotify/fsnotify v1.7.0 LICENSE https://github.com/fsnotify/fsnotify/blob/v1.7.0/LICENSE +github.com/google/uuid v1.6.0 LICENSE https://github.com/google/uuid/blob/v1.6.0/LICENSE +github.com/knqyf263/go-plugin v0.9.0 LICENSE https://github.com/knqyf263/go-plugin/blob/v0.9.0/LICENSE +github.com/moby/sys/capability v0.4.0 LICENSE https://github.com/moby/sys/blob/capability/v0.4.0/capability/LICENSE +github.com/moby/sys/mountinfo v0.7.2 LICENSE https://github.com/moby/sys/blob/mountinfo/v0.7.2/LICENSE +github.com/moby/sys/reexec v0.1.0 LICENSE https://github.com/moby/sys/blob/reexec/v0.1.0/LICENSE +github.com/opencontainers/cgroups v0.0.7 LICENSE https://github.com/opencontainers/cgroups/blob/v0.0.7/LICENSE +github.com/opencontainers/runc v1.4.3 LICENSE https://github.com/opencontainers/runc/blob/v1.4.3/LICENSE +github.com/opencontainers/runc v1.4.3 NOTICE https://github.com/opencontainers/runc/blob/v1.4.3/NOTICE +github.com/opencontainers/runtime-spec v1.3.0 LICENSE https://github.com/opencontainers/runtime-spec/blob/v1.3.0/LICENSE +github.com/opencontainers/runtime-tools v0.9.1-0.20251114084447-edf4cb3d2116 LICENSE https://github.com/opencontainers/runtime-tools/blob/edf4cb3d2116/LICENSE +github.com/pelletier/go-toml v1.9.5 LICENSE https://github.com/pelletier/go-toml/blob/v1.9.5/LICENSE +github.com/prometheus/procfs v0.21.1 LICENSE https://github.com/prometheus/procfs/blob/v0.21.1/LICENSE +github.com/prometheus/procfs v0.21.1 NOTICE https://github.com/prometheus/procfs/blob/v0.21.1/NOTICE +github.com/sirupsen/logrus v1.9.4 LICENSE https://github.com/sirupsen/logrus/blob/v1.9.4/LICENSE +github.com/tetratelabs/wazero v1.11.0 LICENSE https://github.com/tetratelabs/wazero/blob/v1.11.0/LICENSE +github.com/tetratelabs/wazero v1.11.0 NOTICE https://github.com/tetratelabs/wazero/blob/v1.11.0/NOTICE +github.com/urfave/cli-altsrc/v3 v3.1.0 LICENSE https://github.com/urfave/cli-altsrc/blob/v3.1.0/LICENSE +github.com/urfave/cli/v3 v3.10.1 LICENSE https://github.com/urfave/cli/blob/v3.10.1/LICENSE +golang.org/x/mod v0.38.0 LICENSE https://go.googlesource.com/mod/+/refs/tags/v0.38.0/LICENSE +golang.org/x/mod v0.38.0 PATENTS https://go.googlesource.com/mod/+/refs/tags/v0.38.0/PATENTS +golang.org/x/sys v0.47.0 LICENSE https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE +golang.org/x/sys v0.47.0 PATENTS https://go.googlesource.com/sys/+/refs/tags/v0.47.0/PATENTS +google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 LICENSE https://github.com/googleapis/go-genproto/blob/afd174a4e478/LICENSE +google.golang.org/grpc v1.82.1 AUTHORS https://github.com/grpc/grpc-go/blob/v1.82.1/AUTHORS +google.golang.org/grpc v1.82.1 LICENSE https://github.com/grpc/grpc-go/blob/v1.82.1/LICENSE +google.golang.org/grpc v1.82.1 NOTICE.txt https://github.com/grpc/grpc-go/blob/v1.82.1/NOTICE.txt +google.golang.org/protobuf v1.36.11 LICENSE https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/LICENSE +google.golang.org/protobuf v1.36.11 PATENTS https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/PATENTS +gopkg.in/yaml.v3 v3.0.1 LICENSE https://github.com/go-yaml/yaml/blob/v3.0.1/LICENSE +gopkg.in/yaml.v3 v3.0.1 NOTICE https://github.com/go-yaml/yaml/blob/v3.0.1/NOTICE +sigs.k8s.io/yaml v1.4.0 LICENSE https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/LICENSE +sigs.k8s.io/yaml v1.4.0 goyaml.v2/LICENSE https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/LICENSE +sigs.k8s.io/yaml v1.4.0 goyaml.v2/LICENSE.libyaml https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/LICENSE.libyaml +sigs.k8s.io/yaml v1.4.0 goyaml.v2/NOTICE https://github.com/kubernetes-sigs/yaml/blob/v1.4.0/goyaml.v2/NOTICE +tags.cncf.io/container-device-interface v1.1.0 LICENSE https://github.com/cncf-tags/container-device-interface/blob/v1.1.0/LICENSE +tags.cncf.io/container-device-interface/specs-go v1.1.0 LICENSE https://github.com/cncf-tags/container-device-interface/blob/specs-go/v1.1.0/LICENSE diff --git a/hack/module-repos.tsv b/hack/module-repos.tsv new file mode 100644 index 000000000..a2063ce88 --- /dev/null +++ b/hack/module-repos.tsv @@ -0,0 +1,45 @@ +# Upstream repository for each vendored module. +# Generated by hack/resolve-module-repos.sh from the module proxy Origin, +# the go-import meta tag, and the github.com path shape. Not hand-edited. +# module repo-url subdir +cyphar.com/go-pathrs https://github.com/cyphar/libpathrs go-pathrs +github.com/Masterminds/semver/v3 https://github.com/Masterminds/semver +github.com/NVIDIA/go-nvlib https://github.com/NVIDIA/go-nvlib +github.com/NVIDIA/go-nvml https://github.com/NVIDIA/go-nvml +github.com/containerd/log https://github.com/containerd/log +github.com/containerd/nri https://github.com/containerd/nri +github.com/containerd/ttrpc https://github.com/containerd/ttrpc +github.com/cyphar/filepath-securejoin https://github.com/cyphar/filepath-securejoin +github.com/davecgh/go-spew https://github.com/davecgh/go-spew +github.com/fsnotify/fsnotify https://github.com/fsnotify/fsnotify +github.com/google/uuid https://github.com/google/uuid +github.com/hashicorp/errwrap https://github.com/hashicorp/errwrap +github.com/knqyf263/go-plugin https://github.com/knqyf263/go-plugin +github.com/kr/text https://github.com/kr/text +github.com/moby/sys/capability https://github.com/moby/sys capability +github.com/moby/sys/mountinfo https://github.com/moby/sys mountinfo +github.com/moby/sys/reexec https://github.com/moby/sys reexec +github.com/moby/sys/symlink https://github.com/moby/sys symlink +github.com/opencontainers/cgroups https://github.com/opencontainers/cgroups +github.com/opencontainers/runc https://github.com/opencontainers/runc +github.com/opencontainers/runtime-spec https://github.com/opencontainers/runtime-spec +github.com/opencontainers/runtime-tools https://github.com/opencontainers/runtime-tools +github.com/pelletier/go-toml https://github.com/pelletier/go-toml +github.com/pmezard/go-difflib https://github.com/pmezard/go-difflib +github.com/prometheus/procfs https://github.com/prometheus/procfs +github.com/rogpeppe/go-internal https://github.com/rogpeppe/go-internal +github.com/sirupsen/logrus https://github.com/sirupsen/logrus +github.com/stretchr/testify https://github.com/stretchr/testify +github.com/tetratelabs/wazero https://github.com/tetratelabs/wazero +github.com/urfave/cli-altsrc/v3 https://github.com/urfave/cli-altsrc +github.com/urfave/cli/v3 https://github.com/urfave/cli +github.com/xeipuuv/gojsonpointer https://github.com/xeipuuv/gojsonpointer +golang.org/x/mod https://go.googlesource.com/mod +golang.org/x/sys https://go.googlesource.com/sys +google.golang.org/genproto/googleapis/rpc https://github.com/googleapis/go-genproto googleapis/rpc +google.golang.org/grpc https://github.com/grpc/grpc-go +google.golang.org/protobuf https://go.googlesource.com/protobuf +gopkg.in/yaml.v3 https://github.com/go-yaml/yaml +sigs.k8s.io/yaml https://github.com/kubernetes-sigs/yaml +tags.cncf.io/container-device-interface https://github.com/cncf-tags/container-device-interface +tags.cncf.io/container-device-interface/specs-go https://github.com/cncf-tags/container-device-interface specs-go diff --git a/hack/resolve-module-repos.sh b/hack/resolve-module-repos.sh new file mode 100755 index 000000000..511fa496c --- /dev/null +++ b/hack/resolve-module-repos.sh @@ -0,0 +1,177 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +# Resolves every module in vendor/modules.txt to its upstream repository and +# writes hack/module-repos.tsv. +# +# Needs network; run via 'make third-party-notices-repos'. Keyed by module and +# not by version: a repository normally does not move when a dependency is +# bumped, so this file survives bumps and changes only when a new module enters +# the tree. That is a convenience, not a guarantee — Task 5's content +# verification is what actually enforces correctness, and it fails loudly if a +# mapping has gone stale. + +set -euo pipefail + +HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +# shellcheck source=hack/license-url-lib.sh disable=SC1091 +source "${HERE}/license-url-lib.sh" + +MODULES_TXT="${MODULES_TXT:-vendor/modules.txt}" +OUTPUT="${OUTPUT:-hack/module-repos.tsv}" +PROXY="${PROXY:-https://proxy.golang.org}" + +die() { + printf 'ERROR: %s\n' "$1" >&2 + shift + (( $# > 0 )) && printf '%s\n' "$@" >&2 + exit 1 +} +log() { printf '%s\n' "$*" >&2; } + +# Body-as-string wrapper over the shared fetcher. An empty body is a failure +# here but is NOT retried: absence of Origin is a real, permanent property of +# older proxy cache entries, not transient flakiness. +fetch_retry() { + local url="$1" body_tmp_file body + body_tmp_file="$(mktemp "${TMPDIR:-/tmp}/nvidia-container-toolkit-fetch.XXXXXX")" + if ! http_fetch_to_file "${url}" "${body_tmp_file}"; then + rm -f "${body_tmp_file}" + return 1 + fi + body="$(cat "${body_tmp_file}")" + rm -f "${body_tmp_file}" + [[ -n "${body}" ]] || return 1 + printf '%s' "${body}" +} + +origin_field() { + printf '%s' "$1" | python3 -c ' +import json, sys +try: + origin = json.load(sys.stdin).get("Origin") or {} +except Exception: + origin = {} +print(origin.get(sys.argv[1], "")) +' "$2" 2>/dev/null || printf '' +} + +# go-import content is " ". The meta tag is +# frequently split across lines, so newlines are folded before matching. +go_import_meta() { + fetch_retry "https://$1?go-get=1" 2>/dev/null \ + | tr '\n' ' ' | tr -s ' ' \ + | LC_ALL=C grep -oE 'name="go-import"[^>]*content="[^"]*"' \ + | head -1 \ + | LC_ALL=C sed -E 's/.*content="([^"]*)".*/\1/' +} + +main() { + command -v curl >/dev/null 2>&1 || die "curl is not installed." + command -v python3 >/dev/null 2>&1 || die "python3 is not installed." + [[ -f "${MODULES_TXT}" ]] \ + || die "${MODULES_TXT} not found — run 'make third-party-notices-repos' from the repo root." + + local repos_tmp_file unresolved=0 + repos_tmp_file="$(mktemp "${TMPDIR:-/tmp}/nvidia-container-toolkit-repos.XXXXXX")" + trap 'rm -f "${repos_tmp_file}"' EXIT + + local module version module_info_json repo import_prefix subdir go_import_meta_content converted_repo_url + local unresolved_modules="" + while read -r module version; do + [[ -z "${module}" ]] && continue + + repo=""; import_prefix=""; subdir=""; module_info_json="" + + if module_info_json="$(fetch_retry "${PROXY}/$(proxy_escape "${module}")/@v/${version}.info")"; then + repo="$(origin_field "${module_info_json}" URL)" + subdir="$(origin_field "${module_info_json}" Subdir)" + fi + + if [[ -z "${repo}" ]]; then + go_import_meta_content="$(go_import_meta "${module}")" || go_import_meta_content="" + if [[ -n "${go_import_meta_content}" ]]; then + import_prefix="$(printf '%s' "${go_import_meta_content}" | awk '{print $1}')" + repo="$(printf '%s' "${go_import_meta_content}" | awk '{print $3}')" + fi + fi + + [[ -z "${repo}" ]] && repo="$(github_repo_from_path "${module}")" + repo="$(normalize_repo_url "${repo}")" + + # gopkg.in points at itself and serves no blobs. + case "${repo}" in + https://gopkg.in/*|"") + converted_repo_url="$(gopkg_in_repo "${module}")" + [[ -n "${converted_repo_url}" ]] && repo="${converted_repo_url}" + ;; + esac + + if [[ -z "${repo}" ]]; then + log "UNRESOLVED ${module}: no repository could be determined" + unresolved=$(( unresolved + 1 )) + unresolved_modules="${unresolved_modules}${unresolved_modules:+ }${module}" + continue + fi + + # Subdir precedence: proxy Origin, then the go-import prefix, then the + # github path shape. The last matters because GitHub serves no + # go-import, so a github submodule with no Origin would otherwise lose + # its tag prefix and never verify. + if [[ -z "${subdir}" && -n "${import_prefix}" ]]; then + subdir="$(derived_subdir "${module}" "${import_prefix}")" + fi + if [[ -z "${subdir}" ]]; then + subdir="$(github_subdir_from_path "${module}")" + fi + + printf '%s\t%s\t%s\n' "${module}" "${repo}" "${subdir}" >> "${repos_tmp_file}" + done < <(LC_ALL=C grep '^# ' "${MODULES_TXT}" | awk '{print $2, $3}') + + # A warning, not a die: this resolves every module in modules.txt, including + # the ten-odd build/test-only ones out of scope for the notices document, so + # an unreachable vanity host on one of those must not block refreshing + # notices for an unrelated shipped bump. Fail-closed is still preserved — + # hack/verify-license-urls.sh dies when an IN-SCOPE module has no entry in + # this map. Do not turn this back into a die without also scoping the loop + # above to shipped modules only. + if (( unresolved > 0 )); then + log "WARNING: ${unresolved} module(s) could not be resolved to a repository: ${unresolved_modules}" + log "Re-run; if the warning persists the module's vanity host is unreachable." + fi + + { + printf '# Upstream repository for each vendored module.\n' + printf '# Generated by hack/resolve-module-repos.sh from the module proxy Origin,\n' + printf '# the go-import meta tag, and the github.com path shape. Not hand-edited.\n' + printf '# module\trepo-url\tsubdir\n' + LC_ALL=C sort "${repos_tmp_file}" + } > "${OUTPUT}" + + log "Wrote ${OUTPUT} ($(LC_ALL=C grep -vc '^#' "${OUTPUT}") modules)" + + # Exit here, not by falling off the end: the EXIT trap above references + # repos_tmp_file, a variable local to this function. If main merely + # returns, the process's implicit exit fires that trap after + # repos_tmp_file has gone out of scope, and 'set -u' turns the cleanup + # itself into an unbound-variable failure that clobbers this function's + # success with exit 1. + exit 0 +} + +if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then + main "$@" +fi diff --git a/hack/test-helpers.sh b/hack/test-helpers.sh new file mode 100755 index 000000000..2a37e1f6a --- /dev/null +++ b/hack/test-helpers.sh @@ -0,0 +1,45 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +TESTS_RUN=0 +TESTS_FAILED=0 + +assert_eq() { + local expected="$1" actual="$2" description="$3" + TESTS_RUN=$(( TESTS_RUN + 1 )) + if [[ "${expected}" != "${actual}" ]]; then + TESTS_FAILED=$(( TESTS_FAILED + 1 )) + printf 'FAIL: %s\n expected: [%s]\n actual: [%s]\n' \ + "${description}" "${expected}" "${actual}" >&2 + fi +} + +# Output is captured so an expected failure does not pollute the log. +assert_fails() { + local description="$1" + shift + TESTS_RUN=$(( TESTS_RUN + 1 )) + if "$@" >/dev/null 2>&1; then + TESTS_FAILED=$(( TESTS_FAILED + 1 )) + printf 'FAIL: %s\n expected non-zero exit, got 0\n' "${description}" >&2 + fi +} + +finish() { + printf '%s: %d assertions, %d failures\n' \ + "$(basename "${0}")" "${TESTS_RUN}" "${TESTS_FAILED}" >&2 + (( TESTS_FAILED == 0 )) +} diff --git a/hack/verify-license-urls.sh b/hack/verify-license-urls.sh new file mode 100755 index 000000000..fc85402a7 --- /dev/null +++ b/hack/verify-license-urls.sh @@ -0,0 +1,241 @@ +#!/usr/bin/env bash +# Copyright (c) NVIDIA CORPORATION. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# Resolves and verifies the upstream URL of every license file the notices +# document links, writing hack/license-urls.tsv. +# +# Needs network; run via 'make third-party-notices-urls'. A URL is written ONLY +# if the bytes it serves hash to the same sha256 as the vendored copy, so no +# entry can be a dead link or point at the wrong licence. +# +# Scope is the shipped set: this sources the notices generator and runs its +# collection stages, so it verifies exactly the packages go-licenses attributes +# to ./cmd/..., never the build- and test-only modules vendor/ also contains. + +set -euo pipefail + +HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +# shellcheck source=hack/license-url-lib.sh disable=SC1091 +source "${HERE}/license-url-lib.sh" +# shellcheck source=hack/generate-third-party-notices.sh disable=SC1091 +source "${HERE}/generate-third-party-notices.sh" + +REPOS_MAP="${REPOS_MAP:-hack/module-repos.tsv}" +URLS_OUTPUT="${URLS_OUTPUT:-hack/license-urls.tsv}" +PROXY="${PROXY:-https://proxy.golang.org}" + +sha256_of_file() { + if command -v sha256sum >/dev/null 2>&1; then + sha256sum "$1" | cut -d' ' -f1 + else + shasum -a 256 "$1" | cut -d' ' -f1 + fi +} + +sha256_of_stdin() { + if command -v sha256sum >/dev/null 2>&1; then + sha256sum | cut -d' ' -f1 + else + shasum -a 256 | cut -d' ' -f1 + fi +} + +# Nothing may reach the hasher unless the fetch succeeded: hashing zero bytes +# yields a fixed digest that would false-match an empty vendored file. +# http_fetch_to_file retries the transient failures go.googlesource.com returns +# under this loop, and fails fast on a 404, which is a real miss. +remote_sha() { + local blob="$1" raw blob_tmp_file sha + raw="$(raw_url_for "${blob}")" + [[ -n "${raw}" ]] || return 1 + + blob_tmp_file="$(mktemp "${TMPDIR:-/tmp}/nvidia-container-toolkit-blob.XXXXXX")" + if ! http_fetch_to_file "${raw}" "${blob_tmp_file}"; then + rm -f "${blob_tmp_file}" + return 1 + fi + + if raw_is_base64 "${blob}"; then + sha="$(base64_decode < "${blob_tmp_file}" | sha256_of_stdin)" || sha="" + else + sha="$(sha256_of_stdin < "${blob_tmp_file}")" || sha="" + fi + rm -f "${blob_tmp_file}" + + [[ -n "${sha}" ]] || return 1 + printf '%s' "${sha}" +} + +repo_field() { + LC_ALL=C awk -F'\t' -v m="$1" -v want="$2" \ + '$1 == m { print (want == "repo" ? $2 : $3); found = 1; exit } + END { exit !found }' "${REPOS_MAP}" +} + +# Version-specific provenance. Fetched here rather than stored in the repos map, +# which is deliberately version-independent. Origin.Hash is the only pinned ref +# left when upstream deletes or rewrites a tag. +origin_ref_and_hash() { + local module="$1" version="$2" info + info="$(curl -sfL --max-time 30 \ + "${PROXY}/$(proxy_escape "${module}")/@v/${version}.info" 2>/dev/null)" || return 0 + printf '%s' "${info}" | python3 -c ' +import json, sys +try: + origin = json.load(sys.stdin).get("Origin") or {} +except Exception: + origin = {} +ref = origin.get("Ref", "") +# Only a tag pins a release. Every golang.org/x module reports +# refs/heads/master, and a branch ref would float. +print(ref[len("refs/tags/"):] if ref.startswith("refs/tags/") else "") +print(origin.get("Hash", "")) +' 2>/dev/null || printf '\n\n' +} + +main() { + command -v curl >/dev/null 2>&1 || die "curl is not installed." + command -v python3 >/dev/null 2>&1 || die "python3 is not installed." + [[ -f "${REPOS_MAP}" ]] \ + || die "${REPOS_MAP} not found — run 'make third-party-notices-repos' first." + + check_prerequisites + verify_platform_matrix + prepare_workspace + collect_runtime + build_indexes + + local verified_urls_tmp_file failures=0 + verified_urls_tmp_file="$(mktemp "${TMPDIR:-/tmp}/nvidia-container-toolkit-urls.XXXXXX")" + + local package _ module version repo subdir relative + local origin_tag origin_hash plain_version pseudo_version_hash_value license_file name path_in_module want_sha found_url + while IFS=, read -r package _ _ module version; do + [[ -z "${package}" ]] && continue + + repo="$(repo_field "${module}" repo)" \ + || die "${REPOS_MAP} has no entry for ${module}." \ + "Run 'make third-party-notices-repos' and commit the result." + subdir="$(repo_field "${module}" subdir)" || subdir="" + + origin_tag="$(origin_ref_and_hash "${module}" "${version}" | sed -n 1p)" + origin_hash="$(origin_ref_and_hash "${module}" "${version}" | sed -n 2p)" + + # Ref candidates, most specific first. Never a branch ref. Commit + # hashes (pseudo-version hash, Origin.Hash) are tracked apart from tag + # names: go.googlesource.com serves a tag under refs/tags/ but a raw + # commit only under its bare hash, so qualifying a hash the same way + # 404s a pseudo-versioned module such as google.golang.org/protobuf. + local tag_refs=() hash_refs=() + plain_version="$(normalize_version "${version}")" + pseudo_version_hash_value="$(pseudo_version_hash "${version}")" + [[ -n "${origin_tag}" ]] && tag_refs+=( "${origin_tag}" ) + if [[ -n "${pseudo_version_hash_value}" ]]; then + hash_refs+=( "${pseudo_version_hash_value}" ) + else + [[ -n "${subdir}" ]] && tag_refs+=( "${subdir}/${plain_version}" ) + tag_refs+=( "${plain_version}" ) + fi + [[ -n "${origin_hash}" ]] && hash_refs+=( "${origin_hash}" ) + + local refs=() tag_ref + if (( ${#tag_refs[@]} > 0 )); then + case "${repo}" in + https://go.googlesource.com/*) + for tag_ref in "${tag_refs[@]}"; do refs+=( "refs/tags/${tag_ref}" ); done + ;; + *) + refs+=( "${tag_refs[@]}" ) + ;; + esac + fi + (( ${#hash_refs[@]} > 0 )) && refs+=( "${hash_refs[@]}" ) + (( ${#refs[@]} > 0 )) || die "no ref candidates for ${module}@${version}." + + relative="$(license_dir_within_module "${package}" "${module}")" \ + || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." + + local license_file_count=0 + while IFS= read -r license_file; do + [[ -z "${license_file}" ]] && continue + license_file_count=$(( license_file_count + 1 )) + name="$(basename "${license_file}")" + path_in_module="${relative:+${relative}/}${name}" + [[ -f "${VENDOR_DIR}/${module}/${path_in_module}" ]] \ + || die "${VENDOR_DIR}/${module}/${path_in_module} does not exist." + want_sha="$(sha256_of_file "${VENDOR_DIR}/${module}/${path_in_module}")" + + # Both layouts: a submodule may ship its own licence or inherit the + # repository root's. Content decides which is real. Built as an + # array rather than an unquoted ${x:+...} expansion, which would + # word-split a path containing whitespace or a glob character. + local paths=() + [[ -n "${subdir}" ]] && paths+=( "${subdir}/${path_in_module}" ) + paths+=( "${path_in_module}" ) + + found_url="" + local try_ref try_path candidate remote_sha_value + for try_ref in "${refs[@]}"; do + for try_path in "${paths[@]}"; do + candidate="$(blob_url "${repo}" "${try_ref}" "${try_path}")" + # remote_sha's own exit status must gate the match: curl + # failing (404, DNS, timeout, rate-limit) yields no bytes, + # and sha256 of no bytes is a real, fixed hash value — so + # checking only the printed string would treat a failed + # fetch as a match against any zero-byte vendored file. + if remote_sha_value="$(remote_sha "${candidate}")" && [[ "${remote_sha_value}" == "${want_sha}" ]]; then + found_url="${candidate}" + break 2 + fi + done + done + + if [[ -z "${found_url}" ]]; then + log "UNVERIFIED ${module}@${version} ${path_in_module}" + failures=$(( failures + 1 )) + continue + fi + printf '%s\t%s\t%s\t%s\n' "${module}" "${version}" "${path_in_module}" "${found_url}" >> "${verified_urls_tmp_file}" + done < <(license_files_for "${VENDOR_DIR}/${module}${relative:+/${relative}}") + + if (( license_file_count == 0 )); then + log "UNVERIFIED ${module}@${version} — no license file found for ${package}" + failures=$(( failures + 1 )) + fi + done < "${INDEX_FILE}" + + (( failures == 0 )) || die \ + "${failures} license file(s) could not be matched to a verified upstream URL." \ + "Every URL must serve bytes identical to the vendored copy; none of the" \ + "candidates did. The repository mapping may be stale — re-run" \ + "'make third-party-notices-repos' before investigating further." + + { + printf '# Verified upstream URL for every license file the notices document links.\n' + printf '# Generated by hack/verify-license-urls.sh. Each URL was fetched and its\n' + printf '# sha256 matched against the vendored copy, so no entry is a dead or wrong link.\n' + printf '# Covers the shipped set only: build- and test-only dependencies are excluded.\n' + printf '# module\tversion\tlicense-path\turl\n' + LC_ALL=C sort -u "${verified_urls_tmp_file}" + } > "${URLS_OUTPUT}" + rm -f "${verified_urls_tmp_file}" + + log "Wrote ${URLS_OUTPUT} ($(LC_ALL=C grep -vc '^#' "${URLS_OUTPUT}") verified URLs)" + exit 0 +} + +if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then + main "$@" +fi From bb8f92487fc3bc8ed17acb449ab0302723a91ebd Mon Sep 17 00:00:00 2001 From: Abrar Shivani Date: Thu, 27 Aug 2026 17:40:23 -0700 Subject: [PATCH 2/3] List the dependencies of the libnvidia-container libraries the image ships The application stage copies the extracted deb and rpm payloads into the image, so it ships libnvidia-container.so, libnvidia-container.a, libnvidia-container-go.so and nvidia-container-cli alongside this repository's own commands. Those objects carry third-party code that the notices did not mention: five Go modules linked into libnvidia-container-go.so, and three C libraries statically linked into libnvidia-container.so. The Go modules join the existing index rather than forming a second table. What ships is one filesystem, so a module both trees pull at a different version is two honest rows: runtime-spec appears at v1.2.0 and v1.3.0, and x/sys at the two package roots go-licenses attributes for each tree. The tree a row was read from moves into the row as a sixth field, since it is now a property of the row rather than of the table. The C libraries get their own section. elftoolchain and nvidia-modprobe ship no license file of their own, so their terms are the per-file copyright blocks scraped from the sources actually compiled in. libtirpc does ship COPYING, and its Location is checked by fetching it and comparing it byte for byte with the copy in the archive. nvidia-modprobe's COPYING is deliberately not linked: it is GPL-2.0 and covers the nvidia-modprobe binaries, which are not built or shipped here, while the modprobe-utils sources that are compiled in are MIT. The dependency set is derived from the submodule at its pinned commit, so a bump shows up as a diff here rather than changing silently. Signed-off-by: Abrar Shivani --- THIRD_PARTY_NOTICES.md | 2315 ++++++++++++++++++++- hack/generate-third-party-notices.sh | 497 ++++- hack/generate-third-party-notices_test.sh | 43 +- hack/license-urls.tsv | 4 + hack/module-repos.tsv | 4 + hack/resolve-module-repos.sh | 5 +- hack/verify-license-urls.sh | 20 +- 7 files changed, 2814 insertions(+), 74 deletions(-) diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md index 22321c59a..df5d961ce 100644 --- a/THIRD_PARTY_NOTICES.md +++ b/THIRD_PARTY_NOTICES.md @@ -9,15 +9,22 @@ under `cmd/`. The `nvidia-container-runtime-hook`, `nvidia-container-runtime`, `nvidia-container-runtime.cdi`, `nvidia-container-runtime.legacy`, `nvidia-ctk` and `nvidia-cdi-hook` commands ship in the deb and rpm packages. The `nvidia-ctk-installer` command ships in the `container-toolkit` image. + +The image also ships the extracted deb and rpm payloads under `/artifacts`, +which carry libnvidia-container's `libnvidia-container.so`, +`libnvidia-container.a`, `libnvidia-container-go.so` and `nvidia-container-cli` +built from the `third_party/libnvidia-container` submodule. Its Go modules are +listed alongside this repository's own below, and the C libraries statically +linked into those objects are listed under Bundled C Dependencies. Where the +submodule and this repository link the same module at different versions, both +copies ship and both are listed. + Go standard library packages are excluded; they are covered by the license of -the Go distribution itself. +the Go distribution itself. Modules that no shipped command or library links +are not listed; those are vendored only for tests and build tooling. -Each dependency is listed with the version redistributed and a link to the -license file in that version's upstream source. Every link was verified by -fetching it and comparing its contents against the copy vendored here, so each -one resolves to the same license text reproduced below. Modules that no command -under `cmd/` links are not listed; those are vendored only for this module's own -tests and build tooling. +Each dependency is listed with the version redistributed, and its Location +links to the license file in that version's upstream repository. The `container-toolkit` image uses `nvcr.io/nvidia/distroless/go` as a base image. All of the OSS packages and source included in this image can be found at @@ -31,6 +38,7 @@ busybox binary is added to the image, which is licensed under GPLv2. | `github.com/Masterminds/semver/v3` | v3.5.0 | MIT | [LICENSE.txt](https://github.com/Masterminds/semver/blob/v3.5.0/LICENSE.txt) | | `github.com/NVIDIA/go-nvlib/pkg` | v0.12.0 | Apache-2.0 | [LICENSE](https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/LICENSE) / [NOTICE](https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/NOTICE) | | `github.com/NVIDIA/go-nvml/pkg` | v0.13.3-1 | Apache-2.0 | [LICENSE](https://github.com/NVIDIA/go-nvml/blob/v0.13.3-1/LICENSE) | +| `github.com/cilium/ebpf` | v0.8.0 | MIT | [LICENSE](https://github.com/cilium/ebpf/blob/v0.8.0/LICENSE) | | `github.com/containerd/log` | v0.1.0 | Apache-2.0 | [LICENSE](https://github.com/containerd/log/blob/v0.1.0/LICENSE) | | `github.com/containerd/nri/pkg` | v0.12.1 | Apache-2.0 | [LICENSE](https://github.com/containerd/nri/blob/v0.12.1/LICENSE) | | `github.com/containerd/ttrpc` | v1.2.7 | Apache-2.0 | [LICENSE](https://github.com/containerd/ttrpc/blob/v1.2.7/LICENSE) | @@ -43,6 +51,7 @@ busybox binary is added to the image, which is licensed under GPLv2. | `github.com/moby/sys/reexec` | v0.1.0 | Apache-2.0 | [LICENSE](https://github.com/moby/sys/blob/reexec/v0.1.0/LICENSE) | | `github.com/opencontainers/cgroups/devices/config` | v0.0.7 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/cgroups/blob/v0.0.7/LICENSE) | | `github.com/opencontainers/runc` | v1.4.3 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runc/blob/v1.4.3/LICENSE) / [NOTICE](https://github.com/opencontainers/runc/blob/v1.4.3/NOTICE) | +| `github.com/opencontainers/runtime-spec/specs-go` | v1.2.0 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runtime-spec/blob/v1.2.0/LICENSE) | | `github.com/opencontainers/runtime-spec/specs-go` | v1.3.0 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runtime-spec/blob/v1.3.0/LICENSE) | | `github.com/opencontainers/runtime-tools` | v0.9.1-0.20251114084447-edf4cb3d2116 | Apache-2.0 | [LICENSE](https://github.com/opencontainers/runtime-tools/blob/edf4cb3d2116/LICENSE) | | `github.com/pelletier/go-toml` | v1.9.5 | Apache-2.0 / MIT | [LICENSE](https://github.com/pelletier/go-toml/blob/v1.9.5/LICENSE) | @@ -53,6 +62,7 @@ busybox binary is added to the image, which is licensed under GPLv2. | `github.com/urfave/cli/v3` | v3.10.1 | MIT | [LICENSE](https://github.com/urfave/cli/blob/v3.10.1/LICENSE) | | `golang.org/x/mod/semver` | v0.38.0 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/mod/+/refs/tags/v0.38.0/LICENSE) / [PATENTS](https://go.googlesource.com/mod/+/refs/tags/v0.38.0/PATENTS) | | `golang.org/x/sys` | v0.47.0 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE) / [PATENTS](https://go.googlesource.com/sys/+/refs/tags/v0.47.0/PATENTS) | +| `golang.org/x/sys/unix` | v0.46.0 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/sys/+/refs/tags/v0.46.0/LICENSE) / [PATENTS](https://go.googlesource.com/sys/+/refs/tags/v0.46.0/PATENTS) | | `google.golang.org/genproto/googleapis/rpc/status` | v0.0.0-20260414002931-afd174a4e478 | Apache-2.0 | [LICENSE](https://github.com/googleapis/go-genproto/blob/afd174a4e478/LICENSE) | | `google.golang.org/grpc` | v1.82.1 | Apache-2.0 | [AUTHORS](https://github.com/grpc/grpc-go/blob/v1.82.1/AUTHORS) / [LICENSE](https://github.com/grpc/grpc-go/blob/v1.82.1/LICENSE) / [NOTICE.txt](https://github.com/grpc/grpc-go/blob/v1.82.1/NOTICE.txt) | | `google.golang.org/protobuf` | v1.36.11 | BSD-3-Clause | [LICENSE](https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/LICENSE) / [PATENTS](https://go.googlesource.com/protobuf/+/refs/tags/v1.36.11/PATENTS) | @@ -62,6 +72,19 @@ busybox binary is added to the image, which is licensed under GPLv2. | `tags.cncf.io/container-device-interface` | v1.1.0 | Apache-2.0 | [LICENSE](https://github.com/cncf-tags/container-device-interface/blob/v1.1.0/LICENSE) | | `tags.cncf.io/container-device-interface/specs-go` | v1.1.0 | Apache-2.0 | [LICENSE](https://github.com/cncf-tags/container-device-interface/blob/specs-go/v1.1.0/LICENSE) | +## Bundled C Dependency Index + +`Location` is the dependency's own license file upstream, pinned to the version +built here and checked by fetching it and comparing it byte for byte with the +copy inside the archive. Where a dependency has no license file to link, the +column says why; its terms are the per-file copyright notices reproduced below. + +| Dependency | Version | Built when | License (declared) | Pinned in | Location | +|------------|---------|------------|--------------------|-----------|----------| +| `elftoolchain` | 0.7.1 | `WITH_LIBELF=no` | BSD-2-Clause AND BSD-3-Clause | `third_party/libnvidia-container/mk/elftoolchain.mk` | none in this release; the terms are the per-file notices reproduced below | +| `libtirpc` | 1.3.2 | `WITH_TIRPC=yes` | BSD-3-Clause | `third_party/libnvidia-container/mk/libtirpc.mk` | [COPYING](https://git.linux-nfs.org/?p=steved/libtirpc.git;a=blob_plain;f=COPYING;hb=refs/tags/libtirpc-1-3-2) | +| `nvidia-modprobe` | 550.54.14 | `always` | MIT | `third_party/libnvidia-container/mk/nvidia-modprobe.mk` | not the archive's COPYING, which is GPL-2.0 and covers binaries this repository does not ship; the terms are the per-file notices reproduced below | + ## Go Module License Texts ### github.com/Masterminds/semver/v3 @@ -541,6 +564,43 @@ the PCI ID Project at https://pci-ids.ucw.cz/. ``` +### github.com/cilium/ebpf + +* Version: v0.8.0 +* License: MIT + +#### LICENSE + + + +```text +MIT License + +Copyright (c) 2017 Nathan Sweet +Copyright (c) 2018, 2019 Cloudflare +Copyright (c) 2019 Authors of Cilium + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +``` + + ### github.com/containerd/log * Version: v0.1.0 @@ -3085,6 +3145,211 @@ See also http://www.apache.org/dev/crypto.html and/or seek legal counsel. ``` +### github.com/opencontainers/runtime-spec/specs-go + +* Version: v1.2.0 +* License: Apache-2.0 + +#### LICENSE + + + +```text + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + Copyright 2015 The Linux Foundation. + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. + +``` + + ### github.com/opencontainers/runtime-spec/specs-go * Version: v1.3.0 @@ -4458,26 +4723,97 @@ shall terminate as of the date such litigation is filed. ``` -### google.golang.org/genproto/googleapis/rpc/status +### golang.org/x/sys/unix -* Version: v0.0.0-20260414002931-afd174a4e478 -* License: Apache-2.0 +* Version: v0.46.0 +* License: BSD-3-Clause #### LICENSE - + ```text +Copyright 2009 The Go Authors. - Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ - - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION - - 1. Definitions. +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: - "License" shall mean the terms and conditions for use, reproduction, + * Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. + * Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. + * Neither the name of Google LLC nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +``` + +#### PATENTS + + + +```text +Additional IP Rights Grant (Patents) + +"This implementation" means the copyrightable works distributed by +Google as part of the Go project. + +Google hereby grants to You a perpetual, worldwide, non-exclusive, +no-charge, royalty-free, irrevocable (except as stated in this section) +patent license to make, have made, use, offer to sell, sell, import, +transfer and otherwise run, modify and propagate the contents of this +implementation of Go, where such license applies only to those patent +claims, both currently owned or controlled by Google and acquired in +the future, licensable by Google that are necessarily infringed by this +implementation of Go. This grant does not include claims that would be +infringed only as a consequence of further modification of this +implementation. If you or your agent or exclusive licensee institute or +order or agree to the institution of patent litigation against any +entity (including a cross-claim or counterclaim in a lawsuit) alleging +that this implementation of Go or any code incorporated within this +implementation of Go constitutes direct or contributory patent +infringement, or inducement of patent infringement, then any patent +rights granted to you under this License for this implementation of Go +shall terminate as of the date such litigation is filed. + +``` + + +### google.golang.org/genproto/googleapis/rpc/status + +* Version: v0.0.0-20260414002931-afd174a4e478 +* License: Apache-2.0 + +#### LICENSE + + + +```text + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document. "Licensor" shall mean the copyright owner or entity authorized by @@ -6101,3 +6437,1944 @@ limitations under the License. ``` +## Bundled C Dependency License Texts + +### elftoolchain + +* Version: 0.7.1 +* Declared license: BSD-2-Clause AND BSD-3-Clause +* Built when: `WITH_LIBELF=no` +* Pinned in: `third_party/libnvidia-container/mk/elftoolchain.mk` +* Source: https://sourceforge.net/projects/elftoolchain/files/Sources/elftoolchain-0.7.1/elftoolchain-0.7.1.tar.bz2 +* Notices: 19 distinct, gathered from 66 compiled or installed source files + +```text +Copyright (c) 2006,2008-2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: _libelf.h 3174 2015-03-27 17:13:41Z emaste $ +---------------------------------------------------------------------- +Copyright (c) 2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS `AS IS' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: _libelf_ar.h 3013 2014-03-23 06:16:59Z jkoshy $ +---------------------------------------------------------------------- +Copyright (c) 2008-2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: _libelf_config.h 3168 2015-02-24 19:17:47Z emaste $ +---------------------------------------------------------------------- +Copyright (c) 2006,2008,2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008-2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008-2009,2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008,2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008-2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: elf_types.m4 321 2009-03-07 16:59:14Z jkoshy $ +---------------------------------------------------------------------- +Copyright (c) 2006-2011 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2008 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: gelf.h 3174 2015-03-27 17:13:41Z emaste $ +---------------------------------------------------------------------- +Copyright (c) 2006,2008-2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: libelf.h 3174 2015-03-27 17:13:41Z emaste $ +---------------------------------------------------------------------- +Copyright (c) 2006,2008,2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS `AS IS' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2006,2009,2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS `AS IS' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2009 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: _elftc.h 3244 2015-08-31 19:53:08Z emaste $ +---------------------------------------------------------------------- +Copyright (c) 1991, 1993 +The Regents of the University of California. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. +3. Neither the name of the University nor the names of its contributors + may be used to endorse or promote products derived from this software + without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2010 Joseph Koshy +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$Id: elfdefinitions.h 3403 2016-02-13 15:39:27Z jkoshy $ + +``` + +### libtirpc + +* Version: 1.3.2 +* Declared license: BSD-3-Clause +* Built when: `WITH_TIRPC=yes` +* Pinned in: `third_party/libnvidia-container/mk/libtirpc.mk` +* Source: https://downloads.sourceforge.net/project/libtirpc/libtirpc/1.3.2/libtirpc-1.3.2.tar.bz2 +* Notices: 87 distinct, gathered from 112 compiled or installed source files + +```text +--- COPYING --- +/* + * Copyright (c) Copyright (c) Bull S.A. 2005 All Rights Reserved. + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 1988 by Sun Microsystems, Inc. +---------------------------------------------------------------------- + auth_gss.c + + RPCSEC_GSS client routines. + + Copyright (c) 2000 The Regents of the University of Michigan. + All rights reserved. + + Copyright (c) 2000 Dug Song . + All rights reserved, all wrongs reversed. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + + 1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + 3. Neither the name of the University nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED + WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF + MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF + LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +auth_none.c +Creates a client authentication handle for passing "null" +credentials and verifiers to remote systems. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +auth_time.c + +This module contains the private function __rpc_get_time_offset() +which will return the difference in seconds between the local system's +notion of time and a remote server's notion of time. This must be +possible without calling any functions that may invoke the name +service. (netdir_getbyxxx, getXbyY, etc). The function is used in the +synchronize call of the authdes code to synchronize clocks between +NIS+ clients and their servers. + +Note to minimize the amount of duplicate code, portions of the +synchronize() function were folded into this code, and the synchronize +call becomes simply a wrapper around this function. Further, if this +function is called with a timehost it *DOES* recurse to the name +server so don't use it in that mode if you are doing name service code. + +Copyright (c) 1992 Sun Microsystems Inc. +All rights reserved. + +Side effects : +When called a client handle to a RPCBIND process is created +and destroyed. Two strings "netid" and "uaddr" are malloc'd +and returned. The SIGALRM processing is modified only if +needed to deal with TCP connections. +---------------------------------------------------------------------- +auth_unix.c, Implements UNIX style authentication parameters. + +Copyright (C) 1984, Sun Microsystems, Inc. + +The system is very weak. The client uses no encryption for it's +credentials and only sends null verifiers. The server sends backs +null verifiers or optionally a verifier that suggests a new short hand +for the credentials. +---------------------------------------------------------------------- +Copyright (c) 1986-1991 by Sun Microsystems Inc. +---------------------------------------------------------------------- + authgss_prot.c + + Copyright (c) 2000 The Regents of the University of Michigan. + All rights reserved. + + Copyright (c) 2000 Dug Song . + All rights reserved, all wrongs reversed. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + + 1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + 3. Neither the name of the University nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED + WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF + MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF + LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +authunix_prot.c +XDR for UNIX style authentication parameters for RPC + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2018, Oracle America, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 1987 by Sun Microsystems, Inc. + +Portions Copyright(C) 1996, Jason Downs. All rights reserved. +---------------------------------------------------------------------- +clnt_bcast.c +Client interface to broadcast service. + +Copyright (C) 1988, Sun Microsystems, Inc. + +The following is kludged-up support for simple rpc broadcasts. +Someday a large, complicated system will replace these routines. +---------------------------------------------------------------------- +debug.h -- debugging routines for libtirpc + +Copyright (c) 2020 SUSE LINUX GmbH, Nuernberg, Germany. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2010, Oracle America, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of the "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +clnt_perror.c + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +clnt_raw.c + +Copyright (C) 1984, Sun Microsystems, Inc. + +Memory based rpc for simple testing and timing. +Interface to create an rpc client and server in the same process. +This lets us similate rpc and get round trip overhead, without +any interference from the kernel. +---------------------------------------------------------------------- +clnt_tcp.c, Implements a TCP/IP based, client side RPC. + +Copyright (C) 1984, Sun Microsystems, Inc. + +TCP based RPC supports 'batched calls'. +A sequence of calls may be batched-up in a send buffer. The rpc call +return immediately to the client even though the call was not necessarily +sent. The batching occurs if the results' xdr routine is NULL (0) AND +the rpc timeout value is zero (see clnt.h, rpc). + +Clients should NOT casually batch calls that in fact return results; that is, +the server side should be aware that a call is batched and not produce any +return message. Batched calls that produce many result messages can +deadlock (netlock) the client and the server.... + +Now go hang yourself. +---------------------------------------------------------------------- +Copyright (c) 1996 +Bill Paul . All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. +3. All advertising materials mentioning features or use of this software + must display the following acknowledgement: +This product includes software developed by Bill Paul. +4. Neither the name of the author nor the names of any co-contributors + may be used to endorse or promote products derived from this software + without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY Bill Paul AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL Bill Paul OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +debug.c -- debugging routines for libtirpc + +Copyright (C) 2014 Red Hat, Steve Dickson + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +debug.h -- debugging routines for libtirpc + +Copyright (C) 2014 Red Hat, Steve Dickson + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +des_crypt.c, DES encryption library routines +Copyright (C) 1986, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (C) 1992 Eric Young +---------------------------------------------------------------------- +Copyright 2003 Niels Provos +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. +3. The name of the author may not be used to endorse or promote products + derived from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR +IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 1989 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2001 Dima Dorfman. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +---------------------------------------------------------------------- +publickey.c +Copyright (C) 1986, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 1984 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 1985 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 1990, 1991 Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2010, Oracle America, Inc. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + + * Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + * Redistributions in binary form must reproduce the above + copyright notice, this list of conditions and the following + disclaimer in the documentation and/or other materials + provided with the distribution. + * Neither the name of the "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS + "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT + LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS + FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE + COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, + INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE + GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, + WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE + OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +pmap_clnt.c +Client interface to pmap rpc service. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +pmap_getmap.c +Client interface to pmap rpc service. +contains pmap_getmaps, which is only tcp service involved + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +pmap_getport.c +Client interface to pmap rpc service. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +pmap_prot.c +Protocol for the local binder service, or pmap. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +pmap_prot2.c +Protocol for the local binder service, or pmap. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +pmap_rmt.c +Client interface to pmap rpc service. +remote call and broadcast service + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +rpc_callmsg.c + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 1986 - 1991 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2013, Oracle America, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +rpc_prot.c + +Copyright (C) 1984, Sun Microsystems, Inc. + +This set of routines implements the rpc message definition, +its serializer and some common rpc utility routines. +The routines are meant for various implementations of rpc - +they are NOT for the rpc client or rpc service implementations! +Because authentication stuff is easy and is part of rpc, the opaque +routines are also in this program. +---------------------------------------------------------------------- +Copyright (c) 1986-1991 by Sun Microsystems Inc. +In addition, portions of such source code were derived from Berkeley +4.3 BSD under license from the Regents of the University of +California. +---------------------------------------------------------------------- +rpcb_prot.c +XDR routines for the rpcbinder version 3. + +Copyright (C) 1984, 1988, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright 1991 Sun Microsystems, Inc. +rpcb_stat_xdr.c +---------------------------------------------------------------------- +svc.c, Server-side remote procedure call interface. + +There are two sets of procedures here. The xprt routines are +for handling transport handles. The svc routines handle the +list of service routines. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- + svc_auth_gss.c + + Copyright (c) 2000 The Regents of the University of Michigan. + All rights reserved. + + Copyright (c) 2000 Dug Song . + All rights reserved, all wrongs reversed. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + + 1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + 3. Neither the name of the University nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED + WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF + MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF + LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- + svc_auth_none.c + + Copyright (c) 2000 The Regents of the University of Michigan. + All rights reserved. + + Copyright (c) 2000 Dug Song . + All rights reserved, all wrongs reversed. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + + 1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + 3. Neither the name of the University nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED + WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF + MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF + LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + + $Id: svc_auth_none.c,v 1.1 2004/10/22 17:24:30 bfields Exp $ +---------------------------------------------------------------------- +svc_auth_unix.c +Handles UNIX flavor authentication parameters on the service side of rpc. +There are two svc auth implementations here: AUTH_UNIX and AUTH_SHORT. +_svcauth_unix does full blown unix style uid,gid+gids auth, +_svcauth_short uses a shorthand auth to index into a cache of longhand auths. +Note: the shorthand has been gutted for efficiency. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +xdr.c, Generic XDR routines implementation. + +Copyright (C) 1986, Sun Microsystems, Inc. + +These are the "generic" xdr routines used to serialize and de-serialize +most common data items. See xdr.h for more info on the interface to +xdr. +---------------------------------------------------------------------- +xdr_array.c, Generic XDR routines impelmentation. + +Copyright (C) 1984, Sun Microsystems, Inc. + +These are the "non-trivial" xdr primitives used to serialize and de-serialize +arrays. See xdr.h for more info on the interface to xdr. +---------------------------------------------------------------------- +xdr_float.c, Generic XDR routines implementation. + +Copyright (C) 1984, Sun Microsystems, Inc. + +These are the "floating point" xdr routines used to (de)serialize +most common data items. See xdr.h for more info on the interface to +xdr. +---------------------------------------------------------------------- +xdr_mem.h, XDR implementation using memory buffers. + +Copyright (C) 1984, Sun Microsystems, Inc. + +If you have some data to be interpreted as external data representation +or to be converted to external data representation in a memory buffer, +then this is the package for you. +---------------------------------------------------------------------- +xdr_rec.c, Implements TCP/IP based XDR streams with a "record marking" +layer above tcp (for rpc's use). + +Copyright (C) 1984, Sun Microsystems, Inc. + +These routines interface XDRSTREAMS to a tcp/ip connection. +There is a record marking layer between the xdr stream +and the tcp transport level. A record is composed on one or more +record fragments. A record fragment is a thirty-two bit header followed +by n bytes of data, where n is contained in the header. The header +is represented as a htonl(u_long). Thegh order bit encodes +whether or not the fragment is the last fragment of the record +(1 => fragment is last, 0 => more fragments to follow. +The other 31 bits encode the byte length of the fragment. +---------------------------------------------------------------------- +xdr_reference.c, Generic XDR routines impelmentation. + +Copyright (C) 1987, Sun Microsystems, Inc. + +These are the "non-trivial" xdr primitives used to serialize and de-serialize +"pointers". See xdr.h for more info on the interface to xdr. +---------------------------------------------------------------------- +xdr_sizeof.c + +Copyright 1990 Sun Microsystems, Inc. + +General purpose routine to see how much space something will use +when serialized using XDR. +---------------------------------------------------------------------- +xdr_stdio.c, XDR implementation on standard i/o file. + +Copyright (C) 1984, Sun Microsystems, Inc. + +This set of routines implements a XDR on a stdio stream. +XDR_ENCODE serializes onto the stream, XDR_DECODE de-serializes +from the stream. +---------------------------------------------------------------------- +Copyright (c) 1997,98 The NetBSD Foundation, Inc. +All rights reserved. + +This code is derived from software contributed to The NetBSD Foundation +by J.T. Conklin. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS +``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED +TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS +BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)auth.h 1.17 88/02/08 SMI +from: @(#)auth.h 2.3 88/08/07 4.0 RPCSRC +from: @(#)auth.h 1.43 98/02/02 SMI +$FreeBSD: src/include/rpc/auth.h,v 1.20 2003/01/01 18:48:42 schweikh Exp $ +---------------------------------------------------------------------- +auth.h, Authentication interface. + +Copyright (C) 1984, Sun Microsystems, Inc. + +The data structures are completely opaque to the client. The client +is required to pass an AUTH * to routines that create rpc +"sessions". +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)auth_des.h 2.2 88/07/29 4.0 RPCSRC +from: @(#)auth_des.h 1.14 94/04/25 SMI +---------------------------------------------------------------------- + auth_gss.h + + Copyright (c) 2000 The Regents of the University of Michigan. + All rights reserved. + + Copyright (c) 2000 Dug Song . + All rights reserved, all wrongs reversed. + + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + + 1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + 2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + 3. Neither the name of the University nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + + THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED + WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF + MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR + BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF + LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)auth_unix.h 1.8 88/02/08 SMI +from: @(#)auth_unix.h 2.2 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/auth_unix.h,v 1.11 2002/03/23 17:24:55 imp Exp $ +---------------------------------------------------------------------- +auth_unix.h, Protocol for UNIX style authentication parameters for RPC + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2010, Oracle America, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of the "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)clnt.h 1.31 94/04/29 SMI +from: @(#)clnt.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/clnt.h,v 1.21 2003/01/24 01:47:55 fjoe Exp $ +---------------------------------------------------------------------- +Copyright (c) 1984 - 1991 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 1986 - 1991, 1994, 1996, 1997 by Sun Microsystems, Inc. +All rights reserved. +---------------------------------------------------------------------- +Generic DES driver interface +Keep this file hardware independent! +Copyright (c) 1986 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +@(#)des_crypt.h 2.1 88/08/11 4.0 RPCSRC; from 1.4 88/02/08 (C) 1986 SMI +$FreeBSD: src/include/rpc/des_crypt.h,v 1.4 2002/03/23 17:24:55 imp Exp $ + +des_crypt.h, des library routine interface +Copyright (C) 1986, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)pmap_clnt.h 1.11 88/02/08 SMI +from: @(#)pmap_clnt.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/pmap_clnt.h,v 1.14 2002/04/28 15:18:45 des Exp $ +---------------------------------------------------------------------- +pmap_clnt.h +Supplies C routines to get to portmap services. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)pmap_prot.h 1.14 88/02/08 SMI +from: @(#)pmap_prot.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/pmap_prot.h,v 1.12 2002/03/23 17:24:55 imp Exp $ +---------------------------------------------------------------------- +pmap_prot.h +Protocol for the local binder service, or pmap. + +Copyright (C) 1984, Sun Microsystems, Inc. + +The following procedures are supported by the protocol: + +PMAPPROC_NULL() returns () + takes nothing, returns nothing + +PMAPPROC_SET(struct pmap) returns (bool_t) + TRUE is success, FALSE is failure. Registers the tuple +[prog, vers, prot, port]. + +PMAPPROC_UNSET(struct pmap) returns (bool_t) +TRUE is success, FALSE is failure. Un-registers pair +[prog, vers]. prot and port are ignored. + +PMAPPROC_GETPORT(struct pmap) returns (long unsigned). +0 is failure. Otherwise returns the port number where the pair +[prog, vers] is registered. It may lie! + +PMAPPROC_DUMP() RETURNS (struct pmaplist *) + +PMAPPROC_CALLIT(unsigned, unsigned, unsigned, string<>) + RETURNS (port, string<>); +usage: encapsulatedresults = PMAPPROC_CALLIT(prog, vers, proc, encapsulatedargs); + Calls the procedure on the local machine. If it is not registered, +this procedure is quite; ie it does not return error information!!! +This procedure only is supported on rpc/udp and calls via +rpc/udp. This routine only passes null authentication parameters. +This file has no interface to xdr routines for PMAPPROC_CALLIT. + +The service supports remote procedure calls on udp/ip or tcp/ip socket 111. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)pmap_rmt.h 1.2 88/02/08 SMI +from: @(#)pmap_rmt.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/pmap_rmt.h,v 1.12 2002/03/23 17:24:55 imp Exp $ +---------------------------------------------------------------------- +Structures and XDR routines for parameters to and replies from +the portmapper remote-call-service. + +Copyright (C) 1986, Sun Microsystems, Inc. +---------------------------------------------------------------------- +rpc.h, Just includes the billions of rpc header files necessary to +do remote procedure calling. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)rpc_msg.h 1.7 86/07/16 SMI +from: @(#)rpc_msg.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/rpc_msg.h,v 1.15 2003/01/01 18:48:42 schweikh Exp $ +---------------------------------------------------------------------- +rpc_msg.h +rpc message definition + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +$FreeBSD: src/include/rpc/rpcb_prot.x,v 1.3 2002/03/13 10:29:06 obrien Exp $ + +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)svc.h 1.35 88/12/17 SMI +from: @(#)svc.h 1.27 94/04/25 SMI +$FreeBSD: src/include/rpc/svc.h,v 1.24 2003/06/15 10:32:01 mbr Exp $ +---------------------------------------------------------------------- +svc.h, Server-side remote procedure call interface. + +Copyright (C) 1986-1993 by Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)svc_auth.h 1.6 86/07/16 SMI +@(#)svc_auth.h 2.1 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/svc_auth.h,v 1.14 2002/03/23 17:24:55 imp Exp $ +---------------------------------------------------------------------- +svc_auth.h, Service side of rpc authentication. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2015, Oracle America, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of "Oracle America, Inc." nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2015, Axentia Technologies AB. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)types.h 1.18 87/07/24 SMI +from: @(#)types.h 2.3 88/08/15 4.0 RPCSRC +$FreeBSD: src/include/rpc/types.h,v 1.10.6.1 2003/12/18 00:59:50 peter Exp $ +---------------------------------------------------------------------- +Copyright (c) 2009, Sun Microsystems, Inc. +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +- Redistributions of source code must retain the above copyright notice, + this list of conditions and the following disclaimer. +- Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. +- Neither the name of Sun Microsystems, Inc. nor the names of its + contributors may be used to endorse or promote products derived + from this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE +LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR +CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF +SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS +INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN +CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE +POSSIBILITY OF SUCH DAMAGE. + +from: @(#)xdr.h 1.19 87/04/22 SMI +from: @(#)xdr.h 2.2 88/07/29 4.0 RPCSRC +$FreeBSD: src/include/rpc/xdr.h,v 1.23 2003/03/07 13:19:40 nectar Exp $ +---------------------------------------------------------------------- +xdr.h, External Data Representation Serialization Routines. + +Copyright (C) 1984, Sun Microsystems, Inc. +---------------------------------------------------------------------- +Copyright (c) 2001 Daniel Eischen . +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. + +$FreeBSD: src/lib/libc/include/un-namespace.h,v 1.13 2003/05/01 19:03:13 nectar Exp $ + +``` + +### nvidia-modprobe + +* Version: 550.54.14 +* Declared license: MIT +* Built when: `always` +* Pinned in: `third_party/libnvidia-container/mk/nvidia-modprobe.mk` +* Source: https://github.com/NVIDIA/nvidia-modprobe/archive/550.54.14.tar.gz +* Notices: 4 distinct, gathered from 5 compiled or installed source files + +```text +Copyright (c) 2013-2023, NVIDIA CORPORATION. + +Permission is hereby granted, free of charge, to any person +obtaining a copy of this software and associated documentation +files (the "Software"), to deal in the Software without +restriction, including without limitation the rights to use, copy, +modify, merge, publish, distribute, sublicense, and/or sell copies +of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS +BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN +ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +This file provides utility functions on Linux for loading the +NVIDIA kernel module and creating NVIDIA device files. +---------------------------------------------------------------------- +(C) Copyright IBM Corporation 2006 + +Copyright (c) 2007 Paulo R. Zanoni, Tiago Vignatti + +Copyright 2009 Red Hat, Inc. + +Copyright (c) 2014 NVIDIA Corporation + +All Rights Reserved. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. +---------------------------------------------------------------------- +(C) Copyright IBM Corporation 2006 + +Copyright (c) 2014-2018 NVIDIA Corporation + +All Rights Reserved. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. +---------------------------------------------------------------------- +Copyright (c) 2016-2018, NVIDIA CORPORATION. + +Permission is hereby granted, free of charge, to any person +obtaining a copy of this software and associated documentation +files (the "Software"), to deal in the Software without +restriction, including without limitation the rights to use, copy, +modify, merge, publish, distribute, sublicense, and/or sell copies +of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS +BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN +ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +This file provides utility functions on Linux for interfacing +with the sysfs/PCI kernel facility. + +``` + diff --git a/hack/generate-third-party-notices.sh b/hack/generate-third-party-notices.sh index 7d4a74bcd..24e7e8d70 100755 --- a/hack/generate-third-party-notices.sh +++ b/hack/generate-third-party-notices.sh @@ -13,7 +13,9 @@ # See the License for the specific language governing permissions and # limitations under the License. # -# Writes THIRD_PARTY_NOTICES.md for the Go modules linked into ./cmd/... (vendored). +# Writes THIRD_PARTY_NOTICES.md for everything the deb, rpm and image ship: +# this repository's vendored Go modules, and the Go and C dependencies of the +# libnvidia-container libraries built from the submodule. set -euo pipefail @@ -28,6 +30,29 @@ MODULES_TXT="${MODULES_TXT:-vendor/modules.txt}" # Exactly what 'make cmds' builds and ships. PACKAGES=("./cmd/...") +# The image ships the extracted deb and rpm payloads, which carry +# libnvidia-container's shared libraries alongside this repository's own +# commands. Its dependencies are therefore redistributed here and are listed +# below. The submodule is pinned by commit, so a bump shows up as a diff in +# this repository rather than changing silently. +LNC_DIR="${LNC_DIR:-third_party/libnvidia-container}" +LNC_GO_DIR="${LNC_GO_DIR:-${LNC_DIR}/src/nvcgo}" +LNC_MODULES_TXT="${LNC_MODULES_TXT:-${LNC_GO_DIR}/vendor/modules.txt}" +LNC_VENDOR_DIR="${LNC_VENDOR_DIR:-${LNC_GO_DIR}/vendor}" +LNC_PACKAGES=("./...") + +# Copyright blocks are scraped out of the C sources actually compiled in; +# elftoolchain and nvidia-modprobe ship no license file of their own. +NOTICE_SOURCE_RE='\.(c|h|m4)$' +BLOCK_SEP='@@@NVIDIA-CONTAINER-TOOLKIT-NOTICE-BLOCK@@@' + +# id|makefile|tar members|license files|notice sources|built when|SPDX|location file|location url or reason +C_DEPS=( + "elftoolchain|${LNC_DIR}/mk/elftoolchain.mk|common libelf||libelf common/_elftc.h common/elfdefinitions.h|WITH_LIBELF=no|BSD-2-Clause AND BSD-3-Clause|none|none in this release; the terms are the per-file notices reproduced below" + "libtirpc|${LNC_DIR}/mk/libtirpc.mk||COPYING|src tirpc|WITH_TIRPC=yes|BSD-3-Clause|COPYING|https://git.linux-nfs.org/?p=steved/libtirpc.git;a=blob_plain;f=COPYING;hb=refs/tags/libtirpc-\$(VERSION_DASHED)" + "nvidia-modprobe|${LNC_DIR}/mk/nvidia-modprobe.mk|modprobe-utils||modprobe-utils|always|MIT|none|not the archive's COPYING, which is GPL-2.0 and covers binaries this repository does not ship; the terms are the per-file notices reproduced below" +) + # Must match the released image platforms; verify_platform_matrix fails on # drift. go-licenses resolves one platform per run, so collection runs per # target and merges. @@ -120,6 +145,12 @@ prepare_workspace() { SAVE_ROOT="$(mktemp -d "${workspace_template}.XXXXXX")" COMBINED_CSV="$(mktemp "${workspace_template}-csv.XXXXXX")" INDEX_FILE="$(mktemp "${workspace_template}-idx.XXXXXX")" + BUNDLED_CSV="$(mktemp "${workspace_template}-bundled-csv.XXXXXX")" + BUNDLED_INDEX="$(mktemp "${workspace_template}-bundled-idx.XXXXXX")" + MERGED_INDEX="$(mktemp "${workspace_template}-merged-idx.XXXXXX")" + C_INDEX="$(mktemp "${workspace_template}-c-idx.XXXXXX")" + WORK_DIR="$(mktemp -d "${workspace_template}-work.XXXXXX")" + mkdir -p "${WORK_DIR}/c" # Composed next to OUTPUT, not in TMPDIR, so the publish below is a rename. local out_dir @@ -127,7 +158,7 @@ prepare_workspace() { mkdir -p "${out_dir}" OUT_TMP="$(mktemp "${out_dir}/.$(basename "${OUTPUT}").XXXXXX")" - trap 'rm -rf "${SAVE_ROOT}"; rm -f "${COMBINED_CSV}" "${INDEX_FILE}" "${OUT_TMP}"' EXIT + trap 'rm -rf "${SAVE_ROOT}" "${WORK_DIR}"; rm -f "${COMBINED_CSV}" "${INDEX_FILE}" "${BUNDLED_CSV}" "${BUNDLED_INDEX}" "${MERGED_INDEX}" "${C_INDEX}" "${OUT_TMP}"' EXIT } collect_runtime() { @@ -188,7 +219,7 @@ collapse_index() { # location comes from hack/license-urls.tsv. Longest-prefix match, because a # license may sit below the module root. annotate_modules() { - awk -v modfile="${MODULES_TXT}" ' + awk -v modfile="${1:-${MODULES_TXT}}" ' BEGIN { FS = OFS = "," while ((getline line < modfile) > 0) { @@ -231,12 +262,75 @@ annotate_modules() { ' } +# Their vendor tree is the submodule's, not this repository's, so a version can +# differ from the one vendored here. +collect_bundled() { + local platform goos goarch save_dir local_module + + [[ -f "${LNC_MODULES_TXT}" ]] \ + || die "${LNC_MODULES_TXT} not found." \ + "Run 'git submodule update --init ${LNC_DIR}' — the image ships this" \ + "submodule's libraries, so its dependencies must be listed." + + local_module="$(cd "${LNC_GO_DIR}" && go list -m 2>/dev/null || true)" + [[ -n "${local_module}" ]] \ + || die "could not determine the module path of ${LNC_GO_DIR} via 'go list -m'." + + for platform in "${PLATFORMS[@]}"; do + goos="${platform%/*}" + goarch="${platform#*/}" + log "Collecting bundled licenses for ${goos}/${goarch}..." + save_dir="${SAVE_ROOT}/bundled/${goos}_${goarch}" + ( + cd "${LNC_GO_DIR}" + export GOFLAGS="-mod=vendor" + GOOS="${goos}" GOARCH="${goarch}" "${GO_LICENSES}" csv "${LNC_PACKAGES[@]}" \ + --ignore="${local_module}" + ) >> "${BUNDLED_CSV}" + done + + [[ -s "${BUNDLED_CSV}" ]] \ + || die "go-licenses produced no entries for the bundled libraries under ${LNC_GO_DIR}." +} + +# One index for the whole image. The two trees are a build-time detail: what +# ships is one filesystem, so a module both trees pull at different versions is +# two honest rows rather than a second table the reader has to reconcile. The +# source tree moves into the row as a sixth field, since it is now per row +# rather than per table. Same package at the same version is one row; the bytes +# are identical, so this repository's own copy wins. +merge_indexes() { + cat <(sed 's/$/,vendor/' "$1") <(sed 's/$/,bundled/' "$2") \ + | LC_ALL=C awk -F, '!seen[$1 FS $5]++' \ + | LC_ALL=C sort -t, -k1,1 -k5,5 +} + +module_source_dir() { + local module="$1" source_kind="$2" + case "${source_kind}" in + vendor) printf '%s' "${VENDOR_DIR}/${module}" ;; + bundled) printf '%s' "${LNC_VENDOR_DIR}/${module}" ;; + *) die "unknown module source kind '${source_kind}' for ${module}." ;; + esac +} + build_indexes() { log "Generating dependency index..." collapse_index "${COMBINED_CSV}" | annotate_modules > "${INDEX_FILE}" + collapse_index "${BUNDLED_CSV}" | annotate_modules "${LNC_MODULES_TXT}" > "${BUNDLED_INDEX}" [[ -s "${INDEX_FILE}" ]] \ || die "go-licenses produced no entries for ${PACKAGES[*]} — refusing to write empty notices file." + [[ -s "${BUNDLED_INDEX}" ]] \ + || die "go-licenses produced no entries for the bundled libraries — refusing to write incomplete notices." + + if cut -d, -f4 "${BUNDLED_INDEX}" | LC_ALL=C grep -qx 'unknown'; then + die "some bundled packages could not be matched to a module in ${LNC_MODULES_TXT}." + fi + + if cut -d, -f5 "${BUNDLED_INDEX}" | LC_ALL=C grep -qx 'unknown'; then + die "some bundled packages could not be matched to a version in ${LNC_MODULES_TXT}." + fi if cut -d, -f4 "${INDEX_FILE}" | LC_ALL=C grep -qx 'unknown'; then die "some runtime packages could not be matched to a module in ${MODULES_TXT}." \ @@ -255,7 +349,9 @@ build_indexes() { "Check the entries reported as Unknown before committing the file." fi - check_override_coverage "${INDEX_FILE}" + merge_indexes "${INDEX_FILE}" "${BUNDLED_INDEX}" > "${MERGED_INDEX}" + + check_override_coverage "${MERGED_INDEX}" } # A dropped dependency would otherwise leave its row in LICENSE_OVERRIDES @@ -272,8 +368,8 @@ check_override_coverage() { done < "${LICENSE_OVERRIDES}" } -# Filter by name: for restricted licenses 'go-licenses save' copies the whole -# module source. +# For restricted licenses 'go-licenses save' copies the whole module source, so +# a name filter is the only thing keeping non-license files out. license_files_for() { local search_dir="$1" license_file file_basename [[ -d "${search_dir}" ]] || return 0 @@ -315,14 +411,14 @@ license_identifier_for() { printf '%s' "${override_identifier:-${default_identifier}}" } -# The first enclosing directory holding a license file wins, which is how -# go-licenses attributes them. +# Nearest enclosing directory wins, matching how go-licenses attributes a +# license to the packages beneath it. license_dir_within_module() { - local module="$2" dir="$1" relative + local module="$2" dir="$1" module_dir="$3" relative_license_dir while :; do - if [[ -n "$(license_files_for "${VENDOR_DIR}/${dir}")" ]]; then - relative="${dir#"${module}"}" - printf '%s' "${relative#/}" + if [[ -n "$(license_files_for "${module_dir}${dir#"${module}"}")" ]]; then + relative_license_dir="${dir#"${module}"}" + printf '%s' "${relative_license_dir#/}" return 0 fi [[ "${dir}" == "${module}" ]] && return 1 @@ -340,14 +436,15 @@ location_for() { printf '%s' "${url}" } -# Mirrors how the License column joins identifiers. -location_cell() { - local package="$1" module="$2" version="$3" +# Joined with ' / ' so the cell lines up with how the License column joins +# identifiers for a module that ships more than one license file. +license_location_links() { + local package="$1" module="$2" version="$3" module_dir="$4" local relative_license_dir license_file_name license_path url cell="" license_file governing_dir - relative_license_dir="$(license_dir_within_module "${package}" "${module}")" \ - || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." \ + relative_license_dir="$(license_dir_within_module "${package}" "${module}" "${module_dir}")" \ + || die "no license file found for ${package} under ${module_dir}." \ "Run 'make vendor' and re-run." - governing_dir="${VENDOR_DIR}/${module}${relative_license_dir:+/${relative_license_dir}}" + governing_dir="${module_dir}${relative_license_dir:+/${relative_license_dir}}" while IFS= read -r license_file; do [[ -z "${license_file}" ]] && continue license_file_name="$(basename "${license_file}")" @@ -363,13 +460,14 @@ location_cell() { } emit_index_table() { - local index="$1" package _url license module version location license_identifier + local index="$1" package _url license module version source_kind location license_identifier module_dir printf '| Package | Version | License | Location |\n' printf '|---------|---------|---------|----------|\n' - while IFS=, read -r package _url license module version; do + while IFS=, read -r package _url license module version source_kind; do [[ -z "${package}" ]] && continue - location="$(location_cell "${package}" "${module}" "${version}")" + module_dir="$(module_source_dir "${module}" "${source_kind}")" + location="$(license_location_links "${package}" "${module}" "${version}" "${module_dir}")" license_identifier="$(license_identifier_for "${package}" "${license:-Unknown}")" # shellcheck disable=SC2016 # backticks are literal markdown here. printf '| `%s` | %s | %s | %s |\n' \ @@ -380,9 +478,9 @@ emit_index_table() { emit_sections() { local index="$1" - local package _url license module version files license_file fence relative_license_dir license_file_name url governing_dir license_identifier + local package _url license module version source_kind files license_file fence relative_license_dir license_file_name url governing_dir license_identifier module_dir - while IFS=, read -r package _url license module version; do + while IFS=, read -r package _url license module version source_kind; do [[ -z "${package}" ]] && continue license_identifier="$(license_identifier_for "${package}" "${license:-Unknown}")" @@ -390,10 +488,11 @@ emit_sections() { printf '* Version: %s\n' "${version:-unknown}" printf '* License: %s\n\n' "${license_identifier}" - relative_license_dir="$(license_dir_within_module "${package}" "${module}")" \ - || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." \ + module_dir="$(module_source_dir "${module}" "${source_kind}")" + relative_license_dir="$(license_dir_within_module "${package}" "${module}" "${module_dir}")" \ + || die "no license file found for ${package} under ${module_dir}." \ "Run 'make vendor' and re-run." - governing_dir="${VENDOR_DIR}/${module}${relative_license_dir:+/${relative_license_dir}}" + governing_dir="${module_dir}${relative_license_dir:+/${relative_license_dir}}" files=() while IFS= read -r license_file; do @@ -422,6 +521,300 @@ emit_sections() { done < "${index}" } +# libnvidia-container statically links these into the shared libraries the +# image ships, so their terms are redistributed here. elftoolchain and +# nvidia-modprobe carry no license file of their own; their terms live in the +# per-file copyright blocks scraped below. + +sha256_of_file() { + if command -v sha256sum >/dev/null 2>&1; then + sha256sum "$1" | awk '{print $1}' + else + shasum -a 256 "$1" | awk '{print $1}' + fi +} + +read_make_var() { + local file="$1" name="$2" make_value + make_value=$(LC_ALL=C sed -n "s/^${name}[[:space:]]*:=[[:space:]]*//p" "${file}" | head -1) + make_value="${make_value%"${make_value##*[![:space:]]}"}" + [[ -n "${make_value}" ]] || die "could not read ${name} from ${file}." + printf '%s' "${make_value}" +} + +expand_make_vars() { + local expanded="$1" version="$2" prefix="${3:-}" + # libtirpc tags releases with the version's dots turned into dashes. + expanded="${expanded//\$(VERSION_DASHED)/${version//./-}}" + expanded="${expanded//\$(VERSION)/${version}}" + expanded="${expanded//\$(PREFIX)/${prefix}}" + # shellcheck disable=SC2016 # matching a literal '$(' left over by make. + case "${expanded}" in + *'$('*) die "unexpanded make variable in '${expanded}'." ;; + esac + printf '%s' "${expanded}" +} + +extract_notice_blocks() { + LC_ALL=C awk -v separator="${BLOCK_SEP}" ' + !in_block && /\/\*/ { in_block = 1; block = "" } + in_block { + line = $0 + sub(/[ \t]*\*\/[ \t]*$/, "", line) + sub(/^[ \t]*\/\*[-*!]?[ \t]?/, "", line) + sub(/^[ \t]*\*[ \t]?/, "", line) + sub(/[ \t]+$/, "", line) + if (line != "" || $0 !~ /\*\//) block = block line "\n" + if ($0 ~ /\*\//) { + if (block ~ /Copyright/) printf "%s%s\n", block, separator + in_block = 0 + } + } + ' "$1" +} + +dedupe_notice_blocks() { + LC_ALL=C awk -v separator="${BLOCK_SEP}" ' + $0 == separator { + gsub(/^\n+/, "", block) + gsub(/\n+$/, "\n", block) + if (block != "" && !(block in seen)) { + seen[block] = 1 + if (emitted_blocks++) print "----------------------------------------------------------------------" + printf "%s", block + } + block = "" + next + } + { block = block $0 "\n" } + END { printf "%d\n", emitted_blocks > "/dev/stderr" } + ' +} + +fetch_license_bytes() { + local url="$1" destination="$2" label="$3" + curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ + --output "${destination}.encoded" "${url}" \ + || die "could not fetch the license location for ${label}:" \ + " ${url}" \ + "This script needs network access; it will not write an unverified link." + case "${url}" in + *'?format=TEXT') + # GNU coreutils spells the decode flag -d, BSD spells it -D. + if base64 -d < "${destination}.encoded" > "${destination}" 2>/dev/null; then + : + elif base64 -D < "${destination}.encoded" > "${destination}" 2>/dev/null; then + : + else + die "could not base64-decode the license location for ${label}:" " ${url}" + fi + ;; + *) + mv -f "${destination}.encoded" "${destination}" + ;; + esac +} + +verify_remote_matches() { + local url="$1" local_file="$2" label="$3" remote_file="$4" + local local_sha remote_sha + fetch_license_bytes "${url}" "${remote_file}" "${label}" + local_sha="$(sha256_of_file "${local_file}")" + remote_sha="$(sha256_of_file "${remote_file}")" + [[ "${local_sha}" == "${remote_sha}" ]] \ + || die "the license location for ${label} does not serve the bytes reproduced here." \ + " url: ${url}" \ + " upstream sha256: ${remote_sha}" \ + " local sha256: ${local_sha}" \ + "Upstream may have retagged, or the URL points at a different revision." +} + +resolve_license_location() { + local dependency_id="$1" location_path="$2" location_url="$3" + local archive_file remote_file + + if [[ "${location_path}" == "none" ]]; then + [[ -n "${location_url}" ]] \ + || die "${dependency_id} declares no license file but gives no reason." + printf '%s' "${location_url}" + return 0 + fi + + archive_file="${C_ROOT}/${location_path}" + [[ -f "${archive_file}" ]] \ + || die "${dependency_id} ${C_VERSION} does not contain ${location_path}, which C_DEPS pins as its license file." + + remote_file="${WORK_DIR}/c/${dependency_id}.location" + verify_remote_matches "${location_url}" "${archive_file}" \ + "${dependency_id} ${C_VERSION} ${location_path}" "${remote_file}" + + printf '[%s](%s)' "${location_path}" "${location_url}" +} + +fetch_c_dependency() { + local dependency_id="$1" makefile="$2" tar_members="$3" + local version prefix url decompress_flag unpack_dir tarball archive_root decompressor + + [[ -f "${makefile}" ]] \ + || die "${makefile} not found." \ + "Run 'git submodule update --init ${LNC_DIR}'." + + version="$(read_make_var "${makefile}" VERSION)" + prefix="$(expand_make_vars "$(read_make_var "${makefile}" PREFIX)" "${version}")" + url="$(expand_make_vars "$(read_make_var "${makefile}" URL)" "${version}" "${prefix}")" + + case "${url}" in + *.tar.bz2) decompress_flag="-j"; decompressor="bzip2" ;; + *.tar.gz|*.tgz) decompress_flag="-z"; decompressor="gzip" ;; + *) die "unsupported archive type for ${dependency_id}: ${url}" ;; + esac + command -v "${decompressor}" >/dev/null 2>&1 \ + || die "${decompressor} is required to unpack ${dependency_id}, but is not installed." + + unpack_dir="${WORK_DIR}/c/${dependency_id}" + tarball="${WORK_DIR}/${dependency_id}.tar" + mkdir -p "${unpack_dir}" + + log "Fetching ${dependency_id} ${version} from ${url}..." + curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ + --output "${tarball}" "${url}" \ + || die "failed to download ${dependency_id} ${version} from ${url}." \ + "This script needs network access; it will not emit a placeholder license." + + local -a member_args=() + local member + # shellcheck disable=SC2086 # the member list is a deliberate word split. + for member in ${tar_members}; do + member_args+=("${prefix}/${member}") + done + tar -C "${unpack_dir}" -x "${decompress_flag}" -f "${tarball}" \ + ${member_args[@]+"${member_args[@]}"} \ + || die "failed to unpack ${dependency_id} ${version} from ${url}." + rm -f "${tarball}" + + archive_root="${unpack_dir}/${prefix}" + [[ -d "${archive_root}" ]] \ + || die "${dependency_id} ${version} did not unpack into '${prefix}/' as ${makefile} expects." + + C_VERSION="${version}" + C_URL="${url}" + C_ROOT="${archive_root}" +} + +collect_c_notices() { + local dependency_record dependency_id makefile tar_members license_files + local notice_paths build_condition declared_license location_path location_url + local notices_file blocks_file path source_file scanned_file_count distinct_notice_count + local location_cell_value + + for dependency_record in "${C_DEPS[@]}"; do + IFS='|' read -r dependency_id makefile tar_members license_files \ + notice_paths build_condition declared_license location_path location_url \ + <<< "${dependency_record}" + + [[ -n "${location_path}" ]] \ + || die "${dependency_id} has no license-location field in C_DEPS." + + fetch_c_dependency "${dependency_id}" "${makefile}" "${tar_members}" + + notices_file="${WORK_DIR}/c/${dependency_id}.notices" + blocks_file="${WORK_DIR}/c/${dependency_id}.blocks" + : > "${notices_file}" + : > "${blocks_file}" + + # shellcheck disable=SC2086 # the path lists are deliberate word splits. + for path in ${license_files}; do + [[ -f "${C_ROOT}/${path}" ]] \ + || die "${dependency_id} ${C_VERSION} does not contain ${path}, which ${makefile} pins as its license file." + printf '%s\n' "--- ${path} ---" >> "${notices_file}" + cat "${C_ROOT}/${path}" >> "${notices_file}" + done + + scanned_file_count=0 + # shellcheck disable=SC2086 + for path in ${notice_paths}; do + [[ -e "${C_ROOT}/${path}" ]] \ + || die "${dependency_id} ${C_VERSION} does not contain ${path}; update C_DEPS." + while IFS= read -r source_file; do + extract_notice_blocks "${source_file}" >> "${blocks_file}" + scanned_file_count=$(( scanned_file_count + 1 )) + done < <(find "${C_ROOT}/${path}" -type f | LC_ALL=C grep -E "${NOTICE_SOURCE_RE}" | LC_ALL=C sort) + done + (( scanned_file_count > 0 )) \ + || die "found no source files to scan for ${dependency_id} under: ${notice_paths}" + + dedupe_notice_blocks < "${blocks_file}" >> "${notices_file}" \ + 2>"${WORK_DIR}/c/${dependency_id}.count" + distinct_notice_count=$(tr -d '[:space:]' < "${WORK_DIR}/c/${dependency_id}.count") + (( distinct_notice_count > 0 )) \ + || die "extracted no copyright notices from ${scanned_file_count} ${dependency_id} source files." \ + "The comment format probably changed; fix extract_notice_blocks." + + [[ -s "${notices_file}" ]] \ + || die "no license text collected for ${dependency_id} ${C_VERSION}." + + location_cell_value="$(resolve_license_location "${dependency_id}" "${location_path}" \ + "$(expand_make_vars "${location_url}" "${C_VERSION}")")" + + printf '%s|%s|%s|%s|%s|%s|%s|%s|%s\n' \ + "${dependency_id}" "${C_VERSION}" "${build_condition}" "${declared_license}" \ + "${C_URL}" "${makefile}" "${scanned_file_count}" "${distinct_notice_count}" \ + "${location_cell_value}" >> "${C_INDEX}" + log " ${dependency_id} ${C_VERSION}: ${distinct_notice_count} distinct notices from ${scanned_file_count} files" + done + + [[ -s "${C_INDEX}" ]] || die "no bundled C dependencies were collected." + + if cut -d'|' -f4 "${C_INDEX}" | LC_ALL=C grep -qE '^$|(^| )Unknown( |$)'; then + die "a bundled C dependency has no declared license identifier." + fi +} + +emit_fenced_file() { + local file="$1" fence + fence="$(fence_for "${file}")" + printf '%stext\n' "${fence}" + cat "${file}" + echo + printf '%s\n' "${fence}" + echo +} + +emit_c_table() { + local dependency_id version build_condition declared_license url makefile + local scanned_file_count distinct_notice_count location + printf '| Dependency | Version | Built when | License (declared) | Pinned in | Location |\n' + printf '|------------|---------|------------|--------------------|-----------|----------|\n' + while IFS='|' read -r dependency_id version build_condition declared_license url makefile \ + scanned_file_count distinct_notice_count location; do + [[ -z "${dependency_id}" ]] && continue + # shellcheck disable=SC2016 # backticks are literal markdown here. + printf '| `%s` | %s | `%s` | %s | `%s` | %s |\n' \ + "${dependency_id}" "${version}" "${build_condition}" "${declared_license}" \ + "${makefile}" "${location}" + done < "${C_INDEX}" +} + +emit_c_sections() { + local dependency_id version build_condition declared_license url makefile + local scanned_file_count distinct_notice_count location + while IFS='|' read -r dependency_id version build_condition declared_license url makefile \ + scanned_file_count distinct_notice_count location; do + [[ -z "${dependency_id}" ]] && continue + printf '### %s\n\n' "${dependency_id}" + printf '* Version: %s\n' "${version}" + printf '* Declared license: %s\n' "${declared_license}" + # shellcheck disable=SC2016 # backticks are literal markdown here. + printf '* Built when: `%s`\n' "${build_condition}" + # shellcheck disable=SC2016 + printf '* Pinned in: `%s`\n' "${makefile}" + printf '* Source: %s\n' "${url}" + printf '* Notices: %s distinct, gathered from %s compiled or installed source files\n\n' \ + "${distinct_notice_count}" "${scanned_file_count}" + emit_fenced_file "${WORK_DIR}/c/${dependency_id}.notices" + done < "${C_INDEX}" +} + compose_document() { require_url_map log "Composing ${OUTPUT}..." @@ -438,15 +831,22 @@ under `cmd/`. The `nvidia-container-runtime-hook`, `nvidia-container-runtime`, `nvidia-container-runtime.cdi`, `nvidia-container-runtime.legacy`, `nvidia-ctk` and `nvidia-cdi-hook` commands ship in the deb and rpm packages. The `nvidia-ctk-installer` command ships in the `container-toolkit` image. + +The image also ships the extracted deb and rpm payloads under `/artifacts`, +which carry libnvidia-container's `libnvidia-container.so`, +`libnvidia-container.a`, `libnvidia-container-go.so` and `nvidia-container-cli` +built from the `third_party/libnvidia-container` submodule. Its Go modules are +listed alongside this repository's own below, and the C libraries statically +linked into those objects are listed under Bundled C Dependencies. Where the +submodule and this repository link the same module at different versions, both +copies ship and both are listed. + Go standard library packages are excluded; they are covered by the license of -the Go distribution itself. +the Go distribution itself. Modules that no shipped command or library links +are not listed; those are vendored only for tests and build tooling. -Each dependency is listed with the version redistributed and a link to the -license file in that version's upstream source. Every link was verified by -fetching it and comparing its contents against the copy vendored here, so each -one resolves to the same license text reproduced below. Modules that no command -under `cmd/` links are not listed; those are vendored only for this module's own -tests and build tooling. +Each dependency is listed with the version redistributed, and its Location +links to the license file in that version's upstream repository. The `container-toolkit` image uses `nvcr.io/nvidia/distroless/go` as a base image. All of the OSS packages and source included in this image can be found at @@ -456,14 +856,32 @@ busybox binary is added to the image, which is licensed under GPLv2. ## Go Module Index EOF - emit_index_table "${INDEX_FILE}" + emit_index_table "${MERGED_INDEX}" + + cat <<'EOF' + +## Bundled C Dependency Index + +`Location` is the dependency's own license file upstream, pinned to the version +built here and checked by fetching it and comparing it byte for byte with the +copy inside the archive. Where a dependency has no license file to link, the +column says why; its terms are the per-file copyright notices reproduced below. + +EOF + emit_c_table cat <<'EOF' ## Go Module License Texts EOF - emit_sections "${INDEX_FILE}" + emit_sections "${MERGED_INDEX}" + + cat <<'EOF' +## Bundled C Dependency License Texts + +EOF + emit_c_sections } > "${OUT_TMP}" # mv, not cp: OUT_TMP is in OUTPUT's directory, so this is a rename(2) and @@ -478,12 +896,15 @@ main() { prepare_workspace collect_runtime + collect_bundled build_indexes + collect_c_notices compose_document - local runtime_count - runtime_count=$(wc -l < "${INDEX_FILE}" | tr -d ' ') - log "Wrote ${OUTPUT} (${runtime_count} Go packages)" + local go_count c_count + go_count=$(wc -l < "${MERGED_INDEX}" | tr -d ' ') + c_count=$(wc -l < "${C_INDEX}" | tr -d ' ') + log "Wrote ${OUTPUT} (${go_count} Go packages, ${c_count} bundled C dependencies)" } # Sourced by the tests and by hack/verify-license-urls.sh, which reuse these diff --git a/hack/generate-third-party-notices_test.sh b/hack/generate-third-party-notices_test.sh index 3e958881b..4a9a5e96d 100755 --- a/hack/generate-third-party-notices_test.sh +++ b/hack/generate-third-party-notices_test.sh @@ -106,25 +106,54 @@ touch "${vendor_fixture}/sigs.k8s.io/yaml/goyaml.v2/LICENSE.libyaml" touch "${vendor_fixture}/gopkg.in/yaml.v3/LICENSE" assert_eq "goyaml.v2" \ "$(VENDOR_DIR="${vendor_fixture}" license_dir_within_module \ - sigs.k8s.io/yaml/goyaml.v2 sigs.k8s.io/yaml)" \ + sigs.k8s.io/yaml/goyaml.v2 sigs.k8s.io/yaml "${vendor_fixture}/sigs.k8s.io/yaml")" \ "license_dir_within_module finds the nearest enclosing license" assert_eq "" \ "$(VENDOR_DIR="${vendor_fixture}" license_dir_within_module \ - sigs.k8s.io/yaml sigs.k8s.io/yaml)" \ + sigs.k8s.io/yaml sigs.k8s.io/yaml "${vendor_fixture}/sigs.k8s.io/yaml")" \ "license_dir_within_module is empty at the module root" # $1 is expanded by the child bash -c, not here. # shellcheck disable=SC2016 assert_fails "license_dir_within_module fails when no license exists" \ env VENDOR_DIR="${vendor_fixture}" bash -c \ - 'source "$1"; license_dir_within_module github.com/absent/mod github.com/absent/mod' \ + 'source "$1"; license_dir_within_module github.com/absent/mod github.com/absent/mod "$2"' \ + _ "${HERE}/generate-third-party-notices.sh" "${vendor_fixture}/github.com/absent/mod" + +# merge_indexes: the two trees become one table, and the tree each row was +# hashed against moves into the row. +merge_runtime="$(mktemp)" +merge_bundled="$(mktemp)" +cat > "${merge_runtime}" <<'IDX' +github.com/opencontainers/runtime-spec/specs-go,ignored,Apache-2.0,github.com/opencontainers/runtime-spec,v1.3.0 +github.com/google/uuid,ignored,BSD-3-Clause,github.com/google/uuid,v1.6.0 +IDX +cat > "${merge_bundled}" <<'IDX' +github.com/opencontainers/runtime-spec/specs-go,ignored,Apache-2.0,github.com/opencontainers/runtime-spec,v1.2.0 +github.com/google/uuid,ignored,BSD-3-Clause,github.com/google/uuid,v1.6.0 +IDX + +assert_eq "3" \ + "$(merge_indexes "${merge_runtime}" "${merge_bundled}" | wc -l | tr -d ' ')" \ + "merge_indexes keeps both versions of a module but collapses an identical pair" + +assert_eq "github.com/google/uuid,ignored,BSD-3-Clause,github.com/google/uuid,v1.6.0,vendor +github.com/opencontainers/runtime-spec/specs-go,ignored,Apache-2.0,github.com/opencontainers/runtime-spec,v1.2.0,bundled +github.com/opencontainers/runtime-spec/specs-go,ignored,Apache-2.0,github.com/opencontainers/runtime-spec,v1.3.0,vendor" \ + "$(merge_indexes "${merge_runtime}" "${merge_bundled}")" \ + "merge_indexes tags each row with its tree, sorts, and prefers this repository's copy" + +# $1 is expanded by the child bash -c, not here. +# shellcheck disable=SC2016 +assert_fails "module_source_dir rejects an unknown source kind" \ + env bash -c 'source "$1"; module_source_dir some/module wat' \ _ "${HERE}/generate-third-party-notices.sh" render="$(mktemp -d)" mkdir -p "${render}/cache/sigs.k8s.io/yaml/goyaml.v2" printf 'Apache text\n' > "${render}/cache/sigs.k8s.io/yaml/goyaml.v2/LICENSE" cat > "${render}/index.csv" <<'IDX' -sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v1.4.0 -gopkg.in/yaml.v3,ignored,MIT,gopkg.in/yaml.v3,v3.0.1 +sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v1.4.0,vendor +gopkg.in/yaml.v3,ignored,MIT,gopkg.in/yaml.v3,v3.0.1,vendor IDX assert_eq '| Package | Version | License | Location |' \ @@ -142,7 +171,7 @@ assert_eq '| `sigs.k8s.io/yaml/goyaml.v2` | v1.4.0 | Apache-2.0 | [LICENSE](http # must abort the whole table, not render with a blank Location cell. mismatch_index="${render}/mismatch-index.csv" cat > "${mismatch_index}" <<'IDX' -sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v9.9.9 +sigs.k8s.io/yaml/goyaml.v2,ignored,Apache-2.0,sigs.k8s.io/yaml,v9.9.9,vendor IDX # $1/$2 are expanded by the child bash -c, not here. # shellcheck disable=SC2016 @@ -152,7 +181,7 @@ assert_fails "emit_index_table fails closed when the URL map has no entry for a bash -c 'source "$1"; emit_index_table "$2"' _ "${HERE}/generate-third-party-notices.sh" "${mismatch_index}" section="$(LICENSE_URLS="${urls_fixture}" VENDOR_DIR="${vendor_fixture}" LICENSES_DIR="${render}/cache" \ - LICENSE_OVERRIDES="${empty_overrides_fixture}" emit_sections "${render}/index.csv" "${render}/cache")" + LICENSE_OVERRIDES="${empty_overrides_fixture}" emit_sections "${render}/index.csv")" assert_eq "* Version: v1.4.0" "$(printf '%s' "${section}" | sed -n 3p)" "section names the version" assert_eq "* License: Apache-2.0" "$(printf '%s' "${section}" | sed -n 4p)" "section names the license" assert_eq "0" "$(printf '%s' "${section}" | LC_ALL=C grep -c '^\* Module: ')" "section no longer names the module" diff --git a/hack/license-urls.tsv b/hack/license-urls.tsv index ddeb6fd3b..6d8c289f2 100644 --- a/hack/license-urls.tsv +++ b/hack/license-urls.tsv @@ -7,6 +7,7 @@ github.com/Masterminds/semver/v3 v3.5.0 LICENSE.txt https://github.com/Mastermin github.com/NVIDIA/go-nvlib v0.12.0 LICENSE https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/LICENSE github.com/NVIDIA/go-nvlib v0.12.0 NOTICE https://github.com/NVIDIA/go-nvlib/blob/v0.12.0/NOTICE github.com/NVIDIA/go-nvml v0.13.3-1 LICENSE https://github.com/NVIDIA/go-nvml/blob/v0.13.3-1/LICENSE +github.com/cilium/ebpf v0.8.0 LICENSE https://github.com/cilium/ebpf/blob/v0.8.0/LICENSE github.com/containerd/log v0.1.0 LICENSE https://github.com/containerd/log/blob/v0.1.0/LICENSE github.com/containerd/nri v0.12.1 LICENSE https://github.com/containerd/nri/blob/v0.12.1/LICENSE github.com/containerd/ttrpc v1.2.7 LICENSE https://github.com/containerd/ttrpc/blob/v1.2.7/LICENSE @@ -22,6 +23,7 @@ github.com/moby/sys/reexec v0.1.0 LICENSE https://github.com/moby/sys/blob/reexe github.com/opencontainers/cgroups v0.0.7 LICENSE https://github.com/opencontainers/cgroups/blob/v0.0.7/LICENSE github.com/opencontainers/runc v1.4.3 LICENSE https://github.com/opencontainers/runc/blob/v1.4.3/LICENSE github.com/opencontainers/runc v1.4.3 NOTICE https://github.com/opencontainers/runc/blob/v1.4.3/NOTICE +github.com/opencontainers/runtime-spec v1.2.0 LICENSE https://github.com/opencontainers/runtime-spec/blob/v1.2.0/LICENSE github.com/opencontainers/runtime-spec v1.3.0 LICENSE https://github.com/opencontainers/runtime-spec/blob/v1.3.0/LICENSE github.com/opencontainers/runtime-tools v0.9.1-0.20251114084447-edf4cb3d2116 LICENSE https://github.com/opencontainers/runtime-tools/blob/edf4cb3d2116/LICENSE github.com/pelletier/go-toml v1.9.5 LICENSE https://github.com/pelletier/go-toml/blob/v1.9.5/LICENSE @@ -34,6 +36,8 @@ github.com/urfave/cli-altsrc/v3 v3.1.0 LICENSE https://github.com/urfave/cli-alt github.com/urfave/cli/v3 v3.10.1 LICENSE https://github.com/urfave/cli/blob/v3.10.1/LICENSE golang.org/x/mod v0.38.0 LICENSE https://go.googlesource.com/mod/+/refs/tags/v0.38.0/LICENSE golang.org/x/mod v0.38.0 PATENTS https://go.googlesource.com/mod/+/refs/tags/v0.38.0/PATENTS +golang.org/x/sys v0.46.0 LICENSE https://go.googlesource.com/sys/+/refs/tags/v0.46.0/LICENSE +golang.org/x/sys v0.46.0 PATENTS https://go.googlesource.com/sys/+/refs/tags/v0.46.0/PATENTS golang.org/x/sys v0.47.0 LICENSE https://go.googlesource.com/sys/+/refs/tags/v0.47.0/LICENSE golang.org/x/sys v0.47.0 PATENTS https://go.googlesource.com/sys/+/refs/tags/v0.47.0/PATENTS google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 LICENSE https://github.com/googleapis/go-genproto/blob/afd174a4e478/LICENSE diff --git a/hack/module-repos.tsv b/hack/module-repos.tsv index a2063ce88..bb9238d40 100644 --- a/hack/module-repos.tsv +++ b/hack/module-repos.tsv @@ -6,6 +6,7 @@ cyphar.com/go-pathrs https://github.com/cyphar/libpathrs go-pathrs github.com/Masterminds/semver/v3 https://github.com/Masterminds/semver github.com/NVIDIA/go-nvlib https://github.com/NVIDIA/go-nvlib github.com/NVIDIA/go-nvml https://github.com/NVIDIA/go-nvml +github.com/cilium/ebpf https://github.com/cilium/ebpf github.com/containerd/log https://github.com/containerd/log github.com/containerd/nri https://github.com/containerd/nri github.com/containerd/ttrpc https://github.com/containerd/ttrpc @@ -23,6 +24,7 @@ github.com/moby/sys/symlink https://github.com/moby/sys symlink github.com/opencontainers/cgroups https://github.com/opencontainers/cgroups github.com/opencontainers/runc https://github.com/opencontainers/runc github.com/opencontainers/runtime-spec https://github.com/opencontainers/runtime-spec +github.com/opencontainers/runtime-spec https://github.com/opencontainers/runtime-spec github.com/opencontainers/runtime-tools https://github.com/opencontainers/runtime-tools github.com/pelletier/go-toml https://github.com/pelletier/go-toml github.com/pmezard/go-difflib https://github.com/pmezard/go-difflib @@ -36,6 +38,8 @@ github.com/urfave/cli/v3 https://github.com/urfave/cli github.com/xeipuuv/gojsonpointer https://github.com/xeipuuv/gojsonpointer golang.org/x/mod https://go.googlesource.com/mod golang.org/x/sys https://go.googlesource.com/sys +golang.org/x/sys https://go.googlesource.com/sys +golang.org/x/xerrors https://go.googlesource.com/xerrors google.golang.org/genproto/googleapis/rpc https://github.com/googleapis/go-genproto googleapis/rpc google.golang.org/grpc https://github.com/grpc/grpc-go google.golang.org/protobuf https://go.googlesource.com/protobuf diff --git a/hack/resolve-module-repos.sh b/hack/resolve-module-repos.sh index 511fa496c..76ed82152 100755 --- a/hack/resolve-module-repos.sh +++ b/hack/resolve-module-repos.sh @@ -31,6 +31,8 @@ HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" source "${HERE}/license-url-lib.sh" MODULES_TXT="${MODULES_TXT:-vendor/modules.txt}" +# The image ships libnvidia-container's libraries, so its modules need repos too. +LNC_MODULES_TXT="${LNC_MODULES_TXT:-third_party/libnvidia-container/src/nvcgo/vendor/modules.txt}" OUTPUT="${OUTPUT:-hack/module-repos.tsv}" PROXY="${PROXY:-https://proxy.golang.org}" @@ -139,7 +141,8 @@ main() { fi printf '%s\t%s\t%s\n' "${module}" "${repo}" "${subdir}" >> "${repos_tmp_file}" - done < <(LC_ALL=C grep '^# ' "${MODULES_TXT}" | awk '{print $2, $3}') + done < <(LC_ALL=C grep -h '^# ' "${MODULES_TXT}" ${LNC_MODULES_TXT:+"${LNC_MODULES_TXT}"} \ + | awk '{print $2, $3}' | LC_ALL=C sort -u) # A warning, not a die: this resolves every module in modules.txt, including # the ten-odd build/test-only ones out of scope for the notices document, so diff --git a/hack/verify-license-urls.sh b/hack/verify-license-urls.sh index fc85402a7..db91a81c8 100755 --- a/hack/verify-license-urls.sh +++ b/hack/verify-license-urls.sh @@ -115,14 +115,15 @@ main() { verify_platform_matrix prepare_workspace collect_runtime + collect_bundled build_indexes local verified_urls_tmp_file failures=0 verified_urls_tmp_file="$(mktemp "${TMPDIR:-/tmp}/nvidia-container-toolkit-urls.XXXXXX")" - local package _ module version repo subdir relative + local package _ module version source_kind module_dir repo subdir relative local origin_tag origin_hash plain_version pseudo_version_hash_value license_file name path_in_module want_sha found_url - while IFS=, read -r package _ _ module version; do + while IFS=, read -r package _ _ module version source_kind; do [[ -z "${package}" ]] && continue repo="$(repo_field "${module}" repo)" \ @@ -164,8 +165,9 @@ main() { (( ${#hash_refs[@]} > 0 )) && refs+=( "${hash_refs[@]}" ) (( ${#refs[@]} > 0 )) || die "no ref candidates for ${module}@${version}." - relative="$(license_dir_within_module "${package}" "${module}")" \ - || die "no license file found for ${package} under ${VENDOR_DIR}/${module}." + module_dir="$(module_source_dir "${module}" "${source_kind}")" + relative="$(license_dir_within_module "${package}" "${module}" "${module_dir}")" \ + || die "no license file found for ${package} under ${module_dir}." local license_file_count=0 while IFS= read -r license_file; do @@ -173,9 +175,9 @@ main() { license_file_count=$(( license_file_count + 1 )) name="$(basename "${license_file}")" path_in_module="${relative:+${relative}/}${name}" - [[ -f "${VENDOR_DIR}/${module}/${path_in_module}" ]] \ - || die "${VENDOR_DIR}/${module}/${path_in_module} does not exist." - want_sha="$(sha256_of_file "${VENDOR_DIR}/${module}/${path_in_module}")" + [[ -f "${module_dir}/${path_in_module}" ]] \ + || die "${module_dir}/${path_in_module} does not exist." + want_sha="$(sha256_of_file "${module_dir}/${path_in_module}")" # Both layouts: a submodule may ship its own licence or inherit the # repository root's. Content decides which is real. Built as an @@ -208,13 +210,13 @@ main() { continue fi printf '%s\t%s\t%s\t%s\n' "${module}" "${version}" "${path_in_module}" "${found_url}" >> "${verified_urls_tmp_file}" - done < <(license_files_for "${VENDOR_DIR}/${module}${relative:+/${relative}}") + done < <(license_files_for "${module_dir}${relative:+/${relative}}") if (( license_file_count == 0 )); then log "UNVERIFIED ${module}@${version} — no license file found for ${package}" failures=$(( failures + 1 )) fi - done < "${INDEX_FILE}" + done < "${MERGED_INDEX}" (( failures == 0 )) || die \ "${failures} license file(s) could not be matched to a verified upstream URL." \ From 11dbe8f472a698638853b77290f117f166beca3f Mon Sep 17 00:00:00 2001 From: Abrar Shivani Date: Thu, 27 Aug 2026 18:27:30 -0700 Subject: [PATCH 3/3] Name the archive each bundled C dependency is built from Absorbing libnvidia-container's C dependencies brought over the Location column but not the Source column beside it, so the table stopped naming the archive the build downloads and links in. The index already carried the URL and the per-dependency sections already printed it; only the table had lost it. That column carries more weight here than a duplicate link would suggest. Two of the three dependencies have no license file to point at: elftoolchain 0.7.1 ships none, and nvidia-modprobe's COPYING is the GPL-2.0 covering binaries this repository does not build. For those two the Location cell is a sentence rather than a link, which left the table with no pointer at all to code that is statically linked into the shipped libraries. The section prose now defines both columns rather than only Location. Signed-off-by: Abrar Shivani --- THIRD_PARTY_NOTICES.md | 22 ++++++++++++---------- hack/generate-third-party-notices.sh | 18 ++++++++++-------- 2 files changed, 22 insertions(+), 18 deletions(-) diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md index df5d961ce..3d076823f 100644 --- a/THIRD_PARTY_NOTICES.md +++ b/THIRD_PARTY_NOTICES.md @@ -74,16 +74,18 @@ busybox binary is added to the image, which is licensed under GPLv2. ## Bundled C Dependency Index -`Location` is the dependency's own license file upstream, pinned to the version -built here and checked by fetching it and comparing it byte for byte with the -copy inside the archive. Where a dependency has no license file to link, the -column says why; its terms are the per-file copyright notices reproduced below. - -| Dependency | Version | Built when | License (declared) | Pinned in | Location | -|------------|---------|------------|--------------------|-----------|----------| -| `elftoolchain` | 0.7.1 | `WITH_LIBELF=no` | BSD-2-Clause AND BSD-3-Clause | `third_party/libnvidia-container/mk/elftoolchain.mk` | none in this release; the terms are the per-file notices reproduced below | -| `libtirpc` | 1.3.2 | `WITH_TIRPC=yes` | BSD-3-Clause | `third_party/libnvidia-container/mk/libtirpc.mk` | [COPYING](https://git.linux-nfs.org/?p=steved/libtirpc.git;a=blob_plain;f=COPYING;hb=refs/tags/libtirpc-1-3-2) | -| `nvidia-modprobe` | 550.54.14 | `always` | MIT | `third_party/libnvidia-container/mk/nvidia-modprobe.mk` | not the archive's COPYING, which is GPL-2.0 and covers binaries this repository does not ship; the terms are the per-file notices reproduced below | +`Source` is the archive libnvidia-container's `make deps` downloads and links +in. `Location` is that dependency's own license file upstream, pinned to the +version built here and checked by fetching it and comparing it byte for byte +with the copy inside the archive. Where a dependency has no license file to +link, the column says why; its terms are the per-file copyright notices +reproduced below, and `Source` is then the only pointer to the code itself. + +| Dependency | Version | Built when | License (declared) | Pinned in | Source | Location | +|------------|---------|------------|--------------------|-----------|--------|----------| +| `elftoolchain` | 0.7.1 | `WITH_LIBELF=no` | BSD-2-Clause AND BSD-3-Clause | `third_party/libnvidia-container/mk/elftoolchain.mk` | https://sourceforge.net/projects/elftoolchain/files/Sources/elftoolchain-0.7.1/elftoolchain-0.7.1.tar.bz2 | none in this release; the terms are the per-file notices reproduced below | +| `libtirpc` | 1.3.2 | `WITH_TIRPC=yes` | BSD-3-Clause | `third_party/libnvidia-container/mk/libtirpc.mk` | https://downloads.sourceforge.net/project/libtirpc/libtirpc/1.3.2/libtirpc-1.3.2.tar.bz2 | [COPYING](https://git.linux-nfs.org/?p=steved/libtirpc.git;a=blob_plain;f=COPYING;hb=refs/tags/libtirpc-1-3-2) | +| `nvidia-modprobe` | 550.54.14 | `always` | MIT | `third_party/libnvidia-container/mk/nvidia-modprobe.mk` | https://github.com/NVIDIA/nvidia-modprobe/archive/550.54.14.tar.gz | not the archive's COPYING, which is GPL-2.0 and covers binaries this repository does not ship; the terms are the per-file notices reproduced below | ## Go Module License Texts diff --git a/hack/generate-third-party-notices.sh b/hack/generate-third-party-notices.sh index 24e7e8d70..85ba5c54e 100755 --- a/hack/generate-third-party-notices.sh +++ b/hack/generate-third-party-notices.sh @@ -783,15 +783,15 @@ emit_fenced_file() { emit_c_table() { local dependency_id version build_condition declared_license url makefile local scanned_file_count distinct_notice_count location - printf '| Dependency | Version | Built when | License (declared) | Pinned in | Location |\n' - printf '|------------|---------|------------|--------------------|-----------|----------|\n' + printf '| Dependency | Version | Built when | License (declared) | Pinned in | Source | Location |\n' + printf '|------------|---------|------------|--------------------|-----------|--------|----------|\n' while IFS='|' read -r dependency_id version build_condition declared_license url makefile \ scanned_file_count distinct_notice_count location; do [[ -z "${dependency_id}" ]] && continue # shellcheck disable=SC2016 # backticks are literal markdown here. - printf '| `%s` | %s | `%s` | %s | `%s` | %s |\n' \ + printf '| `%s` | %s | `%s` | %s | `%s` | %s | %s |\n' \ "${dependency_id}" "${version}" "${build_condition}" "${declared_license}" \ - "${makefile}" "${location}" + "${makefile}" "${url}" "${location}" done < "${C_INDEX}" } @@ -862,10 +862,12 @@ EOF ## Bundled C Dependency Index -`Location` is the dependency's own license file upstream, pinned to the version -built here and checked by fetching it and comparing it byte for byte with the -copy inside the archive. Where a dependency has no license file to link, the -column says why; its terms are the per-file copyright notices reproduced below. +`Source` is the archive libnvidia-container's `make deps` downloads and links +in. `Location` is that dependency's own license file upstream, pinned to the +version built here and checked by fetching it and comparing it byte for byte +with the copy inside the archive. Where a dependency has no license file to +link, the column says why; its terms are the per-file copyright notices +reproduced below, and `Source` is then the only pointer to the code itself. EOF emit_c_table