Third-Party Licenses for Databricks ODBC Driver
================================================

This file lists the third-party libraries statically linked into, embedded in,
or explicitly dynamically linked by the Databricks ODBC Driver shared library,
together with their respective licenses.

It is split into two parts:

  * C++ / native dependencies — resolved by Conan (see conanfile.py /
    conan.lock), vendored in-tree, or embedded as generated data. These
    are enumerated in full below.

  * Rust dependencies — the driver statically links the Databricks SQL
    Kernel (a Rust staticlib) and, transitively, its entire Cargo
    dependency graph (hundreds of crates). Enumerating every crate's
    license text by hand is neither accurate nor maintainable, so the
    complete per-crate attribution report is GENERATED from the kernel's
    pinned Cargo.lock and shipped alongside this file as
    THIRD_PARTY_RUST_LICENSES.txt (see "Rust dependencies" below and
    docs/third-party-licenses.md for the generation + drift-check
    process).

========================================================================
PART 1 — C++ / NATIVE DEPENDENCIES
========================================================================

------------------------------------------------------------------------
Apache Arrow
------------------------------------------------------------------------
License: Apache License 2.0
URL: https://github.com/apache/arrow
Copyright: The Apache Software Foundation
Note: Conan dependency (arrow/25.0.1). Used for C++ data types and the
      C Data Interface bridge; Parquet and Thrift are disabled
      (conanfile.py), so their transitive trees are not linked.

------------------------------------------------------------------------
Arrow ODBC Framework (vendored)
------------------------------------------------------------------------
License: Apache License 2.0
URL: https://github.com/apache/arrow (cpp/src/arrow/flight/sql/odbc)
Copyright: The Apache Software Foundation
Note: Vendored under third_party/arrow-odbc-framework/, imported from
      Apache Arrow via Copybara at the commit pinned in ARROW_SYNC_REV.
      Distinct source tree from the Conan Arrow package above.

------------------------------------------------------------------------
utfcpp (UTF8-CPP)
------------------------------------------------------------------------
License: Boost Software License 1.0
URL: https://github.com/nemtrif/utfcpp
Copyright: 2006-2018 Nemanja Trifunovic
Note: Apache Arrow's vendored copy, synced with the Arrow ODBC framework
      (arrow/vendored/utfcpp) and used for UTF-8 <-> UTF-16/32 conversion.

------------------------------------------------------------------------
mimalloc
------------------------------------------------------------------------
License: MIT License
URL: https://github.com/microsoft/mimalloc
Copyright: 2018-2025 Microsoft Corporation, Daan Leijen
Note: Conan dependency (mimalloc/2.2.4), pulled in transitively by Apache
      Arrow (Arrow's default memory pool on Windows) and statically
      linked into the driver.

------------------------------------------------------------------------
zlib
------------------------------------------------------------------------
License: zlib License
URL: https://www.zlib.net/ (https://github.com/madler/zlib)
Copyright: 1995-2024 Jean-loup Gailly and Mark Adler
Note: Conan dependency (zlib/1.3.1), pulled in transitively by Apache
      Arrow for compression support and statically linked.

------------------------------------------------------------------------
bzip2
------------------------------------------------------------------------
License: bzip2-1.0.6 (BSD-style)
URL: https://sourceware.org/bzip2/
Copyright: 1996-2019 Julian R Seward
Note: Conan dependency (bzip2/1.0.8), pulled in transitively by Apache
      Arrow for compression support and statically linked.

------------------------------------------------------------------------
xsimd
------------------------------------------------------------------------
License: BSD 3-Clause
URL: https://github.com/xtensor-stack/xsimd
Copyright: 2016 Johan Mabille, Sylvain Corlay, Wolf Vollprecht, Martin Renou,
           and QuantStack; 2018 Serge Guelton
Note: Conan dependency (xsimd/14.2.0), pulled in transitively by Apache
      Arrow for SIMD acceleration and statically linked (header-only).

------------------------------------------------------------------------
cctz
------------------------------------------------------------------------
License: Apache License 2.0
URL: https://github.com/google/cctz
Copyright: Google Inc.
Note: Conan dependency (cctz/2.4).

------------------------------------------------------------------------
Boost
------------------------------------------------------------------------
License: Boost Software License 1.0
URL: https://www.boost.org/
Copyright: Various contributors
Note: Conan dependency (boost/1.86.0).

------------------------------------------------------------------------
RapidJSON
------------------------------------------------------------------------
License: MIT License
URL: https://github.com/Tencent/rapidjson
Copyright: 2015 THL A29 Limited, a Tencent company, and Milo Yip
Note: Conan dependency (rapidjson/cci.20230929).

------------------------------------------------------------------------
OpenSSL
------------------------------------------------------------------------
License: Apache License 2.0
URL: https://www.openssl.org/
Copyright: The OpenSSL Project Authors
Note: Conan dependency (openssl/3.4.1). Statically linked on the
      OpenSSL-backed builds (native Linux/macOS). The Windows and aarch64
      builds select the kernel's pure-Rust rustls TLS backend instead and
      do not link OpenSSL (see CMakeLists.txt / docs).

------------------------------------------------------------------------
unixODBC (libodbcinst)
------------------------------------------------------------------------
License: LGPL-2.1-or-later
URL: https://www.unixodbc.org/
Copyright: Peter Harvey, Nick Gorham and contributors
Note: Linux only, Conan dependency (odbc/2.3.11). Linked DYNAMICALLY
      (libodbcinst.so.2 is a NEEDED entry, not statically absorbed) so
      the driver reads DSN keys through the same shared odbcinst the
      driver manager uses (odbc#288). Not embedded in the driver.

------------------------------------------------------------------------
IANA Time Zone Database
------------------------------------------------------------------------
License: Public Domain
URL: https://www.iana.org/time-zones
Copyright: None (public domain); see the tz project's LICENSE.
Note: A compiled copy (TZif data) is embedded in the driver via
      src/embedded_tzdata_generated.cc (regenerated by
      scripts/gen_embedded_tzdata.py).

========================================================================
PART 2 — RUST DEPENDENCIES
========================================================================

------------------------------------------------------------------------
Databricks SQL Kernel (Rust) and its transitive Cargo dependencies
------------------------------------------------------------------------
License: Apache License 2.0 (kernel itself)
URL: https://github.com/databricks/databricks-sql-kernel
Copyright: Databricks, Inc.

The driver statically links the Databricks SQL Kernel, a Rust staticlib,
and with it the kernel's ENTIRE transitive Cargo dependency graph. Every
crate in that graph is therefore statically absorbed into the shipped
driver and carries an attribution obligation.

The full, per-crate attribution report — every crate, its version, its
SPDX license expression, and the license text — is GENERATED from the
kernel's pinned Cargo.lock (the SHA in CMakeLists.txt's KERNEL_REPO_TAG)
and shipped as a sibling file:

    THIRD_PARTY_RUST_LICENSES.txt

Regenerate it with scripts/generate_license_inventory.sh; CI fails the
build if the checked-in copy drifts from what the current kernel pin
produces (see docs/third-party-licenses.md).

The license families appearing across the Rust graph are constrained by
the kernel's own cargo-deny allowlist (deny.toml, enforced by the
kernel's License Check CI). As of the pinned revision they are:

    Apache-2.0, BSD-2-Clause, BSD-3-Clause, CC0-1.0,
    CDLA-Permissive-2.0, ISC, MIT, MIT-0, MPL-2.0, Unicode-3.0,
    Unicode-DFS-2016, Unlicense, Zlib

All are permissive. A crate whose license falls outside this set cannot
enter the kernel's dependency graph without failing the kernel's upstream
License Check, so no copyleft (GPL/LGPL-static) obligation reaches the
statically linked Rust surface. Representative major crates include:
tokio, hyper, reqwest, rustls, ring, the arrow-rs family, serde, and
chrono.

========================================================================

For the full text of the C++/native licenses above, refer to the
respective project URLs. For the full per-crate text of the Rust
dependencies, see THIRD_PARTY_RUST_LICENSES.txt shipped in this package.
