On Fri Sep 25, 2026 at 10:24 AM CEST, Daniel Turull via lists.openembedded.org wrote: > From: Daniel Turull <[email protected]> > > Record each recipe's release date in the releaseTime property of its > software_Package object, using the SOURCE_DATE_EPOCH already computed > for reproducible builds. > > Accuracy depends on how SOURCE_DATE_EPOCH was derived: exact for > git-tagged recipes, best-effort for tarball/http(s) sources. Some > Python sdists (e.g. cryptography, hypothesis, maturin) normalize all > file mtimes to a fixed placeholder, so their releaseTime reflects > packaging-tool behavior, not the real release date. > > Tested with oe-selftest -r spdx, and with `bitbake world > --runall=do_create_spdx`: 1011/1150 recipes got a releaseTime (range > 1998-12-30 to 2026-09-17), 139 correctly had none. > > AI-Generated: Uses Kiro with Claude Sonnet 5 > Signed-off-by: Daniel Turull <[email protected]> > ---
Hi Daniel, Thanks for the new version, but it looks like the added test is failing: 2026-09-27 08:54:07,889 - oe-selftest - INFO - spdx.SPDX30Check.test_release_date_omitted_for_fallback_value (subunit.RemotedTestCase) 2026-09-27 08:54:07,890 - oe-selftest - INFO - ... FAIL Stderr: 2026-09-27 07:49:50,901 - oe-selftest - INFO - Adding: "include selftest.inc" in /srv/pokybuild/yocto-worker/oe-selftest-debian/build/build-st-2700487/conf/local.conf 2026-09-27 07:49:50,902 - oe-selftest - INFO - Adding: "include bblayers.inc" in bblayers.conf 2026-09-27 08:28:06,204 - oe-selftest - INFO - Found ANNOTATION2: ANNOTATION2=TestAnnotation2 2026-09-27 08:28:06,204 - oe-selftest - INFO - Found ANNOTATION1: ANNOTATION1=TestAnnotation1 2026-09-27 08:28:17,771 - oe-selftest - INFO - External references not found in SPDX output (defensive handling verified) 2026-09-27 08:51:21,993 - oe-selftest - INFO - The spdxId of gcc-16.2.0/README in build-gcc.spdx.json is http://spdx.org/spdxdocs/gcc-f2eaeb0d-b54b-53ba-899a-8c36c21139bf/8d0c5dabebec7cf453eedeadd0b28521a17ebf965ccdf6c437d3613676ca56dc/sourcefile/22 2026-09-27 08:54:07,890 - oe-selftest - INFO - 8: 51/64 792/807 (15.32s) (0 failed) (spdx.SPDX30Check.test_release_date_omitted_for_fallback_value) 2026-09-27 08:54:07,890 - oe-selftest - INFO - testtools.testresult.real._StringException: Traceback (most recent call last): File "/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/lib/oeqa/selftest/cases/spdx.py", line 482, in test_release_date_omitted_for_fallback_value self.assertExists(sde_file) File "/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/lib/oeqa/selftest/case.py", line 249, in assertExists raise self.failureException(msg) AssertionError: '/srv/pokybuild/yocto-worker/oe-selftest-debian/build/build-st-2700487/tmp/work/qemux86_64-poky-linux/packagegroup-base/1.0/source-date-epoch/__source_date_epoch.txt' does not exist https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/4933 https://autobuilder.yoctoproject.org/valkyrie/#/builders/48/builds/4740 Can you have a look at the issue? Thanks, Mathieu -- Mathieu Dubois-Briand, Bootlin Embedded Linux and Kernel engineering https://bootlin.com
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246687): https://lists.openembedded.org/g/openembedded-core/message/246687 Mute This Topic: https://lists.openembedded.org/mt/121423276/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
