Hi,

The script also supports SPDX2, why have it SPDX3 specific?

More comments inline

Daniel

> -----Original Message-----
> From: [email protected] <openembedded-
> [email protected]> On Behalf Of vboudevin via
> lists.openembedded.org
> Sent: Tuesday, 6 January 2026 20:42
> To: [email protected]
> Cc: ValentinBoudevin <[email protected]>
> Subject: [OE-core] [PATCH] improve_kerne_cve_report: Add a bbclass support
>
> The script improve_kernel_cve_report.py doesn't have a bbclass.
> It can be usefull to have one to generate improved cve-check files at every 
> run.
>
> This new class can be used to generate a new file in tmp/deploy/images with a
> .scouted.json in addition to the existing .json cve-check file.
>
> The new .scouted.json is based on the cve-check file and the SBOM (SPDX3
> mandatory) to generate this improved cve-check file with extra entries found 
> by
> the script improve_kernel_cve_report.py.
>
> It only requires an inherit on an image recipe (e.g. "inherit
> improve_kernel_cve_report" in core-image-minimal).
>
> It can be add to core-image-minimal in a second step if revelant.
> ---
>  .../classes/improve_kernel_cve_report.bbclass | 71 +++++++++++++++++++
>  1 file changed, 71 insertions(+)
>  create mode 100644 meta/classes/improve_kernel_cve_report.bbclass
>
> diff --git a/meta/classes/improve_kernel_cve_report.bbclass
> b/meta/classes/improve_kernel_cve_report.bbclass
> new file mode 100644
> index 0000000000..5c496252b4
> --- /dev/null
> +++ b/meta/classes/improve_kernel_cve_report.bbclass
> @@ -0,0 +1,71 @@
> +python do_clean:append() {
> +    import os, glob
> +    if bb.utils.contains('INHERIT', 'create-spdx-2.2', 'false', 'true', d):
> +        deploy_dir = d.expand('${DEPLOY_DIR_IMAGE}')
> +        for f in glob.glob(os.path.join(deploy_dir, '*scouted.json')):
> +            bb.note("Removing " + f)
> +            os.remove(f)
> +}
> +
> +python do_clone_kernel_cve() {
> +    import subprocess
> +    import shutil, os
> +    check_spdx = d.getVar("INHERIT")
> +    rootdir = os.path.join(d.getVar("WORKDIR"), "vulns")
> +    # Check if the feature is enabled and if SPDX 2.2 is not used
> +    if "create-spdx-2.2" not in check_spdx:
> +        d.setVar("SRC_URI",
> "git://git.kernel.org/pub/scm/linux/security/vulns.git;branch=master;protocol=h
> ttps")
> +        d.setVar("SRCREV", "${AUTOREV}")
> +        src_uri = (d.getVar('SRC_URI') or "").split()

This will make the build non reproducible. It was one of the feedback that I 
got with the original series. Could it be possible to make it work with mirrors 
as well for offline builds?


> +        # Fetch the kernel vulnerabilities sources
> +        fetcher = bb.fetch2.Fetch(src_uri, d)
> +        fetcher.download()
> +        # Unpack into the standard work directory
> +        fetcher.unpack(rootdir)
> +        # Remove the folder ${PN} set by unpack
> +        subdirs = [d for d in os.listdir(rootdir) if 
> os.path.isdir(os.path.join(rootdir, d))]
> +        if len(subdirs) == 1:
> +            srcdir = os.path.join(rootdir, subdirs[0])
> +            for f in os.listdir(srcdir):
> +                shutil.move(os.path.join(srcdir, f), rootdir)
> +            shutil.rmtree(srcdir)
> +        bb.note("Vulnerabilities repo unpacked into: %s" % rootdir)
> +    elif "create-spdx-2.2" in check_spdx:
> +        bb.warn(f"improve_kernel_cve_report: Extra Kernel CVEs Scouting
> +is desactivate because incompatible with SPDX 2.2.") }
> +do_clone_kernel_cve[network] = "1"
> +do_clone_kernel_cve[nostamp] = "1"
> +do_clone_kernel_cve[doc] = "Clone the latest kernel vulnerabilities from
> https://git.kernel/.
> org%2Fpub%2Fscm%2Flinux%2Fsecurity%2Fvulns.git&data=05%7C02%7Cdaniel.t
> urull%40ericsson.com%7Ca26e06f7ba0c4992552008de4d5baddb%7C92e84ceb
> fbfd47abbe52080c6b87953f%7C0%7C0%7C639033253334668000%7CUnknown
> %7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJ
> XaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Ql5W
> 0FA1uoB7iuuLEoNk4hVoc4vUAVWRROFzG1BWTLI%3D&reserved=0"
> +addtask clone_kernel_cve after
> +
> +do_scout_extra_kernel_vulns() {
> +    spdx_file="${SPDXIMAGEDEPLOYDIR}/${IMAGE_LINK_NAME}.spdx.json"
> +
> original_cve_check_file="${DEPLOY_DIR_IMAGE}/${IMAGE_LINK_NAME}.json"
> +
> new_cve_report_file="${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.scouted.json"
> +
> improve_kernel_cve_script="${COREBASE}/scripts/contrib/improve_kernel_cve_
> report.py"
> +
> +    if ${@bb.utils.contains('INHERIT', 'create-spdx-2.2', 'true', 'false', 
> d)}; then
> +        bbwarn "improve_kernel_cve_report: Skipping extra kernel 
> vulnerabilities
> scouting because incompatible with SPDX 2."
> +        return 0
> +    elif [ ! -f "${spdx_file}" ]; then
> +        bbwarn "improve_kernel_cve_report: SPDX file not found: ${spdx_file}.
> Skipping extra kernel vulnerabilities scoutings."
> +        return 0
> +    elif [ ! -f "${original_cve_check_file}" ]; then
> +        bbwarn "improve_kernel_cve_report: CVE_CHECK file not found:
> ${original_cve_check_file}. Skipping extra kernel vulnerabilities scouting."
> +        return 0
> +    fi
> +
> +    #Launch the new script to improve the cve report
> +    python3 "${improve_kernel_cve_script}" \
> +        --spdx "${spdx_file}" \
> +        --old-cve-report "${original_cve_check_file}" \
> +        --new-cve-report "${new_cve_report_file}" \
> +        --datadir "${WORKDIR}/vulns"
> +    bbplain "Improve CVE report with extra kernel cves: 
> ${new_cve_report_file}"

You can also use the debug sources as input to be spdx independent.
For example, from the docs.
python3 openembedded-core/scripts/contrib/improve_kernel_cve_report.py \
   --debug-sources 
tmp/pkgdata/qemux86_64/debugsources/linux-yocto-debugsources.json.zstd \
   --datadir ~/vulns \
   --old-cve-report build/tmp/log/cve/cve-summary.json


> +    #Create a symlink as every other JSON file in tmp/deploy/images
> +    ln -sf ${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.scouted.json
> +${DEPLOY_DIR_IMAGE}/${IMAGE_BASENAME}${IMAGE_MACHINE_SUFFIX}${I
> MAGE_NAM
> +E_SUFFIX}.scouted.json
> +}
> +do_scout_extra_kernel_vulns[nostamp] = "1"
> +do_scout_extra_kernel_vulns[doc] = "Scout extra kernel vulnerabilities and
> create a new enhanced version of the cve_check file in the deploy directory"
> +addtask scout_extra_kernel_vulns after do_create_image_sbom_spdx before
> +do_build
> \ No newline at end of file
> --
> 2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#229042): 
https://lists.openembedded.org/g/openembedded-core/message/229042
Mute This Topic: https://lists.openembedded.org/mt/117149340/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to