On Mon Sep 14, 2026 at 1:44 PM CEST, Daniel Wagenknecht via 
lists.openembedded.org wrote:
> Hello,
>
> as discussed before here
> https://lists.openembedded.org/g/openembedded-core/message/226131
> and here
> https://lists.openembedded.org/g/openembedded-core/message/225774
>
> it would be good to include information about the layers used in a build in 
> the
> generated spdx documents.
>
> My primary goal is to track where all the configuration files added via file
> protocol in `SRC_URI` originate from, but the approach could be extended to
> track recipes, classes, machine config etc.
>
> These patches are meant as a basis to discuss the approach and should be
> considered draft status.
>
> The approach is to generate a `layers.spdx.json` on each build invocation
> that lists each layer used in the build as a `softwarePackage` with version
> and source information as well as - if can be reasonably deducted - the
> downloadLocation. Each source file added via file protocol is then linked to 
> the
> containing meta layer via a `contains` relationship.
>
> Open Questions:
> - is the overall architecture reasonable/correct?
> - referring to layers is inconsistent across tooling. E.g. the core layer is
>   either named `core` as defined by `BBFILE_COLLECTIONS` or `meta` as that is
>   the layer directory in the openembedded-core repository.
>   I chose the latter since that is what the utility function
>   `oe.buildcfg.get_layer_revisions` returns. The package URL (PURL)
>   implementation uses the other naming scheme though. Any thoughts on which
>   should be chosen and why?
> - I do not understand the alias linking yet. With the current implementation
>   I see many hash mismatches like
>   WARNING: gcc-runtime-15.3.0-r0 do_create_spdx: Element 
> http://spdx.org/spdxdocs/layers-7ad0d8d7-57f9-5c3c-9411-49227dd50610/layers/layer/meta
>     has alias 
> http://spdx.org/spdxdocs/UNIHASH-7ad0d8d7-57f9-5c3c-9411-49227dd50610/UNIHASH/layer/meta,
>  but it should have prefix
>     
> http://spdxdocs.org/openembedded-alias/by-doc-hash/e80f1d61f4749e663e80a4dfb25ebb1127b5f50600d3065de7ed91030942a1ef/
>
> I've currently got some time available to work on this to get a proper 
> solution
> integrated into openembedded-core.

This series is causing the following issue on our Autobuilder:

  ERROR: No SPDX document named 
/srv/pokybuild/yocto-worker/qemuarm-alt/build/build/tmp/deploy/spdx/3.0.1/bitbake.spdx.json
 found

See full log here: 
https://autobuilder.yoctoproject.org/valkyrie/#/builders/74/builds/4598

Can you look into it?

Thanks,
Antonin
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245824): 
https://lists.openembedded.org/g/openembedded-core/message/245824
Mute This Topic: https://lists.openembedded.org/mt/121240836/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to