Many recipes ship files that originate from a meta-layer. Link each file added via the `file` protocol to the spdx entry of the meta-layer containing that file.
Some files might not originate from a meta-layer (`file` protocol supports absolute paths), fail the build if SPDX_REQUIRE_LAYER_ASSERTION is set to true. Signed-off-by: Daniel Wagenknecht <[email protected]> --- meta/lib/oe/spdx30_tasks.py | 44 +++++++++++++++++++++++++++++++++---- 1 file changed, 40 insertions(+), 4 deletions(-) diff --git a/meta/lib/oe/spdx30_tasks.py b/meta/lib/oe/spdx30_tasks.py index 9094a6cbd64..6b1308c5586 100644 --- a/meta/lib/oe/spdx30_tasks.py +++ b/meta/lib/oe/spdx30_tasks.py @@ -453,6 +453,7 @@ def add_download_files(d, objset): primary_purpose = oe.spdx30.software_SoftwarePurpose.source if fd.type == "file": + (layer_path, layer_objset) = get_layer_info(d, fd.localpath) if os.path.isdir(fd.localpath): walk_idx = 1 for root, dirs, files in os.walk(fd.localpath, onerror=walk_error): @@ -468,23 +469,36 @@ def add_download_files(d, objset): objset.new_spdxid( "source", str(download_idx + 1), str(walk_idx) ), - os.path.join( - file_name, os.path.relpath(f_path, fd.localpath) - ), + os.path.relpath(f_path, layer_path), f_path, purposes=[primary_purpose], ) + if layer_objset is not None: + objset.new_scoped_relationship( + [oe.sbom30.get_element_link_id(layer_objset)], + oe.spdx30.RelationshipType.contains, + oe.spdx30.LifecycleScopeType.build, + [file], + ) + inputs.add(file) walk_idx += 1 else: file = objset.new_file( objset.new_spdxid("source", str(download_idx + 1)), - file_name, + os.path.relpath(fd.localpath, layer_path), fd.localpath, purposes=[primary_purpose], ) + if layer_objset is not None: + objset.new_scoped_relationship( + [oe.sbom30.get_element_link_id(layer_objset)], + oe.spdx30.RelationshipType.contains, + oe.spdx30.LifecycleScopeType.build, + [file], + ) inputs.add(file) else: @@ -774,6 +788,28 @@ def load_recipe_spdx(d): oe.spdx30.software_Package, ) +def get_layer_info(d, path): + layer = None + path = Path(path) + + layers = oe.buildcfg.get_layer_revisions(d) + for (l_path, l_name, l_branch, l_rev, l_ismodified) in layers: + l_path = Path(l_path) + if l_path in path.parents: + layer = l_name + break + + if not l_path: + if oe.utils.vartrue("SPDX_REQUIRE_LAYER_ASSERTION", True, False, d): + bb.fatal(f"Path {path} does not originate from a meta-layer!") + return ("/", None) + + deploy_dir_spdx = Path(d.getVar("DEPLOY_DIR_SPDX")) + objset = oe.sbom30.load_jsonld(d, deploy_dir_spdx / "layers.spdx.json", required=True) + spdx_obj = objset.find_root(oe.spdx30.software_Package, name=l_name) + + return (l_path, spdx_obj) + def create_spdx(d): def set_var_field(var, obj, name, package=None): -- 2.54.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245915): https://lists.openembedded.org/g/openembedded-core/message/245915 Mute This Topic: https://lists.openembedded.org/mt/121274726/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
