On Sat, 2026-10-03 at 18:50 +0200, Mathieu Dubois-Briand wrote:
> On Fri Oct 2, 2026 at 9:54 AM CEST, Daniel Turull via lists.openembedded.org 
> wrote:
> > From: Daniel Turull <[email protected]>
> >
> > We have a requirements to include release time of open source components
> > in the SBOM. There is a field specific for that in spdx 3 spec.
> >
> > https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/
> >
> > This can also be used to evaluate how old are some of the core
> > components and decide if they need replacement.
> >
> > The previous 2 versions did not have cover letter.
> >
> > In v4 I kept the simpler logic to just check for the epoch date, even if
> > we have multiple sources with different release dates. It was getting
> > complicated and adding more code for git and tarfiles. I can do a follow
> > up patch after this simpler version gets in, so we can fine tune it.
> >
> > Tested with oe-selftest -r spdx
> >
> > Daniel Turull (3):
> >   classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash
> >   create-spdx-3.0: record component release date in SPDX output
> >   scripts/contrib: add spdx-release-date-report.py
> >
> >  meta/classes-global/base.bbclass            |   4 +
> >  meta/lib/oe/spdx30_tasks.py                 |  22 +++
> >  meta/lib/oeqa/selftest/cases/spdx.py        |  41 +++++
> >  scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++
> >  4 files changed, 258 insertions(+)
> >  create mode 100755 scripts/contrib/spdx-release-date-report.py
>
> Hi Daniel,
>
> It looks like one of the added tests is failing here:
>
> 2026-10-03 15:26:28,760 - oe-selftest - INFO - 
> spdx.SPDX30Check.test_release_date_source_date_epoch (subunit.RemotedTestCase)
> 2026-10-03 15:26:28,761 - oe-selftest - INFO -  ... FAIL
> ...
> 2026-10-03 15:26:28,761 - oe-selftest - INFO - 
> testtools.testresult.real._StringException: Traceback (most recent call last):
>   File 
> "/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/lib/oeqa/selftest/cases/spdx.py",
>  line 473, in test_release_date_source_date_epoch
>     self.assertEqual(pkg.releaseTime, expected)
>   File "/usr/lib/python3.11/unittest/case.py", line 873, in assertEqual
>     assertion_func(first, second, msg=msg)
>   File "/usr/lib/python3.11/unittest/case.py", line 866, in _baseAssertEqual
>     raise self.failureException(msg)
> AssertionError: datetime.datetime(2023, 7, 18, 6, 55, 23, 
> tzinfo=datetime.timezone.utc) != datetime.datetime(2011, 4, 5, 23, 0, 
> tzinfo=datetime.timezone.utc)
>
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/4997
>

I'll need to investigate further.

I did a rerun and it works on my end. Maybe I choose the wrong recipe for the
selftest. I'm suspecting some sstate issue. I'll keep you posted if I find the
issue.

bitbake tar -c cleanall && oe-selftest -r
spdx.SPDX30Check.test_release_date_source_date_epoch
Loading cache: 100%
|###############################################################################
####################################| Time: 0:00:00
Loaded 0 entries from dependency cache.
Parsing recipes: 100%
|###############################################################################
##################################| Time: 0:00:10
Parsing of 1044 .bb files complete (0 cached, 1044 parsed). 2099 targets, 58
skipped, 0 masked, 0 errors.
Removing 2 recipes from the allarch sysroot: 100%
|###############################################################################
######| Time: 0:00:00
Removing 32 recipes from the qemux86_64 sysroot: 100%
|###############################################################################
##| Time: 0:00:16
Removing 29 recipes from the x86-64-v3 sysroot: 100%
|###############################################################################
###| Time: 0:00:01
Removing 18 recipes from the x86_64 sysroot: 100%
|###############################################################################
######| Time: 0:00:08
NOTE: Resolving any missing task queue dependencies

Build Configuration:
BB_VERSION           = "2.19.1"
BUILD_SYS            = "x86_64-linux"
NATIVELSBSTRING      = "universal"
TARGET_SYS           = "x86_64-oe-linux"
MACHINE              = "qemux86-64"
SDKMACHINE           = "x86_64"
DISTRO               = "nodistro"
DISTRO_VERSION       = "nodistro.0"
TUNE_FEATURES        = "m64 x86-64-v3"
meta
meta-selftest        = "spdx-release:86f3f8bd5e3832411a8d4abb5661f77beb123511"

Sstate summary: Wanted 0 Local 0 Mirrors 0 Missed 0 Current 0 (0% match, 0%
complete)
Initialising tasks: 100%
|###############################################################################
###############################| Time: 0:00:00
NOTE: No setscene tasks
NOTE: Executing Tasks
(spdx.SPDX30Check.test_release_date_source_date_epoch)
2026-10-05 07:05:09,855 - oe-selftest - INFO -  ... ok
2026-10-05 07:05:25,192 - oe-selftest - INFO - ---------------------------------
-------------------------------------
2026-10-05 07:05:25,192 - oe-selftest - INFO - Ran 1 test in 109.248s
2026-10-05 07:05:25,192 - oe-selftest - INFO - OK
2026-10-05 07:05:28,492 - oe-selftest - INFO - RESULTS:
2026-10-05 07:05:28,492 - oe-selftest - INFO - RESULTS -
spdx.SPDX30Check.test_release_date_source_date_epoch: PASSED (93.60s)
2026-10-05 07:05:28,492 - oe-selftest - INFO - SUMMARY:
2026-10-05 07:05:28,493 - oe-selftest - INFO - oe-selftest () - Ran 1 test in
109.249s
2026-10-05 07:05:28,493 - oe-selftest - INFO - oe-selftest - OK - All required
tests passed (successes=1, skipped=0, failures=0, errors=0)

Best regards,
Daniel
> Thanks,
> Mathieu
>

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247221): 
https://lists.openembedded.org/g/openembedded-core/message/247221
Mute This Topic: https://lists.openembedded.org/mt/121543058/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to