On Sat, 2026-10-03 at 18:50 +0200, Mathieu Dubois-Briand wrote: > On Fri Oct 2, 2026 at 9:54 AM CEST, Daniel Turull via lists.openembedded.org > wrote: > > From: Daniel Turull <[email protected]> > > > > We have a requirements to include release time of open source components > > in the SBOM. There is a field specific for that in spdx 3 spec. > > > > https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Properties/releaseTime/ > > > > This can also be used to evaluate how old are some of the core > > components and decide if they need replacement. > > > > The previous 2 versions did not have cover letter. > > > > In v4 I kept the simpler logic to just check for the epoch date, even if > > we have multiple sources with different release dates. It was getting > > complicated and adding more code for git and tarfiles. I can do a follow > > up patch after this simpler version gets in, so we can fine tune it. > > > > Tested with oe-selftest -r spdx > > > > Daniel Turull (3): > > classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash > > create-spdx-3.0: record component release date in SPDX output > > scripts/contrib: add spdx-release-date-report.py > > > > meta/classes-global/base.bbclass | 4 + > > meta/lib/oe/spdx30_tasks.py | 22 +++ > > meta/lib/oeqa/selftest/cases/spdx.py | 41 +++++ > > scripts/contrib/spdx-release-date-report.py | 191 ++++++++++++++++++++ > > 4 files changed, 258 insertions(+) > > create mode 100755 scripts/contrib/spdx-release-date-report.py > > Hi Daniel, > > It looks like one of the added tests is failing here: > > 2026-10-03 15:26:28,760 - oe-selftest - INFO - > spdx.SPDX30Check.test_release_date_source_date_epoch (subunit.RemotedTestCase) > 2026-10-03 15:26:28,761 - oe-selftest - INFO - ... FAIL > ... > 2026-10-03 15:26:28,761 - oe-selftest - INFO - > testtools.testresult.real._StringException: Traceback (most recent call last): > File > "/srv/pokybuild/yocto-worker/oe-selftest-debian/build/layers/openembedded-core/meta/lib/oeqa/selftest/cases/spdx.py", > line 473, in test_release_date_source_date_epoch > self.assertEqual(pkg.releaseTime, expected) > File "/usr/lib/python3.11/unittest/case.py", line 873, in assertEqual > assertion_func(first, second, msg=msg) > File "/usr/lib/python3.11/unittest/case.py", line 866, in _baseAssertEqual > raise self.failureException(msg) > AssertionError: datetime.datetime(2023, 7, 18, 6, 55, 23, > tzinfo=datetime.timezone.utc) != datetime.datetime(2011, 4, 5, 23, 0, > tzinfo=datetime.timezone.utc) > > https://autobuilder.yoctoproject.org/valkyrie/#/builders/35/builds/4997 >
I'll need to investigate further. I did a rerun and it works on my end. Maybe I choose the wrong recipe for the selftest. I'm suspecting some sstate issue. I'll keep you posted if I find the issue. bitbake tar -c cleanall && oe-selftest -r spdx.SPDX30Check.test_release_date_source_date_epoch Loading cache: 100% |############################################################################### ####################################| Time: 0:00:00 Loaded 0 entries from dependency cache. Parsing recipes: 100% |############################################################################### ##################################| Time: 0:00:10 Parsing of 1044 .bb files complete (0 cached, 1044 parsed). 2099 targets, 58 skipped, 0 masked, 0 errors. Removing 2 recipes from the allarch sysroot: 100% |############################################################################### ######| Time: 0:00:00 Removing 32 recipes from the qemux86_64 sysroot: 100% |############################################################################### ##| Time: 0:00:16 Removing 29 recipes from the x86-64-v3 sysroot: 100% |############################################################################### ###| Time: 0:00:01 Removing 18 recipes from the x86_64 sysroot: 100% |############################################################################### ######| Time: 0:00:08 NOTE: Resolving any missing task queue dependencies Build Configuration: BB_VERSION = "2.19.1" BUILD_SYS = "x86_64-linux" NATIVELSBSTRING = "universal" TARGET_SYS = "x86_64-oe-linux" MACHINE = "qemux86-64" SDKMACHINE = "x86_64" DISTRO = "nodistro" DISTRO_VERSION = "nodistro.0" TUNE_FEATURES = "m64 x86-64-v3" meta meta-selftest = "spdx-release:86f3f8bd5e3832411a8d4abb5661f77beb123511" Sstate summary: Wanted 0 Local 0 Mirrors 0 Missed 0 Current 0 (0% match, 0% complete) Initialising tasks: 100% |############################################################################### ###############################| Time: 0:00:00 NOTE: No setscene tasks NOTE: Executing Tasks (spdx.SPDX30Check.test_release_date_source_date_epoch) 2026-10-05 07:05:09,855 - oe-selftest - INFO - ... ok 2026-10-05 07:05:25,192 - oe-selftest - INFO - --------------------------------- ------------------------------------- 2026-10-05 07:05:25,192 - oe-selftest - INFO - Ran 1 test in 109.248s 2026-10-05 07:05:25,192 - oe-selftest - INFO - OK 2026-10-05 07:05:28,492 - oe-selftest - INFO - RESULTS: 2026-10-05 07:05:28,492 - oe-selftest - INFO - RESULTS - spdx.SPDX30Check.test_release_date_source_date_epoch: PASSED (93.60s) 2026-10-05 07:05:28,492 - oe-selftest - INFO - SUMMARY: 2026-10-05 07:05:28,493 - oe-selftest - INFO - oe-selftest () - Ran 1 test in 109.249s 2026-10-05 07:05:28,493 - oe-selftest - INFO - oe-selftest - OK - All required tests passed (successes=1, skipped=0, failures=0, errors=0) Best regards, Daniel > Thanks, > Mathieu >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#247221): https://lists.openembedded.org/g/openembedded-core/message/247221 Mute This Topic: https://lists.openembedded.org/mt/121543058/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
