From: iwanicki92 <iwanicki92@gmail.com>
To: openembedded-core@lists.openembedded.org
Cc: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Subject: [PATCH v2] sbom30.py/spdx30_tasks.py: fix SPDX_* prefix lookup
Date: Mon, 24 Aug 2026 22:10:18 +0200 [thread overview]
Message-ID: <20260824201017.3914783-2-iwanicki92@gmail.com> (raw)
Sub-variables (_name, _type, _comment, _id_email) were being looked
up using the literal string "SPDX_IMAGE_SUPPLIER", "SPDX_SDK_SUPPLIER"
"SPDX_PACKAGE_SUPPLIER", "SPDX_INVOKED_BY", "SPDX_ON_BEHALF_OF",
instead of the value of those variables, breaking the documented
ability to use a custom prefix (e.g. MY_COMPANY).
Tested by setting in local.conf:
```
MY_COMPANY_name = "CCCC"
MY_COMPANY_type = "organization"
SPDX_IMAGE_SUPPLIER = "MY_COMPANY"
SPDX_IMAGE_SUPPLIER_name = "AAAA"
SPDX_IMAGE_SUPPLIER_type = "organization"
SPDX_PACKAGE_SUPPLIER = "MY_COMPANY"
SPDX_PACKAGE_SUPPLIER_name = "BBBB"
SPDX_PACKAGE_SUPPLIER_type = "organization"
```
And then comparing `core-image-minimal-qemux86-64.rootfs.spdx.json`
SBOMs. Before this change SBOM contained only AAAA and BBBB but no CCCC,
after there was only CCCC.
Signed-off-by: iwanicki92 <iwanicki92@gmail.com>
---
Changes in v2:
Change the expand path to fallback to `varname` itself when lookup
doesn't find anything. This change allows for both old, undocumented `_ref`
indirection and documented indirection (`SPDX_* = "<PREFIX>"`)
---
meta/lib/oe/sbom30.py | 6 +++++-
meta/lib/oe/spdx30_tasks.py | 10 +++++-----
2 files changed, 10 insertions(+), 6 deletions(-)
diff --git a/meta/lib/oe/sbom30.py b/meta/lib/oe/sbom30.py
index e02382c3cc78..becf9e30d392 100644
--- a/meta/lib/oe/sbom30.py
+++ b/meta/lib/oe/sbom30.py
@@ -397,7 +397,11 @@ class ObjectSet(oe.spdx30.SHACLObjectSet):
self.doc.import_.append(m)
return spdxid
- def new_agent(self, varname, *, creation_info=None, add=True):
+ def new_agent(self, varname, *, creation_info=None, add=True, expand=False):
+ if expand:
+ varname = self.d.getVar(varname) or varname
+ if not varname:
+ return None
ref_varname = self.d.getVar(f"{varname}_ref")
if ref_varname:
if ref_varname == varname:
diff --git a/meta/lib/oe/spdx30_tasks.py b/meta/lib/oe/spdx30_tasks.py
index dac02e378429..88c707476a65 100644
--- a/meta/lib/oe/spdx30_tasks.py
+++ b/meta/lib/oe/spdx30_tasks.py
@@ -905,7 +905,7 @@ def create_spdx(d):
force_purposes=["install"],
)
- supplier = build_objset.new_agent("SPDX_PACKAGE_SUPPLIER")
+ supplier = build_objset.new_agent("SPDX_PACKAGE_SUPPLIER", expand=True)
if supplier is not None:
spdx_package.suppliedBy = (
supplier if isinstance(supplier, str) else supplier._id
@@ -1213,8 +1213,8 @@ def write_bitbake_spdx(d):
objset = oe.sbom30.ObjectSet.new_objset(d, "bitbake", False)
host_import_key = d.getVar("SPDX_BUILD_HOST")
- invoked_by = objset.new_agent("SPDX_INVOKED_BY", add=False)
- on_behalf_of = objset.new_agent("SPDX_ON_BEHALF_OF", add=False)
+ invoked_by = objset.new_agent("SPDX_INVOKED_BY", add=False, expand=True)
+ on_behalf_of = objset.new_agent("SPDX_ON_BEHALF_OF", add=False, expand=True)
if d.getVar("SPDX_INCLUDE_BITBAKE_PARENT_BUILD") == "1":
# Since the Build objects are unique, we may as well set the creation
@@ -1536,7 +1536,7 @@ def create_image_sbom_spdx(d):
objset, sbom = oe.sbom30.create_sbom(d, image_name, root_elements)
# Set supplier on root elements if SPDX_IMAGE_SUPPLIER is defined
- supplier = objset.new_agent("SPDX_IMAGE_SUPPLIER", add=False)
+ supplier = objset.new_agent("SPDX_IMAGE_SUPPLIER", add=False, expand=True)
if supplier is not None:
supplier_id = supplier if isinstance(supplier, str) else supplier._id
if not isinstance(supplier, str):
@@ -1657,7 +1657,7 @@ def create_sdk_sbom(d, sdk_deploydir, spdx_work_dir, toolchain_outputname):
)
# Set supplier on root elements if SPDX_SDK_SUPPLIER is defined
- supplier = objset.new_agent("SPDX_SDK_SUPPLIER", add=False)
+ supplier = objset.new_agent("SPDX_SDK_SUPPLIER", add=False, expand=True)
if supplier is not None:
supplier_id = supplier if isinstance(supplier, str) else supplier._id
if not isinstance(supplier, str):
--
2.55.0
next reply other threads:[~2026-08-24 20:14 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 20:10 iwanicki92 [this message]
2026-08-24 23:26 ` [OE-core] [PATCH v2] sbom30.py/spdx30_tasks.py: fix SPDX_* prefix lookup Joshua Watt
2026-08-25 5:48 ` iwanicki92
2026-08-25 15:00 ` [OE-core] " Joshua Watt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824201017.3914783-2-iwanicki92@gmail.com \
--to=iwanicki92@gmail.com \
--cc=mathieu.dubois-briand@bootlin.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox