From: "Antonin Godard" <antonin.godard@bootlin.com>
To: <stondo@gmail.com>, <docs@lists.yoctoproject.org>
Cc: <peter.marko@siemens.com>, <adrian.freihofer@siemens.com>,
"Stefano Tondo" <stefano.tondo.ext@siemens.com>
Subject: Re: [docs] [PATCH v6] ref-manual: Document SPDX 3.0.1 variables
Date: Wed, 26 Nov 2025 14:20:24 +0100 [thread overview]
Message-ID: <DEINO55V5PAF.PLIBNY18E3YB@bootlin.com> (raw)
In-Reply-To: <20251125135218.55721-1-stondo@gmail.com>
Hi,
I still can't apply the patch :(
Patch failed at 0001 ref-manual: Document SPDX 3.0.1 variables
error: corrupt patch at line 95
error: could not build fake ancestor
See my other comments below otherwise.
On Tue Nov 25, 2025 at 2:52 PM CET, Stefano Tondo via lists.yoctoproject.org wrote:
> From: Stefano Tondo <stefano.tondo.ext@siemens.com>
>
> Add comprehensive documentation for SPDX-related variables in the
> Yocto reference manual. This includes documenting previously
> undocumented variables and updating existing documentation with
> SPDX 3.0.1 specific information.
>
> New variables documented:
> - SPDX_LICENSES: Path to SPDX license identifier mapping file
> - SPDX_MULTILIB_SSTATE_ARCHS: Architecture list for dependency collection
> - SPDX_UUID_NAMESPACE: Namespace for UUID generation in SPDX documents
>
> Updated existing variables:
> - SPDX_INCLUDE_SOURCES: Added SPDX 3.0.1 format information
> - SPDX_INCLUDE_COMPILED_SOURCES: Clarified relationship with SPDX_INCLUDE_SOURCES
>
> Note: The langdale (SPDX 2.2) information was already present in the
> documentation. This patch adds corresponding information for SPDX 3.0.1
> format based on testing with the master branch.
>
> Signed-off-by: Stefano Tondo <stefano.tondo.ext@siemens.com>
> ---
> documentation/ref-manual/variables.rst | 77 ++++++++++++++++++++++++--
> 1 file changed, 72 insertions(+), 5 deletions(-)
>
> diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst
> index f0a99aafb..8e2a4d8f3 100644
> --- a/documentation/ref-manual/variables.rst
> +++ b/documentation/ref-manual/variables.rst
> @@ -9000,10 +9000,28 @@ system and gives an overview of their function and contents.
>
> SPDX_INCLUDE_COMPILED_SOURCES = "1"
>
> - According to our tests, building ``core-image-minimal`` for the
> - ``qemux86-64`` machine, enabling this option compared with the
> - :term:`SPDX_INCLUDE_SOURCES` reduces the size of the ``tmp/deploy/spdx``
> - directory from 2GB to 1.6GB.
> + For SPDX 2.2 format (release 4.1 "langdale"), building
> + ``core-image-minimal`` for the ``qemux86-64`` machine, this option
> + reduced the size of the ``tmp/deploy/spdx`` directory from 2GB to
> + 1.6GB compared to :term:`SPDX_INCLUDE_SOURCES`, as it includes only
> + compiled objects without original source files.
> +
> + With SPDX 3.0.1 JSON format, enabling this option includes both
> + compiled sources and original source files (same as
> + ``SPDX_INCLUDE_SOURCES = "1"``), which significantly increases
> + the SBOM size. For example, with ``core-image-minimal`` on
> + ``qemux86-64``, the uncompressed SBOM file can grow from hundreds
> + of megabytes to several gigabytes.
> +
> + .. note::
> +
> + SPDX 3.0.1 JSON files are not compressed by default, unlike the
> + tar.zst format used in SPDX 2.2. You can compress the output
> + files manually::
> +
> + zstd core-image-minimal-qemux86-64.rootfs.spdx.json
> +
> + This typically achieves 94-97% compression ratios.
Sorry, my previous comment was probably not clear. I thought you used a
*built-in* way to compress the resulting JSON file and that it would be worth
mentioning it here.
So I would remove this note, and perhaps contribute to OE-Core to add support
for compression of this file, and then document that (if it doesn't exist
already).
Thanks,
Antonin
--
Antonin Godard, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
prev parent reply other threads:[~2025-11-26 13:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-25 13:52 [PATCH v6] ref-manual: Document SPDX 3.0.1 variables stondo
2025-11-26 13:20 ` Antonin Godard [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DEINO55V5PAF.PLIBNY18E3YB@bootlin.com \
--to=antonin.godard@bootlin.com \
--cc=adrian.freihofer@siemens.com \
--cc=docs@lists.yoctoproject.org \
--cc=peter.marko@siemens.com \
--cc=stefano.tondo.ext@siemens.com \
--cc=stondo@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox