Yocto Project Documentation
 help / color / mirror / Atom feed
From: "Antonin Godard" <antonin.godard@bootlin.com>
To: <stondo@gmail.com>, <docs@lists.yoctoproject.org>
Cc: <peter.marko@siemens.com>, <adrian.freihofer@siemens.com>,
	"Stefano Tondo" <stefano.tondo.ext@siemens.com>
Subject: Re: [docs] [PATCH v6] ref-manual: Document SPDX 3.0.1 variables
Date: Wed, 26 Nov 2025 14:20:24 +0100	[thread overview]
Message-ID: <DEINO55V5PAF.PLIBNY18E3YB@bootlin.com> (raw)
In-Reply-To: <20251125135218.55721-1-stondo@gmail.com>

Hi,

I still can't apply the patch :(

Patch failed at 0001 ref-manual: Document SPDX 3.0.1 variables
error: corrupt patch at line 95
error: could not build fake ancestor

See my other comments below otherwise.

On Tue Nov 25, 2025 at 2:52 PM CET, Stefano Tondo via lists.yoctoproject.org wrote:
> From: Stefano Tondo <stefano.tondo.ext@siemens.com>
>
> Add comprehensive documentation for SPDX-related variables in the
> Yocto reference manual. This includes documenting previously
> undocumented variables and updating existing documentation with
> SPDX 3.0.1 specific information.
>
> New variables documented:
> - SPDX_LICENSES: Path to SPDX license identifier mapping file
> - SPDX_MULTILIB_SSTATE_ARCHS: Architecture list for dependency collection
> - SPDX_UUID_NAMESPACE: Namespace for UUID generation in SPDX documents
>
> Updated existing variables:
> - SPDX_INCLUDE_SOURCES: Added SPDX 3.0.1 format information
> - SPDX_INCLUDE_COMPILED_SOURCES: Clarified relationship with SPDX_INCLUDE_SOURCES
>
> Note: The langdale (SPDX 2.2) information was already present in the
> documentation. This patch adds corresponding information for SPDX 3.0.1
> format based on testing with the master branch.
>
> Signed-off-by: Stefano Tondo <stefano.tondo.ext@siemens.com>
> ---
>  documentation/ref-manual/variables.rst | 77 ++++++++++++++++++++++++--
>  1 file changed, 72 insertions(+), 5 deletions(-)
>
> diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst
> index f0a99aafb..8e2a4d8f3 100644
> --- a/documentation/ref-manual/variables.rst
> +++ b/documentation/ref-manual/variables.rst
> @@ -9000,10 +9000,28 @@ system and gives an overview of their function and contents.
>  
>           SPDX_INCLUDE_COMPILED_SOURCES = "1"
>  
> -      According to our tests, building ``core-image-minimal`` for the
> -      ``qemux86-64`` machine, enabling this option compared with the
> -      :term:`SPDX_INCLUDE_SOURCES` reduces the size of the  ``tmp/deploy/spdx``
> -      directory from 2GB to 1.6GB.
> +      For SPDX 2.2 format (release 4.1 "langdale"), building
> +      ``core-image-minimal`` for the ``qemux86-64`` machine, this option
> +      reduced the size of the ``tmp/deploy/spdx`` directory from 2GB to
> +      1.6GB compared to :term:`SPDX_INCLUDE_SOURCES`, as it includes only
> +      compiled objects without original source files.
> +
> +      With SPDX 3.0.1 JSON format, enabling this option includes both
> +      compiled sources and original source files (same as
> +      ``SPDX_INCLUDE_SOURCES = "1"``), which significantly increases
> +      the SBOM size. For example, with ``core-image-minimal`` on
> +      ``qemux86-64``, the uncompressed SBOM file can grow from hundreds
> +      of megabytes to several gigabytes.
> +
> +      .. note::
> +
> +         SPDX 3.0.1 JSON files are not compressed by default, unlike the
> +         tar.zst format used in SPDX 2.2. You can compress the output
> +         files manually::
> +
> +            zstd core-image-minimal-qemux86-64.rootfs.spdx.json
> +
> +         This typically achieves 94-97% compression ratios.

Sorry, my previous comment was probably not clear. I thought you used a
*built-in* way to compress the resulting JSON file and that it would be worth
mentioning it here.

So I would remove this note, and perhaps contribute to OE-Core to add support
for compression of this file, and then document that (if it doesn't exist
already).

Thanks,
Antonin

-- 
Antonin Godard, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com



      reply	other threads:[~2025-11-26 13:20 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-11-25 13:52 [PATCH v6] ref-manual: Document SPDX 3.0.1 variables stondo
2025-11-26 13:20 ` Antonin Godard [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DEINO55V5PAF.PLIBNY18E3YB@bootlin.com \
    --to=antonin.godard@bootlin.com \
    --cc=adrian.freihofer@siemens.com \
    --cc=docs@lists.yoctoproject.org \
    --cc=peter.marko@siemens.com \
    --cc=stefano.tondo.ext@siemens.com \
    --cc=stondo@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox