From patchwork Mon Sep 14 16:08:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Joshua Watt X-Patchwork-Id: 98200 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 315A1C88E72 for ; Mon, 14 Sep 2026 16:08:48 +0000 (UTC) Received: from mail-ot1-f42.google.com (mail-ot1-f42.google.com [209.85.210.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1383.1789402122419446184 for ; Mon, 14 Sep 2026 09:08:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Qio2ospp; spf=pass (domain: gmail.com, ip: 209.85.210.42, mailfrom: jpewhacker@gmail.com) Received: by mail-ot1-f42.google.com with SMTP id 46e09a7af769-805453b1c0cso2533268a34.1 for ; Mon, 14 Sep 2026 09:08:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789402121; x=1790006921; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=zEDrRYTmQqo5wdWqm6gdLLM4eMFHZENFRr7j+KFawt8=; b=Qio2osppZU75W1bq8Ip5qjMlJAWUXLWyG1Dfwr2b/D0TpC52cVYaZWfJfglnL2ofYp axAWVM2X6dkrdtKQEQly+X4xDqoIXmdAsJTw27Ki1CEDgaU/eyFRRe2HSYpnoavV0U/f Nsd6xuV5wrQ8qp2PIUkLE/PSCB3yve/iA2CufLzOrRIf8XjK5UNfeJAzHvcUfuOF5TKe ION/bjYrBWfz8NlAQr9By3bv7oXMzNf8K0bljaLMGy302Uxcn1bIIjuyVa5ujOPC1uWr PJPKJdHXXcoQz+eFwC5O5JRMeGD/jKKb7nCbvQ85BuLKof0i7xJvwPwc93xQmBRZPcto jnnw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789402121; x=1790006921; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zEDrRYTmQqo5wdWqm6gdLLM4eMFHZENFRr7j+KFawt8=; b=SnLKsLhXLicI9o2MZhtU9OhfzopU24wmtFeRvKtlgn6PcCBLrgVU0saZVR/fmeoZoN Tn99QJLuGMp1i8u0nzNDVaL6fBY0gKw3YJ5aPNiUPQ8igH0vHOPymhYQemjlJq1UrLVy k+DG8xRmuNr0GuFApGMZ4g6AhJCeqwLcfVnLvxUbloaFO6l6Tah1YHWJ+2QhmBlLq0Nl wsTwYFpUkCp/CTsKrUbzDLQ/aS22DwVclxV/0NkevME8lt5rLjJRyJTRIBqZX4HutdfU 8w4uohdmZn30tAQIUvnwrVAnUnlWOoa17g9iv2PxYMUFYFWHGBf3XPz+/XtTk0Dw+zJ3 kCxg== X-Gm-Message-State: AFuF++mJx4DXUhyP4tipGBW6h0j0b1VahHEmfDEXgNvNY9FODm/UWUu1 07pPH3sQE313FvHETS36YH+YHO0wUZLNFbLfpDzI0TcgXQBoJ6BqZHaiRDP8ZA== X-Gm-Gg: AYBFou1nD3Dyy5MfaTcqrP11XVGbyT26WgbQqOSoATlElQPZDm1UfFzV70Kx8L8h/vp mDQfJm1qXYnxj8hWglw0IETAcWqhOFISPQRWrKSTOvRq5scZw6SnJ5NCdf9YuPbuf+ThrVl15z1 1TpajmggXUaGxFb+T60MEwT03NM+tcaE/vUnDQEnbMSgW0Ze7kamx9DttNOmEc9WLUAeZjTkYIw 0yANmEv1ivY5CmqqmliugCLuhsSMRrs5uC3oMtWowSDIv2/7SwCdsyYwfClo7qyPTwFL+wmmbe6 KmtZNmthgnirXhMgsNE9YRvVfjeQ/CJETNbWf0GtMd7gUCXK1i4Y+XU47NFTM/ru2ACydcN4UG5 6JRBoLKclG3DXXV8SdGmV6sCSfUDFVCPjJOJ4HLO2eALo3pHfshXeGT/GcNirCqP7PaByhGT/FO VOoMDwi0oaRI00fYrTK5etc1rGXfF5Z+0DRGezaKIUgN2z4qcFTzKvPxKVfP7Zehqs/Iad X-Received: by 2002:a05:6820:4cca:b0:6a1:47c8:c86 with SMTP id 006d021491bc7-6c5400887f9mr1892453eaf.10.1789402121141; Mon, 14 Sep 2026 09:08:41 -0700 (PDT) Received: from localhost.localdomain ([2601:283:4b01:ba50::9413]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6c0990cc05fsm11012356eaf.3.2026.09.14.09.08.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 09:08:40 -0700 (PDT) From: Joshua Watt X-Google-Original-From: Joshua Watt To: docs@lists.yoctoproject.org Cc: Joshua Watt Subject: [docs][PATCH 1/2] ref-manual/variables.rst: Fix the documentation for the SPDX agent variables Date: Mon, 14 Sep 2026 10:08:35 -0600 Message-ID: <20260914160836.1673868-1-JPEWhacker@gmail.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 16:08:48 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/docs/message/10497 The documentation for the SPDX variables related to agents was incorrect and misdirected users about how these variables are intended to be used. Signed-off-by: Joshua Watt --- documentation/ref-manual/variables.rst | 42 +++++++++----------------- 1 file changed, 14 insertions(+), 28 deletions(-) diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst index 83bc59efe..e1d3cd70f 100644 --- a/documentation/ref-manual/variables.rst +++ b/documentation/ref-manual/variables.rst @@ -9567,38 +9567,28 @@ system and gives an overview of their function and contents. PURLs. :term:`SPDX_IMAGE_SUPPLIER` - The name of an agent variable prefix describing the organization or - person who supplies the image SBOM. When set, the supplier is attached - to all root elements of the image SBOM using the ``suppliedBy`` property. + The variable prefix for describing the organization or person who + supplies the image SBOM. When set, the supplier is attached to all root + elements of the image SBOM using the ``suppliedBy`` property. The value of this variable is the base prefix used to look up the agent's details. The following sub-variables are read using that prefix: - - ``_name``: display name of the supplier (required) - - ``_type``: agent type: ``organization``, ``person``, + - ``SPDX_IMAGE_SUPPLIER_name``: display name of the supplier (required) + - ``SPDX_IMAGE_SUPPLIER_type``: agent type: ``organization``, ``person``, ``software``, or ``agent`` (optional, defaults to ``agent``) - - ``_comment``: free-text comment (optional) - - ``_id_email``: contact e-mail address (optional) - - The simplest approach is to use the variable itself as its own prefix, - so the sub-variable names follow directly from - ``SPDX_IMAGE_SUPPLIER``. + - ``SPDX_IMAGE_SUPPLIER_comment``: free-text comment (optional) + - ``SPDX_IMAGE_SUPPLIER_id_email``: contact e-mail address (optional) Example (set in the image recipe or in a :term:`configuration file`):: - SPDX_IMAGE_SUPPLIER = "SPDX_IMAGE_SUPPLIER" SPDX_IMAGE_SUPPLIER_name = "Acme Corp" SPDX_IMAGE_SUPPLIER_type = "organization" - Alternatively, you can use any other prefix name, which is useful for - sharing an agent definition across multiple supplier variables:: - - MY_COMPANY_name = "Acme Corp" - MY_COMPANY_type = "organization" - SPDX_IMAGE_SUPPLIER = "MY_COMPANY" - SPDX_SDK_SUPPLIER = "MY_COMPANY" + Alternatively, it is also possible to reference an agent created by + another variable prefix, using ``SPDX_IMAGE_SUPPLIER_ref``. For example:: - If not set, no supplier information is added to the image SBOM. + SPDX_IMAGE_SUPPLIER_ref = "SPDX_PACKAGE_SUPPLIER" See also :term:`SPDX_PACKAGE_SUPPLIER` and :term:`SPDX_SDK_SUPPLIER`. @@ -9737,7 +9727,7 @@ system and gives an overview of their function and contents. already fixed upstream (warning: this can be large and slow). :term:`SPDX_INVOKED_BY` - The base variable name describing the agent that invoked the build. + The variable prefix describing the agent that invoked the build. Each ``Build`` object in the SPDX output is linked to this agent with an ``invokedBy`` relationship. Requires :term:`SPDX_INCLUDE_BITBAKE_PARENT_BUILD` to be set to ``"1"``. @@ -9751,7 +9741,6 @@ system and gives an overview of their function and contents. Example (CI pipeline invoking the build):: SPDX_INCLUDE_BITBAKE_PARENT_BUILD = "1" - SPDX_INVOKED_BY = "SPDX_INVOKED_BY" SPDX_INVOKED_BY_name = "GitLab CI" SPDX_INVOKED_BY_type = "software" @@ -9792,7 +9781,7 @@ system and gives an overview of their function and contents. ``http://spdx.org/spdxdoc``. :term:`SPDX_ON_BEHALF_OF` - The base variable name describing the agent on whose behalf the invoking + The variable prefix describing the agent on whose behalf the invoking agent (:term:`SPDX_INVOKED_BY`) is running the build. Requires :term:`SPDX_INCLUDE_BITBAKE_PARENT_BUILD` to be set to ``"1"``. Has no effect if :term:`SPDX_INVOKED_BY` is not also set. @@ -9806,10 +9795,8 @@ system and gives an overview of their function and contents. Example (CI system building on behalf of a customer organization):: SPDX_INCLUDE_BITBAKE_PARENT_BUILD = "1" - SPDX_INVOKED_BY = "SPDX_INVOKED_BY" SPDX_INVOKED_BY_name = "GitLab CI" SPDX_INVOKED_BY_type = "software" - SPDX_ON_BEHALF_OF = "SPDX_ON_BEHALF_OF" SPDX_ON_BEHALF_OF_name = "Acme Corp" SPDX_ON_BEHALF_OF_type = "organization" @@ -9822,7 +9809,7 @@ system and gives an overview of their function and contents. :term:`SPDX_INVOKED_BY`, and :term:`SPDX_BUILD_HOST`. :term:`SPDX_PACKAGE_SUPPLIER` - The base variable name describing the agent who supplies the artifacts + The variable prefix describing the agent who supplies the artifacts produced by the build. Works identically to :term:`SPDX_IMAGE_SUPPLIER` but applies to individual packages rather than the image SBOM. @@ -9831,7 +9818,6 @@ system and gives an overview of their function and contents. to apply only to packages of that recipe. Recipe-level overrides (``SPDX_PACKAGE_SUPPLIER:pn-``) are also supported:: - SPDX_PACKAGE_SUPPLIER = "SPDX_PACKAGE_SUPPLIER" SPDX_PACKAGE_SUPPLIER_name = "Acme Corp" SPDX_PACKAGE_SUPPLIER_type = "organization" @@ -11480,7 +11466,7 @@ system and gives an overview of their function and contents. configuration must define the :term:`UBOOT_MACHINE` variable. Additional control variables are: :term:`UBOOT_CONFIG_BINARY`, :term:`UBOOT_CONFIG_FRAGMENTS`, :term:`UBOOT_CONFIG_IMAGE_FSTYPES`, and - :term:`UBOOT_CONFIG_MAKE_OPTS`. + :term:`UBOOT_CONFIG_MAKE_OPTS`. Here is an updated example from the ``meta-freescale`` layer. :: From patchwork Mon Sep 14 16:08:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Joshua Watt X-Patchwork-Id: 98199 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C6BAC88E6E for ; Mon, 14 Sep 2026 16:08:48 +0000 (UTC) Received: from mail-oo2-f42.google.com (mail-oo2-f42.google.com [74.125.231.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.1384.1789402124286011561 for ; Mon, 14 Sep 2026 09:08:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=FdJfEWta; spf=pass (domain: gmail.com, ip: 74.125.231.170, mailfrom: jpewhacker@gmail.com) Received: by mail-oo2-f42.google.com with SMTP id 006d021491bc7-6beed321ad9so1425410eaf.3 for ; Mon, 14 Sep 2026 09:08:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789402123; x=1790006923; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=phYBkVMTQBh9yLYT/87ogJsohkG7NYR7yRccMbxX5ew=; b=FdJfEWtaSghmZ523Oe6gbooKxGELuHzPXntSnYnANmbCuzVgBRKmTW4uY0wiKJOkhH /aInOun/yCOOnxF9QKfSj6VvbxEfohob1nInRf9f06q1PkUctqq3urIm4qRNkNnW4f+G tbOy5xo7S3mFHOrHMSYt40tIDLGMoEQIzHNlmvJIfZ2ziTDlipXNsStzFIKoMCfsqn79 PxT+X8brWoWl6rOq0l+ytUZuH7XnbBhkXX6od3M65Gr4kE9aj7obPtUvHn/TvxZQcOlO c0zSX0FV4OMzq9jpO6dj2/9H0iBuzENhT3W5j+wOfI12C5mdhzVLVs3sf6LDCI6Rdhf5 u8HA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789402123; x=1790006923; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=phYBkVMTQBh9yLYT/87ogJsohkG7NYR7yRccMbxX5ew=; b=OwJmwcEWDbQCVEHILykeOS9KdF9NzMiR341JEzw9t/VwzHM6NH+rTM0H9Z0pyUV6ZI 1WhYQlxqfnJ7uvgJvk5mzOwMimErBxRfvBYnz7PvvciGBV1Prdz7FMplMi3iwLpKd2k6 iZDwFjcZGxe81rg/4HCBWJHtAvVjKqfmNEKtY2/QfH0UGEfLPFkWAvNtvOFQjnQq1JYs ZCSGjtVaeZ+BGHOKfPFk0oMhKXbac3rHPZbnVcnaXT1sUDRv5tm0w5iKHCI+zbS0jF1j 1Clgy3jjSoI2BEtDp9bfhjCkqSlVhl+AN9xJhow0ac8sjJuiY5JCFaLijB0qNoXkiNPc aYgw== X-Gm-Message-State: AFuF++kXERgzlPRuAMHf4zDDBeYiHgr5FgQqIfbAI2GpvwySbBMZ9Wy+ SJwHrQJ4eRCwnjW0p/ZYKO+OLdnFMVNidsY+UrzvcIYPHESUgcj9NZQYCMQVyg== X-Gm-Gg: AYBFou1G6Q9PSVChKGQkcDqoOza/+m9I5fH3u/c+iRWjPAOff1XN6sW2UW2w5MErDbN 7hPnQAJGt/vh9AYDdU3PCsxr/1dSh8zJCAhlJ5eQoVim+JNzxxRUWKzCGgPDkREaFj0sx8hFuvU qoJOfGmV2pJ3xrPp4lJrtT8Lq698njYV5mMBAF7o9b30O3jfO4hvdgbaekf9GJJAjnDci7odhYE Md5cEQyHps2Ea6wTxH4f0Do8Srve+LX/0aL8O+VwnEnwsgzUo9BidwUBIqoBlHv3wh2Uon1VblV iuviEGlygGGptL3vgmayq4mILdI3IGavsPVgdzxo+dlVVJrpaXKNX4M6bqpQCoPVt5lUeJbUovI xCQND27FQzWKVUQAOyiRQAom1kiTaBMiK2+SeuF6hCAM+pUCaEXmvUn1mAjCqHCNAWCVMmS8i9I OByb6Pvax7dhyh42Qzie7IOGmCwbvmj49xrubd9CrJ7rkixHn493DFeSUG1UQ4mrZXKD7mT+3v0 wxvoqY= X-Received: by 2002:a05:6820:3083:b0:6b7:46fa:16a9 with SMTP id 006d021491bc7-6c542832ae1mr1824495eaf.62.1789402123329; Mon, 14 Sep 2026 09:08:43 -0700 (PDT) Received: from localhost.localdomain ([2601:283:4b01:ba50::9413]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6c0990cc05fsm11012356eaf.3.2026.09.14.09.08.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 09:08:43 -0700 (PDT) From: Joshua Watt X-Google-Original-From: Joshua Watt To: docs@lists.yoctoproject.org Cc: Joshua Watt Subject: [docs][PATCH 2/2] ref-manual/variables.rst: Document SPDX_AUTHORS Date: Mon, 14 Sep 2026 10:08:36 -0600 Message-ID: <20260914160836.1673868-2-JPEWhacker@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260914160836.1673868-1-JPEWhacker@gmail.com> References: <20260914160836.1673868-1-JPEWhacker@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 14 Sep 2026 16:08:48 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/docs/message/10498 Document the SPDX_AUTHORS variable. There was some confusion about how this variable works compared to the other single-agent variables, so adding explicit documentation that indicates how it diverges is useful. Signed-off-by: Joshua Watt --- documentation/ref-manual/variables.rst | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/documentation/ref-manual/variables.rst b/documentation/ref-manual/variables.rst index e1d3cd70f..4ec4ce988 100644 --- a/documentation/ref-manual/variables.rst +++ b/documentation/ref-manual/variables.rst @@ -9499,6 +9499,29 @@ system and gives an overview of their function and contents. ``SPDX_IMPORTS``, :term:`SPDX_INVOKED_BY`, and :term:`SPDX_ON_BEHALF_OF`. + :term:`SPDX_AUTHORS` + This variable is used to list the authors of the created SPDX data. + It works slightly differently than the other agent variables (like + :term:`SPDX_IMAGE_SUPPLIER`) in that the base variable provides a list of + suffixes which are used to construct the variable prefixes for the + created authors. For example:: + + SPDX_AUTHORS = "myorg myself" + SPDX_AUTHORS_myorg_name = "My Organization" + SPDX_AUTHORS_myorg_type = "organization" + SPDX_AUTHORS_myself_name = "My Name" + SPDX_AUTHORS_myself_type = "Person" + + + Note that references to other objects can be made using the ``_ref`` + suffix, for example:: + + SPDX_AUTHORS_myself_ref = "SPDX_IMAGE_SUPPLIER" + + And other variables can reference authors by using the correct prefix:: + + SPDX_IMAGE_SUPPLIER_ref = "SPDX_AUTHORS_myorg" + :term:`SPDX_CONCLUDED_LICENSE` The :term:`SPDX_CONCLUDED_LICENSE` variable allows overriding the ``hasConcludedLicense`` object to individual SBOM packages. This can be