From patchwork Mon Sep 28 19:03:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Daniel Turull X-Patchwork-Id: 99517 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 42C98CA5FA2 for ; Mon, 28 Sep 2026 19:04:30 +0000 (UTC) Received: from AM0PR02CU008.outbound.protection.outlook.com (AM0PR02CU008.outbound.protection.outlook.com [52.101.72.63]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.66570.1790622263844724238 for ; Mon, 28 Sep 2026 12:04:24 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@ericsson.com header.s=selector2 header.b=B0PHTYwM; spf=pass (domain: ericsson.com, ip: 52.101.72.63, mailfrom: edaturu@ericsson.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Y14aGTQQCus4VHrBlnoZYJK7RDOqiSf1iNAu5RBo1ZmCcMP0KfriXu0EKd3MGp93cu5QyNChKsq9MCqEZpaU58g/zNy1edNLn6dwsZy69nAkUnmfSUk2RDuB5e5eCxv2ejpE9ldN84L3ww/3bhIbemJ3sewouMYeWcYdDbUdegSal2OFvp/Y4Yp72oqoxnhkSYnnD1ociTHZklfrQdEB9X4mzEf7tKqJ6B/hPAGZgLEWxIDo6ipw5RRRFt2gW6CDZLpMbZ87T+IFP/eX8OlOvsfEoqU03sKzpe+6gvwm4VAa0DcB5B8xJboIWK8/McmqYVGis0h3zVEltebxJPxW/Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=b7EfrB5X37dWayq88Eqa9sWYIr4qXtfB/GbQvvDZmaU=; b=rZs5GGr2CREtGB7MW5igMAaj8+UDTBUn7nfpkZkHMZMOzv+irEh8LVrmUj7GsvAzkpt6hURet9JzCFf7vEP2/oqGlYjiMsE2IWy9kDi6IfqOIsdetwV7/4WQvCzUa/dOX5wDzjv90uQAr3w56u/IRyWFdKpeM+hxn/JV3bED4wszOzTt7O2roku6eeqm0c9O7ZXrGXoe0iP0+CAmBPMjZUaB5J+cLBJCnkyVs2oOQcsRAYd6JO6sMb7fIghVs2G/caVfgVSE/sm9pR49Vdze8p5rPhNMvXKSat4VpiqDEnCMCT85P2Qr9PADYpZRlQbKuXxleX6nSUefPovdj6dcfg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 192.176.1.74) smtp.rcpttodomain=bootlin.com smtp.mailfrom=ericsson.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=ericsson.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b7EfrB5X37dWayq88Eqa9sWYIr4qXtfB/GbQvvDZmaU=; b=B0PHTYwMM0fwtgrYG+XKLKJuSHtHKWtIqqT6vRDOTAev9aosAL87R3hzubb1SanTELrLo2jTV8M0VG4ourffuIuFnpPyCHnnB5yi11sh3d9wNmEL8Su3FmKwWB3DwrFy8drWc05tH3/XuAreefXIXzuA/5YtjdupahJTa0dmd3kmSLkSBtUY2MtWAFVQ/mjWP3723QL7jGAWXekAt9V4l9FheOHbTb9zB6WGzuCyVwKlDArkHla+qJXD78G2jvS7i4BfgRGcV4rljJMHkWDD7qdaFDtlUmszMOsct4tGpJ8rkjm03sjKdgnQtToa8kETItc3CEKvxwAu9a9dSC/QYg== Received: from PAZP264CA0052.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:1fc::15) by DB9PR07MB7770.eurprd07.prod.outlook.com (2603:10a6:10:2af::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.451.24; Mon, 28 Sep 2026 19:04:18 +0000 Received: from MI3PEPF0000848B.eurprd02.prod.outlook.com (2603:10a6:102:1fc:cafe::ac) by PAZP264CA0052.outlook.office365.com (2603:10a6:102:1fc::15) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.451.24 via Frontend Transport; Mon, 28 Sep 2026 19:04:18 +0000 X-MS-Exchange-Authentication-Results: mx.microsoft.com 1; spf=pass (sender IP is 192.176.1.74) smtp.mailfrom=ericsson.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=ericsson.com; Received-SPF: Pass (protection.outlook.com: domain of ericsson.com designates 192.176.1.74 as permitted sender) receiver=protection.outlook.com; client-ip=192.176.1.74; helo=oa.msg.ericsson.com; pr=C Received: from oa.msg.ericsson.com (192.176.1.74) by MI3PEPF0000848B.mail.protection.outlook.com (10.167.240.138) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.472.14 via Frontend Transport; Mon, 28 Sep 2026 19:04:18 +0000 Received: from seroius18813.sero.gic.ericsson.se (153.88.142.248) by smtp-central.internal.ericsson.com (100.87.178.64) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.43; Mon, 28 Sep 2026 21:04:10 +0200 Received: from seroius08462.sero.gic.ericsson.se (seroius08462.sero.gic.ericsson.se [10.63.237.245]) by seroius18813.sero.gic.ericsson.se (Postfix) with ESMTP id DBC6C957DA; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) Received: by seroius08462.sero.gic.ericsson.se (Postfix, from userid 160155) id ACD28700CF27; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) From: To: CC: , , Daniel Turull Subject: [PATCH v3 1/3] classes/base: exclude __CACHED_SOURCE_DATE_EPOCH from task hash Date: Mon, 28 Sep 2026 21:03:58 +0200 Message-ID: <20260928190400.3908822-2-daniel.turull@ericsson.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260928190400.3908822-1-daniel.turull@ericsson.com> References: <20260928190400.3908822-1-daniel.turull@ericsson.com> MIME-Version: 1.0 X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MI3PEPF0000848B:EE_|DB9PR07MB7770:EE_ X-MS-Office365-Filtering-Correlation-Id: dffe7449-a888-4582-6963-08df1d934c13 X-SMTP-Server: smtp-central.internal.ericsson.com X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|36860700016|1800799024|376014|82310400026|10067099003|11063799006|56012099006|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: xRtMuvSky1IcVMU9CHIieaKsBE/Ro1lOpmc+/H9pT5FdRY0MxDqanXMMmqhZCBmrVQbsaa/QUT1kMva6wveP54olNghoB8FP+CdfuKMNXbXXOX7eKjyas+FdCruG8bqKly6KkP578d3hrRozER+KXvW0dkZ3aGYTXl85eff6kF/CG+cOV8tOnyQqOjW58Q8TrDN707lrK/Y9ssafmzMq0QHuyAMP3bfNVgZaX6xPEaKYfhiT7YDs+FUXdi76OFS1sYjUAFDxF+aOd/4/sgwR7midpDyFzy7LcRFc6sUneMJ+afwbVXAQ6NYyhJ5VAqfGTOZJ36olvf2/03PAT/FCJBmYyJgrhddeShtRqJndAp18qZBXHH0GlCkU8/fnR8SWH5bNCogps7lEQgaz1Haoz2r8LdcRL/Yf27FeaM2FAV9y6ra+smiWmAWirpaQVoJZq92aID6kyo1zhyEJZ27UYjRZ7mBuWNYsZh5BoUdhRJ6F/nSyCnBP9JyUKF0D50RJESgDY1Ac8dAO4/tzMTW71v0XTLGbNcZIOOWgi1dEDeVHeiDya+z0VUiAVJac9ViEkdcGNO9Ap51wD7mD+5Km6OVh+ot5kduPeLNKXMntSMu4C8YsXzgrDmC5A59fjHlqSei0axZn37zb2gFKNOv+aUr8zPjBMgVQNfkWegijYtK6e/e2oMbENTO4tquFglkeEmE2qCpyXNtulM98Ckhgdw== X-Forefront-Antispam-Report: CIP:192.176.1.74;CTRY:SE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:oa.msg.ericsson.com;PTR:office365.se.ericsson.net;CAT:NONE;SFS:(13230040)(23010399003)(36860700016)(1800799024)(376014)(82310400026)(10067099003)(11063799006)(56012099006)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 2AqTrtWek6keUqSsGzbUZWQY9+SOR82GaPx8A3FWfNcU/4l0aLAdi3++zPY7BMWDu7lCAbal5TvLI2vfhoLPrJGfcHZJplOZSLz8r1rYPl3FH840F84URTvjnGdNFBwH2ChQBmAY109gRdMjitk3KhxnAEFFDbDINxalxeviMzg6o4jQUt9SdUnbEUUZuTzb7pZM8RVeqc2bYLg5ndSjPixaKULcvMtyQV9f+YnekHYmtjUSgRuEoTaD32tx25TqxzsHnRyYtOwfZiR8Ker9bUMmpRijmtkrFF1+aGJpsLZJD/bGWNMUbEKhWN8dXJKaxlgFkdU9qMDJyGG9QFBOsiizdwvfQZ32v2lkY+UtsAXBrXknjn/hAe68tz+vQVnvtnMqWP8T5kuW/QxS+zVOYAGGQf1pRaFiBX58K/vwG5+H2atnr7NLu+NS/ujBnfMX X-OriginatorOrg: ericsson.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Sep 2026 19:04:18.2847 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: dffe7449-a888-4582-6963-08df1d934c13 X-MS-Exchange-CrossTenant-Id: 92e84ceb-fbfd-47ab-be52-080c6b87953f X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=92e84ceb-fbfd-47ab-be52-080c6b87953f;Ip=[192.176.1.74];Helo=[oa.msg.ericsson.com] X-MS-Exchange-CrossTenant-AuthSource: MI3PEPF0000848B.eurprd02.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR07MB7770 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 28 Sep 2026 19:04:30 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246790 From: Daniel Turull epochfile_read() memoizes its result into __CACHED_SOURCE_DATE_EPOCH via d.setVar(), so its runtime value leaks into the basehash of any task that calls it, causing a "metadata is not deterministic" error once SDE_FILE is populated. Exclude it, since it is not meaningful build metadata. AI-Generated: Uses Kiro with Claude Sonnet 5 Signed-off-by: Daniel Turull --- This should fix the selftest errors reported by Mathieu --- meta/classes-global/base.bbclass | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass index 9553f00432..01a030399e 100644 --- a/meta/classes-global/base.bbclass +++ b/meta/classes-global/base.bbclass @@ -249,6 +249,10 @@ do_unpack[postfuncs] += "create_source_date_epoch_stamp" def get_source_date_epoch_value(d): return oe.reproducible.epochfile_read(d.getVar('SDE_FILE'), d) +# epochfile_read() memoizes into this variable via d.setVar(), so its +# runtime value must not leak into any task's hash. +oe.reproducible.epochfile_read[vardepsexclude] = "__CACHED_SOURCE_DATE_EPOCH" + def get_layers_branch_rev(d): revisions = oe.buildcfg.get_layer_revisions(d) layers_branch_rev = ["%-20s = \"%s:%s\"" % (r[1], r[2], r[3]) for r in revisions] From patchwork Mon Sep 28 19:03:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Daniel Turull X-Patchwork-Id: 99518 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5114CCA5FA6 for ; Mon, 28 Sep 2026 19:04:30 +0000 (UTC) Received: from GVXPR05CU001.outbound.protection.outlook.com (GVXPR05CU001.outbound.protection.outlook.com [52.101.83.32]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.65594.1790622264715364112 for ; Mon, 28 Sep 2026 12:04:25 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@ericsson.com header.s=selector2 header.b=azoNlccQ; spf=pass (domain: ericsson.com, ip: 52.101.83.32, mailfrom: edaturu@ericsson.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=dD7G9skcsgVGP6NbSF+66kShHGDtXZ5CfQOc0RREIlJMGvt+QjKMdKcjFJBtTr7IbZboF8bg/Iq3XaJ99ERulU561LsgiUOLOEQIdOTzqOmkxaqBHgyRVRHVGmAfZDy7Zjyj81u1NZ6lt9TjFBnWJOcaMleueOd/kh5/1q9qdLVenJCDUVExTy5KHpCg3JlVNSZFJ1TJ1VUt+ffjS58mGCoWyJfY3HdhHSkNHB0owFCpznEoK6Xpb7aalaHlH940xkJVI/lirTjWTOps9ufZqPg6ynrnVa7QdaGLaDfgWuzBCGGOSsfNpqUdI2+xfdsx8uETQ56T4Zn7pUXbP02rSg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=/g79nCB8Y3ptmP4PXtL2MjmYNQaP7oeR3x9dEaBKI34=; b=UXnDWkn6hsOLi5NLsUZ+T66uXCeh/3sAPThn9wCnLk2OEESSapPg5KoS8dDR2h1gdHs+Q+11LJ/v2rjfgyF5IS6T1/Z9bSKz7MrA7Y9Jq+ezW5DJtOYHodZtabQNtnpS6IYrCY8w6HDw8lkL+xsx8uP81u5TW2vasISbJ2I/8r0yy94fWKmZX244Fs3GxKl7owzzfyNNywW1xtJIoz/pK7jMURvI93gGlEabyT0TsD7k/cSdkLGoBWB9qoeWrCH9+uXrglSiulByhZQc7PmWNmn55kaEiRXxTRx4DAyu6NlTiUkpbGJPECY8YFChwkJUtb8rutE/u5cFKwQUJ/HfjA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 192.176.1.74) smtp.rcpttodomain=bootlin.com smtp.mailfrom=ericsson.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=ericsson.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=/g79nCB8Y3ptmP4PXtL2MjmYNQaP7oeR3x9dEaBKI34=; b=azoNlccQ22CSi4VqNi/wGXpiEsF02u3PR9xsO/lgN24CQAOk/RKeW5fIVHzGcOB5lwyy+UJafGHiHJqLiNwXN7H9kotPQQWESFw8hqZnK6HIpuPGELcIun6fY0SELLF4P1HK9f2AwtYcEi5LGROWtcXn03SBRzGDHjT8lULZV/rREx9bwVaOOluOq4b+FBeZpImJ9MgSYs41UV51MLDlGKeCPdO9frTlJn0RF1/oCi8AQNXPyPlSWHhULMUZs6ZAJGCKhePeXdiM5UMobiDNGSsgB7pHGGIHNKkTbWgdM4stB/ESZzE2EMRJkjblFGAwSeYv+VlhBzL5hzJmHCIVwg== Received: from PAZP264CA0051.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:1fc::11) by DU2PR07MB8111.eurprd07.prod.outlook.com (2603:10a6:10:270::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.451.24; Mon, 28 Sep 2026 19:04:17 +0000 Received: from MI3PEPF0000848B.eurprd02.prod.outlook.com (2603:10a6:102:1fc:cafe::62) by PAZP264CA0051.outlook.office365.com (2603:10a6:102:1fc::11) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.451.24 via Frontend Transport; Mon, 28 Sep 2026 19:04:17 +0000 X-MS-Exchange-Authentication-Results: mx.microsoft.com 1; spf=pass (sender IP is 192.176.1.74) smtp.mailfrom=ericsson.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=ericsson.com; Received-SPF: Pass (protection.outlook.com: domain of ericsson.com designates 192.176.1.74 as permitted sender) receiver=protection.outlook.com; client-ip=192.176.1.74; helo=oa.msg.ericsson.com; pr=C Received: from oa.msg.ericsson.com (192.176.1.74) by MI3PEPF0000848B.mail.protection.outlook.com (10.167.240.138) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.472.14 via Frontend Transport; Mon, 28 Sep 2026 19:04:17 +0000 Received: from seroius18814.sero.gic.ericsson.se (153.88.142.248) by smtp-central.internal.ericsson.com (100.87.178.64) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.43; Mon, 28 Sep 2026 21:04:07 +0200 Received: from seroius08462.sero.gic.ericsson.se (seroius08462.sero.gic.ericsson.se [10.63.237.245]) by seroius18814.sero.gic.ericsson.se (Postfix) with ESMTP id DB3E740203DF; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) Received: by seroius08462.sero.gic.ericsson.se (Postfix, from userid 160155) id B12D4700CF28; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) From: To: CC: , , Daniel Turull Subject: [PATCH v3 2/3] create-spdx-3.0: record component release date in SPDX output Date: Mon, 28 Sep 2026 21:03:59 +0200 Message-ID: <20260928190400.3908822-3-daniel.turull@ericsson.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260928190400.3908822-1-daniel.turull@ericsson.com> References: <20260928190400.3908822-1-daniel.turull@ericsson.com> MIME-Version: 1.0 X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MI3PEPF0000848B:EE_|DU2PR07MB8111:EE_ X-MS-Office365-Filtering-Correlation-Id: 5d42734c-2322-46d9-a25c-08df1d934b70 X-SMTP-Server: smtp-central.internal.ericsson.com X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|36860700016|376014|82310400026|1800799024|23010399003|22082099003|18002099003|56012099006|10067099003|260925021311599003|260925022911599003|260925021911599003|3023799007|11063799006; X-Microsoft-Antispam-Message-Info: 82GzlZE8iLpA5cYIzoWFc4nzfOg/2ct8rv1njStBQxEqf5ux8fdczVH7tqU29mdC/9Ipj1mOfTCSlTurUjPtXbwFLyr3L1ArPSmNgPxiL7uGjnmEqMd47JSdqnzqFBwnpPltmmCslRfZW8uPch74A6sKH1RW+HCWnokntExKNjrrg0JiDCHKtz3T/Ahm7UaohLmDNVX4xc0nfKEUu69IYWhn4TKsNgfKa6sUTRd5ifzb8jfx0IA48bbzSM6HpUb/MR8mqmYVqpsiMJocybDcONdguZ0oOg5DADh8E1LraB0nPD5Xg1hgxv31kX/MYXD6nUlaLXcDALd61pz1B/mBqiQTQIxrHaYVqrGzMlVjLhkwXnR8fENp3Ez+wIU4cdkNd4hHlR4N1eHl6Y/1Vg531Cjs0sGTDsdpU7oQyJNwa9XR2UfHvdxfHrJ+R/3+T7lctgnrhi3yd0NwJOfPQPm18YOwuRf7QD0zT1xQuOqiJXE9aFPQJSOiVrP5Hy8qePkczOOYMZv21heBJEEX/8yvzGd0dkF48ae6+y3Ht714Q4E3MT/KhiUZprn2dEnFqQvna9q/LkV2dBqrgXDrxkYcatelKCgHEi6Ac8hmlAeToxTHD3DVn2JcYsw6nSD4Z3uJf1g+90c9blBR2jVEclzWtY9ocpRGQ1TE5i/fmgRIQGFxAJ9Duskzbc+3lcrJVhylxpjvdUfxLJ2Fh1cxAp+QyQ== X-Forefront-Antispam-Report: CIP:192.176.1.74;CTRY:SE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:oa.msg.ericsson.com;PTR:office365.se.ericsson.net;CAT:NONE;SFS:(13230040)(36860700016)(376014)(82310400026)(1800799024)(23010399003)(22082099003)(18002099003)(56012099006)(10067099003)(260925021311599003)(260925022911599003)(260925021911599003)(3023799007)(11063799006);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: kFD2VmOPxsVu0hwrTwwDayFlvE1RrhYd4HWarvTHOW8p2YNtdWQEQpXBS83gxXe9X7KKnKxAOK4w4EbDG2cTe0LbLt82f27WoUTk19aMJuJv2rWdGphpCyMVqO95saUnW0ZJa4WcieunRT2AB5rQtJZ3F7oODvtmCYHa21P/8f3+xP4x3yDomGZ/PK39GgPk9cG2XWVfOpAPxEmGL0nOq9wLaQ4/UiU22EgotZNlfbNyeCLUWrJjygyiITFPJzCxNJjBNeWZgWhlcbtHTI/jC9l5xjV8QdOBHTp0196T+rxfuqvuvNwAhrFnEL8csu53GmyAG2xg5ozR4Tx/46rjuE1WLnT6gG8mzKbE3pWQIjfNe65ZDAGy5Mgt/raXttG3Uu8oU7hBMSkftgqYu8Kncj8BIXxuVI8l9MG6y3H4Vs6jlg0Yue50LM1Y5ieUpEi/ X-OriginatorOrg: ericsson.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Sep 2026 19:04:17.2172 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 5d42734c-2322-46d9-a25c-08df1d934b70 X-MS-Exchange-CrossTenant-Id: 92e84ceb-fbfd-47ab-be52-080c6b87953f X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=92e84ceb-fbfd-47ab-be52-080c6b87953f;Ip=[192.176.1.74];Helo=[oa.msg.ericsson.com] X-MS-Exchange-CrossTenant-AuthSource: MI3PEPF0000848B.eurprd02.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU2PR07MB8111 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 28 Sep 2026 19:04:30 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246791 From: Daniel Turull Record each recipe's release date in the releaseTime property of its software_Package object, using the SOURCE_DATE_EPOCH already computed for reproducible builds. Accuracy depends on how SOURCE_DATE_EPOCH was derived: exact for git-tagged recipes, best-effort for tarball/http(s) sources. Some Python sdists (e.g. cryptography, hypothesis, maturin) normalize all file mtimes to a fixed placeholder, so their releaseTime reflects packaging-tool behavior, not the real release date. Tested with oe-selftest -r spdx, and with `bitbake world --runall=do_create_spdx`: 1011/1150 recipes got a releaseTime (range 1998-12-30 to 2026-09-17), 139 correctly had none. AI-Generated: Uses Kiro with Claude Sonnet 5 Signed-off-by: Daniel Turull --- v2: - Dropped all options per Joshua's feedback; read SDE_FILE directly. - Dropped the redundant else: delattr(recipe, "releaseTime") branch. - Selftest compares against SDE_FILE content directly instead of SOURCE_DATE_EPOCH, which can diverge from it. - Fixed a leak: recipes with no git checkout and no fetched source had SDE_FILE holding only SOURCE_DATE_EPOCH_FALLBACK, showing a bogus 2011-04-05T23:00:00Z releaseTime instead of none. v3: - Also run after do_unpack: do_deploy_source_date_epoch's setscene shortcut can skip it, leaving SOURCE_DATE_EPOCH unset. - get_release_date() reads SOURCE_DATE_EPOCH again instead of SDE_FILE, now that they're guaranteed equivalent. - test_release_date_source_date_epoch: switched to tar (base-files has S == UNPACKDIR and never gets a real SOURCE_DATE_EPOCH). - Added test_release_date_omitted_for_fallback_value. --- meta/classes/create-spdx-3.0.bbclass | 2 +- meta/lib/oe/spdx30_tasks.py | 19 ++++++++++++++ meta/lib/oeqa/selftest/cases/spdx.py | 39 ++++++++++++++++++++++++++++ 3 files changed, 59 insertions(+), 1 deletion(-) diff --git a/meta/classes/create-spdx-3.0.bbclass b/meta/classes/create-spdx-3.0.bbclass index 56fd01fd53..2b1465b5a6 100644 --- a/meta/classes/create-spdx-3.0.bbclass +++ b/meta/classes/create-spdx-3.0.bbclass @@ -192,7 +192,7 @@ python do_create_recipe_spdx() { import oe.spdx30_tasks oe.spdx30_tasks.create_recipe_spdx(d) } -addtask do_create_recipe_spdx +addtask do_create_recipe_spdx after do_unpack do_deploy_source_date_epoch SSTATETASKS += "do_create_recipe_spdx" do_create_recipe_spdx[sstate-inputdirs] = "${SPDXRECIPEDEPLOY}" diff --git a/meta/lib/oe/spdx30_tasks.py b/meta/lib/oe/spdx30_tasks.py index b6456a214a..964c2f1594 100644 --- a/meta/lib/oe/spdx30_tasks.py +++ b/meta/lib/oe/spdx30_tasks.py @@ -36,6 +36,21 @@ def set_timestamp_now(d, o, prop): delattr(o, prop) +def get_release_date(d): + """Resolve the release date to record in a recipe's releaseTime property. + + Uses SOURCE_DATE_EPOCH; omits the fallback value since it's not a + meaningful release date. + + Returns a datetime, or None if no release date should be recorded. + """ + source_date_epoch = d.getVar("SOURCE_DATE_EPOCH") + if not source_date_epoch or source_date_epoch == d.getVar("SOURCE_DATE_EPOCH_FALLBACK"): + return None + + return datetime.fromtimestamp(int(source_date_epoch), tz=timezone.utc) + + def add_license_expression( d, objset, license_expression, license_data, search_objsets=[] ): @@ -633,6 +648,10 @@ def create_recipe_spdx(d): if val := d.getVar("DESCRIPTION"): recipe.description = val + release_date = get_release_date(d) + if release_date is not None: + recipe.releaseTime = release_date + for cpe_id in oe.cve_check.get_cpe_ids( d.getVar("CVE_PRODUCT"), d.getVar("CVE_VERSION") ): diff --git a/meta/lib/oeqa/selftest/cases/spdx.py b/meta/lib/oeqa/selftest/cases/spdx.py index 8285189382..668915b686 100644 --- a/meta/lib/oeqa/selftest/cases/spdx.py +++ b/meta/lib/oeqa/selftest/cases/spdx.py @@ -6,6 +6,7 @@ import textwrap import hashlib +from datetime import datetime, timezone from oeqa.selftest.case import OESelftestTestCase from oeqa.utils.commands import bitbake, get_bb_var, get_bb_vars import oe.spdx30 @@ -443,3 +444,41 @@ class SPDX30Check(SPDX3CheckBase, OESelftestTestCase): r'\d', f"Version '{version}' for package '{name}' should contain digits" ) + + def test_release_date_source_date_epoch(self): + """releaseTime should be derived from SOURCE_DATE_EPOCH.""" + objset = self.check_recipe_spdx( + "tar", + "{DEPLOY_DIR_SPDX}/{SSTATE_PKGARCH}/static/static-tar.spdx.json", + task="create_recipe_spdx", + ) + + source_date_epoch = get_bb_var("SOURCE_DATE_EPOCH", "tar") + expected = datetime.fromtimestamp(int(source_date_epoch), tz=timezone.utc) + + recipe = None + for pkg in objset.foreach_type(oe.spdx30.software_Package): + if pkg.name == "tar": + recipe = pkg + break + + self.assertIsNotNone(recipe, "Unable to find tar software_Package") + self.assertEqual(recipe.releaseTime, expected) + + def test_release_date_omitted_for_fallback_value(self): + """releaseTime must be omitted when SDE_FILE only has the fallback.""" + # packagegroup-base has no SRC_URI, so it only ever gets the fallback. + objset = self.check_recipe_spdx( + "packagegroup-base", + "{DEPLOY_DIR_SPDX}/{MACHINE_ARCH}/static/static-packagegroup-base.spdx.json", + task="create_recipe_spdx", + ) + + recipe = None + for pkg in objset.foreach_type(oe.spdx30.software_Package): + if pkg.name == "packagegroup-base": + recipe = pkg + break + + self.assertIsNotNone(recipe, "Unable to find packagegroup-base software_Package") + self.assertIsNone(recipe.releaseTime) From patchwork Mon Sep 28 19:04:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Daniel Turull X-Patchwork-Id: 99516 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6DBC9CA5FA6 for ; Mon, 28 Sep 2026 19:04:20 +0000 (UTC) Received: from DUZPR83CU001.outbound.protection.outlook.com (DUZPR83CU001.outbound.protection.outlook.com [52.101.66.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.66568.1790622256385960592 for ; Mon, 28 Sep 2026 12:04:16 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: body hash did not verify" header.i=@ericsson.com header.s=selector2 header.b=c11exgAM; spf=pass (domain: ericsson.com, ip: 52.101.66.47, mailfrom: edaturu@ericsson.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=U1y/QFVYSCk55aTiMhIR34cXUakS9fP9MQuNQ8ffpp6G0B132q5EmiltOCtqsER+iM7fU6PLhv6zBBfv6D33vYiG9aQps2ZI6WKmST/RKhaST9M+bZGjMAgqv1FupRpdWATgalxQfXxC++bGfqrHbx0G2trPOAgIRpTJHHa9xdjXfdMrpFkq3jTXzvJAaXEPXZ9fAQWduBV1mgZQorjSCAUGwsz2zOL15d+orrbtZpMIrEdr5cX2zxZPFSoU6QSMN9f8tYdiNiIJZZ084YQVsPlbzdtayAhze1HHh0WCb8y+iJ7S5ETrjRc64IawP7kc3VXttqp3Rwjq4RnfhN5wuw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=EpEIlpH0bU3FOZgnB11wItmBSujwMiWkbi9LyN+fNp4=; b=MdpxxMoXQ5E8z4gDXb82s8lIEzhgwkkm/v6jPbAj3dF1MrpK4A+T6iUxC67835t4OoinwlOSkQqncYPLxJ/VZrmu3YNvkb+ub8xhEO9lfCv6MbBqjokjhXKpXgNslCVgaIkrUddZLNuOQ5QUXOxgnITkqQROUSrSxJVgeonvwQDNW/ySPYVhpUUlAkyfuqHLH+7JdphGH3W541R4He+PBsAqEuFFRgBviluIjGMhR0J+hdHUQki5fVNshobX0jcPckyQHQrgFfpLuS/IfbNLRv1q/9vjzDZ8fRJt+QauxyaG5hxEwj6YpeVdZbX/pJOEKtkbUgq7ks6IORzL9G61hw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 192.176.1.74) smtp.rcpttodomain=bootlin.com smtp.mailfrom=ericsson.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=ericsson.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=EpEIlpH0bU3FOZgnB11wItmBSujwMiWkbi9LyN+fNp4=; b=c11exgAMnmiutHG6Is2qiepdpwC7LRUQc64dHH9i1Wo+2AxZ7hlIhZ+/SpE5SdtdatDMisVeKcPE48hvqMr3QlBASOu85clt4UTUuarTyFqmp6ufYLBpP2BYFp0xejupQjI635kFbDTkB4Cv6QyJS/BPcFKUx2eSdRiW6H/j76qeabL2H6exzfIRH0uI3dyE+gXYzgRbdtuOfEGGVJDFPyBNUYtM1GbGC3nrhSPxpe9oZNSxzsZUE4Ug76hwHremca3BkizlUGPshWhCGgHKBgvdYeHLrVJW7+DyLPSynO6/GTJF/h6tBca1LhLWUeoBXsd9bg2sFNA88F8kzZ9z7g== Received: from DUZP191CA0050.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:4fa::23) by AMBPR07MB12326.eurprd07.prod.outlook.com (2603:10a6:20b:760::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.451.24; Mon, 28 Sep 2026 19:04:11 +0000 Received: from MAD0EPF000008BB.eurprd04.prod.outlook.com (2603:10a6:10:4fa:cafe::69) by DUZP191CA0050.outlook.office365.com (2603:10a6:10:4fa::23) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.451.24 via Frontend Transport; Mon, 28 Sep 2026 19:04:10 +0000 X-MS-Exchange-Authentication-Results: mx.microsoft.com 1; spf=pass (sender IP is 192.176.1.74) smtp.mailfrom=ericsson.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=ericsson.com; Received-SPF: Pass (protection.outlook.com: domain of ericsson.com designates 192.176.1.74 as permitted sender) receiver=protection.outlook.com; client-ip=192.176.1.74; helo=oa.msg.ericsson.com; pr=C Received: from oa.msg.ericsson.com (192.176.1.74) by MAD0EPF000008BB.mail.protection.outlook.com (10.167.241.170) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.472.14 via Frontend Transport; Mon, 28 Sep 2026 19:04:10 +0000 Received: from seroius18813.sero.gic.ericsson.se (153.88.142.248) by smtp-central.internal.ericsson.com (100.87.178.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.43; Mon, 28 Sep 2026 21:04:09 +0200 Received: from seroius08462.sero.gic.ericsson.se (seroius08462.sero.gic.ericsson.se [10.63.237.245]) by seroius18813.sero.gic.ericsson.se (Postfix) with ESMTP id E21F19975E; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) Received: by seroius08462.sero.gic.ericsson.se (Postfix, from userid 160155) id B5E6B700CF29; Mon, 28 Sep 2026 21:04:05 +0200 (CEST) From: To: CC: , , Daniel Turull Subject: [PATCH v3 3/3] scripts/contrib: add spdx-release-date-report.py Date: Mon, 28 Sep 2026 21:04:00 +0200 Message-ID: <20260928190400.3908822-4-daniel.turull@ericsson.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260928190400.3908822-1-daniel.turull@ericsson.com> References: <20260928190400.3908822-1-daniel.turull@ericsson.com> MIME-Version: 1.0 X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MAD0EPF000008BB:EE_|AMBPR07MB12326:EE_ X-MS-Office365-Filtering-Correlation-Id: 3ffcfdfa-3674-4496-34cb-08df1d934766 X-SMTP-Server: smtp-central.internal.ericsson.com X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|1800799024|82310400026|23010399003|36860700016|18002099003|22082099003|3023799007|10067099003|260925021311599003|260925022911599003|260925021911599003|11063799006|56012099006; X-Microsoft-Antispam-Message-Info: //qLGyMN1/lR4/5F9+3+hdnfQ6yM7GjFZL9orkVDCeiKKPz5uiwni72/iHPWU0uRwTgt6Nv4AzgKtXPm362YuCuCnbduaVfpwBuzZQLreuAZjYqwzZRdwBDJTfKAzbvhU7s1RTIuvrzWLYOUNgLHtTi/u7TjF8quX2BsSF7wYzc+Q6nd/TDZTyvyUiiswHU4/5i3rBh2lGgM1HrF20Pdkj8WNlijA7nZzJeM6YwdsVt/gT9jHRID6QiAoLi/o4NUflB7lhNMHwTtcW/V+jp/UrOINeiAzTIaTQBFfJN3W2N8RSa6Csu5HiJxOftmh+sguScB+ERmmUJuE3FIznghi7Ekw+P9A822H/p8sTLXCI9ixAAKo7xp4/1HfT8RB53yL33I96P03B/yk3JnUGULNv0HCPwz3yx1G42l8jvEpWTvgmw8LEKf+AO/Muc2xvZyoNfB0/Cn8Vr++Q0LsKWYu4outff4mHJrGDPzczNzntNEHD08lio5/7lDtR64PwLgg6rUO3gZGg6E/hDnie6Gl3KDKc6qoHKQ+DEABMEQHF+GI96kttJoNGHm6ETqOwebwa0G+7uMDVL3T7Jn/T5Eu85hwpM+jvCY4IzAbHmeJBbIz5S62zROIWHBCyn92aR05NZ9SFHPU6zJnmHBPuVPhZxMpSRVrrhvkpT08cFrOgs= X-Forefront-Antispam-Report: CIP:192.176.1.74;CTRY:SE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:oa.msg.ericsson.com;PTR:office365.se.ericsson.net;CAT:NONE;SFS:(13230040)(376014)(1800799024)(82310400026)(23010399003)(36860700016)(18002099003)(22082099003)(3023799007)(10067099003)(260925021311599003)(260925022911599003)(260925021911599003)(11063799006)(56012099006);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 4GLGmVwUjg4AfP7ToIaeCaJR5kvc+r2kuZ6edDuIDZvIk5reuRWUCZM3wreO2YIP5jLJsHPUhFSzOpVNIpqBmPt9pKyXiEgJ4uFNAAo/J0TAO88l1FB7lorts/O7d2LbC+41YchqR9UzRdnf8EGlBISN/OvvnWzJDSFGoME0lOVxGhkIkL9IUlEzcLo2SWD3Q14NMOrB6OwtaS5IWDeFgkEe3+YkQdWnRy4v4j2t3GExhCAmzwmMN8hLAlAHDrQQMDv3qWqdQmc6V7OExCPjV+NunRaxwX4z5Tj5sk8V5kFo0A4WIncW547ZeyJfRRpzU3LM7J0XHBJ3cJ0zrqeKPWNhqdeeuWt1h04iOohXPXf/RnMpa/P23c7MoZvjzBClBSuQzqJrVAIT/M75dRtUWrUkK4VpKjl03YWY4T0Z3OL9csy57UOiB77vQPGDdq3y X-OriginatorOrg: ericsson.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Sep 2026 19:04:10.4053 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 3ffcfdfa-3674-4496-34cb-08df1d934766 X-MS-Exchange-CrossTenant-Id: 92e84ceb-fbfd-47ab-be52-080c6b87953f X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=92e84ceb-fbfd-47ab-be52-080c6b87953f;Ip=[192.176.1.74];Helo=[oa.msg.ericsson.com] X-MS-Exchange-CrossTenant-AuthSource: MAD0EPF000008BB.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: AMBPR07MB12326 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 28 Sep 2026 19:04:20 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246789 From: Daniel Turull Reports each recipe's releaseTime (added by the create-spdx-3.0 patch) from either a DEPLOY_DIR_SPDX tree or a single merged image SBOM. Used to spot-check release dates across a build and surface recipes missing one; helped find the SOURCE_DATE_EPOCH_FALLBACK leak and archive-mtime issues fixed by the two preceding patches. AI-Generated: Uses Kiro with Claude Sonnet 5 Signed-off-by: Daniel Turull --- scripts/contrib/spdx-release-date-report.py | 193 ++++++++++++++++++++ 1 file changed, 193 insertions(+) create mode 100755 scripts/contrib/spdx-release-date-report.py diff --git a/scripts/contrib/spdx-release-date-report.py b/scripts/contrib/spdx-release-date-report.py new file mode 100755 index 0000000000..be429409fc --- /dev/null +++ b/scripts/contrib/spdx-release-date-report.py @@ -0,0 +1,193 @@ +#! /usr/bin/env python3 +# +# Copyright OpenEmbedded Contributors +# +# SPDX-License-Identifier: GPL-2.0-only +# +# Author: Daniel Turull +# +# Reports, per recipe, whether a valid releaseTime was recorded in SPDX +# 3.0.1 output. +# +# AI-Generated: Uses Kiro (Claude) + +import argparse +import csv +import glob +import json +import logging +import os +import re +import sys + + +def load_jsonld_graph(path): + """Return the @graph list of a SPDX 3.0.1 JSON-LD document, or [] on error.""" + try: + with open(path, "r", encoding="utf-8") as f: + data = json.load(f) + except (OSError, json.JSONDecodeError) as e: + logging.warning("Skipping %s: %s", path, e) + return [] + return data.get("@graph", []) + + +def collect_release_dates(deploy_dir): + """ + Map recipe name -> releaseTime (or None) from all static/static-*.spdx.json + files found under deploy_dir. + """ + release_dates = {} + pattern = os.path.join(deploy_dir, "**", "static", "static-*.spdx.json") + for path in sorted(glob.glob(pattern, recursive=True)): + for element in load_jsonld_graph(path): + if element.get("type") != "software_Package": + continue + name = element.get("name") + if not name: + continue + # First occurrence wins; the same recipe can appear for multiple + # arches (e.g. allarch vs machine-specific) with identical data. + release_dates.setdefault(name, element.get("releaseTime")) + return release_dates + + +def _to_row(name, release_date): + return { + "recipe": name, + "release_date": release_date or "", + "valid_date": bool(release_date), + } + + +def build_report(deploy_dir): + """ + Build the report: [{"recipe": ..., "release_date": ..., "valid_date": bool}] + """ + release_dates = collect_release_dates(deploy_dir) + return [_to_row(name, release_dates[name]) for name in sorted(release_dates)] + + +# Per-recipe document namespace shared by all elements of that recipe in a +# merged SBOM, e.g. http://spdx.org/spdxdocs/acl-//recipe/acl +DOC_NAMESPACE_RE = re.compile( + r"^(https?://spdx\.org/spdxdocs/[^/]+-" + r"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})/" +) + + +def doc_namespace(spdx_id): + """Extract the per-recipe document namespace from a SPDX ID, or None.""" + match = DOC_NAMESPACE_RE.match(spdx_id or "") + return match.group(1) if match else None + + +def build_report_from_file(spdx_file): + """ + Build the same report as build_report(), but from a single merged SBOM + document (e.g. an image's *.rootfs.spdx.json) instead of a DEPLOY_DIR_SPDX + tree. Recipes are identified by their document namespace. + """ + graph = load_jsonld_graph(spdx_file) + + recipes = {} # namespace -> {"name": ..., "release_date": ...} + for element in graph: + if element.get("type") != "software_Package": + continue + + namespace = doc_namespace(element.get("spdxId")) + if namespace is None: + continue + + if element.get("software_primaryPurpose") == "specification" and element.get("name"): + # The recipe itself, as opposed to its runtime package(s). + recipes[namespace] = { + "name": element["name"], + "release_date": element.get("releaseTime"), + } + + report = [_to_row(info["name"], info["release_date"]) for info in recipes.values()] + report.sort(key=lambda r: r["recipe"]) + return report + + +def filter_rows(report, missing_only, sort_by_date=False): + rows = [r for r in report if not missing_only or not r["valid_date"]] + if sort_by_date: + rows.sort(key=lambda r: (not r["valid_date"], r["release_date"], r["recipe"])) + return rows + + +def print_table(rows): + if not rows: + print("No matching recipes found.") + return + + name_width = max(len("recipe"), *(len(r["recipe"]) for r in rows)) + print(f"{'recipe':<{name_width}} {'release_date':<21} valid") + for r in rows: + print(f"{r['recipe']:<{name_width}} {r['release_date']:<21} {r['valid_date']}") + + +def write_csv(rows, path): + with open(path, "w", newline="", encoding="utf-8") as f: + writer = csv.writer(f) + writer.writerow(["recipe", "release_date", "valid_date"]) + for r in rows: + writer.writerow([r["recipe"], r["release_date"], r["valid_date"]]) + + +def main(): + parser = argparse.ArgumentParser( + description="Report recipe release dates from SPDX 3.0.1 output" + ) + parser.add_argument( + "--deploy-dir", + required=True, + help="Path to DEPLOY_DIR_SPDX (e.g. tmp/deploy/spdx/3.0.1) or to a " + "single merged image SBOM file (e.g. " + "tmp/deploy/images//.rootfs.spdx.json)", + ) + parser.add_argument( + "--missing-only", + action="store_true", + help="Only report recipes without a valid release date", + ) + parser.add_argument( + "--csv", + help="Write the report to a CSV file instead of only printing a table", + ) + parser.add_argument( + "--sort-by-date", + action="store_true", + help="Sort output by release date instead of recipe name (missing dates last)", + ) + args = parser.parse_args() + + logging.basicConfig(format="[%(filename)s:%(lineno)d] %(message)s", level=logging.INFO) + + if os.path.isdir(args.deploy_dir): + report = build_report(args.deploy_dir) + elif os.path.isfile(args.deploy_dir): + report = build_report_from_file(args.deploy_dir) + else: + parser.error(f"--deploy-dir {args.deploy_dir} does not exist") + + total = len(report) + valid = sum(1 for r in report if r["valid_date"]) + logging.info("Recipes with SPDX static data: %d", total) + logging.info("Recipes with a valid release date: %d", valid) + logging.info("Recipes missing a release date: %d", total - valid) + + rows = filter_rows(report, args.missing_only, args.sort_by_date) + print_table(rows) + + if args.csv: + write_csv(rows, args.csv) + logging.info("CSV report written to %s", args.csv) + + return 0 + + +if __name__ == "__main__": + sys.exit(main())