Bug 15843

Summary: create-spdx-2.2.bbclass broken
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Michael Opdenacker <michael.opdenacker>
Component: oe-core otherAssignee: Joshua Watt <JPEWhacker>
Status: RESOLVED NOTABUG QA Contact:
Severity: major    
Priority: Medium CC: ccasciato, JPEWhacker, michael.opdenacker, randy.macleod
Version: 5.2   
Target Milestone: 5.3   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know
Attachments:
Description Flags
create-spdx-2.2 error log none

Description Michael Opdenacker 2025-04-27 16:08:31 UTC
Created attachment 5114 [details]
create-spdx-2.2 error log

Greetings,

It seems that create-spdx-2.2.bbclass is broken now.

When I try to build "core-image-minimal" on poky master, I get this error:

Exception: FileNotFoundError: [Errno 2] No such file or directory: '/home/mike/work/yocto/poky/build/tmp/deploy/spdx/3.0.1/core2-64/packages/nettle-src.spdx.json'


Time to stop maintaining this version of the class?
Cheers
Michael
Comment 1 Randy MacLeod 2025-05-01 14:39:44 UTC
Joshua to comment on the mix of spdx2/3.
Comment 2 Joshua Watt 2025-05-01 14:44:16 UTC
Something doesn't add up here, because the error file is SPDX 3.0.1, not SPDX 2.2. I'm wondering if maybe you didn't switch from SPDX 3 to SPDX 2 properly?
Comment 3 Michael Opdenacker 2025-05-01 15:53:01 UTC
Hi Joshua

I confirm I have this issue with just this in conf/local.conf:

INHERIT += "create-spdx-2.2"

Can you try to reproduce this?
Cheers
Michael.
Comment 4 Joshua Watt 2025-05-01 18:29:04 UTC
Ya, I think you're getting both SPDX 2.2 and SPDX 3.0 at the same time (which is not supported). Try adding:

INHERIT:remove = "create-spdx"

To remove the creation of the default SPDX 3.0. I realize this is probably not ideal, but we've not really had a good proposal for how to let users choose this.
Comment 5 Michael Opdenacker 2025-05-03 12:44:17 UTC
Hi Joshua
I confirm that your suggestion works.
I'll post an update to the documentation to make users aware of this.
Thanks!
Michael.
Comment 6 Michael Opdenacker 2025-05-03 13:26:55 UTC
By the way, comparing with the current documentation, to update it.

I no longer see a toplevel <IMAGE>-<MACHINE>.spdx.json file

but only
tmp/deploy/images/<machine>/<image>-<machine>.rootfs.spdx.tar.zst
archive of indidividual JSON files.

Is this the expected output for SPDX 2.2?
Comment 7 Randy MacLeod 2026-03-12 15:21:38 UTC
See previous comments.