Bug 16408

Summary: spdx-3.0 variables missing from related task vardeps which result in those variables changing being missed when using sstate-cache.
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Michał Iwanicki <iwanicki92>
Component: oe-core otherAssignee: Joshua Watt <JPEWhacker>
Status: NEW --- QA Contact:
Severity: normal    
Priority: Medium+ CC: randy.macleod
Version: 6.1   
Target Milestone: 6.1 M3   
Hardware: x86   
OS: x86_64   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Michał Iwanicki 2026-08-25 21:36:00 UTC
Changing SPDX related variables, e.g. SPDX_IMAGE_SUPPLIER_name isn't detected and sbom isn't regenerated. This is most likely due to those variables missing from e.g. task vardeps. I posted a patch that tried to fix this https://lists.openembedded.org/g/openembedded-core/message/244004 but it only fixed what I noticed which is likely only very small subsection of missing vardeps. Not only that but the patch is wrong due to findings described in https://bugzilla.yoctoproject.org/show_bug.cgi?id=16407.

The issue is most likely with:

- <PREFIX>_name
- <PREFIX>_type
- <PREFIX>_import
- <PREFIX>_comment
- <PREFIX>_id_* (all of the options in oe.spdx30.ExternalIdentifierType.NAMED_INDIVIDUALS)
- <PREFIX>_ref

Where prefix can be either:

- SPDX_IMAGE_SUPPLIER
- SPDX_PACKAGE_SUPPLIER
- SPDX_SDK_SUPPLIER
- SPDX_INVOKED_BY
- SPDX_ON_BEHALF_OF

And possibly SPDX_AUTHORS and it's combinations like SPDX_AUTHORS_<AUTHOR>_name.

<PREFIX>_ref refers to another variable that should be used for e.g. _name, _type, so if:

SPDX_SDK_SUPPLIER_ref = "SPDX_IMAGE_SUPPLIER"

then task that generates SBOM for SDK should depend on SPDX_IMAGE_SUPPLIER_* variables.

I verified the issue with SPDX_IMAGE_SUPPLIER_name/_type and SPDX_PACKAGE_SUPPLIER_name/_type on the newest master and wrynose release.

Reproduction:

- Build image with e.g. 

  ```
  SPDX_IMAGE_SUPPLIER_name = "AAAA"
  SPDX_IMAGE_SUPPLIER_type = "organization"
  SPDX_PACKAGE_SUPPLIER_name = "BBBB"
  SPDX_PACKAGE_SUPPLIER_type = "organization"
  ```

  set in local.conf

- Rebuild the image after changing SPDX_IMAGE_SUPPLIER_name/SPDX_PACKAGE_SUPPLIER_name to something different - make sure to use sstate-cache

Actual Results:

The SPDX/SBOM tasks didn't run again and generated image SBOM is the same and doesn't contain new supplier name

Expected result:

- SPDX/SBOM generation tasks run again
- image SBOM is regenerated and contains changed supplier name

Build Date & Hardware:

Last one was: 24.08.2026 in kas-container 4.2 (Debian 12)

layer commits used:
- bitbake: d1886335f0d7fa86e87c6001d5be306a8e90586b
- openembedded-core: 35a2c6ed7987763dadbe45ad86095e1aee1c7314 
- meta-yocto: 9c6cf36c3511b94957aba04002d98bec665e9f1e