I'm testing create-spdx.bbclass to create SPDX documents for various recipes in Poky. The written *.spdx.json files contain snippets like "externalDocumentRefs": [ { "checksum": { "algorithm": "SHA1", "checksumValue": "7b15395b164ee6509349af0777719975a960c11a" }, "externalDocumentId": "DocumentRef-dependency-recipe-gettext-minimal-native", "spdxDocument": "http://spdx.org/spdxdoc/recipe-gettext-minimal-native-d0a27f93-c2cb-5d69-ab6b-b5b2d7da1769" }, There are two issues I see with the "spdxDocument" entry: 1. While as per https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#6.5 "spdxDocument" may indeed point to a non-existing website (and just be used as a unique ID), it should start with "https://spdx.org/spdxdocs/" in that case (note "http" -> "https" and "spdxdoc" -> "spdxdocs"). 2. But ideally, "spdxDocument" should directly point to the location where the document can be retrieved from. In this case, it should be a local file:// URI. That would avoid any indirections when resolving the referred document.
Hey Sébastian, For your first point, I think you can change the name space prefix "http" -> "https" and "spdxdoc" -> "spdxdocs") using the classe variable: SPDX_NAMESPACE_PREFIX Which is set by default to "https://spdx.org/spdxdocs", I will make a patch to correct this. For the second point, the problem is if the user wants to publish this, it need to modify all the files. Instead of this it is better to set the variable SPDX_NAMESPACE_PREFIX and put the future location of the file.
> I think you can change the name space prefix [..] using the classe variable: SPDX_NAMESPACE_PREFIX Thanks for pointing this out. I assume this needs to go to the same .conf file where I also define SPDX_ARCHIVE_PACKAGED et al? Also, should that variable be documented at https://docs.yoctoproject.org/ref-manual/variables.html#term-S? > Which is set by default to "https://spdx.org/spdxdocs", I will make a patch to correct this. I believe you mean the default is "http://spdx.org/spdxdoc". Anyway, thanks for making a patch. > For the second point, the problem is if the user wants to publish this, it need to modify all the files. Makes sense. However, is there an efficient way to look up the referred document now without dealing with SPDX_NAMESPACE_PREFIX?
(In reply to Sebastian Schuberth from comment #2) > > I think you can change the name space prefix [..] using the classe variable: SPDX_NAMESPACE_PREFIX > > Thanks for pointing this out. I assume this needs to go to the same .conf > file where I also define SPDX_ARCHIVE_PACKAGED et al? Yes, it can to the same .conf file, or to your distro if you have one. > Also, should that variable be documented at > https://docs.yoctoproject.org/ref-manual/variables.html#term-S? Yes, I made a patch for this as well > > Which is set by default to "https://spdx.org/spdxdocs", I will make a patch to correct this. > > I believe you mean the default is "http://spdx.org/spdxdoc". Anyway, thanks > for making a patch. Exactly > > For the second point, the problem is if the user wants to publish this, it need to modify all the files. > > Makes sense. However, is there an efficient way to look up the referred > document now without dealing with SPDX_NAMESPACE_PREFIX? I really don't know, I think the way it was made, is not really bad, every user has the possibility to change it. And if you expect to have a fixed link, the problem is these file exist in many places, deploydir + workdir ....
Per the spec https://spdx.github.io/spdx-spec/v2.2.2/document-creation-information/#652-intent it should be "http://spdx.org/spdxdocs" (note the added "s"). The document identifier is a little weird in that it's really "just an Identifier that _happens_ to look like a URL", but also does double duty as an actual location where the document can be downloaded. Since the spec says http://, I'd prefer to keep that in case anyone is trying to match that URL prefix as a means of determining if the document can be downloaded or not. Of course, if you are publishing your own documents, feel free to set SPDX_NAMESPACE_PREFIX with "https://"
> Since the spec says http:// Well, as noted in my previous comment, that depends on the version of the spec. SPDX 2.3 has "https" (again see https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#6.5). Which version of the SPDX spec does BitBake officially implement? Unfortunately, the written out documents do not include the SPDX version field (https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#61-spdx-version-field). Could this be fixed as well in this context?
(In reply to Sebastian Schuberth from comment #5) > > Since the spec says http:// > > Well, as noted in my previous comment, that depends on the version of the > spec. SPDX 2.3 has "https" (again see > https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#6.5). Ya, that is fair, see below > > Which version of the SPDX spec does BitBake officially implement? We only (current) implement SPDX 2.2 because it is the ISO standard version. We've talked about implementing SPDX 2.3, but given limited resources we're currently focusing on SPDX 3.0 instead. > > Unfortunately, the written out documents do not include the SPDX version > field > (https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#61- > spdx-version-field). Could this be fixed as well in this context? Ya, this is part of the 2.2 spec so we should definitely add that
Hey Joshua, The comment that you made in my MR is oudated, I made an other MR and it got integrated to master-next. The other one is for documentation, I do not know if it is already accepted. If you think, that it should stay as it is now, please, remove my commit from master-next. and my commit for docs should be corrected.
The patch to fix SPDX_NAMESPACE_PREFIX is submitted. After careful reading of the documentation and SPDX 2.2 JSON schema and Ontology, I think that the SPDX Version is already correctly encoded in our documents as "spdxVersion": "SPDX-2.2". The JSON schema and Ontology use "spdxVersion" as the field name, and I suspect that "specVersion" in the documentation example is incorrect.
> The patch to fix SPDX_NAMESPACE_PREFIX is submitted. Would you have a link to the change? I'm wondering as https://docs.yoctoproject.org/ref-manual/variables.html#term-SPDX_NAMESPACE_PREFIX still says "It is set by default to http://spdx.org/spdxdoc", so still has the original default value without the "http" -> "https" and "spdxdoc" -> "spdxdocs" fixes.
https://git.yoctoproject.org/poky/commit/?id=8d79ca14786c9dcdaaaf3b592c481d36fd2767b5
Thanks Joshua for the patch. However, I believe also "http" needs to be changed to "https" to be conform with the spec.
http:// is the documented URL for SPDX 2.2, we do not support SPDX 2.3
Accidentally reopend
Ah, you're right. Sorry for that!