Bug 16408 - spdx-3.0 variables missing from related task vardeps which result in those variables changing being missed when using sstate-cache.
Summary: spdx-3.0 variables missing from related task vardeps which result in those va...
Status: NEW
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: oe-core other (show other bugs)
Version: 6.1
Hardware: x86 x86_64
: Medium+ normal
Target Milestone: 6.1 M3
Assignee: Joshua Watt
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2026-08-25 21:36 UTC by Michał Iwanicki
Modified: 2026-08-27 14:40 UTC (History)
1 user (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Iwanicki 2026-08-25 21:36:00 UTC
Changing SPDX related variables, e.g. SPDX_IMAGE_SUPPLIER_name isn't detected and sbom isn't regenerated. This is most likely due to those variables missing from e.g. task vardeps. I posted a patch that tried to fix this https://lists.openembedded.org/g/openembedded-core/message/244004 but it only fixed what I noticed which is likely only very small subsection of missing vardeps. Not only that but the patch is wrong due to findings described in https://bugzilla.yoctoproject.org/show_bug.cgi?id=16407.

The issue is most likely with:

- <PREFIX>_name
- <PREFIX>_type
- <PREFIX>_import
- <PREFIX>_comment
- <PREFIX>_id_* (all of the options in oe.spdx30.ExternalIdentifierType.NAMED_INDIVIDUALS)
- <PREFIX>_ref

Where prefix can be either:

- SPDX_IMAGE_SUPPLIER
- SPDX_PACKAGE_SUPPLIER
- SPDX_SDK_SUPPLIER
- SPDX_INVOKED_BY
- SPDX_ON_BEHALF_OF

And possibly SPDX_AUTHORS and it's combinations like SPDX_AUTHORS_<AUTHOR>_name.

<PREFIX>_ref refers to another variable that should be used for e.g. _name, _type, so if:

SPDX_SDK_SUPPLIER_ref = "SPDX_IMAGE_SUPPLIER"

then task that generates SBOM for SDK should depend on SPDX_IMAGE_SUPPLIER_* variables.

I verified the issue with SPDX_IMAGE_SUPPLIER_name/_type and SPDX_PACKAGE_SUPPLIER_name/_type on the newest master and wrynose release.

Reproduction:

- Build image with e.g. 

  ```
  SPDX_IMAGE_SUPPLIER_name = "AAAA"
  SPDX_IMAGE_SUPPLIER_type = "organization"
  SPDX_PACKAGE_SUPPLIER_name = "BBBB"
  SPDX_PACKAGE_SUPPLIER_type = "organization"
  ```

  set in local.conf

- Rebuild the image after changing SPDX_IMAGE_SUPPLIER_name/SPDX_PACKAGE_SUPPLIER_name to something different - make sure to use sstate-cache

Actual Results:

The SPDX/SBOM tasks didn't run again and generated image SBOM is the same and doesn't contain new supplier name

Expected result:

- SPDX/SBOM generation tasks run again
- image SBOM is regenerated and contains changed supplier name

Build Date & Hardware:

Last one was: 24.08.2026 in kas-container 4.2 (Debian 12)

layer commits used:
- bitbake: d1886335f0d7fa86e87c6001d5be306a8e90586b
- openembedded-core: 35a2c6ed7987763dadbe45ad86095e1aee1c7314 
- meta-yocto: 9c6cf36c3511b94957aba04002d98bec665e9f1e