mirror of
https://git.yoctoproject.org/poky
synced 2026-09-12 06:49:32 +02:00
spdx: add option to include only compiled sources
When SPDX_INCLUDE_COMPILED_SOURCES is enabled, only include the source code files that are used during compilation. It uses debugsource information generated during do_package. This enables an external tool to use the SPDX information to disregard vulnerabilities that are not compiled. As example, when used with the default config with linux-yocto, the spdx size is reduced from 156MB to 61MB. Tested with bitbake world on oe-core. CC: Quentin Schulz <quentin.schulz@cherry.de> CC: Joshua Watt <JPEWhacker@gmail.com> CC: Peter Marko <peter.marko@siemens.com> (From OE-Core rev: c6a2f1fca76fae4c3ea471a0c63d0b453beea968) Signed-off-by: Daniel Turull <daniel.turull@ericsson.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
5132c991e6
commit
33fd6f6e82
@@ -137,6 +137,11 @@ def add_package_files(d, doc, spdx_pkg, topdir, get_spdxid, get_types, *, archiv
|
||||
spdx_files = []
|
||||
|
||||
file_counter = 1
|
||||
|
||||
check_compiled_sources = d.getVar("SPDX_INCLUDE_COMPILED_SOURCES") == "1"
|
||||
if check_compiled_sources:
|
||||
compiled_sources, types = oe.spdx_common.get_compiled_sources(d)
|
||||
bb.debug(1, f"Total compiled files: {len(compiled_sources)}")
|
||||
for subdir, dirs, files in os.walk(topdir):
|
||||
dirs[:] = [d for d in dirs if d not in ignore_dirs]
|
||||
if subdir == str(topdir):
|
||||
@@ -147,6 +152,10 @@ def add_package_files(d, doc, spdx_pkg, topdir, get_spdxid, get_types, *, archiv
|
||||
filename = str(filepath.relative_to(topdir))
|
||||
|
||||
if not filepath.is_symlink() and filepath.is_file():
|
||||
# Check if file is compiled
|
||||
if check_compiled_sources:
|
||||
if not oe.spdx_common.is_compiled_source(filename, compiled_sources, types):
|
||||
continue
|
||||
spdx_file = oe.spdx.SPDXFile()
|
||||
spdx_file.SPDXID = get_spdxid(file_counter)
|
||||
for t in get_types(filepath):
|
||||
|
||||
Reference in New Issue
Block a user