Skip to content

hal: nxp: add REUSE.toml and LICENSES/ - #806

Open
kartben wants to merge 1 commit into
zephyrproject-rtos:masterfrom
kartben:reuse-toml-spdx-sbom
Open

kartben wants to merge 1 commit into
zephyrproject-rtos:masterfrom
kartben:reuse-toml-spdx-sbom

Conversation

@kartben

@kartben kartben commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Add REUSE Specification 3.3 compliance infrastructure so west-fetched binary blobs have machine-readable license information that can be accurately reflected in an SBOM (Software Bill of Materials).

Binary blobs cannot carry in-file SPDX tags. Previously their licenses were described only via license-path in zephyr/module.yml:

  • LicenseRef-NXP-Software-License: libcsi, rw61x, nw61x, IW416, IW610, imx-boot-firmware, and IEEE 802.15.4 combo images/libs
  • LicenseRef-NXP-Online-Code-Hosting: mcxw23 BLE controller libs, mcxw70/mcxw71/mcxw72 hosted BLE controller images and mcxw71/mcxw72 EdgeLock S200 firmware
  • BSD-3-Clause: neutron/** and the mcxl255 ADVC libraries

Without REUSE annotations, SBOM generators such as west spdx report NOASSERTION for those files.

Changes:

  • Add REUSE.toml with path-glob annotations mapping each blob tree to its SPDX license expression, per REUSE spec §3.3.
  • Add LICENSES/ directory with canonical full-text copies of:
    • Apache-2.0.txt
    • BSD-3-Clause.txt
    • LicenseRef-NXP-Software-License.txt (copied from zephyr/blobs/license/LA_OPT_NXP_Software_License.txt)
    • LicenseRef-NXP-Online-Code-Hosting.txt (copied from zephyr/blobs/license/LA_OPT_NXP_Online_Code_Hosting.txt)
  • Point the license-path entries in zephyr/module.yml at LICENSES/ and drop the now-redundant zephyr/blobs/license/ copies.

Test plan

  • Every blob in zephyr/module.yml matches a REUSE.toml annotation whose license is the one its license-path points to
  • Every blob license-path resolves to an existing file (scripts/zephyr_module.py blob parsing)
  • LICENSES/ contains the full text for every SPDX id referenced in REUSE.toml
  • west spdx --spdx-version 3.0 reports the annotated license for linked blobs
    • west build -b frdm_rw612 samples/net/wifi/shell -- -DCONFIG_BUILD_OUTPUT_META=y -DCONFIG_NXP_WIFI_CSI_AMI=y and west spdx -d <build> --spdx-version 3.0: zephyr/blobs/libcsi/cm33/libcsi.a is reported as LicenseRef-NXP-Software-License, copyright NXP, with the module.yml description
    • The Wi-Fi firmware image (rw61x_sb_wifi_a2_compressed.bin) is embedded through a custom command, so west spdx leaves it out of the SBOM for now: it only records blobs linked as prebuilt libraries straight from the module. That is a west spdx limitation, independent of this PR.
  • Load the .jsonld files in https://kartben.github.io/spdx3_viz/ and confirm the blob File entry (screenshot below)
libcsi.a in spdx3_viz: zephyr/blobs/libcsi/cm33/libcsi.a with concluded and declared license LicenseRef-NXP-Software-License

@mmahadevan108

Copy link
Copy Markdown
Collaborator

@kartben

kartben commented Sep 2, 2026

Copy link
Copy Markdown
Member Author

Should we delete this folder https://github.com/zephyrproject-rtos/hal_nxp/blob/master/zephyr/blobs/license/ ?

Yeah like I said "it would probably make sense to also update the license-path: entries in zephyr/module.yml so they point to the new REUSE-compliant location(s) under LICENSES/". I can update the PR if you folks would like

@zejiang0jason

Copy link
Copy Markdown
Collaborator

Hi @kartben , after this change, do we still need keep the license-path in module.yml in the future? Such information is already in REUSE.toml. thanks.

Add REUSE Specification 3.3 (https://reuse.software/spec-3.3/)
compliance infrastructure so west-fetched binary blobs have
machine-readable license information that can be accurately
reflected in an SBOM (Software Bill of Materials).

Binary blobs cannot carry in-file SPDX tags. Previously their
licenses were described only via license-path in zephyr/module.yml:
- LicenseRef-NXP-Software-License: libcsi, rw61x, nw61x, IW416,
  IW610, imx-boot-firmware, and IEEE 802.15.4 combo images/libs
- LicenseRef-NXP-Online-Code-Hosting: mcxw23 BLE controller libs
  and mcxw70/71/72 hosted BLE controller images
- BSD-3-Clause: neutron/**

Without REUSE annotations, SBOM generators such as 'west spdx'
report NOASSERTION for those files.

Changes:
- Add REUSE.toml with path-glob annotations mapping each blob
  tree to its SPDX license expression, per REUSE spec §3.3.
- Add LICENSES/ directory with canonical full-text copies of:
  * Apache-2.0.txt
  * BSD-3-Clause.txt
  * LicenseRef-NXP-Software-License.txt (copied from
    zephyr/blobs/license/LA_OPT_NXP_Software_License.txt)
  * LicenseRef-NXP-Online-Code-Hosting.txt (copied from
    zephyr/blobs/license/LA_OPT_NXP_Online_Code_Hosting.txt)
- Point the license-path entries in zephyr/module.yml at
  LICENSES/ and drop the now-redundant zephyr/blobs/license/
  copies.

No source files are modified; upstream NXP content is unchanged.

Assisted-by: Cursor:grok-4.6
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants