Repository navigation
Conversation
Collaborator
|
Should we delete this folder https://github.com/zephyrproject-rtos/hal_nxp/blob/master/zephyr/blobs/license/ ? |
mmahadevan108
requested review from
ZhaoxiangJin,
axelnxp,
iuliana-prodan,
mmahadevan108 and
zejiang0jason
September 2, 2026 19:06
Member
Author
Yeah like I said "it would probably make sense to also update the license-path: entries in zephyr/module.yml so they point to the new REUSE-compliant location(s) under LICENSES/". I can update the PR if you folks would like |
Collaborator
|
Hi @kartben , after this change, do we still need keep the |
Add REUSE Specification 3.3 (https://reuse.software/spec-3.3/) compliance infrastructure so west-fetched binary blobs have machine-readable license information that can be accurately reflected in an SBOM (Software Bill of Materials). Binary blobs cannot carry in-file SPDX tags. Previously their licenses were described only via license-path in zephyr/module.yml: - LicenseRef-NXP-Software-License: libcsi, rw61x, nw61x, IW416, IW610, imx-boot-firmware, and IEEE 802.15.4 combo images/libs - LicenseRef-NXP-Online-Code-Hosting: mcxw23 BLE controller libs and mcxw70/71/72 hosted BLE controller images - BSD-3-Clause: neutron/** Without REUSE annotations, SBOM generators such as 'west spdx' report NOASSERTION for those files. Changes: - Add REUSE.toml with path-glob annotations mapping each blob tree to its SPDX license expression, per REUSE spec §3.3. - Add LICENSES/ directory with canonical full-text copies of: * Apache-2.0.txt * BSD-3-Clause.txt * LicenseRef-NXP-Software-License.txt (copied from zephyr/blobs/license/LA_OPT_NXP_Software_License.txt) * LicenseRef-NXP-Online-Code-Hosting.txt (copied from zephyr/blobs/license/LA_OPT_NXP_Online_Code_Hosting.txt) - Point the license-path entries in zephyr/module.yml at LICENSES/ and drop the now-redundant zephyr/blobs/license/ copies. No source files are modified; upstream NXP content is unchanged. Assisted-by: Cursor:grok-4.6 Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
kartben
force-pushed
the
reuse-toml-spdx-sbom
branch
from
October 1, 2026 16:26
daec5bd to
4bebc29
Compare
kartben
marked this pull request as ready for review
October 1, 2026 20:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add REUSE Specification 3.3 compliance infrastructure so west-fetched binary blobs have machine-readable license information that can be accurately reflected in an SBOM (Software Bill of Materials).
Binary blobs cannot carry in-file SPDX tags. Previously their licenses were described only via
license-pathinzephyr/module.yml:LicenseRef-NXP-Software-License:libcsi,rw61x,nw61x,IW416,IW610,imx-boot-firmware, and IEEE 802.15.4 combo images/libsLicenseRef-NXP-Online-Code-Hosting:mcxw23BLE controller libs,mcxw70/mcxw71/mcxw72hosted BLE controller images andmcxw71/mcxw72EdgeLock S200 firmwareBSD-3-Clause:neutron/**and themcxl255ADVC librariesWithout REUSE annotations, SBOM generators such as
west spdxreportNOASSERTIONfor those files.Changes:
REUSE.tomlwith path-glob annotations mapping each blob tree to its SPDX license expression, per REUSE spec §3.3.LICENSES/directory with canonical full-text copies of:Apache-2.0.txtBSD-3-Clause.txtLicenseRef-NXP-Software-License.txt(copied fromzephyr/blobs/license/LA_OPT_NXP_Software_License.txt)LicenseRef-NXP-Online-Code-Hosting.txt(copied fromzephyr/blobs/license/LA_OPT_NXP_Online_Code_Hosting.txt)license-pathentries inzephyr/module.ymlatLICENSES/and drop the now-redundantzephyr/blobs/license/copies.Test plan
zephyr/module.ymlmatches aREUSE.tomlannotation whose license is the one itslicense-pathpoints tolicense-pathresolves to an existing file (scripts/zephyr_module.pyblob parsing)LICENSES/contains the full text for every SPDX id referenced inREUSE.tomlwest spdx --spdx-version 3.0reports the annotated license for linked blobswest build -b frdm_rw612 samples/net/wifi/shell -- -DCONFIG_BUILD_OUTPUT_META=y -DCONFIG_NXP_WIFI_CSI_AMI=yandwest spdx -d <build> --spdx-version 3.0:zephyr/blobs/libcsi/cm33/libcsi.ais reported asLicenseRef-NXP-Software-License, copyright NXP, with themodule.ymldescriptionrw61x_sb_wifi_a2_compressed.bin) is embedded through a custom command, sowest spdxleaves it out of the SBOM for now: it only records blobs linked as prebuilt libraries straight from the module. That is awest spdxlimitation, independent of this PR..jsonldfiles in https://kartben.github.io/spdx3_viz/ and confirm the blobFileentry (screenshot below)