Verify accepts SPDX 2.3 documents that violate normative MUST rules (document SPDXID, unique SPDXIDs, documentNamespace URI)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 55/100
Línea de trabajo
Comienza con la ruta de validación del comando Verify en tools-java y reproduce los dos documentos JSON del issue utilizando la versión de Java. Compara las comprobaciones de SPDXRef-DOCUMENT, los SPDXIDs duplicados y documentNamespace absoluto con los requisitos de SPDX 2.3 y los resultados del validador de Python. La tarea está terminada cuando Verify informe de que ambos documentos no son válidos por las infracciones indicadas.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hi @goneall :) Hope you are doing well and having fun on all your adventures!
I came across some validation discrepancies (errors?) when comparing validation output between spdx-tools pyhon, java and the plain text spec. I am seeing the Verify command reports documents as "This SPDX Document is valid." even when they violate several normative MUST requirements of the SPDX 2.3 spec. The equivalent Python spdx-tools validator flags the same documents as invalid, so the two reference implementations disagree.
Specifically, Verify with the latest java release does not seem to enforce:
- The document's SPDXID MUST be SPDXRef-DOCUMENT (§6.3)
- Element ID uniqueness (i.e. the document identifier collides with a package identifier and is not reported) (§7.2)
- documentNamespace MUST be an absolute URI (RFC-3986). (§6.5)
Reproduction 1 — non-URI documentNamespace (§6.5):
{"spdxVersion":"SPDX-2.3","dataLicense":"CC0-1.0","SPDXID":"SPDXRef-DOCUMENT","name":"x","documentNamespace":"not-a-uri","creationInfo":{"creators":["Tool: t"],"created":"1970-01-01T00:00:00Z"},"packages":[{"name":"a","SPDXID":"SPDXRef-a","downloadLocation":"NOASSERTION","filesAnalyzed":false}],"relationships":[{"spdxElementId":"SPDXRef-DOCUMENT","relationshipType":"DESCRIBES","relatedSpdxElement":"SPDXRef-a"}]}
$ java -jar tools-java-2.0.7-jar-with-dependencies.jar Verify b-namespace.spdx.json
This SPDX Document is valid.
Reproduction 2 — document SPDXID is not SPDXRef-DOCUMENT and duplicates a package ID (§6.3 + uniqueness):
{"spdxVersion":"SPDX-2.3","dataLicense":"CC0-1.0","SPDXID":"SPDXRef-a","name":"x","documentNamespace":"https://example.com/C","creationInfo":{"creators":["Tool: t"],"created":"1970-01-01T00:00:00Z"},"packages":[{"name":"a","SPDXID":"SPDXRef-a","downloadLocation":"NOASSERTION","filesAnalyzed":false}],"relationships":[{"spdxElementId":"SPDXRef-a","relationshipType":"DESCRIBES","relatedSpdxElement":"SPDXRef-a"}]}
$ java -jar tools-java-2.0.7-jar-with-dependencies.jar Verify c-dup-doc-pkg.spdx.json
This SPDX Document is valid.
Both documents should be reported as invalid. The 2.3 spec requires:
§6.3 SPDX identifier field — the document SPDXID value MUST be SPDXRef-DOCUMENT: https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#63-spdx-identifier-field
§6.5 SPDX document namespace — MUST be a unique absolute URI with no fragment: https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#65-spdx-document-namespace-field
§7.2 / element identifiers — each SPDXID MUST be unique within the document: https://spdx.github.io/spdx-spec/v2.3/package-information/#72-package-spdx-identifier-field
Running the python tools on the same files seems to yield more expected results:
b-namespace.spdx.json -> INVALID: document_namespace must be a valid URI specified in RFC-3986 and must contain no fragment (#), but is: not-a-uri
c-dup-doc-pkg.spdx.json -> INVALID: spdx_id must be SPDXRef-DOCUMENT, but is: SPDXRef-a
every spdx_id must be unique within the document, but found duplicates: ['SPDXRef-a']
It's been a while so totally recognize this could be user error but wanted to open this here in case others run into it.
- Lenguaje dominante
- Java
- Estrellas
- 101
- Forks
- 46
- Merge medio
- 9 h 43 min
- PR fusionados (30 d)
- 8
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de spdx/tools-java
-
Release 2.0.8 Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 20/100
spdx/tools-java#313 · 1 reacción ·
-
spdx-2.x spdx-3.x
Dificultad 3/5 1-2 días Aptitud para principiantes 58/100
spdx/tools-java#290 · 2 comentarios ·
-
Warning when validating Abiertovalidation
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
spdx/tools-java#287 · 1 comentario · 1 reacción ·
-
Case-Sensitive IRI as spdxId Abiertoquestion test
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
spdx/tools-java#283 · 14 comentarios · 1 reacción ·
-
Validate Custom JSON-LD Context Abiertoenhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
spdx/tools-java#263 · 2 comentarios · 1 reacción ·
Todos los issues de spdx/tools-java
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
infinispan/infinispan#18150 ·
-
area/frontend
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
untriaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
opensearch-project/k-NN#3597 ·
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100