Verify accepts SPDX 2.3 documents that violate normative MUST rules (document SPDXID, unique SPDXIDs, documentNamespace URI)
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
Research direction
Start with the Verify command's validation path in tools-java and reproduce the two JSON documents from the issue using the Java release. Compare the checks for SPDXRef-DOCUMENT, duplicate SPDXIDs, and absolute documentNamespace against the SPDX 2.3 requirements and Python validator results. Done means Verify reports both documents as invalid for the stated violations.
Written by the indexing model from the issue text.
Description
Hi @goneall :) Hope you are doing well and having fun on all your adventures!
I came across some validation discrepancies (errors?) when comparing validation output between spdx-tools pyhon, java and the plain text spec. I am seeing the Verify command reports documents as "This SPDX Document is valid." even when they violate several normative MUST requirements of the SPDX 2.3 spec. The equivalent Python spdx-tools validator flags the same documents as invalid, so the two reference implementations disagree.
Specifically, Verify with the latest java release does not seem to enforce:
- The document's SPDXID MUST be SPDXRef-DOCUMENT (§6.3)
- Element ID uniqueness (i.e. the document identifier collides with a package identifier and is not reported) (§7.2)
- documentNamespace MUST be an absolute URI (RFC-3986). (§6.5)
Reproduction 1 — non-URI documentNamespace (§6.5):
{"spdxVersion":"SPDX-2.3","dataLicense":"CC0-1.0","SPDXID":"SPDXRef-DOCUMENT","name":"x","documentNamespace":"not-a-uri","creationInfo":{"creators":["Tool: t"],"created":"1970-01-01T00:00:00Z"},"packages":[{"name":"a","SPDXID":"SPDXRef-a","downloadLocation":"NOASSERTION","filesAnalyzed":false}],"relationships":[{"spdxElementId":"SPDXRef-DOCUMENT","relationshipType":"DESCRIBES","relatedSpdxElement":"SPDXRef-a"}]}
$ java -jar tools-java-2.0.7-jar-with-dependencies.jar Verify b-namespace.spdx.json
This SPDX Document is valid.
Reproduction 2 — document SPDXID is not SPDXRef-DOCUMENT and duplicates a package ID (§6.3 + uniqueness):
{"spdxVersion":"SPDX-2.3","dataLicense":"CC0-1.0","SPDXID":"SPDXRef-a","name":"x","documentNamespace":"https://example.com/C","creationInfo":{"creators":["Tool: t"],"created":"1970-01-01T00:00:00Z"},"packages":[{"name":"a","SPDXID":"SPDXRef-a","downloadLocation":"NOASSERTION","filesAnalyzed":false}],"relationships":[{"spdxElementId":"SPDXRef-a","relationshipType":"DESCRIBES","relatedSpdxElement":"SPDXRef-a"}]}
$ java -jar tools-java-2.0.7-jar-with-dependencies.jar Verify c-dup-doc-pkg.spdx.json
This SPDX Document is valid.
Both documents should be reported as invalid. The 2.3 spec requires:
§6.3 SPDX identifier field — the document SPDXID value MUST be SPDXRef-DOCUMENT: https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#63-spdx-identifier-field
§6.5 SPDX document namespace — MUST be a unique absolute URI with no fragment: https://spdx.github.io/spdx-spec/v2.3/document-creation-information/#65-spdx-document-namespace-field
§7.2 / element identifiers — each SPDXID MUST be unique within the document: https://spdx.github.io/spdx-spec/v2.3/package-information/#72-package-spdx-identifier-field
Running the python tools on the same files seems to yield more expected results:
b-namespace.spdx.json -> INVALID: document_namespace must be a valid URI specified in RFC-3986 and must contain no fragment (#), but is: not-a-uri
c-dup-doc-pkg.spdx.json -> INVALID: spdx_id must be SPDXRef-DOCUMENT, but is: SPDXRef-a
every spdx_id must be unique within the document, but found duplicates: ['SPDXRef-a']
It's been a while so totally recognize this could be user error but wanted to open this here in case others run into it.
- Dominant language
- Java
- Stars
- 101
- Forks
- 46
- Avg merge
- 9h 43m
- Merged PRs (30d)
- 8
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from spdx/tools-java
-
Release 2.0.8 Open
Difficulty 4/5 3-5 days Newbie friendliness 20/100
spdx/tools-java#313 · 1 reaction ·
-
spdx-2.x spdx-3.x
Difficulty 3/5 1-2 days Newbie friendliness 58/100
spdx/tools-java#290 · 2 comments ·
-
validation
Difficulty 3/5 1-2 days Newbie friendliness 48/100
spdx/tools-java#287 · 1 comment · 1 reaction ·
-
question test
Difficulty 3/5 1-2 days Newbie friendliness 48/100
spdx/tools-java#283 · 14 comments · 1 reaction ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 45/100
spdx/tools-java#263 · 2 comments · 1 reaction ·
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
elastic/gradle-plugins#157 ·
-
enhancement Tools
Difficulty 1/5 Under an hour Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
apache/rocketmq-dashboard#5008 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
DETECT_PARAMETER_NAMES=false silently disables @ConstructorProperties-based Creator detection too Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
FasterXML/jackson-databind#6229 ·