fix(build): repair autotools gen-sbom discovery in sbom.am - #6
Open
MarkAtwood wants to merge 2 commits into
Open
fix(build): repair autotools gen-sbom discovery in sbom.am#6MarkAtwood wants to merge 2 commits into
MarkAtwood wants to merge 2 commits into
Conversation
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
$(dir $(lastword $(MAKEFILE_LIST))) cannot locate this fragment: Automake's include is textual, so at make time MAKEFILE_LIST is the top Makefile and SBOM_GEN resolved to <builddir>/gen-sbom, breaking `make sbom` unless every product overrode SBOM_GEN. Name the vendored directory explicitly (SBOM_VENDOR_DIR, default $(srcdir)/tools/sbom) and restore the WOLFSSL_DIR fallback for the wolfSSH-style route. Empty when neither exists so the recipe's `test -f "$(SBOM_GEN)"` fails with a clear error. Fixes #3 Fixes #3
There was a problem hiding this comment.
Pull request overview
This PR fixes autotools SBOM generation (make sbom) by replacing the unreliable $(MAKEFILE_LIST)-based gen-sbom discovery (which doesn’t work with Automake’s textual include) with an explicit vendored tooling directory and reinstating the WOLFSSL_DIR fallback path for wolfSSL-based consumers.
Changes:
- Replace
SBOM_AM_DIR/$(MAKEFILE_LIST)self-location logic with an explicitSBOM_VENDOR_DIR(default$(srcdir)/tools/sbom). - Update
SBOM_GENdefault resolution to prefer the vendoredgen-sbom, otherwise fall back to$(WOLFSSL_DIR)/scripts/gen-sbom. - Expand in-file documentation to explain why self-discovery is not possible under Automake include semantics.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
sameehj
force-pushed
the
master
branch
4 times, most recently
from
July 24, 2026 14:09
3ab77f9 to
9bdf5b7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3.
$(MAKEFILE_LIST)can't locate the fragment under Automake's textualinclude, soSBOM_GENresolved to<builddir>/gen-sbomandmake sbombroke. Replaced with an explicitSBOM_VENDOR_DIR(default$(srcdir)/tools/sbom) and restored theWOLFSSL_DIRfallback. Independent of the other review PRs.