Skip to main content

Requirements Specification

FieldValue
Document IDSRS-OCSA-001
Version1.0
StatusBaseline — Phase 1
Date2026-09-12
OwnerSoftware Quality Management

1. Purpose and scope​

This document specifies the requirements for OCSA: a tool that ingests an SPDX SBOM delivered by a supplier, visualises its dependency structure, and assesses copyleft risk for in-vehicle software. It covers Phase 1 as delivered. Requirements deferred to Phase 2 are listed in section 10.

Definitions​

TermDefinition
SBOMSoftware Bill of Materials; here an SPDX 2.x JSON document
ComponentA package entry in the SBOM
CopyleftLicense condition requiring derivative works to be released under the same or compatible terms
Strong copyleftGPL, AGPL, OSL, EUPL, CPAL, RPL, Sleepycat — obligations reach the combined work
Weak copyleftLGPL, MPL, EPL, CDDL, MS-RL — obligations are limited to the library or to individual files
Distributed unitThe artefact actually shipped (an executable, an ECU image); an SBOM root package
PropagationTransmission of a copyleft obligation from a component to its ancestors
TaintMarking applied to a component that transitively depends on copyleft code
purlPackage URL, from externalRefs — the stable cross-release identity of a component

2. Stakeholders and users​

StakeholderInterestUse of the tool
SQM engineer (primary user)Sign off OSS compliance per milestoneRuns analysis, reviews findings, generates supplier inquiry
Legal counselConfirm license obligationsReviews CRITICAL/HIGH findings; ratifies the tier table
Internal review boardMilestone gate decisionReceives the generated compliance report
SupplierMust answer compliance inquiriesReceives the generated inquiry letter
OEM auditorVerify due diligenceReceives compliance report + waiver register (Phase 2)

Primary user profile​

Works in automotive software quality, fluent in compliance concepts but not a software developer. Needs a tool that produces a defensible verdict with evidence, not a code library. Runs on a locked-down Windows workstation; cannot install services or use admin rights.

Consequence for design: no installation step, no server, no account. The tool must work by opening a URL or running a single command.

3. Business requirements​

IDRequirement
BR-01Every supplier-delivered SBOM shall be assessed for copyleft risk before milestone sign-off
BR-02The assessment shall be reproducible and produce identical results for identical input
BR-03Every adverse finding shall cite the evidence (dependency path) that produced it
BR-04The assessment shall be evidence that due diligence was performed, suitable for OEM audit
BR-05Supplier SBOM content shall not be transmitted to any third party
BR-06License changes between milestones shall be detected, not merely re-assessed
BR-07The tool shall be usable by a non-developer without training

4. Functional requirements​

Priority: M = must (Phase 1), S = should, C = could, W = won't (this phase). The Verified by column points at test case IDs defined in the smoke test report.

4.1 Ingestion​

IDRequirementPriAcceptance criteriaVerified by
FR-01Parse SPDX 2.2 and 2.3 JSONM42 packages and 45 relationships yield 42 components, 45 edgesTC-13
FR-02Extract per package: SPDXID, name, version, supplier, downloadLocation, copyrightText, checksums, purlMAll fields populated in the detail panelTC-17
FR-03Build a dependency graph from relationshipsMEdges oriented parent→child; documentDescribes identifies the rootTC-14
FR-04Classify each edge as static / dynamic / unknown / dev / optional linkageMSTATIC_LINK → static, DYNAMIC_LINK → dynamic, DEPENDS_ON → unknownTC-03, TC-04
FR-05Parse hasExtractedLicensingInfosMCustom LicenseRef- text available for inspectionTC-19
FR-06Ignore non-package elements (SPDXRef-Document-, SPDXRef-File-)MNo phantom components in inventoryTC-13
FR-07Report parse errors with an actionable messageMNon-SPDX JSON rejected with a targeted messageTC-30
FR-08Accept a file by drag-and-drop or file pickerMBoth paths load the documentTC-09
FR-09Load a bundled demo SBOM without a fileS"Load demo SBOM" renders the sampleTC-08

4.2 SBOM quality​

IDRequirementPriAcceptance criteriaVerified by
FR-10Check the 7 NTIA minimum elementsMSupplier, name, version, purl, relationships, author, timestamp each reported pass/failTC-20
FR-11Check 5 additional audit elementsM12 checks total, presented with countsTC-20
FR-12Present a single SBOM quality percentageMpassed / total rendered as a percentageTC-12

4.3 License classification​

IDRequirementPriAcceptance criteriaVerified by
FR-13Classify each license into 5 tiersMGPL-2.0 → CRITICAL; LGPL-2.1 → HIGH; MIT → LOW; NOASSERTION → UNKNOWNTC-01 … TC-08
FR-14Parse SPDX expressions with AND, OR, WITH and parenthesesM(MIT OR Apache-2.0) AND GPL-2.0-only → CRITICALTC-11, TC-12
FR-15AND evaluates to the worst-case tierMGPL-2.0-or-later AND LGPL-2.1-or-later → CRITICALTC-06
FR-16OR evaluates to the most favourable tier and flags the electionMLGPL-2.1 OR GPL-2.0 → HIGH + LIC-007TC-05, TC-18
FR-17Apply linking exceptions that relax copyleftMGPL-2.0+ WITH u-boot-exception-2.0 → HIGHTC-02, TC-03
FR-18An exception with no relaxation effect must not downgradeMGPL-2.0-only WITH Linux-syscall-note stays CRITICALTC-04
FR-19Scan custom LicenseRef- text for copyleft indicatorsMText mentioning the GPL raises LIC-004TC-19
FR-20Treat NOASSERTION / NONE / empty as unresolvedMRaises LIC-003TC-17
FR-21Treat a LicenseRef- with extracted text as resolved for copyleft purposesSNo LIC-003; tier remains UNKNOWN for reviewTC-16

4.4 Risk analysis​

IDRequirementPriAcceptance criteriaVerified by
FR-22Raise LIC-001 for every strong/network copyleft componentMbusybox (GPL-2.0) raises LIC-001 CRITICALTC-15
FR-23Raise LIC-003 for unresolved licensesMlegacy-codec raises LIC-003 HIGHTC-17
FR-24Raise LIC-004 for custom licenses with copyleft textMvendor-camera-sdk raises LIC-004 CRITICALTC-19
FR-25Raise LIC-005 for incompatible license pairs in one distributed unitMGPL-2.0-only + Apache-2.0 conflict reportedTC-21
FR-26Raise LIC-006 when copyleft propagates into a distributed unitMAGPL MQTT client propagates into IVI-HMI-ApplicationTC-16, TC-27
FR-27Raise LIC-007 for multi-licensed componentsMffmpeg (LGPL OR GPL) raises LIC-007TC-18
FR-28Raise LIC-008 for missing copyright textMautosar-bsw raises LIC-008 MEDIUMTC-22
FR-29Raise LIC-009 for LGPL linked without a declared relinking mechanismMQt raises LIC-009 HIGHTC-15
FR-30Mark every ancestor of a copyleft component as taintedMtelematics-agent tainted by eclipse-mosquitto-clientTC-27
FR-31Emit findings once per distributed unit, not per intermediate hopMNo duplicate LIC-006 for the same (source, root) pairTC-28
FR-32Each finding carries rule ID, severity, title, component, evidence, obligation, actionMAll seven fields present in UI and exportsTC-24
FR-33Compute a 0–100 risk score normalised by component countMScore does not monotonically increase with SBOM sizeTC-20
FR-34Derive an obligation set per component from its licenseMLGPL yields source-modified + relinkingTC-23

4.5 Visualisation​

IDRequirementPriAcceptance criteriaVerified by
FR-35Render a force-directed dependency graphMSVG with nodes and edges; pan, zoom, drag, hover-neighbourhoodTC-31 … TC-34
FR-36Colour nodes by risk tierMFive distinct colours matching the legendTC-32
FR-37Distinguish linkage by edge styleMRed = static, blue = dynamic, dashed = devTC-33
FR-38Ring components tainted by transitive copyleftMRed ring on tainted nodesTC-32
FR-39Show KPI strip: score, critical, high, blockers, tainted, qualityMSix cards renderTC-10
FR-40Show license distribution bar chartM14 bars for the demo SBOMTC-11
FR-41Filter the graph by name/license, tier and linkageMFilter reduces node and edge countsTC-35
FR-42Open a detail panel on component selectionMLicense, obligations, dependencies, dependents, taint sourcesTC-36
FR-43Filter and search findings and inventory tablesMSearch narrows rowsTC-25, TC-26
FR-44Cap graph rendering for very large SBOMsSAbove 600 nodes the cap applies and the hidden count is reportedmanual

4.6 Milestone comparison​

IDRequirementPriAcceptance criteriaVerified by
FR-45Match components across releases by stable identity (purl minus version, else name)MA version bump is a change, not add + removeTC-29
FR-46Report added and removed componentsMAGPL MQTT client added; gpsd removedTC-37, TC-38
FR-47Report license changes and flag escalationMOpenSSL relicensed; legacy-codec escalatedTC-39, TC-40
FR-48Report version changesMQt 6.5.2 → 6.5.3TC-41
FR-49Report newly introduced and removed copyleftMAGPL MQTT client listed as new copyleftTC-42
FR-50Report regressions back to unresolvedMlegacy-codec listedTC-43
FR-51Report new and closed findings with severity countsM2 new critical findingsTC-44
FR-52Report risk-score and quality deltasM+3 risk deltaTC-45
FR-53Render the diff in the UI and in markdownMDiff card + cli.mjs diff outputTC-46, TC-47

4.7 Outputs and interfaces​

IDRequirementPriAcceptance criteriaVerified by
FR-54CLI analyze with JSON / markdown / CSV outputMAll three formats producedTC-48
FR-55CLI report producing a compliance reportMVerdict, findings, obligation checklist, source-offer listTC-49, TC-50
FR-56CLI notice producing a NOTICE attribution fileMPer-component blocks with license, source, copyrightTC-51
FR-57CLI inquiry producing a supplier inquiry letterMNumbered items with response blanksTC-52
FR-58CLI gate exiting non-zero on policy violationMExit 1 with reasons; exit 0 when thresholds allowTC-53, TC-54
FR-59MCP server exposing the engine as tools over stdioM9 tools listable and callableTC-55 … TC-58
FR-60Export findings and inventory as JSON / CSV from the UIMDownloads producedTC-24
FR-61Relinking-obligation and source-offer lists in the reportMSections presentTC-50

5. Domain rules​

5.1 License tier model​

TierRankCategoriesMeaning
CRITICAL5strong-copyleft, network-copyleftDistribution triggers source disclosure of the derivative work
HIGH4weak-copyleft, file-copyleftObligations attach to the library or to modified files
UNKNOWN3.5unknown, custom-ref, unrecognised, proprietaryRelease blocker until triaged
MEDIUM3conditional, non-commercial, no-derivatives, share-alike, ambiguousRequires review
LOW2permissive, public-domainNotice and attribution only

UNKNOWN sits at a fractional rank so that every rank is unique. Because AND takes the worst case, GPL-2.0 AND NOASSERTION resolves to CRITICAL rather than masking the copyleft.

5.2 Propagation rules​

ConditionConsequenceFinding
Strong copyleft + static or undeclared linkage into a distributed unitCombined work is a derivative workLIC-006 CRITICAL
Strong copyleft + dynamic linkageSeparate work; confirm replaceabilityLIC-006 HIGH
Weak copyleft (LGPL) + static or undeclared linkageRelinking mechanism requiredLIC-009 HIGH
Weak copyleft + dynamic linkageNo finding—
Any copyleft ancestorAncestor marked tainted (graph ring)—

Conservative default: DEPENDS_ON carries no linkage information. The tool treats it as static — over-reporting is the safe direction and is disclosed as a known limitation.

5.3 Finding rule catalogue​

See Finding Rules for the full catalogue with severities and triggers.

5.4 Release gate criteria​

A distributed unit passes when all hold:

  • Zero CRITICAL findings (unless an approved waiver exists — Phase 2)
  • HIGH findings within the configured threshold
  • Zero unresolved licenses
  • SBOM quality at or above the configured minimum

6. Non-functional requirements​

IDCategoryRequirementVerification
NFR-01ConfidentialityNo SBOM content leaves the user's machine; no external network callsStatic scan: zero external URLs in frontend
NFR-02Performance42-component SBOM analysed and rendered in under 2 sObserved
NFR-03ScalabilitySBOMs up to ~1 000 nodes render; larger SBOMs down-sampled with a visible indicator600-node cap implemented
NFR-04DeterminismIdentical input always produces identical findings and scoreRepeat execution
NFR-05PortabilityRuns in any modern browser; CLI and MCP on Node.js 18+Verified on Node 22.22.2
NFR-06InstallabilityNo build step, no package installation for the web appdist/ served statically
NFR-07MaintainabilityEngine is pure functions with no I/O, shared by UI, CLI and MCPArchitecture review
NFR-08UsabilityPrimary user achieves a verdict without trainingDemo SBOM + one button
NFR-09AuditabilityEvery finding traceable to a rule ID and evidence pathFR-32
NFR-10DeployabilitySingle static folder deployable to any CDNdist/ 281 KB
NFR-11RobustnessMalformed input produces a clear message, not a crashTC-30
NFR-12AccessibilityReadable contrast in dark theme; keyboard-operable controlsManual review
NFR-13Legal safetyOutput labelled engineering triage, never a legal verdictBanner + report disclaimer

7. Data requirements​

Input: SPDX 2.2 / 2.3 JSON. See Supplier SBOM Requirements for the element-by-element table.

8. Interface requirements​

InterfaceConsumerForm
Web dashboardSQM engineerBrowser, dark theme, English
CLICI pipeline, batchnode tools/cli.mjs <command>
MCP serverAI agent / MCP clientJSON-RPC 2.0 over stdio
ExportsReview board, supplierJSON, CSV, Markdown, NOTICE text

9. Supplier SBOM requirements​

Eight requirements, to be placed in supplier quality agreements — see Supplier SBOM Requirements.

10. Requirements deferred to Phase 2​

IDRequirementRationale
P2-01Persistent storage of SBOMs and findings per (supplier, ECU, milestone)Needed for history and waivers
P2-02Approval / waiver workflow with approver and reasonAuditors ask for the waiver register
P2-03CycloneDX ingestionSome suppliers do not emit SPDX
P2-04Per-file license scanning integration (ScanCode / FOSSology)Catches mixed-license files
P2-05CVE correlation via OSV / NVD using purlSecurity use case adjacent to compliance
P2-06Executable / process boundary map per ECURemoves conservative over-reporting of conflicts
P2-07Multi-user accounts and role-based accessTeam use
P2-08PDF / DOCX report exportDistribution to review board

11. Traceability matrix​

The "Verified by" cells in section 4 are indicative pointers. The authoritative definition and numbering of test cases is the smoke test report.

Requirement groupModuleVerification
FR-01 … FR-09 (ingestion)src/spdx.js, src/app.jsTC-13, TC-14, TC-36 … TC-39, MV-13
FR-10 … FR-12 (quality)src/spdx.js (checkSbomQuality)TC-23, TC-43
FR-13 … FR-21 (classification)src/license-db.jsTC-01 … TC-12, TC-16, TC-17
FR-22 … FR-34 (risk analysis)src/risk-engine.jsTC-15 … TC-22, TC-24
FR-35 … FR-44 (visualisation)src/graph.js, src/app.jsTC-40 … TC-53
FR-45 … FR-53 (comparison)src/diff.js, src/report.jsTC-25 … TC-31, TC-54 … TC-58
FR-54 … FR-61 (interfaces)tools/cli.mjs, tools/mcp-server.mjs, src/report.jsMV-01 … MV-12
NFR-01 (confidentiality)allStatic URL scan (zero external URLs)
NFR-05, NFR-06, NFR-10scripts/build-static.mjs, deployment guideMV-13
S-1 … S-8 (supplier requirements)README, deployment guideSupplier agreement update