Re: [RFC cip-dev][isar-cip-core][PATCH 00/14] Add recipes for image hardening

Jan Kiszka <[email protected]> Mon, 27 Jul 2026 16:18:07 +0200
Newsgroups org.cip-project.lists.cip-dev
Message-ID <[email protected]>
On 24.07.26 14:39, Quirin Gylstorff wrote:
> From: Quirin Gylstorff <[email protected]>
> 
> This patch series adds the option to harden the build image according to the guidelines published by CIS.
> The patch introduces the following packages:
> 
> cip-cis-rules-config: user-facing configuration, stored in .config.json and configurable interactively via Kconfig.
> cip-cis-rules: uses the configuration from cip-cis-rules-config to generate a custom Debian package containing the necessary hardening configuration.
> cip-cis-validation: an optional package to validate the hardening rules.
> 
> Additionally, the kernel configuration is checked against the hardening rules.
> This patch set is currently developed and tested for hardening level 2.
> 

Meta question: There are a lot of "cip" prefixes used across the code.
Is everything that is really prefixed like that CIP-specific or
CIP-augmented? Where not, I would suggest to stick with plain
"cis"/"CIS" as prefix.

Jan

-- 
Siemens AG, Foundational Technologies
Linux Expert Center