Re: [RFC cip-dev][isar-cip-core][PATCH 06/14] Apply hardening configuration to the kernel

Jan Kiszka <[email protected]> Fri, 31 Jul 2026 14:24:57 +0200
Newsgroups org.cip-project.lists.cip-dev
Message-ID <[email protected]>
On 31.07.26 14:05, Christoph Steiger wrote:
> On 7/27/26 4:21 PM, Jan Kiszka wrote:
>> On 24.07.26 14:39, Quirin Gylstorff wrote:
>>> From: Quirin Gylstorff <[email protected]>
>>>
>>> Use the provided kernel hardening configuration options in the kernel
>>> build.
>>
>> Err, no, this does not do that. This just drops a dead include that
>> could be used in an own kernel recipe, and only then it will have a real
>> effect.
>>
>=20
> ACK, we will move the corresponding changes and fix the commit message.
>=20
>>>
>>> Co-Authored-by: Felix Moessbauer <[email protected]>
>>> Co-Authored-by: Christoph Steiger <[email protected]>
>>> Signed-off-by: Quirin Gylstorff <[email protected]>
>>> ---
>>> =C2=A0 recipes-kernel/linux/kernel-hardening.inc | 16 ++++++++++++++++
>>> =C2=A0 1 file changed, 16 insertions(+)
>>> =C2=A0 create mode 100644 recipes-kernel/linux/kernel-hardening.inc
>>>
>>> diff --git a/recipes-kernel/linux/kernel-hardening.inc b/recipes-
>>> kernel/linux/kernel-hardening.inc
>>> new file mode 100644
>>> index 0000000..2b22fca
>>> --- /dev/null
>>> +++ b/recipes-kernel/linux/kernel-hardening.inc
>>> @@ -0,0 +1,16 @@
>>> +#
>>> +# CIP Core, generic profile
>>> +#
>>> +# Copyright (c) Siemens AG, 2026
>>> +#
>>> +# SPDX-License-Identifier: MIT
>>> +
>>> +OVERRIDES:append =3D "${@'kernel-hardening' if
>>> bb.utils.to_boolean(d.getVar('CIP_CIS_HARDENING')) else ''}"
>>> +
>>> +KERNEL_CONFIG_FRAGMENTS:kernel-hardening +=3D "hardening.kernel.cfg"
>>> +
>>> +do_dpkg_source[depends] +=3D "${@'cip-cis-rules-
>>> config:do_deploy_hardening' if
>>> bb.utils.to_boolean(d.getVar('CIP_CIS_HARDENING')) else ''}"
>>> +
>>> +do_dpkg_source:prepend:kernel-hardening() {
>>> +=C2=A0=C2=A0=C2=A0 cp ${DEPLOY_DIR_IMAGE}/${DISTRO}-hardening.kernel.c=
fg
>>> ${WORKDIR}/hardening.kernel.cfg
>>
>> Why does this need copying? Can't we just reference the right .cfg file
>> in SRC_URI and let Isar do its magic?
>=20
> The copying is required since having the config snippet in `SRC_URI`
> makes it required at parse time. The snippets are created at build time
> by one of the cip-cis-rules recipes.
>=20
> Either way, we are using most of the magic already by simply adding the
> snippet to `KERNEL_CONFIG_FRAGMENTS`.
>=20

That is fine, but then just refer to the generated snippet this way, do
not copy it. KERNEL_CONFIG_FRAGMENTS was exactly for such use cases
extended recently.

Jan

--=20
Siemens AG, Foundational Technologies
Linux Expert Center