git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Complete audit trail for embedded (Linux) system lifecycle with Git

From
KLKalle Launiala <kalle.launiala@gmail.com>
Date
Jul 15, 2012, 08:47 UTC
Message-ID
<CAHLTmjmrXSGQdS-wZ-K23grQTkxHFJzA-u05GJEqrtdLusBb8Q@mail.gmail.com>
Hello,

We are to solve a complete audit trail solution for full subcontractor value-chain fullfilling European Union machinery directive: http://ec.europa.eu/enterprise/sectors/mechanical/machinery/

To summarize, the directive is created to ensure safe operating environment for all kind of machinery devices (from industrial machinery to consumer shopping-centre lifts/elevators). This also includes the embedded software that controls the machinery (which is as we know, the make-or-break the true safety of the device).

The solution is based on the very core Git functionality, in very brief overview explained here: http://abstractiondev.wordpress.com/git-based-distribution/

As Git is completely file-system based, in our solution it is used as the core technology to audit ANY digital document or information. It is serving as a distributed set of "master data" repositories, including the digital signature repositories and 3rd party validation stacks. In the validation chains it is critical to be able to support responsible decision makers to approve design choises beyond the software, thus the digital signature infrastructure for any legal-binding document is as important as the actual embedded software stack, that is by its nature version controlled within Git as well.

While I would hope this post to serve a purpose for demonstrating that Git works as a perfect solution in the core, I'd also like to hear if there is already established community/ongoing process of achieving anything described above?

We have no intention of "reinventing the wheel" here, although being
very core solution for ANY audit trail and being so close based on Git
- bare functionality, I'm expecting any existing solution to share
much of similar design. Any existing tooling to support the solution
(especially dynamic cross-connected metadata repository searches - the
bottom image of the overview, that indexes the repositories together)
would be very welcome. The current technical solution is using GnuPG
for the digital signatures and open-source cross platform XML-database
for metadata indexing - grid databases being considered for the larger
implementations.
Any comments and/or feedback would be greatly appreciated.
Cheers,
Kalle Launiala
Message 1 of 1 in “Complete audit trail for embedded (Linux) system lifecycle with Git”
  1. Kalle LaunialaJul 15, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.