diff --git a/conf/intel/portage/env/hardened.conf b/conf/intel/portage/env/hardened.conf new file mode 100644 index 0000000..f4492b3 --- /dev/null +++ b/conf/intel/portage/env/hardened.conf @@ -0,0 +1,2 @@ +# This configuration assumes the default profile is -vanilla +GCC_SPECS="" diff --git a/conf/intel/portage/package.env.amd64 b/conf/intel/portage/package.env.amd64 index 3e2ecb6..50cfcb0 100644 --- a/conf/intel/portage/package.env.amd64 +++ b/conf/intel/portage/package.env.amd64 @@ -18,3 +18,6 @@ sys-kernel/linux-xen-domU disable.debug.conf # as of 05/jan/2012 disable graphite on it dev-util/nvidia-cuda-sdk nographite.amd64.conf dev-util/nvidia-cuda-toolkit nographite.amd64.conf + +# Enable hardening +sys-libs/glibc hardened.conf diff --git a/conf/intel/portage/package.env.x86 b/conf/intel/portage/package.env.x86 index 5192308..208b014 100644 --- a/conf/intel/portage/package.env.x86 +++ b/conf/intel/portage/package.env.x86 @@ -20,3 +20,5 @@ sys-kernel/linux-xen-domU disable.debug.conf dev-util/nvidia-cuda-sdk nographite.x86.conf dev-util/nvidia-cuda-toolkit nographite.x86.conf +# Enable hardening +sys-libs/glibc hardened.conf