diff mbox series

[5/6] distro/defaultsetup: Enable security flags by default

Message ID 20260221084230.3219379-5-richard.purdie@linuxfoundation.org
State Under Review
Headers show
Series [1/6] conf: Switch to systemd by default and simplify init manager selection | expand

Commit Message

Richard Purdie Feb. 21, 2026, 8:42 a.m. UTC
This defaults to including our security flags which use stack-protector-strong
and D_FORTIFY_SOURCE=2 by default, as aids to improve detection of security issues.

This change has been tested in poky for a long time and allows us to align
our default compilation flags and environment.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
---
 meta/conf/distro/defaultsetup.conf | 1 +
 1 file changed, 1 insertion(+)
diff mbox series

Patch

diff --git a/meta/conf/distro/defaultsetup.conf b/meta/conf/distro/defaultsetup.conf
index e8f5439a8d9..871fe7b4e88 100644
--- a/meta/conf/distro/defaultsetup.conf
+++ b/meta/conf/distro/defaultsetup.conf
@@ -6,6 +6,7 @@  require conf/distro/include/tcmode-${TCMODE}.inc
 require conf/distro/include/tclibc-${TCLIBC}.inc
 
 require conf/distro/include/no-static-libs.inc
+require conf/distro/include/security_flags.inc
 
 require conf/distro/include/uninative-flags.inc
 require conf/distro/include/yocto-uninative.inc