profiles: update hardened on the new 17.0 profile
authorMagnus Granberg <zorry@gentoo.org>
Fri, 1 Dec 2017 00:41:50 +0000 (01:41 +0100)
committerMagnus Granberg <zorry@gentoo.org>
Fri, 1 Dec 2017 00:43:07 +0000 (01:43 +0100)
profiles/features/hardened/amd64/package.use
profiles/features/hardened/amd64/package.use.force [deleted file]
profiles/features/hardened/make.defaults
profiles/features/hardened/package.use.mask
profiles/features/hardened/packages
profiles/features/hardened/use.force

index 0cef7f8d1d920e90e9ff92eb0dcde6403cc4a28a..dff56ad8871d65b11fca013bb3cd24986fdf9a19 100644 (file)
@@ -3,10 +3,11 @@
 
 # Magnus Granberg <zorry@gentoo.org> (14 Jan, 2015)
 # We need to have the pic flag on.
-# Bugs 490276, 513464, 523736 and 512208.
+# Bugs 358929, 490276, 513464, 523736 and 512208.
 media-libs/x264 pic
 media-video/ffmpeg pic
 media-video/libav pic
->=media-libs/mesa-10.1.6 pic
+media-libs/mesa pic
 media-libs/libpostproc pic
->=media-libs/xvid-1.3.3 pic
+media-libs/xvid pic
+app-emulation/open-vm-tools pic
diff --git a/profiles/features/hardened/amd64/package.use.force b/profiles/features/hardened/amd64/package.use.force
deleted file mode 100644 (file)
index ef833f2..0000000
+++ /dev/null
@@ -1,7 +0,0 @@
-# Copyright 1999-2015 Gentoo Foundation
-# Distributed under the terms of the GNU General Public License v2
-
-# Magnus Granberg <zorry@gentoo.org> (14 Jan, 2015)
-# We need to have the pic flag on.
-# Bugs 358929
-app-emulation/open-vm-tools pic
index d83d7eab8856763aad115732910dd28e897388cd..1f5030f9a41b45bf503ad57bb17e856cfe55bc84 100644 (file)
@@ -5,7 +5,7 @@
 # Rename STAGE1_USE to BOOTSTRAP_USE and stack it to the parent value
 BOOTSTRAP_USE="${BOOTSTRAP_USE} hardened pic xtpax -jit -orc"
 
-USE="hardened pic urandom xtpax -fortran -jit -orc"
+USE="hardened pic xtpax -jit -orc"
 
 # Ian Stakenvicius, 2014-09-03
 # Set a variable just to indicate that the current profile is a hardened one
@@ -13,3 +13,14 @@ USE="hardened pic urandom xtpax -fortran -jit -orc"
 # indicate said package is, say, configured in a way that defeats the purpose
 # of running hardened.
 PROFILE_IS_HARDENED=1
+
+# We set the default markings to XATTR_PAX
+PAX_MARKINGS="XT"
+
+# Default starting set of USE flags for all default/linux profiles.
+# We unset them so we get a clean use flag profile.
+USE="${USE} -berkdb -gdbm -tcpd"
+USE="${USE} -fortran"
+USE="${USE} -cli -session"
+USE="${USE} -dri"
+USE="${USE} -modules"
index e3320e1e4d9df2ce06f708d75a53d4fa0d5a0edd..cdab4d608d053289afa128c076560e609d4d655c 100644 (file)
@@ -3,9 +3,16 @@
 
 sys-apps/hwloc gl
 
-sys-devel/gcc -hardened
+sys-devel/gcc -hardened sanitize
 sys-libs/glibc -hardened
 
+# Ian Stakenvicius <axs@gentoo.org> (03 Dec 2014)
+# Have no way of knowing what Gecko Media Plugins will install in profiles
+www-client/firefox gmp-autoupdate
+
 # net-fs/openafs-kernel module can't be used on hardened,
 # see bug 540196.
 net-fs/openafs modules
+
+# jit don't work on hardened.
+dev-vcs/git pcre-jit
index 2524abdd0c4fda631acd2ba55f5e45fb62b330bc..3790c915840d8b8a34be6b6093a40f718a4bb819 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2013 Gentoo Foundation.
+# Copyright 1999-2017 Gentoo Foundation.
 # Distributed under the terms of the GNU General Public License v2
 
 # This file extends the base packages file for all hardened profiles
index 35e56536ec649e7f0142309fb557f96c88432342..2f57880682b107de9d99e2b7a87855de5337f1f8 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2015 Gentoo Foundation
+# Copyright 1999-2017 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 # Make sure people don't accidentally turn of ssp/pie in important packages.