Hi, In openssl recipe, it has this: # Avoid binaries being marked as requiring an executable stack (which causes # issues with SELinux on the host) CFLAG_append_virtclass-native = " -Wa,--noexecstack" Why this is only enabled for native? yocto doesn't support secure kernel? thanks, yao