[LibOS+Pal] manifest: Remove support for loader.exec and sgx.sigfile

Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
    - the main user of it were our tests
    - worked only for the first process spawned inside Graphene, as it
      was a unidirectional manifest->binary mapping, so the child
      process didn't know about the corresponding manifest.
- sgx.sigfile:
    - probably all existing usages of it were completely redundant
    - was resolved relatively to CWD instead of the executable location,
      which made it mostly useless

From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
  matching name, or
- create a symlink to the binary in the folder where manifests are
  stored and launch it through this symlink
This commit is contained in:
Michał Kowalczyk
2020-10-23 00:06:46 +02:00
parent fcadd3d580
commit e587869e13
98 changed files with 618 additions and 691 deletions
+1
View File
@@ -1 +1,2 @@
*.pyc
/python
+6 -3
View File
@@ -23,7 +23,7 @@ GRAPHENEDEBUG = none
endif
.PHONY: all
all: python.manifest pal_loader
all: python.manifest pal_loader | python
ifeq ($(SGX),1)
all: python.manifest.sgx python.token python.sig
endif
@@ -110,6 +110,7 @@ python.manifest: python.manifest.template python-trusted-libs python-trusted-scr
python.manifest.sgx: python.manifest
$(GRAPHENEDIR)/Pal/src/host/Linux-SGX/signer/pal-sgx-sign \
-exec python \
-libpal $(GRAPHENEDIR)/Runtime/libpal-Linux-SGX.so \
-key $(SGX_SIGNER_KEY) \
-manifest $< -output $@
@@ -119,7 +120,9 @@ python.sig: python.manifest.sgx
python.token: python.sig
$(GRAPHENEDIR)/Pal/src/host/Linux-SGX/signer/pal-sgx-get-token -output $@ -sig $<
# Extra executables
python:
ln -s $(PYTHONEXEC) $@
pal_loader:
ln -s $(GRAPHENEDIR)/Runtime/pal_loader $@
@@ -133,7 +136,7 @@ check: all
.PHONY: clean
clean:
$(RM) *.manifest *.manifest.sgx *.token *.sig pal_loader OUTPUT* *.PID
$(RM) *.manifest *.manifest.sgx *.token *.sig python pal_loader OUTPUT* *.PID
$(RM) -r scripts/__pycache__
.PHONY: distclean
@@ -2,15 +2,6 @@
#
# This manifest was prepared and tested on Ubuntu 16.04/18.04 and tested with
# Python 3.5 and 3.6.
#
# Python must be run with the pal_loader:
#
# ./pal_loader python.manifest <script>
# The executable to load in Graphene. By default, PYTHONHOME points to the
# system installation. To run Python from a local installation, specify PYTHONHOME
# when running `make` in this directory.
loader.exec = file:$(PYTHONEXEC)
# Graphene environment, including the path of the library OS and the debug
# option (inline/none).