mirror of
https://github.com/clearlinux/graphene.git
synced 2026-10-03 23:48:19 +00:00
[LibOS+Pal] manifest: Remove support for loader.exec and sgx.sigfile
Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
- the main user of it were our tests
- worked only for the first process spawned inside Graphene, as it
was a unidirectional manifest->binary mapping, so the child
process didn't know about the corresponding manifest.
- sgx.sigfile:
- probably all existing usages of it were completely redundant
- was resolved relatively to CWD instead of the executable location,
which made it mostly useless
From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
matching name, or
- create a symlink to the binary in the folder where manifests are
stored and launch it through this symlink
This commit is contained in:
@@ -1 +1,2 @@
|
||||
*.pyc
|
||||
/python
|
||||
|
||||
@@ -23,7 +23,7 @@ GRAPHENEDEBUG = none
|
||||
endif
|
||||
|
||||
.PHONY: all
|
||||
all: python.manifest pal_loader
|
||||
all: python.manifest pal_loader | python
|
||||
ifeq ($(SGX),1)
|
||||
all: python.manifest.sgx python.token python.sig
|
||||
endif
|
||||
@@ -110,6 +110,7 @@ python.manifest: python.manifest.template python-trusted-libs python-trusted-scr
|
||||
|
||||
python.manifest.sgx: python.manifest
|
||||
$(GRAPHENEDIR)/Pal/src/host/Linux-SGX/signer/pal-sgx-sign \
|
||||
-exec python \
|
||||
-libpal $(GRAPHENEDIR)/Runtime/libpal-Linux-SGX.so \
|
||||
-key $(SGX_SIGNER_KEY) \
|
||||
-manifest $< -output $@
|
||||
@@ -119,7 +120,9 @@ python.sig: python.manifest.sgx
|
||||
python.token: python.sig
|
||||
$(GRAPHENEDIR)/Pal/src/host/Linux-SGX/signer/pal-sgx-get-token -output $@ -sig $<
|
||||
|
||||
# Extra executables
|
||||
python:
|
||||
ln -s $(PYTHONEXEC) $@
|
||||
|
||||
pal_loader:
|
||||
ln -s $(GRAPHENEDIR)/Runtime/pal_loader $@
|
||||
|
||||
@@ -133,7 +136,7 @@ check: all
|
||||
|
||||
.PHONY: clean
|
||||
clean:
|
||||
$(RM) *.manifest *.manifest.sgx *.token *.sig pal_loader OUTPUT* *.PID
|
||||
$(RM) *.manifest *.manifest.sgx *.token *.sig python pal_loader OUTPUT* *.PID
|
||||
$(RM) -r scripts/__pycache__
|
||||
|
||||
.PHONY: distclean
|
||||
|
||||
@@ -2,15 +2,6 @@
|
||||
#
|
||||
# This manifest was prepared and tested on Ubuntu 16.04/18.04 and tested with
|
||||
# Python 3.5 and 3.6.
|
||||
#
|
||||
# Python must be run with the pal_loader:
|
||||
#
|
||||
# ./pal_loader python.manifest <script>
|
||||
|
||||
# The executable to load in Graphene. By default, PYTHONHOME points to the
|
||||
# system installation. To run Python from a local installation, specify PYTHONHOME
|
||||
# when running `make` in this directory.
|
||||
loader.exec = file:$(PYTHONEXEC)
|
||||
|
||||
# Graphene environment, including the path of the library OS and the debug
|
||||
# option (inline/none).
|
||||
|
||||
Reference in New Issue
Block a user