Because GDB is awesome this isn't actually configurable in .gdbinit (or
at least I couldn't find any way to do this) and we need to fix it via
the commandline.
Plain wildcards `*` in .gitignore are considered a bad practice
because they may cause unintended ignore of files. This commit
replaces `*` with explicit lists of file names.
In certain cases (e.g, a container runtime for production), `make` and `gcc`
programs may be unavailable. In this case, detect `PAL_HOST` based on the
base name of libpal.
For detection of SGX/non-SGX (for example in regression tests) always
use the SGX environment variable. To generate launch/EINIT tokens use
the new 'sgx-tokens' Make target.
This commit removes the following from the master Graphene branch (this
is now moved to the EXPERIMENTAL/linux-reference-monitor branch):
- Remove reference monitor loader code
- Remove sandboxing code and dependency to reference monitor code
- Remove Linux kernel changes for reference monitor
- Remove README instructions and scripts regarding reference monitor
Since clean rule is first target, just "make" means "make clean" as default goal.
This is a surprise. usually "make" means "make all".
So move all rule to the first target.
Signed-off-by: Isaku Yamahata <isaku.yamahata@gmail.com>
This patch fixes up to make LibOS/shim/tests/benchmark build again.
It addresses small 4 issues as follows.
- Runtime/pal_loader
pass --no-print-directory to make pal_loader doesn't work as
expected when it's invoked by make command as below. pal_loader
invokes make with --quiet. But when pal_loader is called by make as
sub command, the message, "Entering/Leaving <dir>" is still output.
pass --no-print-directory to make to suppress Entering/Leaving
message.
> /graphene/Runtime/pal-make[1]: Entering
> directory '/graphene/Pal/test'
> Linux
> make[1]: Leaving directory
> '/graphene/devel/graphene/Pal/test' is not built, or
> security mode is not supported
- fix up Makefiles to build LibOS/shim/tests/benchmark
Otherwise the build fails as follows.
> $ make
> ln -sf ../../../../Runtime/pal_loader
> [ fork_latency ]
> [ test_start.m ]
> [ rpc_latency.libos ]
> /usr/bin/ld: cannot find -llibos
> collect2: error: ld returned 1 exit status
> Makefile:18: recipe for target 'rpc_latency.libos' failed
> make: *** [rpc_latency.libos] Error 1
- update stale manifest.template
- update .gitignore
The change set of 7f5a4cc made Makefile create .lib directory.
So add it to .gitignore.
Signed-off-by: Isaku Yamahata <isaku.yamahata@gmail.com>
1. Redesign of the VMA bookkeeping logic in the library OS
2. ASLR reimplementation
3. Support MAP_32BITS flags for mmap()
4. Safeguarding library OS internal memory from user memory and checkpoint buffers
5. Eliminating race conditions at VMA lookup and bookkeeping
6. Enable early VMA bookkeeping during initialization
7. Adding documentation for the VMA implementation
* add memusg to pal_loader script
* Stop bleeding PAL handles.
Deprecating DkOjectReference and reference counting in PAL handle.
Deprecating DkSemaphoreDestroy and DkEventDestroy (replaced by DkObjectClose).
Cleaning unused PAL handles in the library OS.
Adding a heap tracing feature to profile usage of PAL handles.
* fix a bug in SGX mode that mapping untrusted files into memory never got free by DkVirtualMemoryFree()
* adding lighttpd SSL option
* fixing the freeing convention of PAL handles; On SGX, event and mutex handles need to be freed seperately.
* changing how mutexes and events are allocated on SGX
* fixing GCC regression tests (for both Linux and SGX)
* fix a double-free problem of the first thread handle
- Fixing AES-CMAC algorithm
- Using SHA512 to hash file stubs (much faster than SHA256 and AES-CMAC)
- Hardening enclave interface (still work-in-progress); delt with issue #28
- Handling socket/pipe polling better
- Allowing setting the lowest heap address in enclaves ('sgx.heap_min' in manifest)
- Fixing the pipe between processes (for SGX)
- Fixing race condition in futex handling in LibOS
- Inheriting epoll handles in forked chilren
- Assigning signal code (now only hard-coding FPE_INTDIV, BUS_ADRERR, SEGV_ACCERR, SEGV_MAPERR)
- Fixing race condition in vma allocation (likely to fix bug() in bookkeep/shim_vma.c)
- Clearer debug message in LibOS
- Fixing calling convention in LibOS and glibc
- Fixing futex behavior (FUTEX_WAIT takes relative time, FUTEX_WAIT_BITSET takes absolute time)
- More system call implemented
- More application working (NGINX)