11 Commits
Author SHA1 Message Date
Dmitrii Kuvaiskii 0a4d5ce0e5 [GSC] Refactor GSC and make it work again
Commit "Introduce one, central manifest, zero-config children and
constant MRENCLAVE" broke GSC. This commit fixes GSC (mainly adjusts
it the single-manifest change in that commit). Also, significant
internal refactoring is done (no user-visible changes). Also, scripts
now explicitly use UTF-8 when reading/writing the manifest files because
they are written in TOML which forces UTF-8.
2021-02-03 23:10:29 -08:00
Michał Kowalczyk 3d31f2d18d Introduce one, central manifest, zero-config children and constant MRENCLAVE
This is the next part of the great loader rework, with a lot of breaking changes:

- Complete removal of the "trusted children" thing - now children
  processes can be spawned arbitrarily and from arbitrary mountpoint
  types, without any additional configuration needed.

- There's a new, required option in the manifest: `libos.entrypoint` - it
  specifies the URI to the entry binary in the first process. There's no
  need anymore to name the manifest and the first binary identically.

- On SGX, the main binary is not measured in MRENCLAVE anymore - only
  PAL, LibOS and the manifest are measured. This is enough to bind
  MRENCLAVE to a specific entrypoint user executable if wanted - it
  just has to be mounted as a trusted file.

- All Graphene SGX enclaves have now exactly the same MRENCLAVE. This is
  a hash of a "Graphene stub", which can "fork" into one of two states
  in runtime: initial process or child. The initial process creates a
  new "Graphene namespace" with a clean state, it can also be attested
  remotely (contrary to child processes). The initial process can spawn
  children processes by spawning a Graphene stub and directing it to
  start in the child mode. It then attests it locally, and if
  successful, establishes an encrypted pipe, "connects" to its own
  namespace and treats as trusted (including sending protected files
  key).

- Now, there's only one, central manifest describing the initial state
  of a Graphene instance which can be spawned from it (previously, each
  process required a separate manifest which could have different
  configuration - which wasn't actually supported and didn't make sense
  design-wise). One downside of central manifests is that all processes
  require the same enclave configuration (e.g. size), but that was
  already the case so far because of broken checkpointing code. Also,
  this is only a temporary problem, which will cease to exist after the
  introduction of EDMM.

- `sgx.static_address` was renamed to `sgx.nonpie_binary` and now has to
  be inserted manually by users (`sgx_sign` tools doesn't know about the
  binaries run inside, which can be even provided or generated in
  runtime by the user's workload).

- Caveat: the memory gap for non-PIE executables was removed because it
  requires adding a new option to the manifest to be cleanly
  implemented. This is left for some future loader rework PR.
2021-01-12 19:53:24 +01:00
Dmitrii Kuvaiskii 8eee4a4742 [LibOS,Pal,Examples,GSC,Docs] Move manifest parsing to TOML
The manifest syntax stays exactly the same, including 0 and 1
integers to denote boolean values (this is done for ease of porting
and can be fixed in future commits). The only visible change is
surrounding strings in the manifest with quotes (requirement of
TOML). All manifests and Makefiles of our tests and example apps are
ported to the new TOML syntax. Documentation is updated.
2020-11-12 05:45:07 -08:00
Anjo Vahldiek-Oberwagner 56e6928deb [GSC] Fix test makefile to correctly use configuration file 2020-11-01 20:44:25 +01:00
Dmitrii Kuvaiskii 3bcab01a0c [Pal/Linux-SGX] Remove "sgx.allow_file_creation" and always allow it
The manifest option "sgx.allow_file_creation" is useless (most
real-world apps will set it to "1" anyway). So this commit simply
removes this option and always allows to create files.
2020-10-06 00:20:22 -07:00
Anjo Vahldiek-Oberwagner 34b8eb1ec2 [GSC] Add an option to pre-build Graphene-only image
Previous iterations of GSC always built the Graphene runtime as part of
the `gsc build` command. This commit adds an option to extract the
compilation of the Graphene runtime from the GSC build command into a
separate command called `gsc build-graphene`. Using `gsc build-graphene`,
one can prepare a Docker image that includes the required runtime files
for a `gsc build` command.

The purpose of this separation is to publish Graphene Docker images for
special environments such as cloud environments. This simplifies the
configuration parameters for the user, since they only have to specify
the Graphene Docker image name instead of the Graphene repository and
Driver details.
2020-09-10 01:40:13 +02:00
Anjo Vahldiek-Oberwagner 67c23d74cf [GSC] Test GSC using Linux PAL and add a test for trusted arguments 2020-08-30 11:27:04 +02:00
Lu Ken 54bc4985bf [GSC] Support build-time variables via --build-arg
When building graphenized Docker image, some build-time variables
like http_proxy, https_proxy, no_proxy must be specified (for
private network behind proxy). This commit adds `--build-arg` via
GSC_BUILD_FLAGS.
2020-08-27 15:35:51 +00:00
Michał Kowalczyk 5a765c0533 [GSC] Fix test Makefile to correctly set Graphene branch 2020-07-31 22:09:32 +02:00
Anjo Vahldiek-Oberwagner ac3dc5d6c2 [GSC] Change print behavior of tests to print intermediate results 2020-07-28 18:37:55 +00:00
Anjo Vahldiek-Oberwagner f51aafddf3 Graphene Shielded Containers v1 2020-07-08 10:51:09 -07:00