# PyTorch manifest template # # This manifest was tested on Ubuntu 16.04 and 18.04. loader.argv0_override = "python3" # Graphene environment, including the path to the library OS and the debug # option (inline/none) loader.preload = "file:$(GRAPHENEDIR)/Runtime/libsysdb.so" loader.debug_type = "$(GRAPHENEDEBUG)" # Read application arguments directly from the command line. Don't use this on production! loader.insecure__use_cmdline_argv = 1 # Propagate environment variables from the host. Don't use this on production! loader.insecure__use_host_env = 1 # Overwrite some environment variables loader.env.LD_LIBRARY_PATH = "/lib:/usr/lib:$(ARCH_LIBDIR):/usr/$(ARCH_LIBDIR)" # Default glibc files, mounted from the Runtime directory in GRAPHENEDIR fs.mount.lib.type = "chroot" fs.mount.lib.path = "/lib" fs.mount.lib.uri = "file:$(GRAPHENEDIR)/Runtime/" # More libraries required by PyTorch fs.mount.lib2.type = "chroot" fs.mount.lib2.path = "$(ARCH_LIBDIR)" fs.mount.lib2.uri = "file:$(ARCH_LIBDIR)" fs.mount.usr.type = "chroot" fs.mount.usr.path = "/usr" fs.mount.usr.uri = "file:/usr" # Host-level directory to NSS files required by Glibc + NSS libs fs.mount.etc.type = "chroot" fs.mount.etc.path = "/etc" fs.mount.etc.uri = "file:/etc" # Workload needs to create temporary files fs.mount.tmp.type = "chroot" fs.mount.tmp.path = "/tmp" fs.mount.tmp.uri = "file:/tmp" # PyTorch loads its pre-trained models from here # Uncomment lines below if you want to use torchvision.model.alexnet(pretrained=True) # fs.mount.torch.type = "chroot" # fs.mount.torch.path = "$(HOME)/.cache/torch" # fs.mount.torch.uri = "file:$(HOME)/.cache/torch" # When run as `pip install --user ...`, pip installs Python packages here fs.mount.pip.type = "chroot" fs.mount.pip.path = "$(HOME)/.local/lib" fs.mount.pip.uri = "file:$(HOME)/.local/lib" # SGX general options # Set the virtual memory size of the SGX enclave. For SGX v1, the enclave # size must be specified during signing. If the workload needs more virtual memory # than the enclave size, Graphene will not be able to allocate it. # # In particular, libtorch*.so is more than 1G, thus 4G is the minimum to make this run. sgx.enclave_size = "4G" # Set the maximum number of enclave threads. For SGX v1, the number of enclave # TCSes must be specified during signing, so the application cannot use more # threads than the number of TCSes. Note that Graphene also creates an internal # thread for handling inter-process communication (IPC), and potentially another # thread for asynchronous events. Therefore, the actual number of threads that # the application can create is (sgx.thread_num - 2). # # We (somewhat arbitrarily) specify 128 threads for this workload. sgx.thread_num = 128 # SGX trusted libraries sgx.trusted_files.ld = "file:$(GRAPHENEDIR)/Runtime/ld-linux-x86-64.so.2" sgx.trusted_files.libc = "file:$(GRAPHENEDIR)/Runtime/libc.so.6" sgx.trusted_files.libdl = "file:$(GRAPHENEDIR)/Runtime/libdl.so.2" sgx.trusted_files.libm = "file:$(GRAPHENEDIR)/Runtime/libm.so.6" sgx.trusted_files.libpthread = "file:$(GRAPHENEDIR)/Runtime/libpthread.so.0" sgx.trusted_files.libresolv = "file:$(GRAPHENEDIR)/Runtime/libresolv.so.2" sgx.trusted_files.librt = "file:$(GRAPHENEDIR)/Runtime/librt.so.1" sgx.trusted_files.libutil = "file:$(GRAPHENEDIR)/Runtime/libutil.so.1" sgx.trusted_files.libnssdns = "file:$(GRAPHENEDIR)/Runtime/libnss_dns.so.2" sgx.trusted_files.libstdc = "file:/usr/$(ARCH_LIBDIR)/libstdc++.so.6" sgx.trusted_files.libgccs = "file:$(ARCH_LIBDIR)/libgcc_s.so.1" sgx.trusted_files.libaptpkg = "file:/usr/$(ARCH_LIBDIR)/libapt-pkg.so.5.0" sgx.trusted_files.liblz4 = "file:/usr/$(ARCH_LIBDIR)/liblz4.so.1" sgx.trusted_files.libsystemd = "file:$(ARCH_LIBDIR)/libsystemd.so.0" sgx.trusted_files.libselinux = "file:$(ARCH_LIBDIR)/libselinux.so.1" sgx.trusted_files.libgcrypt = "file:$(ARCH_LIBDIR)/libgcrypt.so.20" sgx.trusted_files.libpcre = "file:$(ARCH_LIBDIR)/libpcre.so.3" sgx.trusted_files.libgpgerror = "file:$(ARCH_LIBDIR)/libgpg-error.so.0" sgx.trusted_files.libexpat = "file:$(ARCH_LIBDIR)/libexpat.so.1" sgx.trusted_files.libz = "file:$(ARCH_LIBDIR)/libz.so.1" sgx.trusted_files.libz2 = "file:$(ARCH_LIBDIR)/libbz2.so.1.0" sgx.trusted_files.liblzma = "file:$(ARCH_LIBDIR)/liblzma.so.5" sgx.trusted_files.libmpdec = "file:/usr/$(ARCH_LIBDIR)/libmpdec.so.2" # Ubuntu16.04 sgx.trusted_files.libcrypto = "file:$(ARCH_LIBDIR)/libcrypto.so.1.0.0" # Ubuntu16.04 sgx.trusted_files.libssl = "file:$(ARCH_LIBDIR)/libssl.so.1.0.0" # Ubuntu18.04 sgx.trusted_files.libcrypto = "file:/usr/$(ARCH_LIBDIR)/libcrypto.so.1.1" # Ubuntu18.04 sgx.trusted_files.libssl = "file:/usr/$(ARCH_LIBDIR)/libssl.so.1.1" # Name Service Switch (NSS) libraries (Glibc dependencies) sgx.trusted_files.libnssfiles = "file:$(ARCH_LIBDIR)/libnss_files.so.2" sgx.trusted_files.libnsscompat = "file:$(ARCH_LIBDIR)/libnss_compat.so.2" sgx.trusted_files.libnssnis = "file:$(ARCH_LIBDIR)/libnss_nis.so.2" sgx.trusted_files.libnsl = "file:$(ARCH_LIBDIR)/libnsl.so.1" sgx.trusted_files.libnssmyhostname = "file:$(ARCH_LIBDIR)/libnss_myhostname.so.2" sgx.trusted_files.libnssmdns = "file:$(ARCH_LIBDIR)/libnss_mdns4_minimal.so.2" # The script to run sgx.trusted_files.script = "file:pytorchexample.py" # required by Python package ctypes (lib/python3.6/lib-dynload/ctypes.cpython-36m-x86_64-linux-gnu.so) # Ubuntu18.04 sgx.trusted_files.libffi = "file:/usr/$(ARCH_LIBDIR)/libffi.so.6" # File containing the classes, i.e., things the classifier has been trained to distinguish between sgx.trusted_files.classes = "file:classes.txt" # Input image sgx.trusted_files.image = "file:input.jpg" # File containing the pre-trained model # Uncomment lines below if you want to use torchvision.model.alexnet(pretrained=True) # sgx.trusted_files.torch = "file:$(HOME)/.cache/torch/checkpoints/alexnet-owt-4df8aa71.pth" # Pre-trained model saved as a file sgx.trusted_files.model = "file:alexnet-pretrained.pt" # Scratch space sgx.allowed_files.tmp = "file:/tmp" # The workload needs to fork/execve; this allows it to do so sgx.trusted_children.fork = "file:python3_child.sig" # Various locations where Python dependencies are found sgx.allowed_files.python3 = "file:/usr/lib/python3" sgx.allowed_files.pythonhome = "file:$(HOME)/.local/lib" # Ubuntu16.04 sgx.allowed_files.python35 = "file:/usr/lib/python3.5" # Ubuntu18.04 sgx.allowed_files.python36 = "file:/usr/lib/python3.6" # Ubuntu16.04 sgx.allowed_files.python35local = "file:/usr/local/lib/python3.5" # Ubuntu18.04 sgx.allowed_files.python36local = "file:/usr/local/lib/python3.6" # APT config files sgx.allowed_files.aptconfd = "file:/etc/apt/apt.conf.d" sgx.allowed_files.aptconf = "file:/etc/apt/apt.conf" sgx.allowed_files.apport = "file:/etc/default/apport" # Name Service Switch (NSS) files (Glibc reads these files) sgx.allowed_files.nsswitch = "file:/etc/nsswitch.conf" sgx.allowed_files.group = "file:/etc/group" sgx.allowed_files.passwd = "file:/etc/passwd" # DNS hostname resolution files (Glibc reads these files) sgx.allowed_files.hostconf = "file:/etc/host.conf" sgx.allowed_files.hosts = "file:/etc/hosts" sgx.allowed_files.gaiconf = "file:/etc/gai.conf" sgx.allowed_files.resolv = "file:/etc/resolv.conf" # System's file system table sgx.allowed_files.fstab = "file:/etc/fstab" # Graphene optionally provides patched OpenMP runtime library that runs faster # inside SGX enclaves (execute `make -C LibOS gcc` to generate it). Uncomment # the lines below to use the patched library. PyTorch's SGX perf overhead # decreases on some workloads from 25% to 8% with this patched library. Note # that we need to preload the library because PyTorch's distribution renames # libgomp.so to smth like libgomp-7c85b1e2.so.1, so it's not just a matter of # searching in the Graphene's Runtime path first, but a matter of intercepting # OpenMP functions. # loader.env.LD_PRELOAD = "/lib/libgomp.so.1" # sgx.trusted_files.libgomp = "file:$(GRAPHENEDIR)/Runtime/libgomp.so.1"