mirror of
https://github.com/clearlinux/graphene.git
synced 2026-09-06 22:01:29 +00:00
Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
- the main user of it were our tests
- worked only for the first process spawned inside Graphene, as it
was a unidirectional manifest->binary mapping, so the child
process didn't know about the corresponding manifest.
- sgx.sigfile:
- probably all existing usages of it were completely redundant
- was resolved relatively to CWD instead of the executable location,
which made it mostly useless
From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
matching name, or
- create a symlink to the binary in the folder where manifests are
stored and launch it through this symlink
Busybox
This directory contains the Makefile and the template manifest for the most recent version of Busybox (as of this writing, commit ac78f2ac96). This was tested on a machine with SGX v1 and Ubuntu 16.04.
The Makefile and the template manifest contain extensive comments and are made self-explanatory. Please review them to gain understanding in Graphene-SGX and requirements for applications running under Graphene-SGX.
Quick Start
# build Busybox and the final manifest
make SGX=1
# run Busybox shell in non-SGX Graphene
./pal_loader busybox sh
# or
./pal_loader busybox.manifest sh
# run Busybox shell in Graphene-SGX
SGX=1 ./pal_loader busybox sh
# or
SGX=1 ./pal_loader busybox.manifest.sgx sh
# now a shell session should be running e.g. typing:
ls
# should run program `ls` which lists current working directory
Note that busybox can also be started via a manifest file (which contains path to the busybox binary):
./busybox.manifest sh # to run a shell
./busybox.manifest ls -l # to list local directory
# or under SGX:
./busybox.manifest.sgx sh # to run a shell
./busybox.manifest.sgx ls -l # to list local directory