mirror of
https://github.com/clearlinux/graphene.git
synced 2026-10-04 07:58:22 +00:00
- Fixing AES-CMAC algorithm - Using SHA512 to hash file stubs (much faster than SHA256 and AES-CMAC) - Hardening enclave interface (still work-in-progress); delt with issue #28 - Handling socket/pipe polling better - Allowing setting the lowest heap address in enclaves ('sgx.heap_min' in manifest) - Fixing the pipe between processes (for SGX) - Fixing race condition in futex handling in LibOS - Inheriting epoll handles in forked chilren - Assigning signal code (now only hard-coding FPE_INTDIV, BUS_ADRERR, SEGV_ACCERR, SEGV_MAPERR) - Fixing race condition in vma allocation (likely to fix bug() in bookkeep/shim_vma.c) - Clearer debug message in LibOS - Fixing calling convention in LibOS and glibc - Fixing futex behavior (FUTEX_WAIT takes relative time, FUTEX_WAIT_BITSET takes absolute time) - More system call implemented - More application working (NGINX)
60 lines
2.2 KiB
Plaintext
60 lines
2.2 KiB
Plaintext
#!$(PAL)
|
|
|
|
loader.preload = file:$(SHIMPATH)
|
|
loader.exec = file:$(JAVA_HOME)/bin/java
|
|
loader.execname = java
|
|
loader.env.LD_LIBRARY_PATH = $(JAVA_HOME)/lib/amd64:$(JAVA_HOME)/lib/amd64/jli:/graphene:/lib/x86_64-linux-gnu:/usr/lib:/usr/lib/x86_64-linux-gnu
|
|
loader.env.PATH = /jre/bin:/bin:/usr/bin
|
|
loader.debug_type = $(DEBUGTYPE)
|
|
|
|
fs.mount.lib1.type = chroot
|
|
fs.mount.lib1.path = /graphene
|
|
fs.mount.lib1.uri = file:$(LIBCDIR)
|
|
|
|
fs.mount.lib2.type = chroot
|
|
fs.mount.lib2.path = /lib/x86_64-linux-gnu
|
|
fs.mount.lib2.uri = file:/lib/x86_64-linux-gnu
|
|
|
|
fs.mount.jre.type = chroot
|
|
fs.mount.jre.path = $(JAVA_HOME)
|
|
fs.mount.jre.uri = file:$(JAVA_HOME)
|
|
|
|
fs.mount.usr.type = chroot
|
|
fs.mount.usr.path = /usr
|
|
fs.mount.usr.uri = file:/usr
|
|
|
|
fs.mount.tmp.type = chroot
|
|
fs.mount.tmp.path = /tmp
|
|
fs.mount.tmp.uri = file:/tmp
|
|
|
|
$(RESOURCE_RULE)
|
|
|
|
sgx.search_trusted_libs.libc = file:$(LIBCDIR)
|
|
sgx.search_trusted_libs.java = file:$(JAVA_HOME)/lib/amd64
|
|
sgx.search_trusted_libs.java_server = file:$(JAVA_HOME)/lib/amd64/server
|
|
|
|
sgx.trusted_libs.librt = file:$(LIBCDIR)/librt.so.1
|
|
sgx.trusted_libs.libjava = file:$(JAVA_HOME)/lib/amd64/libjava.so
|
|
sgx.trusted_libs.libjli = file:$(JAVA_HOME)/lib/amd64/jli/libjli.so
|
|
sgx.trusted_libs.libjvm = file:$(JAVA_HOME)/lib/amd64/server/libjvm.so
|
|
sgx.trusted_libs.libzip = file:$(JAVA_HOME)/lib/amd64/libzip.so
|
|
sgx.trusted_libs.libnet = file:$(JAVA_HOME)/lib/amd64/libnet.so
|
|
sgx.trusted_libs.libnio = file:$(JAVA_HOME)/lib/amd64/libnio.so
|
|
sgx.trusted_libs.libnssc = file:/lib/x86_64-linux-gnu/libnss_compat.so.2
|
|
sgx.trusted_libs.libnssf = file:/lib/x86_64-linux-gnu/libnss_files.so.2
|
|
sgx.trusted_libs.libnssn = file:/lib/x86_64-linux-gnu/libnss_nis.so.2
|
|
|
|
sgx.trusted_files.jvmcfg = file:$(JAVA_HOME)/lib/amd64/jvm.cfg
|
|
sgx.trusted_files.meta = file:$(JAVA_HOME)/lib/meta-index
|
|
sgx.trusted_files.tzdb = file:$(JAVA_HOME)/lib/tzdb.dat
|
|
sgx.trusted_files.currency = file:$(JAVA_HOME)/lib/currency.data
|
|
sgx.trusted_files.rt = file:$(JAVA_HOME)/lib/rt.jar
|
|
sgx.trusted_files.resources = file:$(JAVA_HOME)/lib/resources.jar
|
|
|
|
sgx.allowed_files.ext = file:$(JAVA_HOME)/lib/ext
|
|
|
|
sgx.allowed_files.classes = file:classes
|
|
sgx.allowed_files.tmp = file:/tmp
|
|
sgx.allowed_files.xml_out = file:xml_out
|
|
sgx.allowed_files.SPECjvm2008 = file:SPECjvm2008
|