Files
graphene/Examples/lighttpd/lighttpd.manifest.template
borysp c24bddd5aa [LibOS] Rework signal handling and syscall emulation
Change log (most important only):
- unify CPU context structures - now we have only one version -
  `PAL_CONTEXT` - which is shared between LibOS and PALs and it should
  depend only on the host architecture (not OS),
- syscalls emulation changed:
  - dedicated LibOS stack is now used for syscalls emulation,
  - removed one indirection level in syscalls table - now it stores
    `shim_do_*` functions directly,
- signal handling - completely rewritten:
  - all signal queues use proper locking schemes now,
  - signals are handled *only* when returning to the user app from LibOS
    or PAL,
  - nested signals are now possible,
  - the app is allowed to jump out of signal handler with the same
    sematics as on normal Linux,
  - signal altstack is now fully supported,
  - syscall restarting is now supported,
  - doing a backtrace from the signal handler works properly,
- disallow injecting host-level signals, with one exception, see
  `sys.enable_sigterm_injection` manifest option for more details.
2021-02-05 14:11:21 +01:00

97 lines
3.6 KiB
Plaintext

# lighttpd manifest example
#
# This manifest was prepared and tested on Ubuntu 16.04.
#
# lighttpd must be run with the pal_loader:
#
# ./pal_loader ./lighttpd <script>
libos.entrypoint = "file:$(INSTALL_DIR)/sbin/lighttpd"
# Path to the library OS
loader.preload = "file:$(GRAPHENEDIR)/Runtime/libsysdb.so"
# Graphene log level
loader.log_level = "$(GRAPHENE_LOG_LEVEL)"
# Read application arguments directly from the command line. Don't use this on production!
loader.insecure__use_cmdline_argv = 1
# Environment variables for lighttpd
loader.env.LD_LIBRARY_PATH = "/lib:$(ARCH_LIBDIR):$(INSTALL_DIR)/lib"
# Allow for injecting SIGTERM signal from the host.
sys.enable_sigterm_injection = 1
# Mounted FSes. The following "chroot" FSes mount a part of the host FS into the
# guest. Other parts of the host FS will not be available in the guest.
# Default glibc files, mounted from the Runtime directory in GRAPHENEDIR.
fs.mount.lib.type = "chroot"
fs.mount.lib.path = "/lib"
fs.mount.lib.uri = "file:$(GRAPHENEDIR)/Runtime"
# Host-level libraries (e.g., /lib/x86_64-linux-gnu) required by the lighttpd executable
fs.mount.lib2.type = "chroot"
fs.mount.lib2.path = "$(ARCH_LIBDIR)"
fs.mount.lib2.uri = "file:$(ARCH_LIBDIR)"
# Host-level directory (/usr) required by the lighttpd executable
fs.mount.usr.type = "chroot"
fs.mount.usr.path = "/usr"
fs.mount.usr.uri = "file:/usr"
# Mount the current working directory
fs.mount.cwd.type = "chroot"
fs.mount.cwd.path = "$(INSTALL_DIR_ABSPATH)"
fs.mount.cwd.uri = "file:$(INSTALL_DIR)"
# Mount lighttpd's default server.upload-dirs path
fs.mount.var_tmp.type = "chroot"
fs.mount.var_tmp.path = "/var/tmp"
fs.mount.var_tmp.uri = "file:/var/tmp"
# SGX general options
# Set the virtual memory size of the SGX enclave. For SGX v1, the enclave
# size must be specified during signing. If lighttpd needs more virtual memory
# than the enclave size, Graphene will not be able to allocate it.
sgx.enclave_size = "256M"
# Set the maximum number of enclave threads. For SGX v1, the number of enclave
# TCSes must be specified during signing, so the application cannot use more
# threads than the number of TCSes. Note that Graphene also creates an internal
# thread for handling inter-process communication (IPC), and potentially another
# thread for asynchronous events. Therefore, the actual number of threads that
# the application can create is (sgx.thread_num - 2).
sgx.thread_num = 3
sgx.nonpie_binary = 1
# SGX trusted files
sgx.trusted_files.lighttpd = "file:$(INSTALL_DIR)/sbin/lighttpd"
# Glibc libraries
sgx.trusted_files.ld = "file:$(GRAPHENEDIR)/Runtime/ld-linux-x86-64.so.2"
sgx.trusted_files.libc = "file:$(GRAPHENEDIR)/Runtime/libc.so.6"
sgx.trusted_files.libm = "file:$(GRAPHENEDIR)/Runtime/libm.so.6"
sgx.trusted_files.libdl = "file:$(GRAPHENEDIR)/Runtime/libdl.so.2"
sgx.trusted_files.librt = "file:$(GRAPHENEDIR)/Runtime/librt.so.1"
sgx.trusted_files.libutil = "file:$(GRAPHENEDIR)/Runtime/libutil.so.1"
sgx.trusted_files.libpthread = "file:$(GRAPHENEDIR)/Runtime/libpthread.so.0"
sgx.trusted_files.libz = "file:$(ARCH_LIBDIR)/libz.so.1"
sgx.trusted_files.nss_files = "file:$(ARCH_LIBDIR)/libnss_files.so.2"
# lighttpd modules and dependencies
sgx.trusted_files.mod_indexfile = "file:$(INSTALL_DIR)/lib/mod_indexfile.so"
sgx.trusted_files.mod_dirlisting = "file:$(INSTALL_DIR)/lib/mod_dirlisting.so"
sgx.trusted_files.mod_staticfile = "file:$(INSTALL_DIR)/lib/mod_staticfile.so"
# Trusted configuration files
sgx.trusted_files.conf = "file:lighttpd.conf"
sgx.trusted_files.conf2 = "file:lighttpd-generic.conf"
sgx.trusted_files.conf3 = "file:lighttpd-server.conf"
sgx.allowed_files.install = "file:install"