mirror of
https://github.com/clearlinux/graphene.git
synced 2026-09-04 12:51:41 +00:00
Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
- the main user of it were our tests
- worked only for the first process spawned inside Graphene, as it
was a unidirectional manifest->binary mapping, so the child
process didn't know about the corresponding manifest.
- sgx.sigfile:
- probably all existing usages of it were completely redundant
- was resolved relatively to CWD instead of the executable location,
which made it mostly useless
From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
matching name, or
- create a symlink to the binary in the folder where manifests are
stored and launch it through this symlink
Nginx
This directory contains the Makefile and the template manifest for the most recent version of Nginx web server (as of this writing, version 1.16.1). This was tested on a machine with SGX v1 and Ubuntu 16.04.
The Makefile and the template manifest contain extensive comments. Please review them to understand the requirements for Nginx running under Graphene-SGX.
We build Nginx from the source code instead of using an existing installation. On Ubuntu 16.04, please make sure that the following packages are installed:
sudo apt-get install -y build-essential apache2-utils
Quick Start
# build Nginx and the final manifest
make SGX=1
# run original Nginx against a benchmark (benchmark-http.sh, uses ab)
./install/sbin/nginx -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%
# run Nginx in non-SGX Graphene against a benchmark
./pal_loader ./nginx.manifest -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%
# run Nginx in Graphene-SGX against a benchmark
SGX=1 ./pal_loader ./nginx.manifest -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%
# you can also test the server using other utilities like wget
wget http://127.0.0.1:8002/random/10K.1.html
Alternatively, to run the Nginx server, use one of the following commands:
make start-native-server
make start-graphene-server
make SGX=1 start-graphene-server