Files
Michał Kowalczyk e587869e13 [LibOS+Pal] manifest: Remove support for loader.exec and sgx.sigfile
Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
    - the main user of it were our tests
    - worked only for the first process spawned inside Graphene, as it
      was a unidirectional manifest->binary mapping, so the child
      process didn't know about the corresponding manifest.
- sgx.sigfile:
    - probably all existing usages of it were completely redundant
    - was resolved relatively to CWD instead of the executable location,
      which made it mostly useless

From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
  matching name, or
- create a symlink to the binary in the folder where manifests are
  stored and launch it through this symlink
2020-10-23 00:06:46 +02:00
..

Nginx

This directory contains the Makefile and the template manifest for the most recent version of Nginx web server (as of this writing, version 1.16.1). This was tested on a machine with SGX v1 and Ubuntu 16.04.

The Makefile and the template manifest contain extensive comments. Please review them to understand the requirements for Nginx running under Graphene-SGX.

We build Nginx from the source code instead of using an existing installation. On Ubuntu 16.04, please make sure that the following packages are installed:

sudo apt-get install -y build-essential apache2-utils

Quick Start

# build Nginx and the final manifest
make SGX=1

# run original Nginx against a benchmark (benchmark-http.sh, uses ab)
./install/sbin/nginx -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%

# run Nginx in non-SGX Graphene against a benchmark
./pal_loader ./nginx.manifest -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%

# run Nginx in Graphene-SGX against a benchmark
SGX=1 ./pal_loader ./nginx.manifest -c conf/nginx-graphene.conf &
./benchmark-http.sh 127.0.0.1:8002
kill -SIGINT %%

# you can also test the server using other utilities like wget
wget http://127.0.0.1:8002/random/10K.1.html

Alternatively, to run the Nginx server, use one of the following commands:

make start-native-server
make start-graphene-server
make SGX=1 start-graphene-server