mirror of
https://github.com/clearlinux/graphene.git
synced 2026-08-29 14:34:03 +00:00
c0dc5fce2f
Previously, we introduced `sgx.zero_heap_on_demand` in Linux-SGX as a knob to trade off runtime degradation on memory allocations for faster enclave start-up times. This was an incorrect fix because Linux-SGX's `_DkVirtualMemoryAlloc()` always zeroess the requested memory region, so there was a double-zero of the heap at runtime. Note that LibOS layer silently assumes that `_DkVirtualMemoryAlloc()` zeroes out the memory, and many applications rely on this (Apache, Blender in my experiments). Thus, this commit keeps the zero-out in `_DkVirtualMemoryAlloc()` and removes zero-outs on enclave init and in `get_enclave_pages()`. This renders `sgx.zero_heap_on_demand` useless, so this manifest option is also removed. Also note that this commit doesn't introduce any performance degradation (in fact, now Graphene behaves as if `sgx.zero_heap_on_demand = 1` always).
Bash example
This directory contains an example for running Bash in Graphene, including the Makefile and a template for generating the manifest. The application is tested on Ubuntu 16.04, with both normal Linux and SGX platforms.
Generating the manifest
Building for Linux
Run make (non-debug) or make DEBUG=1 (debug) in the directory.
Building for SGX
Run make SGX=1 (non-debug) or make SGX=1 DEBUG=1 (debug) in the directory.
Running Bash with Graphene
Here's an example of running Bash scripts under Graphene:
Without SGX:
./pal_loader bash.manifest -c "ls"
./pal_loader bash.manifest -c "cd scripts && bash bash_test.sh 2"
With SGX:
SGX=1 ./pal_loader bash.manifest -c "ls"
SGX=1 ./pal_loader bash.manifest -c "cd scripts && bash bash_test.sh 2"