Changelogs for packages with modified content updated.
Following header files movement described:
- ADDED `sgx_dcap_constant_val.h` header (from TVL) that includes common QvE and QAE identity verification constants.
- ADDED sgx_dcap_qal_types.h header containing common QAL types extracted from sgx_dcap_qal.h that is a part of libsgx-dcap-quote-verify-dev package
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
RPM: declare `Obsoletes`/`Conflicts` on `libsgx-dcap-quote-verify-devel < 1.26` to enable clean replacement during upgrades
DEB: add `Replaces`/`Breaks` on `libsgx-dcap-quote-verify-dev (<< 1.26)` so `apt` can resolve the transition automatically
Note: the corresponding changes to the development packages were done in the commit ed8405d
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
SGX Eclipse plugin was deprecated. Removal a source code of the plugin, Eclipse projects files and settings and Eclipse Public License-v1.0 from License.txt file.
---------
Signed-off-by: Lukasz Kalica <lukasz.kalica@intel.com>
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
- Partially reverts ed8405d0fd which included
`sgx_dcap_qal.h` in `libsgx-headers` and transferred ownership of its contents
to this repository.
- The QAL API definitions are now transferred back to DCAP, where the QAL implementation
lives.
- The common structure definitions ( `tee_policy_bundle_t`, `tee_policy_auth_result_t`) which
are shared between SGX (TVL) and DCAP repositories are extracted to a new header
`sgx_dcap_qal_types.h` and kept as part of the SGX repository, with the intent
to also be included by DCAP's 'sgx_dcap_qal.h`.
Additional changes:
--------------------
- SGX SDK installer package and `libsgx-headers` DEB/RPM package's BOM changes:
1) *REMOVE* an SGX-side copy of `sgx_dcap_qal.h` (QAL APIs)
This header is still available via `libsgx-dcap-quote-verify-dev` DEB/RPM package,
matching the exported API of the corresponding `libsgx_dcap_quoteverify.so` library.
2) *ADD* `sgx_dcap_qal_types.h` (QAL types, shared with TVL)
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
Compatibility with CMake < 3.5 has been removed from CMake 3.25+. SGXSDK updated to require minimum cmake version set to 3.5. Ubuntu 26.04 switched to cmake 4.2.3 which no longer accept cmake versions lower than 3.5.
The Maintainer field in Debian packaging must follow RFC 2822 email address format.
---------
Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
SGX Protobuf version update to 33.4. Protobuf's dependency Abseil version update to 20250512.1.
---------
Signed-off-by: Anna Platasz <anna.platasz@intel.com>
SGX SDK–related attestation headers and the TVL sources originating from DCAP
tag: 'DCAP_1.25' are now relocated:
FROM: the intermediate staging area: './external/from_dcap'
(created by the '[from DCAP][move 1/2]...') commit 5b0b8e9)
INTO: their target SGX SDK repository layout.
This is a follow-on commit that places relocated files in its final locations
and updates the build system accordingly.
Additional changes:
--------------------
- `libsgx-headers` DEB/RPM package now also contains the following 2 headers:
1) sgx_qve_header.h
2) sgx_dcap_qal.h
Leveling w/ SDK - both files were part of the SDK already.
- SDK installer package now also contains the `sgx_dcap_constant_val.h` header
(from TVL), including common QvE and QAE identity verification constants.
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
Dependencies updated to be backward compatible with already supported OSes and also support 26.04
---------
Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
Remove `LE_VERSION` extraction and `LE_VER` substitution from `sgx-aesm-service` tarball creation.
Drop `LE_VER` / `LE_*` and `LAUNCH_*` version variables from installer Makefiles where they’re no longer used.
Remove `#define LE_VERSION ...` from `common/inc/internal/se_version.h`.
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Build and collect the QAE shared library (`libsgx_qae.so`) as part of the AE reproducible build.
Add a pre-run cleanup step to remove a potentially problematic WAMR-generated `version.h` on the bind-mounted tree.
Document that `--sgx-src-dir` should point to a clean source tree without prior build artifacts.
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Updated RPM spec metadata (copyright, project URL) and expanded spec changelogs to capture EPID/LE removal and recent release notes.
Updated DEB package maintainer/homepage and rewrote DEB changelogs to include EPID/LE removal plus a historical release entry.
Adjusted DEB `build.sh` version generation to use `DCAP_VERSION` and to update changelog version/date.
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Follows up on 590856d (removing the Linux LE).
Removes all of whitelist management and LE facilities from the AESM and SDK.
Leaves only skeleton API stubs behind (for partial ABI compatibility).
!BREAKING CHANGES!
- Launch-related stub(`libsgx_launch.so`) and simulation (`libsgx_launch_sim.so`) libraries
removed from the SGX SDK.
- Removed AESM support for the deprecated Linux SGX out-of-tree (OOT) driver
(will no longer attempt an enclave load if OOT driver is detected)
- AESM APIs for launch control and whitelist management will now
return SGX_ERROR_FEATURE_NOT_SUPPORTED:
Affected APIs:
* get_launch_token(...)
* sgx_get_whitelist_size(...)
* sgx_get_whitelist(...)
* sgx_register_wl_cert_chain(...)
- Deprecated `sgx_uae_launch.h` SDK header
- Marked init token inputs `reserved` in the relevant loader APIs (no longer in use)
---------
Co-authored-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
Signed-off-by: Mateusz Bronk <mateusz.bronk@intel.com>
Replaces a hardcoded versioned PDF link (2.27) with the “linux-latest” developer reference PDF link.
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Added TTY detection logic using `[ -t 0 ] && [ -t 1 ]` to determine if the script is running in an interactive environment
Refactored Docker command construction to use arrays for proper argument handling and variable expansion
Consolidated duplicate `docker run` commands into a single reusable command array
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Removed the Launch Enclave (LE) build steps
Updated paths for QE3, ID Enclave, TDQE, and QvE to their new locations under `ae/` subdirectory
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Updated copyright year from 2025 to 2026 in RPM spec files
Bumped libsgx-pce-logic and libsgx-qe3-logic minimum version requirements from 1.24 to 1.25
Updated repository homepage URL in Debian control file
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Version numbers updated from 2.27 to 2.28 across build scripts and version headers
Copyright years updated from 2025 to 2026
Repository references renamed from `intel/linux-sgx` to `intel/confidential-computing.sgx`
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Removed reference Launch Enclave implementation and related tools
Removed Launch Enclave service bundle from AESM
Updated build system to remove LE-related compilation flags and targets
Removed LE-related packages from installer scripts
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
Removed:
- Support for EPID based Attestation. Including Remote Attestation. (sgx_uae_epid.h, sgx_key_exchange.h)
- Support for Quote version 1 and 2
---------
Signed-off-by: Lukasz Juzwiuk <lukasz.a.juzwiuk@intel.com>
Unbound variables in installation scripts fixed.
Bash strict mode (-u) treats any attempt to access an unset variable as an error, causing the script to fail whenever an unset variable is found.
---------
Signed-off-by: Anna Platasz <anna.platasz@intel.com>
Updated include paths to use the new directory structure
Updated installer BOM files to reflect the new path
---------
Signed-off-by: Sebastian Przystawski <sebastian.przystawski@intel.com>
Replaced full BSD-3-Clause license text with SPDX identifier
Updated copyright year range to 2011-2025
Fixed incorrect shell variable assignment using `$pwd` instead of `$(pwd)`
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
Corrected shell syntax from `OLDDIR=$pwd` to `OLDDIR=$(pwd)` across all affected spec files
Updated copyright headers from verbose BSD-3-Clause license text to SPDX identifier format
Updated copyright year range to include 2025
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Updated Intel SGX Developer Reference documentation link from version 2.22 to 2.27
Updated DCAP repository reference from version 1.22 to 1.24 with updated repository URL
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Upgraded base Docker image from Ubuntu 20.04 to 22.04
Updated Nix installer from version 2.9.0 to 2.18.0
Added xz-utils to the list of installed packages
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Updated Nix installation URL from version 2.9.0 to 2.18.0 to meet Nixpkgs minimum requirements
---------
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
This PR fixes a dependency discrepancy for the libsgx-aesm-pce-plugin package between Debian and RPM packaging systems by adding a missing dependency.
---------
Signed-off-by: Sankaranarayanan Venkatasubramanian <sankaranarayanan.venkatasubramanian@intel.com>
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Ubuntu should be able to build RPM packages without depending on a RHEL/CentOS using rpm tools
---------
Signed-off-by: Sankaranarayanan Venkatasubramanian <sankaranarayanan.venkatasubramanian@intel.com>
In recent changes to DCAP submodule PCCS paths have been changed. This PR updates to newest submodule and adjusts paths.
---------
Signed-off-by: Pawel Krzysztof Blajer <pawel.krzysztof.blajer@intel.com>
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
Intel® Software Guard Extensions (Intel® SGX) for Linux OS includes the following changes in version 2.26:
- Upgraded to OpenSSL 3.1.6.
- Removed support for the MbedTLS Trusted Library.
- Added support for Red Hat Enterprise Linux Server 9.4 (for x86_64) and SUSE Linux Enterprise Server 15.6 64-bits.
- Added support for the FIPS 140-3 Certifiable OpenSSL Provider as an experimental feature.
- Bug fixes.
Signed-off-by: Gotowalski, Bartosz <bartosz.gotowalski@intel.com>
Upgraded to OpenSSL 3.0.14.
Upgraded Intel(R) Integrated Performance Primitives (IPP) Cryptography library to version
2021.12.1.
Supported FIPS 140-3 Certifiable IPP Crypto based Trusted Library.
Upgraded Intel SGX Architecture Enclaves based on new IPP crypto library.
Upgraded Intel DCAP Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.14.
Removed Intel DCAP PCCS from repository.
Added Ubuntu* 24.04 LTS 64-bit Server support.
Fixed bug.
Note that PCCS is not available from this release. Please follow DCAP installation guide to use
`PCCSAdminTool` to retrieve the attestation collaterals or use old version PCCS.
Signed-off-by: Li, Xun <xun.li@intel.com>
Upgraded to OpenSSL 3.0.13.
Upgraded to Intel(R) Integrated Performance Primitives (IPP) Cryptography library
version 2021.11.
Upgraded to Protobuf 3.23.2.
Upgraded MbedTLS to 3.5.2.
Upgraded Intel DCAP Ring3 Abstraction Layer (R3AAL) library to support ConfigFS-TSM
as communication channel between host and guest for TDX remote attestation.
Upgraded Intel DCAP Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.13.
Upgraded new TDX attestation result “TD_RELAUNCH_ADVISED” in Intel DCAP Quote
Verification Library (QVL) and Appraisal Engine.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Upgraded to OpenSSL 3.0.10.
Added interoperable RA-TLS support which follows CCC design.
Enhanced Protect File System performance and added additional dependency
`libsgx_pthread.a`.
Added the Constant Time instruction Decoder (CTD) into the default AEX-Notify
mitigation handler in order to prevent the introduction of any additional
subtle sidechannel leakages within the default handler.
Added Mistletoe 3 mitigations to the IPP Cryptography Library to the AES-ECB,
AESGCM, and AES-CMAC algorithms. These have been incorporated transparently
into the `sgx_tcrypto` library.
Resigned all Intel® SGX Architecture Enclaves.
Upgraded Intel SGX Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.10.
Added Attestation Library support for Intel(R) TDX Migration TD.
Added Rust wrapper for low-level Quote Generation APIs.
Enabled `SE_TRACE` log in release binary.
Updated Rust QVL wrapper to use native Rust structure for quote verification
collateral.
Added a limitation in the DCAP QVL to only allow the user to set the QvE load
policy once.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Supported the AEX (Asynchronous Enclave Exit) Notify feature.
Supported Mbed-TLS Cryptography library (excluding SSL/TLS portion) in Enclave.
Applied patches to OpenSSL 1.1.1t, fixed CVE-2023-1255, CVE-2023-0465 and
CVE-2023-0466.
Upgraded to Intel(R) Integrated Performance Primitives (IPP) Cryptography
library version 2021.7.
Upgraded Intel SGX Quote Verification Enclave to integrate updated SgxSSL.
Enhanced the attestation local cache functionality by giving users the option
to provide their own cache file.
Enabled QPL/QCNL log in DCAP samples.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Supported the Key Separation and Sharing (KSS) feature in Simulation mode.
Upgraded to OpenSSL 1.1.1t.
Upgraded Intel(R) SGX Quote Verification Enclave to integrate SgxSSL/OpenSSL
version 1.1.1t.
Added new API in quote verification library to extract FMSPC
(Family-Model-SteppingPlatform-CustomSKU) value from ECDSA quote.
Added Rust support for SGX ECDSA quote generation.
Added Linux kernel 5.19 support in TDX R3AAL (Ring 3 Attestation Abstraction Layer).
Removed Protobuf in TDX QGS (Quote Generation Service) and R3AAL (Ring 3
Attestation Abstraction Layer).
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Along with the latest processor microcode address CVE-2022-21233.
Modified the Switchless library to have mitigations for the associated issue.
Added support for the Linux kernel APIs for the Enclave Dynamic Memory
Management (EDMM) features that are available with the Linux kernel v6.0 or
later. Refer to the SGX SDK developer reference for details on new trusted
APIs and enclave configuration for the EDMM features.
Enabled C++17 within SGX SDK.
Supported AMX (Advanced Matrix Extensions) in Enclave.
Replace hardcoded Enclave signing keys in all sample projects with dynamically
generated keys.
Added a new API to allow user to configure enclave internal cache size in the
Protected File System library.
Upgraded to OpenSSL 1.1.1q and upgraded Intel(R) SGX Quote Verification Enclave
to integrate SgxSSL/OpenSSL version 1.1.1q.
Supported new OS: Ubuntu* 22.04 LTS 64-bit Server version, CentOS* 8.3 64bits,
Red Hat* Enterprise Linux* Server 8.6 (for x86_64), SUSE* Linux* Enterprise
Server 15.4 64bits, Debian* 10 and Anolis* OS 8.6.
Upgraded Intel SGX QE3 to make it backward compatible.
Improved ECDSA quote generation and verification performance by caching PCK
certificates and collaterals in memory and disk drive.
Added Java support for quote verification library.
Added new APIs to unify Intel SGX and TDX quote verification in Quote
Verification Library.
Added Advisory ID in ECDSA quote verification supplemental data.
Added Intel TDX support in RA-TLS (Remote Attestation based TLS) library.
Improved TDX quote generation throughput in vsock mode.
Added Rust support for TDX quote generation.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
According to the spec [1], the scriptlet %post of a new package executes
before %preun of the old package.
This will cause the startup.sh of the new package to be executed first,
and then the cleanup.sh of the old package to be executed when
sgx-aesm-service is upgraded, and the user aesmd will be deleted,
which leading aesmd booting error.
Replace %post with %posttrans to make sure the prerequisites for service
aesmd are met.
[1]. https://docs.fedoraproject.org/en-US/packaging-guidelines/Scriptlets/
Signed-off-by: yuguorui <yuguorui@pku.edu.cn>
Along with the latest processor microcode and re-signed all the Intel(R) SGX
Architecture Enclaves (AEs) to address CVE-2022-21123, CVE-2022-21125 and
CVE-2022-21166.
Upgraded to Protobuf 3.20.
Upgraded to SgxSSL/OpenSSL 1.1.1o.
Added Intel TDX Attestation support.
Added Rust support for ECDSA quote verification.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>