Commit Graph

501 Commits

Author SHA1 Message Date
Mateusz Bronk 4ff6da403e Add PCS Client Tool to offline repo packaging make targets
Follow-up of upstream DCAP repo change which added `intel-tee-pcs-client-tool-*{.deb|.rpm}` packages.
Adds corresponding build targets to the top-level `Makefile` (the package is now included in the "local repo" archive).

---------

Signed-off-by: Mateusz Bronk <mateusz.bronk@intel.com>
2025-10-09 11:25:25 +02:00
CC Auto-merge[bot] 2a2a438d0e Auto-merge changes from main branch
Signed-off-by: CC Auto-merge[bot] <sys_cc1s_pr_merge_bot@intel.com>
2025-10-08 19:22:46 +02:00
Bartosz Gotowalski 342c8d0f03 Bump CXX Standard for AESM Service from 14 to 17
Bumped C++ standard from 14 to 17 in the CMake configuration to enable newer OSes

---------

Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
2025-10-08 19:21:27 +02:00
Sankaranarayanan Venkatasubramanian 8565811d90 Fixes RPM build in Ubuntu environments by replacing bash-specific pushd/popd commands with POSIX-compatible cd commands in RPM spec files
Ubuntu should be able to build RPM packages without depending on a RHEL/CentOS using rpm tools

---------

Signed-off-by: Sankaranarayanan Venkatasubramanian <sankaranarayanan.venkatasubramanian@intel.com>
2025-10-08 13:58:01 +02:00
Paweł Blajer 5fa1969c0b Updates the DCAP submodule after moving PCCS to a new submodule
Updates the DCAP submodule to a new commit after separating PCCS Admin Tool (into PCCS Admin Tool and PCS Client Tool), moving PCCS related files to a new repository and linking that repository to DCAP repo via submodule.

---------

Signed-off-by: Pawel Krzysztof Blajer <pawel.krzysztof.blajer@intel.com>
2025-10-06 15:43:56 +02:00
Krzysztof Sandowicz 2f6caabc70 Removes SGX white list functionality from the AESM service by eliminating all references to the white list URL configuration and related network operations. Allow list updated as standalone bin file
Removes `SGX_WHITE_LIST_FILE` enum value and associated URL handling
Eliminates white list configuration parsing and storage
Removes the `update_white_list_by_url()` function and related network operations

---------

Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
2025-09-30 10:49:14 +02:00
gklodkox bde9b196f9 Bump CXX Standard for AESM Service to 17 and DCAP to include -lpthread flag for GTEST
* Bumped C++ standard from 14 to 17 in the CMake configuration
* Updated DCAP source submodule to a newer commit with -lpthread flag for GTEST

---------

Signed-off-by: GracjanX Klodkowski <gracjanx.klodkowski@intel.com>
2025-09-29 16:33:57 +02:00
Paweł Blajer bc92465dce Update dcap submodule and adjust paths to PCCS
In recent changes to DCAP submodule PCCS paths have been changed. This PR updates to newest submodule and adjusts paths.

---------

Signed-off-by: Pawel Krzysztof Blajer <pawel.krzysztof.blajer@intel.com>
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
2025-09-26 16:19:41 +02:00
Krzysztof Sandowicz 519387ff81 Improves logging output by extracting just the filename from the full file path in log messages
Adds a cross-platform filename extraction macro that works with both Unix and Windows path separators
Updates production logging to use the cleaner filename format instead of full file paths
Updates the dcap_source submodule to a newer commit

---------

Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
2025-09-25 12:47:23 +02:00
Krzysztof Sandowicz 209df334b7 Updates the DCAP (Data Center Attestation Primitives) submodule to a newer commit, advancing from commit 497c8163d7960bd5a4f3a4dff8de8c4ab544c518 to 75900b8ac91e1feede9737538e176449a1e73fca
Updates DCAP submodule reference to a newer commit

---------

Signed-off-by: Krzysztof Sandowicz <krzysztof.sandowicz@intel.com>
2025-09-23 07:52:49 +02:00
Bartosz Gotowalski 75fdef7bdb Set DCAP submodule to track the same branch as the current repository
Configure the dcap_source submodule to track the same branch as the current repository instead of being pinned to the main branch

---------

Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
2025-09-22 16:34:03 +02:00
CC Auto-merge[bot] a62ab92bbb Auto-merge changes from main branch
Signed-off-by: CC Auto-merge[bot] <sys_cc1s_pr_merge_bot@intel.com>
2025-09-15 16:09:37 +02:00
Bartosz Gotowalski 53ad2c9fa2 Added "event emitter" workflow (GHA extension point) and CODEOWNERS
The workflow is dormant (skipped) by default (due to env var setting),
but can be enabled on select forks, allowing to intercept branch events
and run additional CI/CD tasks which are external to this repository.

Signed-off-by: Mateusz Bronk <mateusz.bronk@intel.com>
2025-09-15 15:09:55 +02:00
Bartosz Gotowalski fd34b0fe6c Bump DCAP to include OpenSSL 3.0.17 in SSL preparation scripts
Signed-off-by: Gotowalski, Bartosz <bartosz.gotowalski@intel.com>
2025-09-11 09:23:28 +02:00
Bartosz Gotowalski f2318033ca Update DCAP submodule for multiple updates
Several updates in DCAP submodule:
* Removing strip operation as debug info is later stripped while creating deb/rpm prod, dev and debug packages
* Bump brace-expansion from 1.1.11 to 1.1.12 in /QuoteGeneration/pccs
* Bump on-headers and morgan in /QuoteGeneration/pccs
* Bump tar-fs from 2.1.2 to 2.1.3 in /QuoteGeneration/pccs
* Update dcap components nuget License.txt to match Intel Simplified Software License (Version October 2022)
* Fix to ensure safe path buffer operations.
* Platform Manifest buffer limited to 256KB for PCKRetrievalTool
* Fixed paths to WDK
* Added fixes to building sgxssl.cmd
* Admin tools inf packaging process updated. Switched to latest prebuilt AE.
* Added path to libsgx_usgxssl

Signed-off-by: Gotowalski, Bartosz <bartosz.gotowalski@intel.com>
2025-09-01 10:03:01 +02:00
Jessica Marz 90873a0c98 Merge pull request #1088 from intel/jkmarz-patch-1
Update pthread.h license info
2025-07-30 08:27:15 -07:00
Jessica Marz 7e96a23957 Update pthread.h 2025-07-29 15:32:23 -07:00
Pawel Drzycimski 6ce4f4ad0e Basic fixes to make SGX Linux build on GCC14 used by CentOS10
Signed-off-by: Pawel Drzycimski <pawel.drzycimski@intel.com>
2025-07-29 13:18:14 +02:00
krzyszt1 812fa20961 DCAP source updated to fix .so libraries names.
Signed-off-by: Krzysztof Wisniewski <krzysztof1.wisniewski@intel.com>
2025-07-22 12:26:18 +02:00
krzyszt1 b6ec7a4253 Makefile fix for admin tool build path
Signed-off-by: Krzysztof Wisniewski <krzysztof1.wisniewski@intel.com>
2025-07-14 15:46:35 +02:00
Krzysztof Wisniewski 6e6608cb43 Bump DCAP source version
Signed-off-by: Krzysztof Wisniewski <krzysztof1.wisniewski@intel.com>
2025-07-09 15:36:44 +02:00
Bartosz Gotowalski 23ea18b32e Switching submodule path from absolute to relative for external/dcap_source
Signed-off-by: Bartosz Gotowalski <bartosz.gotowalski@intel.com>
2025-07-09 14:12:15 +02:00
Bartosz Gotowalski be829176f8 Update DCAP submodule to version with fixed SSL preparation scripts
Signed-off-by: Gotowalski, Bartosz <bartosz.gotowalski@intel.com>
2025-06-12 16:14:02 +02:00
Bartosz Gotowalski 8e9ed532cc Linux 2.26 Open Source Gold Release
Intel® Software Guard Extensions (Intel® SGX) for Linux OS includes the following changes in version 2.26:
- Upgraded to OpenSSL 3.1.6.
- Removed support for the MbedTLS Trusted Library.
- Added support for Red Hat Enterprise Linux Server 9.4 (for x86_64) and SUSE Linux Enterprise Server 15.6 64-bits.
- Added support for the FIPS 140-3 Certifiable OpenSSL Provider as an experimental feature.
- Bug fixes.

Signed-off-by: Gotowalski, Bartosz <bartosz.gotowalski@intel.com>
sgx_2.26
2025-05-30 14:54:34 +02:00
Li Xun 7385e10ce1 Correct ipp-crypto submodule branch name (#1060)
Only change branch name displayed in `.gitmodules`.
No change to submodule commit or source code.

Signed-off-by: Li, Xun <xun.li@intel.com>
2024-10-08 10:13:33 +08:00
Li Xun d5a2c9cf69 Fix broken link in README (#1054)
Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.25
2024-09-27 18:30:14 +08:00
Li, Xun 9fafc27e8f Linux 2.25 Open Source Gold Release
Upgraded to OpenSSL 3.0.14.
Upgraded Intel(R) Integrated Performance Primitives (IPP) Cryptography library to version
  2021.12.1.
Supported FIPS 140-3 Certifiable IPP Crypto based Trusted Library.
Upgraded Intel SGX Architecture Enclaves based on new IPP crypto library.
Upgraded Intel DCAP Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.14.
Removed Intel DCAP PCCS from repository.
Added Ubuntu* 24.04 LTS 64-bit Server support.
Fixed bug.

Note that PCCS is not available from this release. Please follow DCAP installation guide to use
`PCCSAdminTool` to retrieve the attestation collaterals or use old version PCCS.

Signed-off-by: Li, Xun <xun.li@intel.com>
2024-09-26 15:34:56 +08:00
Sharzy c1ceb4fe14 Fix misused tabs in Makefiles (#1018)
Signed-off-by: SharzyL <me@sharzy.in>
2024-07-02 08:49:57 +08:00
Jo Van Bulck 29321db180 Fix assembler call frame information (CFI) directives
Current macros emit an ENDBR instruction between the function label and
corresponding cfi_start, which confuses binary analysis tools like llvm-bolt.

Also add missing cfi_start/end directives for other assembly functions.

See also: https://sourceware.org/binutils/docs/as/CFI-directives.html

Signed-off-by: Jo Van Bulck <jo.vanbulck@cs.kuleuven.be>
2024-06-03 12:47:00 +08:00
Zhang, Lili Z d1c3b8a70d Fix Debian 12 build.
Signed-off-by: Zhang, Lili Z <lili.z.zhang@intel.com>
2024-05-30 08:47:41 +08:00
He, Jing J 80a6625c49 add action scripts
Signed-off-by: He, Jing J <jing.j.he@intel.com>
2024-05-06 10:48:09 +08:00
Li, Xun a53adeaab7 Linux 2.24 Open Source Gold Release
Upgraded to OpenSSL 3.0.13.
Upgraded to Intel(R) Integrated Performance Primitives (IPP) Cryptography library
  version 2021.11.
Upgraded to Protobuf 3.23.2.
Upgraded MbedTLS to 3.5.2.
Upgraded Intel DCAP Ring3 Abstraction Layer (R3AAL) library to support ConfigFS-TSM
  as communication channel between host and guest for TDX remote attestation.
Upgraded Intel DCAP Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.13.
Upgraded new TDX attestation result “TD_RELAUNCH_ADVISED” in Intel DCAP Quote
  Verification Library (QVL) and Appraisal Engine.
Fixed bugs.

Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.24
2024-04-26 15:24:15 +08:00
Zhang Lili 05851b21a1 Update reproducible README to add the links of AEs' README files.
Signed-off-by: Zhang Lili <lili.z.zhang@intel.com>
2024-04-03 16:47:17 +08:00
Zhang Lili 3e65daae2c Update LE XML files.
Signed-off-by: Zhang Lili <lili.z.zhang@intel.com>
2024-04-03 16:47:17 +08:00
Li, Xun 242644c777 Update external/dcap_source submodule
Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.23
2024-01-18 15:19:20 +08:00
Li, Xun cd6c2a8b81 Linux 2.23 Open Source Gold Release
Supported new OS: Ubuntu* 23.10 64-bit Server version.
Upgraded to OpenSSL 3.0.12.
Upgraded MbedTLS to 3.5.0.
Added SM2 encrypt/decrypt algorithm to the GM/SM (PRC National Commercial
  Cryptographic Algorithms) sample code.
Introduced the Intel® DCAP Appraisal Engine within quote verification library,
  empowering users to evaluate verification results against diverse policies.
Upgraded Intel SGX Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.12.
Added Rust wrapper for quote provider library APIs.
Fixed bugs.

Signed-off-by: Li, Xun <xun.li@intel.com>
2024-01-17 16:33:35 +08:00
Li, Xun 8a22317709 Linux 2.22 Open Source Gold Release
Upgraded to OpenSSL 3.0.10.
Added interoperable RA-TLS support which follows CCC design.
Enhanced Protect File System performance and added additional dependency
  `libsgx_pthread.a`.
Added the Constant Time instruction Decoder (CTD) into the default AEX-Notify
  mitigation handler in order to prevent the introduction of any additional
  subtle sidechannel leakages within the default handler.
Added Mistletoe 3 mitigations to the IPP Cryptography Library to the AES-ECB,
  AESGCM, and AES-CMAC algorithms. These have been incorporated transparently
  into the `sgx_tcrypto` library.
Resigned all Intel® SGX Architecture Enclaves.
Upgraded Intel SGX Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.10.
Added Attestation Library support for Intel(R) TDX Migration TD.
Added Rust wrapper for low-level Quote Generation APIs.
Enabled `SE_TRACE` log in release binary.
Updated Rust QVL wrapper to use native Rust structure for quote verification
  collateral.
Added a limitation in the DCAP QVL to only allow the user to set the QvE load
  policy once.
Fixed bugs.

Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.22
2023-10-24 11:05:23 +08:00
Scott Constable 8be98b1acb Added a constant-time instruction decoder to supplement the default AEX-Notify mitigation. (#960)
Added a constant-time instruction decoder to supplement the default AEX-Notify mitigation.

Signed-off-by: Scott Constable <scott.d.constable@intel.com>
2023-10-20 14:38:23 +08:00
Michael Spiegel f656e74afd Fix memory leak in sign_tool.cpp (#971)
Ownership of the parser is transferred from measure_enclave() to load_enclave(). load_enclave() passes the parser by reference to the CLoader constructor. CLoader cannot be responsible for deleting the parser. The parser must be deleted at the end of load_enclave().

Signed-off-by: Michael Spiegel <michael.m.spiegel@gmail.com>
2023-09-05 14:59:20 +08:00
Zhang, Lili Z f47d0e5a01 Linux 2.21 Open Source Gold Release
Upgraded to OpenSSL 1.1.1u.
Introduced Intel(R) TDX 1.4 and 1.5 support
Upgraded Ring3 Abstraction Layer (R3AAL) library to support
Intel(R) TDX MVP 6.2 kernel
Enhanced quote verification performance in multi-thread scenarios
Fixed bugs.

Signed-off-by: Zhang, Lili Z <lili.z.zhang@intel.com>
sgx_2.21
2023-08-22 10:10:14 +08:00
lzha101 a1eeccba5a Update AEX-Notify default handler. (#959)
Signed-off-by: Zhang, Lili Z <lili.z.zhang@intel.com>
2023-08-04 14:33:48 +08:00
Camila Fonseca 4b888cda73 Fixed minor typo in key definitions (#951)
* Fixed minor typo in sgx_tseal.h and key definitions.

---------

Signed-off-by: Camila Fonseca inrymail@gmail.com
2023-07-21 14:45:09 +08:00
henrywang8atfbdotcom bf9990776d Do traditional Ocall if g_uswitchless_handle is uninitialized
Global object initialization (init_global_object) happens before
g_uswitchless_handle is initialized (via sl_init_switchless).
Some ctors invoke syscalls via switchless ocalls. This causes
init_tswitchless_ocall_mngr to be invoked with sl_call_once
prematurely, returning -1. Subsequent invokations will always return -1, such
that switchless ocalls never happen. A simple solution is to fallback
to traditional ocalls until g_uswitchless_handle has been
initialized.
2023-07-21 14:42:34 +08:00
Li, Xun e7bbc158fa Linux 2.20 Open Source Gold Release
Supported the AEX (Asynchronous Enclave Exit) Notify feature.
Supported Mbed-TLS Cryptography library (excluding SSL/TLS portion) in Enclave.
Applied patches to OpenSSL 1.1.1t, fixed CVE-2023-1255, CVE-2023-0465 and
  CVE-2023-0466.
Upgraded to Intel(R) Integrated Performance Primitives (IPP) Cryptography
  library version 2021.7.
Upgraded Intel SGX Quote Verification Enclave to integrate updated SgxSSL.
Enhanced the attestation local cache functionality by giving users the option
  to provide their own cache file.
Enabled QPL/QCNL log in DCAP samples.
Fixed bugs.

Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.20
2023-07-21 10:11:26 +08:00
lingyuji 1efe23c20e Add support for AESM command line option --supported_attestation_types
Signed-off-by: lingyuji <lingyu.jiang@intel.com>
2023-04-06 14:50:06 +08:00
volcano 33a1ec185f Fix integer overflow bug
Signed-off-by: volcano <volcano_dr@163.com>
2023-04-03 15:12:53 +08:00
Costy Blokh 0471aaef86 enable atomic operations in std::shared_ptr 2023-03-30 11:01:18 +08:00
volcano0dr d3fd8b4511 Fix wrong parameter when calling mm_dealloc
Signed-off-by: volcano0dr <volcano_dr@163.com>
2023-03-16 16:34:00 +08:00
Li, Xun 1bf092a389 Linux 2.19 Open Source Gold Release
Supported the Key Separation and Sharing (KSS) feature in Simulation mode.
Upgraded to OpenSSL 1.1.1t.
Upgraded Intel(R) SGX Quote Verification Enclave to integrate SgxSSL/OpenSSL
  version 1.1.1t.
Added new API in quote verification library to extract FMSPC
  (Family-Model-SteppingPlatform-CustomSKU) value from ECDSA quote.
Added Rust support for SGX ECDSA quote generation.
Added Linux kernel 5.19 support in TDX R3AAL (Ring 3 Attestation Abstraction Layer).
Removed Protobuf in TDX QGS (Quote Generation Service) and R3AAL (Ring 3
  Attestation Abstraction Layer).
Fixed bugs.

Signed-off-by: Li, Xun <xun.li@intel.com>
sgx_2.19
2023-03-10 09:06:21 +08:00
Andy Zhao d5e10dfbd7 Merge pull request #931 from intel/update_license
Update license of Intel signed architecture enclaves
2023-01-13 19:21:09 +08:00