The ce_cdefs header defines SE_64, which this source file depends on.
When building with clang, this missing header causes the build to break.
Signed-off-by: Dionna Glaze <drdeeglaze@gmail.com>
CONFIGURATION_NEEDED Flag is added to Platform Info Blob TLV (version 2). Current implementation is based on version 1.
Signed-off-by: Li, Xun <xun.li@intel.com>
Added support for Reproducible Enclave Build using Docker file.
Added support for Intel AVX-512 instructions and Intel SHA Extensions New Instructions (SHA-NI) in trusted libraries.
Support both EPID and ECDSA based quote for quoting related interfaces in sgx_uae_service library.
Updated key exchange library to support both EPID and ECDSA based remote attestation.
Support new interface to check platform information blob from remote attestation response message.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
The headers for all rdrand sources reference 3-clause BSD, and the Intel
Sample Source Code License is almost assuredly too restrictive. For one,
the license restricts the platform to Windows, which this project does
not support.
Signed-off-by: Dionna Glaze <dionnaglaze@google.com>
Added new APIs in sgx_uae_service.h and sgx_ukey_exchange.h to support ECDSA quote based remote attestation.
The set of legacy APIs supports EPID only and the set of new APIs supports ECDSA quotes.
Enhanced Edger8r with structure deep-copy feature.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
When there are spaces in the ROOT_DIR, some make targets fail because
paths are not properly quoted:
-----------------------------------------------------------------------
$ make -C sdk/ USE_OPT_LIBS=1
make[1]: Entering directory '/home/ao2/dir with spaces/linux-sgx/sdk'
Makefile.opt_lib:133: warning: overriding recipe for target '/home/ao2/dir'
Makefile.opt_lib:88: warning: ignoring old recipe for target '/home/ao2/dir'
Makefile.opt_lib:133: warning: overriding recipe for target 'with'
Makefile.opt_lib:88: warning: ignoring old recipe for target 'with'
...
ERROR: Please run 'download_prebuilt.sh' to download the prebuilt optimized libraries before compiling.
Exiting......
/bin/sh: 1: exit: Illegal number: -2
make[1]: *** [Makefile:49: opt_check_failed] Error 2
make[1]: Leaving directory '/home/ao2/dir with spaces/linux-sgx/sdk'
make: *** [Makefile:41: sdk] Error 2
-----------------------------------------------------------------------
Instead of fixing all the occurrences of the problem, just refuse to
build when there are spaces or colons in the build path.
This is also what kbuild in the linux kernel does:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Makefile?h=v5.0#n126
The meaning of 'static' is to make a symbol private to the source
file, whereas 'extern "C"' is meant for linking symbols across
files with an unmangled name. The combination of the two allowed
by GCC is non-standard.
Signed-off-by: Dionna Glaze <dionnaglaze@google.com>
The templated "storage" field in randomly_placed_buffer is uses alignas
in an undefined way. The field is also not used, so this change removes
it.
Signed-off-by: Dionna Glaze <dionnaglaze@google.com>
In 2.4.0, sgx_report_attestation_status always returns SGX_ERROR_INVALID_PARAMETER due to oal_map_result returns AESM_PLATFORM_INFO_BLOB_INVALID_SIG. The problem is caused by a change in u_certificate_provisioning.cpp, removing essential endian conversion. This commit aims at reverting this change and making sgx_report_attestation_status works again.
One test case on my testbed: 1502006500000800000202020401800000000000000000000007000006000000020000000000000B0D292FE7F0F37C075567E227A454318D29A3E94F035693794FADECD6C31606DE989858BF7FB718A096B52A90EFCD50270C9A0A2F4500CFAC159DD44EAA2C014179
Signed-off-by: Yu Ding <dingelish@gmail.com>
Added support for the Key Separation and Sharing (KSS) feature.
Provided a set of new encryption and decryption functions such as sgx_hmac256_*.
Provided a new untrusted API: sgx_get_target_info.
Provided a new untrusted API: sgx_create_enclave_from_buffer_ex.
Updated the cryptography library and Architecture Enclaves to use Intel(R) Integrated
Performance Primitives Cryptography 2019 Update 1.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>