mirror of
https://github.com/intel/linux-sgx
synced 2026-06-08 14:49:32 +00:00
edfe42a517
Supported loading enclave at address 0. Upgraded Intel(R) Quote Verification Enclave to integrate SgxSSL/OpenSSL version 1.1.1k. Updated the DCAP driver V1.33 with stability fixes, released as V1.33.2. This is to support legacy solutions not ready to transition to the latest DCAP driver V1.41 or kernel 5.11+. Fixed bugs. Signed-off-by: Li, Xun <xun.li@intel.com>
Please, download the latest gperftools code from: https://github.com/gperftools/gperftools
The Intel(R) Software Guard Extensions (Intel(R) SGX) tcmalloc is based on gperftools-2.7 (the latest version avaialble at the release date).
Do the following to enable tcmalloc in Intel(R) SGX:
1. Copy libsgx_tcmalloc.a to the Intel(R) SGX SDK installation directory.
2. Add "-Wl,--whole-archive -lsgx_tcmalloc -Wl,--no-whole-archive" into enclave linking options in the Makefile.
For example:
Enclave_Link_Flags := $(SGX_COMMON_CFLAGS) -Wl,--no-undefined -nostdlib -nodefaultlibs -nostartfiles -L$(SGX_LIBRARY_PATH) \
-Wl,--whole-archive -l$(Trts_Library_Name) -Wl,--no-whole-archive \
-Wl,--whole-archive -lsgx_tcmalloc -Wl,--no-whole-archive \
-Wl,--start-group -lsgx_tstdc -lsgx_tcxx -l$(Crypto_Library_Name) -l$(Service_Library_Name) -Wl,--end-group \
-Wl,-Bstatic -Wl,-Bsymbolic -Wl,--no-undefined \
-Wl,-pie,-eenclave_entry -Wl,--export-dynamic \
-Wl,--defsym,__ImageBase=0 \
-Wl,--version-script=Enclave/Enclave.lds
NOTE: The flags "-Wl,--whole-archive -lsgx_tcmalloc -Wl,--no-whole-archive" must be inserted before "-Wl,--start-group -lsgx_tstdc -lsgx_tcxx -Wl,--end-group".
Otherwise, the enclave build will fail.
3. Set the enclave HeapMaxSize equal or larger than 0x900000 in Enclave.config.xml. For example:
<HeapMaxSize>0x900000</HeapMaxSize>