2020-01-21 18:14:27 +03:00
|
|
|
# Copyright (c) Microsoft Corporation. All rights reserved.
|
|
|
|
# Licensed under the Apache 2.0 License.
|
|
|
|
|
|
|
|
set(ALLOWED_TARGETS "sgx;virtual")
|
2020-03-25 17:50:30 +03:00
|
|
|
|
|
|
|
set(COMPILE_TARGETS
|
|
|
|
"sgx;virtual"
|
|
|
|
CACHE
|
|
|
|
STRING
|
|
|
|
"List of target compilation platforms. Choose from: ${ALLOWED_TARGETS}"
|
|
|
|
)
|
|
|
|
|
2020-01-21 18:14:27 +03:00
|
|
|
set(IS_VALID_TARGET "FALSE")
|
2020-03-25 17:50:30 +03:00
|
|
|
foreach(REQUESTED_TARGET ${COMPILE_TARGETS})
|
2020-01-28 21:09:42 +03:00
|
|
|
if(${REQUESTED_TARGET} IN_LIST ALLOWED_TARGETS)
|
2020-01-21 18:14:27 +03:00
|
|
|
set(IS_VALID_TARGET "TRUE")
|
|
|
|
else()
|
2020-01-28 21:09:42 +03:00
|
|
|
message(
|
|
|
|
FATAL_ERROR
|
|
|
|
"${REQUESTED_TARGET} is not a valid target. Choose from: ${ALLOWED_TARGETS}"
|
|
|
|
)
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
|
|
|
endforeach()
|
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
if((NOT ${IS_VALID_TARGET}))
|
|
|
|
message(
|
|
|
|
FATAL_ERROR
|
2020-03-25 17:50:30 +03:00
|
|
|
"Variable list 'COMPILE_TARGETS' must include at least one supported target. Choose from: ${ALLOWED_TARGETS}"
|
2020-01-28 21:09:42 +03:00
|
|
|
)
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
|
|
|
|
2020-07-27 16:05:38 +03:00
|
|
|
# Find OpenEnclave package
|
2021-07-13 23:00:18 +03:00
|
|
|
find_package(OpenEnclave 0.17.1 CONFIG REQUIRED)
|
2020-03-25 17:50:30 +03:00
|
|
|
# As well as pulling in openenclave:: targets, this sets variables which can be
|
|
|
|
# used for our edge cases (eg - for virtual libraries). These do not follow the
|
|
|
|
# standard naming patterns, for example use OE_INCLUDEDIR rather than
|
|
|
|
# OpenEnclave_INCLUDE_DIRS
|
2020-12-11 17:55:57 +03:00
|
|
|
set(OE_CRYPTO_LIB
|
|
|
|
mbedtls
|
|
|
|
CACHE STRING "Crypto library used by enclaves."
|
|
|
|
)
|
2020-03-25 17:50:30 +03:00
|
|
|
|
2021-01-08 15:47:22 +03:00
|
|
|
set(OE_TARGET_LIBC openenclave::oelibc)
|
|
|
|
set(OE_TARGET_ENCLAVE_AND_STD
|
|
|
|
openenclave::oeenclave openenclave::oecryptombedtls openenclave::oelibcxx
|
|
|
|
openenclave::oelibc openenclave::oecryptoopenssl
|
|
|
|
)
|
|
|
|
# These oe libraries must be linked in specific order
|
|
|
|
set(OE_TARGET_ENCLAVE_CORE_LIBS
|
|
|
|
openenclave::oeenclave openenclave::oecryptombedtls openenclave::oesnmalloc
|
|
|
|
openenclave::oecore openenclave::oesyscall
|
|
|
|
)
|
|
|
|
|
2020-07-31 11:02:47 +03:00
|
|
|
option(LVI_MITIGATIONS "Enable LVI mitigations" ON)
|
2020-07-28 13:56:45 +03:00
|
|
|
if(LVI_MITIGATIONS)
|
2021-01-08 15:47:22 +03:00
|
|
|
string(APPEND OE_TARGET_LIBC -lvi-cfg)
|
|
|
|
list(TRANSFORM OE_TARGET_ENCLAVE_AND_STD APPEND -lvi-cfg)
|
|
|
|
list(TRANSFORM OE_TARGET_ENCLAVE_CORE_LIBS APPEND -lvi-cfg)
|
2020-07-31 11:02:47 +03:00
|
|
|
endif()
|
|
|
|
|
|
|
|
function(add_lvi_mitigations name)
|
|
|
|
if(LVI_MITIGATIONS)
|
|
|
|
apply_lvi_mitigation(${name})
|
|
|
|
endif()
|
|
|
|
endfunction()
|
|
|
|
|
|
|
|
if(LVI_MITIGATIONS)
|
|
|
|
install(FILES ${CMAKE_CURRENT_LIST_DIR}/lvi/lvi_mitigation_config.cmake
|
|
|
|
DESTINATION cmake/lvi
|
|
|
|
)
|
|
|
|
install(
|
|
|
|
FILES ${CMAKE_CURRENT_LIST_DIR}/lvi/configure_lvi_mitigation_build.cmake
|
|
|
|
DESTINATION cmake/lvi
|
|
|
|
)
|
|
|
|
install(FILES ${CMAKE_CURRENT_LIST_DIR}/lvi/apply_lvi_mitigation.cmake
|
|
|
|
DESTINATION cmake/lvi
|
|
|
|
)
|
|
|
|
|
2020-07-28 13:56:45 +03:00
|
|
|
# Also pull in the LVI mitigation wrappers
|
2020-07-31 11:02:47 +03:00
|
|
|
include(${CMAKE_CURRENT_LIST_DIR}/lvi/lvi_mitigation_config.cmake)
|
2020-07-28 13:56:45 +03:00
|
|
|
endif()
|
|
|
|
|
2020-01-21 18:14:27 +03:00
|
|
|
# Sign a built enclave library with oesign
|
|
|
|
function(sign_app_library name app_oe_conf_path enclave_sign_key_path)
|
2020-06-23 12:10:22 +03:00
|
|
|
cmake_parse_arguments(PARSE_ARGV 1 PARSED_ARGS "" "" "INSTALL_LIBS")
|
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
if(TARGET ${name})
|
2020-04-22 13:51:40 +03:00
|
|
|
# Produce a debuggable variant. This doesn't need to be signed, but oesign
|
|
|
|
# also stamps the other config (heap size etc) which _are_ needed
|
|
|
|
set(DEBUG_CONF_NAME ${CMAKE_CURRENT_BINARY_DIR}/${name}.debuggable.conf)
|
|
|
|
|
|
|
|
add_custom_command(
|
|
|
|
OUTPUT ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.debuggable
|
2021-04-08 18:47:20 +03:00
|
|
|
# Copy conf file locally
|
|
|
|
COMMAND cp ${app_oe_conf_path} ${DEBUG_CONF_NAME}
|
|
|
|
# Remove any existing Debug= lines
|
|
|
|
COMMAND sed -i "/^Debug=\.*/d" ${DEBUG_CONF_NAME}
|
|
|
|
# Add Debug=1 line
|
|
|
|
COMMAND echo "Debug=1" >> ${DEBUG_CONF_NAME}
|
2020-07-31 11:02:47 +03:00
|
|
|
COMMAND
|
2021-04-08 18:47:20 +03:00
|
|
|
openenclave::oesign sign -e ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so -c
|
|
|
|
${DEBUG_CONF_NAME} -k ${enclave_sign_key_path} -o
|
|
|
|
${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.debuggable
|
2020-06-23 14:13:08 +03:00
|
|
|
DEPENDS ${name} ${app_oe_conf_path} ${enclave_sign_key_path}
|
2020-04-22 13:51:40 +03:00
|
|
|
)
|
|
|
|
|
|
|
|
add_custom_target(
|
|
|
|
${name}_debuggable ALL
|
|
|
|
DEPENDS ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.debuggable
|
|
|
|
)
|
|
|
|
|
|
|
|
# Produce a releaseable signed variant. This is NOT debuggable - oegdb
|
|
|
|
# cannot be attached
|
|
|
|
set(SIGNED_CONF_NAME ${CMAKE_CURRENT_BINARY_DIR}/${name}.signed.conf)
|
2020-01-21 18:14:27 +03:00
|
|
|
add_custom_command(
|
|
|
|
OUTPUT ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.signed
|
2021-04-08 18:47:20 +03:00
|
|
|
# Copy conf file locally
|
|
|
|
COMMAND cp ${app_oe_conf_path} ${SIGNED_CONF_NAME}
|
|
|
|
# Remove any existing Debug= lines
|
|
|
|
COMMAND sed -i "/^Debug=\.*/d" ${SIGNED_CONF_NAME}
|
|
|
|
# Add Debug=0 line
|
|
|
|
COMMAND echo "Debug=0" >> ${SIGNED_CONF_NAME}
|
2020-01-28 21:09:42 +03:00
|
|
|
COMMAND
|
|
|
|
openenclave::oesign sign -e ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so -c
|
2020-04-22 13:51:40 +03:00
|
|
|
${SIGNED_CONF_NAME} -k ${enclave_sign_key_path}
|
2020-06-23 14:13:08 +03:00
|
|
|
DEPENDS ${name} ${app_oe_conf_path} ${enclave_sign_key_path}
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
add_custom_target(
|
|
|
|
${name}_signed ALL
|
2020-01-21 18:14:27 +03:00
|
|
|
DEPENDS ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.signed
|
|
|
|
)
|
2020-06-23 12:10:22 +03:00
|
|
|
|
|
|
|
if(${PARSED_ARGS_INSTALL_LIBS})
|
|
|
|
install(FILES ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.debuggable
|
|
|
|
DESTINATION lib
|
|
|
|
)
|
|
|
|
install(FILES ${CMAKE_CURRENT_BINARY_DIR}/lib${name}.so.signed
|
|
|
|
DESTINATION lib
|
|
|
|
)
|
|
|
|
endif()
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
|
|
|
endfunction()
|
|
|
|
|
2020-01-28 17:06:12 +03:00
|
|
|
# Util functions used by add_ccf_app and others
|
2020-01-21 18:14:27 +03:00
|
|
|
function(enable_quote_code name)
|
2020-01-28 21:09:42 +03:00
|
|
|
if(QUOTES_ENABLED)
|
2020-01-28 17:06:12 +03:00
|
|
|
target_compile_definitions(${name} PUBLIC -DGET_QUOTE)
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
|
|
|
endfunction()
|
|
|
|
|
|
|
|
function(use_client_mbedtls name)
|
|
|
|
target_include_directories(${name} PRIVATE ${CLIENT_MBEDTLS_INCLUDE_DIR})
|
|
|
|
target_link_libraries(${name} PRIVATE ${CLIENT_MBEDTLS_LIBRARIES})
|
|
|
|
endfunction()
|
|
|
|
|
|
|
|
function(use_oe_mbedtls name)
|
2020-07-28 13:56:45 +03:00
|
|
|
target_link_libraries(${name} PRIVATE ${OE_TARGET_ENCLAVE_AND_STD})
|
2020-01-21 18:14:27 +03:00
|
|
|
endfunction()
|
|
|
|
|
|
|
|
# Enclave library wrapper
|
2020-01-28 17:06:12 +03:00
|
|
|
function(add_ccf_app name)
|
2020-01-21 18:14:27 +03:00
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
cmake_parse_arguments(
|
|
|
|
PARSE_ARGV 1 PARSED_ARGS "" ""
|
2020-06-23 12:10:22 +03:00
|
|
|
"SRCS;INCLUDE_DIRS;LINK_LIBS_ENCLAVE;LINK_LIBS_VIRTUAL;DEPS;INSTALL_LIBS"
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
2020-01-28 17:06:12 +03:00
|
|
|
add_custom_target(${name} ALL)
|
|
|
|
|
2020-03-25 17:50:30 +03:00
|
|
|
if("sgx" IN_LIST COMPILE_TARGETS)
|
2020-01-28 17:06:12 +03:00
|
|
|
set(enc_name ${name}.enclave)
|
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
add_library(${enc_name} SHARED ${PARSED_ARGS_SRCS})
|
2020-01-21 18:14:27 +03:00
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
target_include_directories(
|
|
|
|
${enc_name} SYSTEM PRIVATE ${PARSED_ARGS_INCLUDE_DIRS}
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
2020-07-21 18:08:25 +03:00
|
|
|
add_warning_checks(${enc_name})
|
2020-01-28 21:09:42 +03:00
|
|
|
target_link_libraries(
|
2020-07-28 13:56:45 +03:00
|
|
|
${enc_name} PRIVATE ${PARSED_ARGS_LINK_LIBS_ENCLAVE}
|
|
|
|
${OE_TARGET_ENCLAVE_CORE_LIBS} ccf.enclave
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
|
|
|
|
2020-01-28 17:06:12 +03:00
|
|
|
set_property(TARGET ${enc_name} PROPERTY POSITION_INDEPENDENT_CODE ON)
|
|
|
|
|
2020-07-28 13:56:45 +03:00
|
|
|
add_lvi_mitigations(${enc_name})
|
|
|
|
|
2020-01-28 17:06:12 +03:00
|
|
|
add_dependencies(${name} ${enc_name})
|
2020-04-14 17:00:47 +03:00
|
|
|
if(PARSED_ARGS_DEPS)
|
|
|
|
add_dependencies(${enc_name} ${PARSED_ARGS_DEPS})
|
|
|
|
endif()
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
|
|
|
|
2020-03-25 17:50:30 +03:00
|
|
|
if("virtual" IN_LIST COMPILE_TARGETS)
|
2020-01-28 21:09:42 +03:00
|
|
|
# Build a virtual enclave, loaded as a shared library without OE
|
2020-01-21 18:14:27 +03:00
|
|
|
set(virt_name ${name}.virtual)
|
2020-01-28 17:06:12 +03:00
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
add_library(${virt_name} SHARED ${PARSED_ARGS_SRCS})
|
2020-01-28 17:06:12 +03:00
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
target_include_directories(
|
|
|
|
${virt_name} SYSTEM PRIVATE ${PARSED_ARGS_INCLUDE_DIRS}
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
2020-07-21 18:08:25 +03:00
|
|
|
add_warning_checks(${virt_name})
|
2020-01-21 18:14:27 +03:00
|
|
|
|
2020-01-28 21:09:42 +03:00
|
|
|
target_link_libraries(
|
|
|
|
${virt_name} PRIVATE ${PARSED_ARGS_LINK_LIBS_VIRTUAL} ccf.virtual
|
2020-01-21 18:14:27 +03:00
|
|
|
)
|
2020-01-28 17:06:12 +03:00
|
|
|
|
2020-09-03 18:28:34 +03:00
|
|
|
if(NOT SAN)
|
|
|
|
target_link_options(${virt_name} PRIVATE LINKER:--no-undefined)
|
|
|
|
endif()
|
2020-09-02 12:46:17 +03:00
|
|
|
|
2020-01-21 18:14:27 +03:00
|
|
|
set_property(TARGET ${virt_name} PROPERTY POSITION_INDEPENDENT_CODE ON)
|
|
|
|
|
|
|
|
add_san(${virt_name})
|
2020-01-28 17:06:12 +03:00
|
|
|
|
|
|
|
add_dependencies(${name} ${virt_name})
|
2020-04-14 17:00:47 +03:00
|
|
|
if(PARSED_ARGS_DEPS)
|
|
|
|
add_dependencies(${virt_name} ${PARSED_ARGS_DEPS})
|
|
|
|
endif()
|
2020-06-23 12:10:22 +03:00
|
|
|
|
|
|
|
if(${PARSED_ARGS_INSTALL_LIBS})
|
|
|
|
install(TARGETS ${virt_name} DESTINATION lib)
|
|
|
|
endif()
|
2020-01-21 18:14:27 +03:00
|
|
|
endif()
|
2020-01-28 21:09:42 +03:00
|
|
|
endfunction()
|
2020-04-16 13:31:04 +03:00
|
|
|
|
|
|
|
# Convenience wrapper to build C-libraries that can be linked in enclave, ie. in
|
|
|
|
# a CCF application.
|
|
|
|
function(add_enclave_library_c name files)
|
|
|
|
add_library(${name} STATIC ${files})
|
|
|
|
target_compile_options(${name} PRIVATE -nostdinc)
|
2020-07-28 13:56:45 +03:00
|
|
|
target_link_libraries(${name} PRIVATE ${OE_TARGET_LIBC})
|
2020-04-16 13:31:04 +03:00
|
|
|
set_property(TARGET ${name} PROPERTY POSITION_INDEPENDENT_CODE ON)
|
|
|
|
endfunction()
|
2021-03-25 17:19:15 +03:00
|
|
|
|
|
|
|
# Convenience wrapper to build C++-libraries that can be linked in enclave, ie.
|
|
|
|
# in a CCF application.
|
|
|
|
function(add_enclave_library name files)
|
|
|
|
add_library(${name} ${files})
|
|
|
|
target_compile_options(${name} PUBLIC -nostdinc -nostdinc++)
|
|
|
|
target_compile_definitions(
|
|
|
|
${name} PUBLIC INSIDE_ENCLAVE _LIBCPP_HAS_THREAD_API_PTHREAD
|
|
|
|
)
|
|
|
|
target_link_libraries(${name} PUBLIC ${OE_TARGET_ENCLAVE_AND_STD} -lgcc)
|
|
|
|
set_property(TARGET ${name} PROPERTY POSITION_INDEPENDENT_CODE ON)
|
|
|
|
endfunction()
|
|
|
|
|
|
|
|
function(add_host_library name files)
|
|
|
|
add_library(${name} ${files})
|
|
|
|
target_compile_options(${name} PUBLIC ${COMPILE_LIBCXX})
|
|
|
|
target_link_libraries(${name} PUBLIC ${LINK_LIBCXX} -lgcc openenclave::oehost)
|
|
|
|
set_property(TARGET ${name} PROPERTY POSITION_INDEPENDENT_CODE ON)
|
|
|
|
endfunction()
|