求编译简单Intel SGX Hello World应用的CMakeLists.txt示例及Makefile转译
Absolutely! I get it—most SGX examples on GitHub are way overengineered when all you want is a simple "Hello World" to get started. Let’s take that basic SGX Makefile you mentioned and turn it into a clean, minimal CMakeLists.txt setup that’s easy to follow and adapt.
First, let’s assume your project uses this straightforward structure:
sgx-hello-world/ ├── app/ │ └── main.c ├── enclave/ │ ├── enclave.c │ ├── enclave.edl │ └── enclave.config.xml └── CMakeLists.txt
Root CMakeLists.txt (Project Root)
This file sets up the SGX environment and coordinates building the enclave and application:
cmake_minimum_required(VERSION 3.10) project(SGX_Hello_World) # Configure SGX paths and settings (adjust these if your SDK is in a non-default location) set(SGX_SDK /opt/intel/sgxsdk) set(SGX_ARCH x64) set(SGX_MODE SIM) # Switch to HW for actual SGX hardware set(SGX_DEBUG 1) # Set to 0 for release builds # Include official SGX CMake modules from the SDK set(CMAKE_MODULE_PATH ${CMAKE_MODULE_PATH} "${SGX_SDK}/cmake") find_package(SGX REQUIRED) # Build enclave and application subdirectories add_subdirectory(enclave) add_subdirectory(app)
Enclave CMakeLists.txt (enclave/CMakeLists.txt)
Handles enclave compilation, bridge code generation (via sgx_edger8r), and signing:
set(ENCLAVE_NAME enclave) set(ENCLAVE_CONFIG enclave.config.xml) set(ENCLAVE_EDL enclave.edl) set(ENCLAVE_SRCS enclave.c) # Generate untrusted bridge code for the app to call enclave functions sgx_generate_enclave_bridge( EDL ${ENCLAVE_EDL} EDGER8R_FLAGS --untrusted OUTPUT_DIR ${CMAKE_CURRENT_BINARY_DIR}/bridge ) # Build and sign the enclave using SGX SDK helper functions add_enclave( TARGET ${ENCLAVE_NAME} CONFIG ${ENCLAVE_CONFIG} SRCS ${ENCLAVE_SRCS} EDL ${ENCLAVE_EDL} EDGER8R_FLAGS --trusted LIBRARIES sgx_tservice ) # Copy built enclave and config to the binary directory (optional but convenient) install(TARGETS ${ENCLAVE_NAME} DESTINATION ${CMAKE_BINARY_DIR}) install(FILES ${ENCLAVE_CONFIG} DESTINATION ${CMAKE_BINARY_DIR})
App CMakeLists.txt (app/CMakeLists.txt)
Builds the untrusted application and links it to SGX libraries and the enclave bridge:
set(APP_NAME app) set(APP_SRCS main.c) # Include generated bridge headers to call enclave ECALLs include_directories(${CMAKE_CURRENT_BINARY_DIR}/../enclave/bridge) # Build the application executable add_executable(${APP_NAME} ${APP_SRCS}) # Link against SGX untrusted runtime libraries and the built enclave target_link_libraries(${APP_NAME} sgx_urts sgx_uservice ${CMAKE_BINARY_DIR}/enclave.so ) # Copy app to binary directory (optional) install(TARGETS ${APP_NAME} DESTINATION ${CMAKE_BINARY_DIR})
Example Code Snippets (To Make It Fully Functional)
If you don’t already have these, here’s the minimal code to make your "Hello World" work:
Enclave Code (enclave/enclave.c)
#include "enclave_t.h" #include <stdio.h> void ecall_hello_world() { printf("Hello World from the SGX Enclave!\n"); }
Application Code (app/main.c)
#include "sgx_urts.h" #include "enclave_u.h" #define ENCLAVE_FILE "enclave.so" int main() { sgx_enclave_id_t eid; sgx_status_t status; sgx_launch_token_t token = {0}; int updated = 0; // Initialize the enclave status = sgx_create_enclave(ENCLAVE_FILE, SGX_DEBUG_FLAG, &token, &updated, &eid, NULL); if (status != SGX_SUCCESS) { printf("Failed to create enclave: %d\n", status); return 1; } // Call the enclave's hello world function ecall_hello_world(eid); // Clean up the enclave sgx_destroy_enclave(eid); return 0; }
EDL File (enclave/enclave.edl)
enclave { ecall { void ecall_hello_world(); }; };
Key Notes
- SGX Paths: If your SGX SDK isn’t in
/opt/intel/sgxsdk(e.g., Windows usesC:\Program Files (x86)\Intel\SGXSDK), update theSGX_SDKvariable in the root CMakeLists.txt. - Mode Switch: Change
SGX_MODEtoHWwhen you’re ready to test on actual SGX-enabled hardware. - Debug vs Release: Set
SGX_DEBUGto0for production builds to disable debug features.
内容的提问来源于stack exchange,提问作者asonnino

