You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求编译简单Intel SGX Hello World应用的CMakeLists.txt示例及Makefile转译

Minimal SGX "Hello World" CMake Setup

Absolutely! I get it—most SGX examples on GitHub are way overengineered when all you want is a simple "Hello World" to get started. Let’s take that basic SGX Makefile you mentioned and turn it into a clean, minimal CMakeLists.txt setup that’s easy to follow and adapt.

First, let’s assume your project uses this straightforward structure:

sgx-hello-world/
├── app/
│   └── main.c
├── enclave/
│   ├── enclave.c
│   ├── enclave.edl
│   └── enclave.config.xml
└── CMakeLists.txt

Root CMakeLists.txt (Project Root)

This file sets up the SGX environment and coordinates building the enclave and application:

cmake_minimum_required(VERSION 3.10)
project(SGX_Hello_World)

# Configure SGX paths and settings (adjust these if your SDK is in a non-default location)
set(SGX_SDK /opt/intel/sgxsdk)
set(SGX_ARCH x64)
set(SGX_MODE SIM) # Switch to HW for actual SGX hardware
set(SGX_DEBUG 1) # Set to 0 for release builds

# Include official SGX CMake modules from the SDK
set(CMAKE_MODULE_PATH ${CMAKE_MODULE_PATH} "${SGX_SDK}/cmake")
find_package(SGX REQUIRED)

# Build enclave and application subdirectories
add_subdirectory(enclave)
add_subdirectory(app)

Enclave CMakeLists.txt (enclave/CMakeLists.txt)

Handles enclave compilation, bridge code generation (via sgx_edger8r), and signing:

set(ENCLAVE_NAME enclave)
set(ENCLAVE_CONFIG enclave.config.xml)
set(ENCLAVE_EDL enclave.edl)
set(ENCLAVE_SRCS enclave.c)

# Generate untrusted bridge code for the app to call enclave functions
sgx_generate_enclave_bridge(
    EDL ${ENCLAVE_EDL}
    EDGER8R_FLAGS --untrusted
    OUTPUT_DIR ${CMAKE_CURRENT_BINARY_DIR}/bridge
)

# Build and sign the enclave using SGX SDK helper functions
add_enclave(
    TARGET ${ENCLAVE_NAME}
    CONFIG ${ENCLAVE_CONFIG}
    SRCS ${ENCLAVE_SRCS}
    EDL ${ENCLAVE_EDL}
    EDGER8R_FLAGS --trusted
    LIBRARIES sgx_tservice
)

# Copy built enclave and config to the binary directory (optional but convenient)
install(TARGETS ${ENCLAVE_NAME} DESTINATION ${CMAKE_BINARY_DIR})
install(FILES ${ENCLAVE_CONFIG} DESTINATION ${CMAKE_BINARY_DIR})

App CMakeLists.txt (app/CMakeLists.txt)

Builds the untrusted application and links it to SGX libraries and the enclave bridge:

set(APP_NAME app)
set(APP_SRCS main.c)

# Include generated bridge headers to call enclave ECALLs
include_directories(${CMAKE_CURRENT_BINARY_DIR}/../enclave/bridge)

# Build the application executable
add_executable(${APP_NAME} ${APP_SRCS})

# Link against SGX untrusted runtime libraries and the built enclave
target_link_libraries(${APP_NAME}
    sgx_urts
    sgx_uservice
    ${CMAKE_BINARY_DIR}/enclave.so
)

# Copy app to binary directory (optional)
install(TARGETS ${APP_NAME} DESTINATION ${CMAKE_BINARY_DIR})

Example Code Snippets (To Make It Fully Functional)

If you don’t already have these, here’s the minimal code to make your "Hello World" work:

Enclave Code (enclave/enclave.c)

#include "enclave_t.h"
#include <stdio.h>

void ecall_hello_world() {
    printf("Hello World from the SGX Enclave!\n");
}

Application Code (app/main.c)

#include "sgx_urts.h"
#include "enclave_u.h"

#define ENCLAVE_FILE "enclave.so"

int main() {
    sgx_enclave_id_t eid;
    sgx_status_t status;
    sgx_launch_token_t token = {0};
    int updated = 0;

    // Initialize the enclave
    status = sgx_create_enclave(ENCLAVE_FILE, SGX_DEBUG_FLAG, &token, &updated, &eid, NULL);
    if (status != SGX_SUCCESS) {
        printf("Failed to create enclave: %d\n", status);
        return 1;
    }

    // Call the enclave's hello world function
    ecall_hello_world(eid);

    // Clean up the enclave
    sgx_destroy_enclave(eid);
    return 0;
}

EDL File (enclave/enclave.edl)

enclave {
    ecall {
        void ecall_hello_world();
    };
};

Key Notes

  • SGX Paths: If your SGX SDK isn’t in /opt/intel/sgxsdk (e.g., Windows uses C:\Program Files (x86)\Intel\SGXSDK), update the SGX_SDK variable in the root CMakeLists.txt.
  • Mode Switch: Change SGX_MODE to HW when you’re ready to test on actual SGX-enabled hardware.
  • Debug vs Release: Set SGX_DEBUG to 0 for production builds to disable debug features.

内容的提问来源于stack exchange,提问作者asonnino

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:47:48