|
@@ -1,5 +1,5 @@
|
|
loader.preload = file:$(SHIMPATH)
|
|
loader.preload = file:$(SHIMPATH)
|
|
-loader.exec = file:/bin/ls
|
|
|
|
|
|
+loader.exec = file:/bin/cp
|
|
loader.env.LD_LIBRARY_PATH = /lib:/lib/x86_64-linux-gnu
|
|
loader.env.LD_LIBRARY_PATH = /lib:/lib/x86_64-linux-gnu
|
|
loader.debug_type = none
|
|
loader.debug_type = none
|
|
|
|
|
|
@@ -11,19 +11,15 @@ fs.mount.hostlib.type = chroot
|
|
fs.mount.hostlib.path = /lib/x86_64-linux-gnu
|
|
fs.mount.hostlib.path = /lib/x86_64-linux-gnu
|
|
fs.mount.hostlib.uri = file:/lib/x86_64-linux-gnu
|
|
fs.mount.hostlib.uri = file:/lib/x86_64-linux-gnu
|
|
|
|
|
|
-fs.mount.bin.type = chroot
|
|
|
|
-fs.mount.bin.path = /bin
|
|
|
|
-fs.mount.bin.uri = file:/bin
|
|
|
|
-
|
|
|
|
-# allow to bind on port 8000
|
|
|
|
-net.rules.1 = 127.0.0.1:8000:0.0.0.0:0-65535
|
|
|
|
-# allow to connect to port 8000
|
|
|
|
-net.rules.2 = 0.0.0.0:0-65535:127.0.0.1:8000
|
|
|
|
-
|
|
|
|
# sgx-related
|
|
# sgx-related
|
|
-sgx.trusted_files.ld.uri = file:$(LIBCDIR)/ld-linux-x86-64.so.2
|
|
|
|
-sgx.trusted_files.libc.uri = file:$(LIBCDIR)/libc.so.6
|
|
|
|
-sgx.trusted_files.libselinux.uri = file:/lib/x86_64-linux-gnu/libselinux.so.1
|
|
|
|
-sgx.trusted_files.libacl.uri = file:/lib/x86_64-linux-gnu/libacl.so.1
|
|
|
|
-sgx.trusted_files.libpcre.uri = file:/lib/x86_64-linux-gnu/libpcre.so.3
|
|
|
|
-sgx.trusted_files.libattr.uri = file:/lib/x86_64-linux-gnu/libattr.so.1
|
|
|
|
|
|
+sgx.trusted_files.ld = file:$(LIBCDIR)/ld-linux-x86-64.so.2
|
|
|
|
+sgx.trusted_files.libc = file:$(LIBCDIR)/libc.so.6
|
|
|
|
+sgx.trusted_files.libdl = file:$(LIBCDIR)/libdl.so.2
|
|
|
|
+sgx.trusted_files.libpthread = file:$(LIBCDIR)/libpthread.so.0
|
|
|
|
+sgx.trusted_files.libselinux = file:/lib/x86_64-linux-gnu/libselinux.so.1
|
|
|
|
+sgx.trusted_files.libacl = file:/lib/x86_64-linux-gnu/libacl.so.1
|
|
|
|
+sgx.trusted_files.libpcre = file:/lib/x86_64-linux-gnu/libpcre.so.3
|
|
|
|
+sgx.trusted_files.libattr = file:/lib/x86_64-linux-gnu/libattr.so.1
|
|
|
|
+
|
|
|
|
+sgx.allowed_files.test3 = file:somefile
|
|
|
|
+sgx.allowed_files.testdir = file:testdir
|