• Stars
    star
    122
  • Rank 281,912 (Top 6 %)
  • Language
    C
  • Created over 5 years ago
  • Updated about 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

DISCONTINUATION OF PROJECT

This project will no longer be maintained by Intel.

Intel has ceased development and contributions including, but not limited to, maintenance, bug fixes, new releases, or updates, to this project.

Intel no longer accepts patches to this project.

If you have an ongoing need to use this project, are interested in independently developing it, or would like to maintain patches for the open source software community, please create your own fork of this project.

Contact: [email protected] Intel(R) Software Guard Extensions Software Enabling Application for Linux*

Introduction

This application will enable Intel SGX on Linux systems where the BIOS supports Intel SGX, but does not provide an explicit option to enable it. These systems can only enable Intel SGX via the "software enable" procedure.

License

This application is distributed under the BSD 3-Clause "New" or "Revised" License.

Requirements

Performing the software enable procedure requires:

  • An Intel SGX capable processor
  • A BIOS that supports Intel SGX and the software enable procedure. Some BIOS manufacturers provide an option to explicitly enable or disable Intel SGX.
  • A supported Linux distribution that has been booted in UEFI mode. Systems booted in Legacy mode cannot perform the software enable as the procedure depends on EFI variables. A Legacy mode system can be enabled by booting a Linux Live CD in UEFI mode, and then performing the software enable. Intel SGX enabling occurs at the platform, not OS, level.
  • The EFI filesystem, which should be mounted by default if your Linux system is booted in UEFI mode.

Building the Application

Build the application by running 'make'.

$ make

There are no package requirements beyond a C compiler. If you wish to use a compiler other than gcc*, edit the Makefile and change the CC variable.

There is no installer, as this is a one-time use executable. Once Intel SGX is enabled, it will stay enabled until explicitly disabled in your BIOS (if your BIOS supports this capability).

Running the Application

Usage is:

usage: sgx-enable [ options ]

Options:
  -s, --status      Report the enabling status only
  -h, --help        Show this help

Running sgx_enable with no options will attempt to perform the software enabling procedure on your system. You will need write access to the EFI filesystem which typically means it must be run as root:

$ sudo ./sgx_enable

Once the software enabling procedure has completed successfully you will need to reboot your system for Intel SGX to be available.

The software enabling procedure is a one-time procedure. You will not need to run this application again unless you explicitly disable Intel SGX in your BIOS at a later date.

The --status option prints the status of Intel SGX on your system and does not attempt to enable it. This will also report whether or not your system supports Intel SGX and the software enable procedure.

$ sgx_enable --status

You should not need to be root to display the enabling status of the system unless your EFI filesystem is not world-readable.

The utility will report the enabling status on your system, and the success or failure of the software enabling procedure.

Result Messages

Intel SGX is disabled and can be enabled using this utility

Your system supports Intel SGX, and is in the "software enable" state. Rerun the utility without the --status option to enable Intel SGX.

Intel SGX is already enabled on this system

Your system supports Intel SGX and it has already been enabled. No further action is necessary.

Software enable has been set. Please reboot your system.

The software enabling procedure completed successfully. Once your system is rebooted Intel SGX will be available for use.

You may need to rerun this utility as root

The software enabling procedure could not be performed because you do not have write access to the EFI filesystem. Rerun the utility as root.

This CPU does not support Intel SGX

Your CPU does not support Intel SGX.

Intel SGX is explicitly disabled on your system

Either Intel SGX is explicitly disabled in your BIOS, or your BIOS does not support Intel SGX. Reboot your system into the BIOS setup screen and look for an Intel SGX option. If you don't find any, your system may not support Intel SGX.

Contact your OEM for assistance.

This processor supports Intel SGX but was booted in legacy mode

A UEFI booted system is required to perform the software enabling procedure. If your system has already been built and booted in Legacy mode, you can boot a Linux Live CD in UEFI mode and perform the procedure from the Live image.

Intel SGX is explicitly disabled, and your BIOS does not support the "software enable" option

Your BIOS provides explicit options to enable or disable Intel SGX, and does not have a software enable capability. To enable Intel SGX, boot your system into the BIOS setup screen, locate the Intel SGX options and explicitly set the status to "enabled". You do not need this utility.

Contact your OEM for assistance.

The software enable has been performed on this system and Intel SGX will be enabled after the system is rebooted

The software enable procedure has already been executed. You need to reboot your system for Intel SGX to be enabled for use. You do not need to run this utility again.

I could not attempt the software enable

Your system supports Intel SGX and is in the software enable state, but the software enabling could not be completed because an unexpected error occurred. This is almost always the result of a system error. See the accompanying error message for clues as to what went wrong.

I couldn't make sense of your system

Something terrible has happened. This message usually means that an unexpected error has occurred and is almost always the result of a more serious system error. Look at the error message output for clues as to what might have gone wrong.

More Repositories

1

hyperscan

High-performance regular expression matching library
C++
4,478
star
2

acat

Assistive Context-Aware Toolkit (ACAT)
C#
3,191
star
3

haxm

Intel® Hardware Accelerated Execution Manager (Intel® HAXM)
C
3,029
star
4

appframework

The definitive HTML5 mobile javascript framework
CSS
2,435
star
5

pcm

Intel® Performance Counter Monitor (Intel® PCM)
C++
2,083
star
6

neural-compressor

SOTA low-bit LLM quantization (INT8/FP8/INT4/FP4/NF4) & sparsity; leading model compression techniques on TensorFlow, PyTorch, and ONNX Runtime
Python
1,939
star
7

intel-extension-for-transformers

⚡ Build your chatbot within minutes on your favorite device; offer SOTA compression techniques for LLMs; run LLMs efficiently on Intel Platforms⚡
Python
1,910
star
8

intel-extension-for-pytorch

A Python package for extending the official PyTorch that can easily obtain performance on Intel platform
Python
1,203
star
9

linux-sgx

Intel SGX for Linux*
C++
1,180
star
10

scikit-learn-intelex

Intel(R) Extension for Scikit-learn is a seamless way to speed up your Scikit-learn application
Python
954
star
11

llvm

Intel staging area for llvm.org contribution. Home for Intel LLVM-based projects.
918
star
12

nemu

ARCHIVED: Modern Hypervisor for the Cloud. See https://github.com/cloud-hypervisor/cloud-hypervisor instead
C
915
star
13

compute-runtime

Intel® Graphics Compute Runtime for oneAPI Level Zero and OpenCL™ Driver
C++
912
star
14

caffe

This fork of BVLC/Caffe is dedicated to improving performance of this deep learning framework when running on CPU, in particular Intel® Xeon processors.
C++
845
star
15

isa-l

Intelligent Storage Acceleration Library
C
816
star
16

media-driver

C
783
star
17

cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
Python
721
star
18

intel-cmt-cat

User space software for Intel(R) Resource Director Technology
C
630
star
19

fastuidraw

C++
603
star
20

optimization-manual

Contains the source code examples described in the "Intel® 64 and IA-32 Architectures Optimization Reference Manual"
Assembly
602
star
21

libipt

libipt - an Intel(R) Processor Trace decoder library
C
594
star
22

libxcam

libXCam is a project for extended camera(not limited in camera) features and focus on image quality improvement and video analysis. There are lots features supported in image pre-processing, image post-processing and smart analysis. This library makes GPU/CPU/ISP working together to improve image quality. OpenCL is used to improve performance in different platforms.
C++
577
star
23

clDNN

Compute Library for Deep Neural Networks (clDNN)
C++
573
star
24

libva

Libva is an implementation for VA-API (Video Acceleration API)
C
558
star
25

intel-graphics-compiler

C++
503
star
26

wds

Wireless Display Software For Linux OS (WDS)
C++
496
star
27

thermal_daemon

Thermal daemon for IA
C++
485
star
28

x86-simd-sort

C++ header file library for high performance SIMD based sorting algorithms for primitive datatypes
C++
485
star
29

Intel-Linux-Processor-Microcode-Data-Files

466
star
30

gvt-linux

C
463
star
31

kernel-fuzzer-for-xen-project

Kernel Fuzzer for Xen Project (KF/x) - Hypervisor-based fuzzing using Xen VM forking, VMI & AFL
C
441
star
32

tinycbor

Concise Binary Object Representation (CBOR) Library
C
432
star
33

openfl

An open framework for Federated Learning.
Python
427
star
34

cc-oci-runtime

OCI (Open Containers Initiative) compatible runtime for Intel® Architecture
C
415
star
35

tinycrypt

tinycrypt is a library of cryptographic algorithms with a focus on small, simple implementation.
C
373
star
36

compile-time-init-build

C++ library for composing modular firmware at compile-time.
C++
372
star
37

ARM_NEON_2_x86_SSE

The platform independent header allowing to compile any C/C++ code containing ARM NEON intrinsic functions for x86 target systems using SIMD up to SSE4 intrinsic functions
C
369
star
38

yarpgen

Yet Another Random Program Generator
C++
357
star
39

intel-device-plugins-for-kubernetes

Collection of Intel device plugins for Kubernetes
Go
356
star
40

QAT_Engine

Intel QuickAssist Technology( QAT) OpenSSL Engine (an OpenSSL Plug-In Engine) which provides cryptographic acceleration for both hardware and optimized software using Intel QuickAssist Technology enabled Intel platforms. https://developer.intel.com/quickassist
C
356
star
41

linux-sgx-driver

Intel SGX Linux* Driver
C
334
star
42

safestringlib

C
328
star
43

xess

C
313
star
44

idlf

Intel® Deep Learning Framework
C++
311
star
45

ad-rss-lib

Library implementing the Responsibility Sensitive Safety model (RSS) for Autonomous Vehicles
C++
298
star
46

intel-vaapi-driver

VA-API user mode driver for Intel GEN Graphics family
C
289
star
47

ipp-crypto

C
269
star
48

rohd

The Rapid Open Hardware Development (ROHD) framework is a framework for describing and verifying hardware in the Dart programming language. ROHD enables you to build and traverse a graph of connectivity between module objects using unrestricted software.
Dart
256
star
49

opencl-intercept-layer

Intercept Layer for Debugging and Analyzing OpenCL Applications
C++
255
star
50

FSP

Intel(R) Firmware Support Package (FSP)
C
244
star
51

dffml

The easiest way to use Machine Learning. Mix and match underlying ML libraries and data set sources. Generate new datasets or modify existing ones with ease.
Python
241
star
52

intel-ipsec-mb

Intel(R) Multi-Buffer Crypto for IPSec
C
238
star
53

userspace-cni-network-plugin

Go
232
star
54

isa-l_crypto

Assembly
232
star
55

confidential-computing-zoo

Confidential Computing Zoo provides confidential computing solutions based on Intel SGX, TDX, HEXL, etc. technologies.
CMake
229
star
56

intel-extension-for-tensorflow

Intel® Extension for TensorFlow*
C++
226
star
57

bmap-tools

BMAP Tools
Python
220
star
58

ozone-wayland

Wayland implementation for Chromium Ozone classes
C++
214
star
59

intel-qs

High-performance simulator of quantum circuits
C++
202
star
60

SGXDataCenterAttestationPrimitives

C++
202
star
61

intel-sgx-ssl

Intel® Software Guard Extensions SSL
C
197
star
62

msr-tools

C
195
star
63

depth-camera-web-demo

JavaScript
194
star
64

CPU-Manager-for-Kubernetes

Kubernetes Core Manager for NFV workloads
Python
190
star
65

rmd

Go
189
star
66

asynch_mode_nginx

C
186
star
67

hexl

Intel®️ Homomorphic Encryption Acceleration Library accelerates modular arithmetic operations used in homomorphic encryption
C++
181
star
68

ros_object_analytics

C++
177
star
69

zephyr.js

JavaScript* Runtime for Zephyr* OS
C
176
star
70

generic-sensor-demos

HTML
175
star
71

ipmctl

C
172
star
72

sgx-ra-sample

C++
171
star
73

lmbench

C
171
star
74

cri-resource-manager

Kubernetes Container Runtime Interface proxy service with hardware resource aware workload placement policies
Go
166
star
75

virtual-storage-manager

Python
164
star
76

PerfSpect

System performance characterization tool based on linux perf
Python
164
star
77

systemc-compiler

This tool translates synthesizable SystemC code to synthesizable SystemVerilog.
C++
155
star
78

webml-polyfill

Deprecated, the Web Neural Network Polyfill project has been moved to https://github.com/webmachinelearning/webnn-polyfill
Python
153
star
79

pmem-csi

Persistent Memory Container Storage Interface Driver
Go
151
star
80

libyami

Yet Another Media Infrastructure. it is core part of media codec with hardware acceleration, it is yummy to your video experience on Linux like platform.
C++
148
star
81

ros_openvino_toolkit

C++
147
star
82

rib

Rapid Interface Builder (RIB) is a browser-based design tool for quickly prototyping and creating the user interface for web applications. Layout your UI by dropping widgets onto a canvas. Run the UI in an interactive "Preview mode". Export the generated HTML and Javascript. It's that simple!
JavaScript
147
star
83

ideep

Intel® Optimization for Chainer*, a Chainer module providing numpy like API and DNN acceleration using MKL-DNN.
C++
145
star
84

libva-utils

Libva-utils is a collection of tests for VA-API (VIdeo Acceleration API)
C
144
star
85

gmmlib

C++
141
star
86

platform-aware-scheduling

Enabling Kubernetes to make pod placement decisions with platform intelligence.
Go
140
star
87

numatop

NumaTOP is an observation tool for runtime memory locality characterization and analysis of processes and threads running on a NUMA system.
C
139
star
88

ros2_grasp_library

C++
138
star
89

XBB

C++
133
star
90

tdx-tools

Cloud Stack and Tools for Intel TDX (Trust Domain Extension)
C
131
star
91

ros2_intel_realsense

This project is deprecated and no more maintained. Please visit https://github.com/IntelRealSense/realsense-ros for ROS2 wrapper.
C++
131
star
92

linux-intel-lts

C
131
star
93

CeTune

Python
130
star
94

cm-compiler

C++
130
star
95

pti-gpu

Profiling Tools Interfaces for GPU (PTI for GPU) is a set of Getting Started Documentation and Tools Library to start performance analysis on Intel(R) Processor Graphics easily
C++
129
star
96

fMBT

Free Model Based tool
Python
129
star
97

zlib

C
128
star
98

ros_intel_movidius_ncs

C++
126
star
99

mpi-benchmarks

C
125
star
100

mOS

C
124
star