On Fri, 2020-05-15 at 10:55 -0700, Andi Kleen wrote: > > Indeed, we've seen a few hacks that basically just enable FSGSBASE: > > > > - https://github.com/oscarlab/graphene-sgx-driver > > - https://github.com/occlum/enable_rdfsbase > > > > And would very much like to get rid of them... > > These are insecure and open root holes without the patches > used here. > > -Andi
Yup, totally. /Jarkko