Re: [PATCH v12 00/18] Enable FSGSBASE instructions

From: Jarkko Sakkinen
Date: Sat May 16 2020 - 08:21:13 EST


On Fri, 2020-05-15 at 10:55 -0700, Andi Kleen wrote:
> > Indeed, we've seen a few hacks that basically just enable FSGSBASE:
> >
> > - https://github.com/oscarlab/graphene-sgx-driver
> > - https://github.com/occlum/enable_rdfsbase
> >
> > And would very much like to get rid of them...
>
> These are insecure and open root holes without the patches
> used here.
>
> -Andi

Yup, totally.

/Jarkko