On Mon, 16 Oct 2023 16:09:52 -0500, Huang, Kai <kai.huang@xxxxxxxxx> wrote: [...]
still need to fix the bug mentioned above here. I really think you should just go this simple way: When you want to take EPC back from VM, kill the VM.
My only concern is that this is a compromise due to current limitation (no other sane way to take EPC from VMs). If we define this behavior and it becomes a contract to user space, then we can't change in future.
On the other hand, my understanding the reason you want this behavior is to enforce EPC limit at runtime. I just not sure how important it is and if it is a real usage given all limitations of SGX VMs we have (static EPC size, no migration).
Thanks Haitao