mirror of
https://github.com/clearlinux/graphene.git
synced 2026-10-03 15:39:36 +00:00
[Pal/Linux-SGX] Improve printing of MRENCLAVE and MRSIGNER
Standardize prints of MRENCLAVE. Also print MRSIGNER in output of the pal-sgx-get-token script, so it can be used to retrieve SGX measurements from the SIGSTRUCT (.sig) file for manual inspection.
This commit is contained in:
@@ -52,7 +52,10 @@ int read_enclave_token(int token_file, sgx_arch_token_t * token)
|
||||
if (IS_ERR(bytes))
|
||||
return -ERRNO(bytes);
|
||||
|
||||
SGX_DBG(DBG_I, "read token:\n");
|
||||
#ifdef SGX_DCAP
|
||||
SGX_DBG(DBG_I, "Read dummy DCAP token\n");
|
||||
#else
|
||||
SGX_DBG(DBG_I, "Read token:\n");
|
||||
SGX_DBG(DBG_I, " valid: 0x%08x\n", token->body.valid);
|
||||
SGX_DBG(DBG_I, " attr.flags: 0x%016lx\n", token->body.attributes.flags);
|
||||
SGX_DBG(DBG_I, " attr.xfrm: 0x%016lx\n", token->body.attributes.xfrm);
|
||||
@@ -64,6 +67,7 @@ int read_enclave_token(int token_file, sgx_arch_token_t * token)
|
||||
SGX_DBG(DBG_I, " LE masked_misc_select: 0x%08x\n", token->masked_misc_select_le);
|
||||
SGX_DBG(DBG_I, " LE attr.flags: 0x%016lx\n", token->attributes_le.flags);
|
||||
SGX_DBG(DBG_I, " LE attr.xfrm: 0x%016lx\n", token->attributes_le.xfrm);
|
||||
#endif
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -343,10 +347,7 @@ int init_enclave(sgx_arch_secs_t * secs,
|
||||
|
||||
SGX_DBG(DBG_I, "enclave initializing:\n");
|
||||
SGX_DBG(DBG_I, " enclave id: 0x%016lx\n", enclave_valid_addr);
|
||||
SGX_DBG(DBG_I, " enclave hash:");
|
||||
for (size_t i = 0 ; i < sizeof(sgx_measurement_t) ; i++)
|
||||
SGX_DBG(DBG_I, " %02x", sigstruct->body.enclave_hash.m[i]);
|
||||
SGX_DBG(DBG_I, "\n");
|
||||
SGX_DBG(DBG_I, " mr_enclave: %s\n", ALLOCA_BYTES2HEXSTR(sigstruct->body.enclave_hash.m));
|
||||
|
||||
struct sgx_enclave_init param = {
|
||||
#ifndef SGX_DCAP_16_OR_LATER
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
|
||||
import argparse
|
||||
import array
|
||||
import hashlib
|
||||
import os
|
||||
import socket
|
||||
import struct
|
||||
@@ -163,7 +164,7 @@ argparser.add_argument('--sig', '-sig', metavar='SIGNATURE',
|
||||
type=argparse.FileType('rb'), required=True,
|
||||
help='Input .sig file (contains SIGSTRUCT)')
|
||||
argparser.add_argument('--output', '-output', metavar='OUTPUT',
|
||||
type=argparse.FileType('wb'), required=True,
|
||||
type=argparse.FileType('wb'), required=False,
|
||||
help='Output .token file (contains EINITTOKEN)')
|
||||
|
||||
|
||||
@@ -174,8 +175,13 @@ def main(args=None):
|
||||
attr = read_sigstruct(args.sig.read())
|
||||
set_optional_sgx_features(attr)
|
||||
|
||||
# calculate MRSIGNER as sha256 hash over RSA public key's modulus
|
||||
mrsigner = hashlib.sha256()
|
||||
mrsigner.update(attr['modulus'])
|
||||
|
||||
print("Attributes:")
|
||||
print(" mr_enclave: %s" % attr['enclave_hash'].hex())
|
||||
print(" mr_signer: %s" % mrsigner.digest().hex())
|
||||
print(" isv_prod_id: %d" % attr['isv_prod_id'])
|
||||
print(" isv_svn: %d" % attr['isv_svn'])
|
||||
print(" attr.flags: %016x" % int.from_bytes(attr['flags'], byteorder='big'))
|
||||
@@ -192,7 +198,8 @@ def main(args=None):
|
||||
else:
|
||||
token = connect_aesmd(attr)
|
||||
|
||||
args.output.write(token)
|
||||
if args.output:
|
||||
args.output.write(token)
|
||||
return 0
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user