diff --git a/Pal/src/host/Linux-SGX/db_main-x86_64.c b/Pal/src/host/Linux-SGX/db_main-x86_64.c index e5886324..cbdbead9 100644 --- a/Pal/src/host/Linux-SGX/db_main-x86_64.c +++ b/Pal/src/host/Linux-SGX/db_main-x86_64.c @@ -164,3 +164,31 @@ int _DkGetCPUInfo (PAL_CPU_INFO* ci) { return rv; } + +size_t _DkRandomBitsRead(void* buffer, size_t size) { + uint32_t rand; + for (size_t i = 0; i < size; i += sizeof(rand)) { + rand = rdrand(); + memcpy(buffer + i, &rand, MIN(sizeof(rand), size - i)); + } + return 0; +} + +int _DkSegmentRegisterSet(int reg, const void* addr) { + /* GS is internally used, denied any access to it */ + if (reg != PAL_SEGMENT_FS) + return -PAL_ERROR_DENIED; + + SET_ENCLAVE_TLS(fsbase, (void*)addr); + wrfsbase((uint64_t)addr); + return 0; +} + +int _DkSegmentRegisterGet(int reg, void** addr) { + /* GS is internally used, denied any access to it */ + if (reg != PAL_SEGMENT_FS) + return -PAL_ERROR_DENIED; + + *addr = (void*)GET_ENCLAVE_TLS(fsbase); + return 0; +} diff --git a/Pal/src/host/Linux-SGX/db_misc.c b/Pal/src/host/Linux-SGX/db_misc.c index a753717b..4b3d41dd 100644 --- a/Pal/src/host/Linux-SGX/db_misc.c +++ b/Pal/src/host/Linux-SGX/db_misc.c @@ -31,15 +31,6 @@ unsigned long _DkSystemTimeQuery(void) { return microsec; } -size_t _DkRandomBitsRead(void* buffer, size_t size) { - uint32_t rand; - for (size_t i = 0; i < size; i += sizeof(rand)) { - rand = rdrand(); - memcpy(buffer + i, &rand, MIN(sizeof(rand), size - i)); - } - return 0; -} - int _DkInstructionCacheFlush(const void* addr, int size) { __UNUSED(addr); __UNUSED(size); @@ -47,25 +38,6 @@ int _DkInstructionCacheFlush(const void* addr, int size) { return -PAL_ERROR_NOTIMPLEMENTED; } -int _DkSegmentRegisterSet(int reg, const void* addr) { - /* GS is internally used, denied any access to it */ - if (reg != PAL_SEGMENT_FS) - return -PAL_ERROR_DENIED; - - SET_ENCLAVE_TLS(fsbase, (void*)addr); - wrfsbase((uint64_t)addr); - return 0; -} - -int _DkSegmentRegisterGet(int reg, void** addr) { - /* GS is internally used, denied any access to it */ - if (reg != PAL_SEGMENT_FS) - return -PAL_ERROR_DENIED; - - *addr = (void*)GET_ENCLAVE_TLS(fsbase); - return 0; -} - #define CPUID_CACHE_SIZE 64 #define CPUID_CACHE_INVALID ((unsigned int)-1) diff --git a/Pal/src/host/Linux/db_main-x86_64.c b/Pal/src/host/Linux/db_main-x86_64.c index 4de53fcb..c865523a 100644 --- a/Pal/src/host/Linux/db_main-x86_64.c +++ b/Pal/src/host/Linux/db_main-x86_64.c @@ -7,6 +7,8 @@ * This file contains x86_64-specific functions of the PAL loader. */ +#include + #include "api.h" #include "bogomips.h" #include "cpu.h" @@ -152,3 +154,55 @@ int _DkGetCPUInfo(PAL_CPU_INFO* ci) { return rv; } + +#if USE_ARCH_RDRAND == 1 +int _DkRandomBitsRead(void* buffer, size_t size) { + uint32_t rand; + for (size_t i = 0; i < size; i += sizeof(rand)) { + rand = rdrand(); + memcpy(buffer + i, &rand, MIN(sizeof(rand), size - i)); + } + return 0; +} +#endif + +int _DkSegmentRegisterSet(int reg, const void* addr) { + int ret = 0; + + if (reg == PAL_SEGMENT_FS) { + ret = INLINE_SYSCALL(arch_prctl, 2, ARCH_SET_FS, addr); + } else if (reg == PAL_SEGMENT_GS) { + return -PAL_ERROR_DENIED; + } else { + return -PAL_ERROR_INVAL; + } + if (IS_ERR(ret)) + return -PAL_ERROR_DENIED; + + return 0; +} + +int _DkSegmentRegisterGet(int reg, void** addr) { + int ret; + unsigned long ret_addr; + + if (reg == PAL_SEGMENT_FS) { + ret = INLINE_SYSCALL(arch_prctl, 2, ARCH_GET_FS, &ret_addr); + } else if (reg == PAL_SEGMENT_GS) { + // The GS segment is used for the internal TCB of PAL + return -PAL_ERROR_DENIED; + } else { + return -PAL_ERROR_INVAL; + } + + if (IS_ERR(ret)) + return -PAL_ERROR_DENIED; + + *addr = (void*)ret_addr; + return 0; +} + +int _DkCpuIdRetrieve(unsigned int leaf, unsigned int subleaf, unsigned int values[4]) { + cpuid(leaf, subleaf, values); + return 0; +} diff --git a/Pal/src/host/Linux/db_misc.c b/Pal/src/host/Linux/db_misc.c index a8053ba4..430a3fb6 100644 --- a/Pal/src/host/Linux/db_misc.c +++ b/Pal/src/host/Linux/db_misc.c @@ -97,25 +97,7 @@ unsigned long _DkSystemTimeQuery(void) { #endif } -#if USE_ARCH_RDRAND == 1 -int _DkRandomBitsRead(void* buffer, int size) { - int total_bytes = 0; - do { - unsigned long rand; - asm volatile(".Lretry: rdrand %%rax\r\n jnc .Lretry\r\n" : "=a"(rand)::"memory", "cc"); - - if (total_bytes + sizeof(rand) <= size) { - *(unsigned long*)(buffer + total_bytes) = rand; - total_bytes += sizeof(rand); - } else { - for (int i = 0; i < size - total_bytes; i++) - *(unsigned char*)(buffer + total_bytes + i) = ((unsigned char*)&rand)[i]; - total_bytes = size; - } - } while (total_bytes < size); - return 0; -} -#else +#if USE_ARCH_RD_RAND != 1 size_t _DkRandomBitsRead(void* buffer, size_t size) { if (!pal_sec.random_device) { int fd = INLINE_SYSCALL(open, 3, RANDGEN_DEVICE, O_RDONLY, 0); @@ -139,78 +121,6 @@ size_t _DkRandomBitsRead(void* buffer, size_t size) { } #endif -#if defined(__i386__) -#include -#elif defined(__x86_64__) -#include -#endif - -int _DkSegmentRegisterSet(int reg, const void* addr) { - int ret = 0; - -#if defined(__i386__) - struct user_desc u_info; - - ret = INLINE_SYSCALL(get_thread_area, 1, &u_info); - - if (IS_ERR(ret)) - return NULL; - - u_info->entry_number = -1; - u_info->base_addr = (unsigned int)addr; - - ret = INLINE_SYSCALL(set_thread_area, 1, &u_info); -#elif defined(__x86_64__) - if (reg == PAL_SEGMENT_FS) { - ret = INLINE_SYSCALL(arch_prctl, 2, ARCH_SET_FS, addr); - } else if (reg == PAL_SEGMENT_GS) { - return -PAL_ERROR_DENIED; - } else { - return -PAL_ERROR_INVAL; - } -#else -#error Unsupported architecture -#endif - if (IS_ERR(ret)) - return -PAL_ERROR_DENIED; - - return 0; -} - -int _DkSegmentRegisterGet(int reg, void** addr) { - int ret; - -#if defined(__i386__) - struct user_desc u_info; - - ret = INLINE_SYSCALL(get_thread_area, 1, &u_info); - - if (IS_ERR(ret)) - return -PAL_ERROR_DENIED; - - *addr = (void*)u_info->base_addr; -#elif defined(__x86_64__) - unsigned long ret_addr; - - if (reg == PAL_SEGMENT_FS) { - ret = INLINE_SYSCALL(arch_prctl, 2, ARCH_GET_FS, &ret_addr); - } else if (reg == PAL_SEGMENT_GS) { - // The GS segment is used for the internal TCB of PAL - return -PAL_ERROR_DENIED; - } else { - return -PAL_ERROR_INVAL; - } - - if (IS_ERR(ret)) - return -PAL_ERROR_DENIED; - - *addr = (void*)ret_addr; -#else -#error Unsupported architecture -#endif - return 0; -} - int _DkInstructionCacheFlush(const void* addr, int size) { __UNUSED(addr); __UNUSED(size); @@ -218,11 +128,6 @@ int _DkInstructionCacheFlush(const void* addr, int size) { return -PAL_ERROR_NOTIMPLEMENTED; } -int _DkCpuIdRetrieve(unsigned int leaf, unsigned int subleaf, unsigned int values[4]) { - cpuid(leaf, subleaf, values); - return 0; -} - int _DkAttestationReport(PAL_PTR user_report_data, PAL_NUM* user_report_data_size, PAL_PTR target_info, PAL_NUM* target_info_size, PAL_PTR report, PAL_NUM* report_size) {