MAX_FDS is defined as 3, fds[MAX_FDS] is a 3-element array.
While i in for loop looping from 0 to MAX_FDS, will cause out-of-boundry read for generaic.fds which is a 2-element array.
The generic.fds defiend in pal_host.h should be correctly sized to match with both fds[MAX_FDS] and accommodate for the for loop.
Also fixed another out-of-boundary access for pipeprv
This code path is called when the urts EENTERs to allow us to prepare
the SSA for the following ERESUME (i.e. inject the exception handler).
It is not for the ERESUME itself. So rename it to avoid confusion.
The comment about the register content is only true for EENTER. Also
usually* this code is reached only by EENTER. ERESUME restores the saved
state from the SSA.
*: It is reached if an async exit happens just after EENTER.
Also remove redundant comments directly below.
This commit ensures that TCS.CSSA == 1 while entering enclave
execution to handle a signal from host OS (recall that CSSA == 0 is for
normal enclave execution and CSSA == 1 is for signal-handling
enclave preparation). This effectively disallows nested signal handling
from a malicious OS. Disallowing nested signals simplifies our code.
Benign OS is prevented from nesting by blocking async signals during
signal handling.
Note that currently enclaves are always run with TCS.NSSA == 2, and SGX
hardware will disallow entering the enclave if TCS.CSSA > 1. Thus, this
commit serves as an assertion in case NSSA limit is changed in future.
Before, connect() host-OS syscall was issued unconditionally in
sgx_ocall_sock_connect(). However, UDP clients do not strictly need to
issue connect() before sending packets to UDP server. In this case, addr
is NULL, and sgx_ocall_sock_connect() must not issue connect().
- Time-Of-Check-To-Time-Of-Use (TOCTOU) vulnerability is closed
by first copying untrusted values inside enclave and then
operating on these copied values; see sgx_copy_to_enclave().
- Pointer/integer overflow is closed by comparing against a
trusted maximum value in sgx_copy_to_enclave().
- Untrusted stack overflows in sgx_alloc_on_ustack()/sgx_copy_to_ustack()
are closed by checking for NULL return values.
These vulnerabilities were independently discovered and disclosed
by David Oswald, Jo van Bulck, and others.
Instead we use the fact that the manifest is always placed at the top of
the enclave address range. The manifest size is stored inside the TLS
like we have already done for the enclave size.
Part of issue #509.
Before, pause() was emulated by sleeping for 1s in a loop until
signal interrupted it. If signal arrived in-between these invocations
then pause() could never return. Also, pause() incorrectly returned 0
instead of -1 and errno=EINTR.
This patch emulates pause() by sleeping for a very long time (years).
Also, it correctly returns EINTR.
On weaker machines (Intel NUCs and SGX-enabled laptops),
SGX regression tests take longer than 5 seconds because
Graphene measures/zeroes all enclave memory at startup.
Increase the timeout for SGX regression tests to 20 sec.
Before this change some important memory areas, for example TCS and TLS
were not measured. With this change all mapped enclave memory is
measured with one exception. Since the EEXTEND hashing is rather slow
the heap is not measured. Instead it gets zeroed on enclave startup.
Closes#505.
Before .Lhandle_exception used the stack directly and thereby messed
with the red zone of the interrupted code.
Also ensure that the stack is aligned before calling
_DkExceptionHandler.
ocall_sock_recv/send copied/allocated buffers on untrusted stack.
If buffer sizes were large, the stack overflowed. This patch
allocates buffers on untrusted heap if size is too large.
Before, on many execution paths after failed OCALL, the returned
PAL error was hardcoded. This patch removes these hardcoded errors
and propagates the original error code from OCALL.
Before, OCALLs returned PAL error codes, and Linux-SGX PAL converted
them into Linux error codes later. This led to issues like in #438
if two Linux error codes were represented as a single PAL error code.
This patch rewrites OCALLs to return Linux error codes. As a side
effect, Linux-SGX PAL error handling becomes similar to Linux's.
The old code had one indirection too much. This fixes the case that the
thread function returns (instead of calling DkThreadExit). Before this
triggered a SIGSEGV.
This adds a test for thread cleanup. It tests two things:
1. Thred exit in general works, both through return as well as
DkThreadExit.
2. If there's a thread limit, like on SGX, it tests that after a thread
has finished it no longer counts against the limit (currently
broken, see issue #517).