Commit Graph
311 Commits
Author SHA1 Message Date
Dmitrii Kuvaiskii 17b3997226 [Pal] Fix htonl/htons() byte-order macro to __BYTE_ORDER 2019-05-13 14:37:27 -07:00
Gary 07a021dbea [PAL] Fix an out of bounds read on generic.fds[]
MAX_FDS is defined as 3, fds[MAX_FDS] is a 3-element array.
While i in for loop looping from 0 to MAX_FDS, will cause out-of-boundry read for generaic.fds which is a 2-element array.
The generic.fds defiend in pal_host.h should be correctly sized to match with both fds[MAX_FDS] and accommodate for the for loop.
Also fixed another out-of-boundary access for pipeprv
2019-05-08 14:35:19 +02:00
Gary 4ae620f87b [PAL] Correct memory allocation in file_rename() and dir_rename()
Use strdup() to correctly copy a string with NULL termination.
Prevent memory leak by freeing {file,dir}.realpath when needed.
2019-05-07 16:41:53 -07:00
Isaku Yamahata 5992881c46 [Pal/Linux-SGX] Clear RFLAGS before calling _DkExceptionHandler
This is follow up of https://github.com/oscarlab/graphene/pull/643
RFLAGS.DF must be cleared when calling a C function.
2019-05-07 22:39:50 +02:00
Michał Kowalczyk 2bc2c04194 Remove trailing blanks 2019-05-07 16:32:16 +02:00
Michał Kowalczyk 640b7cc80f [Pal/Linux-SGX] Remove unused user_types.h 2019-05-06 21:42:48 -07:00
Michał Kowalczyk 281a05ce48 Fix camel case in DkStreamAttributes{Query,Set}ByHandle 2019-05-06 18:11:15 -07:00
Simon Gaiser 3f72eb69de [Pal/Linux-SGX] Rename .Lhandle_resume to .Lprepare_resume
This code path is called when the urts EENTERs to allow us to prepare
the SSA for the following ERESUME (i.e. inject the exception handler).
It is not for the ERESUME itself. So rename it to avoid confusion.
2019-05-07 01:24:32 +02:00
Simon Gaiser fcc1c3ee58 [Pal/Linux-SGX] Improve comments below enclave_entry
The comment about the register content is only true for EENTER. Also
usually* this code is reached only by EENTER. ERESUME restores the saved
state from the SSA.

*: It is reached if an async exit happens just after EENTER.

Also remove redundant comments directly below.
2019-05-07 01:23:52 +02:00
Isaku Yamahata d4d7546de0 [Pal] Fix sign of a few PAL return values
Some PAL functions return positive error code accidentally.
2019-05-06 19:49:18 +02:00
Michał Kowalczyk d7b3d6074a Align stack to 16 when calling C from asm 2019-05-04 14:16:21 +02:00
Isaku Yamahata 5b3b69332a [Pal/Linux-SGX] Disallow nested signals at host-OS level
This commit ensures that TCS.CSSA == 1 while entering enclave
execution to handle a signal from host OS (recall that CSSA == 0 is for
normal enclave execution and CSSA == 1 is for signal-handling
enclave preparation). This effectively disallows nested signal handling
from a malicious OS. Disallowing nested signals simplifies our code.
Benign OS is prevented from nesting by blocking async signals during
signal handling.

Note that currently enclaves are always run with TCS.NSSA == 2, and SGX
hardware will disallow entering the enclave if TCS.CSSA > 1. Thus, this
commit serves as an assertion in case NSSA limit is changed in future.
2019-05-03 15:45:00 -07:00
Dmitrii Kuvaiskii 76fa183257 [Pal/Linux-SGX] Fix UDP bug with connect() in sgx_ocall_sock_connect()
Before, connect() host-OS syscall was issued unconditionally in
sgx_ocall_sock_connect(). However, UDP clients do not strictly need to
issue connect() before sending packets to UDP server. In this case, addr
is NULL, and sgx_ocall_sock_connect() must not issue connect().
2019-05-03 12:50:03 -07:00
Dmitrii Kuvaiskii 121fc9bf1d [Pal/{Linux, Linux-SGX}] Initialize addrlen's to zeros in socket_parse_uri() 2019-05-03 12:50:03 -07:00
Isaku Yamahata 0a8f97af5a [Pal/{Linux, Linux-SGX}] Add NULL check in udp_connect/sgx_ocall_sock_connect
This patch also adds a UDP LibOS regression test.
2019-05-03 12:50:03 -07:00
Dmitrii Kuvaiskii 40fc490fcd [Pal/Linux-SGX] OCALL security hardening
- Time-Of-Check-To-Time-Of-Use (TOCTOU) vulnerability is closed
    by first copying untrusted values inside enclave and then
    operating on these copied values; see sgx_copy_to_enclave().
  - Pointer/integer overflow is closed by comparing against a
    trusted maximum value in sgx_copy_to_enclave().
  - Untrusted stack overflows in sgx_alloc_on_ustack()/sgx_copy_to_ustack()
    are closed by checking for NULL return values.

These vulnerabilities were independently discovered and disclosed
by David Oswald, Jo van Bulck, and others.
2019-05-02 14:12:34 -07:00
Isaku Yamahata 47acfc32bc [Pal] Use := to get correct dir in Makefile.Test 2019-05-02 00:10:30 -07:00
Isaku Yamahata 2167a349c9 [Pal/Linux-SGX] Remove unnecessary __alloca()
Replace abuses of __alloca() with normal stack variables.
2019-05-02 02:05:13 +02:00
Isaku Yamahata 8dd311a353 [Pal/Linux-SGX] Add format check to pal_printf
Add __attribute__((format(printf))) check to pal_printf and
fix corresponding format errors.
2019-05-01 15:50:12 -07:00
Isaku Yamahata c29bcc8c5b [Pal, LibOS] Add missing clobbered "cc" to inline asm 2019-05-01 13:21:30 +02:00
Isaku Yamahata 8890b325b4 [Pal, LibOS] Clear RFLAGS on program entry
SYSV x86-64 ABI requires RFLAGS to be cleared in initial register state.
2019-05-01 13:21:30 +02:00
Isaku Yamahata 2de42097fe [Pal/Linux-SGX] Clear RFLAGS.DF on enclave entry
SYSV x86-64 ABI requires RFLAGS.DF to be cleared when entering a function (other flags are
undefined) and we can't trust non-SGX side to do this.
2019-05-01 13:19:31 +02:00
Simon Gaiser 917356119c [Pal/Linux-SGX] Don't get heap min/max from urts
Instead pass them through the measured TLS.

Part of issue #509.
2019-04-30 21:55:19 -07:00
Simon Gaiser 63d4f01194 [Pal/Linux-SGX] Don't get exec addr/size from urts
Instead pass them through the measured TLS.

Part of issue #509.
2019-05-01 03:44:23 +02:00
Simon Gaiser 33433459c7 [Pal/Linux-SGX] Document usage of TLS 2019-05-01 02:49:47 +02:00
Simon Gaiser 7ffc287314 [Pal/Linux-SGX] Don't get manifest addr/size from urts
Instead we use the fact that the manifest is always placed at the top of
the enclave address range. The manifest size is stored inside the TLS
like we have already done for the enclave size.

Part of issue #509.
2019-05-01 02:49:47 +02:00
Isaku Yamahata f72cd48ee5 [LibOS] Emulate pause() by sleeping for a very long time
Before, pause() was emulated by sleeping for 1s in a loop until
signal interrupted it. If signal arrived in-between these invocations
then pause() could never return. Also, pause() incorrectly returned 0
instead of -1 and errno=EINTR.

This patch emulates pause() by sleeping for a very long time (years).
Also, it correctly returns EINTR.
2019-04-30 17:07:51 -07:00
Michał Kowalczyk 382a1ec394 Cleanup .gitignore files 2019-04-30 23:16:38 +02:00
Michał Kowalczyk 29f44c836b [PAL] Document [_]DkRandomBitsRead 2019-04-30 22:26:08 +02:00
Michał Kowalczyk 17102eab9d Change DkRandomBitsRead interface and fix error checking
Now it returns 0 on success and -PAL_* on error.
2019-04-30 22:26:08 +02:00
Michał Kowalczyk 57749eb973 [LibOS] Don't use insecure random 2019-04-30 22:23:04 +02:00
Dmitrii Kuvaiskii bd72b968ee [*/regression] Increase timeout of regression tests
On weaker machines (Intel NUCs and SGX-enabled laptops),
SGX regression tests take longer than 5 seconds because
Graphene measures/zeroes all enclave memory at startup.
Increase the timeout for SGX regression tests to 20 sec.
2019-04-29 18:10:32 -07:00
Simon Gaiser 63b8ef41cf [Pal/regression] Test timeout handling when waiting for events 2019-04-30 01:11:31 +02:00
Simon Gaiser ab29483bbe [Pal/regression] Increase 'Process' test timeout a bit
On SGX spawning processes got slower since we measure/zero all memory.
So the timeout is slightly missed.
2019-04-29 21:31:59 +02:00
Simon Gaiser 014a938767 [Pal/Linux-SGX] Measure all memory except the heap
Before this change some important memory areas, for example TCS and TLS
were not measured. With this change all mapped enclave memory is
measured with one exception. Since the EEXTEND hashing is rather slow
the heap is not measured. Instead it gets zeroed on enclave startup.

Closes #505.
2019-04-29 21:31:15 +02:00
Simon Gaiser 838c14022b [Pal/Linux-SGX] Use autogenerated constants in pal-sgx-sign 2019-04-29 21:30:59 +02:00
Simon Gaiser 402fce72ba Autogenerate offsets for Python
This makes the offset generator more generic to generate a python module
in addition to a header for assembly.
2019-04-29 21:30:09 +02:00
Simon Gaiser b0390865f5 [Pal/Linux-SGX] Clear "extented state" (FPU regs & co) before EEXIT 2019-04-29 19:32:16 +02:00
Simon Gaiser 19fb0d2d89 [Pal/Linux-SGX] Use common code path to clear regs and then EEXIT 2019-04-29 19:32:16 +02:00
Simon Gaiser 3ab875dd52 [Pal/Linux-SGX] Drop unused label in enclave_entry.S 2019-04-29 19:32:16 +02:00
Simon Gaiser bf87ac02f2 [Pal/Linux-SGX] Honor red zone when handling async exits
Before .Lhandle_exception used the stack directly and thereby messed
with the red zone of the interrupted code.

Also ensure that the stack is aligned before calling
_DkExceptionHandler.
2019-04-29 00:05:22 +02:00
Simon Gaiser 2b8c4fc30b [Pal/regression] Add test for red zone 2019-04-29 00:04:22 +02:00
smherwig ac692e1544 [PAL/Linux-SGX] Use PRESET_PAGESIZE instead of hardcoded "4096"
Change applies to the ocall_read, ocall_write, ocall_sock_recv,
and ocall_sock_send functions.
2019-04-28 12:43:05 -07:00
smherwig 4b8f74a8d8 [PAL/Linux-SGX] Allow ocall_sock_send/recv to allocate on heap
ocall_sock_recv/send copied/allocated buffers on untrusted stack.
If buffer sizes were large, the stack overflowed. This patch
allocates buffers on untrusted heap if size is too large.
2019-04-28 12:43:05 -07:00
Isaku Yamahata 144dee3d6b [Pal/Linux-SGX] Propagate exact error code from OCALL
Before, on many execution paths after failed OCALL, the returned
PAL error was hardcoded. This patch removes these hardcoded errors
and propagates the original error code from OCALL.
2019-04-27 12:43:27 +02:00
Isaku Yamahata 016b238b41 [Pal/Linux-SGX] Simplify sgx_create_process() control flow 2019-04-27 12:43:27 +02:00
Isaku Yamahata 4f7841e14c [Pal/Linux-SGX] Return Linux error codes in OCALLs
Before, OCALLs returned PAL error codes, and Linux-SGX PAL converted
them into Linux error codes later. This led to issues like in #438
if two Linux error codes were represented as a single PAL error code.
This patch rewrites OCALLs to return Linux error codes. As a side
effect, Linux-SGX PAL error handling becomes similar to Linux's.
2019-04-27 12:43:27 +02:00
Simon Gaiser 003035de7e [Pal/Linux] Fix _DkThreadExit call in thread_start
The old code had one indirection too much. This fixes the case that the
thread function returns (instead of calling DkThreadExit). Before this
triggered a SIGSEGV.
2019-04-26 18:24:26 +02:00
Simon Gaiser 87b139019a [Pal/regression] Test thread cleanup
This adds a test for thread cleanup. It tests two things:

 1. Thred exit in general works, both through return as well as
    DkThreadExit.

 2. If there's a thread limit, like on SGX, it tests that after a thread
    has finished it no longer counts against the limit (currently
    broken, see issue #517).
2019-04-26 18:24:26 +02:00
Isaku Yamahata 848321909d [Pal/Linux-SGX] Make message on thread allocation failure more friendly 2019-04-26 03:26:56 +02:00