* Fix a bug where configuration error ends up doing a huge allocation, rather than catching the error. Add some documentation to the slabmgr code.
* Add a unit test and some documentation to answer the question in issue #107. I can't see how offset and map_start would end up being different.
* Rewrite of SGX file_map to remove TOCTTTOU now passes all unit tests
* Apply a similar fix to file_read.
* Factor complicated verification code into a common helper routine.
* Adjust the memory copying strategy so that all bits in the returned buffed are exactly the same bits as verified in the trusted, scratch buffer.
* Fixing the TOCTOU issue in file checking
* Adding comments for load_trusted_file() and copy_and_check_trusted_file(); Deprecate the old design
* Documenting the file checking mechanism
Fix a bug where configuration error ends up doing a huge allocation, rather than catching the error. Add some documentation to the slabmgr code.
Fix a stack corruption on signal delivery in a PAL call. Basically, some important code that saves registers and other state, in case we need to jump out of the PAL, was getting optimized out. Added some documentation about how the exception handling code works.
A bugfix for getsockname()
* Fix a PAL unit test
* Make the PAL unit tests fail properly if one that should work doesn't.
* Get consistent indexes with and without graphene ipc module
* A little debugging output for ltp flakiness. Seems to make things a little more stable.
* A bugfix for issue #80. The migration is not complete when a file-backed VMA is larger than
the file size, but the file size is not page-aligned. In Linux, if the file size is smaller
than the mapped memory, accessing the remaining memory that is not backed by the file will
trigger a SIGBUS. However, it is fine to access the remaining memory within the last page that
still overlaps with file, and won't trigger a SIGBUS. This area is commonly used in ELF binary
to store uninitialized, static variables. To improve fork latency, Graphene chooses to
truncate the migration size as the file size, but missed the memory which belongs to the last
file-backed page. The migration size should be aligned up to the page size.
* Fix assertion lines in PAL and LibOS
* Make sure the return code is correct for the LTP script, bump up some timeouts
* Only run gipc tests when the module is loaded, for the purposes of getting CI to work.
* Build fix
- Fixing AES-CMAC algorithm
- Using SHA512 to hash file stubs (much faster than SHA256 and AES-CMAC)
- Hardening enclave interface (still work-in-progress); delt with issue #28
- Handling socket/pipe polling better
- Allowing setting the lowest heap address in enclaves ('sgx.heap_min' in manifest)
- Fixing the pipe between processes (for SGX)
- Fixing race condition in futex handling in LibOS
- Inheriting epoll handles in forked chilren
- Assigning signal code (now only hard-coding FPE_INTDIV, BUS_ADRERR, SEGV_ACCERR, SEGV_MAPERR)
- Fixing race condition in vma allocation (likely to fix bug() in bookkeep/shim_vma.c)
- Clearer debug message in LibOS
- Fixing calling convention in LibOS and glibc
- Fixing futex behavior (FUTEX_WAIT takes relative time, FUTEX_WAIT_BITSET takes absolute time)
- More system call implemented
- More application working (NGINX)
- Fix a severe bug caused by merging #87. The patch does not check the return values from get_config_entries_size(), while the return values can easily be negative (-PAL_ERROR_INVAL). Any usage of this function should carefully check the return values and also pass the size into get_config_entries() to prevent buffer overflow.
- Fix a minor bug in handling IPC disconnection. The callback ipc_child_exit() never receives a "term_signal" parameter. The callback is called when thepipe to a child process unexpectedly terminates, which can only mean the child process has crashed. I believe the proper signal to send is SIGKILL.
- Remove a compilation warning caused by type mismatch of __malloc().
- Allow binding TCP socket to ANY address
- enable LD_PRELOAD in glibc
- disable output buffering in LTP tests to reveal omitted passes
- Remove a double-unlock in shim_async.c
- Replace all int with size_t or ssize_t in Graphene configuration API
- Add new passed LTP tests
Run CI in a Docker image
* Wait a second for lighttp and apache to fully initialize the socket
* Try to add a timeout for lmbench, which is prone to hanging (vfork)
* Set a timeout on gcc; one of the PRs is causing gcc hello to hang. Also, to avoid interference, run apache test on 8001 by default.
* Update lmbench to ignore bin dir
* Do the faster tests first; fail earlier
* Get the IP addr properly for web server tests
* Some notes on flaky LTP tests to debug later. Move a few that tend to heisenbugs off of the required list for now
* Try to detect vma list corruption during the debug dump, lest it be infinite.
* Temporarily disable the lmbench vfork test (Issue #142).
* Catch some failures faster.
* Catch failures in apachebench
* Take apache out of the Linux host/Debug build CI for now, as it hangs consistently. Filed issue #144 to track.
* add memusg to pal_loader script
* Stop bleeding PAL handles.
Deprecating DkOjectReference and reference counting in PAL handle.
Deprecating DkSemaphoreDestroy and DkEventDestroy (replaced by DkObjectClose).
Cleaning unused PAL handles in the library OS.
Adding a heap tracing feature to profile usage of PAL handles.
* fix a bug in SGX mode that mapping untrusted files into memory never got free by DkVirtualMemoryFree()
* adding lighttpd SSL option
* fixing the freeing convention of PAL handles; On SGX, event and mutex handles need to be freed seperately.
* changing how mutexes and events are allocated on SGX
* fixing GCC regression tests (for both Linux and SGX)
* fix a double-free problem of the first thread handle
* A bugfix for issue #80. The migration is not complete when a file-backed VMA is larger than
the file size, but the file size is not page-aligned. In Linux, if the file size is smaller
than the mapped memory, accessing the remaining memory that is not backed by the file will
trigger a SIGBUS. However, it is fine to access the remaining memory within the last page that
still overlaps with file, and won't trigger a SIGBUS. This area is commonly used in ELF binary
to store uninitialized, static variables. To improve fork latency, Graphene chooses to
truncate the migration size as the file size, but missed the memory which belongs to the last
file-backed page. The migration size should be aligned up to the page size.
* adding several test cases for mmap with files
* adding /tmp to the ltp manifest
* add documentation about the corner cases of mmap + fork
* Migrate running unit tests for Linux host to Jenkins. Add a unit test for the Linux host, Debug build
* Ignore files generated as part of unit testsing.
* A quick and dirty fix for port collisions during CI tests. Come back and do a better job if we continue having problems
* For some reason, the PAL Process regression tests fail using the default manifest under a debug build. Go ahead and explicate a template for the Process test.
* Fix a PAL unit test
* Make the PAL unit tests fail properly if one that should work doesn't.
* Get consistent indexes with and without graphene ipc module
* A little debugging output for ltp flakiness. Seems to make things a little more stable.
* A bugfix for issue #80. The migration is not complete when a file-backed VMA is larger than
the file size, but the file size is not page-aligned. In Linux, if the file size is smaller
than the mapped memory, accessing the remaining memory that is not backed by the file will
trigger a SIGBUS. However, it is fine to access the remaining memory within the last page that
still overlaps with file, and won't trigger a SIGBUS. This area is commonly used in ELF binary
to store uninitialized, static variables. To improve fork latency, Graphene chooses to
truncate the migration size as the file size, but missed the memory which belongs to the last
file-backed page. The migration size should be aligned up to the page size.
* Fix assertion lines in PAL and LibOS
* Make sure the return code is correct for the LTP script, bump up some timeouts
* Only run gipc tests when the module is loaded, for the purposes of getting CI to work.
* Build fix