Commit Graph
1455 Commits
Author SHA1 Message Date
Emil Hemdal 22b35e0cb2 [Examples] Use SGX_SIGNER_KEY in Makefiles
The documentation currently specifies SGX_SIGNER_KEY as the parameter to
enable Graphene to find your keys.

Some examples don't use this environment parameter, this commit fixes
that.
2020-05-07 00:21:18 +02:00
Stefan Berger 244a559c48 [Examples] pytorch: Only fail the build if Ubuntu is not used for SGX
The pytorch example can also run on Fedora, so only fail the build
if Ubuntu is not used but the build is for SGX.
2020-05-06 01:19:35 +02:00
borysp d9ed743a6d [LibOS] Add flags checking in wait4 syscall 2020-05-05 19:34:19 +00:00
borysp a9bc8c75ff [LibOS] Remove special handling of stack VMAs 2020-05-02 16:22:47 +02:00
borysp 04ec16c30a [LibOS] Add removing of unmapped VMAs when reexecuting the same binary 2020-05-02 16:22:47 +02:00
borysp a6b50967a6 [LibOS] Add a missing check for stack guard page when removing VMAs 2020-05-02 16:22:47 +02:00
borysp 6cb111b6d1 [LibOS] Completely rework LibOS VMA bookkeeping
This commit completely reworks VMA subsystem along with its usages.
New version should be: cleaner (easier to maintain), faster and allow
for bookkeeping requests from Pal.
It also fixes some bugs and inconsistencies found in the process and
changes brk and mmap/munmap implementations (at least partially).
2020-05-02 16:22:00 +02:00
Dmitrii Kuvaiskii b79940aada [Makefiles] Make Graphene build on Clear Linux
Clear Linux ships with Glibc built with `-Wp,-DFORTIFY_SOURCE=2`.
This overwrites Graphene's `-UFORTIFY_SOURCE` because of the quirk
in how GCC applies arguments (first without Wp, then with Wp).
This commit updates Makefiles to use `-Wp,-UFORTIFY_SOURCE`.
2020-05-01 23:35:49 +00:00
Dmitrii Kuvaiskii 301587065a [LibOS,Pal] Make Graphene build with GCC 9.3
GCC 9.3 adds more static checks on C headers and sources. This
commit fixes all detected issues (mainly possible NULL pointer
dereferences and VLAs on stack).
2020-05-01 23:15:30 +00:00
Stefan Berger dfb7743d41 [Examples] Bash: adjust mount path to directory where executable is found
On Ubuntu 'which' finds 'cp' in '/bin/cp' and on Fedora in
'/usr/bin/cp'. Rather than hard-coding the path '/bin', use
$(EXECDIR) and derive its value from the dirname of the path of the
executable, i.e., either '/bin' or '/usr/bin'.
2020-05-01 20:54:04 +00:00
Stefan Berger 17b1245270 [Examples] Python: adapt Python constants for Fedora
Adapt the python constants so that python-simple also works on
Fedora 31. python-scipy-insecure misses some shared libraries on
Fedora 31, so it does not work there yet.
2020-05-01 20:54:04 +00:00
Stefan Berger 741f5f7cd4 [Examples] Python: move Python constants to Scripts/Makefile.python 2020-05-01 20:54:04 +00:00
Stefan Berger f7f89c2ed2 [Makefiles] Make Graphene compileable and testable on Fedora
Adapt Scripts/Makefile.configs so that we can build and test on
Fedora. Most of the tests in Examples are now also runable on
Fedora. Also add a dependency installation target for Fedora to
TensorFlow example.
2020-05-01 20:54:04 +00:00
Stefan Berger 7f90b68566 [Examples] Nginx: unescape the \n when writing it in config file
Unescape the '\n' as a newline when writing it into the nginx config
file rather than writing it as '\n'. Use printf rather than
`/bin/echo -e` since this seems to work for all distros.
2020-05-01 20:54:04 +00:00
Stefan Berger 206eb81eec [Makefiles] Get arch and distro specific vars from Makefile.configs
Extend Makefile.configs and define several variables for make to use
derived from 'gcc -dumpmachine'. In particular:
- ARCH as the architecture, e.g., x86_64
- ARCH_LONG as the long version of the architecture, e.g., x86_64-linux-gnu
- ARCH_LIBDIR as the directory where libraries are located,
  e.g., /lib/x86_64-linux-gnu

In Makefiles and manifest templates, replace the hard-coded
x86_64-linux_gnu and /lib/x86_64-linux-gnu through these variables.
Extend the already existing sed scripts to replace the necessary
variables.
2020-05-01 20:54:04 +00:00
Michał Kowalczyk b8bfb52520 [Examples] TensorFlow: Fix Makefile and .gitignore 2020-05-01 18:03:28 +00:00
Anjo Vahldiek-Oberwagner f33c368ef6 [Docs] Add prerequisite libcurl4-openssl-dev to Build and Quick Start docs 2020-05-01 16:49:19 +00:00
Michał Kowalczyk 12bedb08a7 [LibOS] Rename SHIM_SYSCALL_PASSTHROUGH to SHIM_SYSCALL_RETURN_ENOSYS 2020-05-01 13:31:09 +02:00
Michał Kowalczyk 6b4e04c859 [Linux-SGX] Fix path to pal-sgx-get-token in error message 2020-04-28 19:41:41 +02:00
Michał Kowalczyk 1cb090d6dd [LibOS] ltp: Revise open() tests 2020-04-27 19:54:55 +02:00
Michał Kowalczyk e39ee4767f Convert flags between PAL API and host syscalls
Currently various flags in file and memory syscalls work mostly by an
accident, because values of some of them align with corresponding Linux
syscall flags. Some APIs weren't that lucky though - e.g.
DkStreamOpen(..., /*options=*/PAL_OPTION_CLOEXEC) deletes file contents
(sic!) intead of opening it with O_CLOEXEC. This is because
PAL_OPTION_CLOEXEC == O_TRUNC.

This commit fixes all this mess and also adds asserts to check validity
of flags passed to Dk* handlers.
2020-04-27 19:54:55 +02:00
Michał Kowalczyk 9aa4370084 [LibOS] test/regression: Make test names consistent 2020-04-25 03:00:53 +02:00
Michał Kowalczyk 19b8dee8ee pal_loader: Disable the annoying GDB banner
Because GDB is awesome this isn't actually configurable in .gdbinit (or
at least I couldn't find any way to do this) and we need to fix it via
the commandline.
2020-04-25 02:14:31 +02:00
Dmitrii Kuvaiskii 642ef8271e [Pal] Remove unused CACHE_LOADED_BINARIES macro 2020-04-23 23:38:06 +00:00
Dmitrii Kuvaiskii 9859fa14cf [Pal/lib] Continue TLS handshake if read/write failed with EAGAIN/EWOULDBLOCK
Linux-SGX PAL uses mbedTLS sessions for encrypted IPC. This requires
a TLS handshake on pipe/socketpair creation. Previously, if the pipe
was created with O_NONBLOCK, read/write callbacks for mbedTLS session
could return EAGAIN or EWOULDBLOCK if the pipe was occupied. We
forgot to check for these error codes, and TLS handshake failed as a
result on the first EAGAIN/EWOULDBLOCK (detected on NodeJS example).
These error codes are actually benign, and Graphene should simply
ask mbedTLS to retry read/write.
2020-04-23 15:01:27 +02:00
Dmitrii Kuvaiskii a7fe4aefa9 [Pal] Force PIE executable to be located at address 0x555555554000
Previously, we forced PIE executables to be located at address
0x00400000 (4MB). However, there is a bug in the ELF relocation code
in LibOS that leads to double-relocation. To circumvent this bug,
relocation code checks if the offset was already relocated. But if
the offset itself exceeds the base address of PIE executable (i.e.,
exceeds 4MB), then the offset is not relocated and segfaults follow.
This commit changes base address from 0x00400000 to 0x555555554000,
similar to what Linux does.
2020-04-22 23:56:38 +00:00
Dmitrii Kuvaiskii f1c65d92df [LibOS] Add attestation pseudo-filesystem under /dev/attestation
This commit adds a new subdirectory in the /dev pseudo-FS and
new pseudo-files to allow applications and helper libraries on
top of Graphene to perform attestation. The currently exposed
primitives are tailored to the Intel SGX local and remote EPID
attestation. App developer writes attestation logic against
this pseudo-FS interface by opening and reading/writing the
following files:
- /dev/attestation/user_report_data: write user-provided report
  data used in `report` and `quote` pseudo-files
- /dev/attestation/target_info: write target info used in
  `report` and `quote` pseudo-files
- /dev/attestation/my_target_info: read this enclave's target info
- /dev/attestation/report: read report (for local attestation)
- /dev/attestation/quote: read quote (for remote attestation)

This commit also adds a corresponding LibOS test `attestation`.
2020-04-21 19:30:58 -07:00
Michał Kowalczyk 2bf40e2a68 [Docs] Fix email formatting in README.rst 2020-04-22 01:03:49 +02:00
Michał Kowalczyk db2c093746 [Pal/Linux-SGX] Drop unused test-sgx.c
It was superseded by sgx-tools (Pal/src/host/Linux-SGX/tools/).
2020-04-21 20:03:44 +00:00
Michał Kowalczyk 4f57ada563 [Pal] Clean up argv handling and PAL invocation
This is a preparation for even more clean-ups and bugfixes, which are
required by protected argv+envp implementation.
2020-04-20 22:00:58 +02:00
Michał Kowalczyk a607e89c7d [Pal] Fix formatting, typos and types in a few places 2020-04-20 22:00:58 +02:00
Michał Kowalczyk f26b4fd254 [Pal] Clean up ELF magic checking 2020-04-20 22:00:58 +02:00
Michał Kowalczyk 412b581c51 [Pal] Add an assert to get_norm_path()
This property was already implicitly assumed in a few callsites. We'd be
better to document & assert it.
2020-04-20 22:00:58 +02:00
Michał Kowalczyk 5e2eee0086 [Pal] Remove likely/unlikely macros 2020-04-20 22:00:58 +02:00
Dmitrii Kuvaiskii 069ac84bfc [Pal/lib] Makefile: add dependency on mbedTLS patch (.diff) 2020-04-20 13:41:42 -07:00
borysp 63cdcd33e4 [LibOS/test/fs] Remove invalid mmap on file opened write-only 2020-04-20 11:18:24 -07:00
Dmitrii Kuvaiskii cd1648bcd8 [Pal] Enforce that executable is always located at a predefined address
Previously, the PAL layer would put an executable at a first unoccupied
address range if the executable was position-independent (PIE). This
could lead to the same executable being located at different addresses
across forks (Graphene correctly checkpoints shared libraries but
has separate handling for the executable). This is a rare scenario
since the PAL initialization code is typically deterministic across
forks. However, rarely there would be small difference in allocations
which would lead to different base addresses for executable segments
in parent and child processes, and segfaults and data corruptions
happened (this was the case for Nginx on Ubuntu 18.04 with change in
the manifest file processing). This commit simply forces executables
to always be loaded at a predefined address (currently 0x00400000).
2020-04-20 02:59:43 +02:00
Dmitrii Kuvaiskii 90585e0d07 [LibOS/test] Fix incorrect options arg for waitpid() in udp.c and tcp.c 2020-04-17 15:39:29 -07:00
Dmitrii Kuvaiskii 21003c9d7a [Linux-SGX] tools: Error out on incorrect SGX measurements
Previously, `verify_quote()` had bug: it errored out on incorrect SGX
measurements only in verbose mode. This led to silently accepting
incorrect measurements if this function was executed in silent mode.
2020-04-17 16:16:10 +00:00
Dmitrii Kuvaiskii 5c28356087 [Linux-SGX] tools: improve APIs to simplify usage in libraries
Previously, APIs `verify_ias_report()`, `verify_quote()`,
`ias_verify_quote()` used hex/decimal strings as arguments and
saved IAS response contents to files. This is not convenient for
library usage. This commit allows to pass raw-data arguments to
`verify_ias_report()` and `verify_quote()`, as well as adds
`ias_verify_quote_raw()` to output IAS response contents in memory.
Also, `hexdump_mem_to_buffer()` utility is added.
2020-04-17 16:16:10 +00:00
Dmitrii Kuvaiskii 8d9f9f567f [Pal/Linux-SGX] Put TLS-context init logic in critical section
mbedTLS configuration used in Graphene is not thread-safe (because
this would require the use of a threading library like pthread which
is not possible in the LibOS/Pal layers). However, some mbedTLS
functions use shared state, in particular TLS context initialization
functions. This led to data races during encrypted-pipe creation,
since it requires two threads performing a TLS handshake. This commit
refactors TLS init into SSLInit (not thread-safe) and SSLHandshake
(thread-safe) and adds spinlocks around SSLInit to protect the racy
mbedTLS logic.
2020-04-17 01:30:00 -07:00
Michał Kowalczyk 964fd17910 [Docs] Misc rewordings 2020-04-15 23:35:12 +02:00
Michał Kowalczyk 1dad67b481 [Docs] Fix links formatting 2020-04-15 23:35:12 +02:00
Michał Kowalczyk e060006bd7 [Docs] Drop the last mention of security monitor 2020-04-15 23:35:12 +02:00
Michał Kowalczyk f07ff167fc [Docs] Clean up mentions of integration examples 2020-04-15 23:32:00 +02:00
Michał Kowalczyk b89d7c6f22 [Docs] Update CONTRIBUTING.rst 2020-04-15 23:32:00 +02:00
Michał Kowalczyk 87f133f435 [Docs] Use auto-numbered lists in reST files 2020-04-15 23:32:00 +02:00
Michał Kowalczyk 9d2f50c355 [Docs] Add notes about security 2020-04-15 23:32:00 +02:00
Michał Kowalczyk 4f6153b4cd [Docs] Mention that DCAP requires root 2020-04-15 23:32:00 +02:00
borysp bbc2387d76 [Pal/lib] Add missing root node update to avl_tree_swap_node 2020-04-15 12:20:29 +02:00