91 Commits
Author SHA1 Message Date
Michał Kowalczyk b789ed3a17 Remove partially-implemented static guard pages
It turns out that our guard pages were incorrectly handled (i.e. not re-
added to LibOS VMA list) on SGX when execve was optimized to re-use the
same enclave, which caused exec_same test to crash from time to time
(when ASLR put heap on a guard page).

Static guard pages aren't too useful and introduce unnecessary
complexity to our code, so we decided to just delete them in order to
fix this bug.
2020-07-21 13:48:18 +02:00
Dmitrii Kuvaiskii 0a06c898d4 [Pal/Linux-SGX] Provision wrap key for protected files at runtime
This commit adds the ability to provision the wrap (master) key for
protected files at runtime (in contrast to previous approach of
hard-coding `protected_files_key` in the manifest as a temporary
solution). This is achieved as follows:

- New PAL API `DkSetProtectedFilesKey()` is added.
- New writable pseudo-file `/dev/attestation/protected_files_key` is
  added. It calls `DkSetProtectedFilesKey()` after it was written to.
- New `SECRET_PROVISION_SET_PF_KEY` option is added to the Secret
  Provisioning library. If it is set, the library assumes that the
  first provisioned secret is the wrap key for PF and writes it into
  the new pseudo-file.

The Secret Provisioning example `ra-tls-secret-prov` is updated to
include the new protected-files client. This client receives the wrap
key for PF via secret provisioning and reads & outputs the protected
file `files/input.txt`.

*NOTE*: The current implementation of provisioning the wrap key does
not work for `loader.argv_src_file` and `loader.env_src_file` if they
point to protected files (because provisioning happens after setting
up arguments and environment variables).
2020-07-19 21:50:45 +00:00
Gary f24bb06fdd [Pal/Linux-SGX] Optimize _DkSystemTimeQuery performance using TSC
This patch optimizes _DkSystemTimeQuery() using RDTSC instead of
ocall_gettime.

This optimization won't take effect if there is no reliable TSC source
available to use i.e. nonstop/invariant TSC.

The TSC drift is bound by syncing with system clock periodically.
2020-07-16 01:34:34 +02:00
Michał Kowalczyk 7b0c160296 [Pal] Protect env from untrusted world 2020-07-13 22:05:04 +02:00
Michał Kowalczyk f948351243 [Pal] Fix out-of-bounds read in strstartswith_static 2020-07-13 22:05:04 +02:00
Rafał Wojdyła cf84489cd5 [Linux-SGX] Add protected files implementation
Protected files (PF) are a new type of file that can be specified in
the manifest (SGX only). They are encrypted on disk and transparently
decrypted when accessed by the Graphene payload.

Other features:
- data is integrity protected (tamper resistance)
- file swap protection (a PF can only be accessed when in a specific path)
- transparency (Graphene payload sees PFs as regular files, no need to modify
  the payload)

See Linux-SGX/protected-files directory for implementation. PF format is
based on protected files from the SGX SDK:
https://github.com/intel/linux-sgx/tree/master/sdk/protected_fs

The following new manifest elements are added:

sgx.protected_files_key = <16-byte hex value>
sgx.protected_files.<name> = file:<host path>

sgx.protected_files_key specifies the encryption key and is only a temporary
implementation. This key should be provisioned with local/remote attestation
in the future.

Paths specifying PF entries can be files or directories. If a directory is
specified, all files/directories within are registered as protected
recursively (and are expected to be encrypted in the PF format).

Linux-SGX/tools directory contains the pf_crypt utility that converts files
to/from the protected format.
2020-07-13 20:19:42 +02:00
Michał Kowalczyk cb7d430655 Remove always_inline where not needed 2020-07-05 17:24:06 +02:00
Dmitrii Kuvaiskii 57bbbe321a [Pal/lib] Replace old memory-handling functions with simpler versions
Graphene used its own implementations of memory-handling functions like
memcmp(), memcpy(), etc. These implementations were copied from Glibc
and contained complicated code from year 2004. Modern HW and compilers
do better job at optimizing simple C implementations of these functions.
Thus, this commit replaces old implementations with simple ones taken
from Musl libc and adapted to our code style.

One particular optimization is made to memcpy() on x86-64. memcpy() is
heavily used in Linux-SGX PAL to copy data in/out of SGX enclave.
Experiments with Redis 5.0 show perf improvement of using "rep movsb" at
3-5% for 4KB payloads over the previous implementation based on Glibc.
2020-07-02 16:38:31 +00:00
Stefan Berger 91709ac2fe [LibOS,Pal] Set weak parameter in atomics operations to false
The `weak` parameter has no influence on x86, but on ppc64 it causes
spurious faults due to a missing check on flags (missing `bne`
instruction).
2020-07-01 22:08:52 +00:00
Jörg Thalheim b8907acf42 [Pal] Add AT_HWCAP2 to include/elf/elf.h 2020-06-30 18:14:57 +00:00
Stefan Berger ab4f14df33 [Pal+LibOS] Drop wrappers from atomic.h
This is the first step in removing this obsolete header.
Additionally, AtomicMath test is removed, as it became obsolete after
these changes (and was relying on undefined behaviors anyway).
2020-06-26 14:31:23 +02:00
Stefan Berger 08311935b5 [Pal] Move x86_64-specific CPUID into cpu.h, pal-arch.h, db_main-x86_64.c 2020-06-18 23:16:23 +00:00
Stefan Berger 4ee3e8242b [LibOS,Pal] Implement arch-specific pal_context_has_user_pagefault() 2020-06-16 19:55:04 +00:00
Michał Kowalczyk 0f55c6de04 Use SPDX IDs for licenses in source files 2020-06-13 03:25:33 +02:00
Dmitrii Kuvaiskii ed3b438755 [LibOS,Pal] Introduce "loader.insecure__disable_aslr" manifest option
Previously, Graphene always performed ASLR at the LibOS layer. ASLR
may lead to a situation when one mmap allocates an object in the
middle of address space, and there is no space for a later mmap of
a large object. This is problematic in restricted environments such
as SGX enclaves. In particular, `large_mmap` LibOS test failed
occasionally because it only has 8GB of enclave size and it may
mmap first objects somewhere in the middle (around 4GB address) and
then fail to find any space for a large 4GB mmap.

This commit adds "loader.insecure__disable_aslr" manifest option.
If it set to one, ASLR is disabled and mappings become deterministic
which guarantees programs like `large_mmap` never fail due to ENOMEM.
2020-06-12 19:19:21 +00:00
Stefan Berger 7b74da7e05 [Pal/Linux-SGX] Implement pal_ucontext_set_function_parameters() 2020-06-11 10:57:02 -07:00
Stefan Berger 7383da296a [Pal/{Linux,Linux-SGX}] Implement pal_ucontext_get_ip() 2020-06-11 10:57:02 -07:00
Dmitrii Kuvaiskii a958ff0bca [LibOS,Pal] Emulate SIGPIPE via creating and sending this signal on EPIPE
Previously, Graphene simply forwarded SIGPIPE generated by the host to
LibOS/app. Unfortunately, SIGPIPE generation is a process-wide feature
and there is no portable way to restrict it only to a subset of pipes,
UNIX domain sockets, etc. This led to sporadic Graphene failures
because Graphene's internal use of pipes and sockets may result in an
unexpected (to application) SIGPIPE.

This commit removes the forwarding of SIGPIPE. Instead, PALs explicitly
ignore SIGPIPE. This forces the host to return EPIPE error code, which
is checked only on a subset of LibOS handles (the ones created by the
app), and if required, LibOS generates a SIGPIPE for the application.

While adding this logic, the whole PAL exception code was refactored,
both in Linux and Linux-SGX. Tests for SIGPIPE are now enabled for
both Linux and Linux-SGX PALs.
2020-06-10 22:30:40 +00:00
Stefan Berger 052033df9d [Pal] Factor out read_file_buffer() from get_bogomips() and refactor 2020-06-10 00:27:10 +00:00
Stefan Berger bf155c7bc9 [Pal/lib] Implement strstr() 2020-06-10 00:27:10 +00:00
Stefan Berger 8e06bbb97a [PAL+LibOS] Replace inline assembly for atomics with atomic built-ins 2020-06-05 11:52:08 +02:00
Stefan Berger fff09c00af Add -Wmissing-prototypes to CFLAGS and deal with the fallout 2020-06-04 17:22:19 +02:00
Stefan Berger ddab51259c [PAL] Move random number call to arch-specific inline function
Also include the header with the prototype of mbedtls_to_pal_error
function to verify it's the same as defined in mbedtls_adapter.c.
2020-05-29 11:43:21 +02:00
Stefan Berger 9fa7fd5186 [PAL] Change comment in code to proper filename dl-machine.h 2020-05-29 11:43:21 +02:00
Stefan Berger c1c085ca15 Remove duplicate ucontext from shim_types-arch.h
Use the ucontext from PAL instead. LibOS now has access to the inline
functions for copying PAL_CONTEXT to ucontext and vice versa and we use
them where possible.

We need to introduce a ucontext.h for Skeleton. It does need ucontext
to be defined for being able to compile shim_signal.c. The easiest way
to achieve this is to rely on Linux's ucontext.h.

SGX can reuse Linux's ucontext.h and sigcontext.h.
2020-05-28 21:08:49 +02:00
Stefan Berger 94480ba1c6 [PAL+LibOS] Wrap accesses to PAL_CONTEXT's instruction poiner
Implement and use pal_context_set_ip and pal_context_get_ip to access
the instruction pointer.
2020-05-28 12:38:41 +02:00
Stefan Berger e379f21419 Implement cpu_pause() in arch-specific cpu.h
... instead of using inline asm. Required for portability to other
architectures.
2020-05-27 22:19:33 +02:00
Stefan Berger 122bc94a80 [Pal] Move x86_64-specific DEFAULT_OBJECT_EXEC_ADDR to pal-arch.h 2020-05-20 03:07:58 +02:00
Stefan Berger 9e6af37f42 [Pal] Move pal_linux_defs.h to include/arch/x86_64/Linux 2020-05-20 03:07:56 +02:00
Stefan Berger e0ca25a413 [Pal] Move x86_64 syscall arch_prctl into Linux-specific pal_set_tcb()
Move the Linux x86_64 specific syscall arch_prctrl into a new inline function
pal_set_tcb located in include/arch/x86_64/Linux/pal_host-arch.h. The SGX and
Skeleton builds now also need a pal_host-arch.h file, empty for now.
2020-05-18 21:26:28 -07:00
Stefan Berger 54d6c87589 [Pal] Implement functions for copying to and from PAL_CONTEXT
Implement inline functions for copying CPU context between PAL_CONTEXT
and ucontext_t. Add an assert to make sure that the number of registers
in both contexts is the same.
2020-05-15 19:27:43 -07:00
Stefan Berger fbf67a2a8e [LibOS,Pal/Linux] Deliver SIGPIPE to an application
This patch adds a new PAL_EVENT_PIPE to handle EPIPE signals
and forward them to the signal handler installed in LibOS.
If the application does not have a signal handler installed,
it will terminate the application with SIGPIPE exit code.
Support for SIGPIPE in Linux-SGX PAL will be added in a follow-up
commit.
2020-05-15 12:25:56 -07:00
Stefan Berger f781cc9192 [Pal] Move Linux elf-x86_64.h to include/arch/x86_64/Linux/elf-arch.h
Also, adapt #includes where needed. Avoid the name elf.h to avoid
clashes. We do not touch the Linux-SGX/elf-x86_64.h file since it is
slightly different.
2020-05-13 14:53:09 +02:00
Stefan Berger a179c79e3c [Pal] Factor out arch-specific TCB part to pal-arch.h 2020-05-12 21:22:04 +02:00
Stefan Berger 14db27c34a [Pal] Define PAGE_SIZE in pal-arch.h and use in regression test
Define the typically used PAGE_SIZE in pal-arch.h and use it in the
File.c regression test that maps memory of one page.
2020-05-12 18:31:35 +02:00
Stefan Berger 2e3e7c526c [Pal] Move PRESET_PAGESIZE into arch/x86_64/pal-arch.h 2020-05-12 18:31:35 +02:00
Stefan Berger ffbc41ba55 [Pal] Fix wrong error code from Pal when pipe is broken
Introduce PAL_ERROR_CONNFAILED_PIPE and treat EPIPE separately
from ECONNRESET.

The effects of this patch on LTP are:

from:
	writev01.c:139: FAIL: write to closed pipe, expected: -1 (EPIPE), got: -1 (ECONNRESET)
to:
	writev01.c:139: PASS: write to closed pipe, expected: -1 (EPIPE), got: -1 (EPIPE)

AND:

from:
	write05.c:82: FAIL: write() failed unexpectedly, expected EPIPE: ECONNRESET
to:
	write05.c:87: FAIL: sigpipe_cnt = 0

writev01 now works correctly, so this commit enables it.
2020-05-12 13:18:07 +02:00
Stefan Berger 98187f6b93 [Pal] Move Linux x86_64 specific ucontext.h to arch/x86_64/Linux
Move the Linux x86_64 specific ucontext.h to arch/x86_64/Linux.
The SGX and non-SGX files are identical.
2020-05-12 06:17:41 +00:00
Stefan Berger ea2c54d39c [Pal] Move x86-64 sigcontext.h and sigset.h to arch/x86_64/Linux
Move the x86-64-specific sigcontext header files to arch/x86_64/Linux.
The SGX and non-SGX files are identical.

We are also moving sigset.h since on ppc64 the following defines are
different:

x86_64: #define _SIGSET_NWORDS (64 / (8 * sizeof(unsigned long int)))
ppc64:  #define _SIGSET_NWORDS (1024 / (8 * sizeof (unsigned long int)))
2020-05-12 03:08:15 +02:00
Stefan Berger 31b752a335 [Pal] Separately declare struct PAL_CONTEXT_ for Doxygen
This is required to cleanly pass the Doxygen build on Ubuntu 18.04.
2020-05-09 14:43:17 +02:00
Stefan Berger 8bbe609bb9 [Pal] Move x86_64/Linux sysdep-x86_64.h to arch/x86_64/Linux/
Also, adapt the Makefiles to add the arch specific directory to the CFLAGS.
The Linux-SGX sysdep-x86_64.h was identical and could therefore be removed.
2020-05-09 14:43:17 +02:00
Stefan Berger 74dc2ebfc3 [Pal] Move x86_64/Linux specifics from pal.h into arch/x86_64/pal-arch.h
Also, adapt the Makefiles to add the directory to the CFLAGS.
2020-05-09 14:43:17 +02:00
Stefan Berger c0163a6036 [Pal] Move x86_64-specific atomic.h to Pal/include/lib/x86_64
Also, adapt the Makefiles to include the new directory in CFLAGS.
2020-05-09 14:43:17 +02:00
Stefan Berger 5354f12a17 [Pal] Move host-generic dl-machine-x86_64.h to Pal/include/arch/x86_64
Also, adapt the Makefiles and INPUT paths in Doxyfile-pal to include the
new directory.
2020-05-09 14:43:17 +02:00
borysp c9742cb9cd Add READ_ONCE and WRITE_ONCE macros
Sometimes we need to prevent the compiler from reading or writing to
a memory location twice to prevent certain TOCTOU bugs. This can now
be achieved by using the introduced macros and this commit does so in
enclave_ocalls.c for Linux-SGX.
2020-05-08 01:43:12 +02:00
borysp 6cb111b6d1 [LibOS] Completely rework LibOS VMA bookkeeping
This commit completely reworks VMA subsystem along with its usages.
New version should be: cleaner (easier to maintain), faster and allow
for bookkeeping requests from Pal.
It also fixes some bugs and inconsistencies found in the process and
changes brk and mmap/munmap implementations (at least partially).
2020-05-02 16:22:00 +02:00
Michał Kowalczyk e39ee4767f Convert flags between PAL API and host syscalls
Currently various flags in file and memory syscalls work mostly by an
accident, because values of some of them align with corresponding Linux
syscall flags. Some APIs weren't that lucky though - e.g.
DkStreamOpen(..., /*options=*/PAL_OPTION_CLOEXEC) deletes file contents
(sic!) intead of opening it with O_CLOEXEC. This is because
PAL_OPTION_CLOEXEC == O_TRUNC.

This commit fixes all this mess and also adds asserts to check validity
of flags passed to Dk* handlers.
2020-04-27 19:54:55 +02:00
Michał Kowalczyk 5e2eee0086 [Pal] Remove likely/unlikely macros 2020-04-20 22:00:58 +02:00
Dmitrii Kuvaiskii 8d9f9f567f [Pal/Linux-SGX] Put TLS-context init logic in critical section
mbedTLS configuration used in Graphene is not thread-safe (because
this would require the use of a threading library like pthread which
is not possible in the LibOS/Pal layers). However, some mbedTLS
functions use shared state, in particular TLS context initialization
functions. This led to data races during encrypted-pipe creation,
since it requires two threads performing a TLS handshake. This commit
refactors TLS init into SSLInit (not thread-safe) and SSLHandshake
(thread-safe) and adds spinlocks around SSLInit to protect the racy
mbedTLS logic.
2020-04-17 01:30:00 -07:00
Michał Kowalczyk 964fd17910 [Docs] Misc rewordings 2020-04-15 23:35:12 +02:00