net.cpp 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589
  1. #include <iostream>
  2. #include "Enclave_u.h"
  3. #include "Untrusted.hpp"
  4. #include "net.hpp"
  5. // The command type byte values
  6. #define COMMAND_EPOCH 0x00
  7. #define COMMAND_MESSAGE 0x01
  8. #define COMMAND_CHUNK 0x02
  9. #define VERBOSE_NET
  10. // #define DEBUG_NET_CLIENTS
  11. #define CEILDIV(x,y) (((x)+(y)-1)/(y))
  12. NetIO *g_netio = NULL;
  13. size_t client_count = 0;
  14. NodeIO::NodeIO(tcp::socket &&socket, nodenum_t nodenum) :
  15. sock(std::move(socket)), node_num(nodenum), msgsize_inflight(0),
  16. chunksize_inflight(0), recv_msgsize_inflight(0),
  17. recv_chunksize_inflight(0), bytes_sent(0)
  18. {
  19. }
  20. uint8_t *NodeIO::request_frame()
  21. {
  22. if (frames_available.empty()) {
  23. // Allocate a new frame. Note that this memory will (at this
  24. // time) never get deallocated. In theory, we could deallocate
  25. // it in return_frame, but if a certain number of frames were
  26. // allocated here, it means we had that much data in flight
  27. // (queued but not accepted for sending by the OS), and we're
  28. // likely to need that much again. Subsequent messages will
  29. // _reuse_ the allocated data, though, so the used memory won't
  30. // grow forever, and will be limited to the amount of in-flight
  31. // data needed.
  32. return new uint8_t[FRAME_SIZE];
  33. }
  34. // Copy the pointer to the frame out of the deque and remove it from
  35. // the deque. Note this is _not_ taking the address of the element
  36. // *in* the deque (and then popping it, which would invalidate that
  37. // pointer).
  38. frame_deque_lock.lock();
  39. uint8_t *frame = frames_available.back();
  40. frames_available.pop_back();
  41. frame_deque_lock.unlock();
  42. return frame;
  43. }
  44. void NodeIO::return_frame(uint8_t *frame)
  45. {
  46. if (!frame) return;
  47. // We push the frame back on to the end of the deque so that it will
  48. // be the next one used. This may lead to better cache behaviour?
  49. frame_deque_lock.lock();
  50. frames_available.push_back(frame);
  51. frame_deque_lock.unlock();
  52. }
  53. void NodeIO::send_header_data(uint64_t header, uint8_t *data, size_t len)
  54. {
  55. commands_deque_lock.lock();
  56. commands_inflight.push_back({header, data, len});
  57. if (commands_inflight.size() == 1) {
  58. async_send_commands();
  59. }
  60. commands_deque_lock.unlock();
  61. }
  62. void NodeIO::async_send_commands()
  63. {
  64. std::vector<boost::asio::const_buffer> tosend;
  65. CommandTuple *commandp = &(commands_inflight.front());
  66. tosend.push_back(boost::asio::buffer(&(std::get<0>(*commandp)), 5));
  67. if (std::get<1>(*commandp) != NULL && std::get<2>(*commandp) > 0) {
  68. tosend.push_back(boost::asio::buffer(std::get<1>(*commandp),
  69. std::get<2>(*commandp)));
  70. }
  71. boost::asio::async_write(sock, tosend,
  72. [this, commandp](boost::system::error_code, std::size_t){
  73. // When the write completes, pop the command from the deque
  74. // (which should now be in the front)
  75. commands_deque_lock.lock();
  76. assert(!commands_inflight.empty() &&
  77. &(commands_inflight.front()) == commandp);
  78. bytes_sent = bytes_sent + 5 + std::get<2>(*commandp);
  79. uint8_t *data = std::get<1>(*commandp);
  80. commands_inflight.pop_front();
  81. if (commands_inflight.size() > 0) {
  82. async_send_commands();
  83. }
  84. // And return the frame
  85. return_frame(data);
  86. commands_deque_lock.unlock();
  87. });
  88. }
  89. void NodeIO::send_epoch(uint32_t epoch_num)
  90. {
  91. uint64_t header = (uint64_t(epoch_num) << 8) + COMMAND_EPOCH;
  92. send_header_data(header, NULL, 0);
  93. }
  94. void NodeIO::send_message_header(uint32_t tot_message_len)
  95. {
  96. uint64_t header = (uint64_t(tot_message_len) << 8) + COMMAND_MESSAGE;
  97. send_header_data(header, NULL, 0);
  98. // If we're sending a new message header, we have to have finished
  99. // sending the previous message.
  100. assert(chunksize_inflight == msgsize_inflight);
  101. msgsize_inflight = tot_message_len;
  102. chunksize_inflight = 0;
  103. }
  104. bool NodeIO::send_chunk(uint8_t *data, uint32_t chunk_len)
  105. {
  106. assert(chunk_len <= FRAME_SIZE);
  107. uint64_t header = (uint64_t(chunk_len) << 8) + COMMAND_CHUNK;
  108. send_header_data(header, data, chunk_len);
  109. chunksize_inflight += chunk_len;
  110. assert(chunksize_inflight <= msgsize_inflight);
  111. return (chunksize_inflight < msgsize_inflight);
  112. }
  113. void NodeIO::recv_commands(
  114. std::function<void(boost::system::error_code)> error_cb,
  115. std::function<void(uint32_t)> epoch_cb)
  116. {
  117. // Asynchronously read the header
  118. receive_header = 0;
  119. boost::asio::async_read(sock, boost::asio::buffer(&receive_header, 5),
  120. [this, error_cb, epoch_cb]
  121. (boost::system::error_code ec, std::size_t) {
  122. if (ec) {
  123. error_cb(ec);
  124. return;
  125. }
  126. if ((receive_header & 0xff) == COMMAND_EPOCH) {
  127. epoch_cb(uint32_t(receive_header >> 8));
  128. recv_commands(error_cb, epoch_cb);
  129. } else if ((receive_header & 0xff) == COMMAND_MESSAGE) {
  130. assert(recv_msgsize_inflight == recv_chunksize_inflight);
  131. recv_msgsize_inflight = uint32_t(receive_header >> 8);
  132. recv_chunksize_inflight = 0;
  133. if (ecall_message(node_num, recv_msgsize_inflight)) {
  134. recv_commands(error_cb, epoch_cb);
  135. } else {
  136. printf("ecall_message failed\n");
  137. }
  138. } else if ((receive_header & 0xff) == COMMAND_CHUNK) {
  139. uint32_t this_chunk_size = uint32_t(receive_header >> 8);
  140. assert(recv_chunksize_inflight + this_chunk_size <=
  141. recv_msgsize_inflight);
  142. recv_chunksize_inflight += this_chunk_size;
  143. boost::asio::async_read(sock, boost::asio::buffer(
  144. receive_frame, this_chunk_size),
  145. [this, error_cb, epoch_cb, this_chunk_size]
  146. (boost::system::error_code ecc, std::size_t) {
  147. if (ecc) {
  148. error_cb(ecc);
  149. return;
  150. }
  151. if (ecall_chunk(node_num, receive_frame,
  152. this_chunk_size)) {
  153. recv_commands(error_cb, epoch_cb);
  154. } else {
  155. printf("ecall_chunk failed\n");
  156. }
  157. });
  158. } else {
  159. error_cb(boost::system::errc::make_error_code(
  160. boost::system::errc::errc_t::invalid_argument));
  161. }
  162. });
  163. }
  164. uint64_t NodeIO::reset_bytes_sent()
  165. {
  166. uint64_t b_sent = bytes_sent;
  167. bytes_sent = 0;
  168. return b_sent;
  169. }
  170. uint64_t NetIO::reset_bytes_sent()
  171. {
  172. uint64_t total=0;
  173. for(size_t i = 0; i<nodeios.size(); i++) {
  174. if(nodeios[i].has_value()) {
  175. total+=((nodeios[i].value()).reset_bytes_sent());
  176. }
  177. }
  178. return total;
  179. }
  180. /*
  181. Receive clients dropped off messages, i.e. a CLIENT_MESSAGE_BUNDLE
  182. */
  183. void NetIO::ing_receive_msgbundle(tcp::socket* csocket, clientid_t c_simid)
  184. {
  185. unsigned char *msgbundle = (unsigned char*) malloc(msgbundle_size);
  186. boost::asio::async_read(*csocket, boost::asio::buffer(msgbundle, msgbundle_size),
  187. [this, csocket, msgbundle, c_simid]
  188. (boost::system::error_code ec, std::size_t) {
  189. if (ec) {
  190. if(ec == boost::asio::error::eof) {
  191. // Client connection terminated so we delete this socket
  192. delete(csocket);
  193. }
  194. else {
  195. printf("Error ing_receive_msgbundle : %s\n", ec.message().c_str());
  196. }
  197. return;
  198. }
  199. //Ingest the message_bundle
  200. bool ret = ecall_ingest_msgbundle(c_simid, msgbundle, conf.m_priv_out);
  201. free(msgbundle);
  202. // Continue to async receive client message bundles
  203. ing_receive_msgbundle(csocket, c_simid);
  204. });
  205. }
  206. /*
  207. Handle new client connections.
  208. New clients always send an authentication message.
  209. For ingestion this is then followed by their msg_bundles every epoch.
  210. */
  211. void NetIO::ing_authenticate_new_client(tcp::socket* csocket,
  212. const boost::system::error_code& error)
  213. {
  214. if(error) {
  215. printf("Accept handler failed\n");
  216. return;
  217. }
  218. #ifdef DEBUG_NET_CLIENTS
  219. printf("Accept handler success\n");
  220. #endif
  221. unsigned char* auth_message = (unsigned char*) malloc(auth_size);
  222. boost::asio::async_read(*csocket, boost::asio::buffer(auth_message, auth_size),
  223. [this, csocket, auth_message]
  224. (boost::system::error_code ec, std::size_t) {
  225. if (ec) {
  226. if(ec == boost::asio::error::eof) {
  227. // Client connection terminated so we delete this socket
  228. delete(csocket);
  229. } else {
  230. printf("Error ing_auth_new_client : %s\n", ec.message().c_str());
  231. }
  232. return;
  233. }
  234. else {
  235. clientid_t c_simid = *((clientid_t *)(auth_message));
  236. // Read the authentication token
  237. unsigned char *auth_ptr = auth_message + sizeof(clientid_t);
  238. bool ret = ecall_authenticate(c_simid, auth_ptr);
  239. free(auth_message);
  240. // Receive client message bundles on this socket
  241. // for client sim_id c_simid
  242. if(ret) {
  243. client_count++;
  244. ing_receive_msgbundle(csocket, c_simid);
  245. } else{
  246. printf("Client <-> Ingestion authentication failed\n");
  247. delete(csocket);
  248. }
  249. }
  250. });
  251. ing_start_accept();
  252. }
  253. /*
  254. Handle new client connections.
  255. New clients always send an authentication message.
  256. For storage this is then followed by the storage servers sending them
  257. their mailbox every epoch.
  258. */
  259. void NetIO::stg_authenticate_new_client(tcp::socket* csocket,
  260. const boost::system::error_code& error)
  261. {
  262. if(error) {
  263. printf("Accept handler failed\n");
  264. return;
  265. }
  266. #ifdef DEBUG_NET_CLIENTS
  267. printf("Accept handler success\n");
  268. #endif
  269. unsigned char* auth_message = (unsigned char*) malloc(auth_size);
  270. boost::asio::async_read(*csocket, boost::asio::buffer(auth_message, auth_size),
  271. [this, csocket, auth_message]
  272. (boost::system::error_code ec, std::size_t) {
  273. if (ec) {
  274. if(ec == boost::asio::error::eof) {
  275. // Client connection terminated so we delete this socket
  276. delete(csocket);
  277. } else {
  278. printf("Error stg_auth_new_client: %s\n", ec.message().c_str());
  279. }
  280. return;
  281. }
  282. else {
  283. clientid_t c_simid = *((clientid_t *)(auth_message));
  284. // Read the authentication token
  285. unsigned char *auth_ptr = auth_message + sizeof(clientid_t);
  286. bool ret = ecall_storage_authenticate(c_simid, auth_ptr);
  287. free(auth_message);
  288. // If the auth is successful, store this socket into
  289. // a client socket array at the local_c_simid index
  290. // for storage servers to send clients their mailbox periodically.
  291. if(ret) {
  292. uint32_t lcid = c_simid / num_stg_nodes;
  293. client_sockets[lcid] = csocket;
  294. }
  295. else{
  296. printf("Client <-> Storage authentication failed\n");
  297. delete (csocket);
  298. }
  299. }
  300. });
  301. stg_start_accept();
  302. }
  303. /*
  304. Asynchronously accept new client connections
  305. */
  306. void NetIO::ing_start_accept()
  307. {
  308. tcp::socket *csocket = new tcp::socket(io_context());
  309. #ifdef DEBUG_NET_CLIENTS
  310. std::cout << "Accepting on " << myconf.clistenhost << ":" << myconf.clistenport << "\n";
  311. #endif
  312. ingestion_acceptor->async_accept(*csocket,
  313. boost::bind(&NetIO::ing_authenticate_new_client, this, csocket,
  314. boost::asio::placeholders::error));
  315. }
  316. void NetIO::stg_start_accept()
  317. {
  318. tcp::socket *csocket = new tcp::socket(io_context());
  319. #ifdef DEBUG_NET_CLIENTS
  320. std::cout << "Accepting on " << myconf.slistenhost << ":" << myconf.slistenport << "\n";
  321. #endif
  322. storage_acceptor->async_accept(*csocket,
  323. boost::bind(&NetIO::stg_authenticate_new_client, this, csocket,
  324. boost::asio::placeholders::error));
  325. }
  326. void NetIO::send_client_mailbox()
  327. {
  328. // Send each client their tokens for the next epoch
  329. for(uint32_t lcid = 0; lcid < num_clients_per_stg; lcid++)
  330. {
  331. unsigned char *tkn_ptr = epoch_tokens + lcid * token_bundle_size;
  332. unsigned char *buf_ptr = epoch_mailboxes + lcid * mailbox_size;
  333. if(client_sockets[lcid]!=nullptr) {
  334. boost::asio::async_write(*(client_sockets[lcid]),
  335. boost::asio::buffer(tkn_ptr, token_bundle_size),
  336. [this, lcid, buf_ptr](boost::system::error_code ec, std::size_t){
  337. if (ec) {
  338. if(ec == boost::asio::error::eof) {
  339. // Client connection terminated so we delete this socket
  340. delete(client_sockets[lcid]);
  341. printf("Client socket terminated!\n");
  342. } else {
  343. printf("Error send_client_mailbox tokens: %s\n", ec.message().c_str());
  344. }
  345. return;
  346. }
  347. boost::asio::async_write(*(client_sockets[lcid]),
  348. boost::asio::buffer(buf_ptr, mailbox_size),
  349. [this, lcid](boost::system::error_code ecc, std::size_t){
  350. //printf("NetIO::send_client_mailbox, Client %d messages was sent\n", lcid);
  351. if (ecc) {
  352. if(ecc == boost::asio::error::eof) {
  353. // Client connection terminated so we delete this socket
  354. delete(client_sockets[lcid]);
  355. printf("Client socket terminated!\n");
  356. } else {
  357. printf("Error send_client_mailbox mailbox (lcid = %d): %s\n",
  358. lcid, ecc.message().c_str());
  359. }
  360. return;
  361. }
  362. });
  363. });
  364. }
  365. /*
  366. else {
  367. printf("Client did not have a socket!\n");
  368. }
  369. */
  370. }
  371. }
  372. NetIO::NetIO(boost::asio::io_context &io_context, const Config &config)
  373. : context(io_context), conf(config),
  374. myconf(config.nodes[config.my_node_num])
  375. {
  376. num_nodes = nodenum_t(conf.nodes.size());
  377. nodeios.resize(num_nodes);
  378. me = conf.my_node_num;
  379. // Node number n will accept connections from nodes 0, ..., n-1 and
  380. // make connections to nodes n+1, ..., num_nodes-1. This is all
  381. // single threaded, but it doesn't deadlock because node 0 isn't
  382. // waiting for any incoming connections, so it immediately makes
  383. // outgoing connections. When it connects to node 1, that node
  384. // accepts its (only) incoming connection, and then starts making
  385. // its outgoing connections, etc.
  386. tcp::resolver resolver(io_context);
  387. tcp::acceptor acceptor(io_context,
  388. resolver.resolve(myconf.listenhost, myconf.listenport)->endpoint());
  389. for(size_t i=0; i<me; ++i) {
  390. #ifdef VERBOSE_NET
  391. std::cerr << "Accepting number " << i << "\n";
  392. #endif
  393. tcp::socket nodesock = acceptor.accept();
  394. #ifdef VERBOSE_NET
  395. std::cerr << "Accepted number " << i << "\n";
  396. #endif
  397. // Read 2 bytes from the socket, which will be the
  398. // connecting node's node number
  399. unsigned short node_num;
  400. boost::asio::read(nodesock,
  401. boost::asio::buffer(&node_num, sizeof(node_num)));
  402. if (node_num >= num_nodes) {
  403. std::cerr << "Received bad node number\n";
  404. } else {
  405. nodeios[node_num].emplace(std::move(nodesock), node_num);
  406. #ifdef VERBOSE_NET
  407. std::cerr << "Received connection from " <<
  408. config.nodes[node_num].name << "\n";
  409. #endif
  410. }
  411. }
  412. for(size_t i=me+1; i<num_nodes; ++i) {
  413. boost::system::error_code err;
  414. tcp::socket nodesock(io_context);
  415. while(1) {
  416. #ifdef VERBOSE_NET
  417. std::cerr << "Connecting to " << config.nodes[i].name << "...\n";
  418. #endif
  419. boost::asio::connect(nodesock,
  420. resolver.resolve(config.nodes[i].listenhost,
  421. config.nodes[i].listenport), err);
  422. if (!err) break;
  423. std::cerr << "Connection to " << config.nodes[i].name <<
  424. " refused, will retry.\n";
  425. sleep(1);
  426. }
  427. // Write 2 bytes to the socket to tell the peer node our node
  428. // number
  429. nodenum_t node_num = (nodenum_t)me;
  430. boost::asio::write(nodesock,
  431. boost::asio::buffer(&node_num, sizeof(node_num)));
  432. nodeios[i].emplace(std::move(nodesock), i);
  433. #ifdef VERBOSE_NET
  434. std::cerr << "Connected to " << config.nodes[i].name << "\n";
  435. #endif
  436. }
  437. auth_size = sizeof(clientid_t) + sizeof(unsigned long) + SGX_AESGCM_KEY_SIZE;
  438. msgbundle_size = SGX_AESGCM_IV_SIZE
  439. + (conf.m_priv_out * (conf.msg_size + TOKEN_SIZE))
  440. + SGX_AESGCM_MAC_SIZE;
  441. uint16_t priv_out = config.m_priv_out;
  442. token_bundle_size = ((priv_out * TOKEN_SIZE)
  443. + SGX_AESGCM_IV_SIZE + SGX_AESGCM_MAC_SIZE);
  444. uint16_t priv_in = conf.m_priv_in;
  445. mailbox_size = (priv_in * conf.msg_size) + SGX_AESGCM_IV_SIZE
  446. + SGX_AESGCM_MAC_SIZE;
  447. if(myconf.roles & ROLE_STORAGE) {
  448. // Setup the client sockets
  449. // Compute no_of_clients per storage_server
  450. uint32_t num_users = config.user_count;
  451. NodeConfig nc;
  452. num_stg_nodes = 0;
  453. for (nodenum_t i=0; i<num_nodes; ++i) {
  454. nc = conf.nodes[i];
  455. if(nc.roles & ROLE_STORAGE) {
  456. num_stg_nodes++;
  457. }
  458. }
  459. num_clients_per_stg = CEILDIV(num_users, num_stg_nodes);
  460. for(uint32_t i = 0; i<num_clients_per_stg; i++) {
  461. client_sockets.emplace_back(nullptr);
  462. }
  463. uint32_t epoch_mailboxes_size = num_clients_per_stg * mailbox_size;
  464. uint32_t epoch_tokens_size = num_clients_per_stg * token_bundle_size;
  465. epoch_mailboxes = (unsigned char *) malloc(epoch_mailboxes_size);
  466. epoch_tokens = (unsigned char *) malloc (epoch_tokens_size);
  467. ecall_supply_storage_buffers(epoch_mailboxes, epoch_mailboxes_size,
  468. epoch_tokens, epoch_tokens_size);
  469. storage_acceptor = std::shared_ptr<tcp::acceptor>(
  470. new tcp::acceptor(io_context,
  471. resolver.resolve(this->myconf.slistenhost,
  472. this->myconf.slistenport)->endpoint()));
  473. stg_start_accept();
  474. }
  475. if(myconf.roles & ROLE_INGESTION) {
  476. ingestion_acceptor = std::shared_ptr<tcp::acceptor>(
  477. new tcp::acceptor(io_context,
  478. resolver.resolve(this->myconf.clistenhost,
  479. this->myconf.clistenport)->endpoint()));
  480. ing_start_accept();
  481. }
  482. }
  483. void NetIO::recv_commands(
  484. std::function<void(boost::system::error_code)> error_cb,
  485. std::function<void(uint32_t)> epoch_cb)
  486. {
  487. for (nodenum_t node_num = 0; node_num < num_nodes; ++node_num) {
  488. if (node_num == me) continue;
  489. NodeIO &n = node(node_num);
  490. n.recv_commands(error_cb, epoch_cb);
  491. }
  492. }
  493. void NetIO::close()
  494. {
  495. for (nodenum_t node_num = 0; node_num < num_nodes; ++node_num) {
  496. if (node_num == me) continue;
  497. NodeIO &n = node(node_num);
  498. n.close();
  499. }
  500. }
  501. /* The enclave calls this to inform the untrusted app that there's a new
  502. * messaage to send. The return value is the frame the enclave should
  503. * use to store the first (encrypted) chunk of this message. */
  504. uint8_t *ocall_message(nodenum_t node_num, uint32_t message_len)
  505. {
  506. assert(g_netio != NULL);
  507. NodeIO &node = g_netio->node(node_num);
  508. node.send_message_header(message_len);
  509. return node.request_frame();
  510. }
  511. /* The enclave calls this to inform the untrusted app that there's a new
  512. * chunk to send. The return value is the frame the enclave should use
  513. * to store the next (encrypted) chunk of this message, or NULL if this
  514. * was the last chunk. */
  515. uint8_t *ocall_chunk(nodenum_t node_num, uint8_t *chunkdata,
  516. uint32_t chunklen)
  517. {
  518. assert(g_netio != NULL);
  519. NodeIO &node = g_netio->node(node_num);
  520. bool morechunks = node.send_chunk(chunkdata, chunklen);
  521. if (morechunks) {
  522. return node.request_frame();
  523. }
  524. return NULL;
  525. }