net.cpp 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603
  1. #include <iostream>
  2. #include "Enclave_u.h"
  3. #include "Untrusted.hpp"
  4. #include "net.hpp"
  5. // The command type byte values
  6. #define COMMAND_EPOCH 0x00
  7. #define COMMAND_MESSAGE 0x01
  8. #define COMMAND_CHUNK 0x02
  9. #define VERBOSE_NET
  10. // #define DEBUG_NET_CLIENTS
  11. #define CEILDIV(x,y) (((x)+(y)-1)/(y))
  12. NetIO *g_netio = NULL;
  13. size_t client_count = 0;
  14. NodeIO::NodeIO(tcp::socket &&socket, nodenum_t nodenum) :
  15. sock(std::move(socket)), node_num(nodenum), msgsize_inflight(0),
  16. chunksize_inflight(0), recv_msgsize_inflight(0),
  17. recv_chunksize_inflight(0), bytes_sent(0)
  18. {
  19. }
  20. uint8_t *NodeIO::request_frame()
  21. {
  22. if (frames_available.empty()) {
  23. // Allocate a new frame. Note that this memory will (at this
  24. // time) never get deallocated. In theory, we could deallocate
  25. // it in return_frame, but if a certain number of frames were
  26. // allocated here, it means we had that much data in flight
  27. // (queued but not accepted for sending by the OS), and we're
  28. // likely to need that much again. Subsequent messages will
  29. // _reuse_ the allocated data, though, so the used memory won't
  30. // grow forever, and will be limited to the amount of in-flight
  31. // data needed.
  32. return new uint8_t[FRAME_SIZE];
  33. }
  34. // Copy the pointer to the frame out of the deque and remove it from
  35. // the deque. Note this is _not_ taking the address of the element
  36. // *in* the deque (and then popping it, which would invalidate that
  37. // pointer).
  38. frame_deque_lock.lock();
  39. uint8_t *frame = frames_available.back();
  40. frames_available.pop_back();
  41. frame_deque_lock.unlock();
  42. return frame;
  43. }
  44. void NodeIO::return_frame(uint8_t *frame)
  45. {
  46. if (!frame) return;
  47. // We push the frame back on to the end of the deque so that it will
  48. // be the next one used. This may lead to better cache behaviour?
  49. frame_deque_lock.lock();
  50. frames_available.push_back(frame);
  51. frame_deque_lock.unlock();
  52. }
  53. void NodeIO::send_header_data(uint64_t header, uint8_t *data, size_t len)
  54. {
  55. commands_deque_lock.lock();
  56. commands_inflight.push_back({header, data, len});
  57. if (commands_inflight.size() == 1) {
  58. async_send_commands();
  59. }
  60. commands_deque_lock.unlock();
  61. }
  62. void NodeIO::async_send_commands()
  63. {
  64. std::vector<boost::asio::const_buffer> tosend;
  65. CommandTuple *commandp = &(commands_inflight.front());
  66. tosend.push_back(boost::asio::buffer(&(std::get<0>(*commandp)), 5));
  67. if (std::get<1>(*commandp) != NULL && std::get<2>(*commandp) > 0) {
  68. tosend.push_back(boost::asio::buffer(std::get<1>(*commandp),
  69. std::get<2>(*commandp)));
  70. }
  71. boost::asio::async_write(sock, tosend,
  72. [this, commandp](boost::system::error_code, std::size_t){
  73. // When the write completes, pop the command from the deque
  74. // (which should now be in the front)
  75. commands_deque_lock.lock();
  76. assert(!commands_inflight.empty() &&
  77. &(commands_inflight.front()) == commandp);
  78. bytes_sent = bytes_sent + 5 + std::get<2>(*commandp);
  79. uint8_t *data = std::get<1>(*commandp);
  80. commands_inflight.pop_front();
  81. if (commands_inflight.size() > 0) {
  82. async_send_commands();
  83. }
  84. // And return the frame
  85. return_frame(data);
  86. commands_deque_lock.unlock();
  87. });
  88. }
  89. void NodeIO::send_epoch(uint32_t epoch_num)
  90. {
  91. uint64_t header = (uint64_t(epoch_num) << 8) + COMMAND_EPOCH;
  92. send_header_data(header, NULL, 0);
  93. }
  94. void NodeIO::send_message_header(uint32_t tot_message_len)
  95. {
  96. uint64_t header = (uint64_t(tot_message_len) << 8) + COMMAND_MESSAGE;
  97. send_header_data(header, NULL, 0);
  98. // If we're sending a new message header, we have to have finished
  99. // sending the previous message.
  100. assert(chunksize_inflight == msgsize_inflight);
  101. msgsize_inflight = tot_message_len;
  102. chunksize_inflight = 0;
  103. }
  104. bool NodeIO::send_chunk(uint8_t *data, uint32_t chunk_len)
  105. {
  106. assert(chunk_len <= FRAME_SIZE);
  107. uint64_t header = (uint64_t(chunk_len) << 8) + COMMAND_CHUNK;
  108. send_header_data(header, data, chunk_len);
  109. chunksize_inflight += chunk_len;
  110. assert(chunksize_inflight <= msgsize_inflight);
  111. return (chunksize_inflight < msgsize_inflight);
  112. }
  113. void NodeIO::recv_commands(
  114. std::function<void(boost::system::error_code)> error_cb,
  115. std::function<void(uint32_t)> epoch_cb)
  116. {
  117. // Asynchronously read the header
  118. receive_header = 0;
  119. boost::asio::async_read(sock, boost::asio::buffer(&receive_header, 5),
  120. [this, error_cb, epoch_cb]
  121. (boost::system::error_code ec, std::size_t) {
  122. if (ec) {
  123. error_cb(ec);
  124. return;
  125. }
  126. if ((receive_header & 0xff) == COMMAND_EPOCH) {
  127. epoch_cb(uint32_t(receive_header >> 8));
  128. recv_commands(error_cb, epoch_cb);
  129. } else if ((receive_header & 0xff) == COMMAND_MESSAGE) {
  130. assert(recv_msgsize_inflight == recv_chunksize_inflight);
  131. recv_msgsize_inflight = uint32_t(receive_header >> 8);
  132. recv_chunksize_inflight = 0;
  133. if (ecall_message(node_num, recv_msgsize_inflight)) {
  134. recv_commands(error_cb, epoch_cb);
  135. } else {
  136. printf("ecall_message failed\n");
  137. }
  138. } else if ((receive_header & 0xff) == COMMAND_CHUNK) {
  139. uint32_t this_chunk_size = uint32_t(receive_header >> 8);
  140. assert(recv_chunksize_inflight + this_chunk_size <=
  141. recv_msgsize_inflight);
  142. recv_chunksize_inflight += this_chunk_size;
  143. boost::asio::async_read(sock, boost::asio::buffer(
  144. receive_frame, this_chunk_size),
  145. [this, error_cb, epoch_cb, this_chunk_size]
  146. (boost::system::error_code ecc, std::size_t) {
  147. if (ecc) {
  148. error_cb(ecc);
  149. return;
  150. }
  151. if (ecall_chunk(node_num, receive_frame,
  152. this_chunk_size)) {
  153. recv_commands(error_cb, epoch_cb);
  154. } else {
  155. printf("ecall_chunk failed\n");
  156. }
  157. });
  158. } else {
  159. error_cb(boost::system::errc::make_error_code(
  160. boost::system::errc::errc_t::invalid_argument));
  161. }
  162. });
  163. }
  164. uint64_t NodeIO::reset_bytes_sent()
  165. {
  166. uint64_t b_sent = bytes_sent;
  167. bytes_sent = 0;
  168. return b_sent;
  169. }
  170. uint64_t NetIO::reset_bytes_sent()
  171. {
  172. uint64_t total=0;
  173. for(size_t i = 0; i<nodeios.size(); i++) {
  174. if(nodeios[i].has_value()) {
  175. total+=((nodeios[i].value()).reset_bytes_sent());
  176. }
  177. }
  178. return total;
  179. }
  180. /*
  181. Receive clients dropped off messages, i.e. a CLIENT_MESSAGE_BUNDLE
  182. */
  183. void NetIO::ing_receive_msgbundle(tcp::socket* csocket, clientid_t c_simid)
  184. {
  185. unsigned char *msgbundle = (unsigned char*) malloc(msgbundle_size);
  186. boost::asio::async_read(*csocket, boost::asio::buffer(msgbundle, msgbundle_size),
  187. [this, csocket, msgbundle, c_simid]
  188. (boost::system::error_code ec, std::size_t) {
  189. if (ec) {
  190. if(ec == boost::asio::error::eof) {
  191. // Client connection terminated so we delete this socket
  192. delete(csocket);
  193. }
  194. else {
  195. printf("Error ing_receive_msgbundle : %s\n", ec.message().c_str());
  196. }
  197. return;
  198. }
  199. bool ret;
  200. //Ingest the message_bundle
  201. if(conf.private_routing) {
  202. ret = ecall_ingest_msgbundle(c_simid, msgbundle, conf.m_priv_out);
  203. } else {
  204. ret = ecall_ingest_msgbundle(c_simid, msgbundle, conf.m_pub_out);
  205. }
  206. free(msgbundle);
  207. // Continue to async receive client message bundles
  208. ing_receive_msgbundle(csocket, c_simid);
  209. });
  210. }
  211. /*
  212. Handle new client connections.
  213. New clients always send an authentication message.
  214. For ingestion this is then followed by their msg_bundles every epoch.
  215. */
  216. void NetIO::ing_authenticate_new_client(tcp::socket* csocket,
  217. const boost::system::error_code& error)
  218. {
  219. if(error) {
  220. printf("Accept handler failed\n");
  221. return;
  222. }
  223. #ifdef DEBUG_NET_CLIENTS
  224. printf("Accept handler success\n");
  225. #endif
  226. unsigned char* auth_message = (unsigned char*) malloc(auth_size);
  227. boost::asio::async_read(*csocket, boost::asio::buffer(auth_message, auth_size),
  228. [this, csocket, auth_message]
  229. (boost::system::error_code ec, std::size_t) {
  230. if (ec) {
  231. if(ec == boost::asio::error::eof) {
  232. // Client connection terminated so we delete this socket
  233. delete(csocket);
  234. } else {
  235. printf("Error ing_auth_new_client : %s\n", ec.message().c_str());
  236. }
  237. return;
  238. }
  239. else {
  240. clientid_t c_simid = *((clientid_t *)(auth_message));
  241. // Read the authentication token
  242. unsigned char *auth_ptr = auth_message + sizeof(clientid_t);
  243. bool ret = ecall_authenticate(c_simid, auth_ptr);
  244. free(auth_message);
  245. // Receive client message bundles on this socket
  246. // for client sim_id c_simid
  247. if(ret) {
  248. client_count++;
  249. ing_receive_msgbundle(csocket, c_simid);
  250. } else{
  251. printf("Client <-> Ingestion authentication failed\n");
  252. delete(csocket);
  253. }
  254. }
  255. });
  256. ing_start_accept();
  257. }
  258. /*
  259. Handle new client connections.
  260. New clients always send an authentication message.
  261. For storage this is then followed by the storage servers sending them
  262. their mailbox every epoch.
  263. */
  264. void NetIO::stg_authenticate_new_client(tcp::socket* csocket,
  265. const boost::system::error_code& error)
  266. {
  267. if(error) {
  268. printf("Accept handler failed\n");
  269. return;
  270. }
  271. #ifdef DEBUG_NET_CLIENTS
  272. printf("Accept handler success\n");
  273. #endif
  274. unsigned char* auth_message = (unsigned char*) malloc(auth_size);
  275. boost::asio::async_read(*csocket, boost::asio::buffer(auth_message, auth_size),
  276. [this, csocket, auth_message]
  277. (boost::system::error_code ec, std::size_t) {
  278. if (ec) {
  279. if(ec == boost::asio::error::eof) {
  280. // Client connection terminated so we delete this socket
  281. delete(csocket);
  282. } else {
  283. printf("Error stg_auth_new_client: %s\n", ec.message().c_str());
  284. }
  285. return;
  286. }
  287. else {
  288. clientid_t c_simid = *((clientid_t *)(auth_message));
  289. // Read the authentication token
  290. unsigned char *auth_ptr = auth_message + sizeof(clientid_t);
  291. bool ret = ecall_storage_authenticate(c_simid, auth_ptr);
  292. free(auth_message);
  293. // If the auth is successful, store this socket into
  294. // a client socket array at the local_c_simid index
  295. // for storage servers to send clients their mailbox periodically.
  296. if(ret) {
  297. uint32_t lcid = c_simid / num_stg_nodes;
  298. client_sockets[lcid] = csocket;
  299. }
  300. else{
  301. printf("Client <-> Storage authentication failed\n");
  302. delete (csocket);
  303. }
  304. }
  305. });
  306. stg_start_accept();
  307. }
  308. /*
  309. Asynchronously accept new client connections
  310. */
  311. void NetIO::ing_start_accept()
  312. {
  313. tcp::socket *csocket = new tcp::socket(io_context());
  314. #ifdef DEBUG_NET_CLIENTS
  315. std::cout << "Accepting on " << myconf.clistenhost << ":" << myconf.clistenport << "\n";
  316. #endif
  317. ingestion_acceptor->async_accept(*csocket,
  318. boost::bind(&NetIO::ing_authenticate_new_client, this, csocket,
  319. boost::asio::placeholders::error));
  320. }
  321. void NetIO::stg_start_accept()
  322. {
  323. tcp::socket *csocket = new tcp::socket(io_context());
  324. #ifdef DEBUG_NET_CLIENTS
  325. std::cout << "Accepting on " << myconf.slistenhost << ":" << myconf.slistenport << "\n";
  326. #endif
  327. storage_acceptor->async_accept(*csocket,
  328. boost::bind(&NetIO::stg_authenticate_new_client, this, csocket,
  329. boost::asio::placeholders::error));
  330. }
  331. void NetIO::send_client_mailbox()
  332. {
  333. // Send each client their tokens for the next epoch
  334. for(uint32_t lcid = 0; lcid < num_clients_per_stg; lcid++)
  335. {
  336. unsigned char *tkn_ptr = epoch_tokens + lcid * token_bundle_size;
  337. unsigned char *buf_ptr = epoch_mailboxes + lcid * mailbox_size;
  338. if(client_sockets[lcid]!=nullptr) {
  339. boost::asio::async_write(*(client_sockets[lcid]),
  340. boost::asio::buffer(tkn_ptr, token_bundle_size),
  341. [this, lcid, buf_ptr](boost::system::error_code ec, std::size_t){
  342. if (ec) {
  343. if(ec == boost::asio::error::eof) {
  344. // Client connection terminated so we delete this socket
  345. delete(client_sockets[lcid]);
  346. printf("Client socket terminated!\n");
  347. } else {
  348. printf("Error send_client_mailbox tokens: %s\n", ec.message().c_str());
  349. }
  350. return;
  351. }
  352. boost::asio::async_write(*(client_sockets[lcid]),
  353. boost::asio::buffer(buf_ptr, mailbox_size),
  354. [this, lcid](boost::system::error_code ecc, std::size_t){
  355. //printf("NetIO::send_client_mailbox, Client %d messages was sent\n", lcid);
  356. if (ecc) {
  357. if(ecc == boost::asio::error::eof) {
  358. // Client connection terminated so we delete this socket
  359. delete(client_sockets[lcid]);
  360. printf("Client socket terminated!\n");
  361. } else {
  362. printf("Error send_client_mailbox mailbox (lcid = %d): %s\n",
  363. lcid, ecc.message().c_str());
  364. }
  365. return;
  366. }
  367. });
  368. });
  369. }
  370. /*
  371. else {
  372. printf("Client did not have a socket!\n");
  373. }
  374. */
  375. }
  376. }
  377. NetIO::NetIO(boost::asio::io_context &io_context, const Config &config)
  378. : context(io_context), conf(config),
  379. myconf(config.nodes[config.my_node_num])
  380. {
  381. num_nodes = nodenum_t(conf.nodes.size());
  382. nodeios.resize(num_nodes);
  383. me = conf.my_node_num;
  384. // Node number n will accept connections from nodes 0, ..., n-1 and
  385. // make connections to nodes n+1, ..., num_nodes-1. This is all
  386. // single threaded, but it doesn't deadlock because node 0 isn't
  387. // waiting for any incoming connections, so it immediately makes
  388. // outgoing connections. When it connects to node 1, that node
  389. // accepts its (only) incoming connection, and then starts making
  390. // its outgoing connections, etc.
  391. tcp::resolver resolver(io_context);
  392. tcp::acceptor acceptor(io_context,
  393. resolver.resolve(myconf.listenhost, myconf.listenport)->endpoint());
  394. for(size_t i=0; i<me; ++i) {
  395. #ifdef VERBOSE_NET
  396. std::cerr << "Accepting number " << i << "\n";
  397. #endif
  398. tcp::socket nodesock = acceptor.accept();
  399. #ifdef VERBOSE_NET
  400. std::cerr << "Accepted number " << i << "\n";
  401. #endif
  402. // Read 2 bytes from the socket, which will be the
  403. // connecting node's node number
  404. unsigned short node_num;
  405. boost::asio::read(nodesock,
  406. boost::asio::buffer(&node_num, sizeof(node_num)));
  407. if (node_num >= num_nodes) {
  408. std::cerr << "Received bad node number\n";
  409. } else {
  410. nodeios[node_num].emplace(std::move(nodesock), node_num);
  411. #ifdef VERBOSE_NET
  412. std::cerr << "Received connection from " <<
  413. config.nodes[node_num].name << "\n";
  414. #endif
  415. }
  416. }
  417. for(size_t i=me+1; i<num_nodes; ++i) {
  418. boost::system::error_code err;
  419. tcp::socket nodesock(io_context);
  420. while(1) {
  421. #ifdef VERBOSE_NET
  422. std::cerr << "Connecting to " << config.nodes[i].name << "...\n";
  423. #endif
  424. boost::asio::connect(nodesock,
  425. resolver.resolve(config.nodes[i].listenhost,
  426. config.nodes[i].listenport), err);
  427. if (!err) break;
  428. std::cerr << "Connection to " << config.nodes[i].name <<
  429. " refused, will retry.\n";
  430. sleep(1);
  431. }
  432. // Write 2 bytes to the socket to tell the peer node our node
  433. // number
  434. nodenum_t node_num = (nodenum_t)me;
  435. boost::asio::write(nodesock,
  436. boost::asio::buffer(&node_num, sizeof(node_num)));
  437. nodeios[i].emplace(std::move(nodesock), i);
  438. #ifdef VERBOSE_NET
  439. std::cerr << "Connected to " << config.nodes[i].name << "\n";
  440. #endif
  441. }
  442. auth_size = sizeof(clientid_t) + sizeof(unsigned long) + SGX_AESGCM_KEY_SIZE;
  443. uint16_t priv_out, priv_in, pub_in;
  444. if(config.private_routing) {
  445. priv_out = conf.m_priv_out;
  446. priv_in = conf.m_priv_in;
  447. msgbundle_size = SGX_AESGCM_IV_SIZE
  448. + (conf.m_priv_out * (conf.msg_size + TOKEN_SIZE))
  449. + SGX_AESGCM_MAC_SIZE;
  450. token_bundle_size = ((priv_out * TOKEN_SIZE)
  451. + SGX_AESGCM_IV_SIZE + SGX_AESGCM_MAC_SIZE);
  452. mailbox_size = (priv_in * conf.msg_size) + SGX_AESGCM_IV_SIZE
  453. + SGX_AESGCM_MAC_SIZE;
  454. } else {
  455. pub_in = conf.m_pub_in;
  456. msgbundle_size = SGX_AESGCM_IV_SIZE
  457. + (conf.m_pub_out * conf.msg_size)
  458. + SGX_AESGCM_MAC_SIZE;
  459. mailbox_size = (pub_in * conf.msg_size) + SGX_AESGCM_IV_SIZE
  460. + SGX_AESGCM_MAC_SIZE;
  461. }
  462. if(myconf.roles & ROLE_STORAGE) {
  463. // Setup the client sockets
  464. // Compute no_of_clients per storage_server
  465. uint32_t num_users = config.user_count;
  466. NodeConfig nc;
  467. num_stg_nodes = 0;
  468. for (nodenum_t i=0; i<num_nodes; ++i) {
  469. nc = conf.nodes[i];
  470. if(nc.roles & ROLE_STORAGE) {
  471. num_stg_nodes++;
  472. }
  473. }
  474. num_clients_per_stg = CEILDIV(num_users, num_stg_nodes);
  475. for(uint32_t i = 0; i<num_clients_per_stg; i++) {
  476. client_sockets.emplace_back(nullptr);
  477. }
  478. uint32_t epoch_mailboxes_size = num_clients_per_stg * mailbox_size;
  479. uint32_t epoch_tokens_size = num_clients_per_stg * token_bundle_size;
  480. epoch_mailboxes = (unsigned char *) malloc(epoch_mailboxes_size);
  481. epoch_tokens = (unsigned char *) malloc (epoch_tokens_size);
  482. ecall_supply_storage_buffers(epoch_mailboxes, epoch_mailboxes_size,
  483. epoch_tokens, epoch_tokens_size);
  484. storage_acceptor = std::shared_ptr<tcp::acceptor>(
  485. new tcp::acceptor(io_context,
  486. resolver.resolve(this->myconf.slistenhost,
  487. this->myconf.slistenport)->endpoint()));
  488. stg_start_accept();
  489. }
  490. if(myconf.roles & ROLE_INGESTION) {
  491. ingestion_acceptor = std::shared_ptr<tcp::acceptor>(
  492. new tcp::acceptor(io_context,
  493. resolver.resolve(this->myconf.clistenhost,
  494. this->myconf.clistenport)->endpoint()));
  495. ing_start_accept();
  496. }
  497. }
  498. void NetIO::recv_commands(
  499. std::function<void(boost::system::error_code)> error_cb,
  500. std::function<void(uint32_t)> epoch_cb)
  501. {
  502. for (nodenum_t node_num = 0; node_num < num_nodes; ++node_num) {
  503. if (node_num == me) continue;
  504. NodeIO &n = node(node_num);
  505. n.recv_commands(error_cb, epoch_cb);
  506. }
  507. }
  508. void NetIO::close()
  509. {
  510. for (nodenum_t node_num = 0; node_num < num_nodes; ++node_num) {
  511. if (node_num == me) continue;
  512. NodeIO &n = node(node_num);
  513. n.close();
  514. }
  515. }
  516. /* The enclave calls this to inform the untrusted app that there's a new
  517. * messaage to send. The return value is the frame the enclave should
  518. * use to store the first (encrypted) chunk of this message. */
  519. uint8_t *ocall_message(nodenum_t node_num, uint32_t message_len)
  520. {
  521. assert(g_netio != NULL);
  522. NodeIO &node = g_netio->node(node_num);
  523. node.send_message_header(message_len);
  524. return node.request_frame();
  525. }
  526. /* The enclave calls this to inform the untrusted app that there's a new
  527. * chunk to send. The return value is the frame the enclave should use
  528. * to store the next (encrypted) chunk of this message, or NULL if this
  529. * was the last chunk. */
  530. uint8_t *ocall_chunk(nodenum_t node_num, uint8_t *chunkdata,
  531. uint32_t chunklen)
  532. {
  533. assert(g_netio != NULL);
  534. NodeIO &node = g_netio->node(node_num);
  535. bool morechunks = node.send_chunk(chunkdata, chunklen);
  536. if (morechunks) {
  537. return node.request_frame();
  538. }
  539. return NULL;
  540. }