sgx_enclave.c 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730
  1. /* -*- mode:c; c-file-style:"k&r"; c-basic-offset: 4; tab-width:4; indent-tabs-mode:nil; mode:auto-fill; fill-column:78; -*- */
  2. /* vim: set ts=4 sw=4 et tw=78 fo=cqt wm=0: */
  3. #include "ocall_types.h"
  4. #include "ecall_types.h"
  5. #include "sgx_internal.h"
  6. #include "pal_security.h"
  7. #include "pal_linux_error.h"
  8. #include <asm/mman.h>
  9. #include <asm/ioctls.h>
  10. #include <asm/socket.h>
  11. #include <asm/signal.h>
  12. #include <linux/fs.h>
  13. #include <linux/in.h>
  14. #include <math.h>
  15. #include <asm/errno.h>
  16. #define PAL_SEC() (&current_enclave->pal_sec)
  17. #define ODEBUG(code, ms) do {} while (0)
  18. static int sgx_ocall_exit(void * pms)
  19. {
  20. ODEBUG(OCALL_EXIT, NULL);
  21. INLINE_SYSCALL(exit, 1, 0);
  22. return 0;
  23. }
  24. static int sgx_ocall_print_string(void * pms)
  25. {
  26. ms_ocall_print_string_t * ms = (ms_ocall_print_string_t *) pms;
  27. INLINE_SYSCALL(write, 3, 2, ms->ms_str, ms->ms_length);
  28. return 0;
  29. }
  30. static int sgx_ocall_alloc_untrusted(void * pms)
  31. {
  32. ms_ocall_alloc_untrusted_t * ms = (ms_ocall_alloc_untrusted_t *) pms;
  33. void * addr;
  34. ODEBUG(OCALL_ALLOC_UNTRUSTED, ms);
  35. addr = (void *) INLINE_SYSCALL(mmap, 6, NULL, ms->ms_size,
  36. PROT_READ|PROT_WRITE,
  37. MAP_ANONYMOUS|MAP_PRIVATE, -1, 0);
  38. if (IS_ERR_P(addr))
  39. return -PAL_ERROR_NOMEM;
  40. ms->ms_mem = addr;
  41. return 0;
  42. }
  43. static int sgx_ocall_map_untrusted(void * pms)
  44. {
  45. ms_ocall_map_untrusted_t * ms = (ms_ocall_map_untrusted_t *) pms;
  46. void * addr;
  47. ODEBUG(OCALL_MAP_UNTRUSTED, ms);
  48. addr = (void *) INLINE_SYSCALL(mmap, 6, NULL, ms->ms_size,
  49. ms->ms_prot,
  50. MAP_FILE|MAP_SHARED,
  51. ms->ms_fd, ms->ms_offset);
  52. if (IS_ERR_P(addr))
  53. return -PAL_ERROR_NOMEM;
  54. ms->ms_mem = addr;
  55. return 0;
  56. }
  57. static int sgx_ocall_unmap_untrusted(void * pms)
  58. {
  59. ms_ocall_unmap_untrusted_t * ms = (ms_ocall_unmap_untrusted_t *) pms;
  60. ODEBUG(OCALL_UNMAP_UNTRUSTED, ms);
  61. INLINE_SYSCALL(munmap, 2, ALLOC_ALIGNDOWN(ms->ms_mem),
  62. ALLOC_ALIGNUP(ms->ms_mem + ms->ms_size) -
  63. ALLOC_ALIGNDOWN(ms->ms_mem));
  64. return 0;
  65. }
  66. static int sgx_ocall_cpuid(void * pms)
  67. {
  68. ms_ocall_cpuid_t * ms = (ms_ocall_cpuid_t *) pms;
  69. ODEBUG(OCALL_CPUID, ms);
  70. asm volatile ("cpuid"
  71. : "=a"(ms->ms_values[0]),
  72. "=b"(ms->ms_values[1]),
  73. "=c"(ms->ms_values[2]),
  74. "=d"(ms->ms_values[3])
  75. : "a"(ms->ms_leaf), "c"(ms->ms_subleaf) : "memory");
  76. return 0;
  77. }
  78. static int sgx_ocall_open(void * pms)
  79. {
  80. ms_ocall_open_t * ms = (ms_ocall_open_t *) pms;
  81. int ret;
  82. ODEBUG(OCALL_OPEN, ms);
  83. ret = INLINE_SYSCALL(open, 3, ms->ms_pathname, ms->ms_flags|O_CLOEXEC,
  84. ms->ms_mode);
  85. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  86. }
  87. static int sgx_ocall_close(void * pms)
  88. {
  89. ms_ocall_close_t * ms = (ms_ocall_close_t *) pms;
  90. ODEBUG(OCALL_CLOSE, ms);
  91. INLINE_SYSCALL(close, 1, ms->ms_fd);
  92. return 0;
  93. }
  94. static int sgx_ocall_read(void * pms)
  95. {
  96. ms_ocall_read_t * ms = (ms_ocall_read_t *) pms;
  97. int ret;
  98. ODEBUG(OCALL_READ, ms);
  99. ret = INLINE_SYSCALL(read, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  100. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  101. }
  102. static int sgx_ocall_write(void * pms)
  103. {
  104. ms_ocall_write_t * ms = (ms_ocall_write_t *) pms;
  105. int ret;
  106. ODEBUG(OCALL_WRITE, ms);
  107. ret = INLINE_SYSCALL(write, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  108. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  109. }
  110. static int sgx_ocall_fstat(void * pms)
  111. {
  112. ms_ocall_fstat_t * ms = (ms_ocall_fstat_t *) pms;
  113. int ret;
  114. ODEBUG(OCALL_FSTAT, ms);
  115. ret = INLINE_SYSCALL(fstat, 2, ms->ms_fd, &ms->ms_stat);
  116. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  117. }
  118. static int sgx_ocall_fionread(void * pms)
  119. {
  120. ms_ocall_fionread_t * ms = (ms_ocall_fionread_t *) pms;
  121. int ret, val;
  122. ODEBUG(OCALL_FIONREAD, ms);
  123. ret = INLINE_SYSCALL(ioctl, 3, ms->ms_fd, FIONREAD, &val);
  124. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : val;
  125. }
  126. static int sgx_ocall_fsetnonblock(void * pms)
  127. {
  128. ms_ocall_fsetnonblock_t * ms = (ms_ocall_fsetnonblock_t *) pms;
  129. int ret, flags;
  130. ODEBUG(OCALL_FSETNONBLOCK, ms);
  131. ret = INLINE_SYSCALL(fcntl, 2, ms->ms_fd, F_GETFL);
  132. if (IS_ERR(ret))
  133. return -ERRNO(ret);
  134. flags = ret;
  135. if (ms->ms_nonblocking) {
  136. if (!(flags & O_NONBLOCK))
  137. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  138. flags | O_NONBLOCK);
  139. } else {
  140. if (flags & O_NONBLOCK)
  141. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  142. flags & ~O_NONBLOCK);
  143. }
  144. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : 0;
  145. }
  146. static int sgx_ocall_fchmod(void * pms)
  147. {
  148. ms_ocall_fchmod_t * ms = (ms_ocall_fchmod_t *) pms;
  149. int ret;
  150. ODEBUG(OCALL_FCHMOD, ms);
  151. ret = INLINE_SYSCALL(fchmod, 2, ms->ms_fd, ms->ms_mode);
  152. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  153. }
  154. static int sgx_ocall_fsync(void * pms)
  155. {
  156. ms_ocall_fsync_t * ms = (ms_ocall_fsync_t *) pms;
  157. ODEBUG(OCALL_FSYNC, ms);
  158. INLINE_SYSCALL(fsync, 1, ms->ms_fd);
  159. return 0;
  160. }
  161. static int sgx_ocall_ftruncate(void * pms)
  162. {
  163. ms_ocall_ftruncate_t * ms = (ms_ocall_ftruncate_t *) pms;
  164. int ret;
  165. ODEBUG(OCALL_FTRUNCATE, ms);
  166. ret = INLINE_SYSCALL(ftruncate, 2, ms->ms_fd, ms->ms_length);
  167. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  168. }
  169. static int sgx_ocall_mkdir(void * pms)
  170. {
  171. ms_ocall_mkdir_t * ms = (ms_ocall_mkdir_t *) pms;
  172. int ret;
  173. ODEBUG(OCALL_MKDIR, ms);
  174. ret = INLINE_SYSCALL(mkdir, 2, ms->ms_pathname, ms->ms_mode);
  175. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  176. }
  177. static int sgx_ocall_getdents(void * pms)
  178. {
  179. ms_ocall_getdents_t * ms = (ms_ocall_getdents_t *) pms;
  180. int ret;
  181. ODEBUG(OCALL_GETDENTS, ms);
  182. ret = INLINE_SYSCALL(getdents64, 3, ms->ms_fd, ms->ms_dirp, ms->ms_size);
  183. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  184. }
  185. int clone_thread(void (*func) (void *),
  186. void * args,
  187. unsigned int * child_tid,
  188. unsigned int * tid);
  189. static int sgx_ocall_clone_thread(void * pms)
  190. {
  191. ms_ocall_clone_thread_t * ms = (ms_ocall_clone_thread_t *) pms;
  192. ODEBUG(OCALL_CLONE_THREAD, ms);
  193. return clone_thread(ms->ms_func, (void *) ms->ms_arg,
  194. ms->ms_child_tid, &ms->ms_tid);
  195. }
  196. int sgx_create_process (const char * uri,
  197. int nargs, const char ** args,
  198. int * retfds);
  199. static int sgx_ocall_create_process(void * pms)
  200. {
  201. ms_ocall_create_process_t * ms = (ms_ocall_create_process_t *) pms;
  202. ODEBUG(OCALL_CREATE_PROCESS, ms);
  203. int ret = sgx_create_process(ms->ms_uri, ms->ms_nargs, ms->ms_args,
  204. ms->ms_proc_fds);
  205. if (ret < 0)
  206. return ret;
  207. ms->ms_pid = ret;
  208. return 0;
  209. }
  210. static int sgx_ocall_exit_process(void * pms)
  211. {
  212. ms_ocall_exit_process_t * ms = (ms_ocall_exit_process_t *) pms;
  213. ODEBUG(OCALL_EXIT_PROCESS, ms);
  214. exit_process(ms->ms_status);
  215. return 0;
  216. }
  217. static int sgx_ocall_futex(void * pms)
  218. {
  219. ms_ocall_futex_t * ms = (ms_ocall_futex_t *) pms;
  220. int ret;
  221. ODEBUG(OCALL_FUTEX, ms);
  222. struct timespec * ts = NULL;
  223. if (ms->ms_timeout != (unsigned long) -1) {
  224. ts = __alloca(sizeof(struct timespec));
  225. ts->tv_sec = ms->ms_timeout / 1000000;
  226. ts->tv_nsec = (ms->ms_timeout - ts->tv_sec * 1000000) * 1000;
  227. }
  228. ret = INLINE_SYSCALL(futex, 6, ms->ms_futex, ms->ms_op, ms->ms_val,
  229. ts, NULL, 0);
  230. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  231. }
  232. static int sgx_ocall_socketpair(void * pms)
  233. {
  234. ms_ocall_socketpair_t * ms = (ms_ocall_socketpair_t *) pms;
  235. int ret;
  236. ODEBUG(OCALL_SOCKETPAIR, ms);
  237. ret = INLINE_SYSCALL(socketpair, 4, ms->ms_domain,
  238. ms->ms_type|SOCK_CLOEXEC,
  239. ms->ms_protocol, &ms->ms_sockfds);
  240. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  241. }
  242. static int sock_getopt(int fd, struct sockopt * opt)
  243. {
  244. return 0;
  245. }
  246. static int sgx_ocall_sock_listen(void * pms)
  247. {
  248. ms_ocall_sock_listen_t * ms = (ms_ocall_sock_listen_t *) pms;
  249. int ret, fd;
  250. ODEBUG(OCALL_SOCK_LISTEN, ms);
  251. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  252. ms->ms_type|SOCK_CLOEXEC,
  253. ms->ms_protocol);
  254. if (IS_ERR(ret)) {
  255. ret = -PAL_ERROR_DENIED;
  256. goto err;
  257. }
  258. fd = ret;
  259. /* must set the socket to be reuseable */
  260. int reuseaddr = 1;
  261. INLINE_SYSCALL(setsockopt, 5, fd, SOL_SOCKET, SO_REUSEADDR, &reuseaddr,
  262. sizeof(int));
  263. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_addr, ms->ms_addrlen);
  264. if (IS_ERR(ret)) {
  265. ret = unix_to_pal_error(ERRNO(ret));
  266. goto err_fd;
  267. }
  268. if (ms->ms_type & SOCK_STREAM) {
  269. ret = INLINE_SYSCALL(listen, 2, fd, DEFAULT_BACKLOG);
  270. if (IS_ERR(ret)) {
  271. ret = -PAL_ERROR_DENIED;
  272. goto err_fd;
  273. }
  274. }
  275. ret = sock_getopt(fd, &ms->ms_sockopt);
  276. if (ret < 0)
  277. goto err_fd;
  278. return fd;
  279. err_fd:
  280. INLINE_SYSCALL(close, 1, fd);
  281. err:
  282. return ret;
  283. }
  284. static int sgx_ocall_sock_accept(void * pms)
  285. {
  286. ms_ocall_sock_accept_t * ms = (ms_ocall_sock_accept_t *) pms;
  287. int ret, fd;
  288. ODEBUG(OCALL_SOCK_ACCEPT, ms);
  289. socklen_t addrlen = ms->ms_addrlen;
  290. ret = INLINE_SYSCALL(accept4, 4, ms->ms_sockfd, ms->ms_addr,
  291. &addrlen, O_CLOEXEC);
  292. if (IS_ERR(ret)) {
  293. ret = unix_to_pal_error(ERRNO(ret));
  294. goto err;
  295. }
  296. fd = ret;
  297. ret = sock_getopt(fd, &ms->ms_sockopt);
  298. if (ret < 0)
  299. goto err_fd;
  300. ms->ms_addrlen = addrlen;
  301. return fd;
  302. err_fd:
  303. INLINE_SYSCALL(close, 1, fd);
  304. err:
  305. return ret;
  306. }
  307. static int sgx_ocall_sock_connect(void * pms)
  308. {
  309. ms_ocall_sock_connect_t * ms = (ms_ocall_sock_connect_t *) pms;
  310. int ret, fd;
  311. ODEBUG(OCALL_SOCK_CONNECT, ms);
  312. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  313. ms->ms_type|SOCK_CLOEXEC,
  314. ms->ms_protocol);
  315. if (IS_ERR(ret)) {
  316. ret = -PAL_ERROR_DENIED;
  317. goto err;
  318. }
  319. fd = ret;
  320. if (ms->ms_bind_addr && ms->ms_bind_addr->sa_family) {
  321. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_bind_addr,
  322. ms->ms_bind_addrlen);
  323. if (IS_ERR(ret)) {
  324. ret = unix_to_pal_error(ERRNO(ret));
  325. goto err_fd;
  326. }
  327. }
  328. ret = INLINE_SYSCALL(connect, 3, fd, ms->ms_addr, ms->ms_addrlen);
  329. if (IS_ERR(ret)) {
  330. ret = unix_to_pal_error(ERRNO(ret));
  331. goto err_fd;
  332. }
  333. if (ms->ms_bind_addr && !ms->ms_bind_addr->sa_family) {
  334. socklen_t addrlen;
  335. ret = INLINE_SYSCALL(getsockname, 3, fd, ms->ms_bind_addr,
  336. &addrlen);
  337. if (IS_ERR(ret)) {
  338. ret = -PAL_ERROR_DENIED;
  339. goto err_fd;
  340. }
  341. ms->ms_bind_addrlen = addrlen;
  342. }
  343. ret = sock_getopt(fd, &ms->ms_sockopt);
  344. if (ret < 0)
  345. goto err_fd;
  346. return fd;
  347. err_fd:
  348. INLINE_SYSCALL(close, 1, fd);
  349. err:
  350. return ret;
  351. }
  352. static int sgx_ocall_sock_recv(void * pms)
  353. {
  354. ms_ocall_sock_recv_t * ms = (ms_ocall_sock_recv_t *) pms;
  355. int ret;
  356. ODEBUG(OCALL_SOCK_RECV, ms);
  357. struct sockaddr * addr = ms->ms_addr;
  358. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  359. if (ms->ms_sockfd == PAL_SEC()->mcast_srv)
  360. addr = NULL;
  361. ret = INLINE_SYSCALL(recvfrom, 6,
  362. ms->ms_sockfd, ms->ms_buf, ms->ms_count, 0,
  363. addr, addr ? &addrlen : NULL);
  364. if (!IS_ERR(ret) && addr)
  365. ms->ms_addrlen = addrlen;
  366. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  367. }
  368. static int sgx_ocall_sock_send(void * pms)
  369. {
  370. ms_ocall_sock_send_t * ms = (ms_ocall_sock_send_t *) pms;
  371. int ret;
  372. ODEBUG(OCALL_SOCK_SEND, ms);
  373. const struct sockaddr * addr = ms->ms_addr;
  374. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  375. if (ms->ms_sockfd == PAL_SEC()->mcast_srv) {
  376. struct sockaddr_in * mcast_addr = __alloca(sizeof(struct sockaddr_in));
  377. mcast_addr->sin_family = AF_INET;
  378. inet_pton4(MCAST_GROUP, sizeof(MCAST_GROUP), &mcast_addr->sin_addr.s_addr);
  379. mcast_addr->sin_port = htons(PAL_SEC()->mcast_port);
  380. addr = (struct sockaddr *) mcast_addr;
  381. addrlen = sizeof(struct sockaddr_in);
  382. }
  383. ret = INLINE_SYSCALL(sendto, 6,
  384. ms->ms_sockfd, ms->ms_buf, ms->ms_count, MSG_NOSIGNAL,
  385. addr, addrlen);
  386. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  387. }
  388. static int sgx_ocall_sock_recv_fd(void * pms)
  389. {
  390. ms_ocall_sock_recv_fd_t * ms = (ms_ocall_sock_recv_fd_t *) pms;
  391. int ret;
  392. ODEBUG(OCALL_SOCK_RECV_FD, ms);
  393. struct msghdr hdr;
  394. struct iovec iov[1];
  395. // receive PAL_HANDLE contents in the body
  396. char cbuf[sizeof(struct cmsghdr) + ms->ms_nfds * sizeof(int)];
  397. iov[0].iov_base = ms->ms_buf;
  398. iov[0].iov_len = ms->ms_count;
  399. // clear body memory
  400. memset(&hdr, 0, sizeof(struct msghdr));
  401. // set message header values
  402. hdr.msg_iov = iov;
  403. hdr.msg_iovlen = 1;
  404. hdr.msg_control = cbuf;
  405. hdr.msg_controllen = sizeof(struct cmsghdr) + sizeof(int) *
  406. ms->ms_nfds;
  407. hdr.msg_flags = 0;
  408. ret = INLINE_SYSCALL(recvmsg, 3, ms->ms_sockfd, &hdr, 0);
  409. if (!IS_ERR(ret)) {
  410. struct cmsghdr * chdr = CMSG_FIRSTHDR(&hdr);
  411. if (chdr &&
  412. chdr->cmsg_type == SCM_RIGHTS) {
  413. ms->ms_nfds = (chdr->cmsg_len - sizeof(struct cmsghdr)) /
  414. sizeof(int);
  415. memcpy(ms->ms_fds, CMSG_DATA(chdr), sizeof(int) * ms->ms_nfds);
  416. } else {
  417. ms->ms_nfds = 0;
  418. }
  419. return ret;
  420. }
  421. return unix_to_pal_error(ERRNO(ret));
  422. }
  423. static int sgx_ocall_sock_send_fd(void * pms)
  424. {
  425. ms_ocall_sock_send_fd_t * ms = (ms_ocall_sock_send_fd_t *) pms;
  426. int ret;
  427. ODEBUG(OCALL_SOCK_SEND_FD, ms);
  428. // Declare variables required for sending the message
  429. struct msghdr hdr; // message header
  430. struct cmsghdr * chdr; //control message header
  431. struct iovec iov[1]; // IO Vector
  432. /* Message Body Composition:
  433. IOVEC[0]: PAL_HANDLE
  434. IOVEC[1..n]: Additional handle member follow
  435. Control Message: file descriptors */
  436. // Control message buffer with added space for 2 fds (ie. max size
  437. // that it will have)
  438. char cbuf[sizeof(struct cmsghdr) + ms->ms_nfds * sizeof(int)];
  439. iov[0].iov_base = (void *) ms->ms_buf;
  440. iov[0].iov_len = ms->ms_count;
  441. hdr.msg_name = NULL;
  442. hdr.msg_namelen = 0;
  443. hdr.msg_iov = iov;
  444. hdr.msg_iovlen = 1;
  445. hdr.msg_flags = 0;
  446. hdr.msg_control = cbuf; // Control Message Buffer
  447. hdr.msg_controllen = sizeof(struct cmsghdr) + sizeof(int) * ms->ms_nfds;
  448. // Fill control message infomation for the file descriptors
  449. // Check hdr.msg_controllen >= sizeof(struct cmsghdr) to point to
  450. // cbuf, which is redundant based on the above code as we have
  451. // statically allocated memory.
  452. // or (struct cmsghdr*) cbuf
  453. chdr = CMSG_FIRSTHDR(&hdr); // Pointer to msg_control
  454. chdr->cmsg_level = SOL_SOCKET; // Originating Protocol
  455. chdr->cmsg_type = SCM_RIGHTS; // Protocol Specific Type
  456. // Length of control message = sizeof(struct cmsghdr) + nfds
  457. chdr->cmsg_len = CMSG_LEN(sizeof(int) * ms->ms_nfds);
  458. // Copy the fds below control header
  459. memcpy(CMSG_DATA(chdr), ms->ms_fds, sizeof(int) * ms->ms_nfds);
  460. // Also, Update main header with control message length (duplicate)
  461. hdr.msg_controllen = chdr->cmsg_len;
  462. ret = INLINE_SYSCALL(sendmsg, 3, ms->ms_sockfd, &hdr, MSG_NOSIGNAL);
  463. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  464. }
  465. static int sgx_ocall_sock_setopt(void * pms)
  466. {
  467. ms_ocall_sock_setopt_t * ms = (ms_ocall_sock_setopt_t *) pms;
  468. int ret;
  469. ODEBUG(OCALL_SOCK_SETOPT, ms);
  470. ret = INLINE_SYSCALL(setsockopt, 5,
  471. ms->ms_sockfd, ms->ms_level, ms->ms_optname,
  472. ms->ms_optval, ms->ms_optlen);
  473. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  474. }
  475. static int sgx_ocall_sock_shutdown(void * pms)
  476. {
  477. ms_ocall_sock_shutdown_t * ms = (ms_ocall_sock_shutdown_t *) pms;
  478. ODEBUG(OCALL_SOCK_SHUTDOWN, ms);
  479. INLINE_SYSCALL(shutdown, 2, ms->ms_sockfd, ms->ms_how);
  480. return 0;
  481. }
  482. static int sgx_ocall_gettime(void * pms)
  483. {
  484. ms_ocall_gettime_t * ms = (ms_ocall_gettime_t *) pms;
  485. ODEBUG(OCALL_GETTIME, ms);
  486. struct timeval tv;
  487. INLINE_SYSCALL(gettimeofday, 2, &tv, NULL);
  488. ms->ms_microsec = tv.tv_sec * 1000000UL + tv.tv_usec;
  489. return 0;
  490. }
  491. static int sgx_ocall_sleep(void * pms)
  492. {
  493. ms_ocall_sleep_t * ms = (ms_ocall_sleep_t *) pms;
  494. int ret;
  495. ODEBUG(OCALL_SLEEP, ms);
  496. struct timespec req, rem;
  497. req.tv_sec = ms->ms_microsec / 1000000;
  498. req.tv_nsec = (ms->ms_microsec - req.tv_sec * 1000000) * 1000;
  499. ret = INLINE_SYSCALL(nanosleep, 2, &req, &rem);
  500. if (IS_ERR(ret) && ERRNO(ret) == EINTR)
  501. ms->ms_microsec = rem.tv_sec * 1000000 + rem.tv_nsec / 1000;
  502. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  503. }
  504. static int sgx_ocall_poll(void * pms)
  505. {
  506. ms_ocall_poll_t * ms = (ms_ocall_poll_t *) pms;
  507. int ret;
  508. ODEBUG(OCALL_POLL, ms);
  509. struct timespec * ts = NULL;
  510. if (ms->ms_timeout != (unsigned long) -1) {
  511. ts = __alloca(sizeof(struct timespec));
  512. ts->tv_sec = ms->ms_timeout / 1000000;
  513. ts->tv_nsec = (ms->ms_timeout - ts->tv_sec * 1000000) * 1000;
  514. }
  515. ret = INLINE_SYSCALL(ppoll, 4, ms->ms_fds, ms->ms_nfds, ts, NULL);
  516. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  517. }
  518. static int sgx_ocall_rename(void * pms)
  519. {
  520. ms_ocall_rename_t * ms = (ms_ocall_rename_t *) pms;
  521. int ret;
  522. ODEBUG(OCALL_RENAME, ms);
  523. ret = INLINE_SYSCALL(rename, 2, ms->ms_oldpath, ms->ms_newpath);
  524. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  525. }
  526. static int sgx_ocall_delete(void * pms)
  527. {
  528. ms_ocall_delete_t * ms = (ms_ocall_delete_t *) pms;
  529. int ret;
  530. ODEBUG(OCALL_DELETE, ms);
  531. ret = INLINE_SYSCALL(unlink, 1, ms->ms_pathname);
  532. if (IS_ERR(ret) && ERRNO(ret) == EISDIR)
  533. ret = INLINE_SYSCALL(rmdir, 1, ms->ms_pathname);
  534. return IS_ERR(ret) ? unix_to_pal_error(ERRNO(ret)) : ret;
  535. }
  536. static int sgx_ocall_schedule(void * pms)
  537. {
  538. ms_ocall_schedule_t * ms = (ms_ocall_schedule_t *) pms;
  539. ODEBUG(OCALL_SCHEDULE, ms);
  540. if (ms->ms_tid) {
  541. INLINE_SYSCALL(tgkill, 3, PAL_SEC()->pid, ms->ms_tid, SIGCONT);
  542. } else {
  543. INLINE_SYSCALL(sched_yield, 0);
  544. }
  545. return 0;
  546. }
  547. void load_gdb_command (const char * command);
  548. static int sgx_ocall_load_debug(void * pms)
  549. {
  550. const char * command = (const char *) pms;
  551. ODEBUG(OCALL_LOAD_DEBUG, (void *) command);
  552. load_gdb_command(command);
  553. return 0;
  554. }
  555. void * ocall_table[OCALL_NR] = {
  556. [OCALL_EXIT] = (void *) sgx_ocall_exit,
  557. [OCALL_PRINT_STRING] = (void *) sgx_ocall_print_string,
  558. [OCALL_ALLOC_UNTRUSTED] = (void *) sgx_ocall_alloc_untrusted,
  559. [OCALL_MAP_UNTRUSTED] = (void *) sgx_ocall_map_untrusted,
  560. [OCALL_UNMAP_UNTRUSTED] = (void *) sgx_ocall_unmap_untrusted,
  561. [OCALL_CPUID] = (void *) sgx_ocall_cpuid,
  562. [OCALL_OPEN] = (void *) sgx_ocall_open,
  563. [OCALL_CLOSE] = (void *) sgx_ocall_close,
  564. [OCALL_READ] = (void *) sgx_ocall_read,
  565. [OCALL_WRITE] = (void *) sgx_ocall_write,
  566. [OCALL_FSTAT] = (void *) sgx_ocall_fstat,
  567. [OCALL_FIONREAD] = (void *) sgx_ocall_fionread,
  568. [OCALL_FSETNONBLOCK] = (void *) sgx_ocall_fsetnonblock,
  569. [OCALL_FCHMOD] = (void *) sgx_ocall_fchmod,
  570. [OCALL_FSYNC] = (void *) sgx_ocall_fsync,
  571. [OCALL_FTRUNCATE] = (void *) sgx_ocall_ftruncate,
  572. [OCALL_MKDIR] = (void *) sgx_ocall_mkdir,
  573. [OCALL_GETDENTS] = (void *) sgx_ocall_getdents,
  574. [OCALL_CLONE_THREAD] = (void *) sgx_ocall_clone_thread,
  575. [OCALL_CREATE_PROCESS] = (void *) sgx_ocall_create_process,
  576. [OCALL_EXIT_PROCESS] = (void *) sgx_ocall_exit_process,
  577. [OCALL_FUTEX] = (void *) sgx_ocall_futex,
  578. [OCALL_SOCKETPAIR] = (void *) sgx_ocall_socketpair,
  579. [OCALL_SOCK_LISTEN] = (void *) sgx_ocall_sock_listen,
  580. [OCALL_SOCK_ACCEPT] = (void *) sgx_ocall_sock_accept,
  581. [OCALL_SOCK_CONNECT] = (void *) sgx_ocall_sock_connect,
  582. [OCALL_SOCK_RECV] = (void *) sgx_ocall_sock_recv,
  583. [OCALL_SOCK_SEND] = (void *) sgx_ocall_sock_send,
  584. [OCALL_SOCK_RECV_FD] = (void *) sgx_ocall_sock_recv_fd,
  585. [OCALL_SOCK_SEND_FD] = (void *) sgx_ocall_sock_send_fd,
  586. [OCALL_SOCK_SETOPT] = (void *) sgx_ocall_sock_setopt,
  587. [OCALL_SOCK_SHUTDOWN] = (void *) sgx_ocall_sock_shutdown,
  588. [OCALL_GETTIME] = (void *) sgx_ocall_gettime,
  589. [OCALL_SLEEP] = (void *) sgx_ocall_sleep,
  590. [OCALL_POLL] = (void *) sgx_ocall_poll,
  591. [OCALL_RENAME] = (void *) sgx_ocall_rename,
  592. [OCALL_DELETE] = (void *) sgx_ocall_delete,
  593. [OCALL_SCHEDULE] = (void *) sgx_ocall_schedule,
  594. [OCALL_LOAD_DEBUG] = (void *) sgx_ocall_load_debug,
  595. };
  596. #define EDEBUG(code, ms) do {} while (0)
  597. int ecall_pal_main (int argc, const char ** argv, const char ** envp)
  598. {
  599. struct pal_enclave * enclave = current_enclave;
  600. ms_ecall_pal_main_t ms;
  601. ms.ms_argc = argc;
  602. ms.ms_argv = argv;
  603. ms.ms_envp = envp;
  604. ms.ms_sec_info = PAL_SEC();
  605. ms.ms_enclave_base = (void *) enclave->baseaddr;
  606. ms.ms_enclave_size = enclave->size;
  607. EDEBUG(ECALL_PAL_MAIN, &ms);
  608. return sgx_ecall(ECALL_PAL_MAIN, &ms);
  609. }
  610. int ecall_thread_start (void (*func) (void *), void * arg,
  611. unsigned int * child_tid, unsigned int tid)
  612. {
  613. ms_ecall_thread_start_t ms;
  614. ms.ms_func = func;
  615. ms.ms_arg = arg;
  616. ms.ms_child_tid = child_tid;
  617. ms.ms_tid = tid;
  618. EDEBUG(ECALL_THREAD_START, &ms);
  619. return sgx_ecall(ECALL_THREAD_START, &ms);
  620. }