sgx_enclave.c 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707
  1. #include "ocall_types.h"
  2. #include "ecall_types.h"
  3. #include "sgx_internal.h"
  4. #include "sgx_enclave.h"
  5. #include "pal_security.h"
  6. #include "pal_linux_error.h"
  7. #include <asm/mman.h>
  8. #include <asm/ioctls.h>
  9. #include <asm/socket.h>
  10. #include <linux/fs.h>
  11. #include <linux/in.h>
  12. #include <linux/in6.h>
  13. #include <math.h>
  14. #include <asm/errno.h>
  15. #define ODEBUG(code, ms) do {} while (0)
  16. static long sgx_ocall_exit(void* pms)
  17. {
  18. ms_ocall_exit_t * ms = (ms_ocall_exit_t *) pms;
  19. ODEBUG(OCALL_EXIT, NULL);
  20. if (ms->ms_is_exitgroup && ms->ms_exitcode == PAL_WAIT_FOR_CHILDREN_EXIT) {
  21. /* this is a "temporary" process exiting after execve'ing a child process: it must still
  22. * be around until the child finally exits (because its parent in turn may wait on it) */
  23. SGX_DBG(DBG_I, "Temporary process exits after emulating execve, wait for child to exit\n");
  24. int wstatus;
  25. int ret = INLINE_SYSCALL(wait4, 4, /*any child*/-1, &wstatus, /*options=*/0, /*rusage=*/NULL);
  26. if (IS_ERR(ret)) {
  27. /* it's too late to recover from errors, just log it and continue with dying */
  28. SGX_DBG(DBG_I, "Temporary process waited for child to exit but received error %d\n", ret);
  29. }
  30. ms->ms_exitcode = wstatus;
  31. }
  32. if (ms->ms_exitcode != (int) ((uint8_t) ms->ms_exitcode)) {
  33. SGX_DBG(DBG_E, "Saturation error in exit code %d, getting rounded down to %u\n",
  34. ms->ms_exitcode, (uint8_t) ms->ms_exitcode);
  35. ms->ms_exitcode = 255;
  36. }
  37. /* exit the whole process if exit_group() */
  38. if (ms->ms_is_exitgroup)
  39. INLINE_SYSCALL(exit_group, 1, (int)ms->ms_exitcode);
  40. /* otherwise call SGX-related thread reset and exit this thread */
  41. block_async_signals(true);
  42. ecall_thread_reset();
  43. unmap_tcs();
  44. thread_exit((int)ms->ms_exitcode);
  45. return 0;
  46. }
  47. static long sgx_ocall_mmap_untrusted(void * pms)
  48. {
  49. ms_ocall_mmap_untrusted_t * ms = (ms_ocall_mmap_untrusted_t *) pms;
  50. void * addr;
  51. ODEBUG(OCALL_MMAP_UNTRUSTED, ms);
  52. addr = (void *) INLINE_SYSCALL(mmap, 6, NULL, ms->ms_size,
  53. ms->ms_prot,
  54. (ms->ms_fd == -1) ? MAP_ANONYMOUS | MAP_PRIVATE
  55. : MAP_FILE | MAP_SHARED,
  56. ms->ms_fd, ms->ms_offset);
  57. if (IS_ERR_P(addr))
  58. return -ERRNO_P(addr);
  59. ms->ms_mem = addr;
  60. return 0;
  61. }
  62. static long sgx_ocall_munmap_untrusted(void * pms)
  63. {
  64. ms_ocall_munmap_untrusted_t * ms = (ms_ocall_munmap_untrusted_t *) pms;
  65. ODEBUG(OCALL_MUNMAP_UNTRUSTED, ms);
  66. INLINE_SYSCALL(munmap, 2, ALLOC_ALIGN_DOWN_PTR(ms->ms_mem),
  67. ALLOC_ALIGN_UP_PTR(ms->ms_mem + ms->ms_size) -
  68. ALLOC_ALIGN_DOWN_PTR(ms->ms_mem));
  69. return 0;
  70. }
  71. static long sgx_ocall_cpuid(void * pms)
  72. {
  73. ms_ocall_cpuid_t * ms = (ms_ocall_cpuid_t *) pms;
  74. ODEBUG(OCALL_CPUID, ms);
  75. __asm__ volatile ("cpuid"
  76. : "=a"(ms->ms_values[0]),
  77. "=b"(ms->ms_values[1]),
  78. "=c"(ms->ms_values[2]),
  79. "=d"(ms->ms_values[3])
  80. : "a"(ms->ms_leaf), "c"(ms->ms_subleaf) : "memory");
  81. return 0;
  82. }
  83. static long sgx_ocall_open(void * pms)
  84. {
  85. ms_ocall_open_t * ms = (ms_ocall_open_t *) pms;
  86. long ret;
  87. ODEBUG(OCALL_OPEN, ms);
  88. ret = INLINE_SYSCALL(open, 3, ms->ms_pathname, ms->ms_flags|O_CLOEXEC,
  89. ms->ms_mode);
  90. return ret;
  91. }
  92. static long sgx_ocall_close(void * pms)
  93. {
  94. ms_ocall_close_t * ms = (ms_ocall_close_t *) pms;
  95. ODEBUG(OCALL_CLOSE, ms);
  96. INLINE_SYSCALL(close, 1, ms->ms_fd);
  97. return 0;
  98. }
  99. static long sgx_ocall_read(void * pms)
  100. {
  101. ms_ocall_read_t * ms = (ms_ocall_read_t *) pms;
  102. long ret;
  103. ODEBUG(OCALL_READ, ms);
  104. ret = INLINE_SYSCALL(read, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  105. return ret;
  106. }
  107. static long sgx_ocall_write(void * pms)
  108. {
  109. ms_ocall_write_t * ms = (ms_ocall_write_t *) pms;
  110. long ret;
  111. ODEBUG(OCALL_WRITE, ms);
  112. ret = INLINE_SYSCALL(write, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  113. return ret;
  114. }
  115. static long sgx_ocall_pread(void* pms) {
  116. ms_ocall_pread_t* ms = (ms_ocall_pread_t*)pms;
  117. long ret;
  118. ODEBUG(OCALL_PREAD, ms);
  119. ret = INLINE_SYSCALL(pread64, 4, ms->ms_fd, ms->ms_buf, ms->ms_count, ms->ms_offset);
  120. return ret;
  121. }
  122. static long sgx_ocall_pwrite(void* pms) {
  123. ms_ocall_pwrite_t* ms = (ms_ocall_pwrite_t*)pms;
  124. long ret;
  125. ODEBUG(OCALL_PWRITE, ms);
  126. ret = INLINE_SYSCALL(pwrite64, 4, ms->ms_fd, ms->ms_buf, ms->ms_count, ms->ms_offset);
  127. return ret;
  128. }
  129. static long sgx_ocall_fstat(void * pms)
  130. {
  131. ms_ocall_fstat_t * ms = (ms_ocall_fstat_t *) pms;
  132. long ret;
  133. ODEBUG(OCALL_FSTAT, ms);
  134. ret = INLINE_SYSCALL(fstat, 2, ms->ms_fd, &ms->ms_stat);
  135. return ret;
  136. }
  137. static long sgx_ocall_fionread(void * pms)
  138. {
  139. ms_ocall_fionread_t * ms = (ms_ocall_fionread_t *) pms;
  140. long ret;
  141. int val;
  142. ODEBUG(OCALL_FIONREAD, ms);
  143. ret = INLINE_SYSCALL(ioctl, 3, ms->ms_fd, FIONREAD, &val);
  144. return IS_ERR(ret) ? ret : val;
  145. }
  146. static long sgx_ocall_fsetnonblock(void * pms)
  147. {
  148. ms_ocall_fsetnonblock_t * ms = (ms_ocall_fsetnonblock_t *) pms;
  149. long ret;
  150. int flags;
  151. ODEBUG(OCALL_FSETNONBLOCK, ms);
  152. ret = INLINE_SYSCALL(fcntl, 2, ms->ms_fd, F_GETFL);
  153. if (IS_ERR(ret))
  154. return ret;
  155. flags = ret;
  156. if (ms->ms_nonblocking) {
  157. if (!(flags & O_NONBLOCK))
  158. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  159. flags | O_NONBLOCK);
  160. } else {
  161. if (flags & O_NONBLOCK)
  162. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  163. flags & ~O_NONBLOCK);
  164. }
  165. return ret;
  166. }
  167. static long sgx_ocall_fchmod(void * pms)
  168. {
  169. ms_ocall_fchmod_t * ms = (ms_ocall_fchmod_t *) pms;
  170. long ret;
  171. ODEBUG(OCALL_FCHMOD, ms);
  172. ret = INLINE_SYSCALL(fchmod, 2, ms->ms_fd, ms->ms_mode);
  173. return ret;
  174. }
  175. static long sgx_ocall_fsync(void * pms)
  176. {
  177. ms_ocall_fsync_t * ms = (ms_ocall_fsync_t *) pms;
  178. ODEBUG(OCALL_FSYNC, ms);
  179. INLINE_SYSCALL(fsync, 1, ms->ms_fd);
  180. return 0;
  181. }
  182. static long sgx_ocall_ftruncate(void * pms)
  183. {
  184. ms_ocall_ftruncate_t * ms = (ms_ocall_ftruncate_t *) pms;
  185. long ret;
  186. ODEBUG(OCALL_FTRUNCATE, ms);
  187. ret = INLINE_SYSCALL(ftruncate, 2, ms->ms_fd, ms->ms_length);
  188. return ret;
  189. }
  190. static long sgx_ocall_mkdir(void * pms)
  191. {
  192. ms_ocall_mkdir_t * ms = (ms_ocall_mkdir_t *) pms;
  193. long ret;
  194. ODEBUG(OCALL_MKDIR, ms);
  195. ret = INLINE_SYSCALL(mkdir, 2, ms->ms_pathname, ms->ms_mode);
  196. return ret;
  197. }
  198. static long sgx_ocall_getdents(void * pms)
  199. {
  200. ms_ocall_getdents_t * ms = (ms_ocall_getdents_t *) pms;
  201. long ret;
  202. ODEBUG(OCALL_GETDENTS, ms);
  203. ret = INLINE_SYSCALL(getdents64, 3, ms->ms_fd, ms->ms_dirp, ms->ms_size);
  204. return ret;
  205. }
  206. static long sgx_ocall_resume_thread(void * pms)
  207. {
  208. ODEBUG(OCALL_RESUME_THREAD, pms);
  209. return interrupt_thread(pms);
  210. }
  211. static long sgx_ocall_clone_thread(void * pms)
  212. {
  213. __UNUSED(pms);
  214. ODEBUG(OCALL_CLONE_THREAD, pms);
  215. return clone_thread();
  216. }
  217. static long sgx_ocall_create_process(void * pms)
  218. {
  219. ms_ocall_create_process_t * ms = (ms_ocall_create_process_t *) pms;
  220. ODEBUG(OCALL_CREATE_PROCESS, ms);
  221. long ret = sgx_create_process(ms->ms_uri, ms->ms_nargs, ms->ms_args,
  222. &ms->ms_stream_fd, &ms->ms_cargo_fd);
  223. if (ret < 0)
  224. return ret;
  225. ms->ms_pid = ret;
  226. return 0;
  227. }
  228. static long sgx_ocall_futex(void * pms)
  229. {
  230. ms_ocall_futex_t * ms = (ms_ocall_futex_t *) pms;
  231. long ret;
  232. ODEBUG(OCALL_FUTEX, ms);
  233. struct timespec* ts = NULL;
  234. if (ms->ms_timeout_us >= 0) {
  235. ts = __alloca(sizeof(struct timespec));
  236. ts->tv_sec = ms->ms_timeout_us / 1000000;
  237. ts->tv_nsec = (ms->ms_timeout_us - ts->tv_sec * 1000000) * 1000;
  238. }
  239. ret = INLINE_SYSCALL(futex, 6, ms->ms_futex, ms->ms_op, ms->ms_val,
  240. ts, NULL, 0);
  241. return ret;
  242. }
  243. static long sgx_ocall_socketpair(void * pms)
  244. {
  245. ms_ocall_socketpair_t * ms = (ms_ocall_socketpair_t *) pms;
  246. long ret;
  247. ODEBUG(OCALL_SOCKETPAIR, ms);
  248. ret = INLINE_SYSCALL(socketpair, 4, ms->ms_domain,
  249. ms->ms_type|SOCK_CLOEXEC,
  250. ms->ms_protocol, &ms->ms_sockfds);
  251. return ret;
  252. }
  253. static long sock_getopt(int fd, struct sockopt * opt)
  254. {
  255. SGX_DBG(DBG_M, "sock_getopt (fd = %d, sockopt addr = %p) is not implemented \
  256. always returns 0\n", fd, opt);
  257. /* initialize *opt with constant */
  258. *opt = (struct sockopt){0};
  259. opt->reuseaddr = 1;
  260. return 0;
  261. }
  262. static long sgx_ocall_listen(void * pms)
  263. {
  264. ms_ocall_listen_t * ms = (ms_ocall_listen_t *) pms;
  265. long ret;
  266. int fd;
  267. ODEBUG(OCALL_LISTEN, ms);
  268. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  269. ms->ms_type|SOCK_CLOEXEC,
  270. ms->ms_protocol);
  271. if (IS_ERR(ret))
  272. goto err;
  273. fd = ret;
  274. /* must set the socket to be reuseable */
  275. int reuseaddr = 1;
  276. ret = INLINE_SYSCALL(setsockopt, 5, fd, SOL_SOCKET, SO_REUSEADDR, &reuseaddr, sizeof(reuseaddr));
  277. if (IS_ERR(ret))
  278. goto err_fd;
  279. if (ms->ms_domain == AF_INET6) {
  280. /* IPV6_V6ONLY socket option can only be set before first bind */
  281. ret = INLINE_SYSCALL(setsockopt, 5, fd, IPPROTO_IPV6, IPV6_V6ONLY, &ms->ms_ipv6_v6only,
  282. sizeof(ms->ms_ipv6_v6only));
  283. if (IS_ERR(ret))
  284. goto err_fd;
  285. }
  286. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_addr, ms->ms_addrlen);
  287. if (IS_ERR(ret))
  288. goto err_fd;
  289. if (ms->ms_addr) {
  290. socklen_t addrlen = ms->ms_addrlen;
  291. ret = INLINE_SYSCALL(getsockname, 3, fd, ms->ms_addr, &addrlen);
  292. if (IS_ERR(ret))
  293. goto err_fd;
  294. ms->ms_addrlen = addrlen;
  295. }
  296. if (ms->ms_type & SOCK_STREAM) {
  297. ret = INLINE_SYSCALL(listen, 2, fd, DEFAULT_BACKLOG);
  298. if (IS_ERR(ret))
  299. goto err_fd;
  300. }
  301. ret = sock_getopt(fd, &ms->ms_sockopt);
  302. if (IS_ERR(ret))
  303. goto err_fd;
  304. return fd;
  305. err_fd:
  306. INLINE_SYSCALL(close, 1, fd);
  307. err:
  308. return ret;
  309. }
  310. static long sgx_ocall_accept(void * pms)
  311. {
  312. ms_ocall_accept_t * ms = (ms_ocall_accept_t *) pms;
  313. long ret;
  314. int fd;
  315. ODEBUG(OCALL_ACCEPT, ms);
  316. socklen_t addrlen = ms->ms_addrlen;
  317. ret = INLINE_SYSCALL(accept4, 4, ms->ms_sockfd, ms->ms_addr,
  318. &addrlen, O_CLOEXEC);
  319. if (IS_ERR(ret))
  320. goto err;
  321. fd = ret;
  322. ret = sock_getopt(fd, &ms->ms_sockopt);
  323. if (IS_ERR(ret))
  324. goto err_fd;
  325. ms->ms_addrlen = addrlen;
  326. return fd;
  327. err_fd:
  328. INLINE_SYSCALL(close, 1, fd);
  329. err:
  330. return ret;
  331. }
  332. static long sgx_ocall_connect(void * pms)
  333. {
  334. ms_ocall_connect_t * ms = (ms_ocall_connect_t *) pms;
  335. long ret;
  336. int fd;
  337. ODEBUG(OCALL_CONNECT, ms);
  338. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  339. ms->ms_type|SOCK_CLOEXEC,
  340. ms->ms_protocol);
  341. if (IS_ERR(ret))
  342. goto err;
  343. fd = ret;
  344. if (ms->ms_bind_addr && ms->ms_bind_addr->sa_family) {
  345. if (ms->ms_domain == AF_INET6) {
  346. /* IPV6_V6ONLY socket option can only be set before first bind */
  347. ret = INLINE_SYSCALL(setsockopt, 5, fd, IPPROTO_IPV6, IPV6_V6ONLY, &ms->ms_ipv6_v6only,
  348. sizeof(ms->ms_ipv6_v6only));
  349. if (IS_ERR(ret))
  350. goto err_fd;
  351. }
  352. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_bind_addr,
  353. ms->ms_bind_addrlen);
  354. if (IS_ERR(ret))
  355. goto err_fd;
  356. }
  357. if (ms->ms_addr) {
  358. ret = INLINE_SYSCALL(connect, 3, fd, ms->ms_addr, ms->ms_addrlen);
  359. if (IS_ERR(ret) && ERRNO(ret) == EINPROGRESS) {
  360. do {
  361. struct pollfd pfd = { .fd = fd, .events = POLLOUT, .revents = 0, };
  362. ret = INLINE_SYSCALL(ppoll, 4, &pfd, 1, NULL, NULL);
  363. } while (IS_ERR(ret) &&
  364. ERRNO(ret) == -EWOULDBLOCK);
  365. }
  366. if (IS_ERR(ret))
  367. goto err_fd;
  368. }
  369. if (ms->ms_bind_addr && !ms->ms_bind_addr->sa_family) {
  370. socklen_t addrlen = ms->ms_bind_addrlen;
  371. ret = INLINE_SYSCALL(getsockname, 3, fd, ms->ms_bind_addr,
  372. &addrlen);
  373. if (IS_ERR(ret))
  374. goto err_fd;
  375. ms->ms_bind_addrlen = addrlen;
  376. }
  377. ret = sock_getopt(fd, &ms->ms_sockopt);
  378. if (IS_ERR(ret))
  379. goto err_fd;
  380. return fd;
  381. err_fd:
  382. INLINE_SYSCALL(close, 1, fd);
  383. err:
  384. return ret;
  385. }
  386. static long sgx_ocall_recv(void * pms)
  387. {
  388. ms_ocall_recv_t * ms = (ms_ocall_recv_t *) pms;
  389. long ret;
  390. ODEBUG(OCALL_RECV, ms);
  391. struct sockaddr * addr = ms->ms_addr;
  392. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  393. struct msghdr hdr;
  394. struct iovec iov[1];
  395. iov[0].iov_base = ms->ms_buf;
  396. iov[0].iov_len = ms->ms_count;
  397. hdr.msg_name = addr;
  398. hdr.msg_namelen = addrlen;
  399. hdr.msg_iov = iov;
  400. hdr.msg_iovlen = 1;
  401. hdr.msg_control = ms->ms_control;
  402. hdr.msg_controllen = ms->ms_controllen;
  403. hdr.msg_flags = 0;
  404. ret = INLINE_SYSCALL(recvmsg, 3, ms->ms_sockfd, &hdr, 0);
  405. if (!IS_ERR(ret) && hdr.msg_name) {
  406. /* note that ms->ms_addr is filled by recvmsg() itself */
  407. ms->ms_addrlen = hdr.msg_namelen;
  408. }
  409. if (!IS_ERR(ret) && hdr.msg_control) {
  410. /* note that ms->ms_control is filled by recvmsg() itself */
  411. ms->ms_controllen = hdr.msg_controllen;
  412. }
  413. return ret;
  414. }
  415. static long sgx_ocall_send(void * pms)
  416. {
  417. ms_ocall_send_t * ms = (ms_ocall_send_t *) pms;
  418. long ret;
  419. ODEBUG(OCALL_SEND, ms);
  420. const struct sockaddr * addr = ms->ms_addr;
  421. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  422. struct msghdr hdr;
  423. struct iovec iov[1];
  424. iov[0].iov_base = (void*)ms->ms_buf;
  425. iov[0].iov_len = ms->ms_count;
  426. hdr.msg_name = (void*)addr;
  427. hdr.msg_namelen = addrlen;
  428. hdr.msg_iov = iov;
  429. hdr.msg_iovlen = 1;
  430. hdr.msg_control = ms->ms_control;
  431. hdr.msg_controllen = ms->ms_controllen;
  432. hdr.msg_flags = 0;
  433. ret = INLINE_SYSCALL(sendmsg, 3, ms->ms_sockfd, &hdr, MSG_NOSIGNAL);
  434. return ret;
  435. }
  436. static long sgx_ocall_setsockopt(void * pms)
  437. {
  438. ms_ocall_setsockopt_t * ms = (ms_ocall_setsockopt_t *) pms;
  439. long ret;
  440. ODEBUG(OCALL_SETSOCKOPT, ms);
  441. ret = INLINE_SYSCALL(setsockopt, 5,
  442. ms->ms_sockfd, ms->ms_level, ms->ms_optname,
  443. ms->ms_optval, ms->ms_optlen);
  444. return ret;
  445. }
  446. static long sgx_ocall_shutdown(void * pms)
  447. {
  448. ms_ocall_shutdown_t * ms = (ms_ocall_shutdown_t *) pms;
  449. ODEBUG(OCALL_SHUTDOWN, ms);
  450. INLINE_SYSCALL(shutdown, 2, ms->ms_sockfd, ms->ms_how);
  451. return 0;
  452. }
  453. static long sgx_ocall_gettime(void * pms)
  454. {
  455. ms_ocall_gettime_t * ms = (ms_ocall_gettime_t *) pms;
  456. ODEBUG(OCALL_GETTIME, ms);
  457. struct timeval tv;
  458. INLINE_SYSCALL(gettimeofday, 2, &tv, NULL);
  459. ms->ms_microsec = tv.tv_sec * 1000000UL + tv.tv_usec;
  460. return 0;
  461. }
  462. static long sgx_ocall_sleep(void * pms)
  463. {
  464. ms_ocall_sleep_t * ms = (ms_ocall_sleep_t *) pms;
  465. long ret;
  466. ODEBUG(OCALL_SLEEP, ms);
  467. if (!ms->ms_microsec) {
  468. INLINE_SYSCALL(sched_yield, 0);
  469. return 0;
  470. }
  471. struct timespec req, rem;
  472. unsigned long microsec = ms->ms_microsec;
  473. const unsigned long VERY_LONG_TIME_IN_US = 1000000L * 60 * 60 * 24 * 365 * 128;
  474. if (ms->ms_microsec > VERY_LONG_TIME_IN_US) {
  475. /* avoid overflow with time_t */
  476. req.tv_sec = VERY_LONG_TIME_IN_US / 1000000;
  477. req.tv_nsec = 0;
  478. } else {
  479. req.tv_sec = ms->ms_microsec / 1000000;
  480. req.tv_nsec = (microsec - req.tv_sec * 1000000) * 1000;
  481. }
  482. ret = INLINE_SYSCALL(nanosleep, 2, &req, &rem);
  483. if (IS_ERR(ret) && ERRNO(ret) == EINTR)
  484. ms->ms_microsec = rem.tv_sec * 1000000UL + rem.tv_nsec / 1000UL;
  485. return ret;
  486. }
  487. static long sgx_ocall_poll(void * pms)
  488. {
  489. ms_ocall_poll_t * ms = (ms_ocall_poll_t *) pms;
  490. long ret;
  491. ODEBUG(OCALL_POLL, ms);
  492. struct timespec * ts = NULL;
  493. if (ms->ms_timeout_us >= 0) {
  494. ts = __alloca(sizeof(struct timespec));
  495. ts->tv_sec = ms->ms_timeout_us / 1000000;
  496. ts->tv_nsec = (ms->ms_timeout_us - ts->tv_sec * 1000000) * 1000;
  497. }
  498. ret = INLINE_SYSCALL(ppoll, 4, ms->ms_fds, ms->ms_nfds, ts, NULL);
  499. return ret;
  500. }
  501. static long sgx_ocall_rename(void * pms)
  502. {
  503. ms_ocall_rename_t * ms = (ms_ocall_rename_t *) pms;
  504. long ret;
  505. ODEBUG(OCALL_RENAME, ms);
  506. ret = INLINE_SYSCALL(rename, 2, ms->ms_oldpath, ms->ms_newpath);
  507. return ret;
  508. }
  509. static long sgx_ocall_delete(void * pms)
  510. {
  511. ms_ocall_delete_t * ms = (ms_ocall_delete_t *) pms;
  512. long ret;
  513. ODEBUG(OCALL_DELETE, ms);
  514. ret = INLINE_SYSCALL(unlink, 1, ms->ms_pathname);
  515. if (IS_ERR(ret) && ERRNO(ret) == EISDIR)
  516. ret = INLINE_SYSCALL(rmdir, 1, ms->ms_pathname);
  517. return ret;
  518. }
  519. static long sgx_ocall_eventfd (void * pms)
  520. {
  521. ms_ocall_eventfd_t * ms = (ms_ocall_eventfd_t *) pms;
  522. long ret;
  523. ODEBUG(OCALL_EVENTFD, ms);
  524. ret = INLINE_SYSCALL(eventfd2, 2, ms->ms_initval, ms->ms_flags);
  525. return ret;
  526. }
  527. void load_gdb_command (const char * command);
  528. static long sgx_ocall_load_debug(void * pms)
  529. {
  530. const char * command = (const char *) pms;
  531. ODEBUG(OCALL_LOAD_DEBUG, (void *) command);
  532. load_gdb_command(command);
  533. return 0;
  534. }
  535. static long sgx_ocall_get_attestation(void* pms) {
  536. ms_ocall_get_attestation_t * ms = (ms_ocall_get_attestation_t *) pms;
  537. ODEBUG(OCALL_GET_ATTESTATION, ms);
  538. return retrieve_verified_quote(&ms->ms_spid, ms->ms_subkey, ms->ms_linkable, &ms->ms_report,
  539. &ms->ms_nonce, &ms->ms_attestation);
  540. }
  541. sgx_ocall_fn_t ocall_table[OCALL_NR] = {
  542. [OCALL_EXIT] = sgx_ocall_exit,
  543. [OCALL_MMAP_UNTRUSTED] = sgx_ocall_mmap_untrusted,
  544. [OCALL_MUNMAP_UNTRUSTED] = sgx_ocall_munmap_untrusted,
  545. [OCALL_CPUID] = sgx_ocall_cpuid,
  546. [OCALL_OPEN] = sgx_ocall_open,
  547. [OCALL_CLOSE] = sgx_ocall_close,
  548. [OCALL_READ] = sgx_ocall_read,
  549. [OCALL_WRITE] = sgx_ocall_write,
  550. [OCALL_PREAD] = sgx_ocall_pread,
  551. [OCALL_PWRITE] = sgx_ocall_pwrite,
  552. [OCALL_FSTAT] = sgx_ocall_fstat,
  553. [OCALL_FIONREAD] = sgx_ocall_fionread,
  554. [OCALL_FSETNONBLOCK] = sgx_ocall_fsetnonblock,
  555. [OCALL_FCHMOD] = sgx_ocall_fchmod,
  556. [OCALL_FSYNC] = sgx_ocall_fsync,
  557. [OCALL_FTRUNCATE] = sgx_ocall_ftruncate,
  558. [OCALL_MKDIR] = sgx_ocall_mkdir,
  559. [OCALL_GETDENTS] = sgx_ocall_getdents,
  560. [OCALL_RESUME_THREAD] = sgx_ocall_resume_thread,
  561. [OCALL_CLONE_THREAD] = sgx_ocall_clone_thread,
  562. [OCALL_CREATE_PROCESS] = sgx_ocall_create_process,
  563. [OCALL_FUTEX] = sgx_ocall_futex,
  564. [OCALL_SOCKETPAIR] = sgx_ocall_socketpair,
  565. [OCALL_LISTEN] = sgx_ocall_listen,
  566. [OCALL_ACCEPT] = sgx_ocall_accept,
  567. [OCALL_CONNECT] = sgx_ocall_connect,
  568. [OCALL_RECV] = sgx_ocall_recv,
  569. [OCALL_SEND] = sgx_ocall_send,
  570. [OCALL_SETSOCKOPT] = sgx_ocall_setsockopt,
  571. [OCALL_SHUTDOWN] = sgx_ocall_shutdown,
  572. [OCALL_GETTIME] = sgx_ocall_gettime,
  573. [OCALL_SLEEP] = sgx_ocall_sleep,
  574. [OCALL_POLL] = sgx_ocall_poll,
  575. [OCALL_RENAME] = sgx_ocall_rename,
  576. [OCALL_DELETE] = sgx_ocall_delete,
  577. [OCALL_LOAD_DEBUG] = sgx_ocall_load_debug,
  578. [OCALL_GET_ATTESTATION] = sgx_ocall_get_attestation,
  579. [OCALL_EVENTFD] = sgx_ocall_eventfd,
  580. };
  581. #define EDEBUG(code, ms) do {} while (0)
  582. int ecall_enclave_start (char * args, size_t args_size, char * env, size_t env_size)
  583. {
  584. ms_ecall_enclave_start_t ms;
  585. ms.ms_args = args;
  586. ms.ms_args_size = args_size;
  587. ms.ms_env = env;
  588. ms.ms_env_size = env_size;
  589. ms.ms_sec_info = &pal_enclave.pal_sec;
  590. EDEBUG(ECALL_ENCLAVE_START, &ms);
  591. return sgx_ecall(ECALL_ENCLAVE_START, &ms);
  592. }
  593. int ecall_thread_start (void)
  594. {
  595. EDEBUG(ECALL_THREAD_START, NULL);
  596. return sgx_ecall(ECALL_THREAD_START, NULL);
  597. }
  598. int ecall_thread_reset(void) {
  599. EDEBUG(ECALL_THREAD_RESET, NULL);
  600. return sgx_ecall(ECALL_THREAD_RESET, NULL);
  601. }
  602. noreturn void __abort(void) {
  603. INLINE_SYSCALL(exit_group, 1, -1);
  604. while (true) {
  605. /* nothing */;
  606. }
  607. }