sgx_enclave.c 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735
  1. #include "ocall_types.h"
  2. #include "ecall_types.h"
  3. #include "sgx_internal.h"
  4. #include "pal_security.h"
  5. #include "pal_linux_error.h"
  6. #include <asm/mman.h>
  7. #include <asm/ioctls.h>
  8. #include <asm/socket.h>
  9. #include <linux/fs.h>
  10. #include <linux/in.h>
  11. #include <linux/in6.h>
  12. #include <math.h>
  13. #include <asm/errno.h>
  14. #ifndef SOL_IPV6
  15. # define SOL_IPV6 41
  16. #endif
  17. #define ODEBUG(code, ms) do {} while (0)
  18. static int sgx_ocall_exit(void* pms)
  19. {
  20. ms_ocall_exit_t * ms = (ms_ocall_exit_t *) pms;
  21. ODEBUG(OCALL_EXIT, NULL);
  22. if (ms->ms_exitcode != (int) ((uint8_t) ms->ms_exitcode)) {
  23. SGX_DBG(DBG_E, "Saturation error in exit code %d, getting rounded down to %u\n",
  24. ms->ms_exitcode, (uint8_t) ms->ms_exitcode);
  25. ms->ms_exitcode = 255;
  26. }
  27. if (ms->ms_is_exitgroup)
  28. INLINE_SYSCALL(exit_group, 1, (int)ms->ms_exitcode);
  29. else
  30. INLINE_SYSCALL(exit, 1, (int)ms->ms_exitcode);
  31. return 0;
  32. }
  33. static int sgx_ocall_print_string(void * pms)
  34. {
  35. ms_ocall_print_string_t * ms = (ms_ocall_print_string_t *) pms;
  36. INLINE_SYSCALL(write, 3, 2, ms->ms_str, ms->ms_length);
  37. return 0;
  38. }
  39. static int sgx_ocall_alloc_untrusted(void * pms)
  40. {
  41. ms_ocall_alloc_untrusted_t * ms = (ms_ocall_alloc_untrusted_t *) pms;
  42. void * addr;
  43. ODEBUG(OCALL_ALLOC_UNTRUSTED, ms);
  44. addr = (void *) INLINE_SYSCALL(mmap, 6, NULL, ms->ms_size,
  45. PROT_READ|PROT_WRITE,
  46. MAP_ANONYMOUS|MAP_PRIVATE, -1, 0);
  47. if (IS_ERR_P(addr))
  48. return -ERRNO_P(addr);
  49. ms->ms_mem = addr;
  50. return 0;
  51. }
  52. static int sgx_ocall_map_untrusted(void * pms)
  53. {
  54. ms_ocall_map_untrusted_t * ms = (ms_ocall_map_untrusted_t *) pms;
  55. void * addr;
  56. ODEBUG(OCALL_MAP_UNTRUSTED, ms);
  57. addr = (void *) INLINE_SYSCALL(mmap, 6, NULL, ms->ms_size,
  58. ms->ms_prot,
  59. MAP_FILE|MAP_SHARED,
  60. ms->ms_fd, ms->ms_offset);
  61. if (IS_ERR_P(addr))
  62. return -ERRNO_P(addr);
  63. ms->ms_mem = addr;
  64. return 0;
  65. }
  66. static int sgx_ocall_unmap_untrusted(void * pms)
  67. {
  68. ms_ocall_unmap_untrusted_t * ms = (ms_ocall_unmap_untrusted_t *) pms;
  69. ODEBUG(OCALL_UNMAP_UNTRUSTED, ms);
  70. INLINE_SYSCALL(munmap, 2, ALLOC_ALIGNDOWN(ms->ms_mem),
  71. ALLOC_ALIGNUP(ms->ms_mem + ms->ms_size) -
  72. ALLOC_ALIGNDOWN(ms->ms_mem));
  73. return 0;
  74. }
  75. static int sgx_ocall_cpuid(void * pms)
  76. {
  77. ms_ocall_cpuid_t * ms = (ms_ocall_cpuid_t *) pms;
  78. ODEBUG(OCALL_CPUID, ms);
  79. __asm__ volatile ("cpuid"
  80. : "=a"(ms->ms_values[0]),
  81. "=b"(ms->ms_values[1]),
  82. "=c"(ms->ms_values[2]),
  83. "=d"(ms->ms_values[3])
  84. : "a"(ms->ms_leaf), "c"(ms->ms_subleaf) : "memory");
  85. return 0;
  86. }
  87. static int sgx_ocall_open(void * pms)
  88. {
  89. ms_ocall_open_t * ms = (ms_ocall_open_t *) pms;
  90. int ret;
  91. ODEBUG(OCALL_OPEN, ms);
  92. ret = INLINE_SYSCALL(open, 3, ms->ms_pathname, ms->ms_flags|O_CLOEXEC,
  93. ms->ms_mode);
  94. return ret;
  95. }
  96. static int sgx_ocall_close(void * pms)
  97. {
  98. ms_ocall_close_t * ms = (ms_ocall_close_t *) pms;
  99. ODEBUG(OCALL_CLOSE, ms);
  100. INLINE_SYSCALL(close, 1, ms->ms_fd);
  101. return 0;
  102. }
  103. static int sgx_ocall_read(void * pms)
  104. {
  105. ms_ocall_read_t * ms = (ms_ocall_read_t *) pms;
  106. int ret;
  107. ODEBUG(OCALL_READ, ms);
  108. ret = INLINE_SYSCALL(read, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  109. return ret;
  110. }
  111. static int sgx_ocall_write(void * pms)
  112. {
  113. ms_ocall_write_t * ms = (ms_ocall_write_t *) pms;
  114. int ret;
  115. ODEBUG(OCALL_WRITE, ms);
  116. ret = INLINE_SYSCALL(write, 3, ms->ms_fd, ms->ms_buf, ms->ms_count);
  117. return ret;
  118. }
  119. static int sgx_ocall_fstat(void * pms)
  120. {
  121. ms_ocall_fstat_t * ms = (ms_ocall_fstat_t *) pms;
  122. int ret;
  123. ODEBUG(OCALL_FSTAT, ms);
  124. ret = INLINE_SYSCALL(fstat, 2, ms->ms_fd, &ms->ms_stat);
  125. return ret;
  126. }
  127. static int sgx_ocall_fionread(void * pms)
  128. {
  129. ms_ocall_fionread_t * ms = (ms_ocall_fionread_t *) pms;
  130. int ret, val;
  131. ODEBUG(OCALL_FIONREAD, ms);
  132. ret = INLINE_SYSCALL(ioctl, 3, ms->ms_fd, FIONREAD, &val);
  133. return IS_ERR(ret) ? ret : val;
  134. }
  135. static int sgx_ocall_fsetnonblock(void * pms)
  136. {
  137. ms_ocall_fsetnonblock_t * ms = (ms_ocall_fsetnonblock_t *) pms;
  138. int ret, flags;
  139. ODEBUG(OCALL_FSETNONBLOCK, ms);
  140. ret = INLINE_SYSCALL(fcntl, 2, ms->ms_fd, F_GETFL);
  141. if (IS_ERR(ret))
  142. return ret;
  143. flags = ret;
  144. if (ms->ms_nonblocking) {
  145. if (!(flags & O_NONBLOCK))
  146. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  147. flags | O_NONBLOCK);
  148. } else {
  149. if (flags & O_NONBLOCK)
  150. ret = INLINE_SYSCALL(fcntl, 3, ms->ms_fd, F_SETFL,
  151. flags & ~O_NONBLOCK);
  152. }
  153. return ret;
  154. }
  155. static int sgx_ocall_fchmod(void * pms)
  156. {
  157. ms_ocall_fchmod_t * ms = (ms_ocall_fchmod_t *) pms;
  158. int ret;
  159. ODEBUG(OCALL_FCHMOD, ms);
  160. ret = INLINE_SYSCALL(fchmod, 2, ms->ms_fd, ms->ms_mode);
  161. return ret;
  162. }
  163. static int sgx_ocall_fsync(void * pms)
  164. {
  165. ms_ocall_fsync_t * ms = (ms_ocall_fsync_t *) pms;
  166. ODEBUG(OCALL_FSYNC, ms);
  167. INLINE_SYSCALL(fsync, 1, ms->ms_fd);
  168. return 0;
  169. }
  170. static int sgx_ocall_ftruncate(void * pms)
  171. {
  172. ms_ocall_ftruncate_t * ms = (ms_ocall_ftruncate_t *) pms;
  173. int ret;
  174. ODEBUG(OCALL_FTRUNCATE, ms);
  175. ret = INLINE_SYSCALL(ftruncate, 2, ms->ms_fd, ms->ms_length);
  176. return ret;
  177. }
  178. static int sgx_ocall_mkdir(void * pms)
  179. {
  180. ms_ocall_mkdir_t * ms = (ms_ocall_mkdir_t *) pms;
  181. int ret;
  182. ODEBUG(OCALL_MKDIR, ms);
  183. ret = INLINE_SYSCALL(mkdir, 2, ms->ms_pathname, ms->ms_mode);
  184. return ret;
  185. }
  186. static int sgx_ocall_getdents(void * pms)
  187. {
  188. ms_ocall_getdents_t * ms = (ms_ocall_getdents_t *) pms;
  189. int ret;
  190. ODEBUG(OCALL_GETDENTS, ms);
  191. ret = INLINE_SYSCALL(getdents64, 3, ms->ms_fd, ms->ms_dirp, ms->ms_size);
  192. return ret;
  193. }
  194. static int sgx_ocall_wake_thread(void * pms)
  195. {
  196. ODEBUG(OCALL_WAKE_THREAD, pms);
  197. return pms ? interrupt_thread(pms) : clone_thread();
  198. }
  199. int sgx_create_process (const char * uri,
  200. int nargs, const char ** args,
  201. int * retfds);
  202. static int sgx_ocall_create_process(void * pms)
  203. {
  204. ms_ocall_create_process_t * ms = (ms_ocall_create_process_t *) pms;
  205. ODEBUG(OCALL_CREATE_PROCESS, ms);
  206. int ret = sgx_create_process(ms->ms_uri, ms->ms_nargs, ms->ms_args,
  207. ms->ms_proc_fds);
  208. if (IS_ERR(ret))
  209. return ret;
  210. ms->ms_pid = ret;
  211. return 0;
  212. }
  213. static int sgx_ocall_futex(void * pms)
  214. {
  215. ms_ocall_futex_t * ms = (ms_ocall_futex_t *) pms;
  216. int ret;
  217. ODEBUG(OCALL_FUTEX, ms);
  218. struct timespec * ts = NULL;
  219. if (ms->ms_timeout != OCALL_NO_TIMEOUT) {
  220. ts = __alloca(sizeof(struct timespec));
  221. ts->tv_sec = ms->ms_timeout / 1000000;
  222. ts->tv_nsec = (ms->ms_timeout - ts->tv_sec * 1000000) * 1000;
  223. }
  224. ret = INLINE_SYSCALL(futex, 6, ms->ms_futex, ms->ms_op, ms->ms_val,
  225. ts, NULL, 0);
  226. return ret;
  227. }
  228. static int sgx_ocall_socketpair(void * pms)
  229. {
  230. ms_ocall_socketpair_t * ms = (ms_ocall_socketpair_t *) pms;
  231. int ret;
  232. ODEBUG(OCALL_SOCKETPAIR, ms);
  233. ret = INLINE_SYSCALL(socketpair, 4, ms->ms_domain,
  234. ms->ms_type|SOCK_CLOEXEC,
  235. ms->ms_protocol, &ms->ms_sockfds);
  236. return ret;
  237. }
  238. static int sock_getopt(int fd, struct sockopt * opt)
  239. {
  240. SGX_DBG(DBG_M, "sock_getopt (fd = %d, sockopt addr = %p) is not implemented \
  241. always returns 0\n", fd, opt);
  242. /* initialize *opt with constant */
  243. *opt = (struct sockopt){0};
  244. opt->reuseaddr = 1;
  245. return 0;
  246. }
  247. static int sgx_ocall_sock_listen(void * pms)
  248. {
  249. ms_ocall_sock_listen_t * ms = (ms_ocall_sock_listen_t *) pms;
  250. int ret, fd;
  251. ODEBUG(OCALL_SOCK_LISTEN, ms);
  252. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  253. ms->ms_type|SOCK_CLOEXEC,
  254. ms->ms_protocol);
  255. if (IS_ERR(ret))
  256. goto err;
  257. fd = ret;
  258. if (ms->ms_addr->sa_family == AF_INET6) {
  259. int ipv6only = 1;
  260. INLINE_SYSCALL(setsockopt, 5, fd, SOL_IPV6, IPV6_V6ONLY, &ipv6only,
  261. sizeof(int));
  262. }
  263. /* must set the socket to be reuseable */
  264. int reuseaddr = 1;
  265. INLINE_SYSCALL(setsockopt, 5, fd, SOL_SOCKET, SO_REUSEADDR, &reuseaddr,
  266. sizeof(int));
  267. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_addr, ms->ms_addrlen);
  268. if (IS_ERR(ret))
  269. goto err_fd;
  270. if (ms->ms_addr) {
  271. socklen_t addrlen = ms->ms_addrlen;
  272. ret = INLINE_SYSCALL(getsockname, 3, fd, ms->ms_addr, &addrlen);
  273. if (IS_ERR(ret))
  274. goto err_fd;
  275. ms->ms_addrlen = addrlen;
  276. }
  277. if (ms->ms_type & SOCK_STREAM) {
  278. ret = INLINE_SYSCALL(listen, 2, fd, DEFAULT_BACKLOG);
  279. if (IS_ERR(ret))
  280. goto err_fd;
  281. }
  282. ret = sock_getopt(fd, &ms->ms_sockopt);
  283. if (IS_ERR(ret))
  284. goto err_fd;
  285. return fd;
  286. err_fd:
  287. INLINE_SYSCALL(close, 1, fd);
  288. err:
  289. return ret;
  290. }
  291. static int sgx_ocall_sock_accept(void * pms)
  292. {
  293. ms_ocall_sock_accept_t * ms = (ms_ocall_sock_accept_t *) pms;
  294. int ret, fd;
  295. ODEBUG(OCALL_SOCK_ACCEPT, ms);
  296. socklen_t addrlen = ms->ms_addrlen;
  297. ret = INLINE_SYSCALL(accept4, 4, ms->ms_sockfd, ms->ms_addr,
  298. &addrlen, O_CLOEXEC);
  299. if (IS_ERR(ret))
  300. goto err;
  301. fd = ret;
  302. ret = sock_getopt(fd, &ms->ms_sockopt);
  303. if (IS_ERR(ret))
  304. goto err_fd;
  305. ms->ms_addrlen = addrlen;
  306. return fd;
  307. err_fd:
  308. INLINE_SYSCALL(close, 1, fd);
  309. err:
  310. return ret;
  311. }
  312. static int sgx_ocall_sock_connect(void * pms)
  313. {
  314. ms_ocall_sock_connect_t * ms = (ms_ocall_sock_connect_t *) pms;
  315. int ret, fd;
  316. ODEBUG(OCALL_SOCK_CONNECT, ms);
  317. ret = INLINE_SYSCALL(socket, 3, ms->ms_domain,
  318. ms->ms_type|SOCK_CLOEXEC,
  319. ms->ms_protocol);
  320. if (IS_ERR(ret))
  321. goto err;
  322. fd = ret;
  323. if (ms->ms_addr && ms->ms_addr->sa_family == AF_INET6) {
  324. int ipv6only = 1;
  325. INLINE_SYSCALL(setsockopt, 5, fd, SOL_IPV6, IPV6_V6ONLY, &ipv6only,
  326. sizeof(int));
  327. }
  328. if (ms->ms_bind_addr && ms->ms_bind_addr->sa_family) {
  329. ret = INLINE_SYSCALL(bind, 3, fd, ms->ms_bind_addr,
  330. ms->ms_bind_addrlen);
  331. if (IS_ERR(ret))
  332. goto err_fd;
  333. }
  334. if (ms->ms_addr) {
  335. ret = INLINE_SYSCALL(connect, 3, fd, ms->ms_addr, ms->ms_addrlen);
  336. if (IS_ERR(ret) && ERRNO(ret) == EINPROGRESS) {
  337. do {
  338. struct pollfd pfd = { .fd = fd, .events = POLLOUT, .revents = 0, };
  339. ret = INLINE_SYSCALL(ppoll, 4, &pfd, 1, NULL, NULL);
  340. } while (IS_ERR(ret) &&
  341. ERRNO(ret) == -EWOULDBLOCK);
  342. }
  343. if (IS_ERR(ret))
  344. goto err_fd;
  345. }
  346. if (ms->ms_bind_addr && !ms->ms_bind_addr->sa_family) {
  347. socklen_t addrlen = ms->ms_bind_addrlen;
  348. ret = INLINE_SYSCALL(getsockname, 3, fd, ms->ms_bind_addr,
  349. &addrlen);
  350. if (IS_ERR(ret))
  351. goto err_fd;
  352. ms->ms_bind_addrlen = addrlen;
  353. }
  354. ret = sock_getopt(fd, &ms->ms_sockopt);
  355. if (IS_ERR(ret))
  356. goto err_fd;
  357. return fd;
  358. err_fd:
  359. INLINE_SYSCALL(close, 1, fd);
  360. err:
  361. return ret;
  362. }
  363. static int sgx_ocall_sock_recv(void * pms)
  364. {
  365. ms_ocall_sock_recv_t * ms = (ms_ocall_sock_recv_t *) pms;
  366. int ret;
  367. ODEBUG(OCALL_SOCK_RECV, ms);
  368. struct sockaddr * addr = ms->ms_addr;
  369. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  370. if (ms->ms_sockfd == PAL_SEC()->mcast_srv)
  371. addr = NULL;
  372. ret = INLINE_SYSCALL(recvfrom, 6,
  373. ms->ms_sockfd, ms->ms_buf, ms->ms_count, 0,
  374. addr, addr ? &addrlen : NULL);
  375. if (!IS_ERR(ret) && addr)
  376. ms->ms_addrlen = addrlen;
  377. return ret;
  378. }
  379. static int sgx_ocall_sock_send(void * pms)
  380. {
  381. ms_ocall_sock_send_t * ms = (ms_ocall_sock_send_t *) pms;
  382. int ret;
  383. ODEBUG(OCALL_SOCK_SEND, ms);
  384. const struct sockaddr * addr = ms->ms_addr;
  385. socklen_t addrlen = ms->ms_addr ? ms->ms_addrlen : 0;
  386. struct sockaddr_in mcast_addr;
  387. if (ms->ms_sockfd == PAL_SEC()->mcast_srv) {
  388. mcast_addr.sin_family = AF_INET;
  389. inet_pton4(MCAST_GROUP, sizeof(MCAST_GROUP), &mcast_addr.sin_addr.s_addr);
  390. mcast_addr.sin_port = htons(PAL_SEC()->mcast_port);
  391. addr = (struct sockaddr *) &mcast_addr;
  392. addrlen = sizeof(struct sockaddr_in);
  393. }
  394. ret = INLINE_SYSCALL(sendto, 6,
  395. ms->ms_sockfd, ms->ms_buf, ms->ms_count, MSG_NOSIGNAL,
  396. addr, addrlen);
  397. return ret;
  398. }
  399. static int sgx_ocall_sock_recv_fd(void * pms)
  400. {
  401. ms_ocall_sock_recv_fd_t * ms = (ms_ocall_sock_recv_fd_t *) pms;
  402. int ret;
  403. ODEBUG(OCALL_SOCK_RECV_FD, ms);
  404. struct msghdr hdr;
  405. struct iovec iov[1];
  406. // receive PAL_HANDLE contents in the body
  407. char cbuf[sizeof(struct cmsghdr) + ms->ms_nfds * sizeof(int)];
  408. iov[0].iov_base = ms->ms_buf;
  409. iov[0].iov_len = ms->ms_count;
  410. // clear body memory
  411. memset(&hdr, 0, sizeof(struct msghdr));
  412. // set message header values
  413. hdr.msg_iov = iov;
  414. hdr.msg_iovlen = 1;
  415. hdr.msg_control = cbuf;
  416. hdr.msg_controllen = sizeof(struct cmsghdr) + sizeof(int) *
  417. ms->ms_nfds;
  418. hdr.msg_flags = 0;
  419. ret = INLINE_SYSCALL(recvmsg, 3, ms->ms_sockfd, &hdr, 0);
  420. if (!IS_ERR(ret)) {
  421. struct cmsghdr * chdr = CMSG_FIRSTHDR(&hdr);
  422. if (chdr &&
  423. chdr->cmsg_type == SCM_RIGHTS) {
  424. ms->ms_nfds = (chdr->cmsg_len - sizeof(struct cmsghdr)) /
  425. sizeof(int);
  426. memcpy(ms->ms_fds, CMSG_DATA(chdr), sizeof(int) * ms->ms_nfds);
  427. } else {
  428. ms->ms_nfds = 0;
  429. }
  430. }
  431. return ret;
  432. }
  433. static int sgx_ocall_sock_send_fd(void * pms)
  434. {
  435. ms_ocall_sock_send_fd_t * ms = (ms_ocall_sock_send_fd_t *) pms;
  436. int ret;
  437. ODEBUG(OCALL_SOCK_SEND_FD, ms);
  438. // Declare variables required for sending the message
  439. struct msghdr hdr; // message header
  440. struct cmsghdr * chdr; //control message header
  441. struct iovec iov[1]; // IO Vector
  442. /* Message Body Composition:
  443. IOVEC[0]: PAL_HANDLE
  444. IOVEC[1..n]: Additional handle member follow
  445. Control Message: file descriptors */
  446. // Control message buffer with added space for 2 fds (ie. max size
  447. // that it will have)
  448. char cbuf[sizeof(struct cmsghdr) + ms->ms_nfds * sizeof(int)];
  449. iov[0].iov_base = (void *) ms->ms_buf;
  450. iov[0].iov_len = ms->ms_count;
  451. hdr.msg_name = NULL;
  452. hdr.msg_namelen = 0;
  453. hdr.msg_iov = iov;
  454. hdr.msg_iovlen = 1;
  455. hdr.msg_flags = 0;
  456. hdr.msg_control = cbuf; // Control Message Buffer
  457. hdr.msg_controllen = sizeof(struct cmsghdr) + sizeof(int) * ms->ms_nfds;
  458. // Fill control message infomation for the file descriptors
  459. // Check hdr.msg_controllen >= sizeof(struct cmsghdr) to point to
  460. // cbuf, which is redundant based on the above code as we have
  461. // statically allocated memory.
  462. // or (struct cmsghdr*) cbuf
  463. chdr = CMSG_FIRSTHDR(&hdr); // Pointer to msg_control
  464. chdr->cmsg_level = SOL_SOCKET; // Originating Protocol
  465. chdr->cmsg_type = SCM_RIGHTS; // Protocol Specific Type
  466. // Length of control message = sizeof(struct cmsghdr) + nfds
  467. chdr->cmsg_len = CMSG_LEN(sizeof(int) * ms->ms_nfds);
  468. // Copy the fds below control header
  469. memcpy(CMSG_DATA(chdr), ms->ms_fds, sizeof(int) * ms->ms_nfds);
  470. // Also, Update main header with control message length (duplicate)
  471. hdr.msg_controllen = chdr->cmsg_len;
  472. ret = INLINE_SYSCALL(sendmsg, 3, ms->ms_sockfd, &hdr, MSG_NOSIGNAL);
  473. return ret;
  474. }
  475. static int sgx_ocall_sock_setopt(void * pms)
  476. {
  477. ms_ocall_sock_setopt_t * ms = (ms_ocall_sock_setopt_t *) pms;
  478. int ret;
  479. ODEBUG(OCALL_SOCK_SETOPT, ms);
  480. ret = INLINE_SYSCALL(setsockopt, 5,
  481. ms->ms_sockfd, ms->ms_level, ms->ms_optname,
  482. ms->ms_optval, ms->ms_optlen);
  483. return ret;
  484. }
  485. static int sgx_ocall_sock_shutdown(void * pms)
  486. {
  487. ms_ocall_sock_shutdown_t * ms = (ms_ocall_sock_shutdown_t *) pms;
  488. ODEBUG(OCALL_SOCK_SHUTDOWN, ms);
  489. INLINE_SYSCALL(shutdown, 2, ms->ms_sockfd, ms->ms_how);
  490. return 0;
  491. }
  492. static int sgx_ocall_gettime(void * pms)
  493. {
  494. ms_ocall_gettime_t * ms = (ms_ocall_gettime_t *) pms;
  495. ODEBUG(OCALL_GETTIME, ms);
  496. struct timeval tv;
  497. INLINE_SYSCALL(gettimeofday, 2, &tv, NULL);
  498. ms->ms_microsec = tv.tv_sec * 1000000UL + tv.tv_usec;
  499. return 0;
  500. }
  501. static int sgx_ocall_sleep(void * pms)
  502. {
  503. ms_ocall_sleep_t * ms = (ms_ocall_sleep_t *) pms;
  504. int ret;
  505. ODEBUG(OCALL_SLEEP, ms);
  506. if (!ms->ms_microsec) {
  507. INLINE_SYSCALL(sched_yield, 0);
  508. return 0;
  509. }
  510. struct timespec req, rem;
  511. unsigned long microsec = ms->ms_microsec;
  512. const unsigned long VERY_LONG_TIME_IN_US = 1000000L * 60 * 60 * 24 * 365 * 128;
  513. if (ms->ms_microsec > VERY_LONG_TIME_IN_US) {
  514. /* avoid overflow with time_t */
  515. req.tv_sec = VERY_LONG_TIME_IN_US / 1000000;
  516. req.tv_nsec = 0;
  517. } else {
  518. req.tv_sec = ms->ms_microsec / 1000000;
  519. req.tv_nsec = (microsec - req.tv_sec * 1000000) * 1000;
  520. }
  521. ret = INLINE_SYSCALL(nanosleep, 2, &req, &rem);
  522. if (IS_ERR(ret) && ERRNO(ret) == EINTR)
  523. ms->ms_microsec = rem.tv_sec * 1000000UL + rem.tv_nsec / 1000UL;
  524. return ret;
  525. }
  526. static int sgx_ocall_poll(void * pms)
  527. {
  528. ms_ocall_poll_t * ms = (ms_ocall_poll_t *) pms;
  529. int ret;
  530. ODEBUG(OCALL_POLL, ms);
  531. struct timespec * ts = NULL;
  532. if (ms->ms_timeout != OCALL_NO_TIMEOUT) {
  533. ts = __alloca(sizeof(struct timespec));
  534. ts->tv_sec = ms->ms_timeout / 1000000;
  535. ts->tv_nsec = (ms->ms_timeout - ts->tv_sec * 1000000) * 1000;
  536. }
  537. ret = INLINE_SYSCALL(ppoll, 4, ms->ms_fds, ms->ms_nfds, ts, NULL);
  538. return ret;
  539. }
  540. static int sgx_ocall_rename(void * pms)
  541. {
  542. ms_ocall_rename_t * ms = (ms_ocall_rename_t *) pms;
  543. int ret;
  544. ODEBUG(OCALL_RENAME, ms);
  545. ret = INLINE_SYSCALL(rename, 2, ms->ms_oldpath, ms->ms_newpath);
  546. return ret;
  547. }
  548. static int sgx_ocall_delete(void * pms)
  549. {
  550. ms_ocall_delete_t * ms = (ms_ocall_delete_t *) pms;
  551. int ret;
  552. ODEBUG(OCALL_DELETE, ms);
  553. ret = INLINE_SYSCALL(unlink, 1, ms->ms_pathname);
  554. if (IS_ERR(ret) && ERRNO(ret) == EISDIR)
  555. ret = INLINE_SYSCALL(rmdir, 1, ms->ms_pathname);
  556. return ret;
  557. }
  558. void load_gdb_command (const char * command);
  559. static int sgx_ocall_load_debug(void * pms)
  560. {
  561. const char * command = (const char *) pms;
  562. ODEBUG(OCALL_LOAD_DEBUG, (void *) command);
  563. load_gdb_command(command);
  564. return 0;
  565. }
  566. sgx_ocall_fn_t ocall_table[OCALL_NR] = {
  567. [OCALL_EXIT] = sgx_ocall_exit,
  568. [OCALL_PRINT_STRING] = sgx_ocall_print_string,
  569. [OCALL_ALLOC_UNTRUSTED] = sgx_ocall_alloc_untrusted,
  570. [OCALL_MAP_UNTRUSTED] = sgx_ocall_map_untrusted,
  571. [OCALL_UNMAP_UNTRUSTED] = sgx_ocall_unmap_untrusted,
  572. [OCALL_CPUID] = sgx_ocall_cpuid,
  573. [OCALL_OPEN] = sgx_ocall_open,
  574. [OCALL_CLOSE] = sgx_ocall_close,
  575. [OCALL_READ] = sgx_ocall_read,
  576. [OCALL_WRITE] = sgx_ocall_write,
  577. [OCALL_FSTAT] = sgx_ocall_fstat,
  578. [OCALL_FIONREAD] = sgx_ocall_fionread,
  579. [OCALL_FSETNONBLOCK] = sgx_ocall_fsetnonblock,
  580. [OCALL_FCHMOD] = sgx_ocall_fchmod,
  581. [OCALL_FSYNC] = sgx_ocall_fsync,
  582. [OCALL_FTRUNCATE] = sgx_ocall_ftruncate,
  583. [OCALL_MKDIR] = sgx_ocall_mkdir,
  584. [OCALL_GETDENTS] = sgx_ocall_getdents,
  585. [OCALL_WAKE_THREAD] = sgx_ocall_wake_thread,
  586. [OCALL_CREATE_PROCESS] = sgx_ocall_create_process,
  587. [OCALL_FUTEX] = sgx_ocall_futex,
  588. [OCALL_SOCKETPAIR] = sgx_ocall_socketpair,
  589. [OCALL_SOCK_LISTEN] = sgx_ocall_sock_listen,
  590. [OCALL_SOCK_ACCEPT] = sgx_ocall_sock_accept,
  591. [OCALL_SOCK_CONNECT] = sgx_ocall_sock_connect,
  592. [OCALL_SOCK_RECV] = sgx_ocall_sock_recv,
  593. [OCALL_SOCK_SEND] = sgx_ocall_sock_send,
  594. [OCALL_SOCK_RECV_FD] = sgx_ocall_sock_recv_fd,
  595. [OCALL_SOCK_SEND_FD] = sgx_ocall_sock_send_fd,
  596. [OCALL_SOCK_SETOPT] = sgx_ocall_sock_setopt,
  597. [OCALL_SOCK_SHUTDOWN] = sgx_ocall_sock_shutdown,
  598. [OCALL_GETTIME] = sgx_ocall_gettime,
  599. [OCALL_SLEEP] = sgx_ocall_sleep,
  600. [OCALL_POLL] = sgx_ocall_poll,
  601. [OCALL_RENAME] = sgx_ocall_rename,
  602. [OCALL_DELETE] = sgx_ocall_delete,
  603. [OCALL_LOAD_DEBUG] = sgx_ocall_load_debug,
  604. };
  605. #define EDEBUG(code, ms) do {} while (0)
  606. int ecall_enclave_start (char * args, size_t args_size, char * env, size_t env_size)
  607. {
  608. ms_ecall_enclave_start_t ms;
  609. ms.ms_args = args;
  610. ms.ms_args_size = args_size;
  611. ms.ms_env = env;
  612. ms.ms_env_size = env_size;
  613. ms.ms_sec_info = PAL_SEC();
  614. EDEBUG(ECALL_ENCLAVE_START, &ms);
  615. return sgx_ecall(ECALL_ENCLAVE_START, &ms);
  616. }
  617. int ecall_thread_start (void)
  618. {
  619. EDEBUG(ECALL_THREAD_START, NULL);
  620. return sgx_ecall(ECALL_THREAD_START, NULL);
  621. }
  622. noreturn void __abort(void) {
  623. INLINE_SYSCALL(exit_group, 1, -1);
  624. while (true) {
  625. /* nothing */;
  626. }
  627. }