-
Notifications
You must be signed in to change notification settings - Fork 153
Description
Is there an existing issue for this?
- I have searched the existing issues
Code of Conduct
- I agree to follow this project's Code of Conduct
Current Behaviour
I am running Ubuntu 20.04.5 LTS (GNU/Linux 6.0.0-rc1 x86_64) inside a QEMU (7.1.0) virtual machine. SGX hardware and driver are available. Linux kernel selftests all work. Enarx platform info shows that SGX is available. Enarx works with backend nil or kvm but fails with backend=sgx.
For example enarx run target/wasm32-wasi/release/hello.wasm returns following:
Error: Failed to create SGX enclave
Caused by:
I/O error (os error 5)
Now strace gives more hints, strace enarx run --backend=sgx target/wasm32-wasi/release/hello.wasm outputs:
execve("/usr/bin/enarx", ["enarx", "run", "--backend=sgx", "target/wasm32-wasi/release/hello"...], 0x7fff9537c4f8 /* 33 vars */) = 0
mmap(NULL, 1264, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f0132599000
arch_prctl(ARCH_SET_FS, 0x7f0132599410) = 0
set_tid_address(0x7f01323c7198) = 10341
poll([{fd=0, events=0}, {fd=1, events=0}, {fd=2, events=0}], 3, 0) = 0 (Timeout)
rt_sigaction(SIGPIPE, {sa_handler=SIG_IGN, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f013144c8c3}, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGSEGV, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigprocmask(SIG_UNBLOCK, [RT_1 RT_2], NULL, 8) = 0
rt_sigaction(SIGSEGV, {sa_handler=0x7f01311c0d20, sa_mask=[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_SIGINFO, sa_restorer=0x7f013144c8c3}, NULL, 8) = 0
rt_sigaction(SIGBUS, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGBUS, {sa_handler=0x7f01311c0d20, sa_mask=[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_SIGINFO, sa_restorer=0x7f013144c8c3}, NULL, 8) = 0
sigaltstack(NULL, {ss_sp=NULL, ss_flags=SS_DISABLE, ss_size=0}) = 0
mmap(NULL, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS|MAP_STACK, -1, 0) = 0x7f0132596000
mprotect(0x7f0132596000, 4096, PROT_NONE) = 0
sigaltstack({ss_sp=0x7f0132597000, ss_flags=0, ss_size=8192}, NULL) = 0
brk(NULL) = 0x555556ae7000
brk(0x555556ae8000) = 0x555556ae8000
rt_sigprocmask(SIG_BLOCK, ~[RTMIN RT_1 RT_2], [], 8) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
getrandom("\x96\x7c\x24\x60\x15\xe0\x91\x80\x96\x9d\xe2\x42\xcf\x0b\xca\x37", 16, 0x4 /* GRND_??? */) = 16
brk(0x555556aea000) = 0x555556aea000
brk(0x555556aec000) = 0x555556aec000
brk(0x555556aed000) = 0x555556aed000
brk(0x555556aef000) = 0x555556aef000
brk(0x555556af0000) = 0x555556af0000
brk(0x555556af1000) = 0x555556af1000
brk(0x555556af2000) = 0x555556af2000
brk(0x555556af3000) = 0x555556af3000
brk(0x555556af4000) = 0x555556af4000
brk(0x555556af5000) = 0x555556af5000
brk(0x555556af6000) = 0x555556af6000
brk(0x555556af7000) = 0x555556af7000
brk(0x555556af9000) = 0x555556af9000
brk(0x555556afa000) = 0x555556afa000
brk(0x555556afb000) = 0x555556afb000
brk(0x555556afc000) = 0x555556afc000
brk(0x555556afd000) = 0x555556afd000
brk(0x555556afe000) = 0x555556afe000
brk(0x555556aff000) = 0x555556aff000
brk(0x555556b00000) = 0x555556b00000
brk(0x555556b02000) = 0x555556b02000
brk(0x555556b03000) = 0x555556b03000
brk(0x555556b04000) = 0x555556b04000
brk(0x555556b05000) = 0x555556b05000
brk(0x555556b07000) = 0x555556b07000
brk(0x555556b08000) = 0x555556b08000
brk(0x555556b09000) = 0x555556b09000
brk(0x555556b0a000) = 0x555556b0a000
brk(0x555556b0b000) = 0x555556b0b000
brk(0x555556b0c000) = 0x555556b0c000
brk(0x555556b0d000) = 0x555556b0d000
brk(0x555556b0e000) = 0x555556b0e000
brk(0x555556b0f000) = 0x555556b0f000
brk(0x555556b10000) = 0x555556b10000
brk(0x555556b12000) = 0x555556b12000
brk(0x555556b14000) = 0x555556b14000
brk(0x555556b15000) = 0x555556b15000
brk(0x555556b16000) = 0x555556b16000
brk(0x555556b17000) = 0x555556b17000
brk(0x555556b1a000) = 0x555556b1a000
brk(0x555556b1c000) = 0x555556b1c000
brk(0x555556b1e000) = 0x555556b1e000
brk(0x555556b20000) = 0x555556b20000
brk(0x555556b21000) = 0x555556b21000
brk(0x555556b22000) = 0x555556b22000
brk(0x555556b23000) = 0x555556b23000
open("/dev/sgx_enclave", O_RDONLY|O_CLOEXEC) = 3
fcntl(3, F_SETFD, FD_CLOEXEC) = 0
close(3) = 0
stat("/var/run/aesmd/aesm.socket", {st_mode=S_IFSOCK|0777, st_size=0, ...}) = 0
stat("/usr/lib/enarx/enarx.sig", {st_mode=S_IFREG|0444, st_size=15210, ...}) = 0
open("/usr/lib/enarx/enarx.sig", O_RDONLY|O_CLOEXEC) = 3
fcntl(3, F_SETFD, FD_CLOEXEC) = 0
fstat(3, {st_mode=S_IFREG|0444, st_size=15210, ...}) = 0
lseek(3, 0, SEEK_CUR) = 0
read(3, "{\"version\":\"0.6.4\",\"sev\":{\"id_bl"..., 15210) = 15210
read(3, "", 32) = 0
close(3) = 0
socketpair(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC, 0, [3, 4]) = 0
open("target/wasm32-wasi/release/hello.wasm", O_RDONLY|O_CLOEXEC) = 5
fcntl(5, F_SETFD, FD_CLOEXEC) = 0
ioctl(4, FIONBIO, [1]) = 0
setsockopt(4, SOL_SOCKET, SO_SNDTIMEO_OLD, "<\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 16) = 0
rt_sigprocmask(SIG_UNBLOCK, [RT_1 RT_2], NULL, 8) = 0
mmap(NULL, 2109440, PROT_NONE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f01307fd000
mprotect(0x7f01307ff000, 2101248, PROT_READ|PROT_WRITE) = 0
rt_sigprocmask(SIG_BLOCK, ~[RTMIN RT_1 RT_2], [], 8) = 0
clone(child_stack=0x7f01309ff6e8, flags=CLONE_VM|CLONE_FS|CLONE_FILES|CLONE_SIGHAND|CLONE_THREAD|CLONE_SYSVSEM|CLONE_SETTLS|CLONE_PARENT_SETTID|CLONE_CHILD_CLEARTID|0x400000, parent_tid=[10342], tls=0x7f01309ffb20, child_tidptr=0x7f01323c7198) = 10342
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
mmap(NULL, 397312, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f0132535000
mmap(NULL, 8589934592, PROT_NONE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7eff307fd000
munmap(0x7eff307fd000, 3481284608) = 0
munmap(0x7f0100000000, 813682688) = 0
open("/dev/sgx_enclave", O_RDWR|O_CLOEXEC) = 4
fcntl(4, F_SETFD, FD_CLOEXEC) = 0
ioctl(4, _IOC(_IOC_WRITE, 0xa4, 0, 0x8), 0x7fffa7ce23c0) = -1 EIO (Input/output error)
close(4) = 0
munmap(0x7f0000000000, 4294967296) = 0
munmap(0x7f0132535000, 397312) = 0
munmap(0x7f01307fd000, 2109440) = 0
close(3) = 0
write(2, "Error: ", 7Error: ) = 7
write(2, "Failed to create SGX enclave", 28Failed to create SGX enclave) = 28
write(2, "\n\nCaused by:", 12
Caused by:) = 12
write(2, "\n", 1
) = 1
write(2, " ", 4 ) = 4
write(2, "I/O error", 9I/O error) = 9
write(2, " (os error ", 11 (os error ) = 11
write(2, "5", 15) = 1
write(2, ")", 1)) = 1
write(2, "\n", 1
) = 1
sigaltstack({ss_sp=NULL, ss_flags=SS_DISABLE, ss_size=8192}, NULL) = 0
munmap(0x7f0132596000, 12288) = 0
exit_group(1) = ?
+++ exited with 1 +++
Expected Behaviour
I expect execution to work by default (or explicitly selecting backend=sgx). Now sgx executions are failing with an error message.
Environment Information
Host machine:
Fedora 36.
5.17.13-300.fc36.x86_64 kernel.
Kernel selftests on linux/tools/testing/selftests/sgx works.
Output from cd ./linux/tools/testing/selftests/sgx/ && make && ./test_sgx eventually shows:
[...]
ok 16 # SKIP Kernel does not support SGX_IOC_ENCLAVE_MODIFY_TYPES ioctl()
# PASSED: 16 / 16 tests passed.
# Totals: pass:6 fail:0 xfail:0 xpass:0 skip:10 error:0
CPU supports SGX2, see cat /proc/cpuinfo output:
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 106
model name : Intel(R) Xeon(R) Silver 4314 CPU @ 2.40GHz
stepping : 6
microcode : 0xd000363
cpu MHz : 800.000
cache size : 24576 KB
physical id : 0
siblings : 32
core id : 0
cpu cores : 16
apicid : 0
initial apicid : 0
fpu : yes
fpu_exception : yes
cpuid level : 27
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb rdtscp lm constant_tsc art arch_perfmon pebs bts rep_good nopl xtopology nonstop_tsc cpuid aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2 ssse3 sdbg fma cx16 xtpr pdcm pcid dca sse4_1 sse4_2 x2apic movbe popcnt tsc_deadline_timer aes xsave avx f16c rdrand lahf_lm abm 3dnowprefetch cpuid_fault epb cat_l3 invpcid_single intel_ppin ssbd mba ibrs ibpb stibp ibrs_enhanced tpr_shadow vnmi flexpriority ept vpid ept_ad fsgsbase tsc_adjust sgx bmi1 avx2 smep bmi2 erms invpcid cqm rdt_a avx512f avx512dq rdseed adx smap avx512ifma clflushopt clwb intel_pt avx512cd sha_ni avx512bw avx512vl xsaveopt xsavec xgetbv1 xsaves cqm_llc cqm_occup_llc cqm_mbm_total cqm_mbm_local split_lock_detect wbnoinvd dtherm ida arat pln pts avx512vbmi umip pku ospke avx512_vbmi2 gfni vaes vpclmulqdq avx512_vnni avx512_bitalg tme avx512_vpopcntdq la57 rdpid sgx_lc fsrm md_clear pconfig flush_l1d arch_capabilities
vmx flags : vnmi preemption_timer posted_intr invvpid ept_x_only ept_ad ept_1gb flexpriority apicv tsc_offset vtpr mtf vapic ept vpid unrestricted_guest vapic_reg vid ple shadow_vmcs pml ept_mode_based_exec tsc_scaling
bugs : spectre_v1 spectre_v2 spec_store_bypass swapgs
bogomips : 4800.00
clflush size : 64
cache_alignment : 64
address sizes : 46 bits physical, 57 bits virtual
power management:
Virtualmachine (Under qemu-x86_64 version 7.1.0):
Ubuntu 20.04.5 LTS (GNU/Linux 6.0.0-rc1 x86_64).
exec qemu-system-x86_64 -enable-kvm -m 4096 -m 4096 -cpu host,+sgx-provisionkey -object memory-backend-epc,id=mem1,size=64M,prealloc=on -M sgx-epc.0.memdev=mem1,sgx-epc.0.node=0 -net user,hostfwd=tcp::20022-:22 -net nic silver-ubuntu20.04.qcow2
Kernel selftests on linux/tools/testing/selftests/sgx: 16 / 16 tests passed.
Command enarx platform info shows:
System Info: Linux 6.0.0-rc1 #1 SMP PREEMPT_DYNAMIC Sun Sep 18 16:58:03 EEST 2022 x86_64
✔ Backend: sgx
✔ Driver: /dev/sgx_enclave
✔ CPU: Intel(R) Xeon(R) Silver 4314 CPU @ 2.40GHz | GenuineIntel
✔ SGX Support
✔ Version 1
✔ Version 2
✔ FLC Support
✔ Max Size (32-bit): 2 GiB
✔ Max Size (64-bit): 64 PiB
✔ MiscSelect: EXINFO
✔ Features: DEBUG | MODE64BIT | PROVISIONING_KEY | EINIT_KEY | KSS
✔ Xfrm: X87 | SSE
✔ EPC Size: 64 MiB
✔ AESM Daemon Socket: /var/run/aesmd/aesm.socket
CPU info:
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 106
model name : Intel(R) Xeon(R) Silver 4314 CPU @ 2.40GHz
stepping : 6
microcode : 0xd000363
cpu MHz : 2399.998
cache size : 16384 KB
physical id : 0
siblings : 1
core id : 0
cpu cores : 1
apicid : 0
initial apicid : 0
fpu : yes
fpu_exception : yes
cpuid level : 27
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ss syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon rep_good nopl xtopology cpuid tsc_known_freq pni pclmulqdq vmx ssse3 fma cx16 pdcm pcid sse4_1 sse4_2 x2apic movbe popcnt tsc_deadline_timer aes xsave avx f16c rdrand hypervisor lahf_lm abm 3dnowprefetch cpuid_fault invpcid_single ssbd ibrs ibpb stibp ibrs_enhanced tpr_shadow vnmi flexpriority ept vpid ept_ad fsgsbase tsc_adjust sgx bmi1 avx2 smep bmi2 erms invpcid avx512f avx512dq rdseed adx smap avx512ifma clflushopt clwb avx512cd sha_ni avx512bw avx512vl xsaveopt xsavec xgetbv1 xsaves wbnoinvd arat avx512vbmi umip pku ospke avx512_vbmi2 gfni vaes vpclmulqdq avx512_vnni avx512_bitalg avx512_vpopcntdq la57 rdpid sgx_lc fsrm md_clear arch_capabilities
vmx flags : vnmi preemption_timer posted_intr invvpid ept_x_only ept_ad ept_1gb flexpriority apicv tsc_offset vtpr mtf vapic ept vpid unrestricted_guest vapic_reg vid shadow_vmcs pml tsc_scaling
bugs : spectre_v1 spectre_v2 spec_store_bypass swapgs taa mmio_stale_data eibrs_pbrsb
bogomips : 4799.99
clflush size : 64
cache_alignment : 64
address sizes : 46 bits physical, 57 bits virtual
power management:
Steps To Reproduce
- Launch the virtual machine under QEMU.
- Test Linux kernel SGX selftests: 16/16 passed.
- Check that enarx platform info shows SGX available.
- Try to run any application with Enarx and with sgx.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status