if (*enclave_fd < 0) {
rc = *enclave_fd; switch (errno) { case NE_ERR_NO_CPUS_AVAIL_IN_POOL: {
printf("Error in create VM, no CPUs available in the NE CPU pool\n");
break;
}
default:
printf("Error in create VM [%m]\n");
}
return rc;
}
return0;
}
/** *ne_poll_enclave_fd()-Threadfunctionforpollingtheenclavefd. *@data:Argumentprovidedforthepollingfunction. * *Context:Processcontext. *Return: **NULLonsuccess/failure.
*/ void *ne_poll_enclave_fd(void *data)
{ int enclave_fd = *(int *)data; struct pollfd fds[1] = {}; int i = 0; int rc = -EINVAL;
printf("Running from poll thread, enclave fd %d\n", enclave_fd);
for (i = 0; i < NE_DEFAULT_NR_MEM_REGIONS; i++)
enclave_memory_size += ne_user_mem_regions[i].memory_size;
rc = stat(enclave_image_path, &image_stat_buf); if (rc < 0) {
printf("Error in get image stat info [%m]\n");
return rc;
}
enclave_image_size = image_stat_buf.st_size;
if (enclave_memory_size < enclave_image_size) {
printf("The enclave memory is smaller than the enclave image size\n");
return -ENOMEM;
}
rc = ioctl(enclave_fd, NE_GET_IMAGE_LOAD_INFO, &image_load_info); if (rc < 0) { switch (errno) { case NE_ERR_NOT_IN_INIT_STATE: {
printf("Error in get image load info, enclave not in init state\n");
break;
}
case NE_ERR_INVALID_FLAG_VALUE: {
printf("Error in get image load info, provided invalid flag\n");
break;
}
default:
printf("Error in get image load info [%m]\n");
}
return rc;
}
printf("Enclave image offset in enclave memory is %lld\n",
image_load_info.memory_offset);
enclave_image_fd = open(enclave_image_path, O_RDONLY); if (enclave_image_fd < 0) {
printf("Error in open enclave image file [%m]\n");
return enclave_image_fd;
}
enclave_image = mmap(NULL, enclave_image_size, PROT_READ,
MAP_PRIVATE, enclave_image_fd, 0); if (enclave_image == MAP_FAILED) {
printf("Error in mmap enclave image [%m]\n");
rc = ioctl(enclave_fd, NE_SET_USER_MEMORY_REGION, &mem_region); if (rc < 0) { switch (errno) { case NE_ERR_NOT_IN_INIT_STATE: {
printf("Error in set user memory region, enclave not in init state\n");
break;
}
case NE_ERR_INVALID_MEM_REGION_SIZE: {
printf("Error in set user memory region, mem size not multiple of 2 MiB\n");
break;
}
case NE_ERR_INVALID_MEM_REGION_ADDR: {
printf("Error in set user memory region, invalid user space address\n");
break;
}
case NE_ERR_UNALIGNED_MEM_REGION_ADDR: {
printf("Error in set user memory region, unaligned user space address\n");
break;
}
case NE_ERR_MEM_REGION_ALREADY_USED: {
printf("Error in set user memory region, memory region already used\n");
break;
}
case NE_ERR_MEM_NOT_HUGE_PAGE: {
printf("Error in set user memory region, not backed by huge pages\n");
break;
}
case NE_ERR_MEM_DIFFERENT_NUMA_NODE: {
printf("Error in set user memory region, different NUMA node than CPUs\n");
break;
}
case NE_ERR_MEM_MAX_REGIONS: {
printf("Error in set user memory region, max memory regions reached\n");
break;
}
case NE_ERR_INVALID_PAGE_SIZE: {
printf("Error in set user memory region, has page not multiple of 2 MiB\n");
break;
}
case NE_ERR_INVALID_FLAG_VALUE: {
printf("Error in set user memory region, provided invalid flag\n");
break;
}
default:
printf("Error in set user memory region [%m]\n");
}
rc = ioctl(enclave_fd, NE_ADD_VCPU, vcpu_id); if (rc < 0) { switch (errno) { case NE_ERR_NO_CPUS_AVAIL_IN_POOL: {
printf("Error in add vcpu, no CPUs available in the NE CPU pool\n");
break;
}
case NE_ERR_VCPU_ALREADY_USED: {
printf("Error in add vcpu, the provided vCPU is already used\n");
break;
}
case NE_ERR_VCPU_NOT_IN_CPU_POOL: {
printf("Error in add vcpu, the provided vCPU is not in the NE CPU pool\n");
break;
}
case NE_ERR_VCPU_INVALID_CPU_CORE: {
printf("Error in add vcpu, the core id of the provided vCPU is invalid\n");
break;
}
case NE_ERR_NOT_IN_INIT_STATE: {
printf("Error in add vcpu, enclave not in init state\n");
break;
}
case NE_ERR_INVALID_VCPU: {
printf("Error in add vcpu, the provided vCPU is out of avail CPUs range\n");
rc = ioctl(enclave_fd, NE_START_ENCLAVE, enclave_start_info); if (rc < 0) { switch (errno) { case NE_ERR_NOT_IN_INIT_STATE: {
printf("Error in start enclave, enclave not in init state\n");
break;
}
case NE_ERR_NO_MEM_REGIONS_ADDED: {
printf("Error in start enclave, no memory regions have been added\n");
break;
}
case NE_ERR_NO_VCPUS_ADDED: {
printf("Error in start enclave, no vCPUs have been added\n");
break;
}
case NE_ERR_FULL_CORES_NOT_USED: {
printf("Error in start enclave, enclave has no full cores set\n");
break;
}
case NE_ERR_ENCLAVE_MEM_MIN_SIZE: {
printf("Error in start enclave, enclave memory is less than min size\n");
break;
}
case NE_ERR_INVALID_FLAG_VALUE: {
printf("Error in start enclave, provided invalid flag\n");
break;
}
case NE_ERR_INVALID_ENCLAVE_CID: {
printf("Error in start enclave, provided invalid enclave CID\n");
break;
}
default:
printf("Error in start enclave [%m]\n");
}
for (i = 0; i < NE_DEFAULT_NR_MEM_REGIONS; i++) {
rc = ne_set_user_mem_region(enclave_fd, ne_user_mem_regions[i]); if (rc < 0) {
printf("Error in set memory region, iter %d\n", i);
goto release_enclave_fd;
}
}
printf("Enclave memory regions were added\n");
for (i = 0; i < NE_DEFAULT_NR_VCPUS; i++) { /* *ThevCPUischosenfromtheenclavevCPUpool,ifthevalue *ofthevcpu_idis0.
*/
ne_vcpus[i] = 0;
rc = ne_add_vcpu(enclave_fd, &ne_vcpus[i]); if (rc < 0) {
printf("Error in add vcpu, iter %d\n", i);
goto release_enclave_fd;
}
printf("Added vCPU %d to the enclave\n", ne_vcpus[i]);
}
printf("Enclave vCPUs were added\n");
rc = ne_start_enclave_check_booted(enclave_fd); if (rc < 0) {
printf("Error in the enclave start / image loading heartbeat logic [rc=%d]\n", rc);
goto release_enclave_fd;
}
printf("Entering sleep for %d seconds ...\n", NE_SLEEP_TIME);
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.