Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file modified litebox_runner_optee_on_linux_userland/tests/aes-ta.elf
Binary file not shown.
63 changes: 1 addition & 62 deletions litebox_shim_optee/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ use litebox::{
shim::ContinueOperation,
utils::TruncateExt,
};
use litebox_common_linux::{MapFlags, ProtFlags, errno::Errno, vmap::GlobalVmapManager};
use litebox_common_linux::{errno::Errno, vmap::GlobalVmapManager};
use litebox_common_optee::{
LdelfArg, LdelfSyscallRequest, SyscallRequest, TaFlags, TeeAlgorithm, TeeAlgorithmClass,
TeeAttributeType, TeeCrypStateHandle, TeeHandleFlag, TeeIdentity, TeeLogin, TeeObjHandle,
Expand Down Expand Up @@ -269,8 +269,6 @@ impl OpteeShim {
ta_entry_point: Cell::new(0),
ta_stack_base_addr: Cell::new(0),
ta_prepared: Cell::new(false),
#[cfg(target_arch = "x86_64")]
tls_base_addr: Cell::new(0),
},
};
if let Some(ta_bin) = ta_bin
Expand Down Expand Up @@ -795,15 +793,9 @@ impl Task {
let ta_entry_point = self.get_ta_entry_point();
let mut elf_loader = loader::elf::ElfLoader::new(self, &ta_bin, false)?;
elf_loader.load_ta_trampoline(ta_entry_point)?;
self.allocate_guest_tls(None).map_err(|_| {
ElfLoaderError::MappingError(litebox::mm::linux::MappingError::OutOfMemory)
})?;
self.ta_prepared.set(true);
}

#[cfg(target_arch = "x86_64")]
self.restore_guest_tls();

let mut ta_stack =
crate::loader::ta_stack::allocate_stack(self, self.get_ta_stack_base_addr()).ok_or(
ElfLoaderError::MappingError(litebox::mm::linux::MappingError::OutOfMemory),
Expand Down Expand Up @@ -851,54 +843,6 @@ impl Task {
}
}

/// Allocate the guest TLS for an OP-TEE TA.
///
/// This function is required to overcome the compatibility issue coming from
/// system and build toolchain differences. OP-TEE OS only supports a single thread and
/// thus does not explicitly set up the TLS area. In contrast, we do use an x86 toolchain to
/// compile OP-TEE TAs and this toolchain assumes there is a valid TLS areas for various purposes
/// including stack protection. To this end, the toolchain generates binaries using
/// the `FS` register for TLS access.
/// This function allocates a TLS area on behalf of the TA to satisfy the toolchain's assumption.
/// Instead of using this function, we could change the flags of the toolchain to not use TLS
/// (e.g., `-fno-stack-protector`), but this might be insecure. Also, the toolchain might have
/// other features relying on TLS.
#[cfg(target_arch = "x86_64")]
fn allocate_guest_tls(
&self,
tls_size: Option<usize>,
) -> Result<(), litebox_common_linux::errno::Errno> {
let tls_size = tls_size.unwrap_or(PAGE_SIZE).next_multiple_of(PAGE_SIZE);
let addr = self.sys_mmap(
0,
tls_size,
ProtFlags::PROT_READ | ProtFlags::PROT_WRITE,
MapFlags::MAP_PRIVATE | MapFlags::MAP_ANONYMOUS,
-1,
0,
)?;
// Store TLS address for later restoration
self.tls_base_addr.set(addr.as_usize());
self.restore_guest_tls();
Ok(())
}

/// Restore the guest TLS (FS base) before entering the TA.
///
/// FS base is cleared across VTL switches, so we must restore it before
/// every TA entry.
#[cfg(target_arch = "x86_64")]
fn restore_guest_tls(&self) {
use litebox::platform::ArchSpecificProvider as _;
let addr = self.tls_base_addr.get();
if addr == 0 {
return; // TLS not allocated yet
}
litebox_platform_multiplex::platform()
.set_arch_specific_register(&litebox::platform::ArchSpecificRegister::FsBase, addr)
.expect("requires guaranteed platform support for FsBase");
}

/// Retrieve the result of the `ldelf` execution.
fn get_ldelf_result(&self) {
let ldelf_arg_address = match self.thread.init_state.get() {
Expand Down Expand Up @@ -1387,9 +1331,6 @@ struct Task {
ta_stack_base_addr: Cell<usize>,
/// Whether the TA has been prepared
ta_prepared: Cell<bool>,
/// TLS base address for x86_64 (stored to restore FS before each TA entry)
#[cfg(target_arch = "x86_64")]
tls_base_addr: Cell<usize>,
// TODO: OP-TEE supports global, persistent objects across sessions. Add these maps if needed.
}

Expand Down Expand Up @@ -1554,8 +1495,6 @@ mod test_utils {
ta_entry_point: Cell::new(0),
ta_stack_base_addr: Cell::new(0),
ta_prepared: Cell::new(false),
#[cfg(target_arch = "x86_64")]
tls_base_addr: Cell::new(0),
}
}
}
Expand Down
Loading