Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp4057053yba; Wed, 17 Apr 2019 03:45:15 -0700 (PDT) X-Google-Smtp-Source: APXvYqxJDTufZINpSXSjeMQFtgOJ3Wwa0ixe3V2IhP4VhLzcMJwgVxxY6otKa+ZH+NKwX1e6KfDQ X-Received: by 2002:a62:6f02:: with SMTP id k2mr73045191pfc.136.1555497915660; Wed, 17 Apr 2019 03:45:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1555497915; cv=none; d=google.com; s=arc-20160816; b=ZPKm85YRsBStBOPoY2/memnkqpvZFdxCfdNt1oq0VtRWYU7OYsjrxV6XeybdZs4RvS mh7TjltxWsdrcD5hOBrcv/RkqoospO3s9ut8DIdLM9VY/LKtMpLlzsgnELkHlWeeawgT CYoITEKZ9RsRRSblr9Rdw7WTPG7L+3QyTcOGRckcOvoTD1EUQ8a9fwriMV1XYFW8szWI I5B9dOg9C+nGo+sxEq4tKrPKpqb+SjSgMjSlPRzMSU4DzPOZv894xdRTiMd7WKDVIZtK ozGyyuUwhw4n2FRTupGLmrjwZmTzsHcCZTo2GWEO9QZYDIyGil6XCx/9VymmXQ4ytP4V xQKQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=cdHJVQ8j+b05hCbcj4dxaWg34lb0DpLHZrRJhJiAa5w=; b=ZgN33D8EyUrHQ/Efnks/X3cflF5tA5HTBKgyAc3FH5MUN6mUhTBRzQKnM68Vj23Wjy pacBkeLZKCZwo9r6ZvEXrj2ozItjhke85q/kF0+CoCN5UZm3z9qRwYas2XPKSSvwvmFp JQnT1WyW10CpxuNinBr6ov1nNlGtzvyMMaznhgKT7idnuuKROBH/R++M8XzRlfyAN9Al tEHu8dRHD8W5vhwLbgzv/7Q2G/cJw1OgaCMR9BRyuGLOrqwrFQaYgLhlmmZyz+X11F/3 a6yfUuaQVBx96ParbfLbjJ8I64PKM1ggA1vOgzkITxj3CdsgmI6nkUw9hXWnAO6eYqWv J/wg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id bc4si40385390plb.246.2019.04.17.03.45.00; Wed, 17 Apr 2019 03:45:15 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732044AbfDQKnR (ORCPT + 99 others); Wed, 17 Apr 2019 06:43:17 -0400 Received: from mga04.intel.com ([192.55.52.120]:54717 "EHLO mga04.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731659AbfDQKnR (ORCPT ); Wed, 17 Apr 2019 06:43:17 -0400 X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga007.jf.intel.com ([10.7.209.58]) by fmsmga104.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 17 Apr 2019 03:43:16 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.60,361,1549958400"; d="scan'208";a="132120357" Received: from jsakkine-mobl1.tm.intel.com (HELO localhost) ([10.237.50.189]) by orsmga007.jf.intel.com with ESMTP; 17 Apr 2019 03:43:09 -0700 From: Jarkko Sakkinen To: linux-kernel@vger.kernel.org, x86@kernel.org, linux-sgx@vger.kernel.org Cc: akpm@linux-foundation.org, dave.hansen@intel.com, sean.j.christopherson@intel.com, nhorman@redhat.com, npmccallum@redhat.com, serge.ayoun@intel.com, shay.katz-zamir@intel.com, haitao.huang@intel.com, andriy.shevchenko@linux.intel.com, tglx@linutronix.de, kai.svahn@intel.com, bp@alien8.de, josh@joshtriplett.org, luto@kernel.org, kai.huang@intel.com, rientjes@google.com, Jarkko Sakkinen Subject: [PATCH v20 27/28] docs: x86/sgx: Document kernel internals Date: Wed, 17 Apr 2019 13:39:37 +0300 Message-Id: <20190417103938.7762-28-jarkko.sakkinen@linux.intel.com> X-Mailer: git-send-email 2.19.1 In-Reply-To: <20190417103938.7762-1-jarkko.sakkinen@linux.intel.com> References: <20190417103938.7762-1-jarkko.sakkinen@linux.intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Sean Christopherson Document some of the more tricky parts of the kernel implementation internals. Signed-off-by: Sean Christopherson Co-developed-by: Jarkko Sakkinen Signed-off-by: Jarkko Sakkinen --- Documentation/x86/sgx/2.Kernel-internals.rst | 56 ++++++++++++++++++++ Documentation/x86/sgx/index.rst | 1 + 2 files changed, 57 insertions(+) create mode 100644 Documentation/x86/sgx/2.Kernel-internals.rst diff --git a/Documentation/x86/sgx/2.Kernel-internals.rst b/Documentation/x86/sgx/2.Kernel-internals.rst new file mode 100644 index 000000000000..de359bf605ca --- /dev/null +++ b/Documentation/x86/sgx/2.Kernel-internals.rst @@ -0,0 +1,56 @@ +.. SPDX-License-Identifier: GPL-2.0 + +================ +Kernel Internals +================ + +CPU configuration +================= + +Because SGX has an ever evolving and expanding feature set, it's possible for +a BIOS or VMM to configure a system in such a way that not all CPUs are equal, +e.g. where Launch Control is only enabled on a subset of CPUs. Linux does +*not* support such a heterogeneous system configuration, nor does it even +attempt to play nice in the face of a misconfigured system. With the exception +of Launch Control's hash MSRs, which can vary per CPU, Linux assumes that all +CPUs have a configuration that is identical to the boot CPU. + +EPC oversubscription +==================== + +SGX allows to have larger enclaves than amount of available EPC by providing a +subset of leaf instruction for swapping EPC pages to the system memory. The +details of these instructions are discussed in the architecture document. Due +to the unique requirements for swapping EPC pages, and because EPC pages do not +have associated page structures, management of the EPC is not handled by the +standard memory subsystem. + +SGX directly handles swapping of EPC pages, including a thread to initiate the +reclaiming process and a rudimentary LRU mechanism. When the amount of free EPC +pages goes below a low watermark the swapping thread starts reclaiming pages. +The pages that have not been recently accessed (i.e. do not have the A bit set) +are selected as victim pages. Each enclave holds an shmem file as a backing +storage for reclaimed pages. + +Launch Control +============== + +The current kernel implementation supports only writable MSRs. The launch is +performed by setting the MSRs to the hash of the public key modulus of the +enclave signer and a token with the valid bit set to zero. Because kernel makes +ultimately all the launch decisions token are not needed for anything. We +don't need or have a launch enclave for generating them as the MSRs must always +be writable. + +Provisioning +============ + +The use of provisioning must be controlled because it allows to get access to +the provisioning keys to attest to a remote party that the software is running +inside a legit enclave. This could be used by a malware network to ensure that +its nodes are running inside legit enclaves. + +The driver introduces a special device file /dev/sgx/provision and a special +ioctl SGX_IOC_ENCLAVE_SET_ATTRIBUTE to accomplish this. A file descriptor +pointing to /dev/sgx/provision is passed to ioctl from which kernel authorizes +the PROVISION_KEY attribute to the enclave. diff --git a/Documentation/x86/sgx/index.rst b/Documentation/x86/sgx/index.rst index c5dfef62e612..5d660e83d984 100644 --- a/Documentation/x86/sgx/index.rst +++ b/Documentation/x86/sgx/index.rst @@ -14,3 +14,4 @@ potentially malicious. :maxdepth: 1 1.Architecture + 2.Kernel-internals -- 2.19.1