传递字符数组至函数获取更新值:sgx_unseal_data调用失败排查
Let's break down what's going wrong with your modified get_alpha() function and how to fix it step by step:
Key Issues in Your Current Implementation
Incorrect handling of
sgx_unseal_data's length parameter
Thep_decrypted_text_lengthparameter is an in/out argument: you pass the total size of your buffer first, and SGX updates it to the actual length of the decrypted data after success. Your code usesuint64_tinstead of the requireduint32_t, and doesn't properly validate if the buffer size is sufficient.Type mismatch in output formatting
Using%llu(forunsigned long long) to print a singlechartriggers undefined behavior. Even if unsealing succeeds, this will give you garbage output that makes you think the operation failed.Missing error checks for OCalls
You don't verify ifocall_get_textsizeorocall_load_filesucceeded. If the sealed file isn't read correctly,sealed_datawill contain garbage, guaranteeing an unseal failure.Uninitialized buffer
The externalresecretbuffer isn't cleared before use, so you might see leftover garbage even if unsealing works.
Fixed get_alpha() Function
int get_alpha(char* resecret) { std::string sealed_alpha_file = "/home/roshan/thesis/osn_server/sealed_alpha"; long fsize; // Check if we can get the sealed file size if (ocall_get_textsize(sealed_alpha_file.c_str(), &fsize, 0) != 0) { mbedtls_printf("Enclave: Failed to retrieve sealed file size\n"); return -1; } unsigned char sealed_data[fsize]; size_t ocall_return; // Verify we read the entire sealed file if (ocall_load_file(&ocall_return, sealed_alpha_file.c_str(), fsize, sealed_data, 0) != 0 || ocall_return != fsize) { mbedtls_printf("Enclave: Failed to load sealed file (read %zu of %ld bytes)\n", ocall_return, fsize); return -1; } // Initialize buffer size (use uint32_t to match sgx_unseal_data's signature) uint32_t resecret_size = 12; // Your buffer is 12 bytes sgx_status_t ret = sgx_unseal_data( (sgx_sealed_data_t*)sealed_data, NULL, // No additional MAC text NULL, (uint8_t*)resecret, &resecret_size ); if(ret != SGX_SUCCESS) { mbedtls_printf("Enclave: Unsealing failed with error %#x\n", ret); return -1; } mbedtls_printf("Enclave: Unsealing succeeded! Decrypted %u bytes\n", resecret_size); return 0; }
Fixed Calling Code
char resecret[12]; // Clear the buffer to avoid garbage data memset(resecret, 0, sizeof(resecret)); if (get_alpha(resecret) != 0) { mbedtls_printf("Enclave: Failed to retrieve alpha\n"); return -1; } // Use the correct format based on your data type: // If resecret is a string: mbedtls_printf("Enclave: Unsealed alpha string: %s\n", resecret); // If resecret is a multi-byte numeric value (e.g., 12-byte integer): // uint64_t high_bits = *(uint64_t*)resecret; // uint32_t low_bits = *(uint32_t*)(resecret + 8); // mbedtls_printf("Enclave: Unsealed alpha value: %llu%u\n", high_bits, low_bits);
Additional Troubleshooting Tips
- If you still get
SGX_ERROR_MAC_MISMATCH, verify the sealed data was created with the same Enclave attributes (MRENCLAVE/MRSIGNER) as your current Enclave. Sealed data is tied to the Enclave that created it (unless you used a sealing key policy that allows other Enclaves). - Check that the sealed file hasn't been corrupted—compare the file size with what
ocall_get_textsizereturns.
内容的提问来源于stack exchange,提问作者Kumar Roshan Mehta

