You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

传递字符数组至函数获取更新值:sgx_unseal_data调用失败排查

Fixing SGX Unseal Failure When Passing Buffer Externally

Let's break down what's going wrong with your modified get_alpha() function and how to fix it step by step:

Key Issues in Your Current Implementation

  1. Incorrect handling of sgx_unseal_data's length parameter
    The p_decrypted_text_length parameter is an in/out argument: you pass the total size of your buffer first, and SGX updates it to the actual length of the decrypted data after success. Your code uses uint64_t instead of the required uint32_t, and doesn't properly validate if the buffer size is sufficient.

  2. Type mismatch in output formatting
    Using %llu (for unsigned long long) to print a single char triggers undefined behavior. Even if unsealing succeeds, this will give you garbage output that makes you think the operation failed.

  3. Missing error checks for OCalls
    You don't verify if ocall_get_textsize or ocall_load_file succeeded. If the sealed file isn't read correctly, sealed_data will contain garbage, guaranteeing an unseal failure.

  4. Uninitialized buffer
    The external resecret buffer isn't cleared before use, so you might see leftover garbage even if unsealing works.

Fixed get_alpha() Function

int get_alpha(char* resecret) {
    std::string sealed_alpha_file = "/home/roshan/thesis/osn_server/sealed_alpha";
    long fsize;

    // Check if we can get the sealed file size
    if (ocall_get_textsize(sealed_alpha_file.c_str(), &fsize, 0) != 0) {
        mbedtls_printf("Enclave: Failed to retrieve sealed file size\n");
        return -1;
    }

    unsigned char sealed_data[fsize];
    size_t ocall_return;

    // Verify we read the entire sealed file
    if (ocall_load_file(&ocall_return, sealed_alpha_file.c_str(), fsize, sealed_data, 0) != 0 || ocall_return != fsize) {
        mbedtls_printf("Enclave: Failed to load sealed file (read %zu of %ld bytes)\n", ocall_return, fsize);
        return -1;
    }

    // Initialize buffer size (use uint32_t to match sgx_unseal_data's signature)
    uint32_t resecret_size = 12; // Your buffer is 12 bytes
    sgx_status_t ret = sgx_unseal_data(
        (sgx_sealed_data_t*)sealed_data,
        NULL, // No additional MAC text
        NULL,
        (uint8_t*)resecret,
        &resecret_size
    );

    if(ret != SGX_SUCCESS) {
        mbedtls_printf("Enclave: Unsealing failed with error %#x\n", ret);
        return -1;
    }

    mbedtls_printf("Enclave: Unsealing succeeded! Decrypted %u bytes\n", resecret_size);
    return 0;
}

Fixed Calling Code

char resecret[12];
// Clear the buffer to avoid garbage data
memset(resecret, 0, sizeof(resecret));

if (get_alpha(resecret) != 0) {
    mbedtls_printf("Enclave: Failed to retrieve alpha\n");
    return -1;
}

// Use the correct format based on your data type:
// If resecret is a string:
mbedtls_printf("Enclave: Unsealed alpha string: %s\n", resecret);
// If resecret is a multi-byte numeric value (e.g., 12-byte integer):
// uint64_t high_bits = *(uint64_t*)resecret;
// uint32_t low_bits = *(uint32_t*)(resecret + 8);
// mbedtls_printf("Enclave: Unsealed alpha value: %llu%u\n", high_bits, low_bits);

Additional Troubleshooting Tips

  • If you still get SGX_ERROR_MAC_MISMATCH, verify the sealed data was created with the same Enclave attributes (MRENCLAVE/MRSIGNER) as your current Enclave. Sealed data is tied to the Enclave that created it (unless you used a sealing key policy that allows other Enclaves).
  • Check that the sealed file hasn't been corrupted—compare the file size with what ocall_get_textsize returns.

内容的提问来源于stack exchange,提问作者Kumar Roshan Mehta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 04:16:11