Skip to content

foreshadow: restore the 0x00 retry and bound transient_access - #111

Open
patapik wants to merge 1 commit into
jovanbulck:masterfrom
patapik:foreshadow-zero-byte-fixes
Open

patapik wants to merge 1 commit into
jovanbulck:masterfrom
patapik:foreshadow-zero-byte-fixes

Conversation

@patapik

@patapik patapik commented Sep 21, 2026

Copy link
Copy Markdown

Hello,

While reproducing app/foreshadow we ran into two small things on the zero-byte path. Both are local changes. Happy to rework either of them if you would rather handle this differently.

foreshadow() retry. The for that is meant to remeasure 0x00 / 0xff has a semicolon after the header, so foreshadow_round() runs once. The increment clause still runs, so fs_zero_retries increases even though no additional measurement happens. Removing the semicolon makes the loop do what the comment above it describes.

transient_access retry. jz retry has no bound. If the byte stays zero after the fault handler has made the page present again, that loop spins in user space. We saw this in an enclave-free harness that restores the mapping the same way app/foreshadow does. We did not see it in the stock enclave build. The patch caps the loop at 64. A non-zero byte still leaves on the first success. A real zero falls through with rax == 0 (oracle slot 0), which callers already treat as no hit.

Tested on an i3-6100, kernel 7.1.5, microcode 0xba, with NO_SGX=1 for the enclave-free harness.

Thanks for the framework. It is what made the reproduction possible.

The zero-byte retry loop had a semicolon after the for header, so
foreshadow_round() ran once while the counter still incremented.
transient_access retried an all-zero result without a bound.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant