aws-nitro-enclaves-cli icon indicating copy to clipboard operation
aws-nitro-enclaves-cli copied to clipboard

Nitro-cli console reports error after successful enclave exit

Open nshyrei opened this issue 3 years ago • 1 comments

I am trying to run an enclave in debug mode with attached console using nitro-cli console or nitro-cli run-enclave --attach-console. Every time my enclave exits I get this at the end:

[   60.505028] Unregister pv shared memory for cpu 1
[   60.506120] Unregister pv shared memory for cpu 0
[   60.507034] reboot: Restarting system
[   60.507642] reboot: machine restart
[ E45 ] Enclave console read error. Such error appears when reading from a running enclave's console fails.

For more details, please visit https://docs.aws.amazon.com/enclaves/latest/user/cli-errors.html#E45

If you open a support ticket, please provide the error log found at "/var/log/nitro_enclaves/err2022-08-25T13:18:36.623632872+00:00.log".

My enclave is a simple bash script that runs on Ubuntu and only does sleep before exiting, so I am pretty sure that enclave exits successfully. The error itself doesn't interfere with the application, but adds confusion for the user. Is this a proper behavior for the console or it could be fixed?

My Dockerfile and script look like this:

FROM ubuntu
COPY start.sh /
CMD ./start.sh

sleep 60s

nshyrei avatar Aug 25 '22 14:08 nshyrei

I don't see console read error now, but what happens is that the enclave won't exit and hangs with:

[   60.505028] Unregister pv shared memory for cpu 1
[   60.506120] Unregister pv shared memory for cpu 0
[   60.507034] reboot: Restarting system
[   60.507642] reboot: machine restart

nshyrei avatar Nov 17 '22 09:11 nshyrei