2001-01-10 01:32:29 +00:00
|
|
|
/* -*- Mode: C++; tab-width: 2; indent-tabs-mode: nil; c-basic-offset: 2 -*-
|
|
|
|
*
|
2004-04-25 15:03:26 +00:00
|
|
|
* ***** BEGIN LICENSE BLOCK *****
|
|
|
|
* Version: MPL 1.1/GPL 2.0/LGPL 2.1
|
2001-01-10 01:32:29 +00:00
|
|
|
*
|
2004-04-25 15:03:26 +00:00
|
|
|
* The contents of this file are subject to the Mozilla Public License Version
|
|
|
|
* 1.1 (the "License"); you may not use this file except in compliance with
|
|
|
|
* the License. You may obtain a copy of the License at
|
|
|
|
* http://www.mozilla.org/MPL/
|
|
|
|
*
|
|
|
|
* Software distributed under the License is distributed on an "AS IS" basis,
|
|
|
|
* WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
|
|
|
|
* for the specific language governing rights and limitations under the
|
|
|
|
* License.
|
2001-01-10 01:32:29 +00:00
|
|
|
*
|
|
|
|
* The Original Code is mozilla.org code.
|
|
|
|
*
|
2004-04-25 15:03:26 +00:00
|
|
|
* The Initial Developer of the Original Code is
|
|
|
|
* Netscape Communications Corporation.
|
|
|
|
* Portions created by the Initial Developer are Copyright (C) 1998
|
|
|
|
* the Initial Developer. All Rights Reserved.
|
2001-01-10 01:32:29 +00:00
|
|
|
*
|
|
|
|
* Contributor(s):
|
2004-04-25 15:03:26 +00:00
|
|
|
* Brian Ryner <bryner@brianryner.com>
|
2006-04-04 13:14:40 +00:00
|
|
|
* Kai Engert <kengert@redhat.com>
|
2004-04-25 15:03:26 +00:00
|
|
|
*
|
|
|
|
* Alternatively, the contents of this file may be used under the terms of
|
|
|
|
* either the GNU General Public License Version 2 or later (the "GPL"), or
|
|
|
|
* the GNU Lesser General Public License Version 2.1 or later (the "LGPL"),
|
|
|
|
* in which case the provisions of the GPL or the LGPL are applicable instead
|
|
|
|
* of those above. If you wish to allow use of your version of this file only
|
|
|
|
* under the terms of either the GPL or the LGPL, and not to allow others to
|
|
|
|
* use your version of this file under the terms of the MPL, indicate your
|
|
|
|
* decision by deleting the provisions above and replace them with the notice
|
|
|
|
* and other provisions required by the GPL or the LGPL. If you do not delete
|
|
|
|
* the provisions above, a recipient may use your version of this file under
|
|
|
|
* the terms of any one of the MPL, the GPL or the LGPL.
|
|
|
|
*
|
|
|
|
* ***** END LICENSE BLOCK ***** */
|
2001-01-10 01:32:29 +00:00
|
|
|
|
|
|
|
#ifndef _NSNSSIOLAYER_H
|
|
|
|
#define _NSNSSIOLAYER_H
|
|
|
|
|
|
|
|
#include "prtypes.h"
|
|
|
|
#include "prio.h"
|
2001-09-06 20:20:50 +00:00
|
|
|
#include "certt.h"
|
2001-01-30 02:12:53 +00:00
|
|
|
#include "nsString.h"
|
2001-01-31 18:03:49 +00:00
|
|
|
#include "nsIInterfaceRequestor.h"
|
2001-09-05 21:27:22 +00:00
|
|
|
#include "nsIInterfaceRequestorUtils.h"
|
2001-03-06 05:10:33 +00:00
|
|
|
#include "nsITransportSecurityInfo.h"
|
2001-01-19 01:12:10 +00:00
|
|
|
#include "nsISSLSocketControl.h"
|
2007-11-30 18:05:54 +00:00
|
|
|
#include "nsSSLStatus.h"
|
2001-11-29 23:36:34 +00:00
|
|
|
#include "nsISSLStatusProvider.h"
|
2007-08-23 21:28:15 +00:00
|
|
|
#include "nsIIdentityInfo.h"
|
2008-04-12 04:47:22 +00:00
|
|
|
#include "nsIAssociatedContentSecurity.h"
|
2001-06-08 00:50:32 +00:00
|
|
|
#include "nsXPIDLString.h"
|
2003-01-18 14:03:00 +00:00
|
|
|
#include "nsNSSShutDown.h"
|
2007-08-23 21:28:15 +00:00
|
|
|
#include "nsAutoPtr.h"
|
|
|
|
#include "nsNSSCertificate.h"
|
2009-05-20 08:23:41 +00:00
|
|
|
#include "nsDataHashtable.h"
|
2001-01-30 02:12:53 +00:00
|
|
|
|
|
|
|
class nsIChannel;
|
2006-04-04 13:14:40 +00:00
|
|
|
class nsSSLThread;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* This class is used to store SSL socket I/O state information,
|
|
|
|
* that is not being executed directly, but defered to
|
|
|
|
* the separate SSL thread.
|
|
|
|
*/
|
|
|
|
class nsSSLSocketThreadData
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
nsSSLSocketThreadData();
|
|
|
|
~nsSSLSocketThreadData();
|
|
|
|
|
|
|
|
PRBool ensure_buffer_size(PRInt32 amount);
|
|
|
|
|
|
|
|
enum ssl_state {
|
2008-02-13 16:14:25 +00:00
|
|
|
ssl_invalid, // used for initializating, should never occur
|
2006-04-04 13:14:40 +00:00
|
|
|
ssl_idle, // not in use by SSL thread, no activity pending
|
|
|
|
ssl_pending_write, // waiting for SSL thread to complete writing
|
|
|
|
ssl_pending_read, // waiting for SSL thread to complete reading
|
|
|
|
ssl_writing_done, // SSL write completed, results are ready
|
|
|
|
ssl_reading_done // SSL read completed, results are ready
|
|
|
|
};
|
|
|
|
|
|
|
|
ssl_state mSSLState;
|
|
|
|
|
|
|
|
// Used to transport I/O error codes between SSL thread
|
|
|
|
// and initial caller thread.
|
|
|
|
PRErrorCode mPRErrorCode;
|
|
|
|
|
|
|
|
// A buffer used to transfer I/O data between threads
|
|
|
|
char *mSSLDataBuffer;
|
|
|
|
PRInt32 mSSLDataBufferAllocatedSize;
|
|
|
|
|
|
|
|
// The amount requested to read or write by the caller.
|
|
|
|
PRInt32 mSSLRequestedTransferAmount;
|
|
|
|
|
|
|
|
// A pointer into our buffer, to the first byte
|
|
|
|
// that has not yet been delivered to the caller.
|
|
|
|
// Necessary, as the caller of the read function
|
|
|
|
// might request smaller chunks.
|
|
|
|
const char *mSSLRemainingReadResultData;
|
|
|
|
|
|
|
|
// The caller previously requested to read or write.
|
|
|
|
// As the initial request to read or write is defered,
|
|
|
|
// the caller might (in theory) request smaller chunks
|
|
|
|
// in subsequent calls.
|
|
|
|
// This variable stores the amount of bytes successfully
|
|
|
|
// transfered, that have not yet been reported to the caller.
|
|
|
|
PRInt32 mSSLResultRemainingBytes;
|
|
|
|
|
|
|
|
// When defering SSL read/write activity to another thread,
|
|
|
|
// we switch the SSL level file descriptor of the original
|
|
|
|
// layered file descriptor to a pollable event,
|
|
|
|
// so we can wake up the original caller of the I/O function
|
|
|
|
// as soon as data is ready.
|
|
|
|
// This variable is used to save the SSL level file descriptor,
|
|
|
|
// to allow us to restore the original file descriptor layering.
|
|
|
|
PRFileDesc *mReplacedSSLFileDesc;
|
2007-06-10 23:42:28 +00:00
|
|
|
|
|
|
|
PRBool mOneBytePendingFromEarlierWrite;
|
|
|
|
unsigned char mThePendingByte;
|
|
|
|
PRInt32 mOriginalRequestedTransferAmount;
|
2006-04-04 13:14:40 +00:00
|
|
|
};
|
2001-01-19 01:12:10 +00:00
|
|
|
|
2001-03-06 05:10:33 +00:00
|
|
|
class nsNSSSocketInfo : public nsITransportSecurityInfo,
|
2001-01-31 18:03:49 +00:00
|
|
|
public nsISSLSocketControl,
|
2001-05-03 00:36:48 +00:00
|
|
|
public nsIInterfaceRequestor,
|
2003-01-18 14:03:00 +00:00
|
|
|
public nsISSLStatusProvider,
|
2007-08-23 21:28:15 +00:00
|
|
|
public nsIIdentityInfo,
|
2008-04-12 04:47:22 +00:00
|
|
|
public nsIAssociatedContentSecurity,
|
2007-11-30 18:05:54 +00:00
|
|
|
public nsISerializable,
|
|
|
|
public nsIClassInfo,
|
2003-01-18 14:03:00 +00:00
|
|
|
public nsNSSShutDownObject,
|
|
|
|
public nsOnPK11LogoutCancelObject
|
2001-01-19 01:12:10 +00:00
|
|
|
{
|
|
|
|
public:
|
|
|
|
nsNSSSocketInfo();
|
|
|
|
virtual ~nsNSSSocketInfo();
|
|
|
|
|
|
|
|
NS_DECL_ISUPPORTS
|
2001-03-06 05:10:33 +00:00
|
|
|
NS_DECL_NSITRANSPORTSECURITYINFO
|
2001-01-19 01:12:10 +00:00
|
|
|
NS_DECL_NSISSLSOCKETCONTROL
|
2001-01-31 18:03:49 +00:00
|
|
|
NS_DECL_NSIINTERFACEREQUESTOR
|
2001-05-03 00:36:48 +00:00
|
|
|
NS_DECL_NSISSLSTATUSPROVIDER
|
2007-08-23 21:28:15 +00:00
|
|
|
NS_DECL_NSIIDENTITYINFO
|
2008-04-12 04:47:22 +00:00
|
|
|
NS_DECL_NSIASSOCIATEDCONTENTSECURITY
|
2007-11-30 18:05:54 +00:00
|
|
|
NS_DECL_NSISERIALIZABLE
|
|
|
|
NS_DECL_NSICLASSINFO
|
2001-01-19 01:12:10 +00:00
|
|
|
|
2002-05-16 20:57:37 +00:00
|
|
|
nsresult SetSecurityState(PRUint32 aState);
|
2001-01-19 01:12:10 +00:00
|
|
|
nsresult SetShortSecurityDescription(const PRUnichar *aText);
|
2007-02-17 03:47:59 +00:00
|
|
|
nsresult SetErrorMessage(const PRUnichar *aText);
|
2001-01-19 01:12:10 +00:00
|
|
|
|
2002-08-14 23:43:28 +00:00
|
|
|
nsresult SetForSTARTTLS(PRBool aForSTARTTLS);
|
|
|
|
nsresult GetForSTARTTLS(PRBool *aForSTARTTLS);
|
2001-02-05 21:46:24 +00:00
|
|
|
|
|
|
|
nsresult GetFileDescPtr(PRFileDesc** aFilePtr);
|
|
|
|
nsresult SetFileDescPtr(PRFileDesc* aFilePtr);
|
2001-06-08 00:50:32 +00:00
|
|
|
|
2002-10-16 22:20:42 +00:00
|
|
|
nsresult GetHandshakePending(PRBool *aHandshakePending);
|
|
|
|
nsresult SetHandshakePending(PRBool aHandshakePending);
|
2001-06-08 00:50:32 +00:00
|
|
|
|
|
|
|
nsresult GetHostName(char **aHostName);
|
|
|
|
nsresult SetHostName(const char *aHostName);
|
|
|
|
|
|
|
|
nsresult GetPort(PRInt32 *aPort);
|
|
|
|
nsresult SetPort(PRInt32 aPort);
|
|
|
|
|
2008-01-14 15:45:07 +00:00
|
|
|
nsresult GetCert(nsIX509Cert** _result);
|
|
|
|
nsresult SetCert(nsIX509Cert *aCert);
|
|
|
|
|
|
|
|
nsresult GetPreviousCert(nsIX509Cert** _result);
|
2007-08-23 21:28:15 +00:00
|
|
|
|
2002-08-14 23:43:28 +00:00
|
|
|
void SetCanceled(PRBool aCanceled);
|
|
|
|
PRBool GetCanceled();
|
|
|
|
|
|
|
|
void SetHasCleartextPhase(PRBool aHasCleartextPhase);
|
|
|
|
PRBool GetHasCleartextPhase();
|
2002-10-16 22:20:42 +00:00
|
|
|
|
2006-08-24 18:14:40 +00:00
|
|
|
void SetHandshakeInProgress(PRBool aIsIn);
|
2002-10-16 22:20:42 +00:00
|
|
|
PRBool GetHandshakeInProgress() { return mHandshakeInProgress; }
|
2006-08-24 18:14:40 +00:00
|
|
|
PRBool HandshakeTimeout();
|
2001-06-08 00:50:32 +00:00
|
|
|
|
2007-02-09 19:12:33 +00:00
|
|
|
void SetAllowTLSIntoleranceTimeout(PRBool aAllow);
|
2007-03-07 19:54:54 +00:00
|
|
|
|
2007-02-17 03:47:59 +00:00
|
|
|
nsresult GetExternalErrorReporting(PRBool* state);
|
|
|
|
nsresult SetExternalErrorReporting(PRBool aState);
|
|
|
|
|
2001-10-30 23:52:01 +00:00
|
|
|
nsresult RememberCAChain(CERTCertList *aCertList);
|
|
|
|
|
2001-05-03 00:36:48 +00:00
|
|
|
/* Set SSL Status values */
|
2007-11-30 18:05:54 +00:00
|
|
|
nsresult SetSSLStatus(nsSSLStatus *aSSLStatus);
|
|
|
|
nsSSLStatus* SSLStatus() { return mSSLStatus; }
|
2008-01-14 15:45:07 +00:00
|
|
|
PRBool hasCertErrors();
|
2006-04-04 13:14:40 +00:00
|
|
|
|
|
|
|
PRStatus CloseSocketAndDestroy();
|
|
|
|
|
2001-01-19 01:12:10 +00:00
|
|
|
protected:
|
2001-03-06 05:10:33 +00:00
|
|
|
nsCOMPtr<nsIInterfaceRequestor> mCallbacks;
|
2001-02-05 21:46:24 +00:00
|
|
|
PRFileDesc* mFd;
|
2008-01-14 15:45:07 +00:00
|
|
|
nsCOMPtr<nsIX509Cert> mCert;
|
2008-04-12 04:47:22 +00:00
|
|
|
nsCOMPtr<nsIX509Cert> mPreviousCert; // DocShellDependent
|
2007-02-15 02:46:25 +00:00
|
|
|
enum {
|
|
|
|
blocking_state_unknown, is_nonblocking_socket, is_blocking_socket
|
|
|
|
} mBlockingState;
|
2002-05-16 20:57:37 +00:00
|
|
|
PRUint32 mSecurityState;
|
2008-04-12 04:47:22 +00:00
|
|
|
PRInt32 mSubRequestsHighSecurity;
|
|
|
|
PRInt32 mSubRequestsLowSecurity;
|
|
|
|
PRInt32 mSubRequestsBrokenSecurity;
|
|
|
|
PRInt32 mSubRequestsNoSecurity;
|
2001-01-19 01:12:10 +00:00
|
|
|
nsString mShortDesc;
|
2007-02-17 03:47:59 +00:00
|
|
|
nsString mErrorMessage;
|
2008-04-12 04:47:22 +00:00
|
|
|
PRPackedBool mDocShellDependentStuffKnown;
|
|
|
|
PRPackedBool mExternalErrorReporting; // DocShellDependent
|
2002-08-14 23:43:28 +00:00
|
|
|
PRPackedBool mForSTARTTLS;
|
2002-10-16 22:20:42 +00:00
|
|
|
PRPackedBool mHandshakePending;
|
2002-08-14 23:43:28 +00:00
|
|
|
PRPackedBool mCanceled;
|
|
|
|
PRPackedBool mHasCleartextPhase;
|
2002-10-16 22:20:42 +00:00
|
|
|
PRPackedBool mHandshakeInProgress;
|
2007-02-09 19:12:33 +00:00
|
|
|
PRPackedBool mAllowTLSIntoleranceTimeout;
|
2006-08-24 18:14:40 +00:00
|
|
|
PRIntervalTime mHandshakeStartTime;
|
2001-07-24 00:42:52 +00:00
|
|
|
PRInt32 mPort;
|
2001-06-08 00:50:32 +00:00
|
|
|
nsXPIDLCString mHostName;
|
2001-05-03 00:36:48 +00:00
|
|
|
|
|
|
|
/* SSL Status */
|
2007-11-30 18:05:54 +00:00
|
|
|
nsRefPtr<nsSSLStatus> mSSLStatus;
|
2002-08-14 23:43:28 +00:00
|
|
|
|
|
|
|
nsresult ActivateSSL();
|
2006-04-04 13:14:40 +00:00
|
|
|
|
|
|
|
nsSSLSocketThreadData *mThreadData;
|
|
|
|
|
2008-04-12 04:47:22 +00:00
|
|
|
nsresult EnsureDocShellDependentStuffKnown();
|
|
|
|
|
2003-01-18 14:03:00 +00:00
|
|
|
private:
|
|
|
|
virtual void virtualDestroyNSSReference();
|
|
|
|
void destructorSafeDestroyNSSReference();
|
2006-04-04 13:14:40 +00:00
|
|
|
|
|
|
|
friend class nsSSLThread;
|
|
|
|
};
|
|
|
|
|
|
|
|
class nsCStringHashSet;
|
|
|
|
|
2009-05-20 08:23:41 +00:00
|
|
|
class nsSSLStatus;
|
|
|
|
class nsNSSSocketInfo;
|
|
|
|
|
|
|
|
class nsPSMRememberCertErrorsTable
|
|
|
|
{
|
|
|
|
private:
|
|
|
|
struct CertStateBits
|
|
|
|
{
|
|
|
|
PRBool mIsDomainMismatch;
|
|
|
|
PRBool mIsNotValidAtThisTime;
|
|
|
|
PRBool mIsUntrusted;
|
|
|
|
};
|
|
|
|
nsDataHashtableMT<nsCStringHashKey, CertStateBits> mErrorHosts;
|
|
|
|
nsresult GetHostPortKey(nsNSSSocketInfo* infoObject, nsCAutoString& result);
|
|
|
|
|
|
|
|
public:
|
|
|
|
friend class nsSSLIOLayerHelpers;
|
|
|
|
nsPSMRememberCertErrorsTable();
|
|
|
|
void RememberCertHasError(nsNSSSocketInfo* infoObject,
|
|
|
|
nsSSLStatus* status,
|
|
|
|
SECStatus certVerificationResult);
|
|
|
|
void LookupCertErrorBits(nsNSSSocketInfo* infoObject,
|
|
|
|
nsSSLStatus* status);
|
|
|
|
};
|
|
|
|
|
2006-04-04 13:14:40 +00:00
|
|
|
class nsSSLIOLayerHelpers
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
static nsresult Init();
|
|
|
|
static void Cleanup();
|
|
|
|
|
2009-02-28 14:06:40 +00:00
|
|
|
static PRBool nsSSLIOLayerInitialized;
|
2006-04-04 13:14:40 +00:00
|
|
|
static PRDescIdentity nsSSLIOLayerIdentity;
|
|
|
|
static PRIOMethods nsSSLIOLayerMethods;
|
|
|
|
|
|
|
|
static PRLock *mutex;
|
|
|
|
static nsCStringHashSet *mTLSIntolerantSites;
|
2009-05-20 08:23:41 +00:00
|
|
|
static nsPSMRememberCertErrorsTable* mHostsWithCertErrors;
|
2006-04-04 13:14:40 +00:00
|
|
|
|
|
|
|
static PRBool rememberPossibleTLSProblemSite(PRFileDesc* fd, nsNSSSocketInfo *socketInfo);
|
|
|
|
|
|
|
|
static void addIntolerantSite(const nsCString &str);
|
|
|
|
static PRBool isKnownAsIntolerantSite(const nsCString &str);
|
|
|
|
|
|
|
|
static PRFileDesc *mSharedPollableEvent;
|
|
|
|
static nsNSSSocketInfo *mSocketOwningPollableEvent;
|
|
|
|
|
|
|
|
static PRBool mPollableEventCurrentlySet;
|
2001-01-19 01:12:10 +00:00
|
|
|
};
|
2001-01-10 01:32:29 +00:00
|
|
|
|
2003-09-11 20:32:33 +00:00
|
|
|
nsresult nsSSLIOLayerNewSocket(PRInt32 family,
|
|
|
|
const char *host,
|
2001-01-10 01:32:29 +00:00
|
|
|
PRInt32 port,
|
|
|
|
const char *proxyHost,
|
|
|
|
PRInt32 proxyPort,
|
|
|
|
PRFileDesc **fd,
|
|
|
|
nsISupports **securityInfo,
|
2009-02-17 22:06:52 +00:00
|
|
|
PRBool forSTARTTLS,
|
|
|
|
PRBool anonymousLoad);
|
2001-01-10 01:32:29 +00:00
|
|
|
|
2003-09-11 20:32:33 +00:00
|
|
|
nsresult nsSSLIOLayerAddToSocket(PRInt32 family,
|
|
|
|
const char *host,
|
2001-01-10 01:32:29 +00:00
|
|
|
PRInt32 port,
|
|
|
|
const char *proxyHost,
|
|
|
|
PRInt32 proxyPort,
|
|
|
|
PRFileDesc *fd,
|
|
|
|
nsISupports **securityInfo,
|
2009-02-17 22:06:52 +00:00
|
|
|
PRBool forSTARTTLS,
|
|
|
|
PRBool anonymousLoad);
|
2001-07-24 00:42:52 +00:00
|
|
|
|
|
|
|
nsresult nsSSLIOLayerFreeTLSIntolerantSites();
|
2001-09-26 00:28:24 +00:00
|
|
|
nsresult displayUnknownCertErrorAlert(nsNSSSocketInfo *infoObject, int error);
|
2007-11-30 18:05:54 +00:00
|
|
|
|
|
|
|
// 16786594-0296-4471-8096-8f84497ca428
|
|
|
|
#define NS_NSSSOCKETINFO_CID \
|
|
|
|
{ 0x16786594, 0x0296, 0x4471, \
|
|
|
|
{ 0x80, 0x96, 0x8f, 0x84, 0x49, 0x7c, 0xa4, 0x28 } }
|
|
|
|
|
|
|
|
|
2001-01-10 01:32:29 +00:00
|
|
|
#endif /* _NSNSSIOLAYER_H */
|