| Index: net/base/x509_certificate_mac.cc
|
| diff --git a/net/base/x509_certificate_mac.cc b/net/base/x509_certificate_mac.cc
|
| index 2c959812c596a05f3db9986fbfb1555217861107..99801aa08d2ad799bbc6590c0233b2f379007294 100644
|
| --- a/net/base/x509_certificate_mac.cc
|
| +++ b/net/base/x509_certificate_mac.cc
|
| @@ -755,6 +755,21 @@ void X509Certificate::GetSubjectAltName(
|
| }
|
| }
|
|
|
| +X509Certificate::OSCertListHandle
|
| +X509Certificate::CreateOSCertListHandle() const {
|
| + CFMutableArrayRef cert_list =
|
| + CFArrayCreateMutable(kCFAllocatorDefault, 0,
|
| + &kCFTypeArrayCallBacks);
|
| + if (!cert_list)
|
| + return NULL;
|
| +
|
| + CFArrayAppendValue(cert_list, cert_handle_);
|
| + for (size_t i = 0; i < intermediate_ca_certs_.size(); ++i)
|
| + CFArrayAppendValue(cert_list, intermediate_ca_certs_[i]);
|
| +
|
| + return cert_list;
|
| +}
|
| +
|
| int X509Certificate::VerifyInternal(const std::string& hostname,
|
| int flags,
|
| CertVerifyResult* verify_result) const {
|
| @@ -768,14 +783,7 @@ int X509Certificate::VerifyInternal(const std::string& hostname,
|
| // array of certificates, the first of which is the certificate we're
|
| // verifying, and the subsequent (optional) certificates are used for
|
| // chain building.
|
| - CFMutableArrayRef cert_array = CFArrayCreateMutable(kCFAllocatorDefault, 0,
|
| - &kCFTypeArrayCallBacks);
|
| - if (!cert_array)
|
| - return ERR_OUT_OF_MEMORY;
|
| - ScopedCFTypeRef<CFArrayRef> scoped_cert_array(cert_array);
|
| - CFArrayAppendValue(cert_array, cert_handle_);
|
| - for (size_t i = 0; i < intermediate_ca_certs_.size(); ++i)
|
| - CFArrayAppendValue(cert_array, intermediate_ca_certs_[i]);
|
| + ScopedCFTypeRef<CFArrayRef> cert_array(CreateOSCertListHandle());
|
|
|
| // From here on, only one thread can be active at a time. We have had a number
|
| // of sporadic crashes in the SecTrustEvaluate call below, way down inside
|
| @@ -1069,6 +1077,12 @@ void X509Certificate::FreeOSCertHandle(OSCertHandle cert_handle) {
|
| }
|
|
|
| // static
|
| +void X509Certificate::FreeOSCertListHandle(
|
| + OSCertListHandle cert_list_handle) {
|
| + CFRelease(cert_list_handle);
|
| +}
|
| +
|
| +// static
|
| SHA1Fingerprint X509Certificate::CalculateFingerprint(
|
| OSCertHandle cert) {
|
| SHA1Fingerprint sha1;
|
|
|