Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(37)

Unified Diff: runtime/bin/secure_socket.cc

Issue 13985012: dart:io | Change the way SecureSocket initializes the NSS library with an empty database. (Closed) Base URL: https://dart.googlecode.com/svn/branches/bleeding_edge/dart
Patch Set: Created 7 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | tests/standalone/io/secure_no_builtin_roots_database_test.dart » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: runtime/bin/secure_socket.cc
diff --git a/runtime/bin/secure_socket.cc b/runtime/bin/secure_socket.cc
index 0f9140b93da357ef3b8cf15b896e49a59a27e532..e66ff357c576bf11ed7db7c7b5af44a679770a82 100644
--- a/runtime/bin/secure_socket.cc
+++ b/runtime/bin/secure_socket.cc
@@ -17,6 +17,7 @@
#include <prerror.h>
#include <prinit.h>
#include <prnetdb.h>
+#include <secmod.h>
#include <ssl.h>
#include <sslproto.h>
@@ -333,36 +334,57 @@ void SSLFilter::RegisterBadCertificateCallback(Dart_Handle callback) {
bad_certificate_callback_ = ThrowIfError(Dart_NewPersistentHandle(callback));
}
+static const char* builtin_roots_module =
Søren Gjesse 2013/04/12 14:59:31 As we don't currently have secure_socket_<platform
+#if defined(TARGET_OS_LINUX) || defined(TARGET_OS_ANDROID)
+ "name=\"Root Certs\" library=\"libnssckbi.so\"";
+#elif defined(TARGET_OS_MACOS)
+ "name=\"Root Certs\" library=\"libnssckbi.dylib\"";
+#elif defined(TARGET_OS_WINDOWS)
+ "name=\"Root Certs\" library=\"nssckbi.dll\"";
+#else
+#error Automatic target os detection failed.
+#endif
+
+
Bill Hesse 2013/04/12 14:42:14 Too many spaces.
void SSLFilter::InitializeLibrary(const char* certificate_database,
const char* password,
bool use_builtin_root_certificates,
bool report_duplicate_initialization) {
MutexLocker locker(&mutex_);
+ SECStatus status;
if (!library_initialized_) {
password_ = strdup(password); // This one copy persists until Dart exits.
PR_Init(PR_USER_THREAD, PR_PRIORITY_NORMAL, 0);
// TODO(whesse): Verify there are no UTF-8 issues here.
- PRUint32 init_flags = NSS_INIT_READONLY;
- if (certificate_database == NULL) {
- // Passing the empty string as the database path does not try to open
- // a database in the current directory.
- certificate_database = "";
- // The flag NSS_INIT_NOCERTDB is documented to do what we want here,
- // however it causes the builtins not to be available on Windows.
- init_flags |= NSS_INIT_FORCEOPEN;
- }
- if (!use_builtin_root_certificates) {
- init_flags |= NSS_INIT_NOMODDB;
- }
- SECStatus status = NSS_Initialize(certificate_database,
- "",
- "",
- SECMOD_DB,
- init_flags);
- if (status != SECSuccess) {
- mutex_.Unlock(); // MutexLocker destructor not called when throwing.
- ThrowPRException("Failed NSS_Init call.");
+ if (certificate_database == NULL || certificate_database[0] == '\0') {
Søren Gjesse 2013/04/12 14:59:31 Maybe add a test which passes both null and the em
+ status = NSS_NoDB_Init(NULL);
+ if (status != SECSuccess) {
+ mutex_.Unlock(); // MutexLocker destructor not called when throwing.
+ ThrowPRException("Failed NSS_NoDB_Init call.");
+ }
+ if (use_builtin_root_certificates) {
+ SECMODModule* module = SECMOD_LoadUserModule(
+ const_cast<char*>(builtin_roots_module), NULL, PR_FALSE);
+ if (!module) {
+ mutex_.Unlock(); // MutexLocker destructor not called when throwing.
+ ThrowPRException("Failed to load builtin root certificates.");
+ }
+ }
+ } else {
+ PRUint32 init_flags = NSS_INIT_READONLY;
+ if (!use_builtin_root_certificates) {
+ init_flags |= NSS_INIT_NOMODDB;
+ }
+ status = NSS_Initialize(certificate_database,
+ "",
+ "",
+ SECMOD_DB,
+ init_flags);
+ if (status != SECSuccess) {
+ mutex_.Unlock(); // MutexLocker destructor not called when throwing.
+ ThrowPRException("Failed NSS_Init call.");
+ }
}
library_initialized_ = true;
« no previous file with comments | « no previous file | tests/standalone/io/secure_no_builtin_roots_database_test.dart » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698