Chromium Code Reviews| OLD | NEW |
|---|---|
| (Empty) | |
| 1 // Copyright 2016 The Chromium Authors. All rights reserved. | |
| 2 // Use of this source code is governed by a BSD-style license that can be | |
| 3 // found in the LICENSE file. | |
| 4 | |
| 5 #include "content/browser/renderer_host/websocket_blob_sender.h" | |
| 6 | |
| 7 #include <algorithm> | |
| 8 #include <utility> | |
| 9 | |
| 10 #include "base/bind.h" | |
| 11 #include "base/bind_helpers.h" | |
| 12 #include "base/callback_helpers.h" | |
| 13 #include "base/logging.h" | |
| 14 #include "base/numerics/safe_conversions.h" | |
| 15 #include "content/browser/renderer_host/websocket_dispatcher_host.h" | |
| 16 #include "content/browser/renderer_host/websocket_host.h" | |
| 17 #include "net/base/io_buffer.h" | |
| 18 #include "net/base/net_errors.h" | |
| 19 #include "net/websockets/websocket_channel.h" | |
| 20 #include "net/websockets/websocket_frame.h" | |
| 21 #include "storage/browser/blob/blob_data_handle.h" | |
| 22 #include "storage/browser/blob/blob_reader.h" | |
| 23 #include "storage/browser/blob/blob_storage_context.h" | |
| 24 | |
| 25 namespace content { | |
| 26 | |
| 27 namespace { | |
| 28 | |
| 29 using storage::BlobReader; | |
| 30 using storage::BlobDataHandle; | |
| 31 using storage::BlobStorageContext; | |
| 32 | |
| 33 // This must be smaller than the send quota high water mark or this class will | |
| 34 // never send anything. | |
| 35 const int kMinimumNonFinalFrameSize = 8 * 1024; | |
| 36 | |
| 37 // The IOBuffer has a fixed size for simplicity. | |
| 38 const size_t kBufferSize = 128 * 1024; | |
| 39 | |
| 40 } // namespace | |
| 41 | |
| 42 WebSocketBlobSender::WebSocketBlobSender(scoped_ptr<Channel> channel) | |
| 43 : channel_(std::move(channel)) {} | |
| 44 | |
| 45 WebSocketBlobSender::~WebSocketBlobSender() {} | |
| 46 | |
| 47 int WebSocketBlobSender::Start( | |
| 48 const std::string& uuid, | |
| 49 uint64_t expected_size, | |
| 50 BlobStorageContext* context, | |
| 51 storage::FileSystemContext* file_system_context, | |
| 52 base::SingleThreadTaskRunner* file_task_runner, | |
| 53 net::WebSocketEventInterface::ChannelState* channel_state, | |
| 54 const net::CompletionCallback& callback) { | |
| 55 DCHECK(context); | |
| 56 DCHECK(channel_state); | |
| 57 scoped_ptr<storage::BlobDataHandle> data_handle( | |
| 58 context->GetBlobDataFromUUID(uuid)); | |
| 59 if (!data_handle) | |
| 60 return net::ERR_INVALID_HANDLE; | |
| 61 reader_ = data_handle->CreateReader(file_system_context, file_task_runner); | |
| 62 expected_size_ = expected_size; | |
| 63 next_state_ = STATE_READ_SIZE; | |
| 64 int rv = DoLoop(net::OK, channel_state); | |
| 65 if (*channel_state == net::WebSocketEventInterface::CHANNEL_ALIVE && | |
| 66 rv == net::ERR_IO_PENDING) { | |
| 67 callback_ = callback; | |
| 68 } | |
| 69 return rv; | |
| 70 } | |
| 71 | |
| 72 void WebSocketBlobSender::OnNewSendQuota() { | |
| 73 if (next_state_ == STATE_WAIT_FOR_QUOTA) | |
| 74 DoLoopAsync(net::OK); | |
| 75 // |this| may be deleted. | |
| 76 } | |
| 77 | |
| 78 uint64_t WebSocketBlobSender::ActualSize() const { | |
| 79 return reader_->total_size(); | |
| 80 } | |
| 81 | |
| 82 void WebSocketBlobSender::OnIOComplete(int rv) { | |
| 83 CHECK_EQ(STATE_READ_COMPLETE, next_state_); | |
|
dcheng
2016/01/20 08:30:06
Would it possible for the renderer to crash the br
Adam Rice
2016/01/20 17:11:20
There are several layers of protection against thi
| |
| 84 DoLoopAsync(rv); | |
| 85 // |this| may be deleted. | |
| 86 } | |
| 87 | |
| 88 void WebSocketBlobSender::OnSizeCalculated(int rv) { | |
| 89 CHECK_EQ(STATE_READ_SIZE_COMPLETE, next_state_); | |
| 90 DoLoopAsync(rv); | |
| 91 // |this| may be deleted. | |
| 92 } | |
| 93 | |
| 94 int WebSocketBlobSender::DoLoop(int result, | |
| 95 Channel::ChannelState* channel_state) { | |
| 96 CHECK_NE(STATE_NONE, next_state_); | |
| 97 int rv = result; | |
| 98 do { | |
| 99 State state = next_state_; | |
| 100 next_state_ = STATE_NONE; | |
| 101 switch (state) { | |
| 102 case STATE_READ_SIZE: | |
| 103 DCHECK_EQ(net::OK, rv); | |
| 104 rv = DoReadSize(); | |
| 105 break; | |
| 106 | |
| 107 case STATE_READ_SIZE_COMPLETE: | |
| 108 rv = DoReadSizeComplete(rv); | |
| 109 break; | |
| 110 | |
| 111 case STATE_WAIT_FOR_QUOTA: | |
| 112 DCHECK_EQ(net::OK, rv); | |
| 113 rv = DoWaitForQuota(); | |
| 114 break; | |
| 115 | |
| 116 case STATE_WAIT_FOR_QUOTA_COMPLETE: | |
| 117 DCHECK_EQ(net::OK, rv); | |
| 118 rv = DoWaitForQuotaComplete(); | |
| 119 break; | |
| 120 | |
| 121 case STATE_READ: | |
| 122 DCHECK_EQ(net::OK, rv); | |
| 123 rv = DoRead(); | |
| 124 break; | |
| 125 | |
| 126 case STATE_READ_COMPLETE: | |
| 127 rv = DoReadComplete(rv, channel_state); | |
| 128 break; | |
| 129 | |
| 130 default: | |
| 131 NOTREACHED(); | |
| 132 break; | |
| 133 } | |
| 134 } while (*channel_state != net::WebSocketEventInterface::CHANNEL_DELETED && | |
| 135 rv != net::ERR_IO_PENDING && next_state_ != STATE_NONE); | |
| 136 return rv; | |
| 137 } | |
| 138 | |
| 139 void WebSocketBlobSender::DoLoopAsync(int result) { | |
| 140 Channel::ChannelState channel_state = | |
| 141 net::WebSocketEventInterface::CHANNEL_ALIVE; | |
| 142 int rv = DoLoop(result, &channel_state); | |
| 143 if (channel_state == net::WebSocketEventInterface::CHANNEL_ALIVE && | |
| 144 rv != net::ERR_IO_PENDING) { | |
| 145 ResetAndReturn(&callback_).Run(rv); | |
| 146 } | |
| 147 // |this| may be deleted. | |
| 148 } | |
| 149 | |
| 150 int WebSocketBlobSender::DoReadSize() { | |
| 151 next_state_ = STATE_READ_SIZE_COMPLETE; | |
| 152 // This use of base::Unretained() is safe because BlobReader cannot call the | |
| 153 // callback after it has been destroyed, and it is owned by this object. | |
| 154 BlobReader::Status status = reader_->CalculateSize(base::Bind( | |
| 155 &WebSocketBlobSender::OnSizeCalculated, base::Unretained(this))); | |
| 156 switch (status) { | |
| 157 case BlobReader::Status::NET_ERROR: | |
| 158 return reader_->net_error(); | |
| 159 | |
| 160 case BlobReader::Status::IO_PENDING: | |
| 161 return net::ERR_IO_PENDING; | |
| 162 | |
| 163 case BlobReader::Status::DONE: | |
| 164 return net::OK; | |
| 165 } | |
| 166 NOTREACHED(); | |
| 167 return net::ERR_UNEXPECTED; | |
| 168 } | |
| 169 | |
| 170 int WebSocketBlobSender::DoReadSizeComplete(int result) { | |
| 171 if (result < 0) | |
| 172 return result; | |
| 173 if (reader_->total_size() != expected_size_) | |
| 174 return net::ERR_UPLOAD_FILE_CHANGED; | |
| 175 bytes_left_ = expected_size_; | |
| 176 // The result of the call to std::min() must fit inside a size_t because | |
| 177 // kBufferSize is type size_t. | |
| 178 size_t buffer_size = static_cast<size_t>( | |
| 179 std::min(bytes_left_, static_cast<uint64_t>(kBufferSize))); | |
| 180 buffer_ = new net::IOBuffer(buffer_size); | |
| 181 next_state_ = STATE_WAIT_FOR_QUOTA; | |
| 182 return net::OK; | |
| 183 } | |
| 184 | |
| 185 // The WAIT_FOR_QUOTA state has a self-edge; it will wait in this state until | |
| 186 // there is enough quota to send some data. | |
| 187 int WebSocketBlobSender::DoWaitForQuota() { | |
| 188 int quota = channel_->GetSendQuota(); | |
| 189 if (kMinimumNonFinalFrameSize <= quota || | |
| 190 bytes_left_ <= base::checked_cast<uint64_t>(quota)) { | |
| 191 next_state_ = STATE_WAIT_FOR_QUOTA_COMPLETE; | |
| 192 return net::OK; | |
| 193 } | |
| 194 next_state_ = STATE_WAIT_FOR_QUOTA; | |
| 195 return net::ERR_IO_PENDING; | |
| 196 } | |
| 197 | |
| 198 // STATE_WAIT_FOR_QUOTA_COMPLETE exists just to give the state machine the | |
| 199 // expected shape. It should be mostly optimised out. | |
| 200 int WebSocketBlobSender::DoWaitForQuotaComplete() { | |
| 201 next_state_ = STATE_READ; | |
| 202 return net::OK; | |
| 203 } | |
| 204 | |
| 205 int WebSocketBlobSender::DoRead() { | |
| 206 next_state_ = STATE_READ_COMPLETE; | |
| 207 uint64_t quota = base::checked_cast<uint64_t>(channel_->GetSendQuota()); | |
| 208 uint64_t desired_bytes = std::min(bytes_left_, quota); | |
| 209 | |
| 210 // |bytes_to_read| must fit in a size_t because |kBufferSize| is of type | |
| 211 // size_t and so cannot be larger than its maximum value. For simplicity this | |
| 212 // method only reads as many bytes as are currently needed. | |
| 213 size_t bytes_to_read = static_cast<size_t>( | |
| 214 std::min(desired_bytes, static_cast<uint64_t>(kBufferSize))); | |
| 215 int bytes_read = 0; | |
| 216 DCHECK(reader_); | |
| 217 DCHECK(buffer_); | |
| 218 | |
| 219 // This use of base::Unretained is safe because the BlobReader object won't | |
| 220 // call the callback after it has been destroyed, and it belongs to this | |
| 221 // object. | |
| 222 BlobReader::Status status = reader_->Read( | |
| 223 buffer_.get(), bytes_to_read, &bytes_read, | |
| 224 base::Bind(&WebSocketBlobSender::OnIOComplete, base::Unretained(this))); | |
| 225 | |
| 226 switch (status) { | |
| 227 case BlobReader::Status::NET_ERROR: | |
| 228 return reader_->net_error(); | |
| 229 | |
| 230 case BlobReader::Status::IO_PENDING: | |
| 231 return net::ERR_IO_PENDING; | |
| 232 | |
| 233 case BlobReader::Status::DONE: | |
| 234 return bytes_read; | |
| 235 } | |
| 236 NOTREACHED(); | |
| 237 return net::ERR_UNEXPECTED; | |
| 238 } | |
| 239 | |
| 240 int WebSocketBlobSender::DoReadComplete(int result, | |
| 241 Channel::ChannelState* channel_state) { | |
| 242 if (result < 0) | |
| 243 return result; | |
| 244 DCHECK_GE(channel_->GetSendQuota(), result); | |
| 245 uint64_t bytes_read = base::checked_cast<uint64_t>(result); | |
| 246 CHECK_GE(bytes_left_, bytes_read); | |
| 247 bytes_left_ -= bytes_read; | |
| 248 bool fin = bytes_left_ == 0; | |
| 249 std::vector<char> data(buffer_->data(), buffer_->data() + bytes_read); | |
| 250 DCHECK(fin || data.size() > 0u) << "Non-final frames should be non-empty"; | |
| 251 *channel_state = channel_->SendFrame(fin, data); | |
| 252 if (*channel_state == net::WebSocketEventInterface::CHANNEL_DELETED) { | |
| 253 // |this| is deleted. | |
| 254 return net::ERR_CONNECTION_RESET; | |
| 255 } | |
| 256 | |
| 257 // It is important not to set next_state_ until after the call to SendFrame() | |
| 258 // because SendFrame() will sometimes call OnNewSendQuota() synchronously. | |
| 259 if (!fin) | |
| 260 next_state_ = STATE_WAIT_FOR_QUOTA; | |
| 261 return net::OK; | |
| 262 } | |
| 263 | |
| 264 } // namespace content | |
| OLD | NEW |