Chromium Code Reviews| OLD | NEW |
|---|---|
| 1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "net/ssl/ssl_client_session_cache.h" | 5 #include "net/ssl/ssl_client_session_cache.h" |
| 6 | 6 |
| 7 #include <openssl/ssl.h> | |
| 8 #include <openssl/x509.h> | |
| 7 #include <utility> | 9 #include <utility> |
| 8 | 10 |
| 9 #include "base/memory/memory_coordinator_client_registry.h" | 11 #include "base/memory/memory_coordinator_client_registry.h" |
| 12 #include "base/strings/stringprintf.h" | |
| 10 #include "base/time/clock.h" | 13 #include "base/time/clock.h" |
| 11 #include "base/time/default_clock.h" | 14 #include "base/time/default_clock.h" |
| 15 #include "base/trace_event/process_memory_dump.h" | |
| 16 #include "net/cert/x509_util_openssl.h" | |
| 12 #include "third_party/boringssl/src/include/openssl/ssl.h" | 17 #include "third_party/boringssl/src/include/openssl/ssl.h" |
| 13 | 18 |
| 14 namespace net { | 19 namespace net { |
| 15 | 20 |
| 16 SSLClientSessionCache::SSLClientSessionCache(const Config& config) | 21 SSLClientSessionCache::SSLClientSessionCache(const Config& config) |
| 17 : clock_(new base::DefaultClock), | 22 : clock_(new base::DefaultClock), |
| 18 config_(config), | 23 config_(config), |
| 19 cache_(config.max_entries), | 24 cache_(config.max_entries), |
| 20 lookups_since_flush_(0) { | 25 lookups_since_flush_(0) { |
| 21 memory_pressure_listener_.reset(new base::MemoryPressureListener(base::Bind( | 26 memory_pressure_listener_.reset(new base::MemoryPressureListener(base::Bind( |
| (...skipping 53 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
| 75 std::unique_ptr<base::Clock> clock) { | 80 std::unique_ptr<base::Clock> clock) { |
| 76 clock_ = std::move(clock); | 81 clock_ = std::move(clock); |
| 77 } | 82 } |
| 78 | 83 |
| 79 bool SSLClientSessionCache::IsExpired(SSL_SESSION* session, time_t now) { | 84 bool SSLClientSessionCache::IsExpired(SSL_SESSION* session, time_t now) { |
| 80 return now < SSL_SESSION_get_time(session) || | 85 return now < SSL_SESSION_get_time(session) || |
| 81 now >= | 86 now >= |
| 82 SSL_SESSION_get_time(session) + SSL_SESSION_get_timeout(session); | 87 SSL_SESSION_get_time(session) + SSL_SESSION_get_timeout(session); |
| 83 } | 88 } |
| 84 | 89 |
| 90 void SSLClientSessionCache::DumpMemoryStats( | |
| 91 base::trace_event::ProcessMemoryDump* pmd) const { | |
| 92 std::string absolute_name = "net/ssl_session_cache"; | |
| 93 base::trace_event::MemoryAllocatorDump* cache_dump = | |
| 94 pmd->GetAllocatorDump(absolute_name); | |
| 95 // This is a singleton, so only log it once. | |
| 96 if (cache_dump) | |
| 97 return; | |
| 98 cache_dump = pmd->CreateAllocatorDump(absolute_name); | |
| 99 auto iter = cache_.begin(); | |
|
eroman
2016/11/29 22:22:50
I would expect |lock_| should be held while access
xunjieli
2016/11/30 16:02:03
Done.
David, do you know why some methods that ac
| |
| 100 while (iter != cache_.end()) { | |
| 101 auto entry = iter->second.get(); | |
| 102 auto cert_chain = entry->x509_chain; | |
| 103 size_t cert_count = sk_X509_num(cert_chain); | |
| 104 base::trace_event::MemoryAllocatorDump* entry_dump = | |
| 105 pmd->CreateAllocatorDump( | |
| 106 base::StringPrintf("%s/entry_%p", absolute_name.c_str(), entry)); | |
| 107 int cert_size = 0; | |
| 108 for (size_t i = 0; i < cert_count; ++i) { | |
| 109 X509* cert = sk_X509_value(cert_chain, i); | |
| 110 cert_size += i2d_X509(cert, nullptr); | |
| 111 } | |
| 112 entry_dump->AddScalar("cert_size", | |
| 113 base::trace_event::MemoryAllocatorDump::kUnitsBytes, | |
| 114 cert_size); | |
| 115 entry_dump->AddScalar("cert_count", | |
| 116 base::trace_event::MemoryAllocatorDump::kUnitsObjects, | |
| 117 cert_count); | |
| 118 entry_dump->AddScalar(base::trace_event::MemoryAllocatorDump::kNameSize, | |
| 119 base::trace_event::MemoryAllocatorDump::kUnitsBytes, | |
| 120 cert_size); | |
| 121 | |
| 122 ++iter; | |
| 123 } | |
| 124 } | |
| 125 | |
| 85 void SSLClientSessionCache::FlushExpiredSessions() { | 126 void SSLClientSessionCache::FlushExpiredSessions() { |
| 86 time_t now = clock_->Now().ToTimeT(); | 127 time_t now = clock_->Now().ToTimeT(); |
| 87 auto iter = cache_.begin(); | 128 auto iter = cache_.begin(); |
| 88 while (iter != cache_.end()) { | 129 while (iter != cache_.end()) { |
| 89 if (IsExpired(iter->second.get(), now)) { | 130 if (IsExpired(iter->second.get(), now)) { |
| 90 iter = cache_.Erase(iter); | 131 iter = cache_.Erase(iter); |
| 91 } else { | 132 } else { |
| 92 ++iter; | 133 ++iter; |
| 93 } | 134 } |
| 94 } | 135 } |
| (...skipping 25 matching lines...) Expand all Loading... | |
| 120 break; | 161 break; |
| 121 case base::MemoryState::SUSPENDED: | 162 case base::MemoryState::SUSPENDED: |
| 122 // Note: Not supported at present. Fall through. | 163 // Note: Not supported at present. Fall through. |
| 123 case base::MemoryState::UNKNOWN: | 164 case base::MemoryState::UNKNOWN: |
| 124 NOTREACHED(); | 165 NOTREACHED(); |
| 125 break; | 166 break; |
| 126 } | 167 } |
| 127 } | 168 } |
| 128 | 169 |
| 129 } // namespace net | 170 } // namespace net |
| OLD | NEW |