OLD | NEW |
---|---|
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 5 #ifndef NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
6 #define NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 6 #define NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
7 | 7 |
8 #include <map> | |
8 #include <string> | 9 #include <string> |
10 #include <vector> | |
9 | 11 |
10 #include "base/memory/ref_counted.h" | 12 #include "base/memory/ref_counted.h" |
11 #include "base/memory/scoped_ptr.h" | 13 #include "base/memory/scoped_ptr.h" |
12 #include "base/time/time.h" | 14 #include "base/time/time.h" |
13 #include "net/base/privacy_mode.h" | 15 #include "net/base/privacy_mode.h" |
14 #include "net/dns/host_resolver.h" | 16 #include "net/dns/host_resolver.h" |
15 #include "net/http/http_response_info.h" | 17 #include "net/http/http_response_info.h" |
16 #include "net/socket/client_socket_pool.h" | 18 #include "net/socket/client_socket_pool.h" |
17 #include "net/socket/client_socket_pool_base.h" | 19 #include "net/socket/client_socket_pool_base.h" |
18 #include "net/socket/client_socket_pool_histograms.h" | 20 #include "net/socket/client_socket_pool_histograms.h" |
(...skipping 68 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
87 const SSLConfig ssl_config_; | 89 const SSLConfig ssl_config_; |
88 const PrivacyMode privacy_mode_; | 90 const PrivacyMode privacy_mode_; |
89 const int load_flags_; | 91 const int load_flags_; |
90 const bool force_spdy_over_ssl_; | 92 const bool force_spdy_over_ssl_; |
91 const bool want_spdy_over_npn_; | 93 const bool want_spdy_over_npn_; |
92 bool ignore_limits_; | 94 bool ignore_limits_; |
93 | 95 |
94 DISALLOW_COPY_AND_ASSIGN(SSLSocketParams); | 96 DISALLOW_COPY_AND_ASSIGN(SSLSocketParams); |
95 }; | 97 }; |
96 | 98 |
99 // SSLConnectJobMessenger handles communication between concurrent | |
100 // SSLConnectJobs that share the same SSL session cache key. | |
101 // | |
102 // SSLConnectJobMessengers tell the session cache when a certain | |
103 // connection should be monitored for success or failure, and | |
104 // tell SSLConnectJobs when to pause or resume their connections. | |
105 class SSLConnectJobMessenger { | |
106 public: | |
107 struct SocketAndCallback { | |
108 SocketAndCallback(SSLClientSocket* ssl_socket, | |
109 const base::Closure& job_resumption_callback) | |
110 : socket(ssl_socket), callback(job_resumption_callback) {} | |
111 | |
112 SSLClientSocket* socket; | |
113 base::Closure callback; | |
114 }; | |
115 | |
116 typedef std::vector<SocketAndCallback> SSLPendingSocketsAndCallbacks; | |
117 | |
118 // Removes |socket| from the set of sockets being monitored. This | |
119 // guarantees that |job_resumption_callback| will not be called for | |
120 // the socket. | |
121 void RemovePendingSocket(SSLClientSocket* ssl_socket); | |
122 | |
123 // Returns true if |ssl_socket|'s Connect() method should be called. | |
124 bool CanProceed(SSLClientSocket* ssl_socket); | |
125 | |
126 // Configures the SSLConnectJobMessenger to begin monitoring |ssl_socket|'s | |
127 // connection status. After a successful connection, or an error, | |
128 // the messenger will determine which sockets that have been added | |
129 // via AddPendingSocket() to allow to proceed. | |
130 void MonitorConnectionResult(SSLClientSocket* ssl_socket); | |
131 | |
132 // Adds |socket| to the list of sockets waiting to Connect(). When | |
133 // the messenger has determined that it's an appropriate time for |socket| | |
134 // to connect, it will asynchronously invoke |callback|. | |
135 // | |
136 // Note: It is an error to call AddPendingSocket() without having first | |
137 // called MonitorConnectionResult() and configuring a socket that WILL | |
138 // have Connect() called on it. | |
139 void AddPendingSocket(SSLClientSocket* ssl_socket, | |
140 const base::Closure& callback); | |
141 | |
142 private: | |
143 // Processes pending callbacks when a socket completes its connection -- | |
144 // either successfully or unsuccessfully. | |
145 void OnJobCompleted(); | |
wtc
2014/07/23 22:53:33
Nit: I suggest renaming this method OnHandshakeCom
mshelley
2014/07/24 20:37:49
Done.
| |
146 | |
147 // Runs all callbacks stored in |pending_sockets_and_callbacks_|. | |
148 void RunAllCallbacks( | |
149 const SSLPendingSocketsAndCallbacks& pending_socket_and_callbacks); | |
150 | |
151 SSLPendingSocketsAndCallbacks pending_sockets_and_callbacks_; | |
152 // Note: this field is a vector to allow for future design changes. Currently, | |
153 // this vector should only ever have one entry. | |
154 std::vector<SSLClientSocket*> connecting_sockets_; | |
155 }; | |
156 | |
97 // SSLConnectJob handles the SSL handshake after setting up the underlying | 157 // SSLConnectJob handles the SSL handshake after setting up the underlying |
98 // connection as specified in the params. | 158 // connection as specified in the params. |
99 class SSLConnectJob : public ConnectJob { | 159 class SSLConnectJob : public ConnectJob { |
100 public: | 160 public: |
101 SSLConnectJob( | 161 // Note: the SSLConnectJob does not own |messenger| so it must outlive the |
102 const std::string& group_name, | 162 // job. |
103 RequestPriority priority, | 163 SSLConnectJob(const std::string& group_name, |
104 const scoped_refptr<SSLSocketParams>& params, | 164 RequestPriority priority, |
105 const base::TimeDelta& timeout_duration, | 165 const scoped_refptr<SSLSocketParams>& params, |
106 TransportClientSocketPool* transport_pool, | 166 const base::TimeDelta& timeout_duration, |
107 SOCKSClientSocketPool* socks_pool, | 167 TransportClientSocketPool* transport_pool, |
108 HttpProxyClientSocketPool* http_proxy_pool, | 168 SOCKSClientSocketPool* socks_pool, |
109 ClientSocketFactory* client_socket_factory, | 169 HttpProxyClientSocketPool* http_proxy_pool, |
110 HostResolver* host_resolver, | 170 ClientSocketFactory* client_socket_factory, |
111 const SSLClientSocketContext& context, | 171 HostResolver* host_resolver, |
112 Delegate* delegate, | 172 const SSLClientSocketContext& context, |
113 NetLog* net_log); | 173 SSLConnectJobMessenger* messenger, |
174 Delegate* delegate, | |
175 NetLog* net_log); | |
114 virtual ~SSLConnectJob(); | 176 virtual ~SSLConnectJob(); |
115 | 177 |
116 // ConnectJob methods. | 178 // ConnectJob methods. |
117 virtual LoadState GetLoadState() const OVERRIDE; | 179 virtual LoadState GetLoadState() const OVERRIDE; |
118 | 180 |
119 virtual void GetAdditionalErrorState(ClientSocketHandle * handle) OVERRIDE; | 181 virtual void GetAdditionalErrorState(ClientSocketHandle * handle) OVERRIDE; |
120 | 182 |
121 private: | 183 private: |
122 enum State { | 184 enum State { |
123 STATE_TRANSPORT_CONNECT, | 185 STATE_TRANSPORT_CONNECT, |
124 STATE_TRANSPORT_CONNECT_COMPLETE, | 186 STATE_TRANSPORT_CONNECT_COMPLETE, |
125 STATE_SOCKS_CONNECT, | 187 STATE_SOCKS_CONNECT, |
126 STATE_SOCKS_CONNECT_COMPLETE, | 188 STATE_SOCKS_CONNECT_COMPLETE, |
127 STATE_TUNNEL_CONNECT, | 189 STATE_TUNNEL_CONNECT, |
128 STATE_TUNNEL_CONNECT_COMPLETE, | 190 STATE_TUNNEL_CONNECT_COMPLETE, |
191 STATE_CREATE_SSL_SOCKET, | |
192 STATE_CHECK_FOR_RESUME, | |
129 STATE_SSL_CONNECT, | 193 STATE_SSL_CONNECT, |
130 STATE_SSL_CONNECT_COMPLETE, | 194 STATE_SSL_CONNECT_COMPLETE, |
131 STATE_NONE, | 195 STATE_NONE, |
132 }; | 196 }; |
133 | 197 |
134 void OnIOComplete(int result); | 198 void OnIOComplete(int result); |
135 | 199 |
136 // Runs the state transition loop. | 200 // Runs the state transition loop. |
137 int DoLoop(int result); | 201 int DoLoop(int result); |
138 | 202 |
139 int DoTransportConnect(); | 203 int DoTransportConnect(); |
140 int DoTransportConnectComplete(int result); | 204 int DoTransportConnectComplete(int result); |
141 int DoSOCKSConnect(); | 205 int DoSOCKSConnect(); |
142 int DoSOCKSConnectComplete(int result); | 206 int DoSOCKSConnectComplete(int result); |
143 int DoTunnelConnect(); | 207 int DoTunnelConnect(); |
144 int DoTunnelConnectComplete(int result); | 208 int DoTunnelConnectComplete(int result); |
209 int DoCreateSSLSocket(); | |
210 int DoCheckForResume(); | |
145 int DoSSLConnect(); | 211 int DoSSLConnect(); |
146 int DoSSLConnectComplete(int result); | 212 int DoSSLConnectComplete(int result); |
147 | 213 |
214 // Tells a waiting SSLConnectJob to resume its SSL connection. | |
215 void ResumeSSLConnection(); | |
216 | |
148 // Returns the initial state for the state machine based on the | 217 // Returns the initial state for the state machine based on the |
149 // |connection_type|. | 218 // |connection_type|. |
150 static State GetInitialState(SSLSocketParams::ConnectionType connection_type); | 219 static State GetInitialState(SSLSocketParams::ConnectionType connection_type); |
151 | 220 |
152 // Starts the SSL connection process. Returns OK on success and | 221 // Starts the SSL connection process. Returns OK on success and |
153 // ERR_IO_PENDING if it cannot immediately service the request. | 222 // ERR_IO_PENDING if it cannot immediately service the request. |
154 // Otherwise, it returns a net error code. | 223 // Otherwise, it returns a net error code. |
155 virtual int ConnectInternal() OVERRIDE; | 224 virtual int ConnectInternal() OVERRIDE; |
156 | 225 |
157 scoped_refptr<SSLSocketParams> params_; | 226 scoped_refptr<SSLSocketParams> params_; |
158 TransportClientSocketPool* const transport_pool_; | 227 TransportClientSocketPool* const transport_pool_; |
159 SOCKSClientSocketPool* const socks_pool_; | 228 SOCKSClientSocketPool* const socks_pool_; |
160 HttpProxyClientSocketPool* const http_proxy_pool_; | 229 HttpProxyClientSocketPool* const http_proxy_pool_; |
161 ClientSocketFactory* const client_socket_factory_; | 230 ClientSocketFactory* const client_socket_factory_; |
162 HostResolver* const host_resolver_; | 231 HostResolver* const host_resolver_; |
163 | 232 |
164 const SSLClientSocketContext context_; | 233 const SSLClientSocketContext context_; |
165 | 234 |
166 State next_state_; | 235 State next_state_; |
167 CompletionCallback callback_; | 236 CompletionCallback io_callback_; |
168 scoped_ptr<ClientSocketHandle> transport_socket_handle_; | 237 scoped_ptr<ClientSocketHandle> transport_socket_handle_; |
169 scoped_ptr<SSLClientSocket> ssl_socket_; | 238 scoped_ptr<SSLClientSocket> ssl_socket_; |
170 | 239 |
240 SSLConnectJobMessenger* messenger_; | |
171 HttpResponseInfo error_response_info_; | 241 HttpResponseInfo error_response_info_; |
172 | 242 |
243 base::WeakPtrFactory<SSLConnectJob> weak_factory_; | |
244 | |
173 DISALLOW_COPY_AND_ASSIGN(SSLConnectJob); | 245 DISALLOW_COPY_AND_ASSIGN(SSLConnectJob); |
174 }; | 246 }; |
175 | 247 |
176 class NET_EXPORT_PRIVATE SSLClientSocketPool | 248 class NET_EXPORT_PRIVATE SSLClientSocketPool |
177 : public ClientSocketPool, | 249 : public ClientSocketPool, |
178 public HigherLayeredPool, | 250 public HigherLayeredPool, |
179 public SSLConfigService::Observer { | 251 public SSLConfigService::Observer { |
180 public: | 252 public: |
181 typedef SSLSocketParams SocketParams; | 253 typedef SSLSocketParams SocketParams; |
182 | 254 |
183 // Only the pools that will be used are required. i.e. if you never | 255 // Only the pools that will be used are required. i.e. if you never |
184 // try to create an SSL over SOCKS socket, |socks_pool| may be NULL. | 256 // try to create an SSL over SOCKS socket, |socks_pool| may be NULL. |
185 SSLClientSocketPool( | 257 SSLClientSocketPool(int max_sockets, |
186 int max_sockets, | 258 int max_sockets_per_group, |
187 int max_sockets_per_group, | 259 ClientSocketPoolHistograms* histograms, |
188 ClientSocketPoolHistograms* histograms, | 260 HostResolver* host_resolver, |
189 HostResolver* host_resolver, | 261 CertVerifier* cert_verifier, |
190 CertVerifier* cert_verifier, | 262 ServerBoundCertService* server_bound_cert_service, |
191 ServerBoundCertService* server_bound_cert_service, | 263 TransportSecurityState* transport_security_state, |
192 TransportSecurityState* transport_security_state, | 264 CTVerifier* cert_transparency_verifier, |
193 CTVerifier* cert_transparency_verifier, | 265 const std::string& ssl_session_cache_shard, |
194 const std::string& ssl_session_cache_shard, | 266 ClientSocketFactory* client_socket_factory, |
195 ClientSocketFactory* client_socket_factory, | 267 TransportClientSocketPool* transport_pool, |
196 TransportClientSocketPool* transport_pool, | 268 SOCKSClientSocketPool* socks_pool, |
197 SOCKSClientSocketPool* socks_pool, | 269 HttpProxyClientSocketPool* http_proxy_pool, |
198 HttpProxyClientSocketPool* http_proxy_pool, | 270 SSLConfigService* ssl_config_service, |
199 SSLConfigService* ssl_config_service, | 271 bool enable_ssl_connect_job_waiting, |
200 NetLog* net_log); | 272 NetLog* net_log); |
201 | 273 |
202 virtual ~SSLClientSocketPool(); | 274 virtual ~SSLClientSocketPool(); |
203 | 275 |
204 // ClientSocketPool implementation. | 276 // ClientSocketPool implementation. |
205 virtual int RequestSocket(const std::string& group_name, | 277 virtual int RequestSocket(const std::string& group_name, |
206 const void* connect_params, | 278 const void* connect_params, |
207 RequestPriority priority, | 279 RequestPriority priority, |
208 ClientSocketHandle* handle, | 280 ClientSocketHandle* handle, |
209 const CompletionCallback& callback, | 281 const CompletionCallback& callback, |
210 const BoundNetLog& net_log) OVERRIDE; | 282 const BoundNetLog& net_log) OVERRIDE; |
(...skipping 46 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
257 typedef ClientSocketPoolBase<SSLSocketParams> PoolBase; | 329 typedef ClientSocketPoolBase<SSLSocketParams> PoolBase; |
258 | 330 |
259 // SSLConfigService::Observer implementation. | 331 // SSLConfigService::Observer implementation. |
260 | 332 |
261 // When the user changes the SSL config, we flush all idle sockets so they | 333 // When the user changes the SSL config, we flush all idle sockets so they |
262 // won't get re-used. | 334 // won't get re-used. |
263 virtual void OnSSLConfigChanged() OVERRIDE; | 335 virtual void OnSSLConfigChanged() OVERRIDE; |
264 | 336 |
265 class SSLConnectJobFactory : public PoolBase::ConnectJobFactory { | 337 class SSLConnectJobFactory : public PoolBase::ConnectJobFactory { |
266 public: | 338 public: |
267 SSLConnectJobFactory( | 339 SSLConnectJobFactory(TransportClientSocketPool* transport_pool, |
268 TransportClientSocketPool* transport_pool, | 340 SOCKSClientSocketPool* socks_pool, |
269 SOCKSClientSocketPool* socks_pool, | 341 HttpProxyClientSocketPool* http_proxy_pool, |
270 HttpProxyClientSocketPool* http_proxy_pool, | 342 ClientSocketFactory* client_socket_factory, |
271 ClientSocketFactory* client_socket_factory, | 343 HostResolver* host_resolver, |
272 HostResolver* host_resolver, | 344 const SSLClientSocketContext& context, |
273 const SSLClientSocketContext& context, | 345 bool enable_ssl_connect_job_waiting, |
274 NetLog* net_log); | 346 NetLog* net_log); |
275 | 347 |
276 virtual ~SSLConnectJobFactory() {} | 348 virtual ~SSLConnectJobFactory(); |
277 | 349 |
278 // ClientSocketPoolBase::ConnectJobFactory methods. | 350 // ClientSocketPoolBase::ConnectJobFactory methods. |
279 virtual scoped_ptr<ConnectJob> NewConnectJob( | 351 virtual scoped_ptr<ConnectJob> NewConnectJob( |
280 const std::string& group_name, | 352 const std::string& group_name, |
281 const PoolBase::Request& request, | 353 const PoolBase::Request& request, |
282 ConnectJob::Delegate* delegate) const OVERRIDE; | 354 ConnectJob::Delegate* delegate) const OVERRIDE; |
283 | 355 |
284 virtual base::TimeDelta ConnectionTimeout() const OVERRIDE; | 356 virtual base::TimeDelta ConnectionTimeout() const OVERRIDE; |
285 | 357 |
286 private: | 358 private: |
359 // Maps SSLConnectJob cache keys to SSLConnectJobMessenger objects. | |
360 typedef std::map<std::string, SSLConnectJobMessenger*> MessengerMap; | |
361 | |
287 TransportClientSocketPool* const transport_pool_; | 362 TransportClientSocketPool* const transport_pool_; |
288 SOCKSClientSocketPool* const socks_pool_; | 363 SOCKSClientSocketPool* const socks_pool_; |
289 HttpProxyClientSocketPool* const http_proxy_pool_; | 364 HttpProxyClientSocketPool* const http_proxy_pool_; |
290 ClientSocketFactory* const client_socket_factory_; | 365 ClientSocketFactory* const client_socket_factory_; |
291 HostResolver* const host_resolver_; | 366 HostResolver* const host_resolver_; |
292 const SSLClientSocketContext context_; | 367 const SSLClientSocketContext context_; |
293 base::TimeDelta timeout_; | 368 base::TimeDelta timeout_; |
369 bool enable_ssl_connect_job_waiting_; | |
294 NetLog* net_log_; | 370 NetLog* net_log_; |
371 // TODO(mshelley) Change this to a non-pointer. | |
372 scoped_ptr<MessengerMap> messenger_map_; | |
295 | 373 |
296 DISALLOW_COPY_AND_ASSIGN(SSLConnectJobFactory); | 374 DISALLOW_COPY_AND_ASSIGN(SSLConnectJobFactory); |
297 }; | 375 }; |
298 | 376 |
299 TransportClientSocketPool* const transport_pool_; | 377 TransportClientSocketPool* const transport_pool_; |
300 SOCKSClientSocketPool* const socks_pool_; | 378 SOCKSClientSocketPool* const socks_pool_; |
301 HttpProxyClientSocketPool* const http_proxy_pool_; | 379 HttpProxyClientSocketPool* const http_proxy_pool_; |
302 PoolBase base_; | 380 PoolBase base_; |
303 const scoped_refptr<SSLConfigService> ssl_config_service_; | 381 const scoped_refptr<SSLConfigService> ssl_config_service_; |
304 | 382 |
305 DISALLOW_COPY_AND_ASSIGN(SSLClientSocketPool); | 383 DISALLOW_COPY_AND_ASSIGN(SSLClientSocketPool); |
306 }; | 384 }; |
307 | 385 |
308 } // namespace net | 386 } // namespace net |
309 | 387 |
310 #endif // NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 388 #endif // NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
OLD | NEW |