OLD | NEW |
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 5 #ifndef NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
6 #define NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 6 #define NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
7 | 7 |
| 8 #include <map> |
8 #include <string> | 9 #include <string> |
| 10 #include <vector> |
9 | 11 |
10 #include "base/memory/ref_counted.h" | 12 #include "base/memory/ref_counted.h" |
11 #include "base/memory/scoped_ptr.h" | 13 #include "base/memory/scoped_ptr.h" |
12 #include "base/time/time.h" | 14 #include "base/time/time.h" |
13 #include "net/base/privacy_mode.h" | 15 #include "net/base/privacy_mode.h" |
14 #include "net/dns/host_resolver.h" | 16 #include "net/dns/host_resolver.h" |
15 #include "net/http/http_response_info.h" | 17 #include "net/http/http_response_info.h" |
16 #include "net/socket/client_socket_pool.h" | 18 #include "net/socket/client_socket_pool.h" |
17 #include "net/socket/client_socket_pool_base.h" | 19 #include "net/socket/client_socket_pool_base.h" |
18 #include "net/socket/client_socket_pool_histograms.h" | 20 #include "net/socket/client_socket_pool_histograms.h" |
(...skipping 68 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
87 const SSLConfig ssl_config_; | 89 const SSLConfig ssl_config_; |
88 const PrivacyMode privacy_mode_; | 90 const PrivacyMode privacy_mode_; |
89 const int load_flags_; | 91 const int load_flags_; |
90 const bool force_spdy_over_ssl_; | 92 const bool force_spdy_over_ssl_; |
91 const bool want_spdy_over_npn_; | 93 const bool want_spdy_over_npn_; |
92 bool ignore_limits_; | 94 bool ignore_limits_; |
93 | 95 |
94 DISALLOW_COPY_AND_ASSIGN(SSLSocketParams); | 96 DISALLOW_COPY_AND_ASSIGN(SSLSocketParams); |
95 }; | 97 }; |
96 | 98 |
| 99 // SSLConnectJobMessenger handles communication between concurrent |
| 100 // SSLConnectJobs that share the same SSL session cache key. |
| 101 // |
| 102 // SSLConnectJobMessengers tell the session cache when a certain |
| 103 // connection should be monitored for success or failure, and |
| 104 // tell SSLConnectJobs when to pause or resume their connections. |
| 105 class SSLConnectJobMessenger { |
| 106 public: |
| 107 struct SocketAndCallback { |
| 108 SocketAndCallback(SSLClientSocket* ssl_socket, |
| 109 const base::Closure& job_resumption_callback); |
| 110 ~SocketAndCallback(); |
| 111 |
| 112 SSLClientSocket* socket; |
| 113 base::Closure callback; |
| 114 }; |
| 115 |
| 116 typedef std::vector<SocketAndCallback> SSLPendingSocketsAndCallbacks; |
| 117 |
| 118 SSLConnectJobMessenger(); |
| 119 ~SSLConnectJobMessenger(); |
| 120 |
| 121 // Removes |socket| from the set of sockets being monitored. This |
| 122 // guarantees that |job_resumption_callback| will not be called for |
| 123 // the socket. |
| 124 void RemovePendingSocket(SSLClientSocket* ssl_socket); |
| 125 |
| 126 // Returns true if |ssl_socket|'s Connect() method should be called. |
| 127 bool CanProceed(SSLClientSocket* ssl_socket); |
| 128 |
| 129 // Configures the SSLConnectJobMessenger to begin monitoring |ssl_socket|'s |
| 130 // connection status. After a successful connection, or an error, |
| 131 // the messenger will determine which sockets that have been added |
| 132 // via AddPendingSocket() to allow to proceed. |
| 133 void MonitorConnectionResult(SSLClientSocket* ssl_socket); |
| 134 |
| 135 // Adds |socket| to the list of sockets waiting to Connect(). When |
| 136 // the messenger has determined that it's an appropriate time for |socket| |
| 137 // to connect, it will asynchronously invoke |callback|. |
| 138 // |
| 139 // Note: It is an error to call AddPendingSocket() without having first |
| 140 // called MonitorConnectionResult() and configuring a socket that WILL |
| 141 // have Connect() called on it. |
| 142 void AddPendingSocket(SSLClientSocket* ssl_socket, |
| 143 const base::Closure& callback); |
| 144 |
| 145 private: |
| 146 // Processes pending callbacks when a socket completes its SSL handshake -- |
| 147 // either successfully or unsuccessfully. |
| 148 void OnSSLHandshakeCompleted(); |
| 149 |
| 150 // Runs all callbacks stored in |pending_sockets_and_callbacks_|. |
| 151 void RunAllCallbacks( |
| 152 const SSLPendingSocketsAndCallbacks& pending_socket_and_callbacks); |
| 153 |
| 154 base::WeakPtrFactory<SSLConnectJobMessenger> weak_factory_; |
| 155 |
| 156 SSLPendingSocketsAndCallbacks pending_sockets_and_callbacks_; |
| 157 // Note: this field is a vector to allow for future design changes. Currently, |
| 158 // this vector should only ever have one entry. |
| 159 std::vector<SSLClientSocket*> connecting_sockets_; |
| 160 }; |
| 161 |
97 // SSLConnectJob handles the SSL handshake after setting up the underlying | 162 // SSLConnectJob handles the SSL handshake after setting up the underlying |
98 // connection as specified in the params. | 163 // connection as specified in the params. |
99 class SSLConnectJob : public ConnectJob { | 164 class SSLConnectJob : public ConnectJob { |
100 public: | 165 public: |
101 SSLConnectJob( | 166 // Note: the SSLConnectJob does not own |messenger| so it must outlive the |
102 const std::string& group_name, | 167 // job. |
103 RequestPriority priority, | 168 SSLConnectJob(const std::string& group_name, |
104 const scoped_refptr<SSLSocketParams>& params, | 169 RequestPriority priority, |
105 const base::TimeDelta& timeout_duration, | 170 const scoped_refptr<SSLSocketParams>& params, |
106 TransportClientSocketPool* transport_pool, | 171 const base::TimeDelta& timeout_duration, |
107 SOCKSClientSocketPool* socks_pool, | 172 TransportClientSocketPool* transport_pool, |
108 HttpProxyClientSocketPool* http_proxy_pool, | 173 SOCKSClientSocketPool* socks_pool, |
109 ClientSocketFactory* client_socket_factory, | 174 HttpProxyClientSocketPool* http_proxy_pool, |
110 HostResolver* host_resolver, | 175 ClientSocketFactory* client_socket_factory, |
111 const SSLClientSocketContext& context, | 176 HostResolver* host_resolver, |
112 Delegate* delegate, | 177 const SSLClientSocketContext& context, |
113 NetLog* net_log); | 178 SSLConnectJobMessenger* messenger, |
| 179 Delegate* delegate, |
| 180 NetLog* net_log); |
114 virtual ~SSLConnectJob(); | 181 virtual ~SSLConnectJob(); |
115 | 182 |
116 // ConnectJob methods. | 183 // ConnectJob methods. |
117 virtual LoadState GetLoadState() const OVERRIDE; | 184 virtual LoadState GetLoadState() const OVERRIDE; |
118 | 185 |
119 virtual void GetAdditionalErrorState(ClientSocketHandle * handle) OVERRIDE; | 186 virtual void GetAdditionalErrorState(ClientSocketHandle * handle) OVERRIDE; |
120 | 187 |
121 private: | 188 private: |
122 enum State { | 189 enum State { |
123 STATE_TRANSPORT_CONNECT, | 190 STATE_TRANSPORT_CONNECT, |
124 STATE_TRANSPORT_CONNECT_COMPLETE, | 191 STATE_TRANSPORT_CONNECT_COMPLETE, |
125 STATE_SOCKS_CONNECT, | 192 STATE_SOCKS_CONNECT, |
126 STATE_SOCKS_CONNECT_COMPLETE, | 193 STATE_SOCKS_CONNECT_COMPLETE, |
127 STATE_TUNNEL_CONNECT, | 194 STATE_TUNNEL_CONNECT, |
128 STATE_TUNNEL_CONNECT_COMPLETE, | 195 STATE_TUNNEL_CONNECT_COMPLETE, |
| 196 STATE_CREATE_SSL_SOCKET, |
| 197 STATE_CHECK_FOR_RESUME, |
129 STATE_SSL_CONNECT, | 198 STATE_SSL_CONNECT, |
130 STATE_SSL_CONNECT_COMPLETE, | 199 STATE_SSL_CONNECT_COMPLETE, |
131 STATE_NONE, | 200 STATE_NONE, |
132 }; | 201 }; |
133 | 202 |
134 void OnIOComplete(int result); | 203 void OnIOComplete(int result); |
135 | 204 |
136 // Runs the state transition loop. | 205 // Runs the state transition loop. |
137 int DoLoop(int result); | 206 int DoLoop(int result); |
138 | 207 |
139 int DoTransportConnect(); | 208 int DoTransportConnect(); |
140 int DoTransportConnectComplete(int result); | 209 int DoTransportConnectComplete(int result); |
141 int DoSOCKSConnect(); | 210 int DoSOCKSConnect(); |
142 int DoSOCKSConnectComplete(int result); | 211 int DoSOCKSConnectComplete(int result); |
143 int DoTunnelConnect(); | 212 int DoTunnelConnect(); |
144 int DoTunnelConnectComplete(int result); | 213 int DoTunnelConnectComplete(int result); |
| 214 int DoCreateSSLSocket(); |
| 215 int DoCheckForResume(); |
145 int DoSSLConnect(); | 216 int DoSSLConnect(); |
146 int DoSSLConnectComplete(int result); | 217 int DoSSLConnectComplete(int result); |
147 | 218 |
| 219 // Tells a waiting SSLConnectJob to resume its SSL connection. |
| 220 void ResumeSSLConnection(); |
| 221 |
148 // Returns the initial state for the state machine based on the | 222 // Returns the initial state for the state machine based on the |
149 // |connection_type|. | 223 // |connection_type|. |
150 static State GetInitialState(SSLSocketParams::ConnectionType connection_type); | 224 static State GetInitialState(SSLSocketParams::ConnectionType connection_type); |
151 | 225 |
152 // Starts the SSL connection process. Returns OK on success and | 226 // Starts the SSL connection process. Returns OK on success and |
153 // ERR_IO_PENDING if it cannot immediately service the request. | 227 // ERR_IO_PENDING if it cannot immediately service the request. |
154 // Otherwise, it returns a net error code. | 228 // Otherwise, it returns a net error code. |
155 virtual int ConnectInternal() OVERRIDE; | 229 virtual int ConnectInternal() OVERRIDE; |
156 | 230 |
157 scoped_refptr<SSLSocketParams> params_; | 231 scoped_refptr<SSLSocketParams> params_; |
158 TransportClientSocketPool* const transport_pool_; | 232 TransportClientSocketPool* const transport_pool_; |
159 SOCKSClientSocketPool* const socks_pool_; | 233 SOCKSClientSocketPool* const socks_pool_; |
160 HttpProxyClientSocketPool* const http_proxy_pool_; | 234 HttpProxyClientSocketPool* const http_proxy_pool_; |
161 ClientSocketFactory* const client_socket_factory_; | 235 ClientSocketFactory* const client_socket_factory_; |
162 HostResolver* const host_resolver_; | 236 HostResolver* const host_resolver_; |
163 | 237 |
164 const SSLClientSocketContext context_; | 238 const SSLClientSocketContext context_; |
165 | 239 |
166 State next_state_; | 240 State next_state_; |
167 CompletionCallback callback_; | 241 CompletionCallback io_callback_; |
168 scoped_ptr<ClientSocketHandle> transport_socket_handle_; | 242 scoped_ptr<ClientSocketHandle> transport_socket_handle_; |
169 scoped_ptr<SSLClientSocket> ssl_socket_; | 243 scoped_ptr<SSLClientSocket> ssl_socket_; |
170 | 244 |
| 245 SSLConnectJobMessenger* messenger_; |
171 HttpResponseInfo error_response_info_; | 246 HttpResponseInfo error_response_info_; |
172 | 247 |
| 248 base::WeakPtrFactory<SSLConnectJob> weak_factory_; |
| 249 |
173 DISALLOW_COPY_AND_ASSIGN(SSLConnectJob); | 250 DISALLOW_COPY_AND_ASSIGN(SSLConnectJob); |
174 }; | 251 }; |
175 | 252 |
176 class NET_EXPORT_PRIVATE SSLClientSocketPool | 253 class NET_EXPORT_PRIVATE SSLClientSocketPool |
177 : public ClientSocketPool, | 254 : public ClientSocketPool, |
178 public HigherLayeredPool, | 255 public HigherLayeredPool, |
179 public SSLConfigService::Observer { | 256 public SSLConfigService::Observer { |
180 public: | 257 public: |
181 typedef SSLSocketParams SocketParams; | 258 typedef SSLSocketParams SocketParams; |
182 | 259 |
183 // Only the pools that will be used are required. i.e. if you never | 260 // Only the pools that will be used are required. i.e. if you never |
184 // try to create an SSL over SOCKS socket, |socks_pool| may be NULL. | 261 // try to create an SSL over SOCKS socket, |socks_pool| may be NULL. |
185 SSLClientSocketPool( | 262 SSLClientSocketPool(int max_sockets, |
186 int max_sockets, | 263 int max_sockets_per_group, |
187 int max_sockets_per_group, | 264 ClientSocketPoolHistograms* histograms, |
188 ClientSocketPoolHistograms* histograms, | 265 HostResolver* host_resolver, |
189 HostResolver* host_resolver, | 266 CertVerifier* cert_verifier, |
190 CertVerifier* cert_verifier, | 267 ChannelIDService* channel_id_service, |
191 ChannelIDService* channel_id_service, | 268 TransportSecurityState* transport_security_state, |
192 TransportSecurityState* transport_security_state, | 269 CTVerifier* cert_transparency_verifier, |
193 CTVerifier* cert_transparency_verifier, | 270 const std::string& ssl_session_cache_shard, |
194 const std::string& ssl_session_cache_shard, | 271 ClientSocketFactory* client_socket_factory, |
195 ClientSocketFactory* client_socket_factory, | 272 TransportClientSocketPool* transport_pool, |
196 TransportClientSocketPool* transport_pool, | 273 SOCKSClientSocketPool* socks_pool, |
197 SOCKSClientSocketPool* socks_pool, | 274 HttpProxyClientSocketPool* http_proxy_pool, |
198 HttpProxyClientSocketPool* http_proxy_pool, | 275 SSLConfigService* ssl_config_service, |
199 SSLConfigService* ssl_config_service, | 276 bool enable_ssl_connect_job_waiting, |
200 NetLog* net_log); | 277 NetLog* net_log); |
201 | 278 |
202 virtual ~SSLClientSocketPool(); | 279 virtual ~SSLClientSocketPool(); |
203 | 280 |
204 // ClientSocketPool implementation. | 281 // ClientSocketPool implementation. |
205 virtual int RequestSocket(const std::string& group_name, | 282 virtual int RequestSocket(const std::string& group_name, |
206 const void* connect_params, | 283 const void* connect_params, |
207 RequestPriority priority, | 284 RequestPriority priority, |
208 ClientSocketHandle* handle, | 285 ClientSocketHandle* handle, |
209 const CompletionCallback& callback, | 286 const CompletionCallback& callback, |
210 const BoundNetLog& net_log) OVERRIDE; | 287 const BoundNetLog& net_log) OVERRIDE; |
(...skipping 46 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
257 typedef ClientSocketPoolBase<SSLSocketParams> PoolBase; | 334 typedef ClientSocketPoolBase<SSLSocketParams> PoolBase; |
258 | 335 |
259 // SSLConfigService::Observer implementation. | 336 // SSLConfigService::Observer implementation. |
260 | 337 |
261 // When the user changes the SSL config, we flush all idle sockets so they | 338 // When the user changes the SSL config, we flush all idle sockets so they |
262 // won't get re-used. | 339 // won't get re-used. |
263 virtual void OnSSLConfigChanged() OVERRIDE; | 340 virtual void OnSSLConfigChanged() OVERRIDE; |
264 | 341 |
265 class SSLConnectJobFactory : public PoolBase::ConnectJobFactory { | 342 class SSLConnectJobFactory : public PoolBase::ConnectJobFactory { |
266 public: | 343 public: |
267 SSLConnectJobFactory( | 344 SSLConnectJobFactory(TransportClientSocketPool* transport_pool, |
268 TransportClientSocketPool* transport_pool, | 345 SOCKSClientSocketPool* socks_pool, |
269 SOCKSClientSocketPool* socks_pool, | 346 HttpProxyClientSocketPool* http_proxy_pool, |
270 HttpProxyClientSocketPool* http_proxy_pool, | 347 ClientSocketFactory* client_socket_factory, |
271 ClientSocketFactory* client_socket_factory, | 348 HostResolver* host_resolver, |
272 HostResolver* host_resolver, | 349 const SSLClientSocketContext& context, |
273 const SSLClientSocketContext& context, | 350 bool enable_ssl_connect_job_waiting, |
274 NetLog* net_log); | 351 NetLog* net_log); |
275 | 352 |
276 virtual ~SSLConnectJobFactory() {} | 353 virtual ~SSLConnectJobFactory(); |
277 | 354 |
278 // ClientSocketPoolBase::ConnectJobFactory methods. | 355 // ClientSocketPoolBase::ConnectJobFactory methods. |
279 virtual scoped_ptr<ConnectJob> NewConnectJob( | 356 virtual scoped_ptr<ConnectJob> NewConnectJob( |
280 const std::string& group_name, | 357 const std::string& group_name, |
281 const PoolBase::Request& request, | 358 const PoolBase::Request& request, |
282 ConnectJob::Delegate* delegate) const OVERRIDE; | 359 ConnectJob::Delegate* delegate) const OVERRIDE; |
283 | 360 |
284 virtual base::TimeDelta ConnectionTimeout() const OVERRIDE; | 361 virtual base::TimeDelta ConnectionTimeout() const OVERRIDE; |
285 | 362 |
286 private: | 363 private: |
| 364 // Maps SSLConnectJob cache keys to SSLConnectJobMessenger objects. |
| 365 typedef std::map<std::string, SSLConnectJobMessenger*> MessengerMap; |
| 366 |
287 TransportClientSocketPool* const transport_pool_; | 367 TransportClientSocketPool* const transport_pool_; |
288 SOCKSClientSocketPool* const socks_pool_; | 368 SOCKSClientSocketPool* const socks_pool_; |
289 HttpProxyClientSocketPool* const http_proxy_pool_; | 369 HttpProxyClientSocketPool* const http_proxy_pool_; |
290 ClientSocketFactory* const client_socket_factory_; | 370 ClientSocketFactory* const client_socket_factory_; |
291 HostResolver* const host_resolver_; | 371 HostResolver* const host_resolver_; |
292 const SSLClientSocketContext context_; | 372 const SSLClientSocketContext context_; |
293 base::TimeDelta timeout_; | 373 base::TimeDelta timeout_; |
| 374 bool enable_ssl_connect_job_waiting_; |
294 NetLog* net_log_; | 375 NetLog* net_log_; |
| 376 // |messenger_map_| is currently a pointer so that an element can be |
| 377 // added to it inside of the const method NewConnectJob. In the future, |
| 378 // elements will be added in a different method. |
| 379 // TODO(mshelley) Change this to a non-pointer. |
| 380 scoped_ptr<MessengerMap> messenger_map_; |
295 | 381 |
296 DISALLOW_COPY_AND_ASSIGN(SSLConnectJobFactory); | 382 DISALLOW_COPY_AND_ASSIGN(SSLConnectJobFactory); |
297 }; | 383 }; |
298 | 384 |
299 TransportClientSocketPool* const transport_pool_; | 385 TransportClientSocketPool* const transport_pool_; |
300 SOCKSClientSocketPool* const socks_pool_; | 386 SOCKSClientSocketPool* const socks_pool_; |
301 HttpProxyClientSocketPool* const http_proxy_pool_; | 387 HttpProxyClientSocketPool* const http_proxy_pool_; |
302 PoolBase base_; | 388 PoolBase base_; |
303 const scoped_refptr<SSLConfigService> ssl_config_service_; | 389 const scoped_refptr<SSLConfigService> ssl_config_service_; |
304 | 390 |
305 DISALLOW_COPY_AND_ASSIGN(SSLClientSocketPool); | 391 DISALLOW_COPY_AND_ASSIGN(SSLClientSocketPool); |
306 }; | 392 }; |
307 | 393 |
308 } // namespace net | 394 } // namespace net |
309 | 395 |
310 #endif // NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ | 396 #endif // NET_SOCKET_SSL_CLIENT_SOCKET_POOL_H_ |
OLD | NEW |