OLD | NEW |
1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "net/ssl/openssl_ssl_util.h" | 5 #include "net/ssl/openssl_ssl_util.h" |
6 | 6 |
7 #include <errno.h> | 7 #include <errno.h> |
8 | 8 |
9 #include <openssl/err.h> | 9 #include <openssl/err.h> |
10 #include <openssl/ssl.h> | 10 #include <openssl/ssl.h> |
11 | 11 |
| 12 #include "base/bind.h" |
12 #include "base/lazy_instance.h" | 13 #include "base/lazy_instance.h" |
13 #include "base/location.h" | 14 #include "base/location.h" |
14 #include "base/logging.h" | 15 #include "base/logging.h" |
| 16 #include "base/values.h" |
15 #include "crypto/openssl_util.h" | 17 #include "crypto/openssl_util.h" |
16 #include "net/base/net_errors.h" | 18 #include "net/base/net_errors.h" |
17 | 19 |
18 namespace net { | 20 namespace net { |
19 | 21 |
20 SslSetClearMask::SslSetClearMask() | 22 SslSetClearMask::SslSetClearMask() |
21 : set_mask(0), | 23 : set_mask(0), |
22 clear_mask(0) { | 24 clear_mask(0) { |
23 } | 25 } |
24 | 26 |
(...skipping 22 matching lines...) Expand all Loading... |
47 unsigned net_error_lib_; | 49 unsigned net_error_lib_; |
48 }; | 50 }; |
49 | 51 |
50 base::LazyInstance<OpenSSLNetErrorLibSingleton>::Leaky g_openssl_net_error_lib = | 52 base::LazyInstance<OpenSSLNetErrorLibSingleton>::Leaky g_openssl_net_error_lib = |
51 LAZY_INSTANCE_INITIALIZER; | 53 LAZY_INSTANCE_INITIALIZER; |
52 | 54 |
53 unsigned OpenSSLNetErrorLib() { | 55 unsigned OpenSSLNetErrorLib() { |
54 return g_openssl_net_error_lib.Get().net_error_lib(); | 56 return g_openssl_net_error_lib.Get().net_error_lib(); |
55 } | 57 } |
56 | 58 |
57 int MapOpenSSLErrorSSL(unsigned long error_code) { | 59 int MapOpenSSLErrorSSL(uint32_t error_code) { |
58 DCHECK_EQ(ERR_LIB_SSL, ERR_GET_LIB(error_code)); | 60 DCHECK_EQ(ERR_LIB_SSL, ERR_GET_LIB(error_code)); |
59 | 61 |
60 DVLOG(1) << "OpenSSL SSL error, reason: " << ERR_GET_REASON(error_code) | 62 DVLOG(1) << "OpenSSL SSL error, reason: " << ERR_GET_REASON(error_code) |
61 << ", name: " << ERR_error_string(error_code, NULL); | 63 << ", name: " << ERR_error_string(error_code, NULL); |
62 switch (ERR_GET_REASON(error_code)) { | 64 switch (ERR_GET_REASON(error_code)) { |
63 case SSL_R_READ_TIMEOUT_EXPIRED: | 65 case SSL_R_READ_TIMEOUT_EXPIRED: |
64 return ERR_TIMED_OUT; | 66 return ERR_TIMED_OUT; |
65 case SSL_R_BAD_RESPONSE_ARGUMENT: | 67 case SSL_R_BAD_RESPONSE_ARGUMENT: |
66 return ERR_INVALID_ARGUMENT; | 68 return ERR_INVALID_ARGUMENT; |
67 case SSL_R_UNKNOWN_CERTIFICATE_TYPE: | 69 case SSL_R_UNKNOWN_CERTIFICATE_TYPE: |
(...skipping 81 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
149 // the leaf certificate changed during a renegotiation. | 151 // the leaf certificate changed during a renegotiation. |
150 return ERR_SSL_SERVER_CERT_CHANGED; | 152 return ERR_SSL_SERVER_CERT_CHANGED; |
151 case SSL_AD_REASON_OFFSET + SSL3_AD_INAPPROPRIATE_FALLBACK: | 153 case SSL_AD_REASON_OFFSET + SSL3_AD_INAPPROPRIATE_FALLBACK: |
152 return ERR_SSL_INAPPROPRIATE_FALLBACK; | 154 return ERR_SSL_INAPPROPRIATE_FALLBACK; |
153 default: | 155 default: |
154 LOG(WARNING) << "Unmapped error reason: " << ERR_GET_REASON(error_code); | 156 LOG(WARNING) << "Unmapped error reason: " << ERR_GET_REASON(error_code); |
155 return ERR_FAILED; | 157 return ERR_FAILED; |
156 } | 158 } |
157 } | 159 } |
158 | 160 |
| 161 base::Value* NetLogOpenSSLErrorCallback(int net_error, |
| 162 int ssl_error, |
| 163 const OpenSSLErrorInfo& error_info, |
| 164 NetLog::LogLevel /* log_level */) { |
| 165 base::DictionaryValue* dict = new base::DictionaryValue(); |
| 166 dict->SetInteger("net_error", net_error); |
| 167 dict->SetInteger("ssl_error", ssl_error); |
| 168 if (error_info.error_code != 0) { |
| 169 dict->SetInteger("error_lib", ERR_GET_LIB(error_info.error_code)); |
| 170 dict->SetInteger("error_reason", ERR_GET_REASON(error_info.error_code)); |
| 171 } |
| 172 if (error_info.file != NULL) |
| 173 dict->SetString("file", error_info.file); |
| 174 if (error_info.line != 0) |
| 175 dict->SetInteger("line", error_info.line); |
| 176 return dict; |
| 177 } |
| 178 |
159 } // namespace | 179 } // namespace |
160 | 180 |
161 void OpenSSLPutNetError(const tracked_objects::Location& location, int err) { | 181 void OpenSSLPutNetError(const tracked_objects::Location& location, int err) { |
162 // Net error codes are negative. Encode them as positive numbers. | 182 // Net error codes are negative. Encode them as positive numbers. |
163 err = -err; | 183 err = -err; |
164 if (err < 0 || err > 0xfff) { | 184 if (err < 0 || err > 0xfff) { |
165 // OpenSSL reserves 12 bits for the reason code. | 185 // OpenSSL reserves 12 bits for the reason code. |
166 NOTREACHED(); | 186 NOTREACHED(); |
167 err = ERR_INVALID_ARGUMENT; | 187 err = ERR_INVALID_ARGUMENT; |
168 } | 188 } |
169 ERR_put_error(OpenSSLNetErrorLib(), 0, err, | 189 ERR_put_error(OpenSSLNetErrorLib(), 0, err, |
170 location.file_name(), location.line_number()); | 190 location.file_name(), location.line_number()); |
171 } | 191 } |
172 | 192 |
173 int MapOpenSSLError(int err, const crypto::OpenSSLErrStackTracer& tracer) { | 193 int MapOpenSSLError(int err, const crypto::OpenSSLErrStackTracer& tracer) { |
| 194 OpenSSLErrorInfo error_info; |
| 195 return MapOpenSSLErrorWithDetails(err, tracer, &error_info); |
| 196 } |
| 197 |
| 198 OpenSSLErrorInfo::OpenSSLErrorInfo() : error_code(0), file(NULL), line(0) {} |
| 199 |
| 200 int MapOpenSSLErrorWithDetails(int err, |
| 201 const crypto::OpenSSLErrStackTracer& tracer, |
| 202 OpenSSLErrorInfo* out_error_info) { |
174 switch (err) { | 203 switch (err) { |
175 case SSL_ERROR_WANT_READ: | 204 case SSL_ERROR_WANT_READ: |
176 case SSL_ERROR_WANT_WRITE: | 205 case SSL_ERROR_WANT_WRITE: |
177 return ERR_IO_PENDING; | 206 return ERR_IO_PENDING; |
178 case SSL_ERROR_SYSCALL: | 207 case SSL_ERROR_SYSCALL: |
179 LOG(ERROR) << "OpenSSL SYSCALL error, earliest error code in " | 208 LOG(ERROR) << "OpenSSL SYSCALL error, earliest error code in " |
180 "error queue: " << ERR_peek_error() << ", errno: " | 209 "error queue: " << ERR_peek_error() << ", errno: " |
181 << errno; | 210 << errno; |
182 return ERR_SSL_PROTOCOL_ERROR; | 211 return ERR_SSL_PROTOCOL_ERROR; |
183 case SSL_ERROR_SSL: | 212 case SSL_ERROR_SSL: |
184 // Walk down the error stack to find an SSL or net error. | 213 // Walk down the error stack to find an SSL or net error. |
185 unsigned long error_code; | 214 uint32_t error_code; |
| 215 const char* file; |
| 216 int line; |
186 do { | 217 do { |
187 error_code = ERR_get_error(); | 218 error_code = ERR_get_error_line(&file, &line); |
188 if (ERR_GET_LIB(error_code) == ERR_LIB_SSL) { | 219 if (ERR_GET_LIB(error_code) == ERR_LIB_SSL) { |
| 220 out_error_info->error_code = error_code; |
| 221 out_error_info->file = file; |
| 222 out_error_info->line = line; |
189 return MapOpenSSLErrorSSL(error_code); | 223 return MapOpenSSLErrorSSL(error_code); |
190 } else if (ERR_GET_LIB(error_code) == OpenSSLNetErrorLib()) { | 224 } else if (ERR_GET_LIB(error_code) == OpenSSLNetErrorLib()) { |
| 225 out_error_info->error_code = error_code; |
| 226 out_error_info->file = file; |
| 227 out_error_info->line = line; |
191 // Net error codes are negative but encoded in OpenSSL as positive | 228 // Net error codes are negative but encoded in OpenSSL as positive |
192 // numbers. | 229 // numbers. |
193 return -ERR_GET_REASON(error_code); | 230 return -ERR_GET_REASON(error_code); |
194 } | 231 } |
195 } while (error_code != 0); | 232 } while (error_code != 0); |
196 return ERR_SSL_PROTOCOL_ERROR; | 233 return ERR_SSL_PROTOCOL_ERROR; |
197 default: | 234 default: |
198 // TODO(joth): Implement full mapping. | 235 // TODO(joth): Implement full mapping. |
199 LOG(WARNING) << "Unknown OpenSSL error " << err; | 236 LOG(WARNING) << "Unknown OpenSSL error " << err; |
200 return ERR_SSL_PROTOCOL_ERROR; | 237 return ERR_SSL_PROTOCOL_ERROR; |
201 } | 238 } |
202 } | 239 } |
203 | 240 |
| 241 NetLog::ParametersCallback CreateNetLogOpenSSLErrorCallback( |
| 242 int net_error, |
| 243 int ssl_error, |
| 244 const OpenSSLErrorInfo& error_info) { |
| 245 return base::Bind(&NetLogOpenSSLErrorCallback, |
| 246 net_error, ssl_error, error_info); |
| 247 } |
| 248 |
204 } // namespace net | 249 } // namespace net |
OLD | NEW |