mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 11:57:32 +09:00
Merge remote-tracking branch 'origin/tracking' into custom
This commit is contained in:
commit
6de07653b9
368 changed files with 144 additions and 46366 deletions
|
|
@ -434,8 +434,7 @@ CertVerifier::VerifyCert(CERTCertificate* cert, SECCertificateUsage usage,
|
|||
// chosen by the server.
|
||||
|
||||
// These configurations are in order of most restrictive to least
|
||||
// restrictive. This enables us to gather telemetry on the expected
|
||||
// results of setting the default policy to a particular configuration.
|
||||
// restrictive.
|
||||
SHA1Mode sha1ModeConfigurations[] = {
|
||||
SHA1Mode::Forbidden,
|
||||
SHA1Mode::ImportedRoot,
|
||||
|
|
@ -474,8 +473,7 @@ CertVerifier::VerifyCert(CERTCertificate* cert, SECCertificateUsage usage,
|
|||
// (mSHA1Mode) is more restrictive than the SHA1 mode option we're on.
|
||||
// (To put it another way, only attempt verification if the SHA1 mode
|
||||
// option we're on is as restrictive or more restrictive than
|
||||
// mSHA1Mode.) This allows us to gather telemetry information while
|
||||
// still enforcing the mode set by preferences.
|
||||
// mSHA1Mode.)
|
||||
if (SHA1ModeMoreRestrictiveThanGivenMode(sha1ModeConfigurations[i])) {
|
||||
continue;
|
||||
}
|
||||
|
|
@ -555,8 +553,7 @@ CertVerifier::VerifyCert(CERTCertificate* cert, SECCertificateUsage usage,
|
|||
// (mSHA1Mode) is more restrictive than the SHA1 mode option we're on.
|
||||
// (To put it another way, only attempt verification if the SHA1 mode
|
||||
// option we're on is as restrictive or more restrictive than
|
||||
// mSHA1Mode.) This allows us to gather telemetry information while
|
||||
// still enforcing the mode set by preferences.
|
||||
// mSHA1Mode.)
|
||||
if (SHA1ModeMoreRestrictiveThanGivenMode(sha1ModeConfigurations[j])) {
|
||||
continue;
|
||||
}
|
||||
|
|
@ -612,10 +609,6 @@ CertVerifier::VerifyCert(CERTCertificate* cert, SECCertificateUsage usage,
|
|||
if (keySizeStatus) {
|
||||
*keySizeStatus = KeySizeStatus::AlreadyBad;
|
||||
}
|
||||
// The telemetry probe CERT_CHAIN_SHA1_POLICY_STATUS gives us feedback on
|
||||
// the result of setting a specific policy. However, we don't want noise
|
||||
// from users who have manually set the policy to something other than the
|
||||
// default, so we only collect for ImportedRoot (which is the default).
|
||||
if (sha1ModeResult && mSHA1Mode == SHA1Mode::ImportedRoot) {
|
||||
*sha1ModeResult = SHA1ModeResult::Failed;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -44,7 +44,6 @@ namespace mozilla { namespace psm {
|
|||
|
||||
typedef mozilla::pkix::Result Result;
|
||||
|
||||
// These values correspond to the CERT_CHAIN_KEY_SIZE_STATUS telemetry.
|
||||
enum class KeySizeStatus {
|
||||
NeverChecked = 0,
|
||||
LargeMinimumSucceeded = 1,
|
||||
|
|
@ -52,7 +51,6 @@ enum class KeySizeStatus {
|
|||
AlreadyBad = 3,
|
||||
};
|
||||
|
||||
// These values correspond to the CERT_CHAIN_SHA1_POLICY_STATUS telemetry.
|
||||
enum class SHA1ModeResult {
|
||||
NeverChecked = 0,
|
||||
SucceededWithoutSHA1 = 1,
|
||||
|
|
@ -92,7 +90,6 @@ public:
|
|||
// TLS feature request_status should be ignored
|
||||
static const Flags FLAG_TLS_IGNORE_STATUS_REQUEST;
|
||||
|
||||
// These values correspond to the SSL_OCSP_STAPLING telemetry.
|
||||
enum OCSPStaplingStatus {
|
||||
OCSP_STAPLING_NEVER_CHECKED = 0,
|
||||
OCSP_STAPLING_GOOD = 1,
|
||||
|
|
|
|||
|
|
@ -57,7 +57,7 @@ OCSPVerificationTrustDomain::CheckSignatureDigestAlgorithm(
|
|||
// The reason for wrapping the NSSCertDBTrustDomain in an
|
||||
// OCSPVerificationTrustDomain is to allow us to bypass the weaker signature
|
||||
// algorithm check - thus all allowable signature digest algorithms should
|
||||
// always be accepted. This is only needed while we gather telemetry on SHA-1.
|
||||
// always be accepted.
|
||||
return Success;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -11,7 +11,6 @@
|
|||
#include "mozilla/dom/ContentParent.h"
|
||||
#include "mozilla/Preferences.h"
|
||||
#include "mozilla/Services.h"
|
||||
#include "mozilla/Telemetry.h"
|
||||
#include "mozilla/Unused.h"
|
||||
#include "nsAppDirectoryServiceDefs.h"
|
||||
#include "nsDirectoryServiceUtils.h"
|
||||
|
|
|
|||
|
|
@ -8,7 +8,6 @@
|
|||
#include "NSSCertDBTrustDomain.h"
|
||||
#include "ScopedNSSTypes.h"
|
||||
#include "SharedSSLState.h"
|
||||
#include "mozilla/Telemetry.h"
|
||||
#include "nsAppDirectoryServiceDefs.h"
|
||||
#include "nsCRT.h"
|
||||
#include "nsILineInputStream.h"
|
||||
|
|
@ -150,7 +149,6 @@ nsCertOverrideService::Observe(nsISupports *,
|
|||
mSettingsFile = nullptr;
|
||||
}
|
||||
Read();
|
||||
CountPermanentOverrideTelemetry();
|
||||
}
|
||||
|
||||
return NS_OK;
|
||||
|
|
@ -597,20 +595,6 @@ nsCertOverrideService::ClearValidityOverride(const nsACString & aHostName, int32
|
|||
return NS_OK;
|
||||
}
|
||||
|
||||
void
|
||||
nsCertOverrideService::CountPermanentOverrideTelemetry()
|
||||
{
|
||||
ReentrantMonitorAutoEnter lock(monitor);
|
||||
uint32_t overrideCount = 0;
|
||||
for (auto iter = mSettingsTable.Iter(); !iter.Done(); iter.Next()) {
|
||||
if (!iter.Get()->mSettings.mIsTemporary) {
|
||||
overrideCount++;
|
||||
}
|
||||
}
|
||||
Telemetry::Accumulate(Telemetry::SSL_PERMANENT_CERT_ERROR_OVERRIDES,
|
||||
overrideCount);
|
||||
}
|
||||
|
||||
static bool
|
||||
matchesDBKey(nsIX509Cert* cert, const nsCString& matchDbKey)
|
||||
{
|
||||
|
|
|
|||
|
|
@ -163,8 +163,6 @@ protected:
|
|||
SECOidTag mOidTagForStoringNewHashes;
|
||||
nsCString mDottedOidForStoringNewHashes;
|
||||
|
||||
void CountPermanentOverrideTelemetry();
|
||||
|
||||
void RemoveAllFromMemory();
|
||||
nsresult Read();
|
||||
nsresult Write();
|
||||
|
|
|
|||
|
|
@ -41,7 +41,6 @@ extern LazyLogModule gPIPNSSLog;
|
|||
|
||||
namespace {
|
||||
|
||||
// Bits in bit mask for SSL_REASONS_FOR_NOT_FALSE_STARTING telemetry probe
|
||||
// These bits are numbered so that the least subtle issues have higher values.
|
||||
// This should make it easier for us to interpret the results.
|
||||
const uint32_t NPN_NOT_NEGOTIATED = 64;
|
||||
|
|
|
|||
|
|
@ -1,4 +1,3 @@
|
|||
/* vim:set ts=2 sw=2 et cindent: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
|
@ -17,7 +16,6 @@
|
|||
#include "mozilla/Logging.h"
|
||||
#include "mozilla/Preferences.h"
|
||||
#include "mozilla/Sprintf.h"
|
||||
#include "mozilla/Telemetry.h"
|
||||
#include "nsCOMPtr.h"
|
||||
#include "nsComponentManagerUtils.h"
|
||||
#include "nsICryptoHMAC.h"
|
||||
|
|
@ -1007,11 +1005,6 @@ nsNTLMAuthModule::Init(const char *serviceName,
|
|||
mPassword = password;
|
||||
mNTLMNegotiateSent = false;
|
||||
|
||||
static bool sTelemetrySent = false;
|
||||
if (!sTelemetrySent) {
|
||||
sTelemetrySent = true;
|
||||
}
|
||||
|
||||
return NS_OK;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -8,7 +8,6 @@
|
|||
|
||||
#include "mozilla/Casting.h"
|
||||
#include "mozilla/Logging.h"
|
||||
#include "mozilla/Telemetry.h"
|
||||
#include "mozilla/Unused.h"
|
||||
#include "nsCOMPtr.h"
|
||||
#include "nsIMutableArray.h"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue