mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-24 09:27:31 +09:00
Replace NSS with Pale Moon's
This commit is contained in:
parent
ff1e5e48bf
commit
8c2e376f94
2870 changed files with 1762232 additions and 1374220 deletions
|
|
@ -1,4 +1,5 @@
|
|||
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
||||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
|
@ -8,10 +9,12 @@
|
|||
|
||||
#include "prio.h"
|
||||
#include "ssl.h"
|
||||
#include "sslproto.h"
|
||||
|
||||
#include <functional>
|
||||
#include <iostream>
|
||||
|
||||
#include "nss_policy.h"
|
||||
#include "test_io.h"
|
||||
|
||||
#define GTEST_HAS_RTTI 0
|
||||
|
|
@ -36,6 +39,13 @@ enum SessionResumptionMode {
|
|||
RESUME_BOTH = RESUME_SESSIONID | RESUME_TICKET
|
||||
};
|
||||
|
||||
enum class ClientAuthCallbackType {
|
||||
kAsyncImmediate,
|
||||
kAsyncDelay,
|
||||
kSync,
|
||||
kNone,
|
||||
};
|
||||
|
||||
class PacketFilter;
|
||||
class TlsAgent;
|
||||
class TlsCipherSpec;
|
||||
|
|
@ -75,8 +85,9 @@ class TlsAgent : public PollTarget {
|
|||
static const std::string kServerEcdhEcdsa;
|
||||
static const std::string kServerEcdhRsa;
|
||||
static const std::string kServerDsa;
|
||||
static const std::string kDelegatorEcdsa256; // draft-ietf-tls-subcerts
|
||||
static const std::string kDelegatorRsae2048; // draft-ietf-tls-subcerts
|
||||
static const std::string kDelegatorEcdsa256; // draft-ietf-tls-subcerts
|
||||
static const std::string kDelegatorRsae2048; // draft-ietf-tls-subcerts
|
||||
static const std::string kDelegatorRsaPss2048; // draft-ietf-tls-subcerts
|
||||
|
||||
TlsAgent(const std::string& name, Role role, SSLProtocolVariant variant);
|
||||
virtual ~TlsAgent();
|
||||
|
|
@ -140,9 +151,13 @@ class TlsAgent : public PollTarget {
|
|||
bool ConfigServerCertWithChain(const std::string& name);
|
||||
bool EnsureTlsSetup(PRFileDesc* modelSocket = nullptr);
|
||||
|
||||
void SetupClientAuth();
|
||||
void SetupClientAuth(
|
||||
ClientAuthCallbackType callbackType = ClientAuthCallbackType::kSync,
|
||||
bool callbackSuccess = true);
|
||||
void RequestClientAuth(bool requireAuth);
|
||||
|
||||
void ClientAuthCallbackComplete();
|
||||
bool CheckClientAuthCallbacksCompleted(uint8_t expected);
|
||||
void CheckClientAuthCompleted(uint8_t handshakes = 1);
|
||||
void SetOption(int32_t option, int value);
|
||||
void ConfigureSessionCache(SessionResumptionMode mode);
|
||||
void Set0RttEnabled(bool en);
|
||||
|
|
@ -155,6 +170,9 @@ class TlsAgent : public PollTarget {
|
|||
void SetServerKeyBits(uint16_t bits);
|
||||
void ExpectReadWriteError();
|
||||
void EnableFalseStart();
|
||||
void ExpectEch(bool expected = true);
|
||||
bool GetEchExpected() const { return expect_ech_; }
|
||||
void ExpectPsk(SSLPskType psk = ssl_psk_external);
|
||||
void ExpectResumption();
|
||||
void SkipVersionChecks();
|
||||
void SetSignatureSchemes(const SSLSignatureScheme* schemes, size_t count);
|
||||
|
|
@ -174,15 +192,19 @@ class TlsAgent : public PollTarget {
|
|||
// Send data directly to the underlying socket, skipping the TLS layer.
|
||||
void SendDirect(const DataBuffer& buf);
|
||||
void SendRecordDirect(const TlsRecord& record);
|
||||
void AddPsk(const ScopedPK11SymKey& psk, std::string label, SSLHashType hash,
|
||||
uint16_t zeroRttSuite = TLS_NULL_WITH_NULL_NULL);
|
||||
void RemovePsk(std::string label);
|
||||
void ReadBytes(size_t max = 16384U);
|
||||
void ResetSentBytes(); // Hack to test drops.
|
||||
void ResetSentBytes(size_t bytes = 0); // Hack to test drops.
|
||||
void EnableExtendedMasterSecret();
|
||||
void CheckExtendedMasterSecret(bool expected);
|
||||
void CheckEarlyDataAccepted(bool expected);
|
||||
void CheckEchAccepted(bool expected);
|
||||
void SetDowngradeCheckVersion(uint16_t version);
|
||||
void CheckSecretsDestroyed();
|
||||
void ConfigNamedGroups(const std::vector<SSLNamedGroup>& groups);
|
||||
void DisableECDHEServerKeyReuse();
|
||||
void EnableECDHEServerKeyReuse();
|
||||
bool GetPeerChainLength(size_t* count);
|
||||
void CheckCipherSuite(uint16_t cipher_suite);
|
||||
void SetResumptionTokenCallback();
|
||||
|
|
@ -221,7 +243,9 @@ class TlsAgent : public PollTarget {
|
|||
|
||||
static const char* state_str(State state) { return states[state]; }
|
||||
|
||||
PRFileDesc* ssl_fd() const { return ssl_fd_.get(); }
|
||||
NssManagedFileDesc ssl_fd() const {
|
||||
return NssManagedFileDesc(ssl_fd_.get(), policy_, option_);
|
||||
}
|
||||
std::shared_ptr<DummyPrSocket>& adapter() { return adapter_; }
|
||||
|
||||
const SSLChannelInfo& info() const {
|
||||
|
|
@ -246,6 +270,8 @@ class TlsAgent : public PollTarget {
|
|||
return true;
|
||||
}
|
||||
|
||||
void expected_cipher_suite(uint16_t suite) { expected_cipher_suite_ = suite; }
|
||||
|
||||
std::string cipher_suite_name() const {
|
||||
if (state_ != STATE_CONNECTED) return "UNKNOWN";
|
||||
|
||||
|
|
@ -295,6 +321,13 @@ class TlsAgent : public PollTarget {
|
|||
void ExpectSendAlert(uint8_t alert, uint8_t level = 0);
|
||||
|
||||
std::string alpn_value_to_use_ = "";
|
||||
// set the given policy before this agent runs
|
||||
void SetPolicy(SECOidTag oid, PRUint32 set, PRUint32 clear) {
|
||||
policy_ = NssPolicy(oid, set, clear);
|
||||
}
|
||||
void SetNssOption(PRInt32 id, PRInt32 value) {
|
||||
option_ = NssOption(id, value);
|
||||
}
|
||||
|
||||
private:
|
||||
const static char* states[];
|
||||
|
|
@ -416,8 +449,9 @@ class TlsAgent : public PollTarget {
|
|||
bool falsestart_enabled_;
|
||||
uint16_t expected_version_;
|
||||
uint16_t expected_cipher_suite_;
|
||||
bool expect_resumption_;
|
||||
bool expect_client_auth_;
|
||||
bool expect_ech_;
|
||||
SSLPskType expect_psk_;
|
||||
bool can_falsestart_hook_called_;
|
||||
bool sni_hook_called_;
|
||||
bool auth_certificate_hook_called_;
|
||||
|
|
@ -440,6 +474,13 @@ class TlsAgent : public PollTarget {
|
|||
SniCallbackFunction sni_callback_;
|
||||
bool skip_version_checks_;
|
||||
std::vector<uint8_t> resumption_token_;
|
||||
NssPolicy policy_;
|
||||
NssOption option_;
|
||||
ClientAuthCallbackType client_auth_callback_type_ =
|
||||
ClientAuthCallbackType::kNone;
|
||||
bool client_auth_callback_success_ = false;
|
||||
uint8_t client_auth_callback_fired_ = 0;
|
||||
bool client_auth_callback_awaiting_ = false;
|
||||
};
|
||||
|
||||
inline std::ostream& operator<<(std::ostream& stream,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue