Supervised user whitelists: Cleanup
[chromium-blink-merge.git] / net / socket / client_socket_pool_manager.cc
blobd89e8f93db1ff5bd7fceb31e14ca5e4beb80d22d
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "net/socket/client_socket_pool_manager.h"
7 #include <string>
9 #include "base/basictypes.h"
10 #include "base/logging.h"
11 #include "base/strings/stringprintf.h"
12 #include "net/base/load_flags.h"
13 #include "net/http/http_proxy_client_socket_pool.h"
14 #include "net/http/http_request_info.h"
15 #include "net/http/http_stream_factory.h"
16 #include "net/proxy/proxy_info.h"
17 #include "net/socket/client_socket_handle.h"
18 #include "net/socket/socks_client_socket_pool.h"
19 #include "net/socket/ssl_client_socket_pool.h"
20 #include "net/socket/transport_client_socket_pool.h"
22 namespace net {
24 namespace {
26 // Limit of sockets of each socket pool.
27 int g_max_sockets_per_pool[] = {
28 256, // NORMAL_SOCKET_POOL
29 256 // WEBSOCKET_SOCKET_POOL
32 static_assert(arraysize(g_max_sockets_per_pool) ==
33 HttpNetworkSession::NUM_SOCKET_POOL_TYPES,
34 "max sockets per pool length mismatch");
36 // Default to allow up to 6 connections per host. Experiment and tuning may
37 // try other values (greater than 0). Too large may cause many problems, such
38 // as home routers blocking the connections!?!? See http://crbug.com/12066.
40 // WebSocket connections are long-lived, and should be treated differently
41 // than normal other connections. 6 connections per group sounded too small
42 // for such use, thus we use a larger limit which was determined somewhat
43 // arbitrarily.
44 // TODO(yutak): Look at the usage and determine the right value after
45 // WebSocket protocol stack starts to work.
46 int g_max_sockets_per_group[] = {
47 6, // NORMAL_SOCKET_POOL
48 30 // WEBSOCKET_SOCKET_POOL
51 static_assert(arraysize(g_max_sockets_per_group) ==
52 HttpNetworkSession::NUM_SOCKET_POOL_TYPES,
53 "max sockets per group length mismatch");
55 // The max number of sockets to allow per proxy server. This applies both to
56 // http and SOCKS proxies. See http://crbug.com/12066 and
57 // http://crbug.com/44501 for details about proxy server connection limits.
58 int g_max_sockets_per_proxy_server[] = {
59 kDefaultMaxSocketsPerProxyServer, // NORMAL_SOCKET_POOL
60 kDefaultMaxSocketsPerProxyServer // WEBSOCKET_SOCKET_POOL
63 static_assert(arraysize(g_max_sockets_per_proxy_server) ==
64 HttpNetworkSession::NUM_SOCKET_POOL_TYPES,
65 "max sockets per proxy server length mismatch");
67 // The meat of the implementation for the InitSocketHandleForHttpRequest,
68 // InitSocketHandleForRawConnect and PreconnectSocketsForHttpRequest methods.
69 int InitSocketPoolHelper(ClientSocketPoolManager::SocketGroupType group_type,
70 const HostPortPair& endpoint,
71 const HttpRequestHeaders& request_extra_headers,
72 int request_load_flags,
73 RequestPriority request_priority,
74 HttpNetworkSession* session,
75 const ProxyInfo& proxy_info,
76 bool want_spdy_over_npn,
77 const SSLConfig& ssl_config_for_origin,
78 const SSLConfig& ssl_config_for_proxy,
79 bool force_tunnel,
80 PrivacyMode privacy_mode,
81 const BoundNetLog& net_log,
82 int num_preconnect_streams,
83 ClientSocketHandle* socket_handle,
84 HttpNetworkSession::SocketPoolType socket_pool_type,
85 const OnHostResolutionCallback& resolution_callback,
86 const CompletionCallback& callback) {
87 scoped_refptr<HttpProxySocketParams> http_proxy_params;
88 scoped_refptr<SOCKSSocketParams> socks_params;
89 scoped_ptr<HostPortPair> proxy_host_port;
91 bool using_ssl = group_type == ClientSocketPoolManager::SSL_GROUP;
92 HostPortPair origin_host_port = endpoint;
94 if (!using_ssl && session->params().testing_fixed_http_port != 0) {
95 origin_host_port.set_port(session->params().testing_fixed_http_port);
96 } else if (using_ssl && session->params().testing_fixed_https_port != 0) {
97 origin_host_port.set_port(session->params().testing_fixed_https_port);
100 bool disable_resolver_cache =
101 request_load_flags & LOAD_BYPASS_CACHE ||
102 request_load_flags & LOAD_VALIDATE_CACHE ||
103 request_load_flags & LOAD_DISABLE_CACHE;
105 int load_flags = request_load_flags;
106 if (session->params().ignore_certificate_errors)
107 load_flags |= LOAD_IGNORE_ALL_CERT_ERRORS;
109 // Build the string used to uniquely identify connections of this type.
110 // Determine the host and port to connect to.
111 std::string connection_group = origin_host_port.ToString();
112 DCHECK(!connection_group.empty());
113 if (group_type == ClientSocketPoolManager::FTP_GROUP) {
114 // Combining FTP with forced SPDY over SSL would be a "path to madness".
115 // Make sure we never do that.
116 DCHECK(!using_ssl);
117 connection_group = "ftp/" + connection_group;
119 if (using_ssl) {
120 // All connections in a group should use the same SSLConfig settings.
121 // Encode version_max in the connection group's name, unless it's the
122 // default version_max. (We want the common case to use the shortest
123 // encoding). A version_max of TLS 1.1 is encoded as "ssl(max:3.2)/"
124 // rather than "tlsv1.1/" because the actual protocol version, which
125 // is selected by the server, may not be TLS 1.1. Do not encode
126 // version_min in the connection group's name because version_min
127 // should be the same for all connections, whereas version_max may
128 // change for version fallbacks.
129 std::string prefix = "ssl/";
130 if (ssl_config_for_origin.version_max !=
131 SSLClientSocket::GetMaxSupportedSSLVersion()) {
132 switch (ssl_config_for_origin.version_max) {
133 case SSL_PROTOCOL_VERSION_TLS1_2:
134 prefix = "ssl(max:3.3)/";
135 break;
136 case SSL_PROTOCOL_VERSION_TLS1_1:
137 prefix = "ssl(max:3.2)/";
138 break;
139 case SSL_PROTOCOL_VERSION_TLS1:
140 prefix = "ssl(max:3.1)/";
141 break;
142 case SSL_PROTOCOL_VERSION_SSL3:
143 prefix = "sslv3/";
144 break;
145 default:
146 CHECK(false);
147 break;
150 // Place sockets with and without deprecated ciphers into separate
151 // connection groups.
152 if (ssl_config_for_origin.enable_deprecated_cipher_suites)
153 prefix += "deprecatedciphers/";
154 connection_group = prefix + connection_group;
157 bool ignore_limits = (request_load_flags & LOAD_IGNORE_LIMITS) != 0;
158 if (!proxy_info.is_direct()) {
159 ProxyServer proxy_server = proxy_info.proxy_server();
160 proxy_host_port.reset(new HostPortPair(proxy_server.host_port_pair()));
161 scoped_refptr<TransportSocketParams> proxy_tcp_params(
162 new TransportSocketParams(
163 *proxy_host_port,
164 disable_resolver_cache,
165 ignore_limits,
166 resolution_callback,
167 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DEFAULT));
169 if (proxy_info.is_http() || proxy_info.is_https()) {
170 std::string user_agent;
171 request_extra_headers.GetHeader(HttpRequestHeaders::kUserAgent,
172 &user_agent);
173 scoped_refptr<SSLSocketParams> ssl_params;
174 if (proxy_info.is_https()) {
175 // Combine connect and write for SSL sockets in TCP FastOpen
176 // field trial.
177 TransportSocketParams::CombineConnectAndWritePolicy
178 combine_connect_and_write =
179 session->params().enable_tcp_fast_open_for_ssl ?
180 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DESIRED :
181 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DEFAULT;
182 proxy_tcp_params = new TransportSocketParams(*proxy_host_port,
183 disable_resolver_cache,
184 ignore_limits,
185 resolution_callback,
186 combine_connect_and_write);
187 // Set ssl_params, and unset proxy_tcp_params
188 ssl_params = new SSLSocketParams(proxy_tcp_params,
189 NULL,
190 NULL,
191 *proxy_host_port.get(),
192 ssl_config_for_proxy,
193 PRIVACY_MODE_DISABLED,
194 load_flags,
195 want_spdy_over_npn);
196 proxy_tcp_params = NULL;
199 http_proxy_params =
200 new HttpProxySocketParams(proxy_tcp_params,
201 ssl_params,
202 user_agent,
203 origin_host_port,
204 session->http_auth_cache(),
205 session->http_auth_handler_factory(),
206 session->spdy_session_pool(),
207 force_tunnel || using_ssl,
208 session->params().proxy_delegate);
209 } else {
210 DCHECK(proxy_info.is_socks());
211 char socks_version;
212 if (proxy_server.scheme() == ProxyServer::SCHEME_SOCKS5)
213 socks_version = '5';
214 else
215 socks_version = '4';
216 connection_group = base::StringPrintf(
217 "socks%c/%s", socks_version, connection_group.c_str());
219 socks_params = new SOCKSSocketParams(proxy_tcp_params,
220 socks_version == '5',
221 origin_host_port);
225 // Change group name if privacy mode is enabled.
226 if (privacy_mode == PRIVACY_MODE_ENABLED)
227 connection_group = "pm/" + connection_group;
229 // Deal with SSL - which layers on top of any given proxy.
230 if (using_ssl) {
231 scoped_refptr<TransportSocketParams> ssl_tcp_params;
232 if (proxy_info.is_direct()) {
233 // Setup TCP params if non-proxied SSL connection.
234 // Combine connect and write for SSL sockets in TCP FastOpen field trial.
235 TransportSocketParams::CombineConnectAndWritePolicy
236 combine_connect_and_write =
237 session->params().enable_tcp_fast_open_for_ssl ?
238 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DESIRED :
239 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DEFAULT;
240 ssl_tcp_params = new TransportSocketParams(origin_host_port,
241 disable_resolver_cache,
242 ignore_limits,
243 resolution_callback,
244 combine_connect_and_write);
246 scoped_refptr<SSLSocketParams> ssl_params =
247 new SSLSocketParams(ssl_tcp_params,
248 socks_params,
249 http_proxy_params,
250 origin_host_port,
251 ssl_config_for_origin,
252 privacy_mode,
253 load_flags,
254 want_spdy_over_npn);
255 SSLClientSocketPool* ssl_pool = NULL;
256 if (proxy_info.is_direct()) {
257 ssl_pool = session->GetSSLSocketPool(socket_pool_type);
258 } else {
259 ssl_pool = session->GetSocketPoolForSSLWithProxy(socket_pool_type,
260 *proxy_host_port);
263 if (num_preconnect_streams) {
264 RequestSocketsForPool(ssl_pool, connection_group, ssl_params,
265 num_preconnect_streams, net_log);
266 return OK;
269 return socket_handle->Init(connection_group, ssl_params,
270 request_priority, callback, ssl_pool,
271 net_log);
274 // Finally, get the connection started.
276 if (proxy_info.is_http() || proxy_info.is_https()) {
277 HttpProxyClientSocketPool* pool =
278 session->GetSocketPoolForHTTPProxy(socket_pool_type, *proxy_host_port);
279 if (num_preconnect_streams) {
280 RequestSocketsForPool(pool, connection_group, http_proxy_params,
281 num_preconnect_streams, net_log);
282 return OK;
285 return socket_handle->Init(connection_group, http_proxy_params,
286 request_priority, callback,
287 pool, net_log);
290 if (proxy_info.is_socks()) {
291 SOCKSClientSocketPool* pool =
292 session->GetSocketPoolForSOCKSProxy(socket_pool_type, *proxy_host_port);
293 if (num_preconnect_streams) {
294 RequestSocketsForPool(pool, connection_group, socks_params,
295 num_preconnect_streams, net_log);
296 return OK;
299 return socket_handle->Init(connection_group, socks_params,
300 request_priority, callback, pool,
301 net_log);
304 DCHECK(proxy_info.is_direct());
305 scoped_refptr<TransportSocketParams> tcp_params =
306 new TransportSocketParams(
307 origin_host_port,
308 disable_resolver_cache,
309 ignore_limits,
310 resolution_callback,
311 TransportSocketParams::COMBINE_CONNECT_AND_WRITE_DEFAULT);
312 TransportClientSocketPool* pool =
313 session->GetTransportSocketPool(socket_pool_type);
314 if (num_preconnect_streams) {
315 RequestSocketsForPool(pool, connection_group, tcp_params,
316 num_preconnect_streams, net_log);
317 return OK;
320 return socket_handle->Init(connection_group, tcp_params,
321 request_priority, callback,
322 pool, net_log);
325 } // namespace
327 ClientSocketPoolManager::ClientSocketPoolManager() {}
328 ClientSocketPoolManager::~ClientSocketPoolManager() {}
330 // static
331 int ClientSocketPoolManager::max_sockets_per_pool(
332 HttpNetworkSession::SocketPoolType pool_type) {
333 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
334 return g_max_sockets_per_pool[pool_type];
337 // static
338 void ClientSocketPoolManager::set_max_sockets_per_pool(
339 HttpNetworkSession::SocketPoolType pool_type,
340 int socket_count) {
341 DCHECK_LT(0, socket_count);
342 DCHECK_GT(1000, socket_count); // Sanity check.
343 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
344 g_max_sockets_per_pool[pool_type] = socket_count;
345 DCHECK_GE(g_max_sockets_per_pool[pool_type],
346 g_max_sockets_per_group[pool_type]);
349 // static
350 int ClientSocketPoolManager::max_sockets_per_group(
351 HttpNetworkSession::SocketPoolType pool_type) {
352 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
353 return g_max_sockets_per_group[pool_type];
356 // static
357 void ClientSocketPoolManager::set_max_sockets_per_group(
358 HttpNetworkSession::SocketPoolType pool_type,
359 int socket_count) {
360 DCHECK_LT(0, socket_count);
361 // The following is a sanity check... but we should NEVER be near this value.
362 DCHECK_GT(100, socket_count);
363 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
364 g_max_sockets_per_group[pool_type] = socket_count;
366 DCHECK_GE(g_max_sockets_per_pool[pool_type],
367 g_max_sockets_per_group[pool_type]);
368 DCHECK_GE(g_max_sockets_per_proxy_server[pool_type],
369 g_max_sockets_per_group[pool_type]);
372 // static
373 int ClientSocketPoolManager::max_sockets_per_proxy_server(
374 HttpNetworkSession::SocketPoolType pool_type) {
375 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
376 return g_max_sockets_per_proxy_server[pool_type];
379 // static
380 void ClientSocketPoolManager::set_max_sockets_per_proxy_server(
381 HttpNetworkSession::SocketPoolType pool_type,
382 int socket_count) {
383 DCHECK_LT(0, socket_count);
384 DCHECK_GT(100, socket_count); // Sanity check.
385 DCHECK_LT(pool_type, HttpNetworkSession::NUM_SOCKET_POOL_TYPES);
386 // Assert this case early on. The max number of sockets per group cannot
387 // exceed the max number of sockets per proxy server.
388 DCHECK_LE(g_max_sockets_per_group[pool_type], socket_count);
389 g_max_sockets_per_proxy_server[pool_type] = socket_count;
392 int InitSocketHandleForHttpRequest(
393 ClientSocketPoolManager::SocketGroupType group_type,
394 const HostPortPair& endpoint,
395 const HttpRequestHeaders& request_extra_headers,
396 int request_load_flags,
397 RequestPriority request_priority,
398 HttpNetworkSession* session,
399 const ProxyInfo& proxy_info,
400 bool want_spdy_over_npn,
401 const SSLConfig& ssl_config_for_origin,
402 const SSLConfig& ssl_config_for_proxy,
403 PrivacyMode privacy_mode,
404 const BoundNetLog& net_log,
405 ClientSocketHandle* socket_handle,
406 const OnHostResolutionCallback& resolution_callback,
407 const CompletionCallback& callback) {
408 DCHECK(socket_handle);
409 return InitSocketPoolHelper(
410 group_type, endpoint, request_extra_headers, request_load_flags,
411 request_priority, session, proxy_info, want_spdy_over_npn,
412 ssl_config_for_origin, ssl_config_for_proxy, /*force_tunnel=*/false,
413 privacy_mode, net_log, 0, socket_handle,
414 HttpNetworkSession::NORMAL_SOCKET_POOL, resolution_callback, callback);
417 int InitSocketHandleForWebSocketRequest(
418 ClientSocketPoolManager::SocketGroupType group_type,
419 const HostPortPair& endpoint,
420 const HttpRequestHeaders& request_extra_headers,
421 int request_load_flags,
422 RequestPriority request_priority,
423 HttpNetworkSession* session,
424 const ProxyInfo& proxy_info,
425 bool want_spdy_over_npn,
426 const SSLConfig& ssl_config_for_origin,
427 const SSLConfig& ssl_config_for_proxy,
428 PrivacyMode privacy_mode,
429 const BoundNetLog& net_log,
430 ClientSocketHandle* socket_handle,
431 const OnHostResolutionCallback& resolution_callback,
432 const CompletionCallback& callback) {
433 DCHECK(socket_handle);
434 return InitSocketPoolHelper(
435 group_type, endpoint, request_extra_headers, request_load_flags,
436 request_priority, session, proxy_info, want_spdy_over_npn,
437 ssl_config_for_origin, ssl_config_for_proxy, /*force_tunnel=*/true,
438 privacy_mode, net_log, 0, socket_handle,
439 HttpNetworkSession::WEBSOCKET_SOCKET_POOL, resolution_callback, callback);
442 int InitSocketHandleForRawConnect(
443 const HostPortPair& host_port_pair,
444 HttpNetworkSession* session,
445 const ProxyInfo& proxy_info,
446 const SSLConfig& ssl_config_for_origin,
447 const SSLConfig& ssl_config_for_proxy,
448 PrivacyMode privacy_mode,
449 const BoundNetLog& net_log,
450 ClientSocketHandle* socket_handle,
451 const CompletionCallback& callback) {
452 DCHECK(socket_handle);
453 HttpRequestHeaders request_extra_headers;
454 int request_load_flags = 0;
455 RequestPriority request_priority = MEDIUM;
456 return InitSocketPoolHelper(
457 ClientSocketPoolManager::NORMAL_GROUP, host_port_pair,
458 request_extra_headers, request_load_flags, request_priority, session,
459 proxy_info, false, ssl_config_for_origin, ssl_config_for_proxy,
460 /*force_tunnel=*/true, privacy_mode, net_log, 0, socket_handle,
461 HttpNetworkSession::NORMAL_SOCKET_POOL, OnHostResolutionCallback(),
462 callback);
465 int InitSocketHandleForTlsConnect(const HostPortPair& endpoint,
466 HttpNetworkSession* session,
467 const ProxyInfo& proxy_info,
468 const SSLConfig& ssl_config_for_origin,
469 const SSLConfig& ssl_config_for_proxy,
470 PrivacyMode privacy_mode,
471 const BoundNetLog& net_log,
472 ClientSocketHandle* socket_handle,
473 const CompletionCallback& callback) {
474 DCHECK(socket_handle);
475 HttpRequestHeaders request_extra_headers;
476 int request_load_flags = 0;
477 RequestPriority request_priority = MEDIUM;
478 return InitSocketPoolHelper(
479 ClientSocketPoolManager::SSL_GROUP, endpoint, request_extra_headers,
480 request_load_flags, request_priority, session, proxy_info,
481 /*want_spdy_over_npn=*/false, ssl_config_for_origin, ssl_config_for_proxy,
482 /*force_tunnel=*/true, privacy_mode, net_log, 0, socket_handle,
483 HttpNetworkSession::NORMAL_SOCKET_POOL, OnHostResolutionCallback(),
484 callback);
487 int PreconnectSocketsForHttpRequest(
488 ClientSocketPoolManager::SocketGroupType group_type,
489 const HostPortPair& endpoint,
490 const HttpRequestHeaders& request_extra_headers,
491 int request_load_flags,
492 RequestPriority request_priority,
493 HttpNetworkSession* session,
494 const ProxyInfo& proxy_info,
495 bool want_spdy_over_npn,
496 const SSLConfig& ssl_config_for_origin,
497 const SSLConfig& ssl_config_for_proxy,
498 PrivacyMode privacy_mode,
499 const BoundNetLog& net_log,
500 int num_preconnect_streams) {
501 return InitSocketPoolHelper(
502 group_type, endpoint, request_extra_headers, request_load_flags,
503 request_priority, session, proxy_info, want_spdy_over_npn,
504 ssl_config_for_origin, ssl_config_for_proxy, /*force_tunnel=*/false,
505 privacy_mode, net_log, num_preconnect_streams, NULL,
506 HttpNetworkSession::NORMAL_SOCKET_POOL, OnHostResolutionCallback(),
507 CompletionCallback());
510 } // namespace net