mirror of
https://github.com/roytam1/palemoon27.git
synced 2026-05-26 14:18:48 +00:00
b0cbe263c6
- Bug 1238964 Part 1: Hold new printable page sizes in print nsIPrintSettingsWin. r=jimm (b5e4d012ba) - Bug 1238964 Part 2: Move separate DEVMODE to nsIPrintSettings copying into nsPrintSettingsWin. r=jimm (cb7bb66037) - Bug 1218029 - Adds SRICheckDataVerifier for progressing data handling. r=francois (8331afc1a7) - Bug 1218029 - Implements progressive Unicode chars decoding in nsScriptLoader. r=djvj (2c32ca259a) - Bug 1237201 part 1 - Use MOZ_ALWAYS_TRUE in nsScriptLoadHandler::TryDecodeRawData. r=yury (8f7496be23) - Bug 1237201 part 2 - Handle Vector OOM in gfx/. r=jrmuizel,kats (d5e8bd3383) - Bug 1237201 part 3 - Handle Vector OOM in StreamingLexer. r=njn (be383e35b4) - Bug 1237201 part 4 - Handle Vector OOM in ipc/. r=billm (fe9a3bf25a) - Bug 1237201 part 5 - Ignore Vector OOM in JSMainRuntimeCompartmentsReporter. r=njn (d0070c0636) - Bug 1237201 part 6 - Handle Vector OOM in media/webrtc/. r=jesup (eab4e00735) - Bug 1186491 - Splitting nsIPerformanceStats in two;r=froydnj (006b578345) - Bug 1186491 - An API for watching slow performance alerts (xpcom-level);r=froydnj (4fcefd66f5) - Bug 1237201 part 7 - Handle Vector OOM in nsPerformanceStats, telemetry. r=Yoric (6021b583ff) - Bug 1237201 part 8 - Make fallible Vector methods MOZ_WARN_UNUSED_RESULT. r=jwalden (90144c2d35) - Bug 1237201 part 9 - Fix remaining issues. r=nfroyd (25b86adb6d) - Bug 1186491 - An API for watching slow performance alerts (js-level); r=felipe (f04d277c80) - Bug 1200172 - AddonWatcher now discards data if the system is apparently too busy/just back from hibernation. r=mossop (66a3840b73) - Bug 1205840 - Typo fixes in AddonWatcher.jsm. r=felipe (760df6764c) - Bug 1186491 - Reworking AddonWatcher to use low-level performance watch API;r=mossop (81cc64263e) - Bug 1200169 - Making the slow add-on watcher more tolerant;r=Felipe (fcf988d985) - Bug 1157009 - Redesign about:performance. r=felipe (cacc590716) - Bug 1189513 - Get rid of separation between e10s and non-e10s probes; r=felipe (7a6d996c93) - Bug 1191327 - Recapitulates alerts in about:performance now. r=felipe (53ecc02da9) - Bug 1189799 - Make sure that about:performance displays each add-on only once (front-end);r=felipe (1ee53a0410) - Bug 1208747 - Move most of Stopwatch-related code to XPCOM-land (JS-level);r=felipe (84af14c20e) - Bug 1229519: Fix miscellaneous parts of toolkit to pass eslint checks. r=MattN (00ce3585c5) - Bug 1230735 - AddonWatcher.alerts is now a map;r=Felipe (81bbafbbd4) - Bug 1241838 - Removing erroneous CPOW suffix, reworking buggy jank suffix;r=Felipe (020d6928e6) - Bug 1175098 - Fix double-loading of PerformanceStats content script. r=mconley (fb1c499343) - Bug 1189799 - Make sure that about:performance displays each add-on only once (back-end);r=felipe (1eac8258df) - Bug 1221761 - Probe.prototype.release() now swallows NS_ERROR_NOT_AVAILABLE. r=felipe (ba1d0032a9) - Bug 1142937 - AddonWatcher now communicates through nsIObserverService. r=felipe (ea2e7ccdaa) - Bug 967873 - Test changes for async removeTab (r=Gijs) (dae5cbf835) - more missing parts of Bug 1132072 - Tab switch refactoring (r=mconley) (dc5e310537) - Bug 1191460 Rebased patch and added userContextId to origin attributes. (r=tanvi,r=sicking) (723999e7fa) - Bug 1239040 - Cleanup of DrawTargetSkia GetBitmapForSurface to use installPixels. r=jrmuizel (4016f4d734) - Bug 1239040 - Cleanup of DrawTargetSkia Mask and MaskSurface. r=jrmuizel (908a44d47e) - Bug 1239040 - Implement PushLayer for DrawTargetSkia. r=Bas (ae74697559) - Bug 1246756 - part 1 - fix moz2d Skia usage for Skia m49 update. r=jrmuizel (5e4b0f41e3) - Bug 1239040 - Allow usage of SkCanvas::getTopDevice in Skia. r=jrmuizel (19bdd2cecb) - Bug 1239040 - Fix DrawTargetCairo/DrawTargetSkia LockBits and BorrowedXlibDrawable to work inside PushLayer. r=jrmuizel (b9ba04009b) - Bug 1239040 - Cleanup of DrawTargetSkia CopySurface to avoid accessing bottom layer directly. r=jrmuizel (6690702507) - Bug 1240437: Implement PushLayer and PopLayer for DrawTargetRecording. r=bas (22673a1b52) - Bug 1220629 - Part 1: Add PushLayer/PopLayer API to DrawTarget baseclass. r=jrmuizel (c4b4315749) - Bug 1220629 - Part 2: Prepare DrawTargetD2D1 for the possibilities of layers existing inside it. r=jrmuizel (f2a74151a8) - Bug 1220629 - Part 3: Implement PushLayer/PopLayer API in cairo. r=jrmuizel (9a52965141) - Bug 1220629 - Part 4: Allow gfxContext to use the native pushlayer implementations based on a pref. r=jrmuizel (f13b773ff3) - Bug 1220629 - Part 5: Implement PushLayer/PopLayer API for Direct2D 1.1. r=jrmuizel (8a040648a2) - Bug 1220629 - Part 6: Implement PushLayer/PopLayer API in several wrapper DT types. r=jrmuizel (cf76723216) - Bug 1220629 - Part 7: Mark several reftests fuzzy. r=jrmuizel (a6deab2300) - Bug 1220629 - Part 8: Enable native PushLayer/PopLayer by default on Windows and Linux. r=jrmuizel (eef18e1e3e) - Bug 1234494 - part 1 - don't build in Skia GPU code if support is disabled, r=jrmuizel (4c74813077) - Bug 1234494 - part 2 - disable Skia GPU support by default on certain *BSDs, r=glandium (6184133b33) - Bug 1246756 - part 2 - update Skia moz.build for m49 update. r=jrmuizel (e0cf4ab953) - Bug 1244454 - Fixed skia compilation on mingw. r=lsalzman (064a56e56e) - Bug 1242044 - "layout/reftests/css-gradients/linear-zero-length-1 fails under Skia content". r=jmuizelaar (bee8f76e72) - Bug 1242751 - fix assertion in SkLinearGradient. r=jmuizelaar (f5df5ed88f) - Bug 1238795 - Fix SkGpuDevice::drawBitmapRect to always update clips. r=jrmuizel (05a9a6b10a) - Bug 1230096 - fix GrAAConvexTessellator assertion. r=jrmuizel (18aef9bdcc) - Bug 1237983 - Investigate and remove the Bagheera Client Implementation. r=gfritzsche (6de39c0e32) - Bug 1246756 - part 3 - update Skia to m49 branch. r=jrmuizel (a02a53e368) - Bug 1234526 - Remove services/healthreport. r=gfritzsche (bb0c567255) - Bug 1234522 - Remove services/datareporting. r=gfritzsche (c7bfec7784) - Bug 1211166 - Use AppConstants in SessionRecorder.jsm r=ted (4434996c34) - Bug 1246756 - Cross compilation fixup. r=upstream (99e3e40ba1) - Bug 1248228 - Build fix for SkOSFile_stdio on OpenBSD. r=jmuizelaar (bbb1eb7ac0) - Bug 1250196 - Part 1: Import mozilla::Forward and mozilla::UniqePtr into the std namespace in a way that is compatible with libc++; r=lsalzman (ffeebcc133) - Bug 1248851 part 4 - Mark UniquePtr::release() MOZ_WARN_UNUSED_RESULT. r=Waldo (f43cced74c) - Bug 1250196 - Part 2: Rename UniquePtr::getDeleter() to get_deleter() in order to make it compatible with std::unique_ptr; r=froydnj (f8aeabfc9a) - Bug 1248851 part 3 - Fix a potential double-free issue in indexedDB. r=sicking (4d13f5047b) - Bug 1248851 part 2 - Remove redundant release() calls in indexedDB code. r=sicking (86d67ffad8) - Bug 1239702 - Fix SK_ARM_HAS_NEON build config r=lsalzman (4233a57122) - Bug 1245979 - make mfbt Function reference-counted so that it can be cheaply copied for compatibility with Skia. r=froydnj (bd69e9c07b) - Bug 1245055 - Remove gfx/skia/Makefile.in. r=mshal (bf2c611f38) - Bug 1232694 - fix typo in Compiler.h; r=botond (2b5abb9d2d) - Bug 1228641 - Rename begin/size to aBegin/aSize to avoid shadow warnings; r=botond (9222809505) - Bug 1248784 - Rename the existing AddRefTraits to ConstRemovingRefPtrTraits. r=froydnj (99d7b0ae1f) - Bug 1248784 - Extract the AddRef/Release calls into a non-inner helper trait. r=froydnj (37243b6235) - Bug 1248784 - Followup to add requested comment. r=froydnj DONTBUILD (0e870b586b) - Bug 1242794 - make SkGrPixelRef::deepCopy preserve alpha type. r=jmuizelaar (0fb454c326) - Bug 1201037 - (Linux) squash network-change events during 1000ms, r=mcmanus (087f57c44d) - Bug 1235509 - Link monitor should not fire link change events for the refresh of the ipv6 lifetime. r=bagder (c507a319c4) - Bug 1234548 - Don't send network change events if routes are changed. r=mcmanus, r=bagder (5cd0bc582e) - Bug 1234548 - Remove unused variables. r=bustage (42df135fbf) - Bug 1240515 - change allocator for addr and localaddr from malloc to new, since the smart pointer that is used uses delete operator. r=dragana (02f5d5433c) - Bug 1241901 part 1 - Remove nsAutoPtr uses in nsNotifyAddrListener on Linux. r=bagder (f8696ad190) - Bug 1241901 part 2 - Use intptr_t to pass bluetooth service class instead of a pointer to heap. r=shawnjohnjr (5c86a164fa) - Bug 1241901 part 3 - Add IsMemberPointer and IsScalar type traits. r=froydnj (80747268bd) - Bug 1243876 - fix ConvertibleTester to not cause incomplete type errors with UniquePtr and Skia. r=nfroyd (c5588dd270) - Bug 1234736 - IonMonkey: Recover Math.imul as an int32 operation. r=h4writer (459b92c618) - Bug 1228571 - Fix GenerateSeed to not leave seed uninitialized if reading from /dev/urandom fails. r=cpeterson (3be0a2816b) - Bug 1233302: Don't crash if we can't open /dev/urandom; just fall back to PRMJ_Now. (d83ae5540a) - Bug 1167248 - Call RtlGenRandom() instead of rand_s() to workaround crashes from injected third-party hooks. r=jandem (678e7a0056) - Bug 1236619 Fix compilation failure with warnings-as-errors with some compilers. r=njn (043956881d) - Bug 1167248 - Cross compilation fixup. (f4a34fb229)
389 lines
13 KiB
C++
389 lines
13 KiB
C++
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
|
/* vim: set ts=8 sts=2 et sw=2 tw=80: */
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
#include "SRICheck.h"
|
|
|
|
#include "mozilla/Base64.h"
|
|
#include "mozilla/Logging.h"
|
|
#include "mozilla/Preferences.h"
|
|
#include "nsContentUtils.h"
|
|
#include "nsIChannel.h"
|
|
#include "nsIDocument.h"
|
|
#include "nsIProtocolHandler.h"
|
|
#include "nsIScriptError.h"
|
|
#include "nsIScriptSecurityManager.h"
|
|
#include "nsIIncrementalStreamLoader.h"
|
|
#include "nsIUnicharStreamLoader.h"
|
|
#include "nsIURI.h"
|
|
#include "nsNetUtil.h"
|
|
#include "nsWhitespaceTokenizer.h"
|
|
|
|
static mozilla::LogModule*
|
|
GetSriLog()
|
|
{
|
|
static mozilla::LazyLogModule gSriPRLog("SRI");
|
|
return gSriPRLog;
|
|
}
|
|
|
|
#define SRILOG(args) MOZ_LOG(GetSriLog(), mozilla::LogLevel::Debug, args)
|
|
#define SRIERROR(args) MOZ_LOG(GetSriLog(), mozilla::LogLevel::Error, args)
|
|
|
|
namespace mozilla {
|
|
namespace dom {
|
|
|
|
/**
|
|
* Returns whether or not the sub-resource about to be loaded is eligible
|
|
* for integrity checks. If it's not, the checks will be skipped and the
|
|
* sub-resource will be loaded.
|
|
*/
|
|
static nsresult
|
|
IsEligible(nsIChannel* aChannel, const CORSMode aCORSMode,
|
|
const nsIDocument* aDocument)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(aDocument);
|
|
|
|
if (!aChannel) {
|
|
SRILOG(("SRICheck::IsEligible, null channel"));
|
|
return NS_ERROR_SRI_NOT_ELIGIBLE;
|
|
}
|
|
|
|
// Was the sub-resource loaded via CORS?
|
|
if (aCORSMode != CORS_NONE) {
|
|
SRILOG(("SRICheck::IsEligible, CORS mode"));
|
|
return NS_OK;
|
|
}
|
|
|
|
nsCOMPtr<nsIURI> finalURI;
|
|
nsresult rv = NS_GetFinalChannelURI(aChannel, getter_AddRefs(finalURI));
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
nsCOMPtr<nsIURI> originalURI;
|
|
rv = aChannel->GetOriginalURI(getter_AddRefs(originalURI));
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
nsAutoCString requestSpec;
|
|
rv = originalURI->GetSpec(requestSpec);
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
if (MOZ_LOG_TEST(GetSriLog(), mozilla::LogLevel::Debug)) {
|
|
nsAutoCString documentSpec, finalSpec;
|
|
aDocument->GetDocumentURI()->GetAsciiSpec(documentSpec);
|
|
if (finalURI) {
|
|
finalURI->GetSpec(finalSpec);
|
|
}
|
|
SRILOG(("SRICheck::IsEligible, documentURI=%s; requestURI=%s; finalURI=%s",
|
|
documentSpec.get(), requestSpec.get(), finalSpec.get()));
|
|
}
|
|
|
|
// Is the sub-resource same-origin?
|
|
nsIScriptSecurityManager* ssm = nsContentUtils::GetSecurityManager();
|
|
if (NS_SUCCEEDED(ssm->CheckSameOriginURI(aDocument->GetDocumentURI(),
|
|
finalURI, false))) {
|
|
SRILOG(("SRICheck::IsEligible, same-origin"));
|
|
return NS_OK;
|
|
}
|
|
SRILOG(("SRICheck::IsEligible, NOT same origin"));
|
|
|
|
NS_ConvertUTF8toUTF16 requestSpecUTF16(requestSpec);
|
|
const char16_t* params[] = { requestSpecUTF16.get() };
|
|
nsContentUtils::ReportToConsole(nsIScriptError::errorFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"IneligibleResource",
|
|
params, ArrayLength(params));
|
|
return NS_ERROR_SRI_NOT_ELIGIBLE;
|
|
}
|
|
|
|
/* static */ nsresult
|
|
SRICheck::IntegrityMetadata(const nsAString& aMetadataList,
|
|
const nsIDocument* aDocument,
|
|
SRIMetadata* outMetadata)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(outMetadata);
|
|
NS_ENSURE_ARG_POINTER(aDocument);
|
|
MOZ_ASSERT(outMetadata->IsEmpty()); // caller must pass empty metadata
|
|
|
|
if (!Preferences::GetBool("security.sri.enable", false)) {
|
|
SRILOG(("SRICheck::IntegrityMetadata, sri is disabled (pref)"));
|
|
return NS_ERROR_SRI_DISABLED;
|
|
}
|
|
|
|
// put a reasonable bound on the length of the metadata
|
|
NS_ConvertUTF16toUTF8 metadataList(aMetadataList);
|
|
if (metadataList.Length() > SRICheck::MAX_METADATA_LENGTH) {
|
|
metadataList.Truncate(SRICheck::MAX_METADATA_LENGTH);
|
|
}
|
|
MOZ_ASSERT(metadataList.Length() <= aMetadataList.Length());
|
|
|
|
// the integrity attribute is a list of whitespace-separated hashes
|
|
// and options so we need to look at them one by one and pick the
|
|
// strongest (valid) one
|
|
nsCWhitespaceTokenizer tokenizer(metadataList);
|
|
nsAutoCString token;
|
|
for (uint32_t i=0; tokenizer.hasMoreTokens() &&
|
|
i < SRICheck::MAX_METADATA_TOKENS; ++i) {
|
|
token = tokenizer.nextToken();
|
|
|
|
SRIMetadata metadata(token);
|
|
if (metadata.IsMalformed()) {
|
|
NS_ConvertUTF8toUTF16 tokenUTF16(token);
|
|
const char16_t* params[] = { tokenUTF16.get() };
|
|
nsContentUtils::ReportToConsole(nsIScriptError::warningFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"MalformedIntegrityHash",
|
|
params, ArrayLength(params));
|
|
} else if (!metadata.IsAlgorithmSupported()) {
|
|
nsAutoCString alg;
|
|
metadata.GetAlgorithm(&alg);
|
|
NS_ConvertUTF8toUTF16 algUTF16(alg);
|
|
const char16_t* params[] = { algUTF16.get() };
|
|
nsContentUtils::ReportToConsole(nsIScriptError::warningFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"UnsupportedHashAlg",
|
|
params, ArrayLength(params));
|
|
}
|
|
|
|
nsAutoCString alg1, alg2;
|
|
if (MOZ_LOG_TEST(GetSriLog(), mozilla::LogLevel::Debug)) {
|
|
outMetadata->GetAlgorithm(&alg1);
|
|
metadata.GetAlgorithm(&alg2);
|
|
}
|
|
if (*outMetadata == metadata) {
|
|
SRILOG(("SRICheck::IntegrityMetadata, alg '%s' is the same as '%s'",
|
|
alg1.get(), alg2.get()));
|
|
*outMetadata += metadata; // add new hash to strongest metadata
|
|
} else if (*outMetadata < metadata) {
|
|
SRILOG(("SRICheck::IntegrityMetadata, alg '%s' is weaker than '%s'",
|
|
alg1.get(), alg2.get()));
|
|
*outMetadata = metadata; // replace strongest metadata with current
|
|
}
|
|
}
|
|
|
|
if (MOZ_LOG_TEST(GetSriLog(), mozilla::LogLevel::Debug)) {
|
|
if (outMetadata->IsValid()) {
|
|
nsAutoCString alg;
|
|
outMetadata->GetAlgorithm(&alg);
|
|
SRILOG(("SRICheck::IntegrityMetadata, using a '%s' hash", alg.get()));
|
|
} else if (outMetadata->IsEmpty()) {
|
|
SRILOG(("SRICheck::IntegrityMetadata, no metadata"));
|
|
} else {
|
|
SRILOG(("SRICheck::IntegrityMetadata, no valid metadata found"));
|
|
}
|
|
}
|
|
return NS_OK;
|
|
}
|
|
|
|
/* static */ nsresult
|
|
SRICheck::VerifyIntegrity(const SRIMetadata& aMetadata,
|
|
nsIUnicharStreamLoader* aLoader,
|
|
const CORSMode aCORSMode,
|
|
const nsAString& aString,
|
|
const nsIDocument* aDocument)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(aLoader);
|
|
|
|
NS_ConvertUTF16toUTF8 utf8Hash(aString);
|
|
nsCOMPtr<nsIChannel> channel;
|
|
aLoader->GetChannel(getter_AddRefs(channel));
|
|
|
|
if (MOZ_LOG_TEST(GetSriLog(), mozilla::LogLevel::Debug)) {
|
|
nsAutoCString requestURL;
|
|
nsCOMPtr<nsIURI> originalURI;
|
|
if (channel &&
|
|
NS_SUCCEEDED(channel->GetOriginalURI(getter_AddRefs(originalURI))) &&
|
|
originalURI) {
|
|
originalURI->GetAsciiSpec(requestURL);
|
|
}
|
|
SRILOG(("SRICheck::VerifyIntegrity (unichar stream)"));
|
|
}
|
|
|
|
SRICheckDataVerifier verifier(aMetadata, aDocument);
|
|
nsresult rv;
|
|
rv = verifier.Update(utf8Hash.Length(), (uint8_t*)utf8Hash.get());
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
return verifier.Verify(aMetadata, channel, aCORSMode, aDocument);
|
|
}
|
|
|
|
//////////////////////////////////////////////////////////////
|
|
//
|
|
//////////////////////////////////////////////////////////////
|
|
SRICheckDataVerifier::SRICheckDataVerifier(const SRIMetadata& aMetadata,
|
|
const nsIDocument* aDocument)
|
|
: mCryptoHash(nullptr),
|
|
mBytesHashed(0),
|
|
mInvalidMetadata(false),
|
|
mComplete(false)
|
|
{
|
|
MOZ_ASSERT(!aMetadata.IsEmpty()); // should be checked by caller
|
|
|
|
// IntegrityMetadata() checks this and returns "no metadata" if
|
|
// it's disabled so we should never make it this far
|
|
MOZ_ASSERT(Preferences::GetBool("security.sri.enable", false));
|
|
|
|
if (!aMetadata.IsValid()) {
|
|
nsContentUtils::ReportToConsole(nsIScriptError::warningFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"NoValidMetadata");
|
|
mInvalidMetadata = true;
|
|
return; // ignore invalid metadata for forward-compatibility
|
|
}
|
|
|
|
uint32_t hashLength;
|
|
aMetadata.GetHashType(&mHashType, &hashLength);
|
|
}
|
|
|
|
nsresult
|
|
SRICheckDataVerifier::EnsureCryptoHash()
|
|
{
|
|
MOZ_ASSERT(!mInvalidMetadata);
|
|
|
|
if (mCryptoHash) {
|
|
return NS_OK;
|
|
}
|
|
|
|
nsresult rv;
|
|
nsCOMPtr<nsICryptoHash> cryptoHash =
|
|
do_CreateInstance("@mozilla.org/security/hash;1", &rv);
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
rv = cryptoHash->Init(mHashType);
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
mCryptoHash = cryptoHash;
|
|
return NS_OK;
|
|
}
|
|
|
|
nsresult
|
|
SRICheckDataVerifier::Update(uint32_t aStringLen, const uint8_t* aString)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(aString);
|
|
if (mInvalidMetadata) {
|
|
return NS_OK; // ignoring any data updates, see mInvalidMetadata usage
|
|
}
|
|
|
|
nsresult rv;
|
|
rv = EnsureCryptoHash();
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
mBytesHashed += aStringLen;
|
|
|
|
return mCryptoHash->Update(aString, aStringLen);
|
|
}
|
|
|
|
nsresult
|
|
SRICheckDataVerifier::Finish()
|
|
{
|
|
if (mInvalidMetadata || mComplete) {
|
|
return NS_OK; // already finished or invalid metadata
|
|
}
|
|
|
|
nsresult rv;
|
|
rv = EnsureCryptoHash(); // we need computed hash even for 0-length data
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
rv = mCryptoHash->Finish(false, mComputedHash);
|
|
mCryptoHash = nullptr;
|
|
mComplete = true;
|
|
return rv;
|
|
}
|
|
|
|
nsresult
|
|
SRICheckDataVerifier::VerifyHash(const SRIMetadata& aMetadata,
|
|
uint32_t aHashIndex,
|
|
const nsIDocument* aDocument)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(aDocument);
|
|
|
|
nsAutoCString base64Hash;
|
|
aMetadata.GetHash(aHashIndex, &base64Hash);
|
|
SRILOG(("SRICheckDataVerifier::VerifyHash, hash[%u]=%s", aHashIndex, base64Hash.get()));
|
|
|
|
nsAutoCString binaryHash;
|
|
if (NS_WARN_IF(NS_FAILED(Base64Decode(base64Hash, binaryHash)))) {
|
|
nsContentUtils::ReportToConsole(nsIScriptError::errorFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"InvalidIntegrityBase64");
|
|
return NS_ERROR_SRI_CORRUPT;
|
|
}
|
|
|
|
uint32_t hashLength;
|
|
int8_t hashType;
|
|
aMetadata.GetHashType(&hashType, &hashLength);
|
|
if (binaryHash.Length() != hashLength) {
|
|
nsContentUtils::ReportToConsole(nsIScriptError::errorFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"InvalidIntegrityLength");
|
|
return NS_ERROR_SRI_CORRUPT;
|
|
}
|
|
|
|
if (!binaryHash.Equals(mComputedHash)) {
|
|
SRILOG(("SRICheckDataVerifier::VerifyHash, hash[%u] did not match", aHashIndex));
|
|
return NS_ERROR_SRI_CORRUPT;
|
|
}
|
|
|
|
SRILOG(("SRICheckDataVerifier::VerifyHash, hash[%u] verified successfully", aHashIndex));
|
|
return NS_OK;
|
|
}
|
|
|
|
nsresult
|
|
SRICheckDataVerifier::Verify(const SRIMetadata& aMetadata,
|
|
nsIChannel* aChannel,
|
|
const CORSMode aCORSMode,
|
|
const nsIDocument* aDocument)
|
|
{
|
|
NS_ENSURE_ARG_POINTER(aDocument);
|
|
|
|
if (MOZ_LOG_TEST(GetSriLog(), mozilla::LogLevel::Debug)) {
|
|
nsAutoCString requestURL;
|
|
nsCOMPtr<nsIRequest> request;
|
|
request = do_QueryInterface(aChannel);
|
|
request->GetName(requestURL);
|
|
SRILOG(("SRICheckDataVerifier::Verify, url=%s (length=%lu)",
|
|
requestURL.get(), mBytesHashed));
|
|
}
|
|
|
|
nsresult rv = Finish();
|
|
NS_ENSURE_SUCCESS(rv, rv);
|
|
|
|
if (NS_FAILED(IsEligible(aChannel, aCORSMode, aDocument))) {
|
|
return NS_ERROR_SRI_NOT_ELIGIBLE;
|
|
}
|
|
|
|
if (mInvalidMetadata) {
|
|
return NS_OK; // ignore invalid metadata for forward-compatibility
|
|
}
|
|
|
|
for (uint32_t i = 0; i < aMetadata.HashCount(); i++) {
|
|
if (NS_SUCCEEDED(VerifyHash(aMetadata, i, aDocument))) {
|
|
return NS_OK; // stop at the first valid hash
|
|
}
|
|
}
|
|
|
|
nsAutoCString alg;
|
|
aMetadata.GetAlgorithm(&alg);
|
|
NS_ConvertUTF8toUTF16 algUTF16(alg);
|
|
const char16_t* params[] = { algUTF16.get() };
|
|
nsContentUtils::ReportToConsole(nsIScriptError::errorFlag,
|
|
NS_LITERAL_CSTRING("Sub-resource Integrity"),
|
|
aDocument,
|
|
nsContentUtils::eSECURITY_PROPERTIES,
|
|
"IntegrityMismatch",
|
|
params, ArrayLength(params));
|
|
return NS_ERROR_SRI_CORRUPT;
|
|
}
|
|
|
|
} // namespace dom
|
|
} // namespace mozilla
|