Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit d6b37fdf authored by Narayan Kamath's avatar Narayan Kamath
Browse files

Allow SSL caches to be installed directly on SSLContexts.

This allows clients to enable ssl session caching without
having to use SSLCertificateSocketFactory.

Change-Id: Id63b8b31f51c96e73beefe9ecc5fd0cf0a1852c6
parent a4558079
Loading
Loading
Loading
Loading
+38 −0
Original line number Diff line number Diff line
@@ -19,12 +19,16 @@ package android.net;
import android.content.Context;
import android.util.Log;

import com.android.org.conscrypt.ClientSessionContext;
import com.android.org.conscrypt.FileClientSessionCache;
import com.android.org.conscrypt.SSLClientSessionCache;

import java.io.File;
import java.io.IOException;

import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLSessionContext;

/**
 * File-based cache of established SSL sessions.  When re-establishing a
 * connection to the same server, using an SSL session cache can save some time,
@@ -37,6 +41,40 @@ public final class SSLSessionCache {
    private static final String TAG = "SSLSessionCache";
    /* package */ final SSLClientSessionCache mSessionCache;

    /**
     * Installs a {@link SSLSessionCache} on a {@link SSLContext}. The cache will
     * be used on all socket factories created by this context (including factories
     * created before this call).
     *
     * @param cache the cache instance to install, or {@code null} to uninstall any
     *         existing cache.
     * @param context the context to install it on.
     * @throws IllegalArgumentException if the context does not support a session
     *         cache.
     *
     * @hide candidate for public API
     */
    public static void install(SSLSessionCache cache, SSLContext context) {
        SSLSessionContext clientContext = context.getClientSessionContext();
        if (clientContext instanceof ClientSessionContext) {
            ((ClientSessionContext) clientContext).setPersistentCache(
                    cache == null ? null : cache.mSessionCache);
        } else {
            throw new IllegalArgumentException("Incompatible SSLContext: " + context);
        }
    }

    /**
     * NOTE: This needs to be Object (and not SSLClientSessionCache) because apps
     * that build directly against the framework (and not the SDK) might not declare
     * a dependency on conscrypt. Javac will then has fail while resolving constructors.
     *
     * @hide For unit test use only
     */
    public SSLSessionCache(Object cache) {
        mSessionCache = (SSLClientSessionCache) cache;
    }

    /**
     * Create a session cache using the specified directory.
     * Individual session entries will be files within the directory.
+108 −0
Original line number Diff line number Diff line
/*
 * Copyright (C) 2013 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License
 */

package android.net;

import com.android.org.conscrypt.ClientSessionContext;
import com.android.org.conscrypt.SSLClientSessionCache;

import com.google.testing.littlemock.LittleMock;

import junit.framework.TestCase;

import java.security.KeyManagementException;
import java.security.SecureRandom;

import javax.net.ssl.KeyManager;
import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLContextSpi;
import javax.net.ssl.SSLEngine;
import javax.net.ssl.SSLServerSocketFactory;
import javax.net.ssl.SSLSessionContext;
import javax.net.ssl.SSLSocketFactory;
import javax.net.ssl.TrustManager;

public class SSLSessionCacheTest extends TestCase {

    public void testInstall_compatibleContext() throws Exception {
        final SSLContext ctx = SSLContext.getDefault();
        final SSLClientSessionCache mock = LittleMock.mock(SSLClientSessionCache.class);
        final ClientSessionContext clientCtx = (ClientSessionContext) ctx.getClientSessionContext();

        try {
            SSLSessionCache.install(new SSLSessionCache(mock), ctx);
            clientCtx.getSession("www.foogle.com", 443);
            LittleMock.verify(mock).getSessionData(LittleMock.anyString(), LittleMock.anyInt());
        } finally {
            // Restore cacheless behaviour.
            SSLSessionCache.install(null, ctx);
            clientCtx.getSession("www.foogle.com", 443);
            LittleMock.verifyNoMoreInteractions(mock);
        }
    }

    public void testInstall_incompatibleContext() {
        try {
            SSLSessionCache.install(
                    new SSLSessionCache(LittleMock.mock(SSLClientSessionCache.class)),
                    new FakeSSLContext());
            fail();
        } catch (IllegalArgumentException expected) {}
    }

    static final class FakeSSLContext extends SSLContext {
        protected FakeSSLContext() {
            super(new FakeSSLContextSpi(), null, "test");
        }
    }

    static final class FakeSSLContextSpi extends SSLContextSpi {
        @Override
        protected void engineInit(KeyManager[] keyManagers, TrustManager[] trustManagers,
                SecureRandom secureRandom) throws KeyManagementException {
        }

        @Override
        protected SSLSocketFactory engineGetSocketFactory() {
            return null;
        }

        @Override
        protected SSLServerSocketFactory engineGetServerSocketFactory() {
            return null;
        }

        @Override
        protected SSLEngine engineCreateSSLEngine(String s, int i) {
            return null;
        }

        @Override
        protected SSLEngine engineCreateSSLEngine() {
            return null;
        }

        @Override
        protected SSLSessionContext engineGetServerSessionContext() {
            return null;
        }

        @Override
        protected SSLSessionContext engineGetClientSessionContext() {
            return LittleMock.mock(SSLSessionContext.class);
        }
    }
}