Sat, 03 Jan 2015 20:18:00 +0100
Conditionally enable double key logic according to:
private browsing mode or privacy.thirdparty.isolate preference and
implement in GetCookieStringCommon and FindCookie where it counts...
With some reservations of how to convince FindCookie users to test
condition and pass a nullptr when disabling double key logic.
michael@0 | 1 | // Copyright (c) 2012, Google Inc. |
michael@0 | 2 | // All rights reserved. |
michael@0 | 3 | // |
michael@0 | 4 | // Redistribution and use in source and binary forms, with or without |
michael@0 | 5 | // modification, are permitted provided that the following conditions are |
michael@0 | 6 | // met: |
michael@0 | 7 | // |
michael@0 | 8 | // * Redistributions of source code must retain the above copyright |
michael@0 | 9 | // notice, this list of conditions and the following disclaimer. |
michael@0 | 10 | // * Redistributions in binary form must reproduce the above |
michael@0 | 11 | // copyright notice, this list of conditions and the following disclaimer |
michael@0 | 12 | // in the documentation and/or other materials provided with the |
michael@0 | 13 | // distribution. |
michael@0 | 14 | // * Neither the name of Google Inc. nor the names of its |
michael@0 | 15 | // contributors may be used to endorse or promote products derived from |
michael@0 | 16 | // this software without specific prior written permission. |
michael@0 | 17 | // |
michael@0 | 18 | // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
michael@0 | 19 | // "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
michael@0 | 20 | // LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
michael@0 | 21 | // A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
michael@0 | 22 | // OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
michael@0 | 23 | // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
michael@0 | 24 | // LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
michael@0 | 25 | // DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
michael@0 | 26 | // THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
michael@0 | 27 | // (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
michael@0 | 28 | // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
michael@0 | 29 | |
michael@0 | 30 | // Android doesn't provide mkdtemp(). Keep this implementation in an |
michael@0 | 31 | // C++ anonymous namespace to avoid conflicts on Chromium (which |
michael@0 | 32 | // already provides an extern "C" mkdtemp function). |
michael@0 | 33 | // |
michael@0 | 34 | // The reason this is inlined here is to avoid linking a new object file |
michael@0 | 35 | // into each unit test program (i.e. keep build files simple). |
michael@0 | 36 | |
michael@0 | 37 | #ifndef GOOGLE_BREAKPAD_COMMON_ANDROID_TESTING_MKDTEMP_H |
michael@0 | 38 | #define GOOGLE_BREAKPAD_COMMON_ANDROID_TESTING_MKDTEMP_H |
michael@0 | 39 | |
michael@0 | 40 | #include <assert.h> |
michael@0 | 41 | #include <errno.h> |
michael@0 | 42 | #include <stdlib.h> |
michael@0 | 43 | #include <stdio.h> |
michael@0 | 44 | #include <string.h> |
michael@0 | 45 | #include <sys/stat.h> |
michael@0 | 46 | |
michael@0 | 47 | namespace { |
michael@0 | 48 | |
michael@0 | 49 | char* mkdtemp(char* path) { |
michael@0 | 50 | if (path == NULL) { |
michael@0 | 51 | errno = EINVAL; |
michael@0 | 52 | return NULL; |
michael@0 | 53 | } |
michael@0 | 54 | |
michael@0 | 55 | // 'path' must be terminated with six 'X' |
michael@0 | 56 | const char kSuffix[] = "XXXXXX"; |
michael@0 | 57 | const size_t kSuffixLen = strlen(kSuffix); |
michael@0 | 58 | char* path_end = path + strlen(path); |
michael@0 | 59 | |
michael@0 | 60 | if (static_cast<size_t>(path_end - path) < kSuffixLen || |
michael@0 | 61 | memcmp(path_end - kSuffixLen, kSuffix, kSuffixLen) != 0) { |
michael@0 | 62 | errno = EINVAL; |
michael@0 | 63 | return NULL; |
michael@0 | 64 | } |
michael@0 | 65 | |
michael@0 | 66 | // If 'path' contains a directory separator, check that it exists to |
michael@0 | 67 | // avoid looping later. |
michael@0 | 68 | char* sep = strrchr(path, '/'); |
michael@0 | 69 | if (sep != NULL) { |
michael@0 | 70 | struct stat st; |
michael@0 | 71 | int ret; |
michael@0 | 72 | *sep = '\0'; // temporarily zero-terminate the dirname. |
michael@0 | 73 | ret = stat(path, &st); |
michael@0 | 74 | *sep = '/'; // restore full path. |
michael@0 | 75 | if (ret < 0) |
michael@0 | 76 | return NULL; |
michael@0 | 77 | if (!S_ISDIR(st.st_mode)) { |
michael@0 | 78 | errno = ENOTDIR; |
michael@0 | 79 | return NULL; |
michael@0 | 80 | } |
michael@0 | 81 | } |
michael@0 | 82 | |
michael@0 | 83 | // Loop. On each iteration, replace the XXXXXX suffix with a random |
michael@0 | 84 | // number. |
michael@0 | 85 | int tries; |
michael@0 | 86 | for (tries = 128; tries > 0; tries--) { |
michael@0 | 87 | int random = rand() % 1000000; |
michael@0 | 88 | |
michael@0 | 89 | snprintf(path_end - kSuffixLen, kSuffixLen + 1, "%0d", random); |
michael@0 | 90 | if (mkdir(path, 0700) == 0) |
michael@0 | 91 | return path; // Success |
michael@0 | 92 | |
michael@0 | 93 | if (errno != EEXIST) |
michael@0 | 94 | return NULL; |
michael@0 | 95 | } |
michael@0 | 96 | |
michael@0 | 97 | assert(errno == EEXIST); |
michael@0 | 98 | return NULL; |
michael@0 | 99 | } |
michael@0 | 100 | |
michael@0 | 101 | } // namespace |
michael@0 | 102 | |
michael@0 | 103 | #endif // GOOGLE_BREAKPAD_COMMON_ANDROID_TESTING_MKDTEMP_H |