Synchronize SecurityOrigin related scheme registries with NetworkProcess
[WebKit-https.git] / Source / WebKit / NetworkProcess / NetworkProcess.h
1 /*
2  * Copyright (C) 2012-2018 Apple Inc. All rights reserved.
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  * 1. Redistributions of source code must retain the above copyright
8  *    notice, this list of conditions and the following disclaimer.
9  * 2. Redistributions in binary form must reproduce the above copyright
10  *    notice, this list of conditions and the following disclaimer in the
11  *    documentation and/or other materials provided with the distribution.
12  *
13  * THIS SOFTWARE IS PROVIDED BY APPLE INC. AND ITS CONTRIBUTORS ``AS IS''
14  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
15  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16  * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR ITS CONTRIBUTORS
17  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
18  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
19  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
20  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
21  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
22  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
23  * THE POSSIBILITY OF SUCH DAMAGE.
24  */
25
26 #pragma once
27
28 #include "CacheModel.h"
29 #include "ChildProcess.h"
30 #include "DownloadManager.h"
31 #include "MessageReceiverMap.h"
32 #include <WebCore/DiagnosticLoggingClient.h>
33 #include <memory>
34 #include <pal/SessionID.h>
35 #include <wtf/Forward.h>
36 #include <wtf/Function.h>
37 #include <wtf/HashSet.h>
38 #include <wtf/MemoryPressureHandler.h>
39 #include <wtf/NeverDestroyed.h>
40 #include <wtf/RetainPtr.h>
41 #include <wtf/WeakPtr.h>
42
43 #if PLATFORM(IOS)
44 #include "WebSQLiteDatabaseTracker.h"
45 #endif
46
47 namespace PAL {
48 class SessionID;
49 }
50
51 namespace WebCore {
52 class DownloadID;
53 class CertificateInfo;
54 class NetworkStorageSession;
55 class ProtectionSpace;
56 class SecurityOrigin;
57 struct SecurityOriginData;
58 struct SoupNetworkProxySettings;
59 enum class StoredCredentialsPolicy;
60 class URL;
61 }
62
63 namespace WebKit {
64 class AuthenticationManager;
65 #if ENABLE(SERVER_PRECONNECT)
66 class PreconnectTask;
67 #endif
68 class NetworkConnectionToWebProcess;
69 class NetworkProcessSupplement;
70 class NetworkResourceLoader;
71 enum class WebsiteDataFetchOption;
72 enum class WebsiteDataType;
73 struct NetworkProcessCreationParameters;
74 struct WebsiteDataStoreParameters;
75
76 namespace NetworkCache {
77 class Cache;
78 }
79
80 class NetworkProcess : public ChildProcess, private DownloadManager::Client {
81     WTF_MAKE_NONCOPYABLE(NetworkProcess);
82     friend NeverDestroyed<NetworkProcess>;
83     friend NeverDestroyed<DownloadManager>;
84 public:
85     static NetworkProcess& singleton();
86
87     template <typename T>
88     T* supplement()
89     {
90         return static_cast<T*>(m_supplements.get(T::supplementName()));
91     }
92
93     template <typename T>
94     void addSupplement()
95     {
96         m_supplements.add(T::supplementName(), std::make_unique<T>(*this));
97     }
98
99     void removeNetworkConnectionToWebProcess(NetworkConnectionToWebProcess*);
100
101     AuthenticationManager& authenticationManager();
102     DownloadManager& downloadManager();
103
104     NetworkCache::Cache* cache() { return m_cache.get(); }
105
106     bool canHandleHTTPSServerTrustEvaluation() const { return m_canHandleHTTPSServerTrustEvaluation; }
107
108     void processWillSuspendImminently(bool& handled);
109     void prepareToSuspend();
110     void cancelPrepareToSuspend();
111     void processDidResume();
112
113     // Diagnostic messages logging.
114     void logDiagnosticMessage(uint64_t webPageID, const String& message, const String& description, WebCore::ShouldSample);
115     void logDiagnosticMessageWithResult(uint64_t webPageID, const String& message, const String& description, WebCore::DiagnosticLoggingResultType, WebCore::ShouldSample);
116     void logDiagnosticMessageWithValue(uint64_t webPageID, const String& message, const String& description, double value, unsigned significantFigures, WebCore::ShouldSample);
117
118 #if PLATFORM(COCOA)
119     RetainPtr<CFDataRef> sourceApplicationAuditData() const;
120     void clearHSTSCache(WebCore::NetworkStorageSession&, WallTime modifiedSince);
121 #endif
122
123     void findPendingDownloadLocation(NetworkDataTask&, ResponseCompletionHandler&&, const WebCore::ResourceResponse&);
124
125 #if USE(PROTECTION_SPACE_AUTH_CALLBACK)
126     void canAuthenticateAgainstProtectionSpace(NetworkResourceLoader&, const WebCore::ProtectionSpace&);
127 #if ENABLE(SERVER_PRECONNECT)
128     void canAuthenticateAgainstProtectionSpace(PreconnectTask&, const WebCore::ProtectionSpace&);
129 #endif
130 #endif
131
132     void prefetchDNS(const String&);
133
134     void addWebsiteDataStore(WebsiteDataStoreParameters&&);
135
136     void grantSandboxExtensionsToStorageProcessForBlobs(const Vector<String>& filenames, Function<void ()>&& completionHandler);
137
138 #if HAVE(CFNETWORK_STORAGE_PARTITIONING)
139     void updatePrevalentDomainsToPartitionOrBlockCookies(PAL::SessionID, const Vector<String>& domainsToPartition, const Vector<String>& domainsToBlock, const Vector<String>& domainsToNeitherPartitionNorBlock, bool shouldClearFirst);
140     void hasStorageAccessForFrame(PAL::SessionID, const String& resourceDomain, const String& firstPartyDomain, uint64_t frameID, uint64_t pageID, uint64_t contextId);
141     void getAllStorageAccessEntries(PAL::SessionID, uint64_t contextId);
142     void grantStorageAccess(PAL::SessionID, const String& resourceDomain, const String& firstPartyDomain, std::optional<uint64_t> frameID, uint64_t pageID, uint64_t contextId);
143     void removeAllStorageAccess(PAL::SessionID);
144     void removePrevalentDomains(PAL::SessionID, const Vector<String>& domains);
145 #endif
146
147     Seconds loadThrottleLatency() const { return m_loadThrottleLatency; }
148     String cacheStorageDirectory(PAL::SessionID) const;
149     uint64_t cacheStoragePerOriginQuota() const;
150
151     void preconnectTo(const WebCore::URL&, WebCore::StoredCredentialsPolicy);
152
153 #if HAVE(CFNETWORK_STORAGE_PARTITIONING) && !RELEASE_LOG_DISABLED
154     bool shouldLogCookieInformation() const { return m_logCookieInformation; }
155 #endif
156
157     void setSessionIsControlledByAutomation(PAL::SessionID, bool);
158     bool sessionIsControlledByAutomation(PAL::SessionID) const;
159
160 private:
161     NetworkProcess();
162     ~NetworkProcess();
163
164     void platformInitializeNetworkProcess(const NetworkProcessCreationParameters&);
165
166     void terminate() override;
167     void platformTerminate();
168
169     void lowMemoryHandler(Critical);
170
171     enum class ShouldAcknowledgeWhenReadyToSuspend { No, Yes };
172     void actualPrepareToSuspend(ShouldAcknowledgeWhenReadyToSuspend);
173
174     // ChildProcess
175     void initializeProcess(const ChildProcessInitializationParameters&) override;
176     void initializeProcessName(const ChildProcessInitializationParameters&) override;
177     void initializeSandbox(const ChildProcessInitializationParameters&, SandboxInitializationParameters&) override;
178     void initializeConnection(IPC::Connection*) override;
179     bool shouldTerminate() override;
180
181     // IPC::Connection::Client
182     void didReceiveMessage(IPC::Connection&, IPC::Decoder&) override;
183     void didReceiveSyncMessage(IPC::Connection&, IPC::Decoder&, std::unique_ptr<IPC::Encoder>&) override;
184     void didClose(IPC::Connection&) override;
185
186     // DownloadManager::Client
187     void didCreateDownload() override;
188     void didDestroyDownload() override;
189     IPC::Connection* downloadProxyConnection() override;
190     AuthenticationManager& downloadsAuthenticationManager() override;
191     void pendingDownloadCanceled(DownloadID) override;
192
193     // Message Handlers
194     void didReceiveNetworkProcessMessage(IPC::Connection&, IPC::Decoder&);
195     void didReceiveSyncNetworkProcessMessage(IPC::Connection&, IPC::Decoder&, std::unique_ptr<IPC::Encoder>&);
196     void initializeNetworkProcess(NetworkProcessCreationParameters&&);
197     void createNetworkConnectionToWebProcess();
198     void destroySession(PAL::SessionID);
199
200     void fetchWebsiteData(PAL::SessionID, OptionSet<WebsiteDataType>, OptionSet<WebsiteDataFetchOption>, uint64_t callbackID);
201     void deleteWebsiteData(PAL::SessionID, OptionSet<WebsiteDataType>, WallTime modifiedSince, uint64_t callbackID);
202     void deleteWebsiteDataForOrigins(PAL::SessionID, OptionSet<WebsiteDataType>, const Vector<WebCore::SecurityOriginData>& origins, const Vector<String>& cookieHostNames, uint64_t callbackID);
203
204     void clearCachedCredentials();
205
206     // FIXME: This should take a session ID so we can identify which disk cache to delete.
207     void clearDiskCache(WallTime modifiedSince, Function<void ()>&& completionHandler);
208
209     void downloadRequest(PAL::SessionID, DownloadID, const WebCore::ResourceRequest&, const String& suggestedFilename);
210     void resumeDownload(PAL::SessionID, DownloadID, const IPC::DataReference& resumeData, const String& path, SandboxExtension::Handle&&);
211     void cancelDownload(DownloadID);
212 #if USE(PROTECTION_SPACE_AUTH_CALLBACK)
213     void continueCanAuthenticateAgainstProtectionSpace(uint64_t resourceLoadIdentifier, bool canAuthenticate);
214 #endif
215     void continueWillSendRequest(DownloadID, WebCore::ResourceRequest&&);
216     void continueDecidePendingDownloadDestination(DownloadID, String destination, SandboxExtension::Handle&&, bool allowOverwrite);
217
218     void setCacheModel(uint32_t);
219     void allowSpecificHTTPSCertificateForHost(const WebCore::CertificateInfo&, const String& host);
220     void setCanHandleHTTPSServerTrustEvaluation(bool);
221     void getNetworkProcessStatistics(uint64_t callbackID);
222     void clearCacheForAllOrigins(uint32_t cachesToClear);
223     void setAllowsAnySSLCertificateForWebSocket(bool);
224     void syncAllCookies();
225
226     void didGrantSandboxExtensionsToStorageProcessForBlobs(uint64_t requestID);
227
228     void writeBlobToFilePath(const WebCore::URL&, const String& path, SandboxExtension::Handle&&, uint64_t requestID);
229
230 #if USE(SOUP)
231     void setIgnoreTLSErrors(bool);
232     void userPreferredLanguagesChanged(const Vector<String>&);
233     void setNetworkProxySettings(const WebCore::SoupNetworkProxySettings&);
234 #endif
235
236     // Platform Helpers
237     void platformSetURLCacheSize(unsigned urlCacheMemoryCapacity, uint64_t urlCacheDiskCapacity);
238
239 #if PLATFORM(MAC)
240     static void setSharedHTTPCookieStorage(const Vector<uint8_t>& identifier);
241 #endif
242
243     void registerURLSchemeAsSecure(const String&) const;
244     void registerURLSchemeAsBypassingContentSecurityPolicy(const String&) const;
245     void registerURLSchemeAsLocal(const String&) const;
246     void registerURLSchemeAsNoAccess(const String&) const;
247     void registerURLSchemeAsDisplayIsolated(const String&) const;
248     void registerURLSchemeAsCORSEnabled(const String&) const;
249     void registerURLSchemeAsCanDisplayOnlyIfCanRequest(const String&) const;
250
251     // Connections to WebProcesses.
252     Vector<RefPtr<NetworkConnectionToWebProcess>> m_webProcessConnections;
253
254     String m_cacheStorageDirectory;
255     uint64_t m_cacheStoragePerOriginQuota { 0 };
256     String m_diskCacheDirectory;
257     bool m_hasSetCacheModel;
258     CacheModel m_cacheModel;
259     int64_t m_diskCacheSizeOverride { -1 };
260     bool m_suppressMemoryPressureHandler { false };
261     bool m_diskCacheIsDisabledForTesting;
262     bool m_canHandleHTTPSServerTrustEvaluation;
263     Seconds m_loadThrottleLatency;
264 #if HAVE(CFNETWORK_STORAGE_PARTITIONING) && !RELEASE_LOG_DISABLED
265     bool m_logCookieInformation { false };
266 #endif
267
268     RefPtr<NetworkCache::Cache> m_cache;
269
270     typedef HashMap<const char*, std::unique_ptr<NetworkProcessSupplement>, PtrHash<const char*>> NetworkProcessSupplementMap;
271     NetworkProcessSupplementMap m_supplements;
272
273     HashMap<uint64_t, Function<void ()>> m_sandboxExtensionForBlobsCompletionHandlers;
274     HashMap<uint64_t, Ref<NetworkResourceLoader>> m_waitingNetworkResourceLoaders;
275 #if ENABLE(SERVER_PRECONNECT)
276     HashMap<uint64_t, WeakPtr<PreconnectTask>> m_waitingPreconnectTasks;
277 #endif
278     HashSet<PAL::SessionID> m_sessionsControlledByAutomation;
279
280 #if PLATFORM(COCOA)
281     void platformInitializeNetworkProcessCocoa(const NetworkProcessCreationParameters&);
282     void setCookieStoragePartitioningEnabled(bool);
283     void setStorageAccessAPIEnabled(bool);
284
285     // FIXME: We'd like to be able to do this without the #ifdef, but WorkQueue + BinarySemaphore isn't good enough since
286     // multiple requests to clear the cache can come in before previous requests complete, and we need to wait for all of them.
287     // In the future using WorkQueue and a counting semaphore would work, as would WorkQueue supporting the libdispatch concept of "work groups".
288     dispatch_group_t m_clearCacheDispatchGroup;
289 #endif
290
291 #if PLATFORM(IOS)
292     WebSQLiteDatabaseTracker m_webSQLiteDatabaseTracker;
293 #endif
294 };
295
296 } // namespace WebKit