Serialize SSLTokensCache to ssl_tokens_cache.bin so TLS session tickets survive browser restarts, enabling 0-RTT on first connections. A new Rust crate handles zlib-compressed (Adler-32 integrity) bincode serialization and atomic tmp→rename writes. Cert chain data is excluded from the persisted format. The cache writes to disk when the application is backgrounded (covering Android OOM kills), daily when idle, and at graceful shutdown via nsIAsyncShutdownBlocker, keeping all file I/O off the main thread. The background read uses nsAutoLowPriorityIO to yield disk bandwidth to startup-critical reads. Consumed and evicted tokens are removed from the Rust shadow immediately, bounding its memory use independently of write frequency. The cache is always partitioned by top-level site via OriginAttributes, matching cookie-partitioning semantics. CLEAR_TLS_TOKEN_CACHE is part of CLEAR_COOKIES_AND_SITE_DATA and CLEAR_FORGET_ABOUT_SITE. Differential Revision: https://phabricator.services.mozilla.com/D288348
19 lines
713 B
Plaintext
19 lines
713 B
Plaintext
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
#include "nsISupports.idl"
|
|
|
|
/**
|
|
* Test-only interface for SSLTokensCache round-trip tests.
|
|
* Implemented by nsNSSComponent (@mozilla.org/psm;1) when ENABLE_TESTS is set.
|
|
*/
|
|
[scriptable, uuid(7b3c4e2a-1d8f-4a5b-9c6d-2e0f1a3b5c7d)]
|
|
interface nsISSLTokensCacheTest : nsISupports {
|
|
/** Returns the number of distinct cache keys currently in SSLTokensCache. */
|
|
uint32_t countSSLTokens();
|
|
|
|
/** Inserts a dummy token for aKey, for use by clearing tests. */
|
|
void putSSLTokenForTest(in ACString aKey);
|
|
};
|