Files
sousa-gecko/security/manager/ssl/nsISSLTokensCacheTest.idl
T
Lars Eggert fd3f821ad1 Bug 2024146 - Persist the SSL session token cache across restarts r=valentin,necko-reviewers,keeler,emz
Serialize SSLTokensCache to ssl_tokens_cache.bin so TLS session tickets
survive browser restarts, enabling 0-RTT on first connections. A new Rust
crate handles zlib-compressed (Adler-32 integrity) bincode serialization
and atomic tmp→rename writes. Cert chain data is excluded from the
persisted format.

The cache writes to disk when the application is backgrounded (covering
Android OOM kills), daily when idle, and at graceful shutdown via
nsIAsyncShutdownBlocker, keeping all file I/O off the main thread. The
background read uses nsAutoLowPriorityIO to yield disk bandwidth to
startup-critical reads. Consumed and evicted tokens are removed from the
Rust shadow immediately, bounding its memory use independently of write
frequency.

The cache is always partitioned by top-level site via OriginAttributes,
matching cookie-partitioning semantics. CLEAR_TLS_TOKEN_CACHE is part of
CLEAR_COOKIES_AND_SITE_DATA and CLEAR_FORGET_ABOUT_SITE.

Differential Revision: https://phabricator.services.mozilla.com/D288348
2026-04-10 12:10:36 +00:00

19 lines
713 B
Plaintext

/* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
#include "nsISupports.idl"
/**
* Test-only interface for SSLTokensCache round-trip tests.
* Implemented by nsNSSComponent (@mozilla.org/psm;1) when ENABLE_TESTS is set.
*/
[scriptable, uuid(7b3c4e2a-1d8f-4a5b-9c6d-2e0f1a3b5c7d)]
interface nsISSLTokensCacheTest : nsISupports {
/** Returns the number of distinct cache keys currently in SSLTokensCache. */
uint32_t countSSLTokens();
/** Inserts a dummy token for aKey, for use by clearing tests. */
void putSSLTokenForTest(in ACString aKey);
};