Upstream version 8.37.180.0
[platform/framework/web/crosswalk.git] / src / content / browser / loader / resource_dispatcher_host_impl.cc
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4
5 // See http://dev.chromium.org/developers/design-documents/multi-process-resource-loading
6
7 #include "content/browser/loader/resource_dispatcher_host_impl.h"
8
9 #include <algorithm>
10 #include <set>
11 #include <vector>
12
13 #include "base/bind.h"
14 #include "base/bind_helpers.h"
15 #include "base/command_line.h"
16 #include "base/compiler_specific.h"
17 #include "base/debug/alias.h"
18 #include "base/logging.h"
19 #include "base/memory/scoped_ptr.h"
20 #include "base/memory/shared_memory.h"
21 #include "base/message_loop/message_loop.h"
22 #include "base/metrics/histogram.h"
23 #include "base/metrics/sparse_histogram.h"
24 #include "base/stl_util.h"
25 #include "base/third_party/dynamic_annotations/dynamic_annotations.h"
26 #include "content/browser/appcache/appcache_interceptor.h"
27 #include "content/browser/appcache/chrome_appcache_service.h"
28 #include "content/browser/cert_store_impl.h"
29 #include "content/browser/child_process_security_policy_impl.h"
30 #include "content/browser/cross_site_request_manager.h"
31 #include "content/browser/download/download_resource_handler.h"
32 #include "content/browser/download/save_file_manager.h"
33 #include "content/browser/download/save_file_resource_handler.h"
34 #include "content/browser/fileapi/chrome_blob_storage_context.h"
35 #include "content/browser/loader/async_resource_handler.h"
36 #include "content/browser/loader/buffered_resource_handler.h"
37 #include "content/browser/loader/cross_site_resource_handler.h"
38 #include "content/browser/loader/detachable_resource_handler.h"
39 #include "content/browser/loader/power_save_block_resource_throttle.h"
40 #include "content/browser/loader/redirect_to_file_resource_handler.h"
41 #include "content/browser/loader/resource_message_filter.h"
42 #include "content/browser/loader/resource_request_info_impl.h"
43 #include "content/browser/loader/stream_resource_handler.h"
44 #include "content/browser/loader/sync_resource_handler.h"
45 #include "content/browser/loader/throttling_resource_handler.h"
46 #include "content/browser/loader/upload_data_stream_builder.h"
47 #include "content/browser/plugin_service_impl.h"
48 #include "content/browser/renderer_host/render_view_host_delegate.h"
49 #include "content/browser/renderer_host/render_view_host_impl.h"
50 #include "content/browser/resource_context_impl.h"
51 #include "content/browser/service_worker/service_worker_request_handler.h"
52 #include "content/browser/streams/stream.h"
53 #include "content/browser/streams/stream_context.h"
54 #include "content/browser/streams/stream_registry.h"
55 #include "content/browser/worker_host/worker_service_impl.h"
56 #include "content/browser/web_contents/web_contents_impl.h"
57 #include "content/common/resource_messages.h"
58 #include "content/common/resource_request_body.h"
59 #include "content/common/ssl_status_serialization.h"
60 #include "content/common/view_messages.h"
61 #include "content/public/browser/browser_thread.h"
62 #include "content/public/browser/content_browser_client.h"
63 #include "content/public/browser/download_manager.h"
64 #include "content/public/browser/download_url_parameters.h"
65 #include "content/public/browser/global_request_id.h"
66 #include "content/public/browser/resource_dispatcher_host_delegate.h"
67 #include "content/public/browser/resource_request_details.h"
68 #include "content/public/browser/resource_throttle.h"
69 #include "content/public/browser/stream_handle.h"
70 #include "content/public/browser/user_metrics.h"
71 #include "content/public/common/content_switches.h"
72 #include "content/public/common/process_type.h"
73 #include "ipc/ipc_message_macros.h"
74 #include "ipc/ipc_message_start.h"
75 #include "net/base/auth.h"
76 #include "net/base/load_flags.h"
77 #include "net/base/mime_util.h"
78 #include "net/base/net_errors.h"
79 #include "net/base/registry_controlled_domains/registry_controlled_domain.h"
80 #include "net/base/request_priority.h"
81 #include "net/base/upload_data_stream.h"
82 #include "net/cert/cert_status_flags.h"
83 #include "net/cookies/cookie_monster.h"
84 #include "net/http/http_response_headers.h"
85 #include "net/http/http_response_info.h"
86 #include "net/ssl/ssl_cert_request_info.h"
87 #include "net/url_request/url_request.h"
88 #include "net/url_request/url_request_context.h"
89 #include "net/url_request/url_request_job_factory.h"
90 #include "url/url_constants.h"
91 #include "webkit/common/blob/blob_data.h"
92 #include "webkit/browser/blob/blob_data_handle.h"
93 #include "webkit/browser/blob/blob_storage_context.h"
94 #include "webkit/browser/blob/blob_url_request_job_factory.h"
95 #include "webkit/browser/fileapi/file_permission_policy.h"
96 #include "webkit/browser/fileapi/file_system_context.h"
97 #include "webkit/common/appcache/appcache_interfaces.h"
98 #include "webkit/common/blob/shareable_file_reference.h"
99
100 using base::Time;
101 using base::TimeDelta;
102 using base::TimeTicks;
103 using webkit_blob::ShareableFileReference;
104
105 // ----------------------------------------------------------------------------
106
107 namespace content {
108
109 namespace {
110
111 static ResourceDispatcherHostImpl* g_resource_dispatcher_host;
112
113 // The interval for calls to ResourceDispatcherHostImpl::UpdateLoadStates
114 const int kUpdateLoadStatesIntervalMsec = 100;
115
116 // Maximum byte "cost" of all the outstanding requests for a renderer.
117 // See delcaration of |max_outstanding_requests_cost_per_process_| for details.
118 // This bound is 25MB, which allows for around 6000 outstanding requests.
119 const int kMaxOutstandingRequestsCostPerProcess = 26214400;
120
121 // The number of milliseconds after noting a user gesture that we will
122 // tag newly-created URLRequest objects with the
123 // net::LOAD_MAYBE_USER_GESTURE load flag. This is a fairly arbitrary
124 // guess at how long to expect direct impact from a user gesture, but
125 // this should be OK as the load flag is a best-effort thing only,
126 // rather than being intended as fully accurate.
127 const int kUserGestureWindowMs = 3500;
128
129 // Ratio of |max_num_in_flight_requests_| that any one renderer is allowed to
130 // use. Arbitrarily chosen.
131 const double kMaxRequestsPerProcessRatio = 0.45;
132
133 // TODO(jkarlin): The value is high to reduce the chance of the detachable
134 // request timing out, forcing a blocked second request to open a new connection
135 // and start over. Reduce this value once we have a better idea of what it
136 // should be and once we stop blocking multiple simultaneous requests for the
137 // same resource (see bugs 46104 and 31014).
138 const int kDefaultDetachableCancelDelayMs = 30000;
139
140 bool IsDetachableResourceType(ResourceType::Type type) {
141   switch (type) {
142     case ResourceType::PREFETCH:
143     case ResourceType::PING:
144       return true;
145     default:
146       return false;
147   }
148 }
149
150 // Aborts a request before an URLRequest has actually been created.
151 void AbortRequestBeforeItStarts(ResourceMessageFilter* filter,
152                                 IPC::Message* sync_result,
153                                 int request_id) {
154   if (sync_result) {
155     SyncLoadResult result;
156     result.error_code = net::ERR_ABORTED;
157     ResourceHostMsg_SyncLoad::WriteReplyParams(sync_result, result);
158     filter->Send(sync_result);
159   } else {
160     // Tell the renderer that this request was disallowed.
161     ResourceMsg_RequestCompleteData request_complete_data;
162     request_complete_data.error_code = net::ERR_ABORTED;
163     request_complete_data.was_ignored_by_handler = false;
164     request_complete_data.exists_in_cache = false;
165     // No security info needed, connection not established.
166     request_complete_data.completion_time = base::TimeTicks();
167     request_complete_data.encoded_data_length = 0;
168     filter->Send(new ResourceMsg_RequestComplete(
169         request_id, request_complete_data));
170   }
171 }
172
173 void SetReferrerForRequest(net::URLRequest* request, const Referrer& referrer) {
174   if (!referrer.url.is_valid() ||
175       CommandLine::ForCurrentProcess()->HasSwitch(switches::kNoReferrers)) {
176     request->SetReferrer(std::string());
177   } else {
178     request->SetReferrer(referrer.url.spec());
179   }
180
181   net::URLRequest::ReferrerPolicy net_referrer_policy =
182       net::URLRequest::CLEAR_REFERRER_ON_TRANSITION_FROM_SECURE_TO_INSECURE;
183   switch (referrer.policy) {
184     case blink::WebReferrerPolicyDefault:
185       net_referrer_policy =
186           net::URLRequest::CLEAR_REFERRER_ON_TRANSITION_FROM_SECURE_TO_INSECURE;
187       break;
188     case blink::WebReferrerPolicyAlways:
189     case blink::WebReferrerPolicyNever:
190     case blink::WebReferrerPolicyOrigin:
191       net_referrer_policy = net::URLRequest::NEVER_CLEAR_REFERRER;
192       break;
193   }
194   request->set_referrer_policy(net_referrer_policy);
195 }
196
197 // Consults the RendererSecurity policy to determine whether the
198 // ResourceDispatcherHostImpl should service this request.  A request might be
199 // disallowed if the renderer is not authorized to retrieve the request URL or
200 // if the renderer is attempting to upload an unauthorized file.
201 bool ShouldServiceRequest(int process_type,
202                           int child_id,
203                           const ResourceHostMsg_Request& request_data,
204                           fileapi::FileSystemContext* file_system_context)  {
205   if (process_type == PROCESS_TYPE_PLUGIN)
206     return true;
207
208   ChildProcessSecurityPolicyImpl* policy =
209       ChildProcessSecurityPolicyImpl::GetInstance();
210
211   // Check if the renderer is permitted to request the requested URL.
212   if (!policy->CanRequestURL(child_id, request_data.url)) {
213     VLOG(1) << "Denied unauthorized request for "
214             << request_data.url.possibly_invalid_spec();
215     return false;
216   }
217
218   // Check if the renderer is permitted to upload the requested files.
219   if (request_data.request_body.get()) {
220     const std::vector<ResourceRequestBody::Element>* uploads =
221         request_data.request_body->elements();
222     std::vector<ResourceRequestBody::Element>::const_iterator iter;
223     for (iter = uploads->begin(); iter != uploads->end(); ++iter) {
224       if (iter->type() == ResourceRequestBody::Element::TYPE_FILE &&
225           !policy->CanReadFile(child_id, iter->path())) {
226         NOTREACHED() << "Denied unauthorized upload of "
227                      << iter->path().value();
228         return false;
229       }
230       if (iter->type() == ResourceRequestBody::Element::TYPE_FILE_FILESYSTEM) {
231         fileapi::FileSystemURL url =
232             file_system_context->CrackURL(iter->filesystem_url());
233         if (!policy->CanReadFileSystemFile(child_id, url)) {
234           NOTREACHED() << "Denied unauthorized upload of "
235                        << iter->filesystem_url().spec();
236           return false;
237         }
238       }
239     }
240   }
241
242   return true;
243 }
244
245 void RemoveDownloadFileFromChildSecurityPolicy(int child_id,
246                                                const base::FilePath& path) {
247   ChildProcessSecurityPolicyImpl::GetInstance()->RevokeAllPermissionsForFile(
248       child_id, path);
249 }
250
251 #if defined(OS_WIN)
252 #pragma warning(disable: 4748)
253 #pragma optimize("", off)
254 #endif
255
256 #if defined(OS_WIN)
257 #pragma optimize("", on)
258 #pragma warning(default: 4748)
259 #endif
260
261 DownloadInterruptReason CallbackAndReturn(
262     const DownloadUrlParameters::OnStartedCallback& started_cb,
263     DownloadInterruptReason interrupt_reason) {
264   if (started_cb.is_null())
265     return interrupt_reason;
266   BrowserThread::PostTask(
267       BrowserThread::UI,
268       FROM_HERE,
269       base::Bind(
270           started_cb, static_cast<DownloadItem*>(NULL), interrupt_reason));
271
272   return interrupt_reason;
273 }
274
275 int GetCertID(net::URLRequest* request, int child_id) {
276   if (request->ssl_info().cert.get()) {
277     return CertStore::GetInstance()->StoreCert(request->ssl_info().cert.get(),
278                                                child_id);
279   }
280   return 0;
281 }
282
283 void NotifyRedirectOnUI(int render_process_id,
284                         int render_frame_host,
285                         scoped_ptr<ResourceRedirectDetails> details) {
286   RenderFrameHostImpl* host =
287       RenderFrameHostImpl::FromID(render_process_id, render_frame_host);
288   WebContentsImpl* web_contents =
289       static_cast<WebContentsImpl*>(WebContents::FromRenderFrameHost(host));
290   if (!web_contents)
291     return;
292   web_contents->DidGetRedirectForResourceRequest(
293       host->render_view_host(), *details.get());
294 }
295
296 void NotifyResponseOnUI(int render_process_id,
297                         int render_frame_host,
298                         scoped_ptr<ResourceRequestDetails> details) {
299   RenderFrameHostImpl* host =
300       RenderFrameHostImpl::FromID(render_process_id, render_frame_host);
301   WebContentsImpl* web_contents =
302       static_cast<WebContentsImpl*>(WebContents::FromRenderFrameHost(host));
303   if (!web_contents)
304     return;
305   web_contents->DidGetResourceResponseStart(*details.get());
306 }
307
308 bool IsValidatedSCT(
309     const net::SignedCertificateTimestampAndStatus& sct_status) {
310   return sct_status.status == net::ct::SCT_STATUS_OK;
311 }
312
313 webkit_blob::BlobStorageContext* GetBlobStorageContext(
314     ResourceMessageFilter* filter) {
315   if (!filter->blob_storage_context())
316     return NULL;
317   return filter->blob_storage_context()->context();
318 }
319
320 }  // namespace
321
322 // static
323 ResourceDispatcherHost* ResourceDispatcherHost::Get() {
324   return g_resource_dispatcher_host;
325 }
326
327 ResourceDispatcherHostImpl::ResourceDispatcherHostImpl()
328     : save_file_manager_(new SaveFileManager()),
329       request_id_(-1),
330       is_shutdown_(false),
331       num_in_flight_requests_(0),
332       max_num_in_flight_requests_(base::SharedMemory::GetHandleLimit()),
333       max_num_in_flight_requests_per_process_(
334           static_cast<int>(
335               max_num_in_flight_requests_ * kMaxRequestsPerProcessRatio)),
336       max_outstanding_requests_cost_per_process_(
337           kMaxOutstandingRequestsCostPerProcess),
338       filter_(NULL),
339       delegate_(NULL),
340       allow_cross_origin_auth_prompt_(false) {
341   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::UI));
342   DCHECK(!g_resource_dispatcher_host);
343   g_resource_dispatcher_host = this;
344
345   GetContentClient()->browser()->ResourceDispatcherHostCreated();
346
347   ANNOTATE_BENIGN_RACE(
348       &last_user_gesture_time_,
349       "We don't care about the precise value, see http://crbug.com/92889");
350
351   BrowserThread::PostTask(BrowserThread::IO,
352                           FROM_HERE,
353                           base::Bind(&ResourceDispatcherHostImpl::OnInit,
354                                      base::Unretained(this)));
355
356   update_load_states_timer_.reset(
357       new base::RepeatingTimer<ResourceDispatcherHostImpl>());
358 }
359
360 ResourceDispatcherHostImpl::~ResourceDispatcherHostImpl() {
361   DCHECK(outstanding_requests_stats_map_.empty());
362   DCHECK(g_resource_dispatcher_host);
363   g_resource_dispatcher_host = NULL;
364 }
365
366 // static
367 ResourceDispatcherHostImpl* ResourceDispatcherHostImpl::Get() {
368   return g_resource_dispatcher_host;
369 }
370
371 void ResourceDispatcherHostImpl::SetDelegate(
372     ResourceDispatcherHostDelegate* delegate) {
373   delegate_ = delegate;
374 }
375
376 void ResourceDispatcherHostImpl::SetAllowCrossOriginAuthPrompt(bool value) {
377   allow_cross_origin_auth_prompt_ = value;
378 }
379
380 void ResourceDispatcherHostImpl::AddResourceContext(ResourceContext* context) {
381   active_resource_contexts_.insert(context);
382 }
383
384 void ResourceDispatcherHostImpl::RemoveResourceContext(
385     ResourceContext* context) {
386   CHECK(ContainsKey(active_resource_contexts_, context));
387   active_resource_contexts_.erase(context);
388 }
389
390 void ResourceDispatcherHostImpl::CancelRequestsForContext(
391     ResourceContext* context) {
392   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::IO));
393   DCHECK(context);
394
395   CHECK(ContainsKey(active_resource_contexts_, context));
396
397   // Note that request cancellation has side effects. Therefore, we gather all
398   // the requests to cancel first, and then we start cancelling. We assert at
399   // the end that there are no more to cancel since the context is about to go
400   // away.
401   typedef std::vector<linked_ptr<ResourceLoader> > LoaderList;
402   LoaderList loaders_to_cancel;
403
404   for (LoaderMap::iterator i = pending_loaders_.begin();
405        i != pending_loaders_.end();) {
406     if (i->second->GetRequestInfo()->GetContext() == context) {
407       loaders_to_cancel.push_back(i->second);
408       IncrementOutstandingRequestsMemory(-1, *i->second->GetRequestInfo());
409       pending_loaders_.erase(i++);
410     } else {
411       ++i;
412     }
413   }
414
415   for (BlockedLoadersMap::iterator i = blocked_loaders_map_.begin();
416        i != blocked_loaders_map_.end();) {
417     BlockedLoadersList* loaders = i->second;
418     if (loaders->empty()) {
419       // This can happen if BlockRequestsForRoute() has been called for a route,
420       // but we haven't blocked any matching requests yet.
421       ++i;
422       continue;
423     }
424     ResourceRequestInfoImpl* info = loaders->front()->GetRequestInfo();
425     if (info->GetContext() == context) {
426       blocked_loaders_map_.erase(i++);
427       for (BlockedLoadersList::const_iterator it = loaders->begin();
428            it != loaders->end(); ++it) {
429         linked_ptr<ResourceLoader> loader = *it;
430         info = loader->GetRequestInfo();
431         // We make the assumption that all requests on the list have the same
432         // ResourceContext.
433         DCHECK_EQ(context, info->GetContext());
434         IncrementOutstandingRequestsMemory(-1, *info);
435         loaders_to_cancel.push_back(loader);
436       }
437       delete loaders;
438     } else {
439       ++i;
440     }
441   }
442
443 #ifndef NDEBUG
444   for (LoaderList::iterator i = loaders_to_cancel.begin();
445        i != loaders_to_cancel.end(); ++i) {
446     // There is no strict requirement that this be the case, but currently
447     // downloads, streams, detachable requests, and transferred requests are the
448     // only requests that aren't cancelled when the associated processes go
449     // away. It may be OK for this invariant to change in the future, but if
450     // this assertion fires without the invariant changing, then it's indicative
451     // of a leak.
452     DCHECK((*i)->GetRequestInfo()->IsDownload() ||
453            (*i)->GetRequestInfo()->is_stream() ||
454            ((*i)->GetRequestInfo()->detachable_handler() &&
455             (*i)->GetRequestInfo()->detachable_handler()->is_detached()) ||
456            (*i)->is_transferring());
457   }
458 #endif
459
460   loaders_to_cancel.clear();
461
462   // Validate that no more requests for this context were added.
463   for (LoaderMap::const_iterator i = pending_loaders_.begin();
464        i != pending_loaders_.end(); ++i) {
465     // http://crbug.com/90971
466     CHECK_NE(i->second->GetRequestInfo()->GetContext(), context);
467   }
468
469   for (BlockedLoadersMap::const_iterator i = blocked_loaders_map_.begin();
470        i != blocked_loaders_map_.end(); ++i) {
471     BlockedLoadersList* loaders = i->second;
472     if (!loaders->empty()) {
473       ResourceRequestInfoImpl* info = loaders->front()->GetRequestInfo();
474       // http://crbug.com/90971
475       CHECK_NE(info->GetContext(), context);
476     }
477   }
478 }
479
480 DownloadInterruptReason ResourceDispatcherHostImpl::BeginDownload(
481     scoped_ptr<net::URLRequest> request,
482     const Referrer& referrer,
483     bool is_content_initiated,
484     ResourceContext* context,
485     int child_id,
486     int route_id,
487     bool prefer_cache,
488     scoped_ptr<DownloadSaveInfo> save_info,
489     uint32 download_id,
490     const DownloadStartedCallback& started_callback) {
491   if (is_shutdown_)
492     return CallbackAndReturn(started_callback,
493                              DOWNLOAD_INTERRUPT_REASON_USER_SHUTDOWN);
494
495   const GURL& url = request->original_url();
496
497   // http://crbug.com/90971
498   char url_buf[128];
499   base::strlcpy(url_buf, url.spec().c_str(), arraysize(url_buf));
500   base::debug::Alias(url_buf);
501   CHECK(ContainsKey(active_resource_contexts_, context));
502
503   SetReferrerForRequest(request.get(), referrer);
504
505   int extra_load_flags = net::LOAD_IS_DOWNLOAD;
506   if (prefer_cache) {
507     // If there is upload data attached, only retrieve from cache because there
508     // is no current mechanism to prompt the user for their consent for a
509     // re-post. For GETs, try to retrieve data from the cache and skip
510     // validating the entry if present.
511     if (request->get_upload() != NULL)
512       extra_load_flags |= net::LOAD_ONLY_FROM_CACHE;
513     else
514       extra_load_flags |= net::LOAD_PREFERRING_CACHE;
515   } else {
516     extra_load_flags |= net::LOAD_DISABLE_CACHE;
517   }
518   request->SetLoadFlags(request->load_flags() | extra_load_flags);
519
520   // Check if the renderer is permitted to request the requested URL.
521   if (!ChildProcessSecurityPolicyImpl::GetInstance()->
522           CanRequestURL(child_id, url)) {
523     VLOG(1) << "Denied unauthorized download request for "
524             << url.possibly_invalid_spec();
525     return CallbackAndReturn(started_callback,
526                              DOWNLOAD_INTERRUPT_REASON_NETWORK_INVALID_REQUEST);
527   }
528
529   request_id_--;
530
531   const net::URLRequestContext* request_context = context->GetRequestContext();
532   if (!request_context->job_factory()->IsHandledURL(url)) {
533     VLOG(1) << "Download request for unsupported protocol: "
534             << url.possibly_invalid_spec();
535     return CallbackAndReturn(started_callback,
536                              DOWNLOAD_INTERRUPT_REASON_NETWORK_INVALID_REQUEST);
537   }
538
539   ResourceRequestInfoImpl* extra_info =
540       CreateRequestInfo(child_id, route_id, true, context);
541   extra_info->AssociateWithRequest(request.get());  // Request takes ownership.
542
543   if (request->url().SchemeIs(url::kBlobScheme)) {
544     ChromeBlobStorageContext* blob_context =
545         GetChromeBlobStorageContextForResourceContext(context);
546     webkit_blob::BlobProtocolHandler::SetRequestedBlobDataHandle(
547         request.get(),
548         blob_context->context()->GetBlobDataFromPublicURL(request->url()));
549   }
550
551   // From this point forward, the |DownloadResourceHandler| is responsible for
552   // |started_callback|.
553   scoped_ptr<ResourceHandler> handler(
554       CreateResourceHandlerForDownload(request.get(), is_content_initiated,
555                                        true, download_id, save_info.Pass(),
556                                        started_callback));
557
558   BeginRequestInternal(request.Pass(), handler.Pass());
559
560   return DOWNLOAD_INTERRUPT_REASON_NONE;
561 }
562
563 void ResourceDispatcherHostImpl::ClearLoginDelegateForRequest(
564     net::URLRequest* request) {
565   ResourceRequestInfoImpl* info = ResourceRequestInfoImpl::ForRequest(request);
566   if (info) {
567     ResourceLoader* loader = GetLoader(info->GetGlobalRequestID());
568     if (loader)
569       loader->ClearLoginDelegate();
570   }
571 }
572
573 void ResourceDispatcherHostImpl::Shutdown() {
574   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::UI));
575   BrowserThread::PostTask(BrowserThread::IO,
576                           FROM_HERE,
577                           base::Bind(&ResourceDispatcherHostImpl::OnShutdown,
578                                      base::Unretained(this)));
579 }
580
581 scoped_ptr<ResourceHandler>
582 ResourceDispatcherHostImpl::CreateResourceHandlerForDownload(
583     net::URLRequest* request,
584     bool is_content_initiated,
585     bool must_download,
586     uint32 id,
587     scoped_ptr<DownloadSaveInfo> save_info,
588     const DownloadUrlParameters::OnStartedCallback& started_cb) {
589   scoped_ptr<ResourceHandler> handler(
590       new DownloadResourceHandler(id, request, started_cb, save_info.Pass()));
591   if (delegate_) {
592     const ResourceRequestInfo* request_info(
593         ResourceRequestInfo::ForRequest(request));
594
595     ScopedVector<ResourceThrottle> throttles;
596     delegate_->DownloadStarting(
597         request, request_info->GetContext(), request_info->GetChildID(),
598         request_info->GetRouteID(), request_info->GetRequestID(),
599         is_content_initiated, must_download, &throttles);
600     if (!throttles.empty()) {
601       handler.reset(
602           new ThrottlingResourceHandler(
603               handler.Pass(), request, throttles.Pass()));
604     }
605   }
606   return handler.Pass();
607 }
608
609 scoped_ptr<ResourceHandler>
610 ResourceDispatcherHostImpl::MaybeInterceptAsStream(net::URLRequest* request,
611                                                    ResourceResponse* response,
612                                                    std::string* payload) {
613   ResourceRequestInfoImpl* info = ResourceRequestInfoImpl::ForRequest(request);
614   const std::string& mime_type = response->head.mime_type;
615
616   GURL origin;
617   if (!delegate_ ||
618       !delegate_->ShouldInterceptResourceAsStream(request,
619                                                   mime_type,
620                                                   &origin,
621                                                   payload)) {
622     return scoped_ptr<ResourceHandler>();
623   }
624
625   StreamContext* stream_context =
626       GetStreamContextForResourceContext(info->GetContext());
627
628   scoped_ptr<StreamResourceHandler> handler(
629       new StreamResourceHandler(request,
630                                 stream_context->registry(),
631                                 origin));
632
633   info->set_is_stream(true);
634   delegate_->OnStreamCreated(
635       request,
636       handler->stream()->CreateHandle(
637           request->url(),
638           mime_type,
639           response->head.headers));
640   return handler.PassAs<ResourceHandler>();
641 }
642
643 void ResourceDispatcherHostImpl::ClearSSLClientAuthHandlerForRequest(
644     net::URLRequest* request) {
645   ResourceRequestInfoImpl* info = ResourceRequestInfoImpl::ForRequest(request);
646   if (info) {
647     ResourceLoader* loader = GetLoader(info->GetGlobalRequestID());
648     if (loader)
649       loader->ClearSSLClientAuthHandler();
650   }
651 }
652
653 ResourceDispatcherHostLoginDelegate*
654 ResourceDispatcherHostImpl::CreateLoginDelegate(
655     ResourceLoader* loader,
656     net::AuthChallengeInfo* auth_info) {
657   if (!delegate_)
658     return NULL;
659
660   return delegate_->CreateLoginDelegate(auth_info, loader->request());
661 }
662
663 bool ResourceDispatcherHostImpl::HandleExternalProtocol(ResourceLoader* loader,
664                                                         const GURL& url) {
665   if (!delegate_)
666     return false;
667
668   ResourceRequestInfoImpl* info = loader->GetRequestInfo();
669
670   if (!ResourceType::IsFrame(info->GetResourceType()))
671     return false;
672
673   const net::URLRequestJobFactory* job_factory =
674       info->GetContext()->GetRequestContext()->job_factory();
675   if (job_factory->IsHandledURL(url))
676     return false;
677
678   bool initiated_by_user_gesture =
679       (loader->request()->load_flags() & net::LOAD_MAYBE_USER_GESTURE) != 0;
680   bool handled = delegate_->HandleExternalProtocol(url, info->GetChildID(),
681                                                    info->GetRouteID(),
682                                                    initiated_by_user_gesture);
683   // Consume the user gesture if the external protocol dialog is shown.
684   if (handled)
685     last_user_gesture_time_ = base::TimeTicks();
686   return handled;
687 }
688
689 void ResourceDispatcherHostImpl::DidStartRequest(ResourceLoader* loader) {
690   // Make sure we have the load state monitor running
691   if (!update_load_states_timer_->IsRunning()) {
692     update_load_states_timer_->Start(FROM_HERE,
693         TimeDelta::FromMilliseconds(kUpdateLoadStatesIntervalMsec),
694         this, &ResourceDispatcherHostImpl::UpdateLoadStates);
695   }
696 }
697
698 void ResourceDispatcherHostImpl::DidReceiveRedirect(ResourceLoader* loader,
699                                                     const GURL& new_url) {
700   ResourceRequestInfoImpl* info = loader->GetRequestInfo();
701
702   int render_process_id, render_frame_host;
703   if (!info->GetAssociatedRenderFrame(&render_process_id, &render_frame_host))
704     return;
705
706   // Notify the observers on the UI thread.
707   scoped_ptr<ResourceRedirectDetails> detail(new ResourceRedirectDetails(
708       loader->request(),
709       GetCertID(loader->request(), info->GetChildID()),
710       new_url));
711   BrowserThread::PostTask(
712       BrowserThread::UI, FROM_HERE,
713       base::Bind(
714           &NotifyRedirectOnUI,
715           render_process_id, render_frame_host, base::Passed(&detail)));
716 }
717
718 void ResourceDispatcherHostImpl::DidReceiveResponse(ResourceLoader* loader) {
719   ResourceRequestInfoImpl* info = loader->GetRequestInfo();
720
721   if (loader->request()->was_fetched_via_proxy() &&
722       loader->request()->was_fetched_via_spdy() &&
723       loader->request()->url().SchemeIs("http")) {
724     scheduler_->OnReceivedSpdyProxiedHttpResponse(
725         info->GetChildID(), info->GetRouteID());
726   }
727
728   int render_process_id, render_frame_host;
729   if (!info->GetAssociatedRenderFrame(&render_process_id, &render_frame_host))
730     return;
731
732   // Notify the observers on the UI thread.
733   scoped_ptr<ResourceRequestDetails> detail(new ResourceRequestDetails(
734       loader->request(),
735       GetCertID(loader->request(), info->GetChildID())));
736   BrowserThread::PostTask(
737       BrowserThread::UI, FROM_HERE,
738       base::Bind(
739           &NotifyResponseOnUI,
740           render_process_id, render_frame_host, base::Passed(&detail)));
741 }
742
743 void ResourceDispatcherHostImpl::DidFinishLoading(ResourceLoader* loader) {
744   ResourceRequestInfo* info = loader->GetRequestInfo();
745
746   // Record final result of all resource loads.
747   if (info->GetResourceType() == ResourceType::MAIN_FRAME) {
748     // This enumeration has "3" appended to its name to distinguish it from
749     // older versions.
750     UMA_HISTOGRAM_SPARSE_SLOWLY(
751         "Net.ErrorCodesForMainFrame3",
752         -loader->request()->status().error());
753
754     if (loader->request()->url().SchemeIsSecure()) {
755       if (loader->request()->url().host() == "www.google.com") {
756         UMA_HISTOGRAM_SPARSE_SLOWLY("Net.ErrorCodesForHTTPSGoogleMainFrame2",
757                                     -loader->request()->status().error());
758       }
759
760       int num_valid_scts = std::count_if(
761           loader->request()->ssl_info().signed_certificate_timestamps.begin(),
762           loader->request()->ssl_info().signed_certificate_timestamps.end(),
763           IsValidatedSCT);
764       UMA_HISTOGRAM_COUNTS_100(
765           "Net.CertificateTransparency.MainFrameValidSCTCount", num_valid_scts);
766     }
767   } else {
768     if (info->GetResourceType() == ResourceType::IMAGE) {
769       UMA_HISTOGRAM_SPARSE_SLOWLY(
770           "Net.ErrorCodesForImages",
771           -loader->request()->status().error());
772     }
773     // This enumeration has "2" appended to distinguish it from older versions.
774     UMA_HISTOGRAM_SPARSE_SLOWLY(
775         "Net.ErrorCodesForSubresources2",
776         -loader->request()->status().error());
777   }
778
779   if (delegate_)
780     delegate_->RequestComplete(loader->request());
781
782   // Destroy the ResourceLoader.
783   RemovePendingRequest(info->GetChildID(), info->GetRequestID());
784 }
785
786 void ResourceDispatcherHostImpl::OnInit() {
787   scheduler_.reset(new ResourceScheduler);
788   AppCacheInterceptor::EnsureRegistered();
789 }
790
791 void ResourceDispatcherHostImpl::OnShutdown() {
792   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::IO));
793
794   is_shutdown_ = true;
795   pending_loaders_.clear();
796
797   // Make sure we shutdown the timer now, otherwise by the time our destructor
798   // runs if the timer is still running the Task is deleted twice (once by
799   // the MessageLoop and the second time by RepeatingTimer).
800   update_load_states_timer_.reset();
801
802   // Clear blocked requests if any left.
803   // Note that we have to do this in 2 passes as we cannot call
804   // CancelBlockedRequestsForRoute while iterating over
805   // blocked_loaders_map_, as it modifies it.
806   std::set<GlobalRoutingID> ids;
807   for (BlockedLoadersMap::const_iterator iter = blocked_loaders_map_.begin();
808        iter != blocked_loaders_map_.end(); ++iter) {
809     std::pair<std::set<GlobalRoutingID>::iterator, bool> result =
810         ids.insert(iter->first);
811     // We should not have duplicates.
812     DCHECK(result.second);
813   }
814   for (std::set<GlobalRoutingID>::const_iterator iter = ids.begin();
815        iter != ids.end(); ++iter) {
816     CancelBlockedRequestsForRoute(iter->child_id, iter->route_id);
817   }
818
819   scheduler_.reset();
820 }
821
822 bool ResourceDispatcherHostImpl::OnMessageReceived(
823     const IPC::Message& message,
824     ResourceMessageFilter* filter) {
825   filter_ = filter;
826   bool handled = true;
827   IPC_BEGIN_MESSAGE_MAP(ResourceDispatcherHostImpl, message)
828     IPC_MESSAGE_HANDLER(ResourceHostMsg_RequestResource, OnRequestResource)
829     IPC_MESSAGE_HANDLER_DELAY_REPLY(ResourceHostMsg_SyncLoad, OnSyncLoad)
830     IPC_MESSAGE_HANDLER(ResourceHostMsg_ReleaseDownloadedFile,
831                         OnReleaseDownloadedFile)
832     IPC_MESSAGE_HANDLER(ResourceHostMsg_DataDownloaded_ACK, OnDataDownloadedACK)
833     IPC_MESSAGE_HANDLER(ResourceHostMsg_UploadProgress_ACK, OnUploadProgressACK)
834     IPC_MESSAGE_HANDLER(ResourceHostMsg_CancelRequest, OnCancelRequest)
835     IPC_MESSAGE_UNHANDLED(handled = false)
836   IPC_END_MESSAGE_MAP()
837
838   if (!handled && IPC_MESSAGE_ID_CLASS(message.type()) == ResourceMsgStart) {
839     PickleIterator iter(message);
840     int request_id = -1;
841     bool ok = iter.ReadInt(&request_id);
842     DCHECK(ok);
843     GlobalRequestID id(filter_->child_id(), request_id);
844     DelegateMap::iterator it = delegate_map_.find(id);
845     if (it != delegate_map_.end()) {
846       ObserverList<ResourceMessageDelegate>::Iterator del_it(*it->second);
847       ResourceMessageDelegate* delegate;
848       while (!handled && (delegate = del_it.GetNext()) != NULL) {
849         handled = delegate->OnMessageReceived(message);
850       }
851     }
852
853     // As the unhandled resource message effectively has no consumer, mark it as
854     // handled to prevent needless propagation through the filter pipeline.
855     handled = true;
856   }
857
858   filter_ = NULL;
859   return handled;
860 }
861
862 void ResourceDispatcherHostImpl::OnRequestResource(
863     int routing_id,
864     int request_id,
865     const ResourceHostMsg_Request& request_data) {
866   BeginRequest(request_id, request_data, NULL, routing_id);
867 }
868
869 // Begins a resource request with the given params on behalf of the specified
870 // child process.  Responses will be dispatched through the given receiver. The
871 // process ID is used to lookup WebContentsImpl from routing_id's in the case of
872 // a request from a renderer.  request_context is the cookie/cache context to be
873 // used for this request.
874 //
875 // If sync_result is non-null, then a SyncLoad reply will be generated, else
876 // a normal asynchronous set of response messages will be generated.
877 void ResourceDispatcherHostImpl::OnSyncLoad(
878     int request_id,
879     const ResourceHostMsg_Request& request_data,
880     IPC::Message* sync_result) {
881   BeginRequest(request_id, request_data, sync_result,
882                sync_result->routing_id());
883 }
884
885 void ResourceDispatcherHostImpl::UpdateRequestForTransfer(
886     int child_id,
887     int route_id,
888     int request_id,
889     const ResourceHostMsg_Request& request_data,
890     const linked_ptr<ResourceLoader>& loader) {
891   ResourceRequestInfoImpl* info = loader->GetRequestInfo();
892   GlobalRoutingID old_routing_id(
893       request_data.transferred_request_child_id, info->GetRouteID());
894   GlobalRequestID old_request_id(request_data.transferred_request_child_id,
895                                  request_data.transferred_request_request_id);
896   GlobalRoutingID new_routing_id(child_id, route_id);
897   GlobalRequestID new_request_id(child_id, request_id);
898
899   // Clear out data that depends on |info| before updating it.
900   IncrementOutstandingRequestsMemory(-1, *info);
901   OustandingRequestsStats empty_stats = { 0, 0 };
902   OustandingRequestsStats old_stats = GetOutstandingRequestsStats(*info);
903   UpdateOutstandingRequestsStats(*info, empty_stats);
904   pending_loaders_.erase(old_request_id);
905
906   // ResourceHandlers should always get state related to the request from the
907   // ResourceRequestInfo rather than caching it locally.  This lets us update
908   // the info object when a transfer occurs.
909   info->UpdateForTransfer(child_id, route_id, request_data.origin_pid,
910                           request_id, request_data.parent_render_frame_id,
911                           filter_->GetWeakPtr());
912
913   // Update maps that used the old IDs, if necessary.  Some transfers in tests
914   // do not actually use a different ID, so not all maps need to be updated.
915   pending_loaders_[new_request_id] = loader;
916   UpdateOutstandingRequestsStats(*info, old_stats);
917   IncrementOutstandingRequestsMemory(1, *info);
918   if (old_routing_id != new_routing_id) {
919     if (blocked_loaders_map_.find(old_routing_id) !=
920             blocked_loaders_map_.end()) {
921       blocked_loaders_map_[new_routing_id] =
922           blocked_loaders_map_[old_routing_id];
923       blocked_loaders_map_.erase(old_routing_id);
924     }
925   }
926   if (old_request_id != new_request_id) {
927     DelegateMap::iterator it = delegate_map_.find(old_request_id);
928     if (it != delegate_map_.end()) {
929       // Tell each delegate that the request ID has changed.
930       ObserverList<ResourceMessageDelegate>::Iterator del_it(*it->second);
931       ResourceMessageDelegate* delegate;
932       while ((delegate = del_it.GetNext()) != NULL) {
933         delegate->set_request_id(new_request_id);
934       }
935       // Now store the observer list under the new request ID.
936       delegate_map_[new_request_id] = delegate_map_[old_request_id];
937       delegate_map_.erase(old_request_id);
938     }
939   }
940
941   AppCacheInterceptor::CompleteCrossSiteTransfer(
942       loader->request(),
943       child_id,
944       request_data.appcache_host_id);
945
946   // We should have a CrossSiteResourceHandler to finish the transfer.
947   DCHECK(info->cross_site_handler());
948 }
949
950 void ResourceDispatcherHostImpl::BeginRequest(
951     int request_id,
952     const ResourceHostMsg_Request& request_data,
953     IPC::Message* sync_result,  // only valid for sync
954     int route_id) {
955   int process_type = filter_->process_type();
956   int child_id = filter_->child_id();
957
958   // Reject invalid priority.
959   if (request_data.priority < net::MINIMUM_PRIORITY ||
960       request_data.priority > net::MAXIMUM_PRIORITY) {
961     RecordAction(base::UserMetricsAction("BadMessageTerminate_RDH"));
962     filter_->BadMessageReceived();
963     return;
964   }
965
966   // If we crash here, figure out what URL the renderer was requesting.
967   // http://crbug.com/91398
968   char url_buf[128];
969   base::strlcpy(url_buf, request_data.url.spec().c_str(), arraysize(url_buf));
970   base::debug::Alias(url_buf);
971
972   // If the request that's coming in is being transferred from another process,
973   // we want to reuse and resume the old loader rather than start a new one.
974   {
975     LoaderMap::iterator it = pending_loaders_.find(
976         GlobalRequestID(request_data.transferred_request_child_id,
977                         request_data.transferred_request_request_id));
978     if (it != pending_loaders_.end()) {
979       // If the request is transferring to a new process, we can update our
980       // state and let it resume with its existing ResourceHandlers.
981       if (it->second->is_transferring()) {
982         linked_ptr<ResourceLoader> deferred_loader = it->second;
983         UpdateRequestForTransfer(child_id, route_id, request_id,
984                                  request_data, deferred_loader);
985
986         deferred_loader->CompleteTransfer();
987       } else {
988         RecordAction(base::UserMetricsAction("BadMessageTerminate_RDH"));
989         filter_->BadMessageReceived();
990       }
991       return;
992     }
993   }
994
995   ResourceContext* resource_context = NULL;
996   net::URLRequestContext* request_context = NULL;
997   filter_->GetContexts(request_data, &resource_context, &request_context);
998   // http://crbug.com/90971
999   CHECK(ContainsKey(active_resource_contexts_, resource_context));
1000
1001   if (is_shutdown_ ||
1002       !ShouldServiceRequest(process_type, child_id, request_data,
1003                             filter_->file_system_context())) {
1004     AbortRequestBeforeItStarts(filter_, sync_result, request_id);
1005     return;
1006   }
1007
1008   // Allow the observer to block/handle the request.
1009   if (delegate_ && !delegate_->ShouldBeginRequest(child_id,
1010                                                   route_id,
1011                                                   request_data.method,
1012                                                   request_data.url,
1013                                                   request_data.resource_type,
1014                                                   resource_context)) {
1015     AbortRequestBeforeItStarts(filter_, sync_result, request_id);
1016     return;
1017   }
1018
1019   bool is_sync_load = sync_result != NULL;
1020   int load_flags =
1021       BuildLoadFlagsForRequest(request_data, child_id, is_sync_load);
1022
1023   // Sync loads should have maximum priority and should be the only
1024   // requets that have the ignore limits flag set.
1025   if (is_sync_load) {
1026     DCHECK_EQ(request_data.priority, net::MAXIMUM_PRIORITY);
1027     DCHECK_NE(load_flags & net::LOAD_IGNORE_LIMITS, 0);
1028   } else {
1029     DCHECK_EQ(load_flags & net::LOAD_IGNORE_LIMITS, 0);
1030   }
1031
1032   // Construct the request.
1033   net::CookieStore* cookie_store =
1034       GetContentClient()->browser()->OverrideCookieStoreForRenderProcess(
1035           child_id);
1036   scoped_ptr<net::URLRequest> new_request;
1037   new_request = request_context->CreateRequest(
1038       request_data.url, request_data.priority, NULL, cookie_store);
1039
1040   new_request->set_method(request_data.method);
1041   new_request->set_first_party_for_cookies(
1042       request_data.first_party_for_cookies);
1043
1044   const Referrer referrer(request_data.referrer, request_data.referrer_policy);
1045   SetReferrerForRequest(new_request.get(), referrer);
1046
1047   net::HttpRequestHeaders headers;
1048   headers.AddHeadersFromString(request_data.headers);
1049   new_request->SetExtraRequestHeaders(headers);
1050
1051   new_request->SetLoadFlags(load_flags);
1052
1053   // Resolve elements from request_body and prepare upload data.
1054   if (request_data.request_body.get()) {
1055     new_request->set_upload(UploadDataStreamBuilder::Build(
1056         request_data.request_body.get(),
1057         GetBlobStorageContext(filter_),
1058         filter_->file_system_context(),
1059         BrowserThread::GetMessageLoopProxyForThread(BrowserThread::FILE)
1060             .get()));
1061   }
1062
1063   bool allow_download = request_data.allow_download &&
1064       ResourceType::IsFrame(request_data.resource_type);
1065
1066   // Make extra info and read footer (contains request ID).
1067   ResourceRequestInfoImpl* extra_info =
1068       new ResourceRequestInfoImpl(
1069           process_type,
1070           child_id,
1071           route_id,
1072           request_data.origin_pid,
1073           request_id,
1074           request_data.render_frame_id,
1075           request_data.is_main_frame,
1076           request_data.parent_is_main_frame,
1077           request_data.parent_render_frame_id,
1078           request_data.resource_type,
1079           request_data.transition_type,
1080           request_data.should_replace_current_entry,
1081           false,  // is download
1082           false,  // is stream
1083           allow_download,
1084           request_data.has_user_gesture,
1085           request_data.referrer_policy,
1086           request_data.visiblity_state,
1087           resource_context,
1088           filter_->GetWeakPtr(),
1089           !is_sync_load);
1090   // Request takes ownership.
1091   extra_info->AssociateWithRequest(new_request.get());
1092
1093   if (new_request->url().SchemeIs(url::kBlobScheme)) {
1094     // Hang on to a reference to ensure the blob is not released prior
1095     // to the job being started.
1096     webkit_blob::BlobProtocolHandler::SetRequestedBlobDataHandle(
1097         new_request.get(),
1098         filter_->blob_storage_context()->context()->
1099             GetBlobDataFromPublicURL(new_request->url()));
1100   }
1101
1102   // Initialize the service worker handler for the request.
1103   ServiceWorkerRequestHandler::InitializeHandler(
1104       new_request.get(),
1105       filter_->service_worker_context(),
1106       GetBlobStorageContext(filter_),
1107       child_id,
1108       request_data.service_worker_provider_id,
1109       request_data.resource_type);
1110
1111   // Have the appcache associate its extra info with the request.
1112   AppCacheInterceptor::SetExtraRequestInfo(
1113       new_request.get(), filter_->appcache_service(), child_id,
1114       request_data.appcache_host_id, request_data.resource_type);
1115
1116   scoped_ptr<ResourceHandler> handler(
1117        CreateResourceHandler(
1118            new_request.get(),
1119            request_data, sync_result, route_id, process_type, child_id,
1120            resource_context));
1121
1122   if (handler)
1123     BeginRequestInternal(new_request.Pass(), handler.Pass());
1124 }
1125
1126 scoped_ptr<ResourceHandler> ResourceDispatcherHostImpl::CreateResourceHandler(
1127     net::URLRequest* request,
1128     const ResourceHostMsg_Request& request_data,
1129     IPC::Message* sync_result,
1130     int route_id,
1131     int process_type,
1132     int child_id,
1133     ResourceContext* resource_context) {
1134   // Construct the IPC resource handler.
1135   scoped_ptr<ResourceHandler> handler;
1136   if (sync_result) {
1137     // download_to_file is not supported for synchronous requests.
1138     if (request_data.download_to_file) {
1139       RecordAction(base::UserMetricsAction("BadMessageTerminate_RDH"));
1140       filter_->BadMessageReceived();
1141       return scoped_ptr<ResourceHandler>();
1142     }
1143
1144     handler.reset(new SyncResourceHandler(request, sync_result, this));
1145   } else {
1146     handler.reset(new AsyncResourceHandler(request, this));
1147
1148     // The RedirectToFileResourceHandler depends on being next in the chain.
1149     if (request_data.download_to_file) {
1150       handler.reset(
1151           new RedirectToFileResourceHandler(handler.Pass(), request));
1152     }
1153   }
1154
1155   // Prefetches and <a ping> requests outlive their child process.
1156   if (!sync_result && IsDetachableResourceType(request_data.resource_type)) {
1157     handler.reset(new DetachableResourceHandler(
1158         request,
1159         base::TimeDelta::FromMilliseconds(kDefaultDetachableCancelDelayMs),
1160         handler.Pass()));
1161   }
1162
1163   // Install a CrossSiteResourceHandler for all main frame requests.  This will
1164   // let us check whether a transfer is required and pause for the unload
1165   // handler either if so or if a cross-process navigation is already under way.
1166   bool is_swappable_navigation =
1167       request_data.resource_type == ResourceType::MAIN_FRAME;
1168   // If we are using --site-per-process, install it for subframes as well.
1169   if (!is_swappable_navigation &&
1170       CommandLine::ForCurrentProcess()->HasSwitch(switches::kSitePerProcess)) {
1171     is_swappable_navigation =
1172         request_data.resource_type == ResourceType::SUB_FRAME;
1173   }
1174   if (is_swappable_navigation && process_type == PROCESS_TYPE_RENDERER)
1175     handler.reset(new CrossSiteResourceHandler(handler.Pass(), request));
1176
1177   // Insert a buffered event handler before the actual one.
1178   handler.reset(
1179       new BufferedResourceHandler(handler.Pass(), this, request));
1180
1181   ScopedVector<ResourceThrottle> throttles;
1182   if (delegate_) {
1183     delegate_->RequestBeginning(request,
1184                                 resource_context,
1185                                 filter_->appcache_service(),
1186                                 request_data.resource_type,
1187                                 child_id,
1188                                 route_id,
1189                                 &throttles);
1190   }
1191
1192   if (request->has_upload()) {
1193     // Block power save while uploading data.
1194     throttles.push_back(new PowerSaveBlockResourceThrottle());
1195   }
1196
1197   throttles.push_back(
1198       scheduler_->ScheduleRequest(child_id, route_id, request).release());
1199
1200   handler.reset(
1201       new ThrottlingResourceHandler(handler.Pass(), request, throttles.Pass()));
1202
1203   return handler.Pass();
1204 }
1205
1206 void ResourceDispatcherHostImpl::OnReleaseDownloadedFile(int request_id) {
1207   UnregisterDownloadedTempFile(filter_->child_id(), request_id);
1208 }
1209
1210 void ResourceDispatcherHostImpl::OnDataDownloadedACK(int request_id) {
1211   // TODO(michaeln): maybe throttle DataDownloaded messages
1212 }
1213
1214 void ResourceDispatcherHostImpl::RegisterDownloadedTempFile(
1215     int child_id, int request_id, const base::FilePath& file_path) {
1216   scoped_refptr<ShareableFileReference> reference =
1217       ShareableFileReference::Get(file_path);
1218   DCHECK(reference);
1219
1220   registered_temp_files_[child_id][request_id] = reference;
1221   ChildProcessSecurityPolicyImpl::GetInstance()->GrantReadFile(
1222       child_id, reference->path());
1223
1224   // When the temp file is deleted, revoke permissions that the renderer has
1225   // to that file. This covers an edge case where the file is deleted and then
1226   // the same name is re-used for some other purpose, we don't want the old
1227   // renderer to still have access to it.
1228   //
1229   // We do this when the file is deleted because the renderer can take a blob
1230   // reference to the temp file that outlives the url loaded that it was
1231   // loaded with to keep the file (and permissions) alive.
1232   reference->AddFinalReleaseCallback(
1233       base::Bind(&RemoveDownloadFileFromChildSecurityPolicy,
1234                  child_id));
1235 }
1236
1237 void ResourceDispatcherHostImpl::UnregisterDownloadedTempFile(
1238     int child_id, int request_id) {
1239   DeletableFilesMap& map = registered_temp_files_[child_id];
1240   DeletableFilesMap::iterator found = map.find(request_id);
1241   if (found == map.end())
1242     return;
1243
1244   map.erase(found);
1245
1246   // Note that we don't remove the security bits here. This will be done
1247   // when all file refs are deleted (see RegisterDownloadedTempFile).
1248 }
1249
1250 bool ResourceDispatcherHostImpl::Send(IPC::Message* message) {
1251   delete message;
1252   return false;
1253 }
1254
1255 void ResourceDispatcherHostImpl::OnUploadProgressACK(int request_id) {
1256   ResourceLoader* loader = GetLoader(filter_->child_id(), request_id);
1257   if (loader)
1258     loader->OnUploadProgressACK();
1259 }
1260
1261 // Note that this cancel is subtly different from the other
1262 // CancelRequest methods in this file, which also tear down the loader.
1263 void ResourceDispatcherHostImpl::OnCancelRequest(int request_id) {
1264   int child_id = filter_->child_id();
1265
1266   // When the old renderer dies, it sends a message to us to cancel its
1267   // requests.
1268   if (IsTransferredNavigation(GlobalRequestID(child_id, request_id)))
1269     return;
1270
1271   ResourceLoader* loader = GetLoader(child_id, request_id);
1272   if (!loader) {
1273     // We probably want to remove this warning eventually, but I wanted to be
1274     // able to notice when this happens during initial development since it
1275     // should be rare and may indicate a bug.
1276     DVLOG(1) << "Canceling a request that wasn't found";
1277     return;
1278   }
1279
1280   loader->CancelRequest(true);
1281 }
1282
1283 ResourceRequestInfoImpl* ResourceDispatcherHostImpl::CreateRequestInfo(
1284     int child_id,
1285     int route_id,
1286     bool download,
1287     ResourceContext* context) {
1288   return new ResourceRequestInfoImpl(
1289       PROCESS_TYPE_RENDERER,
1290       child_id,
1291       route_id,
1292       0,
1293       request_id_,
1294       MSG_ROUTING_NONE,  // render_frame_id
1295       false,     // is_main_frame
1296       false,     // parent_is_main_frame
1297       -1,        // parent_render_frame_id
1298       ResourceType::SUB_RESOURCE,
1299       PAGE_TRANSITION_LINK,
1300       false,     // should_replace_current_entry
1301       download,  // is_download
1302       false,     // is_stream
1303       download,  // allow_download
1304       false,     // has_user_gesture
1305       blink::WebReferrerPolicyDefault,
1306       blink::WebPageVisibilityStateVisible,
1307       context,
1308       base::WeakPtr<ResourceMessageFilter>(),  // filter
1309       true);     // is_async
1310 }
1311
1312 void ResourceDispatcherHostImpl::OnRenderViewHostCreated(
1313     int child_id,
1314     int route_id) {
1315   scheduler_->OnClientCreated(child_id, route_id);
1316 }
1317
1318 void ResourceDispatcherHostImpl::OnRenderViewHostDeleted(
1319     int child_id,
1320     int route_id) {
1321   scheduler_->OnClientDeleted(child_id, route_id);
1322   CancelRequestsForRoute(child_id, route_id);
1323 }
1324
1325 // This function is only used for saving feature.
1326 void ResourceDispatcherHostImpl::BeginSaveFile(
1327     const GURL& url,
1328     const Referrer& referrer,
1329     int child_id,
1330     int route_id,
1331     ResourceContext* context) {
1332   if (is_shutdown_)
1333     return;
1334
1335   // http://crbug.com/90971
1336   char url_buf[128];
1337   base::strlcpy(url_buf, url.spec().c_str(), arraysize(url_buf));
1338   base::debug::Alias(url_buf);
1339   CHECK(ContainsKey(active_resource_contexts_, context));
1340
1341   request_id_--;
1342
1343   const net::URLRequestContext* request_context = context->GetRequestContext();
1344   bool known_proto =
1345       request_context->job_factory()->IsHandledURL(url);
1346   if (!known_proto) {
1347     // Since any URLs which have non-standard scheme have been filtered
1348     // by save manager(see GURL::SchemeIsStandard). This situation
1349     // should not happen.
1350     NOTREACHED();
1351     return;
1352   }
1353
1354   net::CookieStore* cookie_store =
1355       GetContentClient()->browser()->OverrideCookieStoreForRenderProcess(
1356           child_id);
1357   scoped_ptr<net::URLRequest> request(
1358       request_context->CreateRequest(url, net::DEFAULT_PRIORITY, NULL,
1359                                      cookie_store));
1360
1361   request->set_method("GET");
1362   SetReferrerForRequest(request.get(), referrer);
1363
1364   // So far, for saving page, we need fetch content from cache, in the
1365   // future, maybe we can use a configuration to configure this behavior.
1366   request->SetLoadFlags(net::LOAD_PREFERRING_CACHE);
1367
1368   // Since we're just saving some resources we need, disallow downloading.
1369   ResourceRequestInfoImpl* extra_info =
1370       CreateRequestInfo(child_id, route_id, false, context);
1371   extra_info->AssociateWithRequest(request.get());  // Request takes ownership.
1372
1373   scoped_ptr<ResourceHandler> handler(
1374       new SaveFileResourceHandler(request.get(),
1375                                   child_id,
1376                                   route_id,
1377                                   url,
1378                                   save_file_manager_.get()));
1379
1380   BeginRequestInternal(request.Pass(), handler.Pass());
1381 }
1382
1383 void ResourceDispatcherHostImpl::MarkAsTransferredNavigation(
1384     const GlobalRequestID& id) {
1385   GetLoader(id)->MarkAsTransferring();
1386 }
1387
1388 void ResourceDispatcherHostImpl::CancelTransferringNavigation(
1389     const GlobalRequestID& id) {
1390   // Request should still exist and be in the middle of a transfer.
1391   DCHECK(IsTransferredNavigation(id));
1392   RemovePendingRequest(id.child_id, id.request_id);
1393 }
1394
1395 void ResourceDispatcherHostImpl::ResumeDeferredNavigation(
1396     const GlobalRequestID& id) {
1397   ResourceLoader* loader = GetLoader(id);
1398   if (loader) {
1399     // The response we were meant to resume could have already been canceled.
1400     ResourceRequestInfoImpl* info = loader->GetRequestInfo();
1401     if (info->cross_site_handler())
1402       info->cross_site_handler()->ResumeResponse();
1403   }
1404 }
1405
1406 // The object died, so cancel and detach all requests associated with it except
1407 // for downloads and detachable resources, which belong to the browser process
1408 // even if initiated via a renderer.
1409 void ResourceDispatcherHostImpl::CancelRequestsForProcess(int child_id) {
1410   CancelRequestsForRoute(child_id, -1 /* cancel all */);
1411   registered_temp_files_.erase(child_id);
1412 }
1413
1414 void ResourceDispatcherHostImpl::CancelRequestsForRoute(int child_id,
1415                                                         int route_id) {
1416   // Since pending_requests_ is a map, we first build up a list of all of the
1417   // matching requests to be cancelled, and then we cancel them.  Since there
1418   // may be more than one request to cancel, we cannot simply hold onto the map
1419   // iterators found in the first loop.
1420
1421   // Find the global ID of all matching elements.
1422   bool any_requests_transferring = false;
1423   std::vector<GlobalRequestID> matching_requests;
1424   for (LoaderMap::const_iterator i = pending_loaders_.begin();
1425        i != pending_loaders_.end(); ++i) {
1426     if (i->first.child_id != child_id)
1427       continue;
1428
1429     ResourceRequestInfoImpl* info = i->second->GetRequestInfo();
1430
1431     GlobalRequestID id(child_id, i->first.request_id);
1432     DCHECK(id == i->first);
1433     // Don't cancel navigations that are expected to live beyond this process.
1434     if (IsTransferredNavigation(id))
1435       any_requests_transferring = true;
1436     if (info->detachable_handler()) {
1437       info->detachable_handler()->Detach();
1438     } else if (!info->IsDownload() && !info->is_stream() &&
1439                !IsTransferredNavigation(id) &&
1440                (route_id == -1 || route_id == info->GetRouteID())) {
1441       matching_requests.push_back(id);
1442     }
1443   }
1444
1445   // Remove matches.
1446   for (size_t i = 0; i < matching_requests.size(); ++i) {
1447     LoaderMap::iterator iter = pending_loaders_.find(matching_requests[i]);
1448     // Although every matching request was in pending_requests_ when we built
1449     // matching_requests, it is normal for a matching request to be not found
1450     // in pending_requests_ after we have removed some matching requests from
1451     // pending_requests_.  For example, deleting a net::URLRequest that has
1452     // exclusive (write) access to an HTTP cache entry may unblock another
1453     // net::URLRequest that needs exclusive access to the same cache entry, and
1454     // that net::URLRequest may complete and remove itself from
1455     // pending_requests_. So we need to check that iter is not equal to
1456     // pending_requests_.end().
1457     if (iter != pending_loaders_.end())
1458       RemovePendingLoader(iter);
1459   }
1460
1461   // Don't clear the blocked loaders or offline policy maps if any of the
1462   // requests in route_id are being transferred to a new process, since those
1463   // maps will be updated with the new route_id after the transfer.  Otherwise
1464   // we will lose track of this info when the old route goes away, before the
1465   // new one is created.
1466   if (any_requests_transferring)
1467     return;
1468
1469   // Now deal with blocked requests if any.
1470   if (route_id != -1) {
1471     if (blocked_loaders_map_.find(GlobalRoutingID(child_id, route_id)) !=
1472         blocked_loaders_map_.end()) {
1473       CancelBlockedRequestsForRoute(child_id, route_id);
1474     }
1475   } else {
1476     // We have to do all render views for the process |child_id|.
1477     // Note that we have to do this in 2 passes as we cannot call
1478     // CancelBlockedRequestsForRoute while iterating over
1479     // blocked_loaders_map_, as it modifies it.
1480     std::set<int> route_ids;
1481     for (BlockedLoadersMap::const_iterator iter = blocked_loaders_map_.begin();
1482          iter != blocked_loaders_map_.end(); ++iter) {
1483       if (iter->first.child_id == child_id)
1484         route_ids.insert(iter->first.route_id);
1485     }
1486     for (std::set<int>::const_iterator iter = route_ids.begin();
1487         iter != route_ids.end(); ++iter) {
1488       CancelBlockedRequestsForRoute(child_id, *iter);
1489     }
1490   }
1491 }
1492
1493 // Cancels the request and removes it from the list.
1494 void ResourceDispatcherHostImpl::RemovePendingRequest(int child_id,
1495                                                       int request_id) {
1496   LoaderMap::iterator i = pending_loaders_.find(
1497       GlobalRequestID(child_id, request_id));
1498   if (i == pending_loaders_.end()) {
1499     NOTREACHED() << "Trying to remove a request that's not here";
1500     return;
1501   }
1502   RemovePendingLoader(i);
1503 }
1504
1505 void ResourceDispatcherHostImpl::RemovePendingLoader(
1506     const LoaderMap::iterator& iter) {
1507   ResourceRequestInfoImpl* info = iter->second->GetRequestInfo();
1508
1509   // Remove the memory credit that we added when pushing the request onto
1510   // the pending list.
1511   IncrementOutstandingRequestsMemory(-1, *info);
1512
1513   pending_loaders_.erase(iter);
1514
1515   // If we have no more pending requests, then stop the load state monitor
1516   if (pending_loaders_.empty() && update_load_states_timer_)
1517     update_load_states_timer_->Stop();
1518 }
1519
1520 void ResourceDispatcherHostImpl::CancelRequest(int child_id,
1521                                                int request_id) {
1522   ResourceLoader* loader = GetLoader(child_id, request_id);
1523   if (!loader) {
1524     // We probably want to remove this warning eventually, but I wanted to be
1525     // able to notice when this happens during initial development since it
1526     // should be rare and may indicate a bug.
1527     DVLOG(1) << "Canceling a request that wasn't found";
1528     return;
1529   }
1530
1531   RemovePendingRequest(child_id, request_id);
1532 }
1533
1534 ResourceDispatcherHostImpl::OustandingRequestsStats
1535 ResourceDispatcherHostImpl::GetOutstandingRequestsStats(
1536     const ResourceRequestInfoImpl& info) {
1537   OutstandingRequestsStatsMap::iterator entry =
1538       outstanding_requests_stats_map_.find(info.GetChildID());
1539   OustandingRequestsStats stats = { 0, 0 };
1540   if (entry != outstanding_requests_stats_map_.end())
1541     stats = entry->second;
1542   return stats;
1543 }
1544
1545 void ResourceDispatcherHostImpl::UpdateOutstandingRequestsStats(
1546     const ResourceRequestInfoImpl& info,
1547     const OustandingRequestsStats& stats) {
1548   if (stats.memory_cost == 0 && stats.num_requests == 0)
1549     outstanding_requests_stats_map_.erase(info.GetChildID());
1550   else
1551     outstanding_requests_stats_map_[info.GetChildID()] = stats;
1552 }
1553
1554 ResourceDispatcherHostImpl::OustandingRequestsStats
1555 ResourceDispatcherHostImpl::IncrementOutstandingRequestsMemory(
1556     int count,
1557     const ResourceRequestInfoImpl& info) {
1558   DCHECK_EQ(1, abs(count));
1559
1560   // Retrieve the previous value (defaulting to 0 if not found).
1561   OustandingRequestsStats stats = GetOutstandingRequestsStats(info);
1562
1563   // Insert/update the total; delete entries when their count reaches 0.
1564   stats.memory_cost += count * info.memory_cost();
1565   DCHECK_GE(stats.memory_cost, 0);
1566   UpdateOutstandingRequestsStats(info, stats);
1567
1568   return stats;
1569 }
1570
1571 ResourceDispatcherHostImpl::OustandingRequestsStats
1572 ResourceDispatcherHostImpl::IncrementOutstandingRequestsCount(
1573     int count,
1574     const ResourceRequestInfoImpl& info) {
1575   DCHECK_EQ(1, abs(count));
1576   num_in_flight_requests_ += count;
1577
1578   OustandingRequestsStats stats = GetOutstandingRequestsStats(info);
1579   stats.num_requests += count;
1580   DCHECK_GE(stats.num_requests, 0);
1581   UpdateOutstandingRequestsStats(info, stats);
1582
1583   return stats;
1584 }
1585
1586 bool ResourceDispatcherHostImpl::HasSufficientResourcesForRequest(
1587     const net::URLRequest* request_) {
1588   const ResourceRequestInfoImpl* info =
1589       ResourceRequestInfoImpl::ForRequest(request_);
1590   OustandingRequestsStats stats = IncrementOutstandingRequestsCount(1, *info);
1591
1592   if (stats.num_requests > max_num_in_flight_requests_per_process_)
1593     return false;
1594   if (num_in_flight_requests_ > max_num_in_flight_requests_)
1595     return false;
1596
1597   return true;
1598 }
1599
1600 void ResourceDispatcherHostImpl::FinishedWithResourcesForRequest(
1601     const net::URLRequest* request_) {
1602   const ResourceRequestInfoImpl* info =
1603       ResourceRequestInfoImpl::ForRequest(request_);
1604   IncrementOutstandingRequestsCount(-1, *info);
1605 }
1606
1607 // static
1608 int ResourceDispatcherHostImpl::CalculateApproximateMemoryCost(
1609     net::URLRequest* request) {
1610   // The following fields should be a minor size contribution (experimentally
1611   // on the order of 100). However since they are variable length, it could
1612   // in theory be a sizeable contribution.
1613   int strings_cost = request->extra_request_headers().ToString().size() +
1614                      request->original_url().spec().size() +
1615                      request->referrer().size() +
1616                      request->method().size();
1617
1618   // Note that this expression will typically be dominated by:
1619   // |kAvgBytesPerOutstandingRequest|.
1620   return kAvgBytesPerOutstandingRequest + strings_cost;
1621 }
1622
1623 void ResourceDispatcherHostImpl::BeginRequestInternal(
1624     scoped_ptr<net::URLRequest> request,
1625     scoped_ptr<ResourceHandler> handler) {
1626   DCHECK(!request->is_pending());
1627   ResourceRequestInfoImpl* info =
1628       ResourceRequestInfoImpl::ForRequest(request.get());
1629
1630   if ((TimeTicks::Now() - last_user_gesture_time_) <
1631       TimeDelta::FromMilliseconds(kUserGestureWindowMs)) {
1632     request->SetLoadFlags(
1633         request->load_flags() | net::LOAD_MAYBE_USER_GESTURE);
1634   }
1635
1636   // Add the memory estimate that starting this request will consume.
1637   info->set_memory_cost(CalculateApproximateMemoryCost(request.get()));
1638
1639   // If enqueing/starting this request will exceed our per-process memory
1640   // bound, abort it right away.
1641   OustandingRequestsStats stats = IncrementOutstandingRequestsMemory(1, *info);
1642   if (stats.memory_cost > max_outstanding_requests_cost_per_process_) {
1643     // We call "CancelWithError()" as a way of setting the net::URLRequest's
1644     // status -- it has no effect beyond this, since the request hasn't started.
1645     request->CancelWithError(net::ERR_INSUFFICIENT_RESOURCES);
1646
1647     bool defer = false;
1648     handler->OnResponseCompleted(request->status(), std::string(), &defer);
1649     if (defer) {
1650       // TODO(darin): The handler is not ready for us to kill the request. Oops!
1651       NOTREACHED();
1652     }
1653
1654     IncrementOutstandingRequestsMemory(-1, *info);
1655
1656     // A ResourceHandler must not outlive its associated URLRequest.
1657     handler.reset();
1658     return;
1659   }
1660
1661   linked_ptr<ResourceLoader> loader(
1662       new ResourceLoader(request.Pass(), handler.Pass(), this));
1663
1664   GlobalRoutingID id(info->GetGlobalRoutingID());
1665   BlockedLoadersMap::const_iterator iter = blocked_loaders_map_.find(id);
1666   if (iter != blocked_loaders_map_.end()) {
1667     // The request should be blocked.
1668     iter->second->push_back(loader);
1669     return;
1670   }
1671
1672   StartLoading(info, loader);
1673 }
1674
1675 void ResourceDispatcherHostImpl::StartLoading(
1676     ResourceRequestInfoImpl* info,
1677     const linked_ptr<ResourceLoader>& loader) {
1678   pending_loaders_[info->GetGlobalRequestID()] = loader;
1679
1680   loader->StartRequest();
1681 }
1682
1683 void ResourceDispatcherHostImpl::OnUserGesture(WebContentsImpl* contents) {
1684   last_user_gesture_time_ = TimeTicks::Now();
1685 }
1686
1687 net::URLRequest* ResourceDispatcherHostImpl::GetURLRequest(
1688     const GlobalRequestID& id) {
1689   ResourceLoader* loader = GetLoader(id);
1690   if (!loader)
1691     return NULL;
1692
1693   return loader->request();
1694 }
1695
1696 namespace {
1697
1698 // This function attempts to return the "more interesting" load state of |a|
1699 // and |b|.  We don't have temporal information about these load states
1700 // (meaning we don't know when we transitioned into these states), so we just
1701 // rank them according to how "interesting" the states are.
1702 //
1703 // We take advantage of the fact that the load states are an enumeration listed
1704 // in the order in which they occur during the lifetime of a request, so we can
1705 // regard states with larger numeric values as being further along toward
1706 // completion.  We regard those states as more interesting to report since they
1707 // represent progress.
1708 //
1709 // For example, by this measure "tranferring data" is a more interesting state
1710 // than "resolving host" because when we are transferring data we are actually
1711 // doing something that corresponds to changes that the user might observe,
1712 // whereas waiting for a host name to resolve implies being stuck.
1713 //
1714 const net::LoadStateWithParam& MoreInterestingLoadState(
1715     const net::LoadStateWithParam& a, const net::LoadStateWithParam& b) {
1716   return (a.state < b.state) ? b : a;
1717 }
1718
1719 // Carries information about a load state change.
1720 struct LoadInfo {
1721   GURL url;
1722   net::LoadStateWithParam load_state;
1723   uint64 upload_position;
1724   uint64 upload_size;
1725 };
1726
1727 // Map from ProcessID+RouteID pair to LoadState
1728 typedef std::map<GlobalRoutingID, LoadInfo> LoadInfoMap;
1729
1730 // Used to marshal calls to LoadStateChanged from the IO to UI threads.  We do
1731 // them all as a single callback to avoid spamming the UI thread.
1732 void LoadInfoUpdateCallback(const LoadInfoMap& info_map) {
1733   LoadInfoMap::const_iterator i;
1734   for (i = info_map.begin(); i != info_map.end(); ++i) {
1735     RenderViewHostImpl* view =
1736         RenderViewHostImpl::FromID(i->first.child_id, i->first.route_id);
1737     if (view)  // The view could be gone at this point.
1738       view->LoadStateChanged(i->second.url, i->second.load_state,
1739                              i->second.upload_position,
1740                              i->second.upload_size);
1741   }
1742 }
1743
1744 }  // namespace
1745
1746 void ResourceDispatcherHostImpl::UpdateLoadStates() {
1747   // Populate this map with load state changes, and then send them on to the UI
1748   // thread where they can be passed along to the respective RVHs.
1749   LoadInfoMap info_map;
1750
1751   LoaderMap::const_iterator i;
1752
1753   // Determine the largest upload size of all requests
1754   // in each View (good chance it's zero).
1755   std::map<GlobalRoutingID, uint64> largest_upload_size;
1756   for (i = pending_loaders_.begin(); i != pending_loaders_.end(); ++i) {
1757     net::URLRequest* request = i->second->request();
1758     ResourceRequestInfoImpl* info = i->second->GetRequestInfo();
1759     uint64 upload_size = request->GetUploadProgress().size();
1760     if (request->GetLoadState().state != net::LOAD_STATE_SENDING_REQUEST)
1761       upload_size = 0;
1762     GlobalRoutingID id(info->GetGlobalRoutingID());
1763     if (upload_size && largest_upload_size[id] < upload_size)
1764       largest_upload_size[id] = upload_size;
1765   }
1766
1767   for (i = pending_loaders_.begin(); i != pending_loaders_.end(); ++i) {
1768     net::URLRequest* request = i->second->request();
1769     ResourceRequestInfoImpl* info = i->second->GetRequestInfo();
1770     net::LoadStateWithParam load_state = request->GetLoadState();
1771     net::UploadProgress progress = request->GetUploadProgress();
1772
1773     // We also poll for upload progress on this timer and send upload
1774     // progress ipc messages to the plugin process.
1775     i->second->ReportUploadProgress();
1776
1777     GlobalRoutingID id(info->GetGlobalRoutingID());
1778
1779     // If a request is uploading data, ignore all other requests so that the
1780     // upload progress takes priority for being shown in the status bar.
1781     if (largest_upload_size.find(id) != largest_upload_size.end() &&
1782         progress.size() < largest_upload_size[id])
1783       continue;
1784
1785     net::LoadStateWithParam to_insert = load_state;
1786     LoadInfoMap::iterator existing = info_map.find(id);
1787     if (existing != info_map.end()) {
1788       to_insert =
1789           MoreInterestingLoadState(existing->second.load_state, load_state);
1790       if (to_insert.state == existing->second.load_state.state)
1791         continue;
1792     }
1793     LoadInfo& load_info = info_map[id];
1794     load_info.url = request->url();
1795     load_info.load_state = to_insert;
1796     load_info.upload_size = progress.size();
1797     load_info.upload_position = progress.position();
1798   }
1799
1800   if (info_map.empty())
1801     return;
1802
1803   BrowserThread::PostTask(
1804       BrowserThread::UI, FROM_HERE,
1805       base::Bind(&LoadInfoUpdateCallback, info_map));
1806 }
1807
1808 void ResourceDispatcherHostImpl::BlockRequestsForRoute(int child_id,
1809                                                        int route_id) {
1810   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::IO));
1811   GlobalRoutingID key(child_id, route_id);
1812   DCHECK(blocked_loaders_map_.find(key) == blocked_loaders_map_.end()) <<
1813       "BlockRequestsForRoute called  multiple time for the same RVH";
1814   blocked_loaders_map_[key] = new BlockedLoadersList();
1815 }
1816
1817 void ResourceDispatcherHostImpl::ResumeBlockedRequestsForRoute(int child_id,
1818                                                                int route_id) {
1819   ProcessBlockedRequestsForRoute(child_id, route_id, false);
1820 }
1821
1822 void ResourceDispatcherHostImpl::CancelBlockedRequestsForRoute(int child_id,
1823                                                                int route_id) {
1824   ProcessBlockedRequestsForRoute(child_id, route_id, true);
1825 }
1826
1827 void ResourceDispatcherHostImpl::ProcessBlockedRequestsForRoute(
1828     int child_id,
1829     int route_id,
1830     bool cancel_requests) {
1831   BlockedLoadersMap::iterator iter = blocked_loaders_map_.find(
1832       GlobalRoutingID(child_id, route_id));
1833   if (iter == blocked_loaders_map_.end()) {
1834     // It's possible to reach here if the renderer crashed while an interstitial
1835     // page was showing.
1836     return;
1837   }
1838
1839   BlockedLoadersList* loaders = iter->second;
1840
1841   // Removing the vector from the map unblocks any subsequent requests.
1842   blocked_loaders_map_.erase(iter);
1843
1844   for (BlockedLoadersList::iterator loaders_iter = loaders->begin();
1845        loaders_iter != loaders->end(); ++loaders_iter) {
1846     linked_ptr<ResourceLoader> loader = *loaders_iter;
1847     ResourceRequestInfoImpl* info = loader->GetRequestInfo();
1848     if (cancel_requests) {
1849       IncrementOutstandingRequestsMemory(-1, *info);
1850     } else {
1851       StartLoading(info, loader);
1852     }
1853   }
1854
1855   delete loaders;
1856 }
1857
1858 ResourceDispatcherHostImpl::HttpAuthRelationType
1859 ResourceDispatcherHostImpl::HttpAuthRelationTypeOf(
1860     const GURL& request_url,
1861     const GURL& first_party) {
1862   if (!first_party.is_valid())
1863     return HTTP_AUTH_RELATION_TOP;
1864
1865   if (net::registry_controlled_domains::SameDomainOrHost(
1866           first_party, request_url,
1867           net::registry_controlled_domains::INCLUDE_PRIVATE_REGISTRIES))
1868     return HTTP_AUTH_RELATION_SAME_DOMAIN;
1869
1870   if (allow_cross_origin_auth_prompt())
1871     return HTTP_AUTH_RELATION_ALLOWED_CROSS;
1872
1873   return HTTP_AUTH_RELATION_BLOCKED_CROSS;
1874 }
1875
1876 bool ResourceDispatcherHostImpl::allow_cross_origin_auth_prompt() {
1877   return allow_cross_origin_auth_prompt_;
1878 }
1879
1880 bool ResourceDispatcherHostImpl::IsTransferredNavigation(
1881     const GlobalRequestID& id) const {
1882   ResourceLoader* loader = GetLoader(id);
1883   return loader ? loader->is_transferring() : false;
1884 }
1885
1886 ResourceLoader* ResourceDispatcherHostImpl::GetLoader(
1887     const GlobalRequestID& id) const {
1888   DCHECK(BrowserThread::CurrentlyOn(BrowserThread::IO));
1889
1890   LoaderMap::const_iterator i = pending_loaders_.find(id);
1891   if (i == pending_loaders_.end())
1892     return NULL;
1893
1894   return i->second.get();
1895 }
1896
1897 ResourceLoader* ResourceDispatcherHostImpl::GetLoader(int child_id,
1898                                                       int request_id) const {
1899   return GetLoader(GlobalRequestID(child_id, request_id));
1900 }
1901
1902 void ResourceDispatcherHostImpl::RegisterResourceMessageDelegate(
1903     const GlobalRequestID& id, ResourceMessageDelegate* delegate) {
1904   DelegateMap::iterator it = delegate_map_.find(id);
1905   if (it == delegate_map_.end()) {
1906     it = delegate_map_.insert(
1907         std::make_pair(id, new ObserverList<ResourceMessageDelegate>)).first;
1908   }
1909   it->second->AddObserver(delegate);
1910 }
1911
1912 void ResourceDispatcherHostImpl::UnregisterResourceMessageDelegate(
1913     const GlobalRequestID& id, ResourceMessageDelegate* delegate) {
1914   DCHECK(ContainsKey(delegate_map_, id));
1915   DelegateMap::iterator it = delegate_map_.find(id);
1916   DCHECK(it->second->HasObserver(delegate));
1917   it->second->RemoveObserver(delegate);
1918   if (!it->second->might_have_observers()) {
1919     delete it->second;
1920     delegate_map_.erase(it);
1921   }
1922 }
1923
1924 int ResourceDispatcherHostImpl::BuildLoadFlagsForRequest(
1925     const ResourceHostMsg_Request& request_data,
1926     int child_id,
1927     bool is_sync_load) {
1928   int load_flags = request_data.load_flags;
1929
1930   // Although EV status is irrelevant to sub-frames and sub-resources, we have
1931   // to perform EV certificate verification on all resources because an HTTP
1932   // keep-alive connection created to load a sub-frame or a sub-resource could
1933   // be reused to load a main frame.
1934   load_flags |= net::LOAD_VERIFY_EV_CERT;
1935   if (request_data.resource_type == ResourceType::MAIN_FRAME) {
1936     load_flags |= net::LOAD_MAIN_FRAME;
1937   } else if (request_data.resource_type == ResourceType::SUB_FRAME) {
1938     load_flags |= net::LOAD_SUB_FRAME;
1939   } else if (request_data.resource_type == ResourceType::PREFETCH) {
1940     load_flags |= (net::LOAD_PREFETCH | net::LOAD_DO_NOT_PROMPT_FOR_LOGIN);
1941   } else if (request_data.resource_type == ResourceType::FAVICON) {
1942     load_flags |= net::LOAD_DO_NOT_PROMPT_FOR_LOGIN;
1943   } else if (request_data.resource_type == ResourceType::IMAGE) {
1944     // Prevent third-party image content from prompting for login, as this
1945     // is often a scam to extract credentials for another domain from the user.
1946     // Only block image loads, as the attack applies largely to the "src"
1947     // property of the <img> tag. It is common for web properties to allow
1948     // untrusted values for <img src>; this is considered a fair thing for an
1949     // HTML sanitizer to do. Conversely, any HTML sanitizer that didn't
1950     // filter sources for <script>, <link>, <embed>, <object>, <iframe> tags
1951     // would be considered vulnerable in and of itself.
1952     HttpAuthRelationType relation_type = HttpAuthRelationTypeOf(
1953         request_data.url, request_data.first_party_for_cookies);
1954     if (relation_type == HTTP_AUTH_RELATION_BLOCKED_CROSS) {
1955       load_flags |= (net::LOAD_DO_NOT_USE_EMBEDDED_IDENTITY |
1956                      net::LOAD_DO_NOT_PROMPT_FOR_LOGIN);
1957     }
1958   }
1959
1960   if (is_sync_load)
1961     load_flags |= net::LOAD_IGNORE_LIMITS;
1962
1963   ChildProcessSecurityPolicyImpl* policy =
1964       ChildProcessSecurityPolicyImpl::GetInstance();
1965   if (!policy->CanSendCookiesForOrigin(child_id, request_data.url)) {
1966     load_flags |= (net::LOAD_DO_NOT_SEND_COOKIES |
1967                    net::LOAD_DO_NOT_SEND_AUTH_DATA |
1968                    net::LOAD_DO_NOT_SAVE_COOKIES);
1969   }
1970
1971   // Raw headers are sensitive, as they include Cookie/Set-Cookie, so only
1972   // allow requesting them if requester has ReadRawCookies permission.
1973   if ((load_flags & net::LOAD_REPORT_RAW_HEADERS)
1974       && !policy->CanReadRawCookies(child_id)) {
1975     VLOG(1) << "Denied unauthorized request for raw headers";
1976     load_flags &= ~net::LOAD_REPORT_RAW_HEADERS;
1977   }
1978
1979   return load_flags;
1980 }
1981
1982 }  // namespace content