Bug 1829125 - Align the PHC area to the jemalloc chunk size r=glandium
[gecko.git] / image / imgLoader.cpp
blob951f9bc5b18d5faa8a2c40565e1085041a3bf255
1 /* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
2 /* vim: set ts=8 sts=2 et sw=2 tw=80: */
3 /* This Source Code Form is subject to the terms of the Mozilla Public
4 * License, v. 2.0. If a copy of the MPL was not distributed with this
5 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
7 // Undefine windows version of LoadImage because our code uses that name.
8 #include "mozilla/ScopeExit.h"
9 #include "nsIChildChannel.h"
10 #undef LoadImage
12 #include "imgLoader.h"
14 #include <algorithm>
15 #include <utility>
17 #include "DecoderFactory.h"
18 #include "Image.h"
19 #include "ImageLogging.h"
20 #include "ReferrerInfo.h"
21 #include "imgRequestProxy.h"
22 #include "mozilla/Attributes.h"
23 #include "mozilla/BasePrincipal.h"
24 #include "mozilla/ChaosMode.h"
25 #include "mozilla/ClearOnShutdown.h"
26 #include "mozilla/LoadInfo.h"
27 #include "mozilla/NullPrincipal.h"
28 #include "mozilla/Preferences.h"
29 #include "mozilla/ProfilerLabels.h"
30 #include "mozilla/StaticPrefs_image.h"
31 #include "mozilla/StaticPrefs_network.h"
32 #include "mozilla/StoragePrincipalHelper.h"
33 #include "mozilla/dom/ContentParent.h"
34 #include "mozilla/dom/nsMixedContentBlocker.h"
35 #include "mozilla/image/ImageMemoryReporter.h"
36 #include "mozilla/layers/CompositorManagerChild.h"
37 #include "nsCOMPtr.h"
38 #include "nsCRT.h"
39 #include "nsComponentManagerUtils.h"
40 #include "nsContentPolicyUtils.h"
41 #include "nsContentSecurityManager.h"
42 #include "nsContentUtils.h"
43 #include "nsHttpChannel.h"
44 #include "nsIAsyncVerifyRedirectCallback.h"
45 #include "nsICacheInfoChannel.h"
46 #include "nsIChannelEventSink.h"
47 #include "nsIClassOfService.h"
48 #include "nsIEffectiveTLDService.h"
49 #include "nsIFile.h"
50 #include "nsIFileURL.h"
51 #include "nsIHttpChannel.h"
52 #include "nsIInterfaceRequestor.h"
53 #include "nsIInterfaceRequestorUtils.h"
54 #include "nsIMemoryReporter.h"
55 #include "nsINetworkPredictor.h"
56 #include "nsIProgressEventSink.h"
57 #include "nsIProtocolHandler.h"
58 #include "nsImageModule.h"
59 #include "nsMediaSniffer.h"
60 #include "nsMimeTypes.h"
61 #include "nsNetCID.h"
62 #include "nsNetUtil.h"
63 #include "nsProxyRelease.h"
64 #include "nsQueryObject.h"
65 #include "nsReadableUtils.h"
66 #include "nsStreamUtils.h"
67 #include "prtime.h"
69 // we want to explore making the document own the load group
70 // so we can associate the document URI with the load group.
71 // until this point, we have an evil hack:
72 #include "nsIHttpChannelInternal.h"
73 #include "nsILoadGroupChild.h"
74 #include "nsIDocShell.h"
76 using namespace mozilla;
77 using namespace mozilla::dom;
78 using namespace mozilla::image;
79 using namespace mozilla::net;
81 MOZ_DEFINE_MALLOC_SIZE_OF(ImagesMallocSizeOf)
83 class imgMemoryReporter final : public nsIMemoryReporter {
84 ~imgMemoryReporter() = default;
86 public:
87 NS_DECL_ISUPPORTS
89 NS_IMETHOD CollectReports(nsIHandleReportCallback* aHandleReport,
90 nsISupports* aData, bool aAnonymize) override {
91 MOZ_ASSERT(NS_IsMainThread());
93 layers::CompositorManagerChild* manager =
94 mozilla::layers::CompositorManagerChild::GetInstance();
95 if (!manager || !StaticPrefs::image_mem_debug_reporting()) {
96 layers::SharedSurfacesMemoryReport sharedSurfaces;
97 FinishCollectReports(aHandleReport, aData, aAnonymize, sharedSurfaces);
98 return NS_OK;
101 RefPtr<imgMemoryReporter> self(this);
102 nsCOMPtr<nsIHandleReportCallback> handleReport(aHandleReport);
103 nsCOMPtr<nsISupports> data(aData);
104 manager->SendReportSharedSurfacesMemory(
105 [=](layers::SharedSurfacesMemoryReport aReport) {
106 self->FinishCollectReports(handleReport, data, aAnonymize, aReport);
108 [=](mozilla::ipc::ResponseRejectReason&& aReason) {
109 layers::SharedSurfacesMemoryReport sharedSurfaces;
110 self->FinishCollectReports(handleReport, data, aAnonymize,
111 sharedSurfaces);
113 return NS_OK;
116 void FinishCollectReports(
117 nsIHandleReportCallback* aHandleReport, nsISupports* aData,
118 bool aAnonymize, layers::SharedSurfacesMemoryReport& aSharedSurfaces) {
119 nsTArray<ImageMemoryCounter> chrome;
120 nsTArray<ImageMemoryCounter> content;
121 nsTArray<ImageMemoryCounter> uncached;
123 for (uint32_t i = 0; i < mKnownLoaders.Length(); i++) {
124 for (imgCacheEntry* entry : mKnownLoaders[i]->mCache.Values()) {
125 RefPtr<imgRequest> req = entry->GetRequest();
126 RecordCounterForRequest(req, &content, !entry->HasNoProxies());
128 MutexAutoLock lock(mKnownLoaders[i]->mUncachedImagesMutex);
129 for (RefPtr<imgRequest> req : mKnownLoaders[i]->mUncachedImages) {
130 RecordCounterForRequest(req, &uncached, req->HasConsumers());
134 // Note that we only need to anonymize content image URIs.
136 ReportCounterArray(aHandleReport, aData, chrome, "images/chrome",
137 /* aAnonymize */ false, aSharedSurfaces);
139 ReportCounterArray(aHandleReport, aData, content, "images/content",
140 aAnonymize, aSharedSurfaces);
142 // Uncached images may be content or chrome, so anonymize them.
143 ReportCounterArray(aHandleReport, aData, uncached, "images/uncached",
144 aAnonymize, aSharedSurfaces);
146 // Report any shared surfaces that were not merged with the surface cache.
147 ImageMemoryReporter::ReportSharedSurfaces(aHandleReport, aData,
148 aSharedSurfaces);
150 nsCOMPtr<nsIMemoryReporterManager> imgr =
151 do_GetService("@mozilla.org/memory-reporter-manager;1");
152 if (imgr) {
153 imgr->EndReport();
157 static int64_t ImagesContentUsedUncompressedDistinguishedAmount() {
158 size_t n = 0;
159 for (uint32_t i = 0; i < imgLoader::sMemReporter->mKnownLoaders.Length();
160 i++) {
161 for (imgCacheEntry* entry :
162 imgLoader::sMemReporter->mKnownLoaders[i]->mCache.Values()) {
163 if (entry->HasNoProxies()) {
164 continue;
167 RefPtr<imgRequest> req = entry->GetRequest();
168 RefPtr<image::Image> image = req->GetImage();
169 if (!image) {
170 continue;
173 // Both this and EntryImageSizes measure
174 // images/content/raster/used/decoded memory. This function's
175 // measurement is secondary -- the result doesn't go in the "explicit"
176 // tree -- so we use moz_malloc_size_of instead of ImagesMallocSizeOf to
177 // prevent DMD from seeing it reported twice.
178 SizeOfState state(moz_malloc_size_of);
179 ImageMemoryCounter counter(req, image, state, /* aIsUsed = */ true);
181 n += counter.Values().DecodedHeap();
182 n += counter.Values().DecodedNonHeap();
183 n += counter.Values().DecodedUnknown();
186 return n;
189 void RegisterLoader(imgLoader* aLoader) {
190 mKnownLoaders.AppendElement(aLoader);
193 void UnregisterLoader(imgLoader* aLoader) {
194 mKnownLoaders.RemoveElement(aLoader);
197 private:
198 nsTArray<imgLoader*> mKnownLoaders;
200 struct MemoryTotal {
201 MemoryTotal& operator+=(const ImageMemoryCounter& aImageCounter) {
202 if (aImageCounter.Type() == imgIContainer::TYPE_RASTER) {
203 if (aImageCounter.IsUsed()) {
204 mUsedRasterCounter += aImageCounter.Values();
205 } else {
206 mUnusedRasterCounter += aImageCounter.Values();
208 } else if (aImageCounter.Type() == imgIContainer::TYPE_VECTOR) {
209 if (aImageCounter.IsUsed()) {
210 mUsedVectorCounter += aImageCounter.Values();
211 } else {
212 mUnusedVectorCounter += aImageCounter.Values();
214 } else if (aImageCounter.Type() == imgIContainer::TYPE_REQUEST) {
215 // Nothing to do, we did not get to the point of having an image.
216 } else {
217 MOZ_CRASH("Unexpected image type");
220 return *this;
223 const MemoryCounter& UsedRaster() const { return mUsedRasterCounter; }
224 const MemoryCounter& UnusedRaster() const { return mUnusedRasterCounter; }
225 const MemoryCounter& UsedVector() const { return mUsedVectorCounter; }
226 const MemoryCounter& UnusedVector() const { return mUnusedVectorCounter; }
228 private:
229 MemoryCounter mUsedRasterCounter;
230 MemoryCounter mUnusedRasterCounter;
231 MemoryCounter mUsedVectorCounter;
232 MemoryCounter mUnusedVectorCounter;
235 // Reports all images of a single kind, e.g. all used chrome images.
236 void ReportCounterArray(nsIHandleReportCallback* aHandleReport,
237 nsISupports* aData,
238 nsTArray<ImageMemoryCounter>& aCounterArray,
239 const char* aPathPrefix, bool aAnonymize,
240 layers::SharedSurfacesMemoryReport& aSharedSurfaces) {
241 MemoryTotal summaryTotal;
242 MemoryTotal nonNotableTotal;
244 // Report notable images, and compute total and non-notable aggregate sizes.
245 for (uint32_t i = 0; i < aCounterArray.Length(); i++) {
246 ImageMemoryCounter& counter = aCounterArray[i];
248 if (aAnonymize) {
249 counter.URI().Truncate();
250 counter.URI().AppendPrintf("<anonymized-%u>", i);
251 } else {
252 // The URI could be an extremely long data: URI. Truncate if needed.
253 static const size_t max = 256;
254 if (counter.URI().Length() > max) {
255 counter.URI().Truncate(max);
256 counter.URI().AppendLiteral(" (truncated)");
258 counter.URI().ReplaceChar('/', '\\');
261 summaryTotal += counter;
263 if (counter.IsNotable() || StaticPrefs::image_mem_debug_reporting()) {
264 ReportImage(aHandleReport, aData, aPathPrefix, counter,
265 aSharedSurfaces);
266 } else {
267 ImageMemoryReporter::TrimSharedSurfaces(counter, aSharedSurfaces);
268 nonNotableTotal += counter;
272 // Report non-notable images in aggregate.
273 ReportTotal(aHandleReport, aData, /* aExplicit = */ true, aPathPrefix,
274 "<non-notable images>/", nonNotableTotal);
276 // Report a summary in aggregate, outside of the explicit tree.
277 ReportTotal(aHandleReport, aData, /* aExplicit = */ false, aPathPrefix, "",
278 summaryTotal);
281 static void ReportImage(nsIHandleReportCallback* aHandleReport,
282 nsISupports* aData, const char* aPathPrefix,
283 const ImageMemoryCounter& aCounter,
284 layers::SharedSurfacesMemoryReport& aSharedSurfaces) {
285 nsAutoCString pathPrefix("explicit/"_ns);
286 pathPrefix.Append(aPathPrefix);
288 switch (aCounter.Type()) {
289 case imgIContainer::TYPE_RASTER:
290 pathPrefix.AppendLiteral("/raster/");
291 break;
292 case imgIContainer::TYPE_VECTOR:
293 pathPrefix.AppendLiteral("/vector/");
294 break;
295 case imgIContainer::TYPE_REQUEST:
296 pathPrefix.AppendLiteral("/request/");
297 break;
298 default:
299 pathPrefix.AppendLiteral("/unknown=");
300 pathPrefix.AppendInt(aCounter.Type());
301 pathPrefix.AppendLiteral("/");
302 break;
305 pathPrefix.Append(aCounter.IsUsed() ? "used/" : "unused/");
306 if (aCounter.IsValidating()) {
307 pathPrefix.AppendLiteral("validating/");
309 if (aCounter.HasError()) {
310 pathPrefix.AppendLiteral("err/");
313 pathPrefix.AppendLiteral("progress=");
314 pathPrefix.AppendInt(aCounter.Progress(), 16);
315 pathPrefix.AppendLiteral("/");
317 pathPrefix.AppendLiteral("image(");
318 pathPrefix.AppendInt(aCounter.IntrinsicSize().width);
319 pathPrefix.AppendLiteral("x");
320 pathPrefix.AppendInt(aCounter.IntrinsicSize().height);
321 pathPrefix.AppendLiteral(", ");
323 if (aCounter.URI().IsEmpty()) {
324 pathPrefix.AppendLiteral("<unknown URI>");
325 } else {
326 pathPrefix.Append(aCounter.URI());
329 pathPrefix.AppendLiteral(")/");
331 ReportSurfaces(aHandleReport, aData, pathPrefix, aCounter, aSharedSurfaces);
333 ReportSourceValue(aHandleReport, aData, pathPrefix, aCounter.Values());
336 static void ReportSurfaces(
337 nsIHandleReportCallback* aHandleReport, nsISupports* aData,
338 const nsACString& aPathPrefix, const ImageMemoryCounter& aCounter,
339 layers::SharedSurfacesMemoryReport& aSharedSurfaces) {
340 for (const SurfaceMemoryCounter& counter : aCounter.Surfaces()) {
341 nsAutoCString surfacePathPrefix(aPathPrefix);
342 switch (counter.Type()) {
343 case SurfaceMemoryCounterType::NORMAL:
344 if (counter.IsLocked()) {
345 surfacePathPrefix.AppendLiteral("locked/");
346 } else {
347 surfacePathPrefix.AppendLiteral("unlocked/");
349 if (counter.IsFactor2()) {
350 surfacePathPrefix.AppendLiteral("factor2/");
352 if (counter.CannotSubstitute()) {
353 surfacePathPrefix.AppendLiteral("cannot_substitute/");
355 break;
356 case SurfaceMemoryCounterType::CONTAINER:
357 surfacePathPrefix.AppendLiteral("container/");
358 break;
359 default:
360 MOZ_ASSERT_UNREACHABLE("Unknown counter type");
361 break;
364 surfacePathPrefix.AppendLiteral("types=");
365 surfacePathPrefix.AppendInt(counter.Values().SurfaceTypes(), 16);
366 surfacePathPrefix.AppendLiteral("/surface(");
367 surfacePathPrefix.AppendInt(counter.Key().Size().width);
368 surfacePathPrefix.AppendLiteral("x");
369 surfacePathPrefix.AppendInt(counter.Key().Size().height);
371 if (!counter.IsFinished()) {
372 surfacePathPrefix.AppendLiteral(", incomplete");
375 if (counter.Values().ExternalHandles() > 0) {
376 surfacePathPrefix.AppendLiteral(", handles:");
377 surfacePathPrefix.AppendInt(
378 uint32_t(counter.Values().ExternalHandles()));
381 ImageMemoryReporter::AppendSharedSurfacePrefix(surfacePathPrefix, counter,
382 aSharedSurfaces);
384 PlaybackType playback = counter.Key().Playback();
385 if (playback == PlaybackType::eAnimated) {
386 if (StaticPrefs::image_mem_debug_reporting()) {
387 surfacePathPrefix.AppendPrintf(
388 " (animation %4u)", uint32_t(counter.Values().FrameIndex()));
389 } else {
390 surfacePathPrefix.AppendLiteral(" (animation)");
394 if (counter.Key().Flags() != DefaultSurfaceFlags()) {
395 surfacePathPrefix.AppendLiteral(", flags:");
396 surfacePathPrefix.AppendInt(uint32_t(counter.Key().Flags()),
397 /* aRadix = */ 16);
400 if (counter.Key().Region()) {
401 const ImageIntRegion& region = counter.Key().Region().ref();
402 const gfx::IntRect& rect = region.Rect();
403 surfacePathPrefix.AppendLiteral(", region:[ rect=(");
404 surfacePathPrefix.AppendInt(rect.x);
405 surfacePathPrefix.AppendLiteral(",");
406 surfacePathPrefix.AppendInt(rect.y);
407 surfacePathPrefix.AppendLiteral(") ");
408 surfacePathPrefix.AppendInt(rect.width);
409 surfacePathPrefix.AppendLiteral("x");
410 surfacePathPrefix.AppendInt(rect.height);
411 if (region.IsRestricted()) {
412 const gfx::IntRect& restrict = region.Restriction();
413 if (restrict == rect) {
414 surfacePathPrefix.AppendLiteral(", restrict=rect");
415 } else {
416 surfacePathPrefix.AppendLiteral(", restrict=(");
417 surfacePathPrefix.AppendInt(restrict.x);
418 surfacePathPrefix.AppendLiteral(",");
419 surfacePathPrefix.AppendInt(restrict.y);
420 surfacePathPrefix.AppendLiteral(") ");
421 surfacePathPrefix.AppendInt(restrict.width);
422 surfacePathPrefix.AppendLiteral("x");
423 surfacePathPrefix.AppendInt(restrict.height);
426 if (region.GetExtendMode() != gfx::ExtendMode::CLAMP) {
427 surfacePathPrefix.AppendLiteral(", extendMode=");
428 surfacePathPrefix.AppendInt(int32_t(region.GetExtendMode()));
430 surfacePathPrefix.AppendLiteral("]");
433 const SVGImageContext& context = counter.Key().SVGContext();
434 surfacePathPrefix.AppendLiteral(", svgContext:[ ");
435 if (context.GetViewportSize()) {
436 const CSSIntSize& size = context.GetViewportSize().ref();
437 surfacePathPrefix.AppendLiteral("viewport=(");
438 surfacePathPrefix.AppendInt(size.width);
439 surfacePathPrefix.AppendLiteral("x");
440 surfacePathPrefix.AppendInt(size.height);
441 surfacePathPrefix.AppendLiteral(") ");
443 if (context.GetPreserveAspectRatio()) {
444 nsAutoString aspect;
445 context.GetPreserveAspectRatio()->ToString(aspect);
446 surfacePathPrefix.AppendLiteral("preserveAspectRatio=(");
447 LossyAppendUTF16toASCII(aspect, surfacePathPrefix);
448 surfacePathPrefix.AppendLiteral(") ");
450 if (auto scheme = context.GetColorScheme()) {
451 surfacePathPrefix.AppendLiteral("colorScheme=");
452 surfacePathPrefix.AppendInt(int32_t(*scheme));
453 surfacePathPrefix.AppendLiteral(" ");
455 if (context.GetContextPaint()) {
456 const SVGEmbeddingContextPaint* paint = context.GetContextPaint();
457 surfacePathPrefix.AppendLiteral("contextPaint=(");
458 if (paint->GetFill()) {
459 surfacePathPrefix.AppendLiteral(" fill=");
460 surfacePathPrefix.AppendInt(paint->GetFill()->ToABGR(), 16);
462 if (paint->GetFillOpacity() != 1.0) {
463 surfacePathPrefix.AppendLiteral(" fillOpa=");
464 surfacePathPrefix.AppendFloat(paint->GetFillOpacity());
466 if (paint->GetStroke()) {
467 surfacePathPrefix.AppendLiteral(" stroke=");
468 surfacePathPrefix.AppendInt(paint->GetStroke()->ToABGR(), 16);
470 if (paint->GetStrokeOpacity() != 1.0) {
471 surfacePathPrefix.AppendLiteral(" strokeOpa=");
472 surfacePathPrefix.AppendFloat(paint->GetStrokeOpacity());
474 surfacePathPrefix.AppendLiteral(" ) ");
476 surfacePathPrefix.AppendLiteral("]");
478 surfacePathPrefix.AppendLiteral(")/");
480 ReportValues(aHandleReport, aData, surfacePathPrefix, counter.Values());
484 static void ReportTotal(nsIHandleReportCallback* aHandleReport,
485 nsISupports* aData, bool aExplicit,
486 const char* aPathPrefix, const char* aPathInfix,
487 const MemoryTotal& aTotal) {
488 nsAutoCString pathPrefix;
489 if (aExplicit) {
490 pathPrefix.AppendLiteral("explicit/");
492 pathPrefix.Append(aPathPrefix);
494 nsAutoCString rasterUsedPrefix(pathPrefix);
495 rasterUsedPrefix.AppendLiteral("/raster/used/");
496 rasterUsedPrefix.Append(aPathInfix);
497 ReportValues(aHandleReport, aData, rasterUsedPrefix, aTotal.UsedRaster());
499 nsAutoCString rasterUnusedPrefix(pathPrefix);
500 rasterUnusedPrefix.AppendLiteral("/raster/unused/");
501 rasterUnusedPrefix.Append(aPathInfix);
502 ReportValues(aHandleReport, aData, rasterUnusedPrefix,
503 aTotal.UnusedRaster());
505 nsAutoCString vectorUsedPrefix(pathPrefix);
506 vectorUsedPrefix.AppendLiteral("/vector/used/");
507 vectorUsedPrefix.Append(aPathInfix);
508 ReportValues(aHandleReport, aData, vectorUsedPrefix, aTotal.UsedVector());
510 nsAutoCString vectorUnusedPrefix(pathPrefix);
511 vectorUnusedPrefix.AppendLiteral("/vector/unused/");
512 vectorUnusedPrefix.Append(aPathInfix);
513 ReportValues(aHandleReport, aData, vectorUnusedPrefix,
514 aTotal.UnusedVector());
517 static void ReportValues(nsIHandleReportCallback* aHandleReport,
518 nsISupports* aData, const nsACString& aPathPrefix,
519 const MemoryCounter& aCounter) {
520 ReportSourceValue(aHandleReport, aData, aPathPrefix, aCounter);
522 ReportValue(aHandleReport, aData, KIND_HEAP, aPathPrefix, "decoded-heap",
523 "Decoded image data which is stored on the heap.",
524 aCounter.DecodedHeap());
526 ReportValue(aHandleReport, aData, KIND_NONHEAP, aPathPrefix,
527 "decoded-nonheap",
528 "Decoded image data which isn't stored on the heap.",
529 aCounter.DecodedNonHeap());
531 // We don't know for certain whether or not it is on the heap, so let's
532 // just report it as non-heap for reporting purposes.
533 ReportValue(aHandleReport, aData, KIND_NONHEAP, aPathPrefix,
534 "decoded-unknown",
535 "Decoded image data which is unknown to be on the heap or not.",
536 aCounter.DecodedUnknown());
539 static void ReportSourceValue(nsIHandleReportCallback* aHandleReport,
540 nsISupports* aData,
541 const nsACString& aPathPrefix,
542 const MemoryCounter& aCounter) {
543 ReportValue(aHandleReport, aData, KIND_HEAP, aPathPrefix, "source",
544 "Raster image source data and vector image documents.",
545 aCounter.Source());
548 static void ReportValue(nsIHandleReportCallback* aHandleReport,
549 nsISupports* aData, int32_t aKind,
550 const nsACString& aPathPrefix,
551 const char* aPathSuffix, const char* aDescription,
552 size_t aValue) {
553 if (aValue == 0) {
554 return;
557 nsAutoCString desc(aDescription);
558 nsAutoCString path(aPathPrefix);
559 path.Append(aPathSuffix);
561 aHandleReport->Callback(""_ns, path, aKind, UNITS_BYTES, aValue, desc,
562 aData);
565 static void RecordCounterForRequest(imgRequest* aRequest,
566 nsTArray<ImageMemoryCounter>* aArray,
567 bool aIsUsed) {
568 SizeOfState state(ImagesMallocSizeOf);
569 RefPtr<image::Image> image = aRequest->GetImage();
570 if (image) {
571 ImageMemoryCounter counter(aRequest, image, state, aIsUsed);
572 aArray->AppendElement(std::move(counter));
573 } else {
574 // We can at least record some information about the image from the
575 // request, and mark it as not knowing the image type yet.
576 ImageMemoryCounter counter(aRequest, state, aIsUsed);
577 aArray->AppendElement(std::move(counter));
582 NS_IMPL_ISUPPORTS(imgMemoryReporter, nsIMemoryReporter)
584 NS_IMPL_ISUPPORTS(nsProgressNotificationProxy, nsIProgressEventSink,
585 nsIChannelEventSink, nsIInterfaceRequestor)
587 NS_IMETHODIMP
588 nsProgressNotificationProxy::OnProgress(nsIRequest* request, int64_t progress,
589 int64_t progressMax) {
590 nsCOMPtr<nsILoadGroup> loadGroup;
591 request->GetLoadGroup(getter_AddRefs(loadGroup));
593 nsCOMPtr<nsIProgressEventSink> target;
594 NS_QueryNotificationCallbacks(mOriginalCallbacks, loadGroup,
595 NS_GET_IID(nsIProgressEventSink),
596 getter_AddRefs(target));
597 if (!target) {
598 return NS_OK;
600 return target->OnProgress(mImageRequest, progress, progressMax);
603 NS_IMETHODIMP
604 nsProgressNotificationProxy::OnStatus(nsIRequest* request, nsresult status,
605 const char16_t* statusArg) {
606 nsCOMPtr<nsILoadGroup> loadGroup;
607 request->GetLoadGroup(getter_AddRefs(loadGroup));
609 nsCOMPtr<nsIProgressEventSink> target;
610 NS_QueryNotificationCallbacks(mOriginalCallbacks, loadGroup,
611 NS_GET_IID(nsIProgressEventSink),
612 getter_AddRefs(target));
613 if (!target) {
614 return NS_OK;
616 return target->OnStatus(mImageRequest, status, statusArg);
619 NS_IMETHODIMP
620 nsProgressNotificationProxy::AsyncOnChannelRedirect(
621 nsIChannel* oldChannel, nsIChannel* newChannel, uint32_t flags,
622 nsIAsyncVerifyRedirectCallback* cb) {
623 // Tell the original original callbacks about it too
624 nsCOMPtr<nsILoadGroup> loadGroup;
625 newChannel->GetLoadGroup(getter_AddRefs(loadGroup));
626 nsCOMPtr<nsIChannelEventSink> target;
627 NS_QueryNotificationCallbacks(mOriginalCallbacks, loadGroup,
628 NS_GET_IID(nsIChannelEventSink),
629 getter_AddRefs(target));
630 if (!target) {
631 cb->OnRedirectVerifyCallback(NS_OK);
632 return NS_OK;
635 // Delegate to |target| if set, reusing |cb|
636 return target->AsyncOnChannelRedirect(oldChannel, newChannel, flags, cb);
639 NS_IMETHODIMP
640 nsProgressNotificationProxy::GetInterface(const nsIID& iid, void** result) {
641 if (iid.Equals(NS_GET_IID(nsIProgressEventSink))) {
642 *result = static_cast<nsIProgressEventSink*>(this);
643 NS_ADDREF_THIS();
644 return NS_OK;
646 if (iid.Equals(NS_GET_IID(nsIChannelEventSink))) {
647 *result = static_cast<nsIChannelEventSink*>(this);
648 NS_ADDREF_THIS();
649 return NS_OK;
651 if (mOriginalCallbacks) {
652 return mOriginalCallbacks->GetInterface(iid, result);
654 return NS_NOINTERFACE;
657 static void NewRequestAndEntry(bool aForcePrincipalCheckForCacheEntry,
658 imgLoader* aLoader, const ImageCacheKey& aKey,
659 imgRequest** aRequest, imgCacheEntry** aEntry) {
660 RefPtr<imgRequest> request = new imgRequest(aLoader, aKey);
661 RefPtr<imgCacheEntry> entry =
662 new imgCacheEntry(aLoader, request, aForcePrincipalCheckForCacheEntry);
663 aLoader->AddToUncachedImages(request);
664 request.forget(aRequest);
665 entry.forget(aEntry);
668 static bool ShouldRevalidateEntry(imgCacheEntry* aEntry, nsLoadFlags aFlags,
669 bool aHasExpired) {
670 if (aFlags & nsIRequest::LOAD_BYPASS_CACHE) {
671 return false;
673 if (aFlags & nsIRequest::VALIDATE_ALWAYS) {
674 return true;
676 if (aEntry->GetMustValidate()) {
677 return true;
679 if (aHasExpired) {
680 // The cache entry has expired... Determine whether the stale cache
681 // entry can be used without validation...
682 if (aFlags & (nsIRequest::LOAD_FROM_CACHE | nsIRequest::VALIDATE_NEVER |
683 nsIRequest::VALIDATE_ONCE_PER_SESSION)) {
684 // LOAD_FROM_CACHE, VALIDATE_NEVER and VALIDATE_ONCE_PER_SESSION allow
685 // stale cache entries to be used unless they have been explicitly marked
686 // to indicate that revalidation is necessary.
687 return false;
689 // Entry is expired, revalidate.
690 return true;
692 return false;
695 /* Call content policies on cached images that went through a redirect */
696 static bool ShouldLoadCachedImage(imgRequest* aImgRequest,
697 Document* aLoadingDocument,
698 nsIPrincipal* aTriggeringPrincipal,
699 nsContentPolicyType aPolicyType,
700 bool aSendCSPViolationReports) {
701 /* Call content policies on cached images - Bug 1082837
702 * Cached images are keyed off of the first uri in a redirect chain.
703 * Hence content policies don't get a chance to test the intermediate hops
704 * or the final destination. Here we test the final destination using
705 * mFinalURI off of the imgRequest and passing it into content policies.
706 * For Mixed Content Blocker, we do an additional check to determine if any
707 * of the intermediary hops went through an insecure redirect with the
708 * mHadInsecureRedirect flag
710 bool insecureRedirect = aImgRequest->HadInsecureRedirect();
711 nsCOMPtr<nsIURI> contentLocation;
712 aImgRequest->GetFinalURI(getter_AddRefs(contentLocation));
713 nsresult rv;
715 nsCOMPtr<nsIPrincipal> loadingPrincipal =
716 aLoadingDocument ? aLoadingDocument->NodePrincipal()
717 : aTriggeringPrincipal;
718 // If there is no context and also no triggeringPrincipal, then we use a fresh
719 // nullPrincipal as the loadingPrincipal because we can not create a loadinfo
720 // without a valid loadingPrincipal.
721 if (!loadingPrincipal) {
722 loadingPrincipal = NullPrincipal::CreateWithoutOriginAttributes();
725 nsCOMPtr<nsILoadInfo> secCheckLoadInfo = new LoadInfo(
726 loadingPrincipal, aTriggeringPrincipal, aLoadingDocument,
727 nsILoadInfo::SEC_ONLY_FOR_EXPLICIT_CONTENTSEC_CHECK, aPolicyType);
729 secCheckLoadInfo->SetSendCSPViolationEvents(aSendCSPViolationReports);
731 int16_t decision = nsIContentPolicy::REJECT_REQUEST;
732 rv = NS_CheckContentLoadPolicy(contentLocation, secCheckLoadInfo,
733 ""_ns, // mime guess
734 &decision, nsContentUtils::GetContentPolicy());
735 if (NS_FAILED(rv) || !NS_CP_ACCEPTED(decision)) {
736 return false;
739 // We call all Content Policies above, but we also have to call mcb
740 // individually to check the intermediary redirect hops are secure.
741 if (insecureRedirect) {
742 // Bug 1314356: If the image ended up in the cache upgraded by HSTS and the
743 // page uses upgrade-inscure-requests it had an insecure redirect
744 // (http->https). We need to invalidate the image and reload it because
745 // mixed content blocker only bails if upgrade-insecure-requests is set on
746 // the doc and the resource load is http: which would result in an incorrect
747 // mixed content warning.
748 nsCOMPtr<nsIDocShell> docShell =
749 NS_CP_GetDocShellFromContext(ToSupports(aLoadingDocument));
750 if (docShell) {
751 Document* document = docShell->GetDocument();
752 if (document && document->GetUpgradeInsecureRequests(false)) {
753 return false;
757 if (!aTriggeringPrincipal || !aTriggeringPrincipal->IsSystemPrincipal()) {
758 // reset the decision for mixed content blocker check
759 decision = nsIContentPolicy::REJECT_REQUEST;
760 rv = nsMixedContentBlocker::ShouldLoad(insecureRedirect, contentLocation,
761 secCheckLoadInfo,
762 ""_ns, // mime guess
763 true, // aReportError
764 &decision);
765 if (NS_FAILED(rv) || !NS_CP_ACCEPTED(decision)) {
766 return false;
771 return true;
774 // Returns true if this request is compatible with the given CORS mode on the
775 // given loading principal, and false if the request may not be reused due
776 // to CORS.
777 static bool ValidateCORSMode(imgRequest* aRequest, bool aForcePrincipalCheck,
778 CORSMode aCORSMode,
779 nsIPrincipal* aTriggeringPrincipal) {
780 // If the entry's CORS mode doesn't match, or the CORS mode matches but the
781 // document principal isn't the same, we can't use this request.
782 if (aRequest->GetCORSMode() != aCORSMode) {
783 return false;
786 if (aRequest->GetCORSMode() != CORS_NONE || aForcePrincipalCheck) {
787 nsCOMPtr<nsIPrincipal> otherprincipal = aRequest->GetTriggeringPrincipal();
789 // If we previously had a principal, but we don't now, we can't use this
790 // request.
791 if (otherprincipal && !aTriggeringPrincipal) {
792 return false;
795 if (otherprincipal && aTriggeringPrincipal &&
796 !otherprincipal->Equals(aTriggeringPrincipal)) {
797 return false;
801 return true;
804 static bool ValidateSecurityInfo(imgRequest* aRequest,
805 bool aForcePrincipalCheck, CORSMode aCORSMode,
806 nsIPrincipal* aTriggeringPrincipal,
807 Document* aLoadingDocument,
808 nsContentPolicyType aPolicyType) {
809 if (!ValidateCORSMode(aRequest, aForcePrincipalCheck, aCORSMode,
810 aTriggeringPrincipal)) {
811 return false;
813 // Content Policy Check on Cached Images
814 return ShouldLoadCachedImage(aRequest, aLoadingDocument, aTriggeringPrincipal,
815 aPolicyType,
816 /* aSendCSPViolationReports */ false);
819 static nsresult NewImageChannel(
820 nsIChannel** aResult,
821 // If aForcePrincipalCheckForCacheEntry is true, then we will
822 // force a principal check even when not using CORS before
823 // assuming we have a cache hit on a cache entry that we
824 // create for this channel. This is an out param that should
825 // be set to true if this channel ends up depending on
826 // aTriggeringPrincipal and false otherwise.
827 bool* aForcePrincipalCheckForCacheEntry, nsIURI* aURI,
828 nsIURI* aInitialDocumentURI, CORSMode aCORSMode,
829 nsIReferrerInfo* aReferrerInfo, nsILoadGroup* aLoadGroup,
830 nsLoadFlags aLoadFlags, nsContentPolicyType aPolicyType,
831 nsIPrincipal* aTriggeringPrincipal, nsINode* aRequestingNode,
832 bool aRespectPrivacy, uint64_t aEarlyHintPreloaderId) {
833 MOZ_ASSERT(aResult);
835 nsresult rv;
836 nsCOMPtr<nsIHttpChannel> newHttpChannel;
838 nsCOMPtr<nsIInterfaceRequestor> callbacks;
840 if (aLoadGroup) {
841 // Get the notification callbacks from the load group for the new channel.
843 // XXX: This is not exactly correct, because the network request could be
844 // referenced by multiple windows... However, the new channel needs
845 // something. So, using the 'first' notification callbacks is better
846 // than nothing...
848 aLoadGroup->GetNotificationCallbacks(getter_AddRefs(callbacks));
851 // Pass in a nullptr loadgroup because this is the underlying network
852 // request. This request may be referenced by several proxy image requests
853 // (possibly in different documents).
854 // If all of the proxy requests are canceled then this request should be
855 // canceled too.
858 nsSecurityFlags securityFlags =
859 nsContentSecurityManager::ComputeSecurityFlags(
860 aCORSMode, nsContentSecurityManager::CORSSecurityMapping::
861 CORS_NONE_MAPS_TO_INHERITED_CONTEXT);
863 securityFlags |= nsILoadInfo::SEC_ALLOW_CHROME;
865 // Note we are calling NS_NewChannelWithTriggeringPrincipal() here with a
866 // node and a principal. This is for things like background images that are
867 // specified by user stylesheets, where the document is being styled, but
868 // the principal is that of the user stylesheet.
869 if (aRequestingNode && aTriggeringPrincipal) {
870 rv = NS_NewChannelWithTriggeringPrincipal(aResult, aURI, aRequestingNode,
871 aTriggeringPrincipal,
872 securityFlags, aPolicyType,
873 nullptr, // PerformanceStorage
874 nullptr, // loadGroup
875 callbacks, aLoadFlags);
877 if (NS_FAILED(rv)) {
878 return rv;
881 if (aPolicyType == nsIContentPolicy::TYPE_INTERNAL_IMAGE_FAVICON) {
882 // If this is a favicon loading, we will use the originAttributes from the
883 // triggeringPrincipal as the channel's originAttributes. This allows the
884 // favicon loading from XUL will use the correct originAttributes.
886 nsCOMPtr<nsILoadInfo> loadInfo = (*aResult)->LoadInfo();
887 rv = loadInfo->SetOriginAttributes(
888 aTriggeringPrincipal->OriginAttributesRef());
890 } else {
891 // either we are loading something inside a document, in which case
892 // we should always have a requestingNode, or we are loading something
893 // outside a document, in which case the triggeringPrincipal and
894 // triggeringPrincipal should always be the systemPrincipal.
895 // However, there are exceptions: one is Notifications which create a
896 // channel in the parent process in which case we can't get a
897 // requestingNode.
898 rv = NS_NewChannel(aResult, aURI, nsContentUtils::GetSystemPrincipal(),
899 securityFlags, aPolicyType,
900 nullptr, // nsICookieJarSettings
901 nullptr, // PerformanceStorage
902 nullptr, // loadGroup
903 callbacks, aLoadFlags);
905 if (NS_FAILED(rv)) {
906 return rv;
909 // Use the OriginAttributes from the loading principal, if one is available,
910 // and adjust the private browsing ID based on what kind of load the caller
911 // has asked us to perform.
912 OriginAttributes attrs;
913 if (aTriggeringPrincipal) {
914 attrs = aTriggeringPrincipal->OriginAttributesRef();
916 attrs.mPrivateBrowsingId = aRespectPrivacy ? 1 : 0;
918 nsCOMPtr<nsILoadInfo> loadInfo = (*aResult)->LoadInfo();
919 rv = loadInfo->SetOriginAttributes(attrs);
922 if (NS_FAILED(rv)) {
923 return rv;
926 // only inherit if we have a principal
927 *aForcePrincipalCheckForCacheEntry =
928 aTriggeringPrincipal && nsContentUtils::ChannelShouldInheritPrincipal(
929 aTriggeringPrincipal, aURI,
930 /* aInheritForAboutBlank */ false,
931 /* aForceInherit */ false);
933 // Initialize HTTP-specific attributes
934 newHttpChannel = do_QueryInterface(*aResult);
935 if (newHttpChannel) {
936 nsCOMPtr<nsIHttpChannelInternal> httpChannelInternal =
937 do_QueryInterface(newHttpChannel);
938 NS_ENSURE_TRUE(httpChannelInternal, NS_ERROR_UNEXPECTED);
939 rv = httpChannelInternal->SetDocumentURI(aInitialDocumentURI);
940 MOZ_ASSERT(NS_SUCCEEDED(rv));
941 if (aReferrerInfo) {
942 DebugOnly<nsresult> rv = newHttpChannel->SetReferrerInfo(aReferrerInfo);
943 MOZ_ASSERT(NS_SUCCEEDED(rv));
946 if (aEarlyHintPreloaderId) {
947 rv = httpChannelInternal->SetEarlyHintPreloaderId(aEarlyHintPreloaderId);
948 NS_ENSURE_SUCCESS(rv, rv);
952 // Image channels are loaded by default with reduced priority.
953 nsCOMPtr<nsISupportsPriority> p = do_QueryInterface(*aResult);
954 if (p) {
955 uint32_t priority = nsISupportsPriority::PRIORITY_LOW;
957 if (aLoadFlags & nsIRequest::LOAD_BACKGROUND) {
958 ++priority; // further reduce priority for background loads
961 p->AdjustPriority(priority);
964 // Create a new loadgroup for this new channel, using the old group as
965 // the parent. The indirection keeps the channel insulated from cancels,
966 // but does allow a way for this revalidation to be associated with at
967 // least one base load group for scheduling/caching purposes.
969 nsCOMPtr<nsILoadGroup> loadGroup = do_CreateInstance(NS_LOADGROUP_CONTRACTID);
970 nsCOMPtr<nsILoadGroupChild> childLoadGroup = do_QueryInterface(loadGroup);
971 if (childLoadGroup) {
972 childLoadGroup->SetParentLoadGroup(aLoadGroup);
974 (*aResult)->SetLoadGroup(loadGroup);
976 return NS_OK;
979 static uint32_t SecondsFromPRTime(PRTime aTime) {
980 return nsContentUtils::SecondsFromPRTime(aTime);
983 /* static */
984 imgCacheEntry::imgCacheEntry(imgLoader* loader, imgRequest* request,
985 bool forcePrincipalCheck)
986 : mLoader(loader),
987 mRequest(request),
988 mDataSize(0),
989 mTouchedTime(SecondsFromPRTime(PR_Now())),
990 mLoadTime(SecondsFromPRTime(PR_Now())),
991 mExpiryTime(0),
992 mMustValidate(false),
993 // We start off as evicted so we don't try to update the cache.
994 // PutIntoCache will set this to false.
995 mEvicted(true),
996 mHasNoProxies(true),
997 mForcePrincipalCheck(forcePrincipalCheck),
998 mHasNotified(false) {}
1000 imgCacheEntry::~imgCacheEntry() {
1001 LOG_FUNC(gImgLog, "imgCacheEntry::~imgCacheEntry()");
1004 void imgCacheEntry::Touch(bool updateTime /* = true */) {
1005 LOG_SCOPE(gImgLog, "imgCacheEntry::Touch");
1007 if (updateTime) {
1008 mTouchedTime = SecondsFromPRTime(PR_Now());
1011 UpdateCache();
1014 void imgCacheEntry::UpdateCache(int32_t diff /* = 0 */) {
1015 // Don't update the cache if we've been removed from it or it doesn't care
1016 // about our size or usage.
1017 if (!Evicted() && HasNoProxies()) {
1018 mLoader->CacheEntriesChanged(diff);
1022 void imgCacheEntry::UpdateLoadTime() {
1023 mLoadTime = SecondsFromPRTime(PR_Now());
1026 void imgCacheEntry::SetHasNoProxies(bool hasNoProxies) {
1027 if (MOZ_LOG_TEST(gImgLog, LogLevel::Debug)) {
1028 if (hasNoProxies) {
1029 LOG_FUNC_WITH_PARAM(gImgLog, "imgCacheEntry::SetHasNoProxies true", "uri",
1030 mRequest->CacheKey().URI());
1031 } else {
1032 LOG_FUNC_WITH_PARAM(gImgLog, "imgCacheEntry::SetHasNoProxies false",
1033 "uri", mRequest->CacheKey().URI());
1037 mHasNoProxies = hasNoProxies;
1040 imgCacheQueue::imgCacheQueue() : mDirty(false), mSize(0) {}
1042 void imgCacheQueue::UpdateSize(int32_t diff) { mSize += diff; }
1044 uint32_t imgCacheQueue::GetSize() const { return mSize; }
1046 void imgCacheQueue::Remove(imgCacheEntry* entry) {
1047 uint64_t index = mQueue.IndexOf(entry);
1048 if (index == queueContainer::NoIndex) {
1049 return;
1052 mSize -= mQueue[index]->GetDataSize();
1054 // If the queue is clean and this is the first entry,
1055 // then we can efficiently remove the entry without
1056 // dirtying the sort order.
1057 if (!IsDirty() && index == 0) {
1058 std::pop_heap(mQueue.begin(), mQueue.end(), imgLoader::CompareCacheEntries);
1059 mQueue.RemoveLastElement();
1060 return;
1063 // Remove from the middle of the list. This potentially
1064 // breaks the binary heap sort order.
1065 mQueue.RemoveElementAt(index);
1067 // If we only have one entry or the queue is empty, though,
1068 // then the sort order is still effectively good. Simply
1069 // refresh the list to clear the dirty flag.
1070 if (mQueue.Length() <= 1) {
1071 Refresh();
1072 return;
1075 // Otherwise we must mark the queue dirty and potentially
1076 // trigger an expensive sort later.
1077 MarkDirty();
1080 void imgCacheQueue::Push(imgCacheEntry* entry) {
1081 mSize += entry->GetDataSize();
1083 RefPtr<imgCacheEntry> refptr(entry);
1084 mQueue.AppendElement(std::move(refptr));
1085 // If we're not dirty already, then we can efficiently add this to the
1086 // binary heap immediately. This is only O(log n).
1087 if (!IsDirty()) {
1088 std::push_heap(mQueue.begin(), mQueue.end(),
1089 imgLoader::CompareCacheEntries);
1093 already_AddRefed<imgCacheEntry> imgCacheQueue::Pop() {
1094 if (mQueue.IsEmpty()) {
1095 return nullptr;
1097 if (IsDirty()) {
1098 Refresh();
1101 std::pop_heap(mQueue.begin(), mQueue.end(), imgLoader::CompareCacheEntries);
1102 RefPtr<imgCacheEntry> entry = mQueue.PopLastElement();
1104 mSize -= entry->GetDataSize();
1105 return entry.forget();
1108 void imgCacheQueue::Refresh() {
1109 // Resort the list. This is an O(3 * n) operation and best avoided
1110 // if possible.
1111 std::make_heap(mQueue.begin(), mQueue.end(), imgLoader::CompareCacheEntries);
1112 mDirty = false;
1115 void imgCacheQueue::MarkDirty() { mDirty = true; }
1117 bool imgCacheQueue::IsDirty() { return mDirty; }
1119 uint32_t imgCacheQueue::GetNumElements() const { return mQueue.Length(); }
1121 bool imgCacheQueue::Contains(imgCacheEntry* aEntry) const {
1122 return mQueue.Contains(aEntry);
1125 imgCacheQueue::iterator imgCacheQueue::begin() { return mQueue.begin(); }
1127 imgCacheQueue::const_iterator imgCacheQueue::begin() const {
1128 return mQueue.begin();
1131 imgCacheQueue::iterator imgCacheQueue::end() { return mQueue.end(); }
1133 imgCacheQueue::const_iterator imgCacheQueue::end() const {
1134 return mQueue.end();
1137 nsresult imgLoader::CreateNewProxyForRequest(
1138 imgRequest* aRequest, nsIURI* aURI, nsILoadGroup* aLoadGroup,
1139 Document* aLoadingDocument, imgINotificationObserver* aObserver,
1140 nsLoadFlags aLoadFlags, imgRequestProxy** _retval) {
1141 LOG_SCOPE_WITH_PARAM(gImgLog, "imgLoader::CreateNewProxyForRequest",
1142 "imgRequest", aRequest);
1144 /* XXX If we move decoding onto separate threads, we should save off the
1145 calling thread here and pass it off to |proxyRequest| so that it call
1146 proxy calls to |aObserver|.
1149 RefPtr<imgRequestProxy> proxyRequest = new imgRequestProxy();
1151 /* It is important to call |SetLoadFlags()| before calling |Init()| because
1152 |Init()| adds the request to the loadgroup.
1154 proxyRequest->SetLoadFlags(aLoadFlags);
1156 // init adds itself to imgRequest's list of observers
1157 nsresult rv = proxyRequest->Init(aRequest, aLoadGroup, aLoadingDocument, aURI,
1158 aObserver);
1159 if (NS_WARN_IF(NS_FAILED(rv))) {
1160 return rv;
1163 proxyRequest.forget(_retval);
1164 return NS_OK;
1167 class imgCacheExpirationTracker final
1168 : public nsExpirationTracker<imgCacheEntry, 3> {
1169 enum { TIMEOUT_SECONDS = 10 };
1171 public:
1172 imgCacheExpirationTracker();
1174 protected:
1175 void NotifyExpired(imgCacheEntry* entry) override;
1178 imgCacheExpirationTracker::imgCacheExpirationTracker()
1179 : nsExpirationTracker<imgCacheEntry, 3>(TIMEOUT_SECONDS * 1000,
1180 "imgCacheExpirationTracker") {}
1182 void imgCacheExpirationTracker::NotifyExpired(imgCacheEntry* entry) {
1183 // Hold on to a reference to this entry, because the expiration tracker
1184 // mechanism doesn't.
1185 RefPtr<imgCacheEntry> kungFuDeathGrip(entry);
1187 if (MOZ_LOG_TEST(gImgLog, LogLevel::Debug)) {
1188 RefPtr<imgRequest> req = entry->GetRequest();
1189 if (req) {
1190 LOG_FUNC_WITH_PARAM(gImgLog, "imgCacheExpirationTracker::NotifyExpired",
1191 "entry", req->CacheKey().URI());
1195 // We can be called multiple times on the same entry. Don't do work multiple
1196 // times.
1197 if (!entry->Evicted()) {
1198 entry->Loader()->RemoveFromCache(entry);
1201 entry->Loader()->VerifyCacheSizes();
1204 ///////////////////////////////////////////////////////////////////////////////
1205 // imgLoader
1206 ///////////////////////////////////////////////////////////////////////////////
1208 double imgLoader::sCacheTimeWeight;
1209 uint32_t imgLoader::sCacheMaxSize;
1210 imgMemoryReporter* imgLoader::sMemReporter;
1212 NS_IMPL_ISUPPORTS(imgLoader, imgILoader, nsIContentSniffer, imgICache,
1213 nsISupportsWeakReference, nsIObserver)
1215 static imgLoader* gNormalLoader = nullptr;
1216 static imgLoader* gPrivateBrowsingLoader = nullptr;
1218 /* static */
1219 already_AddRefed<imgLoader> imgLoader::CreateImageLoader() {
1220 // In some cases, such as xpctests, XPCOM modules are not automatically
1221 // initialized. We need to make sure that our module is initialized before
1222 // we hand out imgLoader instances and code starts using them.
1223 mozilla::image::EnsureModuleInitialized();
1225 RefPtr<imgLoader> loader = new imgLoader();
1226 loader->Init();
1228 return loader.forget();
1231 imgLoader* imgLoader::NormalLoader() {
1232 if (!gNormalLoader) {
1233 gNormalLoader = CreateImageLoader().take();
1235 return gNormalLoader;
1238 imgLoader* imgLoader::PrivateBrowsingLoader() {
1239 if (!gPrivateBrowsingLoader) {
1240 gPrivateBrowsingLoader = CreateImageLoader().take();
1241 gPrivateBrowsingLoader->RespectPrivacyNotifications();
1243 return gPrivateBrowsingLoader;
1246 imgLoader::imgLoader()
1247 : mUncachedImagesMutex("imgLoader::UncachedImages"),
1248 mRespectPrivacy(false) {
1249 sMemReporter->AddRef();
1250 sMemReporter->RegisterLoader(this);
1253 imgLoader::~imgLoader() {
1254 ClearImageCache();
1256 // If there are any of our imgRequest's left they are in the uncached
1257 // images set, so clear their pointer to us.
1258 MutexAutoLock lock(mUncachedImagesMutex);
1259 for (RefPtr<imgRequest> req : mUncachedImages) {
1260 req->ClearLoader();
1263 sMemReporter->UnregisterLoader(this);
1264 sMemReporter->Release();
1267 void imgLoader::VerifyCacheSizes() {
1268 #ifdef DEBUG
1269 if (!mCacheTracker) {
1270 return;
1273 uint32_t cachesize = mCache.Count();
1274 uint32_t queuesize = mCacheQueue.GetNumElements();
1275 uint32_t trackersize = 0;
1276 for (nsExpirationTracker<imgCacheEntry, 3>::Iterator it(mCacheTracker.get());
1277 it.Next();) {
1278 trackersize++;
1280 MOZ_ASSERT(queuesize == trackersize, "Queue and tracker sizes out of sync!");
1281 MOZ_ASSERT(queuesize <= cachesize, "Queue has more elements than cache!");
1282 #endif
1285 void imgLoader::GlobalInit() {
1286 sCacheTimeWeight = StaticPrefs::image_cache_timeweight_AtStartup() / 1000.0;
1287 int32_t cachesize = StaticPrefs::image_cache_size_AtStartup();
1288 sCacheMaxSize = cachesize > 0 ? cachesize : 0;
1290 sMemReporter = new imgMemoryReporter();
1291 RegisterStrongAsyncMemoryReporter(sMemReporter);
1292 RegisterImagesContentUsedUncompressedDistinguishedAmount(
1293 imgMemoryReporter::ImagesContentUsedUncompressedDistinguishedAmount);
1296 void imgLoader::ShutdownMemoryReporter() {
1297 UnregisterImagesContentUsedUncompressedDistinguishedAmount();
1298 UnregisterStrongMemoryReporter(sMemReporter);
1301 nsresult imgLoader::InitCache() {
1302 nsCOMPtr<nsIObserverService> os = mozilla::services::GetObserverService();
1303 if (!os) {
1304 return NS_ERROR_FAILURE;
1307 os->AddObserver(this, "memory-pressure", false);
1308 os->AddObserver(this, "chrome-flush-caches", false);
1309 os->AddObserver(this, "last-pb-context-exited", false);
1310 os->AddObserver(this, "profile-before-change", false);
1311 os->AddObserver(this, "xpcom-shutdown", false);
1313 mCacheTracker = MakeUnique<imgCacheExpirationTracker>();
1315 return NS_OK;
1318 nsresult imgLoader::Init() {
1319 InitCache();
1321 return NS_OK;
1324 NS_IMETHODIMP
1325 imgLoader::RespectPrivacyNotifications() {
1326 mRespectPrivacy = true;
1327 return NS_OK;
1330 NS_IMETHODIMP
1331 imgLoader::Observe(nsISupports* aSubject, const char* aTopic,
1332 const char16_t* aData) {
1333 if (strcmp(aTopic, "memory-pressure") == 0) {
1334 MinimizeCache();
1335 } else if (strcmp(aTopic, "chrome-flush-caches") == 0) {
1336 MinimizeCache();
1337 ClearImageCache({ClearOption::ChromeOnly});
1338 } else if (strcmp(aTopic, "last-pb-context-exited") == 0) {
1339 if (mRespectPrivacy) {
1340 ClearImageCache();
1342 } else if (strcmp(aTopic, "profile-before-change") == 0) {
1343 mCacheTracker = nullptr;
1344 } else if (strcmp(aTopic, "xpcom-shutdown") == 0) {
1345 mCacheTracker = nullptr;
1346 ShutdownMemoryReporter();
1348 } else {
1349 // (Nothing else should bring us here)
1350 MOZ_ASSERT(0, "Invalid topic received");
1353 return NS_OK;
1356 NS_IMETHODIMP
1357 imgLoader::ClearCache(bool chrome) {
1358 if (XRE_IsParentProcess()) {
1359 bool privateLoader = this == gPrivateBrowsingLoader;
1360 for (auto* cp : ContentParent::AllProcesses(ContentParent::eLive)) {
1361 Unused << cp->SendClearImageCache(privateLoader, chrome);
1364 ClearOptions options;
1365 if (chrome) {
1366 options += ClearOption::ChromeOnly;
1368 return ClearImageCache(options);
1371 NS_IMETHODIMP
1372 imgLoader::RemoveEntriesFromPrincipalInAllProcesses(nsIPrincipal* aPrincipal) {
1373 if (!XRE_IsParentProcess()) {
1374 return NS_ERROR_NOT_AVAILABLE;
1377 for (auto* cp : ContentParent::AllProcesses(ContentParent::eLive)) {
1378 Unused << cp->SendClearImageCacheFromPrincipal(aPrincipal);
1381 imgLoader* loader;
1382 if (aPrincipal->OriginAttributesRef().mPrivateBrowsingId ==
1383 nsIScriptSecurityManager::DEFAULT_PRIVATE_BROWSING_ID) {
1384 loader = imgLoader::NormalLoader();
1385 } else {
1386 loader = imgLoader::PrivateBrowsingLoader();
1389 return loader->RemoveEntriesInternal(aPrincipal, nullptr);
1392 NS_IMETHODIMP
1393 imgLoader::RemoveEntriesFromBaseDomainInAllProcesses(
1394 const nsACString& aBaseDomain) {
1395 if (!XRE_IsParentProcess()) {
1396 return NS_ERROR_NOT_AVAILABLE;
1399 for (auto* cp : ContentParent::AllProcesses(ContentParent::eLive)) {
1400 Unused << cp->SendClearImageCacheFromBaseDomain(aBaseDomain);
1403 return RemoveEntriesInternal(nullptr, &aBaseDomain);
1406 nsresult imgLoader::RemoveEntriesInternal(nsIPrincipal* aPrincipal,
1407 const nsACString* aBaseDomain) {
1408 // Can only clear by either principal or base domain.
1409 if ((!aPrincipal && !aBaseDomain) || (aPrincipal && aBaseDomain)) {
1410 return NS_ERROR_INVALID_ARG;
1413 nsCOMPtr<nsIEffectiveTLDService> tldService;
1414 AutoTArray<RefPtr<imgCacheEntry>, 128> entriesToBeRemoved;
1416 // For base domain we only clear the non-chrome cache.
1417 for (const auto& entry : mCache) {
1418 const auto& key = entry.GetKey();
1420 const bool shouldRemove = [&] {
1421 if (aPrincipal) {
1422 nsCOMPtr<nsIPrincipal> keyPrincipal =
1423 BasePrincipal::CreateContentPrincipal(key.URI(),
1424 key.OriginAttributesRef());
1425 return keyPrincipal->Equals(aPrincipal);
1428 if (!aBaseDomain) {
1429 return false;
1431 // Clear by baseDomain.
1432 nsAutoCString host;
1433 nsresult rv = key.URI()->GetHost(host);
1434 if (NS_FAILED(rv) || host.IsEmpty()) {
1435 return false;
1438 if (!tldService) {
1439 tldService = do_GetService(NS_EFFECTIVETLDSERVICE_CONTRACTID);
1441 if (NS_WARN_IF(!tldService)) {
1442 return false;
1445 bool hasRootDomain = false;
1446 rv = tldService->HasRootDomain(host, *aBaseDomain, &hasRootDomain);
1447 if (NS_SUCCEEDED(rv) && hasRootDomain) {
1448 return true;
1451 // If we don't get a direct base domain match, also check for cache of
1452 // third parties partitioned under aBaseDomain.
1454 // The isolation key is either just the base domain, or an origin suffix
1455 // which contains the partitionKey holding the baseDomain.
1457 if (key.IsolationKeyRef().Equals(*aBaseDomain)) {
1458 return true;
1461 // The isolation key does not match the given base domain. It may be an
1462 // origin suffix. Parse it into origin attributes.
1463 OriginAttributes attrs;
1464 if (!attrs.PopulateFromSuffix(key.IsolationKeyRef())) {
1465 // Key is not an origin suffix.
1466 return false;
1469 return StoragePrincipalHelper::PartitionKeyHasBaseDomain(
1470 attrs.mPartitionKey, *aBaseDomain);
1471 }();
1473 if (shouldRemove) {
1474 entriesToBeRemoved.AppendElement(entry.GetData());
1478 for (auto& entry : entriesToBeRemoved) {
1479 if (!RemoveFromCache(entry)) {
1480 NS_WARNING(
1481 "Couldn't remove an entry from the cache in "
1482 "RemoveEntriesInternal()\n");
1486 return NS_OK;
1489 constexpr auto AllCORSModes() {
1490 return MakeInclusiveEnumeratedRange(kFirstCORSMode, kLastCORSMode);
1493 NS_IMETHODIMP
1494 imgLoader::RemoveEntry(nsIURI* aURI, Document* aDoc) {
1495 if (!aURI) {
1496 return NS_OK;
1498 OriginAttributes attrs;
1499 if (aDoc) {
1500 attrs = aDoc->NodePrincipal()->OriginAttributesRef();
1502 for (auto corsMode : AllCORSModes()) {
1503 ImageCacheKey key(aURI, corsMode, attrs, aDoc);
1504 RemoveFromCache(key);
1506 return NS_OK;
1509 NS_IMETHODIMP
1510 imgLoader::FindEntryProperties(nsIURI* uri, Document* aDoc,
1511 nsIProperties** _retval) {
1512 *_retval = nullptr;
1514 OriginAttributes attrs;
1515 if (aDoc) {
1516 nsCOMPtr<nsIPrincipal> principal = aDoc->NodePrincipal();
1517 if (principal) {
1518 attrs = principal->OriginAttributesRef();
1522 for (auto corsMode : AllCORSModes()) {
1523 ImageCacheKey key(uri, corsMode, attrs, aDoc);
1524 RefPtr<imgCacheEntry> entry;
1525 if (!mCache.Get(key, getter_AddRefs(entry)) || !entry) {
1526 continue;
1528 if (mCacheTracker && entry->HasNoProxies()) {
1529 mCacheTracker->MarkUsed(entry);
1531 RefPtr<imgRequest> request = entry->GetRequest();
1532 if (request) {
1533 nsCOMPtr<nsIProperties> properties = request->Properties();
1534 properties.forget(_retval);
1535 return NS_OK;
1538 return NS_OK;
1541 NS_IMETHODIMP_(void)
1542 imgLoader::ClearCacheForControlledDocument(Document* aDoc) {
1543 MOZ_ASSERT(aDoc);
1544 AutoTArray<RefPtr<imgCacheEntry>, 128> entriesToBeRemoved;
1545 for (const auto& entry : mCache) {
1546 const auto& key = entry.GetKey();
1547 if (key.ControlledDocument() == aDoc) {
1548 entriesToBeRemoved.AppendElement(entry.GetData());
1551 for (auto& entry : entriesToBeRemoved) {
1552 if (!RemoveFromCache(entry)) {
1553 NS_WARNING(
1554 "Couldn't remove an entry from the cache in "
1555 "ClearCacheForControlledDocument()\n");
1560 void imgLoader::Shutdown() {
1561 NS_IF_RELEASE(gNormalLoader);
1562 gNormalLoader = nullptr;
1563 NS_IF_RELEASE(gPrivateBrowsingLoader);
1564 gPrivateBrowsingLoader = nullptr;
1567 bool imgLoader::PutIntoCache(const ImageCacheKey& aKey, imgCacheEntry* entry) {
1568 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::PutIntoCache", "uri",
1569 aKey.URI());
1571 // Check to see if this request already exists in the cache. If so, we'll
1572 // replace the old version.
1573 RefPtr<imgCacheEntry> tmpCacheEntry;
1574 if (mCache.Get(aKey, getter_AddRefs(tmpCacheEntry)) && tmpCacheEntry) {
1575 MOZ_LOG(
1576 gImgLog, LogLevel::Debug,
1577 ("[this=%p] imgLoader::PutIntoCache -- Element already in the cache",
1578 nullptr));
1579 RefPtr<imgRequest> tmpRequest = tmpCacheEntry->GetRequest();
1581 // If it already exists, and we're putting the same key into the cache, we
1582 // should remove the old version.
1583 MOZ_LOG(gImgLog, LogLevel::Debug,
1584 ("[this=%p] imgLoader::PutIntoCache -- Replacing cached element",
1585 nullptr));
1587 RemoveFromCache(aKey);
1588 } else {
1589 MOZ_LOG(gImgLog, LogLevel::Debug,
1590 ("[this=%p] imgLoader::PutIntoCache --"
1591 " Element NOT already in the cache",
1592 nullptr));
1595 mCache.InsertOrUpdate(aKey, RefPtr{entry});
1597 // We can be called to resurrect an evicted entry.
1598 if (entry->Evicted()) {
1599 entry->SetEvicted(false);
1602 // If we're resurrecting an entry with no proxies, put it back in the
1603 // tracker and queue.
1604 if (entry->HasNoProxies()) {
1605 nsresult addrv = NS_OK;
1607 if (mCacheTracker) {
1608 addrv = mCacheTracker->AddObject(entry);
1611 if (NS_SUCCEEDED(addrv)) {
1612 mCacheQueue.Push(entry);
1616 RefPtr<imgRequest> request = entry->GetRequest();
1617 request->SetIsInCache(true);
1618 RemoveFromUncachedImages(request);
1620 return true;
1623 bool imgLoader::SetHasNoProxies(imgRequest* aRequest, imgCacheEntry* aEntry) {
1624 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::SetHasNoProxies", "uri",
1625 aRequest->CacheKey().URI());
1627 aEntry->SetHasNoProxies(true);
1629 if (aEntry->Evicted()) {
1630 return false;
1633 nsresult addrv = NS_OK;
1635 if (mCacheTracker) {
1636 addrv = mCacheTracker->AddObject(aEntry);
1639 if (NS_SUCCEEDED(addrv)) {
1640 mCacheQueue.Push(aEntry);
1643 return true;
1646 bool imgLoader::SetHasProxies(imgRequest* aRequest) {
1647 VerifyCacheSizes();
1649 const ImageCacheKey& key = aRequest->CacheKey();
1651 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::SetHasProxies", "uri",
1652 key.URI());
1654 RefPtr<imgCacheEntry> entry;
1655 if (mCache.Get(key, getter_AddRefs(entry)) && entry) {
1656 // Make sure the cache entry is for the right request
1657 RefPtr<imgRequest> entryRequest = entry->GetRequest();
1658 if (entryRequest == aRequest && entry->HasNoProxies()) {
1659 mCacheQueue.Remove(entry);
1661 if (mCacheTracker) {
1662 mCacheTracker->RemoveObject(entry);
1665 entry->SetHasNoProxies(false);
1667 return true;
1671 return false;
1674 void imgLoader::CacheEntriesChanged(int32_t aSizeDiff /* = 0 */) {
1675 // We only need to dirty the queue if there is any sorting
1676 // taking place. Empty or single-entry lists can't become
1677 // dirty.
1678 if (mCacheQueue.GetNumElements() > 1) {
1679 mCacheQueue.MarkDirty();
1681 mCacheQueue.UpdateSize(aSizeDiff);
1684 void imgLoader::CheckCacheLimits() {
1685 if (mCacheQueue.GetNumElements() == 0) {
1686 NS_ASSERTION(mCacheQueue.GetSize() == 0,
1687 "imgLoader::CheckCacheLimits -- incorrect cache size");
1690 // Remove entries from the cache until we're back at our desired max size.
1691 while (mCacheQueue.GetSize() > sCacheMaxSize) {
1692 // Remove the first entry in the queue.
1693 RefPtr<imgCacheEntry> entry(mCacheQueue.Pop());
1695 NS_ASSERTION(entry, "imgLoader::CheckCacheLimits -- NULL entry pointer");
1697 if (MOZ_LOG_TEST(gImgLog, LogLevel::Debug)) {
1698 RefPtr<imgRequest> req = entry->GetRequest();
1699 if (req) {
1700 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::CheckCacheLimits",
1701 "entry", req->CacheKey().URI());
1705 if (entry) {
1706 // We just popped this entry from the queue, so pass AlreadyRemoved
1707 // to avoid searching the queue again in RemoveFromCache.
1708 RemoveFromCache(entry, QueueState::AlreadyRemoved);
1713 bool imgLoader::ValidateRequestWithNewChannel(
1714 imgRequest* request, nsIURI* aURI, nsIURI* aInitialDocumentURI,
1715 nsIReferrerInfo* aReferrerInfo, nsILoadGroup* aLoadGroup,
1716 imgINotificationObserver* aObserver, Document* aLoadingDocument,
1717 uint64_t aInnerWindowId, nsLoadFlags aLoadFlags,
1718 nsContentPolicyType aLoadPolicyType, imgRequestProxy** aProxyRequest,
1719 nsIPrincipal* aTriggeringPrincipal, CORSMode aCORSMode, bool aLinkPreload,
1720 uint64_t aEarlyHintPreloaderId, bool* aNewChannelCreated) {
1721 // now we need to insert a new channel request object in between the real
1722 // request and the proxy that basically delays loading the image until it
1723 // gets a 304 or figures out that this needs to be a new request
1725 nsresult rv;
1727 // If we're currently in the middle of validating this request, just hand
1728 // back a proxy to it; the required work will be done for us.
1729 if (imgCacheValidator* validator = request->GetValidator()) {
1730 rv = CreateNewProxyForRequest(request, aURI, aLoadGroup, aLoadingDocument,
1731 aObserver, aLoadFlags, aProxyRequest);
1732 if (NS_FAILED(rv)) {
1733 return false;
1736 if (*aProxyRequest) {
1737 imgRequestProxy* proxy = static_cast<imgRequestProxy*>(*aProxyRequest);
1739 // We will send notifications from imgCacheValidator::OnStartRequest().
1740 // In the mean time, we must defer notifications because we are added to
1741 // the imgRequest's proxy list, and we can get extra notifications
1742 // resulting from methods such as StartDecoding(). See bug 579122.
1743 proxy->MarkValidating();
1745 if (aLinkPreload) {
1746 MOZ_ASSERT(aLoadingDocument);
1747 proxy->PrioritizeAsPreload();
1748 auto preloadKey = PreloadHashKey::CreateAsImage(
1749 aURI, aTriggeringPrincipal, aCORSMode);
1750 proxy->NotifyOpen(preloadKey, aLoadingDocument, true);
1753 // Attach the proxy without notifying
1754 validator->AddProxy(proxy);
1757 return true;
1759 // We will rely on Necko to cache this request when it's possible, and to
1760 // tell imgCacheValidator::OnStartRequest whether the request came from its
1761 // cache.
1762 nsCOMPtr<nsIChannel> newChannel;
1763 bool forcePrincipalCheck;
1764 rv =
1765 NewImageChannel(getter_AddRefs(newChannel), &forcePrincipalCheck, aURI,
1766 aInitialDocumentURI, aCORSMode, aReferrerInfo, aLoadGroup,
1767 aLoadFlags, aLoadPolicyType, aTriggeringPrincipal,
1768 aLoadingDocument, mRespectPrivacy, aEarlyHintPreloaderId);
1769 if (NS_FAILED(rv)) {
1770 return false;
1773 if (aNewChannelCreated) {
1774 *aNewChannelCreated = true;
1777 RefPtr<imgRequestProxy> req;
1778 rv = CreateNewProxyForRequest(request, aURI, aLoadGroup, aLoadingDocument,
1779 aObserver, aLoadFlags, getter_AddRefs(req));
1780 if (NS_FAILED(rv)) {
1781 return false;
1784 // Make sure that OnStatus/OnProgress calls have the right request set...
1785 RefPtr<nsProgressNotificationProxy> progressproxy =
1786 new nsProgressNotificationProxy(newChannel, req);
1787 if (!progressproxy) {
1788 return false;
1791 RefPtr<imgCacheValidator> hvc =
1792 new imgCacheValidator(progressproxy, this, request, aLoadingDocument,
1793 aInnerWindowId, forcePrincipalCheck);
1795 // Casting needed here to get past multiple inheritance.
1796 nsCOMPtr<nsIStreamListener> listener =
1797 do_QueryInterface(static_cast<nsIThreadRetargetableStreamListener*>(hvc));
1798 NS_ENSURE_TRUE(listener, false);
1800 // We must set the notification callbacks before setting up the
1801 // CORS listener, because that's also interested inthe
1802 // notification callbacks.
1803 newChannel->SetNotificationCallbacks(hvc);
1805 request->SetValidator(hvc);
1807 // We will send notifications from imgCacheValidator::OnStartRequest().
1808 // In the mean time, we must defer notifications because we are added to
1809 // the imgRequest's proxy list, and we can get extra notifications
1810 // resulting from methods such as StartDecoding(). See bug 579122.
1811 req->MarkValidating();
1813 if (aLinkPreload) {
1814 MOZ_ASSERT(aLoadingDocument);
1815 req->PrioritizeAsPreload();
1816 auto preloadKey =
1817 PreloadHashKey::CreateAsImage(aURI, aTriggeringPrincipal, aCORSMode);
1818 req->NotifyOpen(preloadKey, aLoadingDocument, true);
1821 // Add the proxy without notifying
1822 hvc->AddProxy(req);
1824 mozilla::net::PredictorLearn(aURI, aInitialDocumentURI,
1825 nsINetworkPredictor::LEARN_LOAD_SUBRESOURCE,
1826 aLoadGroup);
1827 rv = newChannel->AsyncOpen(listener);
1828 if (NS_WARN_IF(NS_FAILED(rv))) {
1829 req->CancelAndForgetObserver(rv);
1830 // This will notify any current or future <link preload> tags. Pass the
1831 // non-open channel so that we can read loadinfo and referrer info of that
1832 // channel.
1833 req->NotifyStart(newChannel);
1834 // Use the non-channel overload of this method to force the notification to
1835 // happen. The preload request has not been assigned a channel.
1836 req->NotifyStop(rv);
1837 return false;
1840 req.forget(aProxyRequest);
1841 return true;
1844 void imgLoader::NotifyObserversForCachedImage(
1845 imgCacheEntry* aEntry, imgRequest* request, nsIURI* aURI,
1846 nsIReferrerInfo* aReferrerInfo, Document* aLoadingDocument,
1847 nsIPrincipal* aTriggeringPrincipal, CORSMode aCORSMode,
1848 uint64_t aEarlyHintPreloaderId) {
1849 if (aEntry->HasNotified()) {
1850 return;
1853 nsCOMPtr<nsIObserverService> obsService = services::GetObserverService();
1855 if (!obsService->HasObservers("http-on-image-cache-response")) {
1856 return;
1859 aEntry->SetHasNotified();
1861 nsCOMPtr<nsIChannel> newChannel;
1862 bool forcePrincipalCheck;
1863 nsresult rv = NewImageChannel(
1864 getter_AddRefs(newChannel), &forcePrincipalCheck, aURI, nullptr,
1865 aCORSMode, aReferrerInfo, nullptr, 0,
1866 nsIContentPolicy::TYPE_INTERNAL_IMAGE, aTriggeringPrincipal,
1867 aLoadingDocument, mRespectPrivacy, aEarlyHintPreloaderId);
1868 if (NS_FAILED(rv)) {
1869 return;
1872 RefPtr<HttpBaseChannel> httpBaseChannel = do_QueryObject(newChannel);
1873 if (httpBaseChannel) {
1874 httpBaseChannel->SetDummyChannelForImageCache();
1875 newChannel->SetContentType(nsDependentCString(request->GetMimeType()));
1876 RefPtr<mozilla::image::Image> image = request->GetImage();
1877 if (image) {
1878 newChannel->SetContentLength(aEntry->GetDataSize());
1880 obsService->NotifyObservers(newChannel, "http-on-image-cache-response",
1881 nullptr);
1885 bool imgLoader::ValidateEntry(
1886 imgCacheEntry* aEntry, nsIURI* aURI, nsIURI* aInitialDocumentURI,
1887 nsIReferrerInfo* aReferrerInfo, nsILoadGroup* aLoadGroup,
1888 imgINotificationObserver* aObserver, Document* aLoadingDocument,
1889 nsLoadFlags aLoadFlags, nsContentPolicyType aLoadPolicyType,
1890 bool aCanMakeNewChannel, bool* aNewChannelCreated,
1891 imgRequestProxy** aProxyRequest, nsIPrincipal* aTriggeringPrincipal,
1892 CORSMode aCORSMode, bool aLinkPreload, uint64_t aEarlyHintPreloaderId) {
1893 LOG_SCOPE(gImgLog, "imgLoader::ValidateEntry");
1895 // If the expiration time is zero, then the request has not gotten far enough
1896 // to know when it will expire, or we know it will never expire (see
1897 // nsContentUtils::GetSubresourceCacheValidationInfo).
1898 uint32_t expiryTime = aEntry->GetExpiryTime();
1899 bool hasExpired = expiryTime && expiryTime <= SecondsFromPRTime(PR_Now());
1901 nsresult rv;
1903 // Special treatment for file URLs - aEntry has expired if file has changed
1904 nsCOMPtr<nsIFileURL> fileUrl(do_QueryInterface(aURI));
1905 if (fileUrl) {
1906 uint32_t lastModTime = aEntry->GetLoadTime();
1908 nsCOMPtr<nsIFile> theFile;
1909 rv = fileUrl->GetFile(getter_AddRefs(theFile));
1910 if (NS_SUCCEEDED(rv)) {
1911 PRTime fileLastMod;
1912 rv = theFile->GetLastModifiedTime(&fileLastMod);
1913 if (NS_SUCCEEDED(rv)) {
1914 // nsIFile uses millisec, NSPR usec
1915 fileLastMod *= 1000;
1916 hasExpired = SecondsFromPRTime((PRTime)fileLastMod) > lastModTime;
1921 RefPtr<imgRequest> request(aEntry->GetRequest());
1923 if (!request) {
1924 return false;
1927 if (!ValidateSecurityInfo(request, aEntry->ForcePrincipalCheck(), aCORSMode,
1928 aTriggeringPrincipal, aLoadingDocument,
1929 aLoadPolicyType)) {
1930 return false;
1933 // data URIs are immutable and by their nature can't leak data, so we can
1934 // just return true in that case. Doing so would mean that shift-reload
1935 // doesn't reload data URI documents/images though (which is handy for
1936 // debugging during gecko development) so we make an exception in that case.
1937 if (aURI->SchemeIs("data") && !(aLoadFlags & nsIRequest::LOAD_BYPASS_CACHE)) {
1938 return true;
1941 bool validateRequest = false;
1943 if (!request->CanReuseWithoutValidation(aLoadingDocument)) {
1944 // If we would need to revalidate this entry, but we're being told to
1945 // bypass the cache, we don't allow this entry to be used.
1946 if (aLoadFlags & nsIRequest::LOAD_BYPASS_CACHE) {
1947 return false;
1950 if (MOZ_UNLIKELY(ChaosMode::isActive(ChaosFeature::ImageCache))) {
1951 if (ChaosMode::randomUint32LessThan(4) < 1) {
1952 return false;
1956 // Determine whether the cache aEntry must be revalidated...
1957 validateRequest = ShouldRevalidateEntry(aEntry, aLoadFlags, hasExpired);
1959 MOZ_LOG(gImgLog, LogLevel::Debug,
1960 ("imgLoader::ValidateEntry validating cache entry. "
1961 "validateRequest = %d",
1962 validateRequest));
1963 } else if (!aLoadingDocument && MOZ_LOG_TEST(gImgLog, LogLevel::Debug)) {
1964 MOZ_LOG(gImgLog, LogLevel::Debug,
1965 ("imgLoader::ValidateEntry BYPASSING cache validation for %s "
1966 "because of NULL loading document",
1967 aURI->GetSpecOrDefault().get()));
1970 // If the original request is still transferring don't kick off a validation
1971 // network request because it is a bit silly to issue a validation request if
1972 // the original request hasn't even finished yet. So just return true
1973 // indicating the caller can create a new proxy for the request and use it as
1974 // is.
1975 // This is an optimization but it's also required for correctness. If we don't
1976 // do this then when firing the load complete notification for the original
1977 // request that can unblock load for the document and then spin the event loop
1978 // (see the stack in bug 1641682) which then the OnStartRequest for the
1979 // validation request can fire which can call UpdateProxies and can sync
1980 // notify on the progress tracker about all existing state, which includes
1981 // load complete, so we fire a second load complete notification for the
1982 // image.
1983 // In addition, we want to validate if the original request encountered
1984 // an error for two reasons. The first being if the error was a network error
1985 // then trying to re-fetch the image might succeed. The second is more
1986 // complicated. We decide if we should fire the load or error event for img
1987 // elements depending on if the image has error in its status at the time when
1988 // the load complete notification is received, and we set error status on an
1989 // image if it encounters a network error or a decode error with no real way
1990 // to tell them apart. So if we load an image that will produce a decode error
1991 // the first time we will usually fire the load event, and then decode enough
1992 // to encounter the decode error and set the error status on the image. The
1993 // next time we reference the image in the same document the load complete
1994 // notification is replayed and this time the error status from the decode is
1995 // already present so we fire the error event instead of the load event. This
1996 // is a bug (bug 1645576) that we should fix. In order to avoid that bug in
1997 // some cases (specifically the cases when we hit this code and try to
1998 // validate the request) we make sure to validate. This avoids the bug because
1999 // when the load complete notification arrives the proxy is marked as
2000 // validating so it lies about its status and returns nothing.
2001 bool requestComplete = false;
2002 RefPtr<ProgressTracker> tracker;
2003 RefPtr<mozilla::image::Image> image = request->GetImage();
2004 if (image) {
2005 tracker = image->GetProgressTracker();
2006 } else {
2007 tracker = request->GetProgressTracker();
2009 if (tracker) {
2010 if (tracker->GetProgress() & (FLAG_LOAD_COMPLETE | FLAG_HAS_ERROR)) {
2011 requestComplete = true;
2014 if (!requestComplete) {
2015 return true;
2018 if (validateRequest && aCanMakeNewChannel) {
2019 LOG_SCOPE(gImgLog, "imgLoader::ValidateRequest |cache hit| must validate");
2021 uint64_t innerWindowID =
2022 aLoadingDocument ? aLoadingDocument->InnerWindowID() : 0;
2023 return ValidateRequestWithNewChannel(
2024 request, aURI, aInitialDocumentURI, aReferrerInfo, aLoadGroup,
2025 aObserver, aLoadingDocument, innerWindowID, aLoadFlags, aLoadPolicyType,
2026 aProxyRequest, aTriggeringPrincipal, aCORSMode, aLinkPreload,
2027 aEarlyHintPreloaderId, aNewChannelCreated);
2030 if (!validateRequest) {
2031 NotifyObserversForCachedImage(aEntry, request, aURI, aReferrerInfo,
2032 aLoadingDocument, aTriggeringPrincipal,
2033 aCORSMode, aEarlyHintPreloaderId);
2036 return !validateRequest;
2039 bool imgLoader::RemoveFromCache(const ImageCacheKey& aKey) {
2040 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::RemoveFromCache", "uri",
2041 aKey.URI());
2042 RefPtr<imgCacheEntry> entry;
2043 mCache.Remove(aKey, getter_AddRefs(entry));
2044 if (entry) {
2045 MOZ_ASSERT(!entry->Evicted(), "Evicting an already-evicted cache entry!");
2047 // Entries with no proxies are in the tracker.
2048 if (entry->HasNoProxies()) {
2049 if (mCacheTracker) {
2050 mCacheTracker->RemoveObject(entry);
2052 mCacheQueue.Remove(entry);
2055 entry->SetEvicted(true);
2057 RefPtr<imgRequest> request = entry->GetRequest();
2058 request->SetIsInCache(false);
2059 AddToUncachedImages(request);
2061 return true;
2063 return false;
2066 bool imgLoader::RemoveFromCache(imgCacheEntry* entry, QueueState aQueueState) {
2067 LOG_STATIC_FUNC(gImgLog, "imgLoader::RemoveFromCache entry");
2069 RefPtr<imgRequest> request = entry->GetRequest();
2070 if (request) {
2071 const ImageCacheKey& key = request->CacheKey();
2072 LOG_STATIC_FUNC_WITH_PARAM(gImgLog, "imgLoader::RemoveFromCache",
2073 "entry's uri", key.URI());
2075 mCache.Remove(key);
2077 if (entry->HasNoProxies()) {
2078 LOG_STATIC_FUNC(gImgLog,
2079 "imgLoader::RemoveFromCache removing from tracker");
2080 if (mCacheTracker) {
2081 mCacheTracker->RemoveObject(entry);
2083 // Only search the queue to remove the entry if its possible it might
2084 // be in the queue. If we know its not in the queue this would be
2085 // wasted work.
2086 MOZ_ASSERT_IF(aQueueState == QueueState::AlreadyRemoved,
2087 !mCacheQueue.Contains(entry));
2088 if (aQueueState == QueueState::MaybeExists) {
2089 mCacheQueue.Remove(entry);
2093 entry->SetEvicted(true);
2094 request->SetIsInCache(false);
2095 AddToUncachedImages(request);
2097 return true;
2100 return false;
2103 nsresult imgLoader::ClearImageCache(ClearOptions aOptions) {
2104 const bool chromeOnly = aOptions.contains(ClearOption::ChromeOnly);
2105 const auto ShouldRemove = [&](imgCacheEntry* aEntry) {
2106 if (chromeOnly) {
2107 // TODO: Consider also removing "resource://" etc?
2108 RefPtr<imgRequest> request = aEntry->GetRequest();
2109 if (!request || !request->CacheKey().URI()->SchemeIs("chrome")) {
2110 return false;
2113 return true;
2115 if (aOptions.contains(ClearOption::UnusedOnly)) {
2116 LOG_STATIC_FUNC(gImgLog, "imgLoader::ClearImageCache queue");
2117 // We have to make a temporary, since RemoveFromCache removes the element
2118 // from the queue, invalidating iterators.
2119 nsTArray<RefPtr<imgCacheEntry>> entries(mCacheQueue.GetNumElements());
2120 for (auto& entry : mCacheQueue) {
2121 if (ShouldRemove(entry)) {
2122 entries.AppendElement(entry);
2126 // Iterate in reverse order to minimize array copying.
2127 for (auto& entry : entries) {
2128 if (!RemoveFromCache(entry)) {
2129 return NS_ERROR_FAILURE;
2133 MOZ_ASSERT(chromeOnly || mCacheQueue.GetNumElements() == 0);
2134 return NS_OK;
2137 LOG_STATIC_FUNC(gImgLog, "imgLoader::ClearImageCache table");
2138 // We have to make a temporary, since RemoveFromCache removes the element
2139 // from the queue, invalidating iterators.
2140 const auto entries =
2141 ToTArray<nsTArray<RefPtr<imgCacheEntry>>>(mCache.Values());
2142 for (const auto& entry : entries) {
2143 if (!ShouldRemove(entry)) {
2144 continue;
2146 if (!RemoveFromCache(entry)) {
2147 return NS_ERROR_FAILURE;
2150 MOZ_ASSERT(chromeOnly || mCache.IsEmpty());
2151 return NS_OK;
2154 void imgLoader::AddToUncachedImages(imgRequest* aRequest) {
2155 MutexAutoLock lock(mUncachedImagesMutex);
2156 mUncachedImages.Insert(aRequest);
2159 void imgLoader::RemoveFromUncachedImages(imgRequest* aRequest) {
2160 MutexAutoLock lock(mUncachedImagesMutex);
2161 mUncachedImages.Remove(aRequest);
2164 #define LOAD_FLAGS_CACHE_MASK \
2165 (nsIRequest::LOAD_BYPASS_CACHE | nsIRequest::LOAD_FROM_CACHE)
2167 #define LOAD_FLAGS_VALIDATE_MASK \
2168 (nsIRequest::VALIDATE_ALWAYS | nsIRequest::VALIDATE_NEVER | \
2169 nsIRequest::VALIDATE_ONCE_PER_SESSION)
2171 NS_IMETHODIMP
2172 imgLoader::LoadImageXPCOM(
2173 nsIURI* aURI, nsIURI* aInitialDocumentURI, nsIReferrerInfo* aReferrerInfo,
2174 nsIPrincipal* aTriggeringPrincipal, nsILoadGroup* aLoadGroup,
2175 imgINotificationObserver* aObserver, Document* aLoadingDocument,
2176 nsLoadFlags aLoadFlags, nsISupports* aCacheKey,
2177 nsContentPolicyType aContentPolicyType, imgIRequest** _retval) {
2178 // Optional parameter, so defaults to 0 (== TYPE_INVALID)
2179 if (!aContentPolicyType) {
2180 aContentPolicyType = nsIContentPolicy::TYPE_INTERNAL_IMAGE;
2182 imgRequestProxy* proxy;
2183 nsresult rv =
2184 LoadImage(aURI, aInitialDocumentURI, aReferrerInfo, aTriggeringPrincipal,
2185 0, aLoadGroup, aObserver, aLoadingDocument, aLoadingDocument,
2186 aLoadFlags, aCacheKey, aContentPolicyType, u""_ns,
2187 /* aUseUrgentStartForChannel */ false, /* aListPreload */ false,
2188 0, &proxy);
2189 *_retval = proxy;
2190 return rv;
2193 static void MakeRequestStaticIfNeeded(
2194 Document* aLoadingDocument, imgRequestProxy** aProxyAboutToGetReturned) {
2195 if (!aLoadingDocument || !aLoadingDocument->IsStaticDocument()) {
2196 return;
2199 if (!*aProxyAboutToGetReturned) {
2200 return;
2203 RefPtr<imgRequestProxy> proxy = dont_AddRef(*aProxyAboutToGetReturned);
2204 *aProxyAboutToGetReturned = nullptr;
2206 RefPtr<imgRequestProxy> staticProxy =
2207 proxy->GetStaticRequest(aLoadingDocument);
2208 if (staticProxy != proxy) {
2209 proxy->CancelAndForgetObserver(NS_BINDING_ABORTED);
2210 proxy = std::move(staticProxy);
2212 proxy.forget(aProxyAboutToGetReturned);
2215 bool imgLoader::IsImageAvailable(nsIURI* aURI,
2216 nsIPrincipal* aTriggeringPrincipal,
2217 CORSMode aCORSMode, Document* aDocument) {
2218 ImageCacheKey key(aURI, aCORSMode,
2219 aTriggeringPrincipal->OriginAttributesRef(), aDocument);
2220 RefPtr<imgCacheEntry> entry;
2221 if (!mCache.Get(key, getter_AddRefs(entry)) || !entry) {
2222 return false;
2224 RefPtr<imgRequest> request = entry->GetRequest();
2225 if (!request) {
2226 return false;
2228 if (nsCOMPtr<nsILoadGroup> docLoadGroup = aDocument->GetDocumentLoadGroup()) {
2229 nsLoadFlags requestFlags = nsIRequest::LOAD_NORMAL;
2230 docLoadGroup->GetLoadFlags(&requestFlags);
2231 if (requestFlags & nsIRequest::LOAD_BYPASS_CACHE) {
2232 // If we're bypassing the cache, treat the image as not available.
2233 return false;
2236 return ValidateCORSMode(request, false, aCORSMode, aTriggeringPrincipal);
2239 nsresult imgLoader::LoadImage(
2240 nsIURI* aURI, nsIURI* aInitialDocumentURI, nsIReferrerInfo* aReferrerInfo,
2241 nsIPrincipal* aTriggeringPrincipal, uint64_t aRequestContextID,
2242 nsILoadGroup* aLoadGroup, imgINotificationObserver* aObserver,
2243 nsINode* aContext, Document* aLoadingDocument, nsLoadFlags aLoadFlags,
2244 nsISupports* aCacheKey, nsContentPolicyType aContentPolicyType,
2245 const nsAString& initiatorType, bool aUseUrgentStartForChannel,
2246 bool aLinkPreload, uint64_t aEarlyHintPreloaderId,
2247 imgRequestProxy** _retval) {
2248 VerifyCacheSizes();
2250 NS_ASSERTION(aURI, "imgLoader::LoadImage -- NULL URI pointer");
2252 if (!aURI) {
2253 return NS_ERROR_NULL_POINTER;
2256 auto makeStaticIfNeeded = mozilla::MakeScopeExit(
2257 [&] { MakeRequestStaticIfNeeded(aLoadingDocument, _retval); });
2259 AUTO_PROFILER_LABEL_DYNAMIC_NSCSTRING("imgLoader::LoadImage", NETWORK,
2260 aURI->GetSpecOrDefault());
2262 LOG_SCOPE_WITH_PARAM(gImgLog, "imgLoader::LoadImage", "aURI", aURI);
2264 *_retval = nullptr;
2266 RefPtr<imgRequest> request;
2268 nsresult rv;
2269 nsLoadFlags requestFlags = nsIRequest::LOAD_NORMAL;
2271 #ifdef DEBUG
2272 bool isPrivate = false;
2274 if (aLoadingDocument) {
2275 isPrivate = nsContentUtils::IsInPrivateBrowsing(aLoadingDocument);
2276 } else if (aLoadGroup) {
2277 isPrivate = nsContentUtils::IsInPrivateBrowsing(aLoadGroup);
2279 MOZ_ASSERT(isPrivate == mRespectPrivacy);
2281 if (aLoadingDocument) {
2282 // The given load group should match that of the document if given. If
2283 // that isn't the case, then we need to add more plumbing to ensure we
2284 // block the document as well.
2285 nsCOMPtr<nsILoadGroup> docLoadGroup =
2286 aLoadingDocument->GetDocumentLoadGroup();
2287 MOZ_ASSERT(docLoadGroup == aLoadGroup);
2289 #endif
2291 // Get the default load flags from the loadgroup (if possible)...
2292 if (aLoadGroup) {
2293 aLoadGroup->GetLoadFlags(&requestFlags);
2296 // Merge the default load flags with those passed in via aLoadFlags.
2297 // Currently, *only* the caching, validation and background load flags
2298 // are merged...
2300 // The flags in aLoadFlags take precedence over the default flags!
2302 if (aLoadFlags & LOAD_FLAGS_CACHE_MASK) {
2303 // Override the default caching flags...
2304 requestFlags = (requestFlags & ~LOAD_FLAGS_CACHE_MASK) |
2305 (aLoadFlags & LOAD_FLAGS_CACHE_MASK);
2307 if (aLoadFlags & LOAD_FLAGS_VALIDATE_MASK) {
2308 // Override the default validation flags...
2309 requestFlags = (requestFlags & ~LOAD_FLAGS_VALIDATE_MASK) |
2310 (aLoadFlags & LOAD_FLAGS_VALIDATE_MASK);
2312 if (aLoadFlags & nsIRequest::LOAD_BACKGROUND) {
2313 // Propagate background loading...
2314 requestFlags |= nsIRequest::LOAD_BACKGROUND;
2316 if (aLoadFlags & nsIRequest::LOAD_RECORD_START_REQUEST_DELAY) {
2317 requestFlags |= nsIRequest::LOAD_RECORD_START_REQUEST_DELAY;
2320 if (aLinkPreload) {
2321 // Set background loading if it is <link rel=preload>
2322 requestFlags |= nsIRequest::LOAD_BACKGROUND;
2325 CORSMode corsmode = CORS_NONE;
2326 if (aLoadFlags & imgILoader::LOAD_CORS_ANONYMOUS) {
2327 corsmode = CORS_ANONYMOUS;
2328 } else if (aLoadFlags & imgILoader::LOAD_CORS_USE_CREDENTIALS) {
2329 corsmode = CORS_USE_CREDENTIALS;
2332 // Look in the preloaded images of loading document first.
2333 if (StaticPrefs::network_preload() && !aLinkPreload && aLoadingDocument) {
2334 // All Early Hints preloads are Link preloads, therefore we don't have a
2335 // Early Hints preload here
2336 MOZ_ASSERT(!aEarlyHintPreloaderId);
2337 auto key =
2338 PreloadHashKey::CreateAsImage(aURI, aTriggeringPrincipal, corsmode);
2339 if (RefPtr<PreloaderBase> preload =
2340 aLoadingDocument->Preloads().LookupPreload(key)) {
2341 RefPtr<imgRequestProxy> proxy = do_QueryObject(preload);
2342 MOZ_ASSERT(proxy);
2344 MOZ_LOG(gImgLog, LogLevel::Debug,
2345 ("[this=%p] imgLoader::LoadImage -- preloaded [proxy=%p]"
2346 " [document=%p]\n",
2347 this, proxy.get(), aLoadingDocument));
2349 // Removing the preload for this image to be in parity with Chromium. Any
2350 // following regular image request will be reloaded using the regular
2351 // path: image cache, http cache, network. Any following `<link
2352 // rel=preload as=image>` will start a new image preload that can be
2353 // satisfied from http cache or network.
2355 // There is a spec discussion for "preload cache", see
2356 // https://github.com/w3c/preload/issues/97. And it is also not clear how
2357 // preload image interacts with list of available images, see
2358 // https://github.com/whatwg/html/issues/4474.
2359 proxy->RemoveSelf(aLoadingDocument);
2360 proxy->NotifyUsage(aLoadingDocument);
2362 imgRequest* request = proxy->GetOwner();
2363 nsresult rv =
2364 CreateNewProxyForRequest(request, aURI, aLoadGroup, aLoadingDocument,
2365 aObserver, requestFlags, _retval);
2366 NS_ENSURE_SUCCESS(rv, rv);
2368 imgRequestProxy* newProxy = *_retval;
2369 if (imgCacheValidator* validator = request->GetValidator()) {
2370 newProxy->MarkValidating();
2371 // Attach the proxy without notifying and this will add us to the load
2372 // group.
2373 validator->AddProxy(newProxy);
2374 } else {
2375 // It's OK to add here even if the request is done. If it is, it'll send
2376 // a OnStopRequest()and the proxy will be removed from the loadgroup in
2377 // imgRequestProxy::OnLoadComplete.
2378 newProxy->AddToLoadGroup();
2379 newProxy->NotifyListener();
2382 return NS_OK;
2386 RefPtr<imgCacheEntry> entry;
2388 // Look in the cache for our URI, and then validate it.
2389 // XXX For now ignore aCacheKey. We will need it in the future
2390 // for correctly dealing with image load requests that are a result
2391 // of post data.
2392 OriginAttributes attrs;
2393 if (aTriggeringPrincipal) {
2394 attrs = aTriggeringPrincipal->OriginAttributesRef();
2396 ImageCacheKey key(aURI, corsmode, attrs, aLoadingDocument);
2397 if (mCache.Get(key, getter_AddRefs(entry)) && entry) {
2398 bool newChannelCreated = false;
2399 if (ValidateEntry(entry, aURI, aInitialDocumentURI, aReferrerInfo,
2400 aLoadGroup, aObserver, aLoadingDocument, requestFlags,
2401 aContentPolicyType, true, &newChannelCreated, _retval,
2402 aTriggeringPrincipal, corsmode, aLinkPreload,
2403 aEarlyHintPreloaderId)) {
2404 request = entry->GetRequest();
2406 // If this entry has no proxies, its request has no reference to the
2407 // entry.
2408 if (entry->HasNoProxies()) {
2409 LOG_FUNC_WITH_PARAM(gImgLog,
2410 "imgLoader::LoadImage() adding proxyless entry",
2411 "uri", key.URI());
2412 MOZ_ASSERT(!request->HasCacheEntry(),
2413 "Proxyless entry's request has cache entry!");
2414 request->SetCacheEntry(entry);
2416 if (mCacheTracker && entry->GetExpirationState()->IsTracked()) {
2417 mCacheTracker->MarkUsed(entry);
2421 entry->Touch();
2423 if (!newChannelCreated) {
2424 // This is ugly but it's needed to report CSP violations. We have 3
2425 // scenarios:
2426 // - we don't have cache. We are not in this if() stmt. A new channel is
2427 // created and that triggers the CSP checks.
2428 // - We have a cache entry and this is blocked by CSP directives.
2429 DebugOnly<bool> shouldLoad = ShouldLoadCachedImage(
2430 request, aLoadingDocument, aTriggeringPrincipal, aContentPolicyType,
2431 /* aSendCSPViolationReports */ true);
2432 MOZ_ASSERT(shouldLoad);
2434 } else {
2435 // We can't use this entry. We'll try to load it off the network, and if
2436 // successful, overwrite the old entry in the cache with a new one.
2437 entry = nullptr;
2441 // Keep the channel in this scope, so we can adjust its notificationCallbacks
2442 // later when we create the proxy.
2443 nsCOMPtr<nsIChannel> newChannel;
2444 // If we didn't get a cache hit, we need to load from the network.
2445 if (!request) {
2446 LOG_SCOPE(gImgLog, "imgLoader::LoadImage |cache miss|");
2448 bool forcePrincipalCheck;
2449 rv = NewImageChannel(getter_AddRefs(newChannel), &forcePrincipalCheck, aURI,
2450 aInitialDocumentURI, corsmode, aReferrerInfo,
2451 aLoadGroup, requestFlags, aContentPolicyType,
2452 aTriggeringPrincipal, aContext, mRespectPrivacy,
2453 aEarlyHintPreloaderId);
2454 if (NS_FAILED(rv)) {
2455 return NS_ERROR_FAILURE;
2458 MOZ_ASSERT(NS_UsePrivateBrowsing(newChannel) == mRespectPrivacy);
2460 NewRequestAndEntry(forcePrincipalCheck, this, key, getter_AddRefs(request),
2461 getter_AddRefs(entry));
2463 MOZ_LOG(gImgLog, LogLevel::Debug,
2464 ("[this=%p] imgLoader::LoadImage -- Created new imgRequest"
2465 " [request=%p]\n",
2466 this, request.get()));
2468 nsCOMPtr<nsIClassOfService> cos(do_QueryInterface(newChannel));
2469 if (cos) {
2470 if (aUseUrgentStartForChannel && !aLinkPreload) {
2471 cos->AddClassFlags(nsIClassOfService::UrgentStart);
2474 if (StaticPrefs::network_http_tailing_enabled() &&
2475 aContentPolicyType == nsIContentPolicy::TYPE_INTERNAL_IMAGE_FAVICON) {
2476 cos->AddClassFlags(nsIClassOfService::Throttleable |
2477 nsIClassOfService::Tail);
2478 nsCOMPtr<nsIHttpChannel> httpChannel(do_QueryInterface(newChannel));
2479 if (httpChannel) {
2480 Unused << httpChannel->SetRequestContextID(aRequestContextID);
2485 nsCOMPtr<nsILoadGroup> channelLoadGroup;
2486 newChannel->GetLoadGroup(getter_AddRefs(channelLoadGroup));
2487 rv = request->Init(aURI, aURI, /* aHadInsecureRedirect = */ false,
2488 channelLoadGroup, newChannel, entry, aLoadingDocument,
2489 aTriggeringPrincipal, corsmode, aReferrerInfo);
2490 if (NS_FAILED(rv)) {
2491 return NS_ERROR_FAILURE;
2494 // Add the initiator type for this image load
2495 nsCOMPtr<nsITimedChannel> timedChannel = do_QueryInterface(newChannel);
2496 if (timedChannel) {
2497 timedChannel->SetInitiatorType(initiatorType);
2500 // create the proxy listener
2501 nsCOMPtr<nsIStreamListener> listener = new ProxyListener(request.get());
2503 MOZ_LOG(gImgLog, LogLevel::Debug,
2504 ("[this=%p] imgLoader::LoadImage -- Calling channel->AsyncOpen()\n",
2505 this));
2507 mozilla::net::PredictorLearn(aURI, aInitialDocumentURI,
2508 nsINetworkPredictor::LEARN_LOAD_SUBRESOURCE,
2509 aLoadGroup);
2511 nsresult openRes;
2512 openRes = newChannel->AsyncOpen(listener);
2514 if (NS_FAILED(openRes)) {
2515 MOZ_LOG(
2516 gImgLog, LogLevel::Debug,
2517 ("[this=%p] imgLoader::LoadImage -- AsyncOpen() failed: 0x%" PRIx32
2518 "\n",
2519 this, static_cast<uint32_t>(openRes)));
2520 request->CancelAndAbort(openRes);
2521 return openRes;
2524 // Try to add the new request into the cache.
2525 PutIntoCache(key, entry);
2526 } else {
2527 LOG_MSG_WITH_PARAM(gImgLog, "imgLoader::LoadImage |cache hit|", "request",
2528 request);
2531 // If we didn't get a proxy when validating the cache entry, we need to
2532 // create one.
2533 if (!*_retval) {
2534 // ValidateEntry() has three return values: "Is valid," "might be valid --
2535 // validating over network", and "not valid." If we don't have a _retval,
2536 // we know ValidateEntry is not validating over the network, so it's safe
2537 // to SetLoadId here because we know this request is valid for this context.
2539 // Note, however, that this doesn't guarantee the behaviour we want (one
2540 // URL maps to the same image on a page) if we load the same image in a
2541 // different tab (see bug 528003), because its load id will get re-set, and
2542 // that'll cause us to validate over the network.
2543 request->SetLoadId(aLoadingDocument);
2545 LOG_MSG(gImgLog, "imgLoader::LoadImage", "creating proxy request.");
2546 rv = CreateNewProxyForRequest(request, aURI, aLoadGroup, aLoadingDocument,
2547 aObserver, requestFlags, _retval);
2548 if (NS_FAILED(rv)) {
2549 return rv;
2552 imgRequestProxy* proxy = *_retval;
2554 // Make sure that OnStatus/OnProgress calls have the right request set, if
2555 // we did create a channel here.
2556 if (newChannel) {
2557 nsCOMPtr<nsIInterfaceRequestor> requestor(
2558 new nsProgressNotificationProxy(newChannel, proxy));
2559 if (!requestor) {
2560 return NS_ERROR_OUT_OF_MEMORY;
2562 newChannel->SetNotificationCallbacks(requestor);
2565 if (aLinkPreload) {
2566 MOZ_ASSERT(aLoadingDocument);
2567 proxy->PrioritizeAsPreload();
2568 auto preloadKey =
2569 PreloadHashKey::CreateAsImage(aURI, aTriggeringPrincipal, corsmode);
2570 proxy->NotifyOpen(preloadKey, aLoadingDocument, true);
2573 // Note that it's OK to add here even if the request is done. If it is,
2574 // it'll send a OnStopRequest() to the proxy in imgRequestProxy::Notify and
2575 // the proxy will be removed from the loadgroup.
2576 proxy->AddToLoadGroup();
2578 // If we're loading off the network, explicitly don't notify our proxy,
2579 // because necko (or things called from necko, such as imgCacheValidator)
2580 // are going to call our notifications asynchronously, and we can't make it
2581 // further asynchronous because observers might rely on imagelib completing
2582 // its work between the channel's OnStartRequest and OnStopRequest.
2583 if (!newChannel) {
2584 proxy->NotifyListener();
2587 return rv;
2590 NS_ASSERTION(*_retval, "imgLoader::LoadImage -- no return value");
2592 return NS_OK;
2595 NS_IMETHODIMP
2596 imgLoader::LoadImageWithChannelXPCOM(nsIChannel* channel,
2597 imgINotificationObserver* aObserver,
2598 Document* aLoadingDocument,
2599 nsIStreamListener** listener,
2600 imgIRequest** _retval) {
2601 nsresult result;
2602 imgRequestProxy* proxy;
2603 result = LoadImageWithChannel(channel, aObserver, aLoadingDocument, listener,
2604 &proxy);
2605 *_retval = proxy;
2606 return result;
2609 nsresult imgLoader::LoadImageWithChannel(nsIChannel* channel,
2610 imgINotificationObserver* aObserver,
2611 Document* aLoadingDocument,
2612 nsIStreamListener** listener,
2613 imgRequestProxy** _retval) {
2614 NS_ASSERTION(channel,
2615 "imgLoader::LoadImageWithChannel -- NULL channel pointer");
2617 MOZ_ASSERT(NS_UsePrivateBrowsing(channel) == mRespectPrivacy);
2619 auto makeStaticIfNeeded = mozilla::MakeScopeExit(
2620 [&] { MakeRequestStaticIfNeeded(aLoadingDocument, _retval); });
2622 LOG_SCOPE(gImgLog, "imgLoader::LoadImageWithChannel");
2623 RefPtr<imgRequest> request;
2625 nsCOMPtr<nsIURI> uri;
2626 channel->GetURI(getter_AddRefs(uri));
2628 NS_ENSURE_TRUE(channel, NS_ERROR_FAILURE);
2629 nsCOMPtr<nsILoadInfo> loadInfo = channel->LoadInfo();
2631 OriginAttributes attrs = loadInfo->GetOriginAttributes();
2633 // TODO: Get a meaningful cors mode from the caller probably?
2634 const auto corsMode = CORS_NONE;
2635 ImageCacheKey key(uri, corsMode, attrs, aLoadingDocument);
2637 nsLoadFlags requestFlags = nsIRequest::LOAD_NORMAL;
2638 channel->GetLoadFlags(&requestFlags);
2640 RefPtr<imgCacheEntry> entry;
2642 if (requestFlags & nsIRequest::LOAD_BYPASS_CACHE) {
2643 RemoveFromCache(key);
2644 } else {
2645 // Look in the cache for our URI, and then validate it.
2646 // XXX For now ignore aCacheKey. We will need it in the future
2647 // for correctly dealing with image load requests that are a result
2648 // of post data.
2649 if (mCache.Get(key, getter_AddRefs(entry)) && entry) {
2650 // We don't want to kick off another network load. So we ask
2651 // ValidateEntry to only do validation without creating a new proxy. If
2652 // it says that the entry isn't valid any more, we'll only use the entry
2653 // we're getting if the channel is loading from the cache anyways.
2655 // XXX -- should this be changed? it's pretty much verbatim from the old
2656 // code, but seems nonsensical.
2658 // Since aCanMakeNewChannel == false, we don't need to pass content policy
2659 // type/principal/etc
2661 nsCOMPtr<nsILoadInfo> loadInfo = channel->LoadInfo();
2662 // if there is a loadInfo, use the right contentType, otherwise
2663 // default to the internal image type
2664 nsContentPolicyType policyType = loadInfo->InternalContentPolicyType();
2666 if (ValidateEntry(entry, uri, nullptr, nullptr, nullptr, aObserver,
2667 aLoadingDocument, requestFlags, policyType, false,
2668 nullptr, nullptr, nullptr, corsMode, false, 0)) {
2669 request = entry->GetRequest();
2670 } else {
2671 nsCOMPtr<nsICacheInfoChannel> cacheChan(do_QueryInterface(channel));
2672 bool bUseCacheCopy;
2674 if (cacheChan) {
2675 cacheChan->IsFromCache(&bUseCacheCopy);
2676 } else {
2677 bUseCacheCopy = false;
2680 if (!bUseCacheCopy) {
2681 entry = nullptr;
2682 } else {
2683 request = entry->GetRequest();
2687 if (request && entry) {
2688 // If this entry has no proxies, its request has no reference to
2689 // the entry.
2690 if (entry->HasNoProxies()) {
2691 LOG_FUNC_WITH_PARAM(
2692 gImgLog,
2693 "imgLoader::LoadImageWithChannel() adding proxyless entry", "uri",
2694 key.URI());
2695 MOZ_ASSERT(!request->HasCacheEntry(),
2696 "Proxyless entry's request has cache entry!");
2697 request->SetCacheEntry(entry);
2699 if (mCacheTracker && entry->GetExpirationState()->IsTracked()) {
2700 mCacheTracker->MarkUsed(entry);
2707 nsCOMPtr<nsILoadGroup> loadGroup;
2708 channel->GetLoadGroup(getter_AddRefs(loadGroup));
2710 #ifdef DEBUG
2711 if (aLoadingDocument) {
2712 // The load group of the channel should always match that of the
2713 // document if given. If that isn't the case, then we need to add more
2714 // plumbing to ensure we block the document as well.
2715 nsCOMPtr<nsILoadGroup> docLoadGroup =
2716 aLoadingDocument->GetDocumentLoadGroup();
2717 MOZ_ASSERT(docLoadGroup == loadGroup);
2719 #endif
2721 // Filter out any load flags not from nsIRequest
2722 requestFlags &= nsIRequest::LOAD_REQUESTMASK;
2724 nsresult rv = NS_OK;
2725 if (request) {
2726 // we have this in our cache already.. cancel the current (document) load
2728 // this should fire an OnStopRequest
2729 channel->Cancel(NS_ERROR_PARSED_DATA_CACHED);
2731 *listener = nullptr; // give them back a null nsIStreamListener
2733 rv = CreateNewProxyForRequest(request, uri, loadGroup, aLoadingDocument,
2734 aObserver, requestFlags, _retval);
2735 static_cast<imgRequestProxy*>(*_retval)->NotifyListener();
2736 } else {
2737 // We use originalURI here to fulfil the imgIRequest contract on GetURI.
2738 nsCOMPtr<nsIURI> originalURI;
2739 channel->GetOriginalURI(getter_AddRefs(originalURI));
2741 // XXX(seth): We should be able to just use |key| here, except that |key| is
2742 // constructed above with the *current URI* and not the *original URI*. I'm
2743 // pretty sure this is a bug, and it's preventing us from ever getting a
2744 // cache hit in LoadImageWithChannel when redirects are involved.
2745 ImageCacheKey originalURIKey(originalURI, corsMode, attrs,
2746 aLoadingDocument);
2748 // Default to doing a principal check because we don't know who
2749 // started that load and whether their principal ended up being
2750 // inherited on the channel.
2751 NewRequestAndEntry(/* aForcePrincipalCheckForCacheEntry = */ true, this,
2752 originalURIKey, getter_AddRefs(request),
2753 getter_AddRefs(entry));
2755 // No principal specified here, because we're not passed one.
2756 // In LoadImageWithChannel, the redirects that may have been
2757 // associated with this load would have gone through necko.
2758 // We only have the final URI in ImageLib and hence don't know
2759 // if the request went through insecure redirects. But if it did,
2760 // the necko cache should have handled that (since all necko cache hits
2761 // including the redirects will go through content policy). Hence, we
2762 // can set aHadInsecureRedirect to false here.
2763 rv = request->Init(originalURI, uri, /* aHadInsecureRedirect = */ false,
2764 channel, channel, entry, aLoadingDocument, nullptr,
2765 corsMode, nullptr);
2766 NS_ENSURE_SUCCESS(rv, rv);
2768 RefPtr<ProxyListener> pl =
2769 new ProxyListener(static_cast<nsIStreamListener*>(request.get()));
2770 pl.forget(listener);
2772 // Try to add the new request into the cache.
2773 PutIntoCache(originalURIKey, entry);
2775 rv = CreateNewProxyForRequest(request, originalURI, loadGroup,
2776 aLoadingDocument, aObserver, requestFlags,
2777 _retval);
2779 // Explicitly don't notify our proxy, because we're loading off the
2780 // network, and necko (or things called from necko, such as
2781 // imgCacheValidator) are going to call our notifications asynchronously,
2782 // and we can't make it further asynchronous because observers might rely
2783 // on imagelib completing its work between the channel's OnStartRequest and
2784 // OnStopRequest.
2787 if (NS_FAILED(rv)) {
2788 return rv;
2791 (*_retval)->AddToLoadGroup();
2792 return rv;
2795 bool imgLoader::SupportImageWithMimeType(const nsACString& aMimeType,
2796 AcceptedMimeTypes aAccept
2797 /* = AcceptedMimeTypes::IMAGES */) {
2798 nsAutoCString mimeType(aMimeType);
2799 ToLowerCase(mimeType);
2801 if (aAccept == AcceptedMimeTypes::IMAGES_AND_DOCUMENTS &&
2802 mimeType.EqualsLiteral("image/svg+xml")) {
2803 return true;
2806 DecoderType type = DecoderFactory::GetDecoderType(mimeType.get());
2807 return type != DecoderType::UNKNOWN;
2810 NS_IMETHODIMP
2811 imgLoader::GetMIMETypeFromContent(nsIRequest* aRequest,
2812 const uint8_t* aContents, uint32_t aLength,
2813 nsACString& aContentType) {
2814 nsCOMPtr<nsIChannel> channel(do_QueryInterface(aRequest));
2815 if (channel) {
2816 nsCOMPtr<nsILoadInfo> loadInfo = channel->LoadInfo();
2817 if (loadInfo->GetSkipContentSniffing()) {
2818 return NS_ERROR_NOT_AVAILABLE;
2822 nsresult rv =
2823 GetMimeTypeFromContent((const char*)aContents, aLength, aContentType);
2824 if (NS_SUCCEEDED(rv) && channel && XRE_IsParentProcess()) {
2825 if (RefPtr<mozilla::net::nsHttpChannel> httpChannel =
2826 do_QueryObject(channel)) {
2827 // If the image type pattern matching algorithm given bytes does not
2828 // return undefined, then disable the further check and allow the
2829 // response.
2830 httpChannel->DisableIsOpaqueResponseAllowedAfterSniffCheck(
2831 mozilla::net::nsHttpChannel::SnifferType::Image);
2835 return rv;
2838 /* static */
2839 nsresult imgLoader::GetMimeTypeFromContent(const char* aContents,
2840 uint32_t aLength,
2841 nsACString& aContentType) {
2842 nsAutoCString detected;
2844 /* Is it a GIF? */
2845 if (aLength >= 6 &&
2846 (!strncmp(aContents, "GIF87a", 6) || !strncmp(aContents, "GIF89a", 6))) {
2847 aContentType.AssignLiteral(IMAGE_GIF);
2849 /* or a PNG? */
2850 } else if (aLength >= 8 && ((unsigned char)aContents[0] == 0x89 &&
2851 (unsigned char)aContents[1] == 0x50 &&
2852 (unsigned char)aContents[2] == 0x4E &&
2853 (unsigned char)aContents[3] == 0x47 &&
2854 (unsigned char)aContents[4] == 0x0D &&
2855 (unsigned char)aContents[5] == 0x0A &&
2856 (unsigned char)aContents[6] == 0x1A &&
2857 (unsigned char)aContents[7] == 0x0A)) {
2858 aContentType.AssignLiteral(IMAGE_PNG);
2860 /* maybe a JPEG (JFIF)? */
2861 /* JFIF files start with SOI APP0 but older files can start with SOI DQT
2862 * so we test for SOI followed by any marker, i.e. FF D8 FF
2863 * this will also work for SPIFF JPEG files if they appear in the future.
2865 * (JFIF is 0XFF 0XD8 0XFF 0XE0 <skip 2> 0X4A 0X46 0X49 0X46 0X00)
2867 } else if (aLength >= 3 && ((unsigned char)aContents[0]) == 0xFF &&
2868 ((unsigned char)aContents[1]) == 0xD8 &&
2869 ((unsigned char)aContents[2]) == 0xFF) {
2870 aContentType.AssignLiteral(IMAGE_JPEG);
2872 /* or how about ART? */
2873 /* ART begins with JG (4A 47). Major version offset 2.
2874 * Minor version offset 3. Offset 4 must be nullptr.
2876 } else if (aLength >= 5 && ((unsigned char)aContents[0]) == 0x4a &&
2877 ((unsigned char)aContents[1]) == 0x47 &&
2878 ((unsigned char)aContents[4]) == 0x00) {
2879 aContentType.AssignLiteral(IMAGE_ART);
2881 } else if (aLength >= 2 && !strncmp(aContents, "BM", 2)) {
2882 aContentType.AssignLiteral(IMAGE_BMP);
2884 // ICOs always begin with a 2-byte 0 followed by a 2-byte 1.
2885 // CURs begin with 2-byte 0 followed by 2-byte 2.
2886 } else if (aLength >= 4 && (!memcmp(aContents, "\000\000\001\000", 4) ||
2887 !memcmp(aContents, "\000\000\002\000", 4))) {
2888 aContentType.AssignLiteral(IMAGE_ICO);
2890 // WebPs always begin with RIFF, a 32-bit length, and WEBP.
2891 } else if (aLength >= 12 && !memcmp(aContents, "RIFF", 4) &&
2892 !memcmp(aContents + 8, "WEBP", 4)) {
2893 aContentType.AssignLiteral(IMAGE_WEBP);
2895 } else if (MatchesMP4(reinterpret_cast<const uint8_t*>(aContents), aLength,
2896 detected) &&
2897 detected.Equals(IMAGE_AVIF)) {
2898 aContentType.AssignLiteral(IMAGE_AVIF);
2899 } else if ((aLength >= 2 && !memcmp(aContents, "\xFF\x0A", 2)) ||
2900 (aLength >= 12 &&
2901 !memcmp(aContents, "\x00\x00\x00\x0CJXL \x0D\x0A\x87\x0A", 12))) {
2902 // Each version is for containerless and containerful files respectively.
2903 aContentType.AssignLiteral(IMAGE_JXL);
2904 } else {
2905 /* none of the above? I give up */
2906 return NS_ERROR_NOT_AVAILABLE;
2909 return NS_OK;
2913 * proxy stream listener class used to handle multipart/x-mixed-replace
2916 #include "nsIRequest.h"
2917 #include "nsIStreamConverterService.h"
2919 NS_IMPL_ISUPPORTS(ProxyListener, nsIStreamListener,
2920 nsIThreadRetargetableStreamListener, nsIRequestObserver)
2922 ProxyListener::ProxyListener(nsIStreamListener* dest) : mDestListener(dest) {}
2924 ProxyListener::~ProxyListener() = default;
2926 /** nsIRequestObserver methods **/
2928 NS_IMETHODIMP
2929 ProxyListener::OnStartRequest(nsIRequest* aRequest) {
2930 if (!mDestListener) {
2931 return NS_ERROR_FAILURE;
2934 nsCOMPtr<nsIChannel> channel(do_QueryInterface(aRequest));
2935 if (channel) {
2936 // We need to set the initiator type for the image load
2937 nsCOMPtr<nsITimedChannel> timedChannel = do_QueryInterface(channel);
2938 if (timedChannel) {
2939 nsAutoString type;
2940 timedChannel->GetInitiatorType(type);
2941 if (type.IsEmpty()) {
2942 timedChannel->SetInitiatorType(u"img"_ns);
2946 nsAutoCString contentType;
2947 nsresult rv = channel->GetContentType(contentType);
2949 if (!contentType.IsEmpty()) {
2950 /* If multipart/x-mixed-replace content, we'll insert a MIME decoder
2951 in the pipeline to handle the content and pass it along to our
2952 original listener.
2954 if ("multipart/x-mixed-replace"_ns.Equals(contentType)) {
2955 nsCOMPtr<nsIStreamConverterService> convServ(
2956 do_GetService("@mozilla.org/streamConverters;1", &rv));
2957 if (NS_SUCCEEDED(rv)) {
2958 nsCOMPtr<nsIStreamListener> toListener(mDestListener);
2959 nsCOMPtr<nsIStreamListener> fromListener;
2961 rv = convServ->AsyncConvertData("multipart/x-mixed-replace", "*/*",
2962 toListener, nullptr,
2963 getter_AddRefs(fromListener));
2964 if (NS_SUCCEEDED(rv)) {
2965 mDestListener = fromListener;
2972 return mDestListener->OnStartRequest(aRequest);
2975 NS_IMETHODIMP
2976 ProxyListener::OnStopRequest(nsIRequest* aRequest, nsresult status) {
2977 if (!mDestListener) {
2978 return NS_ERROR_FAILURE;
2981 return mDestListener->OnStopRequest(aRequest, status);
2984 /** nsIStreamListener methods **/
2986 NS_IMETHODIMP
2987 ProxyListener::OnDataAvailable(nsIRequest* aRequest, nsIInputStream* inStr,
2988 uint64_t sourceOffset, uint32_t count) {
2989 if (!mDestListener) {
2990 return NS_ERROR_FAILURE;
2993 return mDestListener->OnDataAvailable(aRequest, inStr, sourceOffset, count);
2996 /** nsThreadRetargetableStreamListener methods **/
2997 NS_IMETHODIMP
2998 ProxyListener::CheckListenerChain() {
2999 NS_ASSERTION(NS_IsMainThread(), "Should be on the main thread!");
3000 nsresult rv = NS_OK;
3001 nsCOMPtr<nsIThreadRetargetableStreamListener> retargetableListener =
3002 do_QueryInterface(mDestListener, &rv);
3003 if (retargetableListener) {
3004 rv = retargetableListener->CheckListenerChain();
3006 MOZ_LOG(
3007 gImgLog, LogLevel::Debug,
3008 ("ProxyListener::CheckListenerChain %s [this=%p listener=%p rv=%" PRIx32
3009 "]",
3010 (NS_SUCCEEDED(rv) ? "success" : "failure"), this,
3011 (nsIStreamListener*)mDestListener, static_cast<uint32_t>(rv)));
3012 return rv;
3016 * http validate class. check a channel for a 304
3019 NS_IMPL_ISUPPORTS(imgCacheValidator, nsIStreamListener, nsIRequestObserver,
3020 nsIThreadRetargetableStreamListener, nsIChannelEventSink,
3021 nsIInterfaceRequestor, nsIAsyncVerifyRedirectCallback)
3023 imgCacheValidator::imgCacheValidator(nsProgressNotificationProxy* progress,
3024 imgLoader* loader, imgRequest* request,
3025 Document* aDocument,
3026 uint64_t aInnerWindowId,
3027 bool forcePrincipalCheckForCacheEntry)
3028 : mProgressProxy(progress),
3029 mRequest(request),
3030 mDocument(aDocument),
3031 mInnerWindowId(aInnerWindowId),
3032 mImgLoader(loader),
3033 mHadInsecureRedirect(false) {
3034 NewRequestAndEntry(forcePrincipalCheckForCacheEntry, loader,
3035 mRequest->CacheKey(), getter_AddRefs(mNewRequest),
3036 getter_AddRefs(mNewEntry));
3039 imgCacheValidator::~imgCacheValidator() {
3040 if (mRequest) {
3041 // If something went wrong, and we never unblocked the requests waiting on
3042 // validation, now is our last chance. We will cancel the new request and
3043 // switch the waiting proxies to it.
3044 UpdateProxies(/* aCancelRequest */ true, /* aSyncNotify */ false);
3048 void imgCacheValidator::AddProxy(imgRequestProxy* aProxy) {
3049 // aProxy needs to be in the loadgroup since we're validating from
3050 // the network.
3051 aProxy->AddToLoadGroup();
3053 mProxies.AppendElement(aProxy);
3056 void imgCacheValidator::RemoveProxy(imgRequestProxy* aProxy) {
3057 mProxies.RemoveElement(aProxy);
3060 void imgCacheValidator::UpdateProxies(bool aCancelRequest, bool aSyncNotify) {
3061 MOZ_ASSERT(mRequest);
3063 // Clear the validator before updating the proxies. The notifications may
3064 // clone an existing request, and its state could be inconsistent.
3065 mRequest->SetValidator(nullptr);
3066 mRequest = nullptr;
3068 // If an error occurred, we will want to cancel the new request, and make the
3069 // validating proxies point to it. Any proxies still bound to the original
3070 // request which are not validating should remain untouched.
3071 if (aCancelRequest) {
3072 MOZ_ASSERT(mNewRequest);
3073 mNewRequest->CancelAndAbort(NS_BINDING_ABORTED);
3076 // We have finished validating the request, so we can safely take ownership
3077 // of the proxy list. imgRequestProxy::SyncNotifyListener can mutate the list
3078 // if imgRequestProxy::CancelAndForgetObserver is called by its owner. Note
3079 // that any potential notifications should still be suppressed in
3080 // imgRequestProxy::ChangeOwner because we haven't cleared the validating
3081 // flag yet, and thus they will remain deferred.
3082 AutoTArray<RefPtr<imgRequestProxy>, 4> proxies(std::move(mProxies));
3084 for (auto& proxy : proxies) {
3085 // First update the state of all proxies before notifying any of them
3086 // to ensure a consistent state (e.g. in case the notification causes
3087 // other proxies to be touched indirectly.)
3088 MOZ_ASSERT(proxy->IsValidating());
3089 MOZ_ASSERT(proxy->NotificationsDeferred(),
3090 "Proxies waiting on cache validation should be "
3091 "deferring notifications!");
3092 if (mNewRequest) {
3093 proxy->ChangeOwner(mNewRequest);
3095 proxy->ClearValidating();
3098 mNewRequest = nullptr;
3099 mNewEntry = nullptr;
3101 for (auto& proxy : proxies) {
3102 if (aSyncNotify) {
3103 // Notify synchronously, because the caller knows we are already in an
3104 // asynchronously-called function (e.g. OnStartRequest).
3105 proxy->SyncNotifyListener();
3106 } else {
3107 // Notify asynchronously, because the caller does not know our current
3108 // call state (e.g. ~imgCacheValidator).
3109 proxy->NotifyListener();
3114 /** nsIRequestObserver methods **/
3116 NS_IMETHODIMP
3117 imgCacheValidator::OnStartRequest(nsIRequest* aRequest) {
3118 // We may be holding on to a document, so ensure that it's released.
3119 RefPtr<Document> document = mDocument.forget();
3121 // If for some reason we don't still have an existing request (probably
3122 // because OnStartRequest got delivered more than once), just bail.
3123 if (!mRequest) {
3124 MOZ_ASSERT_UNREACHABLE("OnStartRequest delivered more than once?");
3125 aRequest->CancelWithReason(NS_BINDING_ABORTED,
3126 "OnStartRequest delivered more than once?"_ns);
3127 return NS_ERROR_FAILURE;
3130 // If this request is coming from cache and has the same URI as our
3131 // imgRequest, the request all our proxies are pointing at is valid, and all
3132 // we have to do is tell them to notify their listeners.
3133 nsCOMPtr<nsICacheInfoChannel> cacheChan(do_QueryInterface(aRequest));
3134 nsCOMPtr<nsIChannel> channel(do_QueryInterface(aRequest));
3135 if (cacheChan && channel) {
3136 bool isFromCache = false;
3137 cacheChan->IsFromCache(&isFromCache);
3139 nsCOMPtr<nsIURI> channelURI;
3140 channel->GetURI(getter_AddRefs(channelURI));
3142 nsCOMPtr<nsIURI> finalURI;
3143 mRequest->GetFinalURI(getter_AddRefs(finalURI));
3145 bool sameURI = false;
3146 if (channelURI && finalURI) {
3147 channelURI->Equals(finalURI, &sameURI);
3150 if (isFromCache && sameURI) {
3151 // We don't need to load this any more.
3152 aRequest->CancelWithReason(NS_BINDING_ABORTED,
3153 "imgCacheValidator::OnStartRequest"_ns);
3154 mNewRequest = nullptr;
3156 // Clear the validator before updating the proxies. The notifications may
3157 // clone an existing request, and its state could be inconsistent.
3158 mRequest->SetLoadId(document);
3159 mRequest->SetInnerWindowID(mInnerWindowId);
3160 UpdateProxies(/* aCancelRequest */ false, /* aSyncNotify */ true);
3161 return NS_OK;
3165 // We can't load out of cache. We have to create a whole new request for the
3166 // data that's coming in off the channel.
3167 nsCOMPtr<nsIURI> uri;
3168 mRequest->GetURI(getter_AddRefs(uri));
3170 LOG_MSG_WITH_PARAM(gImgLog,
3171 "imgCacheValidator::OnStartRequest creating new request",
3172 "uri", uri);
3174 CORSMode corsmode = mRequest->GetCORSMode();
3175 nsCOMPtr<nsIReferrerInfo> referrerInfo = mRequest->GetReferrerInfo();
3176 nsCOMPtr<nsIPrincipal> triggeringPrincipal =
3177 mRequest->GetTriggeringPrincipal();
3179 // Doom the old request's cache entry
3180 mRequest->RemoveFromCache();
3182 // We use originalURI here to fulfil the imgIRequest contract on GetURI.
3183 nsCOMPtr<nsIURI> originalURI;
3184 channel->GetOriginalURI(getter_AddRefs(originalURI));
3185 nsresult rv = mNewRequest->Init(originalURI, uri, mHadInsecureRedirect,
3186 aRequest, channel, mNewEntry, document,
3187 triggeringPrincipal, corsmode, referrerInfo);
3188 if (NS_FAILED(rv)) {
3189 UpdateProxies(/* aCancelRequest */ true, /* aSyncNotify */ true);
3190 return rv;
3193 mDestListener = new ProxyListener(mNewRequest);
3195 // Try to add the new request into the cache. Note that the entry must be in
3196 // the cache before the proxies' ownership changes, because adding a proxy
3197 // changes the caching behaviour for imgRequests.
3198 mImgLoader->PutIntoCache(mNewRequest->CacheKey(), mNewEntry);
3199 UpdateProxies(/* aCancelRequest */ false, /* aSyncNotify */ true);
3200 return mDestListener->OnStartRequest(aRequest);
3203 NS_IMETHODIMP
3204 imgCacheValidator::OnStopRequest(nsIRequest* aRequest, nsresult status) {
3205 // Be sure we've released the document that we may have been holding on to.
3206 mDocument = nullptr;
3208 if (!mDestListener) {
3209 return NS_OK;
3212 return mDestListener->OnStopRequest(aRequest, status);
3215 /** nsIStreamListener methods **/
3217 NS_IMETHODIMP
3218 imgCacheValidator::OnDataAvailable(nsIRequest* aRequest, nsIInputStream* inStr,
3219 uint64_t sourceOffset, uint32_t count) {
3220 if (!mDestListener) {
3221 // XXX see bug 113959
3222 uint32_t _retval;
3223 inStr->ReadSegments(NS_DiscardSegment, nullptr, count, &_retval);
3224 return NS_OK;
3227 return mDestListener->OnDataAvailable(aRequest, inStr, sourceOffset, count);
3230 /** nsIThreadRetargetableStreamListener methods **/
3232 NS_IMETHODIMP
3233 imgCacheValidator::CheckListenerChain() {
3234 NS_ASSERTION(NS_IsMainThread(), "Should be on the main thread!");
3235 nsresult rv = NS_OK;
3236 nsCOMPtr<nsIThreadRetargetableStreamListener> retargetableListener =
3237 do_QueryInterface(mDestListener, &rv);
3238 if (retargetableListener) {
3239 rv = retargetableListener->CheckListenerChain();
3241 MOZ_LOG(
3242 gImgLog, LogLevel::Debug,
3243 ("[this=%p] imgCacheValidator::CheckListenerChain -- rv %" PRId32 "=%s",
3244 this, static_cast<uint32_t>(rv),
3245 NS_SUCCEEDED(rv) ? "succeeded" : "failed"));
3246 return rv;
3249 /** nsIInterfaceRequestor methods **/
3251 NS_IMETHODIMP
3252 imgCacheValidator::GetInterface(const nsIID& aIID, void** aResult) {
3253 if (aIID.Equals(NS_GET_IID(nsIChannelEventSink))) {
3254 return QueryInterface(aIID, aResult);
3257 return mProgressProxy->GetInterface(aIID, aResult);
3260 // These functions are materially the same as the same functions in imgRequest.
3261 // We duplicate them because we're verifying whether cache loads are necessary,
3262 // not unconditionally loading.
3264 /** nsIChannelEventSink methods **/
3265 NS_IMETHODIMP
3266 imgCacheValidator::AsyncOnChannelRedirect(
3267 nsIChannel* oldChannel, nsIChannel* newChannel, uint32_t flags,
3268 nsIAsyncVerifyRedirectCallback* callback) {
3269 // Note all cache information we get from the old channel.
3270 mNewRequest->SetCacheValidation(mNewEntry, oldChannel);
3272 // If the previous URI is a non-HTTPS URI, record that fact for later use by
3273 // security code, which needs to know whether there is an insecure load at any
3274 // point in the redirect chain.
3275 nsCOMPtr<nsIURI> oldURI;
3276 bool schemeLocal = false;
3277 if (NS_FAILED(oldChannel->GetURI(getter_AddRefs(oldURI))) ||
3278 NS_FAILED(NS_URIChainHasFlags(
3279 oldURI, nsIProtocolHandler::URI_IS_LOCAL_RESOURCE, &schemeLocal)) ||
3280 (!oldURI->SchemeIs("https") && !oldURI->SchemeIs("chrome") &&
3281 !schemeLocal)) {
3282 mHadInsecureRedirect = true;
3285 // Prepare for callback
3286 mRedirectCallback = callback;
3287 mRedirectChannel = newChannel;
3289 return mProgressProxy->AsyncOnChannelRedirect(oldChannel, newChannel, flags,
3290 this);
3293 NS_IMETHODIMP
3294 imgCacheValidator::OnRedirectVerifyCallback(nsresult aResult) {
3295 // If we've already been told to abort, just do so.
3296 if (NS_FAILED(aResult)) {
3297 mRedirectCallback->OnRedirectVerifyCallback(aResult);
3298 mRedirectCallback = nullptr;
3299 mRedirectChannel = nullptr;
3300 return NS_OK;
3303 // make sure we have a protocol that returns data rather than opens
3304 // an external application, e.g. mailto:
3305 nsCOMPtr<nsIURI> uri;
3306 mRedirectChannel->GetURI(getter_AddRefs(uri));
3308 nsresult result = NS_OK;
3310 if (nsContentUtils::IsExternalProtocol(uri)) {
3311 result = NS_ERROR_ABORT;
3314 mRedirectCallback->OnRedirectVerifyCallback(result);
3315 mRedirectCallback = nullptr;
3316 mRedirectChannel = nullptr;
3317 return NS_OK;