') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); avoid allocation of SafeFreeSslCredentials and SafeDeleteSslContext on Linux by wfurt · Pull Request #69527 · dotnet/runtime · GitHub
Skip to content

avoid allocation of SafeFreeSslCredentials and SafeDeleteSslContext on Linux - #69527

Merged
wfurt merged 22 commits into
dotnet:mainfrom
wfurt:sslContext
Aug 15, 2022
Merged

avoid allocation of SafeFreeSslCredentials and SafeDeleteSslContext on Linux#69527
wfurt merged 22 commits into
dotnet:mainfrom
wfurt:sslContext

Conversation

@wfurt

Copy link
Copy Markdown
Member

SafeFreeSslCredentials really have no meaning on Linux (unlike Schannel) and we simple drag copy of some properties from sslAuthenticationOptions. The only difference is that we carte copy of certificates handle and key early so it would probably work even if disposed. I moved existing code to AllocateSslContext and we will get the handles when we carte the TLS session.

SafeDeleteSslContext is basically wrapper that only stores reference to another SafeHandle. To avoid that, I made SafeSslHandle subclass from SafeDeleteSslContext so I can use single object. There may be better way to do it. For one, I was thinking about actually merging but the benefits seems same and it would be much bigger change.

@wfurtwfurt added area-System.Net.Security os-linux Linux OS (any supported distro) labels May 18, 2022
@wfurt
wfurt requested review from a team and stephentoubMay 18, 2022 23:50
@wfurtwfurt self-assigned this May 18, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

SafeFreeSslCredentials really have no meaning on Linux (unlike Schannel) and we simple drag copy of some properties from sslAuthenticationOptions. The only difference is that we carte copy of certificates handle and key early so it would probably work even if disposed. I moved existing code to AllocateSslContext and we will get the handles when we carte the TLS session.

SafeDeleteSslContext is basically wrapper that only stores reference to another SafeHandle. To avoid that, I made SafeSslHandle subclass from SafeDeleteSslContext so I can use single object. There may be better way to do it. For one, I was thinking about actually merging but the benefits seems same and it would be much bigger change.

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Security, os-linux

Milestone:-

@rzikmrzikm mentioned this pull request May 24, 2022

using (SafeX509Handle certHandle = Interop.Crypto.X509UpRef(cert.Handle))
{
SetSslCertificate(contextPtr, certHandle, certKeyHandle);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What happens to certKeyHandle after this SetSslCertificate call?

Comment threadsrc/libraries/Common/src/System/Net/Security/Unix/SafeDeleteContext.cs Outdated
@wfurt

wfurt commented Jun 8, 2022

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-extra-platforms

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

@wfurtwfurt mentioned this pull request Jul 1, 2022
@wfurt

wfurt commented Jul 1, 2022

Copy link
Copy Markdown
MemberAuthor

This is ready for another pass @stephentoub.

Comment threadsrc/libraries/Common/src/System/Net/Security/Unix/SafeDeleteNegoContext.cs Outdated

@stephentoubstephentoub left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly looks good, but some SafeHandle-related issues to be addressed before it can be merged.

@wfurt

Copy link
Copy Markdown
MemberAuthor

I made updates to address comments @stephentoub. Can you please take another look?

Comment threadsrc/libraries/Common/src/System/Net/Security/Unix/SafeDeleteNegoContext.cs Outdated
Co-authored-by: Stephen Toub <stoub@microsoft.com>
@wfurt
wfurt merged commit 3af3e80 into dotnet:mainAug 15, 2022
@wfurt
wfurt deleted the sslContext branch August 15, 2022 23:09
@karelzkarelz added this to the 7.0.0 milestone Aug 22, 2022
@ghostghost locked as resolved and limited conversation to collaborators Sep 21, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.Net.Securityos-linuxLinux OS (any supported distro)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wfurt@stephentoub@bartonjs@karelz