diff options
author | JustOff <Off.Just.Off@gmail.com> | 2018-06-06 15:41:35 +0300 |
---|---|---|
committer | wolfbeast <mcwerewolf@gmail.com> | 2018-06-06 15:24:07 +0200 |
commit | 6603359347ef42b4cee2890a27b4e1321e4decf5 (patch) | |
tree | cfbbf49df3acc7d02a9d6f6f25a77b3f5dda0a08 /security/certverifier | |
parent | 6f84242a3526c6889950b43d29f1c47d05b918b2 (diff) | |
download | UXP-6603359347ef42b4cee2890a27b4e1321e4decf5.tar UXP-6603359347ef42b4cee2890a27b4e1321e4decf5.tar.gz UXP-6603359347ef42b4cee2890a27b4e1321e4decf5.tar.lz UXP-6603359347ef42b4cee2890a27b4e1321e4decf5.tar.xz UXP-6603359347ef42b4cee2890a27b4e1321e4decf5.zip |
Request NSS to use DBM as the storage file format
Diffstat (limited to 'security/certverifier')
-rw-r--r-- | security/certverifier/NSSCertDBTrustDomain.cpp | 10 | ||||
-rw-r--r-- | security/certverifier/NSSCertDBTrustDomain.h | 3 | ||||
-rw-r--r-- | security/certverifier/moz.build | 5 |
3 files changed, 15 insertions, 3 deletions
diff --git a/security/certverifier/NSSCertDBTrustDomain.cpp b/security/certverifier/NSSCertDBTrustDomain.cpp index b4e12fe9c..39f7d3e9e 100644 --- a/security/certverifier/NSSCertDBTrustDomain.cpp +++ b/security/certverifier/NSSCertDBTrustDomain.cpp @@ -22,6 +22,7 @@ #include "mozilla/Unused.h" #include "nsNSSCertificate.h" #include "nsServiceManagerUtils.h" +#include "nsThreadUtils.h" #include "nss.h" #include "pk11pub.h" #include "pkix/Result.h" @@ -1087,8 +1088,10 @@ NSSCertDBTrustDomain::NoteAuxiliaryExtension(AuxiliaryExtension extension, } SECStatus -InitializeNSS(const char* dir, bool readOnly, bool loadPKCS11Modules) +InitializeNSS(const nsACString& dir, bool readOnly, bool loadPKCS11Modules) { + MOZ_ASSERT(NS_IsMainThread()); + // The NSS_INIT_NOROOTINIT flag turns off the loading of the root certs // module by NSS_Initialize because we will load it in InstallLoadableRoots // later. It also allows us to work around a bug in the system NSS in @@ -1101,7 +1104,10 @@ InitializeNSS(const char* dir, bool readOnly, bool loadPKCS11Modules) if (!loadPKCS11Modules) { flags |= NSS_INIT_NOMODDB; } - return ::NSS_Initialize(dir, "", "", SECMOD_DB, flags); + nsAutoCString dbTypeAndDirectory; + dbTypeAndDirectory.Append("dbm:"); + dbTypeAndDirectory.Append(dir); + return ::NSS_Initialize(dbTypeAndDirectory.get(), "", "", SECMOD_DB, flags); } void diff --git a/security/certverifier/NSSCertDBTrustDomain.h b/security/certverifier/NSSCertDBTrustDomain.h index 15a5a4a2c..64827536c 100644 --- a/security/certverifier/NSSCertDBTrustDomain.h +++ b/security/certverifier/NSSCertDBTrustDomain.h @@ -36,7 +36,8 @@ enum class NetscapeStepUpPolicy : uint32_t { NeverMatch = 3, }; -SECStatus InitializeNSS(const char* dir, bool readOnly, bool loadPKCS11Modules); +SECStatus InitializeNSS(const nsACString& dir, bool readOnly, + bool loadPKCS11Modules); void DisableMD5(); diff --git a/security/certverifier/moz.build b/security/certverifier/moz.build index 70f049340..97cff1f7d 100644 --- a/security/certverifier/moz.build +++ b/security/certverifier/moz.build @@ -68,6 +68,11 @@ if CONFIG['_MSC_VER']: # class copy constructor is inaccessible or deleted '-wd4626', # assignment operator could not be generated because a base # class assignment operator is inaccessible or deleted + '-wd4628', # digraphs not supported with -Ze (nsThreadUtils.h includes + # what would be the digraph "<:" in the expression + # "mozilla::EnableIf<::detail::...". Since we don't want it + # interpreted as a digraph anyway, we can disable the + # warning.) '-wd4640', # construction of local static object is not thread-safe '-wd4710', # 'function': function not inlined '-wd4711', # function 'function' selected for inline expansion |