Remember user's decisions on SSL errors.

After CL:, Android
WebView just has a NULL SSLHostStateDelegate. So it does not remember
any user decisions on SSL errors. This is a regression of behavior from
L (m37).

JB behavior: Larger error codes are assumed to have higher severity. And
if the user has allowed an SSL error with a high severity, the user
won't be prompted for a lower severity SSL error.

K and L behavior: A specific SSL error will be allowed only if the error
bit field is a subset of previously allowed error codes.

trunk behavior for webview (without this patch): We don't remember
user's decision at all.

This CL:
Maintain the same behavior with K and L.


