Add Trust Anchor IDs support to TlsStreamAttempt/HttpStreamPool

This CL adds support for TLS Trust Anchor IDs
(https://tlswg.org/tls-trust-anchor-ids/draft-ietf-tls-trust-anchor-ids.html)
to the new Happy Eyeballs v3 code path for creating SSLClientSockets.
Initial Trust Anchor IDs (formed from the intersection of the Trust
Anchor IDs that Chrome trusts with those the server advertises in DNS)
are configured on the connection in HttpStreamPool::AttemptManager. If
TlsStreamAttempt fails with a certificate error and the server has
provided up-to-date Trust Anchor IDs in the handshake, then
TlsStreamAttempt retries itself, using the intersection with the new
Trust Anchor IDs provided by the server.

This CL is the HEv3 equivalent of
https://chromium-review.googlesource.com/c/chromium/src/+/6578737 and
https://chromium-review.googlesource.com/c/chromium/src/+/6627510.

Bug: 424256394
Change-Id: Iea3f29036035024b28808588d7819daa1beb2066
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6635900
Commit-Queue: Emily Stark <estark@chromium.org>
Reviewed-by: Kenichi Ishibashi <bashi@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1474668}
7 files changed
tree: 03004ed1c41a3abcf702ec72ef979104a5a908fc
  1. .github/
  2. android_webview/
  3. apps/
  4. ash/
  5. base/
  6. build/
  7. build_overrides/
  8. buildtools/
  9. cc/
  10. chrome/
  11. chromecast/
  12. chromeos/
  13. codelabs/
  14. components/
  15. content/
  16. crypto/
  17. dbus/
  18. device/
  19. docs/
  20. extensions/
  21. fuchsia_web/
  22. gin/
  23. google_apis/
  24. gpu/
  25. headless/
  26. infra/
  27. ios/
  28. ipc/
  29. media/
  30. mojo/
  31. native_client_sdk/
  32. net/
  33. pdf/
  34. ppapi/
  35. printing/
  36. remoting/
  37. rlz/
  38. sandbox/
  39. services/
  40. skia/
  41. sql/
  42. storage/
  43. styleguide/
  44. testing/
  45. third_party/
  46. tools/
  47. ui/
  48. url/
  49. webkit/
  50. .clang-format
  51. .clang-tidy
  52. .clangd
  53. .cursorignore
  54. .git-blame-ignore-revs
  55. .gitallowed
  56. .gitattributes
  57. .gitignore
  58. .gitmodules
  59. .gn
  60. .mailmap
  61. .rustfmt.toml
  62. .vpython3
  63. .yapfignore
  64. ATL_OWNERS
  65. AUTHORS
  66. BUILD.gn
  67. CODE_OF_CONDUCT.md
  68. codereview.settings
  69. CPPLINT.cfg
  70. CRYPTO_OWNERS
  71. DEPS
  72. DIR_METADATA
  73. LICENSE
  74. LICENSE.chromium_os
  75. OWNERS
  76. PRESUBMIT.py
  77. PRESUBMIT_test.py
  78. PRESUBMIT_test_mocks.py
  79. README.md
  80. SECURITY_OWNERS
  81. WATCHLISTS
README.md

Logo Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

The project's web site is https://www.chromium.org.

To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.

Documentation in the source is rooted in docs/README.md.

Learn how to Get Around the Chromium Source Code Directory Structure.

For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.

If you found a bug, please file it at https://crbug.com/new.