mirror of
https://gitflic.ru/project/openide/openide.git
synced 2026-09-27 10:03:11 +07:00
IDEA-136333 (harmful SNI property dropped; check added)
This commit is contained in:
@@ -64,9 +64,8 @@ binding.setVariable("isEap", {
|
||||
|
||||
binding.setVariable("mem32", "-server -Xms128m -Xmx512m -XX:MaxPermSize=250m -XX:ReservedCodeCacheSize=150m")
|
||||
binding.setVariable("mem64", "-Xms128m -Xmx750m -XX:MaxPermSize=350m -XX:ReservedCodeCacheSize=225m")
|
||||
binding.setVariable("common_vmoptions", "-ea -Dsun.io.useCanonCaches=false -Djava.net.preferIPv4Stack=true " +
|
||||
"-Djsse.enableSNIExtension=false " +
|
||||
"-XX:+UseConcMarkSweepGC -XX:SoftRefLRUPolicyMSPerMB=50")
|
||||
binding.setVariable("common_vmoptions", "-XX:+UseConcMarkSweepGC -XX:SoftRefLRUPolicyMSPerMB=50 -ea " +
|
||||
"-Dsun.io.useCanonCaches=false -Djava.net.preferIPv4Stack=true")
|
||||
|
||||
binding.setVariable("vmOptions", { "$common_vmoptions ${isEap() ? '-XX:+HeapDumpOnOutOfMemoryError' : ''}".trim() })
|
||||
binding.setVariable("vmOptions32", { "$mem32 ${vmOptions()}".trim() })
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -20,6 +20,7 @@ import com.intellij.openapi.diagnostic.Logger;
|
||||
import com.intellij.openapi.progress.ProcessCanceledException;
|
||||
import com.intellij.openapi.progress.ProgressIndicator;
|
||||
import com.intellij.openapi.util.SystemInfo;
|
||||
import com.intellij.util.SystemProperties;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
import org.jetbrains.annotations.Nullable;
|
||||
|
||||
@@ -31,8 +32,7 @@ import java.net.*;
|
||||
public class NetUtils {
|
||||
private static final Logger LOG = Logger.getInstance(NetUtils.class);
|
||||
|
||||
private NetUtils() {
|
||||
}
|
||||
private NetUtils() { }
|
||||
|
||||
public static boolean canConnectToSocket(String host, int port) {
|
||||
return canConnectToSocket(host, port, false);
|
||||
@@ -224,4 +224,8 @@ public class NetUtils {
|
||||
|
||||
return total;
|
||||
}
|
||||
|
||||
public static boolean isSniEnabled() {
|
||||
return SystemInfo.isJavaVersionAtLeast("1.7") && SystemProperties.getBooleanProperty("jsse.enableSNIExtension", true);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -32,12 +32,12 @@ import com.intellij.openapi.progress.ProgressManager;
|
||||
import com.intellij.openapi.progress.Task;
|
||||
import com.intellij.openapi.project.Project;
|
||||
import com.intellij.openapi.updateSettings.impl.UpdateSettings;
|
||||
import com.intellij.openapi.util.SystemInfo;
|
||||
import com.intellij.openapi.util.io.FileUtil;
|
||||
import com.intellij.openapi.util.text.StringUtil;
|
||||
import com.intellij.util.Consumer;
|
||||
import com.intellij.util.SystemProperties;
|
||||
import com.intellij.util.containers.ContainerUtil;
|
||||
import com.intellij.util.net.NetUtils;
|
||||
import com.intellij.util.net.ssl.CertificateUtil;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
|
||||
@@ -218,7 +218,7 @@ public class ITNProxy {
|
||||
HttpsURLConnection connection = (HttpsURLConnection)url.openConnection();
|
||||
|
||||
connection.setSSLSocketFactory(ourSslContext.getSocketFactory());
|
||||
if (!(SystemInfo.isJavaVersionAtLeast("1.7") && SystemProperties.getBooleanProperty("jsse.enableSNIExtension", true))) {
|
||||
if (!NetUtils.isSniEnabled()) {
|
||||
connection.setHostnameVerifier(new EaHostnameVerifier(url.getHost(), "ftp.intellij.net"));
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -83,7 +83,7 @@ public class RepositoryHelper {
|
||||
public static List<IdeaPluginDescriptor> loadPlugins(@Nullable String repositoryUrl,
|
||||
@Nullable BuildNumber buildnumber,
|
||||
@Nullable final ProgressIndicator indicator) throws IOException {
|
||||
boolean forceHttps = repositoryUrl == null && IdeaApplication.isLoaded() && UpdateSettings.getInstance().SECURE_CONNECTION;
|
||||
boolean forceHttps = repositoryUrl == null && IdeaApplication.isLoaded() && UpdateSettings.getInstance().canUseSecureConnection();
|
||||
return loadPlugins(repositoryUrl, buildnumber, forceHttps, indicator);
|
||||
}
|
||||
|
||||
|
||||
+3
-3
@@ -214,7 +214,7 @@ public final class UpdateChecker {
|
||||
String updateUrl = uriBuilder.toString();
|
||||
LogUtil.debug(LOG, "load update xml (UPDATE_URL='%s')", updateUrl);
|
||||
|
||||
info = HttpRequests.request(updateUrl).forceHttps(settings.SECURE_CONNECTION).connect(new HttpRequests.RequestProcessor<UpdatesInfo>() {
|
||||
info = HttpRequests.request(updateUrl).forceHttps(settings.canUseSecureConnection()).connect(new HttpRequests.RequestProcessor<UpdatesInfo>() {
|
||||
@Override
|
||||
public UpdatesInfo process(@NotNull HttpRequests.Request request) throws IOException {
|
||||
try {
|
||||
@@ -285,7 +285,7 @@ public final class UpdateChecker {
|
||||
outer:
|
||||
for (String host : hosts) {
|
||||
try {
|
||||
boolean forceHttps = host == null && updateSettings.SECURE_CONNECTION;
|
||||
boolean forceHttps = host == null && updateSettings.canUseSecureConnection();
|
||||
List<IdeaPluginDescriptor> list = RepositoryHelper.loadPlugins(host, buildNumber, forceHttps, indicator);
|
||||
for (IdeaPluginDescriptor descriptor : list) {
|
||||
PluginId id = descriptor.getPluginId();
|
||||
@@ -405,7 +405,7 @@ public final class UpdateChecker {
|
||||
Runnable runnable = new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
new UpdateInfoDialog(updatedChannel, enableLink, updateSettings.SECURE_CONNECTION, updatedPlugins, incompatiblePlugins).show();
|
||||
new UpdateInfoDialog(updatedChannel, enableLink, updateSettings.canUseSecureConnection(), updatedPlugins, incompatiblePlugins).show();
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
+17
-1
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -16,14 +16,18 @@
|
||||
package com.intellij.openapi.updateSettings.impl;
|
||||
|
||||
import com.intellij.ide.AppLifecycleListener;
|
||||
import com.intellij.ide.IdeBundle;
|
||||
import com.intellij.notification.NotificationType;
|
||||
import com.intellij.openapi.application.Application;
|
||||
import com.intellij.openapi.application.ApplicationInfo;
|
||||
import com.intellij.openapi.application.ModalityState;
|
||||
import com.intellij.openapi.components.ApplicationComponent;
|
||||
import com.intellij.openapi.updateSettings.impl.pluginsAdvertisement.PluginsAdvertiser;
|
||||
import com.intellij.openapi.util.Disposer;
|
||||
import com.intellij.openapi.util.Ref;
|
||||
import com.intellij.openapi.util.text.StringUtil;
|
||||
import com.intellij.util.Alarm;
|
||||
import com.intellij.util.net.NetUtils;
|
||||
import com.intellij.util.text.DateFormatUtil;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
|
||||
@@ -49,6 +53,18 @@ public class UpdateCheckerComponent implements ApplicationComponent {
|
||||
|
||||
public UpdateCheckerComponent(@NotNull Application app, @NotNull UpdateSettings settings) {
|
||||
mySettings = settings;
|
||||
|
||||
if (mySettings.SECURE_CONNECTION && !NetUtils.isSniEnabled()) {
|
||||
app.invokeLater(new Runnable() {
|
||||
@Override
|
||||
public void run() {
|
||||
String title = IdeBundle.message("update.notifications.title");
|
||||
String message = IdeBundle.message("update.sni.disabled.notification");
|
||||
UpdateChecker.NOTIFICATIONS.createNotification(title, message, NotificationType.WARNING, null).notify(null);
|
||||
}
|
||||
}, ModalityState.NON_MODAL);
|
||||
}
|
||||
|
||||
app.getMessageBus().connect(app).subscribe(AppLifecycleListener.TOPIC, new AppLifecycleListener.Adapter() {
|
||||
@Override
|
||||
public void appFrameCreated(String[] commandLineArgs, @NotNull Ref<Boolean> willOpenProject) {
|
||||
|
||||
+6
-1
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -24,6 +24,7 @@ import com.intellij.openapi.util.InvalidDataException;
|
||||
import com.intellij.openapi.util.JDOMExternalizableStringList;
|
||||
import com.intellij.openapi.util.WriteExternalException;
|
||||
import com.intellij.util.containers.ContainerUtil;
|
||||
import com.intellij.util.net.NetUtils;
|
||||
import org.jdom.Element;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
|
||||
@@ -140,4 +141,8 @@ public class UpdateSettings implements PersistentStateComponent<Element>, UserUp
|
||||
LAST_TIME_CHECKED = System.currentTimeMillis();
|
||||
LAST_BUILD_CHECKED = ApplicationInfo.getInstance().getBuild().asString();
|
||||
}
|
||||
|
||||
public boolean canUseSecureConnection() {
|
||||
return SECURE_CONNECTION && NetUtils.isSniEnabled();
|
||||
}
|
||||
}
|
||||
|
||||
+10
-4
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2000-2014 JetBrains s.r.o.
|
||||
* Copyright 2000-2015 JetBrains s.r.o.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -26,6 +26,7 @@ import com.intellij.openapi.options.ConfigurationException;
|
||||
import com.intellij.openapi.options.SearchableConfigurable;
|
||||
import com.intellij.openapi.project.Project;
|
||||
import com.intellij.ui.CollectionComboBoxModel;
|
||||
import com.intellij.util.net.NetUtils;
|
||||
import com.intellij.util.text.DateFormatUtil;
|
||||
import org.jetbrains.annotations.NotNull;
|
||||
import org.jetbrains.annotations.Nullable;
|
||||
@@ -131,11 +132,11 @@ public class UpdateSettingsConfigurable extends BaseConfigurable implements Sear
|
||||
private JCheckBox myUseSecureConnection;
|
||||
|
||||
public UpdatesSettingsPanel() {
|
||||
final ApplicationInfo appInfo = ApplicationInfo.getInstance();
|
||||
final String majorVersion = appInfo.getMajorVersion();
|
||||
ApplicationInfo appInfo = ApplicationInfo.getInstance();
|
||||
String majorVersion = appInfo.getMajorVersion();
|
||||
String versionNumber = "";
|
||||
if (majorVersion != null && majorVersion.trim().length() > 0) {
|
||||
final String minorVersion = appInfo.getMinorVersion();
|
||||
String minorVersion = appInfo.getMinorVersion();
|
||||
if (minorVersion != null && minorVersion.trim().length() > 0) {
|
||||
versionNumber = majorVersion + "." + minorVersion;
|
||||
}
|
||||
@@ -163,6 +164,11 @@ public class UpdateSettingsConfigurable extends BaseConfigurable implements Sear
|
||||
UpdateSettings settings = UpdateSettings.getInstance();
|
||||
//noinspection unchecked
|
||||
myUpdateChannels.setModel(new CollectionComboBoxModel(ChannelStatus.all(), ChannelStatus.fromCode(settings.UPDATE_CHANNEL_TYPE)));
|
||||
|
||||
if (!NetUtils.isSniEnabled()) {
|
||||
myUseSecureConnection.setEnabled(false);
|
||||
myUseSecureConnection.setToolTipText(IdeBundle.message("update.sni.disabled.notification"));
|
||||
}
|
||||
}
|
||||
|
||||
private void updateLastCheckedLabel() {
|
||||
|
||||
@@ -944,6 +944,7 @@ update.downloading.patch.error=Failed to download patch file:\n{0}
|
||||
update.plugins.update.action=&Update
|
||||
update.restart.plugins.update.action=&Update and Restart
|
||||
update.shutdown.plugins.update.action=&Update and Shutdown
|
||||
update.sni.disabled.notification=Secure update is impossible with SNI disabled
|
||||
|
||||
hierarchy.method.next.occurence.name=Go to next method
|
||||
hierarchy.method.prev.occurence.name=Go to previous method
|
||||
|
||||
Reference in New Issue
Block a user