blob: a8dc99265cf3bd49458c98ff95febc1204487e0a [file] [log] [blame]
JP Abgrall4a5f5ca2011-06-15 18:37:39 -07001/*
2 * Copyright (C) 2011 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16#ifndef _BANDWIDTH_CONTROLLER_H
17#define _BANDWIDTH_CONTROLLER_H
18
19#include <list>
20#include <string>
JP Abgrallfa6f46d2011-06-17 23:17:28 -070021#include <utility> // for pair
JP Abgralldb7da582011-09-18 12:57:32 -070022
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070023class BandwidthController {
24public:
JP Abgralldb7da582011-09-18 12:57:32 -070025 class TetherStats {
26 public:
27 TetherStats(void)
28 : rxBytes(-1), rxPackets(-1),
29 txBytes(-1), txPackets(-1) {};
30 TetherStats(std::string ifnIn, std::string ifnOut,
31 int64_t rxB, int64_t rxP,
32 int64_t txB, int64_t txP)
33 : ifaceIn(ifnIn), ifaceOut(ifnOut),
34 rxBytes(rxB), rxPackets(rxP),
35 txBytes(txB), txPackets(txP) {};
36 std::string ifaceIn;
37 std::string ifaceOut;
38 int64_t rxBytes, rxPackets;
39 int64_t txBytes, txPackets;
40 /*
41 * Allocates a new string representing this:
42 * ifaceIn ifaceOut rx_bytes rx_packets tx_bytes tx_packets
43 * The caller is responsible for free()'ing the returned ptr.
44 */
45 char *getStatsLine(void);
46 };
47
JP Abgrallfa6f46d2011-06-17 23:17:28 -070048 BandwidthController();
JP Abgrall0031cea2012-04-17 16:38:23 -070049
50 int setupIptablesHooks(void);
51
52 int enableBandwidthControl(bool force);
JP Abgrallfa6f46d2011-06-17 23:17:28 -070053 int disableBandwidthControl(void);
54
JP Abgrall0dad7c22011-06-24 11:58:14 -070055 int setInterfaceSharedQuota(const char *iface, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -070056 int getInterfaceSharedQuota(int64_t *bytes);
JP Abgrallfa6f46d2011-06-17 23:17:28 -070057 int removeInterfaceSharedQuota(const char *iface);
58
JP Abgrall0dad7c22011-06-24 11:58:14 -070059 int setInterfaceQuota(const char *iface, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -070060 int getInterfaceQuota(const char *iface, int64_t *bytes);
JP Abgrall0dad7c22011-06-24 11:58:14 -070061 int removeInterfaceQuota(const char *iface);
62
JP Abgrallfa6f46d2011-06-17 23:17:28 -070063 int addNaughtyApps(int numUids, char *appUids[]);
64 int removeNaughtyApps(int numUids, char *appUids[]);
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070065
JP Abgrall8a932722011-07-13 19:17:35 -070066 int setGlobalAlert(int64_t bytes);
67 int removeGlobalAlert(void);
JP Abgrallc6c67342011-10-07 16:28:54 -070068 int setGlobalAlertInForwardChain(void);
69 int removeGlobalAlertInForwardChain(void);
JP Abgrall8a932722011-07-13 19:17:35 -070070
71 int setSharedAlert(int64_t bytes);
72 int removeSharedAlert(void);
73
74 int setInterfaceAlert(const char *iface, int64_t bytes);
75 int removeInterfaceAlert(const char *iface);
JP Abgrall0dad7c22011-06-24 11:58:14 -070076
JP Abgralldb7da582011-09-18 12:57:32 -070077 /*
78 * stats should have ifaceIn and ifaceOut initialized.
79 * Byte counts should be left to the default (-1).
80 */
JP Abgralla2a64f02011-11-11 20:36:16 -080081 int getTetherStats(TetherStats &stats, std::string &extraProcessingInfo);
JP Abgralldb7da582011-09-18 12:57:32 -070082
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070083protected:
JP Abgrall8a932722011-07-13 19:17:35 -070084 class QuotaInfo {
85 public:
86 QuotaInfo(std::string ifn, int64_t q, int64_t a)
87 : ifaceName(ifn), quota(q), alert(a) {};
88 std::string ifaceName;
89 int64_t quota;
90 int64_t alert;
91 };
JP Abgralldb7da582011-09-18 12:57:32 -070092
JP Abgrall26e0d492011-06-24 19:21:51 -070093 enum IptIpVer { IptIpV4, IptIpV6 };
94 enum IptOp { IptOpInsert, IptOpReplace, IptOpDelete };
95 enum IptRejectOp { IptRejectAdd, IptRejectNoAdd };
96 enum NaughtyAppOp { NaughtyAppOpAdd, NaughtyAppOpRemove };
97 enum QuotaType { QuotaUnique, QuotaShared };
98 enum RunCmdErrHandling { RunCmdFailureBad, RunCmdFailureOk };
JP Abgrall0dad7c22011-06-24 11:58:14 -070099
JP Abgrall26e0d492011-06-24 19:21:51 -0700100 int maninpulateNaughtyApps(int numUids, char *appStrUids[], NaughtyAppOp appOp);
JP Abgrall4a5f5ca2011-06-15 18:37:39 -0700101
JP Abgrall26e0d492011-06-24 19:21:51 -0700102 int prepCostlyIface(const char *ifn, QuotaType quotaType);
103 int cleanupCostlyIface(const char *ifn, QuotaType quotaType);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700104
105 std::string makeIptablesNaughtyCmd(IptOp op, int uid);
JP Abgrall26e0d492011-06-24 19:21:51 -0700106 std::string makeIptablesQuotaCmd(IptOp op, const char *costName, int64_t quota);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700107
JP Abgrall8a932722011-07-13 19:17:35 -0700108 int runIptablesAlertCmd(IptOp op, const char *alertName, int64_t bytes);
JP Abgrallc6c67342011-10-07 16:28:54 -0700109 int runIptablesAlertFwdCmd(IptOp op, const char *alertName, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -0700110
JP Abgrall0dad7c22011-06-24 11:58:14 -0700111 /* Runs for both ipv4 and ipv6 iptables */
JP Abgrall26e0d492011-06-24 19:21:51 -0700112 int runCommands(int numCommands, const char *commands[], RunCmdErrHandling cmdErrHandling);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700113 /* Runs for both ipv4 and ipv6 iptables, appends -j REJECT --reject-with ... */
JP Abgrall26e0d492011-06-24 19:21:51 -0700114 static int runIpxtablesCmd(const char *cmd, IptRejectOp rejectHandling);
115 static int runIptablesCmd(const char *cmd, IptRejectOp rejectHandling, IptIpVer iptIpVer);
116
117 // Provides strncpy() + check overflow.
118 static int StrncpyAndCheck(char *buffer, const char *src, size_t buffSize);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700119
JP Abgrall8a932722011-07-13 19:17:35 -0700120 int updateQuota(const char *alertName, int64_t bytes);
121
JP Abgrall8a932722011-07-13 19:17:35 -0700122 int setCostlyAlert(const char *costName, int64_t bytes, int64_t *alertBytes);
123 int removeCostlyAlert(const char *costName, int64_t *alertBytes);
124
JP Abgrall11b4e9b2011-08-11 15:34:49 -0700125 /*
JP Abgralldb7da582011-09-18 12:57:32 -0700126 * stats should have ifaceIn and ifaceOut initialized.
127 * fp should be a file to the FORWARD rules of iptables.
JP Abgralla2a64f02011-11-11 20:36:16 -0800128 * extraProcessingInfo: contains raw parsed data, and error info.
JP Abgralldb7da582011-09-18 12:57:32 -0700129 */
JP Abgralla2a64f02011-11-11 20:36:16 -0800130 static int parseForwardChainStats(TetherStats &stats, FILE *fp,
JP Abgrall0031cea2012-04-17 16:38:23 -0700131 std::string &extraProcessingInfo);
JP Abgralldb7da582011-09-18 12:57:32 -0700132
133 /*------------------*/
134
135 std::list<std::string> sharedQuotaIfaces;
136 int64_t sharedQuotaBytes;
137 int64_t sharedAlertBytes;
138 int64_t globalAlertBytes;
JP Abgrallc6c67342011-10-07 16:28:54 -0700139 /*
140 * This tracks the number of tethers setup.
141 * The FORWARD chain is updated in the following cases:
142 * - The 1st time a globalAlert is setup and there are tethers setup.
143 * - Anytime a globalAlert is removed and there are tethers setup.
144 * - The 1st tether is setup and there is a globalAlert active.
145 * - The last tether is removed and there is a globalAlert active.
146 */
147 int globalAlertTetherCount;
148
JP Abgralldb7da582011-09-18 12:57:32 -0700149 std::list<QuotaInfo> quotaIfaces;
150 std::list<int /*appUid*/> naughtyAppUids;
151
152private:
JP Abgrall0031cea2012-04-17 16:38:23 -0700153 static const char *IPT_FLUSH_COMMANDS[];
JP Abgralldb7da582011-09-18 12:57:32 -0700154 static const char *IPT_CLEANUP_COMMANDS[];
155 static const char *IPT_SETUP_COMMANDS[];
156 static const char *IPT_BASIC_ACCOUNTING_COMMANDS[];
157
158 /* Alphabetical */
JP Abgralldb7da582011-09-18 12:57:32 -0700159 static const int ALERT_RULE_POS_IN_COSTLY_CHAIN;
JP Abgrallc6c67342011-10-07 16:28:54 -0700160 static const char ALERT_GLOBAL_NAME[];
JP Abgralldb7da582011-09-18 12:57:32 -0700161 static const int MAX_CMD_ARGS;
162 static const int MAX_CMD_LEN;
163 static const int MAX_IFACENAME_LEN;
164 static const int MAX_IPT_OUTPUT_LINE_LEN;
165
166 /*
JP Abgrall11b4e9b2011-08-11 15:34:49 -0700167 * When false, it will directly use system() instead of logwrap()
168 */
169 static bool useLogwrapCall;
JP Abgrall4a5f5ca2011-06-15 18:37:39 -0700170};
171
172#endif