blob: 1aa19e5e5e31cfcfa2d8c6eb5ee119550c6ef307 [file] [log] [blame]
JP Abgrall4a5f5ca2011-06-15 18:37:39 -07001/*
2 * Copyright (C) 2011 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16#ifndef _BANDWIDTH_CONTROLLER_H
17#define _BANDWIDTH_CONTROLLER_H
18
19#include <list>
20#include <string>
JP Abgrallfa6f46d2011-06-17 23:17:28 -070021#include <utility> // for pair
JP Abgralldb7da582011-09-18 12:57:32 -070022
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070023class BandwidthController {
24public:
JP Abgralldb7da582011-09-18 12:57:32 -070025 class TetherStats {
26 public:
27 TetherStats(void)
28 : rxBytes(-1), rxPackets(-1),
29 txBytes(-1), txPackets(-1) {};
30 TetherStats(std::string ifnIn, std::string ifnOut,
31 int64_t rxB, int64_t rxP,
32 int64_t txB, int64_t txP)
33 : ifaceIn(ifnIn), ifaceOut(ifnOut),
34 rxBytes(rxB), rxPackets(rxP),
35 txBytes(txB), txPackets(txP) {};
36 std::string ifaceIn;
37 std::string ifaceOut;
38 int64_t rxBytes, rxPackets;
39 int64_t txBytes, txPackets;
40 /*
41 * Allocates a new string representing this:
42 * ifaceIn ifaceOut rx_bytes rx_packets tx_bytes tx_packets
43 * The caller is responsible for free()'ing the returned ptr.
44 */
45 char *getStatsLine(void);
46 };
47
JP Abgrallfa6f46d2011-06-17 23:17:28 -070048 BandwidthController();
49 int enableBandwidthControl(void);
50 int disableBandwidthControl(void);
51
JP Abgrall0dad7c22011-06-24 11:58:14 -070052 int setInterfaceSharedQuota(const char *iface, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -070053 int getInterfaceSharedQuota(int64_t *bytes);
JP Abgrallfa6f46d2011-06-17 23:17:28 -070054 int removeInterfaceSharedQuota(const char *iface);
55
JP Abgrall0dad7c22011-06-24 11:58:14 -070056 int setInterfaceQuota(const char *iface, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -070057 int getInterfaceQuota(const char *iface, int64_t *bytes);
JP Abgrall0dad7c22011-06-24 11:58:14 -070058 int removeInterfaceQuota(const char *iface);
59
JP Abgrallfa6f46d2011-06-17 23:17:28 -070060 int addNaughtyApps(int numUids, char *appUids[]);
61 int removeNaughtyApps(int numUids, char *appUids[]);
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070062
JP Abgrall8a932722011-07-13 19:17:35 -070063 int setGlobalAlert(int64_t bytes);
64 int removeGlobalAlert(void);
JP Abgrallc6c67342011-10-07 16:28:54 -070065 int setGlobalAlertInForwardChain(void);
66 int removeGlobalAlertInForwardChain(void);
JP Abgrall8a932722011-07-13 19:17:35 -070067
68 int setSharedAlert(int64_t bytes);
69 int removeSharedAlert(void);
70
71 int setInterfaceAlert(const char *iface, int64_t bytes);
72 int removeInterfaceAlert(const char *iface);
JP Abgrall0dad7c22011-06-24 11:58:14 -070073
JP Abgralldb7da582011-09-18 12:57:32 -070074 /*
75 * stats should have ifaceIn and ifaceOut initialized.
76 * Byte counts should be left to the default (-1).
77 */
JP Abgralla2a64f02011-11-11 20:36:16 -080078 int getTetherStats(TetherStats &stats, std::string &extraProcessingInfo);
JP Abgralldb7da582011-09-18 12:57:32 -070079
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070080protected:
JP Abgrall8a932722011-07-13 19:17:35 -070081 class QuotaInfo {
82 public:
83 QuotaInfo(std::string ifn, int64_t q, int64_t a)
84 : ifaceName(ifn), quota(q), alert(a) {};
85 std::string ifaceName;
86 int64_t quota;
87 int64_t alert;
88 };
JP Abgralldb7da582011-09-18 12:57:32 -070089
JP Abgrall26e0d492011-06-24 19:21:51 -070090 enum IptIpVer { IptIpV4, IptIpV6 };
91 enum IptOp { IptOpInsert, IptOpReplace, IptOpDelete };
92 enum IptRejectOp { IptRejectAdd, IptRejectNoAdd };
93 enum NaughtyAppOp { NaughtyAppOpAdd, NaughtyAppOpRemove };
94 enum QuotaType { QuotaUnique, QuotaShared };
95 enum RunCmdErrHandling { RunCmdFailureBad, RunCmdFailureOk };
JP Abgrall0dad7c22011-06-24 11:58:14 -070096
JP Abgrall26e0d492011-06-24 19:21:51 -070097 int maninpulateNaughtyApps(int numUids, char *appStrUids[], NaughtyAppOp appOp);
JP Abgrall4a5f5ca2011-06-15 18:37:39 -070098
JP Abgrall26e0d492011-06-24 19:21:51 -070099 int prepCostlyIface(const char *ifn, QuotaType quotaType);
100 int cleanupCostlyIface(const char *ifn, QuotaType quotaType);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700101
102 std::string makeIptablesNaughtyCmd(IptOp op, int uid);
JP Abgrall26e0d492011-06-24 19:21:51 -0700103 std::string makeIptablesQuotaCmd(IptOp op, const char *costName, int64_t quota);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700104
JP Abgrall8a932722011-07-13 19:17:35 -0700105 int runIptablesAlertCmd(IptOp op, const char *alertName, int64_t bytes);
JP Abgrallc6c67342011-10-07 16:28:54 -0700106 int runIptablesAlertFwdCmd(IptOp op, const char *alertName, int64_t bytes);
JP Abgrall8a932722011-07-13 19:17:35 -0700107
JP Abgrall0dad7c22011-06-24 11:58:14 -0700108 /* Runs for both ipv4 and ipv6 iptables */
JP Abgrall26e0d492011-06-24 19:21:51 -0700109 int runCommands(int numCommands, const char *commands[], RunCmdErrHandling cmdErrHandling);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700110 /* Runs for both ipv4 and ipv6 iptables, appends -j REJECT --reject-with ... */
JP Abgrall26e0d492011-06-24 19:21:51 -0700111 static int runIpxtablesCmd(const char *cmd, IptRejectOp rejectHandling);
112 static int runIptablesCmd(const char *cmd, IptRejectOp rejectHandling, IptIpVer iptIpVer);
113
114 // Provides strncpy() + check overflow.
115 static int StrncpyAndCheck(char *buffer, const char *src, size_t buffSize);
JP Abgrall0dad7c22011-06-24 11:58:14 -0700116
JP Abgrall8a932722011-07-13 19:17:35 -0700117 int updateQuota(const char *alertName, int64_t bytes);
118
JP Abgrall8a932722011-07-13 19:17:35 -0700119 int setCostlyAlert(const char *costName, int64_t bytes, int64_t *alertBytes);
120 int removeCostlyAlert(const char *costName, int64_t *alertBytes);
121
JP Abgrall11b4e9b2011-08-11 15:34:49 -0700122 /*
JP Abgralldb7da582011-09-18 12:57:32 -0700123 * stats should have ifaceIn and ifaceOut initialized.
124 * fp should be a file to the FORWARD rules of iptables.
JP Abgralla2a64f02011-11-11 20:36:16 -0800125 * extraProcessingInfo: contains raw parsed data, and error info.
JP Abgralldb7da582011-09-18 12:57:32 -0700126 */
JP Abgralla2a64f02011-11-11 20:36:16 -0800127 static int parseForwardChainStats(TetherStats &stats, FILE *fp,
128 std::string &extraProcessingInfo);
JP Abgralldb7da582011-09-18 12:57:32 -0700129
130 /*------------------*/
131
132 std::list<std::string> sharedQuotaIfaces;
133 int64_t sharedQuotaBytes;
134 int64_t sharedAlertBytes;
135 int64_t globalAlertBytes;
JP Abgrallc6c67342011-10-07 16:28:54 -0700136 /*
137 * This tracks the number of tethers setup.
138 * The FORWARD chain is updated in the following cases:
139 * - The 1st time a globalAlert is setup and there are tethers setup.
140 * - Anytime a globalAlert is removed and there are tethers setup.
141 * - The 1st tether is setup and there is a globalAlert active.
142 * - The last tether is removed and there is a globalAlert active.
143 */
144 int globalAlertTetherCount;
145
JP Abgralldb7da582011-09-18 12:57:32 -0700146 std::list<QuotaInfo> quotaIfaces;
147 std::list<int /*appUid*/> naughtyAppUids;
148
149private:
150 static const char *IPT_CLEANUP_COMMANDS[];
151 static const char *IPT_SETUP_COMMANDS[];
152 static const char *IPT_BASIC_ACCOUNTING_COMMANDS[];
153
154 /* Alphabetical */
155 static const char ALERT_IPT_TEMPLATE[];
156 static const int ALERT_RULE_POS_IN_COSTLY_CHAIN;
JP Abgrallc6c67342011-10-07 16:28:54 -0700157 static const char ALERT_GLOBAL_NAME[];
JP Abgralldb7da582011-09-18 12:57:32 -0700158 static const char IP6TABLES_PATH[];
159 static const char IPTABLES_PATH[];
160 static const int MAX_CMD_ARGS;
161 static const int MAX_CMD_LEN;
162 static const int MAX_IFACENAME_LEN;
163 static const int MAX_IPT_OUTPUT_LINE_LEN;
164
165 /*
JP Abgrall11b4e9b2011-08-11 15:34:49 -0700166 * When false, it will directly use system() instead of logwrap()
167 */
168 static bool useLogwrapCall;
JP Abgrall4a5f5ca2011-06-15 18:37:39 -0700169};
170
171#endif