blob: ed3bab97ca1975193a83dcabf60f144c22134344 [file] [log] [blame]
Benedict Wonge40eab62018-11-14 17:50:13 -08001/*
2 * Copyright (C) 2018 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Benedict Wonge40eab62018-11-14 17:50:13 -080019import android.annotation.NonNull;
Benedict Wong512ab0d2019-04-18 19:18:43 -070020import android.annotation.Nullable;
Benedict Wonge40eab62018-11-14 17:50:13 -080021import android.content.Context;
Benedict Wong6c242132018-11-14 17:53:19 -080022import android.net.ConnectivityManager;
Benedict Wonge40eab62018-11-14 17:50:13 -080023import android.net.INetd;
24import android.net.ITestNetworkManager;
Benedict Wong6c242132018-11-14 17:53:19 -080025import android.net.IpPrefix;
Benedict Wonge40eab62018-11-14 17:50:13 -080026import android.net.LinkAddress;
Benedict Wong6c242132018-11-14 17:53:19 -080027import android.net.LinkProperties;
28import android.net.NetworkAgent;
29import android.net.NetworkCapabilities;
30import android.net.NetworkInfo;
31import android.net.NetworkInfo.DetailedState;
32import android.net.RouteInfo;
33import android.net.StringNetworkSpecifier;
Benedict Wonge40eab62018-11-14 17:50:13 -080034import android.net.TestNetworkInterface;
35import android.net.util.NetdService;
Benedict Wong6c242132018-11-14 17:53:19 -080036import android.os.Binder;
Benedict Wonge40eab62018-11-14 17:50:13 -080037import android.os.Handler;
38import android.os.HandlerThread;
39import android.os.IBinder;
40import android.os.INetworkManagementService;
Benedict Wong6c242132018-11-14 17:53:19 -080041import android.os.Looper;
42import android.os.ParcelFileDescriptor;
43import android.os.RemoteException;
44import android.util.SparseArray;
Benedict Wonge40eab62018-11-14 17:50:13 -080045
Benedict Wong6c242132018-11-14 17:53:19 -080046import com.android.internal.annotations.GuardedBy;
Benedict Wonge40eab62018-11-14 17:50:13 -080047import com.android.internal.annotations.VisibleForTesting;
48
Benedict Wong6c242132018-11-14 17:53:19 -080049import java.io.UncheckedIOException;
50import java.net.Inet4Address;
51import java.net.Inet6Address;
52import java.net.InterfaceAddress;
53import java.net.NetworkInterface;
54import java.net.SocketException;
Benedict Wong512ab0d2019-04-18 19:18:43 -070055import java.util.ArrayList;
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +000056import java.util.Objects;
Benedict Wong6c242132018-11-14 17:53:19 -080057import java.util.concurrent.atomic.AtomicInteger;
58
Benedict Wonge40eab62018-11-14 17:50:13 -080059/** @hide */
60class TestNetworkService extends ITestNetworkManager.Stub {
61 @NonNull private static final String TAG = TestNetworkService.class.getSimpleName();
62 @NonNull private static final String TEST_NETWORK_TYPE = "TEST_NETWORK";
Benedict Wong6c242132018-11-14 17:53:19 -080063 @NonNull private static final String TEST_TUN_PREFIX = "testtun";
Lorenzo Colittib15fcce2019-04-01 23:41:12 +090064 @NonNull private static final String TEST_TAP_PREFIX = "testtap";
Benedict Wong6c242132018-11-14 17:53:19 -080065 @NonNull private static final AtomicInteger sTestTunIndex = new AtomicInteger();
Benedict Wonge40eab62018-11-14 17:50:13 -080066
67 @NonNull private final Context mContext;
68 @NonNull private final INetworkManagementService mNMS;
69 @NonNull private final INetd mNetd;
70
71 @NonNull private final HandlerThread mHandlerThread;
72 @NonNull private final Handler mHandler;
73
Benedict Wong6c242132018-11-14 17:53:19 -080074 // Native method stubs
Lorenzo Colittib15fcce2019-04-01 23:41:12 +090075 private static native int jniCreateTunTap(boolean isTun, @NonNull String iface);
Benedict Wong6c242132018-11-14 17:53:19 -080076
Benedict Wonge40eab62018-11-14 17:50:13 -080077 @VisibleForTesting
78 protected TestNetworkService(
79 @NonNull Context context, @NonNull INetworkManagementService netManager) {
Benedict Wonge40eab62018-11-14 17:50:13 -080080 mHandlerThread = new HandlerThread("TestNetworkServiceThread");
81 mHandlerThread.start();
82 mHandler = new Handler(mHandlerThread.getLooper());
83
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +000084 mContext = Objects.requireNonNull(context, "missing Context");
85 mNMS = Objects.requireNonNull(netManager, "missing INetworkManagementService");
86 mNetd = Objects.requireNonNull(NetdService.getInstance(), "could not get netd instance");
Benedict Wonge40eab62018-11-14 17:50:13 -080087 }
88
89 /**
Lorenzo Colittib15fcce2019-04-01 23:41:12 +090090 * Create a TUN or TAP interface with the given interface name and link addresses
Benedict Wonge40eab62018-11-14 17:50:13 -080091 *
Lorenzo Colittib15fcce2019-04-01 23:41:12 +090092 * <p>This method will return the FileDescriptor to the interface. Close it to tear down the
93 * interface.
Benedict Wonge40eab62018-11-14 17:50:13 -080094 */
Lorenzo Colittib15fcce2019-04-01 23:41:12 +090095 private TestNetworkInterface createInterface(boolean isTun, LinkAddress[] linkAddrs) {
Benedict Wong6c242132018-11-14 17:53:19 -080096 enforceTestNetworkPermissions(mContext);
97
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +000098 Objects.requireNonNull(linkAddrs, "missing linkAddrs");
Benedict Wong6c242132018-11-14 17:53:19 -080099
Lorenzo Colittib15fcce2019-04-01 23:41:12 +0900100 String ifacePrefix = isTun ? TEST_TUN_PREFIX : TEST_TAP_PREFIX;
101 String iface = ifacePrefix + sTestTunIndex.getAndIncrement();
Benedict Wong6c242132018-11-14 17:53:19 -0800102 return Binder.withCleanCallingIdentity(
103 () -> {
104 try {
105 ParcelFileDescriptor tunIntf =
Lorenzo Colittib15fcce2019-04-01 23:41:12 +0900106 ParcelFileDescriptor.adoptFd(jniCreateTunTap(isTun, iface));
Benedict Wong6c242132018-11-14 17:53:19 -0800107 for (LinkAddress addr : linkAddrs) {
108 mNetd.interfaceAddAddress(
109 iface,
110 addr.getAddress().getHostAddress(),
111 addr.getPrefixLength());
112 }
113
114 return new TestNetworkInterface(tunIntf, iface);
115 } catch (RemoteException e) {
116 throw e.rethrowFromSystemServer();
117 }
118 });
119 }
120
Lorenzo Colittib15fcce2019-04-01 23:41:12 +0900121 /**
122 * Create a TUN interface with the given interface name and link addresses
123 *
124 * <p>This method will return the FileDescriptor to the TUN interface. Close it to tear down the
125 * TUN interface.
126 */
127 @Override
128 public TestNetworkInterface createTunInterface(@NonNull LinkAddress[] linkAddrs) {
129 return createInterface(true, linkAddrs);
130 }
131
132 /**
133 * Create a TAP interface with the given interface name
134 *
135 * <p>This method will return the FileDescriptor to the TAP interface. Close it to tear down the
136 * TAP interface.
137 */
138 @Override
139 public TestNetworkInterface createTapInterface() {
140 return createInterface(false, new LinkAddress[0]);
141 }
142
Benedict Wong6c242132018-11-14 17:53:19 -0800143 // Tracker for TestNetworkAgents
144 @GuardedBy("mTestNetworkTracker")
145 @NonNull
146 private final SparseArray<TestNetworkAgent> mTestNetworkTracker = new SparseArray<>();
147
148 public class TestNetworkAgent extends NetworkAgent implements IBinder.DeathRecipient {
149 private static final int NETWORK_SCORE = 1; // Use a low, non-zero score.
150
151 private final int mUid;
152 @NonNull private final NetworkInfo mNi;
153 @NonNull private final NetworkCapabilities mNc;
154 @NonNull private final LinkProperties mLp;
155
156 @GuardedBy("mBinderLock")
157 @NonNull
158 private IBinder mBinder;
159
160 @NonNull private final Object mBinderLock = new Object();
161
162 private TestNetworkAgent(
163 @NonNull Looper looper,
164 @NonNull Context context,
165 @NonNull NetworkInfo ni,
166 @NonNull NetworkCapabilities nc,
167 @NonNull LinkProperties lp,
168 int uid,
169 @NonNull IBinder binder)
170 throws RemoteException {
171 super(looper, context, TEST_NETWORK_TYPE, ni, nc, lp, NETWORK_SCORE);
172
173 mUid = uid;
174 mNi = ni;
175 mNc = nc;
176 mLp = lp;
177
178 synchronized (mBinderLock) {
179 mBinder = binder; // Binder null-checks in create()
180
181 try {
182 mBinder.linkToDeath(this, 0);
183 } catch (RemoteException e) {
184 binderDied();
185 throw e; // Abort, signal failure up the stack.
186 }
187 }
188 }
189
190 /**
191 * If the Binder object dies, this function is called to free the resources of this
192 * TestNetworkAgent
193 */
194 @Override
195 public void binderDied() {
196 teardown();
197 }
198
199 @Override
200 protected void unwanted() {
201 teardown();
202 }
203
204 private void teardown() {
205 mNi.setDetailedState(DetailedState.DISCONNECTED, null, null);
206 mNi.setIsAvailable(false);
207 sendNetworkInfo(mNi);
208
209 // Synchronize on mBinderLock to ensure that unlinkToDeath is never called more than
210 // once (otherwise it could throw an exception)
211 synchronized (mBinderLock) {
212 // If mBinder is null, this Test Network has already been cleaned up.
213 if (mBinder == null) return;
214 mBinder.unlinkToDeath(this, 0);
215 mBinder = null;
216 }
217
218 // Has to be in TestNetworkAgent to ensure all teardown codepaths properly clean up
219 // resources, even for binder death or unwanted calls.
220 synchronized (mTestNetworkTracker) {
Chalard Jeana0e2aa122019-12-13 19:47:12 +0900221 mTestNetworkTracker.remove(network.netId);
Benedict Wong6c242132018-11-14 17:53:19 -0800222 }
223 }
224 }
225
226 private TestNetworkAgent registerTestNetworkAgent(
227 @NonNull Looper looper,
228 @NonNull Context context,
229 @NonNull String iface,
Benedict Wong512ab0d2019-04-18 19:18:43 -0700230 @Nullable LinkProperties lp,
231 boolean isMetered,
Benedict Wong6c242132018-11-14 17:53:19 -0800232 int callingUid,
233 @NonNull IBinder binder)
234 throws RemoteException, SocketException {
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +0000235 Objects.requireNonNull(looper, "missing Looper");
236 Objects.requireNonNull(context, "missing Context");
Benedict Wong6c242132018-11-14 17:53:19 -0800237 // iface and binder validity checked by caller
238
239 // Build network info with special testing type
240 NetworkInfo ni = new NetworkInfo(ConnectivityManager.TYPE_TEST, 0, TEST_NETWORK_TYPE, "");
241 ni.setDetailedState(DetailedState.CONNECTED, null, null);
242 ni.setIsAvailable(true);
243
244 // Build narrow set of NetworkCapabilities, useful only for testing
245 NetworkCapabilities nc = new NetworkCapabilities();
246 nc.clearAll(); // Remove default capabilities.
247 nc.addTransportType(NetworkCapabilities.TRANSPORT_TEST);
248 nc.addCapability(NetworkCapabilities.NET_CAPABILITY_NOT_SUSPENDED);
249 nc.addCapability(NetworkCapabilities.NET_CAPABILITY_NOT_RESTRICTED);
250 nc.setNetworkSpecifier(new StringNetworkSpecifier(iface));
Benedict Wong512ab0d2019-04-18 19:18:43 -0700251 if (!isMetered) {
252 nc.addCapability(NetworkCapabilities.NET_CAPABILITY_NOT_METERED);
253 }
Benedict Wong6c242132018-11-14 17:53:19 -0800254
255 // Build LinkProperties
Benedict Wong512ab0d2019-04-18 19:18:43 -0700256 if (lp == null) {
257 lp = new LinkProperties();
258 } else {
259 lp = new LinkProperties(lp);
260 // Use LinkAddress(es) from the interface itself to minimize how much the caller
261 // is trusted.
262 lp.setLinkAddresses(new ArrayList<>());
263 }
Benedict Wong6c242132018-11-14 17:53:19 -0800264 lp.setInterfaceName(iface);
265
266 // Find the currently assigned addresses, and add them to LinkProperties
267 boolean allowIPv4 = false, allowIPv6 = false;
268 NetworkInterface netIntf = NetworkInterface.getByName(iface);
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +0000269 Objects.requireNonNull(netIntf, "No such network interface found: " + netIntf);
Benedict Wong6c242132018-11-14 17:53:19 -0800270
271 for (InterfaceAddress intfAddr : netIntf.getInterfaceAddresses()) {
272 lp.addLinkAddress(
273 new LinkAddress(intfAddr.getAddress(), intfAddr.getNetworkPrefixLength()));
274
275 if (intfAddr.getAddress() instanceof Inet6Address) {
276 allowIPv6 |= !intfAddr.getAddress().isLinkLocalAddress();
277 } else if (intfAddr.getAddress() instanceof Inet4Address) {
278 allowIPv4 = true;
279 }
280 }
281
282 // Add global routes (but as non-default, non-internet providing network)
283 if (allowIPv4) {
284 lp.addRoute(new RouteInfo(new IpPrefix(Inet4Address.ANY, 0), null, iface));
285 }
286 if (allowIPv6) {
287 lp.addRoute(new RouteInfo(new IpPrefix(Inet6Address.ANY, 0), null, iface));
288 }
289
290 return new TestNetworkAgent(looper, context, ni, nc, lp, callingUid, binder);
Benedict Wonge40eab62018-11-14 17:50:13 -0800291 }
292
293 /**
294 * Sets up a Network with extremely limited privileges, guarded by the MANAGE_TEST_NETWORKS
295 * permission.
296 *
297 * <p>This method provides a Network that is useful only for testing.
298 */
299 @Override
Benedict Wong512ab0d2019-04-18 19:18:43 -0700300 public void setupTestNetwork(
301 @NonNull String iface,
302 @Nullable LinkProperties lp,
303 boolean isMetered,
304 @NonNull IBinder binder) {
Benedict Wong6c242132018-11-14 17:53:19 -0800305 enforceTestNetworkPermissions(mContext);
306
Daulet Zhanguzinea1a7ca2020-01-03 09:46:50 +0000307 Objects.requireNonNull(iface, "missing Iface");
308 Objects.requireNonNull(binder, "missing IBinder");
Benedict Wong6c242132018-11-14 17:53:19 -0800309
310 if (!(iface.startsWith(INetd.IPSEC_INTERFACE_PREFIX)
311 || iface.startsWith(TEST_TUN_PREFIX))) {
312 throw new IllegalArgumentException(
313 "Cannot create network for non ipsec, non-testtun interface");
314 }
315
316 // Setup needs to be done with NETWORK_STACK privileges.
317 int callingUid = Binder.getCallingUid();
318 Binder.withCleanCallingIdentity(
319 () -> {
320 try {
321 mNMS.setInterfaceUp(iface);
322
323 // Synchronize all accesses to mTestNetworkTracker to prevent the case
324 // where:
325 // 1. TestNetworkAgent successfully binds to death of binder
326 // 2. Before it is added to the mTestNetworkTracker, binder dies,
327 // binderDied() is called (on a different thread)
328 // 3. This thread is pre-empted, put() is called after remove()
329 synchronized (mTestNetworkTracker) {
330 TestNetworkAgent agent =
331 registerTestNetworkAgent(
332 mHandler.getLooper(),
333 mContext,
334 iface,
Benedict Wong512ab0d2019-04-18 19:18:43 -0700335 lp,
336 isMetered,
Benedict Wong6c242132018-11-14 17:53:19 -0800337 callingUid,
338 binder);
339
Chalard Jeana0e2aa122019-12-13 19:47:12 +0900340 mTestNetworkTracker.put(agent.network.netId, agent);
Benedict Wong6c242132018-11-14 17:53:19 -0800341 }
342 } catch (SocketException e) {
343 throw new UncheckedIOException(e);
344 } catch (RemoteException e) {
345 throw e.rethrowFromSystemServer();
346 }
347 });
348 }
Benedict Wonge40eab62018-11-14 17:50:13 -0800349
350 /** Teardown a test network */
351 @Override
Benedict Wong6c242132018-11-14 17:53:19 -0800352 public void teardownTestNetwork(int netId) {
353 enforceTestNetworkPermissions(mContext);
354
Benedict Wong7df36ed2019-03-12 21:54:16 -0700355 final TestNetworkAgent agent;
Benedict Wong6c242132018-11-14 17:53:19 -0800356 synchronized (mTestNetworkTracker) {
357 agent = mTestNetworkTracker.get(netId);
358 }
359
360 if (agent == null) {
361 return; // Already torn down
362 } else if (agent.mUid != Binder.getCallingUid()) {
363 throw new SecurityException("Attempted to modify other user's test networks");
364 }
365
366 // Safe to be called multiple times.
367 agent.teardown();
368 }
369
Benedict Wong3ec38dc2019-04-09 16:29:43 -0700370 private static final String PERMISSION_NAME =
371 android.Manifest.permission.MANAGE_TEST_NETWORKS;
Benedict Wong6c242132018-11-14 17:53:19 -0800372
373 public static void enforceTestNetworkPermissions(@NonNull Context context) {
Benedict Wong3ec38dc2019-04-09 16:29:43 -0700374 context.enforceCallingOrSelfPermission(PERMISSION_NAME, "TestNetworkService");
Benedict Wong6c242132018-11-14 17:53:19 -0800375 }
Benedict Wonge40eab62018-11-14 17:50:13 -0800376}