blob: 9fb85b25527dcb2f36b294bd1c8d038233616e73 [file] [log] [blame]
San Mehat873f2142010-01-14 10:25:07 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Jeff Sharkey4529bb62011-12-14 10:31:54 -080019import static android.Manifest.permission.CONNECTIVITY_INTERNAL;
Jeff Sharkey47eb1022011-08-25 17:48:52 -070020import static android.Manifest.permission.DUMP;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090021import static android.Manifest.permission.NETWORK_STACK;
Jeff Sharkeyaf75c332011-11-18 12:41:12 -080022import static android.Manifest.permission.SHUTDOWN;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070023import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_DOZABLE;
24import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_DOZABLE;
25import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080026import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070027import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_STANDBY;
28import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080029import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070030import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_STANDBY;
31import static android.net.NetworkPolicyManager.FIREWALL_RULE_DEFAULT;
32import static android.net.NetworkPolicyManager.FIREWALL_TYPE_BLACKLIST;
33import static android.net.NetworkPolicyManager.FIREWALL_TYPE_WHITELIST;
Jeff Sharkeyb5d55e32011-08-10 17:53:27 -070034import static android.net.NetworkStats.SET_DEFAULT;
Lorenzo Colittif1912ca2017-08-17 19:23:08 +090035import static android.net.NetworkStats.STATS_PER_UID;
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -080036import static android.net.NetworkStats.TAG_ALL;
Jeff Sharkey1b5a2a92011-06-18 18:34:16 -070037import static android.net.NetworkStats.TAG_NONE;
38import static android.net.NetworkStats.UID_ALL;
Jeff Sharkeyae2c1812011-10-04 13:11:40 -070039import static android.net.TrafficStats.UID_TETHERING;
Lorenzo Colitti79751842013-02-28 16:16:03 +090040import static com.android.server.NetworkManagementService.NetdResponseCode.ClatdStatusResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080041import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceGetCfgResult;
42import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080043import static com.android.server.NetworkManagementService.NetdResponseCode.IpFwdStatusResult;
44import static com.android.server.NetworkManagementService.NetdResponseCode.TetherDnsFwdTgtListResult;
45import static com.android.server.NetworkManagementService.NetdResponseCode.TetherInterfaceListResult;
46import static com.android.server.NetworkManagementService.NetdResponseCode.TetherStatusResult;
Jeff Sharkeye4984be2013-09-10 21:03:27 -070047import static com.android.server.NetworkManagementService.NetdResponseCode.TetheringStatsListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080048import static com.android.server.NetworkManagementService.NetdResponseCode.TtyListResult;
Jeff Sharkeya63ba592011-07-19 23:47:12 -070049import static com.android.server.NetworkManagementSocketTagger.PROP_QTAGUID_ENABLED;
Erik Klineb2cfdfb2017-01-18 20:54:14 +090050
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070051import android.annotation.NonNull;
Jeff Sharkey605eb792014-11-04 13:34:06 -080052import android.app.ActivityManagerNative;
Pierre Imai8e48e672016-04-21 13:30:43 +090053import android.content.ContentResolver;
San Mehat873f2142010-01-14 10:25:07 -080054import android.content.Context;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080055import android.net.ConnectivityManager;
Lorenzo Colitti58967ba2016-02-02 17:21:21 +090056import android.net.INetd;
San Mehat4d02d002010-01-22 16:07:46 -080057import android.net.INetworkManagementEventObserver;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090058import android.net.ITetheringStatsProvider;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070059import android.net.InterfaceConfiguration;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +090060import android.net.IpPrefix;
Robert Greenwalted126402011-01-28 15:34:55 -080061import android.net.LinkAddress;
Lorenzo Colittib57edc52014-08-22 17:10:50 -070062import android.net.Network;
Amith Yamasani15e472352015-04-24 19:06:07 -070063import android.net.NetworkPolicyManager;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070064import android.net.NetworkStats;
Robert Greenwalted126402011-01-28 15:34:55 -080065import android.net.NetworkUtils;
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070066import android.net.RouteInfo;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -040067import android.net.UidRange;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +090068import android.net.util.NetdService;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080069import android.net.wifi.WifiConfiguration;
70import android.net.wifi.WifiConfiguration.KeyMgmt;
Dianne Hackborn91268cf2013-06-13 19:06:50 -070071import android.os.BatteryStats;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070072import android.os.Binder;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070073import android.os.Handler;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080074import android.os.INetworkActivityListener;
San Mehat873f2142010-01-14 10:25:07 -080075import android.os.INetworkManagementService;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080076import android.os.PowerManager;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070077import android.os.Process;
Jeff Sharkey3df273e2011-12-15 15:47:12 -080078import android.os.RemoteCallbackList;
79import android.os.RemoteException;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070080import android.os.ServiceManager;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +090081import android.os.ServiceSpecificException;
Jeff Sharkey605eb792014-11-04 13:34:06 -080082import android.os.StrictMode;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070083import android.os.SystemClock;
Marco Nelissen62dbb222010-02-18 10:56:30 -080084import android.os.SystemProperties;
Pierre Imai8e48e672016-04-21 13:30:43 +090085import android.provider.Settings;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -070086import android.telephony.DataConnectionRealTimeInfo;
87import android.telephony.PhoneStateListener;
Wink Savillefb40dd42014-06-12 17:02:31 -070088import android.telephony.SubscriptionManager;
Wink Saville67e07892014-06-18 16:43:14 -070089import android.telephony.TelephonyManager;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080090import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080091import android.util.Slog;
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -070092import android.util.SparseBooleanArray;
Jeff Sharkey605eb792014-11-04 13:34:06 -080093import android.util.SparseIntArray;
San Mehat873f2142010-01-14 10:25:07 -080094
Jeff Sharkey605eb792014-11-04 13:34:06 -080095import com.android.internal.annotations.GuardedBy;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070096import com.android.internal.app.IBatteryStats;
Jeff Sharkey1059c3c2011-10-04 16:54:49 -070097import com.android.internal.net.NetworkStatsFactory;
Jeff Sharkey605eb792014-11-04 13:34:06 -080098import com.android.internal.util.HexDump;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -070099import com.android.internal.util.Preconditions;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800100import com.android.server.NativeDaemonConnector.Command;
Jeff Sharkey56cd6462013-06-07 15:09:15 -0700101import com.android.server.NativeDaemonConnector.SensitiveArg;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700102import com.google.android.collect.Maps;
Jeff Sharkey4414cea2011-06-24 17:05:24 -0700103
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700104import java.io.BufferedReader;
105import java.io.DataInputStream;
San Mehat873f2142010-01-14 10:25:07 -0800106import java.io.File;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700107import java.io.FileDescriptor;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700108import java.io.FileInputStream;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700109import java.io.IOException;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700110import java.io.InputStreamReader;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700111import java.io.PrintWriter;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700112import java.net.InetAddress;
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700113import java.net.InterfaceAddress;
114import java.net.NetworkInterface;
115import java.net.SocketException;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700116import java.util.ArrayList;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400117import java.util.Arrays;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700118import java.util.HashMap;
jiaguo1da35f72014-01-09 16:39:59 +0800119import java.util.List;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700120import java.util.Map;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700121import java.util.NoSuchElementException;
122import java.util.StringTokenizer;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700123import java.util.concurrent.CountDownLatch;
San Mehat873f2142010-01-14 10:25:07 -0800124
125/**
126 * @hide
127 */
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700128public class NetworkManagementService extends INetworkManagementService.Stub
129 implements Watchdog.Monitor {
Amith Yamasani15e472352015-04-24 19:06:07 -0700130 private static final String TAG = "NetworkManagement";
131 private static final boolean DBG = Log.isLoggable(TAG, Log.DEBUG);
Kenny Root305bcbf2010-09-03 07:56:38 -0700132 private static final String NETD_TAG = "NetdConnector";
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900133 private static final String NETD_SERVICE_NAME = "netd";
Kenny Root305bcbf2010-09-03 07:56:38 -0700134
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400135 private static final int MAX_UID_RANGES_PER_COMMAND = 10;
136
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700137 /**
138 * Name representing {@link #setGlobalAlert(long)} limit when delivered to
139 * {@link INetworkManagementEventObserver#limitReached(String, String)}.
140 */
141 public static final String LIMIT_GLOBAL_ALERT = "globalAlert";
142
Paul Jensen487ffe72015-07-24 15:57:11 -0400143 /**
144 * String to pass to netd to indicate that a network is only accessible
145 * to apps that have the CHANGE_NETWORK_STATE permission.
146 */
147 public static final String PERMISSION_NETWORK = "NETWORK";
148
149 /**
150 * String to pass to netd to indicate that a network is only
151 * accessible to system apps and those with the CONNECTIVITY_INTERNAL
152 * permission.
153 */
154 public static final String PERMISSION_SYSTEM = "SYSTEM";
155
Andrew Scull45f533c2017-05-19 15:37:20 +0100156 static class NetdResponseCode {
Sreeram Ramachandran03666c72014-07-19 23:21:46 -0700157 /* Keep in sync with system/netd/server/ResponseCode.h */
San Mehat873f2142010-01-14 10:25:07 -0800158 public static final int InterfaceListResult = 110;
159 public static final int TetherInterfaceListResult = 111;
160 public static final int TetherDnsFwdTgtListResult = 112;
San Mehat72759df2010-01-19 13:50:37 -0800161 public static final int TtyListResult = 113;
Jeff Sharkeye4984be2013-09-10 21:03:27 -0700162 public static final int TetheringStatsListResult = 114;
San Mehat873f2142010-01-14 10:25:07 -0800163
164 public static final int TetherStatusResult = 210;
165 public static final int IpFwdStatusResult = 211;
San Mehated4fc8a2010-01-22 12:28:36 -0800166 public static final int InterfaceGetCfgResult = 213;
Robert Greenwalte3253922010-02-18 09:23:25 -0800167 public static final int SoftapStatusResult = 214;
San Mehat91cac642010-03-31 14:31:36 -0700168 public static final int InterfaceRxCounterResult = 216;
169 public static final int InterfaceTxCounterResult = 217;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -0700170 public static final int QuotaCounterResult = 220;
171 public static final int TetheringStatsResult = 221;
Selim Gurun84c00c62012-02-27 15:42:38 -0800172 public static final int DnsProxyQueryResult = 222;
Lorenzo Colitti79751842013-02-28 16:16:03 +0900173 public static final int ClatdStatusResult = 223;
Robert Greenwalte3253922010-02-18 09:23:25 -0800174
175 public static final int InterfaceChange = 600;
JP Abgrall12b933d2011-07-14 18:09:22 -0700176 public static final int BandwidthControl = 601;
Haoyu Bai6b7358d2012-07-17 16:36:50 -0700177 public static final int InterfaceClassActivity = 613;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900178 public static final int InterfaceAddressChange = 614;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900179 public static final int InterfaceDnsServerInfo = 615;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900180 public static final int RouteChange = 616;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800181 public static final int StrictCleartext = 617;
San Mehat873f2142010-01-14 10:25:07 -0800182 }
183
Pierre Imai8e48e672016-04-21 13:30:43 +0900184 /* Defaults for resolver parameters. */
185 public static final int DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS = 1800;
186 public static final int DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT = 25;
187 public static final int DNS_RESOLVER_DEFAULT_MIN_SAMPLES = 8;
188 public static final int DNS_RESOLVER_DEFAULT_MAX_SAMPLES = 64;
189
Rebecca Silbersteine2ec94f2016-03-24 13:29:00 -0700190 /**
191 * String indicating a softap command.
192 */
193 static final String SOFT_AP_COMMAND = "softap";
194
195 /**
196 * String passed back to netd connector indicating softap command success.
197 */
198 static final String SOFT_AP_COMMAND_SUCCESS = "Ok";
199
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700200 static final int DAEMON_MSG_MOBILE_CONN_REAL_TIME_INFO = 1;
201
San Mehat873f2142010-01-14 10:25:07 -0800202 /**
203 * Binder context for this service
204 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700205 private final Context mContext;
San Mehat873f2142010-01-14 10:25:07 -0800206
207 /**
208 * connector object for communicating with netd
209 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700210 private final NativeDaemonConnector mConnector;
San Mehat873f2142010-01-14 10:25:07 -0800211
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700212 private final Handler mFgHandler;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700213 private final Handler mDaemonHandler;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700214
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900215 private INetd mNetdService;
216
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800217 private IBatteryStats mBatteryStats;
218
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700219 private final Thread mThread;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700220 private CountDownLatch mConnectedSignal = new CountDownLatch(1);
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700221
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800222 private final RemoteCallbackList<INetworkManagementEventObserver> mObservers =
Christopher Wiley5de073a2016-08-02 11:38:57 -0700223 new RemoteCallbackList<>();
San Mehat4d02d002010-01-22 16:07:46 -0800224
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700225 private final NetworkStatsFactory mStatsFactory = new NetworkStatsFactory();
226
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900227 @GuardedBy("mTetheringStatsProviders")
228 private final HashMap<ITetheringStatsProvider, String>
229 mTetheringStatsProviders = Maps.newHashMap();
230
Andrew Scull45f533c2017-05-19 15:37:20 +0100231 private final Object mQuotaLock = new Object();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800232
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700233 /** Set of interfaces with active quotas. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800234 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700235 private HashMap<String, Long> mActiveQuotas = Maps.newHashMap();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -0700236 /** Set of interfaces with active alerts. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800237 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700238 private HashMap<String, Long> mActiveAlerts = Maps.newHashMap();
Felipe Leme65be3022016-03-22 14:53:13 -0700239 /** Set of UIDs blacklisted on metered networks. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800240 @GuardedBy("mQuotaLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700241 private SparseBooleanArray mUidRejectOnMetered = new SparseBooleanArray();
242 /** Set of UIDs whitelisted on metered networks. */
243 @GuardedBy("mQuotaLock")
244 private SparseBooleanArray mUidAllowOnMetered = new SparseBooleanArray();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800245 /** Set of UIDs with cleartext penalties. */
246 @GuardedBy("mQuotaLock")
247 private SparseIntArray mUidCleartextPolicy = new SparseIntArray();
Amith Yamasani15e472352015-04-24 19:06:07 -0700248 /** Set of UIDs that are to be blocked/allowed by firewall controller. */
249 @GuardedBy("mQuotaLock")
250 private SparseIntArray mUidFirewallRules = new SparseIntArray();
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700251 /**
252 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
253 * to application idles.
254 */
255 @GuardedBy("mQuotaLock")
256 private SparseIntArray mUidFirewallStandbyRules = new SparseIntArray();
257 /**
258 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
259 * to device idles.
260 */
261 @GuardedBy("mQuotaLock")
262 private SparseIntArray mUidFirewallDozableRules = new SparseIntArray();
Felipe Leme011b98f2016-02-10 17:28:31 -0800263 /**
264 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
265 * to device on power-save mode.
266 */
267 @GuardedBy("mQuotaLock")
268 private SparseIntArray mUidFirewallPowerSaveRules = new SparseIntArray();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700269 /** Set of states for the child firewall chains. True if the chain is active. */
270 @GuardedBy("mQuotaLock")
271 final SparseBooleanArray mFirewallChainStates = new SparseBooleanArray();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700272
Felipe Leme65be3022016-03-22 14:53:13 -0700273 @GuardedBy("mQuotaLock")
274 private boolean mDataSaverMode;
275
Andrew Scull45f533c2017-05-19 15:37:20 +0100276 private final Object mIdleTimerLock = new Object();
Haoyu Bai04124232012-06-28 15:26:19 -0700277 /** Set of interfaces with active idle timers. */
278 private static class IdleTimerParams {
279 public final int timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800280 public final int type;
Haoyu Bai04124232012-06-28 15:26:19 -0700281 public int networkCount;
282
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800283 IdleTimerParams(int timeout, int type) {
Haoyu Bai04124232012-06-28 15:26:19 -0700284 this.timeout = timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800285 this.type = type;
Haoyu Bai04124232012-06-28 15:26:19 -0700286 this.networkCount = 1;
287 }
288 }
289 private HashMap<String, IdleTimerParams> mActiveIdleTimers = Maps.newHashMap();
290
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700291 private volatile boolean mBandwidthControlEnabled;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700292 private volatile boolean mFirewallEnabled;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800293 private volatile boolean mStrictEnabled;
Jeff Sharkey350083e2011-06-29 10:45:16 -0700294
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700295 private boolean mMobileActivityFromRadio = false;
296 private int mLastPowerStateFromRadio = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Adam Lesinskie08af192015-03-25 16:42:59 -0700297 private int mLastPowerStateFromWifi = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700298
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800299 private final RemoteCallbackList<INetworkActivityListener> mNetworkActivityListeners =
Christopher Wiley5de073a2016-08-02 11:38:57 -0700300 new RemoteCallbackList<>();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800301 private boolean mNetworkActive;
302
San Mehat873f2142010-01-14 10:25:07 -0800303 /**
304 * Constructs a new NetworkManagementService instance
305 *
306 * @param context Binder context for this service
307 */
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900308 private NetworkManagementService(Context context, String socket) {
San Mehat873f2142010-01-14 10:25:07 -0800309 mContext = context;
San Mehat4d02d002010-01-22 16:07:46 -0800310
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700311 // make sure this is on the same looper as our NativeDaemonConnector for sync purposes
312 mFgHandler = new Handler(FgThread.get().getLooper());
313
Dianne Hackborn4590e522014-03-24 13:36:46 -0700314 // Don't need this wake lock, since we now have a time stamp for when
315 // the network actually went inactive. (It might be nice to still do this,
316 // but I don't want to do it through the power manager because that pollutes the
317 // battery stats history with pointless noise.)
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700318 //PowerManager pm = (PowerManager)context.getSystemService(Context.POWER_SERVICE);
Dianne Hackborn4590e522014-03-24 13:36:46 -0700319 PowerManager.WakeLock wl = null; //pm.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK, NETD_TAG);
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800320
San Mehat873f2142010-01-14 10:25:07 -0800321 mConnector = new NativeDaemonConnector(
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700322 new NetdCallbackReceiver(), socket, 10, NETD_TAG, 160, wl,
323 FgThread.get().getLooper());
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700324 mThread = new Thread(mConnector, NETD_TAG);
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700325
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700326 mDaemonHandler = new Handler(FgThread.get().getLooper());
Wink Saville67e07892014-06-18 16:43:14 -0700327
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700328 // Add ourself to the Watchdog monitors.
329 Watchdog.getInstance().addMonitor(this);
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900330
331 synchronized (mTetheringStatsProviders) {
332 mTetheringStatsProviders.put(new NetdTetheringStatsProvider(), "netd");
333 }
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700334 }
335
Felipe Leme03e689d2016-03-02 16:17:38 -0800336 static NetworkManagementService create(Context context, String socket)
337 throws InterruptedException {
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900338 final NetworkManagementService service = new NetworkManagementService(context, socket);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700339 final CountDownLatch connectedSignal = service.mConnectedSignal;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700340 if (DBG) Slog.d(TAG, "Creating NetworkManagementService");
341 service.mThread.start();
342 if (DBG) Slog.d(TAG, "Awaiting socket connection");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700343 connectedSignal.await();
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700344 if (DBG) Slog.d(TAG, "Connected");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900345 if (DBG) Slog.d(TAG, "Connecting native netd service");
bohu07cc3bb2016-05-03 15:58:01 -0700346 service.connectNativeNetdService();
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900347 if (DBG) Slog.d(TAG, "Connected");
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700348 return service;
San Mehat873f2142010-01-14 10:25:07 -0800349 }
350
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900351 public static NetworkManagementService create(Context context) throws InterruptedException {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900352 return create(context, NETD_SERVICE_NAME);
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900353 }
354
Jeff Sharkey350083e2011-06-29 10:45:16 -0700355 public void systemReady() {
Felipe Leme03e689d2016-03-02 16:17:38 -0800356 if (DBG) {
357 final long start = System.currentTimeMillis();
358 prepareNativeDaemon();
359 final long delta = System.currentTimeMillis() - start;
360 Slog.d(TAG, "Prepared in " + delta + "ms");
361 return;
362 } else {
363 prepareNativeDaemon();
364 }
Jeff Sharkey350083e2011-06-29 10:45:16 -0700365 }
366
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800367 private IBatteryStats getBatteryStats() {
368 synchronized (this) {
369 if (mBatteryStats != null) {
370 return mBatteryStats;
371 }
372 mBatteryStats = IBatteryStats.Stub.asInterface(ServiceManager.getService(
373 BatteryStats.SERVICE_NAME));
374 return mBatteryStats;
375 }
376 }
377
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800378 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800379 public void registerObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800380 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800381 mObservers.register(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800382 }
383
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800384 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800385 public void unregisterObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800386 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800387 mObservers.unregister(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800388 }
389
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900390 @FunctionalInterface
391 private interface NetworkManagementEventCallback {
392 public void sendCallback(INetworkManagementEventObserver o) throws RemoteException;
393 }
394
395 private void invokeForAllObservers(NetworkManagementEventCallback eventCallback) {
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800396 final int length = mObservers.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700397 try {
398 for (int i = 0; i < length; i++) {
399 try {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900400 eventCallback.sendCallback(mObservers.getBroadcastItem(i));
Felipe Leme03e689d2016-03-02 16:17:38 -0800401 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700402 }
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700403 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700404 } finally {
405 mObservers.finishBroadcast();
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700406 }
407 }
408
409 /**
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900410 * Notify our observers of an interface status change
411 */
412 private void notifyInterfaceStatusChanged(String iface, boolean up) {
413 invokeForAllObservers(o -> o.interfaceStatusChanged(iface, up));
414 }
415
416 /**
Mike J. Chenf59c7d02011-06-23 15:33:15 -0700417 * Notify our observers of an interface link state change
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700418 * (typically, an Ethernet cable has been plugged-in or unplugged).
419 */
420 private void notifyInterfaceLinkStateChanged(String iface, boolean up) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900421 invokeForAllObservers(o -> o.interfaceLinkStateChanged(iface, up));
San Mehat4d02d002010-01-22 16:07:46 -0800422 }
423
424 /**
425 * Notify our observers of an interface addition.
426 */
427 private void notifyInterfaceAdded(String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900428 invokeForAllObservers(o -> o.interfaceAdded(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800429 }
430
431 /**
432 * Notify our observers of an interface removal.
433 */
434 private void notifyInterfaceRemoved(String iface) {
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700435 // netd already clears out quota and alerts for removed ifaces; update
436 // our sanity-checking state.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700437 mActiveAlerts.remove(iface);
438 mActiveQuotas.remove(iface);
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700439
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900440 invokeForAllObservers(o -> o.interfaceRemoved(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800441 }
442
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700443 /**
JP Abgrall12b933d2011-07-14 18:09:22 -0700444 * Notify our observers of a limit reached.
445 */
446 private void notifyLimitReached(String limitName, String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900447 invokeForAllObservers(o -> o.limitReached(limitName, iface));
JP Abgrall12b933d2011-07-14 18:09:22 -0700448 }
449
450 /**
Haoyu Baidb3c8672012-06-20 14:29:57 -0700451 * Notify our observers of a change in the data activity state of the interface
452 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700453 private void notifyInterfaceClassActivity(int type, int powerState, long tsNanos,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700454 int uid, boolean fromRadio) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700455 final boolean isMobile = ConnectivityManager.isNetworkTypeMobile(type);
456 if (isMobile) {
457 if (!fromRadio) {
458 if (mMobileActivityFromRadio) {
459 // If this call is not coming from a report from the radio itself, but we
460 // have previously received reports from the radio, then we will take the
461 // power state to just be whatever the radio last reported.
462 powerState = mLastPowerStateFromRadio;
463 }
464 } else {
465 mMobileActivityFromRadio = true;
466 }
467 if (mLastPowerStateFromRadio != powerState) {
468 mLastPowerStateFromRadio = powerState;
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700469 try {
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700470 getBatteryStats().noteMobileRadioPowerState(powerState, tsNanos, uid);
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700471 } catch (RemoteException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700472 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700473 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700474 }
475
Adam Lesinskie08af192015-03-25 16:42:59 -0700476 if (ConnectivityManager.isNetworkTypeWifi(type)) {
477 if (mLastPowerStateFromWifi != powerState) {
478 mLastPowerStateFromWifi = powerState;
479 try {
Adam Lesinski5f056f62016-07-14 16:56:08 -0700480 getBatteryStats().noteWifiRadioPowerState(powerState, tsNanos, uid);
Adam Lesinskie08af192015-03-25 16:42:59 -0700481 } catch (RemoteException e) {
482 }
483 }
484 }
485
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700486 boolean isActive = powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_MEDIUM
487 || powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH;
488
489 if (!isMobile || fromRadio || !mMobileActivityFromRadio) {
490 // Report the change in data activity. We don't do this if this is a change
491 // on the mobile network, that is not coming from the radio itself, and we
492 // have previously seen change reports from the radio. In that case only
493 // the radio is the authority for the current state.
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900494 final boolean active = isActive;
495 invokeForAllObservers(o -> o.interfaceClassDataActivityChanged(
496 Integer.toString(type), active, tsNanos));
Haoyu Baidb3c8672012-06-20 14:29:57 -0700497 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800498
499 boolean report = false;
500 synchronized (mIdleTimerLock) {
501 if (mActiveIdleTimers.isEmpty()) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700502 // If there are no idle timers, we are not monitoring activity, so we
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800503 // are always considered active.
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700504 isActive = true;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800505 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700506 if (mNetworkActive != isActive) {
507 mNetworkActive = isActive;
508 report = isActive;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800509 }
510 }
511 if (report) {
512 reportNetworkActive();
513 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700514 }
515
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900516 @Override
517 public void registerTetheringStatsProvider(ITetheringStatsProvider provider, String name) {
518 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
519 Preconditions.checkNotNull(provider);
520 synchronized(mTetheringStatsProviders) {
521 mTetheringStatsProviders.put(provider, name);
522 }
523 }
524
525 @Override
526 public void unregisterTetheringStatsProvider(ITetheringStatsProvider provider) {
527 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
528 synchronized(mTetheringStatsProviders) {
529 mTetheringStatsProviders.remove(provider);
530 }
531 }
532
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900533 @Override
534 public void tetherLimitReached(ITetheringStatsProvider provider) {
535 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
536 synchronized(mTetheringStatsProviders) {
537 if (!mTetheringStatsProviders.containsKey(provider)) {
538 return;
539 }
540 // No current code examines the interface parameter in a global alert. Just pass null.
541 notifyLimitReached(LIMIT_GLOBAL_ALERT, null);
542 }
543 }
544
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900545 // Sync the state of the given chain with the native daemon.
546 private void syncFirewallChainLocked(int chain, SparseIntArray uidFirewallRules, String name) {
547 int size = uidFirewallRules.size();
548 if (size > 0) {
549 // Make a copy of the current rules, and then clear them. This is because
550 // setFirewallUidRuleInternal only pushes down rules to the native daemon if they are
551 // different from the current rules stored in the mUidFirewall*Rules array for the
552 // specified chain. If we don't clear the rules, setFirewallUidRuleInternal will do
553 // nothing.
554 final SparseIntArray rules = uidFirewallRules.clone();
555 uidFirewallRules.clear();
556
557 // Now push the rules. setFirewallUidRuleInternal will push each of these down to the
558 // native daemon, and also add them to the mUidFirewall*Rules array for the specified
559 // chain.
560 if (DBG) Slog.d(TAG, "Pushing " + size + " active firewall " + name + "UID rules");
561 for (int i = 0; i < rules.size(); i++) {
Felipe Lemea701cad2016-05-12 09:58:14 -0700562 setFirewallUidRuleLocked(chain, rules.keyAt(i), rules.valueAt(i));
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900563 }
564 }
565 }
566
bohu07cc3bb2016-05-03 15:58:01 -0700567 private void connectNativeNetdService() {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900568 mNetdService = NetdService.get();
bohu07cc3bb2016-05-03 15:58:01 -0700569 }
570
571 /**
572 * Prepare native daemon once connected, enabling modules and pushing any
573 * existing in-memory rules.
574 */
575 private void prepareNativeDaemon() {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900576
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700577 mBandwidthControlEnabled = false;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700578
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700579 // only enable bandwidth control when support exists
580 final boolean hasKernelSupport = new File("/proc/net/xt_qtaguid/ctrl").exists();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800581
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700582 // push any existing quota or UID rules
583 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -0700584
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900585 if (hasKernelSupport) {
586 Slog.d(TAG, "enabling bandwidth control");
587 try {
588 mConnector.execute("bandwidth", "enable");
589 mBandwidthControlEnabled = true;
590 } catch (NativeDaemonConnectorException e) {
591 Log.wtf(TAG, "problem enabling bandwidth controls", e);
592 }
593 } else {
594 Slog.i(TAG, "not enabling bandwidth control");
595 }
596
597 SystemProperties.set(PROP_QTAGUID_ENABLED, mBandwidthControlEnabled ? "1" : "0");
598
599 try {
600 mConnector.execute("strict", "enable");
601 mStrictEnabled = true;
602 } catch (NativeDaemonConnectorException e) {
603 Log.wtf(TAG, "Failed strict enable", e);
604 }
605
Felipe Leme65be3022016-03-22 14:53:13 -0700606 setDataSaverModeEnabled(mDataSaverMode);
607
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700608 int size = mActiveQuotas.size();
609 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800610 if (DBG) Slog.d(TAG, "Pushing " + size + " active quota rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700611 final HashMap<String, Long> activeQuotas = mActiveQuotas;
612 mActiveQuotas = Maps.newHashMap();
613 for (Map.Entry<String, Long> entry : activeQuotas.entrySet()) {
614 setInterfaceQuota(entry.getKey(), entry.getValue());
615 }
616 }
617
618 size = mActiveAlerts.size();
619 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800620 if (DBG) Slog.d(TAG, "Pushing " + size + " active alert rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700621 final HashMap<String, Long> activeAlerts = mActiveAlerts;
622 mActiveAlerts = Maps.newHashMap();
623 for (Map.Entry<String, Long> entry : activeAlerts.entrySet()) {
624 setInterfaceAlert(entry.getKey(), entry.getValue());
625 }
626 }
627
Felipe Leme65be3022016-03-22 14:53:13 -0700628 size = mUidRejectOnMetered.size();
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700629 if (size > 0) {
Felipe Leme65be3022016-03-22 14:53:13 -0700630 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered whitelist rules");
631 final SparseBooleanArray uidRejectOnQuota = mUidRejectOnMetered;
632 mUidRejectOnMetered = new SparseBooleanArray();
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700633 for (int i = 0; i < uidRejectOnQuota.size(); i++) {
Felipe Leme65be3022016-03-22 14:53:13 -0700634 setUidMeteredNetworkBlacklist(uidRejectOnQuota.keyAt(i),
635 uidRejectOnQuota.valueAt(i));
636 }
637 }
638
639 size = mUidAllowOnMetered.size();
640 if (size > 0) {
641 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered blacklist rules");
642 final SparseBooleanArray uidAcceptOnQuota = mUidAllowOnMetered;
643 mUidAllowOnMetered = new SparseBooleanArray();
644 for (int i = 0; i < uidAcceptOnQuota.size(); i++) {
645 setUidMeteredNetworkWhitelist(uidAcceptOnQuota.keyAt(i),
646 uidAcceptOnQuota.valueAt(i));
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700647 }
648 }
Jeff Sharkey605eb792014-11-04 13:34:06 -0800649
650 size = mUidCleartextPolicy.size();
651 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800652 if (DBG) Slog.d(TAG, "Pushing " + size + " active UID cleartext policies");
Jeff Sharkey605eb792014-11-04 13:34:06 -0800653 final SparseIntArray local = mUidCleartextPolicy;
654 mUidCleartextPolicy = new SparseIntArray();
655 for (int i = 0; i < local.size(); i++) {
656 setUidCleartextNetworkPolicy(local.keyAt(i), local.valueAt(i));
657 }
658 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700659
Robin Leec3736bc2017-03-10 16:19:54 +0000660 setFirewallEnabled(mFirewallEnabled);
Amith Yamasani15e472352015-04-24 19:06:07 -0700661
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900662 syncFirewallChainLocked(FIREWALL_CHAIN_NONE, mUidFirewallRules, "");
663 syncFirewallChainLocked(FIREWALL_CHAIN_STANDBY, mUidFirewallStandbyRules, "standby ");
664 syncFirewallChainLocked(FIREWALL_CHAIN_DOZABLE, mUidFirewallDozableRules, "dozable ");
665 syncFirewallChainLocked(FIREWALL_CHAIN_POWERSAVE, mUidFirewallPowerSaveRules,
666 "powersave ");
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700667
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700668 if (mFirewallChainStates.get(FIREWALL_CHAIN_STANDBY)) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700669 setFirewallChainEnabled(FIREWALL_CHAIN_STANDBY, true);
670 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700671 if (mFirewallChainStates.get(FIREWALL_CHAIN_DOZABLE)) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700672 setFirewallChainEnabled(FIREWALL_CHAIN_DOZABLE, true);
673 }
Felipe Leme011b98f2016-02-10 17:28:31 -0800674 if (mFirewallChainStates.get(FIREWALL_CHAIN_POWERSAVE)) {
675 setFirewallChainEnabled(FIREWALL_CHAIN_POWERSAVE, true);
676 }
Amith Yamasani15e472352015-04-24 19:06:07 -0700677 }
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900678
679 if (mBandwidthControlEnabled) {
680 try {
681 getBatteryStats().noteNetworkStatsEnabled();
682 } catch (RemoteException e) {
683 }
684 }
685
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700686 }
San Mehat4d02d002010-01-22 16:07:46 -0800687
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900688 /**
689 * Notify our observers of a new or updated interface address.
690 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900691 private void notifyAddressUpdated(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900692 invokeForAllObservers(o -> o.addressUpdated(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900693 }
694
695 /**
696 * Notify our observers of a deleted interface address.
697 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900698 private void notifyAddressRemoved(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900699 invokeForAllObservers(o -> o.addressRemoved(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900700 }
701
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900702 /**
703 * Notify our observers of DNS server information received.
704 */
705 private void notifyInterfaceDnsServerInfo(String iface, long lifetime, String[] addresses) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900706 invokeForAllObservers(o -> o.interfaceDnsServerInfo(iface, lifetime, addresses));
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900707 }
708
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900709 /**
710 * Notify our observers of a route change.
711 */
712 private void notifyRouteChange(String action, RouteInfo route) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900713 if (action.equals("updated")) {
714 invokeForAllObservers(o -> o.routeUpdated(route));
715 } else {
716 invokeForAllObservers(o -> o.routeRemoved(route));
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900717 }
718 }
719
San Mehat873f2142010-01-14 10:25:07 -0800720 //
721 // Netd Callback handling
722 //
723
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700724 private class NetdCallbackReceiver implements INativeDaemonConnectorCallbacks {
725 @Override
San Mehat873f2142010-01-14 10:25:07 -0800726 public void onDaemonConnected() {
Felipe Leme65be3022016-03-22 14:53:13 -0700727 Slog.i(TAG, "onDaemonConnected()");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700728 // event is dispatched from internal NDC thread, so we prepare the
729 // daemon back on main thread.
730 if (mConnectedSignal != null) {
bohu07cc3bb2016-05-03 15:58:01 -0700731 // The system is booting and we're connecting to netd for the first time.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700732 mConnectedSignal.countDown();
733 mConnectedSignal = null;
734 } else {
bohu07cc3bb2016-05-03 15:58:01 -0700735 // We're reconnecting to netd after the socket connection
736 // was interrupted (e.g., if it crashed).
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700737 mFgHandler.post(new Runnable() {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700738 @Override
739 public void run() {
bohu07cc3bb2016-05-03 15:58:01 -0700740 connectNativeNetdService();
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700741 prepareNativeDaemon();
742 }
743 });
744 }
San Mehat873f2142010-01-14 10:25:07 -0800745 }
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700746
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700747 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800748 public boolean onCheckHoldWakeLock(int code) {
749 return code == NetdResponseCode.InterfaceClassActivity;
750 }
751
752 @Override
San Mehat873f2142010-01-14 10:25:07 -0800753 public boolean onEvent(int code, String raw, String[] cooked) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900754 String errorMessage = String.format("Invalid event from daemon (%s)", raw);
JP Abgrall12b933d2011-07-14 18:09:22 -0700755 switch (code) {
756 case NetdResponseCode.InterfaceChange:
757 /*
758 * a network interface change occured
759 * Format: "NNN Iface added <name>"
760 * "NNN Iface removed <name>"
761 * "NNN Iface changed <name> <up/down>"
762 * "NNN Iface linkstatus <name> <up/down>"
763 */
764 if (cooked.length < 4 || !cooked[1].equals("Iface")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900765 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700766 }
767 if (cooked[2].equals("added")) {
768 notifyInterfaceAdded(cooked[3]);
769 return true;
770 } else if (cooked[2].equals("removed")) {
771 notifyInterfaceRemoved(cooked[3]);
772 return true;
773 } else if (cooked[2].equals("changed") && cooked.length == 5) {
774 notifyInterfaceStatusChanged(cooked[3], cooked[4].equals("up"));
775 return true;
776 } else if (cooked[2].equals("linkstate") && cooked.length == 5) {
777 notifyInterfaceLinkStateChanged(cooked[3], cooked[4].equals("up"));
778 return true;
779 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900780 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700781 // break;
782 case NetdResponseCode.BandwidthControl:
783 /*
784 * Bandwidth control needs some attention
785 * Format: "NNN limit alert <alertName> <ifaceName>"
786 */
787 if (cooked.length < 5 || !cooked[1].equals("limit")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900788 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700789 }
790 if (cooked[2].equals("alert")) {
791 notifyLimitReached(cooked[3], cooked[4]);
792 return true;
793 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900794 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700795 // break;
Haoyu Baidb3c8672012-06-20 14:29:57 -0700796 case NetdResponseCode.InterfaceClassActivity:
797 /*
798 * An network interface class state changed (active/idle)
799 * Format: "NNN IfaceClass <active/idle> <label>"
800 */
801 if (cooked.length < 4 || !cooked[1].equals("IfaceClass")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900802 throw new IllegalStateException(errorMessage);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700803 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700804 long timestampNanos = 0;
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700805 int processUid = -1;
806 if (cooked.length >= 5) {
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700807 try {
808 timestampNanos = Long.parseLong(cooked[4]);
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700809 if (cooked.length == 6) {
810 processUid = Integer.parseInt(cooked[5]);
811 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700812 } catch(NumberFormatException ne) {}
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700813 } else {
814 timestampNanos = SystemClock.elapsedRealtimeNanos();
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700815 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700816 boolean isActive = cooked[2].equals("active");
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700817 notifyInterfaceClassActivity(Integer.parseInt(cooked[3]),
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700818 isActive ? DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700819 : DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
820 timestampNanos, processUid, false);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700821 return true;
822 // break;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900823 case NetdResponseCode.InterfaceAddressChange:
824 /*
825 * A network address change occurred
826 * Format: "NNN Address updated <addr> <iface> <flags> <scope>"
827 * "NNN Address removed <addr> <iface> <flags> <scope>"
828 */
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900829 if (cooked.length < 7 || !cooked[1].equals("Address")) {
830 throw new IllegalStateException(errorMessage);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900831 }
832
Lorenzo Colitti64483942013-11-15 18:43:52 +0900833 String iface = cooked[4];
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900834 LinkAddress address;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900835 try {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900836 int flags = Integer.parseInt(cooked[5]);
837 int scope = Integer.parseInt(cooked[6]);
838 address = new LinkAddress(cooked[3], flags, scope);
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900839 } catch(NumberFormatException e) { // Non-numeric lifetime or scope.
840 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti64483942013-11-15 18:43:52 +0900841 } catch(IllegalArgumentException e) { // Malformed/invalid IP address.
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900842 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900843 }
844
845 if (cooked[2].equals("updated")) {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900846 notifyAddressUpdated(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900847 } else {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900848 notifyAddressRemoved(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900849 }
850 return true;
851 // break;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900852 case NetdResponseCode.InterfaceDnsServerInfo:
853 /*
854 * Information about available DNS servers has been received.
855 * Format: "NNN DnsInfo servers <interface> <lifetime> <servers>"
856 */
857 long lifetime; // Actually a 32-bit unsigned integer.
858
859 if (cooked.length == 6 &&
860 cooked[1].equals("DnsInfo") &&
861 cooked[2].equals("servers")) {
862 try {
863 lifetime = Long.parseLong(cooked[4]);
864 } catch (NumberFormatException e) {
865 throw new IllegalStateException(errorMessage);
866 }
867 String[] servers = cooked[5].split(",");
868 notifyInterfaceDnsServerInfo(cooked[3], lifetime, servers);
869 }
870 return true;
871 // break;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900872 case NetdResponseCode.RouteChange:
873 /*
874 * A route has been updated or removed.
875 * Format: "NNN Route <updated|removed> <dst> [via <gateway] [dev <iface>]"
876 */
877 if (!cooked[1].equals("Route") || cooked.length < 6) {
878 throw new IllegalStateException(errorMessage);
879 }
880
881 String via = null;
882 String dev = null;
883 boolean valid = true;
884 for (int i = 4; (i + 1) < cooked.length && valid; i += 2) {
885 if (cooked[i].equals("dev")) {
886 if (dev == null) {
887 dev = cooked[i+1];
888 } else {
889 valid = false; // Duplicate interface.
890 }
891 } else if (cooked[i].equals("via")) {
892 if (via == null) {
893 via = cooked[i+1];
894 } else {
895 valid = false; // Duplicate gateway.
896 }
897 } else {
898 valid = false; // Unknown syntax.
899 }
900 }
901 if (valid) {
902 try {
903 // InetAddress.parseNumericAddress(null) inexplicably returns ::1.
904 InetAddress gateway = null;
905 if (via != null) gateway = InetAddress.parseNumericAddress(via);
906 RouteInfo route = new RouteInfo(new IpPrefix(cooked[3]), gateway, dev);
907 notifyRouteChange(cooked[2], route);
908 return true;
909 } catch (IllegalArgumentException e) {}
910 }
911 throw new IllegalStateException(errorMessage);
912 // break;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800913 case NetdResponseCode.StrictCleartext:
914 final int uid = Integer.parseInt(cooked[1]);
915 final byte[] firstPacket = HexDump.hexStringToByteArray(cooked[2]);
916 try {
917 ActivityManagerNative.getDefault().notifyCleartextNetwork(uid, firstPacket);
918 } catch (RemoteException ignored) {
919 }
920 break;
JP Abgrall12b933d2011-07-14 18:09:22 -0700921 default: break;
Robert Greenwalte3253922010-02-18 09:23:25 -0800922 }
923 return false;
San Mehat873f2142010-01-14 10:25:07 -0800924 }
925 }
926
San Mehated4fc8a2010-01-22 12:28:36 -0800927
San Mehat873f2142010-01-14 10:25:07 -0800928 //
929 // INetworkManagementService members
930 //
Erik Kline4e37b702016-07-05 11:34:21 +0900931 @Override
932 public INetd getNetdService() throws RemoteException {
933 final CountDownLatch connectedSignal = mConnectedSignal;
934 if (connectedSignal != null) {
935 try {
936 connectedSignal.await();
937 } catch (InterruptedException ignored) {}
938 }
939
940 return mNetdService;
941 }
San Mehat873f2142010-01-14 10:25:07 -0800942
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800943 @Override
944 public String[] listInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800945 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -0700946 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800947 return NativeDaemonEvent.filterMessageList(
948 mConnector.executeForList("interface", "list"), InterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -0700949 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -0800950 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -0700951 }
San Mehated4fc8a2010-01-22 12:28:36 -0800952 }
953
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800954 @Override
955 public InterfaceConfiguration getInterfaceConfig(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800956 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800957
958 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -0700959 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800960 event = mConnector.execute("interface", "getcfg", iface);
Kenny Roota80ce062010-06-01 13:23:53 -0700961 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -0800962 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -0700963 }
San Mehated4fc8a2010-01-22 12:28:36 -0800964
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800965 event.checkCode(InterfaceGetCfgResult);
966
967 // Rsp: 213 xx:xx:xx:xx:xx:xx yyy.yyy.yyy.yyy zzz flag1 flag2 flag3
968 final StringTokenizer st = new StringTokenizer(event.getMessage());
San Mehated4fc8a2010-01-22 12:28:36 -0800969
Kenny Roota80ce062010-06-01 13:23:53 -0700970 InterfaceConfiguration cfg;
San Mehated4fc8a2010-01-22 12:28:36 -0800971 try {
Kenny Roota80ce062010-06-01 13:23:53 -0700972 cfg = new InterfaceConfiguration();
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800973 cfg.setHardwareAddress(st.nextToken(" "));
Robert Greenwalted126402011-01-28 15:34:55 -0800974 InetAddress addr = null;
Robert Greenwalt2d2afd12011-02-01 15:30:46 -0800975 int prefixLength = 0;
Kenny Roota80ce062010-06-01 13:23:53 -0700976 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800977 addr = NetworkUtils.numericToInetAddress(st.nextToken());
Robert Greenwalte5903732011-02-22 16:00:42 -0800978 } catch (IllegalArgumentException iae) {
979 Slog.e(TAG, "Failed to parse ipaddr", iae);
Kenny Roota80ce062010-06-01 13:23:53 -0700980 }
981
982 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800983 prefixLength = Integer.parseInt(st.nextToken());
Robert Greenwalt2d2afd12011-02-01 15:30:46 -0800984 } catch (NumberFormatException nfe) {
985 Slog.e(TAG, "Failed to parse prefixLength", nfe);
Kenny Roota80ce062010-06-01 13:23:53 -0700986 }
Robert Greenwalt04808c22010-12-13 17:01:41 -0800987
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800988 cfg.setLinkAddress(new LinkAddress(addr, prefixLength));
989 while (st.hasMoreTokens()) {
990 cfg.setFlag(st.nextToken());
991 }
Kenny Roota80ce062010-06-01 13:23:53 -0700992 } catch (NoSuchElementException nsee) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800993 throw new IllegalStateException("Invalid response from daemon: " + event);
San Mehated4fc8a2010-01-22 12:28:36 -0800994 }
San Mehated4fc8a2010-01-22 12:28:36 -0800995 return cfg;
996 }
997
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800998 @Override
999 public void setInterfaceConfig(String iface, InterfaceConfiguration cfg) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001000 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001001 LinkAddress linkAddr = cfg.getLinkAddress();
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001002 if (linkAddr == null || linkAddr.getAddress() == null) {
1003 throw new IllegalStateException("Null LinkAddress given");
Robert Greenwalted126402011-01-28 15:34:55 -08001004 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001005
1006 final Command cmd = new Command("interface", "setcfg", iface,
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001007 linkAddr.getAddress().getHostAddress(),
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09001008 linkAddr.getPrefixLength());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001009 for (String flag : cfg.getFlags()) {
1010 cmd.appendArg(flag);
1011 }
1012
Kenny Roota80ce062010-06-01 13:23:53 -07001013 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001014 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001015 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001016 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001017 }
San Mehat873f2142010-01-14 10:25:07 -08001018 }
1019
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001020 @Override
1021 public void setInterfaceDown(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001022 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001023 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001024 ifcg.setInterfaceDown();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001025 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001026 }
1027
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001028 @Override
1029 public void setInterfaceUp(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001030 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001031 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001032 ifcg.setInterfaceUp();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001033 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001034 }
1035
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001036 @Override
1037 public void setInterfaceIpv6PrivacyExtensions(String iface, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001038 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sheriff73293612011-09-14 12:31:56 -07001039 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001040 mConnector.execute(
1041 "interface", "ipv6privacyextensions", iface, enable ? "enable" : "disable");
Irfan Sheriff73293612011-09-14 12:31:56 -07001042 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001043 throw e.rethrowAsParcelableException();
Irfan Sheriff73293612011-09-14 12:31:56 -07001044 }
1045 }
1046
Irfan Sherifff5600612011-06-16 10:26:28 -07001047 /* TODO: This is right now a IPv4 only function. Works for wifi which loses its
1048 IPv6 addresses on interface down, but we need to do full clean up here */
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001049 @Override
1050 public void clearInterfaceAddresses(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001051 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sherifff5600612011-06-16 10:26:28 -07001052 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001053 mConnector.execute("interface", "clearaddrs", iface);
Irfan Sherifff5600612011-06-16 10:26:28 -07001054 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001055 throw e.rethrowAsParcelableException();
Irfan Sherifff5600612011-06-16 10:26:28 -07001056 }
1057 }
1058
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001059 @Override
1060 public void enableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001061 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001062 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001063 mConnector.execute("interface", "ipv6", iface, "enable");
repo sync7960d9f2011-09-29 12:40:02 -07001064 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001065 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001066 }
1067 }
1068
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001069 @Override
Joel Scherpelz2db10742017-06-07 15:38:38 +09001070 public void setIPv6AddrGenMode(String iface, int mode) throws ServiceSpecificException {
1071 try {
1072 mNetdService.setIPv6AddrGenMode(iface, mode);
1073 } catch (RemoteException e) {
1074 throw e.rethrowAsRuntimeException();
1075 }
1076 }
1077
1078 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001079 public void disableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001080 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001081 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001082 mConnector.execute("interface", "ipv6", iface, "disable");
repo sync7960d9f2011-09-29 12:40:02 -07001083 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001084 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001085 }
1086 }
1087
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001088 @Override
Lorenzo Colittie21a26b2014-10-28 15:24:03 +09001089 public void setInterfaceIpv6NdOffload(String iface, boolean enable) {
1090 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1091 try {
1092 mConnector.execute(
1093 "interface", "ipv6ndoffload", iface, (enable ? "enable" : "disable"));
1094 } catch (NativeDaemonConnectorException e) {
1095 throw e.rethrowAsParcelableException();
1096 }
1097 }
1098
1099 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001100 public void addRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001101 modifyRoute("add", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001102 }
1103
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001104 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001105 public void removeRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001106 modifyRoute("remove", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001107 }
1108
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001109 private void modifyRoute(String action, String netId, RouteInfo route) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001110 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001111
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001112 final Command cmd = new Command("network", "route", action, netId);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001113
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001114 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001115 cmd.appendArg(route.getInterface());
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +09001116 cmd.appendArg(route.getDestination().toString());
1117
1118 switch (route.getType()) {
1119 case RouteInfo.RTN_UNICAST:
1120 if (route.hasGateway()) {
1121 cmd.appendArg(route.getGateway().getHostAddress());
1122 }
1123 break;
1124 case RouteInfo.RTN_UNREACHABLE:
1125 cmd.appendArg("unreachable");
1126 break;
1127 case RouteInfo.RTN_THROW:
1128 cmd.appendArg("throw");
1129 break;
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07001130 }
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001131
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001132 try {
1133 mConnector.execute(cmd);
1134 } catch (NativeDaemonConnectorException e) {
1135 throw e.rethrowAsParcelableException();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001136 }
1137 }
1138
1139 private ArrayList<String> readRouteList(String filename) {
1140 FileInputStream fstream = null;
Christopher Wiley5de073a2016-08-02 11:38:57 -07001141 ArrayList<String> list = new ArrayList<>();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001142
1143 try {
1144 fstream = new FileInputStream(filename);
1145 DataInputStream in = new DataInputStream(fstream);
1146 BufferedReader br = new BufferedReader(new InputStreamReader(in));
1147 String s;
1148
1149 // throw away the title line
1150
1151 while (((s = br.readLine()) != null) && (s.length() != 0)) {
1152 list.add(s);
1153 }
1154 } catch (IOException ex) {
1155 // return current list, possibly empty
1156 } finally {
1157 if (fstream != null) {
1158 try {
1159 fstream.close();
1160 } catch (IOException ex) {}
1161 }
1162 }
1163
1164 return list;
1165 }
1166
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001167 @Override
sy.yun9d9b74a2013-09-02 05:24:09 +09001168 public void setMtu(String iface, int mtu) {
1169 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1170
1171 final NativeDaemonEvent event;
1172 try {
1173 event = mConnector.execute("interface", "setmtu", iface, mtu);
1174 } catch (NativeDaemonConnectorException e) {
1175 throw e.rethrowAsParcelableException();
1176 }
1177 }
1178
1179 @Override
San Mehat873f2142010-01-14 10:25:07 -08001180 public void shutdown() {
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001181 // TODO: remove from aidl if nobody calls externally
1182 mContext.enforceCallingOrSelfPermission(SHUTDOWN, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001183
Felipe Leme03e689d2016-03-02 16:17:38 -08001184 Slog.i(TAG, "Shutting down");
San Mehat873f2142010-01-14 10:25:07 -08001185 }
1186
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001187 @Override
San Mehat873f2142010-01-14 10:25:07 -08001188 public boolean getIpForwardingEnabled() throws IllegalStateException{
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001189 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001190
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001191 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001192 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001193 event = mConnector.execute("ipfwd", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001194 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001195 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001196 }
San Mehat873f2142010-01-14 10:25:07 -08001197
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001198 // 211 Forwarding enabled
1199 event.checkCode(IpFwdStatusResult);
1200 return event.getMessage().endsWith("enabled");
San Mehat873f2142010-01-14 10:25:07 -08001201 }
1202
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001203 @Override
1204 public void setIpForwardingEnabled(boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001205 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001206 try {
Nilesh Poddarf3d4a582015-02-24 12:11:11 -08001207 mConnector.execute("ipfwd", enable ? "enable" : "disable", "tethering");
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001208 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001209 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001210 }
San Mehat873f2142010-01-14 10:25:07 -08001211 }
1212
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001213 @Override
1214 public void startTethering(String[] dhcpRange) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001215 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001216 // cmd is "tether start first_start first_stop second_start second_stop ..."
1217 // an odd number of addrs will fail
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001218
1219 final Command cmd = new Command("tether", "start");
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001220 for (String d : dhcpRange) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001221 cmd.appendArg(d);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001222 }
Kenny Roota80ce062010-06-01 13:23:53 -07001223
1224 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001225 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001226 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001227 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001228 }
San Mehat873f2142010-01-14 10:25:07 -08001229 }
1230
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001231 @Override
1232 public void stopTethering() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001233 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001234 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001235 mConnector.execute("tether", "stop");
Kenny Roota80ce062010-06-01 13:23:53 -07001236 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001237 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001238 }
San Mehat873f2142010-01-14 10:25:07 -08001239 }
1240
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001241 @Override
1242 public boolean isTetheringStarted() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001243 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001244
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001245 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001246 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001247 event = mConnector.execute("tether", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001248 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001249 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001250 }
San Mehat873f2142010-01-14 10:25:07 -08001251
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001252 // 210 Tethering services started
1253 event.checkCode(TetherStatusResult);
1254 return event.getMessage().endsWith("started");
San Mehat873f2142010-01-14 10:25:07 -08001255 }
Matthew Xiefe19f122012-07-12 16:03:32 -07001256
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001257 @Override
1258 public void tetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001259 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001260 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001261 mConnector.execute("tether", "interface", "add", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001262 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001263 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001264 }
Christopher Wiley5de073a2016-08-02 11:38:57 -07001265 List<RouteInfo> routes = new ArrayList<>();
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001266 // The RouteInfo constructor truncates the LinkAddress to a network prefix, thus making it
1267 // suitable to use as a route destination.
1268 routes.add(new RouteInfo(getInterfaceConfig(iface).getLinkAddress(), null, iface));
1269 addInterfaceToLocalNetwork(iface, routes);
San Mehat873f2142010-01-14 10:25:07 -08001270 }
1271
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001272 @Override
San Mehat873f2142010-01-14 10:25:07 -08001273 public void untetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001274 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001275 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001276 mConnector.execute("tether", "interface", "remove", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001277 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001278 throw e.rethrowAsParcelableException();
Erik Kline1f4278a2016-08-16 16:46:33 +09001279 } finally {
1280 removeInterfaceFromLocalNetwork(iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001281 }
San Mehat873f2142010-01-14 10:25:07 -08001282 }
1283
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001284 @Override
1285 public String[] listTetheredInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001286 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001287 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001288 return NativeDaemonEvent.filterMessageList(
1289 mConnector.executeForList("tether", "interface", "list"),
1290 TetherInterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001291 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001292 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001293 }
San Mehat873f2142010-01-14 10:25:07 -08001294 }
1295
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001296 @Override
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001297 public void setDnsForwarders(Network network, String[] dns) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001298 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001299
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001300 int netId = (network != null) ? network.netId : ConnectivityManager.NETID_UNSET;
1301 final Command cmd = new Command("tether", "dns", "set", netId);
1302
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001303 for (String s : dns) {
1304 cmd.appendArg(NetworkUtils.numericToInetAddress(s).getHostAddress());
1305 }
1306
San Mehat873f2142010-01-14 10:25:07 -08001307 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001308 mConnector.execute(cmd);
1309 } catch (NativeDaemonConnectorException e) {
1310 throw e.rethrowAsParcelableException();
San Mehat873f2142010-01-14 10:25:07 -08001311 }
1312 }
1313
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001314 @Override
1315 public String[] getDnsForwarders() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001316 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001317 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001318 return NativeDaemonEvent.filterMessageList(
1319 mConnector.executeForList("tether", "dns", "list"), TetherDnsFwdTgtListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001320 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001321 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001322 }
San Mehat873f2142010-01-14 10:25:07 -08001323 }
1324
jiaguo1da35f72014-01-09 16:39:59 +08001325 private List<InterfaceAddress> excludeLinkLocal(List<InterfaceAddress> addresses) {
Christopher Wiley5de073a2016-08-02 11:38:57 -07001326 ArrayList<InterfaceAddress> filtered = new ArrayList<>(addresses.size());
jiaguo1da35f72014-01-09 16:39:59 +08001327 for (InterfaceAddress ia : addresses) {
1328 if (!ia.getAddress().isLinkLocalAddress())
1329 filtered.add(ia);
1330 }
1331 return filtered;
1332 }
1333
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001334 private void modifyInterfaceForward(boolean add, String fromIface, String toIface) {
1335 final Command cmd = new Command("ipfwd", add ? "add" : "remove", fromIface, toIface);
1336 try {
1337 mConnector.execute(cmd);
1338 } catch (NativeDaemonConnectorException e) {
1339 throw e.rethrowAsParcelableException();
1340 }
1341 }
1342
1343 @Override
1344 public void startInterfaceForwarding(String fromIface, String toIface) {
1345 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1346 modifyInterfaceForward(true, fromIface, toIface);
1347 }
1348
1349 @Override
1350 public void stopInterfaceForwarding(String fromIface, String toIface) {
1351 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1352 modifyInterfaceForward(false, fromIface, toIface);
1353 }
1354
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001355 private void modifyNat(String action, String internalInterface, String externalInterface)
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001356 throws SocketException {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001357 final Command cmd = new Command("nat", action, internalInterface, externalInterface);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001358
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001359 final NetworkInterface internalNetworkInterface = NetworkInterface.getByName(
1360 internalInterface);
Robert Greenwalte83d1812011-11-21 14:44:39 -08001361 if (internalNetworkInterface == null) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001362 cmd.appendArg("0");
Robert Greenwalte83d1812011-11-21 14:44:39 -08001363 } else {
jiaguo1da35f72014-01-09 16:39:59 +08001364 // Don't touch link-local routes, as link-local addresses aren't routable,
1365 // kernel creates link-local routes on all interfaces automatically
1366 List<InterfaceAddress> interfaceAddresses = excludeLinkLocal(
1367 internalNetworkInterface.getInterfaceAddresses());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001368 cmd.appendArg(interfaceAddresses.size());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001369 for (InterfaceAddress ia : interfaceAddresses) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001370 InetAddress addr = NetworkUtils.getNetworkPart(
1371 ia.getAddress(), ia.getNetworkPrefixLength());
1372 cmd.appendArg(addr.getHostAddress() + "/" + ia.getNetworkPrefixLength());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001373 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001374 }
1375
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001376 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001377 mConnector.execute(cmd);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001378 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001379 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001380 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001381 }
1382
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001383 @Override
1384 public void enableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001385 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001386 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001387 modifyNat("enable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001388 } catch (SocketException e) {
1389 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001390 }
San Mehat873f2142010-01-14 10:25:07 -08001391 }
1392
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001393 @Override
1394 public void disableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001395 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001396 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001397 modifyNat("disable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001398 } catch (SocketException e) {
1399 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001400 }
San Mehat873f2142010-01-14 10:25:07 -08001401 }
San Mehat72759df2010-01-19 13:50:37 -08001402
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001403 @Override
1404 public String[] listTtys() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001405 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001406 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001407 return NativeDaemonEvent.filterMessageList(
1408 mConnector.executeForList("list_ttys"), TtyListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001409 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001410 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001411 }
San Mehat72759df2010-01-19 13:50:37 -08001412 }
1413
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001414 @Override
1415 public void attachPppd(
1416 String tty, String localAddr, String remoteAddr, String dns1Addr, String dns2Addr) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001417 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat72759df2010-01-19 13:50:37 -08001418 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001419 mConnector.execute("pppd", "attach", tty,
Robert Greenwalte5903732011-02-22 16:00:42 -08001420 NetworkUtils.numericToInetAddress(localAddr).getHostAddress(),
1421 NetworkUtils.numericToInetAddress(remoteAddr).getHostAddress(),
1422 NetworkUtils.numericToInetAddress(dns1Addr).getHostAddress(),
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001423 NetworkUtils.numericToInetAddress(dns2Addr).getHostAddress());
Kenny Roota80ce062010-06-01 13:23:53 -07001424 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001425 throw e.rethrowAsParcelableException();
San Mehat72759df2010-01-19 13:50:37 -08001426 }
1427 }
1428
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001429 @Override
1430 public void detachPppd(String tty) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001431 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001432 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001433 mConnector.execute("pppd", "detach", tty);
Kenny Roota80ce062010-06-01 13:23:53 -07001434 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001435 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001436 }
San Mehat72759df2010-01-19 13:50:37 -08001437 }
Robert Greenwaltce1200d2010-02-18 11:25:54 -08001438
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001439 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001440 public void addIdleTimer(String iface, int timeout, final int type) {
Haoyu Bai04124232012-06-28 15:26:19 -07001441 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1442
1443 if (DBG) Slog.d(TAG, "Adding idletimer");
1444
1445 synchronized (mIdleTimerLock) {
1446 IdleTimerParams params = mActiveIdleTimers.get(iface);
1447 if (params != null) {
1448 // the interface already has idletimer, update network count
1449 params.networkCount++;
1450 return;
1451 }
1452
1453 try {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001454 mConnector.execute("idletimer", "add", iface, Integer.toString(timeout),
1455 Integer.toString(type));
Haoyu Bai04124232012-06-28 15:26:19 -07001456 } catch (NativeDaemonConnectorException e) {
1457 throw e.rethrowAsParcelableException();
1458 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001459 mActiveIdleTimers.put(iface, new IdleTimerParams(timeout, type));
1460
Dianne Hackborne13c4c02014-02-11 17:18:35 -08001461 // Networks start up.
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001462 if (ConnectivityManager.isNetworkTypeMobile(type)) {
1463 mNetworkActive = false;
1464 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001465 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001466 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001467 notifyInterfaceClassActivity(type,
1468 DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001469 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001470 }
1471 });
Haoyu Bai04124232012-06-28 15:26:19 -07001472 }
1473 }
1474
1475 @Override
1476 public void removeIdleTimer(String iface) {
1477 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1478
1479 if (DBG) Slog.d(TAG, "Removing idletimer");
1480
1481 synchronized (mIdleTimerLock) {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001482 final IdleTimerParams params = mActiveIdleTimers.get(iface);
Haoyu Bai04124232012-06-28 15:26:19 -07001483 if (params == null || --(params.networkCount) > 0) {
1484 return;
1485 }
1486
1487 try {
1488 mConnector.execute("idletimer", "remove", iface,
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001489 Integer.toString(params.timeout), Integer.toString(params.type));
Haoyu Bai04124232012-06-28 15:26:19 -07001490 } catch (NativeDaemonConnectorException e) {
1491 throw e.rethrowAsParcelableException();
1492 }
1493 mActiveIdleTimers.remove(iface);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001494 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001495 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001496 notifyInterfaceClassActivity(params.type,
1497 DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001498 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001499 }
1500 });
Haoyu Bai04124232012-06-28 15:26:19 -07001501 }
1502 }
1503
1504 @Override
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001505 public NetworkStats getNetworkStatsSummaryDev() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001506 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001507 try {
1508 return mStatsFactory.readNetworkStatsSummaryDev();
1509 } catch (IOException e) {
1510 throw new IllegalStateException(e);
1511 }
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001512 }
1513
1514 @Override
1515 public NetworkStats getNetworkStatsSummaryXt() {
1516 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001517 try {
1518 return mStatsFactory.readNetworkStatsSummaryXt();
1519 } catch (IOException e) {
1520 throw new IllegalStateException(e);
1521 }
Jeff Sharkeyae2c1812011-10-04 13:11:40 -07001522 }
1523
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001524 @Override
Jeff Sharkey9a13f362011-04-26 16:25:36 -07001525 public NetworkStats getNetworkStatsDetail() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001526 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001527 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001528 return mStatsFactory.readNetworkStatsDetail(UID_ALL, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001529 } catch (IOException e) {
1530 throw new IllegalStateException(e);
1531 }
San Mehat91cac642010-03-31 14:31:36 -07001532 }
1533
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001534 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001535 public void setInterfaceQuota(String iface, long quotaBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001536 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001537
Jeff Sharkey350083e2011-06-29 10:45:16 -07001538 // silently discard when control disabled
1539 // TODO: eventually migrate to be always enabled
1540 if (!mBandwidthControlEnabled) return;
1541
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001542 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001543 if (mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001544 throw new IllegalStateException("iface " + iface + " already has quota");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001545 }
1546
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001547 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001548 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001549 mConnector.execute("bandwidth", "setiquota", iface, quotaBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001550 mActiveQuotas.put(iface, quotaBytes);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001551 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001552 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001553 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001554
1555 synchronized (mTetheringStatsProviders) {
1556 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1557 try {
1558 provider.setInterfaceQuota(iface, quotaBytes);
1559 } catch (RemoteException e) {
1560 Log.e(TAG, "Problem setting tethering data limit on provider " +
1561 mTetheringStatsProviders.get(provider) + ": " + e);
1562 }
1563 }
1564 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001565 }
1566 }
1567
1568 @Override
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001569 public void removeInterfaceQuota(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001570 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001571
Jeff Sharkey350083e2011-06-29 10:45:16 -07001572 // silently discard when control disabled
1573 // TODO: eventually migrate to be always enabled
1574 if (!mBandwidthControlEnabled) return;
1575
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001576 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001577 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001578 // TODO: eventually consider throwing
1579 return;
1580 }
1581
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001582 mActiveQuotas.remove(iface);
1583 mActiveAlerts.remove(iface);
Jeff Sharkey38ddeaa2011-11-08 13:04:22 -08001584
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001585 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001586 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001587 mConnector.execute("bandwidth", "removeiquota", iface);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001588 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001589 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001590 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001591
1592 synchronized (mTetheringStatsProviders) {
1593 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1594 try {
1595 provider.setInterfaceQuota(iface, ITetheringStatsProvider.QUOTA_UNLIMITED);
1596 } catch (RemoteException e) {
1597 Log.e(TAG, "Problem removing tethering data limit on provider " +
1598 mTetheringStatsProviders.get(provider) + ": " + e);
1599 }
1600 }
1601 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001602 }
1603 }
1604
1605 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001606 public void setInterfaceAlert(String iface, long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001607 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001608
1609 // silently discard when control disabled
1610 // TODO: eventually migrate to be always enabled
1611 if (!mBandwidthControlEnabled) return;
1612
1613 // quick sanity check
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001614 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001615 throw new IllegalStateException("setting alert requires existing quota on iface");
1616 }
1617
1618 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001619 if (mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001620 throw new IllegalStateException("iface " + iface + " already has alert");
1621 }
1622
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001623 try {
1624 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001625 mConnector.execute("bandwidth", "setinterfacealert", iface, alertBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001626 mActiveAlerts.put(iface, alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001627 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001628 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001629 }
1630 }
1631 }
1632
1633 @Override
1634 public void removeInterfaceAlert(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001635 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001636
1637 // silently discard when control disabled
1638 // TODO: eventually migrate to be always enabled
1639 if (!mBandwidthControlEnabled) return;
1640
1641 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001642 if (!mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001643 // TODO: eventually consider throwing
1644 return;
1645 }
1646
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001647 try {
1648 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001649 mConnector.execute("bandwidth", "removeinterfacealert", iface);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001650 mActiveAlerts.remove(iface);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001651 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001652 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001653 }
1654 }
1655 }
1656
1657 @Override
1658 public void setGlobalAlert(long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001659 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001660
1661 // silently discard when control disabled
1662 // TODO: eventually migrate to be always enabled
1663 if (!mBandwidthControlEnabled) return;
1664
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001665 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001666 mConnector.execute("bandwidth", "setglobalalert", alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001667 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001668 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001669 }
1670 }
1671
Felipe Leme65be3022016-03-22 14:53:13 -07001672 private void setUidOnMeteredNetworkList(SparseBooleanArray quotaList, int uid,
1673 boolean blacklist, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001674 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001675
Jeff Sharkey350083e2011-06-29 10:45:16 -07001676 // silently discard when control disabled
1677 // TODO: eventually migrate to be always enabled
1678 if (!mBandwidthControlEnabled) return;
1679
Felipe Leme65be3022016-03-22 14:53:13 -07001680 final String chain = blacklist ? "naughtyapps" : "niceapps";
1681 final String suffix = enable ? "add" : "remove";
1682
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001683 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -07001684 final boolean oldEnable = quotaList.get(uid, false);
1685 if (oldEnable == enable) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001686 // TODO: eventually consider throwing
1687 return;
1688 }
1689
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001690 try {
Felipe Leme65be3022016-03-22 14:53:13 -07001691 mConnector.execute("bandwidth", suffix + chain, uid);
1692 if (enable) {
1693 quotaList.put(uid, true);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001694 } else {
Felipe Leme65be3022016-03-22 14:53:13 -07001695 quotaList.delete(uid);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001696 }
1697 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001698 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001699 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001700 }
1701 }
1702
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001703 @Override
Felipe Leme65be3022016-03-22 14:53:13 -07001704 public void setUidMeteredNetworkBlacklist(int uid, boolean enable) {
1705 setUidOnMeteredNetworkList(mUidRejectOnMetered, uid, true, enable);
1706 }
1707
1708 @Override
1709 public void setUidMeteredNetworkWhitelist(int uid, boolean enable) {
1710 setUidOnMeteredNetworkList(mUidAllowOnMetered, uid, false, enable);
1711 }
1712
1713 @Override
1714 public boolean setDataSaverModeEnabled(boolean enable) {
1715 if (DBG) Log.d(TAG, "setDataSaverMode: " + enable);
1716 synchronized (mQuotaLock) {
1717 if (mDataSaverMode == enable) {
1718 Log.w(TAG, "setDataSaverMode(): already " + mDataSaverMode);
1719 return true;
1720 }
1721 try {
1722 final boolean changed = mNetdService.bandwidthEnableDataSaver(enable);
1723 if (changed) {
1724 mDataSaverMode = enable;
1725 } else {
1726 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command silently failed");
1727 }
1728 return changed;
1729 } catch (RemoteException e) {
1730 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command failed", e);
1731 return false;
1732 }
1733 }
1734 }
1735
1736 @Override
Robin Lee17e61832016-05-09 13:46:28 +01001737 public void setAllowOnlyVpnForUids(boolean add, UidRange[] uidRanges)
1738 throws ServiceSpecificException {
1739 try {
1740 mNetdService.networkRejectNonSecureVpn(add, uidRanges);
1741 } catch (ServiceSpecificException e) {
1742 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1743 + ": netd command failed", e);
1744 throw e;
1745 } catch (RemoteException e) {
1746 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1747 + ": netd command failed", e);
1748 throw e.rethrowAsRuntimeException();
1749 }
1750 }
1751
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001752 private void applyUidCleartextNetworkPolicy(int uid, int policy) {
1753 final String policyString;
1754 switch (policy) {
1755 case StrictMode.NETWORK_POLICY_ACCEPT:
1756 policyString = "accept";
1757 break;
1758 case StrictMode.NETWORK_POLICY_LOG:
1759 policyString = "log";
1760 break;
1761 case StrictMode.NETWORK_POLICY_REJECT:
1762 policyString = "reject";
1763 break;
1764 default:
1765 throw new IllegalArgumentException("Unknown policy " + policy);
1766 }
1767
1768 try {
1769 mConnector.execute("strict", "set_uid_cleartext_policy", uid, policyString);
1770 mUidCleartextPolicy.put(uid, policy);
1771 } catch (NativeDaemonConnectorException e) {
1772 throw e.rethrowAsParcelableException();
1773 }
1774 }
1775
Robin Lee17e61832016-05-09 13:46:28 +01001776 @Override
Jeff Sharkey605eb792014-11-04 13:34:06 -08001777 public void setUidCleartextNetworkPolicy(int uid, int policy) {
1778 if (Binder.getCallingUid() != uid) {
1779 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1780 }
1781
1782 synchronized (mQuotaLock) {
1783 final int oldPolicy = mUidCleartextPolicy.get(uid, StrictMode.NETWORK_POLICY_ACCEPT);
1784 if (oldPolicy == policy) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001785 // This also ensures we won't needlessly apply an ACCEPT policy if we've just
1786 // enabled strict and the underlying iptables rules are empty.
Jeff Sharkey605eb792014-11-04 13:34:06 -08001787 return;
1788 }
1789
1790 if (!mStrictEnabled) {
1791 // Module isn't enabled yet; stash the requested policy away to
1792 // apply later once the daemon is connected.
1793 mUidCleartextPolicy.put(uid, policy);
1794 return;
1795 }
1796
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001797 // netd does not keep state on strict mode policies, and cannot replace a non-accept
1798 // policy without deleting it first. Rather than add state to netd, just always send
1799 // it an accept policy when switching between two non-accept policies.
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001800 // TODO: consider keeping state in netd so we can simplify this code.
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001801 if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT &&
1802 policy != StrictMode.NETWORK_POLICY_ACCEPT) {
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001803 applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001804 }
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001805
1806 applyUidCleartextNetworkPolicy(uid, policy);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001807 }
1808 }
1809
1810 @Override
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001811 public boolean isBandwidthControlEnabled() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001812 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001813 return mBandwidthControlEnabled;
1814 }
1815
1816 @Override
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001817 public NetworkStats getNetworkStatsUidDetail(int uid) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001818 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001819 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001820 return mStatsFactory.readNetworkStatsDetail(uid, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001821 } catch (IOException e) {
1822 throw new IllegalStateException(e);
1823 }
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001824 }
1825
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001826 private class NetdTetheringStatsProvider extends ITetheringStatsProvider.Stub {
1827 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001828 public NetworkStats getTetherStats(int how) {
1829 // We only need to return per-UID stats. Per-device stats are already counted by
1830 // interface counters.
1831 if (how != STATS_PER_UID) {
1832 return new NetworkStats(SystemClock.elapsedRealtime(), 0);
1833 }
1834
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001835 final NativeDaemonEvent[] events;
1836 try {
1837 events = mConnector.executeForList("bandwidth", "gettetherstats");
1838 } catch (NativeDaemonConnectorException e) {
1839 throw e.rethrowAsParcelableException();
1840 }
1841 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001842 for (NativeDaemonEvent event : events) {
1843 if (event.getCode() != TetheringStatsListResult) continue;
1844
1845 // 114 ifaceIn ifaceOut rx_bytes rx_packets tx_bytes tx_packets
1846 final StringTokenizer tok = new StringTokenizer(event.getMessage());
1847 try {
1848 final String ifaceIn = tok.nextToken();
1849 final String ifaceOut = tok.nextToken();
1850
1851 final NetworkStats.Entry entry = new NetworkStats.Entry();
1852 entry.iface = ifaceOut;
1853 entry.uid = UID_TETHERING;
1854 entry.set = SET_DEFAULT;
1855 entry.tag = TAG_NONE;
1856 entry.rxBytes = Long.parseLong(tok.nextToken());
1857 entry.rxPackets = Long.parseLong(tok.nextToken());
1858 entry.txBytes = Long.parseLong(tok.nextToken());
1859 entry.txPackets = Long.parseLong(tok.nextToken());
1860 stats.combineValues(entry);
1861 } catch (NoSuchElementException e) {
1862 throw new IllegalStateException("problem parsing tethering stats: " + event);
1863 } catch (NumberFormatException e) {
1864 throw new IllegalStateException("problem parsing tethering stats: " + event);
1865 }
1866 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001867 return stats;
1868 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001869
1870 @Override
1871 public void setInterfaceQuota(String iface, long quotaBytes) {
1872 // Do nothing. netd is already informed of quota changes in setInterfaceQuota.
1873 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001874 }
1875
1876 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001877 public NetworkStats getNetworkStatsTethering(int how) {
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001878 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1879
1880 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
1881 synchronized (mTetheringStatsProviders) {
1882 for (ITetheringStatsProvider provider: mTetheringStatsProviders.keySet()) {
1883 try {
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001884 stats.combineAllValues(provider.getTetherStats(how));
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001885 } catch (RemoteException e) {
1886 Log.e(TAG, "Problem reading tethering stats from " +
1887 mTetheringStatsProviders.get(provider) + ": " + e);
1888 }
1889 }
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001890 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001891 return stats;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001892 }
1893
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001894 @Override
Pierre Imai8e48e672016-04-21 13:30:43 +09001895 public void setDnsConfigurationForNetwork(int netId, String[] servers, String domains) {
1896 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1897
1898 ContentResolver resolver = mContext.getContentResolver();
1899
1900 int sampleValidity = Settings.Global.getInt(resolver,
1901 Settings.Global.DNS_RESOLVER_SAMPLE_VALIDITY_SECONDS,
1902 DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS);
1903 if (sampleValidity < 0 || sampleValidity > 65535) {
1904 Slog.w(TAG, "Invalid sampleValidity=" + sampleValidity + ", using default=" +
1905 DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS);
1906 sampleValidity = DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS;
1907 }
1908
1909 int successThreshold = Settings.Global.getInt(resolver,
1910 Settings.Global.DNS_RESOLVER_SUCCESS_THRESHOLD_PERCENT,
1911 DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT);
1912 if (successThreshold < 0 || successThreshold > 100) {
1913 Slog.w(TAG, "Invalid successThreshold=" + successThreshold + ", using default=" +
1914 DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT);
1915 successThreshold = DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT;
1916 }
1917
1918 int minSamples = Settings.Global.getInt(resolver,
1919 Settings.Global.DNS_RESOLVER_MIN_SAMPLES, DNS_RESOLVER_DEFAULT_MIN_SAMPLES);
1920 int maxSamples = Settings.Global.getInt(resolver,
1921 Settings.Global.DNS_RESOLVER_MAX_SAMPLES, DNS_RESOLVER_DEFAULT_MAX_SAMPLES);
1922 if (minSamples < 0 || minSamples > maxSamples || maxSamples > 64) {
1923 Slog.w(TAG, "Invalid sample count (min, max)=(" + minSamples + ", " + maxSamples +
1924 "), using default=(" + DNS_RESOLVER_DEFAULT_MIN_SAMPLES + ", " +
1925 DNS_RESOLVER_DEFAULT_MAX_SAMPLES + ")");
1926 minSamples = DNS_RESOLVER_DEFAULT_MIN_SAMPLES;
1927 maxSamples = DNS_RESOLVER_DEFAULT_MAX_SAMPLES;
1928 }
1929
1930 final String[] domainStrs = domains == null ? new String[0] : domains.split(" ");
1931 final int[] params = { sampleValidity, successThreshold, minSamples, maxSamples };
1932 try {
1933 mNetdService.setResolverConfiguration(netId, servers, domainStrs, params);
1934 } catch (RemoteException e) {
1935 throw new RuntimeException(e);
1936 }
1937 }
1938
1939 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001940 public void addVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001941 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001942 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
1943 argv[0] = "users";
1944 argv[1] = "add";
1945 argv[2] = netId;
1946 int argc = 3;
1947 // Avoid overly long commands by limiting number of UID ranges per command.
1948 for (int i = 0; i < ranges.length; i++) {
1949 argv[argc++] = ranges[i].toString();
1950 if (i == (ranges.length - 1) || argc == argv.length) {
1951 try {
1952 mConnector.execute("network", Arrays.copyOf(argv, argc));
1953 } catch (NativeDaemonConnectorException e) {
1954 throw e.rethrowAsParcelableException();
1955 }
1956 argc = 3;
1957 }
Chad Brubaker3277620a2013-06-12 13:37:30 -07001958 }
1959 }
1960
1961 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001962 public void removeVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001963 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001964 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
1965 argv[0] = "users";
1966 argv[1] = "remove";
1967 argv[2] = netId;
1968 int argc = 3;
1969 // Avoid overly long commands by limiting number of UID ranges per command.
1970 for (int i = 0; i < ranges.length; i++) {
1971 argv[argc++] = ranges[i].toString();
1972 if (i == (ranges.length - 1) || argc == argv.length) {
1973 try {
1974 mConnector.execute("network", Arrays.copyOf(argv, argc));
1975 } catch (NativeDaemonConnectorException e) {
1976 throw e.rethrowAsParcelableException();
1977 }
1978 argc = 3;
1979 }
Chad Brubakercca54c42013-06-27 17:41:38 -07001980 }
1981 }
1982
1983 @Override
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001984 public void setFirewallEnabled(boolean enabled) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001985 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001986 try {
Amith Yamasani15e472352015-04-24 19:06:07 -07001987 mConnector.execute("firewall", "enable", enabled ? "whitelist" : "blacklist");
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001988 mFirewallEnabled = enabled;
1989 } catch (NativeDaemonConnectorException e) {
1990 throw e.rethrowAsParcelableException();
1991 }
1992 }
1993
1994 @Override
1995 public boolean isFirewallEnabled() {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001996 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001997 return mFirewallEnabled;
1998 }
1999
2000 @Override
Jeff Sharkey2c092982012-08-24 11:44:40 -07002001 public void setFirewallInterfaceRule(String iface, boolean allow) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002002 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002003 Preconditions.checkState(mFirewallEnabled);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002004 final String rule = allow ? "allow" : "deny";
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002005 try {
2006 mConnector.execute("firewall", "set_interface_rule", iface, rule);
2007 } catch (NativeDaemonConnectorException e) {
2008 throw e.rethrowAsParcelableException();
2009 }
2010 }
2011
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002012 private void closeSocketsForFirewallChainLocked(int chain, String chainName) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002013 // UID ranges to close sockets on.
2014 UidRange[] ranges;
2015 // UID ranges whose sockets we won't touch.
2016 int[] exemptUids;
2017
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002018 final SparseIntArray rules = getUidFirewallRules(chain);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002019 int numUids = 0;
2020
2021 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2022 // Close all sockets on all non-system UIDs...
2023 ranges = new UidRange[] {
2024 // TODO: is there a better way of finding all existing users? If so, we could
2025 // specify their ranges here.
2026 new UidRange(Process.FIRST_APPLICATION_UID, Integer.MAX_VALUE),
2027 };
2028 // ... except for the UIDs that have allow rules.
2029 exemptUids = new int[rules.size()];
2030 for (int i = 0; i < exemptUids.length; i++) {
2031 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2032 exemptUids[numUids] = rules.keyAt(i);
2033 numUids++;
2034 }
2035 }
2036 // Normally, whitelist chains only contain deny rules, so numUids == exemptUids.length.
2037 // But the code does not guarantee this in any way, and at least in one case - if we add
2038 // a UID rule to the firewall, and then disable the firewall - the chains can contain
2039 // the wrong type of rule. In this case, don't close connections that we shouldn't.
2040 //
2041 // TODO: tighten up this code by ensuring we never set the wrong type of rule, and
2042 // fix setFirewallEnabled to grab mQuotaLock and clear rules.
2043 if (numUids != exemptUids.length) {
2044 exemptUids = Arrays.copyOf(exemptUids, numUids);
2045 }
2046 } else {
2047 // Close sockets for every UID that has a deny rule...
2048 ranges = new UidRange[rules.size()];
2049 for (int i = 0; i < ranges.length; i++) {
2050 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2051 int uid = rules.keyAt(i);
2052 ranges[numUids] = new UidRange(uid, uid);
2053 numUids++;
2054 }
2055 }
2056 // As above; usually numUids == ranges.length, but not always.
2057 if (numUids != ranges.length) {
2058 ranges = Arrays.copyOf(ranges, numUids);
2059 }
2060 // ... with no exceptions.
2061 exemptUids = new int[0];
2062 }
2063
2064 try {
2065 mNetdService.socketDestroy(ranges, exemptUids);
2066 } catch(RemoteException | ServiceSpecificException e) {
2067 Slog.e(TAG, "Error closing sockets after enabling chain " + chainName + ": " + e);
2068 }
2069 }
2070
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002071 @Override
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002072 public void setFirewallChainEnabled(int chain, boolean enable) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002073 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002074 synchronized (mQuotaLock) {
Xiaohui Chen896b49a2015-07-29 14:12:22 -07002075 if (mFirewallChainStates.get(chain) == enable) {
2076 // All is the same, nothing to do. This relies on the fact that netd has child
2077 // chains default detached.
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002078 return;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002079 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002080 mFirewallChainStates.put(chain, enable);
2081
2082 final String operation = enable ? "enable_chain" : "disable_chain";
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002083 final String chainName;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002084 switch(chain) {
2085 case FIREWALL_CHAIN_STANDBY:
2086 chainName = FIREWALL_CHAIN_NAME_STANDBY;
2087 break;
2088 case FIREWALL_CHAIN_DOZABLE:
2089 chainName = FIREWALL_CHAIN_NAME_DOZABLE;
2090 break;
2091 case FIREWALL_CHAIN_POWERSAVE:
2092 chainName = FIREWALL_CHAIN_NAME_POWERSAVE;
2093 break;
2094 default:
2095 throw new IllegalArgumentException("Bad child chain: " + chain);
2096 }
2097
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002098 try {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002099 mConnector.execute("firewall", operation, chainName);
2100 } catch (NativeDaemonConnectorException e) {
2101 throw e.rethrowAsParcelableException();
2102 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002103
2104 // Close any sockets that were opened by the affected UIDs. This has to be done after
2105 // disabling network connectivity, in case they react to the socket close by reopening
2106 // the connection and race with the iptables commands that enable the firewall. All
2107 // whitelist and blacklist chains allow RSTs through.
2108 if (enable) {
2109 if (DBG) Slog.d(TAG, "Closing sockets after enabling chain " + chainName);
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002110 closeSocketsForFirewallChainLocked(chain, chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002111 }
Amith Yamasani15e472352015-04-24 19:06:07 -07002112 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002113 }
2114
2115 private int getFirewallType(int chain) {
2116 switch (chain) {
2117 case FIREWALL_CHAIN_STANDBY:
2118 return FIREWALL_TYPE_BLACKLIST;
2119 case FIREWALL_CHAIN_DOZABLE:
2120 return FIREWALL_TYPE_WHITELIST;
Felipe Leme011b98f2016-02-10 17:28:31 -08002121 case FIREWALL_CHAIN_POWERSAVE:
2122 return FIREWALL_TYPE_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002123 default:
2124 return isFirewallEnabled() ? FIREWALL_TYPE_WHITELIST : FIREWALL_TYPE_BLACKLIST;
2125 }
2126 }
2127
2128 @Override
2129 public void setFirewallUidRules(int chain, int[] uids, int[] rules) {
2130 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002131 synchronized (mQuotaLock) {
2132 SparseIntArray uidFirewallRules = getUidFirewallRules(chain);
2133 SparseIntArray newRules = new SparseIntArray();
2134 // apply new set of rules
2135 for (int index = uids.length - 1; index >= 0; --index) {
2136 int uid = uids[index];
2137 int rule = rules[index];
Felipe Lemea701cad2016-05-12 09:58:14 -07002138 updateFirewallUidRuleLocked(chain, uid, rule);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002139 newRules.put(uid, rule);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002140 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002141 // collect the rules to remove.
2142 SparseIntArray rulesToRemove = new SparseIntArray();
2143 for (int index = uidFirewallRules.size() - 1; index >= 0; --index) {
2144 int uid = uidFirewallRules.keyAt(index);
2145 if (newRules.indexOfKey(uid) < 0) {
2146 rulesToRemove.put(uid, FIREWALL_RULE_DEFAULT);
2147 }
2148 }
2149 // remove dead rules
2150 for (int index = rulesToRemove.size() - 1; index >= 0; --index) {
2151 int uid = rulesToRemove.keyAt(index);
Felipe Lemea701cad2016-05-12 09:58:14 -07002152 updateFirewallUidRuleLocked(chain, uid, FIREWALL_RULE_DEFAULT);
2153 }
2154 try {
2155 switch (chain) {
2156 case FIREWALL_CHAIN_DOZABLE:
2157 mNetdService.firewallReplaceUidChain("fw_dozable", true, uids);
2158 break;
2159 case FIREWALL_CHAIN_STANDBY:
2160 mNetdService.firewallReplaceUidChain("fw_standby", false, uids);
2161 break;
2162 case FIREWALL_CHAIN_POWERSAVE:
2163 mNetdService.firewallReplaceUidChain("fw_powersave", true, uids);
2164 break;
2165 case FIREWALL_CHAIN_NONE:
2166 default:
2167 Slog.d(TAG, "setFirewallUidRules() called on invalid chain: " + chain);
2168 }
2169 } catch (RemoteException e) {
2170 Slog.w(TAG, "Error flushing firewall chain " + chain, e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002171 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002172 }
2173 }
2174
2175 @Override
2176 public void setFirewallUidRule(int chain, int uid, int rule) {
2177 enforceSystemUid();
Felipe Lemea701cad2016-05-12 09:58:14 -07002178 synchronized (mQuotaLock) {
2179 setFirewallUidRuleLocked(chain, uid, rule);
2180 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002181 }
2182
Felipe Lemea701cad2016-05-12 09:58:14 -07002183 private void setFirewallUidRuleLocked(int chain, int uid, int rule) {
2184 if (updateFirewallUidRuleLocked(chain, uid, rule)) {
Amith Yamasani15e472352015-04-24 19:06:07 -07002185 try {
Felipe Lemea701cad2016-05-12 09:58:14 -07002186 mConnector.execute("firewall", "set_uid_rule", getFirewallChainName(chain), uid,
2187 getFirewallRuleName(chain, rule));
Amith Yamasani15e472352015-04-24 19:06:07 -07002188 } catch (NativeDaemonConnectorException e) {
2189 throw e.rethrowAsParcelableException();
2190 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002191 }
2192 }
2193
Felipe Lemea701cad2016-05-12 09:58:14 -07002194 // TODO: now that netd supports batching, NMS should not keep these data structures anymore...
2195 private boolean updateFirewallUidRuleLocked(int chain, int uid, int rule) {
2196 SparseIntArray uidFirewallRules = getUidFirewallRules(chain);
2197
2198 final int oldUidFirewallRule = uidFirewallRules.get(uid, FIREWALL_RULE_DEFAULT);
2199 if (DBG) {
2200 Slog.d(TAG, "oldRule = " + oldUidFirewallRule
2201 + ", newRule=" + rule + " for uid=" + uid + " on chain " + chain);
2202 }
2203 if (oldUidFirewallRule == rule) {
2204 if (DBG) Slog.d(TAG, "!!!!! Skipping change");
2205 // TODO: eventually consider throwing
2206 return false;
2207 }
2208
2209 String ruleName = getFirewallRuleName(chain, rule);
2210 String oldRuleName = getFirewallRuleName(chain, oldUidFirewallRule);
2211
2212 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
2213 uidFirewallRules.delete(uid);
2214 } else {
2215 uidFirewallRules.put(uid, rule);
2216 }
2217 return !ruleName.equals(oldRuleName);
2218 }
2219
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002220 private @NonNull String getFirewallRuleName(int chain, int rule) {
2221 String ruleName;
2222 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2223 if (rule == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2224 ruleName = "allow";
2225 } else {
2226 ruleName = "deny";
2227 }
2228 } else { // Blacklist mode
2229 if (rule == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2230 ruleName = "deny";
2231 } else {
2232 ruleName = "allow";
2233 }
2234 }
2235 return ruleName;
2236 }
2237
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002238 private @NonNull SparseIntArray getUidFirewallRules(int chain) {
2239 switch (chain) {
2240 case FIREWALL_CHAIN_STANDBY:
2241 return mUidFirewallStandbyRules;
2242 case FIREWALL_CHAIN_DOZABLE:
2243 return mUidFirewallDozableRules;
Felipe Leme011b98f2016-02-10 17:28:31 -08002244 case FIREWALL_CHAIN_POWERSAVE:
2245 return mUidFirewallPowerSaveRules;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002246 case FIREWALL_CHAIN_NONE:
2247 return mUidFirewallRules;
2248 default:
2249 throw new IllegalArgumentException("Unknown chain:" + chain);
2250 }
2251 }
2252
2253 public @NonNull String getFirewallChainName(int chain) {
2254 switch (chain) {
2255 case FIREWALL_CHAIN_STANDBY:
2256 return FIREWALL_CHAIN_NAME_STANDBY;
2257 case FIREWALL_CHAIN_DOZABLE:
2258 return FIREWALL_CHAIN_NAME_DOZABLE;
Felipe Leme011b98f2016-02-10 17:28:31 -08002259 case FIREWALL_CHAIN_POWERSAVE:
2260 return FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002261 case FIREWALL_CHAIN_NONE:
2262 return FIREWALL_CHAIN_NAME_NONE;
2263 default:
2264 throw new IllegalArgumentException("Unknown chain:" + chain);
2265 }
2266 }
2267
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002268 private static void enforceSystemUid() {
2269 final int uid = Binder.getCallingUid();
2270 if (uid != Process.SYSTEM_UID) {
2271 throw new SecurityException("Only available to AID_SYSTEM");
2272 }
2273 }
2274
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002275 @Override
Lorenzo Colitti79751842013-02-28 16:16:03 +09002276 public void startClatd(String interfaceName) throws IllegalStateException {
2277 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2278
2279 try {
2280 mConnector.execute("clatd", "start", interfaceName);
2281 } catch (NativeDaemonConnectorException e) {
2282 throw e.rethrowAsParcelableException();
2283 }
2284 }
2285
2286 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002287 public void stopClatd(String interfaceName) throws IllegalStateException {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002288 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2289
2290 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002291 mConnector.execute("clatd", "stop", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002292 } catch (NativeDaemonConnectorException e) {
2293 throw e.rethrowAsParcelableException();
2294 }
2295 }
2296
2297 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002298 public boolean isClatdStarted(String interfaceName) {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002299 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2300
2301 final NativeDaemonEvent event;
2302 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002303 event = mConnector.execute("clatd", "status", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002304 } catch (NativeDaemonConnectorException e) {
2305 throw e.rethrowAsParcelableException();
2306 }
2307
2308 event.checkCode(ClatdStatusResult);
2309 return event.getMessage().endsWith("started");
2310 }
2311
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002312 @Override
2313 public void registerNetworkActivityListener(INetworkActivityListener listener) {
2314 mNetworkActivityListeners.register(listener);
2315 }
2316
2317 @Override
2318 public void unregisterNetworkActivityListener(INetworkActivityListener listener) {
2319 mNetworkActivityListeners.unregister(listener);
2320 }
2321
2322 @Override
2323 public boolean isNetworkActive() {
2324 synchronized (mNetworkActivityListeners) {
2325 return mNetworkActive || mActiveIdleTimers.isEmpty();
2326 }
2327 }
2328
2329 private void reportNetworkActive() {
2330 final int length = mNetworkActivityListeners.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002331 try {
2332 for (int i = 0; i < length; i++) {
2333 try {
2334 mNetworkActivityListeners.getBroadcastItem(i).onNetworkActive();
Felipe Leme03e689d2016-03-02 16:17:38 -08002335 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002336 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002337 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002338 } finally {
2339 mNetworkActivityListeners.finishBroadcast();
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002340 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002341 }
2342
Mattias Falk8b47b362011-08-23 14:15:13 +02002343 /** {@inheritDoc} */
Jeff Sharkey7b4596f2013-02-25 10:55:29 -08002344 @Override
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -07002345 public void monitor() {
2346 if (mConnector != null) {
2347 mConnector.monitor();
2348 }
2349 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002350
2351 @Override
2352 protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
2353 mContext.enforceCallingOrSelfPermission(DUMP, TAG);
2354
Robert Greenwalt470fd722012-01-18 12:51:15 -08002355 pw.println("NetworkManagementService NativeDaemonConnector Log:");
2356 mConnector.dump(fd, pw, args);
2357 pw.println();
2358
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002359 pw.print("Bandwidth control enabled: "); pw.println(mBandwidthControlEnabled);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07002360 pw.print("mMobileActivityFromRadio="); pw.print(mMobileActivityFromRadio);
2361 pw.print(" mLastPowerStateFromRadio="); pw.println(mLastPowerStateFromRadio);
2362 pw.print("mNetworkActive="); pw.println(mNetworkActive);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002363
2364 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07002365 pw.print("Active quota ifaces: "); pw.println(mActiveQuotas.toString());
2366 pw.print("Active alert ifaces: "); pw.println(mActiveAlerts.toString());
Felipe Leme65be3022016-03-22 14:53:13 -07002367 pw.print("Data saver mode: "); pw.println(mDataSaverMode);
2368 dumpUidRuleOnQuotaLocked(pw, "blacklist", mUidRejectOnMetered);
2369 dumpUidRuleOnQuotaLocked(pw, "whitelist", mUidAllowOnMetered);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002370 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002371
Amith Yamasani15e472352015-04-24 19:06:07 -07002372 synchronized (mUidFirewallRules) {
Felipe Leme011b98f2016-02-10 17:28:31 -08002373 dumpUidFirewallRule(pw, "", mUidFirewallRules);
Amith Yamasani15e472352015-04-24 19:06:07 -07002374 }
2375
Felipe Leme65be3022016-03-22 14:53:13 -07002376 pw.print("UID firewall standby chain enabled: "); pw.println(
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002377 mFirewallChainStates.get(FIREWALL_CHAIN_STANDBY));
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002378 synchronized (mUidFirewallStandbyRules) {
Felipe Leme011b98f2016-02-10 17:28:31 -08002379 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_STANDBY, mUidFirewallStandbyRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002380 }
2381
Felipe Leme65be3022016-03-22 14:53:13 -07002382 pw.print("UID firewall dozable chain enabled: "); pw.println(
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002383 mFirewallChainStates.get(FIREWALL_CHAIN_DOZABLE));
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002384 synchronized (mUidFirewallDozableRules) {
Felipe Leme011b98f2016-02-10 17:28:31 -08002385 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_DOZABLE, mUidFirewallDozableRules);
2386 }
2387
2388 pw.println("UID firewall powersave chain enabled: " +
2389 mFirewallChainStates.get(FIREWALL_CHAIN_POWERSAVE));
2390 synchronized (mUidFirewallPowerSaveRules) {
2391 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_POWERSAVE, mUidFirewallPowerSaveRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002392 }
2393
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002394 synchronized (mIdleTimerLock) {
2395 pw.println("Idle timers:");
2396 for (HashMap.Entry<String, IdleTimerParams> ent : mActiveIdleTimers.entrySet()) {
2397 pw.print(" "); pw.print(ent.getKey()); pw.println(":");
2398 IdleTimerParams params = ent.getValue();
2399 pw.print(" timeout="); pw.print(params.timeout);
2400 pw.print(" type="); pw.print(params.type);
2401 pw.print(" networkCount="); pw.println(params.networkCount);
2402 }
2403 }
2404
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002405 pw.print("Firewall enabled: "); pw.println(mFirewallEnabled);
Felipe Leme65be3022016-03-22 14:53:13 -07002406 pw.print("Netd service status: " );
2407 if (mNetdService == null) {
2408 pw.println("disconnected");
2409 } else {
2410 try {
2411 final boolean alive = mNetdService.isAlive();
2412 pw.println(alive ? "alive": "dead");
2413 } catch (RemoteException e) {
2414 pw.println("unreachable");
2415 }
2416 }
2417 }
2418
2419 private void dumpUidRuleOnQuotaLocked(PrintWriter pw, String name, SparseBooleanArray list) {
2420 pw.print("UID bandwith control ");
2421 pw.print(name);
2422 pw.print(" rule: [");
2423 final int size = list.size();
2424 for (int i = 0; i < size; i++) {
2425 pw.print(list.keyAt(i));
2426 if (i < size - 1) pw.print(",");
2427 }
2428 pw.println("]");
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002429 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002430
Felipe Leme011b98f2016-02-10 17:28:31 -08002431 private void dumpUidFirewallRule(PrintWriter pw, String name, SparseIntArray rules) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002432 pw.print("UID firewall ");
Felipe Leme011b98f2016-02-10 17:28:31 -08002433 pw.print(name);
2434 pw.print(" rule: [");
2435 final int size = rules.size();
2436 for (int i = 0; i < size; i++) {
2437 pw.print(rules.keyAt(i));
2438 pw.print(":");
2439 pw.print(rules.valueAt(i));
2440 if (i < size - 1) pw.print(",");
2441 }
2442 pw.println("]");
2443 }
2444
Robert Greenwalt568891d2014-04-04 13:38:00 -07002445 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002446 public void createPhysicalNetwork(int netId, String permission) {
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002447 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2448
2449 try {
Paul Jensen487ffe72015-07-24 15:57:11 -04002450 if (permission != null) {
2451 mConnector.execute("network", "create", netId, permission);
2452 } else {
2453 mConnector.execute("network", "create", netId);
2454 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002455 } catch (NativeDaemonConnectorException e) {
2456 throw e.rethrowAsParcelableException();
2457 }
2458 }
2459
Robert Greenwalt568891d2014-04-04 13:38:00 -07002460 @Override
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002461 public void createVirtualNetwork(int netId, boolean hasDNS, boolean secure) {
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002462 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2463
2464 try {
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002465 mConnector.execute("network", "create", netId, "vpn", hasDNS ? "1" : "0",
2466 secure ? "1" : "0");
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002467 } catch (NativeDaemonConnectorException e) {
2468 throw e.rethrowAsParcelableException();
2469 }
2470 }
2471
2472 @Override
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002473 public void removeNetwork(int netId) {
2474 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2475
2476 try {
2477 mConnector.execute("network", "destroy", netId);
2478 } catch (NativeDaemonConnectorException e) {
2479 throw e.rethrowAsParcelableException();
2480 }
2481 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002482
2483 @Override
Paul Jensen992f2522014-04-28 10:33:11 -04002484 public void addInterfaceToNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002485 modifyInterfaceInNetwork("add", "" + netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002486 }
2487
2488 @Override
2489 public void removeInterfaceFromNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002490 modifyInterfaceInNetwork("remove", "" + netId, iface);
2491 }
Paul Jensen992f2522014-04-28 10:33:11 -04002492
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002493 private void modifyInterfaceInNetwork(String action, String netId, String iface) {
2494 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen992f2522014-04-28 10:33:11 -04002495 try {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002496 mConnector.execute("network", "interface", action, netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002497 } catch (NativeDaemonConnectorException e) {
2498 throw e.rethrowAsParcelableException();
2499 }
2500 }
2501
2502 @Override
Robert Greenwalt913c8952014-04-07 17:36:35 -07002503 public void addLegacyRouteForNetId(int netId, RouteInfo routeInfo, int uid) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002504 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2505
Sreeram Ramachandran03666c72014-07-19 23:21:46 -07002506 final Command cmd = new Command("network", "route", "legacy", uid, "add", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002507
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002508 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandrancc91c7b2014-06-03 18:41:43 -07002509 final LinkAddress la = routeInfo.getDestinationLinkAddress();
Robert Greenwalt568891d2014-04-04 13:38:00 -07002510 cmd.appendArg(routeInfo.getInterface());
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09002511 cmd.appendArg(la.getAddress().getHostAddress() + "/" + la.getPrefixLength());
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002512 if (routeInfo.hasGateway()) {
2513 cmd.appendArg(routeInfo.getGateway().getHostAddress());
2514 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002515
2516 try {
2517 mConnector.execute(cmd);
2518 } catch (NativeDaemonConnectorException e) {
2519 throw e.rethrowAsParcelableException();
2520 }
2521 }
2522
2523 @Override
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002524 public void setDefaultNetId(int netId) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002525 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2526
2527 try {
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002528 mConnector.execute("network", "default", "set", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002529 } catch (NativeDaemonConnectorException e) {
2530 throw e.rethrowAsParcelableException();
2531 }
2532 }
2533
2534 @Override
2535 public void clearDefaultNetId() {
2536 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2537
2538 try {
2539 mConnector.execute("network", "default", "clear");
2540 } catch (NativeDaemonConnectorException e) {
2541 throw e.rethrowAsParcelableException();
2542 }
2543 }
2544
2545 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002546 public void setNetworkPermission(int netId, String permission) {
2547 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2548
2549 try {
2550 if (permission != null) {
2551 mConnector.execute("network", "permission", "network", "set", permission, netId);
2552 } else {
2553 mConnector.execute("network", "permission", "network", "clear", netId);
2554 }
2555 } catch (NativeDaemonConnectorException e) {
2556 throw e.rethrowAsParcelableException();
2557 }
2558 }
2559
2560
2561 @Override
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002562 public void setPermission(String permission, int[] uids) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002563 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2564
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002565 Object[] argv = new Object[4 + MAX_UID_RANGES_PER_COMMAND];
2566 argv[0] = "permission";
2567 argv[1] = "user";
2568 argv[2] = "set";
2569 argv[3] = permission;
2570 int argc = 4;
2571 // Avoid overly long commands by limiting number of UIDs per command.
2572 for (int i = 0; i < uids.length; ++i) {
2573 argv[argc++] = uids[i];
2574 if (i == uids.length - 1 || argc == argv.length) {
2575 try {
2576 mConnector.execute("network", Arrays.copyOf(argv, argc));
2577 } catch (NativeDaemonConnectorException e) {
2578 throw e.rethrowAsParcelableException();
2579 }
2580 argc = 4;
2581 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002582 }
2583 }
2584
2585 @Override
2586 public void clearPermission(int[] uids) {
2587 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2588
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002589 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
2590 argv[0] = "permission";
2591 argv[1] = "user";
2592 argv[2] = "clear";
2593 int argc = 3;
2594 // Avoid overly long commands by limiting number of UIDs per command.
2595 for (int i = 0; i < uids.length; ++i) {
2596 argv[argc++] = uids[i];
2597 if (i == uids.length - 1 || argc == argv.length) {
2598 try {
2599 mConnector.execute("network", Arrays.copyOf(argv, argc));
2600 } catch (NativeDaemonConnectorException e) {
2601 throw e.rethrowAsParcelableException();
2602 }
2603 argc = 3;
2604 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002605 }
2606 }
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002607
2608 @Override
2609 public void allowProtect(int uid) {
2610 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2611
2612 try {
2613 mConnector.execute("network", "protect", "allow", uid);
2614 } catch (NativeDaemonConnectorException e) {
2615 throw e.rethrowAsParcelableException();
2616 }
2617 }
2618
2619 @Override
2620 public void denyProtect(int uid) {
2621 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2622
2623 try {
2624 mConnector.execute("network", "protect", "deny", uid);
2625 } catch (NativeDaemonConnectorException e) {
2626 throw e.rethrowAsParcelableException();
2627 }
2628 }
2629
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002630 @Override
2631 public void addInterfaceToLocalNetwork(String iface, List<RouteInfo> routes) {
2632 modifyInterfaceInNetwork("add", "local", iface);
2633
2634 for (RouteInfo route : routes) {
2635 if (!route.isDefaultRoute()) {
2636 modifyRoute("add", "local", route);
2637 }
2638 }
2639 }
2640
2641 @Override
2642 public void removeInterfaceFromLocalNetwork(String iface) {
2643 modifyInterfaceInNetwork("remove", "local", iface);
2644 }
Erik Kline6599ee82016-07-17 21:28:39 +09002645
2646 @Override
2647 public int removeRoutesFromLocalNetwork(List<RouteInfo> routes) {
2648 int failures = 0;
2649
2650 for (RouteInfo route : routes) {
2651 try {
2652 modifyRoute("remove", "local", route);
2653 } catch (IllegalStateException e) {
2654 failures++;
2655 }
2656 }
2657
2658 return failures;
2659 }
San Mehat873f2142010-01-14 10:25:07 -08002660}