blob: 9631e469f79ab4b8a51c64adb0f2b083b7a81069 [file] [log] [blame]
San Mehat873f2142010-01-14 10:25:07 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Jeff Sharkey4529bb62011-12-14 10:31:54 -080019import static android.Manifest.permission.CONNECTIVITY_INTERNAL;
Jeff Sharkey47eb1022011-08-25 17:48:52 -070020import static android.Manifest.permission.DUMP;
Sehee Parka9139bc2017-12-22 13:54:05 +090021import static android.Manifest.permission.NETWORK_SETTINGS;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090022import static android.Manifest.permission.NETWORK_STACK;
Jeff Sharkeyaf75c332011-11-18 12:41:12 -080023import static android.Manifest.permission.SHUTDOWN;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070024import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_DOZABLE;
25import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_DOZABLE;
26import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080027import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070028import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_STANDBY;
29import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080030import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070031import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_STANDBY;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070032import static android.net.NetworkPolicyManager.FIREWALL_RULE_ALLOW;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070033import static android.net.NetworkPolicyManager.FIREWALL_RULE_DEFAULT;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070034import static android.net.NetworkPolicyManager.FIREWALL_RULE_DENY;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070035import static android.net.NetworkPolicyManager.FIREWALL_TYPE_BLACKLIST;
36import static android.net.NetworkPolicyManager.FIREWALL_TYPE_WHITELIST;
Jeff Sharkeyb5d55e32011-08-10 17:53:27 -070037import static android.net.NetworkStats.SET_DEFAULT;
Lorenzo Colittif1912ca2017-08-17 19:23:08 +090038import static android.net.NetworkStats.STATS_PER_UID;
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -080039import static android.net.NetworkStats.TAG_ALL;
Jeff Sharkey1b5a2a92011-06-18 18:34:16 -070040import static android.net.NetworkStats.TAG_NONE;
41import static android.net.NetworkStats.UID_ALL;
Jeff Sharkeyae2c1812011-10-04 13:11:40 -070042import static android.net.TrafficStats.UID_TETHERING;
Lorenzo Colitti79751842013-02-28 16:16:03 +090043import static com.android.server.NetworkManagementService.NetdResponseCode.ClatdStatusResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080044import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceGetCfgResult;
45import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080046import static com.android.server.NetworkManagementService.NetdResponseCode.IpFwdStatusResult;
47import static com.android.server.NetworkManagementService.NetdResponseCode.TetherDnsFwdTgtListResult;
48import static com.android.server.NetworkManagementService.NetdResponseCode.TetherInterfaceListResult;
49import static com.android.server.NetworkManagementService.NetdResponseCode.TetherStatusResult;
Jeff Sharkeye4984be2013-09-10 21:03:27 -070050import static com.android.server.NetworkManagementService.NetdResponseCode.TetheringStatsListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080051import static com.android.server.NetworkManagementService.NetdResponseCode.TtyListResult;
Jeff Sharkeya63ba592011-07-19 23:47:12 -070052import static com.android.server.NetworkManagementSocketTagger.PROP_QTAGUID_ENABLED;
Erik Klineb2cfdfb2017-01-18 20:54:14 +090053
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070054import android.annotation.NonNull;
Sudheer Shankadc589ac2016-11-10 15:30:17 -080055import android.app.ActivityManager;
Pierre Imai8e48e672016-04-21 13:30:43 +090056import android.content.ContentResolver;
San Mehat873f2142010-01-14 10:25:07 -080057import android.content.Context;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080058import android.net.ConnectivityManager;
Lorenzo Colitti58967ba2016-02-02 17:21:21 +090059import android.net.INetd;
San Mehat4d02d002010-01-22 16:07:46 -080060import android.net.INetworkManagementEventObserver;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090061import android.net.ITetheringStatsProvider;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070062import android.net.InterfaceConfiguration;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +090063import android.net.IpPrefix;
Robert Greenwalted126402011-01-28 15:34:55 -080064import android.net.LinkAddress;
Lorenzo Colittib57edc52014-08-22 17:10:50 -070065import android.net.Network;
Amith Yamasani15e472352015-04-24 19:06:07 -070066import android.net.NetworkPolicyManager;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070067import android.net.NetworkStats;
Robert Greenwalted126402011-01-28 15:34:55 -080068import android.net.NetworkUtils;
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070069import android.net.RouteInfo;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -040070import android.net.UidRange;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +090071import android.net.util.NetdService;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080072import android.net.wifi.WifiConfiguration;
73import android.net.wifi.WifiConfiguration.KeyMgmt;
Dianne Hackborn91268cf2013-06-13 19:06:50 -070074import android.os.BatteryStats;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070075import android.os.Binder;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070076import android.os.Handler;
Lorenzo Colittia0868002017-07-11 02:29:28 +090077import android.os.IBinder;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080078import android.os.INetworkActivityListener;
San Mehat873f2142010-01-14 10:25:07 -080079import android.os.INetworkManagementService;
Lorenzo Colitti563dc452017-09-01 17:12:34 +090080import android.os.PersistableBundle;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080081import android.os.PowerManager;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070082import android.os.Process;
Jeff Sharkey3df273e2011-12-15 15:47:12 -080083import android.os.RemoteCallbackList;
84import android.os.RemoteException;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070085import android.os.ServiceManager;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +090086import android.os.ServiceSpecificException;
Jeff Sharkey605eb792014-11-04 13:34:06 -080087import android.os.StrictMode;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070088import android.os.SystemClock;
Marco Nelissen62dbb222010-02-18 10:56:30 -080089import android.os.SystemProperties;
Felipe Leme29e72ea2016-09-08 13:26:55 -070090import android.os.Trace;
Pierre Imai8e48e672016-04-21 13:30:43 +090091import android.provider.Settings;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -070092import android.telephony.DataConnectionRealTimeInfo;
93import android.telephony.PhoneStateListener;
Wink Savillefb40dd42014-06-12 17:02:31 -070094import android.telephony.SubscriptionManager;
Wink Saville67e07892014-06-18 16:43:14 -070095import android.telephony.TelephonyManager;
Erik Kline4d092232017-10-30 15:29:44 +090096import android.text.TextUtils;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080097import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080098import android.util.Slog;
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -070099import android.util.SparseBooleanArray;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800100import android.util.SparseIntArray;
Bookatz0b028b12018-05-31 16:51:17 -0700101import android.util.StatsLog;
San Mehat873f2142010-01-14 10:25:07 -0800102
Jeff Sharkey605eb792014-11-04 13:34:06 -0800103import com.android.internal.annotations.GuardedBy;
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700104import com.android.internal.annotations.VisibleForTesting;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -0700105import com.android.internal.app.IBatteryStats;
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700106import com.android.internal.net.NetworkStatsFactory;
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -0600107import com.android.internal.util.DumpUtils;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800108import com.android.internal.util.HexDump;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700109import com.android.internal.util.Preconditions;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800110import com.android.server.NativeDaemonConnector.Command;
Jeff Sharkey56cd6462013-06-07 15:09:15 -0700111import com.android.server.NativeDaemonConnector.SensitiveArg;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700112import com.google.android.collect.Maps;
Jeff Sharkey4414cea2011-06-24 17:05:24 -0700113
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700114import java.io.BufferedReader;
115import java.io.DataInputStream;
San Mehat873f2142010-01-14 10:25:07 -0800116import java.io.File;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700117import java.io.FileDescriptor;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700118import java.io.FileInputStream;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700119import java.io.IOException;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700120import java.io.InputStreamReader;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700121import java.io.PrintWriter;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700122import java.net.InetAddress;
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700123import java.net.InterfaceAddress;
124import java.net.NetworkInterface;
125import java.net.SocketException;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700126import java.util.ArrayList;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400127import java.util.Arrays;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700128import java.util.HashMap;
jiaguo1da35f72014-01-09 16:39:59 +0800129import java.util.List;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700130import java.util.Map;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700131import java.util.NoSuchElementException;
132import java.util.StringTokenizer;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700133import java.util.concurrent.CountDownLatch;
San Mehat873f2142010-01-14 10:25:07 -0800134
135/**
136 * @hide
137 */
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700138public class NetworkManagementService extends INetworkManagementService.Stub
139 implements Watchdog.Monitor {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900140
141 /**
142 * Helper class that encapsulates NetworkManagementService dependencies and makes them
143 * easier to mock in unit tests.
144 */
145 static class SystemServices {
146 public IBinder getService(String name) {
147 return ServiceManager.getService(name);
148 }
149 public void registerLocalService(NetworkManagementInternal nmi) {
150 LocalServices.addService(NetworkManagementInternal.class, nmi);
151 }
152 public INetd getNetd() {
153 return NetdService.get();
154 }
155 }
156
Amith Yamasani15e472352015-04-24 19:06:07 -0700157 private static final String TAG = "NetworkManagement";
158 private static final boolean DBG = Log.isLoggable(TAG, Log.DEBUG);
Kenny Root305bcbf2010-09-03 07:56:38 -0700159 private static final String NETD_TAG = "NetdConnector";
Lorenzo Colittia0868002017-07-11 02:29:28 +0900160 static final String NETD_SERVICE_NAME = "netd";
Kenny Root305bcbf2010-09-03 07:56:38 -0700161
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400162 private static final int MAX_UID_RANGES_PER_COMMAND = 10;
163
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700164 /**
165 * Name representing {@link #setGlobalAlert(long)} limit when delivered to
166 * {@link INetworkManagementEventObserver#limitReached(String, String)}.
167 */
168 public static final String LIMIT_GLOBAL_ALERT = "globalAlert";
169
Paul Jensen487ffe72015-07-24 15:57:11 -0400170 /**
171 * String to pass to netd to indicate that a network is only accessible
172 * to apps that have the CHANGE_NETWORK_STATE permission.
173 */
174 public static final String PERMISSION_NETWORK = "NETWORK";
175
176 /**
177 * String to pass to netd to indicate that a network is only
178 * accessible to system apps and those with the CONNECTIVITY_INTERNAL
179 * permission.
180 */
181 public static final String PERMISSION_SYSTEM = "SYSTEM";
182
Andrew Scull45f533c2017-05-19 15:37:20 +0100183 static class NetdResponseCode {
Sreeram Ramachandran03666c72014-07-19 23:21:46 -0700184 /* Keep in sync with system/netd/server/ResponseCode.h */
San Mehat873f2142010-01-14 10:25:07 -0800185 public static final int InterfaceListResult = 110;
186 public static final int TetherInterfaceListResult = 111;
187 public static final int TetherDnsFwdTgtListResult = 112;
San Mehat72759df2010-01-19 13:50:37 -0800188 public static final int TtyListResult = 113;
Jeff Sharkeye4984be2013-09-10 21:03:27 -0700189 public static final int TetheringStatsListResult = 114;
San Mehat873f2142010-01-14 10:25:07 -0800190
191 public static final int TetherStatusResult = 210;
192 public static final int IpFwdStatusResult = 211;
San Mehated4fc8a2010-01-22 12:28:36 -0800193 public static final int InterfaceGetCfgResult = 213;
Robert Greenwalte3253922010-02-18 09:23:25 -0800194 public static final int SoftapStatusResult = 214;
San Mehat91cac642010-03-31 14:31:36 -0700195 public static final int InterfaceRxCounterResult = 216;
196 public static final int InterfaceTxCounterResult = 217;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -0700197 public static final int QuotaCounterResult = 220;
198 public static final int TetheringStatsResult = 221;
Selim Gurun84c00c62012-02-27 15:42:38 -0800199 public static final int DnsProxyQueryResult = 222;
Lorenzo Colitti79751842013-02-28 16:16:03 +0900200 public static final int ClatdStatusResult = 223;
Robert Greenwalte3253922010-02-18 09:23:25 -0800201
202 public static final int InterfaceChange = 600;
JP Abgrall12b933d2011-07-14 18:09:22 -0700203 public static final int BandwidthControl = 601;
Haoyu Bai6b7358d2012-07-17 16:36:50 -0700204 public static final int InterfaceClassActivity = 613;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900205 public static final int InterfaceAddressChange = 614;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900206 public static final int InterfaceDnsServerInfo = 615;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900207 public static final int RouteChange = 616;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800208 public static final int StrictCleartext = 617;
San Mehat873f2142010-01-14 10:25:07 -0800209 }
210
Rebecca Silbersteine2ec94f2016-03-24 13:29:00 -0700211 /**
212 * String indicating a softap command.
213 */
214 static final String SOFT_AP_COMMAND = "softap";
215
216 /**
217 * String passed back to netd connector indicating softap command success.
218 */
219 static final String SOFT_AP_COMMAND_SUCCESS = "Ok";
220
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700221 static final int DAEMON_MSG_MOBILE_CONN_REAL_TIME_INFO = 1;
222
San Mehat873f2142010-01-14 10:25:07 -0800223 /**
224 * Binder context for this service
225 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700226 private final Context mContext;
San Mehat873f2142010-01-14 10:25:07 -0800227
228 /**
229 * connector object for communicating with netd
230 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700231 private final NativeDaemonConnector mConnector;
San Mehat873f2142010-01-14 10:25:07 -0800232
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700233 private final Handler mFgHandler;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700234 private final Handler mDaemonHandler;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700235
Lorenzo Colittia0868002017-07-11 02:29:28 +0900236 private final SystemServices mServices;
237
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900238 private INetd mNetdService;
239
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800240 private IBatteryStats mBatteryStats;
241
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700242 private final Thread mThread;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700243 private CountDownLatch mConnectedSignal = new CountDownLatch(1);
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700244
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800245 private final RemoteCallbackList<INetworkManagementEventObserver> mObservers =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700246 new RemoteCallbackList<>();
San Mehat4d02d002010-01-22 16:07:46 -0800247
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700248 private final NetworkStatsFactory mStatsFactory = new NetworkStatsFactory();
249
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900250 @GuardedBy("mTetheringStatsProviders")
251 private final HashMap<ITetheringStatsProvider, String>
252 mTetheringStatsProviders = Maps.newHashMap();
253
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700254 /**
255 * If both locks need to be held, then they should be obtained in the order:
256 * first {@link #mQuotaLock} and then {@link #mRulesLock}.
257 */
Andrew Scull45f533c2017-05-19 15:37:20 +0100258 private final Object mQuotaLock = new Object();
Andrew Scull519291f2017-05-23 13:11:03 +0100259 private final Object mRulesLock = new Object();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800260
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700261 /** Set of interfaces with active quotas. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800262 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700263 private HashMap<String, Long> mActiveQuotas = Maps.newHashMap();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -0700264 /** Set of interfaces with active alerts. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800265 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700266 private HashMap<String, Long> mActiveAlerts = Maps.newHashMap();
Felipe Leme65be3022016-03-22 14:53:13 -0700267 /** Set of UIDs blacklisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700268 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700269 private SparseBooleanArray mUidRejectOnMetered = new SparseBooleanArray();
270 /** Set of UIDs whitelisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700271 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700272 private SparseBooleanArray mUidAllowOnMetered = new SparseBooleanArray();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800273 /** Set of UIDs with cleartext penalties. */
274 @GuardedBy("mQuotaLock")
275 private SparseIntArray mUidCleartextPolicy = new SparseIntArray();
Amith Yamasani15e472352015-04-24 19:06:07 -0700276 /** Set of UIDs that are to be blocked/allowed by firewall controller. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700277 @GuardedBy("mRulesLock")
Amith Yamasani15e472352015-04-24 19:06:07 -0700278 private SparseIntArray mUidFirewallRules = new SparseIntArray();
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700279 /**
280 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
281 * to application idles.
282 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700283 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700284 private SparseIntArray mUidFirewallStandbyRules = new SparseIntArray();
285 /**
286 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
287 * to device idles.
288 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700289 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700290 private SparseIntArray mUidFirewallDozableRules = new SparseIntArray();
Felipe Leme011b98f2016-02-10 17:28:31 -0800291 /**
292 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
293 * to device on power-save mode.
294 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700295 @GuardedBy("mRulesLock")
Felipe Leme011b98f2016-02-10 17:28:31 -0800296 private SparseIntArray mUidFirewallPowerSaveRules = new SparseIntArray();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700297 /** Set of states for the child firewall chains. True if the chain is active. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700298 @GuardedBy("mRulesLock")
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700299 final SparseBooleanArray mFirewallChainStates = new SparseBooleanArray();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700300
Felipe Leme65be3022016-03-22 14:53:13 -0700301 @GuardedBy("mQuotaLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700302 private volatile boolean mDataSaverMode;
Felipe Leme65be3022016-03-22 14:53:13 -0700303
Andrew Scull45f533c2017-05-19 15:37:20 +0100304 private final Object mIdleTimerLock = new Object();
Haoyu Bai04124232012-06-28 15:26:19 -0700305 /** Set of interfaces with active idle timers. */
306 private static class IdleTimerParams {
307 public final int timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800308 public final int type;
Haoyu Bai04124232012-06-28 15:26:19 -0700309 public int networkCount;
310
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800311 IdleTimerParams(int timeout, int type) {
Haoyu Bai04124232012-06-28 15:26:19 -0700312 this.timeout = timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800313 this.type = type;
Haoyu Bai04124232012-06-28 15:26:19 -0700314 this.networkCount = 1;
315 }
316 }
317 private HashMap<String, IdleTimerParams> mActiveIdleTimers = Maps.newHashMap();
318
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700319 private volatile boolean mBandwidthControlEnabled;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700320 private volatile boolean mFirewallEnabled;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800321 private volatile boolean mStrictEnabled;
Jeff Sharkey350083e2011-06-29 10:45:16 -0700322
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700323 private boolean mMobileActivityFromRadio = false;
324 private int mLastPowerStateFromRadio = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Adam Lesinskie08af192015-03-25 16:42:59 -0700325 private int mLastPowerStateFromWifi = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700326
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800327 private final RemoteCallbackList<INetworkActivityListener> mNetworkActivityListeners =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700328 new RemoteCallbackList<>();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800329 private boolean mNetworkActive;
330
San Mehat873f2142010-01-14 10:25:07 -0800331 /**
332 * Constructs a new NetworkManagementService instance
333 *
334 * @param context Binder context for this service
335 */
Lorenzo Colittia0868002017-07-11 02:29:28 +0900336 private NetworkManagementService(
337 Context context, String socket, SystemServices services) {
San Mehat873f2142010-01-14 10:25:07 -0800338 mContext = context;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900339 mServices = services;
San Mehat4d02d002010-01-22 16:07:46 -0800340
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700341 // make sure this is on the same looper as our NativeDaemonConnector for sync purposes
342 mFgHandler = new Handler(FgThread.get().getLooper());
343
Dianne Hackborn4590e522014-03-24 13:36:46 -0700344 // Don't need this wake lock, since we now have a time stamp for when
345 // the network actually went inactive. (It might be nice to still do this,
346 // but I don't want to do it through the power manager because that pollutes the
347 // battery stats history with pointless noise.)
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700348 //PowerManager pm = (PowerManager)context.getSystemService(Context.POWER_SERVICE);
Dianne Hackborn4590e522014-03-24 13:36:46 -0700349 PowerManager.WakeLock wl = null; //pm.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK, NETD_TAG);
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800350
San Mehat873f2142010-01-14 10:25:07 -0800351 mConnector = new NativeDaemonConnector(
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700352 new NetdCallbackReceiver(), socket, 10, NETD_TAG, 160, wl,
353 FgThread.get().getLooper());
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700354 mThread = new Thread(mConnector, NETD_TAG);
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700355
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700356 mDaemonHandler = new Handler(FgThread.get().getLooper());
Wink Saville67e07892014-06-18 16:43:14 -0700357
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700358 // Add ourself to the Watchdog monitors.
359 Watchdog.getInstance().addMonitor(this);
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700360
Lorenzo Colittia0868002017-07-11 02:29:28 +0900361 mServices.registerLocalService(new LocalService());
Lorenzo Colitti8228eb32017-07-19 06:17:33 +0900362
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900363 synchronized (mTetheringStatsProviders) {
364 mTetheringStatsProviders.put(new NetdTetheringStatsProvider(), "netd");
365 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700366 }
367
368 @VisibleForTesting
369 NetworkManagementService() {
370 mConnector = null;
371 mContext = null;
372 mDaemonHandler = null;
373 mFgHandler = null;
374 mThread = null;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900375 mServices = null;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700376 }
377
Lorenzo Colittia0868002017-07-11 02:29:28 +0900378 static NetworkManagementService create(Context context, String socket, SystemServices services)
Felipe Leme03e689d2016-03-02 16:17:38 -0800379 throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900380 final NetworkManagementService service =
381 new NetworkManagementService(context, socket, services);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700382 final CountDownLatch connectedSignal = service.mConnectedSignal;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700383 if (DBG) Slog.d(TAG, "Creating NetworkManagementService");
384 service.mThread.start();
385 if (DBG) Slog.d(TAG, "Awaiting socket connection");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700386 connectedSignal.await();
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700387 if (DBG) Slog.d(TAG, "Connected");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900388 if (DBG) Slog.d(TAG, "Connecting native netd service");
bohu07cc3bb2016-05-03 15:58:01 -0700389 service.connectNativeNetdService();
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900390 if (DBG) Slog.d(TAG, "Connected");
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700391 return service;
San Mehat873f2142010-01-14 10:25:07 -0800392 }
393
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900394 public static NetworkManagementService create(Context context) throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900395 return create(context, NETD_SERVICE_NAME, new SystemServices());
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900396 }
397
Jeff Sharkey350083e2011-06-29 10:45:16 -0700398 public void systemReady() {
Felipe Leme03e689d2016-03-02 16:17:38 -0800399 if (DBG) {
400 final long start = System.currentTimeMillis();
401 prepareNativeDaemon();
402 final long delta = System.currentTimeMillis() - start;
403 Slog.d(TAG, "Prepared in " + delta + "ms");
404 return;
405 } else {
406 prepareNativeDaemon();
407 }
Jeff Sharkey350083e2011-06-29 10:45:16 -0700408 }
409
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800410 private IBatteryStats getBatteryStats() {
411 synchronized (this) {
412 if (mBatteryStats != null) {
413 return mBatteryStats;
414 }
Lorenzo Colittia0868002017-07-11 02:29:28 +0900415 mBatteryStats =
416 IBatteryStats.Stub.asInterface(mServices.getService(BatteryStats.SERVICE_NAME));
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800417 return mBatteryStats;
418 }
419 }
420
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800421 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800422 public void registerObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800423 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800424 mObservers.register(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800425 }
426
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800427 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800428 public void unregisterObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800429 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800430 mObservers.unregister(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800431 }
432
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900433 @FunctionalInterface
434 private interface NetworkManagementEventCallback {
435 public void sendCallback(INetworkManagementEventObserver o) throws RemoteException;
436 }
437
438 private void invokeForAllObservers(NetworkManagementEventCallback eventCallback) {
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800439 final int length = mObservers.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700440 try {
441 for (int i = 0; i < length; i++) {
442 try {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900443 eventCallback.sendCallback(mObservers.getBroadcastItem(i));
Felipe Leme03e689d2016-03-02 16:17:38 -0800444 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700445 }
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700446 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700447 } finally {
448 mObservers.finishBroadcast();
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700449 }
450 }
451
452 /**
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900453 * Notify our observers of an interface status change
454 */
455 private void notifyInterfaceStatusChanged(String iface, boolean up) {
456 invokeForAllObservers(o -> o.interfaceStatusChanged(iface, up));
457 }
458
459 /**
Mike J. Chenf59c7d02011-06-23 15:33:15 -0700460 * Notify our observers of an interface link state change
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700461 * (typically, an Ethernet cable has been plugged-in or unplugged).
462 */
463 private void notifyInterfaceLinkStateChanged(String iface, boolean up) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900464 invokeForAllObservers(o -> o.interfaceLinkStateChanged(iface, up));
San Mehat4d02d002010-01-22 16:07:46 -0800465 }
466
467 /**
468 * Notify our observers of an interface addition.
469 */
470 private void notifyInterfaceAdded(String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900471 invokeForAllObservers(o -> o.interfaceAdded(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800472 }
473
474 /**
475 * Notify our observers of an interface removal.
476 */
477 private void notifyInterfaceRemoved(String iface) {
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700478 // netd already clears out quota and alerts for removed ifaces; update
479 // our sanity-checking state.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700480 mActiveAlerts.remove(iface);
481 mActiveQuotas.remove(iface);
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700482
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900483 invokeForAllObservers(o -> o.interfaceRemoved(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800484 }
485
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700486 /**
JP Abgrall12b933d2011-07-14 18:09:22 -0700487 * Notify our observers of a limit reached.
488 */
489 private void notifyLimitReached(String limitName, String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900490 invokeForAllObservers(o -> o.limitReached(limitName, iface));
JP Abgrall12b933d2011-07-14 18:09:22 -0700491 }
492
493 /**
Haoyu Baidb3c8672012-06-20 14:29:57 -0700494 * Notify our observers of a change in the data activity state of the interface
495 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700496 private void notifyInterfaceClassActivity(int type, int powerState, long tsNanos,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700497 int uid, boolean fromRadio) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700498 final boolean isMobile = ConnectivityManager.isNetworkTypeMobile(type);
499 if (isMobile) {
500 if (!fromRadio) {
501 if (mMobileActivityFromRadio) {
502 // If this call is not coming from a report from the radio itself, but we
503 // have previously received reports from the radio, then we will take the
504 // power state to just be whatever the radio last reported.
505 powerState = mLastPowerStateFromRadio;
506 }
507 } else {
508 mMobileActivityFromRadio = true;
509 }
510 if (mLastPowerStateFromRadio != powerState) {
511 mLastPowerStateFromRadio = powerState;
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700512 try {
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700513 getBatteryStats().noteMobileRadioPowerState(powerState, tsNanos, uid);
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700514 } catch (RemoteException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700515 }
Bookatz0b028b12018-05-31 16:51:17 -0700516 StatsLog.write_non_chained(StatsLog.MOBILE_RADIO_POWER_STATE_CHANGED, uid, null,
517 powerState);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700518 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700519 }
520
Adam Lesinskie08af192015-03-25 16:42:59 -0700521 if (ConnectivityManager.isNetworkTypeWifi(type)) {
522 if (mLastPowerStateFromWifi != powerState) {
523 mLastPowerStateFromWifi = powerState;
524 try {
Adam Lesinski5f056f62016-07-14 16:56:08 -0700525 getBatteryStats().noteWifiRadioPowerState(powerState, tsNanos, uid);
Adam Lesinskie08af192015-03-25 16:42:59 -0700526 } catch (RemoteException e) {
527 }
Bookatz0b028b12018-05-31 16:51:17 -0700528 StatsLog.write_non_chained(StatsLog.WIFI_RADIO_POWER_STATE_CHANGED, uid, null,
529 powerState);
Adam Lesinskie08af192015-03-25 16:42:59 -0700530 }
531 }
532
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700533 boolean isActive = powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_MEDIUM
534 || powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH;
535
536 if (!isMobile || fromRadio || !mMobileActivityFromRadio) {
537 // Report the change in data activity. We don't do this if this is a change
538 // on the mobile network, that is not coming from the radio itself, and we
539 // have previously seen change reports from the radio. In that case only
540 // the radio is the authority for the current state.
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900541 final boolean active = isActive;
542 invokeForAllObservers(o -> o.interfaceClassDataActivityChanged(
543 Integer.toString(type), active, tsNanos));
Haoyu Baidb3c8672012-06-20 14:29:57 -0700544 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800545
546 boolean report = false;
547 synchronized (mIdleTimerLock) {
548 if (mActiveIdleTimers.isEmpty()) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700549 // If there are no idle timers, we are not monitoring activity, so we
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800550 // are always considered active.
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700551 isActive = true;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800552 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700553 if (mNetworkActive != isActive) {
554 mNetworkActive = isActive;
555 report = isActive;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800556 }
557 }
558 if (report) {
559 reportNetworkActive();
560 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700561 }
562
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900563 @Override
564 public void registerTetheringStatsProvider(ITetheringStatsProvider provider, String name) {
565 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
566 Preconditions.checkNotNull(provider);
567 synchronized(mTetheringStatsProviders) {
568 mTetheringStatsProviders.put(provider, name);
569 }
570 }
571
572 @Override
573 public void unregisterTetheringStatsProvider(ITetheringStatsProvider provider) {
574 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
575 synchronized(mTetheringStatsProviders) {
576 mTetheringStatsProviders.remove(provider);
577 }
578 }
579
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900580 @Override
581 public void tetherLimitReached(ITetheringStatsProvider provider) {
582 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
583 synchronized(mTetheringStatsProviders) {
584 if (!mTetheringStatsProviders.containsKey(provider)) {
585 return;
586 }
587 // No current code examines the interface parameter in a global alert. Just pass null.
588 notifyLimitReached(LIMIT_GLOBAL_ALERT, null);
589 }
590 }
591
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900592 // Sync the state of the given chain with the native daemon.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700593 private void syncFirewallChainLocked(int chain, String name) {
594 SparseIntArray rules;
595 synchronized (mRulesLock) {
596 final SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900597 // Make a copy of the current rules, and then clear them. This is because
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700598 // setFirewallUidRuleInternal only pushes down rules to the native daemon if they
599 // are different from the current rules stored in the mUidFirewall*Rules array for
600 // the specified chain. If we don't clear the rules, setFirewallUidRuleInternal
601 // will do nothing.
602 rules = uidFirewallRules.clone();
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900603 uidFirewallRules.clear();
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700604 }
605 if (rules.size() > 0) {
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900606 // Now push the rules. setFirewallUidRuleInternal will push each of these down to the
607 // native daemon, and also add them to the mUidFirewall*Rules array for the specified
608 // chain.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700609 if (DBG) Slog.d(TAG, "Pushing " + rules.size() + " active firewall "
610 + name + "UID rules");
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900611 for (int i = 0; i < rules.size(); i++) {
Felipe Lemea701cad2016-05-12 09:58:14 -0700612 setFirewallUidRuleLocked(chain, rules.keyAt(i), rules.valueAt(i));
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900613 }
614 }
615 }
616
bohu07cc3bb2016-05-03 15:58:01 -0700617 private void connectNativeNetdService() {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900618 mNetdService = mServices.getNetd();
bohu07cc3bb2016-05-03 15:58:01 -0700619 }
620
621 /**
622 * Prepare native daemon once connected, enabling modules and pushing any
623 * existing in-memory rules.
624 */
625 private void prepareNativeDaemon() {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900626
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700627 mBandwidthControlEnabled = false;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700628
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700629 // only enable bandwidth control when support exists
630 final boolean hasKernelSupport = new File("/proc/net/xt_qtaguid/ctrl").exists();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800631
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700632 // push any existing quota or UID rules
633 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -0700634
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900635 if (hasKernelSupport) {
636 Slog.d(TAG, "enabling bandwidth control");
637 try {
638 mConnector.execute("bandwidth", "enable");
639 mBandwidthControlEnabled = true;
640 } catch (NativeDaemonConnectorException e) {
641 Log.wtf(TAG, "problem enabling bandwidth controls", e);
642 }
643 } else {
644 Slog.i(TAG, "not enabling bandwidth control");
645 }
646
647 SystemProperties.set(PROP_QTAGUID_ENABLED, mBandwidthControlEnabled ? "1" : "0");
648
649 try {
650 mConnector.execute("strict", "enable");
651 mStrictEnabled = true;
652 } catch (NativeDaemonConnectorException e) {
653 Log.wtf(TAG, "Failed strict enable", e);
654 }
655
Felipe Leme65be3022016-03-22 14:53:13 -0700656 setDataSaverModeEnabled(mDataSaverMode);
657
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700658 int size = mActiveQuotas.size();
659 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800660 if (DBG) Slog.d(TAG, "Pushing " + size + " active quota rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700661 final HashMap<String, Long> activeQuotas = mActiveQuotas;
662 mActiveQuotas = Maps.newHashMap();
663 for (Map.Entry<String, Long> entry : activeQuotas.entrySet()) {
664 setInterfaceQuota(entry.getKey(), entry.getValue());
665 }
666 }
667
668 size = mActiveAlerts.size();
669 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800670 if (DBG) Slog.d(TAG, "Pushing " + size + " active alert rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700671 final HashMap<String, Long> activeAlerts = mActiveAlerts;
672 mActiveAlerts = Maps.newHashMap();
673 for (Map.Entry<String, Long> entry : activeAlerts.entrySet()) {
674 setInterfaceAlert(entry.getKey(), entry.getValue());
675 }
676 }
677
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700678 SparseBooleanArray uidRejectOnQuota = null;
679 SparseBooleanArray uidAcceptOnQuota = null;
680 synchronized (mRulesLock) {
681 size = mUidRejectOnMetered.size();
682 if (size > 0) {
683 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered blacklist rules");
684 uidRejectOnQuota = mUidRejectOnMetered;
685 mUidRejectOnMetered = new SparseBooleanArray();
686 }
687
688 size = mUidAllowOnMetered.size();
689 if (size > 0) {
690 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered whitelist rules");
691 uidAcceptOnQuota = mUidAllowOnMetered;
692 mUidAllowOnMetered = new SparseBooleanArray();
693 }
694 }
695 if (uidRejectOnQuota != null) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700696 for (int i = 0; i < uidRejectOnQuota.size(); i++) {
Felipe Leme65be3022016-03-22 14:53:13 -0700697 setUidMeteredNetworkBlacklist(uidRejectOnQuota.keyAt(i),
698 uidRejectOnQuota.valueAt(i));
699 }
700 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700701 if (uidAcceptOnQuota != null) {
Felipe Leme65be3022016-03-22 14:53:13 -0700702 for (int i = 0; i < uidAcceptOnQuota.size(); i++) {
703 setUidMeteredNetworkWhitelist(uidAcceptOnQuota.keyAt(i),
704 uidAcceptOnQuota.valueAt(i));
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700705 }
706 }
Jeff Sharkey605eb792014-11-04 13:34:06 -0800707
708 size = mUidCleartextPolicy.size();
709 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800710 if (DBG) Slog.d(TAG, "Pushing " + size + " active UID cleartext policies");
Jeff Sharkey605eb792014-11-04 13:34:06 -0800711 final SparseIntArray local = mUidCleartextPolicy;
712 mUidCleartextPolicy = new SparseIntArray();
713 for (int i = 0; i < local.size(); i++) {
714 setUidCleartextNetworkPolicy(local.keyAt(i), local.valueAt(i));
715 }
716 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700717
Robin Leec3736bc2017-03-10 16:19:54 +0000718 setFirewallEnabled(mFirewallEnabled);
Amith Yamasani15e472352015-04-24 19:06:07 -0700719
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700720 syncFirewallChainLocked(FIREWALL_CHAIN_NONE, "");
721 syncFirewallChainLocked(FIREWALL_CHAIN_STANDBY, "standby ");
722 syncFirewallChainLocked(FIREWALL_CHAIN_DOZABLE, "dozable ");
723 syncFirewallChainLocked(FIREWALL_CHAIN_POWERSAVE, "powersave ");
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700724
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700725 final int[] chains =
726 {FIREWALL_CHAIN_STANDBY, FIREWALL_CHAIN_DOZABLE, FIREWALL_CHAIN_POWERSAVE};
727 for (int chain : chains) {
728 if (getFirewallChainState(chain)) {
729 setFirewallChainEnabled(chain, true);
730 }
Felipe Leme011b98f2016-02-10 17:28:31 -0800731 }
Amith Yamasani15e472352015-04-24 19:06:07 -0700732 }
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900733
734 if (mBandwidthControlEnabled) {
735 try {
736 getBatteryStats().noteNetworkStatsEnabled();
737 } catch (RemoteException e) {
738 }
739 }
740
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700741 }
San Mehat4d02d002010-01-22 16:07:46 -0800742
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900743 /**
744 * Notify our observers of a new or updated interface address.
745 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900746 private void notifyAddressUpdated(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900747 invokeForAllObservers(o -> o.addressUpdated(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900748 }
749
750 /**
751 * Notify our observers of a deleted interface address.
752 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900753 private void notifyAddressRemoved(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900754 invokeForAllObservers(o -> o.addressRemoved(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900755 }
756
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900757 /**
758 * Notify our observers of DNS server information received.
759 */
760 private void notifyInterfaceDnsServerInfo(String iface, long lifetime, String[] addresses) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900761 invokeForAllObservers(o -> o.interfaceDnsServerInfo(iface, lifetime, addresses));
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900762 }
763
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900764 /**
765 * Notify our observers of a route change.
766 */
767 private void notifyRouteChange(String action, RouteInfo route) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900768 if (action.equals("updated")) {
769 invokeForAllObservers(o -> o.routeUpdated(route));
770 } else {
771 invokeForAllObservers(o -> o.routeRemoved(route));
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900772 }
773 }
774
San Mehat873f2142010-01-14 10:25:07 -0800775 //
776 // Netd Callback handling
777 //
778
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700779 private class NetdCallbackReceiver implements INativeDaemonConnectorCallbacks {
780 @Override
San Mehat873f2142010-01-14 10:25:07 -0800781 public void onDaemonConnected() {
Felipe Leme65be3022016-03-22 14:53:13 -0700782 Slog.i(TAG, "onDaemonConnected()");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700783 // event is dispatched from internal NDC thread, so we prepare the
784 // daemon back on main thread.
785 if (mConnectedSignal != null) {
bohu07cc3bb2016-05-03 15:58:01 -0700786 // The system is booting and we're connecting to netd for the first time.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700787 mConnectedSignal.countDown();
788 mConnectedSignal = null;
789 } else {
bohu07cc3bb2016-05-03 15:58:01 -0700790 // We're reconnecting to netd after the socket connection
791 // was interrupted (e.g., if it crashed).
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700792 mFgHandler.post(new Runnable() {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700793 @Override
794 public void run() {
bohu07cc3bb2016-05-03 15:58:01 -0700795 connectNativeNetdService();
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700796 prepareNativeDaemon();
797 }
798 });
799 }
San Mehat873f2142010-01-14 10:25:07 -0800800 }
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700801
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700802 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800803 public boolean onCheckHoldWakeLock(int code) {
804 return code == NetdResponseCode.InterfaceClassActivity;
805 }
806
807 @Override
San Mehat873f2142010-01-14 10:25:07 -0800808 public boolean onEvent(int code, String raw, String[] cooked) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900809 String errorMessage = String.format("Invalid event from daemon (%s)", raw);
JP Abgrall12b933d2011-07-14 18:09:22 -0700810 switch (code) {
811 case NetdResponseCode.InterfaceChange:
812 /*
813 * a network interface change occured
814 * Format: "NNN Iface added <name>"
815 * "NNN Iface removed <name>"
816 * "NNN Iface changed <name> <up/down>"
817 * "NNN Iface linkstatus <name> <up/down>"
818 */
819 if (cooked.length < 4 || !cooked[1].equals("Iface")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900820 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700821 }
822 if (cooked[2].equals("added")) {
823 notifyInterfaceAdded(cooked[3]);
824 return true;
825 } else if (cooked[2].equals("removed")) {
826 notifyInterfaceRemoved(cooked[3]);
827 return true;
828 } else if (cooked[2].equals("changed") && cooked.length == 5) {
829 notifyInterfaceStatusChanged(cooked[3], cooked[4].equals("up"));
830 return true;
831 } else if (cooked[2].equals("linkstate") && cooked.length == 5) {
832 notifyInterfaceLinkStateChanged(cooked[3], cooked[4].equals("up"));
833 return true;
834 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900835 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700836 // break;
837 case NetdResponseCode.BandwidthControl:
838 /*
839 * Bandwidth control needs some attention
840 * Format: "NNN limit alert <alertName> <ifaceName>"
841 */
842 if (cooked.length < 5 || !cooked[1].equals("limit")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900843 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700844 }
845 if (cooked[2].equals("alert")) {
846 notifyLimitReached(cooked[3], cooked[4]);
847 return true;
848 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900849 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700850 // break;
Haoyu Baidb3c8672012-06-20 14:29:57 -0700851 case NetdResponseCode.InterfaceClassActivity:
852 /*
853 * An network interface class state changed (active/idle)
854 * Format: "NNN IfaceClass <active/idle> <label>"
855 */
856 if (cooked.length < 4 || !cooked[1].equals("IfaceClass")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900857 throw new IllegalStateException(errorMessage);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700858 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700859 long timestampNanos = 0;
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700860 int processUid = -1;
861 if (cooked.length >= 5) {
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700862 try {
863 timestampNanos = Long.parseLong(cooked[4]);
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700864 if (cooked.length == 6) {
865 processUid = Integer.parseInt(cooked[5]);
866 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700867 } catch(NumberFormatException ne) {}
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700868 } else {
869 timestampNanos = SystemClock.elapsedRealtimeNanos();
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700870 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700871 boolean isActive = cooked[2].equals("active");
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700872 notifyInterfaceClassActivity(Integer.parseInt(cooked[3]),
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700873 isActive ? DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700874 : DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
875 timestampNanos, processUid, false);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700876 return true;
877 // break;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900878 case NetdResponseCode.InterfaceAddressChange:
879 /*
880 * A network address change occurred
881 * Format: "NNN Address updated <addr> <iface> <flags> <scope>"
882 * "NNN Address removed <addr> <iface> <flags> <scope>"
883 */
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900884 if (cooked.length < 7 || !cooked[1].equals("Address")) {
885 throw new IllegalStateException(errorMessage);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900886 }
887
Lorenzo Colitti64483942013-11-15 18:43:52 +0900888 String iface = cooked[4];
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900889 LinkAddress address;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900890 try {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900891 int flags = Integer.parseInt(cooked[5]);
892 int scope = Integer.parseInt(cooked[6]);
893 address = new LinkAddress(cooked[3], flags, scope);
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900894 } catch(NumberFormatException e) { // Non-numeric lifetime or scope.
895 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti64483942013-11-15 18:43:52 +0900896 } catch(IllegalArgumentException e) { // Malformed/invalid IP address.
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900897 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900898 }
899
900 if (cooked[2].equals("updated")) {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900901 notifyAddressUpdated(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900902 } else {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900903 notifyAddressRemoved(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900904 }
905 return true;
906 // break;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900907 case NetdResponseCode.InterfaceDnsServerInfo:
908 /*
909 * Information about available DNS servers has been received.
910 * Format: "NNN DnsInfo servers <interface> <lifetime> <servers>"
911 */
912 long lifetime; // Actually a 32-bit unsigned integer.
913
914 if (cooked.length == 6 &&
915 cooked[1].equals("DnsInfo") &&
916 cooked[2].equals("servers")) {
917 try {
918 lifetime = Long.parseLong(cooked[4]);
919 } catch (NumberFormatException e) {
920 throw new IllegalStateException(errorMessage);
921 }
922 String[] servers = cooked[5].split(",");
923 notifyInterfaceDnsServerInfo(cooked[3], lifetime, servers);
924 }
925 return true;
926 // break;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900927 case NetdResponseCode.RouteChange:
928 /*
929 * A route has been updated or removed.
930 * Format: "NNN Route <updated|removed> <dst> [via <gateway] [dev <iface>]"
931 */
932 if (!cooked[1].equals("Route") || cooked.length < 6) {
933 throw new IllegalStateException(errorMessage);
934 }
935
936 String via = null;
937 String dev = null;
938 boolean valid = true;
939 for (int i = 4; (i + 1) < cooked.length && valid; i += 2) {
940 if (cooked[i].equals("dev")) {
941 if (dev == null) {
942 dev = cooked[i+1];
943 } else {
944 valid = false; // Duplicate interface.
945 }
946 } else if (cooked[i].equals("via")) {
947 if (via == null) {
948 via = cooked[i+1];
949 } else {
950 valid = false; // Duplicate gateway.
951 }
952 } else {
953 valid = false; // Unknown syntax.
954 }
955 }
956 if (valid) {
957 try {
958 // InetAddress.parseNumericAddress(null) inexplicably returns ::1.
959 InetAddress gateway = null;
960 if (via != null) gateway = InetAddress.parseNumericAddress(via);
961 RouteInfo route = new RouteInfo(new IpPrefix(cooked[3]), gateway, dev);
962 notifyRouteChange(cooked[2], route);
963 return true;
964 } catch (IllegalArgumentException e) {}
965 }
966 throw new IllegalStateException(errorMessage);
967 // break;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800968 case NetdResponseCode.StrictCleartext:
969 final int uid = Integer.parseInt(cooked[1]);
970 final byte[] firstPacket = HexDump.hexStringToByteArray(cooked[2]);
971 try {
Sudheer Shankadc589ac2016-11-10 15:30:17 -0800972 ActivityManager.getService().notifyCleartextNetwork(uid, firstPacket);
Jeff Sharkey605eb792014-11-04 13:34:06 -0800973 } catch (RemoteException ignored) {
974 }
975 break;
JP Abgrall12b933d2011-07-14 18:09:22 -0700976 default: break;
Robert Greenwalte3253922010-02-18 09:23:25 -0800977 }
978 return false;
San Mehat873f2142010-01-14 10:25:07 -0800979 }
980 }
981
San Mehated4fc8a2010-01-22 12:28:36 -0800982
San Mehat873f2142010-01-14 10:25:07 -0800983 //
984 // INetworkManagementService members
985 //
Erik Kline4e37b702016-07-05 11:34:21 +0900986 @Override
987 public INetd getNetdService() throws RemoteException {
988 final CountDownLatch connectedSignal = mConnectedSignal;
989 if (connectedSignal != null) {
990 try {
991 connectedSignal.await();
992 } catch (InterruptedException ignored) {}
993 }
994
995 return mNetdService;
996 }
San Mehat873f2142010-01-14 10:25:07 -0800997
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800998 @Override
999 public String[] listInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001000 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001001 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001002 return NativeDaemonEvent.filterMessageList(
1003 mConnector.executeForList("interface", "list"), InterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001004 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001005 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001006 }
San Mehated4fc8a2010-01-22 12:28:36 -08001007 }
1008
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001009 @Override
1010 public InterfaceConfiguration getInterfaceConfig(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001011 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001012
1013 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001014 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001015 event = mConnector.execute("interface", "getcfg", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001016 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001017 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001018 }
San Mehated4fc8a2010-01-22 12:28:36 -08001019
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001020 event.checkCode(InterfaceGetCfgResult);
1021
1022 // Rsp: 213 xx:xx:xx:xx:xx:xx yyy.yyy.yyy.yyy zzz flag1 flag2 flag3
1023 final StringTokenizer st = new StringTokenizer(event.getMessage());
San Mehated4fc8a2010-01-22 12:28:36 -08001024
Kenny Roota80ce062010-06-01 13:23:53 -07001025 InterfaceConfiguration cfg;
San Mehated4fc8a2010-01-22 12:28:36 -08001026 try {
Kenny Roota80ce062010-06-01 13:23:53 -07001027 cfg = new InterfaceConfiguration();
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001028 cfg.setHardwareAddress(st.nextToken(" "));
Robert Greenwalted126402011-01-28 15:34:55 -08001029 InetAddress addr = null;
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001030 int prefixLength = 0;
Kenny Roota80ce062010-06-01 13:23:53 -07001031 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001032 addr = NetworkUtils.numericToInetAddress(st.nextToken());
Robert Greenwalte5903732011-02-22 16:00:42 -08001033 } catch (IllegalArgumentException iae) {
1034 Slog.e(TAG, "Failed to parse ipaddr", iae);
Kenny Roota80ce062010-06-01 13:23:53 -07001035 }
1036
1037 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001038 prefixLength = Integer.parseInt(st.nextToken());
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001039 } catch (NumberFormatException nfe) {
1040 Slog.e(TAG, "Failed to parse prefixLength", nfe);
Kenny Roota80ce062010-06-01 13:23:53 -07001041 }
Robert Greenwalt04808c22010-12-13 17:01:41 -08001042
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001043 cfg.setLinkAddress(new LinkAddress(addr, prefixLength));
1044 while (st.hasMoreTokens()) {
1045 cfg.setFlag(st.nextToken());
1046 }
Kenny Roota80ce062010-06-01 13:23:53 -07001047 } catch (NoSuchElementException nsee) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001048 throw new IllegalStateException("Invalid response from daemon: " + event);
San Mehated4fc8a2010-01-22 12:28:36 -08001049 }
San Mehated4fc8a2010-01-22 12:28:36 -08001050 return cfg;
1051 }
1052
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001053 @Override
1054 public void setInterfaceConfig(String iface, InterfaceConfiguration cfg) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001055 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001056 LinkAddress linkAddr = cfg.getLinkAddress();
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001057 if (linkAddr == null || linkAddr.getAddress() == null) {
1058 throw new IllegalStateException("Null LinkAddress given");
Robert Greenwalted126402011-01-28 15:34:55 -08001059 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001060
1061 final Command cmd = new Command("interface", "setcfg", iface,
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001062 linkAddr.getAddress().getHostAddress(),
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09001063 linkAddr.getPrefixLength());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001064 for (String flag : cfg.getFlags()) {
1065 cmd.appendArg(flag);
1066 }
1067
Kenny Roota80ce062010-06-01 13:23:53 -07001068 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001069 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001070 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001071 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001072 }
San Mehat873f2142010-01-14 10:25:07 -08001073 }
1074
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001075 @Override
1076 public void setInterfaceDown(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001077 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001078 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001079 ifcg.setInterfaceDown();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001080 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001081 }
1082
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001083 @Override
1084 public void setInterfaceUp(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001085 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001086 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001087 ifcg.setInterfaceUp();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001088 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001089 }
1090
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001091 @Override
1092 public void setInterfaceIpv6PrivacyExtensions(String iface, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001093 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sheriff73293612011-09-14 12:31:56 -07001094 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001095 mConnector.execute(
1096 "interface", "ipv6privacyextensions", iface, enable ? "enable" : "disable");
Irfan Sheriff73293612011-09-14 12:31:56 -07001097 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001098 throw e.rethrowAsParcelableException();
Irfan Sheriff73293612011-09-14 12:31:56 -07001099 }
1100 }
1101
Irfan Sherifff5600612011-06-16 10:26:28 -07001102 /* TODO: This is right now a IPv4 only function. Works for wifi which loses its
1103 IPv6 addresses on interface down, but we need to do full clean up here */
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001104 @Override
1105 public void clearInterfaceAddresses(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001106 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sherifff5600612011-06-16 10:26:28 -07001107 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001108 mConnector.execute("interface", "clearaddrs", iface);
Irfan Sherifff5600612011-06-16 10:26:28 -07001109 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001110 throw e.rethrowAsParcelableException();
Irfan Sherifff5600612011-06-16 10:26:28 -07001111 }
1112 }
1113
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001114 @Override
1115 public void enableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001116 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001117 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001118 mConnector.execute("interface", "ipv6", iface, "enable");
repo sync7960d9f2011-09-29 12:40:02 -07001119 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001120 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001121 }
1122 }
1123
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001124 @Override
Joel Scherpelz2db10742017-06-07 15:38:38 +09001125 public void setIPv6AddrGenMode(String iface, int mode) throws ServiceSpecificException {
1126 try {
1127 mNetdService.setIPv6AddrGenMode(iface, mode);
1128 } catch (RemoteException e) {
1129 throw e.rethrowAsRuntimeException();
1130 }
1131 }
1132
1133 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001134 public void disableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001135 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001136 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001137 mConnector.execute("interface", "ipv6", iface, "disable");
repo sync7960d9f2011-09-29 12:40:02 -07001138 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001139 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001140 }
1141 }
1142
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001143 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001144 public void addRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001145 modifyRoute("add", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001146 }
1147
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001148 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001149 public void removeRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001150 modifyRoute("remove", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001151 }
1152
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001153 private void modifyRoute(String action, String netId, RouteInfo route) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001154 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001155
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001156 final Command cmd = new Command("network", "route", action, netId);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001157
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001158 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001159 cmd.appendArg(route.getInterface());
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +09001160 cmd.appendArg(route.getDestination().toString());
1161
1162 switch (route.getType()) {
1163 case RouteInfo.RTN_UNICAST:
1164 if (route.hasGateway()) {
1165 cmd.appendArg(route.getGateway().getHostAddress());
1166 }
1167 break;
1168 case RouteInfo.RTN_UNREACHABLE:
1169 cmd.appendArg("unreachable");
1170 break;
1171 case RouteInfo.RTN_THROW:
1172 cmd.appendArg("throw");
1173 break;
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07001174 }
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001175
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001176 try {
1177 mConnector.execute(cmd);
1178 } catch (NativeDaemonConnectorException e) {
1179 throw e.rethrowAsParcelableException();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001180 }
1181 }
1182
1183 private ArrayList<String> readRouteList(String filename) {
1184 FileInputStream fstream = null;
Christopher Wiley212b95f2016-08-02 11:38:57 -07001185 ArrayList<String> list = new ArrayList<>();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001186
1187 try {
1188 fstream = new FileInputStream(filename);
1189 DataInputStream in = new DataInputStream(fstream);
1190 BufferedReader br = new BufferedReader(new InputStreamReader(in));
1191 String s;
1192
1193 // throw away the title line
1194
1195 while (((s = br.readLine()) != null) && (s.length() != 0)) {
1196 list.add(s);
1197 }
1198 } catch (IOException ex) {
1199 // return current list, possibly empty
1200 } finally {
1201 if (fstream != null) {
1202 try {
1203 fstream.close();
1204 } catch (IOException ex) {}
1205 }
1206 }
1207
1208 return list;
1209 }
1210
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001211 @Override
sy.yun9d9b74a2013-09-02 05:24:09 +09001212 public void setMtu(String iface, int mtu) {
1213 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1214
1215 final NativeDaemonEvent event;
1216 try {
1217 event = mConnector.execute("interface", "setmtu", iface, mtu);
1218 } catch (NativeDaemonConnectorException e) {
1219 throw e.rethrowAsParcelableException();
1220 }
1221 }
1222
1223 @Override
San Mehat873f2142010-01-14 10:25:07 -08001224 public void shutdown() {
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001225 // TODO: remove from aidl if nobody calls externally
1226 mContext.enforceCallingOrSelfPermission(SHUTDOWN, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001227
Felipe Leme03e689d2016-03-02 16:17:38 -08001228 Slog.i(TAG, "Shutting down");
San Mehat873f2142010-01-14 10:25:07 -08001229 }
1230
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001231 @Override
San Mehat873f2142010-01-14 10:25:07 -08001232 public boolean getIpForwardingEnabled() throws IllegalStateException{
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001233 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001234
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001235 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001236 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001237 event = mConnector.execute("ipfwd", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001238 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001239 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001240 }
San Mehat873f2142010-01-14 10:25:07 -08001241
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001242 // 211 Forwarding enabled
1243 event.checkCode(IpFwdStatusResult);
1244 return event.getMessage().endsWith("enabled");
San Mehat873f2142010-01-14 10:25:07 -08001245 }
1246
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001247 @Override
1248 public void setIpForwardingEnabled(boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001249 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001250 try {
Nilesh Poddarf3d4a582015-02-24 12:11:11 -08001251 mConnector.execute("ipfwd", enable ? "enable" : "disable", "tethering");
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001252 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001253 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001254 }
San Mehat873f2142010-01-14 10:25:07 -08001255 }
1256
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001257 @Override
1258 public void startTethering(String[] dhcpRange) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001259 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001260 // cmd is "tether start first_start first_stop second_start second_stop ..."
1261 // an odd number of addrs will fail
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001262
1263 final Command cmd = new Command("tether", "start");
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001264 for (String d : dhcpRange) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001265 cmd.appendArg(d);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001266 }
Kenny Roota80ce062010-06-01 13:23:53 -07001267
1268 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001269 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001270 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001271 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001272 }
San Mehat873f2142010-01-14 10:25:07 -08001273 }
1274
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001275 @Override
1276 public void stopTethering() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001277 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001278 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001279 mConnector.execute("tether", "stop");
Kenny Roota80ce062010-06-01 13:23:53 -07001280 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001281 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001282 }
San Mehat873f2142010-01-14 10:25:07 -08001283 }
1284
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001285 @Override
1286 public boolean isTetheringStarted() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001287 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001288
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001289 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001290 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001291 event = mConnector.execute("tether", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001292 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001293 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001294 }
San Mehat873f2142010-01-14 10:25:07 -08001295
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001296 // 210 Tethering services started
1297 event.checkCode(TetherStatusResult);
1298 return event.getMessage().endsWith("started");
San Mehat873f2142010-01-14 10:25:07 -08001299 }
Matthew Xiefe19f122012-07-12 16:03:32 -07001300
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001301 @Override
1302 public void tetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001303 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001304 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001305 mConnector.execute("tether", "interface", "add", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001306 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001307 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001308 }
Christopher Wiley212b95f2016-08-02 11:38:57 -07001309 List<RouteInfo> routes = new ArrayList<>();
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001310 // The RouteInfo constructor truncates the LinkAddress to a network prefix, thus making it
1311 // suitable to use as a route destination.
1312 routes.add(new RouteInfo(getInterfaceConfig(iface).getLinkAddress(), null, iface));
1313 addInterfaceToLocalNetwork(iface, routes);
San Mehat873f2142010-01-14 10:25:07 -08001314 }
1315
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001316 @Override
San Mehat873f2142010-01-14 10:25:07 -08001317 public void untetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001318 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001319 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001320 mConnector.execute("tether", "interface", "remove", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001321 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001322 throw e.rethrowAsParcelableException();
Erik Kline1f4278a2016-08-16 16:46:33 +09001323 } finally {
1324 removeInterfaceFromLocalNetwork(iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001325 }
San Mehat873f2142010-01-14 10:25:07 -08001326 }
1327
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001328 @Override
1329 public String[] listTetheredInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001330 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001331 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001332 return NativeDaemonEvent.filterMessageList(
1333 mConnector.executeForList("tether", "interface", "list"),
1334 TetherInterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001335 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001336 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001337 }
San Mehat873f2142010-01-14 10:25:07 -08001338 }
1339
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001340 @Override
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001341 public void setDnsForwarders(Network network, String[] dns) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001342 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001343
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001344 int netId = (network != null) ? network.netId : ConnectivityManager.NETID_UNSET;
1345 final Command cmd = new Command("tether", "dns", "set", netId);
1346
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001347 for (String s : dns) {
1348 cmd.appendArg(NetworkUtils.numericToInetAddress(s).getHostAddress());
1349 }
1350
San Mehat873f2142010-01-14 10:25:07 -08001351 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001352 mConnector.execute(cmd);
1353 } catch (NativeDaemonConnectorException e) {
1354 throw e.rethrowAsParcelableException();
San Mehat873f2142010-01-14 10:25:07 -08001355 }
1356 }
1357
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001358 @Override
1359 public String[] getDnsForwarders() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001360 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001361 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001362 return NativeDaemonEvent.filterMessageList(
1363 mConnector.executeForList("tether", "dns", "list"), TetherDnsFwdTgtListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001364 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001365 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001366 }
San Mehat873f2142010-01-14 10:25:07 -08001367 }
1368
jiaguo1da35f72014-01-09 16:39:59 +08001369 private List<InterfaceAddress> excludeLinkLocal(List<InterfaceAddress> addresses) {
Christopher Wiley212b95f2016-08-02 11:38:57 -07001370 ArrayList<InterfaceAddress> filtered = new ArrayList<>(addresses.size());
jiaguo1da35f72014-01-09 16:39:59 +08001371 for (InterfaceAddress ia : addresses) {
1372 if (!ia.getAddress().isLinkLocalAddress())
1373 filtered.add(ia);
1374 }
1375 return filtered;
1376 }
1377
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001378 private void modifyInterfaceForward(boolean add, String fromIface, String toIface) {
1379 final Command cmd = new Command("ipfwd", add ? "add" : "remove", fromIface, toIface);
1380 try {
1381 mConnector.execute(cmd);
1382 } catch (NativeDaemonConnectorException e) {
1383 throw e.rethrowAsParcelableException();
1384 }
1385 }
1386
1387 @Override
1388 public void startInterfaceForwarding(String fromIface, String toIface) {
1389 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1390 modifyInterfaceForward(true, fromIface, toIface);
1391 }
1392
1393 @Override
1394 public void stopInterfaceForwarding(String fromIface, String toIface) {
1395 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1396 modifyInterfaceForward(false, fromIface, toIface);
1397 }
1398
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001399 private void modifyNat(String action, String internalInterface, String externalInterface)
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001400 throws SocketException {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001401 final Command cmd = new Command("nat", action, internalInterface, externalInterface);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001402
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001403 final NetworkInterface internalNetworkInterface = NetworkInterface.getByName(
1404 internalInterface);
Robert Greenwalte83d1812011-11-21 14:44:39 -08001405 if (internalNetworkInterface == null) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001406 cmd.appendArg("0");
Robert Greenwalte83d1812011-11-21 14:44:39 -08001407 } else {
jiaguo1da35f72014-01-09 16:39:59 +08001408 // Don't touch link-local routes, as link-local addresses aren't routable,
1409 // kernel creates link-local routes on all interfaces automatically
1410 List<InterfaceAddress> interfaceAddresses = excludeLinkLocal(
1411 internalNetworkInterface.getInterfaceAddresses());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001412 cmd.appendArg(interfaceAddresses.size());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001413 for (InterfaceAddress ia : interfaceAddresses) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001414 InetAddress addr = NetworkUtils.getNetworkPart(
1415 ia.getAddress(), ia.getNetworkPrefixLength());
1416 cmd.appendArg(addr.getHostAddress() + "/" + ia.getNetworkPrefixLength());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001417 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001418 }
1419
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001420 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001421 mConnector.execute(cmd);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001422 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001423 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001424 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001425 }
1426
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001427 @Override
1428 public void enableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001429 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001430 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001431 modifyNat("enable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001432 } catch (SocketException e) {
1433 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001434 }
San Mehat873f2142010-01-14 10:25:07 -08001435 }
1436
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001437 @Override
1438 public void disableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001439 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001440 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001441 modifyNat("disable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001442 } catch (SocketException e) {
1443 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001444 }
San Mehat873f2142010-01-14 10:25:07 -08001445 }
San Mehat72759df2010-01-19 13:50:37 -08001446
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001447 @Override
1448 public String[] listTtys() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001449 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001450 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001451 return NativeDaemonEvent.filterMessageList(
1452 mConnector.executeForList("list_ttys"), TtyListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001453 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001454 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001455 }
San Mehat72759df2010-01-19 13:50:37 -08001456 }
1457
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001458 @Override
1459 public void attachPppd(
1460 String tty, String localAddr, String remoteAddr, String dns1Addr, String dns2Addr) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001461 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat72759df2010-01-19 13:50:37 -08001462 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001463 mConnector.execute("pppd", "attach", tty,
Robert Greenwalte5903732011-02-22 16:00:42 -08001464 NetworkUtils.numericToInetAddress(localAddr).getHostAddress(),
1465 NetworkUtils.numericToInetAddress(remoteAddr).getHostAddress(),
1466 NetworkUtils.numericToInetAddress(dns1Addr).getHostAddress(),
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001467 NetworkUtils.numericToInetAddress(dns2Addr).getHostAddress());
Kenny Roota80ce062010-06-01 13:23:53 -07001468 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001469 throw e.rethrowAsParcelableException();
San Mehat72759df2010-01-19 13:50:37 -08001470 }
1471 }
1472
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001473 @Override
1474 public void detachPppd(String tty) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001475 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001476 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001477 mConnector.execute("pppd", "detach", tty);
Kenny Roota80ce062010-06-01 13:23:53 -07001478 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001479 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001480 }
San Mehat72759df2010-01-19 13:50:37 -08001481 }
Robert Greenwaltce1200d2010-02-18 11:25:54 -08001482
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001483 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001484 public void addIdleTimer(String iface, int timeout, final int type) {
Haoyu Bai04124232012-06-28 15:26:19 -07001485 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1486
1487 if (DBG) Slog.d(TAG, "Adding idletimer");
1488
1489 synchronized (mIdleTimerLock) {
1490 IdleTimerParams params = mActiveIdleTimers.get(iface);
1491 if (params != null) {
1492 // the interface already has idletimer, update network count
1493 params.networkCount++;
1494 return;
1495 }
1496
1497 try {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001498 mConnector.execute("idletimer", "add", iface, Integer.toString(timeout),
1499 Integer.toString(type));
Haoyu Bai04124232012-06-28 15:26:19 -07001500 } catch (NativeDaemonConnectorException e) {
1501 throw e.rethrowAsParcelableException();
1502 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001503 mActiveIdleTimers.put(iface, new IdleTimerParams(timeout, type));
1504
Dianne Hackborne13c4c02014-02-11 17:18:35 -08001505 // Networks start up.
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001506 if (ConnectivityManager.isNetworkTypeMobile(type)) {
1507 mNetworkActive = false;
1508 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001509 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001510 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001511 notifyInterfaceClassActivity(type,
1512 DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001513 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001514 }
1515 });
Haoyu Bai04124232012-06-28 15:26:19 -07001516 }
1517 }
1518
1519 @Override
1520 public void removeIdleTimer(String iface) {
1521 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1522
1523 if (DBG) Slog.d(TAG, "Removing idletimer");
1524
1525 synchronized (mIdleTimerLock) {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001526 final IdleTimerParams params = mActiveIdleTimers.get(iface);
Haoyu Bai04124232012-06-28 15:26:19 -07001527 if (params == null || --(params.networkCount) > 0) {
1528 return;
1529 }
1530
1531 try {
1532 mConnector.execute("idletimer", "remove", iface,
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001533 Integer.toString(params.timeout), Integer.toString(params.type));
Haoyu Bai04124232012-06-28 15:26:19 -07001534 } catch (NativeDaemonConnectorException e) {
1535 throw e.rethrowAsParcelableException();
1536 }
1537 mActiveIdleTimers.remove(iface);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001538 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001539 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001540 notifyInterfaceClassActivity(params.type,
1541 DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001542 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001543 }
1544 });
Haoyu Bai04124232012-06-28 15:26:19 -07001545 }
1546 }
1547
1548 @Override
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001549 public NetworkStats getNetworkStatsSummaryDev() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001550 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001551 try {
1552 return mStatsFactory.readNetworkStatsSummaryDev();
1553 } catch (IOException e) {
1554 throw new IllegalStateException(e);
1555 }
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001556 }
1557
1558 @Override
1559 public NetworkStats getNetworkStatsSummaryXt() {
1560 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001561 try {
1562 return mStatsFactory.readNetworkStatsSummaryXt();
1563 } catch (IOException e) {
1564 throw new IllegalStateException(e);
1565 }
Jeff Sharkeyae2c1812011-10-04 13:11:40 -07001566 }
1567
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001568 @Override
Jeff Sharkey9a13f362011-04-26 16:25:36 -07001569 public NetworkStats getNetworkStatsDetail() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001570 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001571 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001572 return mStatsFactory.readNetworkStatsDetail(UID_ALL, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001573 } catch (IOException e) {
1574 throw new IllegalStateException(e);
1575 }
San Mehat91cac642010-03-31 14:31:36 -07001576 }
1577
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001578 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001579 public void setInterfaceQuota(String iface, long quotaBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001580 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001581
Jeff Sharkey350083e2011-06-29 10:45:16 -07001582 // silently discard when control disabled
1583 // TODO: eventually migrate to be always enabled
1584 if (!mBandwidthControlEnabled) return;
1585
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001586 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001587 if (mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001588 throw new IllegalStateException("iface " + iface + " already has quota");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001589 }
1590
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001591 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001592 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001593 mConnector.execute("bandwidth", "setiquota", iface, quotaBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001594 mActiveQuotas.put(iface, quotaBytes);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001595 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001596 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001597 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001598
1599 synchronized (mTetheringStatsProviders) {
1600 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1601 try {
1602 provider.setInterfaceQuota(iface, quotaBytes);
1603 } catch (RemoteException e) {
1604 Log.e(TAG, "Problem setting tethering data limit on provider " +
1605 mTetheringStatsProviders.get(provider) + ": " + e);
1606 }
1607 }
1608 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001609 }
1610 }
1611
1612 @Override
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001613 public void removeInterfaceQuota(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001614 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001615
Jeff Sharkey350083e2011-06-29 10:45:16 -07001616 // silently discard when control disabled
1617 // TODO: eventually migrate to be always enabled
1618 if (!mBandwidthControlEnabled) return;
1619
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001620 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001621 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001622 // TODO: eventually consider throwing
1623 return;
1624 }
1625
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001626 mActiveQuotas.remove(iface);
1627 mActiveAlerts.remove(iface);
Jeff Sharkey38ddeaa2011-11-08 13:04:22 -08001628
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001629 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001630 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001631 mConnector.execute("bandwidth", "removeiquota", iface);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001632 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001633 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001634 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001635
1636 synchronized (mTetheringStatsProviders) {
1637 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1638 try {
1639 provider.setInterfaceQuota(iface, ITetheringStatsProvider.QUOTA_UNLIMITED);
1640 } catch (RemoteException e) {
1641 Log.e(TAG, "Problem removing tethering data limit on provider " +
1642 mTetheringStatsProviders.get(provider) + ": " + e);
1643 }
1644 }
1645 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001646 }
1647 }
1648
1649 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001650 public void setInterfaceAlert(String iface, long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001651 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001652
1653 // silently discard when control disabled
1654 // TODO: eventually migrate to be always enabled
1655 if (!mBandwidthControlEnabled) return;
1656
1657 // quick sanity check
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001658 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001659 throw new IllegalStateException("setting alert requires existing quota on iface");
1660 }
1661
1662 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001663 if (mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001664 throw new IllegalStateException("iface " + iface + " already has alert");
1665 }
1666
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001667 try {
1668 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001669 mConnector.execute("bandwidth", "setinterfacealert", iface, alertBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001670 mActiveAlerts.put(iface, alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001671 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001672 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001673 }
1674 }
1675 }
1676
1677 @Override
1678 public void removeInterfaceAlert(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001679 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001680
1681 // silently discard when control disabled
1682 // TODO: eventually migrate to be always enabled
1683 if (!mBandwidthControlEnabled) return;
1684
1685 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001686 if (!mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001687 // TODO: eventually consider throwing
1688 return;
1689 }
1690
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001691 try {
1692 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001693 mConnector.execute("bandwidth", "removeinterfacealert", iface);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001694 mActiveAlerts.remove(iface);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001695 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001696 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001697 }
1698 }
1699 }
1700
1701 @Override
1702 public void setGlobalAlert(long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001703 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001704
1705 // silently discard when control disabled
1706 // TODO: eventually migrate to be always enabled
1707 if (!mBandwidthControlEnabled) return;
1708
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001709 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001710 mConnector.execute("bandwidth", "setglobalalert", alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001711 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001712 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001713 }
1714 }
1715
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001716 private void setUidOnMeteredNetworkList(int uid, boolean blacklist, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001717 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001718
Jeff Sharkey350083e2011-06-29 10:45:16 -07001719 // silently discard when control disabled
1720 // TODO: eventually migrate to be always enabled
1721 if (!mBandwidthControlEnabled) return;
1722
Felipe Leme65be3022016-03-22 14:53:13 -07001723 final String chain = blacklist ? "naughtyapps" : "niceapps";
1724 final String suffix = enable ? "add" : "remove";
1725
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001726 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001727 boolean oldEnable;
1728 SparseBooleanArray quotaList;
1729 synchronized (mRulesLock) {
1730 quotaList = blacklist ? mUidRejectOnMetered : mUidAllowOnMetered;
1731 oldEnable = quotaList.get(uid, false);
1732 }
Felipe Leme65be3022016-03-22 14:53:13 -07001733 if (oldEnable == enable) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001734 // TODO: eventually consider throwing
1735 return;
1736 }
1737
Felipe Leme29e72ea2016-09-08 13:26:55 -07001738 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "inetd bandwidth");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001739 try {
Felipe Leme65be3022016-03-22 14:53:13 -07001740 mConnector.execute("bandwidth", suffix + chain, uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001741 synchronized (mRulesLock) {
1742 if (enable) {
1743 quotaList.put(uid, true);
1744 } else {
1745 quotaList.delete(uid);
1746 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001747 }
1748 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001749 throw e.rethrowAsParcelableException();
Felipe Leme29e72ea2016-09-08 13:26:55 -07001750 } finally {
1751 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001752 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001753 }
1754 }
1755
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001756 @Override
Felipe Leme65be3022016-03-22 14:53:13 -07001757 public void setUidMeteredNetworkBlacklist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001758 setUidOnMeteredNetworkList(uid, true, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001759 }
1760
1761 @Override
1762 public void setUidMeteredNetworkWhitelist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001763 setUidOnMeteredNetworkList(uid, false, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001764 }
1765
1766 @Override
1767 public boolean setDataSaverModeEnabled(boolean enable) {
Sehee Parka9139bc2017-12-22 13:54:05 +09001768 mContext.enforceCallingOrSelfPermission(NETWORK_SETTINGS, TAG);
1769
Felipe Leme65be3022016-03-22 14:53:13 -07001770 if (DBG) Log.d(TAG, "setDataSaverMode: " + enable);
1771 synchronized (mQuotaLock) {
1772 if (mDataSaverMode == enable) {
1773 Log.w(TAG, "setDataSaverMode(): already " + mDataSaverMode);
1774 return true;
1775 }
Felipe Leme29e72ea2016-09-08 13:26:55 -07001776 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "bandwidthEnableDataSaver");
Felipe Leme65be3022016-03-22 14:53:13 -07001777 try {
1778 final boolean changed = mNetdService.bandwidthEnableDataSaver(enable);
1779 if (changed) {
1780 mDataSaverMode = enable;
1781 } else {
1782 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command silently failed");
1783 }
1784 return changed;
1785 } catch (RemoteException e) {
1786 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command failed", e);
1787 return false;
Felipe Leme29e72ea2016-09-08 13:26:55 -07001788 } finally {
1789 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Felipe Leme65be3022016-03-22 14:53:13 -07001790 }
1791 }
1792 }
1793
1794 @Override
Robin Lee17e61832016-05-09 13:46:28 +01001795 public void setAllowOnlyVpnForUids(boolean add, UidRange[] uidRanges)
1796 throws ServiceSpecificException {
Rubin Xube806662018-01-11 10:59:19 +00001797 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
1798
Robin Lee17e61832016-05-09 13:46:28 +01001799 try {
1800 mNetdService.networkRejectNonSecureVpn(add, uidRanges);
1801 } catch (ServiceSpecificException e) {
1802 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1803 + ": netd command failed", e);
1804 throw e;
1805 } catch (RemoteException e) {
1806 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1807 + ": netd command failed", e);
1808 throw e.rethrowAsRuntimeException();
1809 }
1810 }
1811
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001812 private void applyUidCleartextNetworkPolicy(int uid, int policy) {
1813 final String policyString;
1814 switch (policy) {
1815 case StrictMode.NETWORK_POLICY_ACCEPT:
1816 policyString = "accept";
1817 break;
1818 case StrictMode.NETWORK_POLICY_LOG:
1819 policyString = "log";
1820 break;
1821 case StrictMode.NETWORK_POLICY_REJECT:
1822 policyString = "reject";
1823 break;
1824 default:
1825 throw new IllegalArgumentException("Unknown policy " + policy);
1826 }
1827
1828 try {
1829 mConnector.execute("strict", "set_uid_cleartext_policy", uid, policyString);
1830 mUidCleartextPolicy.put(uid, policy);
1831 } catch (NativeDaemonConnectorException e) {
1832 throw e.rethrowAsParcelableException();
1833 }
1834 }
1835
Robin Lee17e61832016-05-09 13:46:28 +01001836 @Override
Jeff Sharkey605eb792014-11-04 13:34:06 -08001837 public void setUidCleartextNetworkPolicy(int uid, int policy) {
1838 if (Binder.getCallingUid() != uid) {
1839 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1840 }
1841
1842 synchronized (mQuotaLock) {
1843 final int oldPolicy = mUidCleartextPolicy.get(uid, StrictMode.NETWORK_POLICY_ACCEPT);
1844 if (oldPolicy == policy) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001845 // This also ensures we won't needlessly apply an ACCEPT policy if we've just
1846 // enabled strict and the underlying iptables rules are empty.
Jeff Sharkey605eb792014-11-04 13:34:06 -08001847 return;
1848 }
1849
1850 if (!mStrictEnabled) {
1851 // Module isn't enabled yet; stash the requested policy away to
1852 // apply later once the daemon is connected.
1853 mUidCleartextPolicy.put(uid, policy);
1854 return;
1855 }
1856
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001857 // netd does not keep state on strict mode policies, and cannot replace a non-accept
1858 // policy without deleting it first. Rather than add state to netd, just always send
1859 // it an accept policy when switching between two non-accept policies.
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001860 // TODO: consider keeping state in netd so we can simplify this code.
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001861 if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT &&
1862 policy != StrictMode.NETWORK_POLICY_ACCEPT) {
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001863 applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001864 }
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001865
1866 applyUidCleartextNetworkPolicy(uid, policy);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001867 }
1868 }
1869
1870 @Override
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001871 public boolean isBandwidthControlEnabled() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001872 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001873 return mBandwidthControlEnabled;
1874 }
1875
1876 @Override
Remi NGUYEN VAN088ff682018-03-06 12:36:54 +09001877 public NetworkStats getNetworkStatsUidDetail(int uid, String[] ifaces) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001878 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001879 try {
Remi NGUYEN VAN088ff682018-03-06 12:36:54 +09001880 return mStatsFactory.readNetworkStatsDetail(uid, ifaces, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001881 } catch (IOException e) {
1882 throw new IllegalStateException(e);
1883 }
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001884 }
1885
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001886 private class NetdTetheringStatsProvider extends ITetheringStatsProvider.Stub {
1887 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001888 public NetworkStats getTetherStats(int how) {
1889 // We only need to return per-UID stats. Per-device stats are already counted by
1890 // interface counters.
1891 if (how != STATS_PER_UID) {
1892 return new NetworkStats(SystemClock.elapsedRealtime(), 0);
1893 }
1894
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001895 final PersistableBundle bundle;
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001896 try {
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001897 bundle = mNetdService.tetherGetStats();
1898 } catch (RemoteException | ServiceSpecificException e) {
1899 throw new IllegalStateException("problem parsing tethering stats: ", e);
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001900 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001901
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001902 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(),
1903 bundle.size());
1904 final NetworkStats.Entry entry = new NetworkStats.Entry();
1905
1906 for (String iface : bundle.keySet()) {
1907 long[] statsArray = bundle.getLongArray(iface);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001908 try {
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001909 entry.iface = iface;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001910 entry.uid = UID_TETHERING;
1911 entry.set = SET_DEFAULT;
1912 entry.tag = TAG_NONE;
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001913 entry.rxBytes = statsArray[INetd.TETHER_STATS_RX_BYTES];
1914 entry.rxPackets = statsArray[INetd.TETHER_STATS_RX_PACKETS];
1915 entry.txBytes = statsArray[INetd.TETHER_STATS_TX_BYTES];
1916 entry.txPackets = statsArray[INetd.TETHER_STATS_TX_PACKETS];
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001917 stats.combineValues(entry);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001918 } catch (ArrayIndexOutOfBoundsException e) {
1919 throw new IllegalStateException("invalid tethering stats for " + iface, e);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001920 }
1921 }
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001922
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001923 return stats;
1924 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001925
1926 @Override
1927 public void setInterfaceQuota(String iface, long quotaBytes) {
1928 // Do nothing. netd is already informed of quota changes in setInterfaceQuota.
1929 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001930 }
1931
1932 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001933 public NetworkStats getNetworkStatsTethering(int how) {
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001934 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1935
1936 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
1937 synchronized (mTetheringStatsProviders) {
1938 for (ITetheringStatsProvider provider: mTetheringStatsProviders.keySet()) {
1939 try {
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001940 stats.combineAllValues(provider.getTetherStats(how));
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001941 } catch (RemoteException e) {
1942 Log.e(TAG, "Problem reading tethering stats from " +
1943 mTetheringStatsProviders.get(provider) + ": " + e);
1944 }
1945 }
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001946 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001947 return stats;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001948 }
1949
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001950 @Override
Erik Kline1742fe12017-12-13 19:40:49 +09001951 public void setDnsConfigurationForNetwork(int netId, String[] servers, String[] domains,
Erik Klinee5dac902018-03-04 21:01:01 +09001952 int[] params, String tlsHostname, String[] tlsServers) {
Pierre Imai8e48e672016-04-21 13:30:43 +09001953 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1954
Ben Schwartz6ec28df2017-10-02 13:08:06 -04001955 final String[] tlsFingerprints = new String[0];
Pierre Imai8e48e672016-04-21 13:30:43 +09001956 try {
Erik Kline1742fe12017-12-13 19:40:49 +09001957 mNetdService.setResolverConfiguration(
Erik Klinee5dac902018-03-04 21:01:01 +09001958 netId, servers, domains, params, tlsHostname, tlsServers, tlsFingerprints);
Pierre Imai8e48e672016-04-21 13:30:43 +09001959 } catch (RemoteException e) {
1960 throw new RuntimeException(e);
1961 }
1962 }
1963
1964 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001965 public void addVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001966 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001967 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
1968 argv[0] = "users";
1969 argv[1] = "add";
1970 argv[2] = netId;
1971 int argc = 3;
1972 // Avoid overly long commands by limiting number of UID ranges per command.
1973 for (int i = 0; i < ranges.length; i++) {
1974 argv[argc++] = ranges[i].toString();
1975 if (i == (ranges.length - 1) || argc == argv.length) {
1976 try {
1977 mConnector.execute("network", Arrays.copyOf(argv, argc));
1978 } catch (NativeDaemonConnectorException e) {
1979 throw e.rethrowAsParcelableException();
1980 }
1981 argc = 3;
1982 }
Chad Brubaker3277620a2013-06-12 13:37:30 -07001983 }
1984 }
1985
1986 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001987 public void removeVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001988 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001989 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
1990 argv[0] = "users";
1991 argv[1] = "remove";
1992 argv[2] = netId;
1993 int argc = 3;
1994 // Avoid overly long commands by limiting number of UID ranges per command.
1995 for (int i = 0; i < ranges.length; i++) {
1996 argv[argc++] = ranges[i].toString();
1997 if (i == (ranges.length - 1) || argc == argv.length) {
1998 try {
1999 mConnector.execute("network", Arrays.copyOf(argv, argc));
2000 } catch (NativeDaemonConnectorException e) {
2001 throw e.rethrowAsParcelableException();
2002 }
2003 argc = 3;
2004 }
Chad Brubakercca54c42013-06-27 17:41:38 -07002005 }
2006 }
2007
2008 @Override
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002009 public void setFirewallEnabled(boolean enabled) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002010 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002011 try {
Amith Yamasani15e472352015-04-24 19:06:07 -07002012 mConnector.execute("firewall", "enable", enabled ? "whitelist" : "blacklist");
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002013 mFirewallEnabled = enabled;
2014 } catch (NativeDaemonConnectorException e) {
2015 throw e.rethrowAsParcelableException();
2016 }
2017 }
2018
2019 @Override
2020 public boolean isFirewallEnabled() {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002021 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002022 return mFirewallEnabled;
2023 }
2024
2025 @Override
Jeff Sharkey2c092982012-08-24 11:44:40 -07002026 public void setFirewallInterfaceRule(String iface, boolean allow) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002027 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002028 Preconditions.checkState(mFirewallEnabled);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002029 final String rule = allow ? "allow" : "deny";
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002030 try {
2031 mConnector.execute("firewall", "set_interface_rule", iface, rule);
2032 } catch (NativeDaemonConnectorException e) {
2033 throw e.rethrowAsParcelableException();
2034 }
2035 }
2036
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002037 private void closeSocketsForFirewallChainLocked(int chain, String chainName) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002038 // UID ranges to close sockets on.
2039 UidRange[] ranges;
2040 // UID ranges whose sockets we won't touch.
2041 int[] exemptUids;
2042
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002043 int numUids = 0;
2044
2045 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2046 // Close all sockets on all non-system UIDs...
2047 ranges = new UidRange[] {
2048 // TODO: is there a better way of finding all existing users? If so, we could
2049 // specify their ranges here.
2050 new UidRange(Process.FIRST_APPLICATION_UID, Integer.MAX_VALUE),
2051 };
2052 // ... except for the UIDs that have allow rules.
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002053 synchronized (mRulesLock) {
2054 final SparseIntArray rules = getUidFirewallRulesLR(chain);
2055 exemptUids = new int[rules.size()];
2056 for (int i = 0; i < exemptUids.length; i++) {
2057 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2058 exemptUids[numUids] = rules.keyAt(i);
2059 numUids++;
2060 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002061 }
2062 }
2063 // Normally, whitelist chains only contain deny rules, so numUids == exemptUids.length.
2064 // But the code does not guarantee this in any way, and at least in one case - if we add
2065 // a UID rule to the firewall, and then disable the firewall - the chains can contain
2066 // the wrong type of rule. In this case, don't close connections that we shouldn't.
2067 //
2068 // TODO: tighten up this code by ensuring we never set the wrong type of rule, and
2069 // fix setFirewallEnabled to grab mQuotaLock and clear rules.
2070 if (numUids != exemptUids.length) {
2071 exemptUids = Arrays.copyOf(exemptUids, numUids);
2072 }
2073 } else {
2074 // Close sockets for every UID that has a deny rule...
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002075 synchronized (mRulesLock) {
2076 final SparseIntArray rules = getUidFirewallRulesLR(chain);
2077 ranges = new UidRange[rules.size()];
2078 for (int i = 0; i < ranges.length; i++) {
2079 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2080 int uid = rules.keyAt(i);
2081 ranges[numUids] = new UidRange(uid, uid);
2082 numUids++;
2083 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002084 }
2085 }
2086 // As above; usually numUids == ranges.length, but not always.
2087 if (numUids != ranges.length) {
2088 ranges = Arrays.copyOf(ranges, numUids);
2089 }
2090 // ... with no exceptions.
2091 exemptUids = new int[0];
2092 }
2093
2094 try {
2095 mNetdService.socketDestroy(ranges, exemptUids);
2096 } catch(RemoteException | ServiceSpecificException e) {
2097 Slog.e(TAG, "Error closing sockets after enabling chain " + chainName + ": " + e);
2098 }
2099 }
2100
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002101 @Override
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002102 public void setFirewallChainEnabled(int chain, boolean enable) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002103 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002104 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002105 synchronized (mRulesLock) {
2106 if (getFirewallChainState(chain) == enable) {
2107 // All is the same, nothing to do. This relies on the fact that netd has child
2108 // chains default detached.
2109 return;
2110 }
2111 setFirewallChainState(chain, enable);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002112 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002113
2114 final String operation = enable ? "enable_chain" : "disable_chain";
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002115 final String chainName;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002116 switch(chain) {
2117 case FIREWALL_CHAIN_STANDBY:
2118 chainName = FIREWALL_CHAIN_NAME_STANDBY;
2119 break;
2120 case FIREWALL_CHAIN_DOZABLE:
2121 chainName = FIREWALL_CHAIN_NAME_DOZABLE;
2122 break;
2123 case FIREWALL_CHAIN_POWERSAVE:
2124 chainName = FIREWALL_CHAIN_NAME_POWERSAVE;
2125 break;
2126 default:
2127 throw new IllegalArgumentException("Bad child chain: " + chain);
2128 }
2129
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002130 try {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002131 mConnector.execute("firewall", operation, chainName);
2132 } catch (NativeDaemonConnectorException e) {
2133 throw e.rethrowAsParcelableException();
2134 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002135
2136 // Close any sockets that were opened by the affected UIDs. This has to be done after
2137 // disabling network connectivity, in case they react to the socket close by reopening
2138 // the connection and race with the iptables commands that enable the firewall. All
2139 // whitelist and blacklist chains allow RSTs through.
2140 if (enable) {
2141 if (DBG) Slog.d(TAG, "Closing sockets after enabling chain " + chainName);
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002142 closeSocketsForFirewallChainLocked(chain, chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002143 }
Amith Yamasani15e472352015-04-24 19:06:07 -07002144 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002145 }
2146
2147 private int getFirewallType(int chain) {
2148 switch (chain) {
2149 case FIREWALL_CHAIN_STANDBY:
2150 return FIREWALL_TYPE_BLACKLIST;
2151 case FIREWALL_CHAIN_DOZABLE:
2152 return FIREWALL_TYPE_WHITELIST;
Felipe Leme011b98f2016-02-10 17:28:31 -08002153 case FIREWALL_CHAIN_POWERSAVE:
2154 return FIREWALL_TYPE_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002155 default:
2156 return isFirewallEnabled() ? FIREWALL_TYPE_WHITELIST : FIREWALL_TYPE_BLACKLIST;
2157 }
2158 }
2159
2160 @Override
2161 public void setFirewallUidRules(int chain, int[] uids, int[] rules) {
2162 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002163 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002164 synchronized (mRulesLock) {
2165 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
2166 SparseIntArray newRules = new SparseIntArray();
2167 // apply new set of rules
2168 for (int index = uids.length - 1; index >= 0; --index) {
2169 int uid = uids[index];
2170 int rule = rules[index];
2171 updateFirewallUidRuleLocked(chain, uid, rule);
2172 newRules.put(uid, rule);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002173 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002174 // collect the rules to remove.
2175 SparseIntArray rulesToRemove = new SparseIntArray();
2176 for (int index = uidFirewallRules.size() - 1; index >= 0; --index) {
2177 int uid = uidFirewallRules.keyAt(index);
2178 if (newRules.indexOfKey(uid) < 0) {
2179 rulesToRemove.put(uid, FIREWALL_RULE_DEFAULT);
2180 }
2181 }
2182 // remove dead rules
2183 for (int index = rulesToRemove.size() - 1; index >= 0; --index) {
2184 int uid = rulesToRemove.keyAt(index);
2185 updateFirewallUidRuleLocked(chain, uid, FIREWALL_RULE_DEFAULT);
2186 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002187 }
2188 try {
2189 switch (chain) {
2190 case FIREWALL_CHAIN_DOZABLE:
2191 mNetdService.firewallReplaceUidChain("fw_dozable", true, uids);
2192 break;
2193 case FIREWALL_CHAIN_STANDBY:
2194 mNetdService.firewallReplaceUidChain("fw_standby", false, uids);
2195 break;
2196 case FIREWALL_CHAIN_POWERSAVE:
2197 mNetdService.firewallReplaceUidChain("fw_powersave", true, uids);
2198 break;
2199 case FIREWALL_CHAIN_NONE:
2200 default:
2201 Slog.d(TAG, "setFirewallUidRules() called on invalid chain: " + chain);
2202 }
2203 } catch (RemoteException e) {
2204 Slog.w(TAG, "Error flushing firewall chain " + chain, e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002205 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002206 }
2207 }
2208
2209 @Override
2210 public void setFirewallUidRule(int chain, int uid, int rule) {
2211 enforceSystemUid();
Felipe Lemea701cad2016-05-12 09:58:14 -07002212 synchronized (mQuotaLock) {
2213 setFirewallUidRuleLocked(chain, uid, rule);
2214 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002215 }
2216
Felipe Lemea701cad2016-05-12 09:58:14 -07002217 private void setFirewallUidRuleLocked(int chain, int uid, int rule) {
2218 if (updateFirewallUidRuleLocked(chain, uid, rule)) {
Amith Yamasani15e472352015-04-24 19:06:07 -07002219 try {
Felipe Lemea701cad2016-05-12 09:58:14 -07002220 mConnector.execute("firewall", "set_uid_rule", getFirewallChainName(chain), uid,
2221 getFirewallRuleName(chain, rule));
Amith Yamasani15e472352015-04-24 19:06:07 -07002222 } catch (NativeDaemonConnectorException e) {
2223 throw e.rethrowAsParcelableException();
2224 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002225 }
2226 }
2227
Felipe Lemea701cad2016-05-12 09:58:14 -07002228 // TODO: now that netd supports batching, NMS should not keep these data structures anymore...
2229 private boolean updateFirewallUidRuleLocked(int chain, int uid, int rule) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002230 synchronized (mRulesLock) {
2231 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Felipe Lemea701cad2016-05-12 09:58:14 -07002232
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002233 final int oldUidFirewallRule = uidFirewallRules.get(uid, FIREWALL_RULE_DEFAULT);
2234 if (DBG) {
2235 Slog.d(TAG, "oldRule = " + oldUidFirewallRule
2236 + ", newRule=" + rule + " for uid=" + uid + " on chain " + chain);
2237 }
2238 if (oldUidFirewallRule == rule) {
2239 if (DBG) Slog.d(TAG, "!!!!! Skipping change");
2240 // TODO: eventually consider throwing
2241 return false;
2242 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002243
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002244 String ruleName = getFirewallRuleName(chain, rule);
2245 String oldRuleName = getFirewallRuleName(chain, oldUidFirewallRule);
Felipe Lemea701cad2016-05-12 09:58:14 -07002246
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002247 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
2248 uidFirewallRules.delete(uid);
2249 } else {
2250 uidFirewallRules.put(uid, rule);
2251 }
2252 return !ruleName.equals(oldRuleName);
Felipe Lemea701cad2016-05-12 09:58:14 -07002253 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002254 }
2255
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002256 private @NonNull String getFirewallRuleName(int chain, int rule) {
2257 String ruleName;
2258 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2259 if (rule == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2260 ruleName = "allow";
2261 } else {
2262 ruleName = "deny";
2263 }
2264 } else { // Blacklist mode
2265 if (rule == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2266 ruleName = "deny";
2267 } else {
2268 ruleName = "allow";
2269 }
2270 }
2271 return ruleName;
2272 }
2273
Andreas Gampeaae5aa32018-07-20 12:55:38 -07002274 @GuardedBy("mRulesLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002275 private @NonNull SparseIntArray getUidFirewallRulesLR(int chain) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002276 switch (chain) {
2277 case FIREWALL_CHAIN_STANDBY:
2278 return mUidFirewallStandbyRules;
2279 case FIREWALL_CHAIN_DOZABLE:
2280 return mUidFirewallDozableRules;
Felipe Leme011b98f2016-02-10 17:28:31 -08002281 case FIREWALL_CHAIN_POWERSAVE:
2282 return mUidFirewallPowerSaveRules;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002283 case FIREWALL_CHAIN_NONE:
2284 return mUidFirewallRules;
2285 default:
2286 throw new IllegalArgumentException("Unknown chain:" + chain);
2287 }
2288 }
2289
2290 public @NonNull String getFirewallChainName(int chain) {
2291 switch (chain) {
2292 case FIREWALL_CHAIN_STANDBY:
2293 return FIREWALL_CHAIN_NAME_STANDBY;
2294 case FIREWALL_CHAIN_DOZABLE:
2295 return FIREWALL_CHAIN_NAME_DOZABLE;
Felipe Leme011b98f2016-02-10 17:28:31 -08002296 case FIREWALL_CHAIN_POWERSAVE:
2297 return FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002298 case FIREWALL_CHAIN_NONE:
2299 return FIREWALL_CHAIN_NAME_NONE;
2300 default:
2301 throw new IllegalArgumentException("Unknown chain:" + chain);
2302 }
2303 }
2304
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002305 private static void enforceSystemUid() {
2306 final int uid = Binder.getCallingUid();
2307 if (uid != Process.SYSTEM_UID) {
2308 throw new SecurityException("Only available to AID_SYSTEM");
2309 }
2310 }
2311
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002312 @Override
Lorenzo Colitti79751842013-02-28 16:16:03 +09002313 public void startClatd(String interfaceName) throws IllegalStateException {
2314 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2315
2316 try {
2317 mConnector.execute("clatd", "start", interfaceName);
2318 } catch (NativeDaemonConnectorException e) {
2319 throw e.rethrowAsParcelableException();
2320 }
2321 }
2322
2323 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002324 public void stopClatd(String interfaceName) throws IllegalStateException {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002325 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2326
2327 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002328 mConnector.execute("clatd", "stop", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002329 } catch (NativeDaemonConnectorException e) {
2330 throw e.rethrowAsParcelableException();
2331 }
2332 }
2333
2334 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002335 public boolean isClatdStarted(String interfaceName) {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002336 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2337
2338 final NativeDaemonEvent event;
2339 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002340 event = mConnector.execute("clatd", "status", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002341 } catch (NativeDaemonConnectorException e) {
2342 throw e.rethrowAsParcelableException();
2343 }
2344
2345 event.checkCode(ClatdStatusResult);
2346 return event.getMessage().endsWith("started");
2347 }
2348
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002349 @Override
2350 public void registerNetworkActivityListener(INetworkActivityListener listener) {
2351 mNetworkActivityListeners.register(listener);
2352 }
2353
2354 @Override
2355 public void unregisterNetworkActivityListener(INetworkActivityListener listener) {
2356 mNetworkActivityListeners.unregister(listener);
2357 }
2358
2359 @Override
2360 public boolean isNetworkActive() {
2361 synchronized (mNetworkActivityListeners) {
2362 return mNetworkActive || mActiveIdleTimers.isEmpty();
2363 }
2364 }
2365
2366 private void reportNetworkActive() {
2367 final int length = mNetworkActivityListeners.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002368 try {
2369 for (int i = 0; i < length; i++) {
2370 try {
2371 mNetworkActivityListeners.getBroadcastItem(i).onNetworkActive();
Felipe Leme03e689d2016-03-02 16:17:38 -08002372 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002373 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002374 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002375 } finally {
2376 mNetworkActivityListeners.finishBroadcast();
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002377 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002378 }
2379
Mattias Falk8b47b362011-08-23 14:15:13 +02002380 /** {@inheritDoc} */
Jeff Sharkey7b4596f2013-02-25 10:55:29 -08002381 @Override
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -07002382 public void monitor() {
2383 if (mConnector != null) {
2384 mConnector.monitor();
2385 }
2386 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002387
2388 @Override
2389 protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -06002390 if (!DumpUtils.checkDumpPermission(mContext, TAG, pw)) return;
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002391
Robert Greenwalt470fd722012-01-18 12:51:15 -08002392 pw.println("NetworkManagementService NativeDaemonConnector Log:");
2393 mConnector.dump(fd, pw, args);
2394 pw.println();
2395
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002396 pw.print("Bandwidth control enabled: "); pw.println(mBandwidthControlEnabled);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07002397 pw.print("mMobileActivityFromRadio="); pw.print(mMobileActivityFromRadio);
2398 pw.print(" mLastPowerStateFromRadio="); pw.println(mLastPowerStateFromRadio);
2399 pw.print("mNetworkActive="); pw.println(mNetworkActive);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002400
2401 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07002402 pw.print("Active quota ifaces: "); pw.println(mActiveQuotas.toString());
2403 pw.print("Active alert ifaces: "); pw.println(mActiveAlerts.toString());
Felipe Leme65be3022016-03-22 14:53:13 -07002404 pw.print("Data saver mode: "); pw.println(mDataSaverMode);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002405 synchronized (mRulesLock) {
2406 dumpUidRuleOnQuotaLocked(pw, "blacklist", mUidRejectOnMetered);
2407 dumpUidRuleOnQuotaLocked(pw, "whitelist", mUidAllowOnMetered);
2408 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002409 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002410
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002411 synchronized (mRulesLock) {
Felipe Leme011b98f2016-02-10 17:28:31 -08002412 dumpUidFirewallRule(pw, "", mUidFirewallRules);
Amith Yamasani15e472352015-04-24 19:06:07 -07002413
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002414 pw.print("UID firewall standby chain enabled: "); pw.println(
2415 getFirewallChainState(FIREWALL_CHAIN_STANDBY));
Felipe Leme011b98f2016-02-10 17:28:31 -08002416 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_STANDBY, mUidFirewallStandbyRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002417
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002418 pw.print("UID firewall dozable chain enabled: "); pw.println(
2419 getFirewallChainState(FIREWALL_CHAIN_DOZABLE));
Felipe Leme011b98f2016-02-10 17:28:31 -08002420 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_DOZABLE, mUidFirewallDozableRules);
Felipe Leme011b98f2016-02-10 17:28:31 -08002421
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002422 pw.println("UID firewall powersave chain enabled: " +
2423 getFirewallChainState(FIREWALL_CHAIN_POWERSAVE));
Felipe Leme011b98f2016-02-10 17:28:31 -08002424 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_POWERSAVE, mUidFirewallPowerSaveRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002425 }
2426
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002427 synchronized (mIdleTimerLock) {
2428 pw.println("Idle timers:");
2429 for (HashMap.Entry<String, IdleTimerParams> ent : mActiveIdleTimers.entrySet()) {
2430 pw.print(" "); pw.print(ent.getKey()); pw.println(":");
2431 IdleTimerParams params = ent.getValue();
2432 pw.print(" timeout="); pw.print(params.timeout);
2433 pw.print(" type="); pw.print(params.type);
2434 pw.print(" networkCount="); pw.println(params.networkCount);
2435 }
2436 }
2437
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002438 pw.print("Firewall enabled: "); pw.println(mFirewallEnabled);
Felipe Leme65be3022016-03-22 14:53:13 -07002439 pw.print("Netd service status: " );
2440 if (mNetdService == null) {
2441 pw.println("disconnected");
2442 } else {
2443 try {
2444 final boolean alive = mNetdService.isAlive();
2445 pw.println(alive ? "alive": "dead");
2446 } catch (RemoteException e) {
2447 pw.println("unreachable");
2448 }
2449 }
2450 }
2451
2452 private void dumpUidRuleOnQuotaLocked(PrintWriter pw, String name, SparseBooleanArray list) {
2453 pw.print("UID bandwith control ");
2454 pw.print(name);
2455 pw.print(" rule: [");
2456 final int size = list.size();
2457 for (int i = 0; i < size; i++) {
2458 pw.print(list.keyAt(i));
2459 if (i < size - 1) pw.print(",");
2460 }
2461 pw.println("]");
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002462 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002463
Felipe Leme011b98f2016-02-10 17:28:31 -08002464 private void dumpUidFirewallRule(PrintWriter pw, String name, SparseIntArray rules) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002465 pw.print("UID firewall ");
Felipe Leme011b98f2016-02-10 17:28:31 -08002466 pw.print(name);
2467 pw.print(" rule: [");
2468 final int size = rules.size();
2469 for (int i = 0; i < size; i++) {
2470 pw.print(rules.keyAt(i));
2471 pw.print(":");
2472 pw.print(rules.valueAt(i));
2473 if (i < size - 1) pw.print(",");
2474 }
2475 pw.println("]");
2476 }
2477
Robert Greenwalt568891d2014-04-04 13:38:00 -07002478 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002479 public void createPhysicalNetwork(int netId, String permission) {
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002480 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2481
2482 try {
Paul Jensen487ffe72015-07-24 15:57:11 -04002483 if (permission != null) {
2484 mConnector.execute("network", "create", netId, permission);
2485 } else {
2486 mConnector.execute("network", "create", netId);
2487 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002488 } catch (NativeDaemonConnectorException e) {
2489 throw e.rethrowAsParcelableException();
2490 }
2491 }
2492
Robert Greenwalt568891d2014-04-04 13:38:00 -07002493 @Override
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002494 public void createVirtualNetwork(int netId, boolean hasDNS, boolean secure) {
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002495 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2496
2497 try {
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002498 mConnector.execute("network", "create", netId, "vpn", hasDNS ? "1" : "0",
2499 secure ? "1" : "0");
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002500 } catch (NativeDaemonConnectorException e) {
2501 throw e.rethrowAsParcelableException();
2502 }
2503 }
2504
2505 @Override
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002506 public void removeNetwork(int netId) {
Erik Kline33d8e5c2018-01-15 17:05:07 +09002507 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002508
2509 try {
Erik Kline33d8e5c2018-01-15 17:05:07 +09002510 mNetdService.networkDestroy(netId);
2511 } catch (ServiceSpecificException e) {
2512 Log.w(TAG, "removeNetwork(" + netId + "): ", e);
2513 throw e;
2514 } catch (RemoteException e) {
2515 Log.w(TAG, "removeNetwork(" + netId + "): ", e);
2516 throw e.rethrowAsRuntimeException();
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002517 }
2518 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002519
2520 @Override
Paul Jensen992f2522014-04-28 10:33:11 -04002521 public void addInterfaceToNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002522 modifyInterfaceInNetwork("add", "" + netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002523 }
2524
2525 @Override
2526 public void removeInterfaceFromNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002527 modifyInterfaceInNetwork("remove", "" + netId, iface);
2528 }
Paul Jensen992f2522014-04-28 10:33:11 -04002529
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002530 private void modifyInterfaceInNetwork(String action, String netId, String iface) {
2531 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen992f2522014-04-28 10:33:11 -04002532 try {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002533 mConnector.execute("network", "interface", action, netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002534 } catch (NativeDaemonConnectorException e) {
2535 throw e.rethrowAsParcelableException();
2536 }
2537 }
2538
2539 @Override
Robert Greenwalt913c8952014-04-07 17:36:35 -07002540 public void addLegacyRouteForNetId(int netId, RouteInfo routeInfo, int uid) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002541 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2542
Sreeram Ramachandran03666c72014-07-19 23:21:46 -07002543 final Command cmd = new Command("network", "route", "legacy", uid, "add", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002544
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002545 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandrancc91c7b2014-06-03 18:41:43 -07002546 final LinkAddress la = routeInfo.getDestinationLinkAddress();
Robert Greenwalt568891d2014-04-04 13:38:00 -07002547 cmd.appendArg(routeInfo.getInterface());
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09002548 cmd.appendArg(la.getAddress().getHostAddress() + "/" + la.getPrefixLength());
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002549 if (routeInfo.hasGateway()) {
2550 cmd.appendArg(routeInfo.getGateway().getHostAddress());
2551 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002552
2553 try {
2554 mConnector.execute(cmd);
2555 } catch (NativeDaemonConnectorException e) {
2556 throw e.rethrowAsParcelableException();
2557 }
2558 }
2559
2560 @Override
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002561 public void setDefaultNetId(int netId) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002562 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2563
2564 try {
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002565 mConnector.execute("network", "default", "set", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002566 } catch (NativeDaemonConnectorException e) {
2567 throw e.rethrowAsParcelableException();
2568 }
2569 }
2570
2571 @Override
2572 public void clearDefaultNetId() {
2573 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2574
2575 try {
2576 mConnector.execute("network", "default", "clear");
2577 } catch (NativeDaemonConnectorException e) {
2578 throw e.rethrowAsParcelableException();
2579 }
2580 }
2581
2582 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002583 public void setNetworkPermission(int netId, String permission) {
2584 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2585
2586 try {
2587 if (permission != null) {
2588 mConnector.execute("network", "permission", "network", "set", permission, netId);
2589 } else {
2590 mConnector.execute("network", "permission", "network", "clear", netId);
2591 }
2592 } catch (NativeDaemonConnectorException e) {
2593 throw e.rethrowAsParcelableException();
2594 }
2595 }
2596
2597
2598 @Override
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002599 public void setPermission(String permission, int[] uids) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002600 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2601
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002602 Object[] argv = new Object[4 + MAX_UID_RANGES_PER_COMMAND];
2603 argv[0] = "permission";
2604 argv[1] = "user";
2605 argv[2] = "set";
2606 argv[3] = permission;
2607 int argc = 4;
2608 // Avoid overly long commands by limiting number of UIDs per command.
2609 for (int i = 0; i < uids.length; ++i) {
2610 argv[argc++] = uids[i];
2611 if (i == uids.length - 1 || argc == argv.length) {
2612 try {
2613 mConnector.execute("network", Arrays.copyOf(argv, argc));
2614 } catch (NativeDaemonConnectorException e) {
2615 throw e.rethrowAsParcelableException();
2616 }
2617 argc = 4;
2618 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002619 }
2620 }
2621
2622 @Override
2623 public void clearPermission(int[] uids) {
2624 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2625
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002626 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
2627 argv[0] = "permission";
2628 argv[1] = "user";
2629 argv[2] = "clear";
2630 int argc = 3;
2631 // Avoid overly long commands by limiting number of UIDs per command.
2632 for (int i = 0; i < uids.length; ++i) {
2633 argv[argc++] = uids[i];
2634 if (i == uids.length - 1 || argc == argv.length) {
2635 try {
2636 mConnector.execute("network", Arrays.copyOf(argv, argc));
2637 } catch (NativeDaemonConnectorException e) {
2638 throw e.rethrowAsParcelableException();
2639 }
2640 argc = 3;
2641 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002642 }
2643 }
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002644
2645 @Override
2646 public void allowProtect(int uid) {
2647 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2648
2649 try {
2650 mConnector.execute("network", "protect", "allow", uid);
2651 } catch (NativeDaemonConnectorException e) {
2652 throw e.rethrowAsParcelableException();
2653 }
2654 }
2655
2656 @Override
2657 public void denyProtect(int uid) {
2658 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2659
2660 try {
2661 mConnector.execute("network", "protect", "deny", uid);
2662 } catch (NativeDaemonConnectorException e) {
2663 throw e.rethrowAsParcelableException();
2664 }
2665 }
2666
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002667 @Override
2668 public void addInterfaceToLocalNetwork(String iface, List<RouteInfo> routes) {
2669 modifyInterfaceInNetwork("add", "local", iface);
2670
2671 for (RouteInfo route : routes) {
2672 if (!route.isDefaultRoute()) {
2673 modifyRoute("add", "local", route);
2674 }
2675 }
2676 }
2677
2678 @Override
2679 public void removeInterfaceFromLocalNetwork(String iface) {
2680 modifyInterfaceInNetwork("remove", "local", iface);
2681 }
Erik Kline6599ee82016-07-17 21:28:39 +09002682
2683 @Override
2684 public int removeRoutesFromLocalNetwork(List<RouteInfo> routes) {
2685 int failures = 0;
2686
2687 for (RouteInfo route : routes) {
2688 try {
2689 modifyRoute("remove", "local", route);
2690 } catch (IllegalStateException e) {
2691 failures++;
2692 }
2693 }
2694
2695 return failures;
2696 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002697
Sudheer Shankab8f23162017-08-04 13:30:10 -07002698 @Override
2699 public boolean isNetworkRestricted(int uid) {
2700 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2701 return isNetworkRestrictedInternal(uid);
2702 }
2703
2704 private boolean isNetworkRestrictedInternal(int uid) {
2705 synchronized (mRulesLock) {
2706 if (getFirewallChainState(FIREWALL_CHAIN_STANDBY)
2707 && mUidFirewallStandbyRules.get(uid) == FIREWALL_RULE_DENY) {
2708 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of app standby mode");
2709 return true;
2710 }
2711 if (getFirewallChainState(FIREWALL_CHAIN_DOZABLE)
2712 && mUidFirewallDozableRules.get(uid) != FIREWALL_RULE_ALLOW) {
2713 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of device idle mode");
2714 return true;
2715 }
2716 if (getFirewallChainState(FIREWALL_CHAIN_POWERSAVE)
2717 && mUidFirewallPowerSaveRules.get(uid) != FIREWALL_RULE_ALLOW) {
2718 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of power saver mode");
2719 return true;
2720 }
2721 if (mUidRejectOnMetered.get(uid)) {
2722 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of no metered data"
2723 + " in the background");
2724 return true;
2725 }
2726 if (mDataSaverMode && !mUidAllowOnMetered.get(uid)) {
2727 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of data saver mode");
2728 return true;
2729 }
2730 return false;
2731 }
2732 }
2733
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002734 private void setFirewallChainState(int chain, boolean state) {
2735 synchronized (mRulesLock) {
2736 mFirewallChainStates.put(chain, state);
2737 }
2738 }
2739
2740 private boolean getFirewallChainState(int chain) {
2741 synchronized (mRulesLock) {
2742 return mFirewallChainStates.get(chain);
2743 }
2744 }
2745
2746 @VisibleForTesting
2747 class LocalService extends NetworkManagementInternal {
2748 @Override
2749 public boolean isNetworkRestrictedForUid(int uid) {
Sudheer Shankab8f23162017-08-04 13:30:10 -07002750 return isNetworkRestrictedInternal(uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002751 }
2752 }
2753
2754 @VisibleForTesting
2755 Injector getInjector() {
2756 return new Injector();
2757 }
2758
2759 @VisibleForTesting
2760 class Injector {
2761 void setDataSaverMode(boolean dataSaverMode) {
2762 mDataSaverMode = dataSaverMode;
2763 }
2764
2765 void setFirewallChainState(int chain, boolean state) {
2766 NetworkManagementService.this.setFirewallChainState(chain, state);
2767 }
2768
2769 void setFirewallRule(int chain, int uid, int rule) {
2770 synchronized (mRulesLock) {
2771 getUidFirewallRulesLR(chain).put(uid, rule);
2772 }
2773 }
2774
2775 void setUidOnMeteredNetworkList(boolean blacklist, int uid, boolean enable) {
2776 synchronized (mRulesLock) {
2777 if (blacklist) {
2778 mUidRejectOnMetered.put(uid, enable);
2779 } else {
2780 mUidAllowOnMetered.put(uid, enable);
2781 }
2782 }
2783 }
2784
2785 void reset() {
2786 synchronized (mRulesLock) {
2787 setDataSaverMode(false);
2788 final int[] chains = {
2789 FIREWALL_CHAIN_DOZABLE,
2790 FIREWALL_CHAIN_STANDBY,
2791 FIREWALL_CHAIN_POWERSAVE
2792 };
2793 for (int chain : chains) {
2794 setFirewallChainState(chain, false);
2795 getUidFirewallRulesLR(chain).clear();
2796 }
2797 mUidAllowOnMetered.clear();
2798 mUidRejectOnMetered.clear();
2799 }
2800 }
2801 }
San Mehat873f2142010-01-14 10:25:07 -08002802}