blob: 7f19f0610ef10a3ceb45327291fc2f45cef77b88 [file] [log] [blame]
San Mehat873f2142010-01-14 10:25:07 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Jeff Sharkey4529bb62011-12-14 10:31:54 -080019import static android.Manifest.permission.CONNECTIVITY_INTERNAL;
Sehee Parka9139bc2017-12-22 13:54:05 +090020import static android.Manifest.permission.NETWORK_SETTINGS;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090021import static android.Manifest.permission.NETWORK_STACK;
Jeff Sharkeyaf75c332011-11-18 12:41:12 -080022import static android.Manifest.permission.SHUTDOWN;
Remi NGUYEN VANdacee142019-02-13 18:28:35 +090023import static android.net.INetd.FIREWALL_BLACKLIST;
24import static android.net.INetd.FIREWALL_CHAIN_DOZABLE;
25import static android.net.INetd.FIREWALL_CHAIN_NONE;
26import static android.net.INetd.FIREWALL_CHAIN_POWERSAVE;
27import static android.net.INetd.FIREWALL_CHAIN_STANDBY;
28import static android.net.INetd.FIREWALL_RULE_ALLOW;
29import static android.net.INetd.FIREWALL_RULE_DENY;
30import static android.net.INetd.FIREWALL_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070031import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_DOZABLE;
Felipe Leme011b98f2016-02-10 17:28:31 -080032import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070033import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_STANDBY;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070034import static android.net.NetworkPolicyManager.FIREWALL_RULE_DEFAULT;
Jeff Sharkeyb5d55e32011-08-10 17:53:27 -070035import static android.net.NetworkStats.SET_DEFAULT;
Lorenzo Colittif1912ca2017-08-17 19:23:08 +090036import static android.net.NetworkStats.STATS_PER_UID;
Jeff Sharkey1b5a2a92011-06-18 18:34:16 -070037import static android.net.NetworkStats.TAG_NONE;
Jeff Sharkeyae2c1812011-10-04 13:11:40 -070038import static android.net.TrafficStats.UID_TETHERING;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090039
Jeff Sharkeya63ba592011-07-19 23:47:12 -070040import static com.android.server.NetworkManagementSocketTagger.PROP_QTAGUID_ENABLED;
Erik Klineb2cfdfb2017-01-18 20:54:14 +090041
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070042import android.annotation.NonNull;
Sudheer Shankadc589ac2016-11-10 15:30:17 -080043import android.app.ActivityManager;
San Mehat873f2142010-01-14 10:25:07 -080044import android.content.Context;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080045import android.net.ConnectivityManager;
Lorenzo Colitti58967ba2016-02-02 17:21:21 +090046import android.net.INetd;
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +000047import android.net.INetdUnsolicitedEventListener;
San Mehat4d02d002010-01-22 16:07:46 -080048import android.net.INetworkManagementEventObserver;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090049import android.net.ITetheringStatsProvider;
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +000050import android.net.InetAddresses;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070051import android.net.InterfaceConfiguration;
Luke Huang14f75442018-08-15 19:22:54 +080052import android.net.InterfaceConfigurationParcel;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +090053import android.net.IpPrefix;
Robert Greenwalted126402011-01-28 15:34:55 -080054import android.net.LinkAddress;
Lorenzo Colittib57edc52014-08-22 17:10:50 -070055import android.net.Network;
Amith Yamasani15e472352015-04-24 19:06:07 -070056import android.net.NetworkPolicyManager;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070057import android.net.NetworkStats;
Robert Greenwalted126402011-01-28 15:34:55 -080058import android.net.NetworkUtils;
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070059import android.net.RouteInfo;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090060import android.net.TetherStatsParcel;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -040061import android.net.UidRange;
Lorenzo Colittib90ad242019-03-18 23:50:34 +090062import android.net.UidRangeParcel;
Remi NGUYEN VAN231b52b2019-01-29 15:38:52 +090063import android.net.util.NetdService;
Dianne Hackborn91268cf2013-06-13 19:06:50 -070064import android.os.BatteryStats;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070065import android.os.Binder;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070066import android.os.Handler;
Lorenzo Colittia0868002017-07-11 02:29:28 +090067import android.os.IBinder;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080068import android.os.INetworkActivityListener;
San Mehat873f2142010-01-14 10:25:07 -080069import android.os.INetworkManagementService;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070070import android.os.Process;
Jeff Sharkey3df273e2011-12-15 15:47:12 -080071import android.os.RemoteCallbackList;
72import android.os.RemoteException;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070073import android.os.ServiceManager;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +090074import android.os.ServiceSpecificException;
Jeff Sharkey605eb792014-11-04 13:34:06 -080075import android.os.StrictMode;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070076import android.os.SystemClock;
Marco Nelissen62dbb222010-02-18 10:56:30 -080077import android.os.SystemProperties;
Felipe Leme29e72ea2016-09-08 13:26:55 -070078import android.os.Trace;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -070079import android.telephony.DataConnectionRealTimeInfo;
Lorenzo Colittib90ad242019-03-18 23:50:34 +090080import android.text.TextUtils;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080081import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080082import android.util.Slog;
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -070083import android.util.SparseBooleanArray;
Jeff Sharkey605eb792014-11-04 13:34:06 -080084import android.util.SparseIntArray;
San Mehat873f2142010-01-14 10:25:07 -080085
Jeff Sharkey605eb792014-11-04 13:34:06 -080086import com.android.internal.annotations.GuardedBy;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070087import com.android.internal.annotations.VisibleForTesting;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070088import com.android.internal.app.IBatteryStats;
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -060089import com.android.internal.util.DumpUtils;
Jeff Sharkey605eb792014-11-04 13:34:06 -080090import com.android.internal.util.HexDump;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -070091import com.android.internal.util.Preconditions;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090092
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070093import com.google.android.collect.Maps;
Jeff Sharkey4414cea2011-06-24 17:05:24 -070094
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070095import java.io.BufferedReader;
96import java.io.DataInputStream;
Jeff Sharkey47eb1022011-08-25 17:48:52 -070097import java.io.FileDescriptor;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070098import java.io.FileInputStream;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070099import java.io.IOException;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700100import java.io.InputStreamReader;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700101import java.io.PrintWriter;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700102import java.net.InetAddress;
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700103import java.net.InterfaceAddress;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700104import java.util.ArrayList;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400105import java.util.Arrays;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700106import java.util.HashMap;
jiaguo1da35f72014-01-09 16:39:59 +0800107import java.util.List;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700108import java.util.Map;
San Mehat873f2142010-01-14 10:25:07 -0800109
110/**
111 * @hide
112 */
Luke Huang909b31a2019-03-16 21:21:16 +0800113public class NetworkManagementService extends INetworkManagementService.Stub {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900114
115 /**
116 * Helper class that encapsulates NetworkManagementService dependencies and makes them
117 * easier to mock in unit tests.
118 */
119 static class SystemServices {
120 public IBinder getService(String name) {
121 return ServiceManager.getService(name);
122 }
123 public void registerLocalService(NetworkManagementInternal nmi) {
124 LocalServices.addService(NetworkManagementInternal.class, nmi);
125 }
126 public INetd getNetd() {
127 return NetdService.get();
128 }
129 }
130
Amith Yamasani15e472352015-04-24 19:06:07 -0700131 private static final String TAG = "NetworkManagement";
132 private static final boolean DBG = Log.isLoggable(TAG, Log.DEBUG);
Kenny Root305bcbf2010-09-03 07:56:38 -0700133
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400134 private static final int MAX_UID_RANGES_PER_COMMAND = 10;
135
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700136 /**
137 * Name representing {@link #setGlobalAlert(long)} limit when delivered to
138 * {@link INetworkManagementEventObserver#limitReached(String, String)}.
139 */
140 public static final String LIMIT_GLOBAL_ALERT = "globalAlert";
141
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700142 static final int DAEMON_MSG_MOBILE_CONN_REAL_TIME_INFO = 1;
143
Luke Huang8a462ec2018-08-24 20:33:16 +0800144 static final boolean MODIFY_OPERATION_ADD = true;
145 static final boolean MODIFY_OPERATION_REMOVE = false;
146
San Mehat873f2142010-01-14 10:25:07 -0800147 /**
148 * Binder context for this service
149 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700150 private final Context mContext;
San Mehat873f2142010-01-14 10:25:07 -0800151
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700152 private final Handler mDaemonHandler;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700153
Lorenzo Colittia0868002017-07-11 02:29:28 +0900154 private final SystemServices mServices;
155
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900156 private INetd mNetdService;
157
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000158 private final NetdUnsolicitedEventListener mNetdUnsolicitedEventListener;
Luke Huangd290dd52018-09-04 17:08:18 +0800159
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800160 private IBatteryStats mBatteryStats;
161
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000162 private final RemoteCallbackList<INetworkManagementEventObserver> mObservers =
163 new RemoteCallbackList<>();
164
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900165 @GuardedBy("mTetheringStatsProviders")
166 private final HashMap<ITetheringStatsProvider, String>
167 mTetheringStatsProviders = Maps.newHashMap();
168
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700169 /**
170 * If both locks need to be held, then they should be obtained in the order:
171 * first {@link #mQuotaLock} and then {@link #mRulesLock}.
172 */
Andrew Scull45f533c2017-05-19 15:37:20 +0100173 private final Object mQuotaLock = new Object();
Andrew Scull519291f2017-05-23 13:11:03 +0100174 private final Object mRulesLock = new Object();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800175
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700176 /** Set of interfaces with active quotas. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800177 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700178 private HashMap<String, Long> mActiveQuotas = Maps.newHashMap();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -0700179 /** Set of interfaces with active alerts. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800180 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700181 private HashMap<String, Long> mActiveAlerts = Maps.newHashMap();
Felipe Leme65be3022016-03-22 14:53:13 -0700182 /** Set of UIDs blacklisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700183 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700184 private SparseBooleanArray mUidRejectOnMetered = new SparseBooleanArray();
185 /** Set of UIDs whitelisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700186 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700187 private SparseBooleanArray mUidAllowOnMetered = new SparseBooleanArray();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800188 /** Set of UIDs with cleartext penalties. */
189 @GuardedBy("mQuotaLock")
190 private SparseIntArray mUidCleartextPolicy = new SparseIntArray();
Amith Yamasani15e472352015-04-24 19:06:07 -0700191 /** Set of UIDs that are to be blocked/allowed by firewall controller. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700192 @GuardedBy("mRulesLock")
Amith Yamasani15e472352015-04-24 19:06:07 -0700193 private SparseIntArray mUidFirewallRules = new SparseIntArray();
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700194 /**
195 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
196 * to application idles.
197 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700198 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700199 private SparseIntArray mUidFirewallStandbyRules = new SparseIntArray();
200 /**
201 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
202 * to device idles.
203 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700204 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700205 private SparseIntArray mUidFirewallDozableRules = new SparseIntArray();
Felipe Leme011b98f2016-02-10 17:28:31 -0800206 /**
207 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
208 * to device on power-save mode.
209 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700210 @GuardedBy("mRulesLock")
Felipe Leme011b98f2016-02-10 17:28:31 -0800211 private SparseIntArray mUidFirewallPowerSaveRules = new SparseIntArray();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700212 /** Set of states for the child firewall chains. True if the chain is active. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700213 @GuardedBy("mRulesLock")
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700214 final SparseBooleanArray mFirewallChainStates = new SparseBooleanArray();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700215
Felipe Leme65be3022016-03-22 14:53:13 -0700216 @GuardedBy("mQuotaLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700217 private volatile boolean mDataSaverMode;
Felipe Leme65be3022016-03-22 14:53:13 -0700218
Andrew Scull45f533c2017-05-19 15:37:20 +0100219 private final Object mIdleTimerLock = new Object();
Haoyu Bai04124232012-06-28 15:26:19 -0700220 /** Set of interfaces with active idle timers. */
221 private static class IdleTimerParams {
222 public final int timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800223 public final int type;
Haoyu Bai04124232012-06-28 15:26:19 -0700224 public int networkCount;
225
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800226 IdleTimerParams(int timeout, int type) {
Haoyu Bai04124232012-06-28 15:26:19 -0700227 this.timeout = timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800228 this.type = type;
Haoyu Bai04124232012-06-28 15:26:19 -0700229 this.networkCount = 1;
230 }
231 }
232 private HashMap<String, IdleTimerParams> mActiveIdleTimers = Maps.newHashMap();
233
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700234 private volatile boolean mFirewallEnabled;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800235 private volatile boolean mStrictEnabled;
Jeff Sharkey350083e2011-06-29 10:45:16 -0700236
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700237 private boolean mMobileActivityFromRadio = false;
238 private int mLastPowerStateFromRadio = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Adam Lesinskie08af192015-03-25 16:42:59 -0700239 private int mLastPowerStateFromWifi = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700240
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800241 private final RemoteCallbackList<INetworkActivityListener> mNetworkActivityListeners =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700242 new RemoteCallbackList<>();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800243 private boolean mNetworkActive;
244
San Mehat873f2142010-01-14 10:25:07 -0800245 /**
246 * Constructs a new NetworkManagementService instance
247 *
248 * @param context Binder context for this service
249 */
Lorenzo Colittia0868002017-07-11 02:29:28 +0900250 private NetworkManagementService(
Luke Huang909b31a2019-03-16 21:21:16 +0800251 Context context, SystemServices services) {
San Mehat873f2142010-01-14 10:25:07 -0800252 mContext = context;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900253 mServices = services;
San Mehat4d02d002010-01-22 16:07:46 -0800254
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700255 mDaemonHandler = new Handler(FgThread.get().getLooper());
Wink Saville67e07892014-06-18 16:43:14 -0700256
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000257 mNetdUnsolicitedEventListener = new NetdUnsolicitedEventListener();
258
Lorenzo Colittia0868002017-07-11 02:29:28 +0900259 mServices.registerLocalService(new LocalService());
Lorenzo Colitti8228eb32017-07-19 06:17:33 +0900260
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900261 synchronized (mTetheringStatsProviders) {
262 mTetheringStatsProviders.put(new NetdTetheringStatsProvider(), "netd");
263 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700264 }
265
266 @VisibleForTesting
267 NetworkManagementService() {
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700268 mContext = null;
269 mDaemonHandler = null;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900270 mServices = null;
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000271 mNetdUnsolicitedEventListener = null;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700272 }
273
Luke Huang909b31a2019-03-16 21:21:16 +0800274 static NetworkManagementService create(Context context, SystemServices services)
Felipe Leme03e689d2016-03-02 16:17:38 -0800275 throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900276 final NetworkManagementService service =
Luke Huang909b31a2019-03-16 21:21:16 +0800277 new NetworkManagementService(context, services);
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700278 if (DBG) Slog.d(TAG, "Creating NetworkManagementService");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900279 if (DBG) Slog.d(TAG, "Connecting native netd service");
bohu07cc3bb2016-05-03 15:58:01 -0700280 service.connectNativeNetdService();
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900281 if (DBG) Slog.d(TAG, "Connected");
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700282 return service;
San Mehat873f2142010-01-14 10:25:07 -0800283 }
284
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900285 public static NetworkManagementService create(Context context) throws InterruptedException {
Luke Huang909b31a2019-03-16 21:21:16 +0800286 return create(context, new SystemServices());
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900287 }
288
Jeff Sharkey350083e2011-06-29 10:45:16 -0700289 public void systemReady() {
Felipe Leme03e689d2016-03-02 16:17:38 -0800290 if (DBG) {
291 final long start = System.currentTimeMillis();
292 prepareNativeDaemon();
293 final long delta = System.currentTimeMillis() - start;
294 Slog.d(TAG, "Prepared in " + delta + "ms");
295 return;
296 } else {
297 prepareNativeDaemon();
298 }
Jeff Sharkey350083e2011-06-29 10:45:16 -0700299 }
300
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800301 private IBatteryStats getBatteryStats() {
302 synchronized (this) {
303 if (mBatteryStats != null) {
304 return mBatteryStats;
305 }
Lorenzo Colittia0868002017-07-11 02:29:28 +0900306 mBatteryStats =
307 IBatteryStats.Stub.asInterface(mServices.getService(BatteryStats.SERVICE_NAME));
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800308 return mBatteryStats;
309 }
310 }
311
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800312 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800313 public void registerObserver(INetworkManagementEventObserver observer) {
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000314 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
315 mObservers.register(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800316 }
317
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800318 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800319 public void unregisterObserver(INetworkManagementEventObserver observer) {
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000320 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
321 mObservers.unregister(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800322 }
323
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900324 @FunctionalInterface
325 private interface NetworkManagementEventCallback {
326 public void sendCallback(INetworkManagementEventObserver o) throws RemoteException;
327 }
328
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000329 private void invokeForAllObservers(NetworkManagementEventCallback eventCallback) {
330 final int length = mObservers.beginBroadcast();
331 try {
332 for (int i = 0; i < length; i++) {
333 try {
334 eventCallback.sendCallback(mObservers.getBroadcastItem(i));
335 } catch (RemoteException | RuntimeException e) {
336 }
337 }
338 } finally {
339 mObservers.finishBroadcast();
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900340 }
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000341 }
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900342
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000343 /**
344 * Notify our observers of an interface status change
345 */
346 private void notifyInterfaceStatusChanged(String iface, boolean up) {
347 invokeForAllObservers(o -> o.interfaceStatusChanged(iface, up));
348 }
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900349
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000350 /**
351 * Notify our observers of an interface link state change
352 * (typically, an Ethernet cable has been plugged-in or unplugged).
353 */
354 private void notifyInterfaceLinkStateChanged(String iface, boolean up) {
355 invokeForAllObservers(o -> o.interfaceLinkStateChanged(iface, up));
356 }
357
358 /**
359 * Notify our observers of an interface addition.
360 */
361 private void notifyInterfaceAdded(String iface) {
362 invokeForAllObservers(o -> o.interfaceAdded(iface));
363 }
364
365 /**
366 * Notify our observers of an interface removal.
367 */
368 private void notifyInterfaceRemoved(String iface) {
369 // netd already clears out quota and alerts for removed ifaces; update
370 // our sanity-checking state.
371 mActiveAlerts.remove(iface);
372 mActiveQuotas.remove(iface);
373 invokeForAllObservers(o -> o.interfaceRemoved(iface));
374 }
375
376 /**
377 * Notify our observers of a limit reached.
378 */
379 private void notifyLimitReached(String limitName, String iface) {
380 invokeForAllObservers(o -> o.limitReached(limitName, iface));
381 }
382
383 /**
384 * Notify our observers of a change in the data activity state of the interface
385 */
386 private void notifyInterfaceClassActivity(int type, boolean isActive, long tsNanos,
387 int uid, boolean fromRadio) {
388 final boolean isMobile = ConnectivityManager.isNetworkTypeMobile(type);
389 int powerState = isActive
390 ? DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH
391 : DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
392 if (isMobile) {
393 if (!fromRadio) {
394 if (mMobileActivityFromRadio) {
395 // If this call is not coming from a report from the radio itself, but we
396 // have previously received reports from the radio, then we will take the
397 // power state to just be whatever the radio last reported.
398 powerState = mLastPowerStateFromRadio;
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900399 }
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000400 } else {
401 mMobileActivityFromRadio = true;
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700402 }
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000403 if (mLastPowerStateFromRadio != powerState) {
404 mLastPowerStateFromRadio = powerState;
405 try {
406 getBatteryStats().noteMobileRadioPowerState(powerState, tsNanos, uid);
407 } catch (RemoteException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700408 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700409 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800410 }
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900411
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000412 if (ConnectivityManager.isNetworkTypeWifi(type)) {
413 if (mLastPowerStateFromWifi != powerState) {
414 mLastPowerStateFromWifi = powerState;
415 try {
416 getBatteryStats().noteWifiRadioPowerState(powerState, tsNanos, uid);
417 } catch (RemoteException e) {
418 }
419 }
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900420 }
421
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000422 if (!isMobile || fromRadio || !mMobileActivityFromRadio) {
423 // Report the change in data activity. We don't do this if this is a change
424 // on the mobile network, that is not coming from the radio itself, and we
425 // have previously seen change reports from the radio. In that case only
426 // the radio is the authority for the current state.
427 final boolean active = isActive;
428 invokeForAllObservers(o -> o.interfaceClassDataActivityChanged(
429 Integer.toString(type), active, tsNanos));
430 }
431
432 boolean report = false;
433 synchronized (mIdleTimerLock) {
434 if (mActiveIdleTimers.isEmpty()) {
435 // If there are no idle timers, we are not monitoring activity, so we
436 // are always considered active.
437 isActive = true;
438 }
439 if (mNetworkActive != isActive) {
440 mNetworkActive = isActive;
441 report = isActive;
442 }
443 }
444 if (report) {
445 reportNetworkActive();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800446 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700447 }
448
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900449 @Override
450 public void registerTetheringStatsProvider(ITetheringStatsProvider provider, String name) {
451 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
452 Preconditions.checkNotNull(provider);
453 synchronized(mTetheringStatsProviders) {
454 mTetheringStatsProviders.put(provider, name);
455 }
456 }
457
458 @Override
459 public void unregisterTetheringStatsProvider(ITetheringStatsProvider provider) {
460 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
461 synchronized(mTetheringStatsProviders) {
462 mTetheringStatsProviders.remove(provider);
463 }
464 }
465
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900466 @Override
467 public void tetherLimitReached(ITetheringStatsProvider provider) {
468 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
469 synchronized(mTetheringStatsProviders) {
470 if (!mTetheringStatsProviders.containsKey(provider)) {
471 return;
472 }
473 // No current code examines the interface parameter in a global alert. Just pass null.
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000474 mDaemonHandler.post(() -> notifyLimitReached(LIMIT_GLOBAL_ALERT, null));
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900475 }
476 }
477
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900478 // Sync the state of the given chain with the native daemon.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700479 private void syncFirewallChainLocked(int chain, String name) {
480 SparseIntArray rules;
481 synchronized (mRulesLock) {
482 final SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900483 // Make a copy of the current rules, and then clear them. This is because
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700484 // setFirewallUidRuleInternal only pushes down rules to the native daemon if they
485 // are different from the current rules stored in the mUidFirewall*Rules array for
486 // the specified chain. If we don't clear the rules, setFirewallUidRuleInternal
487 // will do nothing.
488 rules = uidFirewallRules.clone();
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900489 uidFirewallRules.clear();
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700490 }
491 if (rules.size() > 0) {
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900492 // Now push the rules. setFirewallUidRuleInternal will push each of these down to the
493 // native daemon, and also add them to the mUidFirewall*Rules array for the specified
494 // chain.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700495 if (DBG) Slog.d(TAG, "Pushing " + rules.size() + " active firewall "
496 + name + "UID rules");
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900497 for (int i = 0; i < rules.size(); i++) {
Felipe Lemea701cad2016-05-12 09:58:14 -0700498 setFirewallUidRuleLocked(chain, rules.keyAt(i), rules.valueAt(i));
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900499 }
500 }
501 }
502
bohu07cc3bb2016-05-03 15:58:01 -0700503 private void connectNativeNetdService() {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900504 mNetdService = mServices.getNetd();
Luke Huangd290dd52018-09-04 17:08:18 +0800505 try {
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000506 mNetdService.registerUnsolicitedEventListener(mNetdUnsolicitedEventListener);
507 if (DBG) Slog.d(TAG, "Register unsolicited event listener");
Luke Huangd290dd52018-09-04 17:08:18 +0800508 } catch (RemoteException | ServiceSpecificException e) {
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000509 Slog.e(TAG, "Failed to set Netd unsolicited event listener " + e);
Luke Huangd290dd52018-09-04 17:08:18 +0800510 }
bohu07cc3bb2016-05-03 15:58:01 -0700511 }
512
513 /**
514 * Prepare native daemon once connected, enabling modules and pushing any
515 * existing in-memory rules.
516 */
517 private void prepareNativeDaemon() {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900518
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700519 // push any existing quota or UID rules
520 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -0700521
Luke Huang56a03a02018-09-07 12:02:16 +0800522 // Netd unconditionally enable bandwidth control
523 SystemProperties.set(PROP_QTAGUID_ENABLED, "1");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900524
Luke Huang473eb872018-07-26 17:33:14 +0800525 mStrictEnabled = true;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900526
Felipe Leme65be3022016-03-22 14:53:13 -0700527 setDataSaverModeEnabled(mDataSaverMode);
528
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700529 int size = mActiveQuotas.size();
530 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800531 if (DBG) Slog.d(TAG, "Pushing " + size + " active quota rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700532 final HashMap<String, Long> activeQuotas = mActiveQuotas;
533 mActiveQuotas = Maps.newHashMap();
534 for (Map.Entry<String, Long> entry : activeQuotas.entrySet()) {
535 setInterfaceQuota(entry.getKey(), entry.getValue());
536 }
537 }
538
539 size = mActiveAlerts.size();
540 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800541 if (DBG) Slog.d(TAG, "Pushing " + size + " active alert rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700542 final HashMap<String, Long> activeAlerts = mActiveAlerts;
543 mActiveAlerts = Maps.newHashMap();
544 for (Map.Entry<String, Long> entry : activeAlerts.entrySet()) {
545 setInterfaceAlert(entry.getKey(), entry.getValue());
546 }
547 }
548
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700549 SparseBooleanArray uidRejectOnQuota = null;
550 SparseBooleanArray uidAcceptOnQuota = null;
551 synchronized (mRulesLock) {
552 size = mUidRejectOnMetered.size();
553 if (size > 0) {
554 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered blacklist rules");
555 uidRejectOnQuota = mUidRejectOnMetered;
556 mUidRejectOnMetered = new SparseBooleanArray();
557 }
558
559 size = mUidAllowOnMetered.size();
560 if (size > 0) {
561 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered whitelist rules");
562 uidAcceptOnQuota = mUidAllowOnMetered;
563 mUidAllowOnMetered = new SparseBooleanArray();
564 }
565 }
566 if (uidRejectOnQuota != null) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700567 for (int i = 0; i < uidRejectOnQuota.size(); i++) {
Felipe Leme65be3022016-03-22 14:53:13 -0700568 setUidMeteredNetworkBlacklist(uidRejectOnQuota.keyAt(i),
569 uidRejectOnQuota.valueAt(i));
570 }
571 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700572 if (uidAcceptOnQuota != null) {
Felipe Leme65be3022016-03-22 14:53:13 -0700573 for (int i = 0; i < uidAcceptOnQuota.size(); i++) {
574 setUidMeteredNetworkWhitelist(uidAcceptOnQuota.keyAt(i),
575 uidAcceptOnQuota.valueAt(i));
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700576 }
577 }
Jeff Sharkey605eb792014-11-04 13:34:06 -0800578
579 size = mUidCleartextPolicy.size();
580 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800581 if (DBG) Slog.d(TAG, "Pushing " + size + " active UID cleartext policies");
Jeff Sharkey605eb792014-11-04 13:34:06 -0800582 final SparseIntArray local = mUidCleartextPolicy;
583 mUidCleartextPolicy = new SparseIntArray();
584 for (int i = 0; i < local.size(); i++) {
585 setUidCleartextNetworkPolicy(local.keyAt(i), local.valueAt(i));
586 }
587 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700588
Robin Leec3736bc2017-03-10 16:19:54 +0000589 setFirewallEnabled(mFirewallEnabled);
Amith Yamasani15e472352015-04-24 19:06:07 -0700590
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700591 syncFirewallChainLocked(FIREWALL_CHAIN_NONE, "");
592 syncFirewallChainLocked(FIREWALL_CHAIN_STANDBY, "standby ");
593 syncFirewallChainLocked(FIREWALL_CHAIN_DOZABLE, "dozable ");
594 syncFirewallChainLocked(FIREWALL_CHAIN_POWERSAVE, "powersave ");
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700595
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700596 final int[] chains =
597 {FIREWALL_CHAIN_STANDBY, FIREWALL_CHAIN_DOZABLE, FIREWALL_CHAIN_POWERSAVE};
598 for (int chain : chains) {
599 if (getFirewallChainState(chain)) {
600 setFirewallChainEnabled(chain, true);
601 }
Felipe Leme011b98f2016-02-10 17:28:31 -0800602 }
Amith Yamasani15e472352015-04-24 19:06:07 -0700603 }
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900604
Luke Huang56a03a02018-09-07 12:02:16 +0800605
606 try {
607 getBatteryStats().noteNetworkStatsEnabled();
608 } catch (RemoteException e) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900609 }
610
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700611 }
San Mehat4d02d002010-01-22 16:07:46 -0800612
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000613 /**
614 * Notify our observers of a new or updated interface address.
615 */
616 private void notifyAddressUpdated(String iface, LinkAddress address) {
617 invokeForAllObservers(o -> o.addressUpdated(iface, address));
618 }
619
620 /**
621 * Notify our observers of a deleted interface address.
622 */
623 private void notifyAddressRemoved(String iface, LinkAddress address) {
624 invokeForAllObservers(o -> o.addressRemoved(iface, address));
625 }
626
627 /**
628 * Notify our observers of DNS server information received.
629 */
630 private void notifyInterfaceDnsServerInfo(String iface, long lifetime, String[] addresses) {
631 invokeForAllObservers(o -> o.interfaceDnsServerInfo(iface, lifetime, addresses));
632 }
633
634 /**
635 * Notify our observers of a route change.
636 */
637 private void notifyRouteChange(boolean updated, RouteInfo route) {
638 if (updated) {
639 invokeForAllObservers(o -> o.routeUpdated(route));
640 } else {
641 invokeForAllObservers(o -> o.routeRemoved(route));
642 }
643 }
644
645 private class NetdUnsolicitedEventListener extends INetdUnsolicitedEventListener.Stub {
646 @Override
647 public void onInterfaceClassActivityChanged(boolean isActive,
648 int label, long timestamp, int uid) throws RemoteException {
649 final long timestampNanos;
650 if (timestamp <= 0) {
651 timestampNanos = SystemClock.elapsedRealtimeNanos();
652 } else {
653 timestampNanos = timestamp;
654 }
655 mDaemonHandler.post(() ->
656 notifyInterfaceClassActivity(label, isActive, timestampNanos, uid, false));
657 }
658
659 @Override
660 public void onQuotaLimitReached(String alertName, String ifName)
661 throws RemoteException {
662 mDaemonHandler.post(() -> notifyLimitReached(alertName, ifName));
663 }
664
665 @Override
666 public void onInterfaceDnsServerInfo(String ifName,
667 long lifetime, String[] servers) throws RemoteException {
668 mDaemonHandler.post(() -> notifyInterfaceDnsServerInfo(ifName, lifetime, servers));
669 }
670
671 @Override
672 public void onInterfaceAddressUpdated(String addr,
673 String ifName, int flags, int scope) throws RemoteException {
674 final LinkAddress address = new LinkAddress(addr, flags, scope);
675 mDaemonHandler.post(() -> notifyAddressUpdated(ifName, address));
676 }
677
678 @Override
679 public void onInterfaceAddressRemoved(String addr,
680 String ifName, int flags, int scope) throws RemoteException {
681 final LinkAddress address = new LinkAddress(addr, flags, scope);
682 mDaemonHandler.post(() -> notifyAddressRemoved(ifName, address));
683 }
684
685 @Override
686 public void onInterfaceAdded(String ifName) throws RemoteException {
687 mDaemonHandler.post(() -> notifyInterfaceAdded(ifName));
688 }
689
690 @Override
691 public void onInterfaceRemoved(String ifName) throws RemoteException {
692 mDaemonHandler.post(() -> notifyInterfaceRemoved(ifName));
693 }
694
695 @Override
696 public void onInterfaceChanged(String ifName, boolean up)
697 throws RemoteException {
698 mDaemonHandler.post(() -> notifyInterfaceStatusChanged(ifName, up));
699 }
700
701 @Override
702 public void onInterfaceLinkStateChanged(String ifName, boolean up)
703 throws RemoteException {
704 mDaemonHandler.post(() -> notifyInterfaceLinkStateChanged(ifName, up));
705 }
706
707 @Override
708 public void onRouteChanged(boolean updated,
709 String route, String gateway, String ifName) throws RemoteException {
710 final RouteInfo processRoute = new RouteInfo(new IpPrefix(route),
711 ("".equals(gateway)) ? null : InetAddresses.parseNumericAddress(gateway),
712 ifName);
713 mDaemonHandler.post(() -> notifyRouteChange(updated, processRoute));
714 }
715
716 @Override
717 public void onStrictCleartextDetected(int uid, String hex) throws RemoteException {
718 // Don't need to post to mDaemonHandler because the only thing
719 // that notifyCleartextNetwork does is post to a handler
720 ActivityManager.getService().notifyCleartextNetwork(uid,
721 HexDump.hexStringToByteArray(hex));
722 }
Remi NGUYEN VANeec0ed42019-04-09 14:01:51 +0900723
724 @Override
725 public int getInterfaceVersion() {
726 return INetdUnsolicitedEventListener.VERSION;
727 }
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +0000728 }
729
San Mehat873f2142010-01-14 10:25:07 -0800730 //
San Mehat873f2142010-01-14 10:25:07 -0800731 // INetworkManagementService members
732 //
Erik Kline4e37b702016-07-05 11:34:21 +0900733 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800734 public String[] listInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800735 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -0700736 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +0800737 return mNetdService.interfaceGetList();
Luke Huang14f75442018-08-15 19:22:54 +0800738 } catch (RemoteException | ServiceSpecificException e) {
739 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700740 }
San Mehated4fc8a2010-01-22 12:28:36 -0800741 }
742
Lorenzo Colittib90ad242019-03-18 23:50:34 +0900743 /**
744 * Convert InterfaceConfiguration to InterfaceConfigurationParcel with given ifname.
745 */
746 private static InterfaceConfigurationParcel toStableParcel(InterfaceConfiguration cfg,
747 String iface) {
748 InterfaceConfigurationParcel cfgParcel = new InterfaceConfigurationParcel();
749 cfgParcel.ifName = iface;
750 String hwAddr = cfg.getHardwareAddress();
751 if (!TextUtils.isEmpty(hwAddr)) {
752 cfgParcel.hwAddr = hwAddr;
753 } else {
754 cfgParcel.hwAddr = "";
755 }
756 cfgParcel.ipv4Addr = cfg.getLinkAddress().getAddress().getHostAddress();
757 cfgParcel.prefixLength = cfg.getLinkAddress().getPrefixLength();
758 ArrayList<String> flags = new ArrayList<>();
759 for (String flag : cfg.getFlags()) {
760 flags.add(flag);
761 }
762 cfgParcel.flags = flags.toArray(new String[0]);
763
764 return cfgParcel;
765 }
766
767 /**
768 * Construct InterfaceConfiguration from InterfaceConfigurationParcel.
769 */
770 public static InterfaceConfiguration fromStableParcel(InterfaceConfigurationParcel p) {
771 InterfaceConfiguration cfg = new InterfaceConfiguration();
772 cfg.setHardwareAddress(p.hwAddr);
773
774 final InetAddress addr = NetworkUtils.numericToInetAddress(p.ipv4Addr);
775 cfg.setLinkAddress(new LinkAddress(addr, p.prefixLength));
776 for (String flag : p.flags) {
777 cfg.setFlag(flag);
778 }
779
780 return cfg;
781 }
782
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800783 @Override
784 public InterfaceConfiguration getInterfaceConfig(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800785 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang14f75442018-08-15 19:22:54 +0800786 final InterfaceConfigurationParcel result;
Kenny Roota80ce062010-06-01 13:23:53 -0700787 try {
Luke Huang14f75442018-08-15 19:22:54 +0800788 result = mNetdService.interfaceGetCfg(iface);
789 } catch (RemoteException | ServiceSpecificException e) {
790 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700791 }
San Mehated4fc8a2010-01-22 12:28:36 -0800792
San Mehated4fc8a2010-01-22 12:28:36 -0800793 try {
Lorenzo Colittib90ad242019-03-18 23:50:34 +0900794 final InterfaceConfiguration cfg = fromStableParcel(result);
Luke Huang14f75442018-08-15 19:22:54 +0800795 return cfg;
796 } catch (IllegalArgumentException iae) {
797 throw new IllegalStateException("Invalid InterfaceConfigurationParcel", iae);
San Mehated4fc8a2010-01-22 12:28:36 -0800798 }
San Mehated4fc8a2010-01-22 12:28:36 -0800799 }
800
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800801 @Override
802 public void setInterfaceConfig(String iface, InterfaceConfiguration cfg) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800803 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800804 LinkAddress linkAddr = cfg.getLinkAddress();
Robert Greenwalt2d2afd12011-02-01 15:30:46 -0800805 if (linkAddr == null || linkAddr.getAddress() == null) {
806 throw new IllegalStateException("Null LinkAddress given");
Robert Greenwalted126402011-01-28 15:34:55 -0800807 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800808
Lorenzo Colittib90ad242019-03-18 23:50:34 +0900809 final InterfaceConfigurationParcel cfgParcel = toStableParcel(cfg, iface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800810
Kenny Roota80ce062010-06-01 13:23:53 -0700811 try {
Luke Huang14f75442018-08-15 19:22:54 +0800812 mNetdService.interfaceSetCfg(cfgParcel);
813 } catch (RemoteException | ServiceSpecificException e) {
814 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700815 }
San Mehat873f2142010-01-14 10:25:07 -0800816 }
817
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800818 @Override
819 public void setInterfaceDown(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800820 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800821 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800822 ifcg.setInterfaceDown();
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800823 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -0700824 }
825
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800826 @Override
827 public void setInterfaceUp(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800828 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800829 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800830 ifcg.setInterfaceUp();
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800831 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -0700832 }
833
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800834 @Override
835 public void setInterfaceIpv6PrivacyExtensions(String iface, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800836 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sheriff73293612011-09-14 12:31:56 -0700837 try {
Luke Huang14f75442018-08-15 19:22:54 +0800838 mNetdService.interfaceSetIPv6PrivacyExtensions(iface, enable);
839 } catch (RemoteException | ServiceSpecificException e) {
840 throw new IllegalStateException(e);
Irfan Sheriff73293612011-09-14 12:31:56 -0700841 }
842 }
843
Irfan Sherifff5600612011-06-16 10:26:28 -0700844 /* TODO: This is right now a IPv4 only function. Works for wifi which loses its
845 IPv6 addresses on interface down, but we need to do full clean up here */
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800846 @Override
847 public void clearInterfaceAddresses(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800848 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sherifff5600612011-06-16 10:26:28 -0700849 try {
Luke Huang14f75442018-08-15 19:22:54 +0800850 mNetdService.interfaceClearAddrs(iface);
851 } catch (RemoteException | ServiceSpecificException e) {
852 throw new IllegalStateException(e);
Irfan Sherifff5600612011-06-16 10:26:28 -0700853 }
854 }
855
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800856 @Override
857 public void enableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800858 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -0700859 try {
Luke Huang14f75442018-08-15 19:22:54 +0800860 mNetdService.interfaceSetEnableIPv6(iface, true);
861 } catch (RemoteException | ServiceSpecificException e) {
862 throw new IllegalStateException(e);
repo sync7960d9f2011-09-29 12:40:02 -0700863 }
864 }
865
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800866 @Override
Joel Scherpelz2db10742017-06-07 15:38:38 +0900867 public void setIPv6AddrGenMode(String iface, int mode) throws ServiceSpecificException {
868 try {
869 mNetdService.setIPv6AddrGenMode(iface, mode);
870 } catch (RemoteException e) {
871 throw e.rethrowAsRuntimeException();
872 }
873 }
874
875 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800876 public void disableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800877 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -0700878 try {
Luke Huang14f75442018-08-15 19:22:54 +0800879 mNetdService.interfaceSetEnableIPv6(iface, false);
880 } catch (RemoteException | ServiceSpecificException e) {
881 throw new IllegalStateException(e);
repo sync7960d9f2011-09-29 12:40:02 -0700882 }
883 }
884
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800885 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -0700886 public void addRoute(int netId, RouteInfo route) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800887 modifyRoute(MODIFY_OPERATION_ADD, netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700888 }
889
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800890 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -0700891 public void removeRoute(int netId, RouteInfo route) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800892 modifyRoute(MODIFY_OPERATION_REMOVE, netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700893 }
894
Luke Huang8a462ec2018-08-24 20:33:16 +0800895 private void modifyRoute(boolean add, int netId, RouteInfo route) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800896 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700897
Luke Huang8a462ec2018-08-24 20:33:16 +0800898 final String ifName = route.getInterface();
899 final String dst = route.getDestination().toString();
900 final String nextHop;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900901
902 switch (route.getType()) {
903 case RouteInfo.RTN_UNICAST:
904 if (route.hasGateway()) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800905 nextHop = route.getGateway().getHostAddress();
906 } else {
907 nextHop = INetd.NEXTHOP_NONE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900908 }
909 break;
910 case RouteInfo.RTN_UNREACHABLE:
Luke Huang8a462ec2018-08-24 20:33:16 +0800911 nextHop = INetd.NEXTHOP_UNREACHABLE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900912 break;
913 case RouteInfo.RTN_THROW:
Luke Huang8a462ec2018-08-24 20:33:16 +0800914 nextHop = INetd.NEXTHOP_THROW;
915 break;
916 default:
917 nextHop = INetd.NEXTHOP_NONE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900918 break;
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -0700919 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800920 try {
Luke Huang8a462ec2018-08-24 20:33:16 +0800921 if (add) {
922 mNetdService.networkAddRoute(netId, ifName, dst, nextHop);
923 } else {
924 mNetdService.networkRemoveRoute(netId, ifName, dst, nextHop);
925 }
926 } catch (RemoteException | ServiceSpecificException e) {
927 throw new IllegalStateException(e);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700928 }
929 }
930
931 private ArrayList<String> readRouteList(String filename) {
932 FileInputStream fstream = null;
Christopher Wiley212b95f2016-08-02 11:38:57 -0700933 ArrayList<String> list = new ArrayList<>();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700934
935 try {
936 fstream = new FileInputStream(filename);
937 DataInputStream in = new DataInputStream(fstream);
938 BufferedReader br = new BufferedReader(new InputStreamReader(in));
939 String s;
940
941 // throw away the title line
942
943 while (((s = br.readLine()) != null) && (s.length() != 0)) {
944 list.add(s);
945 }
946 } catch (IOException ex) {
947 // return current list, possibly empty
948 } finally {
949 if (fstream != null) {
950 try {
951 fstream.close();
952 } catch (IOException ex) {}
953 }
954 }
955
956 return list;
957 }
958
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800959 @Override
sy.yun9d9b74a2013-09-02 05:24:09 +0900960 public void setMtu(String iface, int mtu) {
961 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
962
sy.yun9d9b74a2013-09-02 05:24:09 +0900963 try {
Luke Huang14f75442018-08-15 19:22:54 +0800964 mNetdService.interfaceSetMtu(iface, mtu);
965 } catch (RemoteException | ServiceSpecificException e) {
966 throw new IllegalStateException(e);
sy.yun9d9b74a2013-09-02 05:24:09 +0900967 }
968 }
969
970 @Override
San Mehat873f2142010-01-14 10:25:07 -0800971 public void shutdown() {
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800972 // TODO: remove from aidl if nobody calls externally
973 mContext.enforceCallingOrSelfPermission(SHUTDOWN, TAG);
San Mehat873f2142010-01-14 10:25:07 -0800974
Felipe Leme03e689d2016-03-02 16:17:38 -0800975 Slog.i(TAG, "Shutting down");
San Mehat873f2142010-01-14 10:25:07 -0800976 }
977
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800978 @Override
San Mehat873f2142010-01-14 10:25:07 -0800979 public boolean getIpForwardingEnabled() throws IllegalStateException{
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800980 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -0800981
Kenny Roota80ce062010-06-01 13:23:53 -0700982 try {
Luke Huang4db488b2018-08-16 15:37:31 +0800983 final boolean isEnabled = mNetdService.ipfwdEnabled();
984 return isEnabled;
985 } catch (RemoteException | ServiceSpecificException e) {
986 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700987 }
San Mehat873f2142010-01-14 10:25:07 -0800988 }
989
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800990 @Override
991 public void setIpForwardingEnabled(boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800992 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800993 try {
Luke Huang4db488b2018-08-16 15:37:31 +0800994 if (enable) {
995 mNetdService.ipfwdEnableForwarding("tethering");
996 } else {
997 mNetdService.ipfwdDisableForwarding("tethering");
998 }
999 } catch (RemoteException | ServiceSpecificException e) {
1000 throw new IllegalStateException(e);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001001 }
San Mehat873f2142010-01-14 10:25:07 -08001002 }
1003
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001004 @Override
1005 public void startTethering(String[] dhcpRange) {
Luke Huangb0d52462019-03-21 14:43:08 +08001006 startTetheringWithConfiguration(true, dhcpRange);
1007 }
1008
1009 @Override
1010 public void startTetheringWithConfiguration(boolean usingLegacyDnsProxy, String[] dhcpRange) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001011 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001012 // an odd number of addrs will fail
Kenny Roota80ce062010-06-01 13:23:53 -07001013 try {
Luke Huangb0d52462019-03-21 14:43:08 +08001014 mNetdService.tetherStartWithConfiguration(usingLegacyDnsProxy, dhcpRange);
Luke Huang4a32bf42018-08-21 19:09:45 +08001015 } catch (RemoteException | ServiceSpecificException e) {
1016 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001017 }
San Mehat873f2142010-01-14 10:25:07 -08001018 }
1019
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001020 @Override
1021 public void stopTethering() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001022 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001023 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001024 mNetdService.tetherStop();
1025 } catch (RemoteException | ServiceSpecificException e) {
1026 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001027 }
San Mehat873f2142010-01-14 10:25:07 -08001028 }
1029
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001030 @Override
1031 public boolean isTetheringStarted() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001032 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001033
Kenny Roota80ce062010-06-01 13:23:53 -07001034 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001035 final boolean isEnabled = mNetdService.tetherIsEnabled();
1036 return isEnabled;
1037 } catch (RemoteException | ServiceSpecificException e) {
1038 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001039 }
San Mehat873f2142010-01-14 10:25:07 -08001040 }
Matthew Xiefe19f122012-07-12 16:03:32 -07001041
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001042 @Override
1043 public void tetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001044 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001045 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001046 mNetdService.tetherInterfaceAdd(iface);
1047 } catch (RemoteException | ServiceSpecificException e) {
1048 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001049 }
Christopher Wiley212b95f2016-08-02 11:38:57 -07001050 List<RouteInfo> routes = new ArrayList<>();
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001051 // The RouteInfo constructor truncates the LinkAddress to a network prefix, thus making it
1052 // suitable to use as a route destination.
1053 routes.add(new RouteInfo(getInterfaceConfig(iface).getLinkAddress(), null, iface));
1054 addInterfaceToLocalNetwork(iface, routes);
San Mehat873f2142010-01-14 10:25:07 -08001055 }
1056
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001057 @Override
San Mehat873f2142010-01-14 10:25:07 -08001058 public void untetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001059 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001060 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001061 mNetdService.tetherInterfaceRemove(iface);
1062 } catch (RemoteException | ServiceSpecificException e) {
1063 throw new IllegalStateException(e);
Erik Kline1f4278a2016-08-16 16:46:33 +09001064 } finally {
1065 removeInterfaceFromLocalNetwork(iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001066 }
San Mehat873f2142010-01-14 10:25:07 -08001067 }
1068
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001069 @Override
1070 public String[] listTetheredInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001071 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001072 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +08001073 return mNetdService.tetherInterfaceList();
Luke Huang4a32bf42018-08-21 19:09:45 +08001074 } catch (RemoteException | ServiceSpecificException e) {
1075 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001076 }
San Mehat873f2142010-01-14 10:25:07 -08001077 }
1078
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001079 @Override
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001080 public void setDnsForwarders(Network network, String[] dns) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001081 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001082
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001083 int netId = (network != null) ? network.netId : ConnectivityManager.NETID_UNSET;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001084
San Mehat873f2142010-01-14 10:25:07 -08001085 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001086 mNetdService.tetherDnsSet(netId, dns);
1087 } catch (RemoteException | ServiceSpecificException e) {
1088 throw new IllegalStateException(e);
San Mehat873f2142010-01-14 10:25:07 -08001089 }
1090 }
1091
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001092 @Override
1093 public String[] getDnsForwarders() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001094 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001095 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +08001096 return mNetdService.tetherDnsList();
Luke Huang4a32bf42018-08-21 19:09:45 +08001097 } catch (RemoteException | ServiceSpecificException e) {
1098 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001099 }
San Mehat873f2142010-01-14 10:25:07 -08001100 }
1101
jiaguo1da35f72014-01-09 16:39:59 +08001102 private List<InterfaceAddress> excludeLinkLocal(List<InterfaceAddress> addresses) {
Christopher Wiley212b95f2016-08-02 11:38:57 -07001103 ArrayList<InterfaceAddress> filtered = new ArrayList<>(addresses.size());
jiaguo1da35f72014-01-09 16:39:59 +08001104 for (InterfaceAddress ia : addresses) {
1105 if (!ia.getAddress().isLinkLocalAddress())
1106 filtered.add(ia);
1107 }
1108 return filtered;
1109 }
1110
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001111 private void modifyInterfaceForward(boolean add, String fromIface, String toIface) {
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001112 try {
Luke Huang4db488b2018-08-16 15:37:31 +08001113 if (add) {
1114 mNetdService.ipfwdAddInterfaceForward(fromIface, toIface);
1115 } else {
1116 mNetdService.ipfwdRemoveInterfaceForward(fromIface, toIface);
1117 }
1118 } catch (RemoteException | ServiceSpecificException e) {
1119 throw new IllegalStateException(e);
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001120 }
1121 }
1122
1123 @Override
1124 public void startInterfaceForwarding(String fromIface, String toIface) {
1125 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1126 modifyInterfaceForward(true, fromIface, toIface);
1127 }
1128
1129 @Override
1130 public void stopInterfaceForwarding(String fromIface, String toIface) {
1131 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1132 modifyInterfaceForward(false, fromIface, toIface);
1133 }
1134
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001135 @Override
1136 public void enableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001137 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001138 try {
Luke Huanga31e0732018-10-22 13:23:10 +09001139 mNetdService.tetherAddForward(internalInterface, externalInterface);
1140 } catch (RemoteException | ServiceSpecificException e) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001141 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001142 }
San Mehat873f2142010-01-14 10:25:07 -08001143 }
1144
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001145 @Override
1146 public void disableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001147 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001148 try {
Luke Huanga31e0732018-10-22 13:23:10 +09001149 mNetdService.tetherRemoveForward(internalInterface, externalInterface);
1150 } catch (RemoteException | ServiceSpecificException e) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001151 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001152 }
San Mehat873f2142010-01-14 10:25:07 -08001153 }
San Mehat72759df2010-01-19 13:50:37 -08001154
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001155 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001156 public void addIdleTimer(String iface, int timeout, final int type) {
Haoyu Bai04124232012-06-28 15:26:19 -07001157 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1158
1159 if (DBG) Slog.d(TAG, "Adding idletimer");
1160
1161 synchronized (mIdleTimerLock) {
1162 IdleTimerParams params = mActiveIdleTimers.get(iface);
1163 if (params != null) {
1164 // the interface already has idletimer, update network count
1165 params.networkCount++;
1166 return;
1167 }
1168
1169 try {
Luke Huanga62d0492018-07-27 20:08:21 +08001170 mNetdService.idletimerAddInterface(iface, timeout, Integer.toString(type));
1171 } catch (RemoteException | ServiceSpecificException e) {
1172 throw new IllegalStateException(e);
Haoyu Bai04124232012-06-28 15:26:19 -07001173 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001174 mActiveIdleTimers.put(iface, new IdleTimerParams(timeout, type));
1175
Dianne Hackborne13c4c02014-02-11 17:18:35 -08001176 // Networks start up.
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001177 if (ConnectivityManager.isNetworkTypeMobile(type)) {
1178 mNetworkActive = false;
1179 }
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +00001180 mDaemonHandler.post(() -> notifyInterfaceClassActivity(type, true,
1181 SystemClock.elapsedRealtimeNanos(), -1, false));
Haoyu Bai04124232012-06-28 15:26:19 -07001182 }
1183 }
1184
1185 @Override
1186 public void removeIdleTimer(String iface) {
1187 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1188
1189 if (DBG) Slog.d(TAG, "Removing idletimer");
1190
1191 synchronized (mIdleTimerLock) {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001192 final IdleTimerParams params = mActiveIdleTimers.get(iface);
Haoyu Bai04124232012-06-28 15:26:19 -07001193 if (params == null || --(params.networkCount) > 0) {
1194 return;
1195 }
1196
1197 try {
Luke Huanga62d0492018-07-27 20:08:21 +08001198 mNetdService.idletimerRemoveInterface(iface,
1199 params.timeout, Integer.toString(params.type));
1200 } catch (RemoteException | ServiceSpecificException e) {
1201 throw new IllegalStateException(e);
Haoyu Bai04124232012-06-28 15:26:19 -07001202 }
1203 mActiveIdleTimers.remove(iface);
Remi NGUYEN VANbfd0aa02019-01-29 04:03:38 +00001204 mDaemonHandler.post(() -> notifyInterfaceClassActivity(params.type, false,
1205 SystemClock.elapsedRealtimeNanos(), -1, false));
Haoyu Bai04124232012-06-28 15:26:19 -07001206 }
1207 }
1208
1209 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001210 public void setInterfaceQuota(String iface, long quotaBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001211 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001212
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001213 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001214 if (mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001215 throw new IllegalStateException("iface " + iface + " already has quota");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001216 }
1217
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001218 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001219 // TODO: support quota shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001220 mNetdService.bandwidthSetInterfaceQuota(iface, quotaBytes);
1221
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001222 mActiveQuotas.put(iface, quotaBytes);
Luke Huangc7bea8662018-08-07 16:04:26 +08001223 } catch (RemoteException | ServiceSpecificException e) {
1224 throw new IllegalStateException(e);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001225 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001226
1227 synchronized (mTetheringStatsProviders) {
1228 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1229 try {
1230 provider.setInterfaceQuota(iface, quotaBytes);
1231 } catch (RemoteException e) {
1232 Log.e(TAG, "Problem setting tethering data limit on provider " +
1233 mTetheringStatsProviders.get(provider) + ": " + e);
1234 }
1235 }
1236 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001237 }
1238 }
1239
1240 @Override
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001241 public void removeInterfaceQuota(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001242 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001243
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001244 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001245 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001246 // TODO: eventually consider throwing
1247 return;
1248 }
1249
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001250 mActiveQuotas.remove(iface);
1251 mActiveAlerts.remove(iface);
Jeff Sharkey38ddeaa2011-11-08 13:04:22 -08001252
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001253 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001254 // TODO: support quota shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001255 mNetdService.bandwidthRemoveInterfaceQuota(iface);
1256 } catch (RemoteException | ServiceSpecificException e) {
1257 throw new IllegalStateException(e);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001258 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001259
1260 synchronized (mTetheringStatsProviders) {
1261 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1262 try {
1263 provider.setInterfaceQuota(iface, ITetheringStatsProvider.QUOTA_UNLIMITED);
1264 } catch (RemoteException e) {
1265 Log.e(TAG, "Problem removing tethering data limit on provider " +
1266 mTetheringStatsProviders.get(provider) + ": " + e);
1267 }
1268 }
1269 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001270 }
1271 }
1272
1273 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001274 public void setInterfaceAlert(String iface, long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001275 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001276
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001277 // quick sanity check
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001278 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001279 throw new IllegalStateException("setting alert requires existing quota on iface");
1280 }
1281
1282 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001283 if (mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001284 throw new IllegalStateException("iface " + iface + " already has alert");
1285 }
1286
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001287 try {
1288 // TODO: support alert shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001289 mNetdService.bandwidthSetInterfaceAlert(iface, alertBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001290 mActiveAlerts.put(iface, alertBytes);
Luke Huangc7bea8662018-08-07 16:04:26 +08001291 } catch (RemoteException | ServiceSpecificException e) {
1292 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001293 }
1294 }
1295 }
1296
1297 @Override
1298 public void removeInterfaceAlert(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001299 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001300
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001301 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001302 if (!mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001303 // TODO: eventually consider throwing
1304 return;
1305 }
1306
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001307 try {
1308 // TODO: support alert shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001309 mNetdService.bandwidthRemoveInterfaceAlert(iface);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001310 mActiveAlerts.remove(iface);
Luke Huangc7bea8662018-08-07 16:04:26 +08001311 } catch (RemoteException | ServiceSpecificException e) {
1312 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001313 }
1314 }
1315 }
1316
1317 @Override
1318 public void setGlobalAlert(long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001319 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001320
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001321 try {
Luke Huangc7bea8662018-08-07 16:04:26 +08001322 mNetdService.bandwidthSetGlobalAlert(alertBytes);
1323 } catch (RemoteException | ServiceSpecificException e) {
1324 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001325 }
1326 }
1327
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001328 private void setUidOnMeteredNetworkList(int uid, boolean blacklist, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001329 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001330
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001331 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001332 boolean oldEnable;
1333 SparseBooleanArray quotaList;
1334 synchronized (mRulesLock) {
1335 quotaList = blacklist ? mUidRejectOnMetered : mUidAllowOnMetered;
1336 oldEnable = quotaList.get(uid, false);
1337 }
Felipe Leme65be3022016-03-22 14:53:13 -07001338 if (oldEnable == enable) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001339 // TODO: eventually consider throwing
1340 return;
1341 }
1342
Felipe Leme29e72ea2016-09-08 13:26:55 -07001343 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "inetd bandwidth");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001344 try {
Luke Huangc7bea8662018-08-07 16:04:26 +08001345 if (blacklist) {
1346 if (enable) {
1347 mNetdService.bandwidthAddNaughtyApp(uid);
1348 } else {
1349 mNetdService.bandwidthRemoveNaughtyApp(uid);
1350 }
1351 } else {
1352 if (enable) {
1353 mNetdService.bandwidthAddNiceApp(uid);
1354 } else {
1355 mNetdService.bandwidthRemoveNiceApp(uid);
1356 }
1357 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001358 synchronized (mRulesLock) {
1359 if (enable) {
1360 quotaList.put(uid, true);
1361 } else {
1362 quotaList.delete(uid);
1363 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001364 }
Luke Huangc7bea8662018-08-07 16:04:26 +08001365 } catch (RemoteException | ServiceSpecificException e) {
1366 throw new IllegalStateException(e);
Felipe Leme29e72ea2016-09-08 13:26:55 -07001367 } finally {
1368 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001369 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001370 }
1371 }
1372
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001373 @Override
Felipe Leme65be3022016-03-22 14:53:13 -07001374 public void setUidMeteredNetworkBlacklist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001375 setUidOnMeteredNetworkList(uid, true, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001376 }
1377
1378 @Override
1379 public void setUidMeteredNetworkWhitelist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001380 setUidOnMeteredNetworkList(uid, false, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001381 }
1382
1383 @Override
1384 public boolean setDataSaverModeEnabled(boolean enable) {
Sehee Parka9139bc2017-12-22 13:54:05 +09001385 mContext.enforceCallingOrSelfPermission(NETWORK_SETTINGS, TAG);
1386
Felipe Leme65be3022016-03-22 14:53:13 -07001387 if (DBG) Log.d(TAG, "setDataSaverMode: " + enable);
1388 synchronized (mQuotaLock) {
1389 if (mDataSaverMode == enable) {
1390 Log.w(TAG, "setDataSaverMode(): already " + mDataSaverMode);
1391 return true;
1392 }
Felipe Leme29e72ea2016-09-08 13:26:55 -07001393 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "bandwidthEnableDataSaver");
Felipe Leme65be3022016-03-22 14:53:13 -07001394 try {
1395 final boolean changed = mNetdService.bandwidthEnableDataSaver(enable);
1396 if (changed) {
1397 mDataSaverMode = enable;
1398 } else {
1399 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command silently failed");
1400 }
1401 return changed;
1402 } catch (RemoteException e) {
1403 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command failed", e);
1404 return false;
Felipe Leme29e72ea2016-09-08 13:26:55 -07001405 } finally {
1406 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Felipe Leme65be3022016-03-22 14:53:13 -07001407 }
1408 }
1409 }
1410
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001411 private static UidRangeParcel makeUidRangeParcel(int start, int stop) {
1412 UidRangeParcel range = new UidRangeParcel();
1413 range.start = start;
1414 range.stop = stop;
1415 return range;
1416 }
1417
1418 private static UidRangeParcel[] toStableParcels(UidRange[] ranges) {
1419 UidRangeParcel[] stableRanges = new UidRangeParcel[ranges.length];
1420 for (int i = 0; i < ranges.length; i++) {
1421 stableRanges[i] = makeUidRangeParcel(ranges[i].start, ranges[i].stop);
1422 }
1423 return stableRanges;
1424 }
1425
Felipe Leme65be3022016-03-22 14:53:13 -07001426 @Override
Robin Lee17e61832016-05-09 13:46:28 +01001427 public void setAllowOnlyVpnForUids(boolean add, UidRange[] uidRanges)
1428 throws ServiceSpecificException {
Rubin Xu2ea6c552018-01-11 10:59:19 +00001429 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
Robin Lee17e61832016-05-09 13:46:28 +01001430 try {
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001431 mNetdService.networkRejectNonSecureVpn(add, toStableParcels(uidRanges));
Robin Lee17e61832016-05-09 13:46:28 +01001432 } catch (ServiceSpecificException e) {
1433 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1434 + ": netd command failed", e);
1435 throw e;
1436 } catch (RemoteException e) {
1437 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1438 + ": netd command failed", e);
1439 throw e.rethrowAsRuntimeException();
1440 }
1441 }
1442
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001443 private void applyUidCleartextNetworkPolicy(int uid, int policy) {
Luke Huang473eb872018-07-26 17:33:14 +08001444 final int policyValue;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001445 switch (policy) {
1446 case StrictMode.NETWORK_POLICY_ACCEPT:
Luke Huang473eb872018-07-26 17:33:14 +08001447 policyValue = INetd.PENALTY_POLICY_ACCEPT;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001448 break;
1449 case StrictMode.NETWORK_POLICY_LOG:
Luke Huang473eb872018-07-26 17:33:14 +08001450 policyValue = INetd.PENALTY_POLICY_LOG;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001451 break;
1452 case StrictMode.NETWORK_POLICY_REJECT:
Luke Huang473eb872018-07-26 17:33:14 +08001453 policyValue = INetd.PENALTY_POLICY_REJECT;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001454 break;
1455 default:
1456 throw new IllegalArgumentException("Unknown policy " + policy);
1457 }
1458
1459 try {
Luke Huang473eb872018-07-26 17:33:14 +08001460 mNetdService.strictUidCleartextPenalty(uid, policyValue);
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001461 mUidCleartextPolicy.put(uid, policy);
Luke Huang473eb872018-07-26 17:33:14 +08001462 } catch (RemoteException | ServiceSpecificException e) {
1463 throw new IllegalStateException(e);
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001464 }
1465 }
1466
Robin Lee17e61832016-05-09 13:46:28 +01001467 @Override
Jeff Sharkey605eb792014-11-04 13:34:06 -08001468 public void setUidCleartextNetworkPolicy(int uid, int policy) {
1469 if (Binder.getCallingUid() != uid) {
1470 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1471 }
1472
1473 synchronized (mQuotaLock) {
1474 final int oldPolicy = mUidCleartextPolicy.get(uid, StrictMode.NETWORK_POLICY_ACCEPT);
1475 if (oldPolicy == policy) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001476 // This also ensures we won't needlessly apply an ACCEPT policy if we've just
1477 // enabled strict and the underlying iptables rules are empty.
Jeff Sharkey605eb792014-11-04 13:34:06 -08001478 return;
1479 }
1480
Luke Huang473eb872018-07-26 17:33:14 +08001481 // TODO: remove this code after removing prepareNativeDaemon()
Jeff Sharkey605eb792014-11-04 13:34:06 -08001482 if (!mStrictEnabled) {
1483 // Module isn't enabled yet; stash the requested policy away to
1484 // apply later once the daemon is connected.
1485 mUidCleartextPolicy.put(uid, policy);
1486 return;
1487 }
1488
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001489 // netd does not keep state on strict mode policies, and cannot replace a non-accept
1490 // policy without deleting it first. Rather than add state to netd, just always send
1491 // it an accept policy when switching between two non-accept policies.
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001492 // TODO: consider keeping state in netd so we can simplify this code.
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001493 if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT &&
1494 policy != StrictMode.NETWORK_POLICY_ACCEPT) {
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001495 applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001496 }
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001497
1498 applyUidCleartextNetworkPolicy(uid, policy);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001499 }
1500 }
1501
1502 @Override
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001503 public boolean isBandwidthControlEnabled() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001504 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang56a03a02018-09-07 12:02:16 +08001505 return true;
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001506 }
1507
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001508 private class NetdTetheringStatsProvider extends ITetheringStatsProvider.Stub {
1509 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001510 public NetworkStats getTetherStats(int how) {
1511 // We only need to return per-UID stats. Per-device stats are already counted by
1512 // interface counters.
1513 if (how != STATS_PER_UID) {
1514 return new NetworkStats(SystemClock.elapsedRealtime(), 0);
1515 }
1516
Luke Huang13b79e82018-09-26 14:53:42 +08001517 final TetherStatsParcel[] tetherStatsVec;
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001518 try {
Luke Huang13b79e82018-09-26 14:53:42 +08001519 tetherStatsVec = mNetdService.tetherGetStats();
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001520 } catch (RemoteException | ServiceSpecificException e) {
1521 throw new IllegalStateException("problem parsing tethering stats: ", e);
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001522 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001523
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001524 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(),
Luke Huang13b79e82018-09-26 14:53:42 +08001525 tetherStatsVec.length);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001526 final NetworkStats.Entry entry = new NetworkStats.Entry();
1527
Luke Huang13b79e82018-09-26 14:53:42 +08001528 for (TetherStatsParcel tetherStats : tetherStatsVec) {
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001529 try {
Luke Huang13b79e82018-09-26 14:53:42 +08001530 entry.iface = tetherStats.iface;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001531 entry.uid = UID_TETHERING;
1532 entry.set = SET_DEFAULT;
1533 entry.tag = TAG_NONE;
Luke Huang13b79e82018-09-26 14:53:42 +08001534 entry.rxBytes = tetherStats.rxBytes;
1535 entry.rxPackets = tetherStats.rxPackets;
1536 entry.txBytes = tetherStats.txBytes;
1537 entry.txPackets = tetherStats.txPackets;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001538 stats.combineValues(entry);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001539 } catch (ArrayIndexOutOfBoundsException e) {
Luke Huang13b79e82018-09-26 14:53:42 +08001540 throw new IllegalStateException("invalid tethering stats " + e);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001541 }
1542 }
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001543
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001544 return stats;
1545 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001546
1547 @Override
1548 public void setInterfaceQuota(String iface, long quotaBytes) {
1549 // Do nothing. netd is already informed of quota changes in setInterfaceQuota.
1550 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001551 }
1552
1553 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001554 public NetworkStats getNetworkStatsTethering(int how) {
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001555 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1556
1557 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
1558 synchronized (mTetheringStatsProviders) {
1559 for (ITetheringStatsProvider provider: mTetheringStatsProviders.keySet()) {
1560 try {
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001561 stats.combineAllValues(provider.getTetherStats(how));
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001562 } catch (RemoteException e) {
1563 Log.e(TAG, "Problem reading tethering stats from " +
1564 mTetheringStatsProviders.get(provider) + ": " + e);
1565 }
1566 }
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001567 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001568 return stats;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001569 }
1570
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001571 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001572 public void addVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001573 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang8a462ec2018-08-24 20:33:16 +08001574
1575 try {
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001576 mNetdService.networkAddUidRanges(netId, toStableParcels(ranges));
Luke Huang8a462ec2018-08-24 20:33:16 +08001577 } catch (RemoteException | ServiceSpecificException e) {
1578 throw new IllegalStateException(e);
Chad Brubaker3277620a2013-06-12 13:37:30 -07001579 }
1580 }
1581
1582 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001583 public void removeVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001584 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang8a462ec2018-08-24 20:33:16 +08001585 try {
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001586 mNetdService.networkRemoveUidRanges(netId, toStableParcels(ranges));
Luke Huang8a462ec2018-08-24 20:33:16 +08001587 } catch (RemoteException | ServiceSpecificException e) {
1588 throw new IllegalStateException(e);
Chad Brubakercca54c42013-06-27 17:41:38 -07001589 }
1590 }
1591
1592 @Override
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001593 public void setFirewallEnabled(boolean enabled) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001594 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001595 try {
Luke Huanga241db92018-07-31 20:15:24 +08001596 mNetdService.firewallSetFirewallType(
1597 enabled ? INetd.FIREWALL_WHITELIST : INetd.FIREWALL_BLACKLIST);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001598 mFirewallEnabled = enabled;
Luke Huanga241db92018-07-31 20:15:24 +08001599 } catch (RemoteException | ServiceSpecificException e) {
1600 throw new IllegalStateException(e);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001601 }
1602 }
1603
1604 @Override
1605 public boolean isFirewallEnabled() {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001606 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001607 return mFirewallEnabled;
1608 }
1609
1610 @Override
Jeff Sharkey2c092982012-08-24 11:44:40 -07001611 public void setFirewallInterfaceRule(String iface, boolean allow) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001612 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001613 Preconditions.checkState(mFirewallEnabled);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001614 try {
Luke Huanga241db92018-07-31 20:15:24 +08001615 mNetdService.firewallSetInterfaceRule(iface,
1616 allow ? INetd.FIREWALL_RULE_ALLOW : INetd.FIREWALL_RULE_DENY);
1617 } catch (RemoteException | ServiceSpecificException e) {
1618 throw new IllegalStateException(e);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001619 }
1620 }
1621
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09001622 private void closeSocketsForFirewallChainLocked(int chain, String chainName) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001623 // UID ranges to close sockets on.
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001624 UidRangeParcel[] ranges;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001625 // UID ranges whose sockets we won't touch.
1626 int[] exemptUids;
1627
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001628 int numUids = 0;
Luke Huanga241db92018-07-31 20:15:24 +08001629 if (DBG) Slog.d(TAG, "Closing sockets after enabling chain " + chainName);
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001630 if (getFirewallType(chain) == FIREWALL_WHITELIST) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001631 // Close all sockets on all non-system UIDs...
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001632 ranges = new UidRangeParcel[] {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001633 // TODO: is there a better way of finding all existing users? If so, we could
1634 // specify their ranges here.
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001635 makeUidRangeParcel(Process.FIRST_APPLICATION_UID, Integer.MAX_VALUE),
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001636 };
1637 // ... except for the UIDs that have allow rules.
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001638 synchronized (mRulesLock) {
1639 final SparseIntArray rules = getUidFirewallRulesLR(chain);
1640 exemptUids = new int[rules.size()];
1641 for (int i = 0; i < exemptUids.length; i++) {
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001642 if (rules.valueAt(i) == FIREWALL_RULE_ALLOW) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001643 exemptUids[numUids] = rules.keyAt(i);
1644 numUids++;
1645 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001646 }
1647 }
1648 // Normally, whitelist chains only contain deny rules, so numUids == exemptUids.length.
1649 // But the code does not guarantee this in any way, and at least in one case - if we add
1650 // a UID rule to the firewall, and then disable the firewall - the chains can contain
1651 // the wrong type of rule. In this case, don't close connections that we shouldn't.
1652 //
1653 // TODO: tighten up this code by ensuring we never set the wrong type of rule, and
1654 // fix setFirewallEnabled to grab mQuotaLock and clear rules.
1655 if (numUids != exemptUids.length) {
1656 exemptUids = Arrays.copyOf(exemptUids, numUids);
1657 }
1658 } else {
1659 // Close sockets for every UID that has a deny rule...
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001660 synchronized (mRulesLock) {
1661 final SparseIntArray rules = getUidFirewallRulesLR(chain);
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001662 ranges = new UidRangeParcel[rules.size()];
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001663 for (int i = 0; i < ranges.length; i++) {
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001664 if (rules.valueAt(i) == FIREWALL_RULE_DENY) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001665 int uid = rules.keyAt(i);
Lorenzo Colittib90ad242019-03-18 23:50:34 +09001666 ranges[numUids] = makeUidRangeParcel(uid, uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001667 numUids++;
1668 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001669 }
1670 }
1671 // As above; usually numUids == ranges.length, but not always.
1672 if (numUids != ranges.length) {
1673 ranges = Arrays.copyOf(ranges, numUids);
1674 }
1675 // ... with no exceptions.
1676 exemptUids = new int[0];
1677 }
1678
1679 try {
1680 mNetdService.socketDestroy(ranges, exemptUids);
1681 } catch(RemoteException | ServiceSpecificException e) {
1682 Slog.e(TAG, "Error closing sockets after enabling chain " + chainName + ": " + e);
1683 }
1684 }
1685
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001686 @Override
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001687 public void setFirewallChainEnabled(int chain, boolean enable) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001688 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001689 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001690 synchronized (mRulesLock) {
1691 if (getFirewallChainState(chain) == enable) {
1692 // All is the same, nothing to do. This relies on the fact that netd has child
1693 // chains default detached.
1694 return;
1695 }
1696 setFirewallChainState(chain, enable);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001697 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001698
Luke Huang615e1022018-10-25 11:54:05 +09001699 final String chainName = getFirewallChainName(chain);
Luke Huanga241db92018-07-31 20:15:24 +08001700 if (chain == FIREWALL_CHAIN_NONE) {
Luke Huang615e1022018-10-25 11:54:05 +09001701 throw new IllegalArgumentException("Bad child chain: " + chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001702 }
1703
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001704 try {
Luke Huanga241db92018-07-31 20:15:24 +08001705 mNetdService.firewallEnableChildChain(chain, enable);
1706 } catch (RemoteException | ServiceSpecificException e) {
1707 throw new IllegalStateException(e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001708 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001709
1710 // Close any sockets that were opened by the affected UIDs. This has to be done after
1711 // disabling network connectivity, in case they react to the socket close by reopening
1712 // the connection and race with the iptables commands that enable the firewall. All
1713 // whitelist and blacklist chains allow RSTs through.
1714 if (enable) {
Luke Huang615e1022018-10-25 11:54:05 +09001715 closeSocketsForFirewallChainLocked(chain, chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001716 }
Amith Yamasani15e472352015-04-24 19:06:07 -07001717 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001718 }
1719
Luke Huanga241db92018-07-31 20:15:24 +08001720 private String getFirewallChainName(int chain) {
1721 switch (chain) {
1722 case FIREWALL_CHAIN_STANDBY:
1723 return FIREWALL_CHAIN_NAME_STANDBY;
1724 case FIREWALL_CHAIN_DOZABLE:
1725 return FIREWALL_CHAIN_NAME_DOZABLE;
1726 case FIREWALL_CHAIN_POWERSAVE:
1727 return FIREWALL_CHAIN_NAME_POWERSAVE;
1728 default:
1729 throw new IllegalArgumentException("Bad child chain: " + chain);
1730 }
1731 }
1732
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001733 private int getFirewallType(int chain) {
1734 switch (chain) {
1735 case FIREWALL_CHAIN_STANDBY:
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001736 return FIREWALL_BLACKLIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001737 case FIREWALL_CHAIN_DOZABLE:
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001738 return FIREWALL_WHITELIST;
Felipe Leme011b98f2016-02-10 17:28:31 -08001739 case FIREWALL_CHAIN_POWERSAVE:
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001740 return FIREWALL_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001741 default:
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001742 return isFirewallEnabled() ? FIREWALL_WHITELIST : FIREWALL_BLACKLIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001743 }
1744 }
1745
1746 @Override
1747 public void setFirewallUidRules(int chain, int[] uids, int[] rules) {
1748 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001749 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001750 synchronized (mRulesLock) {
1751 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
1752 SparseIntArray newRules = new SparseIntArray();
1753 // apply new set of rules
1754 for (int index = uids.length - 1; index >= 0; --index) {
1755 int uid = uids[index];
1756 int rule = rules[index];
1757 updateFirewallUidRuleLocked(chain, uid, rule);
1758 newRules.put(uid, rule);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001759 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001760 // collect the rules to remove.
1761 SparseIntArray rulesToRemove = new SparseIntArray();
1762 for (int index = uidFirewallRules.size() - 1; index >= 0; --index) {
1763 int uid = uidFirewallRules.keyAt(index);
1764 if (newRules.indexOfKey(uid) < 0) {
1765 rulesToRemove.put(uid, FIREWALL_RULE_DEFAULT);
1766 }
1767 }
1768 // remove dead rules
1769 for (int index = rulesToRemove.size() - 1; index >= 0; --index) {
1770 int uid = rulesToRemove.keyAt(index);
1771 updateFirewallUidRuleLocked(chain, uid, FIREWALL_RULE_DEFAULT);
1772 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001773 }
1774 try {
1775 switch (chain) {
1776 case FIREWALL_CHAIN_DOZABLE:
1777 mNetdService.firewallReplaceUidChain("fw_dozable", true, uids);
1778 break;
1779 case FIREWALL_CHAIN_STANDBY:
1780 mNetdService.firewallReplaceUidChain("fw_standby", false, uids);
1781 break;
1782 case FIREWALL_CHAIN_POWERSAVE:
1783 mNetdService.firewallReplaceUidChain("fw_powersave", true, uids);
1784 break;
1785 case FIREWALL_CHAIN_NONE:
1786 default:
1787 Slog.d(TAG, "setFirewallUidRules() called on invalid chain: " + chain);
1788 }
1789 } catch (RemoteException e) {
1790 Slog.w(TAG, "Error flushing firewall chain " + chain, e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001791 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001792 }
1793 }
1794
1795 @Override
1796 public void setFirewallUidRule(int chain, int uid, int rule) {
1797 enforceSystemUid();
Felipe Lemea701cad2016-05-12 09:58:14 -07001798 synchronized (mQuotaLock) {
1799 setFirewallUidRuleLocked(chain, uid, rule);
1800 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001801 }
1802
Felipe Lemea701cad2016-05-12 09:58:14 -07001803 private void setFirewallUidRuleLocked(int chain, int uid, int rule) {
1804 if (updateFirewallUidRuleLocked(chain, uid, rule)) {
Luke Huanga241db92018-07-31 20:15:24 +08001805 final int ruleType = getFirewallRuleType(chain, rule);
Amith Yamasani15e472352015-04-24 19:06:07 -07001806 try {
Luke Huanga241db92018-07-31 20:15:24 +08001807 mNetdService.firewallSetUidRule(chain, uid, ruleType);
1808 } catch (RemoteException | ServiceSpecificException e) {
1809 throw new IllegalStateException(e);
Amith Yamasani15e472352015-04-24 19:06:07 -07001810 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001811 }
1812 }
1813
Felipe Lemea701cad2016-05-12 09:58:14 -07001814 // TODO: now that netd supports batching, NMS should not keep these data structures anymore...
1815 private boolean updateFirewallUidRuleLocked(int chain, int uid, int rule) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001816 synchronized (mRulesLock) {
1817 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Felipe Lemea701cad2016-05-12 09:58:14 -07001818
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001819 final int oldUidFirewallRule = uidFirewallRules.get(uid, FIREWALL_RULE_DEFAULT);
1820 if (DBG) {
1821 Slog.d(TAG, "oldRule = " + oldUidFirewallRule
1822 + ", newRule=" + rule + " for uid=" + uid + " on chain " + chain);
1823 }
1824 if (oldUidFirewallRule == rule) {
1825 if (DBG) Slog.d(TAG, "!!!!! Skipping change");
1826 // TODO: eventually consider throwing
1827 return false;
1828 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001829
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001830 String ruleName = getFirewallRuleName(chain, rule);
1831 String oldRuleName = getFirewallRuleName(chain, oldUidFirewallRule);
Felipe Lemea701cad2016-05-12 09:58:14 -07001832
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001833 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
1834 uidFirewallRules.delete(uid);
1835 } else {
1836 uidFirewallRules.put(uid, rule);
1837 }
1838 return !ruleName.equals(oldRuleName);
Felipe Lemea701cad2016-05-12 09:58:14 -07001839 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001840 }
1841
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001842 private @NonNull String getFirewallRuleName(int chain, int rule) {
1843 String ruleName;
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001844 if (getFirewallType(chain) == FIREWALL_WHITELIST) {
1845 if (rule == FIREWALL_RULE_ALLOW) {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001846 ruleName = "allow";
1847 } else {
1848 ruleName = "deny";
1849 }
1850 } else { // Blacklist mode
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001851 if (rule == FIREWALL_RULE_DENY) {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001852 ruleName = "deny";
1853 } else {
1854 ruleName = "allow";
1855 }
1856 }
1857 return ruleName;
1858 }
1859
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001860 private @NonNull SparseIntArray getUidFirewallRulesLR(int chain) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001861 switch (chain) {
1862 case FIREWALL_CHAIN_STANDBY:
1863 return mUidFirewallStandbyRules;
1864 case FIREWALL_CHAIN_DOZABLE:
1865 return mUidFirewallDozableRules;
Felipe Leme011b98f2016-02-10 17:28:31 -08001866 case FIREWALL_CHAIN_POWERSAVE:
1867 return mUidFirewallPowerSaveRules;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001868 case FIREWALL_CHAIN_NONE:
1869 return mUidFirewallRules;
1870 default:
1871 throw new IllegalArgumentException("Unknown chain:" + chain);
1872 }
1873 }
1874
Luke Huanga241db92018-07-31 20:15:24 +08001875 private int getFirewallRuleType(int chain, int rule) {
Luke Huang615e1022018-10-25 11:54:05 +09001876 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
Remi NGUYEN VANdacee142019-02-13 18:28:35 +09001877 return getFirewallType(chain) == FIREWALL_WHITELIST
Luke Huang615e1022018-10-25 11:54:05 +09001878 ? INetd.FIREWALL_RULE_DENY : INetd.FIREWALL_RULE_ALLOW;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001879 }
Luke Huang615e1022018-10-25 11:54:05 +09001880 return rule;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001881 }
1882
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001883 private static void enforceSystemUid() {
1884 final int uid = Binder.getCallingUid();
1885 if (uid != Process.SYSTEM_UID) {
1886 throw new SecurityException("Only available to AID_SYSTEM");
1887 }
1888 }
1889
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001890 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001891 public void registerNetworkActivityListener(INetworkActivityListener listener) {
1892 mNetworkActivityListeners.register(listener);
1893 }
1894
1895 @Override
1896 public void unregisterNetworkActivityListener(INetworkActivityListener listener) {
1897 mNetworkActivityListeners.unregister(listener);
1898 }
1899
1900 @Override
1901 public boolean isNetworkActive() {
1902 synchronized (mNetworkActivityListeners) {
1903 return mNetworkActive || mActiveIdleTimers.isEmpty();
1904 }
1905 }
1906
1907 private void reportNetworkActive() {
1908 final int length = mNetworkActivityListeners.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001909 try {
1910 for (int i = 0; i < length; i++) {
1911 try {
1912 mNetworkActivityListeners.getBroadcastItem(i).onNetworkActive();
Felipe Leme03e689d2016-03-02 16:17:38 -08001913 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001914 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001915 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001916 } finally {
1917 mNetworkActivityListeners.finishBroadcast();
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001918 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001919 }
1920
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001921 @Override
1922 protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -06001923 if (!DumpUtils.checkDumpPermission(mContext, TAG, pw)) return;
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001924
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001925 pw.print("mMobileActivityFromRadio="); pw.print(mMobileActivityFromRadio);
1926 pw.print(" mLastPowerStateFromRadio="); pw.println(mLastPowerStateFromRadio);
1927 pw.print("mNetworkActive="); pw.println(mNetworkActive);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001928
1929 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001930 pw.print("Active quota ifaces: "); pw.println(mActiveQuotas.toString());
1931 pw.print("Active alert ifaces: "); pw.println(mActiveAlerts.toString());
Felipe Leme65be3022016-03-22 14:53:13 -07001932 pw.print("Data saver mode: "); pw.println(mDataSaverMode);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001933 synchronized (mRulesLock) {
1934 dumpUidRuleOnQuotaLocked(pw, "blacklist", mUidRejectOnMetered);
1935 dumpUidRuleOnQuotaLocked(pw, "whitelist", mUidAllowOnMetered);
1936 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001937 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001938
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001939 synchronized (mRulesLock) {
Felipe Leme011b98f2016-02-10 17:28:31 -08001940 dumpUidFirewallRule(pw, "", mUidFirewallRules);
Amith Yamasani15e472352015-04-24 19:06:07 -07001941
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001942 pw.print("UID firewall standby chain enabled: "); pw.println(
1943 getFirewallChainState(FIREWALL_CHAIN_STANDBY));
Felipe Leme011b98f2016-02-10 17:28:31 -08001944 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_STANDBY, mUidFirewallStandbyRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001945
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001946 pw.print("UID firewall dozable chain enabled: "); pw.println(
1947 getFirewallChainState(FIREWALL_CHAIN_DOZABLE));
Felipe Leme011b98f2016-02-10 17:28:31 -08001948 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_DOZABLE, mUidFirewallDozableRules);
Felipe Leme011b98f2016-02-10 17:28:31 -08001949
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001950 pw.println("UID firewall powersave chain enabled: " +
1951 getFirewallChainState(FIREWALL_CHAIN_POWERSAVE));
Felipe Leme011b98f2016-02-10 17:28:31 -08001952 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_POWERSAVE, mUidFirewallPowerSaveRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001953 }
1954
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001955 synchronized (mIdleTimerLock) {
1956 pw.println("Idle timers:");
1957 for (HashMap.Entry<String, IdleTimerParams> ent : mActiveIdleTimers.entrySet()) {
1958 pw.print(" "); pw.print(ent.getKey()); pw.println(":");
1959 IdleTimerParams params = ent.getValue();
1960 pw.print(" timeout="); pw.print(params.timeout);
1961 pw.print(" type="); pw.print(params.type);
1962 pw.print(" networkCount="); pw.println(params.networkCount);
1963 }
1964 }
1965
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001966 pw.print("Firewall enabled: "); pw.println(mFirewallEnabled);
Felipe Leme65be3022016-03-22 14:53:13 -07001967 pw.print("Netd service status: " );
1968 if (mNetdService == null) {
1969 pw.println("disconnected");
1970 } else {
1971 try {
1972 final boolean alive = mNetdService.isAlive();
1973 pw.println(alive ? "alive": "dead");
1974 } catch (RemoteException e) {
1975 pw.println("unreachable");
1976 }
1977 }
1978 }
1979
1980 private void dumpUidRuleOnQuotaLocked(PrintWriter pw, String name, SparseBooleanArray list) {
1981 pw.print("UID bandwith control ");
1982 pw.print(name);
1983 pw.print(" rule: [");
1984 final int size = list.size();
1985 for (int i = 0; i < size; i++) {
1986 pw.print(list.keyAt(i));
1987 if (i < size - 1) pw.print(",");
1988 }
1989 pw.println("]");
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001990 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07001991
Felipe Leme011b98f2016-02-10 17:28:31 -08001992 private void dumpUidFirewallRule(PrintWriter pw, String name, SparseIntArray rules) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001993 pw.print("UID firewall ");
Felipe Leme011b98f2016-02-10 17:28:31 -08001994 pw.print(name);
1995 pw.print(" rule: [");
1996 final int size = rules.size();
1997 for (int i = 0; i < size; i++) {
1998 pw.print(rules.keyAt(i));
1999 pw.print(":");
2000 pw.print(rules.valueAt(i));
2001 if (i < size - 1) pw.print(",");
2002 }
2003 pw.println("]");
2004 }
2005
Robert Greenwalt568891d2014-04-04 13:38:00 -07002006 @Override
Paul Jensen992f2522014-04-28 10:33:11 -04002007 public void addInterfaceToNetwork(String iface, int netId) {
Luke Huang8a462ec2018-08-24 20:33:16 +08002008 modifyInterfaceInNetwork(MODIFY_OPERATION_ADD, netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002009 }
2010
2011 @Override
2012 public void removeInterfaceFromNetwork(String iface, int netId) {
Luke Huang8a462ec2018-08-24 20:33:16 +08002013 modifyInterfaceInNetwork(MODIFY_OPERATION_REMOVE, netId, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002014 }
Paul Jensen992f2522014-04-28 10:33:11 -04002015
Luke Huang8a462ec2018-08-24 20:33:16 +08002016 private void modifyInterfaceInNetwork(boolean add, int netId, String iface) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002017 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen992f2522014-04-28 10:33:11 -04002018 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002019 if (add) {
2020 mNetdService.networkAddInterface(netId, iface);
2021 } else {
2022 mNetdService.networkRemoveInterface(netId, iface);
2023 }
2024 } catch (RemoteException | ServiceSpecificException e) {
2025 throw new IllegalStateException(e);
Paul Jensen992f2522014-04-28 10:33:11 -04002026 }
2027 }
2028
2029 @Override
Robert Greenwalt913c8952014-04-07 17:36:35 -07002030 public void addLegacyRouteForNetId(int netId, RouteInfo routeInfo, int uid) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002031 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2032
Sreeram Ramachandrancc91c7b2014-06-03 18:41:43 -07002033 final LinkAddress la = routeInfo.getDestinationLinkAddress();
Luke Huang8a462ec2018-08-24 20:33:16 +08002034 final String ifName = routeInfo.getInterface();
2035 final String dst = la.toString();
2036 final String nextHop;
Robert Greenwalt568891d2014-04-04 13:38:00 -07002037
Luke Huang8a462ec2018-08-24 20:33:16 +08002038 if (routeInfo.hasGateway()) {
2039 nextHop = routeInfo.getGateway().getHostAddress();
2040 } else {
2041 nextHop = "";
2042 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002043 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002044 mNetdService.networkAddLegacyRoute(netId, ifName, dst, nextHop, uid);
2045 } catch (RemoteException | ServiceSpecificException e) {
2046 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002047 }
2048 }
2049
2050 @Override
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002051 public void setDefaultNetId(int netId) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002052 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2053
2054 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002055 mNetdService.networkSetDefault(netId);
2056 } catch (RemoteException | ServiceSpecificException e) {
2057 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002058 }
2059 }
2060
2061 @Override
2062 public void clearDefaultNetId() {
2063 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2064
2065 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002066 mNetdService.networkClearDefault();
2067 } catch (RemoteException | ServiceSpecificException e) {
2068 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002069 }
2070 }
2071
2072 @Override
Luke Huang8a462ec2018-08-24 20:33:16 +08002073 public void setNetworkPermission(int netId, int permission) {
Paul Jensen487ffe72015-07-24 15:57:11 -04002074 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2075
2076 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002077 mNetdService.networkSetPermissionForNetwork(netId, permission);
2078 } catch (RemoteException | ServiceSpecificException e) {
2079 throw new IllegalStateException(e);
Paul Jensen487ffe72015-07-24 15:57:11 -04002080 }
2081 }
2082
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002083 @Override
2084 public void allowProtect(int uid) {
2085 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2086
2087 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002088 mNetdService.networkSetProtectAllow(uid);
2089 } catch (RemoteException | ServiceSpecificException e) {
2090 throw new IllegalStateException(e);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002091 }
2092 }
2093
2094 @Override
2095 public void denyProtect(int uid) {
2096 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2097
2098 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002099 mNetdService.networkSetProtectDeny(uid);
2100 } catch (RemoteException | ServiceSpecificException e) {
2101 throw new IllegalStateException(e);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002102 }
2103 }
2104
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002105 @Override
2106 public void addInterfaceToLocalNetwork(String iface, List<RouteInfo> routes) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002107 modifyInterfaceInNetwork(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002108
2109 for (RouteInfo route : routes) {
2110 if (!route.isDefaultRoute()) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002111 modifyRoute(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID, route);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002112 }
2113 }
Jimmy Chen086779d2019-03-07 14:15:36 +08002114
2115 // IPv6 link local should be activated always.
2116 modifyRoute(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID,
2117 new RouteInfo(new IpPrefix("fe80::/64"), null, iface));
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002118 }
2119
2120 @Override
2121 public void removeInterfaceFromLocalNetwork(String iface) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002122 modifyInterfaceInNetwork(MODIFY_OPERATION_REMOVE, INetd.LOCAL_NET_ID, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002123 }
Erik Kline6599ee82016-07-17 21:28:39 +09002124
2125 @Override
2126 public int removeRoutesFromLocalNetwork(List<RouteInfo> routes) {
2127 int failures = 0;
2128
2129 for (RouteInfo route : routes) {
2130 try {
Luke Huang706d7ab2018-10-16 15:42:15 +08002131 modifyRoute(MODIFY_OPERATION_REMOVE, INetd.LOCAL_NET_ID, route);
Erik Kline6599ee82016-07-17 21:28:39 +09002132 } catch (IllegalStateException e) {
2133 failures++;
2134 }
2135 }
2136
2137 return failures;
2138 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002139
Sudheer Shankab8f23162017-08-04 13:30:10 -07002140 @Override
2141 public boolean isNetworkRestricted(int uid) {
2142 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2143 return isNetworkRestrictedInternal(uid);
2144 }
2145
2146 private boolean isNetworkRestrictedInternal(int uid) {
2147 synchronized (mRulesLock) {
2148 if (getFirewallChainState(FIREWALL_CHAIN_STANDBY)
2149 && mUidFirewallStandbyRules.get(uid) == FIREWALL_RULE_DENY) {
2150 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of app standby mode");
2151 return true;
2152 }
2153 if (getFirewallChainState(FIREWALL_CHAIN_DOZABLE)
2154 && mUidFirewallDozableRules.get(uid) != FIREWALL_RULE_ALLOW) {
2155 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of device idle mode");
2156 return true;
2157 }
2158 if (getFirewallChainState(FIREWALL_CHAIN_POWERSAVE)
2159 && mUidFirewallPowerSaveRules.get(uid) != FIREWALL_RULE_ALLOW) {
2160 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of power saver mode");
2161 return true;
2162 }
2163 if (mUidRejectOnMetered.get(uid)) {
2164 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of no metered data"
2165 + " in the background");
2166 return true;
2167 }
2168 if (mDataSaverMode && !mUidAllowOnMetered.get(uid)) {
2169 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of data saver mode");
2170 return true;
2171 }
2172 return false;
2173 }
2174 }
2175
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002176 private void setFirewallChainState(int chain, boolean state) {
2177 synchronized (mRulesLock) {
2178 mFirewallChainStates.put(chain, state);
2179 }
2180 }
2181
2182 private boolean getFirewallChainState(int chain) {
2183 synchronized (mRulesLock) {
2184 return mFirewallChainStates.get(chain);
2185 }
2186 }
2187
2188 @VisibleForTesting
2189 class LocalService extends NetworkManagementInternal {
2190 @Override
2191 public boolean isNetworkRestrictedForUid(int uid) {
Sudheer Shankab8f23162017-08-04 13:30:10 -07002192 return isNetworkRestrictedInternal(uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002193 }
2194 }
2195
2196 @VisibleForTesting
2197 Injector getInjector() {
2198 return new Injector();
2199 }
2200
2201 @VisibleForTesting
2202 class Injector {
2203 void setDataSaverMode(boolean dataSaverMode) {
2204 mDataSaverMode = dataSaverMode;
2205 }
2206
2207 void setFirewallChainState(int chain, boolean state) {
2208 NetworkManagementService.this.setFirewallChainState(chain, state);
2209 }
2210
2211 void setFirewallRule(int chain, int uid, int rule) {
2212 synchronized (mRulesLock) {
2213 getUidFirewallRulesLR(chain).put(uid, rule);
2214 }
2215 }
2216
2217 void setUidOnMeteredNetworkList(boolean blacklist, int uid, boolean enable) {
2218 synchronized (mRulesLock) {
2219 if (blacklist) {
2220 mUidRejectOnMetered.put(uid, enable);
2221 } else {
2222 mUidAllowOnMetered.put(uid, enable);
2223 }
2224 }
2225 }
2226
2227 void reset() {
2228 synchronized (mRulesLock) {
2229 setDataSaverMode(false);
2230 final int[] chains = {
2231 FIREWALL_CHAIN_DOZABLE,
2232 FIREWALL_CHAIN_STANDBY,
2233 FIREWALL_CHAIN_POWERSAVE
2234 };
2235 for (int chain : chains) {
2236 setFirewallChainState(chain, false);
2237 getUidFirewallRulesLR(chain).clear();
2238 }
2239 mUidAllowOnMetered.clear();
2240 mUidRejectOnMetered.clear();
2241 }
2242 }
2243 }
San Mehat873f2142010-01-14 10:25:07 -08002244}