blob: b1d6f7353bdb400c40f1f30519cee25c704b91f8 [file] [log] [blame]
San Mehat873f2142010-01-14 10:25:07 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Jeff Sharkey4529bb62011-12-14 10:31:54 -080019import static android.Manifest.permission.CONNECTIVITY_INTERNAL;
Jeff Sharkey47eb1022011-08-25 17:48:52 -070020import static android.Manifest.permission.DUMP;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090021import static android.Manifest.permission.NETWORK_STACK;
Jeff Sharkeyaf75c332011-11-18 12:41:12 -080022import static android.Manifest.permission.SHUTDOWN;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070023import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_DOZABLE;
24import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_DOZABLE;
25import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080026import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070027import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_STANDBY;
28import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NONE;
Felipe Leme011b98f2016-02-10 17:28:31 -080029import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070030import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_STANDBY;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070031import static android.net.NetworkPolicyManager.FIREWALL_RULE_ALLOW;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070032import static android.net.NetworkPolicyManager.FIREWALL_RULE_DEFAULT;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070033import static android.net.NetworkPolicyManager.FIREWALL_RULE_DENY;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070034import static android.net.NetworkPolicyManager.FIREWALL_TYPE_BLACKLIST;
35import static android.net.NetworkPolicyManager.FIREWALL_TYPE_WHITELIST;
Jeff Sharkeyb5d55e32011-08-10 17:53:27 -070036import static android.net.NetworkStats.SET_DEFAULT;
Lorenzo Colittif1912ca2017-08-17 19:23:08 +090037import static android.net.NetworkStats.STATS_PER_UID;
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -080038import static android.net.NetworkStats.TAG_ALL;
Jeff Sharkey1b5a2a92011-06-18 18:34:16 -070039import static android.net.NetworkStats.TAG_NONE;
40import static android.net.NetworkStats.UID_ALL;
Jeff Sharkeyae2c1812011-10-04 13:11:40 -070041import static android.net.TrafficStats.UID_TETHERING;
Lorenzo Colitti79751842013-02-28 16:16:03 +090042import static com.android.server.NetworkManagementService.NetdResponseCode.ClatdStatusResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080043import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceGetCfgResult;
44import static com.android.server.NetworkManagementService.NetdResponseCode.InterfaceListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080045import static com.android.server.NetworkManagementService.NetdResponseCode.IpFwdStatusResult;
46import static com.android.server.NetworkManagementService.NetdResponseCode.TetherDnsFwdTgtListResult;
47import static com.android.server.NetworkManagementService.NetdResponseCode.TetherInterfaceListResult;
48import static com.android.server.NetworkManagementService.NetdResponseCode.TetherStatusResult;
Jeff Sharkeye4984be2013-09-10 21:03:27 -070049import static com.android.server.NetworkManagementService.NetdResponseCode.TetheringStatsListResult;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -080050import static com.android.server.NetworkManagementService.NetdResponseCode.TtyListResult;
Jeff Sharkeya63ba592011-07-19 23:47:12 -070051import static com.android.server.NetworkManagementSocketTagger.PROP_QTAGUID_ENABLED;
Erik Klineb2cfdfb2017-01-18 20:54:14 +090052
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070053import android.annotation.NonNull;
Sudheer Shankadc589ac2016-11-10 15:30:17 -080054import android.app.ActivityManager;
Pierre Imai8e48e672016-04-21 13:30:43 +090055import android.content.ContentResolver;
San Mehat873f2142010-01-14 10:25:07 -080056import android.content.Context;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080057import android.net.ConnectivityManager;
Lorenzo Colitti58967ba2016-02-02 17:21:21 +090058import android.net.INetd;
San Mehat4d02d002010-01-22 16:07:46 -080059import android.net.INetworkManagementEventObserver;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090060import android.net.ITetheringStatsProvider;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070061import android.net.InterfaceConfiguration;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +090062import android.net.IpPrefix;
Robert Greenwalted126402011-01-28 15:34:55 -080063import android.net.LinkAddress;
Lorenzo Colittib57edc52014-08-22 17:10:50 -070064import android.net.Network;
Amith Yamasani15e472352015-04-24 19:06:07 -070065import android.net.NetworkPolicyManager;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070066import android.net.NetworkStats;
Robert Greenwalted126402011-01-28 15:34:55 -080067import android.net.NetworkUtils;
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070068import android.net.RouteInfo;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -040069import android.net.UidRange;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +090070import android.net.util.NetdService;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080071import android.net.wifi.WifiConfiguration;
72import android.net.wifi.WifiConfiguration.KeyMgmt;
Dianne Hackborn91268cf2013-06-13 19:06:50 -070073import android.os.BatteryStats;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070074import android.os.Binder;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070075import android.os.Handler;
Lorenzo Colittia0868002017-07-11 02:29:28 +090076import android.os.IBinder;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080077import android.os.INetworkActivityListener;
San Mehat873f2142010-01-14 10:25:07 -080078import android.os.INetworkManagementService;
Lorenzo Colitti563dc452017-09-01 17:12:34 +090079import android.os.PersistableBundle;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080080import android.os.PowerManager;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070081import android.os.Process;
Jeff Sharkey3df273e2011-12-15 15:47:12 -080082import android.os.RemoteCallbackList;
83import android.os.RemoteException;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070084import android.os.ServiceManager;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +090085import android.os.ServiceSpecificException;
Jeff Sharkey605eb792014-11-04 13:34:06 -080086import android.os.StrictMode;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070087import android.os.SystemClock;
Marco Nelissen62dbb222010-02-18 10:56:30 -080088import android.os.SystemProperties;
Felipe Leme29e72ea2016-09-08 13:26:55 -070089import android.os.Trace;
Pierre Imai8e48e672016-04-21 13:30:43 +090090import android.provider.Settings;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -070091import android.telephony.DataConnectionRealTimeInfo;
92import android.telephony.PhoneStateListener;
Wink Savillefb40dd42014-06-12 17:02:31 -070093import android.telephony.SubscriptionManager;
Wink Saville67e07892014-06-18 16:43:14 -070094import android.telephony.TelephonyManager;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080095import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080096import android.util.Slog;
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -070097import android.util.SparseBooleanArray;
Jeff Sharkey605eb792014-11-04 13:34:06 -080098import android.util.SparseIntArray;
San Mehat873f2142010-01-14 10:25:07 -080099
Jeff Sharkey605eb792014-11-04 13:34:06 -0800100import com.android.internal.annotations.GuardedBy;
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700101import com.android.internal.annotations.VisibleForTesting;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -0700102import com.android.internal.app.IBatteryStats;
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700103import com.android.internal.net.NetworkStatsFactory;
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -0600104import com.android.internal.util.DumpUtils;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800105import com.android.internal.util.HexDump;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700106import com.android.internal.util.Preconditions;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800107import com.android.server.NativeDaemonConnector.Command;
Jeff Sharkey56cd6462013-06-07 15:09:15 -0700108import com.android.server.NativeDaemonConnector.SensitiveArg;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700109import com.google.android.collect.Maps;
Jeff Sharkey4414cea2011-06-24 17:05:24 -0700110
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700111import java.io.BufferedReader;
112import java.io.DataInputStream;
San Mehat873f2142010-01-14 10:25:07 -0800113import java.io.File;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700114import java.io.FileDescriptor;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700115import java.io.FileInputStream;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700116import java.io.IOException;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700117import java.io.InputStreamReader;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700118import java.io.PrintWriter;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700119import java.net.InetAddress;
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700120import java.net.InterfaceAddress;
121import java.net.NetworkInterface;
122import java.net.SocketException;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700123import java.util.ArrayList;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400124import java.util.Arrays;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700125import java.util.HashMap;
jiaguo1da35f72014-01-09 16:39:59 +0800126import java.util.List;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700127import java.util.Map;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700128import java.util.NoSuchElementException;
129import java.util.StringTokenizer;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700130import java.util.concurrent.CountDownLatch;
San Mehat873f2142010-01-14 10:25:07 -0800131
132/**
133 * @hide
134 */
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700135public class NetworkManagementService extends INetworkManagementService.Stub
136 implements Watchdog.Monitor {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900137
138 /**
139 * Helper class that encapsulates NetworkManagementService dependencies and makes them
140 * easier to mock in unit tests.
141 */
142 static class SystemServices {
143 public IBinder getService(String name) {
144 return ServiceManager.getService(name);
145 }
146 public void registerLocalService(NetworkManagementInternal nmi) {
147 LocalServices.addService(NetworkManagementInternal.class, nmi);
148 }
149 public INetd getNetd() {
150 return NetdService.get();
151 }
152 }
153
Amith Yamasani15e472352015-04-24 19:06:07 -0700154 private static final String TAG = "NetworkManagement";
155 private static final boolean DBG = Log.isLoggable(TAG, Log.DEBUG);
Kenny Root305bcbf2010-09-03 07:56:38 -0700156 private static final String NETD_TAG = "NetdConnector";
Lorenzo Colittia0868002017-07-11 02:29:28 +0900157 static final String NETD_SERVICE_NAME = "netd";
Kenny Root305bcbf2010-09-03 07:56:38 -0700158
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400159 private static final int MAX_UID_RANGES_PER_COMMAND = 10;
160
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700161 /**
162 * Name representing {@link #setGlobalAlert(long)} limit when delivered to
163 * {@link INetworkManagementEventObserver#limitReached(String, String)}.
164 */
165 public static final String LIMIT_GLOBAL_ALERT = "globalAlert";
166
Paul Jensen487ffe72015-07-24 15:57:11 -0400167 /**
168 * String to pass to netd to indicate that a network is only accessible
169 * to apps that have the CHANGE_NETWORK_STATE permission.
170 */
171 public static final String PERMISSION_NETWORK = "NETWORK";
172
173 /**
174 * String to pass to netd to indicate that a network is only
175 * accessible to system apps and those with the CONNECTIVITY_INTERNAL
176 * permission.
177 */
178 public static final String PERMISSION_SYSTEM = "SYSTEM";
179
Andrew Scull45f533c2017-05-19 15:37:20 +0100180 static class NetdResponseCode {
Sreeram Ramachandran03666c72014-07-19 23:21:46 -0700181 /* Keep in sync with system/netd/server/ResponseCode.h */
San Mehat873f2142010-01-14 10:25:07 -0800182 public static final int InterfaceListResult = 110;
183 public static final int TetherInterfaceListResult = 111;
184 public static final int TetherDnsFwdTgtListResult = 112;
San Mehat72759df2010-01-19 13:50:37 -0800185 public static final int TtyListResult = 113;
Jeff Sharkeye4984be2013-09-10 21:03:27 -0700186 public static final int TetheringStatsListResult = 114;
San Mehat873f2142010-01-14 10:25:07 -0800187
188 public static final int TetherStatusResult = 210;
189 public static final int IpFwdStatusResult = 211;
San Mehated4fc8a2010-01-22 12:28:36 -0800190 public static final int InterfaceGetCfgResult = 213;
Robert Greenwalte3253922010-02-18 09:23:25 -0800191 public static final int SoftapStatusResult = 214;
San Mehat91cac642010-03-31 14:31:36 -0700192 public static final int InterfaceRxCounterResult = 216;
193 public static final int InterfaceTxCounterResult = 217;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -0700194 public static final int QuotaCounterResult = 220;
195 public static final int TetheringStatsResult = 221;
Selim Gurun84c00c62012-02-27 15:42:38 -0800196 public static final int DnsProxyQueryResult = 222;
Lorenzo Colitti79751842013-02-28 16:16:03 +0900197 public static final int ClatdStatusResult = 223;
Robert Greenwalte3253922010-02-18 09:23:25 -0800198
199 public static final int InterfaceChange = 600;
JP Abgrall12b933d2011-07-14 18:09:22 -0700200 public static final int BandwidthControl = 601;
Haoyu Bai6b7358d2012-07-17 16:36:50 -0700201 public static final int InterfaceClassActivity = 613;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900202 public static final int InterfaceAddressChange = 614;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900203 public static final int InterfaceDnsServerInfo = 615;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900204 public static final int RouteChange = 616;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800205 public static final int StrictCleartext = 617;
San Mehat873f2142010-01-14 10:25:07 -0800206 }
207
Pierre Imai8e48e672016-04-21 13:30:43 +0900208 /* Defaults for resolver parameters. */
209 public static final int DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS = 1800;
210 public static final int DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT = 25;
211 public static final int DNS_RESOLVER_DEFAULT_MIN_SAMPLES = 8;
212 public static final int DNS_RESOLVER_DEFAULT_MAX_SAMPLES = 64;
213
Rebecca Silbersteine2ec94f2016-03-24 13:29:00 -0700214 /**
215 * String indicating a softap command.
216 */
217 static final String SOFT_AP_COMMAND = "softap";
218
219 /**
220 * String passed back to netd connector indicating softap command success.
221 */
222 static final String SOFT_AP_COMMAND_SUCCESS = "Ok";
223
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700224 static final int DAEMON_MSG_MOBILE_CONN_REAL_TIME_INFO = 1;
225
San Mehat873f2142010-01-14 10:25:07 -0800226 /**
227 * Binder context for this service
228 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700229 private final Context mContext;
San Mehat873f2142010-01-14 10:25:07 -0800230
231 /**
232 * connector object for communicating with netd
233 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700234 private final NativeDaemonConnector mConnector;
San Mehat873f2142010-01-14 10:25:07 -0800235
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700236 private final Handler mFgHandler;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700237 private final Handler mDaemonHandler;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700238
Lorenzo Colittia0868002017-07-11 02:29:28 +0900239 private final SystemServices mServices;
240
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900241 private INetd mNetdService;
242
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800243 private IBatteryStats mBatteryStats;
244
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700245 private final Thread mThread;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700246 private CountDownLatch mConnectedSignal = new CountDownLatch(1);
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700247
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800248 private final RemoteCallbackList<INetworkManagementEventObserver> mObservers =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700249 new RemoteCallbackList<>();
San Mehat4d02d002010-01-22 16:07:46 -0800250
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700251 private final NetworkStatsFactory mStatsFactory = new NetworkStatsFactory();
252
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900253 @GuardedBy("mTetheringStatsProviders")
254 private final HashMap<ITetheringStatsProvider, String>
255 mTetheringStatsProviders = Maps.newHashMap();
256
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700257 /**
258 * If both locks need to be held, then they should be obtained in the order:
259 * first {@link #mQuotaLock} and then {@link #mRulesLock}.
260 */
Andrew Scull45f533c2017-05-19 15:37:20 +0100261 private final Object mQuotaLock = new Object();
Andrew Scull519291f2017-05-23 13:11:03 +0100262 private final Object mRulesLock = new Object();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800263
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700264 /** Set of interfaces with active quotas. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800265 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700266 private HashMap<String, Long> mActiveQuotas = Maps.newHashMap();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -0700267 /** Set of interfaces with active alerts. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800268 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700269 private HashMap<String, Long> mActiveAlerts = Maps.newHashMap();
Felipe Leme65be3022016-03-22 14:53:13 -0700270 /** Set of UIDs blacklisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700271 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700272 private SparseBooleanArray mUidRejectOnMetered = new SparseBooleanArray();
273 /** Set of UIDs whitelisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700274 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700275 private SparseBooleanArray mUidAllowOnMetered = new SparseBooleanArray();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800276 /** Set of UIDs with cleartext penalties. */
277 @GuardedBy("mQuotaLock")
278 private SparseIntArray mUidCleartextPolicy = new SparseIntArray();
Amith Yamasani15e472352015-04-24 19:06:07 -0700279 /** Set of UIDs that are to be blocked/allowed by firewall controller. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700280 @GuardedBy("mRulesLock")
Amith Yamasani15e472352015-04-24 19:06:07 -0700281 private SparseIntArray mUidFirewallRules = new SparseIntArray();
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700282 /**
283 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
284 * to application idles.
285 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700286 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700287 private SparseIntArray mUidFirewallStandbyRules = new SparseIntArray();
288 /**
289 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
290 * to device idles.
291 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700292 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700293 private SparseIntArray mUidFirewallDozableRules = new SparseIntArray();
Felipe Leme011b98f2016-02-10 17:28:31 -0800294 /**
295 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
296 * to device on power-save mode.
297 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700298 @GuardedBy("mRulesLock")
Felipe Leme011b98f2016-02-10 17:28:31 -0800299 private SparseIntArray mUidFirewallPowerSaveRules = new SparseIntArray();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700300 /** Set of states for the child firewall chains. True if the chain is active. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700301 @GuardedBy("mRulesLock")
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700302 final SparseBooleanArray mFirewallChainStates = new SparseBooleanArray();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700303
Felipe Leme65be3022016-03-22 14:53:13 -0700304 @GuardedBy("mQuotaLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700305 private volatile boolean mDataSaverMode;
Felipe Leme65be3022016-03-22 14:53:13 -0700306
Andrew Scull45f533c2017-05-19 15:37:20 +0100307 private final Object mIdleTimerLock = new Object();
Haoyu Bai04124232012-06-28 15:26:19 -0700308 /** Set of interfaces with active idle timers. */
309 private static class IdleTimerParams {
310 public final int timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800311 public final int type;
Haoyu Bai04124232012-06-28 15:26:19 -0700312 public int networkCount;
313
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800314 IdleTimerParams(int timeout, int type) {
Haoyu Bai04124232012-06-28 15:26:19 -0700315 this.timeout = timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800316 this.type = type;
Haoyu Bai04124232012-06-28 15:26:19 -0700317 this.networkCount = 1;
318 }
319 }
320 private HashMap<String, IdleTimerParams> mActiveIdleTimers = Maps.newHashMap();
321
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700322 private volatile boolean mBandwidthControlEnabled;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700323 private volatile boolean mFirewallEnabled;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800324 private volatile boolean mStrictEnabled;
Jeff Sharkey350083e2011-06-29 10:45:16 -0700325
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700326 private boolean mMobileActivityFromRadio = false;
327 private int mLastPowerStateFromRadio = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Adam Lesinskie08af192015-03-25 16:42:59 -0700328 private int mLastPowerStateFromWifi = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700329
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800330 private final RemoteCallbackList<INetworkActivityListener> mNetworkActivityListeners =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700331 new RemoteCallbackList<>();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800332 private boolean mNetworkActive;
333
San Mehat873f2142010-01-14 10:25:07 -0800334 /**
335 * Constructs a new NetworkManagementService instance
336 *
337 * @param context Binder context for this service
338 */
Lorenzo Colittia0868002017-07-11 02:29:28 +0900339 private NetworkManagementService(
340 Context context, String socket, SystemServices services) {
San Mehat873f2142010-01-14 10:25:07 -0800341 mContext = context;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900342 mServices = services;
San Mehat4d02d002010-01-22 16:07:46 -0800343
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700344 // make sure this is on the same looper as our NativeDaemonConnector for sync purposes
345 mFgHandler = new Handler(FgThread.get().getLooper());
346
Dianne Hackborn4590e522014-03-24 13:36:46 -0700347 // Don't need this wake lock, since we now have a time stamp for when
348 // the network actually went inactive. (It might be nice to still do this,
349 // but I don't want to do it through the power manager because that pollutes the
350 // battery stats history with pointless noise.)
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700351 //PowerManager pm = (PowerManager)context.getSystemService(Context.POWER_SERVICE);
Dianne Hackborn4590e522014-03-24 13:36:46 -0700352 PowerManager.WakeLock wl = null; //pm.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK, NETD_TAG);
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800353
San Mehat873f2142010-01-14 10:25:07 -0800354 mConnector = new NativeDaemonConnector(
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700355 new NetdCallbackReceiver(), socket, 10, NETD_TAG, 160, wl,
356 FgThread.get().getLooper());
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700357 mThread = new Thread(mConnector, NETD_TAG);
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700358
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700359 mDaemonHandler = new Handler(FgThread.get().getLooper());
Wink Saville67e07892014-06-18 16:43:14 -0700360
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700361 // Add ourself to the Watchdog monitors.
362 Watchdog.getInstance().addMonitor(this);
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700363
Lorenzo Colittia0868002017-07-11 02:29:28 +0900364 mServices.registerLocalService(new LocalService());
Lorenzo Colitti8228eb32017-07-19 06:17:33 +0900365
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900366 synchronized (mTetheringStatsProviders) {
367 mTetheringStatsProviders.put(new NetdTetheringStatsProvider(), "netd");
368 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700369 }
370
371 @VisibleForTesting
372 NetworkManagementService() {
373 mConnector = null;
374 mContext = null;
375 mDaemonHandler = null;
376 mFgHandler = null;
377 mThread = null;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900378 mServices = null;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700379 }
380
Lorenzo Colittia0868002017-07-11 02:29:28 +0900381 static NetworkManagementService create(Context context, String socket, SystemServices services)
Felipe Leme03e689d2016-03-02 16:17:38 -0800382 throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900383 final NetworkManagementService service =
384 new NetworkManagementService(context, socket, services);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700385 final CountDownLatch connectedSignal = service.mConnectedSignal;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700386 if (DBG) Slog.d(TAG, "Creating NetworkManagementService");
387 service.mThread.start();
388 if (DBG) Slog.d(TAG, "Awaiting socket connection");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700389 connectedSignal.await();
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700390 if (DBG) Slog.d(TAG, "Connected");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900391 if (DBG) Slog.d(TAG, "Connecting native netd service");
bohu07cc3bb2016-05-03 15:58:01 -0700392 service.connectNativeNetdService();
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900393 if (DBG) Slog.d(TAG, "Connected");
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700394 return service;
San Mehat873f2142010-01-14 10:25:07 -0800395 }
396
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900397 public static NetworkManagementService create(Context context) throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900398 return create(context, NETD_SERVICE_NAME, new SystemServices());
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900399 }
400
Jeff Sharkey350083e2011-06-29 10:45:16 -0700401 public void systemReady() {
Felipe Leme03e689d2016-03-02 16:17:38 -0800402 if (DBG) {
403 final long start = System.currentTimeMillis();
404 prepareNativeDaemon();
405 final long delta = System.currentTimeMillis() - start;
406 Slog.d(TAG, "Prepared in " + delta + "ms");
407 return;
408 } else {
409 prepareNativeDaemon();
410 }
Jeff Sharkey350083e2011-06-29 10:45:16 -0700411 }
412
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800413 private IBatteryStats getBatteryStats() {
414 synchronized (this) {
415 if (mBatteryStats != null) {
416 return mBatteryStats;
417 }
Lorenzo Colittia0868002017-07-11 02:29:28 +0900418 mBatteryStats =
419 IBatteryStats.Stub.asInterface(mServices.getService(BatteryStats.SERVICE_NAME));
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800420 return mBatteryStats;
421 }
422 }
423
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800424 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800425 public void registerObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800426 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800427 mObservers.register(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800428 }
429
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800430 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800431 public void unregisterObserver(INetworkManagementEventObserver observer) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800432 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800433 mObservers.unregister(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800434 }
435
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900436 @FunctionalInterface
437 private interface NetworkManagementEventCallback {
438 public void sendCallback(INetworkManagementEventObserver o) throws RemoteException;
439 }
440
441 private void invokeForAllObservers(NetworkManagementEventCallback eventCallback) {
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800442 final int length = mObservers.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700443 try {
444 for (int i = 0; i < length; i++) {
445 try {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900446 eventCallback.sendCallback(mObservers.getBroadcastItem(i));
Felipe Leme03e689d2016-03-02 16:17:38 -0800447 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700448 }
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700449 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700450 } finally {
451 mObservers.finishBroadcast();
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700452 }
453 }
454
455 /**
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900456 * Notify our observers of an interface status change
457 */
458 private void notifyInterfaceStatusChanged(String iface, boolean up) {
459 invokeForAllObservers(o -> o.interfaceStatusChanged(iface, up));
460 }
461
462 /**
Mike J. Chenf59c7d02011-06-23 15:33:15 -0700463 * Notify our observers of an interface link state change
Mike J. Chen6143f5f2011-06-23 15:17:51 -0700464 * (typically, an Ethernet cable has been plugged-in or unplugged).
465 */
466 private void notifyInterfaceLinkStateChanged(String iface, boolean up) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900467 invokeForAllObservers(o -> o.interfaceLinkStateChanged(iface, up));
San Mehat4d02d002010-01-22 16:07:46 -0800468 }
469
470 /**
471 * Notify our observers of an interface addition.
472 */
473 private void notifyInterfaceAdded(String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900474 invokeForAllObservers(o -> o.interfaceAdded(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800475 }
476
477 /**
478 * Notify our observers of an interface removal.
479 */
480 private void notifyInterfaceRemoved(String iface) {
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700481 // netd already clears out quota and alerts for removed ifaces; update
482 // our sanity-checking state.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700483 mActiveAlerts.remove(iface);
484 mActiveQuotas.remove(iface);
Jeff Sharkey89b8a212011-10-11 11:58:11 -0700485
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900486 invokeForAllObservers(o -> o.interfaceRemoved(iface));
San Mehat4d02d002010-01-22 16:07:46 -0800487 }
488
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700489 /**
JP Abgrall12b933d2011-07-14 18:09:22 -0700490 * Notify our observers of a limit reached.
491 */
492 private void notifyLimitReached(String limitName, String iface) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900493 invokeForAllObservers(o -> o.limitReached(limitName, iface));
JP Abgrall12b933d2011-07-14 18:09:22 -0700494 }
495
496 /**
Haoyu Baidb3c8672012-06-20 14:29:57 -0700497 * Notify our observers of a change in the data activity state of the interface
498 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700499 private void notifyInterfaceClassActivity(int type, int powerState, long tsNanos,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700500 int uid, boolean fromRadio) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700501 final boolean isMobile = ConnectivityManager.isNetworkTypeMobile(type);
502 if (isMobile) {
503 if (!fromRadio) {
504 if (mMobileActivityFromRadio) {
505 // If this call is not coming from a report from the radio itself, but we
506 // have previously received reports from the radio, then we will take the
507 // power state to just be whatever the radio last reported.
508 powerState = mLastPowerStateFromRadio;
509 }
510 } else {
511 mMobileActivityFromRadio = true;
512 }
513 if (mLastPowerStateFromRadio != powerState) {
514 mLastPowerStateFromRadio = powerState;
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700515 try {
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700516 getBatteryStats().noteMobileRadioPowerState(powerState, tsNanos, uid);
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700517 } catch (RemoteException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700518 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700519 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700520 }
521
Adam Lesinskie08af192015-03-25 16:42:59 -0700522 if (ConnectivityManager.isNetworkTypeWifi(type)) {
523 if (mLastPowerStateFromWifi != powerState) {
524 mLastPowerStateFromWifi = powerState;
525 try {
Adam Lesinski5f056f62016-07-14 16:56:08 -0700526 getBatteryStats().noteWifiRadioPowerState(powerState, tsNanos, uid);
Adam Lesinskie08af192015-03-25 16:42:59 -0700527 } catch (RemoteException e) {
528 }
529 }
530 }
531
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700532 boolean isActive = powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_MEDIUM
533 || powerState == DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH;
534
535 if (!isMobile || fromRadio || !mMobileActivityFromRadio) {
536 // Report the change in data activity. We don't do this if this is a change
537 // on the mobile network, that is not coming from the radio itself, and we
538 // have previously seen change reports from the radio. In that case only
539 // the radio is the authority for the current state.
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900540 final boolean active = isActive;
541 invokeForAllObservers(o -> o.interfaceClassDataActivityChanged(
542 Integer.toString(type), active, tsNanos));
Haoyu Baidb3c8672012-06-20 14:29:57 -0700543 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800544
545 boolean report = false;
546 synchronized (mIdleTimerLock) {
547 if (mActiveIdleTimers.isEmpty()) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700548 // If there are no idle timers, we are not monitoring activity, so we
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800549 // are always considered active.
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700550 isActive = true;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800551 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700552 if (mNetworkActive != isActive) {
553 mNetworkActive = isActive;
554 report = isActive;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800555 }
556 }
557 if (report) {
558 reportNetworkActive();
559 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700560 }
561
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900562 @Override
563 public void registerTetheringStatsProvider(ITetheringStatsProvider provider, String name) {
564 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
565 Preconditions.checkNotNull(provider);
566 synchronized(mTetheringStatsProviders) {
567 mTetheringStatsProviders.put(provider, name);
568 }
569 }
570
571 @Override
572 public void unregisterTetheringStatsProvider(ITetheringStatsProvider provider) {
573 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
574 synchronized(mTetheringStatsProviders) {
575 mTetheringStatsProviders.remove(provider);
576 }
577 }
578
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900579 @Override
580 public void tetherLimitReached(ITetheringStatsProvider provider) {
581 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
582 synchronized(mTetheringStatsProviders) {
583 if (!mTetheringStatsProviders.containsKey(provider)) {
584 return;
585 }
586 // No current code examines the interface parameter in a global alert. Just pass null.
587 notifyLimitReached(LIMIT_GLOBAL_ALERT, null);
588 }
589 }
590
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900591 // Sync the state of the given chain with the native daemon.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700592 private void syncFirewallChainLocked(int chain, String name) {
593 SparseIntArray rules;
594 synchronized (mRulesLock) {
595 final SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900596 // Make a copy of the current rules, and then clear them. This is because
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700597 // setFirewallUidRuleInternal only pushes down rules to the native daemon if they
598 // are different from the current rules stored in the mUidFirewall*Rules array for
599 // the specified chain. If we don't clear the rules, setFirewallUidRuleInternal
600 // will do nothing.
601 rules = uidFirewallRules.clone();
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900602 uidFirewallRules.clear();
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700603 }
604 if (rules.size() > 0) {
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900605 // Now push the rules. setFirewallUidRuleInternal will push each of these down to the
606 // native daemon, and also add them to the mUidFirewall*Rules array for the specified
607 // chain.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700608 if (DBG) Slog.d(TAG, "Pushing " + rules.size() + " active firewall "
609 + name + "UID rules");
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900610 for (int i = 0; i < rules.size(); i++) {
Felipe Lemea701cad2016-05-12 09:58:14 -0700611 setFirewallUidRuleLocked(chain, rules.keyAt(i), rules.valueAt(i));
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900612 }
613 }
614 }
615
bohu07cc3bb2016-05-03 15:58:01 -0700616 private void connectNativeNetdService() {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900617 mNetdService = mServices.getNetd();
bohu07cc3bb2016-05-03 15:58:01 -0700618 }
619
620 /**
621 * Prepare native daemon once connected, enabling modules and pushing any
622 * existing in-memory rules.
623 */
624 private void prepareNativeDaemon() {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900625
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700626 mBandwidthControlEnabled = false;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700627
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700628 // only enable bandwidth control when support exists
629 final boolean hasKernelSupport = new File("/proc/net/xt_qtaguid/ctrl").exists();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800630
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700631 // push any existing quota or UID rules
632 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -0700633
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900634 if (hasKernelSupport) {
635 Slog.d(TAG, "enabling bandwidth control");
636 try {
637 mConnector.execute("bandwidth", "enable");
638 mBandwidthControlEnabled = true;
639 } catch (NativeDaemonConnectorException e) {
640 Log.wtf(TAG, "problem enabling bandwidth controls", e);
641 }
642 } else {
643 Slog.i(TAG, "not enabling bandwidth control");
644 }
645
646 SystemProperties.set(PROP_QTAGUID_ENABLED, mBandwidthControlEnabled ? "1" : "0");
647
648 try {
649 mConnector.execute("strict", "enable");
650 mStrictEnabled = true;
651 } catch (NativeDaemonConnectorException e) {
652 Log.wtf(TAG, "Failed strict enable", e);
653 }
654
Felipe Leme65be3022016-03-22 14:53:13 -0700655 setDataSaverModeEnabled(mDataSaverMode);
656
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700657 int size = mActiveQuotas.size();
658 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800659 if (DBG) Slog.d(TAG, "Pushing " + size + " active quota rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700660 final HashMap<String, Long> activeQuotas = mActiveQuotas;
661 mActiveQuotas = Maps.newHashMap();
662 for (Map.Entry<String, Long> entry : activeQuotas.entrySet()) {
663 setInterfaceQuota(entry.getKey(), entry.getValue());
664 }
665 }
666
667 size = mActiveAlerts.size();
668 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800669 if (DBG) Slog.d(TAG, "Pushing " + size + " active alert rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700670 final HashMap<String, Long> activeAlerts = mActiveAlerts;
671 mActiveAlerts = Maps.newHashMap();
672 for (Map.Entry<String, Long> entry : activeAlerts.entrySet()) {
673 setInterfaceAlert(entry.getKey(), entry.getValue());
674 }
675 }
676
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700677 SparseBooleanArray uidRejectOnQuota = null;
678 SparseBooleanArray uidAcceptOnQuota = null;
679 synchronized (mRulesLock) {
680 size = mUidRejectOnMetered.size();
681 if (size > 0) {
682 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered blacklist rules");
683 uidRejectOnQuota = mUidRejectOnMetered;
684 mUidRejectOnMetered = new SparseBooleanArray();
685 }
686
687 size = mUidAllowOnMetered.size();
688 if (size > 0) {
689 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered whitelist rules");
690 uidAcceptOnQuota = mUidAllowOnMetered;
691 mUidAllowOnMetered = new SparseBooleanArray();
692 }
693 }
694 if (uidRejectOnQuota != null) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700695 for (int i = 0; i < uidRejectOnQuota.size(); i++) {
Felipe Leme65be3022016-03-22 14:53:13 -0700696 setUidMeteredNetworkBlacklist(uidRejectOnQuota.keyAt(i),
697 uidRejectOnQuota.valueAt(i));
698 }
699 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700700 if (uidAcceptOnQuota != null) {
Felipe Leme65be3022016-03-22 14:53:13 -0700701 for (int i = 0; i < uidAcceptOnQuota.size(); i++) {
702 setUidMeteredNetworkWhitelist(uidAcceptOnQuota.keyAt(i),
703 uidAcceptOnQuota.valueAt(i));
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700704 }
705 }
Jeff Sharkey605eb792014-11-04 13:34:06 -0800706
707 size = mUidCleartextPolicy.size();
708 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800709 if (DBG) Slog.d(TAG, "Pushing " + size + " active UID cleartext policies");
Jeff Sharkey605eb792014-11-04 13:34:06 -0800710 final SparseIntArray local = mUidCleartextPolicy;
711 mUidCleartextPolicy = new SparseIntArray();
712 for (int i = 0; i < local.size(); i++) {
713 setUidCleartextNetworkPolicy(local.keyAt(i), local.valueAt(i));
714 }
715 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700716
Robin Leec3736bc2017-03-10 16:19:54 +0000717 setFirewallEnabled(mFirewallEnabled);
Amith Yamasani15e472352015-04-24 19:06:07 -0700718
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700719 syncFirewallChainLocked(FIREWALL_CHAIN_NONE, "");
720 syncFirewallChainLocked(FIREWALL_CHAIN_STANDBY, "standby ");
721 syncFirewallChainLocked(FIREWALL_CHAIN_DOZABLE, "dozable ");
722 syncFirewallChainLocked(FIREWALL_CHAIN_POWERSAVE, "powersave ");
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700723
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700724 final int[] chains =
725 {FIREWALL_CHAIN_STANDBY, FIREWALL_CHAIN_DOZABLE, FIREWALL_CHAIN_POWERSAVE};
726 for (int chain : chains) {
727 if (getFirewallChainState(chain)) {
728 setFirewallChainEnabled(chain, true);
729 }
Felipe Leme011b98f2016-02-10 17:28:31 -0800730 }
Amith Yamasani15e472352015-04-24 19:06:07 -0700731 }
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900732
733 if (mBandwidthControlEnabled) {
734 try {
735 getBatteryStats().noteNetworkStatsEnabled();
736 } catch (RemoteException e) {
737 }
738 }
739
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700740 }
San Mehat4d02d002010-01-22 16:07:46 -0800741
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900742 /**
743 * Notify our observers of a new or updated interface address.
744 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900745 private void notifyAddressUpdated(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900746 invokeForAllObservers(o -> o.addressUpdated(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900747 }
748
749 /**
750 * Notify our observers of a deleted interface address.
751 */
Lorenzo Colitti64483942013-11-15 18:43:52 +0900752 private void notifyAddressRemoved(String iface, LinkAddress address) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900753 invokeForAllObservers(o -> o.addressRemoved(iface, address));
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900754 }
755
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900756 /**
757 * Notify our observers of DNS server information received.
758 */
759 private void notifyInterfaceDnsServerInfo(String iface, long lifetime, String[] addresses) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900760 invokeForAllObservers(o -> o.interfaceDnsServerInfo(iface, lifetime, addresses));
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900761 }
762
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900763 /**
764 * Notify our observers of a route change.
765 */
766 private void notifyRouteChange(String action, RouteInfo route) {
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900767 if (action.equals("updated")) {
768 invokeForAllObservers(o -> o.routeUpdated(route));
769 } else {
770 invokeForAllObservers(o -> o.routeRemoved(route));
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900771 }
772 }
773
San Mehat873f2142010-01-14 10:25:07 -0800774 //
775 // Netd Callback handling
776 //
777
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700778 private class NetdCallbackReceiver implements INativeDaemonConnectorCallbacks {
779 @Override
San Mehat873f2142010-01-14 10:25:07 -0800780 public void onDaemonConnected() {
Felipe Leme65be3022016-03-22 14:53:13 -0700781 Slog.i(TAG, "onDaemonConnected()");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700782 // event is dispatched from internal NDC thread, so we prepare the
783 // daemon back on main thread.
784 if (mConnectedSignal != null) {
bohu07cc3bb2016-05-03 15:58:01 -0700785 // The system is booting and we're connecting to netd for the first time.
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700786 mConnectedSignal.countDown();
787 mConnectedSignal = null;
788 } else {
bohu07cc3bb2016-05-03 15:58:01 -0700789 // We're reconnecting to netd after the socket connection
790 // was interrupted (e.g., if it crashed).
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700791 mFgHandler.post(new Runnable() {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700792 @Override
793 public void run() {
bohu07cc3bb2016-05-03 15:58:01 -0700794 connectNativeNetdService();
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700795 prepareNativeDaemon();
796 }
797 });
798 }
San Mehat873f2142010-01-14 10:25:07 -0800799 }
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -0700800
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700801 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800802 public boolean onCheckHoldWakeLock(int code) {
803 return code == NetdResponseCode.InterfaceClassActivity;
804 }
805
806 @Override
San Mehat873f2142010-01-14 10:25:07 -0800807 public boolean onEvent(int code, String raw, String[] cooked) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900808 String errorMessage = String.format("Invalid event from daemon (%s)", raw);
JP Abgrall12b933d2011-07-14 18:09:22 -0700809 switch (code) {
810 case NetdResponseCode.InterfaceChange:
811 /*
812 * a network interface change occured
813 * Format: "NNN Iface added <name>"
814 * "NNN Iface removed <name>"
815 * "NNN Iface changed <name> <up/down>"
816 * "NNN Iface linkstatus <name> <up/down>"
817 */
818 if (cooked.length < 4 || !cooked[1].equals("Iface")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900819 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700820 }
821 if (cooked[2].equals("added")) {
822 notifyInterfaceAdded(cooked[3]);
823 return true;
824 } else if (cooked[2].equals("removed")) {
825 notifyInterfaceRemoved(cooked[3]);
826 return true;
827 } else if (cooked[2].equals("changed") && cooked.length == 5) {
828 notifyInterfaceStatusChanged(cooked[3], cooked[4].equals("up"));
829 return true;
830 } else if (cooked[2].equals("linkstate") && cooked.length == 5) {
831 notifyInterfaceLinkStateChanged(cooked[3], cooked[4].equals("up"));
832 return true;
833 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900834 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700835 // break;
836 case NetdResponseCode.BandwidthControl:
837 /*
838 * Bandwidth control needs some attention
839 * Format: "NNN limit alert <alertName> <ifaceName>"
840 */
841 if (cooked.length < 5 || !cooked[1].equals("limit")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900842 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700843 }
844 if (cooked[2].equals("alert")) {
845 notifyLimitReached(cooked[3], cooked[4]);
846 return true;
847 }
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900848 throw new IllegalStateException(errorMessage);
JP Abgrall12b933d2011-07-14 18:09:22 -0700849 // break;
Haoyu Baidb3c8672012-06-20 14:29:57 -0700850 case NetdResponseCode.InterfaceClassActivity:
851 /*
852 * An network interface class state changed (active/idle)
853 * Format: "NNN IfaceClass <active/idle> <label>"
854 */
855 if (cooked.length < 4 || !cooked[1].equals("IfaceClass")) {
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900856 throw new IllegalStateException(errorMessage);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700857 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700858 long timestampNanos = 0;
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700859 int processUid = -1;
860 if (cooked.length >= 5) {
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700861 try {
862 timestampNanos = Long.parseLong(cooked[4]);
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700863 if (cooked.length == 6) {
864 processUid = Integer.parseInt(cooked[5]);
865 }
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700866 } catch(NumberFormatException ne) {}
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700867 } else {
868 timestampNanos = SystemClock.elapsedRealtimeNanos();
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700869 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700870 boolean isActive = cooked[2].equals("active");
Ashish Sharma0535a9f2014-03-12 18:42:23 -0700871 notifyInterfaceClassActivity(Integer.parseInt(cooked[3]),
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700872 isActive ? DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -0700873 : DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
874 timestampNanos, processUid, false);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700875 return true;
876 // break;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900877 case NetdResponseCode.InterfaceAddressChange:
878 /*
879 * A network address change occurred
880 * Format: "NNN Address updated <addr> <iface> <flags> <scope>"
881 * "NNN Address removed <addr> <iface> <flags> <scope>"
882 */
Lorenzo Colittia9626c12013-11-04 17:44:09 +0900883 if (cooked.length < 7 || !cooked[1].equals("Address")) {
884 throw new IllegalStateException(errorMessage);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900885 }
886
Lorenzo Colitti64483942013-11-15 18:43:52 +0900887 String iface = cooked[4];
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900888 LinkAddress address;
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900889 try {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900890 int flags = Integer.parseInt(cooked[5]);
891 int scope = Integer.parseInt(cooked[6]);
892 address = new LinkAddress(cooked[3], flags, scope);
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900893 } catch(NumberFormatException e) { // Non-numeric lifetime or scope.
894 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti64483942013-11-15 18:43:52 +0900895 } catch(IllegalArgumentException e) { // Malformed/invalid IP address.
Lorenzo Colitti5ad421a2013-11-17 15:05:02 +0900896 throw new IllegalStateException(errorMessage, e);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900897 }
898
899 if (cooked[2].equals("updated")) {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900900 notifyAddressUpdated(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900901 } else {
Lorenzo Colitti64483942013-11-15 18:43:52 +0900902 notifyAddressRemoved(iface, address);
Lorenzo Colitti5c7daac2013-08-05 10:39:37 +0900903 }
904 return true;
905 // break;
Lorenzo Colitti5ae4a532013-10-31 11:59:46 +0900906 case NetdResponseCode.InterfaceDnsServerInfo:
907 /*
908 * Information about available DNS servers has been received.
909 * Format: "NNN DnsInfo servers <interface> <lifetime> <servers>"
910 */
911 long lifetime; // Actually a 32-bit unsigned integer.
912
913 if (cooked.length == 6 &&
914 cooked[1].equals("DnsInfo") &&
915 cooked[2].equals("servers")) {
916 try {
917 lifetime = Long.parseLong(cooked[4]);
918 } catch (NumberFormatException e) {
919 throw new IllegalStateException(errorMessage);
920 }
921 String[] servers = cooked[5].split(",");
922 notifyInterfaceDnsServerInfo(cooked[3], lifetime, servers);
923 }
924 return true;
925 // break;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +0900926 case NetdResponseCode.RouteChange:
927 /*
928 * A route has been updated or removed.
929 * Format: "NNN Route <updated|removed> <dst> [via <gateway] [dev <iface>]"
930 */
931 if (!cooked[1].equals("Route") || cooked.length < 6) {
932 throw new IllegalStateException(errorMessage);
933 }
934
935 String via = null;
936 String dev = null;
937 boolean valid = true;
938 for (int i = 4; (i + 1) < cooked.length && valid; i += 2) {
939 if (cooked[i].equals("dev")) {
940 if (dev == null) {
941 dev = cooked[i+1];
942 } else {
943 valid = false; // Duplicate interface.
944 }
945 } else if (cooked[i].equals("via")) {
946 if (via == null) {
947 via = cooked[i+1];
948 } else {
949 valid = false; // Duplicate gateway.
950 }
951 } else {
952 valid = false; // Unknown syntax.
953 }
954 }
955 if (valid) {
956 try {
957 // InetAddress.parseNumericAddress(null) inexplicably returns ::1.
958 InetAddress gateway = null;
959 if (via != null) gateway = InetAddress.parseNumericAddress(via);
960 RouteInfo route = new RouteInfo(new IpPrefix(cooked[3]), gateway, dev);
961 notifyRouteChange(cooked[2], route);
962 return true;
963 } catch (IllegalArgumentException e) {}
964 }
965 throw new IllegalStateException(errorMessage);
966 // break;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800967 case NetdResponseCode.StrictCleartext:
968 final int uid = Integer.parseInt(cooked[1]);
969 final byte[] firstPacket = HexDump.hexStringToByteArray(cooked[2]);
970 try {
Sudheer Shankadc589ac2016-11-10 15:30:17 -0800971 ActivityManager.getService().notifyCleartextNetwork(uid, firstPacket);
Jeff Sharkey605eb792014-11-04 13:34:06 -0800972 } catch (RemoteException ignored) {
973 }
974 break;
JP Abgrall12b933d2011-07-14 18:09:22 -0700975 default: break;
Robert Greenwalte3253922010-02-18 09:23:25 -0800976 }
977 return false;
San Mehat873f2142010-01-14 10:25:07 -0800978 }
979 }
980
San Mehated4fc8a2010-01-22 12:28:36 -0800981
San Mehat873f2142010-01-14 10:25:07 -0800982 //
983 // INetworkManagementService members
984 //
Erik Kline4e37b702016-07-05 11:34:21 +0900985 @Override
986 public INetd getNetdService() throws RemoteException {
987 final CountDownLatch connectedSignal = mConnectedSignal;
988 if (connectedSignal != null) {
989 try {
990 connectedSignal.await();
991 } catch (InterruptedException ignored) {}
992 }
993
994 return mNetdService;
995 }
San Mehat873f2142010-01-14 10:25:07 -0800996
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800997 @Override
998 public String[] listInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800999 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001000 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001001 return NativeDaemonEvent.filterMessageList(
1002 mConnector.executeForList("interface", "list"), InterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001003 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001004 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001005 }
San Mehated4fc8a2010-01-22 12:28:36 -08001006 }
1007
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001008 @Override
1009 public InterfaceConfiguration getInterfaceConfig(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001010 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001011
1012 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001013 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001014 event = mConnector.execute("interface", "getcfg", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001015 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001016 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001017 }
San Mehated4fc8a2010-01-22 12:28:36 -08001018
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001019 event.checkCode(InterfaceGetCfgResult);
1020
1021 // Rsp: 213 xx:xx:xx:xx:xx:xx yyy.yyy.yyy.yyy zzz flag1 flag2 flag3
1022 final StringTokenizer st = new StringTokenizer(event.getMessage());
San Mehated4fc8a2010-01-22 12:28:36 -08001023
Kenny Roota80ce062010-06-01 13:23:53 -07001024 InterfaceConfiguration cfg;
San Mehated4fc8a2010-01-22 12:28:36 -08001025 try {
Kenny Roota80ce062010-06-01 13:23:53 -07001026 cfg = new InterfaceConfiguration();
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001027 cfg.setHardwareAddress(st.nextToken(" "));
Robert Greenwalted126402011-01-28 15:34:55 -08001028 InetAddress addr = null;
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001029 int prefixLength = 0;
Kenny Roota80ce062010-06-01 13:23:53 -07001030 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001031 addr = NetworkUtils.numericToInetAddress(st.nextToken());
Robert Greenwalte5903732011-02-22 16:00:42 -08001032 } catch (IllegalArgumentException iae) {
1033 Slog.e(TAG, "Failed to parse ipaddr", iae);
Kenny Roota80ce062010-06-01 13:23:53 -07001034 }
1035
1036 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001037 prefixLength = Integer.parseInt(st.nextToken());
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001038 } catch (NumberFormatException nfe) {
1039 Slog.e(TAG, "Failed to parse prefixLength", nfe);
Kenny Roota80ce062010-06-01 13:23:53 -07001040 }
Robert Greenwalt04808c22010-12-13 17:01:41 -08001041
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001042 cfg.setLinkAddress(new LinkAddress(addr, prefixLength));
1043 while (st.hasMoreTokens()) {
1044 cfg.setFlag(st.nextToken());
1045 }
Kenny Roota80ce062010-06-01 13:23:53 -07001046 } catch (NoSuchElementException nsee) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001047 throw new IllegalStateException("Invalid response from daemon: " + event);
San Mehated4fc8a2010-01-22 12:28:36 -08001048 }
San Mehated4fc8a2010-01-22 12:28:36 -08001049 return cfg;
1050 }
1051
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001052 @Override
1053 public void setInterfaceConfig(String iface, InterfaceConfiguration cfg) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001054 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001055 LinkAddress linkAddr = cfg.getLinkAddress();
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001056 if (linkAddr == null || linkAddr.getAddress() == null) {
1057 throw new IllegalStateException("Null LinkAddress given");
Robert Greenwalted126402011-01-28 15:34:55 -08001058 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001059
1060 final Command cmd = new Command("interface", "setcfg", iface,
Robert Greenwalt2d2afd12011-02-01 15:30:46 -08001061 linkAddr.getAddress().getHostAddress(),
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09001062 linkAddr.getPrefixLength());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001063 for (String flag : cfg.getFlags()) {
1064 cmd.appendArg(flag);
1065 }
1066
Kenny Roota80ce062010-06-01 13:23:53 -07001067 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001068 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001069 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001070 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001071 }
San Mehat873f2142010-01-14 10:25:07 -08001072 }
1073
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001074 @Override
1075 public void setInterfaceDown(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001076 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001077 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001078 ifcg.setInterfaceDown();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001079 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001080 }
1081
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001082 @Override
1083 public void setInterfaceUp(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001084 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001085 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -08001086 ifcg.setInterfaceUp();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001087 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -07001088 }
1089
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001090 @Override
1091 public void setInterfaceIpv6PrivacyExtensions(String iface, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001092 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sheriff73293612011-09-14 12:31:56 -07001093 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001094 mConnector.execute(
1095 "interface", "ipv6privacyextensions", iface, enable ? "enable" : "disable");
Irfan Sheriff73293612011-09-14 12:31:56 -07001096 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001097 throw e.rethrowAsParcelableException();
Irfan Sheriff73293612011-09-14 12:31:56 -07001098 }
1099 }
1100
Irfan Sherifff5600612011-06-16 10:26:28 -07001101 /* TODO: This is right now a IPv4 only function. Works for wifi which loses its
1102 IPv6 addresses on interface down, but we need to do full clean up here */
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001103 @Override
1104 public void clearInterfaceAddresses(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001105 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sherifff5600612011-06-16 10:26:28 -07001106 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001107 mConnector.execute("interface", "clearaddrs", iface);
Irfan Sherifff5600612011-06-16 10:26:28 -07001108 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001109 throw e.rethrowAsParcelableException();
Irfan Sherifff5600612011-06-16 10:26:28 -07001110 }
1111 }
1112
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001113 @Override
1114 public void enableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001115 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001116 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001117 mConnector.execute("interface", "ipv6", iface, "enable");
repo sync7960d9f2011-09-29 12:40:02 -07001118 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001119 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001120 }
1121 }
1122
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001123 @Override
Joel Scherpelz2db10742017-06-07 15:38:38 +09001124 public void setIPv6AddrGenMode(String iface, int mode) throws ServiceSpecificException {
1125 try {
1126 mNetdService.setIPv6AddrGenMode(iface, mode);
1127 } catch (RemoteException e) {
1128 throw e.rethrowAsRuntimeException();
1129 }
1130 }
1131
1132 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001133 public void disableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001134 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -07001135 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001136 mConnector.execute("interface", "ipv6", iface, "disable");
repo sync7960d9f2011-09-29 12:40:02 -07001137 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001138 throw e.rethrowAsParcelableException();
repo sync7960d9f2011-09-29 12:40:02 -07001139 }
1140 }
1141
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001142 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001143 public void addRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001144 modifyRoute("add", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001145 }
1146
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001147 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001148 public void removeRoute(int netId, RouteInfo route) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001149 modifyRoute("remove", "" + netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001150 }
1151
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001152 private void modifyRoute(String action, String netId, RouteInfo route) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001153 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001154
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001155 final Command cmd = new Command("network", "route", action, netId);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001156
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001157 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -07001158 cmd.appendArg(route.getInterface());
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +09001159 cmd.appendArg(route.getDestination().toString());
1160
1161 switch (route.getType()) {
1162 case RouteInfo.RTN_UNICAST:
1163 if (route.hasGateway()) {
1164 cmd.appendArg(route.getGateway().getHostAddress());
1165 }
1166 break;
1167 case RouteInfo.RTN_UNREACHABLE:
1168 cmd.appendArg("unreachable");
1169 break;
1170 case RouteInfo.RTN_THROW:
1171 cmd.appendArg("throw");
1172 break;
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07001173 }
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001174
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001175 try {
1176 mConnector.execute(cmd);
1177 } catch (NativeDaemonConnectorException e) {
1178 throw e.rethrowAsParcelableException();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001179 }
1180 }
1181
1182 private ArrayList<String> readRouteList(String filename) {
1183 FileInputStream fstream = null;
Christopher Wiley212b95f2016-08-02 11:38:57 -07001184 ArrayList<String> list = new ArrayList<>();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -07001185
1186 try {
1187 fstream = new FileInputStream(filename);
1188 DataInputStream in = new DataInputStream(fstream);
1189 BufferedReader br = new BufferedReader(new InputStreamReader(in));
1190 String s;
1191
1192 // throw away the title line
1193
1194 while (((s = br.readLine()) != null) && (s.length() != 0)) {
1195 list.add(s);
1196 }
1197 } catch (IOException ex) {
1198 // return current list, possibly empty
1199 } finally {
1200 if (fstream != null) {
1201 try {
1202 fstream.close();
1203 } catch (IOException ex) {}
1204 }
1205 }
1206
1207 return list;
1208 }
1209
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001210 @Override
sy.yun9d9b74a2013-09-02 05:24:09 +09001211 public void setMtu(String iface, int mtu) {
1212 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1213
1214 final NativeDaemonEvent event;
1215 try {
1216 event = mConnector.execute("interface", "setmtu", iface, mtu);
1217 } catch (NativeDaemonConnectorException e) {
1218 throw e.rethrowAsParcelableException();
1219 }
1220 }
1221
1222 @Override
San Mehat873f2142010-01-14 10:25:07 -08001223 public void shutdown() {
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001224 // TODO: remove from aidl if nobody calls externally
1225 mContext.enforceCallingOrSelfPermission(SHUTDOWN, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001226
Felipe Leme03e689d2016-03-02 16:17:38 -08001227 Slog.i(TAG, "Shutting down");
San Mehat873f2142010-01-14 10:25:07 -08001228 }
1229
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001230 @Override
San Mehat873f2142010-01-14 10:25:07 -08001231 public boolean getIpForwardingEnabled() throws IllegalStateException{
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001232 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001233
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001234 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001235 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001236 event = mConnector.execute("ipfwd", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001237 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001238 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001239 }
San Mehat873f2142010-01-14 10:25:07 -08001240
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001241 // 211 Forwarding enabled
1242 event.checkCode(IpFwdStatusResult);
1243 return event.getMessage().endsWith("enabled");
San Mehat873f2142010-01-14 10:25:07 -08001244 }
1245
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001246 @Override
1247 public void setIpForwardingEnabled(boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001248 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001249 try {
Nilesh Poddarf3d4a582015-02-24 12:11:11 -08001250 mConnector.execute("ipfwd", enable ? "enable" : "disable", "tethering");
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001251 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001252 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001253 }
San Mehat873f2142010-01-14 10:25:07 -08001254 }
1255
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001256 @Override
1257 public void startTethering(String[] dhcpRange) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001258 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001259 // cmd is "tether start first_start first_stop second_start second_stop ..."
1260 // an odd number of addrs will fail
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001261
1262 final Command cmd = new Command("tether", "start");
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001263 for (String d : dhcpRange) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001264 cmd.appendArg(d);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001265 }
Kenny Roota80ce062010-06-01 13:23:53 -07001266
1267 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001268 mConnector.execute(cmd);
Kenny Roota80ce062010-06-01 13:23:53 -07001269 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001270 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001271 }
San Mehat873f2142010-01-14 10:25:07 -08001272 }
1273
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001274 @Override
1275 public void stopTethering() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001276 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001277 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001278 mConnector.execute("tether", "stop");
Kenny Roota80ce062010-06-01 13:23:53 -07001279 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001280 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001281 }
San Mehat873f2142010-01-14 10:25:07 -08001282 }
1283
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001284 @Override
1285 public boolean isTetheringStarted() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001286 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001287
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001288 final NativeDaemonEvent event;
Kenny Roota80ce062010-06-01 13:23:53 -07001289 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001290 event = mConnector.execute("tether", "status");
Kenny Roota80ce062010-06-01 13:23:53 -07001291 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001292 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001293 }
San Mehat873f2142010-01-14 10:25:07 -08001294
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001295 // 210 Tethering services started
1296 event.checkCode(TetherStatusResult);
1297 return event.getMessage().endsWith("started");
San Mehat873f2142010-01-14 10:25:07 -08001298 }
Matthew Xiefe19f122012-07-12 16:03:32 -07001299
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001300 @Override
1301 public void tetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001302 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001303 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001304 mConnector.execute("tether", "interface", "add", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001305 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001306 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001307 }
Christopher Wiley212b95f2016-08-02 11:38:57 -07001308 List<RouteInfo> routes = new ArrayList<>();
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001309 // The RouteInfo constructor truncates the LinkAddress to a network prefix, thus making it
1310 // suitable to use as a route destination.
1311 routes.add(new RouteInfo(getInterfaceConfig(iface).getLinkAddress(), null, iface));
1312 addInterfaceToLocalNetwork(iface, routes);
San Mehat873f2142010-01-14 10:25:07 -08001313 }
1314
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001315 @Override
San Mehat873f2142010-01-14 10:25:07 -08001316 public void untetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001317 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001318 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001319 mConnector.execute("tether", "interface", "remove", iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001320 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001321 throw e.rethrowAsParcelableException();
Erik Kline1f4278a2016-08-16 16:46:33 +09001322 } finally {
1323 removeInterfaceFromLocalNetwork(iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001324 }
San Mehat873f2142010-01-14 10:25:07 -08001325 }
1326
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001327 @Override
1328 public String[] listTetheredInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001329 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001330 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001331 return NativeDaemonEvent.filterMessageList(
1332 mConnector.executeForList("tether", "interface", "list"),
1333 TetherInterfaceListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001334 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001335 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001336 }
San Mehat873f2142010-01-14 10:25:07 -08001337 }
1338
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001339 @Override
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001340 public void setDnsForwarders(Network network, String[] dns) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001341 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001342
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001343 int netId = (network != null) ? network.netId : ConnectivityManager.NETID_UNSET;
1344 final Command cmd = new Command("tether", "dns", "set", netId);
1345
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001346 for (String s : dns) {
1347 cmd.appendArg(NetworkUtils.numericToInetAddress(s).getHostAddress());
1348 }
1349
San Mehat873f2142010-01-14 10:25:07 -08001350 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001351 mConnector.execute(cmd);
1352 } catch (NativeDaemonConnectorException e) {
1353 throw e.rethrowAsParcelableException();
San Mehat873f2142010-01-14 10:25:07 -08001354 }
1355 }
1356
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001357 @Override
1358 public String[] getDnsForwarders() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001359 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001360 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001361 return NativeDaemonEvent.filterMessageList(
1362 mConnector.executeForList("tether", "dns", "list"), TetherDnsFwdTgtListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001363 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001364 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001365 }
San Mehat873f2142010-01-14 10:25:07 -08001366 }
1367
jiaguo1da35f72014-01-09 16:39:59 +08001368 private List<InterfaceAddress> excludeLinkLocal(List<InterfaceAddress> addresses) {
Christopher Wiley212b95f2016-08-02 11:38:57 -07001369 ArrayList<InterfaceAddress> filtered = new ArrayList<>(addresses.size());
jiaguo1da35f72014-01-09 16:39:59 +08001370 for (InterfaceAddress ia : addresses) {
1371 if (!ia.getAddress().isLinkLocalAddress())
1372 filtered.add(ia);
1373 }
1374 return filtered;
1375 }
1376
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001377 private void modifyInterfaceForward(boolean add, String fromIface, String toIface) {
1378 final Command cmd = new Command("ipfwd", add ? "add" : "remove", fromIface, toIface);
1379 try {
1380 mConnector.execute(cmd);
1381 } catch (NativeDaemonConnectorException e) {
1382 throw e.rethrowAsParcelableException();
1383 }
1384 }
1385
1386 @Override
1387 public void startInterfaceForwarding(String fromIface, String toIface) {
1388 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1389 modifyInterfaceForward(true, fromIface, toIface);
1390 }
1391
1392 @Override
1393 public void stopInterfaceForwarding(String fromIface, String toIface) {
1394 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1395 modifyInterfaceForward(false, fromIface, toIface);
1396 }
1397
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001398 private void modifyNat(String action, String internalInterface, String externalInterface)
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001399 throws SocketException {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001400 final Command cmd = new Command("nat", action, internalInterface, externalInterface);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001401
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001402 final NetworkInterface internalNetworkInterface = NetworkInterface.getByName(
1403 internalInterface);
Robert Greenwalte83d1812011-11-21 14:44:39 -08001404 if (internalNetworkInterface == null) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001405 cmd.appendArg("0");
Robert Greenwalte83d1812011-11-21 14:44:39 -08001406 } else {
jiaguo1da35f72014-01-09 16:39:59 +08001407 // Don't touch link-local routes, as link-local addresses aren't routable,
1408 // kernel creates link-local routes on all interfaces automatically
1409 List<InterfaceAddress> interfaceAddresses = excludeLinkLocal(
1410 internalNetworkInterface.getInterfaceAddresses());
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001411 cmd.appendArg(interfaceAddresses.size());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001412 for (InterfaceAddress ia : interfaceAddresses) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001413 InetAddress addr = NetworkUtils.getNetworkPart(
1414 ia.getAddress(), ia.getNetworkPrefixLength());
1415 cmd.appendArg(addr.getHostAddress() + "/" + ia.getNetworkPrefixLength());
Robert Greenwalte83d1812011-11-21 14:44:39 -08001416 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001417 }
1418
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001419 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001420 mConnector.execute(cmd);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001421 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001422 throw e.rethrowAsParcelableException();
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001423 }
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001424 }
1425
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001426 @Override
1427 public void enableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001428 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001429 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001430 modifyNat("enable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001431 } catch (SocketException e) {
1432 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001433 }
San Mehat873f2142010-01-14 10:25:07 -08001434 }
1435
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001436 @Override
1437 public void disableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001438 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001439 try {
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -07001440 modifyNat("disable", internalInterface, externalInterface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001441 } catch (SocketException e) {
1442 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001443 }
San Mehat873f2142010-01-14 10:25:07 -08001444 }
San Mehat72759df2010-01-19 13:50:37 -08001445
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001446 @Override
1447 public String[] listTtys() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001448 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001449 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001450 return NativeDaemonEvent.filterMessageList(
1451 mConnector.executeForList("list_ttys"), TtyListResult);
Kenny Roota80ce062010-06-01 13:23:53 -07001452 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001453 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001454 }
San Mehat72759df2010-01-19 13:50:37 -08001455 }
1456
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001457 @Override
1458 public void attachPppd(
1459 String tty, String localAddr, String remoteAddr, String dns1Addr, String dns2Addr) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001460 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat72759df2010-01-19 13:50:37 -08001461 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001462 mConnector.execute("pppd", "attach", tty,
Robert Greenwalte5903732011-02-22 16:00:42 -08001463 NetworkUtils.numericToInetAddress(localAddr).getHostAddress(),
1464 NetworkUtils.numericToInetAddress(remoteAddr).getHostAddress(),
1465 NetworkUtils.numericToInetAddress(dns1Addr).getHostAddress(),
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001466 NetworkUtils.numericToInetAddress(dns2Addr).getHostAddress());
Kenny Roota80ce062010-06-01 13:23:53 -07001467 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001468 throw e.rethrowAsParcelableException();
San Mehat72759df2010-01-19 13:50:37 -08001469 }
1470 }
1471
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001472 @Override
1473 public void detachPppd(String tty) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001474 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001475 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001476 mConnector.execute("pppd", "detach", tty);
Kenny Roota80ce062010-06-01 13:23:53 -07001477 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001478 throw e.rethrowAsParcelableException();
Kenny Roota80ce062010-06-01 13:23:53 -07001479 }
San Mehat72759df2010-01-19 13:50:37 -08001480 }
Robert Greenwaltce1200d2010-02-18 11:25:54 -08001481
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001482 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001483 public void addIdleTimer(String iface, int timeout, final int type) {
Haoyu Bai04124232012-06-28 15:26:19 -07001484 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1485
1486 if (DBG) Slog.d(TAG, "Adding idletimer");
1487
1488 synchronized (mIdleTimerLock) {
1489 IdleTimerParams params = mActiveIdleTimers.get(iface);
1490 if (params != null) {
1491 // the interface already has idletimer, update network count
1492 params.networkCount++;
1493 return;
1494 }
1495
1496 try {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001497 mConnector.execute("idletimer", "add", iface, Integer.toString(timeout),
1498 Integer.toString(type));
Haoyu Bai04124232012-06-28 15:26:19 -07001499 } catch (NativeDaemonConnectorException e) {
1500 throw e.rethrowAsParcelableException();
1501 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001502 mActiveIdleTimers.put(iface, new IdleTimerParams(timeout, type));
1503
Dianne Hackborne13c4c02014-02-11 17:18:35 -08001504 // Networks start up.
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001505 if (ConnectivityManager.isNetworkTypeMobile(type)) {
1506 mNetworkActive = false;
1507 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001508 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001509 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001510 notifyInterfaceClassActivity(type,
1511 DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001512 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001513 }
1514 });
Haoyu Bai04124232012-06-28 15:26:19 -07001515 }
1516 }
1517
1518 @Override
1519 public void removeIdleTimer(String iface) {
1520 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1521
1522 if (DBG) Slog.d(TAG, "Removing idletimer");
1523
1524 synchronized (mIdleTimerLock) {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001525 final IdleTimerParams params = mActiveIdleTimers.get(iface);
Haoyu Bai04124232012-06-28 15:26:19 -07001526 if (params == null || --(params.networkCount) > 0) {
1527 return;
1528 }
1529
1530 try {
1531 mConnector.execute("idletimer", "remove", iface,
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001532 Integer.toString(params.timeout), Integer.toString(params.type));
Haoyu Bai04124232012-06-28 15:26:19 -07001533 } catch (NativeDaemonConnectorException e) {
1534 throw e.rethrowAsParcelableException();
1535 }
1536 mActiveIdleTimers.remove(iface);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001537 mDaemonHandler.post(new Runnable() {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001538 @Override public void run() {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001539 notifyInterfaceClassActivity(params.type,
1540 DataConnectionRealTimeInfo.DC_POWER_STATE_LOW,
Ruchi Kandoifa97fcf2016-05-13 15:10:39 -07001541 SystemClock.elapsedRealtimeNanos(), -1, false);
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001542 }
1543 });
Haoyu Bai04124232012-06-28 15:26:19 -07001544 }
1545 }
1546
1547 @Override
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001548 public NetworkStats getNetworkStatsSummaryDev() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001549 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001550 try {
1551 return mStatsFactory.readNetworkStatsSummaryDev();
1552 } catch (IOException e) {
1553 throw new IllegalStateException(e);
1554 }
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001555 }
1556
1557 @Override
1558 public NetworkStats getNetworkStatsSummaryXt() {
1559 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001560 try {
1561 return mStatsFactory.readNetworkStatsSummaryXt();
1562 } catch (IOException e) {
1563 throw new IllegalStateException(e);
1564 }
Jeff Sharkeyae2c1812011-10-04 13:11:40 -07001565 }
1566
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001567 @Override
Jeff Sharkey9a13f362011-04-26 16:25:36 -07001568 public NetworkStats getNetworkStatsDetail() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001569 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001570 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001571 return mStatsFactory.readNetworkStatsDetail(UID_ALL, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001572 } catch (IOException e) {
1573 throw new IllegalStateException(e);
1574 }
San Mehat91cac642010-03-31 14:31:36 -07001575 }
1576
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001577 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001578 public void setInterfaceQuota(String iface, long quotaBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001579 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001580
Jeff Sharkey350083e2011-06-29 10:45:16 -07001581 // silently discard when control disabled
1582 // TODO: eventually migrate to be always enabled
1583 if (!mBandwidthControlEnabled) return;
1584
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001585 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001586 if (mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001587 throw new IllegalStateException("iface " + iface + " already has quota");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001588 }
1589
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001590 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001591 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001592 mConnector.execute("bandwidth", "setiquota", iface, quotaBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001593 mActiveQuotas.put(iface, quotaBytes);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001594 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001595 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001596 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001597
1598 synchronized (mTetheringStatsProviders) {
1599 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1600 try {
1601 provider.setInterfaceQuota(iface, quotaBytes);
1602 } catch (RemoteException e) {
1603 Log.e(TAG, "Problem setting tethering data limit on provider " +
1604 mTetheringStatsProviders.get(provider) + ": " + e);
1605 }
1606 }
1607 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001608 }
1609 }
1610
1611 @Override
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001612 public void removeInterfaceQuota(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001613 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001614
Jeff Sharkey350083e2011-06-29 10:45:16 -07001615 // silently discard when control disabled
1616 // TODO: eventually migrate to be always enabled
1617 if (!mBandwidthControlEnabled) return;
1618
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001619 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001620 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001621 // TODO: eventually consider throwing
1622 return;
1623 }
1624
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001625 mActiveQuotas.remove(iface);
1626 mActiveAlerts.remove(iface);
Jeff Sharkey38ddeaa2011-11-08 13:04:22 -08001627
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001628 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001629 // TODO: support quota shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001630 mConnector.execute("bandwidth", "removeiquota", iface);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001631 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001632 throw e.rethrowAsParcelableException();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001633 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001634
1635 synchronized (mTetheringStatsProviders) {
1636 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1637 try {
1638 provider.setInterfaceQuota(iface, ITetheringStatsProvider.QUOTA_UNLIMITED);
1639 } catch (RemoteException e) {
1640 Log.e(TAG, "Problem removing tethering data limit on provider " +
1641 mTetheringStatsProviders.get(provider) + ": " + e);
1642 }
1643 }
1644 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001645 }
1646 }
1647
1648 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001649 public void setInterfaceAlert(String iface, long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001650 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001651
1652 // silently discard when control disabled
1653 // TODO: eventually migrate to be always enabled
1654 if (!mBandwidthControlEnabled) return;
1655
1656 // quick sanity check
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001657 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001658 throw new IllegalStateException("setting alert requires existing quota on iface");
1659 }
1660
1661 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001662 if (mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001663 throw new IllegalStateException("iface " + iface + " already has alert");
1664 }
1665
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001666 try {
1667 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001668 mConnector.execute("bandwidth", "setinterfacealert", iface, alertBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001669 mActiveAlerts.put(iface, alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001670 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001671 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001672 }
1673 }
1674 }
1675
1676 @Override
1677 public void removeInterfaceAlert(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001678 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001679
1680 // silently discard when control disabled
1681 // TODO: eventually migrate to be always enabled
1682 if (!mBandwidthControlEnabled) return;
1683
1684 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001685 if (!mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001686 // TODO: eventually consider throwing
1687 return;
1688 }
1689
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001690 try {
1691 // TODO: support alert shared across interfaces
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001692 mConnector.execute("bandwidth", "removeinterfacealert", iface);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001693 mActiveAlerts.remove(iface);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001694 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001695 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001696 }
1697 }
1698 }
1699
1700 @Override
1701 public void setGlobalAlert(long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001702 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001703
1704 // silently discard when control disabled
1705 // TODO: eventually migrate to be always enabled
1706 if (!mBandwidthControlEnabled) return;
1707
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001708 try {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001709 mConnector.execute("bandwidth", "setglobalalert", alertBytes);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001710 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001711 throw e.rethrowAsParcelableException();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001712 }
1713 }
1714
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001715 private void setUidOnMeteredNetworkList(int uid, boolean blacklist, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001716 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001717
Jeff Sharkey350083e2011-06-29 10:45:16 -07001718 // silently discard when control disabled
1719 // TODO: eventually migrate to be always enabled
1720 if (!mBandwidthControlEnabled) return;
1721
Felipe Leme65be3022016-03-22 14:53:13 -07001722 final String chain = blacklist ? "naughtyapps" : "niceapps";
1723 final String suffix = enable ? "add" : "remove";
1724
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001725 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001726 boolean oldEnable;
1727 SparseBooleanArray quotaList;
1728 synchronized (mRulesLock) {
1729 quotaList = blacklist ? mUidRejectOnMetered : mUidAllowOnMetered;
1730 oldEnable = quotaList.get(uid, false);
1731 }
Felipe Leme65be3022016-03-22 14:53:13 -07001732 if (oldEnable == enable) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001733 // TODO: eventually consider throwing
1734 return;
1735 }
1736
Felipe Leme29e72ea2016-09-08 13:26:55 -07001737 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "inetd bandwidth");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001738 try {
Felipe Leme65be3022016-03-22 14:53:13 -07001739 mConnector.execute("bandwidth", suffix + chain, uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001740 synchronized (mRulesLock) {
1741 if (enable) {
1742 quotaList.put(uid, true);
1743 } else {
1744 quotaList.delete(uid);
1745 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001746 }
1747 } catch (NativeDaemonConnectorException e) {
Jeff Sharkey276642b2011-12-01 11:24:24 -08001748 throw e.rethrowAsParcelableException();
Felipe Leme29e72ea2016-09-08 13:26:55 -07001749 } finally {
1750 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001751 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001752 }
1753 }
1754
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001755 @Override
Felipe Leme65be3022016-03-22 14:53:13 -07001756 public void setUidMeteredNetworkBlacklist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001757 setUidOnMeteredNetworkList(uid, true, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001758 }
1759
1760 @Override
1761 public void setUidMeteredNetworkWhitelist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001762 setUidOnMeteredNetworkList(uid, false, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001763 }
1764
1765 @Override
1766 public boolean setDataSaverModeEnabled(boolean enable) {
1767 if (DBG) Log.d(TAG, "setDataSaverMode: " + enable);
1768 synchronized (mQuotaLock) {
1769 if (mDataSaverMode == enable) {
1770 Log.w(TAG, "setDataSaverMode(): already " + mDataSaverMode);
1771 return true;
1772 }
Felipe Leme29e72ea2016-09-08 13:26:55 -07001773 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "bandwidthEnableDataSaver");
Felipe Leme65be3022016-03-22 14:53:13 -07001774 try {
1775 final boolean changed = mNetdService.bandwidthEnableDataSaver(enable);
1776 if (changed) {
1777 mDataSaverMode = enable;
1778 } else {
1779 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command silently failed");
1780 }
1781 return changed;
1782 } catch (RemoteException e) {
1783 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command failed", e);
1784 return false;
Felipe Leme29e72ea2016-09-08 13:26:55 -07001785 } finally {
1786 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Felipe Leme65be3022016-03-22 14:53:13 -07001787 }
1788 }
1789 }
1790
1791 @Override
Robin Lee17e61832016-05-09 13:46:28 +01001792 public void setAllowOnlyVpnForUids(boolean add, UidRange[] uidRanges)
1793 throws ServiceSpecificException {
1794 try {
1795 mNetdService.networkRejectNonSecureVpn(add, uidRanges);
1796 } catch (ServiceSpecificException e) {
1797 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1798 + ": netd command failed", e);
1799 throw e;
1800 } catch (RemoteException e) {
1801 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1802 + ": netd command failed", e);
1803 throw e.rethrowAsRuntimeException();
1804 }
1805 }
1806
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001807 private void applyUidCleartextNetworkPolicy(int uid, int policy) {
1808 final String policyString;
1809 switch (policy) {
1810 case StrictMode.NETWORK_POLICY_ACCEPT:
1811 policyString = "accept";
1812 break;
1813 case StrictMode.NETWORK_POLICY_LOG:
1814 policyString = "log";
1815 break;
1816 case StrictMode.NETWORK_POLICY_REJECT:
1817 policyString = "reject";
1818 break;
1819 default:
1820 throw new IllegalArgumentException("Unknown policy " + policy);
1821 }
1822
1823 try {
1824 mConnector.execute("strict", "set_uid_cleartext_policy", uid, policyString);
1825 mUidCleartextPolicy.put(uid, policy);
1826 } catch (NativeDaemonConnectorException e) {
1827 throw e.rethrowAsParcelableException();
1828 }
1829 }
1830
Robin Lee17e61832016-05-09 13:46:28 +01001831 @Override
Jeff Sharkey605eb792014-11-04 13:34:06 -08001832 public void setUidCleartextNetworkPolicy(int uid, int policy) {
1833 if (Binder.getCallingUid() != uid) {
1834 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1835 }
1836
1837 synchronized (mQuotaLock) {
1838 final int oldPolicy = mUidCleartextPolicy.get(uid, StrictMode.NETWORK_POLICY_ACCEPT);
1839 if (oldPolicy == policy) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001840 // This also ensures we won't needlessly apply an ACCEPT policy if we've just
1841 // enabled strict and the underlying iptables rules are empty.
Jeff Sharkey605eb792014-11-04 13:34:06 -08001842 return;
1843 }
1844
1845 if (!mStrictEnabled) {
1846 // Module isn't enabled yet; stash the requested policy away to
1847 // apply later once the daemon is connected.
1848 mUidCleartextPolicy.put(uid, policy);
1849 return;
1850 }
1851
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001852 // netd does not keep state on strict mode policies, and cannot replace a non-accept
1853 // policy without deleting it first. Rather than add state to netd, just always send
1854 // it an accept policy when switching between two non-accept policies.
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001855 // TODO: consider keeping state in netd so we can simplify this code.
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001856 if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT &&
1857 policy != StrictMode.NETWORK_POLICY_ACCEPT) {
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001858 applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001859 }
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001860
1861 applyUidCleartextNetworkPolicy(uid, policy);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001862 }
1863 }
1864
1865 @Override
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001866 public boolean isBandwidthControlEnabled() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001867 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001868 return mBandwidthControlEnabled;
1869 }
1870
1871 @Override
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001872 public NetworkStats getNetworkStatsUidDetail(int uid) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001873 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001874 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001875 return mStatsFactory.readNetworkStatsDetail(uid, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001876 } catch (IOException e) {
1877 throw new IllegalStateException(e);
1878 }
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001879 }
1880
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001881 private class NetdTetheringStatsProvider extends ITetheringStatsProvider.Stub {
1882 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001883 public NetworkStats getTetherStats(int how) {
1884 // We only need to return per-UID stats. Per-device stats are already counted by
1885 // interface counters.
1886 if (how != STATS_PER_UID) {
1887 return new NetworkStats(SystemClock.elapsedRealtime(), 0);
1888 }
1889
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001890 final PersistableBundle bundle;
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001891 try {
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001892 bundle = mNetdService.tetherGetStats();
1893 } catch (RemoteException | ServiceSpecificException e) {
1894 throw new IllegalStateException("problem parsing tethering stats: ", e);
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001895 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001896
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001897 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(),
1898 bundle.size());
1899 final NetworkStats.Entry entry = new NetworkStats.Entry();
1900
1901 for (String iface : bundle.keySet()) {
1902 long[] statsArray = bundle.getLongArray(iface);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001903 try {
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001904 entry.iface = iface;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001905 entry.uid = UID_TETHERING;
1906 entry.set = SET_DEFAULT;
1907 entry.tag = TAG_NONE;
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001908 entry.rxBytes = statsArray[INetd.TETHER_STATS_RX_BYTES];
1909 entry.rxPackets = statsArray[INetd.TETHER_STATS_RX_PACKETS];
1910 entry.txBytes = statsArray[INetd.TETHER_STATS_TX_BYTES];
1911 entry.txPackets = statsArray[INetd.TETHER_STATS_TX_PACKETS];
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001912 stats.combineValues(entry);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001913 } catch (ArrayIndexOutOfBoundsException e) {
1914 throw new IllegalStateException("invalid tethering stats for " + iface, e);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001915 }
1916 }
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001917
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001918 return stats;
1919 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001920
1921 @Override
1922 public void setInterfaceQuota(String iface, long quotaBytes) {
1923 // Do nothing. netd is already informed of quota changes in setInterfaceQuota.
1924 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001925 }
1926
1927 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001928 public NetworkStats getNetworkStatsTethering(int how) {
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001929 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1930
1931 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
1932 synchronized (mTetheringStatsProviders) {
1933 for (ITetheringStatsProvider provider: mTetheringStatsProviders.keySet()) {
1934 try {
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001935 stats.combineAllValues(provider.getTetherStats(how));
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001936 } catch (RemoteException e) {
1937 Log.e(TAG, "Problem reading tethering stats from " +
1938 mTetheringStatsProviders.get(provider) + ": " + e);
1939 }
1940 }
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001941 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001942 return stats;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001943 }
1944
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001945 @Override
Pierre Imai8e48e672016-04-21 13:30:43 +09001946 public void setDnsConfigurationForNetwork(int netId, String[] servers, String domains) {
1947 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1948
1949 ContentResolver resolver = mContext.getContentResolver();
1950
1951 int sampleValidity = Settings.Global.getInt(resolver,
1952 Settings.Global.DNS_RESOLVER_SAMPLE_VALIDITY_SECONDS,
1953 DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS);
1954 if (sampleValidity < 0 || sampleValidity > 65535) {
1955 Slog.w(TAG, "Invalid sampleValidity=" + sampleValidity + ", using default=" +
1956 DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS);
1957 sampleValidity = DNS_RESOLVER_DEFAULT_SAMPLE_VALIDITY_SECONDS;
1958 }
1959
1960 int successThreshold = Settings.Global.getInt(resolver,
1961 Settings.Global.DNS_RESOLVER_SUCCESS_THRESHOLD_PERCENT,
1962 DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT);
1963 if (successThreshold < 0 || successThreshold > 100) {
1964 Slog.w(TAG, "Invalid successThreshold=" + successThreshold + ", using default=" +
1965 DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT);
1966 successThreshold = DNS_RESOLVER_DEFAULT_SUCCESS_THRESHOLD_PERCENT;
1967 }
1968
1969 int minSamples = Settings.Global.getInt(resolver,
1970 Settings.Global.DNS_RESOLVER_MIN_SAMPLES, DNS_RESOLVER_DEFAULT_MIN_SAMPLES);
1971 int maxSamples = Settings.Global.getInt(resolver,
1972 Settings.Global.DNS_RESOLVER_MAX_SAMPLES, DNS_RESOLVER_DEFAULT_MAX_SAMPLES);
1973 if (minSamples < 0 || minSamples > maxSamples || maxSamples > 64) {
1974 Slog.w(TAG, "Invalid sample count (min, max)=(" + minSamples + ", " + maxSamples +
1975 "), using default=(" + DNS_RESOLVER_DEFAULT_MIN_SAMPLES + ", " +
1976 DNS_RESOLVER_DEFAULT_MAX_SAMPLES + ")");
1977 minSamples = DNS_RESOLVER_DEFAULT_MIN_SAMPLES;
1978 maxSamples = DNS_RESOLVER_DEFAULT_MAX_SAMPLES;
1979 }
1980
1981 final String[] domainStrs = domains == null ? new String[0] : domains.split(" ");
1982 final int[] params = { sampleValidity, successThreshold, minSamples, maxSamples };
Ben Schwartzbccbd002017-10-02 13:27:13 -04001983 final boolean useTls = Settings.Global.getInt(resolver,
1984 Settings.Global.DNS_TLS_DISABLED, 0) == 0;
Ben Schwartz6ec28df2017-10-02 13:08:06 -04001985 final String tlsHostname = "";
1986 final String[] tlsFingerprints = new String[0];
Pierre Imai8e48e672016-04-21 13:30:43 +09001987 try {
Ben Schwartz6ec28df2017-10-02 13:08:06 -04001988 mNetdService.setResolverConfiguration(netId, servers, domainStrs, params,
1989 useTls, tlsHostname, tlsFingerprints);
Pierre Imai8e48e672016-04-21 13:30:43 +09001990 } catch (RemoteException e) {
1991 throw new RuntimeException(e);
1992 }
1993 }
1994
1995 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001996 public void addVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001997 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001998 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
1999 argv[0] = "users";
2000 argv[1] = "add";
2001 argv[2] = netId;
2002 int argc = 3;
2003 // Avoid overly long commands by limiting number of UID ranges per command.
2004 for (int i = 0; i < ranges.length; i++) {
2005 argv[argc++] = ranges[i].toString();
2006 if (i == (ranges.length - 1) || argc == argv.length) {
2007 try {
2008 mConnector.execute("network", Arrays.copyOf(argv, argc));
2009 } catch (NativeDaemonConnectorException e) {
2010 throw e.rethrowAsParcelableException();
2011 }
2012 argc = 3;
2013 }
Chad Brubaker3277620a2013-06-12 13:37:30 -07002014 }
2015 }
2016
2017 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002018 public void removeVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07002019 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002020 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
2021 argv[0] = "users";
2022 argv[1] = "remove";
2023 argv[2] = netId;
2024 int argc = 3;
2025 // Avoid overly long commands by limiting number of UID ranges per command.
2026 for (int i = 0; i < ranges.length; i++) {
2027 argv[argc++] = ranges[i].toString();
2028 if (i == (ranges.length - 1) || argc == argv.length) {
2029 try {
2030 mConnector.execute("network", Arrays.copyOf(argv, argc));
2031 } catch (NativeDaemonConnectorException e) {
2032 throw e.rethrowAsParcelableException();
2033 }
2034 argc = 3;
2035 }
Chad Brubakercca54c42013-06-27 17:41:38 -07002036 }
2037 }
2038
2039 @Override
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002040 public void setFirewallEnabled(boolean enabled) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002041 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002042 try {
Amith Yamasani15e472352015-04-24 19:06:07 -07002043 mConnector.execute("firewall", "enable", enabled ? "whitelist" : "blacklist");
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002044 mFirewallEnabled = enabled;
2045 } catch (NativeDaemonConnectorException e) {
2046 throw e.rethrowAsParcelableException();
2047 }
2048 }
2049
2050 @Override
2051 public boolean isFirewallEnabled() {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002052 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002053 return mFirewallEnabled;
2054 }
2055
2056 @Override
Jeff Sharkey2c092982012-08-24 11:44:40 -07002057 public void setFirewallInterfaceRule(String iface, boolean allow) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002058 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002059 Preconditions.checkState(mFirewallEnabled);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002060 final String rule = allow ? "allow" : "deny";
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002061 try {
2062 mConnector.execute("firewall", "set_interface_rule", iface, rule);
2063 } catch (NativeDaemonConnectorException e) {
2064 throw e.rethrowAsParcelableException();
2065 }
2066 }
2067
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002068 private void closeSocketsForFirewallChainLocked(int chain, String chainName) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002069 // UID ranges to close sockets on.
2070 UidRange[] ranges;
2071 // UID ranges whose sockets we won't touch.
2072 int[] exemptUids;
2073
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002074 int numUids = 0;
2075
2076 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2077 // Close all sockets on all non-system UIDs...
2078 ranges = new UidRange[] {
2079 // TODO: is there a better way of finding all existing users? If so, we could
2080 // specify their ranges here.
2081 new UidRange(Process.FIRST_APPLICATION_UID, Integer.MAX_VALUE),
2082 };
2083 // ... except for the UIDs that have allow rules.
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002084 synchronized (mRulesLock) {
2085 final SparseIntArray rules = getUidFirewallRulesLR(chain);
2086 exemptUids = new int[rules.size()];
2087 for (int i = 0; i < exemptUids.length; i++) {
2088 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2089 exemptUids[numUids] = rules.keyAt(i);
2090 numUids++;
2091 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002092 }
2093 }
2094 // Normally, whitelist chains only contain deny rules, so numUids == exemptUids.length.
2095 // But the code does not guarantee this in any way, and at least in one case - if we add
2096 // a UID rule to the firewall, and then disable the firewall - the chains can contain
2097 // the wrong type of rule. In this case, don't close connections that we shouldn't.
2098 //
2099 // TODO: tighten up this code by ensuring we never set the wrong type of rule, and
2100 // fix setFirewallEnabled to grab mQuotaLock and clear rules.
2101 if (numUids != exemptUids.length) {
2102 exemptUids = Arrays.copyOf(exemptUids, numUids);
2103 }
2104 } else {
2105 // Close sockets for every UID that has a deny rule...
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002106 synchronized (mRulesLock) {
2107 final SparseIntArray rules = getUidFirewallRulesLR(chain);
2108 ranges = new UidRange[rules.size()];
2109 for (int i = 0; i < ranges.length; i++) {
2110 if (rules.valueAt(i) == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2111 int uid = rules.keyAt(i);
2112 ranges[numUids] = new UidRange(uid, uid);
2113 numUids++;
2114 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002115 }
2116 }
2117 // As above; usually numUids == ranges.length, but not always.
2118 if (numUids != ranges.length) {
2119 ranges = Arrays.copyOf(ranges, numUids);
2120 }
2121 // ... with no exceptions.
2122 exemptUids = new int[0];
2123 }
2124
2125 try {
2126 mNetdService.socketDestroy(ranges, exemptUids);
2127 } catch(RemoteException | ServiceSpecificException e) {
2128 Slog.e(TAG, "Error closing sockets after enabling chain " + chainName + ": " + e);
2129 }
2130 }
2131
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002132 @Override
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002133 public void setFirewallChainEnabled(int chain, boolean enable) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002134 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002135 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002136 synchronized (mRulesLock) {
2137 if (getFirewallChainState(chain) == enable) {
2138 // All is the same, nothing to do. This relies on the fact that netd has child
2139 // chains default detached.
2140 return;
2141 }
2142 setFirewallChainState(chain, enable);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002143 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002144
2145 final String operation = enable ? "enable_chain" : "disable_chain";
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002146 final String chainName;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002147 switch(chain) {
2148 case FIREWALL_CHAIN_STANDBY:
2149 chainName = FIREWALL_CHAIN_NAME_STANDBY;
2150 break;
2151 case FIREWALL_CHAIN_DOZABLE:
2152 chainName = FIREWALL_CHAIN_NAME_DOZABLE;
2153 break;
2154 case FIREWALL_CHAIN_POWERSAVE:
2155 chainName = FIREWALL_CHAIN_NAME_POWERSAVE;
2156 break;
2157 default:
2158 throw new IllegalArgumentException("Bad child chain: " + chain);
2159 }
2160
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002161 try {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002162 mConnector.execute("firewall", operation, chainName);
2163 } catch (NativeDaemonConnectorException e) {
2164 throw e.rethrowAsParcelableException();
2165 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002166
2167 // Close any sockets that were opened by the affected UIDs. This has to be done after
2168 // disabling network connectivity, in case they react to the socket close by reopening
2169 // the connection and race with the iptables commands that enable the firewall. All
2170 // whitelist and blacklist chains allow RSTs through.
2171 if (enable) {
2172 if (DBG) Slog.d(TAG, "Closing sockets after enabling chain " + chainName);
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09002173 closeSocketsForFirewallChainLocked(chain, chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002174 }
Amith Yamasani15e472352015-04-24 19:06:07 -07002175 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002176 }
2177
2178 private int getFirewallType(int chain) {
2179 switch (chain) {
2180 case FIREWALL_CHAIN_STANDBY:
2181 return FIREWALL_TYPE_BLACKLIST;
2182 case FIREWALL_CHAIN_DOZABLE:
2183 return FIREWALL_TYPE_WHITELIST;
Felipe Leme011b98f2016-02-10 17:28:31 -08002184 case FIREWALL_CHAIN_POWERSAVE:
2185 return FIREWALL_TYPE_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002186 default:
2187 return isFirewallEnabled() ? FIREWALL_TYPE_WHITELIST : FIREWALL_TYPE_BLACKLIST;
2188 }
2189 }
2190
2191 @Override
2192 public void setFirewallUidRules(int chain, int[] uids, int[] rules) {
2193 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002194 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002195 synchronized (mRulesLock) {
2196 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
2197 SparseIntArray newRules = new SparseIntArray();
2198 // apply new set of rules
2199 for (int index = uids.length - 1; index >= 0; --index) {
2200 int uid = uids[index];
2201 int rule = rules[index];
2202 updateFirewallUidRuleLocked(chain, uid, rule);
2203 newRules.put(uid, rule);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002204 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002205 // collect the rules to remove.
2206 SparseIntArray rulesToRemove = new SparseIntArray();
2207 for (int index = uidFirewallRules.size() - 1; index >= 0; --index) {
2208 int uid = uidFirewallRules.keyAt(index);
2209 if (newRules.indexOfKey(uid) < 0) {
2210 rulesToRemove.put(uid, FIREWALL_RULE_DEFAULT);
2211 }
2212 }
2213 // remove dead rules
2214 for (int index = rulesToRemove.size() - 1; index >= 0; --index) {
2215 int uid = rulesToRemove.keyAt(index);
2216 updateFirewallUidRuleLocked(chain, uid, FIREWALL_RULE_DEFAULT);
2217 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002218 }
2219 try {
2220 switch (chain) {
2221 case FIREWALL_CHAIN_DOZABLE:
2222 mNetdService.firewallReplaceUidChain("fw_dozable", true, uids);
2223 break;
2224 case FIREWALL_CHAIN_STANDBY:
2225 mNetdService.firewallReplaceUidChain("fw_standby", false, uids);
2226 break;
2227 case FIREWALL_CHAIN_POWERSAVE:
2228 mNetdService.firewallReplaceUidChain("fw_powersave", true, uids);
2229 break;
2230 case FIREWALL_CHAIN_NONE:
2231 default:
2232 Slog.d(TAG, "setFirewallUidRules() called on invalid chain: " + chain);
2233 }
2234 } catch (RemoteException e) {
2235 Slog.w(TAG, "Error flushing firewall chain " + chain, e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002236 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002237 }
2238 }
2239
2240 @Override
2241 public void setFirewallUidRule(int chain, int uid, int rule) {
2242 enforceSystemUid();
Felipe Lemea701cad2016-05-12 09:58:14 -07002243 synchronized (mQuotaLock) {
2244 setFirewallUidRuleLocked(chain, uid, rule);
2245 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002246 }
2247
Felipe Lemea701cad2016-05-12 09:58:14 -07002248 private void setFirewallUidRuleLocked(int chain, int uid, int rule) {
2249 if (updateFirewallUidRuleLocked(chain, uid, rule)) {
Amith Yamasani15e472352015-04-24 19:06:07 -07002250 try {
Felipe Lemea701cad2016-05-12 09:58:14 -07002251 mConnector.execute("firewall", "set_uid_rule", getFirewallChainName(chain), uid,
2252 getFirewallRuleName(chain, rule));
Amith Yamasani15e472352015-04-24 19:06:07 -07002253 } catch (NativeDaemonConnectorException e) {
2254 throw e.rethrowAsParcelableException();
2255 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002256 }
2257 }
2258
Felipe Lemea701cad2016-05-12 09:58:14 -07002259 // TODO: now that netd supports batching, NMS should not keep these data structures anymore...
2260 private boolean updateFirewallUidRuleLocked(int chain, int uid, int rule) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002261 synchronized (mRulesLock) {
2262 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Felipe Lemea701cad2016-05-12 09:58:14 -07002263
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002264 final int oldUidFirewallRule = uidFirewallRules.get(uid, FIREWALL_RULE_DEFAULT);
2265 if (DBG) {
2266 Slog.d(TAG, "oldRule = " + oldUidFirewallRule
2267 + ", newRule=" + rule + " for uid=" + uid + " on chain " + chain);
2268 }
2269 if (oldUidFirewallRule == rule) {
2270 if (DBG) Slog.d(TAG, "!!!!! Skipping change");
2271 // TODO: eventually consider throwing
2272 return false;
2273 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002274
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002275 String ruleName = getFirewallRuleName(chain, rule);
2276 String oldRuleName = getFirewallRuleName(chain, oldUidFirewallRule);
Felipe Lemea701cad2016-05-12 09:58:14 -07002277
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002278 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
2279 uidFirewallRules.delete(uid);
2280 } else {
2281 uidFirewallRules.put(uid, rule);
2282 }
2283 return !ruleName.equals(oldRuleName);
Felipe Lemea701cad2016-05-12 09:58:14 -07002284 }
Felipe Lemea701cad2016-05-12 09:58:14 -07002285 }
2286
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07002287 private @NonNull String getFirewallRuleName(int chain, int rule) {
2288 String ruleName;
2289 if (getFirewallType(chain) == FIREWALL_TYPE_WHITELIST) {
2290 if (rule == NetworkPolicyManager.FIREWALL_RULE_ALLOW) {
2291 ruleName = "allow";
2292 } else {
2293 ruleName = "deny";
2294 }
2295 } else { // Blacklist mode
2296 if (rule == NetworkPolicyManager.FIREWALL_RULE_DENY) {
2297 ruleName = "deny";
2298 } else {
2299 ruleName = "allow";
2300 }
2301 }
2302 return ruleName;
2303 }
2304
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002305 private @NonNull SparseIntArray getUidFirewallRulesLR(int chain) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002306 switch (chain) {
2307 case FIREWALL_CHAIN_STANDBY:
2308 return mUidFirewallStandbyRules;
2309 case FIREWALL_CHAIN_DOZABLE:
2310 return mUidFirewallDozableRules;
Felipe Leme011b98f2016-02-10 17:28:31 -08002311 case FIREWALL_CHAIN_POWERSAVE:
2312 return mUidFirewallPowerSaveRules;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002313 case FIREWALL_CHAIN_NONE:
2314 return mUidFirewallRules;
2315 default:
2316 throw new IllegalArgumentException("Unknown chain:" + chain);
2317 }
2318 }
2319
2320 public @NonNull String getFirewallChainName(int chain) {
2321 switch (chain) {
2322 case FIREWALL_CHAIN_STANDBY:
2323 return FIREWALL_CHAIN_NAME_STANDBY;
2324 case FIREWALL_CHAIN_DOZABLE:
2325 return FIREWALL_CHAIN_NAME_DOZABLE;
Felipe Leme011b98f2016-02-10 17:28:31 -08002326 case FIREWALL_CHAIN_POWERSAVE:
2327 return FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002328 case FIREWALL_CHAIN_NONE:
2329 return FIREWALL_CHAIN_NAME_NONE;
2330 default:
2331 throw new IllegalArgumentException("Unknown chain:" + chain);
2332 }
2333 }
2334
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07002335 private static void enforceSystemUid() {
2336 final int uid = Binder.getCallingUid();
2337 if (uid != Process.SYSTEM_UID) {
2338 throw new SecurityException("Only available to AID_SYSTEM");
2339 }
2340 }
2341
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002342 @Override
Lorenzo Colitti79751842013-02-28 16:16:03 +09002343 public void startClatd(String interfaceName) throws IllegalStateException {
2344 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2345
2346 try {
2347 mConnector.execute("clatd", "start", interfaceName);
2348 } catch (NativeDaemonConnectorException e) {
2349 throw e.rethrowAsParcelableException();
2350 }
2351 }
2352
2353 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002354 public void stopClatd(String interfaceName) throws IllegalStateException {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002355 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2356
2357 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002358 mConnector.execute("clatd", "stop", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002359 } catch (NativeDaemonConnectorException e) {
2360 throw e.rethrowAsParcelableException();
2361 }
2362 }
2363
2364 @Override
Lorenzo Colitti95439462014-10-09 13:44:48 +09002365 public boolean isClatdStarted(String interfaceName) {
Lorenzo Colitti79751842013-02-28 16:16:03 +09002366 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2367
2368 final NativeDaemonEvent event;
2369 try {
Lorenzo Colitti95439462014-10-09 13:44:48 +09002370 event = mConnector.execute("clatd", "status", interfaceName);
Lorenzo Colitti79751842013-02-28 16:16:03 +09002371 } catch (NativeDaemonConnectorException e) {
2372 throw e.rethrowAsParcelableException();
2373 }
2374
2375 event.checkCode(ClatdStatusResult);
2376 return event.getMessage().endsWith("started");
2377 }
2378
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002379 @Override
2380 public void registerNetworkActivityListener(INetworkActivityListener listener) {
2381 mNetworkActivityListeners.register(listener);
2382 }
2383
2384 @Override
2385 public void unregisterNetworkActivityListener(INetworkActivityListener listener) {
2386 mNetworkActivityListeners.unregister(listener);
2387 }
2388
2389 @Override
2390 public boolean isNetworkActive() {
2391 synchronized (mNetworkActivityListeners) {
2392 return mNetworkActive || mActiveIdleTimers.isEmpty();
2393 }
2394 }
2395
2396 private void reportNetworkActive() {
2397 final int length = mNetworkActivityListeners.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002398 try {
2399 for (int i = 0; i < length; i++) {
2400 try {
2401 mNetworkActivityListeners.getBroadcastItem(i).onNetworkActive();
Felipe Leme03e689d2016-03-02 16:17:38 -08002402 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002403 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002404 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07002405 } finally {
2406 mNetworkActivityListeners.finishBroadcast();
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002407 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002408 }
2409
Mattias Falk8b47b362011-08-23 14:15:13 +02002410 /** {@inheritDoc} */
Jeff Sharkey7b4596f2013-02-25 10:55:29 -08002411 @Override
Jeff Sharkeyfa23c5a2011-08-09 21:44:24 -07002412 public void monitor() {
2413 if (mConnector != null) {
2414 mConnector.monitor();
2415 }
2416 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002417
2418 @Override
2419 protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -06002420 if (!DumpUtils.checkDumpPermission(mContext, TAG, pw)) return;
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002421
Robert Greenwalt470fd722012-01-18 12:51:15 -08002422 pw.println("NetworkManagementService NativeDaemonConnector Log:");
2423 mConnector.dump(fd, pw, args);
2424 pw.println();
2425
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002426 pw.print("Bandwidth control enabled: "); pw.println(mBandwidthControlEnabled);
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07002427 pw.print("mMobileActivityFromRadio="); pw.print(mMobileActivityFromRadio);
2428 pw.print(" mLastPowerStateFromRadio="); pw.println(mLastPowerStateFromRadio);
2429 pw.print("mNetworkActive="); pw.println(mNetworkActive);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002430
2431 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07002432 pw.print("Active quota ifaces: "); pw.println(mActiveQuotas.toString());
2433 pw.print("Active alert ifaces: "); pw.println(mActiveAlerts.toString());
Felipe Leme65be3022016-03-22 14:53:13 -07002434 pw.print("Data saver mode: "); pw.println(mDataSaverMode);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002435 synchronized (mRulesLock) {
2436 dumpUidRuleOnQuotaLocked(pw, "blacklist", mUidRejectOnMetered);
2437 dumpUidRuleOnQuotaLocked(pw, "whitelist", mUidAllowOnMetered);
2438 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002439 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002440
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002441 synchronized (mRulesLock) {
Felipe Leme011b98f2016-02-10 17:28:31 -08002442 dumpUidFirewallRule(pw, "", mUidFirewallRules);
Amith Yamasani15e472352015-04-24 19:06:07 -07002443
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002444 pw.print("UID firewall standby chain enabled: "); pw.println(
2445 getFirewallChainState(FIREWALL_CHAIN_STANDBY));
Felipe Leme011b98f2016-02-10 17:28:31 -08002446 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_STANDBY, mUidFirewallStandbyRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002447
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002448 pw.print("UID firewall dozable chain enabled: "); pw.println(
2449 getFirewallChainState(FIREWALL_CHAIN_DOZABLE));
Felipe Leme011b98f2016-02-10 17:28:31 -08002450 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_DOZABLE, mUidFirewallDozableRules);
Felipe Leme011b98f2016-02-10 17:28:31 -08002451
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002452 pw.println("UID firewall powersave chain enabled: " +
2453 getFirewallChainState(FIREWALL_CHAIN_POWERSAVE));
Felipe Leme011b98f2016-02-10 17:28:31 -08002454 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_POWERSAVE, mUidFirewallPowerSaveRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002455 }
2456
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002457 synchronized (mIdleTimerLock) {
2458 pw.println("Idle timers:");
2459 for (HashMap.Entry<String, IdleTimerParams> ent : mActiveIdleTimers.entrySet()) {
2460 pw.print(" "); pw.print(ent.getKey()); pw.println(":");
2461 IdleTimerParams params = ent.getValue();
2462 pw.print(" timeout="); pw.print(params.timeout);
2463 pw.print(" type="); pw.print(params.type);
2464 pw.print(" networkCount="); pw.println(params.networkCount);
2465 }
2466 }
2467
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002468 pw.print("Firewall enabled: "); pw.println(mFirewallEnabled);
Felipe Leme65be3022016-03-22 14:53:13 -07002469 pw.print("Netd service status: " );
2470 if (mNetdService == null) {
2471 pw.println("disconnected");
2472 } else {
2473 try {
2474 final boolean alive = mNetdService.isAlive();
2475 pw.println(alive ? "alive": "dead");
2476 } catch (RemoteException e) {
2477 pw.println("unreachable");
2478 }
2479 }
2480 }
2481
2482 private void dumpUidRuleOnQuotaLocked(PrintWriter pw, String name, SparseBooleanArray list) {
2483 pw.print("UID bandwith control ");
2484 pw.print(name);
2485 pw.print(" rule: [");
2486 final int size = list.size();
2487 for (int i = 0; i < size; i++) {
2488 pw.print(list.keyAt(i));
2489 if (i < size - 1) pw.print(",");
2490 }
2491 pw.println("]");
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002492 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002493
Felipe Leme011b98f2016-02-10 17:28:31 -08002494 private void dumpUidFirewallRule(PrintWriter pw, String name, SparseIntArray rules) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002495 pw.print("UID firewall ");
Felipe Leme011b98f2016-02-10 17:28:31 -08002496 pw.print(name);
2497 pw.print(" rule: [");
2498 final int size = rules.size();
2499 for (int i = 0; i < size; i++) {
2500 pw.print(rules.keyAt(i));
2501 pw.print(":");
2502 pw.print(rules.valueAt(i));
2503 if (i < size - 1) pw.print(",");
2504 }
2505 pw.println("]");
2506 }
2507
Robert Greenwalt568891d2014-04-04 13:38:00 -07002508 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002509 public void createPhysicalNetwork(int netId, String permission) {
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002510 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2511
2512 try {
Paul Jensen487ffe72015-07-24 15:57:11 -04002513 if (permission != null) {
2514 mConnector.execute("network", "create", netId, permission);
2515 } else {
2516 mConnector.execute("network", "create", netId);
2517 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002518 } catch (NativeDaemonConnectorException e) {
2519 throw e.rethrowAsParcelableException();
2520 }
2521 }
2522
Robert Greenwalt568891d2014-04-04 13:38:00 -07002523 @Override
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002524 public void createVirtualNetwork(int netId, boolean hasDNS, boolean secure) {
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002525 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2526
2527 try {
Sreeram Ramachandran8cd33ed2014-07-23 15:23:15 -07002528 mConnector.execute("network", "create", netId, "vpn", hasDNS ? "1" : "0",
2529 secure ? "1" : "0");
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002530 } catch (NativeDaemonConnectorException e) {
2531 throw e.rethrowAsParcelableException();
2532 }
2533 }
2534
2535 @Override
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002536 public void removeNetwork(int netId) {
2537 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2538
2539 try {
2540 mConnector.execute("network", "destroy", netId);
2541 } catch (NativeDaemonConnectorException e) {
2542 throw e.rethrowAsParcelableException();
2543 }
2544 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002545
2546 @Override
Paul Jensen992f2522014-04-28 10:33:11 -04002547 public void addInterfaceToNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002548 modifyInterfaceInNetwork("add", "" + netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002549 }
2550
2551 @Override
2552 public void removeInterfaceFromNetwork(String iface, int netId) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002553 modifyInterfaceInNetwork("remove", "" + netId, iface);
2554 }
Paul Jensen992f2522014-04-28 10:33:11 -04002555
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002556 private void modifyInterfaceInNetwork(String action, String netId, String iface) {
2557 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen992f2522014-04-28 10:33:11 -04002558 try {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002559 mConnector.execute("network", "interface", action, netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002560 } catch (NativeDaemonConnectorException e) {
2561 throw e.rethrowAsParcelableException();
2562 }
2563 }
2564
2565 @Override
Robert Greenwalt913c8952014-04-07 17:36:35 -07002566 public void addLegacyRouteForNetId(int netId, RouteInfo routeInfo, int uid) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002567 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2568
Sreeram Ramachandran03666c72014-07-19 23:21:46 -07002569 final Command cmd = new Command("network", "route", "legacy", uid, "add", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002570
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002571 // create triplet: interface dest-ip-addr/prefixlength gateway-ip-addr
Sreeram Ramachandrancc91c7b2014-06-03 18:41:43 -07002572 final LinkAddress la = routeInfo.getDestinationLinkAddress();
Robert Greenwalt568891d2014-04-04 13:38:00 -07002573 cmd.appendArg(routeInfo.getInterface());
Lorenzo Colitti7dc78cf2014-06-09 22:58:46 +09002574 cmd.appendArg(la.getAddress().getHostAddress() + "/" + la.getPrefixLength());
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -07002575 if (routeInfo.hasGateway()) {
2576 cmd.appendArg(routeInfo.getGateway().getHostAddress());
2577 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002578
2579 try {
2580 mConnector.execute(cmd);
2581 } catch (NativeDaemonConnectorException e) {
2582 throw e.rethrowAsParcelableException();
2583 }
2584 }
2585
2586 @Override
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002587 public void setDefaultNetId(int netId) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002588 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2589
2590 try {
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002591 mConnector.execute("network", "default", "set", netId);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002592 } catch (NativeDaemonConnectorException e) {
2593 throw e.rethrowAsParcelableException();
2594 }
2595 }
2596
2597 @Override
2598 public void clearDefaultNetId() {
2599 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2600
2601 try {
2602 mConnector.execute("network", "default", "clear");
2603 } catch (NativeDaemonConnectorException e) {
2604 throw e.rethrowAsParcelableException();
2605 }
2606 }
2607
2608 @Override
Paul Jensen487ffe72015-07-24 15:57:11 -04002609 public void setNetworkPermission(int netId, String permission) {
2610 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2611
2612 try {
2613 if (permission != null) {
2614 mConnector.execute("network", "permission", "network", "set", permission, netId);
2615 } else {
2616 mConnector.execute("network", "permission", "network", "clear", netId);
2617 }
2618 } catch (NativeDaemonConnectorException e) {
2619 throw e.rethrowAsParcelableException();
2620 }
2621 }
2622
2623
2624 @Override
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002625 public void setPermission(String permission, int[] uids) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002626 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2627
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002628 Object[] argv = new Object[4 + MAX_UID_RANGES_PER_COMMAND];
2629 argv[0] = "permission";
2630 argv[1] = "user";
2631 argv[2] = "set";
2632 argv[3] = permission;
2633 int argc = 4;
2634 // Avoid overly long commands by limiting number of UIDs per command.
2635 for (int i = 0; i < uids.length; ++i) {
2636 argv[argc++] = uids[i];
2637 if (i == uids.length - 1 || argc == argv.length) {
2638 try {
2639 mConnector.execute("network", Arrays.copyOf(argv, argc));
2640 } catch (NativeDaemonConnectorException e) {
2641 throw e.rethrowAsParcelableException();
2642 }
2643 argc = 4;
2644 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002645 }
2646 }
2647
2648 @Override
2649 public void clearPermission(int[] uids) {
2650 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2651
Sreeram Ramachandrane4a05af2014-09-24 09:16:19 -07002652 Object[] argv = new Object[3 + MAX_UID_RANGES_PER_COMMAND];
2653 argv[0] = "permission";
2654 argv[1] = "user";
2655 argv[2] = "clear";
2656 int argc = 3;
2657 // Avoid overly long commands by limiting number of UIDs per command.
2658 for (int i = 0; i < uids.length; ++i) {
2659 argv[argc++] = uids[i];
2660 if (i == uids.length - 1 || argc == argv.length) {
2661 try {
2662 mConnector.execute("network", Arrays.copyOf(argv, argc));
2663 } catch (NativeDaemonConnectorException e) {
2664 throw e.rethrowAsParcelableException();
2665 }
2666 argc = 3;
2667 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002668 }
2669 }
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002670
2671 @Override
2672 public void allowProtect(int uid) {
2673 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2674
2675 try {
2676 mConnector.execute("network", "protect", "allow", uid);
2677 } catch (NativeDaemonConnectorException e) {
2678 throw e.rethrowAsParcelableException();
2679 }
2680 }
2681
2682 @Override
2683 public void denyProtect(int uid) {
2684 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2685
2686 try {
2687 mConnector.execute("network", "protect", "deny", uid);
2688 } catch (NativeDaemonConnectorException e) {
2689 throw e.rethrowAsParcelableException();
2690 }
2691 }
2692
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002693 @Override
2694 public void addInterfaceToLocalNetwork(String iface, List<RouteInfo> routes) {
2695 modifyInterfaceInNetwork("add", "local", iface);
2696
2697 for (RouteInfo route : routes) {
2698 if (!route.isDefaultRoute()) {
2699 modifyRoute("add", "local", route);
2700 }
2701 }
2702 }
2703
2704 @Override
2705 public void removeInterfaceFromLocalNetwork(String iface) {
2706 modifyInterfaceInNetwork("remove", "local", iface);
2707 }
Erik Kline6599ee82016-07-17 21:28:39 +09002708
2709 @Override
2710 public int removeRoutesFromLocalNetwork(List<RouteInfo> routes) {
2711 int failures = 0;
2712
2713 for (RouteInfo route : routes) {
2714 try {
2715 modifyRoute("remove", "local", route);
2716 } catch (IllegalStateException e) {
2717 failures++;
2718 }
2719 }
2720
2721 return failures;
2722 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002723
2724 private void setFirewallChainState(int chain, boolean state) {
2725 synchronized (mRulesLock) {
2726 mFirewallChainStates.put(chain, state);
2727 }
2728 }
2729
2730 private boolean getFirewallChainState(int chain) {
2731 synchronized (mRulesLock) {
2732 return mFirewallChainStates.get(chain);
2733 }
2734 }
2735
2736 @VisibleForTesting
2737 class LocalService extends NetworkManagementInternal {
2738 @Override
2739 public boolean isNetworkRestrictedForUid(int uid) {
2740 synchronized (mRulesLock) {
2741 if (getFirewallChainState(FIREWALL_CHAIN_STANDBY)
2742 && mUidFirewallStandbyRules.get(uid) == FIREWALL_RULE_DENY) {
2743 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of app standby mode");
2744 return true;
2745 }
2746 if (getFirewallChainState(FIREWALL_CHAIN_DOZABLE)
2747 && mUidFirewallDozableRules.get(uid) != FIREWALL_RULE_ALLOW) {
2748 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of device idle mode");
2749 return true;
2750 }
2751 if (getFirewallChainState(FIREWALL_CHAIN_POWERSAVE)
2752 && mUidFirewallPowerSaveRules.get(uid) != FIREWALL_RULE_ALLOW) {
2753 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of power saver mode");
2754 return true;
2755 }
2756 if (mUidRejectOnMetered.get(uid)) {
2757 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of no metered data"
2758 + " in the background");
2759 return true;
2760 }
2761 if (mDataSaverMode && !mUidAllowOnMetered.get(uid)) {
2762 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of data saver mode");
2763 return true;
2764 }
2765 return false;
2766 }
2767 }
2768 }
2769
2770 @VisibleForTesting
2771 Injector getInjector() {
2772 return new Injector();
2773 }
2774
2775 @VisibleForTesting
2776 class Injector {
2777 void setDataSaverMode(boolean dataSaverMode) {
2778 mDataSaverMode = dataSaverMode;
2779 }
2780
2781 void setFirewallChainState(int chain, boolean state) {
2782 NetworkManagementService.this.setFirewallChainState(chain, state);
2783 }
2784
2785 void setFirewallRule(int chain, int uid, int rule) {
2786 synchronized (mRulesLock) {
2787 getUidFirewallRulesLR(chain).put(uid, rule);
2788 }
2789 }
2790
2791 void setUidOnMeteredNetworkList(boolean blacklist, int uid, boolean enable) {
2792 synchronized (mRulesLock) {
2793 if (blacklist) {
2794 mUidRejectOnMetered.put(uid, enable);
2795 } else {
2796 mUidAllowOnMetered.put(uid, enable);
2797 }
2798 }
2799 }
2800
2801 void reset() {
2802 synchronized (mRulesLock) {
2803 setDataSaverMode(false);
2804 final int[] chains = {
2805 FIREWALL_CHAIN_DOZABLE,
2806 FIREWALL_CHAIN_STANDBY,
2807 FIREWALL_CHAIN_POWERSAVE
2808 };
2809 for (int chain : chains) {
2810 setFirewallChainState(chain, false);
2811 getUidFirewallRulesLR(chain).clear();
2812 }
2813 mUidAllowOnMetered.clear();
2814 mUidRejectOnMetered.clear();
2815 }
2816 }
2817 }
San Mehat873f2142010-01-14 10:25:07 -08002818}