blob: 8d76634b7018f263452b5982347b589e97da9563 [file] [log] [blame]
San Mehat873f2142010-01-14 10:25:07 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Jeff Sharkey4529bb62011-12-14 10:31:54 -080019import static android.Manifest.permission.CONNECTIVITY_INTERNAL;
Sehee Parka9139bc2017-12-22 13:54:05 +090020import static android.Manifest.permission.NETWORK_SETTINGS;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090021import static android.Manifest.permission.NETWORK_STACK;
Jeff Sharkeyaf75c332011-11-18 12:41:12 -080022import static android.Manifest.permission.SHUTDOWN;
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +090023import static android.net.INetd.FIREWALL_BLACKLIST;
24import static android.net.INetd.FIREWALL_CHAIN_DOZABLE;
25import static android.net.INetd.FIREWALL_CHAIN_NONE;
26import static android.net.INetd.FIREWALL_CHAIN_POWERSAVE;
27import static android.net.INetd.FIREWALL_CHAIN_STANDBY;
28import static android.net.INetd.FIREWALL_RULE_ALLOW;
29import static android.net.INetd.FIREWALL_RULE_DENY;
30import static android.net.INetd.FIREWALL_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070031import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_DOZABLE;
Felipe Leme011b98f2016-02-10 17:28:31 -080032import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_POWERSAVE;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070033import static android.net.NetworkPolicyManager.FIREWALL_CHAIN_NAME_STANDBY;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070034import static android.net.NetworkPolicyManager.FIREWALL_RULE_DEFAULT;
Jeff Sharkeyb5d55e32011-08-10 17:53:27 -070035import static android.net.NetworkStats.SET_DEFAULT;
Lorenzo Colittif1912ca2017-08-17 19:23:08 +090036import static android.net.NetworkStats.STATS_PER_UID;
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -080037import static android.net.NetworkStats.TAG_ALL;
Jeff Sharkey1b5a2a92011-06-18 18:34:16 -070038import static android.net.NetworkStats.TAG_NONE;
39import static android.net.NetworkStats.UID_ALL;
Jeff Sharkeyae2c1812011-10-04 13:11:40 -070040import static android.net.TrafficStats.UID_TETHERING;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090041
Jeff Sharkeya63ba592011-07-19 23:47:12 -070042import static com.android.server.NetworkManagementSocketTagger.PROP_QTAGUID_ENABLED;
Erik Klineb2cfdfb2017-01-18 20:54:14 +090043
Xiaohui Chenb41c9f72015-06-17 15:55:37 -070044import android.annotation.NonNull;
Sudheer Shankadc589ac2016-11-10 15:30:17 -080045import android.app.ActivityManager;
San Mehat873f2142010-01-14 10:25:07 -080046import android.content.Context;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080047import android.net.ConnectivityManager;
Lorenzo Colitti58967ba2016-02-02 17:21:21 +090048import android.net.INetd;
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +090049import android.net.INetdUnsolicitedEventListener;
San Mehat4d02d002010-01-22 16:07:46 -080050import android.net.INetworkManagementEventObserver;
Lorenzo Colitti07f13042017-07-10 19:06:57 +090051import android.net.ITetheringStatsProvider;
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +090052import android.net.InetAddresses;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070053import android.net.InterfaceConfiguration;
Luke Huang14f75442018-08-15 19:22:54 +080054import android.net.InterfaceConfigurationParcel;
Lorenzo Colittic18cbfd2014-06-13 21:21:03 +090055import android.net.IpPrefix;
Robert Greenwalted126402011-01-28 15:34:55 -080056import android.net.LinkAddress;
Lorenzo Colittib57edc52014-08-22 17:10:50 -070057import android.net.Network;
Amith Yamasani15e472352015-04-24 19:06:07 -070058import android.net.NetworkPolicyManager;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -070059import android.net.NetworkStats;
Robert Greenwalted126402011-01-28 15:34:55 -080060import android.net.NetworkUtils;
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070061import android.net.RouteInfo;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090062import android.net.TetherStatsParcel;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -040063import android.net.UidRange;
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +090064import android.net.UidRangeParcel;
Remi NGUYEN VAN231b52b2019-01-29 15:38:52 +090065import android.net.util.NetdService;
Dianne Hackborn91268cf2013-06-13 19:06:50 -070066import android.os.BatteryStats;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070067import android.os.Binder;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070068import android.os.Handler;
Lorenzo Colittia0868002017-07-11 02:29:28 +090069import android.os.IBinder;
Dianne Hackborn77b987f2014-02-26 16:20:52 -080070import android.os.INetworkActivityListener;
San Mehat873f2142010-01-14 10:25:07 -080071import android.os.INetworkManagementService;
Jeff Sharkeyf56e2432012-09-06 17:54:29 -070072import android.os.Process;
Jeff Sharkey3df273e2011-12-15 15:47:12 -080073import android.os.RemoteCallbackList;
74import android.os.RemoteException;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070075import android.os.ServiceManager;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +090076import android.os.ServiceSpecificException;
Jeff Sharkey605eb792014-11-04 13:34:06 -080077import android.os.StrictMode;
Jeff Sharkey9a13f362011-04-26 16:25:36 -070078import android.os.SystemClock;
Marco Nelissen62dbb222010-02-18 10:56:30 -080079import android.os.SystemProperties;
Felipe Leme29e72ea2016-09-08 13:26:55 -070080import android.os.Trace;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -070081import android.telephony.DataConnectionRealTimeInfo;
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +090082import android.text.TextUtils;
Irfan Sheriff9ab518ad2010-03-12 15:48:17 -080083import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080084import android.util.Slog;
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -070085import android.util.SparseBooleanArray;
Jeff Sharkey605eb792014-11-04 13:34:06 -080086import android.util.SparseIntArray;
Bookatz0b028b12018-05-31 16:51:17 -070087import android.util.StatsLog;
San Mehat873f2142010-01-14 10:25:07 -080088
Jeff Sharkey605eb792014-11-04 13:34:06 -080089import com.android.internal.annotations.GuardedBy;
Sudheer Shanka62f5c172017-03-17 16:25:55 -070090import com.android.internal.annotations.VisibleForTesting;
Jeff Sharkey7a1c3fc2013-06-04 12:29:00 -070091import com.android.internal.app.IBatteryStats;
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -060092import com.android.internal.util.DumpUtils;
Jeff Sharkey605eb792014-11-04 13:34:06 -080093import com.android.internal.util.HexDump;
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -070094import com.android.internal.util.Preconditions;
Chenbo Feng061cec72019-03-01 15:07:24 -080095import com.android.server.net.NetworkStatsFactory;
Lorenzo Colitti9307ca22019-01-12 01:54:23 +090096
Jeff Sharkeyb24a7852012-05-01 15:19:37 -070097import com.google.android.collect.Maps;
Jeff Sharkey4414cea2011-06-24 17:05:24 -070098
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -070099import java.io.BufferedReader;
100import java.io.DataInputStream;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700101import java.io.FileDescriptor;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700102import java.io.FileInputStream;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700103import java.io.IOException;
Jeff Sharkey9a13f362011-04-26 16:25:36 -0700104import java.io.InputStreamReader;
Jeff Sharkey47eb1022011-08-25 17:48:52 -0700105import java.io.PrintWriter;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700106import java.net.InetAddress;
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700107import java.net.InterfaceAddress;
Jeff Sharkeyeedcb952011-05-17 14:55:15 -0700108import java.util.ArrayList;
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400109import java.util.Arrays;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700110import java.util.HashMap;
jiaguo1da35f72014-01-09 16:39:59 +0800111import java.util.List;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700112import java.util.Map;
San Mehat873f2142010-01-14 10:25:07 -0800113
114/**
115 * @hide
116 */
Luke Huang909b31a2019-03-16 21:21:16 +0800117public class NetworkManagementService extends INetworkManagementService.Stub {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900118
119 /**
120 * Helper class that encapsulates NetworkManagementService dependencies and makes them
121 * easier to mock in unit tests.
122 */
123 static class SystemServices {
124 public IBinder getService(String name) {
125 return ServiceManager.getService(name);
126 }
127 public void registerLocalService(NetworkManagementInternal nmi) {
128 LocalServices.addService(NetworkManagementInternal.class, nmi);
129 }
130 public INetd getNetd() {
131 return NetdService.get();
132 }
133 }
134
Amith Yamasani15e472352015-04-24 19:06:07 -0700135 private static final String TAG = "NetworkManagement";
136 private static final boolean DBG = Log.isLoggable(TAG, Log.DEBUG);
Kenny Root305bcbf2010-09-03 07:56:38 -0700137
Paul Jensen6bc2c2c2014-05-07 15:27:40 -0400138 private static final int MAX_UID_RANGES_PER_COMMAND = 10;
139
Jeff Sharkey8e9992a2011-08-23 18:37:23 -0700140 /**
141 * Name representing {@link #setGlobalAlert(long)} limit when delivered to
142 * {@link INetworkManagementEventObserver#limitReached(String, String)}.
143 */
144 public static final String LIMIT_GLOBAL_ALERT = "globalAlert";
145
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700146 static final int DAEMON_MSG_MOBILE_CONN_REAL_TIME_INFO = 1;
147
Luke Huang8a462ec2018-08-24 20:33:16 +0800148 static final boolean MODIFY_OPERATION_ADD = true;
149 static final boolean MODIFY_OPERATION_REMOVE = false;
150
San Mehat873f2142010-01-14 10:25:07 -0800151 /**
152 * Binder context for this service
153 */
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700154 private final Context mContext;
San Mehat873f2142010-01-14 10:25:07 -0800155
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700156 private final Handler mDaemonHandler;
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700157
Lorenzo Colittia0868002017-07-11 02:29:28 +0900158 private final SystemServices mServices;
159
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900160 private INetd mNetdService;
161
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900162 private final NetdUnsolicitedEventListener mNetdUnsolicitedEventListener;
Luke Huangd290dd52018-09-04 17:08:18 +0800163
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800164 private IBatteryStats mBatteryStats;
165
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900166 private final RemoteCallbackList<INetworkManagementEventObserver> mObservers =
167 new RemoteCallbackList<>();
168
Jeff Sharkey1059c3c2011-10-04 16:54:49 -0700169 private final NetworkStatsFactory mStatsFactory = new NetworkStatsFactory();
170
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900171 @GuardedBy("mTetheringStatsProviders")
172 private final HashMap<ITetheringStatsProvider, String>
173 mTetheringStatsProviders = Maps.newHashMap();
174
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700175 /**
176 * If both locks need to be held, then they should be obtained in the order:
177 * first {@link #mQuotaLock} and then {@link #mRulesLock}.
178 */
Andrew Scull45f533c2017-05-19 15:37:20 +0100179 private final Object mQuotaLock = new Object();
Andrew Scull519291f2017-05-23 13:11:03 +0100180 private final Object mRulesLock = new Object();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800181
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700182 /** Set of interfaces with active quotas. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800183 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700184 private HashMap<String, Long> mActiveQuotas = Maps.newHashMap();
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -0700185 /** Set of interfaces with active alerts. */
Jeff Sharkey605eb792014-11-04 13:34:06 -0800186 @GuardedBy("mQuotaLock")
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700187 private HashMap<String, Long> mActiveAlerts = Maps.newHashMap();
Felipe Leme65be3022016-03-22 14:53:13 -0700188 /** Set of UIDs blacklisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700189 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700190 private SparseBooleanArray mUidRejectOnMetered = new SparseBooleanArray();
191 /** Set of UIDs whitelisted on metered networks. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700192 @GuardedBy("mRulesLock")
Felipe Leme65be3022016-03-22 14:53:13 -0700193 private SparseBooleanArray mUidAllowOnMetered = new SparseBooleanArray();
Jeff Sharkey605eb792014-11-04 13:34:06 -0800194 /** Set of UIDs with cleartext penalties. */
195 @GuardedBy("mQuotaLock")
196 private SparseIntArray mUidCleartextPolicy = new SparseIntArray();
Amith Yamasani15e472352015-04-24 19:06:07 -0700197 /** Set of UIDs that are to be blocked/allowed by firewall controller. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700198 @GuardedBy("mRulesLock")
Amith Yamasani15e472352015-04-24 19:06:07 -0700199 private SparseIntArray mUidFirewallRules = new SparseIntArray();
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700200 /**
201 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
202 * to application idles.
203 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700204 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700205 private SparseIntArray mUidFirewallStandbyRules = new SparseIntArray();
206 /**
207 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
208 * to device idles.
209 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700210 @GuardedBy("mRulesLock")
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700211 private SparseIntArray mUidFirewallDozableRules = new SparseIntArray();
Felipe Leme011b98f2016-02-10 17:28:31 -0800212 /**
213 * Set of UIDs that are to be blocked/allowed by firewall controller. This set of Ids matches
214 * to device on power-save mode.
215 */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700216 @GuardedBy("mRulesLock")
Felipe Leme011b98f2016-02-10 17:28:31 -0800217 private SparseIntArray mUidFirewallPowerSaveRules = new SparseIntArray();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700218 /** Set of states for the child firewall chains. True if the chain is active. */
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700219 @GuardedBy("mRulesLock")
Xiaohui Chen8dca36d2015-06-19 12:44:59 -0700220 final SparseBooleanArray mFirewallChainStates = new SparseBooleanArray();
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -0700221
Felipe Leme65be3022016-03-22 14:53:13 -0700222 @GuardedBy("mQuotaLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700223 private volatile boolean mDataSaverMode;
Felipe Leme65be3022016-03-22 14:53:13 -0700224
Andrew Scull45f533c2017-05-19 15:37:20 +0100225 private final Object mIdleTimerLock = new Object();
Haoyu Bai04124232012-06-28 15:26:19 -0700226 /** Set of interfaces with active idle timers. */
227 private static class IdleTimerParams {
228 public final int timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800229 public final int type;
Haoyu Bai04124232012-06-28 15:26:19 -0700230 public int networkCount;
231
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800232 IdleTimerParams(int timeout, int type) {
Haoyu Bai04124232012-06-28 15:26:19 -0700233 this.timeout = timeout;
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800234 this.type = type;
Haoyu Bai04124232012-06-28 15:26:19 -0700235 this.networkCount = 1;
236 }
237 }
238 private HashMap<String, IdleTimerParams> mActiveIdleTimers = Maps.newHashMap();
239
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700240 private volatile boolean mFirewallEnabled;
Jeff Sharkey605eb792014-11-04 13:34:06 -0800241 private volatile boolean mStrictEnabled;
Jeff Sharkey350083e2011-06-29 10:45:16 -0700242
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700243 private boolean mMobileActivityFromRadio = false;
244 private int mLastPowerStateFromRadio = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Adam Lesinskie08af192015-03-25 16:42:59 -0700245 private int mLastPowerStateFromWifi = DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700246
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800247 private final RemoteCallbackList<INetworkActivityListener> mNetworkActivityListeners =
Christopher Wiley212b95f2016-08-02 11:38:57 -0700248 new RemoteCallbackList<>();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800249 private boolean mNetworkActive;
250
San Mehat873f2142010-01-14 10:25:07 -0800251 /**
252 * Constructs a new NetworkManagementService instance
253 *
254 * @param context Binder context for this service
255 */
Lorenzo Colittia0868002017-07-11 02:29:28 +0900256 private NetworkManagementService(
Luke Huang909b31a2019-03-16 21:21:16 +0800257 Context context, SystemServices services) {
San Mehat873f2142010-01-14 10:25:07 -0800258 mContext = context;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900259 mServices = services;
San Mehat4d02d002010-01-22 16:07:46 -0800260
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700261 mDaemonHandler = new Handler(FgThread.get().getLooper());
Wink Saville67e07892014-06-18 16:43:14 -0700262
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900263 mNetdUnsolicitedEventListener = new NetdUnsolicitedEventListener();
264
Lorenzo Colittia0868002017-07-11 02:29:28 +0900265 mServices.registerLocalService(new LocalService());
Lorenzo Colitti8228eb32017-07-19 06:17:33 +0900266
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900267 synchronized (mTetheringStatsProviders) {
268 mTetheringStatsProviders.put(new NetdTetheringStatsProvider(), "netd");
269 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700270 }
271
272 @VisibleForTesting
273 NetworkManagementService() {
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700274 mContext = null;
275 mDaemonHandler = null;
Lorenzo Colittia0868002017-07-11 02:29:28 +0900276 mServices = null;
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900277 mNetdUnsolicitedEventListener = null;
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700278 }
279
Luke Huang909b31a2019-03-16 21:21:16 +0800280 static NetworkManagementService create(Context context, SystemServices services)
Felipe Leme03e689d2016-03-02 16:17:38 -0800281 throws InterruptedException {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900282 final NetworkManagementService service =
Luke Huang909b31a2019-03-16 21:21:16 +0800283 new NetworkManagementService(context, services);
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700284 if (DBG) Slog.d(TAG, "Creating NetworkManagementService");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900285 if (DBG) Slog.d(TAG, "Connecting native netd service");
bohu07cc3bb2016-05-03 15:58:01 -0700286 service.connectNativeNetdService();
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900287 if (DBG) Slog.d(TAG, "Connected");
Robert Greenwalte5c3afb2010-09-22 14:32:35 -0700288 return service;
San Mehat873f2142010-01-14 10:25:07 -0800289 }
290
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900291 public static NetworkManagementService create(Context context) throws InterruptedException {
Luke Huang909b31a2019-03-16 21:21:16 +0800292 return create(context, new SystemServices());
Lorenzo Colitti7421a012013-08-20 22:51:24 +0900293 }
294
Jeff Sharkey350083e2011-06-29 10:45:16 -0700295 public void systemReady() {
Felipe Leme03e689d2016-03-02 16:17:38 -0800296 if (DBG) {
297 final long start = System.currentTimeMillis();
298 prepareNativeDaemon();
299 final long delta = System.currentTimeMillis() - start;
300 Slog.d(TAG, "Prepared in " + delta + "ms");
301 return;
302 } else {
303 prepareNativeDaemon();
304 }
Jeff Sharkey350083e2011-06-29 10:45:16 -0700305 }
306
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800307 private IBatteryStats getBatteryStats() {
308 synchronized (this) {
309 if (mBatteryStats != null) {
310 return mBatteryStats;
311 }
Lorenzo Colittia0868002017-07-11 02:29:28 +0900312 mBatteryStats =
313 IBatteryStats.Stub.asInterface(mServices.getService(BatteryStats.SERVICE_NAME));
Dianne Hackborne13c4c02014-02-11 17:18:35 -0800314 return mBatteryStats;
315 }
316 }
317
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800318 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800319 public void registerObserver(INetworkManagementEventObserver observer) {
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900320 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
321 mObservers.register(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800322 }
323
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800324 @Override
Jeff Sharkey3df273e2011-12-15 15:47:12 -0800325 public void unregisterObserver(INetworkManagementEventObserver observer) {
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900326 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
327 mObservers.unregister(observer);
San Mehat4d02d002010-01-22 16:07:46 -0800328 }
329
Erik Klineb2cfdfb2017-01-18 20:54:14 +0900330 @FunctionalInterface
331 private interface NetworkManagementEventCallback {
332 public void sendCallback(INetworkManagementEventObserver o) throws RemoteException;
333 }
334
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900335 private void invokeForAllObservers(NetworkManagementEventCallback eventCallback) {
336 final int length = mObservers.beginBroadcast();
337 try {
338 for (int i = 0; i < length; i++) {
339 try {
340 eventCallback.sendCallback(mObservers.getBroadcastItem(i));
341 } catch (RemoteException | RuntimeException e) {
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700342 }
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900343 }
344 } finally {
345 mObservers.finishBroadcast();
346 }
347 }
348
349 /**
350 * Notify our observers of an interface status change
351 */
352 private void notifyInterfaceStatusChanged(String iface, boolean up) {
353 invokeForAllObservers(o -> o.interfaceStatusChanged(iface, up));
354 }
355
356 /**
357 * Notify our observers of an interface link state change
358 * (typically, an Ethernet cable has been plugged-in or unplugged).
359 */
360 private void notifyInterfaceLinkStateChanged(String iface, boolean up) {
361 invokeForAllObservers(o -> o.interfaceLinkStateChanged(iface, up));
362 }
363
364 /**
365 * Notify our observers of an interface addition.
366 */
367 private void notifyInterfaceAdded(String iface) {
368 invokeForAllObservers(o -> o.interfaceAdded(iface));
369 }
370
371 /**
372 * Notify our observers of an interface removal.
373 */
374 private void notifyInterfaceRemoved(String iface) {
375 // netd already clears out quota and alerts for removed ifaces; update
376 // our sanity-checking state.
377 mActiveAlerts.remove(iface);
378 mActiveQuotas.remove(iface);
379 invokeForAllObservers(o -> o.interfaceRemoved(iface));
380 }
381
382 /**
383 * Notify our observers of a limit reached.
384 */
385 private void notifyLimitReached(String limitName, String iface) {
386 invokeForAllObservers(o -> o.limitReached(limitName, iface));
387 }
388
389 /**
390 * Notify our observers of a change in the data activity state of the interface
391 */
392 private void notifyInterfaceClassActivity(int type, boolean isActive, long tsNanos,
393 int uid, boolean fromRadio) {
394 final boolean isMobile = ConnectivityManager.isNetworkTypeMobile(type);
395 int powerState = isActive
396 ? DataConnectionRealTimeInfo.DC_POWER_STATE_HIGH
397 : DataConnectionRealTimeInfo.DC_POWER_STATE_LOW;
398 if (isMobile) {
399 if (!fromRadio) {
400 if (mMobileActivityFromRadio) {
401 // If this call is not coming from a report from the radio itself, but we
402 // have previously received reports from the radio, then we will take the
403 // power state to just be whatever the radio last reported.
404 powerState = mLastPowerStateFromRadio;
405 }
406 } else {
407 mMobileActivityFromRadio = true;
408 }
409 if (mLastPowerStateFromRadio != powerState) {
410 mLastPowerStateFromRadio = powerState;
411 try {
412 getBatteryStats().noteMobileRadioPowerState(powerState, tsNanos, uid);
413 } catch (RemoteException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -0700414 }
Bookatz0b028b12018-05-31 16:51:17 -0700415 StatsLog.write_non_chained(StatsLog.MOBILE_RADIO_POWER_STATE_CHANGED, uid, null,
416 powerState);
Haoyu Baidb3c8672012-06-20 14:29:57 -0700417 }
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900418 }
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -0700419
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900420 if (ConnectivityManager.isNetworkTypeWifi(type)) {
421 if (mLastPowerStateFromWifi != powerState) {
422 mLastPowerStateFromWifi = powerState;
423 try {
424 getBatteryStats().noteWifiRadioPowerState(powerState, tsNanos, uid);
425 } catch (RemoteException e) {
Adam Lesinskie08af192015-03-25 16:42:59 -0700426 }
Bookatz0b028b12018-05-31 16:51:17 -0700427 StatsLog.write_non_chained(StatsLog.WIFI_RADIO_POWER_STATE_CHANGED, uid, null,
428 powerState);
Adam Lesinskie08af192015-03-25 16:42:59 -0700429 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800430 }
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900431
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900432 if (!isMobile || fromRadio || !mMobileActivityFromRadio) {
433 // Report the change in data activity. We don't do this if this is a change
434 // on the mobile network, that is not coming from the radio itself, and we
435 // have previously seen change reports from the radio. In that case only
436 // the radio is the authority for the current state.
437 final boolean active = isActive;
438 invokeForAllObservers(o -> o.interfaceClassDataActivityChanged(
439 Integer.toString(type), active, tsNanos));
Lorenzo Colittid8bc8292019-01-24 13:28:50 +0900440 }
441
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900442 boolean report = false;
443 synchronized (mIdleTimerLock) {
444 if (mActiveIdleTimers.isEmpty()) {
445 // If there are no idle timers, we are not monitoring activity, so we
446 // are always considered active.
447 isActive = true;
448 }
449 if (mNetworkActive != isActive) {
450 mNetworkActive = isActive;
451 report = isActive;
452 }
453 }
454 if (report) {
455 reportNetworkActive();
Dianne Hackborn77b987f2014-02-26 16:20:52 -0800456 }
Haoyu Baidb3c8672012-06-20 14:29:57 -0700457 }
458
Lorenzo Colitti07f13042017-07-10 19:06:57 +0900459 @Override
460 public void registerTetheringStatsProvider(ITetheringStatsProvider provider, String name) {
461 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
462 Preconditions.checkNotNull(provider);
463 synchronized(mTetheringStatsProviders) {
464 mTetheringStatsProviders.put(provider, name);
465 }
466 }
467
468 @Override
469 public void unregisterTetheringStatsProvider(ITetheringStatsProvider provider) {
470 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
471 synchronized(mTetheringStatsProviders) {
472 mTetheringStatsProviders.remove(provider);
473 }
474 }
475
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900476 @Override
477 public void tetherLimitReached(ITetheringStatsProvider provider) {
478 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
479 synchronized(mTetheringStatsProviders) {
480 if (!mTetheringStatsProviders.containsKey(provider)) {
481 return;
482 }
483 // No current code examines the interface parameter in a global alert. Just pass null.
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900484 mDaemonHandler.post(() -> notifyLimitReached(LIMIT_GLOBAL_ALERT, null));
Lorenzo Colitti9f0baa92017-08-15 19:25:51 +0900485 }
486 }
487
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900488 // Sync the state of the given chain with the native daemon.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700489 private void syncFirewallChainLocked(int chain, String name) {
490 SparseIntArray rules;
491 synchronized (mRulesLock) {
492 final SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900493 // Make a copy of the current rules, and then clear them. This is because
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700494 // setFirewallUidRuleInternal only pushes down rules to the native daemon if they
495 // are different from the current rules stored in the mUidFirewall*Rules array for
496 // the specified chain. If we don't clear the rules, setFirewallUidRuleInternal
497 // will do nothing.
498 rules = uidFirewallRules.clone();
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900499 uidFirewallRules.clear();
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700500 }
501 if (rules.size() > 0) {
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900502 // Now push the rules. setFirewallUidRuleInternal will push each of these down to the
503 // native daemon, and also add them to the mUidFirewall*Rules array for the specified
504 // chain.
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700505 if (DBG) Slog.d(TAG, "Pushing " + rules.size() + " active firewall "
506 + name + "UID rules");
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900507 for (int i = 0; i < rules.size(); i++) {
Felipe Lemea701cad2016-05-12 09:58:14 -0700508 setFirewallUidRuleLocked(chain, rules.keyAt(i), rules.valueAt(i));
Lorenzo Colitti9eb844e2016-03-23 23:22:49 +0900509 }
510 }
511 }
512
bohu07cc3bb2016-05-03 15:58:01 -0700513 private void connectNativeNetdService() {
Lorenzo Colittia0868002017-07-11 02:29:28 +0900514 mNetdService = mServices.getNetd();
Luke Huangd290dd52018-09-04 17:08:18 +0800515 try {
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900516 mNetdService.registerUnsolicitedEventListener(mNetdUnsolicitedEventListener);
517 if (DBG) Slog.d(TAG, "Register unsolicited event listener");
Luke Huangd290dd52018-09-04 17:08:18 +0800518 } catch (RemoteException | ServiceSpecificException e) {
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900519 Slog.e(TAG, "Failed to set Netd unsolicited event listener " + e);
Luke Huangd290dd52018-09-04 17:08:18 +0800520 }
bohu07cc3bb2016-05-03 15:58:01 -0700521 }
522
523 /**
524 * Prepare native daemon once connected, enabling modules and pushing any
525 * existing in-memory rules.
526 */
527 private void prepareNativeDaemon() {
Lorenzo Colitti58967ba2016-02-02 17:21:21 +0900528
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700529 // push any existing quota or UID rules
530 synchronized (mQuotaLock) {
Felipe Leme65be3022016-03-22 14:53:13 -0700531
Luke Huang56a03a02018-09-07 12:02:16 +0800532 // Netd unconditionally enable bandwidth control
533 SystemProperties.set(PROP_QTAGUID_ENABLED, "1");
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900534
Luke Huang473eb872018-07-26 17:33:14 +0800535 mStrictEnabled = true;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900536
Felipe Leme65be3022016-03-22 14:53:13 -0700537 setDataSaverModeEnabled(mDataSaverMode);
538
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700539 int size = mActiveQuotas.size();
540 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800541 if (DBG) Slog.d(TAG, "Pushing " + size + " active quota rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700542 final HashMap<String, Long> activeQuotas = mActiveQuotas;
543 mActiveQuotas = Maps.newHashMap();
544 for (Map.Entry<String, Long> entry : activeQuotas.entrySet()) {
545 setInterfaceQuota(entry.getKey(), entry.getValue());
546 }
547 }
548
549 size = mActiveAlerts.size();
550 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800551 if (DBG) Slog.d(TAG, "Pushing " + size + " active alert rules");
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700552 final HashMap<String, Long> activeAlerts = mActiveAlerts;
553 mActiveAlerts = Maps.newHashMap();
554 for (Map.Entry<String, Long> entry : activeAlerts.entrySet()) {
555 setInterfaceAlert(entry.getKey(), entry.getValue());
556 }
557 }
558
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700559 SparseBooleanArray uidRejectOnQuota = null;
560 SparseBooleanArray uidAcceptOnQuota = null;
561 synchronized (mRulesLock) {
562 size = mUidRejectOnMetered.size();
563 if (size > 0) {
564 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered blacklist rules");
565 uidRejectOnQuota = mUidRejectOnMetered;
566 mUidRejectOnMetered = new SparseBooleanArray();
567 }
568
569 size = mUidAllowOnMetered.size();
570 if (size > 0) {
571 if (DBG) Slog.d(TAG, "Pushing " + size + " UIDs to metered whitelist rules");
572 uidAcceptOnQuota = mUidAllowOnMetered;
573 mUidAllowOnMetered = new SparseBooleanArray();
574 }
575 }
576 if (uidRejectOnQuota != null) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700577 for (int i = 0; i < uidRejectOnQuota.size(); i++) {
Felipe Leme65be3022016-03-22 14:53:13 -0700578 setUidMeteredNetworkBlacklist(uidRejectOnQuota.keyAt(i),
579 uidRejectOnQuota.valueAt(i));
580 }
581 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700582 if (uidAcceptOnQuota != null) {
Felipe Leme65be3022016-03-22 14:53:13 -0700583 for (int i = 0; i < uidAcceptOnQuota.size(); i++) {
584 setUidMeteredNetworkWhitelist(uidAcceptOnQuota.keyAt(i),
585 uidAcceptOnQuota.valueAt(i));
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700586 }
587 }
Jeff Sharkey605eb792014-11-04 13:34:06 -0800588
589 size = mUidCleartextPolicy.size();
590 if (size > 0) {
Felipe Leme03e689d2016-03-02 16:17:38 -0800591 if (DBG) Slog.d(TAG, "Pushing " + size + " active UID cleartext policies");
Jeff Sharkey605eb792014-11-04 13:34:06 -0800592 final SparseIntArray local = mUidCleartextPolicy;
593 mUidCleartextPolicy = new SparseIntArray();
594 for (int i = 0; i < local.size(); i++) {
595 setUidCleartextNetworkPolicy(local.keyAt(i), local.valueAt(i));
596 }
597 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -0700598
Robin Leec3736bc2017-03-10 16:19:54 +0000599 setFirewallEnabled(mFirewallEnabled);
Amith Yamasani15e472352015-04-24 19:06:07 -0700600
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700601 syncFirewallChainLocked(FIREWALL_CHAIN_NONE, "");
602 syncFirewallChainLocked(FIREWALL_CHAIN_STANDBY, "standby ");
603 syncFirewallChainLocked(FIREWALL_CHAIN_DOZABLE, "dozable ");
604 syncFirewallChainLocked(FIREWALL_CHAIN_POWERSAVE, "powersave ");
Xiaohui Chenb41c9f72015-06-17 15:55:37 -0700605
Sudheer Shanka62f5c172017-03-17 16:25:55 -0700606 final int[] chains =
607 {FIREWALL_CHAIN_STANDBY, FIREWALL_CHAIN_DOZABLE, FIREWALL_CHAIN_POWERSAVE};
608 for (int chain : chains) {
609 if (getFirewallChainState(chain)) {
610 setFirewallChainEnabled(chain, true);
611 }
Felipe Leme011b98f2016-02-10 17:28:31 -0800612 }
Amith Yamasani15e472352015-04-24 19:06:07 -0700613 }
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900614
Luke Huang56a03a02018-09-07 12:02:16 +0800615
616 try {
617 getBatteryStats().noteNetworkStatsEnabled();
618 } catch (RemoteException e) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +0900619 }
620
Jeff Sharkeyb24a7852012-05-01 15:19:37 -0700621 }
San Mehat4d02d002010-01-22 16:07:46 -0800622
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900623 /**
624 * Notify our observers of a new or updated interface address.
625 */
626 private void notifyAddressUpdated(String iface, LinkAddress address) {
627 invokeForAllObservers(o -> o.addressUpdated(iface, address));
628 }
629
630 /**
631 * Notify our observers of a deleted interface address.
632 */
633 private void notifyAddressRemoved(String iface, LinkAddress address) {
634 invokeForAllObservers(o -> o.addressRemoved(iface, address));
635 }
636
637 /**
638 * Notify our observers of DNS server information received.
639 */
640 private void notifyInterfaceDnsServerInfo(String iface, long lifetime, String[] addresses) {
641 invokeForAllObservers(o -> o.interfaceDnsServerInfo(iface, lifetime, addresses));
642 }
643
644 /**
645 * Notify our observers of a route change.
646 */
647 private void notifyRouteChange(boolean updated, RouteInfo route) {
648 if (updated) {
649 invokeForAllObservers(o -> o.routeUpdated(route));
650 } else {
651 invokeForAllObservers(o -> o.routeRemoved(route));
652 }
653 }
654
655 private class NetdUnsolicitedEventListener extends INetdUnsolicitedEventListener.Stub {
656 @Override
657 public void onInterfaceClassActivityChanged(boolean isActive,
658 int label, long timestamp, int uid) throws RemoteException {
659 final long timestampNanos;
660 if (timestamp <= 0) {
661 timestampNanos = SystemClock.elapsedRealtimeNanos();
662 } else {
663 timestampNanos = timestamp;
664 }
665 mDaemonHandler.post(() ->
666 notifyInterfaceClassActivity(label, isActive, timestampNanos, uid, false));
667 }
668
669 @Override
670 public void onQuotaLimitReached(String alertName, String ifName)
671 throws RemoteException {
672 mDaemonHandler.post(() -> notifyLimitReached(alertName, ifName));
673 }
674
675 @Override
676 public void onInterfaceDnsServerInfo(String ifName,
677 long lifetime, String[] servers) throws RemoteException {
678 mDaemonHandler.post(() -> notifyInterfaceDnsServerInfo(ifName, lifetime, servers));
679 }
680
681 @Override
682 public void onInterfaceAddressUpdated(String addr,
683 String ifName, int flags, int scope) throws RemoteException {
684 final LinkAddress address = new LinkAddress(addr, flags, scope);
685 mDaemonHandler.post(() -> notifyAddressUpdated(ifName, address));
686 }
687
688 @Override
689 public void onInterfaceAddressRemoved(String addr,
690 String ifName, int flags, int scope) throws RemoteException {
691 final LinkAddress address = new LinkAddress(addr, flags, scope);
692 mDaemonHandler.post(() -> notifyAddressRemoved(ifName, address));
693 }
694
695 @Override
696 public void onInterfaceAdded(String ifName) throws RemoteException {
697 mDaemonHandler.post(() -> notifyInterfaceAdded(ifName));
698 }
699
700 @Override
701 public void onInterfaceRemoved(String ifName) throws RemoteException {
702 mDaemonHandler.post(() -> notifyInterfaceRemoved(ifName));
703 }
704
705 @Override
706 public void onInterfaceChanged(String ifName, boolean up)
707 throws RemoteException {
708 mDaemonHandler.post(() -> notifyInterfaceStatusChanged(ifName, up));
709 }
710
711 @Override
712 public void onInterfaceLinkStateChanged(String ifName, boolean up)
713 throws RemoteException {
714 mDaemonHandler.post(() -> notifyInterfaceLinkStateChanged(ifName, up));
715 }
716
717 @Override
718 public void onRouteChanged(boolean updated,
719 String route, String gateway, String ifName) throws RemoteException {
720 final RouteInfo processRoute = new RouteInfo(new IpPrefix(route),
721 ("".equals(gateway)) ? null : InetAddresses.parseNumericAddress(gateway),
722 ifName);
723 mDaemonHandler.post(() -> notifyRouteChange(updated, processRoute));
724 }
725
726 @Override
727 public void onStrictCleartextDetected(int uid, String hex) throws RemoteException {
728 // Don't need to post to mDaemonHandler because the only thing
729 // that notifyCleartextNetwork does is post to a handler
730 ActivityManager.getService().notifyCleartextNetwork(uid,
731 HexDump.hexStringToByteArray(hex));
732 }
Remi NGUYEN VANd361ff32019-04-11 11:36:26 -0700733
734 @Override
735 public int getInterfaceVersion() {
736 return INetdUnsolicitedEventListener.VERSION;
737 }
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +0900738 }
739
San Mehat873f2142010-01-14 10:25:07 -0800740 //
San Mehat873f2142010-01-14 10:25:07 -0800741 // INetworkManagementService members
742 //
Erik Kline4e37b702016-07-05 11:34:21 +0900743 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800744 public String[] listInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800745 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -0700746 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +0800747 return mNetdService.interfaceGetList();
Luke Huang14f75442018-08-15 19:22:54 +0800748 } catch (RemoteException | ServiceSpecificException e) {
749 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700750 }
San Mehated4fc8a2010-01-22 12:28:36 -0800751 }
752
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +0900753 /**
754 * Convert InterfaceConfiguration to InterfaceConfigurationParcel with given ifname.
755 */
756 private static InterfaceConfigurationParcel toStableParcel(InterfaceConfiguration cfg,
757 String iface) {
758 InterfaceConfigurationParcel cfgParcel = new InterfaceConfigurationParcel();
759 cfgParcel.ifName = iface;
760 String hwAddr = cfg.getHardwareAddress();
761 if (!TextUtils.isEmpty(hwAddr)) {
762 cfgParcel.hwAddr = hwAddr;
763 } else {
764 cfgParcel.hwAddr = "";
765 }
766 cfgParcel.ipv4Addr = cfg.getLinkAddress().getAddress().getHostAddress();
767 cfgParcel.prefixLength = cfg.getLinkAddress().getPrefixLength();
768 ArrayList<String> flags = new ArrayList<>();
769 for (String flag : cfg.getFlags()) {
770 flags.add(flag);
771 }
772 cfgParcel.flags = flags.toArray(new String[0]);
773
774 return cfgParcel;
775 }
776
777 /**
778 * Construct InterfaceConfiguration from InterfaceConfigurationParcel.
779 */
780 public static InterfaceConfiguration fromStableParcel(InterfaceConfigurationParcel p) {
781 InterfaceConfiguration cfg = new InterfaceConfiguration();
782 cfg.setHardwareAddress(p.hwAddr);
783
784 final InetAddress addr = NetworkUtils.numericToInetAddress(p.ipv4Addr);
785 cfg.setLinkAddress(new LinkAddress(addr, p.prefixLength));
786 for (String flag : p.flags) {
787 cfg.setFlag(flag);
788 }
789
790 return cfg;
791 }
792
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800793 @Override
794 public InterfaceConfiguration getInterfaceConfig(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800795 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang14f75442018-08-15 19:22:54 +0800796 final InterfaceConfigurationParcel result;
Kenny Roota80ce062010-06-01 13:23:53 -0700797 try {
Luke Huang14f75442018-08-15 19:22:54 +0800798 result = mNetdService.interfaceGetCfg(iface);
799 } catch (RemoteException | ServiceSpecificException e) {
800 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700801 }
San Mehated4fc8a2010-01-22 12:28:36 -0800802
San Mehated4fc8a2010-01-22 12:28:36 -0800803 try {
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +0900804 final InterfaceConfiguration cfg = fromStableParcel(result);
Luke Huang14f75442018-08-15 19:22:54 +0800805 return cfg;
806 } catch (IllegalArgumentException iae) {
807 throw new IllegalStateException("Invalid InterfaceConfigurationParcel", iae);
San Mehated4fc8a2010-01-22 12:28:36 -0800808 }
San Mehated4fc8a2010-01-22 12:28:36 -0800809 }
810
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800811 @Override
812 public void setInterfaceConfig(String iface, InterfaceConfiguration cfg) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800813 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800814 LinkAddress linkAddr = cfg.getLinkAddress();
Robert Greenwalt2d2afd12011-02-01 15:30:46 -0800815 if (linkAddr == null || linkAddr.getAddress() == null) {
816 throw new IllegalStateException("Null LinkAddress given");
Robert Greenwalted126402011-01-28 15:34:55 -0800817 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800818
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +0900819 final InterfaceConfigurationParcel cfgParcel = toStableParcel(cfg, iface);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800820
Kenny Roota80ce062010-06-01 13:23:53 -0700821 try {
Luke Huang14f75442018-08-15 19:22:54 +0800822 mNetdService.interfaceSetCfg(cfgParcel);
823 } catch (RemoteException | ServiceSpecificException e) {
824 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700825 }
San Mehat873f2142010-01-14 10:25:07 -0800826 }
827
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800828 @Override
829 public void setInterfaceDown(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800830 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800831 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800832 ifcg.setInterfaceDown();
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800833 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -0700834 }
835
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800836 @Override
837 public void setInterfaceUp(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800838 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800839 final InterfaceConfiguration ifcg = getInterfaceConfig(iface);
Jeff Sharkeyddba1062011-11-29 18:37:04 -0800840 ifcg.setInterfaceUp();
Jeff Sharkey31c6e482011-11-18 17:09:01 -0800841 setInterfaceConfig(iface, ifcg);
Irfan Sheriff7244c972011-08-05 20:40:45 -0700842 }
843
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800844 @Override
845 public void setInterfaceIpv6PrivacyExtensions(String iface, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800846 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sheriff73293612011-09-14 12:31:56 -0700847 try {
Luke Huang14f75442018-08-15 19:22:54 +0800848 mNetdService.interfaceSetIPv6PrivacyExtensions(iface, enable);
849 } catch (RemoteException | ServiceSpecificException e) {
850 throw new IllegalStateException(e);
Irfan Sheriff73293612011-09-14 12:31:56 -0700851 }
852 }
853
Irfan Sherifff5600612011-06-16 10:26:28 -0700854 /* TODO: This is right now a IPv4 only function. Works for wifi which loses its
855 IPv6 addresses on interface down, but we need to do full clean up here */
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800856 @Override
857 public void clearInterfaceAddresses(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800858 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Irfan Sherifff5600612011-06-16 10:26:28 -0700859 try {
Luke Huang14f75442018-08-15 19:22:54 +0800860 mNetdService.interfaceClearAddrs(iface);
861 } catch (RemoteException | ServiceSpecificException e) {
862 throw new IllegalStateException(e);
Irfan Sherifff5600612011-06-16 10:26:28 -0700863 }
864 }
865
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800866 @Override
867 public void enableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800868 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -0700869 try {
Luke Huang14f75442018-08-15 19:22:54 +0800870 mNetdService.interfaceSetEnableIPv6(iface, true);
871 } catch (RemoteException | ServiceSpecificException e) {
872 throw new IllegalStateException(e);
repo sync7960d9f2011-09-29 12:40:02 -0700873 }
874 }
875
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800876 @Override
Joel Scherpelz2db10742017-06-07 15:38:38 +0900877 public void setIPv6AddrGenMode(String iface, int mode) throws ServiceSpecificException {
878 try {
879 mNetdService.setIPv6AddrGenMode(iface, mode);
880 } catch (RemoteException e) {
881 throw e.rethrowAsRuntimeException();
882 }
883 }
884
885 @Override
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800886 public void disableIpv6(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800887 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
repo sync7960d9f2011-09-29 12:40:02 -0700888 try {
Luke Huang14f75442018-08-15 19:22:54 +0800889 mNetdService.interfaceSetEnableIPv6(iface, false);
890 } catch (RemoteException | ServiceSpecificException e) {
891 throw new IllegalStateException(e);
repo sync7960d9f2011-09-29 12:40:02 -0700892 }
893 }
894
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800895 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -0700896 public void addRoute(int netId, RouteInfo route) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800897 modifyRoute(MODIFY_OPERATION_ADD, netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700898 }
899
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800900 @Override
Sreeram Ramachandranb2829fa2014-04-15 19:07:12 -0700901 public void removeRoute(int netId, RouteInfo route) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800902 modifyRoute(MODIFY_OPERATION_REMOVE, netId, route);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700903 }
904
Luke Huang8a462ec2018-08-24 20:33:16 +0800905 private void modifyRoute(boolean add, int netId, RouteInfo route) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800906 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwalt3b28e9a2011-11-02 14:37:19 -0700907
Luke Huang8a462ec2018-08-24 20:33:16 +0800908 final String ifName = route.getInterface();
909 final String dst = route.getDestination().toString();
910 final String nextHop;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900911
912 switch (route.getType()) {
913 case RouteInfo.RTN_UNICAST:
914 if (route.hasGateway()) {
Luke Huang8a462ec2018-08-24 20:33:16 +0800915 nextHop = route.getGateway().getHostAddress();
916 } else {
917 nextHop = INetd.NEXTHOP_NONE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900918 }
919 break;
920 case RouteInfo.RTN_UNREACHABLE:
Luke Huang8a462ec2018-08-24 20:33:16 +0800921 nextHop = INetd.NEXTHOP_UNREACHABLE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900922 break;
923 case RouteInfo.RTN_THROW:
Luke Huang8a462ec2018-08-24 20:33:16 +0800924 nextHop = INetd.NEXTHOP_THROW;
925 break;
926 default:
927 nextHop = INetd.NEXTHOP_NONE;
Lorenzo Colitti4b0f8e62014-09-19 01:49:05 +0900928 break;
Sreeram Ramachandran1fbcb272014-05-22 16:30:48 -0700929 }
Jeff Sharkeyba2896e2011-11-30 18:13:54 -0800930 try {
Luke Huang8a462ec2018-08-24 20:33:16 +0800931 if (add) {
932 mNetdService.networkAddRoute(netId, ifName, dst, nextHop);
933 } else {
934 mNetdService.networkRemoveRoute(netId, ifName, dst, nextHop);
935 }
936 } catch (RemoteException | ServiceSpecificException e) {
937 throw new IllegalStateException(e);
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700938 }
939 }
940
941 private ArrayList<String> readRouteList(String filename) {
942 FileInputStream fstream = null;
Christopher Wiley212b95f2016-08-02 11:38:57 -0700943 ArrayList<String> list = new ArrayList<>();
Robert Greenwalt59b1a4e2011-05-10 15:05:02 -0700944
945 try {
946 fstream = new FileInputStream(filename);
947 DataInputStream in = new DataInputStream(fstream);
948 BufferedReader br = new BufferedReader(new InputStreamReader(in));
949 String s;
950
951 // throw away the title line
952
953 while (((s = br.readLine()) != null) && (s.length() != 0)) {
954 list.add(s);
955 }
956 } catch (IOException ex) {
957 // return current list, possibly empty
958 } finally {
959 if (fstream != null) {
960 try {
961 fstream.close();
962 } catch (IOException ex) {}
963 }
964 }
965
966 return list;
967 }
968
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800969 @Override
sy.yun9d9b74a2013-09-02 05:24:09 +0900970 public void setMtu(String iface, int mtu) {
971 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
972
sy.yun9d9b74a2013-09-02 05:24:09 +0900973 try {
Luke Huang14f75442018-08-15 19:22:54 +0800974 mNetdService.interfaceSetMtu(iface, mtu);
975 } catch (RemoteException | ServiceSpecificException e) {
976 throw new IllegalStateException(e);
sy.yun9d9b74a2013-09-02 05:24:09 +0900977 }
978 }
979
980 @Override
San Mehat873f2142010-01-14 10:25:07 -0800981 public void shutdown() {
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800982 // TODO: remove from aidl if nobody calls externally
983 mContext.enforceCallingOrSelfPermission(SHUTDOWN, TAG);
San Mehat873f2142010-01-14 10:25:07 -0800984
Felipe Leme03e689d2016-03-02 16:17:38 -0800985 Slog.i(TAG, "Shutting down");
San Mehat873f2142010-01-14 10:25:07 -0800986 }
987
Jeff Sharkeyaf75c332011-11-18 12:41:12 -0800988 @Override
San Mehat873f2142010-01-14 10:25:07 -0800989 public boolean getIpForwardingEnabled() throws IllegalStateException{
Jeff Sharkey4529bb62011-12-14 10:31:54 -0800990 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -0800991
Kenny Roota80ce062010-06-01 13:23:53 -0700992 try {
Luke Huang4db488b2018-08-16 15:37:31 +0800993 final boolean isEnabled = mNetdService.ipfwdEnabled();
994 return isEnabled;
995 } catch (RemoteException | ServiceSpecificException e) {
996 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -0700997 }
San Mehat873f2142010-01-14 10:25:07 -0800998 }
999
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001000 @Override
1001 public void setIpForwardingEnabled(boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001002 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001003 try {
Luke Huang4db488b2018-08-16 15:37:31 +08001004 if (enable) {
1005 mNetdService.ipfwdEnableForwarding("tethering");
1006 } else {
1007 mNetdService.ipfwdDisableForwarding("tethering");
1008 }
1009 } catch (RemoteException | ServiceSpecificException e) {
1010 throw new IllegalStateException(e);
Jeff Sharkey31c6e482011-11-18 17:09:01 -08001011 }
San Mehat873f2142010-01-14 10:25:07 -08001012 }
1013
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001014 @Override
1015 public void startTethering(String[] dhcpRange) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001016 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Robert Greenwaltbfb7bfa2010-03-24 16:03:21 -07001017 // an odd number of addrs will fail
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001018
Kenny Roota80ce062010-06-01 13:23:53 -07001019 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001020 mNetdService.tetherStart(dhcpRange);
1021 } catch (RemoteException | ServiceSpecificException e) {
1022 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001023 }
San Mehat873f2142010-01-14 10:25:07 -08001024 }
1025
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001026 @Override
1027 public void stopTethering() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001028 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001029 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001030 mNetdService.tetherStop();
1031 } catch (RemoteException | ServiceSpecificException e) {
1032 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001033 }
San Mehat873f2142010-01-14 10:25:07 -08001034 }
1035
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001036 @Override
1037 public boolean isTetheringStarted() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001038 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
San Mehat873f2142010-01-14 10:25:07 -08001039
Kenny Roota80ce062010-06-01 13:23:53 -07001040 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001041 final boolean isEnabled = mNetdService.tetherIsEnabled();
1042 return isEnabled;
1043 } catch (RemoteException | ServiceSpecificException e) {
1044 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001045 }
San Mehat873f2142010-01-14 10:25:07 -08001046 }
Matthew Xiefe19f122012-07-12 16:03:32 -07001047
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001048 @Override
1049 public void tetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001050 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001051 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001052 mNetdService.tetherInterfaceAdd(iface);
1053 } catch (RemoteException | ServiceSpecificException e) {
1054 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001055 }
Christopher Wiley212b95f2016-08-02 11:38:57 -07001056 List<RouteInfo> routes = new ArrayList<>();
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07001057 // The RouteInfo constructor truncates the LinkAddress to a network prefix, thus making it
1058 // suitable to use as a route destination.
1059 routes.add(new RouteInfo(getInterfaceConfig(iface).getLinkAddress(), null, iface));
1060 addInterfaceToLocalNetwork(iface, routes);
San Mehat873f2142010-01-14 10:25:07 -08001061 }
1062
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001063 @Override
San Mehat873f2142010-01-14 10:25:07 -08001064 public void untetherInterface(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001065 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001066 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001067 mNetdService.tetherInterfaceRemove(iface);
1068 } catch (RemoteException | ServiceSpecificException e) {
1069 throw new IllegalStateException(e);
Erik Kline1f4278a2016-08-16 16:46:33 +09001070 } finally {
1071 removeInterfaceFromLocalNetwork(iface);
Kenny Roota80ce062010-06-01 13:23:53 -07001072 }
San Mehat873f2142010-01-14 10:25:07 -08001073 }
1074
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001075 @Override
1076 public String[] listTetheredInterfaces() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001077 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001078 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +08001079 return mNetdService.tetherInterfaceList();
Luke Huang4a32bf42018-08-21 19:09:45 +08001080 } catch (RemoteException | ServiceSpecificException e) {
1081 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001082 }
San Mehat873f2142010-01-14 10:25:07 -08001083 }
1084
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001085 @Override
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001086 public void setDnsForwarders(Network network, String[] dns) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001087 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001088
Lorenzo Colittib57edc52014-08-22 17:10:50 -07001089 int netId = (network != null) ? network.netId : ConnectivityManager.NETID_UNSET;
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001090
San Mehat873f2142010-01-14 10:25:07 -08001091 try {
Luke Huang4a32bf42018-08-21 19:09:45 +08001092 mNetdService.tetherDnsSet(netId, dns);
1093 } catch (RemoteException | ServiceSpecificException e) {
1094 throw new IllegalStateException(e);
San Mehat873f2142010-01-14 10:25:07 -08001095 }
1096 }
1097
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001098 @Override
1099 public String[] getDnsForwarders() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001100 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001101 try {
Luke Huang1b4f92f2018-12-12 15:59:31 +08001102 return mNetdService.tetherDnsList();
Luke Huang4a32bf42018-08-21 19:09:45 +08001103 } catch (RemoteException | ServiceSpecificException e) {
1104 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001105 }
San Mehat873f2142010-01-14 10:25:07 -08001106 }
1107
jiaguo1da35f72014-01-09 16:39:59 +08001108 private List<InterfaceAddress> excludeLinkLocal(List<InterfaceAddress> addresses) {
Christopher Wiley212b95f2016-08-02 11:38:57 -07001109 ArrayList<InterfaceAddress> filtered = new ArrayList<>(addresses.size());
jiaguo1da35f72014-01-09 16:39:59 +08001110 for (InterfaceAddress ia : addresses) {
1111 if (!ia.getAddress().isLinkLocalAddress())
1112 filtered.add(ia);
1113 }
1114 return filtered;
1115 }
1116
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001117 private void modifyInterfaceForward(boolean add, String fromIface, String toIface) {
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001118 try {
Luke Huang4db488b2018-08-16 15:37:31 +08001119 if (add) {
1120 mNetdService.ipfwdAddInterfaceForward(fromIface, toIface);
1121 } else {
1122 mNetdService.ipfwdRemoveInterfaceForward(fromIface, toIface);
1123 }
1124 } catch (RemoteException | ServiceSpecificException e) {
1125 throw new IllegalStateException(e);
Lorenzo Colitti35e36db2015-02-26 01:25:36 +09001126 }
1127 }
1128
1129 @Override
1130 public void startInterfaceForwarding(String fromIface, String toIface) {
1131 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1132 modifyInterfaceForward(true, fromIface, toIface);
1133 }
1134
1135 @Override
1136 public void stopInterfaceForwarding(String fromIface, String toIface) {
1137 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1138 modifyInterfaceForward(false, fromIface, toIface);
1139 }
1140
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001141 @Override
1142 public void enableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001143 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001144 try {
Luke Huanga31e0732018-10-22 13:23:10 +09001145 mNetdService.tetherAddForward(internalInterface, externalInterface);
1146 } catch (RemoteException | ServiceSpecificException e) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001147 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001148 }
San Mehat873f2142010-01-14 10:25:07 -08001149 }
1150
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001151 @Override
1152 public void disableNat(String internalInterface, String externalInterface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001153 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Kenny Roota80ce062010-06-01 13:23:53 -07001154 try {
Luke Huanga31e0732018-10-22 13:23:10 +09001155 mNetdService.tetherRemoveForward(internalInterface, externalInterface);
1156 } catch (RemoteException | ServiceSpecificException e) {
Jeff Sharkeyba2896e2011-11-30 18:13:54 -08001157 throw new IllegalStateException(e);
Kenny Roota80ce062010-06-01 13:23:53 -07001158 }
San Mehat873f2142010-01-14 10:25:07 -08001159 }
San Mehat72759df2010-01-19 13:50:37 -08001160
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001161 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001162 public void addIdleTimer(String iface, int timeout, final int type) {
Haoyu Bai04124232012-06-28 15:26:19 -07001163 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1164
1165 if (DBG) Slog.d(TAG, "Adding idletimer");
1166
1167 synchronized (mIdleTimerLock) {
1168 IdleTimerParams params = mActiveIdleTimers.get(iface);
1169 if (params != null) {
1170 // the interface already has idletimer, update network count
1171 params.networkCount++;
1172 return;
1173 }
1174
1175 try {
Luke Huanga62d0492018-07-27 20:08:21 +08001176 mNetdService.idletimerAddInterface(iface, timeout, Integer.toString(type));
1177 } catch (RemoteException | ServiceSpecificException e) {
1178 throw new IllegalStateException(e);
Haoyu Bai04124232012-06-28 15:26:19 -07001179 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001180 mActiveIdleTimers.put(iface, new IdleTimerParams(timeout, type));
1181
Dianne Hackborne13c4c02014-02-11 17:18:35 -08001182 // Networks start up.
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001183 if (ConnectivityManager.isNetworkTypeMobile(type)) {
1184 mNetworkActive = false;
1185 }
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +09001186 mDaemonHandler.post(() -> notifyInterfaceClassActivity(type, true,
1187 SystemClock.elapsedRealtimeNanos(), -1, false));
Haoyu Bai04124232012-06-28 15:26:19 -07001188 }
1189 }
1190
1191 @Override
1192 public void removeIdleTimer(String iface) {
1193 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1194
1195 if (DBG) Slog.d(TAG, "Removing idletimer");
1196
1197 synchronized (mIdleTimerLock) {
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001198 final IdleTimerParams params = mActiveIdleTimers.get(iface);
Haoyu Bai04124232012-06-28 15:26:19 -07001199 if (params == null || --(params.networkCount) > 0) {
1200 return;
1201 }
1202
1203 try {
Luke Huanga62d0492018-07-27 20:08:21 +08001204 mNetdService.idletimerRemoveInterface(iface,
1205 params.timeout, Integer.toString(params.type));
1206 } catch (RemoteException | ServiceSpecificException e) {
1207 throw new IllegalStateException(e);
Haoyu Bai04124232012-06-28 15:26:19 -07001208 }
1209 mActiveIdleTimers.remove(iface);
Remi NGUYEN VAN9ebc3fc2019-01-29 19:12:13 +09001210 mDaemonHandler.post(() -> notifyInterfaceClassActivity(params.type, false,
1211 SystemClock.elapsedRealtimeNanos(), -1, false));
Haoyu Bai04124232012-06-28 15:26:19 -07001212 }
1213 }
1214
1215 @Override
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001216 public NetworkStats getNetworkStatsSummaryDev() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001217 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001218 try {
1219 return mStatsFactory.readNetworkStatsSummaryDev();
1220 } catch (IOException e) {
1221 throw new IllegalStateException(e);
1222 }
Jeff Sharkeye8914c32012-05-01 16:26:09 -07001223 }
1224
1225 @Override
1226 public NetworkStats getNetworkStatsSummaryXt() {
1227 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001228 try {
1229 return mStatsFactory.readNetworkStatsSummaryXt();
1230 } catch (IOException e) {
1231 throw new IllegalStateException(e);
1232 }
Jeff Sharkeyae2c1812011-10-04 13:11:40 -07001233 }
1234
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001235 @Override
Jeff Sharkey9a13f362011-04-26 16:25:36 -07001236 public NetworkStats getNetworkStatsDetail() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001237 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001238 try {
Dianne Hackbornd0c5b9a2014-02-21 16:19:05 -08001239 return mStatsFactory.readNetworkStatsDetail(UID_ALL, null, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001240 } catch (IOException e) {
1241 throw new IllegalStateException(e);
1242 }
San Mehat91cac642010-03-31 14:31:36 -07001243 }
1244
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001245 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001246 public void setInterfaceQuota(String iface, long quotaBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001247 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001248
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001249 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001250 if (mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001251 throw new IllegalStateException("iface " + iface + " already has quota");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001252 }
1253
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001254 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001255 // TODO: support quota shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001256 mNetdService.bandwidthSetInterfaceQuota(iface, quotaBytes);
1257
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001258 mActiveQuotas.put(iface, quotaBytes);
Luke Huangc7bea8662018-08-07 16:04:26 +08001259 } catch (RemoteException | ServiceSpecificException e) {
1260 throw new IllegalStateException(e);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001261 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001262
1263 synchronized (mTetheringStatsProviders) {
1264 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1265 try {
1266 provider.setInterfaceQuota(iface, quotaBytes);
1267 } catch (RemoteException e) {
1268 Log.e(TAG, "Problem setting tethering data limit on provider " +
1269 mTetheringStatsProviders.get(provider) + ": " + e);
1270 }
1271 }
1272 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001273 }
1274 }
1275
1276 @Override
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001277 public void removeInterfaceQuota(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001278 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001279
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001280 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001281 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001282 // TODO: eventually consider throwing
1283 return;
1284 }
1285
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001286 mActiveQuotas.remove(iface);
1287 mActiveAlerts.remove(iface);
Jeff Sharkey38ddeaa2011-11-08 13:04:22 -08001288
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001289 try {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001290 // TODO: support quota shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001291 mNetdService.bandwidthRemoveInterfaceQuota(iface);
1292 } catch (RemoteException | ServiceSpecificException e) {
1293 throw new IllegalStateException(e);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001294 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001295
1296 synchronized (mTetheringStatsProviders) {
1297 for (ITetheringStatsProvider provider : mTetheringStatsProviders.keySet()) {
1298 try {
1299 provider.setInterfaceQuota(iface, ITetheringStatsProvider.QUOTA_UNLIMITED);
1300 } catch (RemoteException e) {
1301 Log.e(TAG, "Problem removing tethering data limit on provider " +
1302 mTetheringStatsProviders.get(provider) + ": " + e);
1303 }
1304 }
1305 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001306 }
1307 }
1308
1309 @Override
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001310 public void setInterfaceAlert(String iface, long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001311 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001312
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001313 // quick sanity check
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001314 if (!mActiveQuotas.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001315 throw new IllegalStateException("setting alert requires existing quota on iface");
1316 }
1317
1318 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001319 if (mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001320 throw new IllegalStateException("iface " + iface + " already has alert");
1321 }
1322
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001323 try {
1324 // TODO: support alert shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001325 mNetdService.bandwidthSetInterfaceAlert(iface, alertBytes);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001326 mActiveAlerts.put(iface, alertBytes);
Luke Huangc7bea8662018-08-07 16:04:26 +08001327 } catch (RemoteException | ServiceSpecificException e) {
1328 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001329 }
1330 }
1331 }
1332
1333 @Override
1334 public void removeInterfaceAlert(String iface) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001335 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001336
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001337 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001338 if (!mActiveAlerts.containsKey(iface)) {
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001339 // TODO: eventually consider throwing
1340 return;
1341 }
1342
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001343 try {
1344 // TODO: support alert shared across interfaces
Luke Huangc7bea8662018-08-07 16:04:26 +08001345 mNetdService.bandwidthRemoveInterfaceAlert(iface);
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001346 mActiveAlerts.remove(iface);
Luke Huangc7bea8662018-08-07 16:04:26 +08001347 } catch (RemoteException | ServiceSpecificException e) {
1348 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001349 }
1350 }
1351 }
1352
1353 @Override
1354 public void setGlobalAlert(long alertBytes) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001355 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001356
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001357 try {
Luke Huangc7bea8662018-08-07 16:04:26 +08001358 mNetdService.bandwidthSetGlobalAlert(alertBytes);
1359 } catch (RemoteException | ServiceSpecificException e) {
1360 throw new IllegalStateException(e);
Jeff Sharkey41ff7ec2011-07-25 15:21:22 -07001361 }
1362 }
1363
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001364 private void setUidOnMeteredNetworkList(int uid, boolean blacklist, boolean enable) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001365 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001366
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001367 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001368 boolean oldEnable;
1369 SparseBooleanArray quotaList;
1370 synchronized (mRulesLock) {
1371 quotaList = blacklist ? mUidRejectOnMetered : mUidAllowOnMetered;
1372 oldEnable = quotaList.get(uid, false);
1373 }
Felipe Leme65be3022016-03-22 14:53:13 -07001374 if (oldEnable == enable) {
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001375 // TODO: eventually consider throwing
1376 return;
1377 }
1378
Felipe Leme29e72ea2016-09-08 13:26:55 -07001379 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "inetd bandwidth");
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001380 try {
Luke Huangc7bea8662018-08-07 16:04:26 +08001381 if (blacklist) {
1382 if (enable) {
1383 mNetdService.bandwidthAddNaughtyApp(uid);
1384 } else {
1385 mNetdService.bandwidthRemoveNaughtyApp(uid);
1386 }
1387 } else {
1388 if (enable) {
1389 mNetdService.bandwidthAddNiceApp(uid);
1390 } else {
1391 mNetdService.bandwidthRemoveNiceApp(uid);
1392 }
1393 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001394 synchronized (mRulesLock) {
1395 if (enable) {
1396 quotaList.put(uid, true);
1397 } else {
1398 quotaList.delete(uid);
1399 }
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001400 }
Luke Huangc7bea8662018-08-07 16:04:26 +08001401 } catch (RemoteException | ServiceSpecificException e) {
1402 throw new IllegalStateException(e);
Felipe Leme29e72ea2016-09-08 13:26:55 -07001403 } finally {
1404 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Jeff Sharkeyb3f19ca2011-06-29 23:54:13 -07001405 }
Ashish Sharma50fd36d2011-06-15 19:34:53 -07001406 }
1407 }
1408
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001409 @Override
Felipe Leme65be3022016-03-22 14:53:13 -07001410 public void setUidMeteredNetworkBlacklist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001411 setUidOnMeteredNetworkList(uid, true, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001412 }
1413
1414 @Override
1415 public void setUidMeteredNetworkWhitelist(int uid, boolean enable) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001416 setUidOnMeteredNetworkList(uid, false, enable);
Felipe Leme65be3022016-03-22 14:53:13 -07001417 }
1418
1419 @Override
1420 public boolean setDataSaverModeEnabled(boolean enable) {
Sehee Parka9139bc2017-12-22 13:54:05 +09001421 mContext.enforceCallingOrSelfPermission(NETWORK_SETTINGS, TAG);
1422
Felipe Leme65be3022016-03-22 14:53:13 -07001423 if (DBG) Log.d(TAG, "setDataSaverMode: " + enable);
1424 synchronized (mQuotaLock) {
1425 if (mDataSaverMode == enable) {
1426 Log.w(TAG, "setDataSaverMode(): already " + mDataSaverMode);
1427 return true;
1428 }
Felipe Leme29e72ea2016-09-08 13:26:55 -07001429 Trace.traceBegin(Trace.TRACE_TAG_NETWORK, "bandwidthEnableDataSaver");
Felipe Leme65be3022016-03-22 14:53:13 -07001430 try {
1431 final boolean changed = mNetdService.bandwidthEnableDataSaver(enable);
1432 if (changed) {
1433 mDataSaverMode = enable;
1434 } else {
1435 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command silently failed");
1436 }
1437 return changed;
1438 } catch (RemoteException e) {
1439 Log.w(TAG, "setDataSaverMode(" + enable + "): netd command failed", e);
1440 return false;
Felipe Leme29e72ea2016-09-08 13:26:55 -07001441 } finally {
1442 Trace.traceEnd(Trace.TRACE_TAG_NETWORK);
Felipe Leme65be3022016-03-22 14:53:13 -07001443 }
1444 }
1445 }
1446
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001447 private static UidRangeParcel makeUidRangeParcel(int start, int stop) {
1448 UidRangeParcel range = new UidRangeParcel();
1449 range.start = start;
1450 range.stop = stop;
1451 return range;
1452 }
1453
1454 private static UidRangeParcel[] toStableParcels(UidRange[] ranges) {
1455 UidRangeParcel[] stableRanges = new UidRangeParcel[ranges.length];
1456 for (int i = 0; i < ranges.length; i++) {
1457 stableRanges[i] = makeUidRangeParcel(ranges[i].start, ranges[i].stop);
1458 }
1459 return stableRanges;
1460 }
1461
Felipe Leme65be3022016-03-22 14:53:13 -07001462 @Override
Robin Lee17e61832016-05-09 13:46:28 +01001463 public void setAllowOnlyVpnForUids(boolean add, UidRange[] uidRanges)
1464 throws ServiceSpecificException {
Rubin Xube806662018-01-11 10:59:19 +00001465 mContext.enforceCallingOrSelfPermission(NETWORK_STACK, TAG);
Robin Lee17e61832016-05-09 13:46:28 +01001466 try {
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001467 mNetdService.networkRejectNonSecureVpn(add, toStableParcels(uidRanges));
Robin Lee17e61832016-05-09 13:46:28 +01001468 } catch (ServiceSpecificException e) {
1469 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1470 + ": netd command failed", e);
1471 throw e;
1472 } catch (RemoteException e) {
1473 Log.w(TAG, "setAllowOnlyVpnForUids(" + add + ", " + Arrays.toString(uidRanges) + ")"
1474 + ": netd command failed", e);
1475 throw e.rethrowAsRuntimeException();
1476 }
1477 }
1478
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001479 private void applyUidCleartextNetworkPolicy(int uid, int policy) {
Luke Huang473eb872018-07-26 17:33:14 +08001480 final int policyValue;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001481 switch (policy) {
1482 case StrictMode.NETWORK_POLICY_ACCEPT:
Luke Huang473eb872018-07-26 17:33:14 +08001483 policyValue = INetd.PENALTY_POLICY_ACCEPT;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001484 break;
1485 case StrictMode.NETWORK_POLICY_LOG:
Luke Huang473eb872018-07-26 17:33:14 +08001486 policyValue = INetd.PENALTY_POLICY_LOG;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001487 break;
1488 case StrictMode.NETWORK_POLICY_REJECT:
Luke Huang473eb872018-07-26 17:33:14 +08001489 policyValue = INetd.PENALTY_POLICY_REJECT;
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001490 break;
1491 default:
1492 throw new IllegalArgumentException("Unknown policy " + policy);
1493 }
1494
1495 try {
Luke Huang473eb872018-07-26 17:33:14 +08001496 mNetdService.strictUidCleartextPenalty(uid, policyValue);
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001497 mUidCleartextPolicy.put(uid, policy);
Luke Huang473eb872018-07-26 17:33:14 +08001498 } catch (RemoteException | ServiceSpecificException e) {
1499 throw new IllegalStateException(e);
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001500 }
1501 }
1502
Robin Lee17e61832016-05-09 13:46:28 +01001503 @Override
Jeff Sharkey605eb792014-11-04 13:34:06 -08001504 public void setUidCleartextNetworkPolicy(int uid, int policy) {
1505 if (Binder.getCallingUid() != uid) {
1506 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1507 }
1508
1509 synchronized (mQuotaLock) {
1510 final int oldPolicy = mUidCleartextPolicy.get(uid, StrictMode.NETWORK_POLICY_ACCEPT);
1511 if (oldPolicy == policy) {
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001512 // This also ensures we won't needlessly apply an ACCEPT policy if we've just
1513 // enabled strict and the underlying iptables rules are empty.
Jeff Sharkey605eb792014-11-04 13:34:06 -08001514 return;
1515 }
1516
Luke Huang473eb872018-07-26 17:33:14 +08001517 // TODO: remove this code after removing prepareNativeDaemon()
Jeff Sharkey605eb792014-11-04 13:34:06 -08001518 if (!mStrictEnabled) {
1519 // Module isn't enabled yet; stash the requested policy away to
1520 // apply later once the daemon is connected.
1521 mUidCleartextPolicy.put(uid, policy);
1522 return;
1523 }
1524
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001525 // netd does not keep state on strict mode policies, and cannot replace a non-accept
1526 // policy without deleting it first. Rather than add state to netd, just always send
1527 // it an accept policy when switching between two non-accept policies.
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001528 // TODO: consider keeping state in netd so we can simplify this code.
Lorenzo Colitti8c253ad2017-07-19 00:23:44 +09001529 if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT &&
1530 policy != StrictMode.NETWORK_POLICY_ACCEPT) {
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001531 applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001532 }
Lorenzo Colitti26364f12017-08-20 11:54:57 +09001533
1534 applyUidCleartextNetworkPolicy(uid, policy);
Jeff Sharkey605eb792014-11-04 13:34:06 -08001535 }
1536 }
1537
1538 @Override
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001539 public boolean isBandwidthControlEnabled() {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001540 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang56a03a02018-09-07 12:02:16 +08001541 return true;
Jeff Sharkey63d27a92011-08-03 17:04:22 -07001542 }
1543
1544 @Override
Remi NGUYEN VAN088ff682018-03-06 12:36:54 +09001545 public NetworkStats getNetworkStatsUidDetail(int uid, String[] ifaces) {
Jeff Sharkey4529bb62011-12-14 10:31:54 -08001546 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001547 try {
Remi NGUYEN VAN088ff682018-03-06 12:36:54 +09001548 return mStatsFactory.readNetworkStatsDetail(uid, ifaces, TAG_ALL, null);
Jeff Sharkey9a2c2a62013-01-14 16:48:51 -08001549 } catch (IOException e) {
1550 throw new IllegalStateException(e);
1551 }
Jeff Sharkeyeedcb952011-05-17 14:55:15 -07001552 }
1553
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001554 private class NetdTetheringStatsProvider extends ITetheringStatsProvider.Stub {
1555 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001556 public NetworkStats getTetherStats(int how) {
1557 // We only need to return per-UID stats. Per-device stats are already counted by
1558 // interface counters.
1559 if (how != STATS_PER_UID) {
1560 return new NetworkStats(SystemClock.elapsedRealtime(), 0);
1561 }
1562
Luke Huang13b79e82018-09-26 14:53:42 +08001563 final TetherStatsParcel[] tetherStatsVec;
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001564 try {
Luke Huang13b79e82018-09-26 14:53:42 +08001565 tetherStatsVec = mNetdService.tetherGetStats();
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001566 } catch (RemoteException | ServiceSpecificException e) {
1567 throw new IllegalStateException("problem parsing tethering stats: ", e);
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001568 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001569
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001570 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(),
Luke Huang13b79e82018-09-26 14:53:42 +08001571 tetherStatsVec.length);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001572 final NetworkStats.Entry entry = new NetworkStats.Entry();
1573
Luke Huang13b79e82018-09-26 14:53:42 +08001574 for (TetherStatsParcel tetherStats : tetherStatsVec) {
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001575 try {
Luke Huang13b79e82018-09-26 14:53:42 +08001576 entry.iface = tetherStats.iface;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001577 entry.uid = UID_TETHERING;
1578 entry.set = SET_DEFAULT;
1579 entry.tag = TAG_NONE;
Luke Huang13b79e82018-09-26 14:53:42 +08001580 entry.rxBytes = tetherStats.rxBytes;
1581 entry.rxPackets = tetherStats.rxPackets;
1582 entry.txBytes = tetherStats.txBytes;
1583 entry.txPackets = tetherStats.txPackets;
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001584 stats.combineValues(entry);
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001585 } catch (ArrayIndexOutOfBoundsException e) {
Luke Huang13b79e82018-09-26 14:53:42 +08001586 throw new IllegalStateException("invalid tethering stats " + e);
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001587 }
1588 }
Lorenzo Colitti563dc452017-09-01 17:12:34 +09001589
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001590 return stats;
1591 }
Lorenzo Colitti50b60fc2017-08-11 13:47:49 +09001592
1593 @Override
1594 public void setInterfaceQuota(String iface, long quotaBytes) {
1595 // Do nothing. netd is already informed of quota changes in setInterfaceQuota.
1596 }
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001597 }
1598
1599 @Override
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001600 public NetworkStats getNetworkStatsTethering(int how) {
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001601 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
1602
1603 final NetworkStats stats = new NetworkStats(SystemClock.elapsedRealtime(), 1);
1604 synchronized (mTetheringStatsProviders) {
1605 for (ITetheringStatsProvider provider: mTetheringStatsProviders.keySet()) {
1606 try {
Lorenzo Colittif1912ca2017-08-17 19:23:08 +09001607 stats.combineAllValues(provider.getTetherStats(how));
Lorenzo Colitti07f13042017-07-10 19:06:57 +09001608 } catch (RemoteException e) {
1609 Log.e(TAG, "Problem reading tethering stats from " +
1610 mTetheringStatsProviders.get(provider) + ": " + e);
1611 }
1612 }
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001613 }
Jeff Sharkeye4984be2013-09-10 21:03:27 -07001614 return stats;
Jeff Sharkeycdd02c5d2011-09-16 01:52:49 -07001615 }
1616
Jeff Sharkeyaf75c332011-11-18 12:41:12 -08001617 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001618 public void addVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001619 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang8a462ec2018-08-24 20:33:16 +08001620
1621 try {
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001622 mNetdService.networkAddUidRanges(netId, toStableParcels(ranges));
Luke Huang8a462ec2018-08-24 20:33:16 +08001623 } catch (RemoteException | ServiceSpecificException e) {
1624 throw new IllegalStateException(e);
Chad Brubaker3277620a2013-06-12 13:37:30 -07001625 }
1626 }
1627
1628 @Override
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04001629 public void removeVpnUidRanges(int netId, UidRange[] ranges) {
Chad Brubaker3277620a2013-06-12 13:37:30 -07001630 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Luke Huang8a462ec2018-08-24 20:33:16 +08001631 try {
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001632 mNetdService.networkRemoveUidRanges(netId, toStableParcels(ranges));
Luke Huang8a462ec2018-08-24 20:33:16 +08001633 } catch (RemoteException | ServiceSpecificException e) {
1634 throw new IllegalStateException(e);
Chad Brubakercca54c42013-06-27 17:41:38 -07001635 }
1636 }
1637
1638 @Override
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001639 public void setFirewallEnabled(boolean enabled) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001640 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001641 try {
Luke Huanga241db92018-07-31 20:15:24 +08001642 mNetdService.firewallSetFirewallType(
1643 enabled ? INetd.FIREWALL_WHITELIST : INetd.FIREWALL_BLACKLIST);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001644 mFirewallEnabled = enabled;
Luke Huanga241db92018-07-31 20:15:24 +08001645 } catch (RemoteException | ServiceSpecificException e) {
1646 throw new IllegalStateException(e);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001647 }
1648 }
1649
1650 @Override
1651 public boolean isFirewallEnabled() {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001652 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001653 return mFirewallEnabled;
1654 }
1655
1656 @Override
Jeff Sharkey2c092982012-08-24 11:44:40 -07001657 public void setFirewallInterfaceRule(String iface, boolean allow) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001658 enforceSystemUid();
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001659 Preconditions.checkState(mFirewallEnabled);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001660 try {
Luke Huanga241db92018-07-31 20:15:24 +08001661 mNetdService.firewallSetInterfaceRule(iface,
1662 allow ? INetd.FIREWALL_RULE_ALLOW : INetd.FIREWALL_RULE_DENY);
1663 } catch (RemoteException | ServiceSpecificException e) {
1664 throw new IllegalStateException(e);
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001665 }
1666 }
1667
Lorenzo Colitti3fef7232016-04-29 18:00:03 +09001668 private void closeSocketsForFirewallChainLocked(int chain, String chainName) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001669 // UID ranges to close sockets on.
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001670 UidRangeParcel[] ranges;
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001671 // UID ranges whose sockets we won't touch.
1672 int[] exemptUids;
1673
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001674 int numUids = 0;
Luke Huanga241db92018-07-31 20:15:24 +08001675 if (DBG) Slog.d(TAG, "Closing sockets after enabling chain " + chainName);
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001676 if (getFirewallType(chain) == FIREWALL_WHITELIST) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001677 // Close all sockets on all non-system UIDs...
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001678 ranges = new UidRangeParcel[] {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001679 // TODO: is there a better way of finding all existing users? If so, we could
1680 // specify their ranges here.
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001681 makeUidRangeParcel(Process.FIRST_APPLICATION_UID, Integer.MAX_VALUE),
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001682 };
1683 // ... except for the UIDs that have allow rules.
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001684 synchronized (mRulesLock) {
1685 final SparseIntArray rules = getUidFirewallRulesLR(chain);
1686 exemptUids = new int[rules.size()];
1687 for (int i = 0; i < exemptUids.length; i++) {
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001688 if (rules.valueAt(i) == FIREWALL_RULE_ALLOW) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001689 exemptUids[numUids] = rules.keyAt(i);
1690 numUids++;
1691 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001692 }
1693 }
1694 // Normally, whitelist chains only contain deny rules, so numUids == exemptUids.length.
1695 // But the code does not guarantee this in any way, and at least in one case - if we add
1696 // a UID rule to the firewall, and then disable the firewall - the chains can contain
1697 // the wrong type of rule. In this case, don't close connections that we shouldn't.
1698 //
1699 // TODO: tighten up this code by ensuring we never set the wrong type of rule, and
1700 // fix setFirewallEnabled to grab mQuotaLock and clear rules.
1701 if (numUids != exemptUids.length) {
1702 exemptUids = Arrays.copyOf(exemptUids, numUids);
1703 }
1704 } else {
1705 // Close sockets for every UID that has a deny rule...
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001706 synchronized (mRulesLock) {
1707 final SparseIntArray rules = getUidFirewallRulesLR(chain);
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001708 ranges = new UidRangeParcel[rules.size()];
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001709 for (int i = 0; i < ranges.length; i++) {
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001710 if (rules.valueAt(i) == FIREWALL_RULE_DENY) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001711 int uid = rules.keyAt(i);
Lorenzo Colitticc7f1db2019-03-18 23:50:34 +09001712 ranges[numUids] = makeUidRangeParcel(uid, uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001713 numUids++;
1714 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001715 }
1716 }
1717 // As above; usually numUids == ranges.length, but not always.
1718 if (numUids != ranges.length) {
1719 ranges = Arrays.copyOf(ranges, numUids);
1720 }
1721 // ... with no exceptions.
1722 exemptUids = new int[0];
1723 }
1724
1725 try {
1726 mNetdService.socketDestroy(ranges, exemptUids);
1727 } catch(RemoteException | ServiceSpecificException e) {
1728 Slog.e(TAG, "Error closing sockets after enabling chain " + chainName + ": " + e);
1729 }
1730 }
1731
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001732 @Override
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001733 public void setFirewallChainEnabled(int chain, boolean enable) {
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001734 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001735 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001736 synchronized (mRulesLock) {
1737 if (getFirewallChainState(chain) == enable) {
1738 // All is the same, nothing to do. This relies on the fact that netd has child
1739 // chains default detached.
1740 return;
1741 }
1742 setFirewallChainState(chain, enable);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001743 }
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001744
Luke Huang615e1022018-10-25 11:54:05 +09001745 final String chainName = getFirewallChainName(chain);
Luke Huanga241db92018-07-31 20:15:24 +08001746 if (chain == FIREWALL_CHAIN_NONE) {
Luke Huang615e1022018-10-25 11:54:05 +09001747 throw new IllegalArgumentException("Bad child chain: " + chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001748 }
1749
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001750 try {
Luke Huanga241db92018-07-31 20:15:24 +08001751 mNetdService.firewallEnableChildChain(chain, enable);
1752 } catch (RemoteException | ServiceSpecificException e) {
1753 throw new IllegalStateException(e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001754 }
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001755
1756 // Close any sockets that were opened by the affected UIDs. This has to be done after
1757 // disabling network connectivity, in case they react to the socket close by reopening
1758 // the connection and race with the iptables commands that enable the firewall. All
1759 // whitelist and blacklist chains allow RSTs through.
1760 if (enable) {
Luke Huang615e1022018-10-25 11:54:05 +09001761 closeSocketsForFirewallChainLocked(chain, chainName);
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09001762 }
Amith Yamasani15e472352015-04-24 19:06:07 -07001763 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001764 }
1765
Luke Huanga241db92018-07-31 20:15:24 +08001766 private String getFirewallChainName(int chain) {
1767 switch (chain) {
1768 case FIREWALL_CHAIN_STANDBY:
1769 return FIREWALL_CHAIN_NAME_STANDBY;
1770 case FIREWALL_CHAIN_DOZABLE:
1771 return FIREWALL_CHAIN_NAME_DOZABLE;
1772 case FIREWALL_CHAIN_POWERSAVE:
1773 return FIREWALL_CHAIN_NAME_POWERSAVE;
1774 default:
1775 throw new IllegalArgumentException("Bad child chain: " + chain);
1776 }
1777 }
1778
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001779 private int getFirewallType(int chain) {
1780 switch (chain) {
1781 case FIREWALL_CHAIN_STANDBY:
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001782 return FIREWALL_BLACKLIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001783 case FIREWALL_CHAIN_DOZABLE:
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001784 return FIREWALL_WHITELIST;
Felipe Leme011b98f2016-02-10 17:28:31 -08001785 case FIREWALL_CHAIN_POWERSAVE:
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001786 return FIREWALL_WHITELIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001787 default:
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001788 return isFirewallEnabled() ? FIREWALL_WHITELIST : FIREWALL_BLACKLIST;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001789 }
1790 }
1791
1792 @Override
1793 public void setFirewallUidRules(int chain, int[] uids, int[] rules) {
1794 enforceSystemUid();
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001795 synchronized (mQuotaLock) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001796 synchronized (mRulesLock) {
1797 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
1798 SparseIntArray newRules = new SparseIntArray();
1799 // apply new set of rules
1800 for (int index = uids.length - 1; index >= 0; --index) {
1801 int uid = uids[index];
1802 int rule = rules[index];
1803 updateFirewallUidRuleLocked(chain, uid, rule);
1804 newRules.put(uid, rule);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001805 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001806 // collect the rules to remove.
1807 SparseIntArray rulesToRemove = new SparseIntArray();
1808 for (int index = uidFirewallRules.size() - 1; index >= 0; --index) {
1809 int uid = uidFirewallRules.keyAt(index);
1810 if (newRules.indexOfKey(uid) < 0) {
1811 rulesToRemove.put(uid, FIREWALL_RULE_DEFAULT);
1812 }
1813 }
1814 // remove dead rules
1815 for (int index = rulesToRemove.size() - 1; index >= 0; --index) {
1816 int uid = rulesToRemove.keyAt(index);
1817 updateFirewallUidRuleLocked(chain, uid, FIREWALL_RULE_DEFAULT);
1818 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001819 }
1820 try {
1821 switch (chain) {
1822 case FIREWALL_CHAIN_DOZABLE:
1823 mNetdService.firewallReplaceUidChain("fw_dozable", true, uids);
1824 break;
1825 case FIREWALL_CHAIN_STANDBY:
1826 mNetdService.firewallReplaceUidChain("fw_standby", false, uids);
1827 break;
1828 case FIREWALL_CHAIN_POWERSAVE:
1829 mNetdService.firewallReplaceUidChain("fw_powersave", true, uids);
1830 break;
1831 case FIREWALL_CHAIN_NONE:
1832 default:
1833 Slog.d(TAG, "setFirewallUidRules() called on invalid chain: " + chain);
1834 }
1835 } catch (RemoteException e) {
1836 Slog.w(TAG, "Error flushing firewall chain " + chain, e);
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001837 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001838 }
1839 }
1840
1841 @Override
1842 public void setFirewallUidRule(int chain, int uid, int rule) {
1843 enforceSystemUid();
Felipe Lemea701cad2016-05-12 09:58:14 -07001844 synchronized (mQuotaLock) {
1845 setFirewallUidRuleLocked(chain, uid, rule);
1846 }
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001847 }
1848
Felipe Lemea701cad2016-05-12 09:58:14 -07001849 private void setFirewallUidRuleLocked(int chain, int uid, int rule) {
1850 if (updateFirewallUidRuleLocked(chain, uid, rule)) {
Luke Huanga241db92018-07-31 20:15:24 +08001851 final int ruleType = getFirewallRuleType(chain, rule);
Amith Yamasani15e472352015-04-24 19:06:07 -07001852 try {
Luke Huanga241db92018-07-31 20:15:24 +08001853 mNetdService.firewallSetUidRule(chain, uid, ruleType);
1854 } catch (RemoteException | ServiceSpecificException e) {
1855 throw new IllegalStateException(e);
Amith Yamasani15e472352015-04-24 19:06:07 -07001856 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001857 }
1858 }
1859
Felipe Lemea701cad2016-05-12 09:58:14 -07001860 // TODO: now that netd supports batching, NMS should not keep these data structures anymore...
1861 private boolean updateFirewallUidRuleLocked(int chain, int uid, int rule) {
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001862 synchronized (mRulesLock) {
1863 SparseIntArray uidFirewallRules = getUidFirewallRulesLR(chain);
Felipe Lemea701cad2016-05-12 09:58:14 -07001864
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001865 final int oldUidFirewallRule = uidFirewallRules.get(uid, FIREWALL_RULE_DEFAULT);
1866 if (DBG) {
1867 Slog.d(TAG, "oldRule = " + oldUidFirewallRule
1868 + ", newRule=" + rule + " for uid=" + uid + " on chain " + chain);
1869 }
1870 if (oldUidFirewallRule == rule) {
1871 if (DBG) Slog.d(TAG, "!!!!! Skipping change");
1872 // TODO: eventually consider throwing
1873 return false;
1874 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001875
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001876 String ruleName = getFirewallRuleName(chain, rule);
1877 String oldRuleName = getFirewallRuleName(chain, oldUidFirewallRule);
Felipe Lemea701cad2016-05-12 09:58:14 -07001878
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001879 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
1880 uidFirewallRules.delete(uid);
1881 } else {
1882 uidFirewallRules.put(uid, rule);
1883 }
1884 return !ruleName.equals(oldRuleName);
Felipe Lemea701cad2016-05-12 09:58:14 -07001885 }
Felipe Lemea701cad2016-05-12 09:58:14 -07001886 }
1887
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001888 private @NonNull String getFirewallRuleName(int chain, int rule) {
1889 String ruleName;
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001890 if (getFirewallType(chain) == FIREWALL_WHITELIST) {
1891 if (rule == FIREWALL_RULE_ALLOW) {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001892 ruleName = "allow";
1893 } else {
1894 ruleName = "deny";
1895 }
1896 } else { // Blacklist mode
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001897 if (rule == FIREWALL_RULE_DENY) {
Xiaohui Chen8dca36d2015-06-19 12:44:59 -07001898 ruleName = "deny";
1899 } else {
1900 ruleName = "allow";
1901 }
1902 }
1903 return ruleName;
1904 }
1905
Andreas Gampeaae5aa32018-07-20 12:55:38 -07001906 @GuardedBy("mRulesLock")
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001907 private @NonNull SparseIntArray getUidFirewallRulesLR(int chain) {
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001908 switch (chain) {
1909 case FIREWALL_CHAIN_STANDBY:
1910 return mUidFirewallStandbyRules;
1911 case FIREWALL_CHAIN_DOZABLE:
1912 return mUidFirewallDozableRules;
Felipe Leme011b98f2016-02-10 17:28:31 -08001913 case FIREWALL_CHAIN_POWERSAVE:
1914 return mUidFirewallPowerSaveRules;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001915 case FIREWALL_CHAIN_NONE:
1916 return mUidFirewallRules;
1917 default:
1918 throw new IllegalArgumentException("Unknown chain:" + chain);
1919 }
1920 }
1921
Luke Huanga241db92018-07-31 20:15:24 +08001922 private int getFirewallRuleType(int chain, int rule) {
Luke Huang615e1022018-10-25 11:54:05 +09001923 if (rule == NetworkPolicyManager.FIREWALL_RULE_DEFAULT) {
Remi NGUYEN VANf9a8c2e2019-02-13 18:28:35 +09001924 return getFirewallType(chain) == FIREWALL_WHITELIST
Luke Huang615e1022018-10-25 11:54:05 +09001925 ? INetd.FIREWALL_RULE_DENY : INetd.FIREWALL_RULE_ALLOW;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001926 }
Luke Huang615e1022018-10-25 11:54:05 +09001927 return rule;
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001928 }
1929
Jeff Sharkeyf56e2432012-09-06 17:54:29 -07001930 private static void enforceSystemUid() {
1931 final int uid = Binder.getCallingUid();
1932 if (uid != Process.SYSTEM_UID) {
1933 throw new SecurityException("Only available to AID_SYSTEM");
1934 }
1935 }
1936
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001937 @Override
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001938 public void registerNetworkActivityListener(INetworkActivityListener listener) {
1939 mNetworkActivityListeners.register(listener);
1940 }
1941
1942 @Override
1943 public void unregisterNetworkActivityListener(INetworkActivityListener listener) {
1944 mNetworkActivityListeners.unregister(listener);
1945 }
1946
1947 @Override
1948 public boolean isNetworkActive() {
1949 synchronized (mNetworkActivityListeners) {
1950 return mNetworkActive || mActiveIdleTimers.isEmpty();
1951 }
1952 }
1953
1954 private void reportNetworkActive() {
1955 final int length = mNetworkActivityListeners.beginBroadcast();
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001956 try {
1957 for (int i = 0; i < length; i++) {
1958 try {
1959 mNetworkActivityListeners.getBroadcastItem(i).onNetworkActive();
Felipe Leme03e689d2016-03-02 16:17:38 -08001960 } catch (RemoteException | RuntimeException e) {
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001961 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001962 }
Robert Greenwalt2c9f5472014-04-21 14:50:28 -07001963 } finally {
1964 mNetworkActivityListeners.finishBroadcast();
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001965 }
Dianne Hackborn77b987f2014-02-26 16:20:52 -08001966 }
1967
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001968 @Override
1969 protected void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
Jeff Sharkeyfe9a53b2017-03-31 14:08:23 -06001970 if (!DumpUtils.checkDumpPermission(mContext, TAG, pw)) return;
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001971
Dianne Hackborn2ffa11e2014-04-21 15:56:18 -07001972 pw.print("mMobileActivityFromRadio="); pw.print(mMobileActivityFromRadio);
1973 pw.print(" mLastPowerStateFromRadio="); pw.println(mLastPowerStateFromRadio);
1974 pw.print("mNetworkActive="); pw.println(mNetworkActive);
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001975
1976 synchronized (mQuotaLock) {
Jeff Sharkeyb24a7852012-05-01 15:19:37 -07001977 pw.print("Active quota ifaces: "); pw.println(mActiveQuotas.toString());
1978 pw.print("Active alert ifaces: "); pw.println(mActiveAlerts.toString());
Felipe Leme65be3022016-03-22 14:53:13 -07001979 pw.print("Data saver mode: "); pw.println(mDataSaverMode);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001980 synchronized (mRulesLock) {
1981 dumpUidRuleOnQuotaLocked(pw, "blacklist", mUidRejectOnMetered);
1982 dumpUidRuleOnQuotaLocked(pw, "whitelist", mUidAllowOnMetered);
1983 }
Jeff Sharkey47eb1022011-08-25 17:48:52 -07001984 }
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07001985
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001986 synchronized (mRulesLock) {
Felipe Leme011b98f2016-02-10 17:28:31 -08001987 dumpUidFirewallRule(pw, "", mUidFirewallRules);
Amith Yamasani15e472352015-04-24 19:06:07 -07001988
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001989 pw.print("UID firewall standby chain enabled: "); pw.println(
1990 getFirewallChainState(FIREWALL_CHAIN_STANDBY));
Felipe Leme011b98f2016-02-10 17:28:31 -08001991 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_STANDBY, mUidFirewallStandbyRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07001992
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001993 pw.print("UID firewall dozable chain enabled: "); pw.println(
1994 getFirewallChainState(FIREWALL_CHAIN_DOZABLE));
Felipe Leme011b98f2016-02-10 17:28:31 -08001995 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_DOZABLE, mUidFirewallDozableRules);
Felipe Leme011b98f2016-02-10 17:28:31 -08001996
Sudheer Shanka62f5c172017-03-17 16:25:55 -07001997 pw.println("UID firewall powersave chain enabled: " +
1998 getFirewallChainState(FIREWALL_CHAIN_POWERSAVE));
Felipe Leme011b98f2016-02-10 17:28:31 -08001999 dumpUidFirewallRule(pw, FIREWALL_CHAIN_NAME_POWERSAVE, mUidFirewallPowerSaveRules);
Xiaohui Chenb41c9f72015-06-17 15:55:37 -07002000 }
2001
Dianne Hackborn77b987f2014-02-26 16:20:52 -08002002 synchronized (mIdleTimerLock) {
2003 pw.println("Idle timers:");
2004 for (HashMap.Entry<String, IdleTimerParams> ent : mActiveIdleTimers.entrySet()) {
2005 pw.print(" "); pw.print(ent.getKey()); pw.println(":");
2006 IdleTimerParams params = ent.getValue();
2007 pw.print(" timeout="); pw.print(params.timeout);
2008 pw.print(" type="); pw.print(params.type);
2009 pw.print(" networkCount="); pw.println(params.networkCount);
2010 }
2011 }
2012
Jeff Sharkeyc268f0b2012-08-24 10:25:31 -07002013 pw.print("Firewall enabled: "); pw.println(mFirewallEnabled);
Felipe Leme65be3022016-03-22 14:53:13 -07002014 pw.print("Netd service status: " );
2015 if (mNetdService == null) {
2016 pw.println("disconnected");
2017 } else {
2018 try {
2019 final boolean alive = mNetdService.isAlive();
2020 pw.println(alive ? "alive": "dead");
2021 } catch (RemoteException e) {
2022 pw.println("unreachable");
2023 }
2024 }
2025 }
2026
2027 private void dumpUidRuleOnQuotaLocked(PrintWriter pw, String name, SparseBooleanArray list) {
2028 pw.print("UID bandwith control ");
2029 pw.print(name);
2030 pw.print(" rule: [");
2031 final int size = list.size();
2032 for (int i = 0; i < size; i++) {
2033 pw.print(list.keyAt(i));
2034 if (i < size - 1) pw.print(",");
2035 }
2036 pw.println("]");
Jeff Sharkey47eb1022011-08-25 17:48:52 -07002037 }
Robert Greenwalt9ba9c582014-03-19 17:56:12 -07002038
Felipe Leme011b98f2016-02-10 17:28:31 -08002039 private void dumpUidFirewallRule(PrintWriter pw, String name, SparseIntArray rules) {
Lorenzo Colitti4cb42402016-04-24 12:52:00 +09002040 pw.print("UID firewall ");
Felipe Leme011b98f2016-02-10 17:28:31 -08002041 pw.print(name);
2042 pw.print(" rule: [");
2043 final int size = rules.size();
2044 for (int i = 0; i < size; i++) {
2045 pw.print(rules.keyAt(i));
2046 pw.print(":");
2047 pw.print(rules.valueAt(i));
2048 if (i < size - 1) pw.print(",");
2049 }
2050 pw.println("]");
2051 }
2052
Robert Greenwalt568891d2014-04-04 13:38:00 -07002053 @Override
Paul Jensen992f2522014-04-28 10:33:11 -04002054 public void addInterfaceToNetwork(String iface, int netId) {
Luke Huang8a462ec2018-08-24 20:33:16 +08002055 modifyInterfaceInNetwork(MODIFY_OPERATION_ADD, netId, iface);
Paul Jensen992f2522014-04-28 10:33:11 -04002056 }
2057
2058 @Override
2059 public void removeInterfaceFromNetwork(String iface, int netId) {
Luke Huang8a462ec2018-08-24 20:33:16 +08002060 modifyInterfaceInNetwork(MODIFY_OPERATION_REMOVE, netId, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002061 }
Paul Jensen992f2522014-04-28 10:33:11 -04002062
Luke Huang8a462ec2018-08-24 20:33:16 +08002063 private void modifyInterfaceInNetwork(boolean add, int netId, String iface) {
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002064 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
Paul Jensen992f2522014-04-28 10:33:11 -04002065 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002066 if (add) {
2067 mNetdService.networkAddInterface(netId, iface);
2068 } else {
2069 mNetdService.networkRemoveInterface(netId, iface);
2070 }
2071 } catch (RemoteException | ServiceSpecificException e) {
2072 throw new IllegalStateException(e);
Paul Jensen992f2522014-04-28 10:33:11 -04002073 }
2074 }
2075
2076 @Override
Robert Greenwalt913c8952014-04-07 17:36:35 -07002077 public void addLegacyRouteForNetId(int netId, RouteInfo routeInfo, int uid) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002078 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2079
Sreeram Ramachandrancc91c7b2014-06-03 18:41:43 -07002080 final LinkAddress la = routeInfo.getDestinationLinkAddress();
Luke Huang8a462ec2018-08-24 20:33:16 +08002081 final String ifName = routeInfo.getInterface();
2082 final String dst = la.toString();
2083 final String nextHop;
Robert Greenwalt568891d2014-04-04 13:38:00 -07002084
Luke Huang8a462ec2018-08-24 20:33:16 +08002085 if (routeInfo.hasGateway()) {
2086 nextHop = routeInfo.getGateway().getHostAddress();
2087 } else {
2088 nextHop = "";
2089 }
Robert Greenwalt568891d2014-04-04 13:38:00 -07002090 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002091 mNetdService.networkAddLegacyRoute(netId, ifName, dst, nextHop, uid);
2092 } catch (RemoteException | ServiceSpecificException e) {
2093 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002094 }
2095 }
2096
2097 @Override
Sreeram Ramachandranf047f2a2014-04-15 16:04:26 -07002098 public void setDefaultNetId(int netId) {
Robert Greenwalt568891d2014-04-04 13:38:00 -07002099 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2100
2101 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002102 mNetdService.networkSetDefault(netId);
2103 } catch (RemoteException | ServiceSpecificException e) {
2104 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002105 }
2106 }
2107
2108 @Override
2109 public void clearDefaultNetId() {
2110 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2111
2112 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002113 mNetdService.networkClearDefault();
2114 } catch (RemoteException | ServiceSpecificException e) {
2115 throw new IllegalStateException(e);
Robert Greenwalt568891d2014-04-04 13:38:00 -07002116 }
2117 }
2118
2119 @Override
Luke Huang8a462ec2018-08-24 20:33:16 +08002120 public void setNetworkPermission(int netId, int permission) {
Paul Jensen487ffe72015-07-24 15:57:11 -04002121 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2122
2123 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002124 mNetdService.networkSetPermissionForNetwork(netId, permission);
2125 } catch (RemoteException | ServiceSpecificException e) {
2126 throw new IllegalStateException(e);
Paul Jensen487ffe72015-07-24 15:57:11 -04002127 }
2128 }
2129
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002130 @Override
2131 public void allowProtect(int uid) {
2132 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2133
2134 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002135 mNetdService.networkSetProtectAllow(uid);
2136 } catch (RemoteException | ServiceSpecificException e) {
2137 throw new IllegalStateException(e);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002138 }
2139 }
2140
2141 @Override
2142 public void denyProtect(int uid) {
2143 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2144
2145 try {
Luke Huang8a462ec2018-08-24 20:33:16 +08002146 mNetdService.networkSetProtectDeny(uid);
2147 } catch (RemoteException | ServiceSpecificException e) {
2148 throw new IllegalStateException(e);
Paul Jensen6bc2c2c2014-05-07 15:27:40 -04002149 }
2150 }
2151
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002152 @Override
2153 public void addInterfaceToLocalNetwork(String iface, List<RouteInfo> routes) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002154 modifyInterfaceInNetwork(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002155
2156 for (RouteInfo route : routes) {
2157 if (!route.isDefaultRoute()) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002158 modifyRoute(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID, route);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002159 }
2160 }
Jimmy Chen086779d2019-03-07 14:15:36 +08002161
2162 // IPv6 link local should be activated always.
2163 modifyRoute(MODIFY_OPERATION_ADD, INetd.LOCAL_NET_ID,
2164 new RouteInfo(new IpPrefix("fe80::/64"), null, iface));
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002165 }
2166
2167 @Override
2168 public void removeInterfaceFromLocalNetwork(String iface) {
Luke Huang706d7ab2018-10-16 15:42:15 +08002169 modifyInterfaceInNetwork(MODIFY_OPERATION_REMOVE, INetd.LOCAL_NET_ID, iface);
Sreeram Ramachandrana77760d2014-07-17 17:09:07 -07002170 }
Erik Kline6599ee82016-07-17 21:28:39 +09002171
2172 @Override
2173 public int removeRoutesFromLocalNetwork(List<RouteInfo> routes) {
2174 int failures = 0;
2175
2176 for (RouteInfo route : routes) {
2177 try {
Luke Huang706d7ab2018-10-16 15:42:15 +08002178 modifyRoute(MODIFY_OPERATION_REMOVE, INetd.LOCAL_NET_ID, route);
Erik Kline6599ee82016-07-17 21:28:39 +09002179 } catch (IllegalStateException e) {
2180 failures++;
2181 }
2182 }
2183
2184 return failures;
2185 }
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002186
Sudheer Shankab8f23162017-08-04 13:30:10 -07002187 @Override
2188 public boolean isNetworkRestricted(int uid) {
2189 mContext.enforceCallingOrSelfPermission(CONNECTIVITY_INTERNAL, TAG);
2190 return isNetworkRestrictedInternal(uid);
2191 }
2192
2193 private boolean isNetworkRestrictedInternal(int uid) {
2194 synchronized (mRulesLock) {
2195 if (getFirewallChainState(FIREWALL_CHAIN_STANDBY)
2196 && mUidFirewallStandbyRules.get(uid) == FIREWALL_RULE_DENY) {
2197 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of app standby mode");
2198 return true;
2199 }
2200 if (getFirewallChainState(FIREWALL_CHAIN_DOZABLE)
2201 && mUidFirewallDozableRules.get(uid) != FIREWALL_RULE_ALLOW) {
2202 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of device idle mode");
2203 return true;
2204 }
2205 if (getFirewallChainState(FIREWALL_CHAIN_POWERSAVE)
2206 && mUidFirewallPowerSaveRules.get(uid) != FIREWALL_RULE_ALLOW) {
2207 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of power saver mode");
2208 return true;
2209 }
2210 if (mUidRejectOnMetered.get(uid)) {
2211 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of no metered data"
2212 + " in the background");
2213 return true;
2214 }
2215 if (mDataSaverMode && !mUidAllowOnMetered.get(uid)) {
2216 if (DBG) Slog.d(TAG, "Uid " + uid + " restricted because of data saver mode");
2217 return true;
2218 }
2219 return false;
2220 }
2221 }
2222
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002223 private void setFirewallChainState(int chain, boolean state) {
2224 synchronized (mRulesLock) {
2225 mFirewallChainStates.put(chain, state);
2226 }
2227 }
2228
2229 private boolean getFirewallChainState(int chain) {
2230 synchronized (mRulesLock) {
2231 return mFirewallChainStates.get(chain);
2232 }
2233 }
2234
2235 @VisibleForTesting
2236 class LocalService extends NetworkManagementInternal {
2237 @Override
2238 public boolean isNetworkRestrictedForUid(int uid) {
Sudheer Shankab8f23162017-08-04 13:30:10 -07002239 return isNetworkRestrictedInternal(uid);
Sudheer Shanka62f5c172017-03-17 16:25:55 -07002240 }
2241 }
2242
2243 @VisibleForTesting
2244 Injector getInjector() {
2245 return new Injector();
2246 }
2247
2248 @VisibleForTesting
2249 class Injector {
2250 void setDataSaverMode(boolean dataSaverMode) {
2251 mDataSaverMode = dataSaverMode;
2252 }
2253
2254 void setFirewallChainState(int chain, boolean state) {
2255 NetworkManagementService.this.setFirewallChainState(chain, state);
2256 }
2257
2258 void setFirewallRule(int chain, int uid, int rule) {
2259 synchronized (mRulesLock) {
2260 getUidFirewallRulesLR(chain).put(uid, rule);
2261 }
2262 }
2263
2264 void setUidOnMeteredNetworkList(boolean blacklist, int uid, boolean enable) {
2265 synchronized (mRulesLock) {
2266 if (blacklist) {
2267 mUidRejectOnMetered.put(uid, enable);
2268 } else {
2269 mUidAllowOnMetered.put(uid, enable);
2270 }
2271 }
2272 }
2273
2274 void reset() {
2275 synchronized (mRulesLock) {
2276 setDataSaverMode(false);
2277 final int[] chains = {
2278 FIREWALL_CHAIN_DOZABLE,
2279 FIREWALL_CHAIN_STANDBY,
2280 FIREWALL_CHAIN_POWERSAVE
2281 };
2282 for (int chain : chains) {
2283 setFirewallChainState(chain, false);
2284 getUidFirewallRulesLR(chain).clear();
2285 }
2286 mUidAllowOnMetered.clear();
2287 mUidRejectOnMetered.clear();
2288 }
2289 }
2290 }
San Mehat873f2142010-01-14 10:25:07 -08002291}