tree 826b3fd29a09d5df2cdfe955bd5e612c398d8389
parent 310966665c47886033c8267ddcbed2bf164daf6d
author Peter Qiu <zqiu@chromium.org> 1424804357 -0800
committer ChromeOS Commit Bot <chromeos-commit-bot@chromium.org> 1424916213 +0000

apmanager: add DHCP firewall rule per interface basis

With the recent update in permission_broker to allow firewall rules per
interface basis, update apmanager to dynamically request/release DHCP
port access when an AP service is started/terminated. And only request
the port access for the interface that AP service is running on.

BUG=chromium:450408
TEST=USE="asan clang" FEATURES=test emerge-$BOARD apmanager
     Run security_Firewall test
Manual Test:
1. Use "iptables -S" command to verify no firewall rule is added
   for port 67 when AP service is not started.
2. Start an AP service, verify firewall rule for port 67 is added
   for the wifi interface (wlan0 for wolf device) and client can
   connect to it with IP connectivity.
3. Stop the AP service, verify firewall rule for port 67 is deleted.
CQ-DEPEND=CL:252931

Change-Id: If7a5150d224ff1a5085b5e8032a162e8ca07c545
Reviewed-on: https://chromium-review.googlesource.com/252941
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Tested-by: Zeping Qiu <zqiu@chromium.org>
Commit-Queue: Zeping Qiu <zqiu@chromium.org>
