Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #ifndef NETD_SERVER_VIRTUAL_NETWORK_H |
| 18 | #define NETD_SERVER_VIRTUAL_NETWORK_H |
| 19 | |
| 20 | #include "Network.h" |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 21 | #include "UidRanges.h" |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 22 | |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame^] | 23 | // A VirtualNetwork may be "secure" or not. |
| 24 | // |
| 25 | // A secure VPN is the usual type of VPN that grabs the default route (and thus all user traffic). |
| 26 | // Only a few privileged UIDs may skip the VPN and go directly to the underlying physical network. |
| 27 | // |
| 28 | // A non-secure VPN ("bypassable" VPN) also grabs all user traffic by default. But all apps are |
| 29 | // permitted to skip it and pick any other network for their connections. |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 30 | class VirtualNetwork : public Network { |
| 31 | public: |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame^] | 32 | VirtualNetwork(unsigned netId, bool hasDns, bool secure); |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 33 | virtual ~VirtualNetwork(); |
| 34 | |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 35 | bool getHasDns() const; |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame^] | 36 | bool isSecure() const; |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 37 | bool appliesToUser(uid_t uid) const; |
| 38 | |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 39 | int addUsers(const UidRanges& uidRanges) WARN_UNUSED_RESULT; |
| 40 | int removeUsers(const UidRanges& uidRanges) WARN_UNUSED_RESULT; |
| 41 | |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 42 | private: |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 43 | Type getType() const override; |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 44 | int addInterface(const std::string& interface) override WARN_UNUSED_RESULT; |
| 45 | int removeInterface(const std::string& interface) override WARN_UNUSED_RESULT; |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 46 | |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 47 | const bool mHasDns; |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame^] | 48 | const bool mSecure; |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 49 | UidRanges mUidRanges; |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 50 | }; |
| 51 | |
| 52 | #endif // NETD_SERVER_VIRTUAL_NETWORK_H |