Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #ifndef NETD_SERVER_VIRTUAL_NETWORK_H |
| 18 | #define NETD_SERVER_VIRTUAL_NETWORK_H |
| 19 | |
Lorenzo Colitti | fff4bd3 | 2016-04-14 00:56:01 +0900 | [diff] [blame^] | 20 | #include <set> |
| 21 | |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 22 | #include "Network.h" |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 23 | #include "UidRanges.h" |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 24 | |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame] | 25 | // A VirtualNetwork may be "secure" or not. |
| 26 | // |
| 27 | // A secure VPN is the usual type of VPN that grabs the default route (and thus all user traffic). |
| 28 | // Only a few privileged UIDs may skip the VPN and go directly to the underlying physical network. |
| 29 | // |
| 30 | // A non-secure VPN ("bypassable" VPN) also grabs all user traffic by default. But all apps are |
| 31 | // permitted to skip it and pick any other network for their connections. |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 32 | class VirtualNetwork : public Network { |
| 33 | public: |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame] | 34 | VirtualNetwork(unsigned netId, bool hasDns, bool secure); |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 35 | virtual ~VirtualNetwork(); |
| 36 | |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 37 | bool getHasDns() const; |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame] | 38 | bool isSecure() const; |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 39 | bool appliesToUser(uid_t uid) const; |
| 40 | |
Lorenzo Colitti | fff4bd3 | 2016-04-14 00:56:01 +0900 | [diff] [blame^] | 41 | int addUsers(const UidRanges& uidRanges, |
| 42 | const std::set<uid_t>& protectableUsers) WARN_UNUSED_RESULT; |
| 43 | int removeUsers(const UidRanges& uidRanges, |
| 44 | const std::set<uid_t>& protectableUsers) WARN_UNUSED_RESULT; |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 45 | |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 46 | private: |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 47 | Type getType() const override; |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 48 | int addInterface(const std::string& interface) override WARN_UNUSED_RESULT; |
| 49 | int removeInterface(const std::string& interface) override WARN_UNUSED_RESULT; |
Lorenzo Colitti | fff4bd3 | 2016-04-14 00:56:01 +0900 | [diff] [blame^] | 50 | int maybeCloseSockets(bool add, const UidRanges& uidRanges, |
| 51 | const std::set<uid_t>& protectableUsers); |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 52 | |
Sreeram Ramachandran | e09b20a | 2014-07-05 17:15:14 -0700 | [diff] [blame] | 53 | const bool mHasDns; |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame] | 54 | const bool mSecure; |
Sreeram Ramachandran | b1425cc | 2014-06-23 18:54:27 -0700 | [diff] [blame] | 55 | UidRanges mUidRanges; |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 56 | }; |
| 57 | |
| 58 | #endif // NETD_SERVER_VIRTUAL_NETWORK_H |