From a9294eb1c9c090f5c896c0212efed0234678d970 Mon Sep 17 00:00:00 2001 From: Sreeram Ramachandran Date: Wed, 9 Jul 2014 21:43:03 -0700 Subject: [PATCH] Allow a VPN to be declared bypassable. A VPN declared bypassable allows apps to use the new multinetwork APIs to send/receive traffic directly over the underlying network, whereas without it, traffic from those apps would be forced to go via the VPN. Apps still need the right permissions to access the underlying network. For example, if the underlying network is "untrusted", only apps with CHANGE_NETWORK_STATE (or such permission) can actually use it directly. New API with stub implementation to be filled out later. Bug: 15347374 Change-Id: I8794715e024e08380a43f7a090613c5897611c5b --- api/current.txt | 1 + core/java/android/net/VpnService.java | 15 +++++++++++++++ 2 files changed, 16 insertions(+) diff --git a/api/current.txt b/api/current.txt index 9d43d58191248..d00493baede7e 100644 --- a/api/current.txt +++ b/api/current.txt @@ -16850,6 +16850,7 @@ package android.net { method public android.net.VpnService.Builder addRoute(java.net.InetAddress, int); method public android.net.VpnService.Builder addRoute(java.lang.String, int); method public android.net.VpnService.Builder addSearchDomain(java.lang.String); + method public android.net.VpnService.Builder allowBypass(); method public android.net.VpnService.Builder allowFamily(int); method public android.os.ParcelFileDescriptor establish(); method public android.net.VpnService.Builder setConfigureIntent(android.app.PendingIntent); diff --git a/core/java/android/net/VpnService.java b/core/java/android/net/VpnService.java index 680b8f26d2a4b..5d61de22e9aca 100644 --- a/core/java/android/net/VpnService.java +++ b/core/java/android/net/VpnService.java @@ -552,6 +552,21 @@ public class VpnService extends Service { return this; } + /** + * Allows all apps to bypass this VPN connection. + * + * By default, all traffic from apps is forwarded through the VPN interface and it is not + * possible for apps to side-step the VPN. If this method is called, apps may use methods + * such as {@link ConnectivityManager#setProcessDefaultNetwork} to instead send/receive + * directly over the underlying network or any other network they have permissions for. + * + * @return this {@link Builder} object to facilitate chaining of method calls. + */ + public Builder allowBypass() { + // TODO + return this; + } + /** * Create a VPN interface using the parameters supplied to this * builder. The interface works on IP packets, and a file descriptor