From 55c261ade61ba6879e007c57b734e69972b8ecfc Mon Sep 17 00:00:00 2001 From: Martijn Coenen Date: Wed, 20 Apr 2022 07:37:59 +0000 Subject: [PATCH] Add in sandbox UIDs when configuring VPN. SDK sandboxes that belong to an application should follow the same VPN configuration that their corresponding app does. Bug: 225317905 Test: atest VpnTest Change-Id: I634f47a013fa2e42908d963fcd0634778298fee5 --- services/core/java/com/android/server/connectivity/Vpn.java | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/services/core/java/com/android/server/connectivity/Vpn.java b/services/core/java/com/android/server/connectivity/Vpn.java index d9db28a9aa781..054838ad0fb57 100644 --- a/services/core/java/com/android/server/connectivity/Vpn.java +++ b/services/core/java/com/android/server/connectivity/Vpn.java @@ -1533,11 +1533,17 @@ public class Vpn { } // Note: Return type guarantees results are deduped and sorted, which callers require. + // This method also adds the SDK sandbox UIDs corresponding to the applications by default, + // since apps are generally not aware of them, yet they should follow the VPN configuration + // of the app they belong to. private SortedSet getAppsUids(List packageNames, int userId) { SortedSet uids = new TreeSet<>(); for (String app : packageNames) { int uid = getAppUid(app, userId); if (uid != -1) uids.add(uid); + if (Process.isApplicationUid(uid)) { + uids.add(Process.toSdkSandboxUid(uid)); + } } return uids; }