From 7a2b13ea6c640c2fb228c1fa11c9e5cd6c32c057 Mon Sep 17 00:00:00 2001 From: Lorenzo Colitti Date: Sun, 20 Aug 2017 11:54:57 +0900 Subject: [PATCH] Fix transitioning between non-accept strict policies. https://android-review.googlesource.com/438278/ attempted to fix changing between two non-accept StrictMode policies (which is not supported by netd) by ensuring that if neither the old nor the new policy were accept, we'd first set an accept policy. Unfortunately, while this is what the comment says, what the code actually does is send the new policy twice. Fix the code to match the comment and the intent of the CL. While I'm at it, also move applyUidCleartextNetworkPolicy into the synchronized block, so multiple concurrent calls to setUidCleartextNetworkPolicy don't result in NMS state going out of sync with netd state. (cherry picked from commit 26364f1dea5f244f87d39615438266ef7eb3f28f) Bug: 28362720 Test: builds Change-Id: I7fe6871bda20566f4cc01ad75711ea52f9a72145 --- .../java/com/android/server/NetworkManagementService.java | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/services/core/java/com/android/server/NetworkManagementService.java b/services/core/java/com/android/server/NetworkManagementService.java index a678cb3681868..1854e2b740f40 100644 --- a/services/core/java/com/android/server/NetworkManagementService.java +++ b/services/core/java/com/android/server/NetworkManagementService.java @@ -1838,12 +1838,14 @@ public class NetworkManagementService extends INetworkManagementService.Stub // netd does not keep state on strict mode policies, and cannot replace a non-accept // policy without deleting it first. Rather than add state to netd, just always send // it an accept policy when switching between two non-accept policies. + // TODO: consider keeping state in netd so we can simplify this code. if (oldPolicy != StrictMode.NETWORK_POLICY_ACCEPT && policy != StrictMode.NETWORK_POLICY_ACCEPT) { - applyUidCleartextNetworkPolicy(uid, policy); + applyUidCleartextNetworkPolicy(uid, StrictMode.NETWORK_POLICY_ACCEPT); } + + applyUidCleartextNetworkPolicy(uid, policy); } - applyUidCleartextNetworkPolicy(uid, policy); } @Override