From 2796cff6f5c89c8ab034a818c77d471932eb096c Mon Sep 17 00:00:00 2001 From: Benedict Wong Date: Mon, 17 Feb 2020 16:36:18 -0800 Subject: [PATCH] Remove UdpEncapsulationSocket references in VPNs This changes the IkeSessionParams generation to set a specific Network, and no longer passes a UDP encapsulation socket. Bug: 149356682 Test: FrameworksNetTests passing. Change-Id: I69f184762490b1dd3d3261d00c81fd32bbebddfc Merged-In: I69f184762490b1dd3d3261d00c81fd32bbebddfc --- .../com/android/server/connectivity/Vpn.java | 23 +------------------ .../server/connectivity/VpnIkev2Utils.java | 8 +++---- 2 files changed, 5 insertions(+), 26 deletions(-) diff --git a/services/core/java/com/android/server/connectivity/Vpn.java b/services/core/java/com/android/server/connectivity/Vpn.java index 3c21d1a5169ef..84ed7fbc73e59 100644 --- a/services/core/java/com/android/server/connectivity/Vpn.java +++ b/services/core/java/com/android/server/connectivity/Vpn.java @@ -52,7 +52,6 @@ import android.net.Ikev2VpnProfile; import android.net.IpPrefix; import android.net.IpSecManager; import android.net.IpSecManager.IpSecTunnelInterface; -import android.net.IpSecManager.UdpEncapsulationSocket; import android.net.IpSecTransform; import android.net.LinkAddress; import android.net.LinkProperties; @@ -2197,7 +2196,6 @@ public class Vpn { /** Signal to ensure shutdown is honored even if a new Network is connected. */ private boolean mIsRunning = true; - @Nullable private UdpEncapsulationSocket mEncapSocket; @Nullable private IpSecTunnelInterface mTunnelIface; @Nullable private IkeSession mSession; @Nullable private Network mActiveNetwork; @@ -2348,12 +2346,8 @@ public class Vpn { resetIkeState(); mActiveNetwork = network; - // TODO(b/149356682): Update this based on new IKE API - mEncapSocket = mIpSecManager.openUdpEncapsulationSocket(); - - // TODO(b/149356682): Update this based on new IKE API final IkeSessionParams ikeSessionParams = - VpnIkev2Utils.buildIkeSessionParams(mProfile, mEncapSocket); + VpnIkev2Utils.buildIkeSessionParams(mContext, mProfile, network); final ChildSessionParams childSessionParams = VpnIkev2Utils.buildChildSessionParams(); @@ -2366,11 +2360,6 @@ public class Vpn { network); mNetd.setInterfaceUp(mTunnelIface.getInterfaceName()); - // Socket must be bound to prevent network switches from causing - // the IKE teardown to fail/timeout. - // TODO(b/149356682): Update this based on new IKE API - network.bindSocket(mEncapSocket.getFileDescriptor()); - mSession = mIkev2SessionCreator.createIkeSession( mContext, ikeSessionParams, @@ -2455,16 +2444,6 @@ public class Vpn { mSession.kill(); // Kill here to make sure all resources are released immediately mSession = null; } - - // TODO(b/149356682): Update this based on new IKE API - if (mEncapSocket != null) { - try { - mEncapSocket.close(); - } catch (IOException e) { - Log.e(TAG, "Failed to close encap socket", e); - } - mEncapSocket = null; - } } /** diff --git a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java index 33fc32b78df71..1e20ae752709b 100644 --- a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java +++ b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java @@ -35,10 +35,10 @@ import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_AES128_XCBC import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1; import android.annotation.NonNull; +import android.content.Context; import android.net.Ikev2VpnProfile; import android.net.InetAddresses; import android.net.IpPrefix; -import android.net.IpSecManager.UdpEncapsulationSocket; import android.net.IpSecTransform; import android.net.Network; import android.net.RouteInfo; @@ -84,7 +84,7 @@ import java.util.List; */ public class VpnIkev2Utils { static IkeSessionParams buildIkeSessionParams( - @NonNull Ikev2VpnProfile profile, @NonNull UdpEncapsulationSocket socket) { + @NonNull Context context, @NonNull Ikev2VpnProfile profile, @NonNull Network network) { // TODO(b/149356682): Update this based on new IKE API. Only numeric addresses supported // until then. All others throw IAE (caught by caller). final InetAddress serverAddr = InetAddresses.parseNumericAddress(profile.getServerAddr()); @@ -93,9 +93,9 @@ public class VpnIkev2Utils { // TODO(b/149356682): Update this based on new IKE API. final IkeSessionParams.Builder ikeOptionsBuilder = - new IkeSessionParams.Builder() + new IkeSessionParams.Builder(context) .setServerAddress(serverAddr) - .setUdpEncapsulationSocket(socket) + .setNetwork(network) .setLocalIdentification(localId) .setRemoteIdentification(remoteId); setIkeAuth(profile, ikeOptionsBuilder);