Merge "Replace NetworkPolicyManagerInternal#isUidNetworkingBlocked()" am: 158e8ae1f1 am: 42a2d40519

Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1535722

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I623a01c29978908b213e888ffebc06f38d5ee085
This commit is contained in:
Paul Hu
2021-01-12 11:11:08 +00:00
committed by Automerger Merge Worker
4 changed files with 37 additions and 43 deletions

View File

@@ -432,6 +432,24 @@ public class NetworkPolicyManager {
} }
} }
/**
* Check that networking is blocked for the given uid.
*
* @param uid The target uid.
* @param meteredNetwork True if the network is metered.
* @return true if networking is blocked for the given uid according to current networking
* policies.
*
* @hide
*/
public boolean isUidNetworkingBlocked(int uid, boolean meteredNetwork) {
try {
return mService.isUidNetworkingBlocked(uid, meteredNetwork);
} catch (RemoteException e) {
throw e.rethrowFromSystemServer();
}
}
/** /**
* Get multipath preference for the given network. * Get multipath preference for the given network.
*/ */

View File

@@ -1331,15 +1331,20 @@ public class ConnectivityService extends IConnectivityManager.Stub
/** /**
* Check if UID should be blocked from using the specified network. * Check if UID should be blocked from using the specified network.
*/ */
private boolean isNetworkWithLinkPropertiesBlocked(LinkProperties lp, int uid, private boolean isNetworkWithCapabilitiesBlocked(@Nullable final NetworkCapabilities nc,
boolean ignoreBlocked) { final int uid, final boolean ignoreBlocked) {
// Networks aren't blocked when ignoring blocked status // Networks aren't blocked when ignoring blocked status
if (ignoreBlocked) { if (ignoreBlocked) {
return false; return false;
} }
if (isUidBlockedByVpn(uid, mVpnBlockedUidRanges)) return true; if (isUidBlockedByVpn(uid, mVpnBlockedUidRanges)) return true;
final String iface = (lp == null ? "" : lp.getInterfaceName()); final long ident = Binder.clearCallingIdentity();
return mPolicyManagerInternal.isUidNetworkingBlocked(uid, iface); try {
final boolean metered = nc == null ? true : nc.isMetered();
return mPolicyManager.isUidNetworkingBlocked(uid, metered);
} finally {
Binder.restoreCallingIdentity(ident);
}
} }
private void maybeLogBlockedNetworkInfo(NetworkInfo ni, int uid) { private void maybeLogBlockedNetworkInfo(NetworkInfo ni, int uid) {
@@ -1377,12 +1382,13 @@ public class ConnectivityService extends IConnectivityManager.Stub
/** /**
* Apply any relevant filters to {@link NetworkState} for the given UID. For * Apply any relevant filters to {@link NetworkState} for the given UID. For
* example, this may mark the network as {@link DetailedState#BLOCKED} based * example, this may mark the network as {@link DetailedState#BLOCKED} based
* on {@link #isNetworkWithLinkPropertiesBlocked}. * on {@link #isNetworkWithCapabilitiesBlocked}.
*/ */
private void filterNetworkStateForUid(NetworkState state, int uid, boolean ignoreBlocked) { private void filterNetworkStateForUid(NetworkState state, int uid, boolean ignoreBlocked) {
if (state == null || state.networkInfo == null || state.linkProperties == null) return; if (state == null || state.networkInfo == null || state.linkProperties == null) return;
if (isNetworkWithLinkPropertiesBlocked(state.linkProperties, uid, ignoreBlocked)) { if (isNetworkWithCapabilitiesBlocked(state.networkCapabilities, uid,
ignoreBlocked)) {
state.networkInfo.setDetailedState(DetailedState.BLOCKED, null, null); state.networkInfo.setDetailedState(DetailedState.BLOCKED, null, null);
} }
synchronized (mVpns) { synchronized (mVpns) {
@@ -1442,8 +1448,8 @@ public class ConnectivityService extends IConnectivityManager.Stub
} }
} }
nai = getDefaultNetwork(); nai = getDefaultNetwork();
if (nai != null if (nai != null && isNetworkWithCapabilitiesBlocked(
&& isNetworkWithLinkPropertiesBlocked(nai.linkProperties, uid, ignoreBlocked)) { nai.networkCapabilities, uid, ignoreBlocked)) {
nai = null; nai = null;
} }
return nai != null ? nai.network : null; return nai != null ? nai.network : null;
@@ -1515,7 +1521,7 @@ public class ConnectivityService extends IConnectivityManager.Stub
enforceAccessPermission(); enforceAccessPermission();
final int uid = mDeps.getCallingUid(); final int uid = mDeps.getCallingUid();
NetworkState state = getFilteredNetworkState(networkType, uid); NetworkState state = getFilteredNetworkState(networkType, uid);
if (!isNetworkWithLinkPropertiesBlocked(state.linkProperties, uid, false)) { if (!isNetworkWithCapabilitiesBlocked(state.networkCapabilities, uid, false)) {
return state.network; return state.network;
} }
return null; return null;
@@ -4473,7 +4479,8 @@ public class ConnectivityService extends IConnectivityManager.Stub
if (!nai.everConnected) { if (!nai.everConnected) {
return; return;
} }
if (isNetworkWithLinkPropertiesBlocked(nai.linkProperties, uid, false)) { final NetworkCapabilities nc = getNetworkCapabilitiesInternal(nai);
if (isNetworkWithCapabilitiesBlocked(nc, uid, false)) {
return; return;
} }
nai.networkMonitor().forceReevaluation(uid); nai.networkMonitor().forceReevaluation(uid);

View File

@@ -43,12 +43,6 @@ public abstract class NetworkPolicyManagerInternal {
*/ */
public abstract boolean isUidRestrictedOnMeteredNetworks(int uid); public abstract boolean isUidRestrictedOnMeteredNetworks(int uid);
/**
* @return true if networking is blocked on the given interface for the given uid according
* to current networking policies.
*/
public abstract boolean isUidNetworkingBlocked(int uid, String ifname);
/** /**
* Figure out if networking is blocked for a given set of conditions. * Figure out if networking is blocked for a given set of conditions.
* *

View File

@@ -71,6 +71,7 @@ import static android.net.NetworkPolicyManager.isProcStateAllowedWhileOnRestrict
import static android.net.NetworkPolicyManager.resolveNetworkId; import static android.net.NetworkPolicyManager.resolveNetworkId;
import static android.net.NetworkPolicyManager.uidPoliciesToString; import static android.net.NetworkPolicyManager.uidPoliciesToString;
import static android.net.NetworkPolicyManager.uidRulesToString; import static android.net.NetworkPolicyManager.uidRulesToString;
import static android.net.NetworkStack.PERMISSION_MAINLINE_NETWORK_STACK;
import static android.net.NetworkTemplate.MATCH_MOBILE; import static android.net.NetworkTemplate.MATCH_MOBILE;
import static android.net.NetworkTemplate.MATCH_WIFI; import static android.net.NetworkTemplate.MATCH_WIFI;
import static android.net.NetworkTemplate.buildTemplateMobileAll; import static android.net.NetworkTemplate.buildTemplateMobileAll;
@@ -5224,7 +5225,7 @@ public class NetworkPolicyManagerService extends INetworkPolicyManager.Stub {
public boolean isUidNetworkingBlocked(int uid, boolean isNetworkMetered) { public boolean isUidNetworkingBlocked(int uid, boolean isNetworkMetered) {
final long startTime = mStatLogger.getTime(); final long startTime = mStatLogger.getTime();
mContext.enforceCallingOrSelfPermission(OBSERVE_NETWORK_POLICY, TAG); enforceAnyPermissionOf(OBSERVE_NETWORK_POLICY, PERMISSION_MAINLINE_NETWORK_STACK);
final int uidRules; final int uidRules;
final boolean isBackgroundRestricted; final boolean isBackgroundRestricted;
synchronized (mUidRulesFirstLock) { synchronized (mUidRulesFirstLock) {
@@ -5327,32 +5328,6 @@ public class NetworkPolicyManagerService extends INetworkPolicyManager.Stub {
&& !hasRule(uidRules, RULE_TEMPORARY_ALLOW_METERED); && !hasRule(uidRules, RULE_TEMPORARY_ALLOW_METERED);
} }
/**
* @return true if networking is blocked on the given interface for the given uid according
* to current networking policies.
*/
@Override
public boolean isUidNetworkingBlocked(int uid, String ifname) {
final long startTime = mStatLogger.getTime();
final int uidRules;
final boolean isBackgroundRestricted;
synchronized (mUidRulesFirstLock) {
uidRules = mUidRules.get(uid, RULE_NONE);
isBackgroundRestricted = mRestrictBackground;
}
final boolean isNetworkMetered;
synchronized (mMeteredIfacesLock) {
isNetworkMetered = mMeteredIfaces.contains(ifname);
}
final boolean ret = isUidNetworkingBlockedInternal(uid, uidRules, isNetworkMetered,
isBackgroundRestricted, mLogger);
mStatLogger.logDurationStat(Stats.IS_UID_NETWORKING_BLOCKED, startTime);
return ret;
}
@Override @Override
public void onTempPowerSaveWhitelistChange(int appId, boolean added) { public void onTempPowerSaveWhitelistChange(int appId, boolean added) {
synchronized (mUidRulesFirstLock) { synchronized (mUidRulesFirstLock) {