Merge changes I752c39bd,I00f49555

* changes:
  Fix Ikev2 vpn cannot establish through startLegacyVpn()
  Throw UnsupportedOperationException if startLegacyVpn is called
This commit is contained in:
Lucas Lin
2021-08-05 06:35:39 +00:00
committed by Gerrit Code Review
3 changed files with 22 additions and 5 deletions

View File

@@ -389,6 +389,10 @@ public class VpnManager {
/** /**
* Starts a legacy VPN. * Starts a legacy VPN.
*
* Legacy VPN is deprecated starting from Android S. So this API shouldn't be called if the
* initial SDK version of device is Android S+. Otherwise, UnsupportedOperationException will be
* thrown.
* @hide * @hide
*/ */
public void startLegacyVpn(VpnProfile profile) { public void startLegacyVpn(VpnProfile profile) {

View File

@@ -377,12 +377,15 @@ public final class VpnProfile implements Cloneable, Parcelable {
/** Checks if this profile specifies a LegacyVpn type. */ /** Checks if this profile specifies a LegacyVpn type. */
public static boolean isLegacyType(int type) { public static boolean isLegacyType(int type) {
switch (type) { switch (type) {
case VpnProfile.TYPE_IKEV2_IPSEC_USER_PASS: // fall through case VpnProfile.TYPE_PPTP:
case VpnProfile.TYPE_IKEV2_IPSEC_RSA: // fall through case VpnProfile.TYPE_L2TP_IPSEC_PSK:
case VpnProfile.TYPE_IKEV2_IPSEC_PSK: case VpnProfile.TYPE_L2TP_IPSEC_RSA:
return false; case VpnProfile.TYPE_IPSEC_XAUTH_PSK:
default: case VpnProfile.TYPE_IPSEC_XAUTH_RSA:
case VpnProfile.TYPE_IPSEC_HYBRID_RSA:
return true; return true;
default:
return false;
} }
} }

View File

@@ -38,6 +38,7 @@ import android.net.VpnManager;
import android.net.VpnService; import android.net.VpnService;
import android.net.util.NetdService; import android.net.util.NetdService;
import android.os.Binder; import android.os.Binder;
import android.os.Build;
import android.os.Handler; import android.os.Handler;
import android.os.HandlerThread; import android.os.HandlerThread;
import android.os.INetworkManagementService; import android.os.INetworkManagementService;
@@ -348,9 +349,18 @@ public class VpnManagerService extends IVpnManager.Stub {
/** /**
* Start legacy VPN, controlling native daemons as needed. Creates a * Start legacy VPN, controlling native daemons as needed. Creates a
* secondary thread to perform connection work, returning quickly. * secondary thread to perform connection work, returning quickly.
*
* Legacy VPN is deprecated starting from Android S. So this API shouldn't be called if the
* initial SDK version of device is Android S+. Otherwise, UnsupportedOperationException will be
* thrown.
*/ */
@SuppressWarnings("AndroidFrameworkCompatChange") // This is not an app-visible API.
@Override @Override
public void startLegacyVpn(VpnProfile profile) { public void startLegacyVpn(VpnProfile profile) {
if (Build.VERSION.DEVICE_INITIAL_SDK_INT >= Build.VERSION_CODES.S
&& VpnProfile.isLegacyType(profile.type)) {
throw new UnsupportedOperationException("Legacy VPN is deprecated");
}
int user = UserHandle.getUserId(mDeps.getCallingUid()); int user = UserHandle.getUserId(mDeps.getCallingUid());
// Note that if the caller is not system (uid >= Process.FIRST_APPLICATION_UID), // Note that if the caller is not system (uid >= Process.FIRST_APPLICATION_UID),
// the code might not work well since getActiveNetwork might return null if the uid is // the code might not work well since getActiveNetwork might return null if the uid is