Merge "Use consistent naming for allocating SPI."
This commit is contained in:
@@ -25628,12 +25628,12 @@ package android.net {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public final class IpSecManager {
|
public final class IpSecManager {
|
||||||
|
method public android.net.IpSecManager.SecurityParameterIndex allocateSecurityParameterIndex(int, java.net.InetAddress) throws android.net.IpSecManager.ResourceUnavailableException;
|
||||||
|
method public android.net.IpSecManager.SecurityParameterIndex allocateSecurityParameterIndex(int, java.net.InetAddress, int) throws android.net.IpSecManager.ResourceUnavailableException, android.net.IpSecManager.SpiUnavailableException;
|
||||||
method public void applyTransportModeTransform(java.io.FileDescriptor, android.net.IpSecTransform) throws java.io.IOException;
|
method public void applyTransportModeTransform(java.io.FileDescriptor, android.net.IpSecTransform) throws java.io.IOException;
|
||||||
method public android.net.IpSecManager.UdpEncapsulationSocket openUdpEncapsulationSocket(int) throws java.io.IOException, android.net.IpSecManager.ResourceUnavailableException;
|
method public android.net.IpSecManager.UdpEncapsulationSocket openUdpEncapsulationSocket(int) throws java.io.IOException, android.net.IpSecManager.ResourceUnavailableException;
|
||||||
method public android.net.IpSecManager.UdpEncapsulationSocket openUdpEncapsulationSocket() throws java.io.IOException, android.net.IpSecManager.ResourceUnavailableException;
|
method public android.net.IpSecManager.UdpEncapsulationSocket openUdpEncapsulationSocket() throws java.io.IOException, android.net.IpSecManager.ResourceUnavailableException;
|
||||||
method public void removeTransportModeTransform(java.io.FileDescriptor, android.net.IpSecTransform) throws java.io.IOException;
|
method public void removeTransportModeTransform(java.io.FileDescriptor, android.net.IpSecTransform) throws java.io.IOException;
|
||||||
method public android.net.IpSecManager.SecurityParameterIndex reserveSecurityParameterIndex(int, java.net.InetAddress) throws android.net.IpSecManager.ResourceUnavailableException;
|
|
||||||
method public android.net.IpSecManager.SecurityParameterIndex reserveSecurityParameterIndex(int, java.net.InetAddress, int) throws android.net.IpSecManager.ResourceUnavailableException, android.net.IpSecManager.SpiUnavailableException;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public static final class IpSecManager.ResourceUnavailableException extends android.util.AndroidException {
|
public static final class IpSecManager.ResourceUnavailableException extends android.util.AndroidException {
|
||||||
|
|||||||
@@ -30,7 +30,7 @@ import android.os.ParcelFileDescriptor;
|
|||||||
*/
|
*/
|
||||||
interface IIpSecService
|
interface IIpSecService
|
||||||
{
|
{
|
||||||
IpSecSpiResponse reserveSecurityParameterIndex(
|
IpSecSpiResponse allocateSecurityParameterIndex(
|
||||||
int direction, in String remoteAddress, int requestedSpi, in IBinder binder);
|
int direction, in String remoteAddress, int requestedSpi, in IBinder binder);
|
||||||
|
|
||||||
void releaseSecurityParameterIndex(int resourceId);
|
void releaseSecurityParameterIndex(int resourceId);
|
||||||
|
|||||||
@@ -59,8 +59,7 @@ public final class IpSecManager {
|
|||||||
*
|
*
|
||||||
* @hide
|
* @hide
|
||||||
*/
|
*/
|
||||||
@TestApi
|
@TestApi public static final int INVALID_SECURITY_PARAMETER_INDEX = 0;
|
||||||
public static final int INVALID_SECURITY_PARAMETER_INDEX = 0;
|
|
||||||
|
|
||||||
/** @hide */
|
/** @hide */
|
||||||
public interface Status {
|
public interface Status {
|
||||||
@@ -78,7 +77,7 @@ public final class IpSecManager {
|
|||||||
* <p>The combination of remote {@code InetAddress} and SPI must be unique across all apps on
|
* <p>The combination of remote {@code InetAddress} and SPI must be unique across all apps on
|
||||||
* one device. If this error is encountered, a new SPI is required before a transform may be
|
* one device. If this error is encountered, a new SPI is required before a transform may be
|
||||||
* created. This error can be avoided by calling {@link
|
* created. This error can be avoided by calling {@link
|
||||||
* IpSecManager#reserveSecurityParameterIndex}.
|
* IpSecManager#allocateSecurityParameterIndex}.
|
||||||
*/
|
*/
|
||||||
public static final class SpiUnavailableException extends AndroidException {
|
public static final class SpiUnavailableException extends AndroidException {
|
||||||
private final int mSpi;
|
private final int mSpi;
|
||||||
@@ -121,7 +120,7 @@ public final class IpSecManager {
|
|||||||
* This class represents a reserved SPI.
|
* This class represents a reserved SPI.
|
||||||
*
|
*
|
||||||
* <p>Objects of this type are used to track reserved security parameter indices. They can be
|
* <p>Objects of this type are used to track reserved security parameter indices. They can be
|
||||||
* obtained by calling {@link IpSecManager#reserveSecurityParameterIndex} and must be released
|
* obtained by calling {@link IpSecManager#allocateSecurityParameterIndex} and must be released
|
||||||
* by calling {@link #close()} when they are no longer needed.
|
* by calling {@link #close()} when they are no longer needed.
|
||||||
*/
|
*/
|
||||||
public static final class SecurityParameterIndex implements AutoCloseable {
|
public static final class SecurityParameterIndex implements AutoCloseable {
|
||||||
@@ -170,7 +169,7 @@ public final class IpSecManager {
|
|||||||
mRemoteAddress = remoteAddress;
|
mRemoteAddress = remoteAddress;
|
||||||
try {
|
try {
|
||||||
IpSecSpiResponse result =
|
IpSecSpiResponse result =
|
||||||
mService.reserveSecurityParameterIndex(
|
mService.allocateSecurityParameterIndex(
|
||||||
direction, remoteAddress.getHostAddress(), spi, new Binder());
|
direction, remoteAddress.getHostAddress(), spi, new Binder());
|
||||||
|
|
||||||
if (result == null) {
|
if (result == null) {
|
||||||
@@ -228,7 +227,7 @@ public final class IpSecManager {
|
|||||||
* for this user
|
* for this user
|
||||||
* @throws SpiUnavailableException indicating that a particular SPI cannot be reserved
|
* @throws SpiUnavailableException indicating that a particular SPI cannot be reserved
|
||||||
*/
|
*/
|
||||||
public SecurityParameterIndex reserveSecurityParameterIndex(
|
public SecurityParameterIndex allocateSecurityParameterIndex(
|
||||||
int direction, InetAddress remoteAddress) throws ResourceUnavailableException {
|
int direction, InetAddress remoteAddress) throws ResourceUnavailableException {
|
||||||
try {
|
try {
|
||||||
return new SecurityParameterIndex(
|
return new SecurityParameterIndex(
|
||||||
@@ -255,7 +254,7 @@ public final class IpSecManager {
|
|||||||
* for this user
|
* for this user
|
||||||
* @throws SpiUnavailableException indicating that the requested SPI could not be reserved
|
* @throws SpiUnavailableException indicating that the requested SPI could not be reserved
|
||||||
*/
|
*/
|
||||||
public SecurityParameterIndex reserveSecurityParameterIndex(
|
public SecurityParameterIndex allocateSecurityParameterIndex(
|
||||||
int direction, InetAddress remoteAddress, int requestedSpi)
|
int direction, InetAddress remoteAddress, int requestedSpi)
|
||||||
throws SpiUnavailableException, ResourceUnavailableException {
|
throws SpiUnavailableException, ResourceUnavailableException {
|
||||||
if (requestedSpi == IpSecManager.INVALID_SECURITY_PARAMETER_INDEX) {
|
if (requestedSpi == IpSecManager.INVALID_SECURITY_PARAMETER_INDEX) {
|
||||||
@@ -278,11 +277,13 @@ public final class IpSecManager {
|
|||||||
* will throw IOException if the user deactivates the transform (by calling {@link
|
* will throw IOException if the user deactivates the transform (by calling {@link
|
||||||
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
||||||
*
|
*
|
||||||
* <h4>Rekey Procedure</h4> <p>When applying a new tranform to a socket, the previous transform
|
* <h4>Rekey Procedure</h4>
|
||||||
* will be removed. However, inbound traffic on the old transform will continue to be decrypted
|
*
|
||||||
* until that transform is deallocated by calling {@link IpSecTransform#close()}. This overlap
|
* <p>When applying a new tranform to a socket, the previous transform will be removed. However,
|
||||||
* allows rekey procedures where both transforms are valid until both endpoints are using the
|
* inbound traffic on the old transform will continue to be decrypted until that transform is
|
||||||
* new transform and all in-flight packets have been received.
|
* deallocated by calling {@link IpSecTransform#close()}. This overlap allows rekey procedures
|
||||||
|
* where both transforms are valid until both endpoints are using the new transform and all
|
||||||
|
* in-flight packets have been received.
|
||||||
*
|
*
|
||||||
* @param socket a stream socket
|
* @param socket a stream socket
|
||||||
* @param transform a transport mode {@code IpSecTransform}
|
* @param transform a transport mode {@code IpSecTransform}
|
||||||
@@ -310,11 +311,13 @@ public final class IpSecManager {
|
|||||||
* will throw IOException if the user deactivates the transform (by calling {@link
|
* will throw IOException if the user deactivates the transform (by calling {@link
|
||||||
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
||||||
*
|
*
|
||||||
* <h4>Rekey Procedure</h4> <p>When applying a new tranform to a socket, the previous transform
|
* <h4>Rekey Procedure</h4>
|
||||||
* will be removed. However, inbound traffic on the old transform will continue to be decrypted
|
*
|
||||||
* until that transform is deallocated by calling {@link IpSecTransform#close()}. This overlap
|
* <p>When applying a new tranform to a socket, the previous transform will be removed. However,
|
||||||
* allows rekey procedures where both transforms are valid until both endpoints are using the
|
* inbound traffic on the old transform will continue to be decrypted until that transform is
|
||||||
* new transform and all in-flight packets have been received.
|
* deallocated by calling {@link IpSecTransform#close()}. This overlap allows rekey procedures
|
||||||
|
* where both transforms are valid until both endpoints are using the new transform and all
|
||||||
|
* in-flight packets have been received.
|
||||||
*
|
*
|
||||||
* @param socket a datagram socket
|
* @param socket a datagram socket
|
||||||
* @param transform a transport mode {@code IpSecTransform}
|
* @param transform a transport mode {@code IpSecTransform}
|
||||||
@@ -342,11 +345,13 @@ public final class IpSecManager {
|
|||||||
* will throw IOException if the user deactivates the transform (by calling {@link
|
* will throw IOException if the user deactivates the transform (by calling {@link
|
||||||
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
* IpSecTransform#close()}) without calling {@link #removeTransportModeTransform}.
|
||||||
*
|
*
|
||||||
* <h4>Rekey Procedure</h4> <p>When applying a new tranform to a socket, the previous transform
|
* <h4>Rekey Procedure</h4>
|
||||||
* will be removed. However, inbound traffic on the old transform will continue to be decrypted
|
*
|
||||||
* until that transform is deallocated by calling {@link IpSecTransform#close()}. This overlap
|
* <p>When applying a new tranform to a socket, the previous transform will be removed. However,
|
||||||
* allows rekey procedures where both transforms are valid until both endpoints are using the
|
* inbound traffic on the old transform will continue to be decrypted until that transform is
|
||||||
* new transform and all in-flight packets have been received.
|
* deallocated by calling {@link IpSecTransform#close()}. This overlap allows rekey procedures
|
||||||
|
* where both transforms are valid until both endpoints are using the new transform and all
|
||||||
|
* in-flight packets have been received.
|
||||||
*
|
*
|
||||||
* @param socket a socket file descriptor
|
* @param socket a socket file descriptor
|
||||||
* @param transform a transport mode {@code IpSecTransform}
|
* @param transform a transport mode {@code IpSecTransform}
|
||||||
@@ -379,7 +384,8 @@ public final class IpSecManager {
|
|||||||
* Applications should probably not use this API directly. Instead, they should use {@link
|
* Applications should probably not use this API directly. Instead, they should use {@link
|
||||||
* VpnService} to provide VPN capability in a more generic fashion.
|
* VpnService} to provide VPN capability in a more generic fashion.
|
||||||
*
|
*
|
||||||
* TODO: Update javadoc for tunnel mode APIs at the same time the APIs are re-worked.
|
* <p>TODO: Update javadoc for tunnel mode APIs at the same time the APIs are re-worked.
|
||||||
|
*
|
||||||
* @param net a {@link Network} that will be tunneled via IP Sec.
|
* @param net a {@link Network} that will be tunneled via IP Sec.
|
||||||
* @param transform an {@link IpSecTransform}, which must be an active Tunnel Mode transform.
|
* @param transform an {@link IpSecTransform}, which must be an active Tunnel Mode transform.
|
||||||
* @hide
|
* @hide
|
||||||
@@ -469,7 +475,8 @@ public final class IpSecManager {
|
|||||||
* all traffic that cannot be routed to the Tunnel's outbound interface. If that interface is
|
* all traffic that cannot be routed to the Tunnel's outbound interface. If that interface is
|
||||||
* lost, all traffic will drop.
|
* lost, all traffic will drop.
|
||||||
*
|
*
|
||||||
* TODO: Update javadoc for tunnel mode APIs at the same time the APIs are re-worked.
|
* <p>TODO: Update javadoc for tunnel mode APIs at the same time the APIs are re-worked.
|
||||||
|
*
|
||||||
* @param net a network that currently has transform applied to it.
|
* @param net a network that currently has transform applied to it.
|
||||||
* @param transform a Tunnel Mode IPsec Transform that has been previously applied to the given
|
* @param transform a Tunnel Mode IPsec Transform that has been previously applied to the given
|
||||||
* network
|
* network
|
||||||
|
|||||||
@@ -116,8 +116,7 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Checks the result status and throws an appropriate exception if
|
* Checks the result status and throws an appropriate exception if the status is not Status.OK.
|
||||||
* the status is not Status.OK.
|
|
||||||
*/
|
*/
|
||||||
private void checkResultStatus(int status)
|
private void checkResultStatus(int status)
|
||||||
throws IOException, IpSecManager.ResourceUnavailableException,
|
throws IOException, IpSecManager.ResourceUnavailableException,
|
||||||
@@ -267,9 +266,7 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/** This class is used to build {@link IpSecTransform} objects. */
|
||||||
* This class is used to build {@link IpSecTransform} objects.
|
|
||||||
*/
|
|
||||||
public static class Builder {
|
public static class Builder {
|
||||||
private Context mContext;
|
private Context mContext;
|
||||||
private IpSecConfig mConfig;
|
private IpSecConfig mConfig;
|
||||||
@@ -339,7 +336,7 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
*
|
*
|
||||||
* <p>Because IPsec operates at the IP layer, this 32-bit identifier uniquely identifies
|
* <p>Because IPsec operates at the IP layer, this 32-bit identifier uniquely identifies
|
||||||
* packets to a given destination address. To prevent SPI collisions, values should be
|
* packets to a given destination address. To prevent SPI collisions, values should be
|
||||||
* reserved by calling {@link IpSecManager#reserveSecurityParameterIndex}.
|
* reserved by calling {@link IpSecManager#allocateSecurityParameterIndex}.
|
||||||
*
|
*
|
||||||
* <p>If the SPI and algorithms are omitted for one direction, traffic in that direction
|
* <p>If the SPI and algorithms are omitted for one direction, traffic in that direction
|
||||||
* will not be encrypted or authenticated.
|
* will not be encrypted or authenticated.
|
||||||
@@ -377,7 +374,6 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
* ESP Packets</a>
|
* ESP Packets</a>
|
||||||
* @see <a href="https://tools.ietf.org/html/rfc7296#section-2.23">RFC 7296 section 2.23,
|
* @see <a href="https://tools.ietf.org/html/rfc7296#section-2.23">RFC 7296 section 2.23,
|
||||||
* NAT Traversal of IKEv2</a>
|
* NAT Traversal of IKEv2</a>
|
||||||
*
|
|
||||||
* @param localSocket a socket for sending and receiving encapsulated traffic
|
* @param localSocket a socket for sending and receiving encapsulated traffic
|
||||||
* @param remotePort the UDP port number of the remote host that will send and receive
|
* @param remotePort the UDP port number of the remote host that will send and receive
|
||||||
* encapsulated traffic. In the case of IKEv2, this should be port 4500.
|
* encapsulated traffic. In the case of IKEv2, this should be port 4500.
|
||||||
@@ -402,7 +398,6 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
*
|
*
|
||||||
* @param intervalSeconds the maximum number of seconds between keepalive packets. Must be
|
* @param intervalSeconds the maximum number of seconds between keepalive packets. Must be
|
||||||
* between 20s and 3600s.
|
* between 20s and 3600s.
|
||||||
*
|
|
||||||
* @hide
|
* @hide
|
||||||
*/
|
*/
|
||||||
@SystemApi
|
@SystemApi
|
||||||
@@ -418,7 +413,6 @@ public final class IpSecTransform implements AutoCloseable {
|
|||||||
* will not affect any network traffic until it has been applied to one or more sockets.
|
* will not affect any network traffic until it has been applied to one or more sockets.
|
||||||
*
|
*
|
||||||
* @see IpSecManager#applyTransportModeTransform
|
* @see IpSecManager#applyTransportModeTransform
|
||||||
*
|
|
||||||
* @param remoteAddress the remote {@code InetAddress} of traffic on sockets that will use
|
* @param remoteAddress the remote {@code InetAddress} of traffic on sockets that will use
|
||||||
* this transform
|
* this transform
|
||||||
* @throws IllegalArgumentException indicating that a particular combination of transform
|
* @throws IllegalArgumentException indicating that a particular combination of transform
|
||||||
|
|||||||
@@ -827,15 +827,15 @@ public class IpSecService extends IIpSecService.Stub {
|
|||||||
throw new IllegalArgumentException("Invalid Direction: " + direction);
|
throw new IllegalArgumentException("Invalid Direction: " + direction);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
|
||||||
/** Get a new SPI and maintain the reservation in the system server */
|
/** Get a new SPI and maintain the reservation in the system server */
|
||||||
public synchronized IpSecSpiResponse reserveSecurityParameterIndex(
|
@Override
|
||||||
|
public synchronized IpSecSpiResponse allocateSecurityParameterIndex(
|
||||||
int direction, String remoteAddress, int requestedSpi, IBinder binder)
|
int direction, String remoteAddress, int requestedSpi, IBinder binder)
|
||||||
throws RemoteException {
|
throws RemoteException {
|
||||||
checkDirection(direction);
|
checkDirection(direction);
|
||||||
checkInetAddress(remoteAddress);
|
checkInetAddress(remoteAddress);
|
||||||
/* requestedSpi can be anything in the int range, so no check is needed. */
|
/* requestedSpi can be anything in the int range, so no check is needed. */
|
||||||
checkNotNull(binder, "Null Binder passed to reserveSecurityParameterIndex");
|
checkNotNull(binder, "Null Binder passed to allocateSecurityParameterIndex");
|
||||||
|
|
||||||
UserRecord userRecord = mUserResourceTracker.getUserRecord(Binder.getCallingUid());
|
UserRecord userRecord = mUserResourceTracker.getUserRecord(Binder.getCallingUid());
|
||||||
int resourceId = mNextResourceId.getAndIncrement();
|
int resourceId = mNextResourceId.getAndIncrement();
|
||||||
|
|||||||
@@ -80,7 +80,7 @@ public class IpSecManagerTest {
|
|||||||
int resourceId = 1;
|
int resourceId = 1;
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
new IpSecSpiResponse(IpSecManager.Status.OK, resourceId, DROID_SPI);
|
new IpSecSpiResponse(IpSecManager.Status.OK, resourceId, DROID_SPI);
|
||||||
when(mMockIpSecService.reserveSecurityParameterIndex(
|
when(mMockIpSecService.allocateSecurityParameterIndex(
|
||||||
eq(IpSecTransform.DIRECTION_IN),
|
eq(IpSecTransform.DIRECTION_IN),
|
||||||
eq(GOOGLE_DNS_4.getHostAddress()),
|
eq(GOOGLE_DNS_4.getHostAddress()),
|
||||||
eq(DROID_SPI),
|
eq(DROID_SPI),
|
||||||
@@ -88,7 +88,7 @@ public class IpSecManagerTest {
|
|||||||
.thenReturn(spiResp);
|
.thenReturn(spiResp);
|
||||||
|
|
||||||
IpSecManager.SecurityParameterIndex droidSpi =
|
IpSecManager.SecurityParameterIndex droidSpi =
|
||||||
mIpSecManager.reserveSecurityParameterIndex(
|
mIpSecManager.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_IN, GOOGLE_DNS_4, DROID_SPI);
|
IpSecTransform.DIRECTION_IN, GOOGLE_DNS_4, DROID_SPI);
|
||||||
assertEquals(DROID_SPI, droidSpi.getSpi());
|
assertEquals(DROID_SPI, droidSpi.getSpi());
|
||||||
|
|
||||||
@@ -102,7 +102,7 @@ public class IpSecManagerTest {
|
|||||||
int resourceId = 1;
|
int resourceId = 1;
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
new IpSecSpiResponse(IpSecManager.Status.OK, resourceId, DROID_SPI);
|
new IpSecSpiResponse(IpSecManager.Status.OK, resourceId, DROID_SPI);
|
||||||
when(mMockIpSecService.reserveSecurityParameterIndex(
|
when(mMockIpSecService.allocateSecurityParameterIndex(
|
||||||
eq(IpSecTransform.DIRECTION_OUT),
|
eq(IpSecTransform.DIRECTION_OUT),
|
||||||
eq(GOOGLE_DNS_4.getHostAddress()),
|
eq(GOOGLE_DNS_4.getHostAddress()),
|
||||||
eq(IpSecManager.INVALID_SECURITY_PARAMETER_INDEX),
|
eq(IpSecManager.INVALID_SECURITY_PARAMETER_INDEX),
|
||||||
@@ -110,7 +110,7 @@ public class IpSecManagerTest {
|
|||||||
.thenReturn(spiResp);
|
.thenReturn(spiResp);
|
||||||
|
|
||||||
IpSecManager.SecurityParameterIndex randomSpi =
|
IpSecManager.SecurityParameterIndex randomSpi =
|
||||||
mIpSecManager.reserveSecurityParameterIndex(
|
mIpSecManager.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
||||||
|
|
||||||
assertEquals(DROID_SPI, randomSpi.getSpi());
|
assertEquals(DROID_SPI, randomSpi.getSpi());
|
||||||
@@ -127,12 +127,13 @@ public class IpSecManagerTest {
|
|||||||
public void testAllocSpiResUnavaiableExeption() throws Exception {
|
public void testAllocSpiResUnavaiableExeption() throws Exception {
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
new IpSecSpiResponse(IpSecManager.Status.RESOURCE_UNAVAILABLE, 0, 0);
|
new IpSecSpiResponse(IpSecManager.Status.RESOURCE_UNAVAILABLE, 0, 0);
|
||||||
when(mMockIpSecService.reserveSecurityParameterIndex(
|
when(mMockIpSecService.allocateSecurityParameterIndex(
|
||||||
anyInt(), anyString(), anyInt(), anyObject()))
|
anyInt(), anyString(), anyInt(), anyObject()))
|
||||||
.thenReturn(spiResp);
|
.thenReturn(spiResp);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
mIpSecManager.reserveSecurityParameterIndex(IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
mIpSecManager.allocateSecurityParameterIndex(
|
||||||
|
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
||||||
fail("ResourceUnavailableException was not thrown");
|
fail("ResourceUnavailableException was not thrown");
|
||||||
} catch (IpSecManager.ResourceUnavailableException e) {
|
} catch (IpSecManager.ResourceUnavailableException e) {
|
||||||
}
|
}
|
||||||
@@ -144,12 +145,13 @@ public class IpSecManagerTest {
|
|||||||
@Test
|
@Test
|
||||||
public void testAllocSpiSpiUnavaiableExeption() throws Exception {
|
public void testAllocSpiSpiUnavaiableExeption() throws Exception {
|
||||||
IpSecSpiResponse spiResp = new IpSecSpiResponse(IpSecManager.Status.SPI_UNAVAILABLE, 0, 0);
|
IpSecSpiResponse spiResp = new IpSecSpiResponse(IpSecManager.Status.SPI_UNAVAILABLE, 0, 0);
|
||||||
when(mMockIpSecService.reserveSecurityParameterIndex(
|
when(mMockIpSecService.allocateSecurityParameterIndex(
|
||||||
anyInt(), anyString(), anyInt(), anyObject()))
|
anyInt(), anyString(), anyInt(), anyObject()))
|
||||||
.thenReturn(spiResp);
|
.thenReturn(spiResp);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
mIpSecManager.reserveSecurityParameterIndex(IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
mIpSecManager.allocateSecurityParameterIndex(
|
||||||
|
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4);
|
||||||
fail("ResourceUnavailableException was not thrown");
|
fail("ResourceUnavailableException was not thrown");
|
||||||
} catch (IpSecManager.ResourceUnavailableException e) {
|
} catch (IpSecManager.ResourceUnavailableException e) {
|
||||||
}
|
}
|
||||||
@@ -161,7 +163,7 @@ public class IpSecManagerTest {
|
|||||||
@Test
|
@Test
|
||||||
public void testRequestAllocInvalidSpi() throws Exception {
|
public void testRequestAllocInvalidSpi() throws Exception {
|
||||||
try {
|
try {
|
||||||
mIpSecManager.reserveSecurityParameterIndex(
|
mIpSecManager.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4, 0);
|
IpSecTransform.DIRECTION_OUT, GOOGLE_DNS_4, 0);
|
||||||
fail("Able to allocate invalid spi");
|
fail("Able to allocate invalid spi");
|
||||||
} catch (IllegalArgumentException e) {
|
} catch (IllegalArgumentException e) {
|
||||||
|
|||||||
@@ -125,7 +125,7 @@ public class IpSecServiceParameterizedTest {
|
|||||||
.thenReturn(TEST_SPI_OUT);
|
.thenReturn(TEST_SPI_OUT);
|
||||||
|
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_OUT, mRemoteAddr, TEST_SPI_OUT, new Binder());
|
IpSecTransform.DIRECTION_OUT, mRemoteAddr, TEST_SPI_OUT, new Binder());
|
||||||
assertEquals(IpSecManager.Status.OK, spiResp.status);
|
assertEquals(IpSecManager.Status.OK, spiResp.status);
|
||||||
assertEquals(TEST_SPI_OUT, spiResp.spi);
|
assertEquals(TEST_SPI_OUT, spiResp.spi);
|
||||||
@@ -142,7 +142,7 @@ public class IpSecServiceParameterizedTest {
|
|||||||
.thenReturn(TEST_SPI_OUT);
|
.thenReturn(TEST_SPI_OUT);
|
||||||
|
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_OUT, mRemoteAddr, TEST_SPI_OUT, new Binder());
|
IpSecTransform.DIRECTION_OUT, mRemoteAddr, TEST_SPI_OUT, new Binder());
|
||||||
|
|
||||||
mIpSecService.releaseSecurityParameterIndex(spiResp.resourceId);
|
mIpSecService.releaseSecurityParameterIndex(spiResp.resourceId);
|
||||||
@@ -212,7 +212,7 @@ public class IpSecServiceParameterizedTest {
|
|||||||
.thenReturn(returnSpi);
|
.thenReturn(returnSpi);
|
||||||
|
|
||||||
IpSecSpiResponse spi =
|
IpSecSpiResponse spi =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
direction,
|
direction,
|
||||||
NetworkUtils.numericToInetAddress(remoteAddress).getHostAddress(),
|
NetworkUtils.numericToInetAddress(remoteAddress).getHostAddress(),
|
||||||
IpSecManager.INVALID_SECURITY_PARAMETER_INDEX,
|
IpSecManager.INVALID_SECURITY_PARAMETER_INDEX,
|
||||||
|
|||||||
@@ -287,7 +287,7 @@ public class IpSecServiceTest {
|
|||||||
for (String address : invalidAddresses) {
|
for (String address : invalidAddresses) {
|
||||||
try {
|
try {
|
||||||
IpSecSpiResponse spiResp =
|
IpSecSpiResponse spiResp =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
IpSecTransform.DIRECTION_OUT, address, DROID_SPI, new Binder());
|
IpSecTransform.DIRECTION_OUT, address, DROID_SPI, new Binder());
|
||||||
fail("Invalid address was passed through IpSecService validation: " + address);
|
fail("Invalid address was passed through IpSecService validation: " + address);
|
||||||
} catch (IllegalArgumentException e) {
|
} catch (IllegalArgumentException e) {
|
||||||
@@ -368,7 +368,7 @@ public class IpSecServiceTest {
|
|||||||
// Reserve spis until it fails.
|
// Reserve spis until it fails.
|
||||||
for (int i = 0; i < MAX_NUM_SPIS; i++) {
|
for (int i = 0; i < MAX_NUM_SPIS; i++) {
|
||||||
IpSecSpiResponse newSpi =
|
IpSecSpiResponse newSpi =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
0x1,
|
0x1,
|
||||||
InetAddress.getLoopbackAddress().getHostAddress(),
|
InetAddress.getLoopbackAddress().getHostAddress(),
|
||||||
DROID_SPI + i,
|
DROID_SPI + i,
|
||||||
@@ -384,7 +384,7 @@ public class IpSecServiceTest {
|
|||||||
|
|
||||||
// Try to reserve one more SPI, and should fail.
|
// Try to reserve one more SPI, and should fail.
|
||||||
IpSecSpiResponse extraSpi =
|
IpSecSpiResponse extraSpi =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
0x1,
|
0x1,
|
||||||
InetAddress.getLoopbackAddress().getHostAddress(),
|
InetAddress.getLoopbackAddress().getHostAddress(),
|
||||||
DROID_SPI + MAX_NUM_SPIS,
|
DROID_SPI + MAX_NUM_SPIS,
|
||||||
@@ -398,7 +398,7 @@ public class IpSecServiceTest {
|
|||||||
|
|
||||||
// Should successfully reserve one more spi.
|
// Should successfully reserve one more spi.
|
||||||
extraSpi =
|
extraSpi =
|
||||||
mIpSecService.reserveSecurityParameterIndex(
|
mIpSecService.allocateSecurityParameterIndex(
|
||||||
0x1,
|
0x1,
|
||||||
InetAddress.getLoopbackAddress().getHostAddress(),
|
InetAddress.getLoopbackAddress().getHostAddress(),
|
||||||
DROID_SPI + MAX_NUM_SPIS,
|
DROID_SPI + MAX_NUM_SPIS,
|
||||||
|
|||||||
Reference in New Issue
Block a user