From 69d77da91aabce7f080f90bf73bb1d8989d2fe9d Mon Sep 17 00:00:00 2001 From: evitayan Date: Wed, 30 Oct 2019 19:58:48 -0700 Subject: [PATCH 1/5] Expose IKE module API: IKE ID, TS and SaProposal This commit updates system-current to expose APIs of IKE mainline module. Changes include: - Feed IKE API source file to base/Android.bp - Update system-current.txt to expose IkeIdentification, IkeTrafficSelector and SaProposal Bug: 143983419 Test: make update-api && make Change-Id: I3826434850de7b264ab44d46ca0bd82359dc98fe --- Android.bp | 1 + api/system-current.txt | 90 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 91 insertions(+) diff --git a/Android.bp b/Android.bp index 284e7015c1158..28ced18d3a650 100644 --- a/Android.bp +++ b/Android.bp @@ -1068,6 +1068,7 @@ stubs_defaults { ":core-current-stubs-source", ":core_public_api_files", ":updatable-media-srcs", + ":ike-api-srcs", ], libs: ["framework-internal-utils"], local_sourcepaths: frameworks_base_subdirs, diff --git a/api/system-current.txt b/api/system-current.txt index 48d453e7fb814..31b187ded2ee5 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -4273,6 +4273,96 @@ package android.net.apf { } +package android.net.ipsec.ike { + + public final class ChildSaProposal extends android.net.ipsec.ike.SaProposal { + } + + public static final class ChildSaProposal.Builder { + ctor public ChildSaProposal.Builder(); + method @NonNull public android.net.ipsec.ike.ChildSaProposal.Builder addDhGroup(int); + method @NonNull public android.net.ipsec.ike.ChildSaProposal.Builder addEncryptionAlgorithm(int, int); + method @NonNull public android.net.ipsec.ike.ChildSaProposal.Builder addIntegrityAlgorithm(int); + method @NonNull public android.net.ipsec.ike.ChildSaProposal build(); + } + + public class IkeFqdnIdentification extends android.net.ipsec.ike.IkeIdentification { + ctor public IkeFqdnIdentification(@NonNull String); + field @NonNull public final String fqdn; + } + + public abstract class IkeIdentification { + } + + public final class IkeIpv4AddrIdentification extends android.net.ipsec.ike.IkeIdentification { + ctor public IkeIpv4AddrIdentification(@NonNull java.net.Inet4Address); + field @NonNull public final java.net.Inet4Address ipv4Address; + } + + public class IkeIpv6AddrIdentification extends android.net.ipsec.ike.IkeIdentification { + ctor public IkeIpv6AddrIdentification(@NonNull java.net.Inet6Address); + field @NonNull public final java.net.Inet6Address ipv6Address; + } + + public final class IkeKeyIdIdentification extends android.net.ipsec.ike.IkeIdentification { + ctor public IkeKeyIdIdentification(@NonNull byte[]); + field @NonNull public final byte[] keyId; + } + + public final class IkeRfc822AddrIdentification extends android.net.ipsec.ike.IkeIdentification { + ctor public IkeRfc822AddrIdentification(@NonNull String); + field @NonNull public final String rfc822Name; + } + + public final class IkeSaProposal extends android.net.ipsec.ike.SaProposal { + method @NonNull public java.util.List getPseudorandomFunctions(); + } + + public static final class IkeSaProposal.Builder { + ctor public IkeSaProposal.Builder(); + method @NonNull public android.net.ipsec.ike.IkeSaProposal.Builder addDhGroup(int); + method @NonNull public android.net.ipsec.ike.IkeSaProposal.Builder addEncryptionAlgorithm(int, int); + method @NonNull public android.net.ipsec.ike.IkeSaProposal.Builder addIntegrityAlgorithm(int); + method @NonNull public android.net.ipsec.ike.IkeSaProposal.Builder addPseudorandomFunction(int); + method @NonNull public android.net.ipsec.ike.IkeSaProposal build(); + } + + public final class IkeTrafficSelector { + ctor public IkeTrafficSelector(int, int, @NonNull java.net.InetAddress, @NonNull java.net.InetAddress); + field public final int endPort; + field @NonNull public final java.net.InetAddress endingAddress; + field public final int startPort; + field @NonNull public final java.net.InetAddress startingAddress; + } + + public abstract class SaProposal { + method @NonNull public java.util.List getDhGroups(); + method @NonNull public java.util.List> getEncryptionAlgorithms(); + method @NonNull public java.util.List getIntegrityAlgorithms(); + field public static final int DH_GROUP_1024_BIT_MODP = 2; // 0x2 + field public static final int DH_GROUP_2048_BIT_MODP = 14; // 0xe + field public static final int DH_GROUP_NONE = 0; // 0x0 + field public static final int ENCRYPTION_ALGORITHM_3DES = 3; // 0x3 + field public static final int ENCRYPTION_ALGORITHM_AES_CBC = 12; // 0xc + field public static final int ENCRYPTION_ALGORITHM_AES_GCM_12 = 19; // 0x13 + field public static final int ENCRYPTION_ALGORITHM_AES_GCM_16 = 20; // 0x14 + field public static final int ENCRYPTION_ALGORITHM_AES_GCM_8 = 18; // 0x12 + field public static final int INTEGRITY_ALGORITHM_AES_XCBC_96 = 5; // 0x5 + field public static final int INTEGRITY_ALGORITHM_HMAC_SHA1_96 = 2; // 0x2 + field public static final int INTEGRITY_ALGORITHM_HMAC_SHA2_256_128 = 12; // 0xc + field public static final int INTEGRITY_ALGORITHM_HMAC_SHA2_384_192 = 13; // 0xd + field public static final int INTEGRITY_ALGORITHM_HMAC_SHA2_512_256 = 14; // 0xe + field public static final int INTEGRITY_ALGORITHM_NONE = 0; // 0x0 + field public static final int KEY_LEN_AES_128 = 128; // 0x80 + field public static final int KEY_LEN_AES_192 = 192; // 0xc0 + field public static final int KEY_LEN_AES_256 = 256; // 0x100 + field public static final int KEY_LEN_UNUSED = 0; // 0x0 + field public static final int PSEUDORANDOM_FUNCTION_AES128_XCBC = 4; // 0x4 + field public static final int PSEUDORANDOM_FUNCTION_HMAC_SHA1 = 2; // 0x2 + } + +} + package android.net.metrics { public final class ApfProgramEvent implements android.net.metrics.IpConnectivityLog.Event { From c4a5883fc51dadbccf2b6991d91189b8806b3ba9 Mon Sep 17 00:00:00 2001 From: evitayan Date: Mon, 11 Nov 2019 17:23:34 -0800 Subject: [PATCH 2/5] Expose IKE module API: IkeException, configuration & callback This commit updates system-current.txt to expose APIs including: - IkeException, IkeInternalException and IkeProtocolException - IkeSessionConfiguration and ChildSessionConfiguration - IkeSessionCallback and ChildSessionCallback Bug: 143983419 Test: make update-api && make Change-Id: I941be4dcbb31ef5781eb3f143c2211767b26f612 --- api/system-current.txt | 63 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) diff --git a/api/system-current.txt b/api/system-current.txt index 31b187ded2ee5..638f7783f27c3 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -4286,6 +4286,23 @@ package android.net.ipsec.ike { method @NonNull public android.net.ipsec.ike.ChildSaProposal build(); } + public interface ChildSessionCallback { + method public void onClosed(); + method public void onClosedExceptionally(@NonNull android.net.ipsec.ike.exceptions.IkeException); + method public void onIpSecTransformCreated(@NonNull android.net.IpSecTransform, int); + method public void onIpSecTransformDeleted(@NonNull android.net.IpSecTransform, int); + method public void onOpened(@NonNull android.net.ipsec.ike.ChildSessionConfiguration); + } + + public final class ChildSessionConfiguration { + method @NonNull public java.util.List getInboundTrafficSelectors(); + method @NonNull public java.util.List getInternalAddresses(); + method @NonNull public java.util.List getInternalDhcpServers(); + method @NonNull public java.util.List getInternalDnsServers(); + method @NonNull public java.util.List getInternalSubnets(); + method @NonNull public java.util.List getOutboundTrafficSelectors(); + } + public class IkeFqdnIdentification extends android.net.ipsec.ike.IkeIdentification { ctor public IkeFqdnIdentification(@NonNull String); field @NonNull public final String fqdn; @@ -4327,6 +4344,21 @@ package android.net.ipsec.ike { method @NonNull public android.net.ipsec.ike.IkeSaProposal build(); } + public interface IkeSessionCallback { + method public void onClosed(); + method public void onClosedExceptionally(@NonNull android.net.ipsec.ike.exceptions.IkeException); + method public void onError(@NonNull android.net.ipsec.ike.exceptions.IkeProtocolException); + method public void onOpened(@NonNull android.net.ipsec.ike.IkeSessionConfiguration); + } + + public final class IkeSessionConfiguration { + ctor public IkeSessionConfiguration(); + method @NonNull public String getRemoteApplicationVersion(); + method public boolean isIkeExtensionEnabled(int); + field public static final int EXTENSION_TYPE_FRAGMENTATION = 1; // 0x1 + field public static final int EXTENSION_TYPE_MOBIKE = 2; // 0x2 + } + public final class IkeTrafficSelector { ctor public IkeTrafficSelector(int, int, @NonNull java.net.InetAddress, @NonNull java.net.InetAddress); field public final int endPort; @@ -4363,6 +4395,37 @@ package android.net.ipsec.ike { } +package android.net.ipsec.ike.exceptions { + + public abstract class IkeException extends java.lang.Exception { + } + + public final class IkeInternalException extends android.net.ipsec.ike.exceptions.IkeException { + } + + public abstract class IkeProtocolException extends android.net.ipsec.ike.exceptions.IkeException { + method @Nullable public byte[] getErrorData(); + method public int getErrorType(); + field public static final int ERROR_TYPE_AUTHENTICATION_FAILED = 24; // 0x18 + field public static final int ERROR_TYPE_CHILD_SA_NOT_FOUND = 44; // 0x2c + field public static final int ERROR_TYPE_FAILED_CP_REQUIRED = 37; // 0x25 + field public static final int ERROR_TYPE_INTERNAL_ADDRESS_FAILURE = 36; // 0x24 + field public static final int ERROR_TYPE_INVALID_IKE_SPI = 4; // 0x4 + field public static final int ERROR_TYPE_INVALID_KE_PAYLOAD = 17; // 0x11 + field public static final int ERROR_TYPE_INVALID_MAJOR_VERSION = 5; // 0x5 + field public static final int ERROR_TYPE_INVALID_MESSAGE_ID = 9; // 0x9 + field public static final int ERROR_TYPE_INVALID_SELECTORS = 39; // 0x27 + field public static final int ERROR_TYPE_INVALID_SYNTAX = 7; // 0x7 + field public static final int ERROR_TYPE_NO_ADDITIONAL_SAS = 35; // 0x23 + field public static final int ERROR_TYPE_NO_PROPOSAL_CHOSEN = 14; // 0xe + field public static final int ERROR_TYPE_SINGLE_PAIR_REQUIRED = 34; // 0x22 + field public static final int ERROR_TYPE_TEMPORARY_FAILURE = 43; // 0x2b + field public static final int ERROR_TYPE_TS_UNACCEPTABLE = 38; // 0x26 + field public static final int ERROR_TYPE_UNSUPPORTED_CRITICAL_PAYLOAD = 1; // 0x1 + } + +} + package android.net.metrics { public final class ApfProgramEvent implements android.net.metrics.IpConnectivityLog.Event { From 39202c84a1adb6fd9e38c4157e780d11c98edd28 Mon Sep 17 00:00:00 2001 From: evitayan Date: Mon, 11 Nov 2019 18:11:59 -0800 Subject: [PATCH 3/5] Expose IKE module API: Session Options & EapSessionConfig This commit updates system-current to expose APIs including: - EapSessionConfig - IkeSessionOptions - ChildSessionOptions and its subclasses Bug: 143983419 Test: make update-api && make Change-Id: Ia97f3e3d507930957260d165de251834b43b84ea --- api/system-current.txt | 91 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 91 insertions(+) diff --git a/api/system-current.txt b/api/system-current.txt index 638f7783f27c3..e8f5d2981ee80 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -4273,6 +4273,48 @@ package android.net.apf { } +package android.net.eap { + + public final class EapSessionConfig { + } + + public static final class EapSessionConfig.Builder { + ctor public EapSessionConfig.Builder(); + method @NonNull public android.net.eap.EapSessionConfig build(); + method @NonNull public android.net.eap.EapSessionConfig.Builder setEapAkaConfig(int, int); + method @NonNull public android.net.eap.EapSessionConfig.Builder setEapAkaPrimeConfig(int, int, @NonNull String, boolean); + method @NonNull public android.net.eap.EapSessionConfig.Builder setEapIdentity(@NonNull byte[]); + method @NonNull public android.net.eap.EapSessionConfig.Builder setEapMsChapV2Config(@NonNull String, @NonNull String); + method @NonNull public android.net.eap.EapSessionConfig.Builder setEapSimConfig(int, int); + } + + public static class EapSessionConfig.EapAkaConfig extends android.net.eap.EapSessionConfig.EapUiccConfig { + } + + public static class EapSessionConfig.EapAkaPrimeConfig extends android.net.eap.EapSessionConfig.EapAkaConfig { + method public boolean allowsMismatchedNetworkNames(); + method @NonNull public String getNetworkName(); + } + + public abstract static class EapSessionConfig.EapMethodConfig { + method public int getMethodType(); + } + + public static class EapSessionConfig.EapMsChapV2Config extends android.net.eap.EapSessionConfig.EapMethodConfig { + method @NonNull public String getPassword(); + method @NonNull public String getUsername(); + } + + public static class EapSessionConfig.EapSimConfig extends android.net.eap.EapSessionConfig.EapUiccConfig { + } + + public abstract static class EapSessionConfig.EapUiccConfig extends android.net.eap.EapSessionConfig.EapMethodConfig { + method public int getAppType(); + method public int getSubId(); + } + +} + package android.net.ipsec.ike { public final class ChildSaProposal extends android.net.ipsec.ike.SaProposal { @@ -4303,6 +4345,9 @@ package android.net.ipsec.ike { method @NonNull public java.util.List getOutboundTrafficSelectors(); } + public abstract class ChildSessionOptions { + } + public class IkeFqdnIdentification extends android.net.ipsec.ike.IkeIdentification { ctor public IkeFqdnIdentification(@NonNull String); field @NonNull public final String fqdn; @@ -4359,6 +4404,23 @@ package android.net.ipsec.ike { field public static final int EXTENSION_TYPE_MOBIKE = 2; // 0x2 } + public final class IkeSessionOptions { + } + + public static final class IkeSessionOptions.Builder { + ctor public IkeSessionOptions.Builder(); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder addSaProposal(@NonNull android.net.ipsec.ike.IkeSaProposal); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions build(); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setAuthDigitalSignature(@NonNull java.security.cert.X509Certificate, @NonNull java.security.cert.X509Certificate, @NonNull java.security.PrivateKey); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setAuthDigitalSignature(@NonNull java.security.cert.X509Certificate, @NonNull java.security.cert.X509Certificate, @NonNull java.util.List, @NonNull java.security.PrivateKey); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setAuthEap(@NonNull java.security.cert.X509Certificate, @NonNull android.net.eap.EapSessionConfig); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setAuthPsk(@NonNull byte[]); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setLocalIdentification(@NonNull android.net.ipsec.ike.IkeIdentification); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setRemoteIdentification(@NonNull android.net.ipsec.ike.IkeIdentification); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setServerAddress(@NonNull java.net.InetAddress); + method @NonNull public android.net.ipsec.ike.IkeSessionOptions.Builder setUdpEncapsulationSocket(@NonNull android.net.IpSecManager.UdpEncapsulationSocket); + } + public final class IkeTrafficSelector { ctor public IkeTrafficSelector(int, int, @NonNull java.net.InetAddress, @NonNull java.net.InetAddress); field public final int endPort; @@ -4393,6 +4455,35 @@ package android.net.ipsec.ike { field public static final int PSEUDORANDOM_FUNCTION_HMAC_SHA1 = 2; // 0x2 } + public final class TransportModeChildSessionOptions extends android.net.ipsec.ike.ChildSessionOptions { + } + + public static final class TransportModeChildSessionOptions.Builder { + ctor public TransportModeChildSessionOptions.Builder(); + method @NonNull public android.net.ipsec.ike.TransportModeChildSessionOptions.Builder addInboundTrafficSelectors(@NonNull android.net.ipsec.ike.IkeTrafficSelector); + method @NonNull public android.net.ipsec.ike.TransportModeChildSessionOptions.Builder addOutboundTrafficSelectors(@NonNull android.net.ipsec.ike.IkeTrafficSelector); + method @NonNull public android.net.ipsec.ike.TransportModeChildSessionOptions.Builder addSaProposal(@NonNull android.net.ipsec.ike.ChildSaProposal); + method @NonNull public android.net.ipsec.ike.TransportModeChildSessionOptions build(); + } + + public final class TunnelModeChildSessionOptions extends android.net.ipsec.ike.ChildSessionOptions { + } + + public static final class TunnelModeChildSessionOptions.Builder { + ctor public TunnelModeChildSessionOptions.Builder(); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInboundTrafficSelectors(@NonNull android.net.ipsec.ike.IkeTrafficSelector); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalAddressRequest(int); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalAddressRequest(@NonNull java.net.InetAddress, int); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalDhcpServerRequest(int); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalDhcpServerRequest(@NonNull java.net.InetAddress); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalDnsServerRequest(int); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalDnsServerRequest(@NonNull java.net.InetAddress); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addInternalSubnetRequest(int); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addOutboundTrafficSelectors(@NonNull android.net.ipsec.ike.IkeTrafficSelector); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions.Builder addSaProposal(@NonNull android.net.ipsec.ike.ChildSaProposal); + method @NonNull public android.net.ipsec.ike.TunnelModeChildSessionOptions build(); + } + } package android.net.ipsec.ike.exceptions { From dce4df8a1969c02cd88269c7887dee376ffcb597 Mon Sep 17 00:00:00 2001 From: evitayan Date: Mon, 11 Nov 2019 19:51:53 -0800 Subject: [PATCH 4/5] Expose IKE module API: IkeManager and IkeSession This commit updates system-current to expose IkeManager and IkeSession Bug: 143983419 Test: make update-api && make Change-Id: Id1542a902aaa6c5da58bedea12f748586a41f9d1 --- api/system-current.txt | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/api/system-current.txt b/api/system-current.txt index e8f5d2981ee80..d1665649fbc1c 100644 --- a/api/system-current.txt +++ b/api/system-current.txt @@ -4389,6 +4389,14 @@ package android.net.ipsec.ike { method @NonNull public android.net.ipsec.ike.IkeSaProposal build(); } + public final class IkeSession implements java.lang.AutoCloseable { + ctor public IkeSession(@NonNull android.content.Context, @NonNull android.net.ipsec.ike.IkeSessionOptions, @NonNull android.net.ipsec.ike.ChildSessionOptions, @NonNull java.util.concurrent.Executor, @NonNull android.net.ipsec.ike.IkeSessionCallback, @NonNull android.net.ipsec.ike.ChildSessionCallback); + method public void close(); + method public void closeChildSession(@NonNull android.net.ipsec.ike.ChildSessionCallback); + method public void kill(); + method public void openChildSession(@NonNull android.net.ipsec.ike.ChildSessionOptions, @NonNull android.net.ipsec.ike.ChildSessionCallback); + } + public interface IkeSessionCallback { method public void onClosed(); method public void onClosedExceptionally(@NonNull android.net.ipsec.ike.exceptions.IkeException); From 1b70ca2b899ad1b882903f69763521516e6e0ef3 Mon Sep 17 00:00:00 2001 From: Benedict Wong Date: Tue, 19 Nov 2019 18:45:17 -0800 Subject: [PATCH 5/5] Add IKE to allowable zygote paths This change adds the IKE apex to the whitelist of open paths. Without this change, adding IKE to the boot classpath will fail. Bug: 143905344 Test: Compiles, doesn't fail. Change-Id: I63a2531e88b9d715e5089a6dc9fec721970d0de5 --- core/jni/fd_utils.cpp | 1 + 1 file changed, 1 insertion(+) diff --git a/core/jni/fd_utils.cpp b/core/jni/fd_utils.cpp index 3704ccdfb8ea2..8fabb23673182 100644 --- a/core/jni/fd_utils.cpp +++ b/core/jni/fd_utils.cpp @@ -34,6 +34,7 @@ // Static whitelist of open paths that the zygote is allowed to keep open. static const char* kPathWhitelist[] = { "/apex/com.android.conscrypt/javalib/conscrypt.jar", + "/apex/com.android.ipsec/javalib/ike.jar", "/apex/com.android.media/javalib/updatable-media.jar", "/dev/null", "/dev/socket/zygote",