From 8b555224badfd81bc53dc4e0a5ef25226f0c053b Mon Sep 17 00:00:00 2001 From: Benedict Wong Date: Mon, 17 Feb 2020 16:36:18 -0800 Subject: [PATCH 1/2] Remove UdpEncapsulationSocket references in VPNs This changes the IkeSessionParams generation to set a specific Network, and no longer passes a UDP encapsulation socket. Bug: 149356682 Test: FrameworksNetTests passing. Change-Id: I69f184762490b1dd3d3261d00c81fd32bbebddfc Merged-In: I69f184762490b1dd3d3261d00c81fd32bbebddfc (cherry picked from commit 818dca1aad37e4e398e5707cdf4a19bf1fc77126) --- .../com/android/server/connectivity/Vpn.java | 23 +------------------ .../server/connectivity/VpnIkev2Utils.java | 8 +++---- 2 files changed, 5 insertions(+), 26 deletions(-) diff --git a/services/core/java/com/android/server/connectivity/Vpn.java b/services/core/java/com/android/server/connectivity/Vpn.java index e484ca0a24879..97502c8001d19 100644 --- a/services/core/java/com/android/server/connectivity/Vpn.java +++ b/services/core/java/com/android/server/connectivity/Vpn.java @@ -52,7 +52,6 @@ import android.net.Ikev2VpnProfile; import android.net.IpPrefix; import android.net.IpSecManager; import android.net.IpSecManager.IpSecTunnelInterface; -import android.net.IpSecManager.UdpEncapsulationSocket; import android.net.IpSecTransform; import android.net.LinkAddress; import android.net.LinkProperties; @@ -2201,7 +2200,6 @@ public class Vpn { /** Signal to ensure shutdown is honored even if a new Network is connected. */ private boolean mIsRunning = true; - @Nullable private UdpEncapsulationSocket mEncapSocket; @Nullable private IpSecTunnelInterface mTunnelIface; @Nullable private IkeSession mSession; @Nullable private Network mActiveNetwork; @@ -2352,12 +2350,8 @@ public class Vpn { resetIkeState(); mActiveNetwork = network; - // TODO(b/149356682): Update this based on new IKE API - mEncapSocket = mIpSecManager.openUdpEncapsulationSocket(); - - // TODO(b/149356682): Update this based on new IKE API final IkeSessionParams ikeSessionParams = - VpnIkev2Utils.buildIkeSessionParams(mProfile, mEncapSocket); + VpnIkev2Utils.buildIkeSessionParams(mContext, mProfile, network); final ChildSessionParams childSessionParams = VpnIkev2Utils.buildChildSessionParams(); @@ -2370,11 +2364,6 @@ public class Vpn { network); mNetd.setInterfaceUp(mTunnelIface.getInterfaceName()); - // Socket must be bound to prevent network switches from causing - // the IKE teardown to fail/timeout. - // TODO(b/149356682): Update this based on new IKE API - network.bindSocket(mEncapSocket.getFileDescriptor()); - mSession = mIkev2SessionCreator.createIkeSession( mContext, ikeSessionParams, @@ -2459,16 +2448,6 @@ public class Vpn { mSession.kill(); // Kill here to make sure all resources are released immediately mSession = null; } - - // TODO(b/149356682): Update this based on new IKE API - if (mEncapSocket != null) { - try { - mEncapSocket.close(); - } catch (IOException e) { - Log.e(TAG, "Failed to close encap socket", e); - } - mEncapSocket = null; - } } /** diff --git a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java index 33fc32b78df71..1e20ae752709b 100644 --- a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java +++ b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java @@ -35,10 +35,10 @@ import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_AES128_XCBC import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1; import android.annotation.NonNull; +import android.content.Context; import android.net.Ikev2VpnProfile; import android.net.InetAddresses; import android.net.IpPrefix; -import android.net.IpSecManager.UdpEncapsulationSocket; import android.net.IpSecTransform; import android.net.Network; import android.net.RouteInfo; @@ -84,7 +84,7 @@ import java.util.List; */ public class VpnIkev2Utils { static IkeSessionParams buildIkeSessionParams( - @NonNull Ikev2VpnProfile profile, @NonNull UdpEncapsulationSocket socket) { + @NonNull Context context, @NonNull Ikev2VpnProfile profile, @NonNull Network network) { // TODO(b/149356682): Update this based on new IKE API. Only numeric addresses supported // until then. All others throw IAE (caught by caller). final InetAddress serverAddr = InetAddresses.parseNumericAddress(profile.getServerAddr()); @@ -93,9 +93,9 @@ public class VpnIkev2Utils { // TODO(b/149356682): Update this based on new IKE API. final IkeSessionParams.Builder ikeOptionsBuilder = - new IkeSessionParams.Builder() + new IkeSessionParams.Builder(context) .setServerAddress(serverAddr) - .setUdpEncapsulationSocket(socket) + .setNetwork(network) .setLocalIdentification(localId) .setRemoteIdentification(remoteId); setIkeAuth(profile, ikeOptionsBuilder); From a9159882e5d88a47a945cf54c4e2245bc193b24d Mon Sep 17 00:00:00 2001 From: Benedict Wong Date: Mon, 17 Feb 2020 17:46:23 -0800 Subject: [PATCH 2/2] Pass server address directly to IKE. This change updates the buildIkeSessionParams() method to use the new IKE API that allows the VPN to pass the server address, and let IKE do the DNS resolution. Bug: 149356682 Test: FrameworksNetTests passing Change-Id: Ic1077c6eb1f49bca9331e49555b3787cee02788c Merged-In: Ic1077c6eb1f49bca9331e49555b3787cee02788c (cherry picked from commit fe975fea5d228514fd19f95e56859d5c98433f7d) --- services/core/java/com/android/server/connectivity/Vpn.java | 5 +++-- .../java/com/android/server/connectivity/VpnIkev2Utils.java | 6 +----- 2 files changed, 4 insertions(+), 7 deletions(-) diff --git a/services/core/java/com/android/server/connectivity/Vpn.java b/services/core/java/com/android/server/connectivity/Vpn.java index 97502c8001d19..968528ca5b29d 100644 --- a/services/core/java/com/android/server/connectivity/Vpn.java +++ b/services/core/java/com/android/server/connectivity/Vpn.java @@ -2357,10 +2357,11 @@ public class Vpn { // TODO: Remove the need for adding two unused addresses with // IPsec tunnels. + final InetAddress address = InetAddress.getLocalHost(); mTunnelIface = mIpSecManager.createIpSecTunnelInterface( - ikeSessionParams.getServerAddress() /* unused */, - ikeSessionParams.getServerAddress() /* unused */, + address /* unused */, + address /* unused */, network); mNetd.setInterfaceUp(mTunnelIface.getInterfaceName()); diff --git a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java index 1e20ae752709b..3da304c07910e 100644 --- a/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java +++ b/services/core/java/com/android/server/connectivity/VpnIkev2Utils.java @@ -85,16 +85,12 @@ import java.util.List; public class VpnIkev2Utils { static IkeSessionParams buildIkeSessionParams( @NonNull Context context, @NonNull Ikev2VpnProfile profile, @NonNull Network network) { - // TODO(b/149356682): Update this based on new IKE API. Only numeric addresses supported - // until then. All others throw IAE (caught by caller). - final InetAddress serverAddr = InetAddresses.parseNumericAddress(profile.getServerAddr()); final IkeIdentification localId = parseIkeIdentification(profile.getUserIdentity()); final IkeIdentification remoteId = parseIkeIdentification(profile.getServerAddr()); - // TODO(b/149356682): Update this based on new IKE API. final IkeSessionParams.Builder ikeOptionsBuilder = new IkeSessionParams.Builder(context) - .setServerAddress(serverAddr) + .setServerHostname(profile.getServerAddr()) .setNetwork(network) .setLocalIdentification(localId) .setRemoteIdentification(remoteId);