Merge changes from topic "ikeparams-api-change"

* changes:
  Pass server address directly to IKE.
  Remove UdpEncapsulationSocket references in VPNs
This commit is contained in:
Yan Yan
2020-03-02 17:22:59 +00:00
committed by Gerrit Code Review
2 changed files with 9 additions and 33 deletions

View File

@@ -52,7 +52,6 @@ import android.net.Ikev2VpnProfile;
import android.net.IpPrefix; import android.net.IpPrefix;
import android.net.IpSecManager; import android.net.IpSecManager;
import android.net.IpSecManager.IpSecTunnelInterface; import android.net.IpSecManager.IpSecTunnelInterface;
import android.net.IpSecManager.UdpEncapsulationSocket;
import android.net.IpSecTransform; import android.net.IpSecTransform;
import android.net.LinkAddress; import android.net.LinkAddress;
import android.net.LinkProperties; import android.net.LinkProperties;
@@ -2197,7 +2196,6 @@ public class Vpn {
/** Signal to ensure shutdown is honored even if a new Network is connected. */ /** Signal to ensure shutdown is honored even if a new Network is connected. */
private boolean mIsRunning = true; private boolean mIsRunning = true;
@Nullable private UdpEncapsulationSocket mEncapSocket;
@Nullable private IpSecTunnelInterface mTunnelIface; @Nullable private IpSecTunnelInterface mTunnelIface;
@Nullable private IkeSession mSession; @Nullable private IkeSession mSession;
@Nullable private Network mActiveNetwork; @Nullable private Network mActiveNetwork;
@@ -2348,29 +2346,21 @@ public class Vpn {
resetIkeState(); resetIkeState();
mActiveNetwork = network; mActiveNetwork = network;
// TODO(b/149356682): Update this based on new IKE API
mEncapSocket = mIpSecManager.openUdpEncapsulationSocket();
// TODO(b/149356682): Update this based on new IKE API
final IkeSessionParams ikeSessionParams = final IkeSessionParams ikeSessionParams =
VpnIkev2Utils.buildIkeSessionParams(mProfile, mEncapSocket); VpnIkev2Utils.buildIkeSessionParams(mContext, mProfile, network);
final ChildSessionParams childSessionParams = final ChildSessionParams childSessionParams =
VpnIkev2Utils.buildChildSessionParams(); VpnIkev2Utils.buildChildSessionParams();
// TODO: Remove the need for adding two unused addresses with // TODO: Remove the need for adding two unused addresses with
// IPsec tunnels. // IPsec tunnels.
final InetAddress address = InetAddress.getLocalHost();
mTunnelIface = mTunnelIface =
mIpSecManager.createIpSecTunnelInterface( mIpSecManager.createIpSecTunnelInterface(
ikeSessionParams.getServerAddress() /* unused */, address /* unused */,
ikeSessionParams.getServerAddress() /* unused */, address /* unused */,
network); network);
mNetd.setInterfaceUp(mTunnelIface.getInterfaceName()); mNetd.setInterfaceUp(mTunnelIface.getInterfaceName());
// Socket must be bound to prevent network switches from causing
// the IKE teardown to fail/timeout.
// TODO(b/149356682): Update this based on new IKE API
network.bindSocket(mEncapSocket.getFileDescriptor());
mSession = mIkev2SessionCreator.createIkeSession( mSession = mIkev2SessionCreator.createIkeSession(
mContext, mContext,
ikeSessionParams, ikeSessionParams,
@@ -2455,16 +2445,6 @@ public class Vpn {
mSession.kill(); // Kill here to make sure all resources are released immediately mSession.kill(); // Kill here to make sure all resources are released immediately
mSession = null; mSession = null;
} }
// TODO(b/149356682): Update this based on new IKE API
if (mEncapSocket != null) {
try {
mEncapSocket.close();
} catch (IOException e) {
Log.e(TAG, "Failed to close encap socket", e);
}
mEncapSocket = null;
}
} }
/** /**

View File

@@ -35,10 +35,10 @@ import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_AES128_XCBC
import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1; import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1;
import android.annotation.NonNull; import android.annotation.NonNull;
import android.content.Context;
import android.net.Ikev2VpnProfile; import android.net.Ikev2VpnProfile;
import android.net.InetAddresses; import android.net.InetAddresses;
import android.net.IpPrefix; import android.net.IpPrefix;
import android.net.IpSecManager.UdpEncapsulationSocket;
import android.net.IpSecTransform; import android.net.IpSecTransform;
import android.net.Network; import android.net.Network;
import android.net.RouteInfo; import android.net.RouteInfo;
@@ -84,18 +84,14 @@ import java.util.List;
*/ */
public class VpnIkev2Utils { public class VpnIkev2Utils {
static IkeSessionParams buildIkeSessionParams( static IkeSessionParams buildIkeSessionParams(
@NonNull Ikev2VpnProfile profile, @NonNull UdpEncapsulationSocket socket) { @NonNull Context context, @NonNull Ikev2VpnProfile profile, @NonNull Network network) {
// TODO(b/149356682): Update this based on new IKE API. Only numeric addresses supported
// until then. All others throw IAE (caught by caller).
final InetAddress serverAddr = InetAddresses.parseNumericAddress(profile.getServerAddr());
final IkeIdentification localId = parseIkeIdentification(profile.getUserIdentity()); final IkeIdentification localId = parseIkeIdentification(profile.getUserIdentity());
final IkeIdentification remoteId = parseIkeIdentification(profile.getServerAddr()); final IkeIdentification remoteId = parseIkeIdentification(profile.getServerAddr());
// TODO(b/149356682): Update this based on new IKE API.
final IkeSessionParams.Builder ikeOptionsBuilder = final IkeSessionParams.Builder ikeOptionsBuilder =
new IkeSessionParams.Builder() new IkeSessionParams.Builder(context)
.setServerAddress(serverAddr) .setServerHostname(profile.getServerAddr())
.setUdpEncapsulationSocket(socket) .setNetwork(network)
.setLocalIdentification(localId) .setLocalIdentification(localId)
.setRemoteIdentification(remoteId); .setRemoteIdentification(remoteId);
setIkeAuth(profile, ikeOptionsBuilder); setIkeAuth(profile, ikeOptionsBuilder);