Merge changes from topic "ikeparams-api-change"
* changes: Pass server address directly to IKE. Remove UdpEncapsulationSocket references in VPNs
This commit is contained in:
@@ -52,7 +52,6 @@ import android.net.Ikev2VpnProfile;
|
|||||||
import android.net.IpPrefix;
|
import android.net.IpPrefix;
|
||||||
import android.net.IpSecManager;
|
import android.net.IpSecManager;
|
||||||
import android.net.IpSecManager.IpSecTunnelInterface;
|
import android.net.IpSecManager.IpSecTunnelInterface;
|
||||||
import android.net.IpSecManager.UdpEncapsulationSocket;
|
|
||||||
import android.net.IpSecTransform;
|
import android.net.IpSecTransform;
|
||||||
import android.net.LinkAddress;
|
import android.net.LinkAddress;
|
||||||
import android.net.LinkProperties;
|
import android.net.LinkProperties;
|
||||||
@@ -2197,7 +2196,6 @@ public class Vpn {
|
|||||||
/** Signal to ensure shutdown is honored even if a new Network is connected. */
|
/** Signal to ensure shutdown is honored even if a new Network is connected. */
|
||||||
private boolean mIsRunning = true;
|
private boolean mIsRunning = true;
|
||||||
|
|
||||||
@Nullable private UdpEncapsulationSocket mEncapSocket;
|
|
||||||
@Nullable private IpSecTunnelInterface mTunnelIface;
|
@Nullable private IpSecTunnelInterface mTunnelIface;
|
||||||
@Nullable private IkeSession mSession;
|
@Nullable private IkeSession mSession;
|
||||||
@Nullable private Network mActiveNetwork;
|
@Nullable private Network mActiveNetwork;
|
||||||
@@ -2348,29 +2346,21 @@ public class Vpn {
|
|||||||
resetIkeState();
|
resetIkeState();
|
||||||
mActiveNetwork = network;
|
mActiveNetwork = network;
|
||||||
|
|
||||||
// TODO(b/149356682): Update this based on new IKE API
|
|
||||||
mEncapSocket = mIpSecManager.openUdpEncapsulationSocket();
|
|
||||||
|
|
||||||
// TODO(b/149356682): Update this based on new IKE API
|
|
||||||
final IkeSessionParams ikeSessionParams =
|
final IkeSessionParams ikeSessionParams =
|
||||||
VpnIkev2Utils.buildIkeSessionParams(mProfile, mEncapSocket);
|
VpnIkev2Utils.buildIkeSessionParams(mContext, mProfile, network);
|
||||||
final ChildSessionParams childSessionParams =
|
final ChildSessionParams childSessionParams =
|
||||||
VpnIkev2Utils.buildChildSessionParams();
|
VpnIkev2Utils.buildChildSessionParams();
|
||||||
|
|
||||||
// TODO: Remove the need for adding two unused addresses with
|
// TODO: Remove the need for adding two unused addresses with
|
||||||
// IPsec tunnels.
|
// IPsec tunnels.
|
||||||
|
final InetAddress address = InetAddress.getLocalHost();
|
||||||
mTunnelIface =
|
mTunnelIface =
|
||||||
mIpSecManager.createIpSecTunnelInterface(
|
mIpSecManager.createIpSecTunnelInterface(
|
||||||
ikeSessionParams.getServerAddress() /* unused */,
|
address /* unused */,
|
||||||
ikeSessionParams.getServerAddress() /* unused */,
|
address /* unused */,
|
||||||
network);
|
network);
|
||||||
mNetd.setInterfaceUp(mTunnelIface.getInterfaceName());
|
mNetd.setInterfaceUp(mTunnelIface.getInterfaceName());
|
||||||
|
|
||||||
// Socket must be bound to prevent network switches from causing
|
|
||||||
// the IKE teardown to fail/timeout.
|
|
||||||
// TODO(b/149356682): Update this based on new IKE API
|
|
||||||
network.bindSocket(mEncapSocket.getFileDescriptor());
|
|
||||||
|
|
||||||
mSession = mIkev2SessionCreator.createIkeSession(
|
mSession = mIkev2SessionCreator.createIkeSession(
|
||||||
mContext,
|
mContext,
|
||||||
ikeSessionParams,
|
ikeSessionParams,
|
||||||
@@ -2455,16 +2445,6 @@ public class Vpn {
|
|||||||
mSession.kill(); // Kill here to make sure all resources are released immediately
|
mSession.kill(); // Kill here to make sure all resources are released immediately
|
||||||
mSession = null;
|
mSession = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
// TODO(b/149356682): Update this based on new IKE API
|
|
||||||
if (mEncapSocket != null) {
|
|
||||||
try {
|
|
||||||
mEncapSocket.close();
|
|
||||||
} catch (IOException e) {
|
|
||||||
Log.e(TAG, "Failed to close encap socket", e);
|
|
||||||
}
|
|
||||||
mEncapSocket = null;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -35,10 +35,10 @@ import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_AES128_XCBC
|
|||||||
import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1;
|
import static android.net.ipsec.ike.SaProposal.PSEUDORANDOM_FUNCTION_HMAC_SHA1;
|
||||||
|
|
||||||
import android.annotation.NonNull;
|
import android.annotation.NonNull;
|
||||||
|
import android.content.Context;
|
||||||
import android.net.Ikev2VpnProfile;
|
import android.net.Ikev2VpnProfile;
|
||||||
import android.net.InetAddresses;
|
import android.net.InetAddresses;
|
||||||
import android.net.IpPrefix;
|
import android.net.IpPrefix;
|
||||||
import android.net.IpSecManager.UdpEncapsulationSocket;
|
|
||||||
import android.net.IpSecTransform;
|
import android.net.IpSecTransform;
|
||||||
import android.net.Network;
|
import android.net.Network;
|
||||||
import android.net.RouteInfo;
|
import android.net.RouteInfo;
|
||||||
@@ -84,18 +84,14 @@ import java.util.List;
|
|||||||
*/
|
*/
|
||||||
public class VpnIkev2Utils {
|
public class VpnIkev2Utils {
|
||||||
static IkeSessionParams buildIkeSessionParams(
|
static IkeSessionParams buildIkeSessionParams(
|
||||||
@NonNull Ikev2VpnProfile profile, @NonNull UdpEncapsulationSocket socket) {
|
@NonNull Context context, @NonNull Ikev2VpnProfile profile, @NonNull Network network) {
|
||||||
// TODO(b/149356682): Update this based on new IKE API. Only numeric addresses supported
|
|
||||||
// until then. All others throw IAE (caught by caller).
|
|
||||||
final InetAddress serverAddr = InetAddresses.parseNumericAddress(profile.getServerAddr());
|
|
||||||
final IkeIdentification localId = parseIkeIdentification(profile.getUserIdentity());
|
final IkeIdentification localId = parseIkeIdentification(profile.getUserIdentity());
|
||||||
final IkeIdentification remoteId = parseIkeIdentification(profile.getServerAddr());
|
final IkeIdentification remoteId = parseIkeIdentification(profile.getServerAddr());
|
||||||
|
|
||||||
// TODO(b/149356682): Update this based on new IKE API.
|
|
||||||
final IkeSessionParams.Builder ikeOptionsBuilder =
|
final IkeSessionParams.Builder ikeOptionsBuilder =
|
||||||
new IkeSessionParams.Builder()
|
new IkeSessionParams.Builder(context)
|
||||||
.setServerAddress(serverAddr)
|
.setServerHostname(profile.getServerAddr())
|
||||||
.setUdpEncapsulationSocket(socket)
|
.setNetwork(network)
|
||||||
.setLocalIdentification(localId)
|
.setLocalIdentification(localId)
|
||||||
.setRemoteIdentification(remoteId);
|
.setRemoteIdentification(remoteId);
|
||||||
setIkeAuth(profile, ikeOptionsBuilder);
|
setIkeAuth(profile, ikeOptionsBuilder);
|
||||||
|
|||||||
Reference in New Issue
Block a user