Merge "Add a new API startProvisionedVpnProfileSession()"

This commit is contained in:
Lucas Lin
2022-02-09 01:12:03 +00:00
committed by Gerrit Code Review
5 changed files with 30 additions and 8 deletions

View File

@@ -25606,7 +25606,8 @@ package android.net {
public class VpnManager { public class VpnManager {
method public void deleteProvisionedVpnProfile(); method public void deleteProvisionedVpnProfile();
method @Nullable public android.content.Intent provisionVpnProfile(@NonNull android.net.PlatformVpnProfile); method @Nullable public android.content.Intent provisionVpnProfile(@NonNull android.net.PlatformVpnProfile);
method public void startProvisionedVpnProfile(); method @Deprecated public void startProvisionedVpnProfile();
method @NonNull public String startProvisionedVpnProfileSession();
method public void stopProvisionedVpnProfile(); method public void stopProvisionedVpnProfile();
} }

View File

@@ -38,7 +38,7 @@ interface IVpnManager {
/** VpnManager APIs */ /** VpnManager APIs */
boolean provisionVpnProfile(in VpnProfile profile, String packageName); boolean provisionVpnProfile(in VpnProfile profile, String packageName);
void deleteVpnProfile(String packageName); void deleteVpnProfile(String packageName);
void startVpnProfile(String packageName); String startVpnProfile(String packageName);
void stopVpnProfile(String packageName); void stopVpnProfile(String packageName);
/** Always-on VPN APIs */ /** Always-on VPN APIs */

View File

@@ -317,17 +317,32 @@ public class VpnManager {
/** /**
* Request the startup of a previously provisioned VPN. * Request the startup of a previously provisioned VPN.
* *
* @return A unique key corresponding to this session.
* @throws SecurityException exception if user or device settings prevent this VPN from being * @throws SecurityException exception if user or device settings prevent this VPN from being
* setup, or if user consent has not been granted * setup, or if user consent has not been granted
*/ */
public void startProvisionedVpnProfile() { @NonNull
public String startProvisionedVpnProfileSession() {
try { try {
mService.startVpnProfile(mContext.getOpPackageName()); return mService.startVpnProfile(mContext.getOpPackageName());
} catch (RemoteException e) { } catch (RemoteException e) {
throw e.rethrowFromSystemServer(); throw e.rethrowFromSystemServer();
} }
} }
/**
* Request the startup of a previously provisioned VPN.
*
* @throws SecurityException exception if user or device settings prevent this VPN from being
* setup, or if user consent has not been granted
* @deprecated This method is replaced by startProvisionedVpnProfileSession which returns a
* session key for the caller to diagnose the errors.
*/
@Deprecated
public void startProvisionedVpnProfile() {
startProvisionedVpnProfileSession();
}
/** Tear down the VPN provided by the calling app (if any) */ /** Tear down the VPN provided by the calling app (if any) */
public void stopProvisionedVpnProfile() { public void stopProvisionedVpnProfile() {
try { try {

View File

@@ -340,17 +340,18 @@ public class VpnManagerService extends IVpnManager.Stub {
* <p>This is designed to serve the VpnManager only; settings-based VPN profiles are managed * <p>This is designed to serve the VpnManager only; settings-based VPN profiles are managed
* exclusively by the Settings app, and passed into the platform at startup time. * exclusively by the Settings app, and passed into the platform at startup time.
* *
* @return A unique key corresponding to this session.
* @throws IllegalArgumentException if no profile was found for the given package name. * @throws IllegalArgumentException if no profile was found for the given package name.
* @hide * @hide
*/ */
@Override @Override
public void startVpnProfile(@NonNull String packageName) { public String startVpnProfile(@NonNull String packageName) {
final int callingUid = Binder.getCallingUid(); final int callingUid = Binder.getCallingUid();
verifyCallingUidAndPackage(packageName, callingUid); verifyCallingUidAndPackage(packageName, callingUid);
final int user = UserHandle.getUserId(callingUid); final int user = UserHandle.getUserId(callingUid);
synchronized (mVpns) { synchronized (mVpns) {
throwIfLockdownEnabled(); throwIfLockdownEnabled();
mVpns.get(user).startVpnProfile(packageName); return mVpns.get(user).startVpnProfile(packageName);
} }
} }

View File

@@ -151,6 +151,7 @@ import java.util.Objects;
import java.util.Set; import java.util.Set;
import java.util.SortedSet; import java.util.SortedSet;
import java.util.TreeSet; import java.util.TreeSet;
import java.util.UUID;
import java.util.concurrent.CompletableFuture; import java.util.concurrent.CompletableFuture;
import java.util.concurrent.ExecutionException; import java.util.concurrent.ExecutionException;
import java.util.concurrent.Executor; import java.util.concurrent.Executor;
@@ -203,6 +204,7 @@ public class Vpn {
private final NetworkInfo mNetworkInfo; private final NetworkInfo mNetworkInfo;
private int mLegacyState; private int mLegacyState;
@VisibleForTesting protected String mPackage; @VisibleForTesting protected String mPackage;
private String mSessionKey;
private int mOwnerUID; private int mOwnerUID;
private boolean mIsPackageTargetingAtLeastQ; private boolean mIsPackageTargetingAtLeastQ;
@VisibleForTesting @VisibleForTesting
@@ -2503,6 +2505,7 @@ public class Vpn {
mProfile = profile; mProfile = profile;
mIpSecManager = (IpSecManager) mContext.getSystemService(Context.IPSEC_SERVICE); mIpSecManager = (IpSecManager) mContext.getSystemService(Context.IPSEC_SERVICE);
mNetworkCallback = new VpnIkev2Utils.Ikev2VpnNetworkCallback(TAG, this); mNetworkCallback = new VpnIkev2Utils.Ikev2VpnNetworkCallback(TAG, this);
mSessionKey = UUID.randomUUID().toString();
} }
@Override @Override
@@ -2824,6 +2827,7 @@ public class Vpn {
*/ */
private void disconnectVpnRunner() { private void disconnectVpnRunner() {
mActiveNetwork = null; mActiveNetwork = null;
mSessionKey = null;
mIsRunning = false; mIsRunning = false;
resetIkeState(); resetIkeState();
@@ -3314,7 +3318,7 @@ public class Vpn {
* *
* @param packageName the package name of the app provisioning this profile * @param packageName the package name of the app provisioning this profile
*/ */
public synchronized void startVpnProfile(@NonNull String packageName) { public synchronized String startVpnProfile(@NonNull String packageName) {
requireNonNull(packageName, "No package name provided"); requireNonNull(packageName, "No package name provided");
enforceNotRestrictedUser(); enforceNotRestrictedUser();
@@ -3332,6 +3336,7 @@ public class Vpn {
} }
startVpnProfilePrivileged(profile, packageName); startVpnProfilePrivileged(profile, packageName);
return mSessionKey;
} finally { } finally {
Binder.restoreCallingIdentity(token); Binder.restoreCallingIdentity(token);
} }