Commit Graph

5927 Commits

Author SHA1 Message Date
Benedict Wong
d7d2d2a15b Merge changes from topic "vcn-fwd"
* changes:
  Apply transform to FWD policy if configured to provide tethering
  Add internal support for IPsec forward policies
2021-05-11 01:30:31 +00:00
Benedict Wong
1d9c19a635 Add additional logging to improve debugability of VcnManagementService
Test: atest FrameworksVcnTests
Change-Id: I23af20ea655e11934f6ac679c1bfc0943d5a148f
2021-05-07 17:18:21 -07:00
Benedict Wong
7f5a2fe728 Add internal support for IPsec forward policies
This change adds support for IPsec forward policies, which are necessary
for packets to be allowed to be forwarded to another interface, as is
the case with tethering. This is necessary and useful only within the
system server, and as such is not exposed as a public API.

This change is safe, since the addition of a FWD policy on IPsec tunnel
interfaces will by default block forwarded traffic (as would be the case
without this patch). In the event that the (system) owner of the tunnel
requires support for forwarded packets (eg tethering), this patch allows
application of transforms in the FWD direction as well.

This will be used to ensure that the VCN can be used as the underlying
network for the purposes of tethering.

Bug: 185495453
Test: atest IpSecServiceTest
Test: atest IpSecServiceParameterizedTest
Test: manual testing with tethering over VCN
Change-Id: I74ecea71f1954029f6fbdbe34598c82e0aac386b
2021-05-07 15:09:42 -07:00
Treehugger Robot
2f83b6a72d Merge "Add getters to NetworkStateSnapshot" 2021-04-29 09:20:34 +00:00
Treehugger Robot
e2e8b9ce88 Merge "Add getters to UnderlyingNetworkInfo" 2021-04-29 07:29:08 +00:00
Benedict Wong
c6fe30068d Merge "Update set|getRetryIntervalsMs to Millis" 2021-04-29 04:35:45 +00:00
Benedict Wong
913ae2b89b Allow VcnTransportInfo to be parcelled
Allows VCN transport info to be parcelled for purposes of sysUI

Bug: 186025257
Test: atest FrameworksVcnTests
Change-Id: I5a5d9b88659c8dcaa9ded16d491b2bac0529169a
2021-04-27 17:35:44 -07:00
Benedict Wong
e7f06d9eb9 Update set|getRetryIntervalsMs to Millis
Bug: 184612525
Test: atest FrameworksVcnTests
Change-Id: I696854960ca9488ae2c8a0c569c57a8563998ac8
2021-04-27 22:28:43 +00:00
Yan Yan
b8f67d1bd7 Merge "Remove TunnelConnectionParams interface" 2021-04-27 18:34:08 +00:00
Les Lee
bef2f5be94 Merge "wifi data usage: support to get carrier merged wifi network." 2021-04-27 02:13:32 +00:00
Yan Yan
de7222cba5 Remove TunnelConnectionParams interface
To avoid exposing empty interface.

Test: atest FrameworksVcnTests
Bug: 180664474
Change-Id: Ia33e75b77f1563a1c3d31e0145b7ec2be728b6db
2021-04-26 10:47:05 -07:00
Aaron Huang
7511be401e Add getters to UnderlyingNetworkInfo
Address API review feedback, add getters to UnderlyingNetworkInfo
instead of exposing fields.

Instead of wasting memory by converting this into an array, have
migrateTun take a List<String>. In turn, tunAdjustmentInit should
also take a List<String>.

(cherry picked from ag/14211075)
Bug: 183972554
Test: atest android.net.UnderlyingNetworkInfoTest
Merged-In: Id59744097208d91298a25ef110ade91a9cf291a1
Change-Id: Id59744097208d91298a25ef110ade91a9cf291a1
2021-04-22 22:30:42 +08:00
Aaron Huang
a3ae9b1c38 Add getters to NetworkStateSnapshot
Address API council feedback, add getters to NetworkStateSnapshot
instead of exposing the bare fields directly.

(cherry picked from ag/14233655)
Bug: 183972826
Test: FrameworksNetTests
Merged-In: Id1707753b42ae88d2b95e4bd00a792609434e4f5
Change-Id: Id1707753b42ae88d2b95e4bd00a792609434e4f5
2021-04-22 18:21:00 +08:00
Yan Yan
bc545c8a8a Merge changes from topics "encrypted-tunnel-interface", "iketunnelparams", "vcn-encrypted-tunnel"
* changes:
  Replace VcnControlPlaneConfig with TunnelConnectionParams
  Convert TunnelConnectionParams to/from PersistableBundle
  Create TunnelConnectionParams interface
2021-04-22 08:39:20 +00:00
Yan Yan
4eaa894d84 Replace VcnControlPlaneConfig with TunnelConnectionParams
Use the more generic object TunnelConnectionParams in VCN.
TunnelConnectionParams may also be used in VPN in the future.

Test: atest FrameworksVcnTests
Bug: 180664474
Change-Id: Ie433f9df614e1f51cdff200d915b68b61e5ca35e
2021-04-21 22:52:22 -07:00
Yan Yan
c0b7c4fa5a Convert TunnelConnectionParams to/from PersistableBundle
Add utility class to convert TunnelConnectionParams to and from
PersistableBundle.

Bug: 180664474
Test: atest EncryptedTunnelParamsUtilsTest
Change-Id: I93ae068eb6d1e1c4d3fcbaccbaae867db8d07a38
2021-04-21 22:49:47 -07:00
Yan Yan
83956e2a5d Create TunnelConnectionParams interface
TunnelConnectionParams represents configurations for setting up a
secure encrypted tunnel with a remote endpoint. TunnelConnectionParams
will be used to configure a VCN and will be used for VPN configuration
in the future.

Bug: 180664474
Test: make update-api
Change-Id: Ic8e5c8535e84971517f16c54ce8b8645cfc7f944
2021-04-21 22:48:21 -07:00
Lorenzo Colitti
0549ca0217 Merge "Hide NetworkPolicyManager.blockedReasonsToString API." 2021-04-22 02:36:11 +00:00
Benedict Wong
80afe1eeee Merge changes I64b56575,I40553a7b
* changes:
  Expose API for retrieval of subscription groups with VCN configured
  Add support for retrieval of configured VCNs by carrier privilege
2021-04-22 01:31:11 +00:00
Benedict Wong
d776b3762e Expose API for retrieval of subscription groups with VCN configured
Per API council feedback, this change adds a new API to retrieve all
subscription groups that have a VCN configured.

Bug: 184612525
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I64b565758e0a27552eee9f860e0674db2fb35980
2021-04-21 13:49:35 -07:00
Benedict Wong
6e8c1d6da7 Add support for retrieval of configured VCNs by carrier privilege
This change adds support for retrieval of a list of subscription groups
that have a VCN configured.

Bug: 184612525
Test: atest FrameworksVcnTests
Change-Id: I40553a7bb45d9b1f948c7d0a791f1b22a422d55c
2021-04-21 13:49:14 -07:00
Yan Yan
c65ed07b59 Merge "Include PORT_4500 option when encoding IkeSessionParams" 2021-04-21 18:08:33 +00:00
Sudheer Shanka
00f344a18e Hide NetworkPolicyManager.blockedReasonsToString API.
BLOCKED_REASON_* constants have been moved to ConnectivityManager
and blockedReasonsToString() util method doesn't belong in
NetworkPolicyManager as an API. So, just removing it for now.

Bug: 185967486
Test: treehugger
Change-Id: Ie04044980fdfc7ec772444be13fc659880953bd1
2021-04-21 07:23:54 +00:00
Benedict Wong
85d294282c Rename get/setRetryInterval to get/setRetryIntervalsMs
Per API feedback, the get/set methods for retry intervals are renamed to
be plural, and have time units

Bug: 184612525
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I51b3ffcfa44f72805f359e56b263da2558325372
2021-04-21 00:44:37 +00:00
Yan Yan
c130a2a8b1 Include PORT_4500 option when encoding IkeSessionParams
This commit makes sure IKE_OPTION_FORCE_PORT_4500 is included
when converting IkeSessionParams to a PersistableBundle.

Bug: 185637142
Test: atest IkeSessionParamsUtilsTest
Change-Id: I1fcd6d26e64217091ad960a1c51659046e70a6ac
2021-04-20 16:41:00 -07:00
Yan Yan
3022c5437c Merge "Use #setNetwork and #getNetwork for IkeSessionParams" 2021-04-19 17:04:25 +00:00
lesl
f4c0625458 wifi data usage: support to get carrier merged wifi network.
Carrier merged wifi network is a specific cerrier wifi network
which provides the same user experience as mobile.

To support data usage accounting for carrier merged wifi,
the change provide several APIs in NetworkTemplate:

  1. extend buildTemplateWifi so it could be used for matching
     wifi networks with subscriber Id (IMSI).
  2. add buildTemplateCarrier to let
     NetworkPolicyManagerService creates a single policy for
     a given carrier regardless of network type.

Bug: 176396812
Test: atest -c NetworkTemplateTest
Test: atest -c NetworkStatsServiceTest
Test: Manual Test with test code on mobile and wifi network.
      1. buildTemplateCarrier includes the carrier wifi and
         mobile usage
      2. buildTemplateWifi can get carrier wifi usage and support the
         filter via subscriberId

Change-Id: I667b4adf3eec0bdd3a7385109dd8c1fae8e7be32
2021-04-19 16:13:27 +08:00
Paul Hu
e87f10b9a6 Merge "Add NWM#getWatchlistConfigHash to test api for testing" 2021-04-16 08:10:33 +00:00
Lorenzo Colitti
103e78ed48 Don't expose raw IBinder APIs.
APIs should not expose raw IBinder objects.

Fix: 184735751
Test: builds, boots
Test: atest CtsNetTestCases:android.net.cts.ConnectivityManagerTest
Test: atest CtsNetTestCases:android.net.cts.DnsResolverTest
Change-Id: Ia0c4170def31123f0b79318fec2cfe02e4fcd3bf
2021-04-15 18:47:21 +09:00
paulhu
675ffd271b Add NWM#getWatchlistConfigHash to test api for testing
Bug: 185309847
Test: m update-api
Change-Id: I4fb1503827b3a9e3105c2340ffbaaa2ec593d96b
2021-04-14 23:54:55 +08:00
Lorenzo Colitti
fb7f36b3cb Make TYPE_VPN_LEGACY no longer deprecated.
Addresses API council feedback.

Test: m
Fix: 185311050
Change-Id: I93c8c46ceda7b08f9fc0ab8930f6a3c960f30930
2021-04-14 23:30:48 +09:00
Yan Yan
66a9973b9d Use #setNetwork and #getNetwork for IkeSessionParams
This pacth changes VCN to call #setNetwork and #getNetwork instead
of #setConfiguredNetwork and #getConfiguredNetwork because the
later two methods will not be APIs.

This patch also changes VCN unit tests to build an IkeSessionParams
without a Context because the constructor requring a Context
is deprecated.

Bug: 180521384
Test: FrameworksVcnTests, CtsVcnTestCases
Change-Id: I971d0d1b6824890c58263a1960f3b8d0e66fe7d1
2021-04-13 21:46:53 -07:00
Treehugger Robot
682a98d823 Merge "Add documentation on EthernetNetworkSpecifier API" 2021-04-09 01:26:54 +00:00
Remi NGUYEN VAN
f9dae9fec6 Add documentation on EthernetNetworkSpecifier API
Add javadoc on the constructor and getInterfaceName method.

Fixes: 182979732
Test: m
Change-Id: Iced805149a8344b953331501b48184661be0053a
2021-04-08 15:32:08 +09:00
Sudheer Shanka
d01e3f164d Fix an issue in NPMS where ALLOWED_REASON_SYSTEM will be ignored.
Bug: 184701934
Test: atest services/tests/servicestests/src/com/android/server/net/NetworkPolicyManagerServiceTest.java
Change-Id: Ic430eed075f466e1c50552053a100809a2780ba7
Merged-In: Ic430eed075f466e1c50552053a100809a2780ba7
2021-04-07 05:11:25 +00:00
Les Lee
cadd76044e Merge "Fix Wi-Fi SSID null handling" 2021-04-06 03:52:52 +00:00
Paul Hu
7cd588e210 Merge "Remove unused method checkUidNetworkingBlocked" 2021-04-06 01:49:57 +00:00
Cody Kesting
36a84ebbaf Merge "Clarify docs for status codes in VcnStatusCallback." 2021-04-02 01:24:25 +00:00
Cody Kesting
03f00e5a52 Merge changes from topic "gateway-connection-id"
* changes:
  Expose API for identifying GatewayConnections.
  Update identification for onGatewayConnectionError().
2021-04-01 18:27:28 +00:00
Cody Kesting
24aa7bc5cb Clarify docs for status codes in VcnStatusCallback.
This CL clarifies the documentation for status codes used in
VcnStatusCallback #onStatusChanged() and #onGatewayConnectionError, per
API Council feedback.

Bug: 182345902
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I86770a19f3d9f9a42aa3713489943fbe78561773
2021-03-31 14:23:55 -07:00
Cody Kesting
5926d20e03 Expose API for identifying GatewayConnections.
This CL exposes the updated APIs for identifying GatewayConnections via
a user-configured String set in VcnGatewayConnectionConfig.Builder, as
requested by the API Council.

Bug: 182345902
Bug: 180522464
Test: atest FrameworksVcnTests
Change-Id: I10afd074906bc0f3831157dcee1da813b4cfce78
2021-03-31 14:23:29 -07:00
Cody Kesting
52265aab76 Update identification for onGatewayConnectionError().
This CL updates the identification method for
VcnStatusCallback#onGatewayConnectionErrror. Previously,
GatewayConnections were identified by an int[] specifying the
GatewayConnection's exposed NetworkCapabilities. Following API Council
feedback, this is updated to identify GatewayConnections by a
caller-provided String set in the VcnGatewayConnectionConfig.Builder.

Bug: 182345902
Bug: 180522464
Test: atest FrameworksVcnTests
Change-Id: I933c2330edb9bfc1b6bb62276debac02460e24f8
2021-03-31 14:22:54 -07:00
paulhu
6d5643f87e Remove unused method checkUidNetworkingBlocked
aosp/1612823 removed the usage from CS, no one is using
checkUidNetworkingBlocked() now. Thus, remove it from
NetworkPolicyManager, AIDL and NetworkPolicyManagerService.

Bug: 180084343
Test: atest FrameworksNetTests
Test: atest CtsNetTestCases
Test: atest CtsHostsideNetworkTests
Test: atest FrameworksCoreTests:NetworkPolicyManagerTest
Test: atest FrameworksServicesTests:NetworkPolicyManagerServiceTest
Change-Id: I632efa4b775a0238bb912690d48e766597e5e623
2021-03-31 15:48:10 +08:00
lesl
15d809b9f4 Fix Wi-Fi SSID null handling
When Wi-Fi SSID is null in NetworkCapabilities,
get Wi-Fi SSID from connection info (WifiInfo) which is non-null design.

Bug: 176396812
Test: FrameworksNetTests NetworkPolicyManagerServiceTest
Change-Id: I59c7d8f7e176d0c6bb100721269f3f6165f0ca21
2021-03-30 23:57:56 +08:00
Junyu Lai
3757df2e7d Merge "[SP31] Expose onSetWarningAndLimit System API" 2021-03-30 08:00:45 +00:00
Sudheer Shanka
d3ba15beeb Remove NetworkPolicyManager.isUidBlocked() API.
It isn't used by ConnectivityService any more and even if
it needs such utility method in the future, we could create
one which is part of connectivity module and doesn't need
to be exposed as part of NetworkPolicyManager API surface.

Bug: 183696103
Test: atest ./tests/net/java/com/android/server/ConnectivityServiceTest.java
Change-Id: Ie3c681f88e4b2b9bb92d2224c5ea96b074f155d5
2021-03-29 12:39:12 +00:00
Junyu Lai
ac196a1e07 Merge "[SP28] Add API for set data warning" 2021-03-29 11:06:05 +00:00
Lorenzo Colitti
5ab70251e8 Add onBlockedStatusChanged(Network, int) to NetworkCallback.
This is similar to onBlockedStatusChanged(Network, boolean) but
it allows the callback holder to know the exact reason why
networking was blocked. It is useful to privileged system
components such as JobScheduler that are able to ignore some
blocked reasons but not others.

Also add a new BLOCKED_REASON_LOCKDOWN_VPN that is used when
networking is blocked because an always-on VPN is in
lockdown mode.

Also move BLOCKED_METERED_REASON_MASK to ConnectivityManager.
This is necessary because ConnectivityService must ensure that
the blocked status callbacks are correctly sent when meteredness
changes (e.g., a UID that is blocked on metered networks will
become unblocked on a network that becomes unmetered). In order
to do this it needs to know which reasons apply only on metered
networks.

Bug: 165835257
Test: unit tests in subsequent CLs in the stack
Change-Id: I647db4f5a01280be220288e73ffa85c15bec9370
2021-03-26 02:37:19 +09:00
junyulai
59b0a621e7 [SP31] Expose onSetWarningAndLimit System API
Test: atest NetworkPolicyManagerServiceTest NetworkStatsServiceTest
Bug: 149467454
CTS-Coverage-Bug: 183598414
Merged-In: I6f5e22e3a7b80a38cae9f3c5d7296a1dff34facf
Change-Id: I6f5e22e3a7b80a38cae9f3c5d7296a1dff34facf
  (cherry-picked from ag/13981689)
2021-03-25 09:32:43 +08:00
Sudheer Shanka
d533fa78b1 Move BLOCKED_REASON_* constants from NPMS into ConnectivityManager.
These constants will now be including all the reasons for why an
uid's network access can be blocked, instead of only the
restrictions that could be imposed by NPMS.

Bug: 183473548
Test: atest ./tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Merged-In: I4c544415e12adf442fd2415c371b1b70a39c3aa4
Change-Id: I6dcea43fbefa9eac8b5a971b822a5be5422a54b4
2021-03-25 01:33:26 +09:00