This change adds support for IPsec forward policies, which are necessary
for packets to be allowed to be forwarded to another interface, as is
the case with tethering. This is necessary and useful only within the
system server, and as such is not exposed as a public API.
This change is safe, since the addition of a FWD policy on IPsec tunnel
interfaces will by default block forwarded traffic (as would be the case
without this patch). In the event that the (system) owner of the tunnel
requires support for forwarded packets (eg tethering), this patch allows
application of transforms in the FWD direction as well.
This will be used to ensure that the VCN can be used as the underlying
network for the purposes of tethering.
Bug: 185495453
Test: atest IpSecServiceTest
Test: atest IpSecServiceParameterizedTest
Test: manual testing with tethering over VCN
Change-Id: I74ecea71f1954029f6fbdbe34598c82e0aac386b
Allows VCN transport info to be parcelled for purposes of sysUI
Bug: 186025257
Test: atest FrameworksVcnTests
Change-Id: I5a5d9b88659c8dcaa9ded16d491b2bac0529169a
Address API review feedback, add getters to UnderlyingNetworkInfo
instead of exposing fields.
Instead of wasting memory by converting this into an array, have
migrateTun take a List<String>. In turn, tunAdjustmentInit should
also take a List<String>.
(cherry picked from ag/14211075)
Bug: 183972554
Test: atest android.net.UnderlyingNetworkInfoTest
Merged-In: Id59744097208d91298a25ef110ade91a9cf291a1
Change-Id: Id59744097208d91298a25ef110ade91a9cf291a1
Address API council feedback, add getters to NetworkStateSnapshot
instead of exposing the bare fields directly.
(cherry picked from ag/14233655)
Bug: 183972826
Test: FrameworksNetTests
Merged-In: Id1707753b42ae88d2b95e4bd00a792609434e4f5
Change-Id: Id1707753b42ae88d2b95e4bd00a792609434e4f5
Use the more generic object TunnelConnectionParams in VCN.
TunnelConnectionParams may also be used in VPN in the future.
Test: atest FrameworksVcnTests
Bug: 180664474
Change-Id: Ie433f9df614e1f51cdff200d915b68b61e5ca35e
Add utility class to convert TunnelConnectionParams to and from
PersistableBundle.
Bug: 180664474
Test: atest EncryptedTunnelParamsUtilsTest
Change-Id: I93ae068eb6d1e1c4d3fcbaccbaae867db8d07a38
TunnelConnectionParams represents configurations for setting up a
secure encrypted tunnel with a remote endpoint. TunnelConnectionParams
will be used to configure a VCN and will be used for VPN configuration
in the future.
Bug: 180664474
Test: make update-api
Change-Id: Ic8e5c8535e84971517f16c54ce8b8645cfc7f944
Per API council feedback, this change adds a new API to retrieve all
subscription groups that have a VCN configured.
Bug: 184612525
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I64b565758e0a27552eee9f860e0674db2fb35980
This change adds support for retrieval of a list of subscription groups
that have a VCN configured.
Bug: 184612525
Test: atest FrameworksVcnTests
Change-Id: I40553a7bb45d9b1f948c7d0a791f1b22a422d55c
BLOCKED_REASON_* constants have been moved to ConnectivityManager
and blockedReasonsToString() util method doesn't belong in
NetworkPolicyManager as an API. So, just removing it for now.
Bug: 185967486
Test: treehugger
Change-Id: Ie04044980fdfc7ec772444be13fc659880953bd1
Per API feedback, the get/set methods for retry intervals are renamed to
be plural, and have time units
Bug: 184612525
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I51b3ffcfa44f72805f359e56b263da2558325372
This commit makes sure IKE_OPTION_FORCE_PORT_4500 is included
when converting IkeSessionParams to a PersistableBundle.
Bug: 185637142
Test: atest IkeSessionParamsUtilsTest
Change-Id: I1fcd6d26e64217091ad960a1c51659046e70a6ac
Carrier merged wifi network is a specific cerrier wifi network
which provides the same user experience as mobile.
To support data usage accounting for carrier merged wifi,
the change provide several APIs in NetworkTemplate:
1. extend buildTemplateWifi so it could be used for matching
wifi networks with subscriber Id (IMSI).
2. add buildTemplateCarrier to let
NetworkPolicyManagerService creates a single policy for
a given carrier regardless of network type.
Bug: 176396812
Test: atest -c NetworkTemplateTest
Test: atest -c NetworkStatsServiceTest
Test: Manual Test with test code on mobile and wifi network.
1. buildTemplateCarrier includes the carrier wifi and
mobile usage
2. buildTemplateWifi can get carrier wifi usage and support the
filter via subscriberId
Change-Id: I667b4adf3eec0bdd3a7385109dd8c1fae8e7be32
This pacth changes VCN to call #setNetwork and #getNetwork instead
of #setConfiguredNetwork and #getConfiguredNetwork because the
later two methods will not be APIs.
This patch also changes VCN unit tests to build an IkeSessionParams
without a Context because the constructor requring a Context
is deprecated.
Bug: 180521384
Test: FrameworksVcnTests, CtsVcnTestCases
Change-Id: I971d0d1b6824890c58263a1960f3b8d0e66fe7d1
This CL clarifies the documentation for status codes used in
VcnStatusCallback #onStatusChanged() and #onGatewayConnectionError, per
API Council feedback.
Bug: 182345902
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I86770a19f3d9f9a42aa3713489943fbe78561773
This CL exposes the updated APIs for identifying GatewayConnections via
a user-configured String set in VcnGatewayConnectionConfig.Builder, as
requested by the API Council.
Bug: 182345902
Bug: 180522464
Test: atest FrameworksVcnTests
Change-Id: I10afd074906bc0f3831157dcee1da813b4cfce78
This CL updates the identification method for
VcnStatusCallback#onGatewayConnectionErrror. Previously,
GatewayConnections were identified by an int[] specifying the
GatewayConnection's exposed NetworkCapabilities. Following API Council
feedback, this is updated to identify GatewayConnections by a
caller-provided String set in the VcnGatewayConnectionConfig.Builder.
Bug: 182345902
Bug: 180522464
Test: atest FrameworksVcnTests
Change-Id: I933c2330edb9bfc1b6bb62276debac02460e24f8
aosp/1612823 removed the usage from CS, no one is using
checkUidNetworkingBlocked() now. Thus, remove it from
NetworkPolicyManager, AIDL and NetworkPolicyManagerService.
Bug: 180084343
Test: atest FrameworksNetTests
Test: atest CtsNetTestCases
Test: atest CtsHostsideNetworkTests
Test: atest FrameworksCoreTests:NetworkPolicyManagerTest
Test: atest FrameworksServicesTests:NetworkPolicyManagerServiceTest
Change-Id: I632efa4b775a0238bb912690d48e766597e5e623
When Wi-Fi SSID is null in NetworkCapabilities,
get Wi-Fi SSID from connection info (WifiInfo) which is non-null design.
Bug: 176396812
Test: FrameworksNetTests NetworkPolicyManagerServiceTest
Change-Id: I59c7d8f7e176d0c6bb100721269f3f6165f0ca21
It isn't used by ConnectivityService any more and even if
it needs such utility method in the future, we could create
one which is part of connectivity module and doesn't need
to be exposed as part of NetworkPolicyManager API surface.
Bug: 183696103
Test: atest ./tests/net/java/com/android/server/ConnectivityServiceTest.java
Change-Id: Ie3c681f88e4b2b9bb92d2224c5ea96b074f155d5
This is similar to onBlockedStatusChanged(Network, boolean) but
it allows the callback holder to know the exact reason why
networking was blocked. It is useful to privileged system
components such as JobScheduler that are able to ignore some
blocked reasons but not others.
Also add a new BLOCKED_REASON_LOCKDOWN_VPN that is used when
networking is blocked because an always-on VPN is in
lockdown mode.
Also move BLOCKED_METERED_REASON_MASK to ConnectivityManager.
This is necessary because ConnectivityService must ensure that
the blocked status callbacks are correctly sent when meteredness
changes (e.g., a UID that is blocked on metered networks will
become unblocked on a network that becomes unmetered). In order
to do this it needs to know which reasons apply only on metered
networks.
Bug: 165835257
Test: unit tests in subsequent CLs in the stack
Change-Id: I647db4f5a01280be220288e73ffa85c15bec9370
These constants will now be including all the reasons for why an
uid's network access can be blocked, instead of only the
restrictions that could be imposed by NPMS.
Bug: 183473548
Test: atest ./tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Merged-In: I4c544415e12adf442fd2415c371b1b70a39c3aa4
Change-Id: I6dcea43fbefa9eac8b5a971b822a5be5422a54b4