Commit Graph

6300 Commits

Author SHA1 Message Date
Yan Yan
10987d8c02 Merge "Improve IKEv2/IPsec VPN by proposing more IPsec algorithms" am: 94a4cdd4e8 am: 7b8b5fd6de
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1690265

Change-Id: I0e467627fdbf70d6ec704f1f2be58223df9642ed
2021-05-21 23:12:45 +00:00
Yan Yan
94a4cdd4e8 Merge "Improve IKEv2/IPsec VPN by proposing more IPsec algorithms" 2021-05-21 22:00:30 +00:00
Yan Yan
cc258065e1 Improve IKEv2/IPsec VPN by proposing more IPsec algorithms
This commit allows IKEv2/IPsec VPN to propose more algorithms that
newly added in IpSecAlgorithm. Those new algorithms have stronger
security guarantees and better performances.

This commit also removes algorithm name validation because all
algorithms are URL encoded to ensure no special characters create
problems due to their use by VpnProfile for list or field delimiting
(e.g. rfc7539esp(chacha20,poly1305))

Bug: 185265778
Test: atest FrameworksNetTests, CtsNetTestCases
Test: All new algorithms are manually verified
Change-Id: I1de322c95aacc8924e95bcdbcfdbd1ec441de99c
2021-05-21 17:46:54 +00:00
Treehugger Robot
1ffe8e3a8f Merge "Improve documentation of IpSecTunnelInterface#setUnderlyingNetwork" am: 06a4f88eb9 am: 932ee4368e
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1590415

Change-Id: I02207954757c9135fbf6674720dd8e623fc9e435
2021-05-20 21:22:32 +00:00
Treehugger Robot
06a4f88eb9 Merge "Improve documentation of IpSecTunnelInterface#setUnderlyingNetwork" 2021-05-20 20:33:41 +00:00
Chris Weir
3be5715ee4 Merge "Print human-readable OEM managed states" am: c4099ac074 am: c589d4e2a3
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1636561

Change-Id: I4ecc049acf7a5f2e3c99808c7e5f6c2f064d7e5c
2021-05-18 17:39:57 +00:00
Chris Weir
c4099ac074 Merge "Print human-readable OEM managed states" 2021-05-18 16:29:26 +00:00
Les Lee
bb2bce3215 Merge "Add metered filter for API: buildTemplateCarrier" am: 287dcfbc80 am: 94fa18312d
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1699687

Change-Id: I46d8d8f0d9b83fb0a817a3455cbbc28d558b871c
2021-05-18 13:57:06 +00:00
Les Lee
287dcfbc80 Merge "Add metered filter for API: buildTemplateCarrier" 2021-05-18 13:01:38 +00:00
Aaron Huang
329aede902 Merge "Add ConnectivityAnnotations class" into sc-dev am: d2d8fa6c17
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/14186142

Change-Id: Ib74156e9f29e62e861d19f5b58a12ab106478b4c
2021-05-17 14:26:25 +00:00
Aaron Huang
d2d8fa6c17 Merge "Add ConnectivityAnnotations class" into sc-dev 2021-05-17 14:07:45 +00:00
Junyu Lai
8354c4531a Merge changes I3ba50cbd,I970ee365 am: 37f2408143 am: ed64c29783
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1620859

Change-Id: If9a3e37e5359b955e330002d81cbeb48f90ee22b
2021-05-15 17:24:42 +00:00
Junyu Lai
37f2408143 Merge changes I3ba50cbd,I970ee365
* changes:
  [FUI29] Migrate ConnectivityService to use getAllNetworkStateSnapshots
  [FUI27] Fix internal naming of notifyNetworkStatus
2021-05-15 16:21:38 +00:00
Benedict Wong
b9b8c45d66 Merge "Make VcnTransportInfo unparcel to null if no data contained" into sc-dev am: e0ee346120
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/14554154

Change-Id: I419ab78dbca7e418f702ad93b90dc481ff90578b
2021-05-14 23:18:15 +00:00
Benedict Wong
6452f6f978 Merge "Remove underlying network caps" am: 886e94b0a3 am: a6006f1d44
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1709008

Change-Id: I9dc2ede9a3e01b1f6988e847d2176a33c159a7fb
2021-05-14 23:13:41 +00:00
Nathan Harold
e386a1fbe8 Merge "Update VCN Owners Post-Initial-Development" am: 4b8d448b3b am: b9ec9c28ef
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1709010

Change-Id: I5fd07130187aed119c27d25082981964b7d12597
2021-05-14 23:12:57 +00:00
Benedict Wong
e0ee346120 Merge "Make VcnTransportInfo unparcel to null if no data contained" into sc-dev 2021-05-14 23:00:21 +00:00
Benedict Wong
d9695aced3 Make VcnTransportInfo unparcel to null if no data contained
When VcnTransportInfo is redacted, it contains no useful information. In
order to preserve the abstraction, the VcnTransportInfo should be
unparcelled to null


Bug: 8675309
Test: atest VcnTransportInfoTest
Change-Id: Ia9dbb9f259027acc74004eb1207e0a13cea56088
2021-05-14 22:53:51 +00:00
Benedict Wong
886e94b0a3 Merge "Remove underlying network caps" 2021-05-14 22:40:54 +00:00
Benedict Wong
b2632543c0 Remove underlying network caps
Bug: 182219992
Test: atest FrameworksVcnTests
Change-Id: Ic2fec8a87fd19a1780333c61759c4092598d349e
2021-05-14 15:28:34 -07:00
Nathan Harold
e0f865d554 Update VCN Owners Post-Initial-Development
Owners files update for VCN now that primary development
is complete and the codebase is stable.

Bug: 8675309
Test: compilation
Change-Id: Ie686729b33f0a7e1c3414374ce4bf3d7ef514a22
2021-05-14 15:05:26 -07:00
junyulai
9c964b11e6 [FUI27] Fix internal naming of notifyNetworkStatus
Test: TH
Bug: 174123988
Change-Id: I970ee365ca221956ee85788005d331374b5fa71a
2021-05-14 19:48:17 +08:00
Aaron Huang
f281058618 Merge "Rename *Iface* APIs to *Interface*" 2021-05-14 09:11:29 +00:00
Benedict Wong
d9c05c23e6 Merge "Custom network selection" am: bc3638ce5d am: b3f0495383 am: 2a86eae65e
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1706226

Change-Id: Icdf319d564e4eab468d9d4e722716a2ef7d2c3cd
2021-05-14 05:25:38 +00:00
Aaron Huang
a5b9e6ed7d Rename *Iface* APIs to *Interface*
Address API review feedback, other APIs have been refering to
these as "interface" instead of "iface" so migrate the APIs named
*Iface* to *Interface*.

(cherry-picked from ag/14326779)
Bug: 183972554
Test: atest android.net.UnderlyingNetworkInfoTest
Merged-In: I38b476e762fb57fa88c4a789092d0af6f5330d80
Change-Id: I38b476e762fb57fa88c4a789092d0af6f5330d80
2021-05-14 11:05:22 +08:00
lesl
d9b6ed80b9 Add metered filter for API: buildTemplateCarrier
This CL modifies NetworkTemplate#buildTemplateCarrier to force on
metered carrier network and rename to buildTemplateCarrierMetered.
This method was introduced recently and has no callers.

This method will be used in Settings and NetworkPolicyManagerService
to display and manage data usage on carrier metered networks.

Settings/NetworkPolicyManagerService will use it instead of the existing
method buildTemplateMobileAll method, which only matches metered networks.
That code will change from matching metered mobile networks to matching
metered carrier networks.

Note: The carrier metered network includes metered mobile network and
metered "merged carrier wifi network" that is a specific cerrier wifi network
which provides the same user experience as mobile.

Bug: 176396812
Test: atest -c NetworkTemplateTest
Change-Id: I7196d62bb60844458a6c4b1d94e2baccb71e15cd
2021-05-14 11:04:17 +08:00
Aaron Huang
4a9f988934 Add ConnectivityAnnotations class
This change is to address API review, add respective
@IntDef for network policy API.

Typedef cannot be exposed as SystemApi so add
ConnectivityAnnotations class and add an annotation library
so that it can be used in module and platform.

Bug: 183972925
Test: m, build doc target framework-doc-stubs_annotations.zip
      and check the APIs have an attribute IntDef annotation
Change-Id: Ie3ec40cf48818edd422a4550377774eae387d3b2
2021-05-14 10:30:49 +08:00
Benedict Wong
9028cac4fe Custom network selection
This change adds a basic prioritization framework in the VCN, and signal
strength thresholds for WiFi.

Bug: 188104094
Test: atest FrameworksVcnTests
Change-Id: Iee4e3dbecf1102ddc127a8c8daf08a00b6fccbbd
2021-05-13 18:57:05 -07:00
Lorenzo Colitti
1ad18702f1 Immediately redact VcnTransportInfo.
Redaction of NetworkCapabilities is changing from redacting at
parcel time to redacting immediately when makeCopy() is called.
Update VcnTransportInfo redaction accordingly.

Bug: 183938194
Test: atest VcnTransportInfoTest
Change-Id: I0c9406f426b66fd36b47d11799955def531c16ba
2021-05-13 20:24:20 +09:00
Ken Chen
92bc335785 Merge "Add testVpnTypesEqual to verify consistency" am: 785dc4871c am: 3ae939569e am: 233682e675
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1705385

Change-Id: I53d58c5b2277ba2d88a848ed3e6d6269b4b886b3
2021-05-13 03:00:17 +00:00
Ken Chen
2216da85aa Merge "Switch from networkCreate[Physical/Vpn] to networkCreate" am: c9d5cd9fbc am: 62258932ff am: a4d53bfa6d
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1669648

Change-Id: I3475e674c3914c4c61fd0a4246c9ee3e7e02c4fb
2021-05-13 02:59:30 +00:00
Ken Chen
785dc4871c Merge "Add testVpnTypesEqual to verify consistency" 2021-05-13 01:22:08 +00:00
Ken Chen
c9d5cd9fbc Merge "Switch from networkCreate[Physical/Vpn] to networkCreate" 2021-05-13 01:20:39 +00:00
Lorenzo Colitti
79d74a6448 Merge changes from topic "transportinfo-explicit-redaction" into sc-dev
* changes:
  Immediately redact VcnTransportInfo.
  Do not automatically redact TransportInfo objects.
2021-05-12 22:46:36 +00:00
Treehugger Robot
1761a873cb Merge changes Icb59b15d,I6fc6a266,I5cc340e5,I94db52a8 am: b79dcb24d0 am: 5804521e8c am: 32c2d34383
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1700309

Change-Id: Ifab0469fb2687cae7b361b5009abe152a35048c5
2021-05-12 17:16:19 +00:00
Treehugger Robot
b79dcb24d0 Merge changes Icb59b15d,I6fc6a266,I5cc340e5,I94db52a8
* changes:
  Request Test Networks for VCNs when in Test Mode.
  Specify if a VCN is in 'test-mode' in VcnContext.
  Create test-mode for VcnConfig.
  Require MOBIKE for IkeSessionParams in VCN configs.
2021-05-12 16:21:25 +00:00
Ken Chen
bf8bf735d6 Add testVpnTypesEqual to verify consistency
VPN types are defined in both VpnManager.java and NativeVpnType.aidl.
The definitions on both sides should match (except TYPE_VPN_NONE).

VpnManager.java:
TYPE_VPN_NONE = -1
TYPE_VPN_SERVICE = 1
TYPE_VPN_PLATFORM = 2
TYPE_VPN_LEGACY = 3
TYPE_VPN_OEM = 4

NativeVpnType.aidl:
SERVICE = 1
PLATFORM = 2
LEGACY = 3
OEM = 4

Bug: N/A
Test: atest android.net.VpnManagerTest#testVpnTypesEqual
Change-Id: Ie618e227d861100c5318da696140e486af1093a0
2021-05-12 17:34:34 +08:00
Aaron Huang
8a520d604e Merge "Add return type javadoc to NetworkStateSnapshot#getLegacyType" into sc-dev 2021-05-12 05:11:45 +00:00
Cody Kesting
fd57083e39 Create test-mode for VcnConfig.
This CL creates a test-mode for VcnConfig so that they will only
match with Test Networks. This is necessary for CTS testing so
that VCNs can run on test networks and IKE negotiations can be
injected over the Test Networks.

Bug: 182291467
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I5cc340e5aaa34c5de8efafa52de49185a18d4bd3
2021-05-11 18:32:32 -07:00
Cody Kesting
92959d6774 Require MOBIKE for IkeSessionParams in VCN configs.
This CL updates VcnGatewayConnectionConfigs to require
IkeTunnelConnectionParams with MOBIKE enabled for the
IkeSessionParams. This is necessary for VCNs - without it,
they do not support IPsec mobility (one of the main features
of the VCN).

Bug: 187851560
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I94db52a8c42d9fa4681fefb8f787f006933caa18
2021-05-11 16:40:56 -07:00
Lorenzo Colitti
327cff1969 Immediately redact VcnTransportInfo.
Redaction of NetworkCapabilities is changing from redacting at
parcel time to redacting immediately when makeCopy() is called.
Update VcnTransportInfo redaction accordingly.

Bug: 183938194
Test: atest VcnTransportInfoTest
Change-Id: I0c9406f426b66fd36b47d11799955def531c16ba
2021-05-11 22:47:34 +09:00
Ken Chen
8dbaacfe45 Switch from networkCreate[Physical/Vpn] to networkCreate
networkCreatePhysical and networkCreateVpn are non-extensible. In order
to pass OEM requested VPN type to Netd, we need to migrate to
networkCreate API.

Modify test code accordingly since networkCreatePhysical and
networkCreateVpn have been deprecated on Netd.

Bug: 171872481
Test: atest FrameworksNetTests
atest atest HostsideVpnTests

Change-Id: I50ab8615346c49559c16e815482e7804a1e765c8
2021-05-11 16:06:54 +08:00
Benedict Wong
275bf90709 Merge changes from topic "vcn-fwd" am: d7d2d2a15b am: f980436b32 am: 600401154a
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1682047

Change-Id: I745687f69366657dc33bfdacd878e06affd6a8ec
2021-05-11 06:10:32 +00:00
Benedict Wong
d7d2d2a15b Merge changes from topic "vcn-fwd"
* changes:
  Apply transform to FWD policy if configured to provide tethering
  Add internal support for IPsec forward policies
2021-05-11 01:30:31 +00:00
Benedict Wong
a91e5123fc Merge "Add additional logging to improve debugability of VcnManagementService" am: 3996048bad am: 30b760733b am: 4182201ae9
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1692661

Change-Id: I24973d2eff043af411460df6227954e55249f2ec
2021-05-10 22:21:30 +00:00
Aaron Huang
f5755c2919 Add return type javadoc to NetworkStateSnapshot#getLegacyType
Add javadoc to document the return type is the legacy network
type in getLegacyType.

Bug: 183972826
Test: only update javadoc
Change-Id: I7757253af5955f7d489d6349c090dcba146cfd7f
2021-05-10 23:18:41 +08:00
Benedict Wong
1d9c19a635 Add additional logging to improve debugability of VcnManagementService
Test: atest FrameworksVcnTests
Change-Id: I23af20ea655e11934f6ac679c1bfc0943d5a148f
2021-05-07 17:18:21 -07:00
Benedict Wong
7f5a2fe728 Add internal support for IPsec forward policies
This change adds support for IPsec forward policies, which are necessary
for packets to be allowed to be forwarded to another interface, as is
the case with tethering. This is necessary and useful only within the
system server, and as such is not exposed as a public API.

This change is safe, since the addition of a FWD policy on IPsec tunnel
interfaces will by default block forwarded traffic (as would be the case
without this patch). In the event that the (system) owner of the tunnel
requires support for forwarded packets (eg tethering), this patch allows
application of transforms in the FWD direction as well.

This will be used to ensure that the VCN can be used as the underlying
network for the purposes of tethering.

Bug: 185495453
Test: atest IpSecServiceTest
Test: atest IpSecServiceParameterizedTest
Test: manual testing with tethering over VCN
Change-Id: I74ecea71f1954029f6fbdbe34598c82e0aac386b
2021-05-07 15:09:42 -07:00
Chris Weir
9943124ba6 Print human-readable OEM managed states
For NetworkTemplate and NetworkIdentity, print human-readable
representations of the OEM managed state in the classes' respective
toString() functions.

Bug: 180557699
Test: Manual - run atest NetworkTemplateTest NetworkIdentityTest
and verify that the logcat output shows the String representation of the
OEM managed state correctly.

Change-Id: Ia180b911f91f41937ac713e6b3691d82f682e146
2021-05-07 10:26:31 -07:00
Treehugger Robot
2f83b6a72d Merge "Add getters to NetworkStateSnapshot" 2021-04-29 09:20:34 +00:00