Commit Graph

49 Commits

Author SHA1 Message Date
Rambo Wang
3a8a004d2a [DO NOT MERGE] Revert "Remove VCN Carrier Privilege grace period"
This reverts commit fb4a590dbc.

This change brings back the grace period built in VCN because
the carrier privileges grace period is turn off.

Bug: 229418673
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I85738c969c2bf78da33beaebe5863432948b7735
2022-05-19 22:58:29 +00:00
Benedict Wong
1a8f3e0a14 Allow provisioning package to retrieve subGrp, clear it's own config
This changes the VCN to allow a VCN provisioning package to retrieve
its listing of configured subgroups and clear its own configurations,
regardless of whether it is the active subscription group.

Safety is guaranteed based on the VCN's clearing of packages when app
data is cleared, and when the app is uninstalled. In addition to the
configurations not being retrievable, the clearing of the configs will
ensure that sideloading of an app with the same package name provides
no ability to otherwise impact settings.

Bug: 227248744
Test: atest FrameworksVcnTests
Change-Id: I2c774c00373942f895169a761d4e9a1d5b0b2edb
2022-04-13 22:10:21 +00:00
Benedict Wong
fb4a590dbc Remove VCN Carrier Privilege grace period
This change removes the grace period after the VCN is notified that a
provisioning app is no longer carrier privileged. This is due to the
switch to use CarrierPrivilegesTracker, which inherently has the
identical grace period.

This both simplifies the code, as well as removes some edge cases. As
such, tests for the delay before VCN tears down are no longer necessary.

Bug: 183554244
Test: atest FrameworksVcnTests
Change-Id: Ia50223108e45eeaedc860adf5e29a6ea459d956f
2022-01-07 22:11:26 +00:00
Benedict Wong
3433a8e5d9 Limit VCNs to one running at a given time
This change ensures that there is only ever one VCN running at a given
point in time, and that if the device has switched to using a
subscription in a different subscription group, the VCN will immediately
tear down.

This ensures that when on a DSDS device, when the VCN-enabled
subscription is not the default/active subscription, the other
subscription's network will never be outscored by the VCN, and thus get
torn down.

Bug: 190761448
Test: atest FrameworksVcnTests
Test: Manual testing to ensure common functionality
Change-Id: I8031fab7502880d38420058451df41f47567c458
2021-07-15 12:04:05 -07:00
Cody Kesting
1fd3dadc22 Allow MANAGE_TEST_NETWORKS to register and get VCN policies.
This CL updates VcnManagementService to allow permission
MANAGE_TEST_NETWORKS to register/unregister VCN policy listers as
well as apply VCN policies. Previously, only permission
NETWORK_FACTORY was allowed to perform this operations.

Bug: 189125789
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I6ad3a58f4ef87d931917fbd772a810af81b27da1
2021-06-09 11:52:53 -07:00
Cody Kesting
5f65a440e2 Specify if a VCN is in 'test-mode' in VcnContext.
This CL updates VcnContext to include whether the VCN instance
it is created for is in test-mode (as specified by the VcnConfig).
This also changes the lifetime of VcnContext to be created uniquely
for each VCN instance (as opposed to a single VcnContext created in
VcnManagementService and used for all VCNs).

Bug: 182291467
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I6fc6a266bf67ab2aa64202153c3c109ee98a16ca
2021-05-11 18:32:32 -07:00
Cody Kesting
fd57083e39 Create test-mode for VcnConfig.
This CL creates a test-mode for VcnConfig so that they will only
match with Test Networks. This is necessary for CTS testing so
that VCNs can run on test networks and IKE negotiations can be
injected over the Test Networks.

Bug: 182291467
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I5cc340e5aaa34c5de8efafa52de49185a18d4bd3
2021-05-11 18:32:32 -07:00
Cody Kesting
2225648d47 Notify policy listeners when VCN subIds change.
This CL updates VcnManagementService to notify policy listeners
when the subIds for any VCN instances change. This is necessary to
ensure that NetworkFactories properly update their Networks in the
event that a Network comes up under an existing VCN are properly
marked as VCN-managed.

Bug: 187112989
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: Iecab1226119c8fd876131c381647267f18339db2
2021-05-04 15:57:32 -07:00
Treehugger Robot
a2da3ebb16 Merge "[VCN19] Rename get/setSubIds to get/setSubscriptionIds" 2021-04-22 04:43:26 +00:00
Benedict Wong
80afe1eeee Merge changes I64b56575,I40553a7b
* changes:
  Expose API for retrieval of subscription groups with VCN configured
  Add support for retrieval of configured VCNs by carrier privilege
2021-04-22 01:31:11 +00:00
Benedict Wong
6e8c1d6da7 Add support for retrieval of configured VCNs by carrier privilege
This change adds support for retrieval of a list of subscription groups
that have a VCN configured.

Bug: 184612525
Test: atest FrameworksVcnTests
Change-Id: I40553a7bb45d9b1f948c7d0a791f1b22a422d55c
2021-04-21 13:49:14 -07:00
Chiachang Wang
580fda2670 Remove hidden connectivity method access in FrameworksVcnTests
Due to connectivity modularization work, hidden connectivity
methods and members are not accessible outside the module.
Remove the corresponding usage.

The test case in VcnNetworkProviderTest are not able to create
NetworkRequests with request id assigned. The loop to create
different request is removed. After that, the test does not
provide more test coverage than other tests. Thus, Remove the
test case directly.

Bug: 182859030
Test: atest FrameworksVcnTests
Merged-In: I488f62089d1dbe93c232f892885d944bef896df6
Change-Id: I488f62089d1dbe93c232f892885d944bef896df6
(cherry picked from commit 18f3a26efa)
2021-04-19 13:12:43 -07:00
junyulai
d6b1d4b355 [VCN19] Rename get/setSubIds to get/setSubscriptionIds
Test: atest FrameworksNetTests FrameworksVcnTests
Fix: 185215036
Merged-In: I9d90df5fc13b36d2cdc4920b456dcc87fcd2b3a7
Change-Id: I9d90df5fc13b36d2cdc4920b456dcc87fcd2b3a7
  (cherry-picked from ag/14198665)
2021-04-19 17:41:01 +08:00
Cody Kesting
5b6355a09f Remove location-permission check from VcnStatusCallbacks.
This CL updates VcnManagementService to not require location permissions
for receiving VcnStatusCallback invocations. This change is safe to make
because these callbacks are not capable of leaking any location-related
information.

Bug: 180556279
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I38600aeb2489f139b3479b07de77facc2ae838c5
2021-04-07 15:27:45 -07:00
Benedict Wong
80056e834e Allow soft-start and opportunistic safe mode
This change adds support for opportunistic safe mode, where the VCN will
continue to provide networks, but not restrict underlying networks.
Similarly, this change allows for soft-starting of the VCN, where VCN
underlying networks can be selected without restricting them directly.

Additionally, this change ensures networks are torn down when
VcnGatewayConnections enter safe mode. This change is required due to
changes in the lifecycle of the VcnGatwayConnection, where in safe mode
they are NOT torn down, but allowed to continue retrying. During these
broken-connectivity windows, the VCN network should be torn down to
prevent blackholing traffic.

Bug: 183174340
Test: atest FrameworksVcnTests
Change-Id: I50f2c0e92552281731c843db89e9a9a1ccff5346
2021-04-05 10:34:25 -07:00
Benedict Wong
f8db8d8c43 Prevent changes to immutable capabilities for carrier wifi
This change prevents carrier wifi from having changes to the RESTRICTED
network capability, which is an immutable capability.

Bug: 184101137
Test: atest FrameworksVcnTests
Change-Id: I802d36a754d961c9928a2e642e25f1b25b8be12d
2021-04-01 16:37:33 -07:00
Benedict Wong
bd1085ef03 Switch to using status codes for Vcn
This change adds status codes, and switches the Vcn class to use these
to signal safe mode status. Additionally, this allows a distinction
between a VCN that is quitting and one that is simply in safe mode,
providing potential for an opportunistic safe mode where the VCN will
continue to attempt to serve NetworkRequests while not restricting
underlying networks.

Bug: 183174340
Bug: 181789060
Test: atest FrameworksVcnTests
Change-Id: I9f2b2d0d8d7b3ade19ca5adcd48cc920171bf8c3
2021-04-01 15:11:17 -07:00
Benedict Wong
85c6ad2363 Switch to using list of subIds for policy generation
Bug: 183174340
Test: atest FrameworksVcnTests
Change-Id: I2d30b75c282cf619d81b0f6dc06638566af61a33
2021-03-30 14:21:49 -07:00
Benedict Wong
62f01dfbd5 Trigger re-evaluation of privileged apps upon app install/uninstall
This change registers listeners for package installs and uninstalls,
ensuring that changes to app install statuses are reflected in the VCN

Bug: 183465258
Test: atest FrameworksVcnTests
Change-Id: I8d2afd351208cac12392bf945439845cc521b7ec
2021-03-23 17:42:12 -07:00
Benedict Wong
d68c1f6cb2 Check carrier privilege permissions with package name
This change ensures that carrier privileges for the right packages are
always checked.

Bug: 183465199
Test: atest FrameworksVcnTests
Change-Id: If46c660e54870529868a7b4b1e271c9009b81d45
2021-03-23 17:42:12 -07:00
Roshan Pius
adee4b7b7e TransportInfo: Add a generic redaction mechanism
This replaces the existing mechanism for redacting location sensitive
fields with a more extensible mechanism. Currently supported redactions
are for the following permissions:
i. ACCESS_FINE_LOCATION
ii. LOCAL_MAC_ADDRESS
iii. NETWORK_SETTINGS

Also, removed WifiInfo from ConnectivityServiceTest to reduce cross
dependencies on wifi code.

Bug: 156867433
Bug: 162602799
Test: atest android.net
Test: atest com.android.server
Change-Id: I2bb980c624667a55c1383f13ab71b9b97ed6eeab
2021-03-19 20:15:21 +00:00
Remi NGUYEN VAN
a89a2ae676 Merge "Move LocationPermissionChecker to libs/net" 2021-03-17 00:13:21 +00:00
Cody Kesting
ae3c3593cb Update Policy Listener API naming.
This CL changes the policy listener API to be
VcnNetworkPolicyChangeListener (it was previously
VcnNetworkPolicyListener) per API Council guidance.

This CL also requires permission NETWORK_FACTORY for removing registered
policy listeners.

Bug: 181562364
Test: atest FrameworksVcnTests
Change-Id: I026eaefa62d8f64b9180fc182a7cf0605d83bf97
Merged-In: I026eaefa62d8f64b9180fc182a7cf0605d83bf97
(cherry picked from commit a96ec13821)
2021-03-11 09:48:22 -08:00
Remi NGUYEN VAN
0c4e4a2059 Move LocationPermissionChecker to libs/net
LocationPermissionChecker was written to be used by multiple
connectivity modules, so it belongs in the frameworks/libs/net library.

The file is moved as-is with minor modifications in the test to avoid
usage of the privileged ActivityManager.getCurrentUser API.

Bug: 181837977
Test: atest NetworkStaticLibTests
Change-Id: I63bce35ba87c45138b3aaf6244367e982dfec455
2021-03-09 17:00:39 +09:00
Cody Kesting
212c06aaa6 Notify VcnStatusCallbacks for VCN start/stop.
This CL updates VcnManagementService to notify VcnStatusCallbacks when a
VCN is started or stopped. VcnStatusCallbacks will also be notified for
config changes that cause a VCN to exit Safe Mode.

Bug: 180659281
Test: atest FrameworksVcnTests
Change-Id: I4168c868185880621333855dfcb51e46cb662741
2021-03-08 11:14:25 -08:00
Cody Kesting
f38b347ca8 Call VcnStatusCallback#onVcnStatusChanged on register.
This CL updates VcnMangementService to notify VcnStatusCallbacks on
registration with the current status of the VCN for the specified
subscription group.

Bug: 180659281
Test: atest FrameworksVcnTests
Change-Id: Id2c74e855fa12d21d292ee94a72ad047f2d56aca
2021-03-03 14:06:55 -08:00
Cody Kesting
7458bf88a0 Notify VcnStatusCallback#onVcnStatusChanged for Safe Mode.
This CL updates VcnManagementService to notify callbacks when VCNs enter
Safe Mode via #onVcnStatusChanged. Callbacks were previously notified
via #onEnteredSafeMode - however, VcnStatusCallbacks were changed to
provide more status information by defining onVcnStatusChanged(int) per
API Council feedback.

Bug: 1597023
Test: atest FrameworksVcnTests
Change-Id: I34ef76ec29f4369390449b70b37bc3cf99c09c77
2021-02-22 17:35:29 -08:00
Cody Kesting
a65c2d8ad1 Implement VCN error callback use.
This CL updates VcnGatewayConnection to notify VcnManagementService
(through Vcn) when errors occur with a gateway. VcnManagementService
then notifies registered, permissioned VcnStatusCallbacks via

Bug: 163433613
Test: atest FrameworksVcnTests
Change-Id: I3be3cac4b591b19a0b0075767fde0ba2eb6e12a2
2021-02-17 14:28:34 -08:00
Cody Kesting
59881b17b4 Notify status callbacks when a VCN enters Safemode.
This CL updates VcnManagementService to notify VcnStatusCallbacks when
the VCN for their specified subscription group enters Safemode. In order
to be notified, the registering app must also have permissions for the
specified permission.

Bug: 163433613
Test: atest FrameworksVcnTests
Change-Id: I3242ad0ee1dc406aef56253f884c2544a994869e
2021-02-16 21:41:03 -08:00
Cody Kesting
f14145e37a Define VcnStatusCallback register/unregister.
This CL defines VcnStatusCallbacks, which are callbacks used to register
for status updates to a specific subscription group. These Callbacks may
be registered with VcnManager at any time, but will only be invoked for
the specifies subscription group and only if the registering app has
carrier privileges for that subscription.

Bug: 163433613
Test: atest FrameworksVcnTests
Change-Id: Iefd284ae2d09676d195e2a12bf660be3596da59b
2021-02-16 21:33:40 -08:00
Benedict Wong
cebde1ed9a Restrict Carrier Wifi while VCN is configured & privileged
This change removes the NOT_RESTRICTED capability for Carrier Wifi. This
is done even if a VCN is in safe mode, but will ONLY be performed if the
VCN is provisioned, and has the appropriate carrier privileges to run.

This change also fixes a test bug where the NOT_VCN_MANAGED capability
was not present in the query to getUnderlyingNetworkPolicy(), and
therefore was incorrectly passing.

Bug: 163432273
Test: atest FrameworksVcnTests
Change-Id: Iecb827b5341bdeb93ef8692c1d62f0eaf9d416ba
2021-02-09 18:43:21 -08:00
Cody Kesting
204a2fed4f Support Safemode for VCNs.
This CL updates VcnManagementService to support Safemode for VCN
instances. Specifically, VcnGatewayConnections will notify their Vcn
instance when they enter Safemode. Vcn instances will in-turn notify
VcnManagementService, which notifies all registered
UnderlyingNetworkPolicyListeners to update their policies.

Bug: 178140973
Test: atest FrameworksVcnTests
Change-Id: I3336c150e9406b3eb2330d2e86cae2ed835730bb
2021-02-04 16:22:55 -08:00
Cody Kesting
f5915a7f3a Fix test method naming in VcnManagementServiceTest.
Bug: 175914059
Test: atest FrameworksVcnTests
Change-Id: I03be15d63adfccc357000ee670e373d0359a3c06
2021-02-03 20:28:51 -08:00
Cody Kesting
26409bfe5d Notify PolicyListeners to refresh their policy on VCN changes.
This CL updates VcnManagementService to notify all registered
VcnUnderlyingNetworkPolicyListeners to refresh their
UnderlyingNetworkPolicy when any VCN is added or removed.

Bug: 175914059
Test: atest FrameworksVcnTests
Change-Id: Ie87f4aa3401c6c4ba9f932130a1d475e35f59d4e
2021-02-03 20:28:51 -08:00
Cody Kesting
50e9bf04aa Unit test TelephonySubscriptionSnapshot changes for VCNs.
This CL adds unit testing for TelephonySubscriptionSnapshot updates in
UnderlyingNetworkTracker, Vcn, and VcnManagementService.

Bug: 177364490
Test: atest FrameworksVcnTests
Change-Id: I244744194a1360c7c7dee062a302e04f9b5efc32
2021-02-03 20:28:43 -08:00
Cody Kesting
2b0754517c Notify UnderlyingNetworkTracker for Subscription changes.
This CL updates VcnManagementService to notify active VCNs when it is
notified of subscription changes by TelephonySubscriptionTracker. These
subscription changes are passed down to each VCN's
UnderlyingNetworkTracker, which determines whether it needs to register
or unregister bringup NetworkRequests based on subIds within that VCN's
Subscription Group.

Bug: 177364490
Test: atest FrameworksVcnTests
Change-Id: I15bc9aaf3d5f97046d0ce9fcf1e12c9b1e0e1446
2021-02-03 19:04:01 -08:00
Cody Kesting
07979a07cc Implement Network policy in VcnManagementService.
This CL implements #getUnderlyingNetworkPolicy() for
VcnManagementService. Specifically, it takes the provided
NetworkCapabilities and checks for a corresponding VCN. If one exists,
a VcnUnderlyingNetworkPolicy will be returned with a copy of the
original NetworkCapabilities without the capability NOT_VCN_MANAGED and
with the unwanted capability NOT_VCN_MANAGED.

Any NetworkCapabilities without a corresponding VCN will be returned a
VcnUnderlyingNetworkPolicy with the original NetworkCapabilities intact.

Bug: 175914059
Test: atest FrameworksVcnTests
Change-Id: Icdffc4f586f58a0e5b6290d5c6449e2bbed5cab0
2021-02-01 14:46:58 -08:00
Cody Kesting
7de2e8443c Allow system components to request underlying network policies.
This CL updates VcnManager to allow system components with permission
NETWORK_FACTORY to request the current VcnUnderlingNetworkPolicy for a
specific Network's NetworkCapabilities and LinkProperties.

Bug: 175900686
Test: atest FrameworksVcnTests
Change-Id: I16416e619bdb03630582f5660260b0090730e9eb
2021-01-28 19:38:06 -08:00
Benedict Wong
4f27883485 Merge "Implement Disconnected state" 2021-01-25 22:41:08 +00:00
Benedict Wong
60d326ba08 Implement Disconnected state
This change implements the signal handling for the Disconnected state.

Bug: 165827287
Test: atest FrameworksVcnTests
Change-Id: I4853b0801b82fddc4ef9e9c6e6a659f9b81e2ac3
2021-01-20 12:01:10 -08:00
Cody Kesting
88d43b69ea Implement Policy Listener add/remove in VcnService.
This CL updates VcnManagementService to implement
VcnUnderlyingNetworkPolicyListener add and remove operations. It also
adds functionality to remove any listeners if the registering app dies
without unregistering.

Bug: 175739863
Test: atest FrameworksVcnTests
Change-Id: I9db2729d404f232b84577d2d90909b9152d53b5a
2021-01-19 13:38:22 -08:00
Benedict Wong
db8cf2a13d Pull VcnNetworkProvider out into a separate class
This change makes the VcnNetworkProvider a separate class, and caches
all NetworkRequest(s) to ensure that VcnTunnel(s) satisfy all requests
that they can accept.

Bug: 163431879
Test: atest FrameworksVcnTests
Change-Id: I3b7695628d0153a33f7e7f40d839df1463d58b07
2021-01-07 17:13:39 -08:00
Benedict Wong
9cb5807845 Verify carrier privileges for VCN-providing packages
This change adds and verifies packages in the VcnManagmentService,
ensuring that carrier privilege gain/loss correctly starts/tears down
VCN instances.

Bug: 163431877
Test: atest FrameworksNetTests
Change-Id: I63203188c57fdde1cfc58aaf1108aa3e70eb4a50
2021-01-07 17:13:37 -08:00
Benedict Wong
6153723db5 Add TelephonySubscriptionTracker to VcnMgmtSvc
This changes adds the TelephonySubscriptionTracker to
VcnManagementService, ensuring that VCN Instances are only ever started
once a relevant Subscription has been loaded in Telephony

Bug: 163430955
Test: New VcnManagementService tests added, passing
Change-Id: Ia9396d66b41fadc0a5ed7aa66306e6223a2d29b8
2021-01-07 17:00:15 -08:00
Benedict Wong
1fe26df538 Add basic VcnMgmtSvc --> Vcn signals (startup, teardown, NetworkReq)
This change adds the relevant calls to ensure that the VcnMgmtSvc
starts, updates and stops a Vcn instance when configs are set/removed

Additionally, this change ensures that upon new network requests, the
Vcn instance is notified.

Bug: 163432852
Test: atest FrameworksVcnTests
Change-Id: Ifec34fad8282a3d64b540d24f643f546463f4379
2021-01-07 17:00:12 -08:00
Benedict Wong
ab1b484ac7 Add persistence for VcnConfig objects by Subscription Group
This commit adds the ability for the VcnManagementService to track/store
VCN profiles by subscription groups, and saving/loading to/from disk.

Bug: 163611304
Test: New tests added, passing
Change-Id: Ifabf5e2be090d529cd29e2c68d55ece4858b2aad
2020-12-17 17:17:13 -08:00
Benedict Wong
264973663c Implement basic VcnConfig and VcnGatewayConnectionConfig
This change adds some of the basic fields in VcnConfig and
VcnGatewayConnectionConfig, plus adds a persistability layer to ensure
all VcnConfig(s) are disk-stable.

Bug: 163602123
Bug: 163594033
Test: New tests added, passing
Change-Id: I2e632532809e7768b284be376f2b0a77f634fef5
2020-12-16 17:51:58 -08:00
Benedict Wong
ad3271875a Enforce carrier privileges when setting/clearing VCN configs
This change ensures that only carrier-privileged apps can modify VCN
configs.

Since carrier privilege is checked per-subId, we iterate through all
subIds in the group, and check if any of them grant the calling app
carrier privileges.

Bug: 165670724
Test: New tests added, passing.
Change-Id: Iac032136d9c1975e6b95a2d2ad9b811ce45c9a53
2020-12-08 16:26:49 -08:00
Benedict Wong
0acd4caf23 Add NetworkProvider to VcnManagementService
This change adds a skeleton VcnNetworkProvider, and registers it with
ConnectivityService upon system startup.

Bug: 163431879
Test: FrameworksVcnTests passing
Change-Id: I7720db1cea805cbdca052a2e37cb2d754189ea05
2020-11-16 13:29:34 -08:00