Provide a way for the system Setting app or other similar system
apps to set the app exclusion list for the specific VPN from
VpnManager. The list affects only VPN provisioned from
VpnManager to keep the design consistence for app using
VpnService.
The list is stored in the keystore for its persistence.
Bug: 192078259
Test: atest FrameworksNetTests CtsNetTestCases
Change-Id: I157823866e1899b40aa36ea2c0bc4a80370108be
The interpretation of the path depends on whether the scheme or
authority are specified and should be observed when unparcelling
URIs.
Bug: 171966843
Test: atest FrameworksCoreTests:android.net.UriTest
Test: atest com.android.devicehealthchecks.SystemAppCheck
Change-Id: I06981d1c6e387b16df792494523994518848db37
Merged-In: I06981d1c6e387b16df792494523994518848db37
(cherry picked from commit f37a94ae92)
The underlying network, NetworkCapabilities and LinkProperties
are not necessary to send to VPN app since the purpose of
CATEGORY_EVENT_DEACTIVATED_BY_USER and
CATEGORY_EVENT_ALWAYS_ON_STATE_CHANGED are to notify VPN
app that VPN is deactivated by the user or VPN always-on
status is changed.
Bug: 191413541
Test: Javadoc only changes.
Change-Id: I7fd4b6dad1a4363336f03c217e635fc45bcd0ab6
This change ensures that carrier configs are saved as part of the
snapshot, allowing all entities in the VCN to query telephony
subscription information from the same source.
Test: atest FrameworksVcnTests
Change-Id: I31447d84fe98d6bd2cc78ead41746198728c400b
From current design, NetworkPolicyManagerService should only
creates metered carrier/mobile templates. However, if someone
calls the hidden API interface or the template was created
before NetworkTemplate#Builder is published. The caller may
create a non-metered carrier template and persist into the
storage.
This CL elimates this possibility and mark non-metered carrier
template non-persistable, so devices could auto-recover from
this symptom after reboot.
Fix: 222382637
Test: TH
Change-Id: Ia7ba3d92a84b8b246a4f11080f6fec0957865650
Since the onUidStateChanged() callbacks will be
happening from more than one thread, we need to make
sure we only handle the latest uid state change
callbacks and ignore any older callbacks that could
override the latest uid states in NPMS. In order to
this, every uid state change will be associated with
a unique seq number.
Also, remove the UidRecord.lastDispatchedProcStateSeq.
This was added as a safety measure to make sure we
don't unnecessarily end up waiting but it isn't
necessary and if we need to keep it, we need to add
a way to access it without holding global AMS lock,
which isn't worth the complexity.
Bug: 226299593
Test: atest tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Change-Id: I631f5e01f6627916a96c930c22849a1d11eab636
Merged-In: I631f5e01f6627916a96c930c22849a1d11eab636
This changes the VCN to allow a VCN provisioning package to retrieve
its listing of configured subgroups and clear its own configurations,
regardless of whether it is the active subscription group.
Safety is guaranteed based on the VCN's clearing of packages when app
data is cleared, and when the app is uninstalled. In addition to the
configurations not being retrievable, the clearing of the configs will
ensure that sideloading of an app with the same package name provides
no ability to otherwise impact settings.
Bug: 227248744
Test: atest FrameworksVcnTests
Change-Id: I2c774c00373942f895169a761d4e9a1d5b0b2edb
Since the onUidStateChanged() callbacks will be
happening from more than one thread, we need to make
sure we only handle the latest uid state change
callbacks and ignore any older callbacks that could
override the latest uid states in NPMS. In order to
this, every uid state change will be associated with
a unique seq number.
Also, remove the UidRecord.lastDispatchedProcStateSeq.
This was added as a safety measure to make sure we
don't unnecessarily end up waiting but it isn't
necessary and if we need to keep it, we need to add
a way to access it without holding global AMS lock,
which isn't worth the complexity.
Bug: 226299593
Test: atest tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Change-Id: I631f5e01f6627916a96c930c22849a1d11eab636
This adds additional logs to the VCN's dumpsys to facilitate debugging
of the VCN.
Test: atest FrameworksVcnTests
Change-Id: Id8cd668991331dbf2f3395172e5cd90b36c408a9
Stop parsing the IKE options from the input IkeTunnelConnectionParams
if exists. The caller shuould get the relevant infortation the
params.
The field is also stored in the VpnProfile if it built from an
Ikev2VpnProfile.
Bug: 184750836
Test: atest FrameworksNetTests HostsideVpnTests
Test: build ; flash ; connect VPN successfully
Change-Id: Id05c17285915462c7a6cd51d5fb4ee5da7f465ba
Add a duration that the plans last and don't read to/write from disk
for plans. Make non-duration setSubscriptionPlans API deprecated.
Test: atest SubscriptionManagerTest, NetworkPolicyManagerServiceTest
Bug: 210696427
Change-Id: I93aece78eda324c333fbf9f1adbedcf46e4864f0
Merged-In: I93aece78eda324c333fbf9f1adbedcf46e4864f0
getSubscriptionPlans can return null if a plan has not been set for the
given subId yet. Change the annotation from @NonNull -> @Nullable and
update the documentation. SubscriptionManager#getSubscriptionPlans will
return the @NonNull plans instead.
Test: build
Bug: 213896944
Change-Id: I7b232a1a695d1db7cb0d0a177bb1090e9033b805
Merged-In: I7b232a1a695d1db7cb0d0a177bb1090e9033b805
This class can provide the state of VPN, session key and the
settings of always-on and lockdown.
CTS-Coverage-Bug: 225010642
Bug: 225010642
Test: N/A
Change-Id: Ia80da6d4c165680f8c8c7cba0aa4246a5c5934da
IkeTunnelConnectionParams contains more information than the
existing fields inside Ikev2VpnProfile. If the Ikev2VpnProfile
is built from an IkeTunnelConnectionParams, saving it to the
existing fields of Ikev2VpnProfile may cause information lost,
such as IKE options. Thus, store the IkeTunnelConnectionParams
as a field inside Ikev2VpnProfile.
The other Ike options are mutually exclusive with
IkeTunnelConnectionParams. The information such as Preshared
key or username/password may not return expected values if a
profile is built from an IkeTunnelConnectionParams. This may
confuse API callers for using the other getters. Thus, expose
a getter to retrieve IkeTunnelConnectionParams
Bug: 184750836
Test: atest FrameworksNetTests
CTS-Coverage-Bug: 184750836
Change-Id: I61e9a9549b87951956afdcbae2518228994e4729
Add the ability to configure NTP port for tests via the command line and
the associated plumbing / knock-ons.
In-progress CTS tests will run a fake NTP server on the device itself.
Binding to NTP's default port of 123 is restricted. Therefore, we need
to be able to override the port for tests.
adb shell cmd network_time_update_service set_server_config --port 9999
adb shell dumpsys network_time_update_service
<observe port value>
adb shell cmd network_time_update_service force_refresh
<observe false>
adb shell cmd network_time_update_service set_server_config
adb shell dumpsys network_time_update_service
<observe port value>
adb shell cmd network_time_update_service force_refresh
<observe true>
Bug: 213393821
Test: See above
Change-Id: I21e8b735fab268df0d617848b8a562f86560ad16
Divide the NetworkPolicyManager API
notifyStatsProviderWarningOrLimitReached into the following two APIs:
1. notifyStatsProviderWarningReached()
2. notifyStatsProviderLimitReached()
Bug: 216474563
Test: atest NetworkStatsServiceTest NetworkPolicyManagerTest
NetworkPolicyManagerServiceTest OffloadControllerTest
Change-Id: Ic413eb532b5e24d4a7e2afabdcf643ab6607b1ed