Commit Graph

5877 Commits

Author SHA1 Message Date
Sudheer Shanka
d533fa78b1 Move BLOCKED_REASON_* constants from NPMS into ConnectivityManager.
These constants will now be including all the reasons for why an
uid's network access can be blocked, instead of only the
restrictions that could be imposed by NPMS.

Bug: 183473548
Test: atest ./tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Merged-In: I4c544415e12adf442fd2415c371b1b70a39c3aa4
Change-Id: I6dcea43fbefa9eac8b5a971b822a5be5422a54b4
2021-03-25 01:33:26 +09:00
Benedict Wong
d68c1f6cb2 Check carrier privilege permissions with package name
This change ensures that carrier privileges for the right packages are
always checked.

Bug: 183465199
Test: atest FrameworksVcnTests
Change-Id: If46c660e54870529868a7b4b1e271c9009b81d45
2021-03-23 17:42:12 -07:00
Cody Kesting
46c10cbc4d Merge changes from topic "vcn-status-changed"
* changes:
  Rename VcnStatusCallback#onVcnStatusChanged.
  Reevaluate VcnGatewayConnections on receiving new configs.
2021-03-23 17:10:51 +00:00
Cody Kesting
c57281504e Rename VcnStatusCallback#onVcnStatusChanged.
Per API Council feedback, VcnStatusCallback#onVcnStatusChanged is
renamed to VcnStatusCallback#onStatusChanged.

Bug: 182345902
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: Ie0277c5f053e1802aa98240618a9d9e8aa6d9d09
2021-03-22 11:59:27 -07:00
Sudheer Shanka
f072281f63 Fix the case where blocked reasons for dataSaver are not considered.
Fixes: 183267528
Test: atest ./tests/cts/hostside/src/com/android/cts/net/HostsideNetworkCallbackTests.java
Merged-In: I3c90c3849261df4c289c398f22661f91f7cf4994
Change-Id: Iba3ff804a74fb482847dd999c2854405b21affd2
2021-03-22 17:36:21 +00:00
Lorenzo Colitti
f969377a96 Expose isUidNetworkingBlocked and isUidRestrictedOnMeteredNetworks
These methods are used by ConnectivityService for synchronous
calls such as getActiveNetworkInfo, isActiveNetworkMetered, etc.

These calls must call into NPMS and acquire the NPMS lock because
they are synchronous. They cannot use the stale copy of the
policy rules maintained by ConnectivityService, because if they
did, races like the following could occur:

1. App gets broadcast/callback/....
2. App calls isActiveNetworkMetered or other synchronous method.
3. ConnectivityService's copy of the rules is out of date, so the
   call returns stale information that the UID is still blocked.
4. The app thinks it has no networking, and does not call the
   synchronous method again until some other event occurs,
   potentially much later.

Bug: 176289731
Test: passes existing tests in ConnectivityServiceTest
Change-Id: I4ad0ca60431fe3702be85332530b6e93728d55e7
Merged-In: I4ad0ca60431fe3702be85332530b6e93728d55e7
2021-03-20 22:23:23 +09:00
Remi NGUYEN VAN
00b8d2cf37 Add multipath preference, background status API
Add APIs for getMultipathPreference and getRestrictBackgroundStatus.
Both are used by Connectivity to back the external
ConnectivityManager.getRestrictBackgroundStatus, and
ConnectivityManager.getMultipathPreference APIs.

Test: atest CtsNetTestCases
      atest ConnectivityServiceTests
      atest NetworkPolicyManagerServiceTest
Bug: 176289731
Change-Id: I8a03162b2f6691086bb64e75ffd354cdfca7f86a
Merged-In: I8a03162b2f6691086bb64e75ffd354cdfca7f86a
2021-03-20 22:23:16 +09:00
Treehugger Robot
66794f915f Merge "Reland "Add an API to listen for changes in network blocked status of an uid."" 2021-03-19 10:12:15 +00:00
Remi NGUYEN VAN
c9f553c7ed Merge "Move network selection utils to Connectivity" 2021-03-18 23:57:34 +00:00
Sudheer Shanka
da90e7a2bb Reland "Add an API to listen for changes in network blocked status of an uid."
This reverts commit 8623f2b3ca.

Reason for revert: The issue causing the build breakage has been fixed

Change-Id: I03fa406551b51aaa4d4d9255cf1a53f9b4bcc1bd
Merged-In: Ib9949b8619c6b148f73630b314c4113d76c31ec1
2021-03-18 19:11:55 +00:00
Benedict Wong
d4b7104f7b Merge "Hide required underlying caps APIs" 2021-03-18 17:05:37 +00:00
Anthony Stange
677f4420b9 Merge "Revert "Add an API to listen for changes in network blocked status of an uid."" 2021-03-18 16:52:08 +00:00
Anthony Stange
8623f2b3ca Revert "Add an API to listen for changes in network blocked status of an uid."
This reverts commit 7dc302d612.

Reason for revert: Breaking build - b/183106805
Bug: 183106805
Merged-In: Ib9949b8619c6b148f73630b314c4113d76c31ec1
Change-Id: I9789ed81e630f49c71034b6917188983bd11d774
2021-03-18 16:51:22 +00:00
Sudheer Shanka
5497657433 Merge "Add an API to listen for changes in network blocked status of an uid." 2021-03-18 15:29:17 +00:00
Remi NGUYEN VAN
3e6dde82a9 Move network selection utils to Connectivity
NetworkScore, IOnCompleteListener should be in the Connectivity scope,
as they are supporting classes for the ConnectivityManager APIs.

Bug: 181512874
Test: m
Change-Id: I6dc40a80e0bf5f86f5625b657b01eba969d41fcf
2021-03-18 23:57:26 +09:00
Sudheer Shanka
7dc302d612 Add an API to listen for changes in network blocked status of an uid.
Given that ConnectivityService is moving to a mainline module, we need
a @SystemApi for it to listen for changes in blocked status of an uid.
So, we decided to create a new API for this which can provide
ConnectivityService with more info about why an uid is blocked (which
will be useful for adding a new similar onBlockedStatusChanged callback
in CM.NetworkCallback) and also captures data saver restriction without
having out to track it separately.

Currently, NPMS does some redundant computations because we are
calculating both uid rules and blocked reasons separately. In a
follow-up change, we will compute uid rules using blocked reasons
and later possibly remove that onUidRulesChanged callback.

Bug: 176289731
Test: atest ./tests/cts/hostside/src/com/android/cts/net/HostsideRestrictBackgroundNetworkTests.java
Test: atest ./tests/net/java/com/android/server/ConnectivityServiceTest.java
Test: atest ./services/tests/servicestests/src/com/android/server/net/NetworkPolicyManagerServiceTest.java
Change-Id: Ib9949b8619c6b148f73630b314c4113d76c31ec1
Merged-In: Ib9949b8619c6b148f73630b314c4113d76c31ec1
2021-03-18 10:42:25 +00:00
Lorenzo Colitti
4763300fab Add a VpnManager.TYPE_VPN_OEM.
This needed for OEMs that have VPN types not supported by AOSP.

Bug: 171872481
Test: new test coverage in VpnTransportInfoTest
Change-Id: Ic7529bef7f12d2c74a3be5b1a4a2d54fb0d0bfac
2021-03-18 05:54:53 +00:00
Benedict Wong
226af1dbfd Hide required underlying caps APIs
VCN underlying network capabilities should be transport-dependent in
order to allow using anything other than the INTERNET capability for
VCN types that support wifi offload. Specifically, if underlying
network capabilities are not transport-dependent, and Wifi only ever
supports the INTERNET capability, the VCN is unable to utilize wifi
offload together with requiring NET_CAPABILITY_IMS or
NET_CAPABILITY_CBS, since the IMS or CBS capability would be required
for both cellular and wifi underlying networks.

Until such time as a per-transport capability set is allowed, hide
the exposedCapability pieces, and document that all underlying networks
MUST have INTERNET capability in order to be used.

Bug: 182219992
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I50d7f1be42e0e001f1413a3d5fe8aa4b7afec223
2021-03-17 10:26:21 -07:00
Chalard Jean
b1cd4d7b9d Public API for per-profile network preference.
This patch defines the API, but does not make it public
yet as there is no implementation yet.

Test: none so far
Change-Id: I854a952dfe35cc80847eb62f522b1667b8e9b8a0
2021-03-16 12:13:27 +00:00
Chalard Jean
1a645067e5 Merge "[NS01] Add NetworkScore" 2021-03-16 06:36:07 +00:00
Aaron Huang
16f50075b1 Merge changes from topic "pacproxy-service"
* changes:
  Make PacProxyService be a system service
  Revert^2 "Refactor setCurrentProxyScriptUrl to a void method"
2021-03-15 11:49:45 +00:00
Chalard Jean
5c4bb91134 [NS01] Add NetworkScore
As attested by numerous TODOs in the code, a new way of
representing network quality and policy is needed instead
of an int.

An int representing the quality of the network requires
all parties using it to know how all other parties are
using it, and implementation details about the decision
algorithm. For all intents and purposes, the selection
is left to individual network factories who try to
achieve a desired result while piecing together all
possible states of the system.

As the number of such cases and desires increases, this
becomes both intractable and unmaintainable. Indeed, at
this time in the codebase nobody can really predict exactly
how a given change in score will affect selection across
the board, and it is essentially impossible to figure out
the behavior of network selection by inspecting the code
because the moving parts are scattered throughout the
entire codebase.

Having an object encapsulating policy and quality values
will let us centralize the selection and make it again
possible to maintain without knowledge of all behaviors
of all network factories. It will also provide better
guarantees of respecting policy, and allow bugfixes that
were not possible before because they'd touch too many
parts of the code.

Test: FrameworksNetTests FrameworksWifiTests NetworkStackTests
Change-Id: I3185a6412b9b659798faf0c6882699e9c63cc115
2021-03-15 09:49:47 +00:00
Aaron Huang
5d31a15d84 Make PacProxyService be a system service
PacProxyInstaller class is running a thread all the time and is
listening to intent ACTION_PAC_REFRESH so it would be better to
make it be a system service with a manager class PacProxyManager
which is obtained with getSystemService(PacProxyManager.class).
Besides, rename PacProxyInstaller to PacProxyService will
be easier to know it's the service for PacProxyManager.

ConnectivityService is going to be a mainline module and it
needs constructor of PacProxyService to be SystemApi.
However, in current design, it needs to pass a handler and
an int arguments to the constructor which would be difficult
to maintain if just expose the constructor directly.

So, define a listener for the event that the current PAC
proxy has been installed so that the handler and the int
arguments can be removed from the constructor.

Bug: 177035719
Test: FrameworksNetTests
Change-Id: I2abff75ec59a17628ef006aad348c53fadbed076
2021-03-15 14:40:58 +08:00
Cody Kesting
a93e2f9545 Merge "Update Policy Listener API naming." 2021-03-12 21:32:08 +00:00
Remi NGUYEN VAN
cb35ed09da Merge "Move ParseException to Connectivity" 2021-03-12 04:27:55 +00:00
Cody Kesting
ae3c3593cb Update Policy Listener API naming.
This CL changes the policy listener API to be
VcnNetworkPolicyChangeListener (it was previously
VcnNetworkPolicyListener) per API Council guidance.

This CL also requires permission NETWORK_FACTORY for removing registered
policy listeners.

Bug: 181562364
Test: atest FrameworksVcnTests
Change-Id: I026eaefa62d8f64b9180fc182a7cf0605d83bf97
Merged-In: I026eaefa62d8f64b9180fc182a7cf0605d83bf97
(cherry picked from commit a96ec13821)
2021-03-11 09:48:22 -08:00
Remi NGUYEN VAN
c5479a0886 Add Ethernet, TestNetworkSpecifier API
Rename StringNetworkSpecifier to EthernetNetworkSpecifier (its only
production user), and make it module-lib API.
The original StringNetworkSpecifier file is actually kept to satisfy
some invalid dependencies; it will be removed separately.

This allows specifying an Ethernet interface with a non-deprecated API:
until this change the only way to do so would be to use
NetworkRequest#setSpecifier(String), which is deprecated.

Similarly, add the TestNetworkSpecifier API for TestNetworkManager, to
replace previous usage of StringNetworkSpecifier. TestNetworkManager is
module API, so TestNetworkSpecifier should be module API too. This
allows tests to request the test interface specifically, without using
the deprecated NetworkRequest#setSpecifier(String).

Bug: 179329291
Test: m
Merged-In: Iee569f5c8bbdc4bc979610e1191308281f3d4620

Change-Id: Iee569f5c8bbdc4bc979610e1191308281f3d4620
2021-03-11 23:02:02 +08:00
Remi NGUYEN VAN
ebacbf75b4 Move ParseException to Connectivity
ParseException is a public API class used to support Connectivity APIs,
so it should be in the same API surface as connectivity.

Bug: 181512874
Test: m
Change-Id: Ie1213de0d0facc8f409f7b4c2553abb382e4afbf
2021-03-11 17:19:18 +09:00
Lucas Lin
d2b8d781f8 Merge "Expose TYPE_VPN_* constants" 2021-03-11 01:30:02 +00:00
lucaslin
62b2252831 Expose TYPE_VPN_* constants
Expose TYPE_VPN_* constants so that connectivity mainline module
can access them.

Bug: 172183305
Test: atest FrameworksNetTests
Change-Id: Ic8d46a392f3deda5983c52b43585707fa2c98f57
2021-03-10 16:57:57 +08:00
Yan Yan
a8d51aac66 Merge changes from topic "ike-params"
* changes:
  Support converting VcnControlPlaneIkeConfig to/from PersistableBundle
  Support converting IKE Options to/from PersistableBundle
  Support converting IkeConfigRequest to/from PersistableBundle
  Support converting IkeAuthEapConfig to/from PersistableBundle
  Support converting IkeAuthDigitalSignConfig to/from PersistableBundle
  Support converting IkeAuthConfig to/from PersistableBundle
  Support converting IkeSessionParams to/from PersistableBundle
2021-03-10 02:31:36 +00:00
Remi NGUYEN VAN
7f8fae2b3a Remove unused buildNetworkIdentity
The overload using a NetworkState is now unused.

Bug: 174123988
Change-Id: I22f2d2fffd2d70c08097d3217f01393ff8e75ab5
Test: m
2021-03-09 09:31:21 +00:00
Remi NGUYEN VAN
f9a30cfa4c Move OemNetworkPreferences to Connectivity
The data class supports a ConnectivityManager API, so it should be
together with the ConnectivityManager API surface.

Bug: 181512874
Test: m
Change-Id: I5642486ea0febcb08cadcbd4cd3f0c6056deae0e
2021-03-08 09:26:41 +09:00
Remi NGUYEN VAN
d0355e1be2 Merge "Move NetworkState to Connectivity" 2021-03-05 10:27:57 +00:00
Junyu Lai
0bb7932183 Merge "[FUI23] Remove getNetworkQuotaInfo" 2021-03-05 10:05:06 +00:00
Treehugger Robot
4c73e05c1d Merge "[FUI22] Support getAllNetworkStateSnapshot" 2021-03-05 05:16:43 +00:00
Treehugger Robot
dd2877eabe Merge "Make VCN network policy listener oneway" 2021-03-05 04:25:22 +00:00
Janis Danisevskis
421c5739ea Merge "Keystore 2.0: Make VPN Keystore 2.0 ready." 2021-03-05 02:57:34 +00:00
Yan Yan
aef89adfdc Merge "Revert "Use VERSION_CODES.S instead of VERSION_CODES.R + 1"" 2021-03-05 02:30:21 +00:00
Yan Yan
713ec685cb Revert "Use VERSION_CODES.S instead of VERSION_CODES.R + 1"
This reverts commit 7f13ec417e.

Reason for revert:
1. The BUILD_VERSIONS.S is 1000, and thus it will prevent
   the code from requiring new algorithms on devices whose
   first sdk is 31 (e.g. cuttlefish), though these devices
   should be treated as first launched with SDK S.
2. It will break #testValidationForAlgosAddedInS, because
   the test code is using BUILD_VERSIONS.R to gate the test,
   which is inconsistent with the implementation.

Bug: 181887451
Test: atest IpSecAlgorithmTest
Change-Id: I5cd717c5ebd6086ae5cf9abf76311ae4fca0c6e9
2021-03-05 00:15:15 +00:00
Remi NGUYEN VAN
eb02d4969c Move NetworkState to Connectivity
NetworkState is becoming an internal implementation class, with
NetworkStateSnapshot replacing it as a proper API. Considering this it
belongs inside Connectivity.

Bug: 174123988
Test: m
Change-Id: I201f1a07c50d9da31e33f5c207875da8863ef57c
2021-03-05 08:56:55 +09:00
Yan Yan
f8bce7ede4 Support converting VcnControlPlaneIkeConfig to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(new tests added)
Change-Id: I38d066949d1543dc6b53a9e00ab6c1d1bd820c5f
2021-03-04 14:19:42 -08:00
Yan Yan
3d9908aa99 Support converting IKE Options to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(add new tests)
Change-Id: I28cad3cf4d8ccccb8233f76c631db3a302eb320b
2021-03-04 14:15:57 -08:00
Yan Yan
85414c1c24 Support converting IkeConfigRequest to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(add new tests)
Change-Id: I9a0f7ad91de41749fdf05629bf86bdb010ba13fb
2021-03-04 14:15:42 -08:00
Yan Yan
c3da07fb9c Support converting IkeAuthEapConfig to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(add new tests)
Change-Id: Ifaddd113d9267664404d75b7e4e5410622bf5d7b
2021-03-04 14:13:32 -08:00
Yan Yan
848568a3ce Support converting IkeAuthDigitalSignConfig to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(add new tests)
Change-Id: I62cdf4cb0297a394e0c97973e621b5c051ab0192
2021-03-04 13:30:48 -08:00
Yan Yan
2f0f6b575c Support converting IkeAuthConfig to/from PersistableBundle
Bug: 163604823
Test: FrameworksVcnTests(add new tests)
Change-Id: I97d9a7db423711dbccea412b96f069fe1dbd2779
2021-03-04 12:37:43 -08:00
Yan Yan
067b3dffa4 Merge changes I65dbc509,I1e338d9c,Ib4a0ed69,Iac7077b4,I9c53d425, ...
* changes:
  Support converting IKE ID to/from PersistableBundle
  Support converting EAP-TTLS to/from PersistableBundle
  Support converting EAP-SIM, AKA and AKA' to/from PersistableBundle
  Support converting EapSessionConfig to/from PersistableBundle
  Support converting TunnelModeConfigRequest to/from PersistableBundle
  Support converting TunnelModeChildSessionParams to/from PersistableBundle
  Support converting ChildSaProposal to/from PersistableBundle
  Support converting IkeSaProposal to/from PersistableBundle
2021-03-04 18:30:17 +00:00
Cody Kesting
dcaf81ebff Merge changes from topic "vcn-status-cb"
* changes:
  Call VcnStatusCallback#onVcnStatusChanged on register.
  Remove VcnStatusCallback#onEnteredSafemode().
  Expose APIs for VcnStatusCallback.
2021-03-04 18:09:40 +00:00
junyulai
52facd7e3a [FUI23] Remove getNetworkQuotaInfo
Currently, getNetworkQuotaInfo in NetworkPolicyManagerService
uses NetworkState class, which will not be available after
ConnectivityService moved to mainline module.

Thus, to remove the usage of NetworkState, remove this function
since:
  1. There is no internal usage and the function only prints
     debug log.
  2. It is non-SDK API which annotated with maxTargetSdk = 30,
     callers should not expect it will continoue to work in next
     Android release.
  3. go/nonsdk-dash shows zero usage statistics.

Test: TH
Bug: 174123988
Change-Id: I450964a692b85f3ba89bf9f847e8089ee2445bda
2021-03-04 18:41:09 +08:00