Commit Graph

5958 Commits

Author SHA1 Message Date
Treehugger Robot
e98c98156c Merge "Convert VcnNetworkProvider to use NetworkOffers" 2021-06-16 19:48:58 +00:00
Cody Kesting
705021aa6b Convert VcnNetworkProvider to use NetworkOffers
This change brings VcnNetworkProvider to full functionality in the new
NetworkProvider paradigm, where NetworkProviders offer networks, and are
notified based on NetworkOfferCallbacks.

Bug: 185204197
Test: atest FrameworksVcnTests
Change-Id: I88c69c0be9f6fd81839fb1595ed00341001694a5
Merged-In: I88c69c0be9f6fd81839fb1595ed00341001694a5
2021-06-15 18:13:56 -07:00
Sarah Chin
ab9f5d46b2 Merge "Update documentation for setSubscriptionOverride" 2021-06-14 19:30:48 +00:00
Luke Huang
b4cbf81dd7 Make NsdService only start the native daemon when needed and automatically clean it up.
Currently, NsdService starts the native mdnsresponder daemon if any
NsdManager connect to it, which results in that when any constant
service holds the NsdManager connection, the device would always be
in the mdns multicast group whatever the connection is not used or not.
This is because mdnsresponder will join the multicast group when it
starts.

To solve this problem, start the native daemon only when needed, and
clean it up after the given idle timeout.

1. Start the native daemon when a new request come.
2. If there is no pending request, clean up the daemon after 3 seconds
of idle time.

Bug: 181810560
Test: atest NsdManagerTest NsdServiceTest
Change-Id: I3eb04552f6cf6c0c68c07abffe751bb4d0669215
2021-06-08 10:09:30 +08:00
Sarah Chin
2aaa2c3205 Update documentation for setSubscriptionOverride
Test: build
Fix: 180496714
Change-Id: Iebfcd0ece1891c1b77d132b92e93d8c1eea3aa6e
Merged-In: Iebfcd0ece1891c1b77d132b92e93d8c1eea3aa6e
2021-06-03 17:40:53 -07:00
Les Lee
9eb7688535 Merge "carrier data usage: Use carrier template as default policy" 2021-06-01 10:42:08 +00:00
Yan Yan
94a4cdd4e8 Merge "Improve IKEv2/IPsec VPN by proposing more IPsec algorithms" 2021-05-21 22:00:30 +00:00
Yan Yan
cc258065e1 Improve IKEv2/IPsec VPN by proposing more IPsec algorithms
This commit allows IKEv2/IPsec VPN to propose more algorithms that
newly added in IpSecAlgorithm. Those new algorithms have stronger
security guarantees and better performances.

This commit also removes algorithm name validation because all
algorithms are URL encoded to ensure no special characters create
problems due to their use by VpnProfile for list or field delimiting
(e.g. rfc7539esp(chacha20,poly1305))

Bug: 185265778
Test: atest FrameworksNetTests, CtsNetTestCases
Test: All new algorithms are manually verified
Change-Id: I1de322c95aacc8924e95bcdbcfdbd1ec441de99c
2021-05-21 17:46:54 +00:00
Treehugger Robot
06a4f88eb9 Merge "Improve documentation of IpSecTunnelInterface#setUnderlyingNetwork" 2021-05-20 20:33:41 +00:00
lesl
95904d435d carrier data usage: Use carrier template as default policy
The carrier network means any network which linked with sepcific
subscriberId (for instances: merged Wifi or mobile).
Update default policy to use carrier network template to replace mobile
template.

No impact for current AOSP user because no any wifi network is merged
wifi. (Because the merged wifi network requires to support from the wifi module).

Also this change convert all of the old policies which template is
TYEP_MOBILE to TYPE_CARRIER to match the default policy.

Bug: 176396812
Test: atest -c NetworkPolicyManagerServiceTest
Test: atest -c CtsHostsideNetworkTests
Test: Manual Test with test code (Force wifi to merged wifi).
      The data will limit when using merged wifi.
      And mobile policy also work normally.

Change-Id: I33c10f7549e713c52ce9afd5b8c4cce2abbda616
2021-05-20 23:46:39 +08:00
Chris Weir
c4099ac074 Merge "Print human-readable OEM managed states" 2021-05-18 16:29:26 +00:00
Les Lee
287dcfbc80 Merge "Add metered filter for API: buildTemplateCarrier" 2021-05-18 13:01:38 +00:00
Junyu Lai
37f2408143 Merge changes I3ba50cbd,I970ee365
* changes:
  [FUI29] Migrate ConnectivityService to use getAllNetworkStateSnapshots
  [FUI27] Fix internal naming of notifyNetworkStatus
2021-05-15 16:21:38 +00:00
Benedict Wong
886e94b0a3 Merge "Remove underlying network caps" 2021-05-14 22:40:54 +00:00
Benedict Wong
b2632543c0 Remove underlying network caps
Bug: 182219992
Test: atest FrameworksVcnTests
Change-Id: Ic2fec8a87fd19a1780333c61759c4092598d349e
2021-05-14 15:28:34 -07:00
Nathan Harold
e0f865d554 Update VCN Owners Post-Initial-Development
Owners files update for VCN now that primary development
is complete and the codebase is stable.

Bug: 8675309
Test: compilation
Change-Id: Ie686729b33f0a7e1c3414374ce4bf3d7ef514a22
2021-05-14 15:05:26 -07:00
junyulai
9c964b11e6 [FUI27] Fix internal naming of notifyNetworkStatus
Test: TH
Bug: 174123988
Change-Id: I970ee365ca221956ee85788005d331374b5fa71a
2021-05-14 19:48:17 +08:00
Aaron Huang
f281058618 Merge "Rename *Iface* APIs to *Interface*" 2021-05-14 09:11:29 +00:00
Aaron Huang
a5b9e6ed7d Rename *Iface* APIs to *Interface*
Address API review feedback, other APIs have been refering to
these as "interface" instead of "iface" so migrate the APIs named
*Iface* to *Interface*.

(cherry-picked from ag/14326779)
Bug: 183972554
Test: atest android.net.UnderlyingNetworkInfoTest
Merged-In: I38b476e762fb57fa88c4a789092d0af6f5330d80
Change-Id: I38b476e762fb57fa88c4a789092d0af6f5330d80
2021-05-14 11:05:22 +08:00
lesl
d9b6ed80b9 Add metered filter for API: buildTemplateCarrier
This CL modifies NetworkTemplate#buildTemplateCarrier to force on
metered carrier network and rename to buildTemplateCarrierMetered.
This method was introduced recently and has no callers.

This method will be used in Settings and NetworkPolicyManagerService
to display and manage data usage on carrier metered networks.

Settings/NetworkPolicyManagerService will use it instead of the existing
method buildTemplateMobileAll method, which only matches metered networks.
That code will change from matching metered mobile networks to matching
metered carrier networks.

Note: The carrier metered network includes metered mobile network and
metered "merged carrier wifi network" that is a specific cerrier wifi network
which provides the same user experience as mobile.

Bug: 176396812
Test: atest -c NetworkTemplateTest
Change-Id: I7196d62bb60844458a6c4b1d94e2baccb71e15cd
2021-05-14 11:04:17 +08:00
Benedict Wong
9028cac4fe Custom network selection
This change adds a basic prioritization framework in the VCN, and signal
strength thresholds for WiFi.

Bug: 188104094
Test: atest FrameworksVcnTests
Change-Id: Iee4e3dbecf1102ddc127a8c8daf08a00b6fccbbd
2021-05-13 18:57:05 -07:00
Lorenzo Colitti
1ad18702f1 Immediately redact VcnTransportInfo.
Redaction of NetworkCapabilities is changing from redacting at
parcel time to redacting immediately when makeCopy() is called.
Update VcnTransportInfo redaction accordingly.

Bug: 183938194
Test: atest VcnTransportInfoTest
Change-Id: I0c9406f426b66fd36b47d11799955def531c16ba
2021-05-13 20:24:20 +09:00
Ken Chen
785dc4871c Merge "Add testVpnTypesEqual to verify consistency" 2021-05-13 01:22:08 +00:00
Ken Chen
c9d5cd9fbc Merge "Switch from networkCreate[Physical/Vpn] to networkCreate" 2021-05-13 01:20:39 +00:00
Treehugger Robot
b79dcb24d0 Merge changes Icb59b15d,I6fc6a266,I5cc340e5,I94db52a8
* changes:
  Request Test Networks for VCNs when in Test Mode.
  Specify if a VCN is in 'test-mode' in VcnContext.
  Create test-mode for VcnConfig.
  Require MOBIKE for IkeSessionParams in VCN configs.
2021-05-12 16:21:25 +00:00
Ken Chen
bf8bf735d6 Add testVpnTypesEqual to verify consistency
VPN types are defined in both VpnManager.java and NativeVpnType.aidl.
The definitions on both sides should match (except TYPE_VPN_NONE).

VpnManager.java:
TYPE_VPN_NONE = -1
TYPE_VPN_SERVICE = 1
TYPE_VPN_PLATFORM = 2
TYPE_VPN_LEGACY = 3
TYPE_VPN_OEM = 4

NativeVpnType.aidl:
SERVICE = 1
PLATFORM = 2
LEGACY = 3
OEM = 4

Bug: N/A
Test: atest android.net.VpnManagerTest#testVpnTypesEqual
Change-Id: Ie618e227d861100c5318da696140e486af1093a0
2021-05-12 17:34:34 +08:00
Cody Kesting
fd57083e39 Create test-mode for VcnConfig.
This CL creates a test-mode for VcnConfig so that they will only
match with Test Networks. This is necessary for CTS testing so
that VCNs can run on test networks and IKE negotiations can be
injected over the Test Networks.

Bug: 182291467
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I5cc340e5aaa34c5de8efafa52de49185a18d4bd3
2021-05-11 18:32:32 -07:00
Cody Kesting
92959d6774 Require MOBIKE for IkeSessionParams in VCN configs.
This CL updates VcnGatewayConnectionConfigs to require
IkeTunnelConnectionParams with MOBIKE enabled for the
IkeSessionParams. This is necessary for VCNs - without it,
they do not support IPsec mobility (one of the main features
of the VCN).

Bug: 187851560
Test: atest FrameworksVcnTests CtsVcnTestCases
Change-Id: I94db52a8c42d9fa4681fefb8f787f006933caa18
2021-05-11 16:40:56 -07:00
Ken Chen
8dbaacfe45 Switch from networkCreate[Physical/Vpn] to networkCreate
networkCreatePhysical and networkCreateVpn are non-extensible. In order
to pass OEM requested VPN type to Netd, we need to migrate to
networkCreate API.

Modify test code accordingly since networkCreatePhysical and
networkCreateVpn have been deprecated on Netd.

Bug: 171872481
Test: atest FrameworksNetTests
atest atest HostsideVpnTests

Change-Id: I50ab8615346c49559c16e815482e7804a1e765c8
2021-05-11 16:06:54 +08:00
Benedict Wong
d7d2d2a15b Merge changes from topic "vcn-fwd"
* changes:
  Apply transform to FWD policy if configured to provide tethering
  Add internal support for IPsec forward policies
2021-05-11 01:30:31 +00:00
Benedict Wong
1d9c19a635 Add additional logging to improve debugability of VcnManagementService
Test: atest FrameworksVcnTests
Change-Id: I23af20ea655e11934f6ac679c1bfc0943d5a148f
2021-05-07 17:18:21 -07:00
Benedict Wong
7f5a2fe728 Add internal support for IPsec forward policies
This change adds support for IPsec forward policies, which are necessary
for packets to be allowed to be forwarded to another interface, as is
the case with tethering. This is necessary and useful only within the
system server, and as such is not exposed as a public API.

This change is safe, since the addition of a FWD policy on IPsec tunnel
interfaces will by default block forwarded traffic (as would be the case
without this patch). In the event that the (system) owner of the tunnel
requires support for forwarded packets (eg tethering), this patch allows
application of transforms in the FWD direction as well.

This will be used to ensure that the VCN can be used as the underlying
network for the purposes of tethering.

Bug: 185495453
Test: atest IpSecServiceTest
Test: atest IpSecServiceParameterizedTest
Test: manual testing with tethering over VCN
Change-Id: I74ecea71f1954029f6fbdbe34598c82e0aac386b
2021-05-07 15:09:42 -07:00
Chris Weir
9943124ba6 Print human-readable OEM managed states
For NetworkTemplate and NetworkIdentity, print human-readable
representations of the OEM managed state in the classes' respective
toString() functions.

Bug: 180557699
Test: Manual - run atest NetworkTemplateTest NetworkIdentityTest
and verify that the logcat output shows the String representation of the
OEM managed state correctly.

Change-Id: Ia180b911f91f41937ac713e6b3691d82f682e146
2021-05-07 10:26:31 -07:00
Treehugger Robot
2f83b6a72d Merge "Add getters to NetworkStateSnapshot" 2021-04-29 09:20:34 +00:00
Treehugger Robot
e2e8b9ce88 Merge "Add getters to UnderlyingNetworkInfo" 2021-04-29 07:29:08 +00:00
Benedict Wong
c6fe30068d Merge "Update set|getRetryIntervalsMs to Millis" 2021-04-29 04:35:45 +00:00
Benedict Wong
913ae2b89b Allow VcnTransportInfo to be parcelled
Allows VCN transport info to be parcelled for purposes of sysUI

Bug: 186025257
Test: atest FrameworksVcnTests
Change-Id: I5a5d9b88659c8dcaa9ded16d491b2bac0529169a
2021-04-27 17:35:44 -07:00
Benedict Wong
e7f06d9eb9 Update set|getRetryIntervalsMs to Millis
Bug: 184612525
Test: atest FrameworksVcnTests
Change-Id: I696854960ca9488ae2c8a0c569c57a8563998ac8
2021-04-27 22:28:43 +00:00
Yan Yan
b8f67d1bd7 Merge "Remove TunnelConnectionParams interface" 2021-04-27 18:34:08 +00:00
Les Lee
bef2f5be94 Merge "wifi data usage: support to get carrier merged wifi network." 2021-04-27 02:13:32 +00:00
Yan Yan
de7222cba5 Remove TunnelConnectionParams interface
To avoid exposing empty interface.

Test: atest FrameworksVcnTests
Bug: 180664474
Change-Id: Ia33e75b77f1563a1c3d31e0145b7ec2be728b6db
2021-04-26 10:47:05 -07:00
Aaron Huang
7511be401e Add getters to UnderlyingNetworkInfo
Address API review feedback, add getters to UnderlyingNetworkInfo
instead of exposing fields.

Instead of wasting memory by converting this into an array, have
migrateTun take a List<String>. In turn, tunAdjustmentInit should
also take a List<String>.

(cherry picked from ag/14211075)
Bug: 183972554
Test: atest android.net.UnderlyingNetworkInfoTest
Merged-In: Id59744097208d91298a25ef110ade91a9cf291a1
Change-Id: Id59744097208d91298a25ef110ade91a9cf291a1
2021-04-22 22:30:42 +08:00
Aaron Huang
a3ae9b1c38 Add getters to NetworkStateSnapshot
Address API council feedback, add getters to NetworkStateSnapshot
instead of exposing the bare fields directly.

(cherry picked from ag/14233655)
Bug: 183972826
Test: FrameworksNetTests
Merged-In: Id1707753b42ae88d2b95e4bd00a792609434e4f5
Change-Id: Id1707753b42ae88d2b95e4bd00a792609434e4f5
2021-04-22 18:21:00 +08:00
Yan Yan
bc545c8a8a Merge changes from topics "encrypted-tunnel-interface", "iketunnelparams", "vcn-encrypted-tunnel"
* changes:
  Replace VcnControlPlaneConfig with TunnelConnectionParams
  Convert TunnelConnectionParams to/from PersistableBundle
  Create TunnelConnectionParams interface
2021-04-22 08:39:20 +00:00
Yan Yan
4eaa894d84 Replace VcnControlPlaneConfig with TunnelConnectionParams
Use the more generic object TunnelConnectionParams in VCN.
TunnelConnectionParams may also be used in VPN in the future.

Test: atest FrameworksVcnTests
Bug: 180664474
Change-Id: Ie433f9df614e1f51cdff200d915b68b61e5ca35e
2021-04-21 22:52:22 -07:00
Yan Yan
c0b7c4fa5a Convert TunnelConnectionParams to/from PersistableBundle
Add utility class to convert TunnelConnectionParams to and from
PersistableBundle.

Bug: 180664474
Test: atest EncryptedTunnelParamsUtilsTest
Change-Id: I93ae068eb6d1e1c4d3fcbaccbaae867db8d07a38
2021-04-21 22:49:47 -07:00
Yan Yan
83956e2a5d Create TunnelConnectionParams interface
TunnelConnectionParams represents configurations for setting up a
secure encrypted tunnel with a remote endpoint. TunnelConnectionParams
will be used to configure a VCN and will be used for VPN configuration
in the future.

Bug: 180664474
Test: make update-api
Change-Id: Ic8e5c8535e84971517f16c54ce8b8645cfc7f944
2021-04-21 22:48:21 -07:00
Lorenzo Colitti
0549ca0217 Merge "Hide NetworkPolicyManager.blockedReasonsToString API." 2021-04-22 02:36:11 +00:00
Benedict Wong
80afe1eeee Merge changes I64b56575,I40553a7b
* changes:
  Expose API for retrieval of subscription groups with VCN configured
  Add support for retrieval of configured VCNs by carrier privilege
2021-04-22 01:31:11 +00:00
Benedict Wong
d776b3762e Expose API for retrieval of subscription groups with VCN configured
Per API council feedback, this change adds a new API to retrieve all
subscription groups that have a VCN configured.

Bug: 184612525
Test: atest FrameworksVcnTests
Test: atest CtsVcnTestCases
Change-Id: I64b565758e0a27552eee9f860e0674db2fb35980
2021-04-21 13:49:35 -07:00