19066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project/*
29066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * Copyright 2008, The Android Open Source Project
39066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project *
4dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * Licensed under the Apache License, Version 2.0 (the "License");
5dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * you may not use this file except in compliance with the License.
6dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * You may obtain a copy of the License at
79066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project *
8dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes *     http://www.apache.org/licenses/LICENSE-2.0
99066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project *
10dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * Unless required by applicable law or agreed to in writing, software
11dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * distributed under the License is distributed on an "AS IS" BASIS,
12dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * See the License for the specific language governing permissions and
149066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * limitations under the License.
159066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project */
169066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
179066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#define LOG_TAG "NetUtils"
189066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
199066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include "jni.h"
2012324b46049f9bcba9aa3d5fe7ae540d49a03076Chad Brubaker#include "JNIHelp.h"
213876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen#include "NetdClient.h"
229066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <utils/misc.h>
239066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <android_runtime/AndroidRuntime.h>
249066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <utils/Log.h>
259066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <arpa/inet.h>
26cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <net/if.h>
27cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/filter.h>
28cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if.h>
29578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <linux/if_arp.h>
30cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if_ether.h>
31cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if_packet.h>
32cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <net/if_ether.h>
33578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <netinet/icmp6.h>
34cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <netinet/ip.h>
35578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <netinet/ip6.h>
36cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <netinet/udp.h>
370216e618198393bfd7ac0625fa6ad251d5ea682fRobert Greenwalt#include <cutils/properties.h>
389066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
39987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe#include "core_jni_helpers.h"
40987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe
419066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectextern "C" {
420900f3657664d9046e6723825fd32b244eef2b6cMike Lockwoodint ifc_enable(const char *ifname);
439066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectint ifc_disable(const char *ifname);
449066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project}
459066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
469066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#define NETUTILS_PKG_NAME "android/net/NetworkUtils"
479066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
489066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectnamespace android {
499066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
50473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kEtherTypeOffset = offsetof(ether_header, ether_type);
51473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kEtherHeaderLen = sizeof(ether_header);
52473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv4Protocol = kEtherHeaderLen + offsetof(iphdr, protocol);
53473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv4FlagsOffset = kEtherHeaderLen + offsetof(iphdr, frag_off);
54473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv6NextHeader = kEtherHeaderLen + offsetof(ip6_hdr, ip6_nxt);
55473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv6PayloadStart = kEtherHeaderLen + sizeof(ip6_hdr);
56473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kICMPv6TypeOffset = kIPv6PayloadStart + offsetof(icmp6_hdr, icmp6_type);
57473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kUDPSrcPortIndirectOffset = kEtherHeaderLen + offsetof(udphdr, source);
58473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kUDPDstPortIndirectOffset = kEtherHeaderLen + offsetof(udphdr, dest);
59cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colittistatic const uint16_t kDhcpClientPort = 68;
60cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
61cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colittistatic void android_net_utils_attachDhcpFilter(JNIEnv *env, jobject clazz, jobject javaFd)
62cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti{
63cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    struct sock_filter filter_code[] = {
64cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        // Check the protocol is UDP.
65473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kIPv4Protocol),
66cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K,    IPPROTO_UDP, 0, 6),
67cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
68cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        // Check this is not a fragment.
69473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H    | BPF_ABS, kIPv4FlagsOffset),
70473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JSET | BPF_K,   IP_OFFMASK, 4, 0),
71cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
72cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        // Get the IP header length.
73473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LDX | BPF_B    | BPF_MSH, kEtherHeaderLen),
74cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
75cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        // Check the destination port.
76473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H    | BPF_IND, kUDPDstPortIndirectOffset),
77cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        BPF_JUMP(BPF_JMP | BPF_JEQ  | BPF_K,   kDhcpClientPort, 0, 1),
78cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
79cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        // Accept or reject.
80cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        BPF_STMT(BPF_RET | BPF_K,              0xffff),
81cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        BPF_STMT(BPF_RET | BPF_K,              0)
82cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    };
83cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    struct sock_fprog filter = {
84cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        sizeof(filter_code) / sizeof(filter_code[0]),
85cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        filter_code,
86cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    };
87cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
88578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    int fd = jniGetFDFromFileDescriptor(env, javaFd);
89578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) {
90578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        jniThrowExceptionFmt(env, "java/net/SocketException",
91578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen                "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno));
92578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    }
93578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen}
94578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen
95578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensenstatic void android_net_utils_attachRaFilter(JNIEnv *env, jobject clazz, jobject javaFd,
96578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        jint hardwareAddressType)
97578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen{
98578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    if (hardwareAddressType != ARPHRD_ETHER) {
99578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        jniThrowExceptionFmt(env, "java/net/SocketException",
100578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen                "attachRaFilter only supports ARPHRD_ETHER");
101578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        return;
102578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    }
103578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen
104578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    struct sock_filter filter_code[] = {
105578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        // Check IPv6 Next Header is ICMPv6.
106473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kIPv6NextHeader),
107578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K,    IPPROTO_ICMPV6, 0, 3),
108578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen
109578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        // Check ICMPv6 type is Router Advertisement.
110473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kICMPv6TypeOffset),
111578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K,    ND_ROUTER_ADVERT, 0, 1),
112578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen
113578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        // Accept or reject.
114578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        BPF_STMT(BPF_RET | BPF_K,              0xffff),
115578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        BPF_STMT(BPF_RET | BPF_K,              0)
116578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    };
117578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    struct sock_fprog filter = {
118578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        sizeof(filter_code) / sizeof(filter_code[0]),
119578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen        filter_code,
120578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    };
121578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen
122578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    int fd = jniGetFDFromFileDescriptor(env, javaFd);
123cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) {
124cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti        jniThrowExceptionFmt(env, "java/net/SocketException",
125cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti                "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno));
126cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    }
127cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti}
128cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
129473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline// TODO: Move all this filter code into libnetutils.
130473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic void android_net_utils_attachControlPacketFilter(
131473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        JNIEnv *env, jobject clazz, jobject javaFd, jint hardwareAddressType) {
132473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    if (hardwareAddressType != ARPHRD_ETHER) {
133473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
134473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline                "attachControlPacketFilter only supports ARPHRD_ETHER");
135473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        return;
136473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    }
137473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
138473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    // Capture all:
139473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     - ARPs
140473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     - DHCPv4 packets
141473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     - Router Advertisements & Solicitations
142473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     - Neighbor Advertisements & Solicitations
143473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //
144473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    // tcpdump:
145473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     arp or
146473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     '(ip and udp port 68)' or
147473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    //     '(icmp6 and ip6[40] >= 133 and ip6[40] <= 136)'
148473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    struct sock_filter filter_code[] = {
149473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Load the link layer next payload field.
150473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H   | BPF_ABS,  kEtherTypeOffset),
151473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
152473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Accept all ARP.
153473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // TODO: Figure out how to better filter ARPs on noisy networks.
154473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_ARP, 16, 0),
155473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
156473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // If IPv4:
157473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_IP, 0, 9),
158473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
159473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Check the protocol is UDP.
160473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kIPv4Protocol),
161473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K,    IPPROTO_UDP, 0, 14),
162473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
163473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Check this is not a fragment.
164473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H    | BPF_ABS, kIPv4FlagsOffset),
165473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JSET | BPF_K,   IP_OFFMASK, 12, 0),
166473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
167473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Get the IP header length.
168473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LDX | BPF_B    | BPF_MSH, kEtherHeaderLen),
169473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
170473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Check the source port.
171473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H    | BPF_IND, kUDPSrcPortIndirectOffset),
172473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ  | BPF_K,   kDhcpClientPort, 8, 0),
173473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
174473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Check the destination port.
175473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_H    | BPF_IND, kUDPDstPortIndirectOffset),
176473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ  | BPF_K,   kDhcpClientPort, 6, 7),
177473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
178473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // IPv6 ...
179473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_IPV6, 0, 6),
180473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // ... check IPv6 Next Header is ICMPv6 (ignore fragments), ...
181473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kIPv6NextHeader),
182473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K,    IPPROTO_ICMPV6, 0, 4),
183473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // ... and check the ICMPv6 type is one of RS/RA/NS/NA.
184473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_LD  | BPF_B   | BPF_ABS,  kICMPv6TypeOffset),
185473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JGE | BPF_K,    ND_ROUTER_SOLICIT, 0, 2),
186473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_JUMP(BPF_JMP | BPF_JGT | BPF_K,    ND_NEIGHBOR_ADVERT, 1, 0),
187473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
188473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        // Accept or reject.
189473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_RET | BPF_K,              0xffff),
190473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        BPF_STMT(BPF_RET | BPF_K,              0)
191473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    };
192473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    struct sock_fprog filter = {
193473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        sizeof(filter_code) / sizeof(filter_code[0]),
194473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        filter_code,
195473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    };
196473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
197473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    int fd = jniGetFDFromFileDescriptor(env, javaFd);
198473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) {
199473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
200473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline                "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno));
201473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    }
202473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline}
203473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline
204a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Klinestatic void android_net_utils_setupRaSocket(JNIEnv *env, jobject clazz, jobject javaFd,
205a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jint ifIndex)
206a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline{
207a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    static const int kLinkLocalHopLimit = 255;
208a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
209a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    int fd = jniGetFDFromFileDescriptor(env, javaFd);
210a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
211a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Set an ICMPv6 filter that only passes Router Solicitations.
212a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    struct icmp6_filter rs_only;
213a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    ICMP6_FILTER_SETBLOCKALL(&rs_only);
214a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    ICMP6_FILTER_SETPASS(ND_ROUTER_SOLICIT, &rs_only);
215a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    socklen_t len = sizeof(rs_only);
216a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_ICMPV6, ICMP6_FILTER, &rs_only, len) != 0) {
217a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
218a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(ICMP6_FILTER): %s", strerror(errno));
219a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
220a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
221a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
222a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Most/all of the rest of these options can be set via Java code, but
223a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // because we're here on account of setting an icmp6_filter go ahead
224a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // and do it all natively for now.
225a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    //
226a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // TODO: Consider moving these out to Java.
227a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
228a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Set the multicast hoplimit to 255 (link-local only).
229a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    int hops = kLinkLocalHopLimit;
230a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(hops);
231a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_HOPS, &hops, len) != 0) {
232a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
233a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(IPV6_MULTICAST_HOPS): %s", strerror(errno));
234a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
235a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
236a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
237a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Set the unicast hoplimit to 255 (link-local only).
238a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    hops = kLinkLocalHopLimit;
239a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(hops);
240a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &hops, len) != 0) {
241a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
242a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(IPV6_UNICAST_HOPS): %s", strerror(errno));
243a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
244a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
245a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
246a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Explicitly disable multicast loopback.
247a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    int off = 0;
248a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(off);
249a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_LOOP, &off, len) != 0) {
250a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
251a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(IPV6_MULTICAST_LOOP): %s", strerror(errno));
252a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
253a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
254a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
255a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Specify the IPv6 interface to use for outbound multicast.
256a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(ifIndex);
257a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_IF, &ifIndex, len) != 0) {
258a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
259a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(IPV6_MULTICAST_IF): %s", strerror(errno));
260a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
261a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
262a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
263a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Additional options to be considered:
264a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    //     - IPV6_TCLASS
265a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    //     - IPV6_RECVPKTINFO
266a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    //     - IPV6_RECVHOPLIMIT
267a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
268a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Bind to [::].
269a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    const struct sockaddr_in6 sin6 = {
270a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline            .sin6_family = AF_INET6,
271a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline            .sin6_port = 0,
272a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline            .sin6_flowinfo = 0,
273a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline            .sin6_addr = IN6ADDR_ANY_INIT,
274a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline            .sin6_scope_id = 0,
275a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    };
276a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    auto sa = reinterpret_cast<const struct sockaddr *>(&sin6);
277a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(sin6);
278a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (bind(fd, sa, len) != 0) {
279a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
280a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "bind(IN6ADDR_ANY): %s", strerror(errno));
281a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
282a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
283a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
284a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    // Join the all-routers multicast group, ff02::2%index.
285a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    struct ipv6_mreq all_rtrs = {
286a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        .ipv6mr_multiaddr = {{{0xff,2,0,0,0,0,0,0,0,0,0,0,0,0,0,2}}},
287a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        .ipv6mr_interface = ifIndex,
288a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    };
289a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    len = sizeof(all_rtrs);
290a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    if (setsockopt(fd, IPPROTO_IPV6, IPV6_JOIN_GROUP, &all_rtrs, len) != 0) {
291a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        jniThrowExceptionFmt(env, "java/net/SocketException",
292a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline                "setsockopt(IPV6_JOIN_GROUP): %s", strerror(errno));
293a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline        return;
294a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    }
295a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline}
296a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline
29732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensenstatic jboolean android_net_utils_bindProcessToNetwork(JNIEnv *env, jobject thiz, jint netId)
2983876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{
29932a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen    return (jboolean) !setNetworkForProcess(netId);
3003876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen}
3013876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen
30272db88e46fba5f2581eb21c042dc79887cda1c10Paul Jensenstatic jint android_net_utils_getBoundNetworkForProcess(JNIEnv *env, jobject thiz)
3033876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{
3043876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen    return getNetworkForProcess();
3053876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen}
3063876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen
30732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensenstatic jboolean android_net_utils_bindProcessToNetworkForHostResolution(JNIEnv *env, jobject thiz,
30832a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen        jint netId)
3093876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{
31032a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen    return (jboolean) !setNetworkForResolv(netId);
3113876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen}
3123876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen
3139f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colittistatic jint android_net_utils_bindSocketToNetwork(JNIEnv *env, jobject thiz, jint socket,
31432a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen        jint netId)
3153876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{
3169f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colitti    return setNetworkForSocket(netId, socket);
3173876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen}
3183876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen
3196bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensenstatic jboolean android_net_utils_protectFromVpn(JNIEnv *env, jobject thiz, jint socket)
3206bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen{
3216bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen    return (jboolean) !protectFromVpn(socket);
3226bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen}
3236bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen
324cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensenstatic jboolean android_net_utils_queryUserAccess(JNIEnv *env, jobject thiz, jint uid, jint netId)
325cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen{
326cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen    return (jboolean) !queryUserAccess(uid, netId);
327cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen}
328cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen
329cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti
3309066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project// ----------------------------------------------------------------------------
3319066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
3329066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project/*
3339066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * JNI registration.
3349066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project */
33576f6a86de25e1bf74717e047e55fd44b089673f3Daniel Micaystatic const JNINativeMethod gNetworkUtilMethods[] = {
3369066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project    /* name, signature, funcPtr */
33732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen    { "bindProcessToNetwork", "(I)Z", (void*) android_net_utils_bindProcessToNetwork },
33872db88e46fba5f2581eb21c042dc79887cda1c10Paul Jensen    { "getBoundNetworkForProcess", "()I", (void*) android_net_utils_getBoundNetworkForProcess },
33932a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen    { "bindProcessToNetworkForHostResolution", "(I)Z", (void*) android_net_utils_bindProcessToNetworkForHostResolution },
3409f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colitti    { "bindSocketToNetwork", "(II)I", (void*) android_net_utils_bindSocketToNetwork },
3416bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen    { "protectFromVpn", "(I)Z", (void*)android_net_utils_protectFromVpn },
342cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen    { "queryUserAccess", "(II)Z", (void*)android_net_utils_queryUserAccess },
343cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti    { "attachDhcpFilter", "(Ljava/io/FileDescriptor;)V", (void*) android_net_utils_attachDhcpFilter },
344578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen    { "attachRaFilter", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_attachRaFilter },
345473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline    { "attachControlPacketFilter", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_attachControlPacketFilter },
346a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline    { "setupRaSocket", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_setupRaSocket },
3479066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project};
3489066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
3499066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectint register_android_net_NetworkUtils(JNIEnv* env)
3509066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project{
351987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe    return RegisterMethodsOrDie(env, NETUTILS_PKG_NAME, gNetworkUtilMethods,
352987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe                                NELEM(gNetworkUtilMethods));
3539066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project}
3549066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project
3559066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project}; // namespace android
356