19066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project/* 29066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * Copyright 2008, The Android Open Source Project 39066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * 4dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * Licensed under the Apache License, Version 2.0 (the "License"); 5dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * you may not use this file except in compliance with the License. 6dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * You may obtain a copy of the License at 79066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * 8dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * http://www.apache.org/licenses/LICENSE-2.0 99066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * 10dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * Unless required by applicable law or agreed to in writing, software 11dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * distributed under the License is distributed on an "AS IS" BASIS, 12dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13dd66bcbf9d6ef0c50a18d9c4b1b39ce7ef7afcc4Elliott Hughes * See the License for the specific language governing permissions and 149066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * limitations under the License. 159066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project */ 169066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 179066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#define LOG_TAG "NetUtils" 189066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 199066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include "jni.h" 2012324b46049f9bcba9aa3d5fe7ae540d49a03076Chad Brubaker#include "JNIHelp.h" 213876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen#include "NetdClient.h" 229066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <utils/misc.h> 239066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <android_runtime/AndroidRuntime.h> 249066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <utils/Log.h> 259066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#include <arpa/inet.h> 26cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <net/if.h> 27cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/filter.h> 28cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if.h> 29578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <linux/if_arp.h> 30cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if_ether.h> 31cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <linux/if_packet.h> 32cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <net/if_ether.h> 33578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <netinet/icmp6.h> 34cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <netinet/ip.h> 35578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen#include <netinet/ip6.h> 36cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti#include <netinet/udp.h> 370216e618198393bfd7ac0625fa6ad251d5ea682fRobert Greenwalt#include <cutils/properties.h> 389066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 39987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe#include "core_jni_helpers.h" 40987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe 419066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectextern "C" { 420900f3657664d9046e6723825fd32b244eef2b6cMike Lockwoodint ifc_enable(const char *ifname); 439066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectint ifc_disable(const char *ifname); 449066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project} 459066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 469066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project#define NETUTILS_PKG_NAME "android/net/NetworkUtils" 479066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 489066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectnamespace android { 499066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 50473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kEtherTypeOffset = offsetof(ether_header, ether_type); 51473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kEtherHeaderLen = sizeof(ether_header); 52473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv4Protocol = kEtherHeaderLen + offsetof(iphdr, protocol); 53473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv4FlagsOffset = kEtherHeaderLen + offsetof(iphdr, frag_off); 54473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv6NextHeader = kEtherHeaderLen + offsetof(ip6_hdr, ip6_nxt); 55473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kIPv6PayloadStart = kEtherHeaderLen + sizeof(ip6_hdr); 56473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kICMPv6TypeOffset = kIPv6PayloadStart + offsetof(icmp6_hdr, icmp6_type); 57473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kUDPSrcPortIndirectOffset = kEtherHeaderLen + offsetof(udphdr, source); 58473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic const uint32_t kUDPDstPortIndirectOffset = kEtherHeaderLen + offsetof(udphdr, dest); 59cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colittistatic const uint16_t kDhcpClientPort = 68; 60cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 61cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colittistatic void android_net_utils_attachDhcpFilter(JNIEnv *env, jobject clazz, jobject javaFd) 62cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti{ 63cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti struct sock_filter filter_code[] = { 64cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti // Check the protocol is UDP. 65473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kIPv4Protocol), 66cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_UDP, 0, 6), 67cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 68cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti // Check this is not a fragment. 69473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_ABS, kIPv4FlagsOffset), 70473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JSET | BPF_K, IP_OFFMASK, 4, 0), 71cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 72cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti // Get the IP header length. 73473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LDX | BPF_B | BPF_MSH, kEtherHeaderLen), 74cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 75cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti // Check the destination port. 76473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_IND, kUDPDstPortIndirectOffset), 77cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, kDhcpClientPort, 0, 1), 78cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 79cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti // Accept or reject. 80cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti BPF_STMT(BPF_RET | BPF_K, 0xffff), 81cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti BPF_STMT(BPF_RET | BPF_K, 0) 82cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti }; 83cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti struct sock_fprog filter = { 84cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti sizeof(filter_code) / sizeof(filter_code[0]), 85cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti filter_code, 86cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti }; 87cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 88578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen int fd = jniGetFDFromFileDescriptor(env, javaFd); 89578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) { 90578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen jniThrowExceptionFmt(env, "java/net/SocketException", 91578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno)); 92578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen } 93578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen} 94578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen 95578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensenstatic void android_net_utils_attachRaFilter(JNIEnv *env, jobject clazz, jobject javaFd, 96578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen jint hardwareAddressType) 97578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen{ 98578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen if (hardwareAddressType != ARPHRD_ETHER) { 99578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen jniThrowExceptionFmt(env, "java/net/SocketException", 100578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen "attachRaFilter only supports ARPHRD_ETHER"); 101578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen return; 102578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen } 103578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen 104578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen struct sock_filter filter_code[] = { 105578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen // Check IPv6 Next Header is ICMPv6. 106473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kIPv6NextHeader), 107578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_ICMPV6, 0, 3), 108578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen 109578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen // Check ICMPv6 type is Router Advertisement. 110473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kICMPv6TypeOffset), 111578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ND_ROUTER_ADVERT, 0, 1), 112578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen 113578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen // Accept or reject. 114578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen BPF_STMT(BPF_RET | BPF_K, 0xffff), 115578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen BPF_STMT(BPF_RET | BPF_K, 0) 116578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen }; 117578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen struct sock_fprog filter = { 118578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen sizeof(filter_code) / sizeof(filter_code[0]), 119578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen filter_code, 120578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen }; 121578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen 122578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen int fd = jniGetFDFromFileDescriptor(env, javaFd); 123cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) { 124cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti jniThrowExceptionFmt(env, "java/net/SocketException", 125cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno)); 126cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti } 127cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti} 128cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 129473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline// TODO: Move all this filter code into libnetutils. 130473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Klinestatic void android_net_utils_attachControlPacketFilter( 131473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline JNIEnv *env, jobject clazz, jobject javaFd, jint hardwareAddressType) { 132473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline if (hardwareAddressType != ARPHRD_ETHER) { 133473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 134473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline "attachControlPacketFilter only supports ARPHRD_ETHER"); 135473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline return; 136473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline } 137473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 138473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Capture all: 139473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // - ARPs 140473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // - DHCPv4 packets 141473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // - Router Advertisements & Solicitations 142473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // - Neighbor Advertisements & Solicitations 143473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // 144473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // tcpdump: 145473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // arp or 146473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // '(ip and udp port 68)' or 147473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // '(icmp6 and ip6[40] >= 133 and ip6[40] <= 136)' 148473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline struct sock_filter filter_code[] = { 149473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Load the link layer next payload field. 150473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_ABS, kEtherTypeOffset), 151473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 152473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Accept all ARP. 153473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // TODO: Figure out how to better filter ARPs on noisy networks. 154473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_ARP, 16, 0), 155473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 156473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // If IPv4: 157473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_IP, 0, 9), 158473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 159473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Check the protocol is UDP. 160473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kIPv4Protocol), 161473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_UDP, 0, 14), 162473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 163473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Check this is not a fragment. 164473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_ABS, kIPv4FlagsOffset), 165473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JSET | BPF_K, IP_OFFMASK, 12, 0), 166473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 167473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Get the IP header length. 168473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LDX | BPF_B | BPF_MSH, kEtherHeaderLen), 169473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 170473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Check the source port. 171473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_IND, kUDPSrcPortIndirectOffset), 172473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, kDhcpClientPort, 8, 0), 173473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 174473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Check the destination port. 175473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_H | BPF_IND, kUDPDstPortIndirectOffset), 176473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, kDhcpClientPort, 6, 7), 177473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 178473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // IPv6 ... 179473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ETHERTYPE_IPV6, 0, 6), 180473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // ... check IPv6 Next Header is ICMPv6 (ignore fragments), ... 181473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kIPv6NextHeader), 182473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_ICMPV6, 0, 4), 183473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // ... and check the ICMPv6 type is one of RS/RA/NS/NA. 184473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_LD | BPF_B | BPF_ABS, kICMPv6TypeOffset), 185473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JGE | BPF_K, ND_ROUTER_SOLICIT, 0, 2), 186473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_JUMP(BPF_JMP | BPF_JGT | BPF_K, ND_NEIGHBOR_ADVERT, 1, 0), 187473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 188473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline // Accept or reject. 189473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_RET | BPF_K, 0xffff), 190473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline BPF_STMT(BPF_RET | BPF_K, 0) 191473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline }; 192473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline struct sock_fprog filter = { 193473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline sizeof(filter_code) / sizeof(filter_code[0]), 194473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline filter_code, 195473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline }; 196473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 197473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline int fd = jniGetFDFromFileDescriptor(env, javaFd); 198473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) { 199473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 200473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno)); 201473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline } 202473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline} 203473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline 204a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Klinestatic void android_net_utils_setupRaSocket(JNIEnv *env, jobject clazz, jobject javaFd, 205a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jint ifIndex) 206a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline{ 207a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline static const int kLinkLocalHopLimit = 255; 208a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 209a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline int fd = jniGetFDFromFileDescriptor(env, javaFd); 210a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 211a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Set an ICMPv6 filter that only passes Router Solicitations. 212a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline struct icmp6_filter rs_only; 213a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline ICMP6_FILTER_SETBLOCKALL(&rs_only); 214a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline ICMP6_FILTER_SETPASS(ND_ROUTER_SOLICIT, &rs_only); 215a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline socklen_t len = sizeof(rs_only); 216a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_ICMPV6, ICMP6_FILTER, &rs_only, len) != 0) { 217a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 218a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(ICMP6_FILTER): %s", strerror(errno)); 219a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 220a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 221a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 222a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Most/all of the rest of these options can be set via Java code, but 223a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // because we're here on account of setting an icmp6_filter go ahead 224a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // and do it all natively for now. 225a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // 226a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // TODO: Consider moving these out to Java. 227a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 228a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Set the multicast hoplimit to 255 (link-local only). 229a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline int hops = kLinkLocalHopLimit; 230a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(hops); 231a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_HOPS, &hops, len) != 0) { 232a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 233a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(IPV6_MULTICAST_HOPS): %s", strerror(errno)); 234a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 235a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 236a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 237a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Set the unicast hoplimit to 255 (link-local only). 238a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline hops = kLinkLocalHopLimit; 239a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(hops); 240a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &hops, len) != 0) { 241a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 242a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(IPV6_UNICAST_HOPS): %s", strerror(errno)); 243a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 244a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 245a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 246a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Explicitly disable multicast loopback. 247a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline int off = 0; 248a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(off); 249a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_LOOP, &off, len) != 0) { 250a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 251a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(IPV6_MULTICAST_LOOP): %s", strerror(errno)); 252a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 253a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 254a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 255a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Specify the IPv6 interface to use for outbound multicast. 256a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(ifIndex); 257a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_IF, &ifIndex, len) != 0) { 258a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 259a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(IPV6_MULTICAST_IF): %s", strerror(errno)); 260a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 261a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 262a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 263a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Additional options to be considered: 264a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // - IPV6_TCLASS 265a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // - IPV6_RECVPKTINFO 266a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // - IPV6_RECVHOPLIMIT 267a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 268a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Bind to [::]. 269a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline const struct sockaddr_in6 sin6 = { 270a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .sin6_family = AF_INET6, 271a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .sin6_port = 0, 272a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .sin6_flowinfo = 0, 273a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .sin6_addr = IN6ADDR_ANY_INIT, 274a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .sin6_scope_id = 0, 275a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline }; 276a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline auto sa = reinterpret_cast<const struct sockaddr *>(&sin6); 277a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(sin6); 278a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (bind(fd, sa, len) != 0) { 279a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 280a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "bind(IN6ADDR_ANY): %s", strerror(errno)); 281a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 282a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 283a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 284a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline // Join the all-routers multicast group, ff02::2%index. 285a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline struct ipv6_mreq all_rtrs = { 286a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .ipv6mr_multiaddr = {{{0xff,2,0,0,0,0,0,0,0,0,0,0,0,0,0,2}}}, 287a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline .ipv6mr_interface = ifIndex, 288a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline }; 289a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline len = sizeof(all_rtrs); 290a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline if (setsockopt(fd, IPPROTO_IPV6, IPV6_JOIN_GROUP, &all_rtrs, len) != 0) { 291a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline jniThrowExceptionFmt(env, "java/net/SocketException", 292a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline "setsockopt(IPV6_JOIN_GROUP): %s", strerror(errno)); 293a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline return; 294a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline } 295a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline} 296a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline 29732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensenstatic jboolean android_net_utils_bindProcessToNetwork(JNIEnv *env, jobject thiz, jint netId) 2983876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{ 29932a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen return (jboolean) !setNetworkForProcess(netId); 3003876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen} 3013876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen 30272db88e46fba5f2581eb21c042dc79887cda1c10Paul Jensenstatic jint android_net_utils_getBoundNetworkForProcess(JNIEnv *env, jobject thiz) 3033876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{ 3043876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen return getNetworkForProcess(); 3053876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen} 3063876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen 30732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensenstatic jboolean android_net_utils_bindProcessToNetworkForHostResolution(JNIEnv *env, jobject thiz, 30832a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen jint netId) 3093876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{ 31032a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen return (jboolean) !setNetworkForResolv(netId); 3113876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen} 3123876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen 3139f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colittistatic jint android_net_utils_bindSocketToNetwork(JNIEnv *env, jobject thiz, jint socket, 31432a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen jint netId) 3153876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen{ 3169f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colitti return setNetworkForSocket(netId, socket); 3173876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen} 3183876495129cce3ed8ac6f247189b075dc9baec8fPaul Jensen 3196bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensenstatic jboolean android_net_utils_protectFromVpn(JNIEnv *env, jobject thiz, jint socket) 3206bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen{ 3216bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen return (jboolean) !protectFromVpn(socket); 3226bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen} 3236bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen 324cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensenstatic jboolean android_net_utils_queryUserAccess(JNIEnv *env, jobject thiz, jint uid, jint netId) 325cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen{ 326cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen return (jboolean) !queryUserAccess(uid, netId); 327cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen} 328cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen 329cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti 3309066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project// ---------------------------------------------------------------------------- 3319066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 3329066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project/* 3339066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project * JNI registration. 3349066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project */ 33576f6a86de25e1bf74717e047e55fd44b089673f3Daniel Micaystatic const JNINativeMethod gNetworkUtilMethods[] = { 3369066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project /* name, signature, funcPtr */ 33732a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen { "bindProcessToNetwork", "(I)Z", (void*) android_net_utils_bindProcessToNetwork }, 33872db88e46fba5f2581eb21c042dc79887cda1c10Paul Jensen { "getBoundNetworkForProcess", "()I", (void*) android_net_utils_getBoundNetworkForProcess }, 33932a58f00d388584f5f47c0d5d4c74ce7c8457d78Paul Jensen { "bindProcessToNetworkForHostResolution", "(I)Z", (void*) android_net_utils_bindProcessToNetworkForHostResolution }, 3409f1274b7e43d14c7e3a42148ebfda3905fec8b06Lorenzo Colitti { "bindSocketToNetwork", "(II)I", (void*) android_net_utils_bindSocketToNetwork }, 3416bc2c2c34f2b23eae79ad733c97a691734055c4fPaul Jensen { "protectFromVpn", "(I)Z", (void*)android_net_utils_protectFromVpn }, 342cee9b51c4beec4494d78bab784ba7e7e20c30e31Paul Jensen { "queryUserAccess", "(II)Z", (void*)android_net_utils_queryUserAccess }, 343cbe4f7c225f87ef1e8cb496bce434f334774bc88Lorenzo Colitti { "attachDhcpFilter", "(Ljava/io/FileDescriptor;)V", (void*) android_net_utils_attachDhcpFilter }, 344578a76e7de77492ac33e407fff4fb9a2f5550d8aPaul Jensen { "attachRaFilter", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_attachRaFilter }, 345473355f96b91a1fbeb6f8f8f0bcd3c887da12f40Erik Kline { "attachControlPacketFilter", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_attachControlPacketFilter }, 346a3ca6bd3e03a5311b37e4c1c7a9e8625e53d78b3Erik Kline { "setupRaSocket", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_setupRaSocket }, 3479066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project}; 3489066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 3499066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Projectint register_android_net_NetworkUtils(JNIEnv* env) 3509066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project{ 351987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe return RegisterMethodsOrDie(env, NETUTILS_PKG_NAME, gNetworkUtilMethods, 352987f79f60bb1f0a4bcd3ef22e57301c743f0b94fAndreas Gampe NELEM(gNetworkUtilMethods)); 3539066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project} 3549066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project 3559066cfe9886ac131c34d59ed0e2d287b0e3c0087The Android Open Source Project}; // namespace android 356