1 /* 2 * Copyright 2008, The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 #define LOG_TAG "NetUtils" 18 19 #include "jni.h" 20 #include "JNIHelp.h" 21 #include "NetdClient.h" 22 #include <utils/misc.h> 23 #include <android_runtime/AndroidRuntime.h> 24 #include <utils/Log.h> 25 #include <arpa/inet.h> 26 #include <net/if.h> 27 #include <linux/filter.h> 28 #include <linux/if.h> 29 #include <linux/if_arp.h> 30 #include <linux/if_ether.h> 31 #include <linux/if_packet.h> 32 #include <net/if_ether.h> 33 #include <netinet/icmp6.h> 34 #include <netinet/ip.h> 35 #include <netinet/ip6.h> 36 #include <netinet/udp.h> 37 #include <cutils/properties.h> 38 39 #include "core_jni_helpers.h" 40 41 extern "C" { 42 int ifc_enable(const char *ifname); 43 int ifc_disable(const char *ifname); 44 } 45 46 #define NETUTILS_PKG_NAME "android/net/NetworkUtils" 47 48 namespace android { 49 50 static const uint16_t kDhcpClientPort = 68; 51 52 static void android_net_utils_attachDhcpFilter(JNIEnv *env, jobject clazz, jobject javaFd) 53 { 54 uint32_t ip_offset = sizeof(ether_header); 55 uint32_t proto_offset = ip_offset + offsetof(iphdr, protocol); 56 uint32_t flags_offset = ip_offset + offsetof(iphdr, frag_off); 57 uint32_t dport_indirect_offset = ip_offset + offsetof(udphdr, dest); 58 struct sock_filter filter_code[] = { 59 // Check the protocol is UDP. 60 BPF_STMT(BPF_LD | BPF_B | BPF_ABS, proto_offset), 61 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_UDP, 0, 6), 62 63 // Check this is not a fragment. 64 BPF_STMT(BPF_LD | BPF_H | BPF_ABS, flags_offset), 65 BPF_JUMP(BPF_JMP | BPF_JSET | BPF_K, 0x1fff, 4, 0), 66 67 // Get the IP header length. 68 BPF_STMT(BPF_LDX | BPF_B | BPF_MSH, ip_offset), 69 70 // Check the destination port. 71 BPF_STMT(BPF_LD | BPF_H | BPF_IND, dport_indirect_offset), 72 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, kDhcpClientPort, 0, 1), 73 74 // Accept or reject. 75 BPF_STMT(BPF_RET | BPF_K, 0xffff), 76 BPF_STMT(BPF_RET | BPF_K, 0) 77 }; 78 struct sock_fprog filter = { 79 sizeof(filter_code) / sizeof(filter_code[0]), 80 filter_code, 81 }; 82 83 int fd = jniGetFDFromFileDescriptor(env, javaFd); 84 if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) { 85 jniThrowExceptionFmt(env, "java/net/SocketException", 86 "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno)); 87 } 88 } 89 90 static void android_net_utils_attachRaFilter(JNIEnv *env, jobject clazz, jobject javaFd, 91 jint hardwareAddressType) 92 { 93 if (hardwareAddressType != ARPHRD_ETHER) { 94 jniThrowExceptionFmt(env, "java/net/SocketException", 95 "attachRaFilter only supports ARPHRD_ETHER"); 96 return; 97 } 98 99 uint32_t ipv6_offset = sizeof(ether_header); 100 uint32_t ipv6_next_header_offset = ipv6_offset + offsetof(ip6_hdr, ip6_nxt); 101 uint32_t icmp6_offset = ipv6_offset + sizeof(ip6_hdr); 102 uint32_t icmp6_type_offset = icmp6_offset + offsetof(icmp6_hdr, icmp6_type); 103 struct sock_filter filter_code[] = { 104 // Check IPv6 Next Header is ICMPv6. 105 BPF_STMT(BPF_LD | BPF_B | BPF_ABS, ipv6_next_header_offset), 106 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, IPPROTO_ICMPV6, 0, 3), 107 108 // Check ICMPv6 type is Router Advertisement. 109 BPF_STMT(BPF_LD | BPF_B | BPF_ABS, icmp6_type_offset), 110 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, ND_ROUTER_ADVERT, 0, 1), 111 112 // Accept or reject. 113 BPF_STMT(BPF_RET | BPF_K, 0xffff), 114 BPF_STMT(BPF_RET | BPF_K, 0) 115 }; 116 struct sock_fprog filter = { 117 sizeof(filter_code) / sizeof(filter_code[0]), 118 filter_code, 119 }; 120 121 int fd = jniGetFDFromFileDescriptor(env, javaFd); 122 if (setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter, sizeof(filter)) != 0) { 123 jniThrowExceptionFmt(env, "java/net/SocketException", 124 "setsockopt(SO_ATTACH_FILTER): %s", strerror(errno)); 125 } 126 } 127 128 static void android_net_utils_setupRaSocket(JNIEnv *env, jobject clazz, jobject javaFd, 129 jint ifIndex) 130 { 131 static const int kLinkLocalHopLimit = 255; 132 133 int fd = jniGetFDFromFileDescriptor(env, javaFd); 134 135 // Set an ICMPv6 filter that only passes Router Solicitations. 136 struct icmp6_filter rs_only; 137 ICMP6_FILTER_SETBLOCKALL(&rs_only); 138 ICMP6_FILTER_SETPASS(ND_ROUTER_SOLICIT, &rs_only); 139 socklen_t len = sizeof(rs_only); 140 if (setsockopt(fd, IPPROTO_ICMPV6, ICMP6_FILTER, &rs_only, len) != 0) { 141 jniThrowExceptionFmt(env, "java/net/SocketException", 142 "setsockopt(ICMP6_FILTER): %s", strerror(errno)); 143 return; 144 } 145 146 // Most/all of the rest of these options can be set via Java code, but 147 // because we're here on account of setting an icmp6_filter go ahead 148 // and do it all natively for now. 149 // 150 // TODO: Consider moving these out to Java. 151 152 // Set the multicast hoplimit to 255 (link-local only). 153 int hops = kLinkLocalHopLimit; 154 len = sizeof(hops); 155 if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_HOPS, &hops, len) != 0) { 156 jniThrowExceptionFmt(env, "java/net/SocketException", 157 "setsockopt(IPV6_MULTICAST_HOPS): %s", strerror(errno)); 158 return; 159 } 160 161 // Set the unicast hoplimit to 255 (link-local only). 162 hops = kLinkLocalHopLimit; 163 len = sizeof(hops); 164 if (setsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &hops, len) != 0) { 165 jniThrowExceptionFmt(env, "java/net/SocketException", 166 "setsockopt(IPV6_UNICAST_HOPS): %s", strerror(errno)); 167 return; 168 } 169 170 // Explicitly disable multicast loopback. 171 int off = 0; 172 len = sizeof(off); 173 if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_LOOP, &off, len) != 0) { 174 jniThrowExceptionFmt(env, "java/net/SocketException", 175 "setsockopt(IPV6_MULTICAST_LOOP): %s", strerror(errno)); 176 return; 177 } 178 179 // Specify the IPv6 interface to use for outbound multicast. 180 len = sizeof(ifIndex); 181 if (setsockopt(fd, IPPROTO_IPV6, IPV6_MULTICAST_IF, &ifIndex, len) != 0) { 182 jniThrowExceptionFmt(env, "java/net/SocketException", 183 "setsockopt(IPV6_MULTICAST_IF): %s", strerror(errno)); 184 return; 185 } 186 187 // Additional options to be considered: 188 // - IPV6_TCLASS 189 // - IPV6_RECVPKTINFO 190 // - IPV6_RECVHOPLIMIT 191 192 // Bind to [::]. 193 const struct sockaddr_in6 sin6 = { 194 .sin6_family = AF_INET6, 195 .sin6_port = 0, 196 .sin6_flowinfo = 0, 197 .sin6_addr = IN6ADDR_ANY_INIT, 198 .sin6_scope_id = 0, 199 }; 200 auto sa = reinterpret_cast<const struct sockaddr *>(&sin6); 201 len = sizeof(sin6); 202 if (bind(fd, sa, len) != 0) { 203 jniThrowExceptionFmt(env, "java/net/SocketException", 204 "bind(IN6ADDR_ANY): %s", strerror(errno)); 205 return; 206 } 207 208 // Join the all-routers multicast group, ff02::2%index. 209 struct ipv6_mreq all_rtrs = { 210 .ipv6mr_multiaddr = {{{0xff,2,0,0,0,0,0,0,0,0,0,0,0,0,0,2}}}, 211 .ipv6mr_interface = ifIndex, 212 }; 213 len = sizeof(all_rtrs); 214 if (setsockopt(fd, IPPROTO_IPV6, IPV6_JOIN_GROUP, &all_rtrs, len) != 0) { 215 jniThrowExceptionFmt(env, "java/net/SocketException", 216 "setsockopt(IPV6_JOIN_GROUP): %s", strerror(errno)); 217 return; 218 } 219 } 220 221 static jboolean android_net_utils_bindProcessToNetwork(JNIEnv *env, jobject thiz, jint netId) 222 { 223 return (jboolean) !setNetworkForProcess(netId); 224 } 225 226 static jint android_net_utils_getBoundNetworkForProcess(JNIEnv *env, jobject thiz) 227 { 228 return getNetworkForProcess(); 229 } 230 231 static jboolean android_net_utils_bindProcessToNetworkForHostResolution(JNIEnv *env, jobject thiz, 232 jint netId) 233 { 234 return (jboolean) !setNetworkForResolv(netId); 235 } 236 237 static jint android_net_utils_bindSocketToNetwork(JNIEnv *env, jobject thiz, jint socket, 238 jint netId) 239 { 240 return setNetworkForSocket(netId, socket); 241 } 242 243 static jboolean android_net_utils_protectFromVpn(JNIEnv *env, jobject thiz, jint socket) 244 { 245 return (jboolean) !protectFromVpn(socket); 246 } 247 248 static jboolean android_net_utils_queryUserAccess(JNIEnv *env, jobject thiz, jint uid, jint netId) 249 { 250 return (jboolean) !queryUserAccess(uid, netId); 251 } 252 253 254 // ---------------------------------------------------------------------------- 255 256 /* 257 * JNI registration. 258 */ 259 static const JNINativeMethod gNetworkUtilMethods[] = { 260 /* name, signature, funcPtr */ 261 { "bindProcessToNetwork", "(I)Z", (void*) android_net_utils_bindProcessToNetwork }, 262 { "getBoundNetworkForProcess", "()I", (void*) android_net_utils_getBoundNetworkForProcess }, 263 { "bindProcessToNetworkForHostResolution", "(I)Z", (void*) android_net_utils_bindProcessToNetworkForHostResolution }, 264 { "bindSocketToNetwork", "(II)I", (void*) android_net_utils_bindSocketToNetwork }, 265 { "protectFromVpn", "(I)Z", (void*)android_net_utils_protectFromVpn }, 266 { "queryUserAccess", "(II)Z", (void*)android_net_utils_queryUserAccess }, 267 { "attachDhcpFilter", "(Ljava/io/FileDescriptor;)V", (void*) android_net_utils_attachDhcpFilter }, 268 { "attachRaFilter", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_attachRaFilter }, 269 { "setupRaSocket", "(Ljava/io/FileDescriptor;I)V", (void*) android_net_utils_setupRaSocket }, 270 }; 271 272 int register_android_net_NetworkUtils(JNIEnv* env) 273 { 274 return RegisterMethodsOrDie(env, NETUTILS_PKG_NAME, gNetworkUtilMethods, 275 NELEM(gNetworkUtilMethods)); 276 } 277 278 }; // namespace android 279