Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
Bernie Innocenti | 762dcf4 | 2019-06-14 19:52:49 +0900 | [diff] [blame] | 17 | #pragma once |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 18 | |
Lorenzo Colitti | fff4bd3 | 2016-04-14 00:56:01 +0900 | [diff] [blame] | 19 | #include <set> |
| 20 | |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 21 | #include "Network.h" |
| 22 | |
Bernie Innocenti | 762dcf4 | 2019-06-14 19:52:49 +0900 | [diff] [blame] | 23 | namespace android::net { |
Lorenzo Colitti | 7035f22 | 2017-02-13 18:29:00 +0900 | [diff] [blame] | 24 | |
Sreeram Ramachandran | 95684ba | 2014-07-23 13:27:31 -0700 | [diff] [blame] | 25 | // A VirtualNetwork may be "secure" or not. |
| 26 | // |
| 27 | // A secure VPN is the usual type of VPN that grabs the default route (and thus all user traffic). |
| 28 | // Only a few privileged UIDs may skip the VPN and go directly to the underlying physical network. |
| 29 | // |
| 30 | // A non-secure VPN ("bypassable" VPN) also grabs all user traffic by default. But all apps are |
Chiachang Wang | 3e5d071 | 2022-01-14 21:31:32 +0800 | [diff] [blame] | 31 | // permitted to skip it and pick any other network for their connections. A bypassable VPN may |
| 32 | // optionally exclude local routes, which means it will not grab traffic that is destined to IP |
| 33 | // addresses considered to be on the local link. |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 34 | class VirtualNetwork : public Network { |
| 35 | public: |
Chiachang Wang | 3e5d071 | 2022-01-14 21:31:32 +0800 | [diff] [blame] | 36 | explicit VirtualNetwork(unsigned netId, bool secure, bool excludeLocalRoutes = false); |
Chiachang Wang | 2b0abee | 2022-01-12 10:03:17 +0800 | [diff] [blame] | 37 | virtual ~VirtualNetwork(); |
Ken Chen | 1a028a7 | 2022-10-27 17:54:38 +0800 | [diff] [blame] | 38 | Permission getPermission() const { return PERMISSION_SYSTEM; }; |
Chiachang Wang | 2b0abee | 2022-01-12 10:03:17 +0800 | [diff] [blame] | 39 | [[nodiscard]] int addUsers(const UidRanges& uidRanges, int32_t subPriority) override; |
| 40 | [[nodiscard]] int removeUsers(const UidRanges& uidRanges, int32_t subPriority) override; |
| 41 | bool isVirtual() override { return true; } |
| 42 | bool canAddUsers() override { return true; } |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 43 | |
Chiachang Wang | 2b0abee | 2022-01-12 10:03:17 +0800 | [diff] [blame] | 44 | private: |
| 45 | std::string getTypeString() const override { return "VIRTUAL"; }; |
| 46 | [[nodiscard]] int addInterface(const std::string& interface) override; |
| 47 | [[nodiscard]] int removeInterface(const std::string& interface) override; |
| 48 | bool isValidSubPriority(int32_t priority) override; |
| 49 | // Whether the local traffic will be excluded from the VPN network. |
| 50 | [[maybe_unused]] const bool mExcludeLocalRoutes; |
Sreeram Ramachandran | 4043f01 | 2014-06-23 12:41:37 -0700 | [diff] [blame] | 51 | }; |
| 52 | |
Bernie Innocenti | 762dcf4 | 2019-06-14 19:52:49 +0900 | [diff] [blame] | 53 | } // namespace android::net |