JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2011 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | #ifndef _BANDWIDTH_CONTROLLER_H |
| 17 | #define _BANDWIDTH_CONTROLLER_H |
| 18 | |
| 19 | #include <list> |
| 20 | #include <string> |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 21 | #include <utility> // for pair |
Lalit Kansara | 75d8bcd | 2016-12-06 22:46:44 +0530 | [diff] [blame] | 22 | #include <vector> |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 23 | |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 24 | #include <sysutils/SocketClient.h> |
Lorenzo Colitti | dedd271 | 2016-03-22 12:36:29 +0900 | [diff] [blame] | 25 | #include <utils/RWLock.h> |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 26 | |
Lorenzo Colitti | 13debb8 | 2016-03-27 17:46:30 +0900 | [diff] [blame] | 27 | #include "NetdConstants.h" |
| 28 | |
JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 29 | class BandwidthController { |
| 30 | public: |
Lorenzo Colitti | dedd271 | 2016-03-22 12:36:29 +0900 | [diff] [blame] | 31 | android::RWLock lock; |
| 32 | |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 33 | class TetherStats { |
| 34 | public: |
| 35 | TetherStats(void) |
| 36 | : rxBytes(-1), rxPackets(-1), |
| 37 | txBytes(-1), txPackets(-1) {}; |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 38 | TetherStats(std::string intIfn, std::string extIfn, |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 39 | int64_t rxB, int64_t rxP, |
| 40 | int64_t txB, int64_t txP) |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 41 | : intIface(intIfn), extIface(extIfn), |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 42 | rxBytes(rxB), rxPackets(rxP), |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 43 | txBytes(txB), txPackets(txP) {}; |
| 44 | /* Internal interface. Same as NatController's notion. */ |
| 45 | std::string intIface; |
| 46 | /* External interface. Same as NatController's notion. */ |
| 47 | std::string extIface; |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 48 | int64_t rxBytes, rxPackets; |
| 49 | int64_t txBytes, txPackets; |
| 50 | /* |
| 51 | * Allocates a new string representing this: |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 52 | * intIface extIface rx_bytes rx_packets tx_bytes tx_packets |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 53 | * The caller is responsible for free()'ing the returned ptr. |
| 54 | */ |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 55 | char *getStatsLine(void) const; |
Lorenzo Colitti | 7364b75 | 2016-07-08 18:24:53 +0900 | [diff] [blame] | 56 | |
| 57 | bool addStatsIfMatch(const TetherStats& other) { |
| 58 | if (intIface == other.intIface && extIface == other.extIface) { |
| 59 | rxBytes += other.rxBytes; |
| 60 | rxPackets += other.rxPackets; |
| 61 | txBytes += other.txBytes; |
| 62 | txPackets += other.txPackets; |
| 63 | return true; |
| 64 | } |
| 65 | return false; |
| 66 | } |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 67 | }; |
| 68 | |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 69 | BandwidthController(); |
JP Abgrall | 0031cea | 2012-04-17 16:38:23 -0700 | [diff] [blame] | 70 | |
| 71 | int setupIptablesHooks(void); |
| 72 | |
| 73 | int enableBandwidthControl(bool force); |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 74 | int disableBandwidthControl(void); |
Lorenzo Colitti | 7618ccb | 2016-03-18 12:36:03 +0900 | [diff] [blame] | 75 | int enableDataSaver(bool enable); |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 76 | |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 77 | int setInterfaceSharedQuota(const char *iface, int64_t bytes); |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 78 | int getInterfaceSharedQuota(int64_t *bytes); |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 79 | int removeInterfaceSharedQuota(const char *iface); |
| 80 | |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 81 | int setInterfaceQuota(const char *iface, int64_t bytes); |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 82 | int getInterfaceQuota(const char *iface, int64_t *bytes); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 83 | int removeInterfaceQuota(const char *iface); |
| 84 | |
JP Abgrall | fa6f46d | 2011-06-17 23:17:28 -0700 | [diff] [blame] | 85 | int addNaughtyApps(int numUids, char *appUids[]); |
| 86 | int removeNaughtyApps(int numUids, char *appUids[]); |
JP Abgrall | e478873 | 2013-07-02 20:28:45 -0700 | [diff] [blame] | 87 | int addNiceApps(int numUids, char *appUids[]); |
| 88 | int removeNiceApps(int numUids, char *appUids[]); |
JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 89 | |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 90 | int setGlobalAlert(int64_t bytes); |
| 91 | int removeGlobalAlert(void); |
JP Abgrall | c6c6734 | 2011-10-07 16:28:54 -0700 | [diff] [blame] | 92 | int setGlobalAlertInForwardChain(void); |
| 93 | int removeGlobalAlertInForwardChain(void); |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 94 | |
| 95 | int setSharedAlert(int64_t bytes); |
| 96 | int removeSharedAlert(void); |
| 97 | |
| 98 | int setInterfaceAlert(const char *iface, int64_t bytes); |
| 99 | int removeInterfaceAlert(const char *iface); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 100 | |
farenl | d228c54 | 2016-09-01 12:30:35 +0800 | [diff] [blame] | 101 | int addRestrictAppsOnData(int numUids, char *appUids[]); |
| 102 | int removeRestrictAppsOnData(int numUids, char *appUids[]); |
| 103 | |
| 104 | int addRestrictAppsOnWlan(int numUids, char *appUids[]); |
| 105 | int removeRestrictAppsOnWlan(int numUids, char *appUids[]); |
| 106 | |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 107 | /* |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 108 | * For single pair of ifaces, stats should have ifaceIn and ifaceOut initialized. |
| 109 | * For all pairs, stats should have ifaceIn=ifaceOut="". |
| 110 | * Sends out to the cli the single stat (TetheringStatsReluts) or a list of stats |
| 111 | * (TetheringStatsListResult+CommandOkay). |
JP Abgrall | f3cc83f | 2013-09-11 20:01:59 -0700 | [diff] [blame] | 112 | * Error is to be handled on the outside. |
| 113 | * It results in an error if invoked and no tethering counter rules exist. |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 114 | */ |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 115 | int getTetherStats(SocketClient *cli, TetherStats &stats, std::string &extraProcessingInfo); |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 116 | |
Jeff Sharkey | 8e188ed | 2012-07-12 18:32:03 -0700 | [diff] [blame] | 117 | static const char* LOCAL_INPUT; |
| 118 | static const char* LOCAL_FORWARD; |
| 119 | static const char* LOCAL_OUTPUT; |
| 120 | static const char* LOCAL_RAW_PREROUTING; |
| 121 | static const char* LOCAL_MANGLE_POSTROUTING; |
| 122 | |
JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 123 | protected: |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 124 | class QuotaInfo { |
| 125 | public: |
| 126 | QuotaInfo(std::string ifn, int64_t q, int64_t a) |
| 127 | : ifaceName(ifn), quota(q), alert(a) {}; |
| 128 | std::string ifaceName; |
| 129 | int64_t quota; |
| 130 | int64_t alert; |
| 131 | }; |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 132 | |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 133 | enum IptIpVer { IptIpV4, IptIpV6 }; |
JP Abgrall | 109899b | 2013-02-12 19:20:13 -0800 | [diff] [blame] | 134 | enum IptOp { IptOpInsert, IptOpReplace, IptOpDelete, IptOpAppend }; |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 135 | enum IptJumpOp { IptJumpReject, IptJumpReturn, IptJumpNoAdd }; |
| 136 | enum SpecialAppOp { SpecialAppOpAdd, SpecialAppOpRemove }; |
farenl | d228c54 | 2016-09-01 12:30:35 +0800 | [diff] [blame] | 137 | enum RestrictAppOp { RestrictAppOpAdd, RestrictAppOpRemove}; |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 138 | enum QuotaType { QuotaUnique, QuotaShared }; |
| 139 | enum RunCmdErrHandling { RunCmdFailureBad, RunCmdFailureOk }; |
JP Abgrall | 1fb02df | 2012-04-24 23:27:44 -0700 | [diff] [blame] | 140 | #if LOG_NDEBUG |
| 141 | enum IptFailureLog { IptFailShow, IptFailHide }; |
| 142 | #else |
| 143 | enum IptFailureLog { IptFailShow, IptFailHide = IptFailShow }; |
| 144 | #endif |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 145 | |
| 146 | int manipulateSpecialApps(int numUids, char *appStrUids[], |
| 147 | const char *chain, |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 148 | IptJumpOp jumpHandling, SpecialAppOp appOp); |
| 149 | int manipulateNaughtyApps(int numUids, char *appStrUids[], SpecialAppOp appOp); |
JP Abgrall | e478873 | 2013-07-02 20:28:45 -0700 | [diff] [blame] | 150 | int manipulateNiceApps(int numUids, char *appStrUids[], SpecialAppOp appOp); |
JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 151 | |
farenl | d228c54 | 2016-09-01 12:30:35 +0800 | [diff] [blame] | 152 | int manipulateRestrictAppsOnData(int numUids, char* appStrUids[], RestrictAppOp appOp); |
| 153 | int manipulateRestrictAppsOnWlan(int numUids, char* appStrUids[], RestrictAppOp appOp); |
| 154 | int manipulateRestrictApps(int numUids, char *appStrUids[], |
| 155 | const char *chain, |
| 156 | std::list<int /*appUid*/> &restrictAppUids, |
| 157 | RestrictAppOp appOp); |
| 158 | |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 159 | int prepCostlyIface(const char *ifn, QuotaType quotaType); |
| 160 | int cleanupCostlyIface(const char *ifn, QuotaType quotaType); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 161 | |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 162 | std::string makeIptablesSpecialAppCmd(IptOp op, int uid, const char *chain); |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 163 | std::string makeIptablesQuotaCmd(IptOp op, const char *costName, int64_t quota); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 164 | |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 165 | int runIptablesAlertCmd(IptOp op, const char *alertName, int64_t bytes); |
JP Abgrall | c6c6734 | 2011-10-07 16:28:54 -0700 | [diff] [blame] | 166 | int runIptablesAlertFwdCmd(IptOp op, const char *alertName, int64_t bytes); |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 167 | |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 168 | /* Runs for both ipv4 and ipv6 iptables */ |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 169 | int runCommands(int numCommands, const char *commands[], RunCmdErrHandling cmdErrHandling); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 170 | /* Runs for both ipv4 and ipv6 iptables, appends -j REJECT --reject-with ... */ |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 171 | static int runIpxtablesCmd(const char *cmd, IptJumpOp jumpHandling, |
JP Abgrall | 1fb02df | 2012-04-24 23:27:44 -0700 | [diff] [blame] | 172 | IptFailureLog failureHandling = IptFailShow); |
JP Abgrall | a9ba4cb | 2013-07-02 19:08:48 -0700 | [diff] [blame] | 173 | static int runIptablesCmd(const char *cmd, IptJumpOp jumpHandling, IptIpVer iptIpVer, |
JP Abgrall | 1fb02df | 2012-04-24 23:27:44 -0700 | [diff] [blame] | 174 | IptFailureLog failureHandling = IptFailShow); |
| 175 | |
JP Abgrall | 26e0d49 | 2011-06-24 19:21:51 -0700 | [diff] [blame] | 176 | |
| 177 | // Provides strncpy() + check overflow. |
| 178 | static int StrncpyAndCheck(char *buffer, const char *src, size_t buffSize); |
JP Abgrall | 0dad7c2 | 2011-06-24 11:58:14 -0700 | [diff] [blame] | 179 | |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 180 | int updateQuota(const char *alertName, int64_t bytes); |
| 181 | |
JP Abgrall | 8a93272 | 2011-07-13 19:17:35 -0700 | [diff] [blame] | 182 | int setCostlyAlert(const char *costName, int64_t bytes, int64_t *alertBytes); |
| 183 | int removeCostlyAlert(const char *costName, int64_t *alertBytes); |
| 184 | |
Lorenzo Colitti | 7364b75 | 2016-07-08 18:24:53 +0900 | [diff] [blame] | 185 | typedef std::vector<TetherStats> TetherStatsList; |
| 186 | |
| 187 | static void addStats(TetherStatsList& statsList, const TetherStats& stats); |
| 188 | |
| 189 | static int addForwardChainStats(const TetherStats& filter, |
| 190 | TetherStatsList& statsList, FILE *fp, |
| 191 | std::string &extraProcessingInfo); |
| 192 | |
| 193 | |
JP Abgrall | 11b4e9b | 2011-08-11 15:34:49 -0700 | [diff] [blame] | 194 | /* |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 195 | * stats should never have only intIface initialized. Other 3 combos are ok. |
| 196 | * fp should be a file to the apropriate FORWARD chain of iptables rules. |
JP Abgrall | a2a64f0 | 2011-11-11 20:36:16 -0800 | [diff] [blame] | 197 | * extraProcessingInfo: contains raw parsed data, and error info. |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 198 | * This strongly requires that setup of the rules is in a specific order: |
| 199 | * in:intIface out:extIface |
| 200 | * in:extIface out:intIface |
| 201 | * and the rules are grouped in pairs when more that one tethering was setup. |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 202 | */ |
JP Abgrall | baeccc4 | 2013-06-25 09:44:10 -0700 | [diff] [blame] | 203 | static int parseForwardChainStats(SocketClient *cli, const TetherStats filter, FILE *fp, |
JP Abgrall | 0031cea | 2012-04-17 16:38:23 -0700 | [diff] [blame] | 204 | std::string &extraProcessingInfo); |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 205 | |
JP Abgrall | 0e540ec | 2013-08-26 15:13:10 -0700 | [diff] [blame] | 206 | /* |
| 207 | * Attempt to find the bw_costly_* tables that need flushing, |
| 208 | * and flush them. |
| 209 | * If doClean then remove the tables also. |
| 210 | * Deals with both ip4 and ip6 tables. |
| 211 | */ |
| 212 | void flushExistingCostlyTables(bool doClean); |
| 213 | static void parseAndFlushCostlyTables(FILE *fp, bool doRemove); |
| 214 | |
| 215 | /* |
| 216 | * Attempt to flush our tables. |
| 217 | * If doClean then remove them also. |
| 218 | * Deals with both ip4 and ip6 tables. |
| 219 | */ |
| 220 | void flushCleanTables(bool doClean); |
| 221 | |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 222 | /*------------------*/ |
| 223 | |
| 224 | std::list<std::string> sharedQuotaIfaces; |
| 225 | int64_t sharedQuotaBytes; |
| 226 | int64_t sharedAlertBytes; |
| 227 | int64_t globalAlertBytes; |
JP Abgrall | c6c6734 | 2011-10-07 16:28:54 -0700 | [diff] [blame] | 228 | /* |
| 229 | * This tracks the number of tethers setup. |
| 230 | * The FORWARD chain is updated in the following cases: |
| 231 | * - The 1st time a globalAlert is setup and there are tethers setup. |
| 232 | * - Anytime a globalAlert is removed and there are tethers setup. |
| 233 | * - The 1st tether is setup and there is a globalAlert active. |
| 234 | * - The last tether is removed and there is a globalAlert active. |
| 235 | */ |
| 236 | int globalAlertTetherCount; |
| 237 | |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 238 | std::list<QuotaInfo> quotaIfaces; |
JP Abgrall | db7da58 | 2011-09-18 12:57:32 -0700 | [diff] [blame] | 239 | |
Lorenzo Colitti | 86a4798 | 2016-03-18 17:52:25 +0900 | [diff] [blame] | 240 | // For testing. |
| 241 | friend class BandwidthControllerTest; |
| 242 | static int (*execFunction)(int, char **, int *, bool, bool); |
| 243 | static FILE *(*popenFunction)(const char *, const char *); |
Lorenzo Colitti | 13debb8 | 2016-03-27 17:46:30 +0900 | [diff] [blame] | 244 | static int (*iptablesRestoreFunction)(IptablesTarget, const std::string&); |
farenl | d228c54 | 2016-09-01 12:30:35 +0800 | [diff] [blame] | 245 | |
| 246 | std::list<int /*appUid*/> restrictAppUidsOnData; |
| 247 | std::list<int /*appUid*/> restrictAppUidsOnWlan; |
JP Abgrall | 4a5f5ca | 2011-06-15 18:37:39 -0700 | [diff] [blame] | 248 | }; |
| 249 | |
| 250 | #endif |