OSDN Git Service

Merge "bundle init.rc contents with its service"
[android-x86/system-netd.git] / server / CommandListener.cpp
1 /*
2  * Copyright (C) 2008 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16
17 // #define LOG_NDEBUG 0
18
19 #include <stdlib.h>
20 #include <sys/socket.h>
21 #include <sys/types.h>
22 #include <netinet/in.h>
23 #include <arpa/inet.h>
24 #include <dirent.h>
25 #include <errno.h>
26 #include <string.h>
27 #include <linux/if.h>
28 #include <resolv_netid.h>
29
30 #define __STDC_FORMAT_MACROS 1
31 #include <inttypes.h>
32
33 #define LOG_TAG "CommandListener"
34
35 #include <cutils/log.h>
36 #include <netutils/ifc.h>
37 #include <sysutils/SocketClient.h>
38
39 #include "CommandListener.h"
40 #include "ResponseCode.h"
41 #include "BandwidthController.h"
42 #include "IdletimerController.h"
43 #include "oem_iptables_hook.h"
44 #include "NetdConstants.h"
45 #include "FirewallController.h"
46 #include "RouteController.h"
47 #include "UidRanges.h"
48
49 #include <string>
50 #include <vector>
51
52 namespace {
53
54 const unsigned NUM_OEM_IDS = NetworkController::MAX_OEM_ID - NetworkController::MIN_OEM_ID + 1;
55
56 Permission stringToPermission(const char* arg) {
57     if (!strcmp(arg, "NETWORK")) {
58         return PERMISSION_NETWORK;
59     }
60     if (!strcmp(arg, "SYSTEM")) {
61         return PERMISSION_SYSTEM;
62     }
63     return PERMISSION_NONE;
64 }
65
66 unsigned stringToNetId(const char* arg) {
67     if (!strcmp(arg, "local")) {
68         return NetworkController::LOCAL_NET_ID;
69     }
70     // OEM NetIds are "oem1", "oem2", .., "oem50".
71     if (!strncmp(arg, "oem", 3)) {
72         unsigned n = strtoul(arg + 3, NULL, 0);
73         if (1 <= n && n <= NUM_OEM_IDS) {
74             return NetworkController::MIN_OEM_ID + n;
75         }
76         return NETID_UNSET;
77     }
78     // strtoul() returns 0 on errors, which is fine because 0 is an invalid netId.
79     return strtoul(arg, NULL, 0);
80 }
81
82 }  // namespace
83
84 NetworkController *CommandListener::sNetCtrl = NULL;
85 TetherController *CommandListener::sTetherCtrl = NULL;
86 NatController *CommandListener::sNatCtrl = NULL;
87 PppController *CommandListener::sPppCtrl = NULL;
88 SoftapController *CommandListener::sSoftapCtrl = NULL;
89 BandwidthController * CommandListener::sBandwidthCtrl = NULL;
90 IdletimerController * CommandListener::sIdletimerCtrl = NULL;
91 InterfaceController *CommandListener::sInterfaceCtrl = NULL;
92 ResolverController *CommandListener::sResolverCtrl = NULL;
93 FirewallController *CommandListener::sFirewallCtrl = NULL;
94 ClatdController *CommandListener::sClatdCtrl = NULL;
95 StrictController *CommandListener::sStrictCtrl = NULL;
96
97 /**
98  * List of module chains to be created, along with explicit ordering. ORDERING
99  * IS CRITICAL, AND SHOULD BE TRIPLE-CHECKED WITH EACH CHANGE.
100  */
101 static const char* FILTER_INPUT[] = {
102         // Bandwidth should always be early in input chain, to make sure we
103         // correctly count incoming traffic against data plan.
104         BandwidthController::LOCAL_INPUT,
105         FirewallController::LOCAL_INPUT,
106         NULL,
107 };
108
109 static const char* FILTER_FORWARD[] = {
110         OEM_IPTABLES_FILTER_FORWARD,
111         FirewallController::LOCAL_FORWARD,
112         BandwidthController::LOCAL_FORWARD,
113         NatController::LOCAL_FORWARD,
114         NULL,
115 };
116
117 static const char* FILTER_OUTPUT[] = {
118         OEM_IPTABLES_FILTER_OUTPUT,
119         FirewallController::LOCAL_OUTPUT,
120         StrictController::LOCAL_OUTPUT,
121         BandwidthController::LOCAL_OUTPUT,
122         NULL,
123 };
124
125 static const char* RAW_PREROUTING[] = {
126         BandwidthController::LOCAL_RAW_PREROUTING,
127         IdletimerController::LOCAL_RAW_PREROUTING,
128         NULL,
129 };
130
131 static const char* MANGLE_POSTROUTING[] = {
132         BandwidthController::LOCAL_MANGLE_POSTROUTING,
133         IdletimerController::LOCAL_MANGLE_POSTROUTING,
134         NULL,
135 };
136
137 static const char* MANGLE_FORWARD[] = {
138         NatController::LOCAL_MANGLE_FORWARD,
139         NULL,
140 };
141
142 static const char* NAT_PREROUTING[] = {
143         OEM_IPTABLES_NAT_PREROUTING,
144         NULL,
145 };
146
147 static const char* NAT_POSTROUTING[] = {
148         NatController::LOCAL_NAT_POSTROUTING,
149         NULL,
150 };
151
152 static void createChildChains(IptablesTarget target, const char* table, const char* parentChain,
153         const char** childChains) {
154     const char** childChain = childChains;
155     do {
156         // Order is important:
157         // -D to delete any pre-existing jump rule (removes references
158         //    that would prevent -X from working)
159         // -F to flush any existing chain
160         // -X to delete any existing chain
161         // -N to create the chain
162         // -A to append the chain to parent
163
164         execIptablesSilently(target, "-t", table, "-D", parentChain, "-j", *childChain, NULL);
165         execIptablesSilently(target, "-t", table, "-F", *childChain, NULL);
166         execIptablesSilently(target, "-t", table, "-X", *childChain, NULL);
167         execIptables(target, "-t", table, "-N", *childChain, NULL);
168         execIptables(target, "-t", table, "-A", parentChain, "-j", *childChain, NULL);
169     } while (*(++childChain) != NULL);
170 }
171
172 CommandListener::CommandListener() :
173                  FrameworkListener("netd", true) {
174     registerCmd(new InterfaceCmd());
175     registerCmd(new IpFwdCmd());
176     registerCmd(new TetherCmd());
177     registerCmd(new NatCmd());
178     registerCmd(new ListTtysCmd());
179     registerCmd(new PppdCmd());
180     registerCmd(new SoftapCmd());
181     registerCmd(new BandwidthControlCmd());
182     registerCmd(new IdletimerControlCmd());
183     registerCmd(new ResolverCmd());
184     registerCmd(new FirewallCmd());
185     registerCmd(new ClatdCmd());
186     registerCmd(new NetworkCommand());
187     registerCmd(new StrictCmd());
188
189     if (!sNetCtrl)
190         sNetCtrl = new NetworkController();
191     if (!sTetherCtrl)
192         sTetherCtrl = new TetherController();
193     if (!sNatCtrl)
194         sNatCtrl = new NatController();
195     if (!sPppCtrl)
196         sPppCtrl = new PppController();
197     if (!sSoftapCtrl)
198         sSoftapCtrl = new SoftapController();
199     if (!sBandwidthCtrl)
200         sBandwidthCtrl = new BandwidthController();
201     if (!sIdletimerCtrl)
202         sIdletimerCtrl = new IdletimerController();
203     if (!sResolverCtrl)
204         sResolverCtrl = new ResolverController();
205     if (!sFirewallCtrl)
206         sFirewallCtrl = new FirewallController();
207     if (!sInterfaceCtrl)
208         sInterfaceCtrl = new InterfaceController();
209     if (!sClatdCtrl)
210         sClatdCtrl = new ClatdController(sNetCtrl);
211     if (!sStrictCtrl)
212         sStrictCtrl = new StrictController();
213
214     /*
215      * This is the only time we touch top-level chains in iptables; controllers
216      * should only mutate rules inside of their children chains, as created by
217      * the constants above.
218      *
219      * Modules should never ACCEPT packets (except in well-justified cases);
220      * they should instead defer to any remaining modules using RETURN, or
221      * otherwise DROP/REJECT.
222      */
223
224     // Create chains for children modules
225     createChildChains(V4V6, "filter", "INPUT", FILTER_INPUT);
226     createChildChains(V4V6, "filter", "FORWARD", FILTER_FORWARD);
227     createChildChains(V4V6, "filter", "OUTPUT", FILTER_OUTPUT);
228     createChildChains(V4V6, "raw", "PREROUTING", RAW_PREROUTING);
229     createChildChains(V4V6, "mangle", "POSTROUTING", MANGLE_POSTROUTING);
230     createChildChains(V4, "mangle", "FORWARD", MANGLE_FORWARD);
231     createChildChains(V4, "nat", "PREROUTING", NAT_PREROUTING);
232     createChildChains(V4, "nat", "POSTROUTING", NAT_POSTROUTING);
233
234     // Let each module setup their child chains
235     setupOemIptablesHook();
236
237     /* When enabled, DROPs all packets except those matching rules. */
238     sFirewallCtrl->setupIptablesHooks();
239
240     /* Does DROPs in FORWARD by default */
241     sNatCtrl->setupIptablesHooks();
242     /*
243      * Does REJECT in INPUT, OUTPUT. Does counting also.
244      * No DROP/REJECT allowed later in netfilter-flow hook order.
245      */
246     sBandwidthCtrl->setupIptablesHooks();
247     /*
248      * Counts in nat: PREROUTING, POSTROUTING.
249      * No DROP/REJECT allowed later in netfilter-flow hook order.
250      */
251     sIdletimerCtrl->setupIptablesHooks();
252
253     sBandwidthCtrl->enableBandwidthControl(false);
254
255     if (int ret = RouteController::Init(NetworkController::LOCAL_NET_ID)) {
256         ALOGE("failed to initialize RouteController (%s)", strerror(-ret));
257     }
258 }
259
260 CommandListener::InterfaceCmd::InterfaceCmd() :
261                  NetdCommand("interface") {
262 }
263
264 int CommandListener::InterfaceCmd::runCommand(SocketClient *cli,
265                                                       int argc, char **argv) {
266     if (argc < 2) {
267         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
268         return 0;
269     }
270
271     if (!strcmp(argv[1], "list")) {
272         DIR *d;
273         struct dirent *de;
274
275         if (!(d = opendir("/sys/class/net"))) {
276             cli->sendMsg(ResponseCode::OperationFailed, "Failed to open sysfs dir", true);
277             return 0;
278         }
279
280         while((de = readdir(d))) {
281             if (de->d_name[0] == '.')
282                 continue;
283             cli->sendMsg(ResponseCode::InterfaceListResult, de->d_name, false);
284         }
285         closedir(d);
286         cli->sendMsg(ResponseCode::CommandOkay, "Interface list completed", false);
287         return 0;
288     } else {
289         /*
290          * These commands take a minimum of 3 arguments
291          */
292         if (argc < 3) {
293             cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
294             return 0;
295         }
296
297         if (!strcmp(argv[1], "getcfg")) {
298             struct in_addr addr;
299             int prefixLength;
300             unsigned char hwaddr[6];
301             unsigned flags = 0;
302
303             ifc_init();
304             memset(hwaddr, 0, sizeof(hwaddr));
305
306             if (ifc_get_info(argv[2], &addr.s_addr, &prefixLength, &flags)) {
307                 cli->sendMsg(ResponseCode::OperationFailed, "Interface not found", true);
308                 ifc_close();
309                 return 0;
310             }
311
312             if (ifc_get_hwaddr(argv[2], (void *) hwaddr)) {
313                 ALOGW("Failed to retrieve HW addr for %s (%s)", argv[2], strerror(errno));
314             }
315
316             char *addr_s = strdup(inet_ntoa(addr));
317             const char *updown, *brdcst, *loopbk, *ppp, *running, *multi;
318
319             updown =  (flags & IFF_UP)           ? "up" : "down";
320             brdcst =  (flags & IFF_BROADCAST)    ? " broadcast" : "";
321             loopbk =  (flags & IFF_LOOPBACK)     ? " loopback" : "";
322             ppp =     (flags & IFF_POINTOPOINT)  ? " point-to-point" : "";
323             running = (flags & IFF_RUNNING)      ? " running" : "";
324             multi =   (flags & IFF_MULTICAST)    ? " multicast" : "";
325
326             char *flag_s;
327
328             asprintf(&flag_s, "%s%s%s%s%s%s", updown, brdcst, loopbk, ppp, running, multi);
329
330             char *msg = NULL;
331             asprintf(&msg, "%.2x:%.2x:%.2x:%.2x:%.2x:%.2x %s %d %s",
332                      hwaddr[0], hwaddr[1], hwaddr[2], hwaddr[3], hwaddr[4], hwaddr[5],
333                      addr_s, prefixLength, flag_s);
334
335             cli->sendMsg(ResponseCode::InterfaceGetCfgResult, msg, false);
336
337             free(addr_s);
338             free(flag_s);
339             free(msg);
340
341             ifc_close();
342             return 0;
343         } else if (!strcmp(argv[1], "setcfg")) {
344             // arglist: iface [addr prefixLength] flags
345             if (argc < 4) {
346                 cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
347                 return 0;
348             }
349             ALOGD("Setting iface cfg");
350
351             struct in_addr addr;
352             int index = 5;
353
354             ifc_init();
355
356             if (!inet_aton(argv[3], &addr)) {
357                 // Handle flags only case
358                 index = 3;
359             } else {
360                 if (ifc_set_addr(argv[2], addr.s_addr)) {
361                     cli->sendMsg(ResponseCode::OperationFailed, "Failed to set address", true);
362                     ifc_close();
363                     return 0;
364                 }
365
366                 // Set prefix length on a non zero address
367                 if (addr.s_addr != 0 && ifc_set_prefixLength(argv[2], atoi(argv[4]))) {
368                    cli->sendMsg(ResponseCode::OperationFailed, "Failed to set prefixLength", true);
369                    ifc_close();
370                    return 0;
371                }
372             }
373
374             /* Process flags */
375             for (int i = index; i < argc; i++) {
376                 char *flag = argv[i];
377                 if (!strcmp(flag, "up")) {
378                     ALOGD("Trying to bring up %s", argv[2]);
379                     if (ifc_up(argv[2])) {
380                         ALOGE("Error upping interface");
381                         cli->sendMsg(ResponseCode::OperationFailed, "Failed to up interface", true);
382                         ifc_close();
383                         return 0;
384                     }
385                 } else if (!strcmp(flag, "down")) {
386                     ALOGD("Trying to bring down %s", argv[2]);
387                     if (ifc_down(argv[2])) {
388                         ALOGE("Error downing interface");
389                         cli->sendMsg(ResponseCode::OperationFailed, "Failed to down interface", true);
390                         ifc_close();
391                         return 0;
392                     }
393                 } else if (!strcmp(flag, "broadcast")) {
394                     // currently ignored
395                 } else if (!strcmp(flag, "multicast")) {
396                     // currently ignored
397                 } else if (!strcmp(flag, "running")) {
398                     // currently ignored
399                 } else if (!strcmp(flag, "loopback")) {
400                     // currently ignored
401                 } else if (!strcmp(flag, "point-to-point")) {
402                     // currently ignored
403                 } else {
404                     cli->sendMsg(ResponseCode::CommandParameterError, "Flag unsupported", false);
405                     ifc_close();
406                     return 0;
407                 }
408             }
409
410             cli->sendMsg(ResponseCode::CommandOkay, "Interface configuration set", false);
411             ifc_close();
412             return 0;
413         } else if (!strcmp(argv[1], "clearaddrs")) {
414             // arglist: iface
415             ALOGD("Clearing all IP addresses on %s", argv[2]);
416
417             ifc_clear_addresses(argv[2]);
418
419             cli->sendMsg(ResponseCode::CommandOkay, "Interface IP addresses cleared", false);
420             return 0;
421         } else if (!strcmp(argv[1], "ipv6privacyextensions")) {
422             if (argc != 4) {
423                 cli->sendMsg(ResponseCode::CommandSyntaxError,
424                         "Usage: interface ipv6privacyextensions <interface> <enable|disable>",
425                         false);
426                 return 0;
427             }
428             int enable = !strncmp(argv[3], "enable", 7);
429             if (sInterfaceCtrl->setIPv6PrivacyExtensions(argv[2], enable) == 0) {
430                 cli->sendMsg(ResponseCode::CommandOkay, "IPv6 privacy extensions changed", false);
431             } else {
432                 cli->sendMsg(ResponseCode::OperationFailed,
433                         "Failed to set ipv6 privacy extensions", true);
434             }
435             return 0;
436         } else if (!strcmp(argv[1], "ipv6")) {
437             if (argc != 4) {
438                 cli->sendMsg(ResponseCode::CommandSyntaxError,
439                         "Usage: interface ipv6 <interface> <enable|disable>",
440                         false);
441                 return 0;
442             }
443
444             int enable = !strncmp(argv[3], "enable", 7);
445             if (sInterfaceCtrl->setEnableIPv6(argv[2], enable) == 0) {
446                 cli->sendMsg(ResponseCode::CommandOkay, "IPv6 state changed", false);
447             } else {
448                 cli->sendMsg(ResponseCode::OperationFailed,
449                         "Failed to change IPv6 state", true);
450             }
451             return 0;
452         } else if (!strcmp(argv[1], "ipv6ndoffload")) {
453             if (argc != 4) {
454                 cli->sendMsg(ResponseCode::CommandSyntaxError,
455                         "Usage: interface ipv6ndoffload <interface> <enable|disable>",
456                         false);
457                 return 0;
458             }
459             int enable = !strncmp(argv[3], "enable", 7);
460             if (sInterfaceCtrl->setIPv6NdOffload(argv[2], enable) == 0) {
461                 cli->sendMsg(ResponseCode::CommandOkay, "IPv6 ND offload changed", false);
462             } else {
463                 cli->sendMsg(ResponseCode::OperationFailed,
464                         "Failed to change IPv6 ND offload state", true);
465             }
466             return 0;
467         } else if (!strcmp(argv[1], "setmtu")) {
468             if (argc != 4) {
469                 cli->sendMsg(ResponseCode::CommandSyntaxError,
470                         "Usage: interface setmtu <interface> <val>", false);
471                 return 0;
472             }
473             if (sInterfaceCtrl->setMtu(argv[2], argv[3]) == 0) {
474                 cli->sendMsg(ResponseCode::CommandOkay, "MTU changed", false);
475             } else {
476                 cli->sendMsg(ResponseCode::OperationFailed,
477                         "Failed to get MTU", true);
478             }
479             return 0;
480         } else {
481             cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown interface cmd", false);
482             return 0;
483         }
484     }
485     return 0;
486 }
487
488
489 CommandListener::ListTtysCmd::ListTtysCmd() :
490                  NetdCommand("list_ttys") {
491 }
492
493 int CommandListener::ListTtysCmd::runCommand(SocketClient *cli,
494                                              int /* argc */, char ** /* argv */) {
495     TtyCollection *tlist = sPppCtrl->getTtyList();
496     TtyCollection::iterator it;
497
498     for (it = tlist->begin(); it != tlist->end(); ++it) {
499         cli->sendMsg(ResponseCode::TtyListResult, *it, false);
500     }
501
502     cli->sendMsg(ResponseCode::CommandOkay, "Ttys listed.", false);
503     return 0;
504 }
505
506 CommandListener::IpFwdCmd::IpFwdCmd() :
507                  NetdCommand("ipfwd") {
508 }
509
510 int CommandListener::IpFwdCmd::runCommand(SocketClient *cli,
511                                                       int argc, char **argv) {
512     int rc = 0;
513
514     if (argc < 2) {
515         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
516         return 0;
517     }
518
519     if (!strcmp(argv[1], "status")) {
520         char *tmp = NULL;
521
522         asprintf(&tmp, "Forwarding %s", (sTetherCtrl->getIpFwdEnabled() ? "enabled" : "disabled"));
523         cli->sendMsg(ResponseCode::IpFwdStatusResult, tmp, false);
524         free(tmp);
525         return 0;
526     } else if (!strcmp(argv[1], "enable")) {
527         rc = sTetherCtrl->setIpFwdEnabled(true);
528     } else if (!strcmp(argv[1], "disable")) {
529         rc = sTetherCtrl->setIpFwdEnabled(false);
530     } else {
531         cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown ipfwd cmd", false);
532         return 0;
533     }
534
535     if (!rc) {
536         cli->sendMsg(ResponseCode::CommandOkay, "ipfwd operation succeeded", false);
537     } else {
538         cli->sendMsg(ResponseCode::OperationFailed, "ipfwd operation failed", true);
539     }
540
541     return 0;
542 }
543
544 CommandListener::TetherCmd::TetherCmd() :
545                  NetdCommand("tether") {
546 }
547
548 int CommandListener::TetherCmd::runCommand(SocketClient *cli,
549                                                       int argc, char **argv) {
550     int rc = 0;
551
552     if (argc < 2) {
553         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
554         return 0;
555     }
556
557     if (!strcmp(argv[1], "stop")) {
558         rc = sTetherCtrl->stopTethering();
559     } else if (!strcmp(argv[1], "status")) {
560         char *tmp = NULL;
561
562         asprintf(&tmp, "Tethering services %s",
563                  (sTetherCtrl->isTetheringStarted() ? "started" : "stopped"));
564         cli->sendMsg(ResponseCode::TetherStatusResult, tmp, false);
565         free(tmp);
566         return 0;
567     } else if (argc == 3) {
568         if (!strcmp(argv[1], "interface") && !strcmp(argv[2], "list")) {
569             InterfaceCollection *ilist = sTetherCtrl->getTetheredInterfaceList();
570             InterfaceCollection::iterator it;
571             for (it = ilist->begin(); it != ilist->end(); ++it) {
572                 cli->sendMsg(ResponseCode::TetherInterfaceListResult, *it, false);
573             }
574         } else if (!strcmp(argv[1], "dns") && !strcmp(argv[2], "list")) {
575             char netIdStr[UINT32_STRLEN];
576             snprintf(netIdStr, sizeof(netIdStr), "%u", sTetherCtrl->getDnsNetId());
577             cli->sendMsg(ResponseCode::TetherDnsFwdNetIdResult, netIdStr, false);
578
579             NetAddressCollection *dlist = sTetherCtrl->getDnsForwarders();
580             NetAddressCollection::iterator it;
581
582             for (it = dlist->begin(); it != dlist->end(); ++it) {
583                 cli->sendMsg(ResponseCode::TetherDnsFwdTgtListResult, inet_ntoa(*it), false);
584             }
585         }
586     } else {
587         /*
588          * These commands take a minimum of 4 arguments
589          */
590         if (argc < 4) {
591             cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
592             return 0;
593         }
594
595         if (!strcmp(argv[1], "start")) {
596             if (argc % 2 == 1) {
597                 cli->sendMsg(ResponseCode::CommandSyntaxError, "Bad number of arguments", false);
598                 return 0;
599             }
600
601             int num_addrs = argc - 2;
602             int arg_index = 2;
603             int array_index = 0;
604             in_addr *addrs = (in_addr *)malloc(sizeof(in_addr) * num_addrs);
605             while (array_index < num_addrs) {
606                 if (!inet_aton(argv[arg_index++], &(addrs[array_index++]))) {
607                     cli->sendMsg(ResponseCode::CommandParameterError, "Invalid address", false);
608                     free(addrs);
609                     return 0;
610                 }
611             }
612             rc = sTetherCtrl->startTethering(num_addrs, addrs);
613             free(addrs);
614         } else if (!strcmp(argv[1], "interface")) {
615             if (!strcmp(argv[2], "add")) {
616                 rc = sTetherCtrl->tetherInterface(argv[3]);
617             } else if (!strcmp(argv[2], "remove")) {
618                 rc = sTetherCtrl->untetherInterface(argv[3]);
619             /* else if (!strcmp(argv[2], "list")) handled above */
620             } else {
621                 cli->sendMsg(ResponseCode::CommandParameterError,
622                              "Unknown tether interface operation", false);
623                 return 0;
624             }
625         } else if (!strcmp(argv[1], "dns")) {
626             if (!strcmp(argv[2], "set")) {
627                 if (argc < 5) {
628                     cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
629                     return 0;
630                 }
631                 unsigned netId = stringToNetId(argv[3]);
632                 rc = sTetherCtrl->setDnsForwarders(netId, &argv[4], argc - 4);
633             /* else if (!strcmp(argv[2], "list")) handled above */
634             } else {
635                 cli->sendMsg(ResponseCode::CommandParameterError,
636                              "Unknown tether interface operation", false);
637                 return 0;
638             }
639         } else {
640             cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown tether cmd", false);
641             return 0;
642         }
643     }
644
645     if (!rc) {
646         cli->sendMsg(ResponseCode::CommandOkay, "Tether operation succeeded", false);
647     } else {
648         cli->sendMsg(ResponseCode::OperationFailed, "Tether operation failed", true);
649     }
650
651     return 0;
652 }
653
654 CommandListener::NatCmd::NatCmd() :
655                  NetdCommand("nat") {
656 }
657
658 int CommandListener::NatCmd::runCommand(SocketClient *cli,
659                                                       int argc, char **argv) {
660     int rc = 0;
661
662     if (argc < 5) {
663         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
664         return 0;
665     }
666
667     //  0     1       2        3
668     // nat  enable intiface extiface
669     // nat disable intiface extiface
670     if (!strcmp(argv[1], "enable") && argc >= 4) {
671         rc = sNatCtrl->enableNat(argv[2], argv[3]);
672         if(!rc) {
673             /* Ignore ifaces for now. */
674             rc = sBandwidthCtrl->setGlobalAlertInForwardChain();
675         }
676     } else if (!strcmp(argv[1], "disable") && argc >= 4) {
677         /* Ignore ifaces for now. */
678         rc = sBandwidthCtrl->removeGlobalAlertInForwardChain();
679         rc |= sNatCtrl->disableNat(argv[2], argv[3]);
680     } else {
681         cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown nat cmd", false);
682         return 0;
683     }
684
685     if (!rc) {
686         cli->sendMsg(ResponseCode::CommandOkay, "Nat operation succeeded", false);
687     } else {
688         cli->sendMsg(ResponseCode::OperationFailed, "Nat operation failed", true);
689     }
690
691     return 0;
692 }
693
694 CommandListener::PppdCmd::PppdCmd() :
695                  NetdCommand("pppd") {
696 }
697
698 int CommandListener::PppdCmd::runCommand(SocketClient *cli,
699                                                       int argc, char **argv) {
700     int rc = 0;
701
702     if (argc < 3) {
703         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
704         return 0;
705     }
706
707     if (!strcmp(argv[1], "attach")) {
708         struct in_addr l, r, dns1, dns2;
709
710         memset(&dns1, 0, sizeof(struct in_addr));
711         memset(&dns2, 0, sizeof(struct in_addr));
712
713         if (!inet_aton(argv[3], &l)) {
714             cli->sendMsg(ResponseCode::CommandParameterError, "Invalid local address", false);
715             return 0;
716         }
717         if (!inet_aton(argv[4], &r)) {
718             cli->sendMsg(ResponseCode::CommandParameterError, "Invalid remote address", false);
719             return 0;
720         }
721         if ((argc > 3) && (!inet_aton(argv[5], &dns1))) {
722             cli->sendMsg(ResponseCode::CommandParameterError, "Invalid dns1 address", false);
723             return 0;
724         }
725         if ((argc > 4) && (!inet_aton(argv[6], &dns2))) {
726             cli->sendMsg(ResponseCode::CommandParameterError, "Invalid dns2 address", false);
727             return 0;
728         }
729         rc = sPppCtrl->attachPppd(argv[2], l, r, dns1, dns2);
730     } else if (!strcmp(argv[1], "detach")) {
731         rc = sPppCtrl->detachPppd(argv[2]);
732     } else {
733         cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown pppd cmd", false);
734         return 0;
735     }
736
737     if (!rc) {
738         cli->sendMsg(ResponseCode::CommandOkay, "Pppd operation succeeded", false);
739     } else {
740         cli->sendMsg(ResponseCode::OperationFailed, "Pppd operation failed", true);
741     }
742
743     return 0;
744 }
745
746 CommandListener::SoftapCmd::SoftapCmd() :
747                  NetdCommand("softap") {
748 }
749
750 int CommandListener::SoftapCmd::runCommand(SocketClient *cli,
751                                         int argc, char **argv) {
752     int rc = ResponseCode::SoftapStatusResult;
753     char *retbuf = NULL;
754
755     if (sSoftapCtrl == NULL) {
756       cli->sendMsg(ResponseCode::ServiceStartFailed, "SoftAP is not available", false);
757       return -1;
758     }
759     if (argc < 2) {
760         cli->sendMsg(ResponseCode::CommandSyntaxError,
761                      "Missing argument in a SoftAP command", false);
762         return 0;
763     }
764
765     if (!strcmp(argv[1], "startap")) {
766         rc = sSoftapCtrl->startSoftap();
767     } else if (!strcmp(argv[1], "stopap")) {
768         rc = sSoftapCtrl->stopSoftap();
769     } else if (!strcmp(argv[1], "fwreload")) {
770         rc = sSoftapCtrl->fwReloadSoftap(argc, argv);
771     } else if (!strcmp(argv[1], "status")) {
772         asprintf(&retbuf, "Softap service %s running",
773                  (sSoftapCtrl->isSoftapStarted() ? "is" : "is not"));
774         cli->sendMsg(rc, retbuf, false);
775         free(retbuf);
776         return 0;
777     } else if (!strcmp(argv[1], "set")) {
778         rc = sSoftapCtrl->setSoftap(argc, argv);
779     } else {
780         cli->sendMsg(ResponseCode::CommandSyntaxError, "Unrecognized SoftAP command", false);
781         return 0;
782     }
783
784     if (rc >= 400 && rc < 600)
785       cli->sendMsg(rc, "SoftAP command has failed", false);
786     else
787       cli->sendMsg(rc, "Ok", false);
788
789     return 0;
790 }
791
792 CommandListener::ResolverCmd::ResolverCmd() :
793         NetdCommand("resolver") {
794 }
795
796 int CommandListener::ResolverCmd::runCommand(SocketClient *cli, int argc, char **margv) {
797     int rc = 0;
798     const char **argv = const_cast<const char **>(margv);
799
800     if (argc < 2) {
801         cli->sendMsg(ResponseCode::CommandSyntaxError, "Resolver missing arguments", false);
802         return 0;
803     }
804
805     if (!strcmp(argv[1], "setnetdns")) {
806         // "resolver setnetdns <netId> <domains> <dns1> <dns2> ..."
807         if (argc >= 5) {
808             rc = sResolverCtrl->setDnsServers(strtoul(argv[2], NULL, 0), argv[3], &argv[4], argc - 4);
809         } else {
810             cli->sendMsg(ResponseCode::CommandSyntaxError,
811                     "Wrong number of arguments to resolver setnetdns", false);
812             return 0;
813         }
814     } else if (!strcmp(argv[1], "clearnetdns")) { // "resolver clearnetdns <netId>"
815         if (argc == 3) {
816             rc = sResolverCtrl->clearDnsServers(strtoul(argv[2], NULL, 0));
817         } else {
818             cli->sendMsg(ResponseCode::CommandSyntaxError,
819                     "Wrong number of arguments to resolver clearnetdns", false);
820             return 0;
821         }
822     } else if (!strcmp(argv[1], "flushnet")) { // "resolver flushnet <netId>"
823         if (argc == 3) {
824             rc = sResolverCtrl->flushDnsCache(strtoul(argv[2], NULL, 0));
825         } else {
826             cli->sendMsg(ResponseCode::CommandSyntaxError,
827                     "Wrong number of arguments to resolver flushnet", false);
828             return 0;
829         }
830     } else {
831         cli->sendMsg(ResponseCode::CommandSyntaxError,"Resolver unknown command", false);
832         return 0;
833     }
834
835     if (!rc) {
836         cli->sendMsg(ResponseCode::CommandOkay, "Resolver command succeeded", false);
837     } else {
838         cli->sendMsg(ResponseCode::OperationFailed, "Resolver command failed", true);
839     }
840
841     return 0;
842 }
843
844 CommandListener::BandwidthControlCmd::BandwidthControlCmd() :
845     NetdCommand("bandwidth") {
846 }
847
848 void CommandListener::BandwidthControlCmd::sendGenericSyntaxError(SocketClient *cli, const char *usageMsg) {
849     char *msg;
850     asprintf(&msg, "Usage: bandwidth %s", usageMsg);
851     cli->sendMsg(ResponseCode::CommandSyntaxError, msg, false);
852     free(msg);
853 }
854
855 void CommandListener::BandwidthControlCmd::sendGenericOkFail(SocketClient *cli, int cond) {
856     if (!cond) {
857         cli->sendMsg(ResponseCode::CommandOkay, "Bandwidth command succeeeded", false);
858     } else {
859         cli->sendMsg(ResponseCode::OperationFailed, "Bandwidth command failed", false);
860     }
861 }
862
863 void CommandListener::BandwidthControlCmd::sendGenericOpFailed(SocketClient *cli, const char *errMsg) {
864     cli->sendMsg(ResponseCode::OperationFailed, errMsg, false);
865 }
866
867 int CommandListener::BandwidthControlCmd::runCommand(SocketClient *cli, int argc, char **argv) {
868     if (argc < 2) {
869         sendGenericSyntaxError(cli, "<cmds> <args...>");
870         return 0;
871     }
872
873     ALOGV("bwctrlcmd: argc=%d %s %s ...", argc, argv[0], argv[1]);
874
875     if (!strcmp(argv[1], "enable")) {
876         int rc = sBandwidthCtrl->enableBandwidthControl(true);
877         sendGenericOkFail(cli, rc);
878         return 0;
879
880     }
881     if (!strcmp(argv[1], "disable")) {
882         int rc = sBandwidthCtrl->disableBandwidthControl();
883         sendGenericOkFail(cli, rc);
884         return 0;
885
886     }
887     if (!strcmp(argv[1], "removequota") || !strcmp(argv[1], "rq")) {
888         if (argc != 3) {
889             sendGenericSyntaxError(cli, "removequota <interface>");
890             return 0;
891         }
892         int rc = sBandwidthCtrl->removeInterfaceSharedQuota(argv[2]);
893         sendGenericOkFail(cli, rc);
894         return 0;
895
896     }
897     if (!strcmp(argv[1], "getquota") || !strcmp(argv[1], "gq")) {
898         int64_t bytes;
899         if (argc != 2) {
900             sendGenericSyntaxError(cli, "getquota");
901             return 0;
902         }
903         int rc = sBandwidthCtrl->getInterfaceSharedQuota(&bytes);
904         if (rc) {
905             sendGenericOpFailed(cli, "Failed to get quota");
906             return 0;
907         }
908
909         char *msg;
910         asprintf(&msg, "%" PRId64, bytes);
911         cli->sendMsg(ResponseCode::QuotaCounterResult, msg, false);
912         free(msg);
913         return 0;
914
915     }
916     if (!strcmp(argv[1], "getiquota") || !strcmp(argv[1], "giq")) {
917         int64_t bytes;
918         if (argc != 3) {
919             sendGenericSyntaxError(cli, "getiquota <iface>");
920             return 0;
921         }
922
923         int rc = sBandwidthCtrl->getInterfaceQuota(argv[2], &bytes);
924         if (rc) {
925             sendGenericOpFailed(cli, "Failed to get quota");
926             return 0;
927         }
928         char *msg;
929         asprintf(&msg, "%" PRId64, bytes);
930         cli->sendMsg(ResponseCode::QuotaCounterResult, msg, false);
931         free(msg);
932         return 0;
933
934     }
935     if (!strcmp(argv[1], "setquota") || !strcmp(argv[1], "sq")) {
936         if (argc != 4) {
937             sendGenericSyntaxError(cli, "setquota <interface> <bytes>");
938             return 0;
939         }
940         int rc = sBandwidthCtrl->setInterfaceSharedQuota(argv[2], atoll(argv[3]));
941         sendGenericOkFail(cli, rc);
942         return 0;
943     }
944     if (!strcmp(argv[1], "setquotas") || !strcmp(argv[1], "sqs")) {
945         int rc;
946         if (argc < 4) {
947             sendGenericSyntaxError(cli, "setquotas <bytes> <interface> ...");
948             return 0;
949         }
950
951         for (int q = 3; argc >= 4; q++, argc--) {
952             rc = sBandwidthCtrl->setInterfaceSharedQuota(argv[q], atoll(argv[2]));
953             if (rc) {
954                 char *msg;
955                 asprintf(&msg, "bandwidth setquotas %s %s failed", argv[2], argv[q]);
956                 cli->sendMsg(ResponseCode::OperationFailed,
957                              msg, false);
958                 free(msg);
959                 return 0;
960             }
961         }
962         sendGenericOkFail(cli, rc);
963         return 0;
964
965     }
966     if (!strcmp(argv[1], "removequotas") || !strcmp(argv[1], "rqs")) {
967         int rc;
968         if (argc < 3) {
969             sendGenericSyntaxError(cli, "removequotas <interface> ...");
970             return 0;
971         }
972
973         for (int q = 2; argc >= 3; q++, argc--) {
974             rc = sBandwidthCtrl->removeInterfaceSharedQuota(argv[q]);
975             if (rc) {
976                 char *msg;
977                 asprintf(&msg, "bandwidth removequotas %s failed", argv[q]);
978                 cli->sendMsg(ResponseCode::OperationFailed,
979                              msg, false);
980                 free(msg);
981                 return 0;
982             }
983         }
984         sendGenericOkFail(cli, rc);
985         return 0;
986
987     }
988     if (!strcmp(argv[1], "removeiquota") || !strcmp(argv[1], "riq")) {
989         if (argc != 3) {
990             sendGenericSyntaxError(cli, "removeiquota <interface>");
991             return 0;
992         }
993         int rc = sBandwidthCtrl->removeInterfaceQuota(argv[2]);
994         sendGenericOkFail(cli, rc);
995         return 0;
996
997     }
998     if (!strcmp(argv[1], "setiquota") || !strcmp(argv[1], "siq")) {
999         if (argc != 4) {
1000             sendGenericSyntaxError(cli, "setiquota <interface> <bytes>");
1001             return 0;
1002         }
1003         int rc = sBandwidthCtrl->setInterfaceQuota(argv[2], atoll(argv[3]));
1004         sendGenericOkFail(cli, rc);
1005         return 0;
1006
1007     }
1008     if (!strcmp(argv[1], "addnaughtyapps") || !strcmp(argv[1], "ana")) {
1009         if (argc < 3) {
1010             sendGenericSyntaxError(cli, "addnaughtyapps <appUid> ...");
1011             return 0;
1012         }
1013         int rc = sBandwidthCtrl->addNaughtyApps(argc - 2, argv + 2);
1014         sendGenericOkFail(cli, rc);
1015         return 0;
1016
1017
1018     }
1019     if (!strcmp(argv[1], "removenaughtyapps") || !strcmp(argv[1], "rna")) {
1020         if (argc < 3) {
1021             sendGenericSyntaxError(cli, "removenaughtyapps <appUid> ...");
1022             return 0;
1023         }
1024         int rc = sBandwidthCtrl->removeNaughtyApps(argc - 2, argv + 2);
1025         sendGenericOkFail(cli, rc);
1026         return 0;
1027     }
1028     if (!strcmp(argv[1], "happybox")) {
1029         if (argc < 3) {
1030             sendGenericSyntaxError(cli, "happybox (enable | disable)");
1031             return 0;
1032         }
1033         if (!strcmp(argv[2], "enable")) {
1034             int rc = sBandwidthCtrl->enableHappyBox();
1035             sendGenericOkFail(cli, rc);
1036             return 0;
1037
1038         }
1039         if (!strcmp(argv[2], "disable")) {
1040             int rc = sBandwidthCtrl->disableHappyBox();
1041             sendGenericOkFail(cli, rc);
1042             return 0;
1043         }
1044         sendGenericSyntaxError(cli, "happybox (enable | disable)");
1045         return 0;
1046     }
1047     if (!strcmp(argv[1], "addniceapps") || !strcmp(argv[1], "aha")) {
1048         if (argc < 3) {
1049             sendGenericSyntaxError(cli, "addniceapps <appUid> ...");
1050             return 0;
1051         }
1052         int rc = sBandwidthCtrl->addNiceApps(argc - 2, argv + 2);
1053         sendGenericOkFail(cli, rc);
1054         return 0;
1055     }
1056     if (!strcmp(argv[1], "removeniceapps") || !strcmp(argv[1], "rha")) {
1057         if (argc < 3) {
1058             sendGenericSyntaxError(cli, "removeniceapps <appUid> ...");
1059             return 0;
1060         }
1061         int rc = sBandwidthCtrl->removeNiceApps(argc - 2, argv + 2);
1062         sendGenericOkFail(cli, rc);
1063         return 0;
1064     }
1065     if (!strcmp(argv[1], "setglobalalert") || !strcmp(argv[1], "sga")) {
1066         if (argc != 3) {
1067             sendGenericSyntaxError(cli, "setglobalalert <bytes>");
1068             return 0;
1069         }
1070         int rc = sBandwidthCtrl->setGlobalAlert(atoll(argv[2]));
1071         sendGenericOkFail(cli, rc);
1072         return 0;
1073     }
1074     if (!strcmp(argv[1], "debugsettetherglobalalert") || !strcmp(argv[1], "dstga")) {
1075         if (argc != 4) {
1076             sendGenericSyntaxError(cli, "debugsettetherglobalalert <interface0> <interface1>");
1077             return 0;
1078         }
1079         /* We ignore the interfaces for now. */
1080         int rc = sBandwidthCtrl->setGlobalAlertInForwardChain();
1081         sendGenericOkFail(cli, rc);
1082         return 0;
1083
1084     }
1085     if (!strcmp(argv[1], "removeglobalalert") || !strcmp(argv[1], "rga")) {
1086         if (argc != 2) {
1087             sendGenericSyntaxError(cli, "removeglobalalert");
1088             return 0;
1089         }
1090         int rc = sBandwidthCtrl->removeGlobalAlert();
1091         sendGenericOkFail(cli, rc);
1092         return 0;
1093
1094     }
1095     if (!strcmp(argv[1], "debugremovetetherglobalalert") || !strcmp(argv[1], "drtga")) {
1096         if (argc != 4) {
1097             sendGenericSyntaxError(cli, "debugremovetetherglobalalert <interface0> <interface1>");
1098             return 0;
1099         }
1100         /* We ignore the interfaces for now. */
1101         int rc = sBandwidthCtrl->removeGlobalAlertInForwardChain();
1102         sendGenericOkFail(cli, rc);
1103         return 0;
1104
1105     }
1106     if (!strcmp(argv[1], "setsharedalert") || !strcmp(argv[1], "ssa")) {
1107         if (argc != 3) {
1108             sendGenericSyntaxError(cli, "setsharedalert <bytes>");
1109             return 0;
1110         }
1111         int rc = sBandwidthCtrl->setSharedAlert(atoll(argv[2]));
1112         sendGenericOkFail(cli, rc);
1113         return 0;
1114
1115     }
1116     if (!strcmp(argv[1], "removesharedalert") || !strcmp(argv[1], "rsa")) {
1117         if (argc != 2) {
1118             sendGenericSyntaxError(cli, "removesharedalert");
1119             return 0;
1120         }
1121         int rc = sBandwidthCtrl->removeSharedAlert();
1122         sendGenericOkFail(cli, rc);
1123         return 0;
1124
1125     }
1126     if (!strcmp(argv[1], "setinterfacealert") || !strcmp(argv[1], "sia")) {
1127         if (argc != 4) {
1128             sendGenericSyntaxError(cli, "setinterfacealert <interface> <bytes>");
1129             return 0;
1130         }
1131         int rc = sBandwidthCtrl->setInterfaceAlert(argv[2], atoll(argv[3]));
1132         sendGenericOkFail(cli, rc);
1133         return 0;
1134
1135     }
1136     if (!strcmp(argv[1], "removeinterfacealert") || !strcmp(argv[1], "ria")) {
1137         if (argc != 3) {
1138             sendGenericSyntaxError(cli, "removeinterfacealert <interface>");
1139             return 0;
1140         }
1141         int rc = sBandwidthCtrl->removeInterfaceAlert(argv[2]);
1142         sendGenericOkFail(cli, rc);
1143         return 0;
1144
1145     }
1146     if (!strcmp(argv[1], "gettetherstats") || !strcmp(argv[1], "gts")) {
1147         BandwidthController::TetherStats tetherStats;
1148         std::string extraProcessingInfo = "";
1149         if (argc < 2 || argc > 4) {
1150             sendGenericSyntaxError(cli, "gettetherstats [<intInterface> <extInterface>]");
1151             return 0;
1152         }
1153         tetherStats.intIface = argc > 2 ? argv[2] : "";
1154         tetherStats.extIface = argc > 3 ? argv[3] : "";
1155         // No filtering requested and there are no interface pairs to lookup.
1156         if (argc <= 2 && sNatCtrl->ifacePairList.empty()) {
1157             cli->sendMsg(ResponseCode::CommandOkay, "Tethering stats list completed", false);
1158             return 0;
1159         }
1160         int rc = sBandwidthCtrl->getTetherStats(cli, tetherStats, extraProcessingInfo);
1161         if (rc) {
1162                 extraProcessingInfo.insert(0, "Failed to get tethering stats.\n");
1163                 sendGenericOpFailed(cli, extraProcessingInfo.c_str());
1164                 return 0;
1165         }
1166         return 0;
1167
1168     }
1169
1170     cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown bandwidth cmd", false);
1171     return 0;
1172 }
1173
1174 CommandListener::IdletimerControlCmd::IdletimerControlCmd() :
1175     NetdCommand("idletimer") {
1176 }
1177
1178 int CommandListener::IdletimerControlCmd::runCommand(SocketClient *cli, int argc, char **argv) {
1179   // TODO(ashish): Change the error statements
1180     if (argc < 2) {
1181         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1182         return 0;
1183     }
1184
1185     ALOGV("idletimerctrlcmd: argc=%d %s %s ...", argc, argv[0], argv[1]);
1186
1187     if (!strcmp(argv[1], "enable")) {
1188       if (0 != sIdletimerCtrl->enableIdletimerControl()) {
1189         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1190       } else {
1191         cli->sendMsg(ResponseCode::CommandOkay, "Enable success", false);
1192       }
1193       return 0;
1194
1195     }
1196     if (!strcmp(argv[1], "disable")) {
1197       if (0 != sIdletimerCtrl->disableIdletimerControl()) {
1198         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1199       } else {
1200         cli->sendMsg(ResponseCode::CommandOkay, "Disable success", false);
1201       }
1202       return 0;
1203     }
1204     if (!strcmp(argv[1], "add")) {
1205         if (argc != 5) {
1206             cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1207             return 0;
1208         }
1209         if(0 != sIdletimerCtrl->addInterfaceIdletimer(
1210                                         argv[2], atoi(argv[3]), argv[4])) {
1211           cli->sendMsg(ResponseCode::OperationFailed, "Failed to add interface", false);
1212         } else {
1213           cli->sendMsg(ResponseCode::CommandOkay,  "Add success", false);
1214         }
1215         return 0;
1216     }
1217     if (!strcmp(argv[1], "remove")) {
1218         if (argc != 5) {
1219             cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1220             return 0;
1221         }
1222         // ashish: fixme timeout
1223         if (0 != sIdletimerCtrl->removeInterfaceIdletimer(
1224                                         argv[2], atoi(argv[3]), argv[4])) {
1225           cli->sendMsg(ResponseCode::OperationFailed, "Failed to remove interface", false);
1226         } else {
1227           cli->sendMsg(ResponseCode::CommandOkay, "Remove success", false);
1228         }
1229         return 0;
1230     }
1231
1232     cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown idletimer cmd", false);
1233     return 0;
1234 }
1235
1236 CommandListener::FirewallCmd::FirewallCmd() :
1237     NetdCommand("firewall") {
1238 }
1239
1240 int CommandListener::FirewallCmd::sendGenericOkFail(SocketClient *cli, int cond) {
1241     if (!cond) {
1242         cli->sendMsg(ResponseCode::CommandOkay, "Firewall command succeeded", false);
1243     } else {
1244         cli->sendMsg(ResponseCode::OperationFailed, "Firewall command failed", false);
1245     }
1246     return 0;
1247 }
1248
1249 FirewallRule CommandListener::FirewallCmd::parseRule(const char* arg) {
1250     if (!strcmp(arg, "allow")) {
1251         return ALLOW;
1252     } else {
1253         return DENY;
1254     }
1255 }
1256
1257 int CommandListener::FirewallCmd::runCommand(SocketClient *cli, int argc,
1258         char **argv) {
1259     if (argc < 2) {
1260         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing command", false);
1261         return 0;
1262     }
1263
1264     if (!strcmp(argv[1], "enable")) {
1265         int res = sFirewallCtrl->enableFirewall();
1266         return sendGenericOkFail(cli, res);
1267     }
1268     if (!strcmp(argv[1], "disable")) {
1269         int res = sFirewallCtrl->disableFirewall();
1270         return sendGenericOkFail(cli, res);
1271     }
1272     if (!strcmp(argv[1], "is_enabled")) {
1273         int res = sFirewallCtrl->isFirewallEnabled();
1274         return sendGenericOkFail(cli, res);
1275     }
1276
1277     if (!strcmp(argv[1], "set_interface_rule")) {
1278         if (argc != 4) {
1279             cli->sendMsg(ResponseCode::CommandSyntaxError,
1280                          "Usage: firewall set_interface_rule <rmnet0> <allow|deny>", false);
1281             return 0;
1282         }
1283
1284         const char* iface = argv[2];
1285         FirewallRule rule = parseRule(argv[3]);
1286
1287         int res = sFirewallCtrl->setInterfaceRule(iface, rule);
1288         return sendGenericOkFail(cli, res);
1289     }
1290
1291     if (!strcmp(argv[1], "set_egress_source_rule")) {
1292         if (argc != 4) {
1293             cli->sendMsg(ResponseCode::CommandSyntaxError,
1294                          "Usage: firewall set_egress_source_rule <192.168.0.1> <allow|deny>",
1295                          false);
1296             return 0;
1297         }
1298
1299         const char* addr = argv[2];
1300         FirewallRule rule = parseRule(argv[3]);
1301
1302         int res = sFirewallCtrl->setEgressSourceRule(addr, rule);
1303         return sendGenericOkFail(cli, res);
1304     }
1305
1306     if (!strcmp(argv[1], "set_egress_dest_rule")) {
1307         if (argc != 5) {
1308             cli->sendMsg(ResponseCode::CommandSyntaxError,
1309                          "Usage: firewall set_egress_dest_rule <192.168.0.1> <80> <allow|deny>",
1310                          false);
1311             return 0;
1312         }
1313
1314         const char* addr = argv[2];
1315         int port = atoi(argv[3]);
1316         FirewallRule rule = parseRule(argv[4]);
1317
1318         int res = 0;
1319         res |= sFirewallCtrl->setEgressDestRule(addr, PROTOCOL_TCP, port, rule);
1320         res |= sFirewallCtrl->setEgressDestRule(addr, PROTOCOL_UDP, port, rule);
1321         return sendGenericOkFail(cli, res);
1322     }
1323
1324     if (!strcmp(argv[1], "set_uid_rule")) {
1325         if (argc != 4) {
1326             cli->sendMsg(ResponseCode::CommandSyntaxError,
1327                          "Usage: firewall set_uid_rule <1000> <allow|deny>",
1328                          false);
1329             return 0;
1330         }
1331
1332         int uid = atoi(argv[2]);
1333         FirewallRule rule = parseRule(argv[3]);
1334
1335         int res = sFirewallCtrl->setUidRule(uid, rule);
1336         return sendGenericOkFail(cli, res);
1337     }
1338
1339     cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown command", false);
1340     return 0;
1341 }
1342
1343 CommandListener::ClatdCmd::ClatdCmd() : NetdCommand("clatd") {
1344 }
1345
1346 int CommandListener::ClatdCmd::runCommand(SocketClient *cli, int argc,
1347                                                             char **argv) {
1348     int rc = 0;
1349     if (argc < 3) {
1350         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing argument", false);
1351         return 0;
1352     }
1353
1354     if (!strcmp(argv[1], "stop")) {
1355         rc = sClatdCtrl->stopClatd(argv[2]);
1356     } else if (!strcmp(argv[1], "status")) {
1357         char *tmp = NULL;
1358         asprintf(&tmp, "Clatd status: %s", (sClatdCtrl->isClatdStarted(argv[2]) ?
1359                                             "started" : "stopped"));
1360         cli->sendMsg(ResponseCode::ClatdStatusResult, tmp, false);
1361         free(tmp);
1362         return 0;
1363     } else if (!strcmp(argv[1], "start")) {
1364         rc = sClatdCtrl->startClatd(argv[2]);
1365     } else {
1366         cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown clatd cmd", false);
1367         return 0;
1368     }
1369
1370     if (!rc) {
1371         cli->sendMsg(ResponseCode::CommandOkay, "Clatd operation succeeded", false);
1372     } else {
1373         cli->sendMsg(ResponseCode::OperationFailed, "Clatd operation failed", false);
1374     }
1375
1376     return 0;
1377 }
1378
1379 CommandListener::StrictCmd::StrictCmd() :
1380     NetdCommand("strict") {
1381 }
1382
1383 int CommandListener::StrictCmd::sendGenericOkFail(SocketClient *cli, int cond) {
1384     if (!cond) {
1385         cli->sendMsg(ResponseCode::CommandOkay, "Strict command succeeded", false);
1386     } else {
1387         cli->sendMsg(ResponseCode::OperationFailed, "Strict command failed", false);
1388     }
1389     return 0;
1390 }
1391
1392 StrictPenalty CommandListener::StrictCmd::parsePenalty(const char* arg) {
1393     if (!strcmp(arg, "reject")) {
1394         return REJECT;
1395     } else if (!strcmp(arg, "log")) {
1396         return LOG;
1397     } else if (!strcmp(arg, "accept")) {
1398         return ACCEPT;
1399     } else {
1400         return INVALID;
1401     }
1402 }
1403
1404 int CommandListener::StrictCmd::runCommand(SocketClient *cli, int argc,
1405         char **argv) {
1406     if (argc < 2) {
1407         cli->sendMsg(ResponseCode::CommandSyntaxError, "Missing command", false);
1408         return 0;
1409     }
1410
1411     if (!strcmp(argv[1], "enable")) {
1412         int res = sStrictCtrl->enableStrict();
1413         return sendGenericOkFail(cli, res);
1414     }
1415     if (!strcmp(argv[1], "disable")) {
1416         int res = sStrictCtrl->disableStrict();
1417         return sendGenericOkFail(cli, res);
1418     }
1419
1420     if (!strcmp(argv[1], "set_uid_cleartext_policy")) {
1421         if (argc != 4) {
1422             cli->sendMsg(ResponseCode::CommandSyntaxError,
1423                          "Usage: strict set_uid_cleartext_policy <uid> <accept|log|reject>",
1424                          false);
1425             return 0;
1426         }
1427
1428         errno = 0;
1429         unsigned long int uid = strtoul(argv[2], NULL, 0);
1430         if (errno || uid > UID_MAX) {
1431             cli->sendMsg(ResponseCode::CommandSyntaxError, "Invalid UID", false);
1432             return 0;
1433         }
1434
1435         StrictPenalty penalty = parsePenalty(argv[3]);
1436         if (penalty == INVALID) {
1437             cli->sendMsg(ResponseCode::CommandSyntaxError, "Invalid penalty argument", false);
1438             return 0;
1439         }
1440
1441         int res = sStrictCtrl->setUidCleartextPenalty((uid_t) uid, penalty);
1442         return sendGenericOkFail(cli, res);
1443     }
1444
1445     cli->sendMsg(ResponseCode::CommandSyntaxError, "Unknown command", false);
1446     return 0;
1447 }
1448
1449 CommandListener::NetworkCommand::NetworkCommand() : NetdCommand("network") {
1450 }
1451
1452 int CommandListener::NetworkCommand::syntaxError(SocketClient* client, const char* message) {
1453     client->sendMsg(ResponseCode::CommandSyntaxError, message, false);
1454     return 0;
1455 }
1456
1457 int CommandListener::NetworkCommand::operationError(SocketClient* client, const char* message,
1458                                                     int ret) {
1459     errno = -ret;
1460     client->sendMsg(ResponseCode::OperationFailed, message, true);
1461     return 0;
1462 }
1463
1464 int CommandListener::NetworkCommand::success(SocketClient* client) {
1465     client->sendMsg(ResponseCode::CommandOkay, "success", false);
1466     return 0;
1467 }
1468
1469 int CommandListener::NetworkCommand::runCommand(SocketClient* client, int argc, char** argv) {
1470     if (argc < 2) {
1471         return syntaxError(client, "Missing argument");
1472     }
1473
1474     //    0      1      2      3      4       5         6            7           8
1475     // network route [legacy <uid>]  add   <netId> <interface> <destination> [nexthop]
1476     // network route [legacy <uid>] remove <netId> <interface> <destination> [nexthop]
1477     //
1478     // nexthop may be either an IPv4/IPv6 address or one of "unreachable" or "throw".
1479     if (!strcmp(argv[1], "route")) {
1480         if (argc < 6 || argc > 9) {
1481             return syntaxError(client, "Incorrect number of arguments");
1482         }
1483
1484         int nextArg = 2;
1485         bool legacy = false;
1486         uid_t uid = 0;
1487         if (!strcmp(argv[nextArg], "legacy")) {
1488             ++nextArg;
1489             legacy = true;
1490             uid = strtoul(argv[nextArg++], NULL, 0);
1491         }
1492
1493         bool add = false;
1494         if (!strcmp(argv[nextArg], "add")) {
1495             add = true;
1496         } else if (strcmp(argv[nextArg], "remove")) {
1497             return syntaxError(client, "Unknown argument");
1498         }
1499         ++nextArg;
1500
1501         if (argc < nextArg + 3 || argc > nextArg + 4) {
1502             return syntaxError(client, "Incorrect number of arguments");
1503         }
1504
1505         unsigned netId = stringToNetId(argv[nextArg++]);
1506         const char* interface = argv[nextArg++];
1507         const char* destination = argv[nextArg++];
1508         const char* nexthop = argc > nextArg ? argv[nextArg] : NULL;
1509
1510         int ret;
1511         if (add) {
1512             ret = sNetCtrl->addRoute(netId, interface, destination, nexthop, legacy, uid);
1513         } else {
1514             ret = sNetCtrl->removeRoute(netId, interface, destination, nexthop, legacy, uid);
1515         }
1516         if (ret) {
1517             return operationError(client, add ? "addRoute() failed" : "removeRoute() failed", ret);
1518         }
1519
1520         return success(client);
1521     }
1522
1523     //    0        1       2       3         4
1524     // network interface  add   <netId> <interface>
1525     // network interface remove <netId> <interface>
1526     if (!strcmp(argv[1], "interface")) {
1527         if (argc != 5) {
1528             return syntaxError(client, "Missing argument");
1529         }
1530         unsigned netId = stringToNetId(argv[3]);
1531         if (!strcmp(argv[2], "add")) {
1532             if (int ret = sNetCtrl->addInterfaceToNetwork(netId, argv[4])) {
1533                 return operationError(client, "addInterfaceToNetwork() failed", ret);
1534             }
1535         } else if (!strcmp(argv[2], "remove")) {
1536             if (int ret = sNetCtrl->removeInterfaceFromNetwork(netId, argv[4])) {
1537                 return operationError(client, "removeInterfaceFromNetwork() failed", ret);
1538             }
1539         } else {
1540             return syntaxError(client, "Unknown argument");
1541         }
1542         return success(client);
1543     }
1544
1545     //    0      1       2         3
1546     // network create <netId> [permission]
1547     //
1548     //    0      1       2     3     4        5
1549     // network create <netId> vpn <hasDns> <secure>
1550     if (!strcmp(argv[1], "create")) {
1551         if (argc < 3) {
1552             return syntaxError(client, "Missing argument");
1553         }
1554         unsigned netId = stringToNetId(argv[2]);
1555         if (argc == 6 && !strcmp(argv[3], "vpn")) {
1556             bool hasDns = atoi(argv[4]);
1557             bool secure = atoi(argv[5]);
1558             if (int ret = sNetCtrl->createVirtualNetwork(netId, hasDns, secure)) {
1559                 return operationError(client, "createVirtualNetwork() failed", ret);
1560             }
1561         } else if (argc > 4) {
1562             return syntaxError(client, "Unknown trailing argument(s)");
1563         } else {
1564             Permission permission = PERMISSION_NONE;
1565             if (argc == 4) {
1566                 permission = stringToPermission(argv[3]);
1567                 if (permission == PERMISSION_NONE) {
1568                     return syntaxError(client, "Unknown permission");
1569                 }
1570             }
1571             if (int ret = sNetCtrl->createPhysicalNetwork(netId, permission)) {
1572                 return operationError(client, "createPhysicalNetwork() failed", ret);
1573             }
1574         }
1575         return success(client);
1576     }
1577
1578     //    0       1       2
1579     // network destroy <netId>
1580     if (!strcmp(argv[1], "destroy")) {
1581         if (argc != 3) {
1582             return syntaxError(client, "Incorrect number of arguments");
1583         }
1584         unsigned netId = stringToNetId(argv[2]);
1585         if (int ret = sNetCtrl->destroyNetwork(netId)) {
1586             return operationError(client, "destroyNetwork() failed", ret);
1587         }
1588         return success(client);
1589     }
1590
1591     //    0       1      2      3
1592     // network default  set  <netId>
1593     // network default clear
1594     if (!strcmp(argv[1], "default")) {
1595         if (argc < 3) {
1596             return syntaxError(client, "Missing argument");
1597         }
1598         unsigned netId = NETID_UNSET;
1599         if (!strcmp(argv[2], "set")) {
1600             if (argc < 4) {
1601                 return syntaxError(client, "Missing netId");
1602             }
1603             netId = stringToNetId(argv[3]);
1604         } else if (strcmp(argv[2], "clear")) {
1605             return syntaxError(client, "Unknown argument");
1606         }
1607         if (int ret = sNetCtrl->setDefaultNetwork(netId)) {
1608             return operationError(client, "setDefaultNetwork() failed", ret);
1609         }
1610         return success(client);
1611     }
1612
1613     //    0        1         2      3        4          5
1614     // network permission   user   set  <permission>  <uid> ...
1615     // network permission   user  clear    <uid> ...
1616     // network permission network  set  <permission> <netId> ...
1617     // network permission network clear   <netId> ...
1618     if (!strcmp(argv[1], "permission")) {
1619         if (argc < 5) {
1620             return syntaxError(client, "Missing argument");
1621         }
1622         int nextArg = 4;
1623         Permission permission = PERMISSION_NONE;
1624         if (!strcmp(argv[3], "set")) {
1625             permission = stringToPermission(argv[4]);
1626             if (permission == PERMISSION_NONE) {
1627                 return syntaxError(client, "Unknown permission");
1628             }
1629             nextArg = 5;
1630         } else if (strcmp(argv[3], "clear")) {
1631             return syntaxError(client, "Unknown argument");
1632         }
1633         if (nextArg == argc) {
1634             return syntaxError(client, "Missing id");
1635         }
1636         std::vector<unsigned> ids;
1637         for (; nextArg < argc; ++nextArg) {
1638             char* endPtr;
1639             unsigned id = strtoul(argv[nextArg], &endPtr, 0);
1640             if (!*argv[nextArg] || *endPtr) {
1641                 return syntaxError(client, "Invalid id");
1642             }
1643             ids.push_back(id);
1644         }
1645         if (!strcmp(argv[2], "user")) {
1646             sNetCtrl->setPermissionForUsers(permission, ids);
1647         } else if (!strcmp(argv[2], "network")) {
1648             if (int ret = sNetCtrl->setPermissionForNetworks(permission, ids)) {
1649                 return operationError(client, "setPermissionForNetworks() failed", ret);
1650             }
1651         } else {
1652             return syntaxError(client, "Unknown argument");
1653         }
1654         return success(client);
1655     }
1656
1657     //    0      1     2       3           4
1658     // network users  add   <netId> [<uid>[-<uid>]] ...
1659     // network users remove <netId> [<uid>[-<uid>]] ...
1660     if (!strcmp(argv[1], "users")) {
1661         if (argc < 4) {
1662             return syntaxError(client, "Missing argument");
1663         }
1664         unsigned netId = stringToNetId(argv[3]);
1665         UidRanges uidRanges;
1666         if (!uidRanges.parseFrom(argc - 4, argv + 4)) {
1667             return syntaxError(client, "Invalid UIDs");
1668         }
1669         if (!strcmp(argv[2], "add")) {
1670             if (int ret = sNetCtrl->addUsersToNetwork(netId, uidRanges)) {
1671                 return operationError(client, "addUsersToNetwork() failed", ret);
1672             }
1673         } else if (!strcmp(argv[2], "remove")) {
1674             if (int ret = sNetCtrl->removeUsersFromNetwork(netId, uidRanges)) {
1675                 return operationError(client, "removeUsersFromNetwork() failed", ret);
1676             }
1677         } else {
1678             return syntaxError(client, "Unknown argument");
1679         }
1680         return success(client);
1681     }
1682
1683     //    0       1      2     3
1684     // network protect allow <uid> ...
1685     // network protect  deny <uid> ...
1686     if (!strcmp(argv[1], "protect")) {
1687         if (argc < 4) {
1688             return syntaxError(client, "Missing argument");
1689         }
1690         std::vector<uid_t> uids;
1691         for (int i = 3; i < argc; ++i) {
1692             uids.push_back(strtoul(argv[i], NULL, 0));
1693         }
1694         if (!strcmp(argv[2], "allow")) {
1695             sNetCtrl->allowProtect(uids);
1696         } else if (!strcmp(argv[2], "deny")) {
1697             sNetCtrl->denyProtect(uids);
1698         } else {
1699             return syntaxError(client, "Unknown argument");
1700         }
1701         return success(client);
1702     }
1703
1704     return syntaxError(client, "Unknown argument");
1705 }