Repository navigation
Conversation
… car-wide internet loss The wired IPv6/NCM VPN currently applies to every app UID on Android unless an application allowlist is configured. On some head-unit systems, this causes all system and third-party traffic (navigation, streaming, system services) to be erroneously routed into the CarPlay TUN interface, resulting in head-unit internet loss. Restrict the tunnel to xcertplay's runtime package before establishment via `addAllowedApplication(packageName)`. If allowlisting fails or permission is revoked, the existing attachment transaction returns failure and releases its resources cleanly without opening an unrestricted tunnel.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix an issue where wired CarPlay's
VpnServiceTUN interface captures all system and third-party traffic on certain Android head units, causing system-wide network disconnection.Problem
In wired CarPlay mode, an IPv6 NCM tunnel is established via Android's
VpnService. When initializingVpnService.Builder(), if no application allowlist is configured, Android defaults to routing all UID network traffic through this TUN interface.On many Android car head-unit ROMs, this results in:
Solution
.addAllowedApplication(packageName)onVpnService.Builder()prior to.establish().xcertplayitself, ensuring all other system and third-party applications continue to use the vehicle's standard cellular/Wi-Fi connection normally.Verification
中文说明
问题背景:
在有线 CarPlay 模式下,底层通过 Android
VpnService虚拟网卡桥接 NCM IPv6 链路。原先在构建VpnService.Builder()时未指定应用白名单,导致部分车机系统的全部网络流量(包括原车高德、在线音乐、系统网络服务)被默认路由至该 TUN 网卡中,造成车机系统级断网。解决方案:
在
Builder().establish()之前增加.addAllowedApplication(packageName),将该 TUN 虚拟网卡严格限制在xcertplay自身进程内,车机上其他所有应用的流量继续走原生蜂窝/Wi-Fi 网络,彻底解决断网问题。