Skip to content

fix(vpn): restrict VpnService TUN interface to app package to prevent car-wide internet loss - #37

Open
yanwuu wants to merge 1 commit into
shilapi:masterfrom
yanwuu:fix/vpn-isolate-tun-interface
Open

yanwuu wants to merge 1 commit into
shilapi:masterfrom
yanwuu:fix/vpn-isolate-tun-interface

Conversation

@yanwuu

@yanwuu yanwuu commented Oct 8, 2026

Copy link
Copy Markdown

Summary

Fix an issue where wired CarPlay's VpnService TUN interface captures all system and third-party traffic on certain Android head units, causing system-wide network disconnection.

Problem

In wired CarPlay mode, an IPv6 NCM tunnel is established via Android's VpnService. When initializing VpnService.Builder(), if no application allowlist is configured, Android defaults to routing all UID network traffic through this TUN interface.

On many Android car head-unit ROMs, this results in:

  • Native car navigation (AutoNavi/Baidu Maps) losing GPS network traffic and real-time updates.
  • Native music/radio apps losing connectivity.
  • System OTA, weather, and telematics services going completely offline.

Solution

  • Call .addAllowedApplication(packageName) on VpnService.Builder() prior to .establish().
  • Explicitly scope the virtual network adapter only to xcertplay itself, ensuring all other system and third-party applications continue to use the vehicle's standard cellular/Wi-Fi connection normally.
  • If package scoping fails (e.g. permission or security exception), the existing error handling cleans up the attachment state cleanly without falling back to an unconstrained car-wide tunnel.

Verification

  • Preserves existing link-local IPv6 addressing, MTU, routing, and wireless hotspot behavior.
  • Zero new permissions, external dependencies, or breaking API changes.

中文说明

问题背景:
在有线 CarPlay 模式下,底层通过 Android VpnService 虚拟网卡桥接 NCM IPv6 链路。原先在构建 VpnService.Builder() 时未指定应用白名单,导致部分车机系统的全部网络流量(包括原车高德、在线音乐、系统网络服务)被默认路由至该 TUN 网卡中,造成车机系统级断网。

解决方案:
在 Builder().establish() 之前增加 .addAllowedApplication(packageName),将该 TUN 虚拟网卡严格限制在 xcertplay 自身进程内,车机上其他所有应用的流量继续走原生蜂窝/Wi-Fi 网络,彻底解决断网问题。

… car-wide internet loss

The wired IPv6/NCM VPN currently applies to every app UID on Android unless an application allowlist is configured. On some head-unit systems, this causes all system and third-party traffic (navigation, streaming, system services) to be erroneously routed into the CarPlay TUN interface, resulting in head-unit internet loss.

Restrict the tunnel to xcertplay's runtime package before establishment via `addAllowedApplication(packageName)`. If allowlisting fails or permission is revoked, the existing attachment transaction returns failure and releases its resources cleanly without opening an unrestricted tunnel.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant