From Newsgroup: comp.mobile.android
PSA: Android ADB/eBPF app internet blocking (without NetGuard)
Given that the NetGuard VPN can interfere with wireless ADB
debugging by affecting network routing and the local IP addresses
usedfor the connection, it is useful to note that Muntashirakon App
Manager's eBPF-based Internet blocking can avoid using the NetGuard
VPN to block Internet access for an app.
eBPF (Extended Berkeley Packet Filter) is an in-kernel mechanism
that allows small, verified programs to be loaded into the Linux
kernel and attached to kernel events, including networking hooks.
Android began using eBPF-based network traffic monitoring in
Android 9, replacing the older xt_qtaguid-based infrastructure on
devices meeting the relevant requirements.
eBPF itself is not an Android-specific "app Internet blocker."
Android's networking stack can use eBPF programs and maps to
identify and control network traffic associated with an app's UID.
This allows network traffic to be filtered at the kernel/networking
layer rather than by creating a user-space VPN.
For example, on systems where these commands are supported:
adb shell cmd connectivity set-chain3-enabled true
adb shell cmd connectivity set-package-networking-enabled false com.example.app
The first command enables the Chain 3 firewall mechanism, while the
second disables networking for the specified package. This blocks
the app's network access without requiring a VPN such as NetGuard.
In App Manager v4.1.1, Muntashirakon specifically added the ability
to block Internet access for individual applications using eBPF
rules in root or ADB mode.
You go to the app's "Uses permissions" tab and toggle android.permission.INTERNET. App Manager then applies the
corresponding eBPF-based Internet-blocking rule.
https://github.com/MuntashirAkon/AppManager/releases
Note that Muntashirakon's implementation has a notable limitation:
the eBPF rules are lost after a reboot. App Manager attempts to
restore the rules after reboot. In ADB mode, however, reconnecting
to wireless debugging can take some time depending on Wi-Fi
availability, which can temporarily allow applications that start
before the rules are restored to access the Internet.
For a NetGuard + wireless ADB situation, the direct ADB/eBPF
approach allows us to block the target app's network access without
running a VPN at all. This avoids putting the target app's traffic
through NetGuard's VPN while wireless ADB is being used.
--
On Usenet, we can pool our knowledge and skills so everyong learns more.
--- Synchronet 3.22a-Linux NewsLink 1.2