• PSA: Android ADB/eBPF app internet blocking (without NetGuard)

    From Maria Sophia@mariasophia@comprehension.com to comp.mobile.android on Wed Sep 30 08:06:00 2026
    From Newsgroup: comp.mobile.android

    PSA: Android ADB/eBPF app internet blocking (without NetGuard)

    Given that the NetGuard VPN can interfere with wireless ADB
    debugging by affecting network routing and the local IP addresses
    usedfor the connection, it is useful to note that Muntashirakon App
    Manager's eBPF-based Internet blocking can avoid using the NetGuard
    VPN to block Internet access for an app.

    eBPF (Extended Berkeley Packet Filter) is an in-kernel mechanism
    that allows small, verified programs to be loaded into the Linux
    kernel and attached to kernel events, including networking hooks.

    Android began using eBPF-based network traffic monitoring in
    Android 9, replacing the older xt_qtaguid-based infrastructure on
    devices meeting the relevant requirements.

    eBPF itself is not an Android-specific "app Internet blocker."
    Android's networking stack can use eBPF programs and maps to
    identify and control network traffic associated with an app's UID.
    This allows network traffic to be filtered at the kernel/networking
    layer rather than by creating a user-space VPN.

    For example, on systems where these commands are supported:
    adb shell cmd connectivity set-chain3-enabled true
    adb shell cmd connectivity set-package-networking-enabled false com.example.app

    The first command enables the Chain 3 firewall mechanism, while the
    second disables networking for the specified package. This blocks
    the app's network access without requiring a VPN such as NetGuard.

    In App Manager v4.1.1, Muntashirakon specifically added the ability
    to block Internet access for individual applications using eBPF
    rules in root or ADB mode.

    You go to the app's "Uses permissions" tab and toggle android.permission.INTERNET. App Manager then applies the
    corresponding eBPF-based Internet-blocking rule.

    https://github.com/MuntashirAkon/AppManager/releases

    Note that Muntashirakon's implementation has a notable limitation:
    the eBPF rules are lost after a reboot. App Manager attempts to
    restore the rules after reboot. In ADB mode, however, reconnecting
    to wireless debugging can take some time depending on Wi-Fi
    availability, which can temporarily allow applications that start
    before the rules are restored to access the Internet.

    For a NetGuard + wireless ADB situation, the direct ADB/eBPF
    approach allows us to block the target app's network access without
    running a VPN at all. This avoids putting the target app's traffic
    through NetGuard's VPN while wireless ADB is being used.
    --
    On Usenet, we can pool our knowledge and skills so everyong learns more.
    --- Synchronet 3.22a-Linux NewsLink 1.2