Skip to content

[BUG]: VPN may be bypassed even when upstream interface is set to tun0 #310

Description

@Glinte

Kernel Version

6.12.69-android16-Wild

Kernel Source Link (REQUIRED)

https://github.com/WildKernels/GKI_KernelSU_SUSFS/releases/download/r20/6.12.69-android16-2026-03-ReSukiSU-AnyKernel3.zip

Droidspaces Version

v6.5.5

Rooting Method

KernelSU (ReSukiSU)

Device OEM & Model

Google Pixel 11 Pro XL

Android Version & ROM

Android 17, stock ROM

Execution Mode

DAEMON

Networking Mode

NAT

Describe the Bug

My observation: on the host android with VPN enabled (NordVPN specifically), and with a container with upstream interface explicitly set to tun0, the internet traffic is still not routed through the VPN. I have verified the VPN is creating the interface at tun0.

It seems like my VPN is represented using split routes such as:

0.0.0.0/5 dev tun0
8.0.0.0/7 dev tun0
11.0.0.0/8 dev tun0
12.0.0.0/6 dev tun0
16.0.0.0/4 dev tun0
32.0.0.0/3 dev tun0
64.0.0.0/2 dev tun0
128.0.0.0/3 dev tun0
...
208.0.0.0/4 dev tun0

instead of a default dev tun0


AI: --upstream=tun0 assumes the selected interface's routing table contains an IPv4 0.0.0.0/0 route, but Android VpnService networks may represent a full-tunnel VPN using complementary/split prefixes rather than a literal default route.

You can also read my debugging session: https://chatgpt.com/share/6aa5f546-e3a0-83ec-883c-9cb4db32efa4, ChatGPT wrote a draft bug report that is a bit longer, and contains a suggested fix, but I have chosen to omit them here.

Steps to Reproduce

  1. Turn on NordVPN
  2. Open a container with --upstream=tun0
  3. Observe that the traffic isn't routed through the VPN

Logs / Screenshots

Droidspaces-bugreport_2026-09-13_01-08-05.tar.gz

Required Acknowledgments

  • I have verified this is not a duplicate issue.
  • I am using a kernel compiled strictly according to Droidspaces' official documentation.
  • I am NOT using a kernel with 69+ random configs, CRC nukes, or a broken ABI.
  • I have confirmed this issue persists in both Daemon and Direct modes.
  • I admit that I am a clown for checking this box, confirming I have NOT read these rules.
  • I admit I did zero research, didn't ask my AI waifu for a fix, and am dropping this here because I'm 100% sure the fault lies with Droidspaces.

Activity

  1. Glinte commented on Sep 13, 2026

    @Glinte
    Author

    Funny GitHub bug caused me to not be able to edit the issue body, but running ip rule add pref 6101 from 172.28.0.0/16 lookup tun0 as root makes the container traffic route to VPN properly.

  2. ravindu644 commented on Sep 13, 2026

    @ravindu644
    Owner

    Thanks. I'll look into this. Should be something that's introduced in newer Android versions :)

  3. ravindu644 commented on Sep 13, 2026

    @ravindu644
    Owner

    Anyway, can you run these commands inside a root shell with and without the VPN running while the droidspaces container is set to upstream tun0?

    ip rule show
    
    ip route show table all

    That means:

    1. Fire up the VPN and start the container.
    2. Run both commands one by one.
    3. Save the output from both commands to report1.txt.

    Then:

    1. Turn off the VPN while the container is running.
    2. Run both commands in a new root shell one by one.
    3. Save the output from both commands to report2.txt.

    Drop both txt files in here.

  4. Glinte commented on Sep 13, 2026

    @Glinte
    Author
  5. ravindu644 commented on Sep 19, 2026

    @ravindu644
    Owner
  6. Glinte commented on Sep 21, 2026

    @Glinte
    Author

    yes it is fixed for me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions