shared-tun: preserve member ownership on mobile

Introduce shared NIC source ownership and dispatcher handling so a
single dev_name can be shared by multiple tun-enabled instances while
keeping per-member IP and route claims distinct.

Pass Android VpnService fd registration with per-instance source and
route claims. Keep the VPN address list limited to real member
addresses and allow AF_INET6 without installing hidden fd00::1.

Invalidate dispatcher flow and NAT state when source ownership changes
or a member unregisters. Avoid rewriting non-first IPv4 fragment
payloads, and adjust fragmented TCP/UDP checksums without recomputing
over partial fragment bodies.

Preserve source-owner routing for equal-prefix route conflicts, keep
ICMP echo NAT entries distinct by echo id, and retry stale flow-owner
send failures from the original packet. Only record NAT state after a
translated packet is accepted by its member.

Apply Linux IPv4 route preferred-source hints for shared routes and keep
route repair paths source-aware. Keep Darwin ifcfg access scoped to
cleanup-only paths where netns is not available.
This commit is contained in:
sijie.sun
2026-06-16 00:15:35 +08:00
parent ca17e856a6
commit 800c840bb5
13 changed files with 2423 additions and 175 deletions
@@ -5,6 +5,7 @@ import android.net.VpnService
import android.os.Build
import android.os.ParcelFileDescriptor
import android.os.Bundle
import android.system.OsConstants.AF_INET6
import java.net.InetAddress
import java.util.Arrays
@@ -115,7 +116,7 @@ class TauriVpnService : VpnService() {
if (ipParts.size != 2) throw IllegalArgumentException("Invalid IP addr string")
builder.addAddress(ipParts[0], ipParts[1].toInt())
}
builder.addAddress("fd00::1", 128)
builder.allowFamily(AF_INET6)
builder.setMtu(mtu)
dns?.let { builder.addDnsServer(it) }