Route IPv6 DNS servers through the VPN - #613
Merged
Merged
Conversation
This was referenced Jul 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
/128VPN host route for every accepted IPv6 DNS server/32routing behavior for local IPv4 DNS serversWhy
Follow-up to #604. That change correctly accepts IPv6 DNS on IPv6-only networks, but ULA resolvers (
fc00::/7) are outside TrackerControl's general2000::/3IPv6 route. Accepting one without a host route can leave DNS unreachable or outside TrackerControl's filtering path. Link-local resolvers have the same problem plus an interface-scope requirement that the VPN cannot carry.Impact
Global and ULA IPv6 DNS servers are explicitly captured by the VPN and remain subject to tracker filtering. Link-local resolvers fall through to the existing public DNS fallback instead of being advertised as unusable VPN DNS.
Validation
git diff --check./gradlew :app:compileGithubDebugJavaWithJavac(BUILD SUCCESSFUL)On-device validation on an IPv6-only cellular network with a ULA resolver remains recommended.