You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: split tunneling routing and silent SSH disconnect detection
Three related fixes for the split tunneling mode:
1. Added own package (com.example.sshproxy) to VPN allowlist when split
tunneling is enabled. Without this, the app's IP checker and health
checks bypassed the tunnel entirely, showing the real IP.
2. Applied VPN-protected socket factory to SSH client via reflection.
When the app package is in the allowlist, its SSH socket would route
through the VPN → proxy → SSH creating an infinite loop. protect()
is called on each socket before connecting to bypass the tunnel.
3. Improved SSH health check to test the actual proxy port (127.0.0.1:httpProxyPort)
instead of relying on sshj's isConnected/isAuthenticated state. sshj
returns true even after the TCP session silently drops (server timeout,
NAT expiry), so the health monitor never triggered reconnection.
Investigated user reports of tunneled apps losing internet when switching
between apps in the foreground, and own IP checker showing real IP.
Reviewed sshj internals, VpnService allowlist semantics, and health
monitor reconnection flow. Spent ~1.5h tracing the root causes.
Context: bugs reported by user after v1.3 split tunneling release.
Tested by building APK; logic verified by code review of routing path.