feat(android): 实现 M2 Android VPN 隧道 — PangolinVpnService 接入 libbox [tsk_w1NvZdmwGPyd]
接线 11B libbox.aar + 11C Dart 桥接骨架,完成 Android 端 M2 PoC:
### PangolinVpnService(完整实现)
- `handleStart(configJson)` → 后台线程 → `Libbox.newBoxService(platformInterface, json)` → `start()`
- 内 inner class `PangolinPlatformInterface` 实现 libbox `PlatformInterface`:
- `openTun(TunOptions)`: 调用 `VpnService.Builder()` 配置地址/MTU/路由,`establish()` 取 TUN fd
- `autoDetectInterfaceControl(fd)`: `VpnService.protect(fd)` 防环路
- 安全 getter 兜底:TunOptions 方法名与 libbox.aar 不符时降级到 PoC 默认值
- 统计双轨:优先 libbox `CommandClient`(status/traffic)→ 失败时退回 `TrafficStats` 定时器
- 幂等 `doStop()`:commandClient.disconnect → boxService.close → tunPfd.close → stopForeground
- `onRevoke()` 推 error 状态再 doStop,不留假 on
### VpnEventBus
- 新增 `currentStatus` 字段(volatile),供 `getStatus()` 一次性查询
### MainActivity
- `VpnService.prepare()` 权限流程:未授权 → 弹 prepare Intent → `onActivityResult` 后启动
- `getStatus()` 从 `VpnEventBus.currentStatus` 返回真实状态
- 首次连接时引导 `REQUEST_IGNORE_BATTERY_OPTIMIZATIONS`(后台存活)
### AndroidManifest.xml
- `android:foregroundServiceType="specialUse"`(Android 14 API 34 强制要求)
- 新增权限:`FOREGROUND_SERVICE_SPECIAL_USE`、`REQUEST_IGNORE_BATTERY_OPTIMIZATIONS`
### build.gradle
- `implementation files('../../../app/kernel/dist/android/libbox.aar')`(条件存在检查)
- `minSdkVersion` 提升至 21(gomobile -androidapi 21 要求)
### 新增文件
- `assets/poc_config.json`: PoC 单节点测试配置模板(含占位符 __NODE_HOST__ 等)
通知文案已过红线词扫描:「加速已开启」「正在连接…」「穿山甲加速」,无 VPN/翻墙等禁词。
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,11 +1,25 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
|
||||
|
||||
<!-- 网络权限(实际隧道流量) -->
|
||||
<!-- 网络权限(隧道流量) -->
|
||||
<uses-permission android:name="android.permission.INTERNET" />
|
||||
|
||||
<!-- 前台服务(VPN 持续运行所需,API 28+) -->
|
||||
<uses-permission android:name="android.permission.FOREGROUND_SERVICE" />
|
||||
|
||||
<!--
|
||||
Android 14 (API 34+) 要求前台服务必须声明类型。
|
||||
VPN 不属于任何预定义类型,故使用 specialUse。
|
||||
Play Store 上架时需在 specialUse 说明中填写 VPN 用途(国内合规绕过此字段)。
|
||||
-->
|
||||
<uses-permission android:name="android.permission.FOREGROUND_SERVICE_SPECIAL_USE" />
|
||||
|
||||
<!--
|
||||
允许应用请求豁免电池优化(后台 30 分钟不被杀必须)。
|
||||
不能在运行时动态请求,必须在 manifest 声明。
|
||||
-->
|
||||
<uses-permission android:name="android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS" />
|
||||
|
||||
<application
|
||||
android:label="穿山甲"
|
||||
android:name="${applicationName}"
|
||||
@@ -30,18 +44,27 @@
|
||||
</activity>
|
||||
|
||||
<!--
|
||||
VPN 服务(骨架)。
|
||||
VPN 服务。
|
||||
android:permission="android.permission.BIND_VPN_SERVICE" 确保只有系统可 bind。
|
||||
intent-filter android.net.VpnService 是 VpnService 规范要求。
|
||||
TODO(11E): 启用后在设备上需用户授权 VPN 权限(VpnService.prepare())。
|
||||
android:foregroundServiceType="specialUse" — Android 14 (API 34) 强制要求。
|
||||
-->
|
||||
<service
|
||||
android:name=".PangolinVpnService"
|
||||
android:exported="false"
|
||||
android:permission="android.permission.BIND_VPN_SERVICE">
|
||||
android:permission="android.permission.BIND_VPN_SERVICE"
|
||||
android:foregroundServiceType="specialUse">
|
||||
<intent-filter>
|
||||
<action android:name="android.net.VpnService" />
|
||||
</intent-filter>
|
||||
|
||||
<!--
|
||||
Android 14 specialUse 前台服务类型需在此声明用途说明。
|
||||
若目标 API < 34 可忽略此 meta-data;保留不影响低版本兼容性。
|
||||
-->
|
||||
<property
|
||||
android:name="android.app.PROPERTY_SPECIAL_USE_FGS_SUBTYPE"
|
||||
android:value="vpn" />
|
||||
</service>
|
||||
|
||||
<meta-data
|
||||
|
||||
Reference in New Issue
Block a user