guardianproject / guardianproject/orbot-android

[BUG] On a GrapheneOS User Profile, Orbot fails SILENTLY, apps connect seamlessly over clearnet

Open
#1,187 8 comments 0 reactions 0 assignees View on GitHub
Bug GrapheneOS
Dominant language
Kotlin
Stars
3.5k
Forks
485
Avg merge
2d 14h
Merged PRs (30d)
24

Description

**Describe the Bug**
Orbot on new User Profile does not connect or provide VPN to any apps. (Graphene OS). Fails silently, despite onion icon visible. Apps connect in clearnet.

**To Reproduce**
1. Make new user profile on GrapheneOS install (note, no relevant settings have been knowingly altered in Owner)
2. Install Orbot from Google Play in Owner profile, push to new profile
3. Launch profile, review settings in Orbot but make no changes (I'm a noob) - Orbot declares it will provide VPN to all apps. Note onion icon in tray.
4. Separately, use Tor Browser with its own connection - works as expected.
5. Use apps, Infinity_for_reddit, Vanadium browser.
6. discover that Vanadium browser loads `whatismyisp.com` with correct, real ISP location
7. Freak out.
8. Review settings: selecting apps does nothing; connection is by bridges <-- thought I saw that somewhere, but cannot find it in settings now (very tired).
9. Tried different settings, (below), no success

**Expected Behavior**
If the app says its providing a VPN for all apps, it _should provide VPN_ for all apps.

**It should _NOT_ fail silently.**

If there are special config considerations, they should be announced in a first-run dialog/wizard, in-app.

If the app needs to be integrated into the operation of e.g. Android VPN settings, instructions should be provided in-app (VPN settings are not self-evident).

Consider also a 'fail-safe' mode, where apps fail to make connections without functional Tor connection.

EDIT II : Actually, failsafe is apparently already built in to Android. See instructions [here on Graphene OS forum](https://discuss.grapheneos.org/d/16480-struggling-to-get-orbot-to-work-failing-silently/4). For this issue, I just don't understand why it didn't work.

EDIT I: The onion icon is displayed in the tray _at all times_, regardless of connection status. This is deceptive. If you insist on having an icon at all times, consider an 'empty onion' to indicate lack of connectivity, or a 'strikethrough onion' for no VPN services, or something like that. It _has to indicate status_.

**What Custom Configuration Do You Use?**
Installation as above. Didn't understand the config options, so left them be for first couple of sessions.
Later, tried the options:
- `isolate destination addresses`
- selected apps to use VPN
- change exit
- refresh
but don't seem to have an effect

**Screenshots**
No screenshot, but log highlights (different device, retyped here) include:
- `Tor is no longer dormant`
- `No circuits are opened. Relaxed timeout for circuit 373... to 6000ms...`
- `Heartbeat: Tor's uptime is 6:00 hours, with 5 circuits open ... sent 3.29MB and received 2.43 MB`
- etc. There's not much, really.

Also the message:

Proxy Ports
HTTP:8118 - SOCKS: 9050

Orbot 17.3.2-RC-1-tor-0.4.8.12
Tor v0.4.8.12

**Smartphone (please complete the following information):**
Pixel 8a, GrapheneOS Android 14 (all updated)

**Crash Logs (Advanced)**
If applicable, add crash logs collected using ADB Logcat.

**Additional Context**
See additional steps in comments.

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file or test is named. Reproduce the user-profile and VPN setup on GrapheneOS, then inspect Orbot's connection and VPN status behavior against the supplied logs; done means apps cannot silently use clearnet when Orbot claims to provide VPN, and the tray indicator reflects actual status.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
mobile-dev, networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.