guardianproject / guardianproject/orbot-android
[BUG] On a GrapheneOS User Profile, Orbot fails SILENTLY, apps connect seamlessly over clearnet
- Dominant language
- Kotlin
- Stars
- 3.5k
- Forks
- 485
- Avg merge
- 2d 14h
- Merged PRs (30d)
- 24
Description
**Describe the Bug**
Orbot on new User Profile does not connect or provide VPN to any apps. (Graphene OS). Fails silently, despite onion icon visible. Apps connect in clearnet.
**To Reproduce**
1. Make new user profile on GrapheneOS install (note, no relevant settings have been knowingly altered in Owner)
2. Install Orbot from Google Play in Owner profile, push to new profile
3. Launch profile, review settings in Orbot but make no changes (I'm a noob) - Orbot declares it will provide VPN to all apps. Note onion icon in tray.
4. Separately, use Tor Browser with its own connection - works as expected.
5. Use apps, Infinity_for_reddit, Vanadium browser.
6. discover that Vanadium browser loads `whatismyisp.com` with correct, real ISP location
7. Freak out.
8. Review settings: selecting apps does nothing; connection is by bridges <-- thought I saw that somewhere, but cannot find it in settings now (very tired).
9. Tried different settings, (below), no success
**Expected Behavior**
If the app says its providing a VPN for all apps, it _should provide VPN_ for all apps.
**It should _NOT_ fail silently.**
If there are special config considerations, they should be announced in a first-run dialog/wizard, in-app.
If the app needs to be integrated into the operation of e.g. Android VPN settings, instructions should be provided in-app (VPN settings are not self-evident).
Consider also a 'fail-safe' mode, where apps fail to make connections without functional Tor connection.
EDIT II : Actually, failsafe is apparently already built in to Android. See instructions [here on Graphene OS forum](https://discuss.grapheneos.org/d/16480-struggling-to-get-orbot-to-work-failing-silently/4). For this issue, I just don't understand why it didn't work.
EDIT I: The onion icon is displayed in the tray _at all times_, regardless of connection status. This is deceptive. If you insist on having an icon at all times, consider an 'empty onion' to indicate lack of connectivity, or a 'strikethrough onion' for no VPN services, or something like that. It _has to indicate status_.
**What Custom Configuration Do You Use?**
Installation as above. Didn't understand the config options, so left them be for first couple of sessions.
Later, tried the options:
- `isolate destination addresses`
- selected apps to use VPN
- change exit
- refresh
but don't seem to have an effect
**Screenshots**
No screenshot, but log highlights (different device, retyped here) include:
- `Tor is no longer dormant`
- `No circuits are opened. Relaxed timeout for circuit 373... to 6000ms...`
- `Heartbeat: Tor's uptime is 6:00 hours, with 5 circuits open ... sent 3.29MB and received 2.43 MB`
- etc. There's not much, really.
Also the message:
Proxy Ports
HTTP:8118 - SOCKS: 9050
Orbot 17.3.2-RC-1-tor-0.4.8.12
Tor v0.4.8.12
**Smartphone (please complete the following information):**
Pixel 8a, GrapheneOS Android 14 (all updated)
**Crash Logs (Advanced)**
If applicable, add crash logs collected using ADB Logcat.
**Additional Context**
See additional steps in comments.
Contributor guide
No contributing guide indexed for this repository
Research direction
No source file or test is named. Reproduce the user-profile and VPN setup on GrapheneOS, then inspect Orbot's connection and VPN status behavior against the supplied logs; done means apps cannot silently use clearnet when Orbot claims to provide VPN, and the tray indicator reflects actual status.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, kotlin
- Domain
- mobile-dev, networking, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100