It took me a while to figure out why many of my self-hosted services were intermittently failing to connect on my phone after updating to Android 17. I eventually figured out there’s a new ACCESS_LOCAL_NETWORK permission which means the “Nearby devices” permission is now required to access devices on the same network subnet. For an avid self-hoster, this can be quite a bit.

I had my DNS configured so my public-facing server resolved to a local IP address when on my LAN. This meant that my web, immich, xmpp, NTP, jellyfin and DoH servers all resolved to a local IP address on wifi. On Android 17, it all broke without warning. No error messages. No asking for extra permissions. Just silent packet dropping.

I’ve solved it by configuring my public-facing services to resolve to my external (static) IP address, even when inside the network. I couldn’t make any internal services resolve to the external address (SMB, CUPS etc) because they are (obviously) not bound to my WAN interface.

I get why the change was made. A lot of apps were snooping around people’s networks to gather intel. A potentially massive privacy violation.

Has anyone else had this issue? Is this the cleanest solution?

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    18 hours ago

    Do you have any network segmentation is all your stuff on the same lan?

    You also could try IPv6 public or private addresses

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 hours ago

      I’ve been on IPv6 years before Google turned it on. My ISP gave me a /48 and I’ve got different subnets for my WAN, LAN and guest LAN. I have a 4-port NIC so I could put a different subnet on each port.

      I didn’t mention it in my first post, but I only made AAAA DNS entries for my internal stuff. I just enable IPv4 for the few services that actually need it.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 hours ago

        Ah, that makes sense

        Side note: you don’t need multiple ports to have multiple subnets. (You can just use vlans)