Skip to content

fix(runtime): keep live NE manager after wedged preference load - #103

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-ef4d
Draft

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-ef4d

Conversation

@cursor

@cursor cursor Bot commented Oct 4, 2026

Copy link
Copy Markdown

Bug and impact

When System Extension capture is already connected, a live apply can hit a wedged loadAllFromPreferences (nehelper never callbacks). #99 recovered by constructing a fresh NETransparentProxyManager and assigning it to self.manager.

stop() only drives the actor-owned manager. After that replacement, fallback teardown (HostBridge live-update failure → stop(dropWedgedConfiguration:) ) targets a disconnected preference and never calls stopVPNTunnel() on the running session. The old tunnel can keep capturing (failOpen: true leak) or leave NEDNSProxy intercepting after the SOCKS/DNS backend is gone (resolver blackhole).

Root cause

The wedged-enumeration recovery treated “create a new manager object” as equivalent to owning the live tunnel. Preference I/O and the in-memory session are not the same object after a timeout.

Fix

  • If an owned manager already exists, keep it when enumeration times out or returns nothing.
  • Only create a fresh manager when nothing is already owned (first enable / after reset).

Validation

  • Reviewed configure → configureAndApplyRunning → HostBridge fallback stop() ownership.
  • git diff --check
  • Swift Network Extension build is not available in this Linux environment.
Open in Web View Automation 

Replacing the owned transparent-proxy manager when loadAllFromPreferences times out made stop() target a disconnected preference and left the running tunnel/DNS session up after a failed live update.

Co-authored-by: redial.solute_1r <redial.solute_1r@icloud.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant