RKNHardering Help

Complete Matrix of Checks and Countermeasures

This page is a completeness check for the current RKNHardering 2.10.0 source tree. It does not replace the topic-specific explanations. The “without root” and “with root” columns describe changes to the observable state, not a guaranteed pass. External projects may cover only part of a row on a particular kernel or ROM. Specific downloads and step-by-step installation are collected on the VPNHide, VPNHide Next, and root stack page, while primary references are listed under sources.

1. All EvidenceSource values — 65

ID Area What the source reports Without root With root Limitation
GEO_IP Server path Country, ASN/ISP, hosting/datacenter, and proxy/VPN indicators for the public IP. Choose a consistent egress in the required country and network type; an external router does not change GeoIP by itself. Root cannot correct remote databases; change the route or exit. GeoIP databases disagree and lag; one clean provider does not guarantee the final verdict.
DIRECT_NETWORK_CAPABILITIES Framework TRANSPORT_VPN, IS_VPN, and VpnTransportInfo for the active network. This generally cannot be hidden locally; remove VpnService from the phone by using an external gateway. Run VPNHide or VPNHide Next in system_server with only System Framework in scope. A native backend without the framework layer does not change the Binder model.
INDIRECT_NETWORK_CAPABILITIES Framework Missing NOT_VPN, inconsistent capabilities, and an indirect VPN model. Use an external gateway; per-app bypass can leave a contradiction. Filter NetworkCapabilities and related Parcel data at the system level. The active network, capabilities, callbacks, and LinkProperties must agree.
ICMP_SPOOFING Server path ICMP replies from addresses or domains the operator is expected to block, including possible substitution. Do not falsify this locally; test on the actual operator network and repeat the run. Root is normally unnecessary; a firewall can distort the result and create a false signal. ICMP behavior depends on the operator, NAT, and rate limits; this is more often a review signal.
RTT_TRIANGULATION Server path Latency comparison between Russian and foreign hosts (SNITCH β or diagnostics). Use a real, consistent route; do not treat a single RTT sample as proof. Root cannot remove physical latency; local delay injection is unreliable. Mobile networks, congestion, and Wi-Fi introduce substantial noise.
SYSTEM_PROXY Proxy Java properties, Proxy, default and per-network proxy state, PAC, exclusions, and validity. Disable the system proxy or PAC; use a TUN or an external gateway instead. A system hook is possible, but removing the proxy is preferable; VPNHide Zygisk can filter some properties. Applications may ignore the proxy, but its presence remains a separate signal.
INSTALLED_APP Packages Known VPN or proxy packages and name heuristics. Do not install the client in the same profile; use an external router or a separate profile. Use VPNHide Apps or PackageManager filtering for the observer UID. Package visibility depends on Android, the OEM, and permissions; installation does not prove activity.
VPN_SERVICE_DECLARATION Packages Services declaring the android.net.VpnService intent. Keep the VPN client outside the target profile or on another device. Filter PackageManager query, resolve, and direct-lookup paths. System or privileged callers and self-lookups must continue to work.
ACTIVE_VPN Framework An active VPN network reported by Android connectivity APIs. Remove the local VpnService or accept that it is visible. Filter the active network and network list in system_server. Native TUN and route indicators must be closed at the same time.
LOCAL_PROXY Localhost SOCKS5 or HTTP CONNECT on loopback and comparison of proxy and direct IP addresses. Disable the listener or API; do not rely on changing the port. Use a UID firewall, portshide, or kernel security_socket_connect filtering. A timeout and a refused connection are different; the shell UID is not equivalent to the application UID.
XRAY_API Localhost The Xray gRPC control API and its outbound list. Disable the API or listener, or move the control plane off the phone. Block loopback for the target UID; a secret does not conceal the port itself. A full scan can discover the service on a different port.
CLASH_API Localhost Clash, Mihomo, or sing-box REST endpoints such as /configs, /connections, and /proxies. Disable the controller, use a Unix socket, or place it in an inaccessible namespace. Use a UID firewall, portshide, or a kernel block. A strong secret protects control operations, not the existence of the listener or protocol.
SPLIT_TUNNEL_BYPASS Bypass An explicit direct path for the application while a VPN or TUN exists. Per-app direct routing fixes the egress but remains detectable; the best non-root option is an external gateway. Conceal the local TUN and Binder model and make the direct egress consistent. When the server IP and local model contradict each other, the bypass remains strong evidence.
PROXY_AUTH_BYPASS Localhost Weak or absent authentication on a local SOCKS or HTTP proxy. Use strong authentication and disable any unnecessary listener. Block the target UID even when authentication is enabled. The scanner may identify the proxy before checking credentials.
NETWORK_INTERFACE Interfaces Java NetworkInterface, tun, wg, ppp, or ipsec names, and MTU. Use an external gateway; renaming an interface or changing MTU does not close the other channels. Use a kernel backend; the framework layer alone is insufficient. Raw netlink, ioctl, and the interface type must be consistent.
ROUTING Routes LinkProperties, /proc/net/route, default and split routes, and policy routing. Use an external gateway; a local split route remains visible. Combine kernel route and netlink filtering with LinkProperties filtering in system_server. Single lookup, host-route, and backend-parity coverage vary by backend.
DNS DNS Loopback, private, or replaced DNS and differences between VPN and direct resolution. Make DNS follow the HTTP and UDP outbound and remove the system proxy. Root does not replace correct routing; the framework can hide DNS in LinkProperties, but server-side DNS remains. DoH, DoT, and IPv6 can take a different path.
PROXY_TECHNICAL_SIGNAL Proxy Known ports, multiple high ports, and proc socket artifacts. Disable the daemon and listeners or use an external gateway. Block loopback for the UID and filter proc or socket views when necessary. Closing a control port does not remove the VPN interface itself.
DUMPSYS Framework dumpsys vpn_management and active VpnService instances when accessible. Access is often restricted on stock systems; a local application cannot conceal a system service. Harden the system or framework and do not grant shell, Shizuku, or privileged access to the target. ROM and privilege level determine access; denial does not prove that no VPN exists.
LOCATION_SIGNALS Location MCC/MNC, SIM, cell, Wi-Fi or BeaconDB, and Russia versus non-Russia context. Use a real, consistent location and egress; do not base the strategy on fake GPS. Root-level substitution is risky and creates inconsistencies; a correct egress is preferable. Missing permissions or data usually lowers confidence but does not clear other channels.
HOME_ROUTED_ROAMING Location Legitimate roaming in which the visited network exits through the home country. Preserve this context and ensure the SIM and roaming state explains the foreign egress. Root is not required. The context reduces false conclusions but does not conceal a VPN automatically.
VPN_GATEWAY_LEAK Bypass Discovery of a VPN gateway or underlying path that exposes a separate network. Remove ambiguous multipath behavior or use an external gateway. Conceal local routes and socket identity and make routing consistent. The actual gateway may remain observable from the server side.
VPN_NETWORK_BINDING Bypass Binding a socket to the VPN or underlying Network produces a different path or IP. Do not leave an allowed bypass, or make both paths consistent. Framework or native concealment does not change the real bind; correct the policy or route. Internal and external observations must agree.
TUN_ACTIVE_PROBE Bypass A TUN exists while the application does not consider the active network a VPN, with DNS or path mismatch. Do not use local per-app bypass as the only measure; use an external router. Combine kernel and framework concealment with a consistent direct or in-tunnel path. The probe is designed to catch split tunneling combined with a local TUN.
TELEGRAM_CALL_TRANSPORT UDP and calls Telegram, MTProto, or UDP transport probes and a possible leak. Make UDP follow the intended route; do not block it without understanding the effect on calls. A root firewall can route or block it, but may break the service. Often experimental or review-only; repeat the test.
WHATSAPP_CALL_TRANSPORT UDP and calls WhatsApp STUN or UDP path and a possible separate egress. Make UDP consistent and verify fallback behavior. Use root firewall or routing changes only deliberately. Blocking the response is not always a clean result.
STUN_PROBE UDP and calls The mapped address reported by Russian and global STUN servers. UDP must follow the selected outbound; use an external gateway where appropriate. Root does not alter a server-reported mapped IP; change routing or NAT. NAT, IPv6, and blocking produce different states.
NATIVE_INTERFACE Native Native interface names, types, and addresses. Use an external gateway. Prefer a kernel backend; use Zygisk only as a fallback. Raw syscalls bypass userspace hooks.
NATIVE_ROUTE Native Native route dumps, policy state, and proc routes. Use an external gateway. Use a kernel backend. Verify IPv4 and IPv6, dump and single-lookup behavior, and interface indices.
NATIVE_HOST_ROUTE Native A public /32 or /128 host route to the VPN server through a physical interface. This is normally absent with VpnService; when present, change VPN routing. Upstream kernel backends claim route-shape filtering. A server route through a physical interface is not concealed by a simple name filter.
NATIVE_SOCKET Native Socket addresses, bind-to-device state, UDP port conflicts, MSS, PMTU, and related socket indicators. Use an external gateway or normalize the client where possible. Use a kernel backend or VPNHide Next Medium or Max for the specific signal. Some signals are heuristic and kernel-dependent.
NATIVE_HOOK_MARKERS Integrity maps, hook libraries, RWX memory, and known markers. Do not repackage or inject the target. Use a kernel plus system_server architecture and remove the target from Xposed or Zygisk scope. Renaming a module does not remove structural artifacts.
NATIVE_JVM_MISMATCH Integrity Java and native APIs report different interfaces or routes. Avoid partial hooks; use an external gateway. Enable matching framework and kernel layers from the same release and verify the UID. Partial concealment is worse than no concealment.
NATIVE_LIBRARY_INTEGRITY Integrity dlsym, ELF, linker, and library integrity. Do not repackage or use rootless injection. Do not inject the target; use a kernel backend. Zygisk or inline hooks may remain visible.
NATIVE_ROOT_DETECTION Root su, /data/adb, properties, mounts, SELinux, and UID 0. Use a stock device without root. Do not grant root; use unmount or deny behavior, enforcing SELinux, read-only system partitions, and a minimal stack. Undetectable root is not guaranteed.
NATIVE_EMULATOR Device QEMU, Goldfish, BlueStacks, and build indicators. Use a physical device. Root-based spoofing does not make an emulator physical and is not recommended. Hardware and driver inconsistencies remain.
SANDBOX_ISOLATION Profile Secondary-user, work-profile, clone, and profile identity. Run under the owner user; a profile is not concealment. Do not break UserManager; only target the correct full UID. The truthful isolation signal remains.
BETA_VPN_BINDER β Framework A hidden Binder probe of the VPN service or state. Use an external gateway. Filter in system_server and verify with repeated runs. One of two β hard-authority paths when repeated results are stable.
BETA_USER_PROFILE β Profile User, profile, and foreground-user context. Use the owner user. Do not conceal this globally; target the correct UID. A profile combined with a network discrepancy can form a quorum.
BETA_CONNECTIVITY_BINDER β Framework Binder connectivity state compared with the public API. Use an external gateway. The system_server hook must remain internally consistent. A partial Java hook appears as a mismatch.
BETA_NETD_NETID β Kernel netd, network ID, and extended rtnetlink context. Use an external gateway. Apply kernel and system filtering; VPNHide Next claims broader coverage. Backend parity depends on the ROM and kernel.
BETA_SOCKET_MARK β Socket Socket mark, network ID, and identity. Use an external gateway or one consistent path. Apply kernel-level socket filtering or correct route policy. A userspace hook may not observe raw socket metadata.
BETA_SOCKET_DIAG β Socket INET_DIAG cookie and socket identity. Use an external gateway. Filter in the kernel; do not weaken SELinux merely to hide the result. Denial is neutral; access depends on the kernel.
BETA_WIREGUARD_GENL β Kernel VPN The WireGuard generic-netlink control plane. Do not run kernel WireGuard on the phone; use an external gateway. Filter or conceal it with a compatible kernel backend. This privileged probe is opt-in; denial is neutral.
BETA_OVPN_GENL β Kernel VPN OpenVPN DCO or generic-netlink state. Use an external gateway or avoid local DCO. Filter in the kernel. The privileged probe is opt-in.
BETA_XFRM β IPsec XFRM states and policies. Use an external gateway or avoid local IPsec. Filter in the kernel. IPsec can be legitimate in an enterprise context.
BETA_UNIX_DIAG β Localhost Unix sockets and peer identity for the local control plane. Disable or move the daemon off the device. Filter by namespace or UID. Hiding a TCP port does not close a Unix socket.
BETA_BPF_NETFILTER β Policy BPF, netd, cgroup, netfilter, and original-destination state. Use an external gateway and minimize local redirection. Apply kernel-level policy concealment; Next Max claims BPF coverage. Portability across kernels is difficult; this is usually a review signal.
BETA_NAMESPACE β Integrity Mount and network namespace identity. Do not use virtualization or profile wrappers. Use a correct unmount namespace without breaking system namespaces. The root manager itself can create namespace differences.
BETA_SANDBOX_IDENTITY β Integrity Process, filesystem, and fscrypt identity of virtualization. Use the original APK in an ordinary owner-user sandbox. Do not repackage or run through a virtual container. Root does not turn a virtualized APK into an ordinary one.
BETA_HOOK_CONSISTENCY β Integrity Direct syscalls, io_uring, file descriptors, and linker consistency. Do not inject or repackage the process. Use a kernel backend and keep the target outside Zygisk and Xposed. Alternate paths reveal a partial hook.
BETA_TUN_FD β Kernel VPN A kernel query on a TUN file descriptor. Remove the local VpnService or use an external gateway. Filter in the kernel and verify the exact backend. The second β hard-authority path when repeated results are stable.
BETA_DNS_NETID β DNS DNS network ID and native resolver path. Make DNS and egress consistent. Framework or kernel concealment does not replace correct DNS routing. DoH and the native resolver can diverge.
BETA_ROUTE_LOOKUP β Route A single route lookup to selected targets. Use an external gateway. Use a kernel backend and account for the upstream single-lookup gap. A clean route dump does not guarantee a clean single lookup.
BETA_POLICY_RULE β Route Policy rules by UID and network ID. Use an external gateway. Use a kernel backend with RTM_GETRULE coverage. ROM and netd can create complex legitimate rules.
BETA_RTNL_ADDRESS β Interface An RTNL address dump. Use an external gateway. Apply kernel netlink filtering. Both IPv4 and IPv6 must be covered.
BETA_LINK_DRIVER β Interface Interface driver, kind, and details. Use an external gateway. Filter in the kernel; Next claims sysfs and driver coverage. Renaming an interface does not change its driver or kind.
BETA_INTERFACE_TRAFFIC β Path Traffic counters showing the active egress. Use an external gateway or one consistent route. Next Max claims BPF and statistics concealment. Counters and timing must remain consistent.
BETA_PROXY_SELECTOR β Proxy Java ProxySelector and the system proxy model. Disable the proxy or PAC. Use a system hook only when necessary; removing the setting is preferable. Application and native paths can disagree.
BETA_TRANSPORT_MATRIX β Server An HTTP, DNS, and UDP transport matrix against canary endpoints. Make every protocol follow the intended path. Root does not alter server observation; change the route. The network and epoch must remain stable.
BETA_TLS_INTERCEPTION β TLS Certificate and handshake indicators of TLS interception. Do not install a MITM CA or proxy for the target; use direct TLS. Exclude the target from MITM and remove injected trust or hooks. An enterprise CA can be legitimate; this is usually a review signal.
BETA_PKTINFO β Socket IP_PKTINFO, IPv6 packet info, and incoming-interface identity. Use an external gateway. Apply kernel socket filtering. The result must agree with the route and interface model.
BETA_NETWORK_TRANSITION β Timeline Netlink transitions and the temporal sequence of networks. Do not run the test during a handover; use an external gateway. System and kernel filtering must be atomic. Policy suppresses races, but repetition remains important.
BETA_TRACEROUTE β Path Traceroute and path observation. Use a real, consistent route. A root firewall can only restrict the probe; the server-side path remains. Usually system context, not hard VPN evidence.
BETA_SERVER_FINGERPRINT β Server Canary or server fingerprint of the active path. Select the expected egress. Root cannot correct a server fingerprint. System-network context alone is excluded from the β hard quorum.

2. All NativeSignalId values — 85

Each row links to an existing article in the native reference, where the signal interpretation is explained. This table adds the practical inverse path.

ID What is checked Without root With root What may remain
NATIVE_LIBRARY Loading and availability of the native check library. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
INTERFACE_ENUMERATION Interface enumeration through native APIs. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
TUNTAP_TYPE The TUN or TAP interface type, such as ARPHRD_NONE or 65534, rather than only its name. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
IPSEC_INTERFACE IPsec, XFRM, or VTI interfaces and their related names and types. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
JVM_NATIVE_MISMATCH The Java and native views of the network do not agree. Use an external gateway or avoid partial hooks. Enable matching framework and kernel layers from the same release and keep the target outside injection scope. Any uncovered channel recreates the mismatch.
ROUTE_TABLE The native routing table and VPN routes. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
HOST_ROUTE A public /32 or /128 host route to the VPN server. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
HOOK_MARKERS Known hook or injection libraries and markers inside the process. Do not repackage the APK or inject rootless or Xposed hooks. Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. Process-local Zygisk and third-party concealment modules may remain visible.
RWX_MEMORY_REGIONS Memory regions that are both writable and executable. Do not repackage the APK or inject rootless or Xposed hooks. Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. Process-local Zygisk and third-party concealment modules may remain visible.
LIBRARY_INTEGRITY Integrity of libc, the linker, symbols, and dlsym paths. Do not repackage the APK or inject rootless or Xposed hooks. Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. Process-local Zygisk and third-party concealment modules may remain visible.
ROOT_INDICATORS Aggregate root signal. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_SU_BINARY An accessible su binary at a common path. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_PROPERTY Unsafe root or debug system properties. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_MANAGEMENT Magisk, KernelSU, APatch, and module directories or files. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_SYSTEM_RW Writable system partitions. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_SUSPICIOUS_MOUNT Unusual bind or magic mounts. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_OVERLAY_MOUNT OverlayFS or overlay mounts typical of module systems. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_SELINUX SELinux in permissive or disabled state, or an inconsistent state. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_UID The process or helper obtained UID or GID 0. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
ROOT_MAGISK_PROPERTY Magisk service or configuration properties. A stock non-root system is the only reliable non-root baseline. Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. Individual kernel, property, or mount artifacts may remain; there is no guarantee.
EMULATOR_INDICATORS Aggregate emulator signal. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_QEMU_PROPERTY QEMU or system properties. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_QEMU_PIPE QEMU pipes or devices. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_GOLDFISH Goldfish or Ranchu artifacts. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_QEMU_DRIVER QEMU drivers or kernel markers. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_BLUESTACKS BlueStacks files or properties. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
EMULATOR_BUILD Emulator build fingerprint, model, or tags. Use a physical device. Do not partially spoof an emulator; root-based spoofing creates inconsistencies. Hardware, driver, and build indicators remain.
ISOLATION_PROFILE Aggregate profile or isolation state. Run under the owner user; use a profile only as a deliberate test. Add the full UID correctly to the concealment configuration and do not break UserManager. The user or profile fact remains true.
ISOLATION_CLONE Clone or Dual Apps user ranges and OEM context. Run under the owner user; use a profile only as a deliberate test. Add the full UID correctly to the concealment configuration and do not break UserManager. The user or profile fact remains true.
ISOLATION_SECONDARY_USER Execution with userId > 0. Run under the owner user; use a profile only as a deliberate test. Add the full UID correctly to the concealment configuration and do not break UserManager. The user or profile fact remains true.
ISOLATION_WORK_PROFILE A managed or work profile and profile owner. Run under the owner user; use a profile only as a deliberate test. Add the full UID correctly to the concealment configuration and do not break UserManager. The user or profile fact remains true.
VPN_PROPERTY System properties resembling VPN state. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
DNS_PROPERTY DNS properties indicating an altered path. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
VPN_FILE Files or paths associated with VPN artifacts. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
VPNHIDE VPNHide regression oracles and markers for clean or inconsistent states. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
LSPOSED LSPosed, Vector, or Xposed indicators. Do not repackage the APK or inject rootless or Xposed hooks. Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. Process-local Zygisk and third-party concealment modules may remain visible.
HOOK_PROPERTY Properties associated with hooks or frameworks. Do not repackage the APK or inject rootless or Xposed hooks. Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. Process-local Zygisk and third-party concealment modules may remain visible.
TCP_VPN_PORT A TCP listener or connection on a characteristic VPN or proxy port. Disable the listener or control API, or move the daemon to a gateway. Use a UID firewall, portshide, or a kernel loopback block. The shell and target UIDs may see different rules; changing the port is insufficient.
UDP_VPN_PORT A UDP listener or connection on a characteristic VPN or proxy port. Disable the listener or control API, or move the daemon to a gateway. Use a UID firewall, portshide, or a kernel loopback block. The shell and target UIDs may see different rules; changing the port is insufficient.
INET6_VPN_INTERFACE A VPN-like interface in /proc/net/if_inet6. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
ROUTE_VPN_INTERFACE A VPN interface in /proc/net/route or route output. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
ARP_VPN_INTERFACE A VPN-like interface or neighbor in ARP data. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
SYSCTL_FORWARDING An unusual IP forwarding state. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
SYSCTL_RP_FILTER An unusual reverse-path filter state. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
ESTABLISHED_VPN_SOCKET An established socket associated with a VPN address or port. Disable the listener or control API, or move the daemon to a gateway. Use a UID firewall, portshide, or a kernel loopback block. The shell and target UIDs may see different rules; changing the port is insufficient.
VPN_POLICY_RULES Policy rules characteristic of VPN or per-UID routing. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
VPN_QDISC A qdisc or queue discipline on the VPN path. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
HIDDEN_MAC_NEIGHBORS Inconsistent MAC or neighbor data. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
TCP_MSS_LOW A reduced TCP MSS as an indirect tunnel indicator. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
SO_BINDTODEVICE SO_BINDTODEVICE behavior and interface availability. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
LOOPBACK_PORT_CONFLICT A loopback-port conflict or occupancy difference between paths. Disable the listener or control API, or move the daemon to a gateway. Use a UID firewall, portshide, or a kernel loopback block. The shell and target UIDs may see different rules; changing the port is insufficient.
BPF_MAP_ACCESSIBLE Accessibility of BPF maps or netd statistics. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
IP_RECVERR Error-queue, IP_RECVERR, and PMTU behavior. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
SYSCALL_UNAVAILABLE A native syscall probe is unavailable or unsupported. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
SYSFS_VPN_LEAK A VPN interface exposed through sysfs. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
GETIFADDRS_VPN A VPN interface or address returned by getifaddrs(). Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
SYSCLASSNET_VPN A VPN interface in /sys/class/net. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
RTM_GETLINK_VPN A VPN interface in netlink RTM_GETLINK output. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
PROC_IF_INET6_VPN A VPN IPv6 entry in /proc/net/if_inet6. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
PROC_IPV6_ROUTE_VPN A VPN route in /proc/net/ipv6_route. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
PROC_NET_DEV_VPN A VPN interface or counters in /proc/net/dev. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
IFINDEXNAME_VPN Resolution from an interface index to a VPN name or synthetic if<N>. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
VPN_POLICY_RULES_NETLINK VPN policy rules obtained through netlink RTM_GETRULE. Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths.
FIB_TRIE_DENIED Access to /proc/net/fib_trie is denied or behaves specially. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
INET_DIAG_DENIED INET_DIAG access is denied or behaves specially. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
BINDTODEVICE_LEAK Binding to a physical or VPN interface exposes the path. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
GETSOCKNAME_LEAK getsockname() exposes the path address or interface. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
UDP_PORT_CONFLICT_PHYSICAL A UDP bind or port conflict differs between the physical and VPN paths. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
DEEP_VPN_QDISC An extended qdisc probe. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
DEEP_BPF_MAP_ACCESSIBLE Extended BPF or netd statistics. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
ROUTE_COUNT The route count as an indirect oracle. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
TRIM_ORACLE The size or trimming of a netlink dump reveals a hidden entry. Use an external gateway; this generally cannot be filtered locally without root. Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. Backend parity and kernel ABI differ; repeated verification is required.
PMTU_MSS_COMBINED A combined PMTU and MSS fingerprint. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
UDP_PMTU_OK A UDP PMTU probe succeeds at a characteristic size. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
UDP_PMTU_FAIL A UDP PMTU probe fails in a characteristic way. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
NORMAL_PMTU The normal or baseline PMTU control. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
TIMING_ORACLE A timing difference between the physical and concealed paths. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
BACKPRESSURE Socket backpressure or buffering as an indirect fingerprint. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
GSO_FAILED A GSO option or probe is unsupported or rejected. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
GSO_SEND_FAILED Sending a GSO datagram fails. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
GSO_OK The GSO control succeeds. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
HW_TIMESTAMP Hardware and software timestamping behavior. Normalize the actual VPN, route, or socket parameter, or use an external gateway. VPNHide Next Medium or Max claims some coverage; verify the exact signal. These heuristics depend on the kernel and network; false positives are possible.
TRACEROUTE_DENIED A traceroute or path probe is unavailable or blocked. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
GENERAL_DIAGNOSTICS General native diagnostic output. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.
UNKNOWN An unknown or unmapped native kind. Do not “fix” a denied or unavailable result; repeat the check on a control device. Root is needed only for diagnostics; do not weaken SELinux. Usually informational or availability-related; interpret it together with the other rows.

3. All β check IDs — 41

ID Source Domain / group What is checked Without root With root Residual state
beta.vpn_binder BETA_VPN_BINDER VPN_OR_PROXY / android_vpn_service; hard-authority A Binder query to the Android VPN service or state. Use an external gateway. Apply framework filtering in system_server and keep the target outside Xposed scope. The Binder and native models must agree.
beta.user_profile BETA_USER_PROFILE ISOLATED_PROFILE / android_user_manager The current user or profile through Android user APIs. Run under the owner user. Target the correct UID only; do not break UserManager. The truthful profile signal remains.
beta.foreground_user BETA_USER_PROFILE ISOLATED_PROFILE / android_user_manager The foreground user and its consistency with the process context. Run under the owner user. Target the correct UID only; do not break UserManager. The truthful profile signal remains.
beta.connectivity_binder BETA_CONNECTIVITY_BINDER NETWORK_PATH_DIVERGENCE / android_connectivity Connectivity Binder responses compared with the public model. Use an external gateway. Apply framework filtering in system_server and keep the target outside Xposed scope. The Binder and native models must agree.
beta.netd_netid BETA_NETD_NETID NETWORK_PATH_DIVERGENCE / netd The netd or network ID of the active path. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.socket_identity BETA_SOCKET_MARK NETWORK_PATH_DIVERGENCE / kernel_socket Socket mark, network ID, and identity. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.inet_diag_cookie BETA_SOCKET_DIAG NETWORK_PATH_DIVERGENCE / socket_diag INET_DIAG cookie and socket identity. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.route_lookup BETA_ROUTE_LOOKUP NETWORK_PATH_DIVERGENCE / kernel_route A single route lookup to a control target. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.policy_rules BETA_POLICY_RULE NETWORK_PATH_DIVERGENCE / kernel_route Policy-routing rules for the UID or network ID. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.rtnl_address BETA_RTNL_ADDRESS NETWORK_PATH_DIVERGENCE / kernel_link An IPv4 and IPv6 RTNL address dump. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.extended_rtnetlink BETA_NETD_NETID NETWORK_PATH_DIVERGENCE / kernel_routing Extended rtnetlink and netd routing context. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.interface_driver BETA_LINK_DRIVER VPN_OR_PROXY / kernel_link Network-interface driver, kind, and details. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.interface_traffic BETA_INTERFACE_TRAFFIC NETWORK_PATH_DIVERGENCE / active_egress Interface counters and the actual egress. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.wireguard_genl BETA_WIREGUARD_GENL VPN_OR_PROXY / kernel_vpn WireGuard generic-netlink state. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.ovpn_genl BETA_OVPN_GENL VPN_OR_PROXY / kernel_vpn OpenVPN DCO or generic-netlink state. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.xfrm BETA_XFRM VPN_OR_PROXY / kernel_ipsec XFRM or IPsec states and policies. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.unix_diag BETA_UNIX_DIAG VPN_OR_PROXY / local_control_plane Unix-domain sockets in the local control plane. Disable the proxy or control daemon. Block by UID or namespace. The listener or Unix socket may remain visible.
beta.unix_peer_identity BETA_UNIX_DIAG VPN_OR_PROXY / local_control_plane Peer credentials and identity on a Unix socket. Disable the proxy or control daemon. Block by UID or namespace. The listener or Unix socket may remain visible.
beta.tun_fd BETA_TUN_FD VPN_OR_PROXY / process_fd; hard-authority A kernel query on a TUN file descriptor. Remove the local VpnService through an external gateway. Filter in the kernel; a userspace hook is insufficient. This is hard evidence only after at least two stable, matching samples.
beta.bpf_netd BETA_BPF_NETFILTER NETWORK_PATH_DIVERGENCE / packet_policy BPF or netd maps and traffic policy. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.cgroup_bpf BETA_BPF_NETFILTER NETWORK_PATH_DIVERGENCE / packet_policy Cgroup BPF attachment and policy. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.netfilter_path BETA_BPF_NETFILTER NETWORK_PATH_DIVERGENCE / packet_policy Netfilter path or redirection state. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.original_destination BETA_BPF_NETFILTER NETWORK_PATH_DIVERGENCE / packet_policy The original destination after transparent redirection. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.direct_syscall_consistency BETA_HOOK_CONSISTENCY HOOK_OR_TAMPERING / hook_consistency Comparison of a libc API with a direct syscall. Avoid process injection. Use a kernel backend and keep the target outside Zygisk and Xposed. An alternate path exposes a partial hook.
beta.io_uring_consistency BETA_HOOK_CONSISTENCY HOOK_OR_TAMPERING / alternate_syscall_path An alternate io_uring path compared with a hooked API. Avoid process injection. Use a kernel backend and keep the target outside Zygisk and Xposed. An alternate path exposes a partial hook.
beta.fd_identity BETA_HOOK_CONSISTENCY HOOK_OR_TAMPERING / process_fd The type and identity of process file descriptors. Avoid process injection. Use a kernel backend and keep the target outside Zygisk and Xposed. An alternate path exposes a partial hook.
beta.sandbox_identity.process BETA_SANDBOX_IDENTITY APP_VIRTUALIZATION / process_identity Process identity inside a virtual container. Use the original APK in an ordinary sandbox. Do not use a virtual container or repackaged APK. Root does not turn a container into an ordinary profile.
beta.sandbox_identity.filesystem BETA_SANDBOX_IDENTITY APP_VIRTUALIZATION / filesystem_identity Sandbox filesystem layout and identity. Use the original APK in an ordinary sandbox. Do not use a virtual container or repackaged APK. Root does not turn a container into an ordinary profile.
beta.sandbox_identity.namespace BETA_NAMESPACE APP_VIRTUALIZATION / namespace_identity Sandbox or virtualization namespace identity. Use the original APK in an ordinary sandbox. Do not use a virtual container or repackaged APK. Root does not turn a container into an ordinary profile.
beta.fscrypt_identity BETA_SANDBOX_IDENTITY APP_VIRTUALIZATION / filesystem_identity fscrypt and user-storage identity. Use the original APK in an ordinary sandbox. Do not use a virtual container or repackaged APK. Root does not turn a container into an ordinary profile.
beta.linker_integrity BETA_HOOK_CONSISTENCY HOOK_OR_TAMPERING / loader_integrity Linker and loader integrity and hooks. Avoid process injection. Use a kernel backend and keep the target outside Zygisk and Xposed. An alternate path exposes a partial hook.
beta.dns_netid BETA_DNS_NETID NETWORK_PATH_DIVERGENCE / dns_path DNS resolver network ID and path. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.native_dns_resolver BETA_DNS_NETID NETWORK_PATH_DIVERGENCE / dns_path The native resolver compared with framework DNS. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.proxy_selector BETA_PROXY_SELECTOR VPN_OR_PROXY / android_proxy Java ProxySelector and system-proxy consistency. Disable the proxy or control daemon. Block by UID or namespace. The listener or Unix socket may remain visible.
beta.transport_matrix BETA_TRANSPORT_MATRIX NETWORK_PATH_DIVERGENCE / active_egress An HTTP, DNS, and UDP matrix against canary endpoints. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.tls_interception BETA_TLS_INTERCEPTION VPN_OR_PROXY / tls_path TLS interception and certificate path. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.pktinfo BETA_PKTINFO NETWORK_PATH_DIVERGENCE / kernel_socket IP_PKTINFO or IPv6 packet info for the incoming or outgoing path. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.netlink_transitions BETA_NETWORK_TRANSITION NETWORK_PATH_DIVERGENCE / network_timeline The temporal sequence of netlink network events. Use an external gateway or remove the local VPN. Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. Denial is often neutral, and kernel or ROM parity differs.
beta.traceroute BETA_TRACEROUTE SYSTEM_NETWORK_CONTEXT / path_observation Traceroute and path observation. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.server_fingerprint BETA_SERVER_FINGERPRINT SYSTEM_NETWORK_CONTEXT / server_observation A remote fingerprint of the observed path. Make the actual route, DNS, and TLS path consistent, or use an external gateway. Root cannot alter the server-side path; exclude the target from MITM. Network-epoch changes and noise matter; server context alone is not always hard evidence.
beta.root_emulator NATIVE_ROOT_DETECTION DEVICE_INTEGRITY / device_integrity Aggregate β assessment of root, emulator, and device integrity. Use a physical stock device without root. Minimize the root surface and do not partially spoof an emulator. A review state or quorum remains possible.

4. Remediation priority

  1. Start with server-side observations and the actual egress: GEO_IP, IP consensus, DNS, CDN, STUN and call transport, and underlying-network binding.
  2. Then address the framework layer: direct and indirect capabilities, active VPN state, LinkProperties, and Binder β checks.
  3. Then address the native kernel layer: interfaces, routes, TUN type, netlink, interface indices, socket identity, and the TUN file descriptor.
  4. Then address localhost and package visibility.
  5. Leave root, hooks, isolation, and heuristic PMTU, GSO, or timing rows until last.

This order reduces false conclusions. Installing a root-concealment module is pointless while the application still sees an open Clash API and a foreign egress; tuning MTU is pointless while TRANSPORT_VPN remains direct evidence.

5. Coverage status

The matrix is considered complete only when _validate.py confirms an exact match between the rows in all three sections and the source code, with populated root and non-root columns. When a new EvidenceSource, NativeSignalId, or BetaCheckRegistry.definition() is added, the local validation must fail until a separate row is added here.

Back to the contents