It took me a while to figure out why many of my self-hosted services were intermittently failing to connect on my phone after updating to Android 17. I eventually figured out there’s a new ACCESS_LOCAL_NETWORK permission which means the “Nearby devices” permission is now required to access devices on the same network subnet. For an avid self-hoster, this can be quite a bit.

I had my DNS configured so my public-facing server resolved to a local IP address when on my LAN. This meant that my web, immich, xmpp, NTP, jellyfin and DoH servers all resolved to a local IP address on wifi. On Android 17, it all broke without warning. No error messages. No asking for extra permissions. Just silent packet dropping.

I’ve solved it by configuring my public-facing services to resolve to my external (static) IP address, even when inside the network. I couldn’t make any internal services resolve to the external address (SMB, CUPS etc) because they are (obviously) not bound to my WAN interface.

I get why the change was made. A lot of apps were snooping around people’s networks to gather intel. A potentially massive privacy violation.

Has anyone else had this issue? Is this the cleanest solution?

  • mxdcodes@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 hours ago

    It works but I wouldn’t call it the cleanest solution, more a workaround. As far as I know only apps targeting SDK 37 are affected, older apps still get the permission implicitly. So the proper way would be to just grant “Nearby devices” to the apps that need it e.g. Immich or Jellyfin and if an app doesn’t ask for it that’s actually a bug and worth reporting, because it should request the permission as soon as the server resolves to a local IP. I also find the “Nearby Devices” title a bit misleading for apps that only need it to reach your own server, but on the other side it gives a somehow proper hint what the permission actually allows.

  • Joelk111@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Why are permissions so damn confusing? I say this as someone who knows why permissions are needed, such as location to find nearby devices. But why must we keep track of “permission X is for thing unrelated to X” in our heads? Now I haven’t tried to make a permissions system for the masses, so I guess I can’t say too much, but it doesn’t seem that difficult to just make the permission name relate to what it does and provide a short synopsis for it.

    • Kairos@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      ·
      16 hours ago

      Android is run by the stupidest people you can imagine. They make these decisions like MBAs

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      It’s because people keep finding ways around them and they evolve in nonsensical ways.

  • bonn2@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    I gave permission to Firefox, but honestly most of my services weren’t affected because I connect to 99% of them via Tailscale which doesn’t seem to trigger the permission. (Yes that was an absolute nightmare to figure out why only one service was failing to connect)

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    2 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    DHCP Dynamic Host Configuration Protocol, automates assignment of IPs when connecting to a network
    DNS Domain Name Service/System
    ISP Internet Service Provider

    3 acronyms in this thread; the most compressed thread commented on today has 13 acronyms.

    [Thread #115 for this comm, first seen 27th Sep 2026, 20:10] [FAQ] [Full list] [Contact] [Source code]

  • Lenna 🔞@piefed.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    I had my DNS configured so my public-facing server resolved to a local IP address when on my LAN. This meant that my web, immich, xmpp, NTP, jellyfin and DoH servers all resolved to a local IP address on wifi.

    I unfortunately don’t have an answer to your question since I’m not on Android 17, but I do want to ask about this part. What’s the benefit of this? Does it improve speed when streaming on Jellyfin?

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      Routing between two interfaces on the same NIC takes nanoseconds. You wouldn’t notice a performance difference.

      When I first set it up, I didn’t have a static IP address, so it would not be great when it changed. I also want my server to remain reachable locally if my internet goes down. I had different firewall/ACL rules for wifi too. For example, some of my internal websites only prompt for a login if you’re outside the network.

      IPv6 has been awesome here. I have my server and clients on different /64 subnets in the same /48 block. The nearby devices on Android assumes only the same /64 is local.

    • wholookshere@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      Not OP but I do the same for two reasons.

      A) it eleimitaes my ISP traffic. It doesn’t have to go out to my router, to come back in on the public IP. They can’t track what never hits them.

      B) I also have completely internal services. So the DNS entries are internal only. Can’t map my internal network publicly.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        A router shouldn’t be sending that traffic outside. It should already have routes to send it right back, either regular or NAT rules.

        • wholookshere@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 day ago

          It still has to hit the ISP router?

          Depends on the IP. I have a static block, so the other IPs have to hit the public IP and come back, because the router doesn’t hold those IPs, itnjust forwards the traffic.

      • pHr34kY@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        I’ve also got a completely different DNS config for WAN and LAN traffic. WAN devices can only resolve PTR records for my mail server. My LAN devices have DDNS so internally they a get allocated DNS entries by hostname. Even my guest network has a different config for isolation.

        They definitely all need to be kept separate.

      • Rai@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Would you have any recommendations to resources where I can read about setting something like this up? I’ve recently picked up a managed switch and set up a computer to act as a router, and I’ve been learning how VLANs be. I don’t have things fully working on my home network yet, though, but I’m very interested!

        • KyuubiNoKitsune@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 days ago

          If you host your own internal dns server like a pihole, you can just add them in as local names.

          Careful of something called split brain dns though.

          For reference, I use AWS Route53 to host my dns domain publicly and internally I use pihole and Traefik. Traefik deals with getting certificates for my internal resources.

          • Rai@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 days ago

            Thank you! I currently do run a PiHole, which I’ve been running for like six years? I really need to get that updated as well hahaha. I’ll look into doing it they way!

        • tburkhol@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 days ago

          I don’t know how the others set theirs up, but I use “views” in bind 9 https://kb.isc.org/docs/aa-00851

          Essentially, the DNS I run on a router-like box much like you describe uses a different database depending on whether you query from an internal IP address or a public address. For me, the advantages are that I can let devices on my local network declare their own names to DHCP and enter them in DNS without worrying about the outside world. Mu internal network doesn’t crash if my ISP changes my address, Certbot happily requests certs for any site with a public address, and that cert works seamlessly on the corresponding internal address, no wildcards or DNS challenge required.

          • Rai@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 days ago

            That’s so sick! That’s definitely above my skill level at the moment, but I will save this for when I’m more knowledgeable—thank you much!

            • frongt@lemmy.zip
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 days ago

              What are you running on your router? If you use opnsense, I’m pretty sure it has a GUI for DNS stuff. Been a while since I’ve used it.

              If you use pihole for DNS, you can set it up in there too, but it’s not the same process as most other systems.

        • wholookshere@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 days ago

          I’ll admit I dont have one.

          I’ve been meaning to write one myself on how I use things. As how I’ve gotten it to work has really been from a decade of doing this professionally. And I have opnions.

          I’ll for sure post links to this community when I have them.

  • Noxy@pawb.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    confused me when I suddenly had to give Firefox this permission to access websites on my LAN

    More ways to control what can access what is a welcome change for me

    (I’m on GrapheneOS but yeah, Android 17 based now)

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Do you have any network segmentation is all your stuff on the same lan?

    You also could try IPv6 public or private addresses

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      I’ve been on IPv6 years before Google turned it on. My ISP gave me a /48 and I’ve got different subnets for my WAN, LAN and guest LAN. I have a 4-port NIC so I could put a different subnet on each port.

      I didn’t mention it in my first post, but I only made AAAA DNS entries for my internal stuff. I just enable IPv4 for the few services that actually need it.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Ah, that makes sense

        Side note: you don’t need multiple ports to have multiple subnets. (You can just use vlans)

  • Avid Amoeba@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Thanks for the heads up. This would have been a nasty surprise followed by unknown duration of hair pulling.

  • giant_smeeg@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Luckily grapheneos allows a hybrid approach so allows just the lan subnet permission without the wider nearby devices permission.

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      I’m actually on GrapheneOS.

      I’ve found that you can deny “Network” permissions and permit “Nearby devices”. The app becomes LAN-only this way.

    • NarrativeBear@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      Hey can you let me know where I can find more info on this? I am running GrapheneOS as I was having this exact same issue as OP a few day back.

      On my browsers I have network access, but nearby devices was disabled.

      I checked my private dns settings and granted nearby devices access to my browsers, which allowed me to hit my local self-hosted services.

      Just wondering if there is a better way to achieve the same.

  • SkyNTP@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    I had this issue in firefox. And only firefox. Was pulling my hair for hours. Wish I had been warned.

    Anyway I just gave firefox the permission and the issue was resolved. Native apps seem unaffected. Which makes me think maybe this is an opt in setting right now?

    • pHr34kY@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      I think Firefox also gave me the first clue that something was up.

      Native apps all have a backwards-compatible setting so it’s allowed by default. That will surely get dropped when Google bumps the minimum Android target API so newly published apps need to explicitly configure it.

      I actually went through my apps list and disabled nearby devices for all the apps that don’t need it. It’s a good security measure. I just don’t like how it was rolled out.