MuntashirAkon/AppManager · error · RemoteException

Firewall overlays require Android 13+

Error message

Firewall overlays require Android 13+

What it means

ConnectivityPermissionOverridePlatform.apply() enforces network firewall rules per UID using hidden ConnectivityManager firewall-chain APIs whose per-UID rule support requires Android 13 (TIRAMISU). On older builds it throws RemoteException('Firewall overlays require Android 13+').

Solutions

  1. Run the operation on an Android 13+ device, or gate the feature behind Build.VERSION.SDK_INT >= TIRAMISU in the caller
  2. Use a fallback override mechanism (e.g. standard network permission grant/revoke) on older Android versions
  3. Skip connectivity overrides for affected UIDs on pre-13 devices and inform the user

Example fix

// before
platform.apply(uid, override); // throws on Android 12
// after
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU) {
    platform.apply(uid, override);
} else {
    applyLegacyNetworkOverride(uid, override);
}
Defensive patterns

Strategy: fallback

Validate before calling

if (Build.VERSION.SDK_INT < Build.VERSION_CODES.TIRAMISU) {
    return; // or use legacy override path
}

Try / catch

try {
    platform.apply(uid, override);
} catch (RemoteException e) {
    Log.w(TAG, "Firewall overlays unavailable", e);
    applyLegacyOverride(uid, override);
}

Prevention

When it happens

Trigger: Applying a connectivity/network permission override through this platform implementation on a device running Android 12 or lower.

Common situations: Applying network access rules on Android 12 or older devices; running batch permission overrides on pre-13 firmware.

Understand the failure class

Background: "unsupported platform" / "not supported on this platform" errors: what they mean and how to fix them — this error's family across 47 libraries.

Related errors


AI-assisted analysis of MuntashirAkon/AppManager@0152f468fc (2026-09-12). Data as JSON: /api/errors/1f8e95308575e977. Report an issue: GitHub.

Appendix: source

Thrown at app/src/main/java/io/github/muntashirakon/AppManager/permission/ConnectivityPermissionOverridePlatform.java:44

    public boolean isEnforced(int uid, @NonNull PermissionOverride override) throws Exception {
        if (Build.VERSION.SDK_INT < Build.VERSION_CODES.UPSIDE_DOWN_CAKE) {
            return false;
        }
        int firewallChain = chain(override);
        if (!ConnectivityManagerCompat.getFirewallChainEnabled(firewallChain)) {
            return false;
        }
        int rule = ConnectivityManagerCompat.getUidFirewallRule(firewallChain, uid);
        int expected = override.desiredGranted
                ? android.net.ConnectivityManagerHidden.FIREWALL_RULE_DEFAULT
                : android.net.ConnectivityManagerHidden.FIREWALL_RULE_DENY;
        return rule == expected;
    }

    @Override
    public void apply(int uid, @NonNull PermissionOverride override) throws Exception {
        if (Build.VERSION.SDK_INT < Build.VERSION_CODES.TIRAMISU) {
            throw new RemoteException("Firewall overlays require Android 13+");
        }
        int firewallChain = chain(override);
        // Per-UID rules only take effect while their chain is enabled.
        ConnectivityManagerCompat.setFirewallChainEnabled(firewallChain, true);
        int rule = override.desiredGranted
                ? android.net.ConnectivityManagerHidden.FIREWALL_RULE_DEFAULT
                : android.net.ConnectivityManagerHidden.FIREWALL_RULE_DENY;
        ConnectivityManagerCompat.setUidFirewallRule(firewallChain, uid, rule);
    }

    private static int chain(@NonNull PermissionOverride override) {
        return Integer.parseInt(override.controller);
    }
}

View on GitHub (pinned to 0152f468fc)