MuntashirAkon/AppManager · error · RemoteException
Firewall overlays require Android 13+
Error message
Firewall overlays require Android 13+
What it means
ConnectivityPermissionOverridePlatform.apply() enforces network firewall rules per UID using hidden ConnectivityManager firewall-chain APIs whose per-UID rule support requires Android 13 (TIRAMISU). On older builds it throws RemoteException('Firewall overlays require Android 13+').
Solutions
- Run the operation on an Android 13+ device, or gate the feature behind Build.VERSION.SDK_INT >= TIRAMISU in the caller
- Use a fallback override mechanism (e.g. standard network permission grant/revoke) on older Android versions
- Skip connectivity overrides for affected UIDs on pre-13 devices and inform the user
Example fix
// before
platform.apply(uid, override); // throws on Android 12
// after
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU) {
platform.apply(uid, override);
} else {
applyLegacyNetworkOverride(uid, override);
} Defensive patterns
Strategy: fallback
Validate before calling
if (Build.VERSION.SDK_INT < Build.VERSION_CODES.TIRAMISU) {
return; // or use legacy override path
} Try / catch
try {
platform.apply(uid, override);
} catch (RemoteException e) {
Log.w(TAG, "Firewall overlays unavailable", e);
applyLegacyOverride(uid, override);
} Prevention
- Gate connectivity-override features on Build.VERSION.SDK_INT >= TIRAMISU
- Provide a legacy permission path for older Android versions
- Hide or disable the feature in the UI on unsupported devices
When it happens
Trigger: Applying a connectivity/network permission override through this platform implementation on a device running Android 12 or lower.
Common situations: Applying network access rules on Android 12 or older devices; running batch permission overrides on pre-13 firmware.
Understand the failure class
Background: "unsupported platform" / "not supported on this platform" errors: what they mean and how to fix them — this error's family across 47 libraries.
Related errors
- ADB daemon not running.
- Backup only allowed for current user
- Bad component name
- Could not connect to ADB.
- Could not mount
AI-assisted analysis of MuntashirAkon/AppManager@0152f468fc (2026-09-12).
Data as JSON: /api/errors/1f8e95308575e977.
Report an issue: GitHub.
Appendix: source
Thrown at app/src/main/java/io/github/muntashirakon/AppManager/permission/ConnectivityPermissionOverridePlatform.java:44
public boolean isEnforced(int uid, @NonNull PermissionOverride override) throws Exception {
if (Build.VERSION.SDK_INT < Build.VERSION_CODES.UPSIDE_DOWN_CAKE) {
return false;
}
int firewallChain = chain(override);
if (!ConnectivityManagerCompat.getFirewallChainEnabled(firewallChain)) {
return false;
}
int rule = ConnectivityManagerCompat.getUidFirewallRule(firewallChain, uid);
int expected = override.desiredGranted
? android.net.ConnectivityManagerHidden.FIREWALL_RULE_DEFAULT
: android.net.ConnectivityManagerHidden.FIREWALL_RULE_DENY;
return rule == expected;
}
@Override
public void apply(int uid, @NonNull PermissionOverride override) throws Exception {
if (Build.VERSION.SDK_INT < Build.VERSION_CODES.TIRAMISU) {
throw new RemoteException("Firewall overlays require Android 13+");
}
int firewallChain = chain(override);
// Per-UID rules only take effect while their chain is enabled.
ConnectivityManagerCompat.setFirewallChainEnabled(firewallChain, true);
int rule = override.desiredGranted
? android.net.ConnectivityManagerHidden.FIREWALL_RULE_DEFAULT
: android.net.ConnectivityManagerHidden.FIREWALL_RULE_DENY;
ConnectivityManagerCompat.setUidFirewallRule(firewallChain, uid, rule);
}
private static int chain(@NonNull PermissionOverride override) {
return Integer.parseInt(override.controller);
}
}
View on GitHub (pinned to 0152f468fc)