Conversation
The Cloud/Family DoH profile also caught iOS's captive-portal probe (captive.apple.com), so walled-garden wifi never showed the sign-in sheet and looked like no internet. Add NEDNSSettingsManager.onDemandRules that send Apple's probe hosts to system DNS, with a trailing Connect rule so DoH keeps filtering everything else. Existing users pick this up on the next launch, since the profile is re-saved on every start. Refs blokadaorg/issue-tracker#283 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Confirmed most points. I'll skip the native sign-in sheet check because it's hard to reproduce, the change is small enough that it just has to work. :D If ok I'll merge |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Real-device captive-portal verification remains incomplete.
Review effort: Lite
Findings: None
What changed in this PR
Updates iOS DoH profiles to bypass Apple captive-portal probes while preserving DoH for other traffic.
Changes:
- Adds captive-portal probe exceptions.
- Adds a trailing DoH connection rule.
- Consolidates profile URL and rule configuration.
| File | Summary |
|---|---|
ios/App/Service/PrivateDnsService.swift |
Configures captive-portal bypass rules for iOS DNS profiles. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
I tested this on a captive-portal setup, and it turns out the spec described the wrong failure. Sorry about that. What the test showed
What actually breaks
I've updated the spec accordingly. |
Testing showed iOS already exempts its own captive probe from DNS profiles; what breaks is the portal's login page opened in Safari, whose host often exists only in the portal network's DNS (e.g. wifi.finnair.com is NXDOMAIN publicly). Extend the neverConnect list with known in-flight, rail and hotel-platform portal hosts, keeping Apple's probe hosts as a hedge for networks where no sheet appears. Refs blokadaorg/issue-tracker#283 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PHms5UiGbdr44cLAS922fK
|
@balboah Thanks for re-testing and updating the spec. I've retargeted this PR: it now carries the spec's portal list (plus the Apple probe hosts as the hedge) and is a draft until the spike passes. I don't have a wired Mac for the rig, so could you run it? It should be one session on your setup. I've already verified upgrade safety (see the PR description), so this is only about whether the exemptions work. Build: check out this branch and build Six on your iPhone. Note that The rig is your spec's, with two changed scripts. Neither needs a test-only domain in the app: the portal uses names that are in the real list, plus one control name that isn't.
|
Addresses blokadaorg/issue-tracker#283 (updated spec). Draft until the captive-portal spike passes.
On captive Wi-Fi with the Blokada Cloud/Family DNS profile active, the portal's login page never loads in Safari. Portal hosts often exist only in the network's own DNS (e.g.
wifi.finnair.comis NXDOMAIN publicly), so DoH can't answer them. iOS already exempts its own captive probe, so the sign-in sheet isn't the problem.Change (
PrivateDnsService.swift):NEDNSSettingsManager.onDemandRulesholds anNEOnDemandRuleEvaluateConnectionwithNEEvaluateConnectionRule(.neverConnect)for known portal hosts. Those names resolve via the network's DNS. A trailingNEOnDemandRuleConnectkeeps DoH for everything else.syncPermsAfterTagChange) and Family (_checkDns) re-save the profile on every launch, so users pick it up on their next app start.Verified (iPhone 16e, Six, installed in place without uninstalling):
mainkeeps the profile enabled: no re-activation prompt (currentDns = enabledafter the save that adds the rules)make -C ios run-sixuninstalls first. That deletes the DNS profile, so after it the profile always reads disabled. Don't use it to judge upgrade behaviour.Still needed: the spike on the captive rig (instructions in the comment below)
If Stage B fails, a domain list can't work: close this PR and rethink the mechanism.
Out of scope: Android (no API for this), third-party hosts loaded inside portal pages (e.g. payment providers), and the macOS mobileconfig.
🤖 Generated with Claude Code
https://claude.ai/code/session_01PHms5UiGbdr44cLAS922fK