Overview
Configuring system-wide transparent proxy routing on Android typically involves third-party VPN apps that require persistent foreground notifications, consume battery through Android’s VpnService abstraction layer, and frequently drop connections during network handoffs.
Developed by Tkocean, Aurora transforms an Android device into a native routing gateway. Operating directly at the Linux networking layer through Magisk, KernelSU, or APatch, Aurora orchestrates modern proxy cores—specifically sing-box and mihomo—to handle all system inbound and outbound network packets using kernel-level TProxy and TUN socket tables.
Network Routing Modes
Aurora routes traffic systemlessly without utilizing Android’s battery-intensive VpnService API:
- TProxy (TCP + UDP): Intercepts network packets at the kernel netfilter stage and redirects them to the local proxy port while preserving the original packet headers and destination IP addresses.
- TUN Virtual Adapter: Allocates a virtual network interface managed directly by the proxy core, providing complete protocol coverage for applications that bypass standard socket tables.
Directory Structure & Configuration
Core binaries, scripts, and runtime files are isolated in the module tree, while persistent user configurations are stored in /data/adb/aurora/:
/data/adb/aurora/config/: Directory where your customsing-box(config.json) ormihomo(config.yaml) configuration files reside./data/adb/aurora/scripts/: Network init scripts handling iptables rules, routing policy databases (ip rule), and interface lifecycle.
Installation & Setup
- Ensure your device is running Android 12 or higher with a compatible root manager.
- Download and flash the Aurora
.zippackage. - Place your proxy configuration file (sing-box JSON or mihomo YAML) into
/data/adb/aurora/. - Reboot the device. The background daemon will start automatically and apply kernel routing tables.
Troubleshooting
- No Internet Connectivity After Boot: If network traffic fails to resolve, verify that your proxy configuration contains valid server endpoints and that your DNS upstream is reachable without proxy routing.
- Kernel Lacks TProxy Support: If logcat indicates iptables failures (
No chain/target/match by that name), your kernel may lackxt_TPROXYmodules; switch your configuration mode to TUN in the module configuration.
