You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CompileSDK改为Oreo后Android设备TLS网络操作失败,求net.dns*替代方案

Fixing "Access denied finding property 'net.dns*'" on Android Oreo+ for TLS Operations

Hey there, I’ve run into this exact DNS property issue before when targeting newer Android versions. The problem boils down to Google removing access to the net.dns* system properties starting in Oreo (API 26) to boost platform privacy. When you bump your compile SDK to Oreo, the enforcer kicks in even on older devices like Android N, blocking those calls entirely.

Let’s go through the most reliable alternatives to get your TLS network operations back on track:

Starting from Android 7.0 (API 24), Google introduced the LinkProperties class which lets you safely retrieve DNS servers without relying on deprecated system properties. This is the official, future-proof approach.

First, add the required permission to your AndroidManifest.xml:

<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />

Then use this code to fetch active DNS servers:

ConnectivityManager connectivityManager = 
    (ConnectivityManager) getSystemService(Context.CONNECTIVITY_SERVICE);

if (connectivityManager != null) {
    // Iterate through all active networks
    for (Network network : connectivityManager.getAllNetworks()) {
        NetworkInfo networkInfo = connectivityManager.getNetworkInfo(network);
        if (networkInfo != null && networkInfo.isConnected()) {
            LinkProperties linkProperties = connectivityManager.getLinkProperties(network);
            if (linkProperties != null) {
                List<InetAddress> dnsServers = linkProperties.getDnsServers();
                // Use these servers for your TLS connection setup
                for (InetAddress dns : dnsServers) {
                    Log.d("DNS", "Active server: " + dns.getHostAddress());
                }
            }
        }
    }
}

2. Read DNS Info from System Files (Fallback)

If you need compatibility with even older devices or can’t use the Network API, you can read DNS configurations directly from /proc/net/dns. Note that this approach is less reliable (file format might vary across OEMs) but works as a fallback.

Here’s how to do it:

try {
    BufferedReader reader = new BufferedReader(new FileReader("/proc/net/dns"));
    String line;
    while ((line = reader.readLine()) != null) {
        // Parse the line to extract DNS server addresses
        String[] parts = line.split("\\s+");
        if (parts.length >= 5) {
            // Remove trailing dot from the DNS address
            String dnsServer = parts[4].replaceAll("\\.$", "");
            Log.d("DNS", "Server from /proc: " + dnsServer);
        }
    }
    reader.close();
} catch (IOException e) {
    e.printStackTrace();
}

3. Use a Third-Party Network Library (Low-Effort)

Libraries like OkHttp handle DNS resolution internally, so you don’t have to worry about deprecated system properties at all. They automatically use the correct system APIs to fetch DNS servers, making your code cleaner and more robust.

Here’s a quick example with OkHttp:

// Initialize OkHttpClient with default (or custom) DNS handling
OkHttpClient client = new OkHttpClient.Builder()
        .dns(Dns.SYSTEM) // Uses system's default DNS resolver
        .build();

// Make a TLS request
Request request = new Request.Builder()
        .url("https://your-target-domain.com")
        .build();

client.newCall(request).enqueue(new Callback() {
    @Override
    public void onFailure(Call call, IOException e) {
        // Handle error
        e.printStackTrace();
    }

    @Override
    public void onResponse(Call call, Response response) throws IOException {
        // Process successful response
        String responseBody = response.body().string();
        Log.d("Response", responseBody);
    }
});

Key Notes:

  • Always prefer the Network API first—it’s maintained by Google and less likely to break across devices.
  • If you stick with system file reading, add error handling since some OEMs might modify the /proc/net/dns format.
  • Third-party libraries like OkHttp or Retrofit (which uses OkHttp under the hood) will save you from manual DNS handling entirely.

内容的提问来源于stack exchange,提问作者Dushyant Suthar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:17:20