Telephony & Wireless

Android Data Call: Control, netd, eBPF & Packets

How Android leases a cellular data call on the control plane, then how every packet of an app's request travels from socket to server and back through the kernel, netd, eBPF and the modem. This is the hop-by-hop walk that Trace a Path Through the Android Stack only maps.

~90 min read 0 interview questions
In 30 seconds
  • Control plane leases the data call (APN/DNN, setupDataCall, PDN or PDU session, IP, CID, interface). Data plane is every packet after that. Mixing the two is the usual interview fail.
  • netd is the native daemon that paints Linux policy: addresses, ip rule / ip route, DNS, firewall and eBPF. ConnectivityService decides which Network; netd makes the kernel obey.
  • eBPF (loaded by bpfloader / netd / the Tethering module) accounts UID traffic, enforces UID firewall, Data Saver, Doze and App Standby, and offloads tethering and CLAT. It replaced most of xt_qtaguid.
  • A socket gets an fwmark; ip rule sends that mark to the routing table of one Network. That is how dual Wi-Fi + cellular, VPN overlay and bindProcessToNetwork actually work.
  • Uplink is app → ART/bionic → tcp_sendmsg → sk_buff → netfilter/eBPF → route → optional CLAT → driver → vendor offload → modem → RAN → GTP-U → NAT → server.
  • Downlink is not the reverse with the same interrupts: NAPI, GRO, softirq and IPA-style aggregation mean the AP sees batched IRQs, then the socket wait queue / epoll wakes the app.
  • "Connected but no internet" is almost never the modem alone. Bisect CID/IP, routes and fwmark, validation, DNS, UID firewall, then tcpdump versus modem logs.

Two planes: control vs data

A cellular data call is two conversations that share a radio and a kernel interface but almost no logic. Interviewers use this split as a filter. If you start an "HTTPS over LTE" answer with RRC and never name netd, or you start with sk_buff and never mention setupDataCall, you have mixed the planes.

Control plane (lease the lane)

  • Policy: data enabled, roaming, APN/DNN, restricted capabilities, retry.
  • Radio signalling: camp, RRC, NAS session management (ESM / 5GSM).
  • HAL: IRadioData.setupDataCall / deactivateDataCall.
  • Result: CID, ifname, addresses, DNS, gateway, MTU, optional PDU session id and URSP traffic descriptors.
  • Userspace finish: netd programs the iface; ConnectivityService registers a NetworkAgent and validates.

Data plane (drive on the lane)

  • App socket (OkHttp, HttpURLConnection, raw Socket, QUIC/UDP).
  • Kernel TCP/IP or UDP, netfilter/nftables, eBPF cgroup/skb, fwmark, policy routing.
  • Optional 464XLAT (clat) on IPv6-only cellular.
  • Vendor net driver (rmnet / CCMNI / generic) and optional hardware offload (IPA on Qualcomm; other SoCs have equivalents).
  • Modem user plane (PDCP/RLC/MAC/PHY), RAN, GTP-U to P-GW or UPF, NAT, Internet, server — and the reverse.
Analogy

Leasing a private highway lane versus driving a truck on it. The lease (control plane) is paperwork: which entrance (APN), your badge (IP), the lane number (rmnet_dataX), and the traffic office painting signs (netd). The trucks (packets) never fill out that paperwork again. NAS signalling that leased the lane is a different conversation from the HTTPS payload. See the map on Trace a Path Through the Android Stack; this page is the walk.

CONTROL (once per data call)                    DATA (every packet)
App / system NetworkRequest                     App write/send / QUIC datagram
        |                                               |
Telephony DataNetwork / DcTracker               ART / libcore / bionic
        |                                               |
IRadioData.setupDataCall                        tcp_sendmsg / udp_sendmsg
        |                                               |
Modem NAS ESM / 5GSM + RRC                      sk_buff + eBPF + fwmark
        |                                               |
P-GW / SMF+UPF assigns IP                       rmnet/CCMNI + offload + modem UP
        |                                               |
netd + NetworkAgent + validation                GTP-U + NAT + server
        v                                               v
   "Network is usable"                          bytes on the wire
Common pitfall Answering "trace a packet" with Attach / Registration only, or answering "how does data come up?" with TCP and IPA only. Name both planes, then stay on the one the question asked.
Interview angle Open with one sentence per plane, then ask which they want. Radio-deep signalling lives on Telephony, RIL and modem and 5G NR. Packet-deep kernel concepts live on Linux Kernel & BSP.

Radio prerequisites: camped, RRC, bearers and APN types

No amount of Android policy creates a data call if the UE is not a guest of a cell and a session in the core. Separate three states that juniors collapse into "we have signal": camped (cell selected), registered (core knows the UE), and RRC connected (there is an air-interface signalling path right now).

Camped, idle, connected

StateWhat is trueCan user-plane data flow?
Camped, RRC_IDLE (LTE) or RRC_IDLE / RRC_INACTIVE (NR)Suitable cell, may be EMM/5GMM registered, listening to paging / DRXNot yet. Uplink data triggers Service Request (and often RRC setup). Downlink data is paged first.
RRC_CONNECTEDSRBs up; DRBs exist if a session is activeYes, once a default bearer or PDU session user plane is active and the iface is configured.
Limited / emergency onlyCamped but not fully registeredEmergency PDN/PDU only, if the network and APN type allow it.

RRC_INACTIVE (NR) keeps the RAN and core context so resume is cheaper than a full idle-to-connected transition. It is still not "packets flowing"; the user plane must be resumed. Details: 5G NR.

Default bearer vs dedicated bearer (LTE)

LTE attach creates a default EPS bearer to one APN: always-on IP, best-effort QoS (typically QCI 9 for internet, QCI 5 for the IMS APN). A dedicated bearer is extra QoS (for example QCI 1 conversational voice) on the same PDN, usually network-initiated after IMS asks the PCRF. Android apps never "open a dedicated bearer" for HTTPS; they use the default internet bearer. IMS media is the usual dedicated-bearer story; see IMS & VoLTE.

APN / DNN types

An APN (LTE) or DNN (5G) is the named entrance into the operator's packet core. Android stores types in the telephony provider (from apns-conf.xml plus carrier / user edits). Types are capabilities, not interface names.

TypeUsed forInterview notes
defaultGeneral internetUsual initial-attach APN on LTE; the Network that validation must pass for apps.
imsIMS SIP and often mediaSeparate PDN/PDU; often IPv6; stays up when the user turns mobile data off.
mmsMMS HTTP to the MMSCOn-demand; frequently works with mobile data off; often a restricted Network.
dunTethering / hotspotSome carriers require a separate DUN APN so tethered traffic is billed or filtered differently.
fotaCarrier firmware updateRestricted; not the app default Network.
emergencyEmergency IMSCan be set up without a normal subscription when the network allows it.
hipriHigh-priority / explicit cellularLegacy TYPE_MOBILE_HIPRI and "use cellular while Wi-Fi is default" requests; still appears in APN DBs.

Other types you will see in dumps and carrier XML: supl, xcap, cbs, ia (initial attach), enterprise. Do not invent a type in an interview; if it is not in the dump, say "carrier-specific type in the APN database".

Tip "We have LTE bars" is not "we have a default bearer". Bars are camp + registration. A default bearer / PDU session is a session-management success plus an iface with an address.

LTE attach + default EPS bearer vs 5G registration + PDU session

This is the radio control plane at interview depth, not a second copy of the 5G page. The trap: LTE Attach creates the first data connection; 5G Registration does not. On SA, data is a separate PDU Session Establishment. NSA still uses the EPC for the master node, so the phone's "internet" session is an LTE PDN even while NR is aggregated. Radio-deep procedures: telephony / RIL and 5G NR.

LTE: Attach carries ESM

EMM Attach Request is bundled with an ESM PDN Connectivity Request. The MME creates a session toward S-GW / P-GW. Attach Accept arrives with Activate Default EPS Bearer Context Request: EPS bearer id, APN, PDN address (IPv4 and/or IPv6 IID), QoS, and often PCO (DNS, P-CSCF). The UE accepts; the default bearer is up. Later dedicated bearers use ESM Activate Dedicated EPS Bearer Context. If the default bearer is rejected, attach fails with an ESM cause wrapped in EMM.

5G SA: 5GMM then 5GSM

Registration (5GMM, AMF) makes the UE known: SUCI, 5G-AKA or EAP-AKA', NAS security, 5G-GUTI, TAI list, Allowed NSSAI. Then the UE sends PDU Session Establishment Request (5GSM, SMF): PDU session id, DNN, S-NSSAI, session type (IPv4 / IPv6 / IPv4v6 / Ethernet / Unstructured), SSC mode. The SMF picks a UPF; the user plane is an N3 GTP-U tunnel. QoS inside that tunnel is QoS flows (QFI), not one GTP tunnel per QCI as in LTE. URSP traffic descriptors on the UE can steer an app onto a different DNN or slice; Android surfaces those as TrafficDescriptor / slice info on the data call.

LTE (always-on IP at attach)
 UE -- ESM PDN Connectivity Request --> MME -- GTP-C --> S-GW/P-GW
 UE <-- Activate Default EPS Bearer (IP, DNS, QCI) --
        user plane: DRB -- S1-U GTP-U -- S-GW -- S5/S8 GTP-U -- P-GW -- Internet

5G SA (registration then session)
 UE -- 5GMM Registration --> AMF          (no IP yet)
 UE -- 5GSM PDU Session Est. --> AMF --> SMF -- N4 --> UPF
        user plane: DRB -- N3 GTP-U -- UPF -- N6 -- Internet

GTP-C vs GTP-U

GTP-C (control)GTP-U (user)
JobCreate/modify/delete sessions and bearersCarry the UE's IP packets in a tunnel
LTEMME ↔ S-GW ↔ P-GW (and related)eNB ↔ S-GW ↔ P-GW
5GSession logic is PFCP on N4 (SMF ↔ UPF), not classic GTP-C on that hopgNB ↔ UPF (N3), UPF ↔ UPF (N9)
On the phone?Never. The modem speaks NAS; the core speaks GTP-C/PFCP.Never as a stack the app sees. The modem encapsulates after PDCP.

Say in interviews: "GTP-U is the user-plane tunnel in the core; GTP-C (LTE) or PFCP (5G N4) is how the core builds that tunnel. The UE only sees NAS session management and a local IP on rmnet_dataX."

Common pitfall "5G registration creates the default bearer." That sentence is LTE. On SA, say registration then PDU session. On NSA, say EPC PDN plus EN-DC radio.
Interview angle Name ESM vs 5GSM message families, default vs dedicated bearer, PDU session vs QoS flow, and GTP-U as the packet path in the core. Then stop and point at the 5G page rather than reciting numerology.

Android telephony data stack

The framework decides when a data call exists. The modem decides how the NAS signalling runs. ConnectivityService decides whether apps may use the resulting Network. Keep those three verbs straight.

Before Android 13: DcTracker

  • DcTracker per transport (cellular, and sometimes IWLAN).
  • ApnContext per APN type; DataConnection state machine per live call.
  • Bring-up, teardown, retry and handover logic spread across interacting machines; races were common.

Android 13+: DataNetworkController

  • One DataNetworkController per Phone.
  • DataNetwork is one active connection (own state machine).
  • DataProfileManager picks a DataProfile; DataRetryManager retries and honours T3396/T3346; DataSettingsManager tracks user/roaming/policy; AccessNetworksManager picks cellular vs IWLAN.
  • Request-driven evaluations with explicit reasons, which is what you read in telephony logs.

DataService and the APN database

android.telephony.data.DataService is the pluggable data-plane control API. The default implementation talks to IRadioData. Vendors (and AOSP IWLAN) can ship another DataService that sets up an IPsec tunnel to an ePDG instead of a cellular PDN. Telephony binds the service, sends a setup request with a profile, and gets back the same shape of result: interface, addresses, DNS.

APNs live in the telephony provider (content://telephony/carriers), seeded from apns-conf.xml, filtered by MCC-MNC / carrier ID, and editable by the user or a carrier-privileged app. The framework pushes the initial attach profile (setInitialAttachApn) and the full list (setDataProfile) so the modem can attach and can also originate a second PDN later.

Gates before setup

  1. SIM and PS service Card loaded, PS domain in service (or emergency exception).
  2. Data enabled User mobile-data toggle, carrier policy, and device policy (user restriction / parental / enterprise). This gate applies to the internet APN, not IMS.
  3. Roaming Data roaming setting and carrier roaming rules. Voice/IMS roaming is a different policy.
  4. DDS / PhoneSwitcher On DSDS, only the preferred data subscription's TelephonyNetworkFactory is live for default internet.
  5. Restricted capabilities IMS, MMS, FOTA Networks usually lack NET_CAPABILITY_NOT_RESTRICTED. Ordinary apps never receive them as the default Network.
  6. Throttle / retry DataRetryManager plus modem-reported suggested retry; permanent ESM/5GSM causes (unknown APN, not subscribed) should not tight-loop.

IWLAN / Wi-Fi offload (high level)

When AccessNetworksManager prefers IWLAN, setup uses the IWLAN DataService: IPsec to the ePDG, then into the EPC/5GC as if it were another access. setupDataCall can carry a handover reason and existing addresses so the IP is preserved. Apps keep the same Network object if handover succeeds; if it fails, ConnectivityService falls back. Do not describe IWLAN as "just Wi-Fi" — it is a cellular PDN/PDU over untrusted WLAN.

Analogy

DataNetworkController is the receptionist: it opens a named entrance (APN) only when a NetworkRequest needs it, checks whether that visitor is allowed today (data enabled, roaming, the right SIM), and closes it when nobody is using it. The modem is the locksmith who actually cuts the key (NAS). ConnectivityService is the building security desk that badges the resulting Network for apps.

Interview angle "What replaced DcTracker and why?" — name DataNetworkController, DataNetwork, evaluation reasons, and retry/handover as first-class managers. Then trace request → factory → profile → setupDataCall → agent.

IRadioData.setupDataCall and SetupDataCallResult

The Radio HAL data slice is android.hardware.radio.data.IRadioData (AIDL; HIDL on older releases). Framework RIL.java issues a solicited request with a serial; the vendor answers later on IRadioDataResponse.setupDataCallResponse. Unsolicited dataCallListChanged is how the modem tells Android the call list moved (network drop, handover, IP change). Binder/AIDL mechanics: Binder & AIDL.

setupDataCall / deactivateDataCall

Exact parameter lists move by HAL version. In interviews, name the ideas and say you would confirm the current AIDL:

  • accessNetwork — EUTRAN, NGRAN, IWLAN, and so on.
  • dataProfile — APN/DNN, protocol (IP / IPV6 / IPV4V6), auth, type bits, optional traffic descriptor / slice.
  • roamingAllowed, reason — normal, handover, shutdown (names as in the current DataRequestReason enum).
  • addresses / dnses — filled on handover so the session can keep its IP.
  • pduSessionId, sliceInfo, trafficDescriptors, matchAllRuleAllowed — 5G / URSP path; omit or zero on plain LTE internet if the HAL allows.

deactivateDataCall(serial, cid, reason) tears down by the CID the modem assigned. After a modem restart the list is empty; the framework must not assume old CIDs.

SetupDataCallResult fields that interviews expect

FieldMeaning
cause / fail causeNone on success; otherwise a DataCallFailCause (maps ESM/5GSM and local reasons). Pair with suggestedRetryTime.
cidModem-local connection id. Key for deactivate, keepalive, and getDataCallList.
ifnameKernel interface the vendor created or will create (rmnet_data0, ccmni0, …).
addressesUE addresses with prefix length (IPv4 and/or IPv6).
dnses, gatewaysResolver and on-link gateway(s) for that PDN.
mtu / mtuV4 / mtuV6Path MTU the stack and CLAT must honour. Prefer the split fields when present.
pduSessionId5G PDU session identity allocated/used for this call.
trafficDescriptorsURSP-matched descriptors (app id, DNN, IP descriptors, connection capabilities). Check current AIDL for the exact struct.
Also commonP-CSCF list, active/dormant, QoS sessions, slice info, handover failure mode. Name them if the dump has them; do not invent ioctl names.

Radio HAL vs vendor RIL / QMI WDS

AOSP stops at the HAL. The vendor radio process translates setupDataCall into chipset IPC. On Qualcomm-based designs the usual example is QMI WDS (Wireless Data Service: start/stop network interface, profile, packet status) plus QMI DSD for which RAT should carry data. Other SoCs have the same job under different names (vendor AT, custom RPC). You never debug "QMI WDS" from Java; you debug HAL cause + vendor logs. Prefer: "the vendor RIL maps IRadioData onto QMI WDS or the SoC equivalent" over a guessed TLV list.

DataNetwork / DataService
        |  Binder (IRadioData)
Vendor radio HAL process
        |  QMI WDS / SoC equivalent (example)
Modem NAS ESM / 5GSM
        |
SetupDataCallResult {cid, ifname, addresses, dnses, ...}
        |
TelephonyNetworkAgent --> ConnectivityService
netd configures ifname
Common pitfall Treating ifname as created by Java. The vendor/modem/kernel driver creates it; Android only configures it. A success cause with an empty ifname is a vendor bug, not an APN typo.

Kernel interface bring-up: rmnet, QMAP, offload, netlink

Each data call is a Linux netdev. The TCP/IP stack does not know it is cellular. Vendor drivers multiplex several logical calls over one physical link to the modem.

Family (examples)Typical ifnamesNotes
Qualcomm rmnetrmnet_data0, rmnet_data1, …Logical PDNs. Physical/mux devices vary by generation; do not hard-code older names like a single rmnet0 in a modern answer.
MediaTek CCMNIccmni0, ccmni1, …Same idea: one iface per data call.
Generic / other SoCswwan0, vendor prefixeswwan subsystem or proprietary. Always take ifname from the HAL result.

QMAP (Qualcomm example)

QMAP (Qualcomm Multiplexing and Aggregation Protocol) is a header in front of each Ethernet-like frame on the AP–modem link. Multiplexing: a mux id maps to one PDN/iface. Aggregation: several packets share one transfer so the AP and IPA see fewer transactions. Other vendors do multiplexing too; do not say "QMAP" as if it were 3GPP.

Vendor offload (IPA as the Qualcomm example)

An IP Accelerator (IPA) is a hardware block that can route, filter, NAT, header-convert and aggregate between the modem, AP memory, and peripherals (USB / Wi-Fi for tethering) so the application processor is not in every packet. Other SoCs ship equivalent DMA/offload engines under different names. Interview sentence: "Offload sits beside the netdev, not instead of the Linux stack for app sockets; exception is hardware tethering forward, where packets may never enter the AP stack."

What netd does on the netdev (via netlink)

After Telephony has ifname and addresses, netd (and the kernel) apply the usual RTNetlink objects. You will see the effects with ip even if you never read a netlink dump:

  • RTM_NEWLINK / flags: iface up.
  • RTM_NEWADDR: IPv4 and IPv6 addresses from SetupDataCallResult.
  • RTM_NEWRULE + RTM_NEWROUTE: per-Network table, default route, occasionally on-link prefixes.
  • IPv6: host autoconfig may already have a link-local; netd still adds the global / delegated address the modem reported.

Kernel driver internals (probe, NAPI, DMA) belong with Linux Kernel & BSP.

Analogy

The physical modem link is one freight railway. QMAP stickers say which customer (PDN) a crate belongs to and let the yard crane lift a whole pallet (aggregation). IPA is the automated yard that sorts pallets without waking the station master (the AP). rmnet_data0 is the platform number published to Linux.

ConnectivityService: agents, scoring, validation, binding, VPN

ConnectivityService in system_server is the only component apps should think of as "am I on the internet?". Telephony offers a Network; Wi-Fi offers another; VPN may overlay both. Framework overview: Android frameworks.

NetworkAgent and NetworkCapabilities

A TelephonyNetworkAgent (or Wi-Fi / VPN agent) publishes a Network plus NetworkCapabilities: transports (TRANSPORT_CELLULAR, TRANSPORT_WIFI, TRANSPORT_VPN, …) and capabilities (INTERNET, NOT_METERED, NOT_RESTRICTED, VALIDATED, CAPTIVE_PORTAL, IMS, MMS, DUN, FOTA, enterprise / slice-related flags on recent releases). Scoring / NetworkScore (and the current prefer-policy) ranks candidates. Cellular typically loses to validated Wi-Fi for the default Network unless the app binds or Wi-Fi is unvalidated / lost.

Validation and captive portal

A Network with INTERNET is not default-usable until validation succeeds (or the platform decides to skip). NetworkMonitor (in the Network stack module; names have moved with Mainline) issues an HTTPS probe to a well-known connectivity URL, follows redirects, and may detect a captive portal. Success adds NET_CAPABILITY_VALIDATED. Failure: the interface can still have an IP — this is the "connected, no internet" UI case. Private DNS failures can also keep a Network from becoming the happy default.

NetworkRequest and binding

  • ConnectivityManager.requestNetwork / registerDefaultNetworkCallback — system and apps (with permissions) ask for capabilities.
  • bindProcessToNetwork(Network) — that process's default socket routing uses that Network's fwmark/table (until cleared).
  • Network.bindSocket(fd) / Network.openConnection — one socket or URLConnection, not the whole process.
  • Without a bind, the socket follows the current default Network (and can break mid-transfer if the default switches — modern stacks re-bind or use the callback).

VPN overlay and dual Wi-Fi + cellular

A VPN creates a TUN Network that typically becomes default; underlying cellular/Wi-Fi stay up as the VPN's egress. Lockdown VPN blocks non-VPN sockets. protect() / fwmark protect bits let the VPN's own tunnel sockets escape the VPN table (otherwise the tunnel would loop). Dual networks: Wi-Fi default + cellular for a bound MMS/IMS/HIPRI request, or OEM dual-STA plus cellular. Each Network has its own netId, table and mark. Multipath / MultipathPreference is policy on top, not a second TCP stack.

Interview angle "How does Android choose the network?" — capabilities + score + validation + VPN overlay, then fwmark. Name bindProcessToNetwork vs bindSocket. Restricted Networks never become the app default.

netd in depth

netd is Android's native network daemon: a privileged process that applies kernel policy on behalf of ConnectivityService, NetworkManagementService, NetworkPolicyManagerService and a few modules. Java does not call ip with Runtime.exec for production paths; it talks Binder/AIDL to netd, and netd talks netlink, sockopts, nftables/iptables compatibility, and eBPF maps.

Analogy

netd is the city traffic-control office. ConnectivityService is the mayor who decides which roads are open. The office paints lane markings (ip route), hangs "this badge uses lane 100" signs (ip rule + fwmark), staffs the DNS desk (DnsResolver), and installs cameras and barriers (eBPF / firewall). Apps never visit the office; they just drive and get fined if a camera says their UID is blocked.

Binder / AIDL to netd

The stable interface is android.net.INetd (plus related AIDL in the Network stack / Tethering / DnsResolver modules depending on release). Calls are capability-checked; only system_server and a short allowlist may use them. Older code and some OEM scripts still speak the ndc text protocol on the netd socket; treat ndc as a remnant for dumps and bring-up, not the modern control path. See Binder & AIDL.

What netd actually applies

AreaKernel / userspace effect
InterfaceUp/down, MTU, MAC (where relevant), add/del address — the ip addr / ip link you dump.
Physical Network objectCreate netId, attach iface, add routes and default route into that table.
Policy routingip rule from fwmark/mask and sometimes UID ranges → table N.
Firewall / UIDeBPF cgroup/skb programs and leftover xtables; Data Saver, standby, doze, restricted networking.
TetheringIP forward, NAT/prefix, DHCP/RA coordination with the tethering module, eBPF offload where present.
Traffic controllerPer-UID counters and tags that TrafficStats reads (eBPF maps; historically qtaguid).

DnsResolver

Stub resolution moved out of monolithic netd into the DnsResolver component (Mainline / Network stack). It still receives per-netId DNS servers from the data call or DHCP, implements Private DNS (DNS-over-TLS), happy-eyeballs-ish races, and DNS64 synthesis when configured. dumpsys netd and resolver dumps both matter; do not assume one process owns everything on every release.

Realistic commands and dumps

# Effects you should be able to read in an interview
ip link show
ip addr show dev rmnet_data0
ip rule show
ip route show table all
ip route show table 100          # netId table; number is an example

# Framework view
dumpsys connectivity
dumpsys netd
dumpsys dnsresolver              # name can vary slightly by release; check the device

# Historical / still useful remnant
ndc interface list
ndc network list
ndc resolver dump

# Policy leftovers you may still see
iptables -t mangle -L -n
iptables -t filter -L -n
nft list ruleset                 # prefer this on nft-first devices

When you quote ndc in an interview, label it as remnant. The live path is AIDL → netd → netlink/eBPF.

Tip If ip addr looks perfect and apps still fail, you are no longer debugging the modem. You are debugging validation, fwmark, DNS or UID policy — all netd / ConnectivityService territory.

eBPF on Android

eBPF programs run in the kernel at well-defined hook points (cgroup skb, tc, sockops, xdp on some devices, tracepoints). Android uses them so per-UID firewall and accounting no longer depend on walking a giant xt_qtaguid table in the forwarding path. Do not recite invented program names. ELF object names and map names change with the Tethering / Network stack / bpfloader drop; say "cgroup skb ingress/egress programs loaded by bpfloader and owned by netd or the tethering module — check current AOSP."

Analogy

eBPF is a programmable checkpoint bolted onto the highway, not a new highway. Each car (packet) is inspected in-kernel: whose badge (UID), which lane (Network), is this car allowed at night (Doze / standby), should we count it (TrafficStats), should we rewrite the address (CLAT), should we shunt it to the hotspot ramp (tether). xt_qtaguid was a single aging checkpoint design; eBPF is swappable cameras.

bpfloader and attachment

bpfloader (init-started) loads pinned programs and maps from well-known paths under /sys/fs/bpf and module directories (system, Tethering APEX, others). netd's traffic controller and the tethering/clat daemons attach programs to cgroups and interfaces. If bpfloader fails, you often get "data connected, some UIDs mysteriously blackholed" or zero TrafficStats — not necessarily a radio fail.

cgroup skb ingress / egress

The hooks that matter for app sockets are cgroup/skb on ingress and egress. They see the socket's UID/cgroup, can drop, and can account. This is the UID firewall: NetworkPolicyManagerService (Data Saver, rule-based background, parked / standby, doze network off) pushes policy down; the program enforces it on every packet. Cellular metered + Data Saver is the usual "my UID cannot leave" bug after the iface looks fine.

xt_bpf leftover and qtaguid history

Older Android tagged sockets with xt_qtaguid and counted in /proc/net/xt_qtaguid/stats. TrafficStats and Settings data usage grew on that. Modern releases keep the Java API and migrate the backend to eBPF maps. You may still see xt_bpf matches in iptables for a transitional rule, or OEM leftover qtaguid config. Interview line: "TrafficStats is the API; qtaguid is history; eBPF maps are the current counters — confirm on the build."

Doze, App Standby, Data Saver

These are not modem features. They are NetworkPolicyManagerService + netd + eBPF (and some ConnectivityService scoring). Doze shuts app network in idle; App Standby buckets tighten background; Data Saver restricts background UIDs unless allowlisted. Foreground / temporary exemptions punch holes. Power interaction: Power & thermal.

Tethering eBPF and CLAT eBPF

Tethering offload programs rewrite and forward between the downstream iface (wlan AP, USB, BT-PAN) and the upstream Network, with NAT44 or prefix translation, so the AP CPU is not in every forwarded packet. CLAT programs translate IPv4 sockets onto the NAT64 prefix on IPv6-only cellular (and the reverse on downlink). If CLAT eBPF is down, IPv4-only apps fail while IPv6 apps work. Check current AOSP for the ELF names; do not invent clat_foo.o in an interview unless you just read the tree.

Interview angle Name bpfloader, cgroup skb, UID firewall, TrafficStats history, tethering and CLAT as the five Android eBPF stories. Refuse to guess map IDs. Offer bpftool prog show / pinned paths as the way you would confirm.

fwmark and policy routing

Linux routes a packet by looking up a table. Android has many tables (one per Network, plus local/main/default leftovers). The selector that picks the table is an fwmark on the socket or skb, matched by ip rule. Without this, every app would use main and you could not have VPN + Wi-Fi + cellular at once.

Analogy

An fwmark is a coloured wristband at a festival. The rule list is the signage: "green band → tent 100 (cellular netId), blue band → tent 101 (Wi-Fi), gold band → tent 102 (VPN)". The socket receives a band when it is created or bound; bindProcessToNetwork hands every new socket in that process the same band. OEM UID ranges are VIP wristbands issued to platform-signed UIDs so they can be steered without being ordinary apps.

How a socket gets a mark

  1. Default netd / the Network stack apply a per-UID or per-process mark that encodes the current default netId plus permission/protect bits.
  2. Explicit Network Network.bindSocket / bindProcessToNetwork sets the mark for that netId (and typically the "explicitly selected" bit so VPN lockdown and default switches do not steal it).
  3. VPN protect The VPN app's tunnel sockets get a protect mark so they use the underlying Network, not the TUN table.
  4. OEM / privileged UID ranges Platform and OEM reserved AIDs (see android_filesystem_config.h OEM reserved ranges) can have extra rules so system UIDs keep a path when app UIDs are fenced. Quote ranges from the tree on that build; do not memorise unofficial OEM splits.

The bit layout of the 32-bit mark is an AOSP Fwmark contract (netId, permission, explicitlySelected, protect, and related flags). It has been revised. In an interview, draw netId + flags, not a guessed bitfield from memory.

ip rule and per-Network tables

socket (fwmark = netId | flags)
        |
ip rule:  fwmark 0x.../mask  lookup table <netId>
        |
table <netId>:  default via <gw> dev rmnet_data0
                (plus local connected routes)
        |
output dev rmnet_data0  (or wlan0, tun0, clat)

Dump with ip rule and ip route show table all. If the socket's mark does not match a rule, traffic falls through to main, which may have no default, a Wi-Fi default, or a stale route — classic "ping from the shell works, the app does not" (shell UID ≠ app UID) or the reverse.

Common pitfall Debugging routes only in ip route (main table). Cellular defaults almost always live in a numbered table selected by fwmark.

IPv4, IPv6, CLAT/464XLAT, MTU, Private DNS, DNS64

Carriers increasingly hand the UE IPv6-only on the internet APN (IMS was often IPv6 first). Apps and literal IPv4 APIs still exist. Android's answer is 464XLAT, plus DNS64 in the resolver when needed.

Analogy

CLAT is a booth at the edge of an IPv6-only city that wraps your IPv4 postcard in an IPv6 envelope addressed to the city's NAT64 post office (PLAT). You still write an IPv4 address (or you looked up a synthetic AAAA via DNS64). The booth on the phone is CLAT; the post office in the network is PLAT. Together they are 464XLAT. The booth's local IPv4 address is typically in 192.0.0.0/29 (hosts often see 192.0.0.4 on the clat interface) — confirm with ip addr rather than memorising a single host number as law.

ModeWhat the UE hasWhat apps see
IPv4 onlyIPv4 on rmnetIPv4 sockets; no CLAT
Dual stack (IPV4V6)BothHappy Eyeballs races v6/v4; CLAT usually off
IPv6-only + 464XLATGlobal IPv6 + clat ifaceIPv6 natively; IPv4 via CLAT → NAT64 prefix

MTU and MSS

Use the MTU from SetupDataCallResult (and clat's computed MTU, which is smaller because of the extra IPv6 header). PMTUD blackholes are common on operator NATs that drop ICMP. Symptoms: TCP handshake works, small requests work, large POST/TLS records stall. Fix: honour MTU, clamp MSS, or repair ICMP; do not raise MTU blindly.

Private DNS (DoT) and DNS64/NAT64

Private DNS (Off / Automatic / Specified hostname) is implemented in DnsResolver as DNS-over-TLS to the chosen resolver. Strict mode can fail validation of a Network if DoT cannot be established. Automatic typically uses opportunistic DoT and falls back. DNS64: when the APN is v6-only and the resolver (or synthesizer) produces AAAA from A, the app connects to a NAT64 prefix; CLAT is still required for IPv4 literals and IPv4-only stacks that never query AAAA. Android may also learn the NAT64 prefix via PREF64 / router advertisements on some networks — treat the discovery method as version- and carrier-specific.

Interview angle "IPv6-only cellular, IPv4-only app" should produce the words CLAT, PLAT, DNS64, IPv4 literal, and MTU-40-for-the-IPv6-wrapper. Private DNS is a validation and resolver problem, not a bearer problem.

Tethering, VPN, and IMS data-call coexistence

A phone commonly holds several data calls at once. They are different netdevs, CIDs, and Networks. Routing and eBPF keep them from being one bucket of "mobile data".

Internet APN

Default Network for apps when cellular is chosen. Subject to the mobile-data toggle, Data Saver, and validation. Tethering usually SNATs off this Network, or off a dedicated DUN APN if the profile requires it.

IMS APN

Restricted Network for SIP (and media). Not the app default. The mobile-data toggle must not deactivate it or VoLTE/VoNR and SMS-over-IMS die. Details: IMS & VoLTE.

VPN TUN

Overlay default for apps; egress still uses internet Wi-Fi or cellular. IMS and some system sockets stay off the VPN (restricted / protect / OEM rules).

Tethering

Hotspot / USB / BT-PAN: netd + the Tethering module enable forwarding, hand out prefixes or RFC1918 + NAT, and attach eBPF offload. Hardware (IPA example) may forward USB/Wi-Fi ↔ modem without the AP stack. If the carrier requires dun, Telephony brings a second data call; using the default APN for tethering on those carriers is a policy bug, not a routing mystery.

VPN coexistence

Always-on + lockdown: app sockets without the VPN mark are dropped. The IMS iface must remain reachable for the IMS stack (different Network, restricted). Split-tunnel OEM VPNs add more tables; dump ip rule before theorising.

Common pitfall Implementing "mobile data off" as "deactivate every CID". IMS (and often MMS, emergency, carrier FOTA) must stay. That bug shows up as "VoLTE broken when data is off" — see also call flows.

Power: aggregation, modem DRX, chatty sockets

Cellular power is radio tail plus AP wakeup. A correct data path is one that lets both sleep. Broader budget and Doze: Power & thermal.

  • IPA / vendor aggregation — fewer IRQs, less softirq, AP can hit cpuidle and suspend during a bulk transfer if no userspace is scheduled.
  • Modem DRX / C-DRX — connected-mode gaps on the air. Small, frequent packets reset the inactivity timer and keep RF in a high-power connected state (tail energy).
  • Chatty sockets — heartbeats every few seconds (push, analytics, QUIC PING, TLS close/open) defeat both DRX and AP suspend. One persistent multiplexed connection that batches is cheaper than many short connections.
  • Doze / App Standby — eBPF drops or delays background UID traffic so the radio can DRX; exemptions (FCM high priority, foreground) punch holes on purpose.

Interview formula: energy ≈ (radio connected time) × (connected power) + (AP wakeups) × (resume energy). Batching reduces both terms. Offload failure increases only the AP term until the radio is also kept awake by ACKs.

Debug playbook

Work top-down for "no icon", bottom-up for "icon but no packets", and always bisect connected vs validated vs UID-allowed.

Dumps and commands

dumpsys connectivity          # Networks, scores, validation, requests
dumpsys netd                  # netIds, rules netd thinks it installed
dumpsys dnsresolver           # per-netId resolvers, Private DNS, errors
dumpsys telephony.registry    # data connection state, APN, rat
dumpsys telephony_ims         # IMS registration (if present on the build)

ip addr
ip rule
ip route show table all
ip -6 route show table all

# eBPF (if bpftool is on the image or in a debug build)
bpftool prog show
bpftool map show
ls /sys/fs/bpf

tcpdump -i rmnet_data0 -n       # or any ifname from the HAL
# compare with modem / QXDM / vendor log (on-device path varies)

iptables-save
nft list ruleset
dumpsys netpolicy             # Data Saver, UID rules
dumpsys batterystats          # radio and app network attribution

"Connected but no internet" bisect

  1. CID and iface IP — dumpsys telephony.registry / data dump + ip addr. No address: still control plane (APN, reject cause, vendor WDS).
  2. Routes and rules — default in the Network table? fwmark rules present? Main table red herring.
  3. Validation — dumpsys connectivity: VALIDATED vs CAPTIVE vs none. Probe URL, Private DNS, HTTP proxy.
  4. DNS vs IP — ping a literal vs a name from the same UID if you can; resolver dump for SERVFAIL / DoT.
  5. UID policy — Data Saver, standby, VPN lockdown, enterprise. Shell ping succeeding proves little for uid 10123.
  6. CLAT — IPv6 ping works, IPv4 app fails: clat iface, eBPF, NAT64 prefix.
  7. On-air vs on-AP — tcpdump shows uplink but no downlink: modem logs, MTU, core GTP-U, operator NAT. tcpdump empty: never left the stack (fwmark, eBPF drop, wrong dev).
  8. Offload — bulk throughput + high IRQ + high CPU: aggregation/IPA path. Compare with Wi-Fi on the same build.

The map-level version of this list is on Trace a Path Through the Android Stack; use this page's dumps when you are the owner of the bug.

Failure modes

SymptomLikely layerWhat you prove next
No IP on cellular ifaceControl plane: APN, NAS reject, vendor setupFail cause, T3396, getDataCallList, modem NAS
IP present, not VALIDATEDConnectivity / DNS / captive / Private DNSNetworkMonitor probe, resolver, HTTP intercept
IP works, names failDNS / DNS64 / DoTLiteral ping vs hostname; DnsResolver dump
One app blocked, others fineUID eBPF / Data Saver / standby / VPNdumpsys netpolicy, same host via bindSocket
Small transfers work, large stallMTU / MSS blackholeClamp MSS, tcpdump sizes, ICMP filtered?
IPv6 apps work, IPv4-only apps failCLAT / NAT64 prefixclat iface, PREF64, eBPF clat programs
High drain or CPU at good throughputOffload / aggregation / NAPI brokenIRQ rate, softirq, vendor offload stats
VoLTE dies when data toggle offWrong teardown of IMS CIDIMS iface still up? See IMS page
Works on Wi-Fi, fails on cell onlyAPN, IPv6-only, MTU, carrier firewallRepeat bisect bound to TRANSPORT_CELLULAR
Tether clients fail, phone apps workForwarding / NAT / DUN / tether eBPFip_forward, nft NAT, second CID for DUN

Quick revision

  • Control plane leases the PDN/PDU; data plane is every packet after the iface is configured.
  • Camped + registered is not RRC connected; idle uplink needs Service Request.
  • LTE Attach creates a default EPS bearer; 5G Registration does not create a PDU session by itself.
  • Default bearer is always-on IP; dedicated bearers are extra QoS (IMS voice), not how Chrome gets HTTPS.
  • APN (LTE) = DNN (5G). Types: default, ims, mms, dun, fota, emergency, hipri, plus carrier extras.
  • ESM PDN Connectivity / Activate Default EPS Bearer vs 5GSM PDU Session Establishment.
  • GTP-U carries user packets in the core; GTP-C/PFCP builds sessions. The UE speaks NAS, not GTP.
  • DcTracker (pre-13) vs DataNetworkController + DataNetwork + DataRetryManager + AccessNetworksManager.
  • DataService is the pluggable setup API; IWLAN is a DataService, not "just Wi-Fi".
  • Gates: SIM, PS service, data enabled, roaming, DDS, restricted caps, throttle/T3396.
  • Mobile data off must not tear down the IMS data call.
  • IRadioData.setupDataCall / deactivateDataCall; unsolicited dataCallListChanged.
  • SetupDataCallResult: cause, cid, ifname, addresses, dnses, gateways, mtu(V4/V6), pduSessionId, trafficDescriptors.
  • Vendor maps HAL to QMI WDS (Qualcomm example) or the SoC equivalent — do not invent TLVs.
  • ifname comes from the vendor/kernel, not from Java constructing a string.
  • rmnet_data / ccmni / generic wwan: one netdev per data call; QMAP mux+agg is a Qualcomm-example header.
  • IPA (Qualcomm example) offloads route/filter/NAT/aggregation; other SoCs have equivalents.
  • netd applies addresses, rules, routes, firewall/eBPF; Java uses INetd AIDL, not Runtime.exec("ip").
  • ndc is a remnant text interface; still useful to read, not the modern control path.
  • DnsResolver owns stub DNS, Private DNS (DoT), and often DNS64 synthesis.
  • ConnectivityService: NetworkAgent, capabilities, score, validation, VPN overlay.
  • VALIDATED is not the same as "iface has an IP".
  • bindProcessToNetwork vs Network.bindSocket vs default Network.
  • Restricted Networks (IMS/MMS) never become the ordinary app default.
  • eBPF: bpfloader, cgroup skb in/out, UID firewall, stats, tethering, CLAT — check current AOSP names.
  • TrafficStats API stayed; xt_qtaguid is history; counters live in eBPF maps now.
  • Doze / App Standby / Data Saver are netd+eBPF policy, not NAS.
  • fwmark + ip rule select the per-Network routing table; dump table all, not only main.
  • VPN protect mark keeps tunnel sockets off the TUN table.
  • OEM reserved UID ranges can have extra policy rules; quote android_filesystem_config.h for the build.
  • Uplink: OkHttp → ART → bionic → tcp_sendmsg → skb → nft/eBPF → route → CLAT? → rmnet → offload → PDCP… → GTP-U → NAT → server.
  • TCP SYN uses the same path as later data; QUIC uses udp_sendmsg.
  • MSS = MTU − IP − TCP (40 v4, 60 v6, minus options).
  • Downlink: offload aggregation, NAPI, GRO, softirq, then socket queue / epoll — not per-packet hardirq.
  • IRQ rate ≈ pps / aggregation depth when offload is healthy.
  • 464XLAT = CLAT on the UE + PLAT (NAT64) in the network; DNS64 synthesises AAAA from A.
  • IPv4 literals on v6-only need CLAT even if DNS64 exists.
  • Private DNS (DoT) can fail validation independently of the bearer.
  • Tethering may require a DUN APN; hardware may forward without the AP stack.
  • Chatty sockets kill modem DRX and AP suspend; batch and multiplex.
  • Bisect no-internet: CID/IP → rules/routes → validation → DNS → UID → CLAT → tcpdump vs modem → offload.
  • MTU blackhole: handshake works, large segments die; ICMP often filtered on cellular.
  • Shell ping ≠ app UID. Always ask which UID you just tested.

Glossary

5GMM / 5GSM
5G NAS mobility management (AMF) and session management (SMF). Registration is 5GMM; PDU sessions are 5GSM.
464XLAT
CLAT on the customer side plus PLAT (NAT64) in the network so IPv4 sockets work on IPv6-only access.
AccessNetworksManager
Telephony component that prefers cellular vs IWLAN (and related access) for a data call.
AMF
Access and Mobility Function in the 5G core; terminates 5GMM.
APN
Access Point Name; the LTE name of a packet data network. 5G name is DNN.
ApnContext
Pre-Android 13 object tracking one APN type's desire for a DataConnection.
bpfloader
Init service that loads Android's pinned eBPF programs and maps. Confirm paths on the build.
Captive portal
Network that intercepts HTTP(S) until a sign-in; validation marks CAPTIVE_PORTAL instead of a clean VALIDATED.
CCMNI
MediaTek cellular netdev family (ccmniN), one interface per data call.
cgroup skb
eBPF hook on packets associated with a cgroup; Android's UID firewall and accounting attach here.
CID
Connection id assigned by the modem for a data call; argument to deactivate and list queries.
CLAT
Customer-side translator: IPv4 (typically 192.0.0.0/29) to IPv6 toward a NAT64 prefix.
ConnectivityService
system_server owner of Networks, requests, scoring, validation and binding.
DataNetwork
Android 13+ state machine for one active telephony data connection.
DataNetworkController
Android 13+ per-Phone orchestrator that replaced DcTracker.
DataProfile
Framework object for an APN/DNN plus protocol, auth and 5G extras (slice, traffic descriptor).
DataRetryManager
Applies carrier retry/backoff and network-provided timers such as T3396.
DataService
android.telephony.data.DataService: pluggable implementer of setup/teardown (RIL or IWLAN).
DcTracker
Pre-13 data connection tracker; still in logs and older branches.
Dedicated bearer
Extra LTE EPS bearer for QoS on an existing PDN (for example QCI 1 voice).
Default EPS bearer
The always-on bearer created at LTE attach (or additional PDN connect) that carries general IP.
DNN
Data Network Name; 5G name for APN.
DnsResolver
Android stub resolver (DoT, per-netId servers, DNS64). Split out of classic netd.
DoT
DNS-over-TLS; what Private DNS uses.
DRB
Data Radio Bearer on the air interface; carries user plane after PDCP.
DRX
Discontinuous reception; modem sleeps between monitoring occasions. Chatty traffic defeats it.
DSD
Qualcomm QMI Data System Determination example: which RAT should carry data.
DUN
Dial-Up Networking APN type used by some carriers for tethering.
eBPF
Extended Berkeley Packet Filter; in-kernel programs Android uses for UID policy, stats, tethering and CLAT.
EMM / ESM
LTE NAS mobility and session management. Attach is EMM; PDN/bearer is ESM.
ePDG
Evolved Packet Data Gateway; IPsec peer for IWLAN.
fwmark
32-bit firewall mark on a socket/skb used with ip rule to select a Network's routing table.
GRO
Generic Receive Offload; kernel merging of incoming segments before TCP.
GTP-C
GTP control plane in LTE EPC (session/bearer signalling between core nodes).
GTP-U
GTP user plane; tunnels UE IP packets (S1-U, S5, N3, N9).
HIPRI
High-priority mobile APN/type used to request cellular while another default exists.
ifname
Kernel interface name returned in SetupDataCallResult.
INetd
AIDL interface to the netd daemon.
IPA
IP Accelerator; Qualcomm example of hardware data-path offload. Other SoCs have equivalents.
IRadioData
Radio HAL interface for data calls: setup, deactivate, profiles, keepalive, slicing helpers.
IWLAN
Untrusted WLAN access to the packet core via IPsec to an ePDG; still a cellular session.
MSS
Maximum Segment Size; TCP payload per segment, derived from MTU minus headers.
MTU
Maximum Transmission Unit; largest IP packet the path claims to carry.
NAPI
New API; kernel polling of a nic under load so the CPU is not hardirq-per-packet.
NAT64 / PLAT
Provider-side translator from IPv6 to IPv4; the network half of 464XLAT.
ndc
Legacy netd command-line/text protocol; remnant beside INetd.
netd
Native daemon that programs interfaces, policy routing, firewall/eBPF and related kernel state.
NetworkAgent
Producer of a Network (telephony, Wi-Fi, VPN, Ethernet) into ConnectivityService.
NetworkRequest
App or system request for a Network matching a capability filter.
PCO
Protocol Configuration Options; NAS container for DNS, P-CSCF and similar.
PDN
Packet Data Network connection (LTE name for the IP session to an APN).
PDCP
Packet Data Convergence Protocol; ciphering, integrity, ROHC, reordering on the radio user plane.
PDU session
5G IP (or Ethernet/unstructured) session to a DNN, anchored at a UPF.
PFCP
Packet Forwarding Control Protocol on N4 (SMF controls UPF). 5G replacement for much of GTP-C on that hop.
P-GW
PDN Gateway; LTE user-plane anchor and often NAT to the Internet.
PREF64
RA option that can advertise a NAT64 prefix to the UE.
Private DNS
User setting that forces or prefers DoT in DnsResolver.
QFI
QoS Flow Identifier inside a 5G PDU session / GTP-U header.
QMAP
Qualcomm Multiplexing and Aggregation Protocol example header on the AP–modem link.
qtaguid
Legacy xtables module for per-UID traffic tags and stats; replaced in spirit by eBPF.
QMI WDS
Qualcomm Wireless Data Service example: vendor IPC to start/stop packet data.
rmnet
Qualcomm kernel driver family exposing modem data calls as rmnet_dataN interfaces.
RRC
Radio Resource Control; idle/inactive/connected and bearer setup on the air.
SetupDataCallResult
HAL structure returned after setup: cause, cid, ifname, addresses, DNS, routes, MTU, 5G extras.
sk_buff
Linux socket buffer; the packet object in the kernel stack.
SMF
Session Management Function; 5G owner of PDU sessions.
softirq
Deferred kernel interrupt processing; NAPI poll and much of TCP input run here.
T3346 / T3396
3GPP back-off timers (mobility congestion / per-APN session management). Framework must honour them.
TelephonyNetworkFactory
Offers cellular Networks to ConnectivityService; live on the preferred data subscription.
TrafficDescriptor
URSP match key (application id, DNN, IP descriptors, connection capabilities) carried into setup and the HAL result.
TrafficStats
SDK API for per-UID bytes/packets; backend moved from xt_qtaguid to eBPF maps.
TUN
Virtual iface used by VpnService; typically the default Network while the tunnel egresses on Wi-Fi or cellular.
UPF
User Plane Function; 5G gateway that terminates N3 GTP-U and forwards on N6.
URSP
UE Route Selection Policy; rules from the PCF that map traffic to a DNN, slice and session.
VALIDATED
NetworkCapabilities flag set after a successful connectivity probe (and related checks).
VPN protect
fwmark/socket option that exempts the VPN's own tunnel sockets from the VPN routing table.
WDS
Wireless Data Service; Qualcomm QMI example for PDN/PDU start and stop.
wwan
Generic kernel subsystem / iface name some SoCs use instead of rmnet or ccmni.
xt_bpf
iptables match that runs an eBPF program; leftover on devices still using xtables.
xt_qtaguid
Legacy per-UID tagging and stats module; historical TrafficStats backend.

Interview questions

Fundamentals

What are the two planes of a cellular data call?

The control plane leases the session: APN/DNN policy, IRadioData.setupDataCall, NAS ESM or 5GSM, CID, IP, DNS, MTU, and netd plus a NetworkAgent. The data plane is every packet after that: socket, kernel, eBPF, fwmark, optional CLAT, vendor netdev/offload, modem user plane, RAN, GTP-U, NAT, server, and the reverse. Signalling that leased the lane is not the HTTPS payload.

Why do interviewers fail answers that mix control and data plane?

Because the bugs and the owners differ. A NAS reject is not an fwmark bug. An eBPF UID drop is not a missing default bearer. A strong answer names both planes in one sentence, then stays on the plane the question asked. The map is on Trace a Path Through the Android Stack; this page is the walk.

What is an APN, and what is a DNN?

An APN (Access Point Name) is the LTE name of the packet data network the UE asks to join (internet, ims, mms, …). DNN (Data Network Name) is the same idea in 5G. Android stores them in the telephony provider as types and protocols; the modem puts the name in ESM/5GSM.

Name the common APN types and what each is for.

default is app internet; ims is IMS SIP/media; mms is MMSC; dun is tethering on carriers that require it; fota is carrier firmware; emergency is emergency IMS; hipri is explicit/high-priority cellular while another default exists. Others (supl, xcap, ia) are carrier-specific. Types are capabilities, not ifnames.

What is a default EPS bearer?

The always-on LTE IP bearer created at attach (or at an additional PDN connect). It has a QCI (often 9 for internet, 5 for IMS signalling) and carries general packets. Android apps use this bearer for HTTPS. It is not a dedicated GBR voice bearer.

What is a dedicated bearer?

An extra LTE EPS bearer on an existing PDN for a different QoS (classic example: QCI 1 conversational voice after IMS talks to the PCRF). Chrome does not open one for a web request. See IMS & VoLTE.

What is a PDU session?

The 5G IP (or Ethernet/unstructured) connection to a DNN, anchored at a UPF, identified by a PDU session id. QoS inside it is QoS flows (QFI), not one GTP tunnel per QCI. Radio-deep detail: 5G NR.

How does LTE attach differ from 5G registration for data?

LTE Attach includes ESM PDN connectivity and activates a default EPS bearer, so the UE is "always on IP" at attach. 5G Registration (5GMM) only makes the UE known to the AMF. A PDU session (5GSM) is a separate request. NSA still uses an EPC PDN for internet even if NR is aggregated.

What does "camped" mean, and is that enough for data?

Camped means the UE selected a suitable cell and is listening there. Data also needs registration (core context) and a session (default bearer or PDU session), and for the user plane to flow it needs RRC connected (or a resume from RRC_INACTIVE) plus a configured iface. Bars are not a bearer.

RRC idle versus RRC connected: can packets flow?

Not in idle. Uplink data triggers a Service Request and RRC establishment (or INACTIVE resume). Downlink data is paged first. Once RRC connected and a DRB exists for the session, user-plane PDUs can flow. See telephony / RIL.

What replaced DcTracker, and why?

Android 13 introduced DataNetworkController (one per Phone) and DataNetwork per live connection, with DataProfileManager, DataRetryManager, DataSettingsManager and AccessNetworksManager. DcTracker plus ApnContext plus DataConnection spread bring-up, retry and handover across racing state machines. The new stack is request-driven with logged evaluation reasons.

What is IRadioData.setupDataCall?

The Radio HAL method that asks the vendor/modem to create a PDN or PDU session. Arguments include access network, data profile, roaming flag, reason (normal/handover/shutdown), optional handover addresses/DNS, and 5G fields (pduSessionId, slice, traffic descriptors). The async result is SetupDataCallResult. Confirm the current AIDL; lists move by version.

What is a CID in the data-call result?

A modem-local connection identifier. Android uses it to deactivate the call, match getDataCallList / dataCallListChanged, and target keepalives. CIDs do not survive a modem restart.

What is ifname in SetupDataCallResult?

The kernel netdev the vendor created or will use (rmnet_data0, ccmni0, …). Java does not invent it. netd then adds addresses and policy on that name. An empty ifname with a success cause is a vendor bug.

What is netd?

Android's privileged native network daemon. ConnectivityService and related services call it over Binder (INetd). It applies interface addresses, ip rule/ip route, firewall and eBPF policy, and coordinates tethering pieces. It is the traffic office, not the mayor (ConnectivityService) and not the modem.

What is eBPF used for on Android's data path?

In-kernel programs for UID accounting, UID firewall (Data Saver, Doze, App Standby), tethering offload and CLAT. bpfloader loads them; netd and the Tethering module attach them (cgroup skb is the hook to name). They replaced most of xt_qtaguid. Do not invent ELF names; check current AOSP.

What is fwmark?

A 32-bit mark on a socket or skb. Android encodes the Network id and flags (explicit bind, VPN protect, permissions). ip rule matches the mark and selects that Network's routing table. That is how dual networks and VPN overlay work.

What is rmnet?

Qualcomm's kernel net driver family for modem data. Each data call is a Linux iface, typically rmnet_dataN, multiplexed on the AP–modem link (QMAP). The kernel IPv4/IPv6 stack sees a normal netdev. Other SoCs use ccmni or wwan.

What is IPA and why does it matter?

IPA (IP Accelerator) is the Qualcomm-example hardware offload between modem, AP memory and peripherals. It can route, filter, NAT and aggregate so the AP is not interrupted per packet and can sleep during bulk transfer. Other SoCs have equivalent engines. If it is broken, throughput may still work but power and CPU will not.

What is QMAP?

Qualcomm Multiplexing and Aggregation Protocol: a vendor header that maps packets to a mux id (PDN) and can pack several packets in one transfer. It is not a 3GPP name. Other vendors multiplex too.

What is CLAT / 464XLAT?

CLAT is the phone-side translator from IPv4 sockets to IPv6 toward a NAT64 prefix (typical local range 192.0.0.0/29). PLAT is NAT64 in the network. Together they are 464XLAT, which lets IPv4-only apps work on IPv6-only cellular. DNS64 synthesises AAAA from A; IPv4 literals still need CLAT.

What is ConnectivityService?

The system_server service that owns Networks: agents, capabilities, scoring, validation, callbacks, default Network, and process/socket binding. Apps should not parse rmnet_data0 themselves. See Android frameworks.

What is a NetworkAgent?

The object a provider (telephony, Wi-Fi, VPN, Ethernet) uses to publish a Network and its NetworkCapabilities / score / link properties into ConnectivityService. Telephony uses a TelephonyNetworkAgent after a successful data call.

What is Network validation?

A probe (typically HTTPS to a connectivity URL, plus related checks) that sets NET_CAPABILITY_VALIDATED. An iface can have an IP and still fail validation (captive portal, DNS, Private DNS, blackholed HTTP). Unvalidated internet Networks usually do not become the happy default.

What is bindProcessToNetwork?

A ConnectivityManager API that forces that process's default routing/mark onto a specific Network until cleared. Network.bindSocket does one file descriptor. Neither changes the system default for other apps.

Does the mobile-data toggle tear down IMS?

It must not. IMS uses a separate APN/DNN and a restricted Network. Voice, SMS-over-IMS and incoming INVITEs depend on it. A bug that deactivates every CID when data is off breaks VoLTE/VoNR. See IMS & VoLTE.

What is GTP-U versus GTP-C?

GTP-U tunnels user IP packets in the core (S1-U, S5/S8, N3, N9). GTP-C (LTE) signals session/bearer create and delete between core nodes. 5G SMF–UPF control is PFCP on N4, not classic GTP-C. The UE never implements GTP; it speaks NAS and sees a local IP.

What is a NetworkRequest?

A filter for transports and capabilities that ConnectivityService matches against offered Networks. The system requests default internet; apps and telephony request IMS, MMS, or a bound cellular Network. Satisfying a request is what triggers DataNetworkController to set up a call.

What is DnsResolver?

The Mainline/network-stack resolver that performs stub DNS per netId, Private DNS (DoT), and often DNS64. It is no longer "just a function inside netd" on modern releases. dumpsys dnsresolver (name may vary slightly) is the dump to name.

What is Private DNS?

A user setting (Off / Automatic / specified hostname) that sends DNS over TLS. Strict specified mode can keep a Network from validating if DoT cannot be established. It is a resolver/validation issue, not a missing bearer.

What is TrafficStats, and where do the numbers come from now?

TrafficStats is the SDK for per-UID and per-tag byte/packet counters. Historically xt_qtaguid and /proc/net/xt_qtaguid/stats. Modern Android stores the same idea in eBPF maps via netd's traffic controller. The Java API stayed; the kernel backend changed.

What is Data Saver at the packet layer?

A NetworkPolicyManagerService policy that netd programs into eBPF (and leftover xtables): background UIDs are blocked or restricted on metered Networks unless allowlisted or foreground-exempt. The modem and APN are usually fine; one UID is not.

What is HIPRI in the APN list?

A high-priority / explicit-cellular type used so a request can bring or use mobile data while Wi-Fi is the default (legacy TYPE_MOBILE_HIPRI and similar). It still appears in APN databases. It is not a 3GPP QoS class.

What addresses, DNS and MTU fields should you name from SetupDataCallResult?

At minimum: addresses (with prefix), dnses, gateways, and mtu or the split mtuV4/mtuV6. Also mention cause, cid, ifname, pduSessionId and trafficDescriptors on 5G. P-CSCF and QoS sessions if the dump has them.

Going deeper

Walk the control plane from a NetworkRequest to a validated default Network.

ConnectivityService matches the request. TelephonyNetworkFactory (on the DDS via PhoneSwitcher) gives it to DataNetworkController. Evaluation checks SIM, PS service, data enabled, roaming, throttle. DataProfileManager picks a profile. DataNetwork calls setupDataCall. The modem runs ESM or 5GSM. The result supplies cid, ifname, addresses, DNS, MTU. netd programs the netdev and policy routing. A TelephonyNetworkAgent is registered. NetworkMonitor probes; success adds VALIDATED and the Network can become default if it wins scoring versus Wi-Fi/VPN.

What is DataService, and when is it not the Radio HAL?

android.telephony.data.DataService is the pluggable setup/teardown API. The default implementation talks to IRadioData. IWLAN (and some OEM transports) ship another service that builds an IPsec tunnel to an ePDG and still returns ifname, addresses and DNS. Telephony should not assume every setup is QMI WDS.

How does IWLAN / Wi-Fi offload work at a high level?

AccessNetworksManager prefers IWLAN. The IWLAN DataService establishes IPsec to the ePDG; the session is still a PDN/PDU in the core. setupDataCall can pass a handover reason and existing addresses so the IP is preserved. Apps keep the same Network on success. It is not "just Wi-Fi browsing."

How does the Radio HAL relate to QMI WDS?

AOSP stops at IRadioData. The vendor radio process maps setup/deactivate onto chipset IPC. On Qualcomm-based designs the usual example is QMI WDS (start/stop network, profiles, packet status) plus DSD for RAT choice. Other SoCs use their own RPC. Debug HAL cause and vendor logs; do not invent QMI TLVs in an interview.

How do addresses actually appear on rmnet_data0?

The vendor/kernel creates and often pre-configures the netdev. Telephony passes HAL addresses to ConnectivityService / netd. netd sends RTNetlink RTM_NEWADDR (and link up, MTU). You verify with ip addr show dev …. IPv6 link-local may exist before the global address from the result is added.

What is the difference between ip rule and ip route on Android?

ip route entries live in a table (main, or table 100 for a netId). ip rule chooses which table to use, matching fwmark, and sometimes UID or iif. If you only dump ip route you miss the cellular default that lives in a numbered table. Always ip rule plus ip route show table all.

How does a socket get an fwmark?

The Network stack / netd apply a default mark from the UID's current default Network. bindProcessToNetwork or Network.bindSocket sets an explicit netId (and typically an "explicitly selected" flag). VPN protect() sets a protect flag so tunnel sockets use the underlying Network. Exact bit layout is the AOSP Fwmark contract and has been revised — draw netId + flags, do not recite a stale bitfield.

When do you use bindProcessToNetwork versus Network.bindSocket?

Process bind: every new socket in that process should stay on one Network (a carrier app talking only to the MMS Network; a diagnostic tool). Socket bind: one connection (a backup upload on cellular while Wi-Fi is default). Prefer the narrower API. Remember to clear process bind.

What is a restricted Network?

A Network that lacks NET_CAPABILITY_NOT_RESTRICTED. IMS, MMS, FOTA typically. Ordinary apps never receive it as the default internet Network. Privileged components request the matching capability. This is how IMS traffic stays off Chrome.

What is PhoneSwitcher / DDS in the data path?

On DSDS, only the preferred data subscription should satisfy default internet requests. PhoneSwitcher activates TelephonyNetworkFactory on that Phone. The other SIM may still have IMS. Wrong DDS looks like "SIM 2 has bars but apps have no data."

What are T3396 and T3346, and who honours them?

T3396 is per-APN session-management back-off after an ESM/5GSM reject (for example insufficient resources). T3346 is mobility-management congestion back-off. The modem reports a suggested retry time; DataRetryManager must not tight-loop. Permanent causes (unknown APN, not subscribed) should stop until APN/SIM/settings change.

Why can a device have several rmnet or ccmni interfaces at once?

Each data call is a netdev: internet, IMS, sometimes MMS, DUN, emergency, enterprise slice. Separate IPs, DNS, QoS and routing. IMS can stay up when the internet CID is torn down. QMAP muxes them on one physical link on Qualcomm-style designs.

How do DNS64 and CLAT differ, and when do you need both?

DNS64 synthesises AAAA from A so an IPv6-capable stub can connect toward NAT64. CLAT translates IPv4 packets the app already formed (literals, IPv4-only stacks) onto the NAT64 prefix. IPv6-only cellular with an IPv4-only app needs CLAT even if DNS64 exists. Dual-stack usually needs neither.

How are MTU and MSS related on cellular?

MSS = MTU − IP − TCP. IPv4 without options: MTU − 40; IPv6: MTU − 60; TCP options shrink it more. CLAT adds an IPv6 wrapper, so the IPv4-facing MSS is smaller. Honour SetupDataCallResult MTU. If a core hop is smaller and ICMP is filtered, large segments blackhole while SYNs succeed.

How is a captive portal different from "no internet"?

Captive: the probe is redirected or a sign-in page is detected; capability CAPTIVE_PORTAL; user can authenticate. No internet: probe times out or fails; iface may still have DHCP/PDN IP; apps should not treat it as default. Both show "connected" in casual speech; dumpsys connectivity distinguishes them.

What is VPN protect and why does the tunnel need it?

If the VPN is the default Network, the VPN app's own UDP/ESP/TCP sockets to the concentrator would be routed into tun0 and loop. protect() / the protect fwmark sends those sockets out the underlying Wi-Fi or cellular table. Lockdown still blocks everyone else.

When does tethering use a DUN APN instead of default?

When the carrier profile requires dun so hotspot traffic is billed or filtered separately. Telephony must bring a second data call. Using only the default APN on those carriers is a policy bug. Hardware offload (IPA example) may then forward USB/Wi-Fi to that CID.

How did cgroup skb replace xt_qtaguid?

qtaguid tagged sockets and counted in a proc file, with iptables matches in the forwarding path. cgroup/skb eBPF programs attach to the UID's cgroup, drop or account in-kernel, and export maps to userspace. TrafficStats kept the API. You may still see xt_bpf or OEM qtaguid leftovers; say "confirm on the build."

What does bpfloader do?

An init-started service that loads pinned eBPF objects into /sys/fs/bpf (and module paths). If it fails, firewall and stats programs may be missing: UIDs blackholed or TrafficStats stuck at zero while radio looks fine. Check current AOSP for ELF names; do not invent them.

Is ndc still a valid interview answer?

As a remnant you can still dump (ndc network list, ndc resolver dump), yes. As the production control path, no: ConnectivityService uses INetd AIDL. Say both sentences.

What is INetd?

The Binder/AIDL interface to netd (android.net.INetd and related module AIDL). Only system_server and a short allowlist may call it. It is how Java creates netIds, attaches ifaces, adds routes, and pushes firewall/tether operations. See Binder & AIDL.

Which NetworkCapabilities matter for cellular internet?

TRANSPORT_CELLULAR, INTERNET, NOT_RESTRICTED (for app default), VALIDATED, NOT_METERED (usually absent on cell), and sometimes FOREGROUND. IMS/MMS/DUN/FOTA are extra capabilities on restricted Networks. Slice/enterprise flags appear on recent releases for URSP.

How does scoring choose Wi-Fi versus cellular?

ConnectivityService ranks validated Networks. Validated Wi-Fi typically wins default over cellular. Unvalidated or lost Wi-Fi yields to cellular. VPN overlays both. Explicit binds ignore the default winner. Quote the current score policy as "prefer-policy + capabilities," not a memorised integer from an old release.

What is PCO, and what does Android do with it?

Protocol Configuration Options in NAS: DNS, P-CSCF, MTU, and other extras. The modem surfaces them in the HAL result (dnses, pcscf, mtu). Telephony hands DNS to the resolver and P-CSCF to IMS. You do not parse PCO in an app.

What are traffic descriptors and URSP on Android?

URSP rules from the PCF map app traffic to a DNN/slice. Android carries a TrafficDescriptor (app id, DNN, IP descriptors, connection capabilities) into setupDataCall and may get matching descriptors back. That can yield a second PDU session. Check current AIDL struct names. Deep 5G: 5G NR.

When do you deactivate versus wait for dataCallListChanged?

Framework teardown (no requests, data off for that APN, shutdown) calls deactivateDataCall(cid, reason). The network or modem can drop the session and notify via dataCallListChanged / list poll. After radio reset the list is empty; do not deactivate stale CIDs as if they still exist.

An IPv4-only app on an IPv6-only APN — what must be up?

CLAT (clat iface + translator, often eBPF) and a NAT64 prefix (DNS64 and/or PREF64). IPv6 ping succeeding is not enough. If CLAT is down, only dual-stack-aware apps work. Confirm with ip addr and a literal IPv4 connect.

Why can adb shell ping succeed when an app fails?

Shell UID is not the app UID. eBPF / Data Saver / standby / VPN lockdown may allow the shell and drop the app. Also the shell may not use the same fwmark (explicit routing, ping bind). Always retest as the failing UID or with bindSocket.

How does QUIC differ from TCP on this Android path?

Same control plane, same fwmark, eBPF, CLAT, rmnet, offload, GTP-U. The kernel send path is udp_sendmsg instead of tcp_sendmsg. There is no kernel TCP handshake; the first datagram is already QUIC. NAT sees UDP/443. Loss recovery is in userspace (Cronet), not the kernel TCP stack.

What is NAPI, and why do you mention it on downlink?

NAPI is the kernel's poll mode for a busy nic: disable per-packet hardirq, poll a budget in softirq (or a NAPI thread), then re-enable IRQs. Combined with GRO and vendor aggregation, the AP is not interrupted once per GTP-U packet. See Linux Kernel & BSP.

What does setInitialAttachApn / setDataProfile do?

They push the initial-attach profile and the full APN list to the modem so LTE attach and later additional PDNs use the right names and protocols. Wrong initial attach is a common "attached but no useful IP" or "IMS used as internet" bug. They are IRadioData methods, not netd.

What is setDataAllowed versus the user data toggle?

The user/policy toggle is framework state (DataSettingsManager). setDataAllowed tells the modem whether PS data is permitted (DSDS, provisioning, policy). Both must agree for the internet APN. IMS is gated separately. Dump both if "data enabled" in UI disagrees with the modem.

What is a dormant data call?

The session and IP still exist, but the user plane is idle (often RRC idle/inactive). The HAL may report a dormant/active flag. The next packet triggers service request. Do not treat dormant as "no data call" and tear down IMS.

How does Doze actually stop background packets?

Not by detaching the PDN. NetworkPolicyManagerService marks UIDs; netd updates eBPF so those sockets cannot egress (and often cannot ingress) until a maintenance window or exemption (high-priority FCM, foreground). The modem can DRX. Power: Power & thermal.

Advanced

Why is downlink not "uplink with the arrows reversed"?

Uplink is mostly process-context send and ndo_start_xmit. Downlink is interrupt- and poll-driven: vendor aggregation (one IRQ per batch), NAPI poll in softirq, GRO, then the socket wait queue / epoll. The AP's IRQ rate and wakeup pattern are designed to be batched. Saying "the modem interrupts once per packet" is the junior answer on a healthy offload path.

Give a formula for IRQ reduction from aggregation.

IRQs/s ≈ (packets/s) / A, where A is the aggregation depth actually achieved by QMAP/IPA/NAPI coalescing. At 80 000 pps and A = 16 you are near 5 000 IRQs/s instead of 80 000. If A collapses to 1, softirq and power look like a cellular drain bug at the same throughput. Measure IRQ deltas and vendor offload stats; do not assume A from a datasheet.

How do GRO and segmentation offload fit this story?

GRO merges eligible downlink segments so TCP and eBPF see fewer, larger skbs. On uplink, GSO/TSO (if enabled on the path) lets the stack pass a large skb that the nic or offload splits. Cellular vendors often segment in IPA or the modem. If someone disabled GRO for a "latency" experiment, CPU and eBPF cost jump. Confirm features on the netdev rather than assuming PC nic behaviour.

Where does Android attach eBPF, and what must you not invent?

Name cgroup/skb ingress and egress for UID policy and stats; tethering and CLAT programs on the relevant ifaces (owned by the Tethering module / clatd). xt_bpf may remain in iptables. Do not recite unofficial ELF names like a guessed clat_foo.o unless you just read that tree. Say "bpfloader pins objects under /sys/fs/bpf; I would bpftool prog show on the build."

How should you talk about the fwmark bitfield in an interview?

Say it is a 32-bit AOSP contract that encodes netId plus flags (explicitly selected, protect, permission, and related). It has been revised. Draw the idea, not a remembered bit table from a random year. Offer to read Fwmark.h / Network stack sources on the branch under test.

What are OEM reserved UID ranges, and why do they appear in ip rule?

AOSP android_filesystem_config.h reserves AID ranges for OEM system UIDs (historically including 2900–2999 and 5000–5999; confirm on the tree). Extra ip rule or eBPF exceptions can keep those UIDs on a path when ordinary app UIDs are fenced (VPN lockdown variants, OEM routing). Quote the header for that build; do not invent a vendor-specific split.

CLAT in eBPF versus a userspace translator — what is the interview-safe statement?

Android has moved CLAT toward in-kernel eBPF for the hot path, with a userspace helper (clatd / tethering code) for setup, addresses and prefix discovery. The exact split is version-specific. Symptom of a broken CLAT path: IPv6 apps work, IPv4 literals and IPv4-only APIs fail. Check current AOSP rather than naming a single ioctl.

How can tethering bypass the AP network stack?

When hardware forward is programmed (IPA is the Qualcomm example), packets between USB/Wi-Fi AP and the modem CID are switched/NATed in the offload engine. tcpdump on rmnet_data0 may miss them. Debug vendor offload counters plus client-side captures. If offload falls back to software, CPU and eBPF tethering programs take the load.

Why is PFCP not the same as GTP-C, and why does the phone not speak either?

LTE core uses GTP-C between MME/S-GW/P-GW to build tunnels. 5G SMF controls the UPF with PFCP on N4. The UE only runs NAS (ESM/5GSM) and RRC. Interviewers use this to see if you stuffed the whole core into the modem. User packets in the core are still GTP-U on N3/N9 or S1-U/S5.

How does a 5G QoS flow differ from an LTE dedicated bearer on the packet path?

LTE: another EPS bearer, often another GTP-U TEID, another DRB. 5G: one PDU session / N3 tunnel; QFI in the GTP-U header; SDAP maps flows to DRBs. Android still sees one ifname per PDU session unless a second session is created. Apps do not pick QFI for HTTPS. See 5G NR.

What is matchAllRuleAllowed in setup?

A 5G/URSP-related flag on recent HAL versions meaning the UE may use a match-all URSP rule for this request. If you are not sure of the exact semantics on the AIDL you shipped, say so and describe URSP match versus default DNN. Do not invent a QMI field to match the name.

How does handover setupDataCall preserve the IP?

The reason is handover; the request includes the existing addresses (and often DNS). The new access (IWLAN or the other RAT) should accept the same UE IP so TCP/QUIC sessions survive. Failure modes include the network assigning a new IP (sessions die) or HAL handoverFailureMode telling the framework to retry or fall back. ConnectivityService may keep or replace the Network object depending on the agent implementation — describe the IP-preservation goal, then check the dump.

How can Private DNS fail a Network that has a working bearer?

Strict DoT to a configured hostname must complete. If the resolver is blocked, the certificate does not match, or the bootstrap DNS for the DoT name fails, validation can fail even though ping to a literal works. Automatic/opportunistic mode is more forgiving. Dump DnsResolver and the validation attempt, not only ip addr.

How does CLAT change the MTU blackhole story?

IPv4 packets grow by a 40-byte IPv6 header (plus any extension headers). The clat iface MTU must be the IPv6 MTU minus that overhead. If you honour 1500 on the IPv4 socket while the IPv6 path is 1280, large IPv4 writes fragment or blackhole. Always take MTU from HAL + clat, and clamp MSS.

What is setDataThrottling for?

An IRadioData API so the framework can ask the modem to reduce throughput (thermal, data-limit policies). It is not eBPF Data Saver. If thermal mitigation "kills data," check this path and modem throughput caps as well as AP CPU thermal. See Power & thermal.

How do nftables and iptables coexist on Android data devices?

Newer releases prefer nftables; compatibility layers and OEM remnants still show iptables tables (mangle for marks, filter for UID). netd/eBPF own the modern UID path. In debug, run both nft list ruleset and iptables-save, and believe the one that actually has counters incrementing.

How do you explain dual Wi-Fi + cellular without waving hands?

Two NetworkAgents, two netIds, two tables, two marks. Default scoring picks one for unbound sockets. MMS/IMS/HIPRI or bindSocket use the other. OEM dual-STA adds more Wi-Fi Networks. MultipathPreference is policy on which extra path may be used; it is not a second TCP stack inside the kernel.

How does lockdown VPN coexist with IMS?

Lockdown drops app sockets that are not on the VPN Network. IMS uses a restricted Network and privileged UIDs; those sockets must remain on the IMS iface (or a documented exemption). A lockdown implementation that installs a catch-all drop without exempting the IMS netId breaks VoLTE. Dump ip rule and netpolicy together.

Why do chatty QUIC PINGs or HTTP/2 pings drain cellular like a failed suspend?

Each small packet can restart the modem's connected-mode inactivity timer (tail energy) and schedule the AP (epoll, ART, TLS). Aggregation never gets a full batch. Energy ≈ radio connected time × connected power + wakeups × resume energy. Batch, lengthen ping intervals, or use FCM instead of an app heartbeat. See power.

Trace uplink data when the UE is RRC idle.

The first tcp_sendmsg still builds an skb, but the modem has no DRB. NAS Service Request (or NR resume from INACTIVE) plus RRC runs on the control plane; then the same skb path can hit the air. Mixing "the SYN is a Service Request" is wrong: Service Request is NAS; SYN is TCP after the user plane is back. Timing: you will see a delay before tcpdump on the iface and a longer delay on the air.

Where does internet traffic go in NSA (EN-DC)?

The PDN is still in the EPC (P-GW). NR is a secondary radio; user-plane split/bearer can send packets on LTE, NR, or both per the SN configuration. Android still has one internet ifname/CID. Do not say "NSA uses a 5GC PDU session" unless the device is actually on SA. See 5G NR.

What should you do with suggestedRetryTime in the HAL result?

Honour it. It is how T3396/T3346 and vendor back-off reach the framework. Ignoring it causes setup storms, modem load, and sometimes a longer network ban. Permanent fail causes should not retry on a 1-second loop even if the time field is zero — check the cause class.

How does keepalive / NAT refresh show up on this stack?

IRadioData start/stop keepalive asks the modem to emit periodic packets (often off the AP) so NATs and the core do not drop the session while the AP sleeps. If keepalive is missing, chatty userspace timers replace it and kill suspend. If it is too aggressive, radio tail never ends. Confirm the current HAL method names on the branch.

What does allocatePduSessionId exist for?

5G allows the UE to allocate a PDU session id before establishment (and for some handover/slice cases). The framework asks the modem via IRadioData, then passes the id into setupDataCall. If you do not remember the exact pairing with releasePduSessionId, say "id lifecycle is HAL-managed; I would read the AIDL."

How do you reason about GSO/checksum offload on rmnet?

Prefer a general statement: the netdev and IPA/modem may advertise checksum and segmentation features; if they are wrongly advertised, you get corruption that tcpdump on the AP (already checksum-complete) will not show. Disable offload only as a bisect, then fix the driver. Do not invent a Qualcomm ioctl name.

What is the difference between netd's Network object and ConnectivityService's Network?

ConnectivityService's Network is the Java token apps hold (netId). netd's physical network is the kernel policy object with that netId: iface, routes, rules, resolver binding. They should stay in lockstep. A leak (Java Network still default, netd table already destroyed) is a platform bug that looks like random no-internet.

How does App Standby interact with an already-open socket?

Policy is per-UID, not per-socket lifetime. A connection opened in the foreground can start failing when the app is bucketed and Data Saver / standby rules apply, even though the TCP state is ESTABLISHED. The kernel will see eBPF drops; the app sees timeouts. Dumps: netpolicy + bpf maps, not only ss -t.

Why might dumpsys connectivity show VALIDATED while a specific app still fails?

Validation is a system probe UID, not the app UID. The Network is fine; the app is firewalled, bound to a dead Network, using a hard-coded proxy, pinning a broken TLS stack, or using an IPv4 literal without CLAT. Bisect with the app's UID and bindSocket from a test harness.

How do you talk about Network stack Mainline modules without lying about process names?

Say NetworkMonitor, DnsResolver and tethering/clat have moved between system_server, the Network stack process, and APEXes across releases. Name the role, then "I would confirm the process with dumpsys connectivity and ps on that build." Inventing a single process name for all years is how people fail senior loops.

What is the interview-safe description of QMAP mux id versus CID versus netId?

CID is the modem/HAL connection id. ifname is the Linux netdev. netId is Android's policy object. QMAP mux id (Qualcomm example) is the header field that demuxes PDNs on the physical link. They should map 1:1:1 in the happy case, but they are assigned by different layers. Never assume CID == 0 means rmnet_data0.

How does enterprise slicing appear on the data call without duplicating the 5G page?

URSP matches a traffic descriptor; Telephony sets up another PDU session (another CID/ifname) with slice info (S-NSSAI) in the HAL request/result. ConnectivityService exposes extra capabilities (enterprise / latency / bandwidth — confirm current names). The packet path is the same once the iface exists. Radio slice selection: 5G NR.

Scenario & debugging

Mobile data shows connected, but apps have no internet. Walk the bisect.
  1. CID and IP: telephony dump + ip addr.
  2. Routes/rules: ip rule, ip route show table all.
  3. Validation: dumpsys connectivity (VALIDATED vs captive vs none).
  4. DNS vs IP: literal versus hostname; DnsResolver dump.
  5. UID policy: netpolicy, Data Saver, VPN lockdown — shell ping is not the app.
  6. CLAT if v6-only.
  7. tcpdump empty versus UL-only: stack drop versus modem/core/MTU.
  8. Offload only if throughput/power is the bug.

This is the playbook Trace a Path Through the Android Stack points to.

There is no IPv4 or IPv6 address on the cellular iface. Where do you look?

Control plane. HAL cause and suggestedRetryTime, APN protocol vs network (IP vs IPV6 vs IPV4V6), ESM/5GSM reject, T3396, vendor WDS/setup logs, initial attach profile. Do not start with eBPF. If cause is success but addresses are empty, it is a vendor/modem bug.

The Network never becomes VALIDATED. How do you debug?

Read the validation attempt in dumpsys connectivity: probe URL, HTTP status, redirect, timeout. Check Private DNS, captive portal, DNS failure, and whether the probe UID is blocked. tcpdump the probe. A working ping to 8.8.8.8 with a failing HTTPS probe is still a validation bug, not a missing PDN.

IP literals work; hostnames fail. What is the likely layer?

DnsResolver / per-netId DNS / Private DNS / DNS64. Dump resolver config for that netId. Compare carrier DNS from the HAL versus overridden Private DNS. Do not recreate the data call first. If only AAAA synthesis is broken, IPv4-only names fail on a v6-only APN even when CLAT is up.

Only one app cannot use cellular; others are fine.

UID eBPF, Data Saver allowlist, App Standby bucket, background restriction, VPN per-app, or that app bound to a stale Network. dumpsys netpolicy, usagestats bucket, and a test bindSocket to the same Network from a privileged shell tool. TrafficStats for that UID stuck at zero while others increment is a strong hint.

TCP handshake works; a large POST hangs. What do you suspect?

MTU/MSS blackhole: a smaller hop in the core or NAT64 path, ICMP filtered. Clamp MSS, lower iface MTU, tcpdump segment sizes. CLAT makes the effective IPv4 MTU smaller. Small GETs and SYNs fit; TLS records or large writes do not.

IPv6 apps work on cellular; IPv4-only apps fail.

CLAT or NAT64 prefix. Check clat iface address (often 192.0.0.0/29), PREF64/DNS64, and whether CLAT eBPF loaded. Dual-stack APN would not show this split. Do not "fix" it by forcing IPv4-only APN without a carrier reason — that can break IMS or modern cores.

Throughput is fine but cellular drain and CPU are awful after a BSP drop.

Suspect aggregation/offload/NAPI: IRQ rate in /proc/interrupts, softirq CPU, vendor IPA/offload counters, GRO flags. Compare to last good build and to Wi-Fi. Chatty sockets are the other branch (modem never DRXes). See power.

VoLTE dies when the user turns mobile data off.

Someone tore down the IMS CID with the internet APN. Confirm ims iface and IMS registration stay up. Fix DataNetworkController / settings evaluation, not "restart RIL." See IMS and call flows.

Everything works on Wi-Fi; only cellular fails.

Bind a test to TRANSPORT_CELLULAR and repeat the bisect: APN, IPv6-only+CLAT, MTU, carrier firewall, roaming flag, validation URL blocked on the operator, Private DNS bootstrap. Wi-Fi succeeding only proves the app and TLS stack, not the PDN.

The phone has internet; tethered clients do not.

Forwarding, NAT, prefix, DUN second CID, tether eBPF, or hardware offload. ip_forward, nft/iptables NAT counters, tethering dumps, and a capture on the AP iface versus rmnet_data. Carrier may require DUN. Client using IPv6 only while you only NATed IPv4 is a common miss.

After a modem restart, data never comes back until airplane mode.

Framework still holds stale CIDs or did not re-push profiles / initial attach. Radio HAL death should fail pending requests with RADIO_NOT_AVAILABLE and clear the call list. Check RIL recovery, dataCallListChanged empty list, and whether DataNetwork retried setup. See RIL.

Roaming: voice works, data does not.

Data roaming toggle, carrier roaming APN vs home APN, forbidden APN types, and T3396 on the visited network. IMS may use a different policy than default internet. Confirm DDS and that the roaming APN protocol matches (v6-only visited network).

DSDS: the UI shows data on SIM A but packets use SIM B (or none).

PhoneSwitcher / DDS vs which factory is registered, vs which CID is up, vs which netId is default. Dump telephony + connectivity + ip rule. A leftover agent from the other Phone is a classic race.

Private DNS is set to a hostname; cellular icon is unhappy, Wi-Fi is fine.

DoT bootstrap or the DoT server is unreachable on the operator (port 853 filtered). Wi-Fi path can reach it. Try Automatic, or a literal probe. This is resolver/validation, not APN. Some enterprises break DoT on one access only.

An app works only after bindProcessToNetwork to cellular.

The default Network is Wi-Fi (maybe unvalidated or a broken captive) or a VPN the app cannot use. Binding proves cellular is healthy. Fix scoring/validation/VPN, or teach the app to request the right Network. Do not change the APN.

Enabling always-on VPN kills all connectivity, including the VPN itself.

Protect mark missing: tunnel sockets enter tun0 and loop. Or lockdown dropped the underlying Network before the tunnel came up. Dump fwmark on the VPN PID's sockets and ip rule. IMS may also be dead if lockdown is too broad.

tcpdump on the cellular iface is empty while the app is sending.

Packets never reached that netdev: wrong fwmark/table (sent to wlan0 or tun0), eBPF drop before egress, or the app is not actually writing. Confirm ss / connection 5-tuple, marks, and tcpdump on other ifaces. Hardware tethering is the exception where AP tcpdump misses forwarded packets.

tcpdump shows uplink but no downlink.

Left the AP. Check modem PDCP counters, GTP-U in network logs, operator NAT, MTU (large only), and whether the source IP is wrong (not NAT'ed, wrong APN). If modem never gets the packet, offload/driver between tcpdump and the modem. If modem sends but nothing returns, it is core or server, not netd.

IMS is registered; Settings says mobile data is off; a browser has no internet. Is that a bug?

No, if the internet CID is down and IMS CID is up. That is the required coexistence. A bug is the reverse (IMS down, data toggle off) or the browser somehow using the IMS iface (restricted Network leak).

IWLAN handover drops every TCP session.

IP changed, or the Network object was torn down and apps did not migrate. Check setup reason, addresses passed in, HAL handover failure mode, and whether ConnectivityService kept the same Network. IPsec flap to the ePDG also resets the path even if the framework thinks it handed over.

softirq time is huge during a download; Wi-Fi on the same build is fine.

Cellular aggregation/GRO/NAPI/offload not working; per-packet path on AP. Compare IRQ rates and offload stats. A debug tcpdump with large snaplen can also disable offload — measure without a noisy capture first.

Settings data usage is zero but the radio is clearly transferring.

eBPF/traffic-controller maps not updating (bpfloader, netd crash, wrong iface accounting). Historical qtaguid path missing on a new kernel. Hardware tethering bytes may bypass AP counters. Do not trust TrafficStats alone; use modem counters and a power rail if needed.

setupDataCall retries every second with ESM #26 / 5GSM insufficient resources.

Not honouring T3396 / suggestedRetryTime. Fix DataRetryManager. Continuing to retry can lengthen the network back-off. Log the cause and the timer, do not add a "faster retry" feature.

Fail cause is unknown APN or not subscribed. What should the framework do?

Stop automatic retry until the APN database, SIM, or carrier config changes. Hammering the modem will not create a subscription. Check MCC-MNC, carrier ID, and whether the user edited the APN name. See telephony APN notes on Telephony, RIL and modem.

A captive-portal Wi-Fi is default; the user expects cellular to take over. It does not.

Scoring may still prefer Wi-Fi until validation fails or the user wants "mobile data always." Check whether Wi-Fi is marked CAPTIVE but still default, and whether cellular is VALIDATED. The fix is ConnectivityService prefer-policy / validated-wifi-only defaults, not a new APN.

Emergency calling works; normal data never sets up after a new SIM.

Limited service can still open an emergency PDN. Default internet needs full registration and a subscribed APN. Check attach/registration accept, forbidden PLMN, and APN for that carrier ID. Do not confuse emergency ifname with default.

You can ping the gateway on rmnet but not an Internet IP.

On-link works; default route, NAT, or core forwarding does not. Check the Network table's default via, whether you are pinging from the right mark, and modem/core. A missing default in the netId table with a leftover main-table route is a netd bug.

MMS fails while browsing works.

MMS is a different request/capability, often a restricted Network and sometimes a different APN or proxy. Mobile data off may still allow MMS on many carriers. Debug the MMS Network's IP, routing, and MMSC reachability, not the default Network validation.

FOTA cannot reach the carrier server; Chrome can reach the internet.

FOTA is a restricted APN/Network. Chrome uses default. Bring up the FOTA call, check its routing table and DNS, and whether the UID is allowed. Forcing FOTA onto the default APN may violate carrier policy.

A kernel change renamed the iface; telephony still looks for rmnet_data0.

Believe HAL ifname, not a hard-coded string. netd and iptables remnants that bake in an old name will fail. Search the tree for the old ifname. Generic wwan renames are a common SoC bring-up miss.

How would you structure "trace HTTPS from OkHttp to the server and back" in 90 seconds?

One sentence control plane (already up). Then uplink: OkHttp → ART → bionic → tcp_sendmsg → skb → nft/eBPF → fwmark table → optional CLAT → rmnet/QMAP → offload → PDCP… → GTP-U → NAT → server. Downlink: reverse but name aggregation, NAPI, GRO, softirq, epoll. Offer dumps for each layer. Point radio-deep to telephony and 5G.

An interviewer asks you to compose "take a photo and upload it over cellular." What do you add beyond this page?

Camera2/CameraX → CameraService → HAL3 → ISP buffers, then this page's data path once the JPEG is written. Name one tool per stage. The upload half is exactly the uplink walk here, after a data call exists. The map for composing flows is on Trace a Path Through the Android Stack.