ClearDeck

About

ClearDeck is a local network firewall for Android. It uses Android’s VPN API to look at each app’s connections on the device: a connection that matches a rule is rejected on the spot, and everything else goes straight out to the internet. No traffic passes through any server of ours — there is no server to pass it through.

  • v0.1.0
  • GPL-3.0
  • Android 10 – 17

The company

ClearDeck is developed and maintained by Beijing Fenghong Technology Co., Ltd. (北京烽鸿科技有限责任公司). The app, this website, and the licence obligations described below are all that company’s responsibility.

What it is built on

ClearDeck does not hide where it comes from. The Android front end is derived from ClashMetaForAndroid, and the networking engine inside it is derived from the mihomo kernel. Both are published under GPL-3.0, and ClearDeck as a whole is released under GPL-3.0 too.

These are licence obligations, and they double as the honest answer to how the app does so much with so little CPU: the hard parts of tunnelling and rule matching were not written from scratch. The credit belongs upstream.

The bundled ad and tracker rule data comes from anti-AD, which is published under the MIT licence.

The rule lists are compiled from these upstream sources

Source Feeds
EasyList ads
EasyList Ad Servers ads
217heidai/adblockfilters ads
AWAvenue Ads Rule ads, trackers
EasyPrivacy trackers
AdGuard Tracking Protection trackers
Hagezi Threat Intelligence Feeds (TIF, mini) malware

Engineering notes worth telling

A few decisions that are invisible from the outside but shape how the app behaves.

The UI cannot take the VPN down

The interface runs in the app process, and the engine runs in a separate :tun process. If the UI crashes, the tunnel keeps running — protection does not drop because a screen threw an exception.

Both IPv4 and IPv6 are captured

Traffic on both address families is routed through the tunnel. Capture only one and an IPv6 network would carry traffic around every rule without touching it.

The control channel stays on loopback

The local control channel listens only on 127.0.0.1, on a random port, and generates a fresh random secret every time a configuration is loaded.

Core logic is testable on a desktop JVM

The project is split into 9 Gradle modules. The pure-Kotlin ones — core-rules and core-analytics — carry no Android dependency, so their logic runs in ordinary JVM unit tests (19 test files at the time of writing).

It does not capture itself

ClearDeck adds itself to the list of apps the tunnel leaves alone: on some devices, letting the tunnel capture its own relay socket takes the network down.

Contact

For questions about the app or this site, write to:

This address is a placeholder. The real contact address will be published here before release.

Status

ClearDeck is version 0.1.0 and has not been publicly released. It is not on any app store, F-Droid or GitHub Releases, and there is no public download yet. When it does ship, the source has to be available alongside it — that is what GPL-3.0 requires.

Legal

The three documents that ship inside the app are published here as well:

Get notified when ClearDeck launches

We are finishing the first release. Leave an email and we will tell you when it is ready — once, and nothing else.

Signups will open shortly.

Only used to tell you about the launch. No newsletter, no sharing.