ShizuStore

De1984

dorumrr

2.7.8 · GitHub

Download APK
Network Android 8.0+ 5 days ago MIT
201 ShizuStore
21.6k GitHub
439 Stars
6 MB Size

More about this app

App firewall without using an VPN; can also manage packages

De1984

Privacy isnโ€™t default. Take it back with De1984 Firewall and Package Control.

The name De1984 is inspired by George Orwellโ€™s novel Nineteen Eighty-Four, reflecting the appโ€™s philosophy of resisting surveillance and reclaiming digital privacy. It symbolizes a reversal of the dystopian control described in the book, empowering users to take back control over their devices and data.

๐Ÿ“ธ Screenshots

De 1984 Firewall by Doru Moraru De1984 Firewall Controls by Doru Moraru De1984 Packages by Doru Moraru De1984 Packages Control by Doru Moraru De1984 Options by Doru Moraru

โœจ Features

๐Ÿ›ก๏ธ Firewall

  • Multiple firewall capabilities: iptables, ConnectivityManager, NetworkPolicyManager, and VPN fallback
  • Automatic firewall method selection based on device capabilities
  • Comprehensive iptables for rooted devices provides kernel-level blocking with superior performance
  • ConnectivityManager for Android 13+ devices with Shizuku, no root required
  • NetworkPolicyManager for older devices with Shizuku, selectable manually
  • VPN backend as fallback for maximum compatibility (no root required)
  • Block apps from accessing WiFi, Mobile Data, or Roaming independently
  • Global firewall policies: "Block All by Default" (allowlist) or "Allow All by Default" (blocklist)
  • Screen-off blocking to save battery and data
  • Real-time network state monitoring and automatic rule application

๐Ÿ“ฆ Package Management (with Shizuku or root)

  • Enable/disable system apps
  • Force stop running apps
  • Uninstall system and user apps
  • Works with Shizuku (no root required) or traditional root access
  • Filter packages by system/user apps, enabled/disabled state
  • Search functionality for quick package lookup

๐Ÿ”’ Privacy First

  • Zero tracking or analytics
  • No telemetry
  • Local-only data storage
  • No proprietary libraries
  • Buildable from source
  • 100% open source (MIT License)

๐Ÿ“‹ Requirements

  • Android 8.0 (API 26) or higher
  • For iptables firewall: Root, or Shizuku running in root mode. Shizuku started over ADB runs as the shell user and cannot create kernel rules, so this backend stays unavailable in that mode
  • For ConnectivityManager firewall: Shizuku + Android 13+ (no root required)
  • For NetworkPolicyManager firewall: Shizuku (no root required). On ROMs that do not implement POLICY_REJECT_ALL it can only block metered background data, not WiFi
  • For VPN firewall: VPN permission (no root required, works on all Android versions)
  • For package management: Shizuku or root access

๐Ÿ” Permissions

  • ACCESS_NETWORK_STATE: Monitor network connectivity for automatic rule application
  • BIND_VPN_SERVICE: Create local VPN for VPN-based firewall backend
  • QUERY_ALL_PACKAGES: View all installed apps
  • POST_NOTIFICATIONS: Show notifications for new app installations (optional)
  • RECEIVE_BOOT_COMPLETED: Auto-start firewall on device boot
  • Shizuku or root access: For the iptables, ConnectivityManager and NetworkPolicyManager firewalls, and for package management (optional)

โš ๏ธ Good to Know

If you use VPN mode, turn OFF "Block connections without VPN"

In Android's VPN settings, De1984 must not have "Block connections without VPN" (also called lockdown) enabled. De1984's VPN routes only the apps you have blocked through its tunnel โ€” allowed apps deliberately bypass it and use the network directly. Apps that share a user ID share one verdict, so an allowed app that shares one with an app whose rule blocks goes through the tunnel too. Lockdown tells Android to drop anything that does not go through the VPN, so it blocks exactly those allowed apps. On recent Android versions this switch is turned on automatically when you grant a VPN, so it is worth checking.

iptables needs real root, not ADB-mode Shizuku

Shizuku started over ADB runs as the shell user (uid 2000), which cannot create kernel firewall rules. The iptables backend stays greyed out in that mode. It becomes available with root, or with Shizuku itself started in root mode.

AUTO mode never picks NetworkPolicyManager

Automatic selection tries iptables, then ConnectivityManager, then VPN. NetworkPolicyManager is available only by choosing it manually in Settings, and on ROMs that do not implement POLICY_REJECT_ALL it can block metered background data but not WiFi.

๐Ÿค Contributing

Help make this app better. No contribution is too small!

How to Contribute

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Make your changes
  4. Commit your changes (git commit -m 'Add some amazing feature')
  5. Push to the branch (git push origin feature/amazing-feature)
  6. Open a Pull Request

All contributions are valued and appreciated!

๐Ÿ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

๐Ÿ’– Support Development

De1984 protects your privacy. You can protect its future!

DONATE


Late nights for brighter days.

Created by Doru Moraru

Close

How Shizuku is used

Can block apps without VPN, manage packages, keep protection after reboot and tune connectivity checks via `Shizuku`.

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

De1984 uses Shizuku to enforce its firewall, manage installed apps and change system connectivity settings without using a VPN connection.

  • Block apps without VPN: per app network access is turned on or off through Shizuku using the system network policy service and the cmd connectivity set-package-networking-enabled and cmd connectivity set-chain3-enabled shell commands.
  • Filter traffic by address: internet and local network traffic is filtered per app with iptables and ip6tables rules applied through Shizuku.
  • Enable or disable apps: installed apps are enabled or disabled for a user with the pm enable and pm disable-user shell commands through Shizuku.
  • Uninstall and restore apps: apps are removed with the pm uninstall shell command and system apps are restored with the cmd package install-existing shell command through Shizuku, and installed packages are listed with pm list packages.
  • Stop running apps: selected apps are stopped with the am force-stop shell command through Shizuku.
  • Stay protected after reboot: a boot time block is installed and removed through Shizuku and the device is rebooted with the svc power reboot shell command so the on disk state and live filtering agree.
  • Customize connectivity checks: captive portal detection mode, server URLs, defaults and restore are read and changed with the settings get, settings put and settings delete shell commands through Shizuku.
  • Support multiple profiles: access across user profiles is enabled with a pm grant shell command through Shizuku so work profile and secondary user apps can be listed and controlled.

Android APIs or commands used

  • INetworkPolicyManager.setUidPolicy
  • INetworkPolicyManager.getUidPolicy
  • pm enable
  • pm disable-user
  • pm list packages
  • pm uninstall
  • cmd package install-existing
  • am force-stop
  • cmd connectivity set-chain3-enabled
  • cmd connectivity set-package-networking-enabled
  • settings get
  • settings put
  • settings delete
  • iptables
  • ip6tables
  • dumpsys netpolicy
  • svc power reboot
  • pm grant

Notable details

Current connectivity check values can be viewed without Shizuku, changing them and all firewall and package actions need Shizuku.

Close

Changelog

What's new for version 2.7.8

  • Fixed: stop could keep failing after ConnectivityManager was used #107
  • "Allow in Background" is now "Allow while screen off" #105
  • One verdict per shared user ID; VPN Block All no longer cuts off Android System, Bluetooth, NFC
  • Fixed: a removed app's rule could block its user ID
  • Fixed: a VPN restart loop, and taking another VPN's slot unasked
  • Fixed: no new-app notifications for the main profile
  • Fixed: work-profile rows on ConnectivityManager; false or stale banners and notifications
Close

Permissions

19 permissions requested

  • android.permission.ACCESS_NETWORK_STATE
  • android.permission.ACCESS_WIFI_STATE
  • android.permission.FOREGROUND_SERVICE
  • android.permission.FOREGROUND_SERVICE_SPECIAL_USE
  • android.permission.RECEIVE_BOOT_COMPLETED
  • android.permission.INTERACT_ACROSS_USERS
  • android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
  • com.android.launcher.permission.INSTALL_SHORTCUT
  • android.permission.BIND_VPN_SERVICE
  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.REQUEST_DELETE_PACKAGES
  • android.permission.POST_NOTIFICATIONS
  • android.permission.WRITE_SECURE_SETTINGS
  • android.permission.CHANGE_COMPONENT_ENABLED_STATE
  • android.permission.KILL_BACKGROUND_PROCESSES
  • android.permission.ACCESS_SUPERUSER
  • moe.shizuku.manager.permission.API_V23
  • android.permission.WAKE_LOCK
  • io.github.dorumrr.de1984.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Close

Sources

2 sources

2.7.8 GitHub ยท io.github.dorumrr.de1984
Selected Download
2.7.5 F-Droid · io.github.dorumrr.de1984 ยท io.github.dorumrr.de1984
Download