AFWall Boot AntiLeak

gjf

Magisk
May 2, 2025
Updated

Module Info

  • Source Code View Repository
  • Tags
    #AFWall Boot AntiLeak #AFWall+ #Android Firewall #Boot Protection #iptables #Network Privacy #Magisk Module

About this module

AFWall Boot AntiLeak is a companion Magisk module that blocks network access early in Android startup and keeps the connection closed until AFWall+ has had time to apply the user's firewall rules.

Close the Firewall Boot Gap

Prevent applications and system services from reaching the network before AFWall+ initializes its regular iptables policy.

Early-Boot Lockdown

Disables Wi-Fi and mobile data before AFWall+ starts, covering the period when the application's normal iptables policy is not yet active.

Wi-Fi and Mobile Data

The documented rule set covers both primary connection types so neither interface provides an unfiltered startup path.

Delayed Handoff

Allows time for AFWall+ to load, then removes the temporary startup script from the supported Magisk service paths.

Boot Protection Sequence

  1. Post-fs-data phase: the module removes stale afwallstart helper files from the documented Magisk service directories, then disables both Wi-Fi and mobile data.
  2. Late-start phase: it disables both connection types again and checks for the AFWall+ process identified as dev.ukanth.ufirewall.
  3. Waiting period: while AFWall+ is not running, the script repeats the radio shutdown every five seconds. This prevents another startup component from restoring connectivity prematurely.
  4. Handoff: after AFWall+ appears, the module waits another five seconds and then enables Wi-Fi and mobile data, allowing AFWall+ to enforce the user's configured firewall policy.

How It Complements AFWall+

AFWall+ remains the component that creates per-application iptables rules. This module does not reproduce those rules or act as a second firewall; it controls connectivity during startup so applications cannot transmit before AFWall+ reaches its running state.

The design deliberately favors blocking over availability. Network access is delayed on every boot, and Wi-Fi and mobile data are both re-enabled after the AFWall+ process is detected. Users should therefore verify that AFWall+ is configured to apply its policy automatically and that its process starts reliably.