Skip to content

How to block gambling/betting domains effectively with Firestack in an Android Kotlin app? (University project) #167

Description

@Mateusdsr

Hi, hope you’re well!

I’m a Computer Science student in Brazil and I’m developing my undergraduate thesis (final project/TCC) about helping users avoid online gambling.
My goal is to build an Android app (Kotlin) that can effectively block access to betting and gambling sites (such as bet365, blaze, sportingbet, etc) using Firestack as a local VPN/DNS filter.

My questions:

What’s the recommended way to implement a custom blocklist of gambling/betting domains with Firestack on Android?

Is there an official or suggested method to load and update a list of banned domains (for both DNS and IP-level blocking), and make sure it works for all apps (not just browsers)?

Are there any special caveats, limitations, or Android-specific behaviors I should consider to ensure gambling domains are truly blocked?

If possible, could you provide a basic code example or point to the relevant API/classes for this use case in Kotlin?

This is a university project and not for commercial use.
Any guidance or references would be hugely appreciated! Thank you for your work on this amazing project.

Activity

  1. ignoramous commented on Jun 18, 2025

    @ignoramous
    Contributor

    Thanks for your kind words.

    What's the recommended way to implement a custom blocklist of gambling/betting domains with Firestack on Android?

    Firestack calls client code's DNSListener.onQuery(uid, domain, querytype) every time it is about to resolve a domain (not in its cache). The uid here denotes the Linux UID that sent the request. Android assigns UIDs to apps and other components, ideally one per app (but apps that are signed with the same signing keys may share UIDs, as it the case for apps by Google, for example). DNSListener.onQuery must return DNSOpts back with at least PIDCSV (comma-separated value for primary DNS transports to use) set.

    • To block a given domain, return PIDCSV as backend.BlockAll.
    • To allow, set PIDCSV to a valid Transport ID. If you don't know which one to use, then backend.Default will use the built-in preset DNS Transport, which may or may not work.

    To register a DNS Transport (DoH, ODoH, DNS53, DoT) against an ID of your choice, see funcs starting with Add*** in intra/dns.go.

    Is there an official or suggested method to load and update a list of banned domains (for both DNS and IP-level blocking), and make sure it works for all apps (not just browsers)?

    Rethink (the client app that firestack was built for) has its own blocklists, yes. It isn't that straight forward to use it, so if I were you, I'd avoid relying on it. The blocklists that Rethink downloads is configured here: serverless-dns/blocklists/config.json.

    Are there any special caveats, limitations, or Android-specific behaviors I should consider to ensure gambling domains are truly blocked?

    You could look at how Rethink uses firestack (main repo, lead developer's repo which targets the latest firestack commit, right now), Copilot, if you've got access is pretty good at navigating open source codebases.

    If possible, could you provide a basic code example or point to the relevant API/classes for this use case in Kotlin?

    Look at BraveVPNService.kt and GoVPNAdapter.kt. It can be overwhelming at first, but as before, see if Copilot helps. You could try asking it to outline what a file does function by function, class by class etc before asking it more specific queries around integration.

    To get you started, tun2socks.Connect is the entrypoint that kickstarts everything up, after BraveVPNService has got its hands on the TUN device (file descriptor) which represents an active VPN session on Android. tun2socks.Connect returns intra.Tunnel which is the primary way to mod firestack. There's a bunch of global levers client code can pull, but you can also leave them in their defaults: intra/settings.

    (moving this to discussion)

  2. locked and limited conversation to collaborators on Jun 18, 2025
  3. converted this issue into a discussion #168 on Jun 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions