The key links and current project states were last checked manually on July 19, 2026. Always download through releases/latest in the official repository rather than using repackaged APK or ZIP files from chats. When a project publishes a SHA-256 checksum or signature, verify it before installation.
DirectSignsChecker, IndirectSignsChecker, BypassChecker, NativeSignsChecker, VpnNativeDetectorChecker, BetaCheckRegistry, BetaEvidencePolicy, VerdictEngine, NativeSignalId, and EvidenceSource.Every exact count and ID in this guide was derived from the local code rather than from a third-party list.
VpnService — virtual-interface creation, protect(), and underlying networks.VpnService.Builder — allowed and disallowed applications, routes, DNS, MTU, and proxy configuration.Important limitations documented by the project: server-side signals are outside its scope; raw syscalls bypass Zygisk; kernel backends and Zygisk should not be stacked; and some procfs and KPM-parity cases remain conditional.
The project claims additional coverage for MTU, MSS, TCP_INFO, PMTU, GSO, BPF, qdisc, timing, sysfs, procfs, and profile vectors. Its README separately warns about instability, boot loops, and kernel panics. This guide labels those capabilities as external claims.
NoHello, Zygisk Next, SUSFS, and HMA are not required and are not guaranteed to work against RKNHardering. They are listed as options for researching the root surface. It is particularly important not to confuse HMA with VPNHide Apps: HMA usually operates in the selected application’s context, whereas VPNHide filters PackageManager through system_server.
Removing a profile erases its data. Make a separate backup before experimenting.
The RKNHardering-defense materials are labeled as community reports. They are useful examples for split routing and external gateways, but they do not demonstrate concealment of every local and β vector in version 2.10.0.
An application that demands disabling Play Protect, granting Accessibility or Device Admin without a clear reason, uploading a SuperKey, importing a private subscription, or installing an unsigned kernel ZIP creates disproportionate risk. Verify the source, repository history, release signature or hash, and requested permissions. Never give root keys, VPN secrets, or logs containing tokens to authors of unverified builds.