BaoLianDeng: The macOS Proxy App That Hides a Rust Core Behind SwiftUI

A look at how BaoLianDeng intercepts flows at the socket layer, rewrites config before startup, and makes a Go-based proxy engine feel native on macOS.

9 min read · madeye/BaoLianDeng

A macOS-style desktop window floats above a stream of network traffic that is intercepted by a transparent gate before it can rush into a tunnel. The flow splits into direct and proxied paths, then feeds a compact engine room that suggests multiple layers working together. It explains that BaoLianDeng is a flow router with a control plane, not just a branded tunnel.
BaoLianDeng works closer to a traffic controller than a classic tunnel app. It catches flows, decides where they go, and hands the result to the proxy core.
Key Takeaways

It does not tunnel traffic. It intercepts flows.

That distinction is the whole story. BaoLianDeng uses NETransparentProxyProvider, so the system hands it flows, not raw packets. The app can then decide whether traffic should be routed, bypassed, or handled through a local proxy engine.

This is why the project feels more like a native macOS control surface than a generic VPN shell. It is not trying to fake a network stack in user space. It is leaning on Apple’s network extension model and using it as the enforcement point.

The cleanest way to understand BaoLianDeng is as a flow pipeline. The extension catches traffic, the runtime decides what to do with it, and Mihomo handles the routing logic.

SwiftUI is the shell. Rust is the shock absorber. Go is the routing brain.

The codebase is split with intent. SwiftUI owns the app surface, shared state, and user actions. The network extension handles interception. Between them sits a Rust bridge that wraps the Go-based Mihomo core and gives the macOS targets a safer, more controlled interface.

That middle layer is the interesting move. Many projects would call into Go more directly or bury the logic inside a helper tool. BaoLianDeng instead uses Rust as an adapter, which is a strong signal that stability inside a system extension is being treated as a first-class product requirement.

macOS VPN proxy app powered by Mihomo (Clash Meta) core.

madeye, Author/Maintainer · BaoLianDeng README

The config file is not static. It gets rewritten for the runtime.

BaoLianDeng does not simply load a YAML file and hope for the best. The config manager sanitizes user input, adjusts proxy selection, and patches the file before the engine starts. That means the runtime gets a configuration that already reflects the current app state.

This matters because proxy apps are full of state that users do not want to manage manually. The active node, subscription refreshes, routing rules, and local runtime constraints all collide at startup. BaoLianDeng handles that collision up front.

A close-up of a YAML configuration sheet being adjusted by a precise mechanical hand before it enters a compact proxy engine. One line is lifted to the top of a list and another is trimmed into place, making the file look like it has been surgically prepared for runtime use. It explains that the app rewrites configuration before the engine starts instead of treating config as a passive document.
The config layer is active, not decorative. BaoLianDeng rewrites the runtime setup before traffic ever reaches the core.

Per-app routing is the feature that turns it into a desktop tool

Per-app routing is where the macOS story becomes practical. The app can treat browsers, terminals, and background services differently, which is exactly what serious proxy users want on a desktop machine.

That control is more valuable than a long feature checklist. It makes the proxy engine feel like part of the operating system workflow, not a separate utility you launch and forget.

Why this stack beats heavier macOS proxy clients

BaoLianDeng is not trying to win by being the biggest or the flashiest client. It wins by being native where it counts, which is the right tradeoff for a niche tool that lives close to the network stack.

ProjectUI stackCoreNetwork handlingOpen sourceWhat it optimizes for
BaoLianDengSwiftUIMihomoSystem ExtensionYesNative macOS control and a disciplined runtime
Clash for Windows style clientsElectronClash or Clash MetaHelper tools or mixed approachesUsually noCross-platform reach and feature breadth
ClashX / ClashX ProNative macOSClashNative macOS integrationMixedA familiar macOS Clash experience
Surge for MacNative macOSProprietaryNative macOS integrationNoAn advanced power-user network suite
A split composition compares a bulky desktop client stacked on multiple thick layers with a slimmer native macOS stack that routes directly into a system extension. The left side feels overbuilt and heavy, while the right side feels tighter and more integrated. It clarifies that BaoLianDeng competes on architectural discipline rather than feature sprawl.
The contrast is architectural, not just cosmetic. BaoLianDeng aims for a tighter native path into macOS.

This is what a maintained niche tool looks like

The repository does not look thrown together. It has end-to-end tests, stress scripts, mock servers, structured logging, and a build flow that spans Makefile orchestration, Rust, and Xcode. That is a lot of ceremony for a proxy client, which is exactly why it feels trustworthy.

The maturity signal is not just code volume. It is the separation of concerns, the use of modern macOS APIs, and the willingness to treat network stability as something that can be tested instead of merely hoped for. In a category full of rough edges, that is the differentiator that matters.