Repository navigation
Automation
Shizuku+ includes a small, event-driven automation engine that adjusts privacy and access controls automatically based on what network you're on and which app is in the foreground. It's built around three built-in rules, evaluated by a lightweight foreground AutomationService that only runs while you have at least one rule configured.
The engine reacts to two kinds of events:
- Network events — Wi-Fi connect/disconnect and SSID changes.
- Foreground-app events — the app currently on screen changing.
Automatically toggles the Binder Firewall based on the Wi-Fi network you're on:
- On a network whose SSID is in your trusted networks list → Binder Firewall is disabled (apps get normal Shizuku access).
- On any other network — untrusted Wi-Fi, mobile data, or no connection → Binder Firewall is enabled (Shizuku access restricted).
The trusted-network set is read live on every network event, so editing it in Settings takes effect on the next connection change without re-registering anything. If the SSID can't be read (e.g. location permission is off), the network is treated as untrusted.
While a foreground app is in your auto-hide list, Shizuku+ adds it to ShadowBinder's effective hidden-packages set for as long as it's on screen, then recomputes when you switch away. This auto-hide list is separate from the static hidden-packages list you manage by hand — the rule never mutates your manual list.
Applies a per-app Binder Firewall override when the foreground app changes. This is the rule behind the App Profiles screen.
The App Profiles screen lists your installed apps, each with a state chip you cycle by tapping:
| State | Chip | Behaviour when the app is in the foreground |
|---|---|---|
| Default | neutral | No override — your global Binder Firewall setting applies. |
| Block | error color | Forces binder_firewall = true — restricts Shizuku access while this app is foreground. |
| Allow | accent color | Forces binder_firewall = false — permits Shizuku access while this app is foreground. |
Tapping the chip cycles Default → Block → Allow → Default. Configured apps float to the top of the list; a search box filters by name or package.
Profiles are stored as JSON in settings, e.g.:
{ "com.some.app": { "binder_firewall": true } }Apps left on Default have no entry. The rule captures your global firewall value the first time it overrides, and restores it when a Default app returns to the foreground — so a per-app profile never permanently overwrites your manual global setting.
AutomationService starts automatically as soon as you configure at least one rule (for example, setting any app to Block/Allow), and stops when no rules remain configured. You don't start or stop it manually.
All three rules ultimately flip Shizuku+ settings (Binder Firewall, ShadowBinder hidden packages) and push them to the server via the normal feature-sync path, so their effects are exactly the same as toggling those controls by hand — just triggered automatically.