Skip to content

Automation

thejaustin edited this page Sep 19, 2026 · 1 revision

Automation

Shizuku+ includes a small, event-driven automation engine that adjusts privacy and access controls automatically based on what network you're on and which app is in the foreground. It's built around three built-in rules, evaluated by a lightweight foreground AutomationService that only runs while you have at least one rule configured.

The engine reacts to two kinds of events:

  • Network events — Wi-Fi connect/disconnect and SSID changes.
  • Foreground-app events — the app currently on screen changing.

The three rules

1. Network Firewall Rule

Automatically toggles the Binder Firewall based on the Wi-Fi network you're on:

  • On a network whose SSID is in your trusted networks list → Binder Firewall is disabled (apps get normal Shizuku access).
  • On any other network — untrusted Wi-Fi, mobile data, or no connection → Binder Firewall is enabled (Shizuku access restricted).

The trusted-network set is read live on every network event, so editing it in Settings takes effect on the next connection change without re-registering anything. If the SSID can't be read (e.g. location permission is off), the network is treated as untrusted.

2. App Auto-Hide Rule

While a foreground app is in your auto-hide list, Shizuku+ adds it to ShadowBinder's effective hidden-packages set for as long as it's on screen, then recomputes when you switch away. This auto-hide list is separate from the static hidden-packages list you manage by hand — the rule never mutates your manual list.

3. App-Specific Profile Rule (App Profiles)

Applies a per-app Binder Firewall override when the foreground app changes. This is the rule behind the App Profiles screen.


App Profiles screen

The App Profiles screen lists your installed apps, each with a state chip you cycle by tapping:

State Chip Behaviour when the app is in the foreground
Default neutral No override — your global Binder Firewall setting applies.
Block error color Forces binder_firewall = true — restricts Shizuku access while this app is foreground.
Allow accent color Forces binder_firewall = false — permits Shizuku access while this app is foreground.

Tapping the chip cycles Default → Block → Allow → Default. Configured apps float to the top of the list; a search box filters by name or package.

Profiles are stored as JSON in settings, e.g.:

{ "com.some.app": { "binder_firewall": true } }

Apps left on Default have no entry. The rule captures your global firewall value the first time it overrides, and restores it when a Default app returns to the foreground — so a per-app profile never permanently overwrites your manual global setting.


Service lifecycle

AutomationService starts automatically as soon as you configure at least one rule (for example, setting any app to Block/Allow), and stops when no rules remain configured. You don't start or stop it manually.

All three rules ultimately flip Shizuku+ settings (Binder Firewall, ShadowBinder hidden packages) and push them to the server via the normal feature-sync path, so their effects are exactly the same as toggling those controls by hand — just triggered automatically.

Clone this wiki locally