The interface is a package name and a boolean
Lightweight, no vpn firewall solution for Android 11+
At a glance
- What is it?
- ShizuWall is an Android firewall that does not implement a firewall. It calls a platform mechanism called Chain 3, which intercepts per-package network access at the system level, through four shell commands, and then puts a list management interface on top. The interesting decisions are the three ways it gets the privilege to run those commands and the documented broadcast contract that lets a script drive it.
- Who is it for?
- Adopt ShizuWall if you want to cut several applications off the network on a device you own and you would rather not hand a VPN slot to an app, since Chain 3 blocks at the connectivity layer with no tunnel and no VPN service.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Four commands, and one of them has to run first
The how-it-works section is four shell commands, and they are the entire mechanism. Chain 3 is described as an Android platform mechanism that intercepts and controls per-package network access at the system level, allowing fine-grained firewall control, and ShizuWall executes the platform commands through Shizuku or the local daemon. The commands are these:
# Enable firewall framework
cmd connectivity set-chain3-enabled true
# Block specific app
cmd connectivity set-package-networking-enabled false <package.name>
# Unblock specific app
cmd connectivity set-package-networking-enabled true <package.name>
# Disable firewall framework
cmd connectivity set-chain3-enabled falseThe structure is worth pausing on, because it is a two-level design. The first command switches the framework on, the second and third set the per-package state, and the fourth switches the framework off. That means the framework and the rules are separate: if you never enable it, the per-app toggles are recorded but inert, and if you disable it, your list is still there but nothing is enforced. For a user, that is a feature, because the toggle in quick settings is instant and the framework is a deliberate act. For a script, it is a detail you have to get right.
Why not a VPN, stated plainly
The first reason in the list is no VPN, and the explanation is that it avoids packet interception and the side effects of a persistent tunnel. That is a real difference and not a marketing one. A VPN-based firewall has to occupy the system's VPN slot, which means it shows up as an always-active connection, it can be detected by other applications, it costs battery, and the whole system's traffic passes through a process whose author you have to trust. A Chain 3 block happens inside the connectivity stack, so there is no tunnel, no VPN service and no second app. The honest counterweight is that the two approaches answer different questions. A VPN firewall can inspect where traffic is going and block a destination while letting the rest through; Chain 3 as exposed here takes a package name and a boolean, so an application is entirely off or entirely on. There is no destination, no port and no protocol in that command. If your problem is a single app that phones home, that is exactly right. If your problem is one app that needs to reach the internet for a legitimate reason, this tool cannot express the exception.
Three ways to get the privilege, one without an extra app
The requirements are Android 11, API 30 or higher, and one control backend out of three. Shizuku is described as a secure API that communicates with system services, requiring the Shizuku app, and the README notes that forks are supported, which is a community-health decision in a project with one dominant implementation. Root is the second option, direct root access, and needs no explanation. The third is the interesting one. LibADB, or LADB, uses the built-in wireless debugging feature of the phone to act like a computer connected over USB, which lets the application perform advanced system changes with no computer, no root and no helper application like Shizuku. The setup is enabling wireless debugging and pairing in developer options, with the guide inside the app. That route is a genuine convenience, and it also relocates the security question: the privilege now comes from a pairing you performed with a debugging feature, so the thing that matters is what is paired to your device and for how long, not which helper application happens to be installed.
The broadcast contract is documented like an API
Automation is a first-class feature and the contract is specific enough to implement against. The action is a custom string, the component is a named receiver class inside the application, and there are two extras. The state extra is a required boolean meaning enable or disable. The apps extra is an optional comma-separated list of app keys, and if you omit it the application uses its own saved selection rather than an empty list, which is the detail that catches people out when they write a first script. The example lines cover all four combinations, and the last one is the one worth understanding:
# Enable firewall for an app in user 0 and its work-profile clone
adb shell am broadcast -a shizuwall.CONTROL -n com.arslan.shizuwall/.receivers.FirewallControlReceiver --ez state true --es apps "com.example.app,150:com.example.app"A bare package name targets user 0, while an entry carrying a profile prefix targets the work-profile or cloned copy of the same application. So a single broadcast can cut off both copies of an app on a managed device, and the README adds that clones are handled automatically unless a setting called Show other profiles is on. For anyone scripting this, that is a complete specification.
Three ways to flip the switch, which is the actual product
Once the mechanism is four commands, the design work moves to the interface, and here ShizuWall offers three: a quick settings toggle, an app widget, and a floating firewall button. That is a considered answer to a real problem, which is that a firewall you have to open an app to use is a firewall you stop using. A quick settings tile is one pull and one tap, which is the fastest option and the one you will actually reach for. A widget puts the same control on a home screen, which matters if you do not think of the quick settings as a control panel. A floating button is the aggressive version, a permanent overlay you can hit without leaving the app you are currently trying to stop from connecting. The README frames all three together as convenient ways to control the firewall, and for a tool whose whole function is a single boolean, that framing is correct. The screenshots in the repository are numbered from a version 4.6 directory, which suggests a long life of incremental interface work rather than one settled design.
Play Store and F-Droid, and a second licence for the data
Distribution tells you something about a privacy tool, and this one is on both the Google Play listing and F-Droid. That is the arrangement that lets you check your assumption: the F-Droid build is produced from the visible source, so if what you install matters to you, that is the artefact to compare against a store build. The repository also carries a privacy policy file and, more unusually, a separate licence file for tracker data. The existence of that second file is the interesting part, because it means the blocking data has its own provenance and its own terms, which is the situation you get when a filter list is derived from another project's collection rather than authored from scratch. A tool that ships one licence for its code and another for its data is telling you the data is not simply its own, and that is worth reading before you rely on either. The project is GPL-3.0, which for a client-side application is about as permissive as open source gets in practice, since there is no server component to run.
Ten translations, a directory listing, and a release line that skips
The repository holds ten translated readmes in a documentation directory, covering Turkish, German, Italian, Portuguese, Czech, Russian, Arabic, Hindi, Chinese and Japanese, with English as the source. That is a real signal about who uses the tool and about the author's priorities, and it is more informative than any badge. The project is also listed in the network section of a community directory of Shizuku-based tools, which is how this category of application reaches users, since a firewall with no privileged backend is useless and a privileged backend is a niche corner. The release numbering has a small irregularity worth noting if you script against tags, with v4.6.1, then v4.6.3, then v4.6.4 visible in the list, so patch numbers are skipped rather than sequential. The last release is v4.6.4 from 2026-09-09 and the last push to main is 2026-09-27, so the branch is ahead of the tag, which is normal for a project shipping through two stores with different review cycles.
Editorial conclusion
Adopt ShizuWall if you want to cut several applications off the network on a device you own and you would rather not hand a VPN slot to an app, since Chain 3 blocks at the connectivity layer with no tunnel and no VPN service. Do not adopt it if you need rules by destination, port or protocol, because the command signature takes a package name and a boolean, so an app is either off or on, and read the privacy policy and the separate tracker data licence before you rely on either. Verify four things: that your device is on Android 11 or newer, which is the stated floor, that the backend you pick gives the app the shell access it needs and that you understand what that access means, since wireless debugging pairing in particular grants adb to whatever is paired, that the framework itself gets enabled before per-app toggles do anything, and that you read the broadcast contract before scripting it, including the profile prefix that distinguishes a work-profile copy from the user 0 copy of the same app. The licence is GPL-3.0, the latest release is v4.6.4 from 2026-09-09, and the last push was 2026-09-27.
Frequently asked questions
What is Chain 3 in ShizuWall?
It is an Android platform mechanism that intercepts and controls per-package network access at the system level. ShizuWall executes the platform commands through Shizuku or the local daemon, first enabling the framework with set-chain3-enabled and then setting each package with set-package-networking-enabled.
What do I need to run ShizuWall?
Android 11, API 30 or higher, and one control backend: the Shizuku application, root access, or LibADB, which uses the phone's built-in wireless debugging to act like a computer over USB with no computer, root or extra app involved.
Can I script ShizuWall?
Yes. It accepts an adb broadcast with the action shizuwall.CONTROL, a required boolean state extra, and an optional comma-separated apps list. If you omit the apps list, the application uses its own saved selection rather than treating it as empty.
What does the profile prefix mean in a ShizuWall broadcast?
A bare package name targets the app in user 0, while an entry carrying a profile prefix such as 150:com.example.app targets the work-profile or cloned copy of the same application. That lets one broadcast cover both copies, and the README notes clones are handled automatically unless the Show other profiles setting is on.
Where is ShizuWall available from?
Both the Google Play listing and F-Droid. The repository is GPL-3.0, carries a separate privacy policy document and a distinct licence file for tracker data, and the latest release is v4.6.4 from 2026-09-09.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/ahmetcanarslan-shizuwall)