S
ShizuPortal
ShizuStore

Unofficial ShizuStore Web Portal

This is an unofficial web portal for ShizuStore self-hosted by rdevz-ph. Visit the official portal at https://shizustore.com/.

XFiles

XFiles

v1.5.0
by Local1stDotApp•File management•GPL-3.0
Need ShizuStore app? Download APK

Screenshots

(7)

About Application

XFiles logo

XFiles

An offline, open-source Android file manager with X-plore's workflow — dual-pane tree browsing, archive-as-folder, app manager, APK/AAB/XAPK install, root & Shizuku access — on the latest Android stack with a Material 3 Expressive UI.

Release License Android Kotlin No network

English · 简体中文

One tour on a OnePlus 7 Pro: copy files, inspect an installed app's components and APK splits, then browse the root-only directories under /data

Real capture on a OnePlus 7 Pro (Android 16), sped up. One run: file copy → App manager (an app's components & APK splits) → Root (the real filesystem, /data and all).


Why

  • X-plore broke on Waydroid over the past half-year; I needed a replacement.
  • It's the LLM era — if a tool doesn't fit, build your own.
  • Software with dangerous root powers should be open-source, fully offline, and collect nothing. XFiles has no INTERNET permission and no analytics.

Download

Grab an APK from Releases:

  • vX.Y — stable, cut whenever versionName is bumped.
  • nightly — a single rolling prerelease, refreshed on every push to main.

Requires Android 8.0 (API 26) or newer. On first launch, grant All files access (the app deep-links to the system page). Or build it yourself.

Features

Dual-pane tree browser

X-plore's signature: two independent panes — side-by-side on wide screens, a swipeable pager on phones. Folders expand in place as a tree with indent guide lines, and each pane carries its own floating breadcrumb pill. On phones, a target chip at the top keeps the hidden pane's folder visible and switches to that pane when tapped.

Archives sit in the tree like any other folder — the breadcrumb descends straight into project.zip.

Thumbnails in the tree

Images and video poster frames render inline. Video frames are extracted once at thumbnail size and disk-cached, so they are instant after a restart, with a play badge and an icon fallback while loading.

File operations

Multi-select via right-edge checkmarks. The other pane is the destination for copy, move, zip and extract: set its folder, return to the source pane, then run the operation directly. Copy to…/Move to… in the long-press menu remain available when you want a one-off explicit destination. Delete on internal storage, an SD card, or a USB drive moves the files to the Recycle Bin, where they can be restored. Empty Recycle Bin, and delete under Root or a network location, remove them permanently. Plus rename and new folder. Mounted USB OTG drives appear as pane roots next to internal storage and SD cards, and the list updates when a drive is plugged or unplugged. On Android 8–10, writes to SD cards, USB drives and other secondary volumes work through a one-time SAF grant.

Add location (home screen or Settings) grants a document tree from another app — RSAF (rclone), CIFS Documents Provider, Nextcloud, or any DocumentsProvider — and pins it as a pane root. Copy and move then stream through the system; XFiles still has no INTERNET permission, so the other app is what actually talks to the network. A tree that is already local storage is pinned as a favorite instead of a duplicate root. Step-by-step: Add a network location (source).

A background engine drives it all with progress (the wavy Expressive indicator), cancellation, and Skip / Overwrite / Keep-both conflict resolution.

High-performance zip

Creation deflates every entry across all CPU cores (commons-compress ParallelScatterZipCreator, STORE for already-compressed media). Extraction runs one ZipFile handle per worker off a shared queue. Zip-Slip guarded; falls back to single-threaded streaming when temp space is tight.

Foreground service

Long copy/move/zip/extract operations keep running when the app is backgrounded, shown in an ongoing notification with a Cancel action and a wake lock. The service self-stops when idle.

Archives as folders

Browse zip/jar/apk, 7z, tar(.gz/.bz2/.xz) and rar read-only; extract by copying out. Anything installable installs from right there — see below.

App manager

Installed and system apps in two groups, with real icons, version/package badges and rich details. Install, launch, uninstall, or copy an APK out to share an app as a file.

Expand an app and you get everything that belongs to it in one place: a Components node broken down into activities / providers / receivers / services, plus base.apk and every split_config.* APK — each one expandable, because an APK is just a zip.

Drill into a category and each component shows its class name and its real manifest state — exported / not exported, enabled / disabled. Launch activities, create shortcuts, and enable/disable components where the system permits.

Package installer

APKs install with a tap — and so does everything APK-shaped: split bundles (.apks / .apkm / .xapk, with XAPK OBB expansion files placed where the game expects them) and even raw .aab files. A vendored bundletool converts the bundle on the phone into split APKs matched to the device and signs them with a built-in certificate — no PC, no Play Store. Installs run in the foreground service, so backgrounding the app mid-install doesn't kill the session.

Root & Shizuku

On by default. A Root entry (/) sits with the storage roots — turn Root access off in Settings to hide it. A separate Read-only switch (also on by default) blocks anything needing privilege to write, so you can go look without being able to break your system.

Two interchangeable transports power it, and Settings lets you pick (or leave it on auto):

  • su — full superuser on rooted devices. /data opens up to adb, anr, app, app-private, dalvik-cache — directories a normal app can't even list — with list/read/write/mkdir/rename/delete under /data, /system, …
  • Shizuku — no root required: XFiles binds a Shizuku user service running at shell (ADB) privilege that hands over real file descriptors. Settings walks you through setup and permission.

Whichever transport is live also kicks in transparently where plain file access is denied — most notably Android/data and Android/obb, which open like any other folder. Thumbnails, viewers and even video playback work on privileged paths. Opening Root uses su when it is available. Without it, Shizuku can still list / and browse what the adb shell can see (/system, /proc, /storage, Android/data). /data and /data/data stay closed until superuser is granted.

The settings screen carries the rest of the preferences too — theme, dynamic color, hidden files, folders-first, sort key and direction.

Viewers

An image viewer (pager + pinch zoom), a text viewer with edit/save, a hex viewer with on-demand paging, an audio player, and a custom video player (Media3/ExoPlayer) with frame-accurate stepping.

Tap the time readout to swap it for a frame counter — current frame, total, and the real frame rate — then step ±1 frame, swipe on the picture to scrub by time or frames with live preview, drag the compact control card out of the way, or go fullscreen immersive.

Search

Live streaming recursive search with */? wildcards. Descends into archives, and reveals results in the tree on tap.

Open from other apps

Off by default so XFiles never hijacks anything. Three opt-in toggles in Settings register XFiles with the system resolver for archives, images and videos — after that, "open with XFiles" from any app lands in the archive tree or the right viewer.

Material 3 Expressive

MaterialExpressiveTheme + expressive motion, dynamic color (Android 12+), light/dark/system, floating toolbar, LoadingIndicator / LinearWavyProgressIndicator. True edge-to-edge: no top app bar — content scrolls under the status bar behind a gradient scrim, with floating breadcrumb and settings buttons.

18 languages

The UI follows the system language: English plus Arabic, Chinese (Simplified and Traditional), Dutch, French, German, Hindi, Indonesian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Russian, Spanish, Turkish and Vietnamese.

Permissions & privacy

No network permission, no telemetry, no accounts, no ads. Every permission the app declares, and why:

PermissionWhy
MANAGE_EXTERNAL_STORAGEBrowse and modify all of shared storage — the whole point of an X-plore-style manager
READ_EXTERNAL_STORAGE (≤ API 32)Legacy read path on older Android
WRITE_EXTERNAL_STORAGE (≤ API 29)Legacy write path on older Android
QUERY_ALL_PACKAGESThe App manager lists what is installed
REQUEST_DELETE_PACKAGESUninstall from the App manager
REQUEST_INSTALL_PACKAGESThe package installer: APKs, split bundles (.apks/.apkm/.xapk), AABs
POST_NOTIFICATIONSShow the progress notification for long operations
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNCKeep a copy/move or install running when backgrounded
WAKE_LOCKDon't sleep mid-operation
INTERNETNot requested. The app cannot talk to the network at all

That last row is enforced by the OS, not by policy — verify it yourself in AndroidManifest.xml or with aapt dump permissions on the APK.

Tech stack

LayerChoice
Language / UIKotlin, Jetpack Compose (BOM 2026.09.00), material3 1.5.0-alpha28 (Expressive APIs)
BuildAGP 9.4.1 (built-in Kotlin, no KGP), Gradle 9.7.1, compileSdk 37 / target 37 / min 26
ArchitectureMVVM + StateFlow, manual DI composition root (di/Graph); app module + a shaded bundletool vendor module
PersistenceDataStore Preferences
Media/ImagesCoil 3 (GIF, custom fetchers: app icons, disk-cached video thumbnails), Media3 ExoPlayer
Archivesjava.util.zip, commons-compress (+xz), junrar
Privileged accessShizuku 13.1.5 (user service, real fds) · su shell
Package installPackageInstaller sessions · vendored bundletool 1.18.3 · ARSCLib (in-process aapt2) · minimal self-signed signer

Note: material3 is pinned to the 1.5 alpha line (1.5.0-alpha28) because the Expressive APIs are internal in the 1.4.0 stable release.

Project layout

app/src/main/java/app/local1st/files/
├── core/
│   ├── fs/        XEntry model, XId id scheme, XFileSystem + FsRegistry,
│   │   │          Local/Archive/Apps/Root filesystems, storage roots, legacy SAF writes
│   │   └── priv/  privileged transports — su shell & Shizuku user service (real fds)
│   ├── ops/       OperationEngine (copy/move/delete/compress + conflicts), OpsService
│   ├── search/    recursive SearchEngine
│   ├── prefs/     DataStore settings
│   ├── thumb/     Coil fetchers: app icons, disk-cached video thumbnails
│   └── util/      formatters, mime/category mapping, intents; package install —
│                  PackageInstaller sessions, AAB→APKs (bundletool), XAPK/OBB,
│                  in-process aapt2 (ARSCLib), self-signed signing
├── di/            Graph (composition root) + GraphInit wiring
└── ui/
    ├── browser/   PaneController (tree state machine), PaneView, EntryRow
    ├── components/ shared Compose bits (tooltips, predictive back)
    ├── main/      MainViewModel, MainScreen (dual pane + floating toolbar), PermissionGate
    ├── dialogs/   rename/new-folder/delete/zip/details, ops progress + conflicts
    ├── viewer/    image / text / hex viewers, audio player, frame-accurate video player
    ├── search/    search overlay
    ├── settings/  settings screen
    ├── appinfo/   app details overlay
    └── theme/     MaterialExpressiveTheme setup

vendor/bundletool-shaded/   Gradle module shading bundletool 1.18.3 + its pinned deps

Entry ids are URI-like strings: file:///abs/path, zip:///abs/archive.zip!/inner/path, apps://package.name, root:///abs/path.

Build & run

./gradlew :app:assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk

Requires JDK 17+ and an Android SDK with platform 37. On first launch grant "All files access" (the app deep-links to the system page).

Releases

A GitHub Actions workflow (.github/workflows/release.yml) builds a signed APK on every push to main on GitHub-hosted Ubuntu runners:

  • The build number (versionCode) increments each run (github.run_number).
  • versionName lives in version.properties. While it's unchanged, each push just refreshes a single rolling nightly prerelease with the latest build. Bump versionName to cut a new stable vX.Y release.
  • Signing keys/passwords come from repo secrets: KEYSTORE_BASE64, KEYSTORE_PASSWORD, KEY_ALIAS, KEY_PASSWORD.

License

GPL-3.0-only. A file manager that can be handed root deserves a licence that keeps every future copy open — if you ship a modified XFiles, ship its source too.


This is a study/clone project inspired by X-plore File Manager; it shares no code or assets with the original.

Release Notes & Changelog

XFiles 1.5.0 · build 44 (007807918e6a67e6eb3080fe5a585130d3d9db6e). Offline, open-source file manager — no network, no telemetry.

Changes since v1.4.0

  • Write 1.4.0 release notes for Play
  • Offer XFiles as a PDF and text viewer from other apps
  • Edit a slice of a large text file instead of the whole document
  • Keep the play control from flipping while seeking video
  • Switch release builds to GitHub-hosted Ubuntu runners
  • Show folder item counts that match the visible tree
  • Edit text one row at a time with document-range selection
  • Bump AGP, Gradle, and Compose to current releases
  • Keep lists and pickers above the system bars
  • Switch screens with Activity-style predictive back
  • Replace several file ranges in one pass, or in place
  • Edit large text as loaded stretches, not one window
  • Edit empty local files opened from the list
  • Honor wrap while editing text
  • Keep the keyboard up when the caret changes rows
  • Show a saved text file's new size and time in the list
  • Show video under the screen switcher on Android 10
  • Start screen motions after the revealed page's first frame
  • Add a Recycle Bin on each volume
  • Keep storage and Root rows out of Rename and Delete
  • Keep the space before "and N more" in delete confirmations
  • Draw moving screens offscreen when they can't show video
  • Let pane headers skip when a folder expands or collapses
  • Draw the unselected ring instead of an icon per row
  • Ship a Baseline Profile
  • Keep the search hint on one line
  • Give the viewers light status bar icons in the light theme
  • Keep moving screens square when the display reports no corner radius
  • Bump versionName to 1.5.0
  • Write 1.5.0 release notes for Play

Full diff

Declared Android Permissions

13 total

Shizuku API Permissions

moe.shizuku.manager.permission.API_V23

This application connects to the Shizuku service to execute system-level operations with ADB elevated privileges.

Standard Android Permissions

MANAGE_EXTERNAL_STORAGE
READ_EXTERNAL_STORAGE
WRITE_EXTERNAL_STORAGE
QUERY_ALL_PACKAGES
REQUEST_DELETE_PACKAGES
REQUEST_INSTALL_PACKAGES
POST_NOTIFICATIONS
FOREGROUND_SERVICE
FOREGROUND_SERVICE_DATA_SYNC
WAKE_LOCK
ACCESS_NETWORK_STATE
app.local1st.files.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Specifications

Packageapp.local1st.files
LicenseGPL-3.0
GitHub Stars50
Installs174
Target SDKAndroid 14+ (API 37)
Last UpdatedOctober 2, 2026
Release DateOctober 2, 2026
Root RequirementRootless (Shizuku)
ShizuStore Installation

Install via ShizuStore to enable automatic updates and silent installations using Shizuku.

More in File management

Other applications in this category

View all (7)
9.1k383
7.6k745
XFiles - Shizuku App | ShizuPortal