name: Setup SUSFS description: Clone and apply SUSFS patches with version-specific fixes inputs: use_latest_commits: description: 'Use the latest commit on the branch instead of the pinned commit' required: false default: true version: description: 'Kernel config version (e.g., android15-6.6)' required: true android_version: description: 'Android version (e.g., android15)' required: true kernel_version: description: 'Kernel version (e.g., 6.6)' required: true os_patch_level: description: 'OS patch level (e.g., 2024-07)' required: true sublevel: description: 'Kernel sublevel' required: true runs: using: composite steps: - name: Setup SUSFS Branch shell: bash run: | set -euo pipefail SUSFS_BRANCH="gki-${{ inputs.version }}" SUSFS_REPO="https://gitlab.com/simonpunk/susfs4ksu.git" echo "Preparing SUSFS for branch: $SUSFS_BRANCH" echo "Cloning latest from $SUSFS_BRANCH..." git clone "$SUSFS_REPO" -b "$SUSFS_BRANCH" susfs4ksu if [ "${{ inputs.use_latest_commits }}" != "true" ]; then COMMITS_JSON="${{ github.workspace }}/.github/config/commits.json" SUSFS_COMMIT=$(jq -er --arg key "$SUSFS_BRANCH" '.susfs[$key]' "$COMMITS_JSON") cd ${{ github.workspace }}/susfs4ksu git checkout "$SUSFS_COMMIT" fi - name: Enable KernelSU SUSFS Config shell: bash working-directory: ${{ github.workspace }}/kernel run: | cat >> "${{ github.workspace }}/wild_gki.fragment" << 'EOF' # KernelSU SUSFS Configuration CONFIG_KSU_SUSFS=y CONFIG_KSU_SUSFS_SUS_PATH=y CONFIG_KSU_SUSFS_SUS_MOUNT=y CONFIG_KSU_SUSFS_SUS_KSTAT=y CONFIG_KSU_SUSFS_SPOOF_UNAME=y CONFIG_KSU_SUSFS_ENABLE_LOG=y CONFIG_KSU_SUSFS_HIDE_KSU_SUSFS_SYMBOLS=y CONFIG_KSU_SUSFS_SPOOF_CMDLINE_OR_BOOTCONFIG=y CONFIG_KSU_SUSFS_OPEN_REDIRECT=y CONFIG_KSU_SUSFS_SUS_MAP=y EOF - name: Apply KSU SUSFS Patches if: false shell: bash working-directory: ${{ github.workspace }}/kernel/KernelSU-Next run: | cp ${{ github.workspace }}/kernel_patches/wild/ksun-5a4a718-susfs-f7ae19ef-gki-android14-6.1.patch ./ patch -p1 < ksun-5a4a718-susfs-f7ae19ef-gki-android14-6.1.patch - name: Apply Kernel SUSFS Patches shell: bash working-directory: ${{ github.workspace }}/kernel/common run: | # Apply base SUSFS patches cp "${{ github.workspace }}/susfs4ksu/kernel_patches/fs/"* "${{ github.workspace }}/kernel/common/fs/" cp "${{ github.workspace }}/susfs4ksu/kernel_patches/include/linux/"* "${{ github.workspace }}/kernel/common/include/linux/" cp ${{ github.workspace }}/susfs4ksu/kernel_patches/50_add_susfs_in_gki-${{ inputs.version }}.patch ./ - name: Apply Android 12 5.10 Fake Patches shell: bash if: inputs.version == 'android12-5.10' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "43" ]; then echo "Applying base.c Android 12 5.10 Fake Patch" perl -i -pe 's/(int|size_t)\s+this_len\s*=\s*min_t\s*\(\s*\1\s*,/size_t this_len = min_t(size_t,/;' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "117" ]; then echo "Applying fdinfo.c Android 12 5.10 Fake Patch" sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c fi - name: Apply Android 13 5.10 Fake Patches shell: bash if: inputs.version == 'android13-5.10' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Applying Android 13 5.10 SUSFS fixes" if [ "${{ inputs.sublevel }}" -le "107" ]; then echo "Applying fdinfo.c Android 13 5.10 Fake Patch" sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c fi - name: Apply Android 13 5.15 Fake Patches shell: bash if: inputs.version == 'android13-5.15' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Applying Android 13 5.15 SUSFS fixes" if [ "${{ inputs.sublevel }}" -le "41" ]; then #echo "Applying base.c Android 13 5.15 Fake Patch" #sed -i 's/^int this_len = min_t(int, count, PAGE_SIZE);$/size_t this_len = min_t(size_t, count, PAGE_SIZE);/' fs/proc/base.c echo "Applying namespace.c Android 13 5.15 SUSFS fixes" sed -i '/^#include $/a #include ' fs/namespace.c echo "Applying open.c Android 13 5.15 Fake Patch" sed -i '/^#include $/a #include ' fs/open.c echo "Applying fdinfo.c Android 13 5.15 Fake Patch" sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c fi if [ "${{ inputs.sublevel }}" -ge "207" ]; then echo "Applying task_mmu.c Android 13 5.15 Fake Patch" sed -i '/^#include $/d' fs/proc/task_mmu.c fi - name: Apply Android 14 6.1 Fake Patches shell: bash if: inputs.version == 'android14-6.1' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "25" ]; then echo "Applying base.c Android 14 6.1 Fake Patch" sed -i '/^#include $/a #include ' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "141" ]; then echo "Applying base.c Android 14 6.1 Fake Patch" sed -i '/^#include $/a #include ' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -ge "157" ]; then echo "Applying namespace.c Android 14 6.1 Fake Patch" sed -i '/^#include $/d' fs/namespace.c fi - name: Apply Android 15 6.6 Fake Patches shell: bash if: inputs.version == 'android15-6.6' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Applying 6.6 SUSFS fixes" if [ "${{ inputs.sublevel }}" -le "30" ]; then echo "Applying taskmmu.c Android 15 6.6 Fake Patch" sed -i '/smap_gather_stats(vma, &mss, last_vma_end);/a\last_vma_end = vma->vm_end;' fs/proc/task_mmu.c fi if [ "${{ inputs.sublevel }}" -le "92" ]; then echo "Applying base.c Android 15 6.6 Fake Patch" sed -i '/^#include $/a #include ' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "57" ]; then echo "Applying base.c Android 15 6.6 Fake Patch" sed -i '/^#include $/a #include ' mm/memory.c fi - name: Apply Android 16 6.12 Fake Patches shell: bash if: inputs.version == 'android16-6.12' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Applying 6.12 SUSFS fixes" if [ "${{ inputs.sublevel }}" -ge "58" ]; then echo "Applying exec.c Android 16 6.12 Fake Patch" sed -i '/^#include $/d' fs/exec.c fi if [ "${{ inputs.sublevel }}" -ge "69" ]; then echo "Applying task_mmu.c Android 16 6.12 Fake Patch" sed -i 's/vma_pages/vma_data_pages/g' fs/proc/task_mmu.c fi - name: Apply Kernel SUSFS Patches shell: bash working-directory: ${{ github.workspace }}/kernel/common run: | patch -p1 < 50_add_susfs_in_gki-${{ inputs.version }}.patch - name: Revert Android 12 5.10 Fake Patches shell: bash if: inputs.version == 'android12-5.10' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "43" ]; then echo "Reverting base.c Android 12 5.10 Fake Patch" sed -i 's/^size_t this_len = min_t(size_t, count, PAGE_SIZE);$/int this_len = min_t(int, count, PAGE_SIZE);/' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "117" ]; then echo "Reverting fdinfo.c Android 12 5.10 Fake Patch" perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c fi - name: Revert Android 13 5.10 Fake Patches shell: bash if: inputs.version == 'android13-5.10' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "107" ]; then echo "Reverting fdinfo.c Android 13 5.10 Fake Patch" perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c fi - name: Revert Android 13 5.15 Fake Patches shell: bash if: inputs.version == 'android13-5.15' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "41" ]; then #echo "Reverting base.c Android 13 5.15 Fake Patch" #sed -i 's/^size_t this_len = min_t(size_t, count, PAGE_SIZE);$/int this_len = min_t(int, count, PAGE_SIZE);/' fs/proc/base.c echo "Reverting namespace.c Android 13 5.15 Fake Patch" sed -i '/#include $/d' fs/namespace.c echo "Reverting open.c Android 13 5.15 Fake Patch" sed -i '/#include $/d' fs/open.c echo "Reverting fdinfo.c Android 13 5.15 Fake Patch" perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c sed -i 's|i_uid_into_mnt(i_user_ns(&fi->inode), &fi->inode).val|i_uid_into_mnt(\&init_user_ns, \&fi->inode).val|g' fs/susfs.c sed -i 's|i_uid_into_mnt(i_user_ns(inode), inode).val|i_uid_into_mnt(\&init_user_ns, inode).val|g' fs/susfs.c fi if [ "${{ inputs.sublevel }}" -ge "207" ]; then echo "Reverting task_mmu.c Android 13 5.15 Fake Patch" sed -i '/^#include $/a #include ' fs/proc/task_mmu.c fi - name: Revert Android 14 6.1 Fake Patches shell: bash if: inputs.version == 'android14-6.1' working-directory: ${{ github.workspace }}/kernel/common run: | if [ "${{ inputs.sublevel }}" -le "25" ]; then sed -i '/^#include $/d' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "141" ]; then echo "Reverting base.c Android 14 6.1 Fake Patch" sed -i '/^#include $/d' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -ge "157" ]; then echo "Reverting namespace.c Android 14 6.1 Fake Patch" sed -i '/^#include "internal.h"$/a #include ' fs/namespace.c fi - name: Revert Android 15 6.6 Fake Patches shell: bash if: inputs.version == 'android15-6.6' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Reverting 6.6 Fake Patches" if [ "${{ inputs.sublevel }}" -le "92" ]; then echo "Reverting base.c Android 15 6.6 Fake Patch" sed -i '/^#include $/d' fs/proc/base.c fi if [ "${{ inputs.sublevel }}" -le "57" ]; then echo "Reverting memory.c Android 15 6.6 Fake Patch" sed -i '/^#include $/d' mm/memory.c fi - name: Revert Android 16 6.12 Fake Patches shell: bash if: inputs.version == 'android16-6.12' working-directory: ${{ github.workspace }}/kernel/common run: | echo "Reverting 6.12 Fake Patches" if [ "${{ inputs.sublevel }}" -ge "58" ]; then echo "Reverting exec.c Android 16 6.12 Fake Patch" sed -i '/^#include /a #include ' fs/exec.c fi if [ "${{ inputs.sublevel }}" -ge "69" ]; then echo "Reverting task_mmu.c Android 16 6.12 Fake Patch" sed -i 's/vma_pages/vma_data_pages/g' fs/proc/task_mmu.c fi - name: Apply Kernel SUSFS Patches shell: bash if: true working-directory: ${{ github.workspace }}/kernel/common run: | SHOW_PAD_FIX=0 if [[ "${{ inputs.version }}" = "android12-5.10" && "${{ inputs.sublevel }}" -le 209 ]]; then SHOW_PAD_FIX=1 elif [[ "${{ inputs.version }}" = "android13-5.10" && "${{ inputs.sublevel }}" -le 209 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then SHOW_PAD_FIX=1 elif [[ "${{ inputs.version }}" = "android13-5.15" && "${{ inputs.sublevel }}" -le 148 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then SHOW_PAD_FIX=1 elif [[ "${{ inputs.version }}" = "android14-5.15" && "${{ inputs.sublevel }}" -le 148 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then SHOW_PAD_FIX=1 elif [[ "${{ inputs.version }}" = "android14-6.1" && "${{ inputs.sublevel }}" -le 75 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then SHOW_PAD_FIX=1 fi if [[ "$SHOW_PAD_FIX" = "1" ]]; then sed -i -e 's/goto show_pad;/return 0;/' ./fs/proc/task_mmu.c fi