action.yml 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319
  1. name: Setup SUSFS
  2. description: Clone and apply SUSFS patches with version-specific fixes
  3. inputs:
  4. use_latest_commits:
  5. description: 'Use the latest commit on the branch instead of the pinned commit'
  6. required: false
  7. default: true
  8. version:
  9. description: 'Kernel config version (e.g., android15-6.6)'
  10. required: true
  11. android_version:
  12. description: 'Android version (e.g., android15)'
  13. required: true
  14. kernel_version:
  15. description: 'Kernel version (e.g., 6.6)'
  16. required: true
  17. os_patch_level:
  18. description: 'OS patch level (e.g., 2024-07)'
  19. required: true
  20. sublevel:
  21. description: 'Kernel sublevel'
  22. required: true
  23. runs:
  24. using: composite
  25. steps:
  26. - name: Setup SUSFS Branch
  27. shell: bash
  28. run: |
  29. set -euo pipefail
  30. SUSFS_BRANCH="gki-${{ inputs.version }}"
  31. SUSFS_REPO="https://gitlab.com/simonpunk/susfs4ksu.git"
  32. echo "Preparing SUSFS for branch: $SUSFS_BRANCH"
  33. echo "Cloning latest from $SUSFS_BRANCH..."
  34. git clone "$SUSFS_REPO" -b "$SUSFS_BRANCH" susfs4ksu
  35. if [ "${{ inputs.use_latest_commits }}" != "true" ]; then
  36. COMMITS_JSON="${{ github.workspace }}/.github/config/commits.json"
  37. SUSFS_COMMIT=$(jq -er --arg key "$SUSFS_BRANCH" '.susfs[$key]' "$COMMITS_JSON")
  38. cd ${{ github.workspace }}/susfs4ksu
  39. git checkout "$SUSFS_COMMIT"
  40. fi
  41. - name: Enable KernelSU SUSFS Config
  42. shell: bash
  43. working-directory: ${{ github.workspace }}/kernel
  44. run: |
  45. cat >> "${{ github.workspace }}/wild_gki.fragment" << 'EOF'
  46. # KernelSU SUSFS Configuration
  47. CONFIG_KSU_SUSFS=y
  48. CONFIG_KSU_SUSFS_SUS_PATH=y
  49. CONFIG_KSU_SUSFS_SUS_MOUNT=y
  50. CONFIG_KSU_SUSFS_SUS_KSTAT=y
  51. CONFIG_KSU_SUSFS_SPOOF_UNAME=y
  52. CONFIG_KSU_SUSFS_ENABLE_LOG=y
  53. CONFIG_KSU_SUSFS_HIDE_KSU_SUSFS_SYMBOLS=y
  54. CONFIG_KSU_SUSFS_SPOOF_CMDLINE_OR_BOOTCONFIG=y
  55. CONFIG_KSU_SUSFS_OPEN_REDIRECT=y
  56. CONFIG_KSU_SUSFS_SUS_MAP=y
  57. EOF
  58. - name: Apply KSU SUSFS Patches
  59. if: false
  60. shell: bash
  61. working-directory: ${{ github.workspace }}/kernel/KernelSU-Next
  62. run: |
  63. cp ${{ github.workspace }}/kernel_patches/wild/ksun-5a4a718-susfs-f7ae19ef-gki-android14-6.1.patch ./
  64. patch -p1 < ksun-5a4a718-susfs-f7ae19ef-gki-android14-6.1.patch
  65. - name: Apply Kernel SUSFS Patches
  66. shell: bash
  67. working-directory: ${{ github.workspace }}/kernel/common
  68. run: |
  69. # Apply base SUSFS patches
  70. cp "${{ github.workspace }}/susfs4ksu/kernel_patches/fs/"* "${{ github.workspace }}/kernel/common/fs/"
  71. cp "${{ github.workspace }}/susfs4ksu/kernel_patches/include/linux/"* "${{ github.workspace }}/kernel/common/include/linux/"
  72. cp ${{ github.workspace }}/susfs4ksu/kernel_patches/50_add_susfs_in_gki-${{ inputs.version }}.patch ./
  73. - name: Apply Android 12 5.10 Fake Patches
  74. shell: bash
  75. if: inputs.version == 'android12-5.10'
  76. working-directory: ${{ github.workspace }}/kernel/common
  77. run: |
  78. if [ "${{ inputs.sublevel }}" -le "43" ]; then
  79. echo "Applying base.c Android 12 5.10 Fake Patch"
  80. perl -i -pe 's/(int|size_t)\s+this_len\s*=\s*min_t\s*\(\s*\1\s*,/size_t this_len = min_t(size_t,/;' fs/proc/base.c
  81. fi
  82. if [ "${{ inputs.sublevel }}" -le "117" ]; then
  83. echo "Applying fdinfo.c Android 12 5.10 Fake Patch"
  84. sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c
  85. perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c
  86. perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c
  87. fi
  88. - name: Apply Android 13 5.10 Fake Patches
  89. shell: bash
  90. if: inputs.version == 'android13-5.10'
  91. working-directory: ${{ github.workspace }}/kernel/common
  92. run: |
  93. echo "Applying Android 13 5.10 SUSFS fixes"
  94. if [ "${{ inputs.sublevel }}" -le "107" ]; then
  95. echo "Applying fdinfo.c Android 13 5.10 Fake Patch"
  96. sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c
  97. perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c
  98. perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c
  99. fi
  100. - name: Apply Android 13 5.15 Fake Patches
  101. shell: bash
  102. if: inputs.version == 'android13-5.15'
  103. working-directory: ${{ github.workspace }}/kernel/common
  104. run: |
  105. echo "Applying Android 13 5.15 SUSFS fixes"
  106. if [ "${{ inputs.sublevel }}" -le "41" ]; then
  107. #echo "Applying base.c Android 13 5.15 Fake Patch"
  108. #sed -i 's/^int this_len = min_t(int, count, PAGE_SIZE);$/size_t this_len = min_t(size_t, count, PAGE_SIZE);/' fs/proc/base.c
  109. echo "Applying namespace.c Android 13 5.15 SUSFS fixes"
  110. sed -i '/^#include <linux\/shmem_fs.h>$/a #include <linux/mnt_idmapping.h>' fs/namespace.c
  111. echo "Applying open.c Android 13 5.15 Fake Patch"
  112. sed -i '/^#include <linux\/compat.h>$/a #include <linux/mnt_idmapping.h>' fs/open.c
  113. echo "Applying fdinfo.c Android 13 5.15 Fake Patch"
  114. sed -i '/^[[:space:]]*\/\*$/,/^[[:space:]]*u32 mask = mark->mask & IN_ALL_EVENTS;$/d' fs/notify/fdinfo.c
  115. perl -i -pe 's/\bmask,\s*mark->ignored_mask/inotify_mark_user_mask(mark)/g' fs/notify/fdinfo.c
  116. perl -i -pe 's/ignored_mask:%x/ignored_mask:0/g' fs/notify/fdinfo.c
  117. fi
  118. if [ "${{ inputs.sublevel }}" -ge "197" ]; then
  119. echo "Applying namespace.c Android 13 5.15 Fake Patch"
  120. sed -i '/^#include <trace\/hooks\/blk.h>$/d' fs/namespace.c
  121. fi
  122. if [ "${{ inputs.sublevel }}" -ge "207" ]; then
  123. echo "Applying task_mmu.c Android 13 5.15 Fake Patch"
  124. sed -i '/^#include <trace\/hooks\/mm.h>$/d' fs/proc/task_mmu.c
  125. fi
  126. - name: Apply Android 14 6.1 Fake Patches
  127. shell: bash
  128. if: inputs.version == 'android14-6.1'
  129. working-directory: ${{ github.workspace }}/kernel/common
  130. run: |
  131. if [ "${{ inputs.sublevel }}" -le "25" ]; then
  132. echo "Applying base.c Android 14 6.1 Fake Patch"
  133. sed -i '/^#include <trace\/events\/oom.h>$/a #include <trace/hooks/sched.h>' fs/proc/base.c
  134. fi
  135. if [ "${{ inputs.sublevel }}" -le "141" ]; then
  136. echo "Applying base.c Android 14 6.1 Fake Patch"
  137. sed -i '/^#include <linux\/cpufreq_times.h>$/a #include <linux/dma-buf.h>' fs/proc/base.c
  138. fi
  139. if [ "${{ inputs.sublevel }}" -ge "157" ]; then
  140. echo "Applying namespace.c Android 14 6.1 Fake Patch"
  141. sed -i '/^#include <trace\/hooks\/blk.h>$/d' fs/namespace.c
  142. fi
  143. - name: Apply Android 15 6.6 Fake Patches
  144. shell: bash
  145. if: inputs.version == 'android15-6.6'
  146. working-directory: ${{ github.workspace }}/kernel/common
  147. run: |
  148. echo "Applying 6.6 SUSFS fixes"
  149. if [ "${{ inputs.sublevel }}" -le "30" ]; then
  150. echo "Applying taskmmu.c Android 15 6.6 Fake Patch"
  151. sed -i '/smap_gather_stats(vma, &mss, last_vma_end);/a\last_vma_end = vma->vm_end;' fs/proc/task_mmu.c
  152. #sed -i '0,/last_vma_end = vma->vm_end;/{s/last_vma_end = vma->vm_end;/\t\t\t\t&/}' fs/proc/task_mmu.c
  153. fi
  154. if [ "${{ inputs.sublevel }}" -le "92" ]; then
  155. echo "Applying base.c Android 15 6.6 Fake Patch"
  156. sed -i '/^#include <linux\/cpufreq_times.h>$/a #include <linux/dma-buf.h>' fs/proc/base.c
  157. fi
  158. if [ "${{ inputs.sublevel }}" -le "57" ]; then
  159. echo "Applying base.c Android 15 6.6 Fake Patch"
  160. sed -i '/^#include <linux\/sched\/sysctl.h>$/a #include <linux/zswap.h>' mm/memory.c
  161. fi
  162. - name: Apply Android 16 6.12 Fake Patches
  163. shell: bash
  164. if: inputs.version == 'android16-6.12'
  165. working-directory: ${{ github.workspace }}/kernel/common
  166. run: |
  167. echo "Applying 6.12 SUSFS fixes"
  168. if [ "${{ inputs.sublevel }}" -ge "58" ]; then
  169. echo "Applying exec.c Android 16 6.12 Fake Patch"
  170. sed -i '/^#include <linux\/dma-buf.h>$/d' fs/exec.c
  171. fi
  172. if [ "${{ inputs.sublevel }}" -ge "69" ]; then
  173. echo "Applying task_mmu.c Android 16 6.12 Fake Patch"
  174. sed -i 's/vma_data_pages/vma_pages/g' fs/proc/task_mmu.c
  175. fi
  176. - name: Apply Kernel SUSFS Patches
  177. shell: bash
  178. working-directory: ${{ github.workspace }}/kernel/common
  179. run: |
  180. patch -p1 < 50_add_susfs_in_gki-${{ inputs.version }}.patch
  181. - name: Revert Android 12 5.10 Fake Patches
  182. shell: bash
  183. if: inputs.version == 'android12-5.10'
  184. working-directory: ${{ github.workspace }}/kernel/common
  185. run: |
  186. if [ "${{ inputs.sublevel }}" -le "43" ]; then
  187. echo "Reverting base.c Android 12 5.10 Fake Patch"
  188. sed -i 's/^size_t this_len = min_t(size_t, count, PAGE_SIZE);$/int this_len = min_t(int, count, PAGE_SIZE);/' fs/proc/base.c
  189. fi
  190. if [ "${{ inputs.sublevel }}" -le "117" ]; then
  191. echo "Reverting fdinfo.c Android 12 5.10 Fake Patch"
  192. perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c
  193. perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c
  194. perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c
  195. fi
  196. - name: Revert Android 13 5.10 Fake Patches
  197. shell: bash
  198. if: inputs.version == 'android13-5.10'
  199. working-directory: ${{ github.workspace }}/kernel/common
  200. run: |
  201. if [ "${{ inputs.sublevel }}" -le "107" ]; then
  202. echo "Reverting fdinfo.c Android 13 5.10 Fake Patch"
  203. perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c
  204. perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c
  205. perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c
  206. fi
  207. - name: Revert Android 13 5.15 Fake Patches
  208. shell: bash
  209. if: inputs.version == 'android13-5.15'
  210. working-directory: ${{ github.workspace }}/kernel/common
  211. run: |
  212. if [ "${{ inputs.sublevel }}" -le "41" ]; then
  213. #echo "Reverting base.c Android 13 5.15 Fake Patch"
  214. #sed -i 's/^size_t this_len = min_t(size_t, count, PAGE_SIZE);$/int this_len = min_t(int, count, PAGE_SIZE);/' fs/proc/base.c
  215. echo "Reverting namespace.c Android 13 5.15 Fake Patch"
  216. sed -i '/#include <linux\/mnt_idmapping.h>$/d' fs/namespace.c
  217. echo "Reverting open.c Android 13 5.15 Fake Patch"
  218. sed -i '/#include <linux\/mnt_idmapping.h>$/d' fs/open.c
  219. echo "Reverting fdinfo.c Android 13 5.15 Fake Patch"
  220. perl -i -pe 's/^(\s+if \(inode\) \{)/$1\n\t\t\/\*\n\t\t * IN_ALL_EVENTS represents all of the mask bits\n\t\t * that we expose to userspace. There is at\n\t\t * least one bit (FS_EVENT_ON_CHILD) which is\n\t\t * used only internally to the kernel.\n\t\t *\/\n\t\tu32 mask = mark->mask & IN_ALL_EVENTS;/m' fs/notify/fdinfo.c
  221. perl -i -pe 's/\binotify_mark_user_mask\(mark\)/mask, mark->ignored_mask/g' fs/notify/fdinfo.c
  222. perl -i -pe 's/ignored_mask:0/ignored_mask:%x/g' fs/notify/fdinfo.c
  223. sed -i 's|i_uid_into_mnt(i_user_ns(&fi->inode), &fi->inode).val|i_uid_into_mnt(\&init_user_ns, \&fi->inode).val|g' fs/susfs.c
  224. sed -i 's|i_uid_into_mnt(i_user_ns(inode), inode).val|i_uid_into_mnt(\&init_user_ns, inode).val|g' fs/susfs.c
  225. fi
  226. if [ "${{ inputs.sublevel }}" -ge "197" ]; then
  227. echo "Reverting namespace.c Android 13 5.15 Fake Patch"
  228. sed -i '/^#include "internal.h"$/a #include <trace/hooks/blk.h>' fs/namespace.c
  229. fi
  230. if [ "${{ inputs.sublevel }}" -ge "207" ]; then
  231. echo "Reverting task_mmu.c Android 13 5.15 Fake Patch"
  232. sed -i '/^#include <linux\/pkeys.h>$/a #include <trace/hooks/mm.h>' fs/proc/task_mmu.c
  233. fi
  234. - name: Revert Android 14 6.1 Fake Patches
  235. shell: bash
  236. if: inputs.version == 'android14-6.1'
  237. working-directory: ${{ github.workspace }}/kernel/common
  238. run: |
  239. if [ "${{ inputs.sublevel }}" -le "25" ]; then
  240. sed -i '/^#include <trace\/hooks\/sched.h>$/d' fs/proc/base.c
  241. fi
  242. if [ "${{ inputs.sublevel }}" -le "141" ]; then
  243. echo "Reverting base.c Android 14 6.1 Fake Patch"
  244. sed -i '/^#include <linux\/dma-buf.h>$/d' fs/proc/base.c
  245. fi
  246. if [ "${{ inputs.sublevel }}" -ge "157" ]; then
  247. echo "Reverting namespace.c Android 14 6.1 Fake Patch"
  248. sed -i '/^#include "internal.h"$/a #include <trace/hooks/blk.h>' fs/namespace.c
  249. fi
  250. - name: Revert Android 15 6.6 Fake Patches
  251. shell: bash
  252. if: inputs.version == 'android15-6.6'
  253. working-directory: ${{ github.workspace }}/kernel/common
  254. run: |
  255. echo "Reverting 6.6 Fake Patches"
  256. if [ "${{ inputs.sublevel }}" -le "92" ]; then
  257. echo "Reverting base.c Android 15 6.6 Fake Patch"
  258. sed -i '/^#include <linux\/dma-buf.h>$/d' fs/proc/base.c
  259. fi
  260. if [ "${{ inputs.sublevel }}" -le "57" ]; then
  261. echo "Reverting memory.c Android 15 6.6 Fake Patch"
  262. sed -i '/^#include <linux\/zswap.h>$/d' mm/memory.c
  263. fi
  264. - name: Revert Android 16 6.12 Fake Patches
  265. shell: bash
  266. if: inputs.version == 'android16-6.12'
  267. working-directory: ${{ github.workspace }}/kernel/common
  268. run: |
  269. echo "Reverting 6.12 Fake Patches"
  270. if [ "${{ inputs.sublevel }}" -ge "58" ]; then
  271. echo "Reverting exec.c Android 16 6.12 Fake Patch"
  272. sed -i '/^#include /a #include <linux/dma-buf.h>' fs/exec.c
  273. fi
  274. if [ "${{ inputs.sublevel }}" -ge "69" ]; then
  275. echo "Reverting task_mmu.c Android 16 6.12 Fake Patch"
  276. sed -i 's/vma_pages/vma_data_pages/g' fs/proc/task_mmu.c
  277. fi
  278. - name: Apply Kernel SUSFS Patches
  279. shell: bash
  280. if: true
  281. working-directory: ${{ github.workspace }}/kernel/common
  282. run: |
  283. SHOW_PAD_FIX=0
  284. if [[ "${{ inputs.version }}" = "android12-5.10" && "${{ inputs.sublevel }}" -le 209 ]]; then
  285. SHOW_PAD_FIX=1
  286. elif [[ "${{ inputs.version }}" = "android13-5.10" && "${{ inputs.sublevel }}" -le 209 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then
  287. SHOW_PAD_FIX=1
  288. elif [[ "${{ inputs.version }}" = "android13-5.15" && "${{ inputs.sublevel }}" -le 148 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then
  289. SHOW_PAD_FIX=1
  290. elif [[ "${{ inputs.version }}" = "android14-5.15" && "${{ inputs.sublevel }}" -le 148 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then
  291. SHOW_PAD_FIX=1
  292. elif [[ "${{ inputs.version }}" = "android14-6.1" && "${{ inputs.sublevel }}" -le 75 && "${{ inputs.os_patch_level }}" != "2024-05" ]]; then
  293. SHOW_PAD_FIX=1
  294. fi
  295. if [[ "$SHOW_PAD_FIX" = "1" ]]; then
  296. sed -i -e 's/goto show_pad;/return 0;/' ./fs/proc/task_mmu.c
  297. fi