Go to file
topjohnwu 5f1174de27 Introduce new boot flow to handle SAR 2SI
The existing method for handling legacy SAR is:
1. Mount /sbin tmpfs overlay
2. Dump all patched/new files into /sbin
3. Magic mount root dir and re-exec patched stock init

With Android 11 removing the /sbin folder, it is quite obvious that
things completely break down right in step 1.

To overcome this issue, we have to find a way to swap out the init
binary AFTER we re-exec stock init. This is where 2SI comes to rescue!

2SI normal boot procedure is:
1st stage -> Load sepolicy -> 2nd stage -> boot continue...

2SI Magisk boot procedure is:
MagiskInit 1st stage -> Stock 1st stage -> MagiskInit 2nd Stage ->
-> Stock init load sepolicy -> Stock 2nd stage -> boot continue...

As you can see, the trick is to make stock 1st stage init re-exec back
into MagiskInit so we can do our setup. This is possible by manipulating
some ramdisk files on initramfs based 2SI devices (old ass non SAR
devices AND super modern devices like Pixel 3/4), but not possible
on device that are stuck using legacy SAR (device that are not that
modern but not too old, like Pixel 1/2. Fucking Google logic!!)

This commit introduces a new way to intercept stock init re-exec flow:
ptrace init with forked tracer, monitor PTRACE_EVENT_EXEC, then swap
out the init file with bind mounts right before execv returns!

Going through this flow however will lose some necessary backup files,
so some bookkeeping has to be done by making the tracer hold these
files in memory and act as a daemon. 2nd stage MagiskInit will ack the
daemon to release these files at the correct time.

It just works™  ¯\_(ツ)_/¯
2020-04-01 04:39:28 -07:00
app Move surequest out of legacy 2020-03-30 23:53:21 -07:00
docs Update logo.png 2020-03-23 05:12:30 -07:00
gradle/wrapper Update AS 2020-01-12 04:51:52 +08:00
native Introduce new boot flow to handle SAR 2SI 2020-04-01 04:39:28 -07:00
scripts Make version reporting consistent 2020-03-23 01:17:13 -07:00
shared Move several stuffs out of shared 2020-03-30 04:25:42 -07:00
signing Ignore existing attributes in manifest 2020-03-28 21:42:31 -07:00
snet Update snet extension 2019-08-08 04:18:32 -07:00
stub Properly set themes for dialogs in stub 2020-03-30 04:03:33 -07:00
tools Clean elf after building shared binaries 2019-08-22 02:51:17 +08:00
.gitattributes Small native code reorganization 2020-03-09 01:50:30 -07:00
.gitignore Make main app fully independent from the stub 2019-10-17 02:55:42 -04:00
.gitmodules Add BusyBox SELinux support 2020-01-20 20:48:05 +08:00
build.gradle Don't need to find system_dev 2020-03-31 22:41:25 -07:00
build.py Update build.py 2020-03-27 23:23:26 -07:00
config.prop.sample Assign signing keystore location in config 2019-10-17 16:20:01 -04:00
gradle.properties Updated build tools & enabled incremental kapt 2019-05-09 15:27:37 +02:00
gradlew Update Gradle wrapper to 5.6.1 2019-09-01 01:17:22 +08:00
gradlew.bat Update Gradle wrapper to 5.6.1 2019-09-01 01:17:22 +08:00
LICENSE Use GPL v3 license and update copyright messages 2017-04-22 17:12:54 +08:00
README.MD Update stable release badges 2020-03-27 21:43:52 -07:00
settings.gradle Remove net module 2019-08-04 18:33:20 -07:00

ZIP Downloads APK Downloads

Introduction

Magisk is a suite of open source tools for customizing Android, supporting devices higher than Android 4.2. It covers fundamental parts of Android customization: root, boot scripts, SELinux patches, AVB2.0 / dm-verity / forceencrypt removals etc.

Here are some feature highlights:

  • MagiskSU: Provide root access to your device
  • Magisk Modules: Modify read-only partitions by installing modules
  • MagiskHide: Hide Magisk from root detections / system integrity checks

Download


Android Version Support

  • Android 4.2+: MagiskSU and Magisk Modules Only
  • Android 4.4+: All core features available
  • Android 6.0+: Guaranteed MagiskHide support
  • Android 7.0+: Full MagiskHide protection
  • Android 9.0+: Magisk Manager stealth mode

Bug Reports

Canary Channels are cutting edge builds for those adventurous. To access canary builds, install either Canary Magisk Manager, switch to a Canary Channel in settings and upgrade.

Only bug reports from Canary DEBUG builds will be accepted.

For installation issues, upload both boot image and install logs.
For Magisk issues, upload boot logcat or dmesg.
For Magisk Manager crashes, record and upload the logcat when the crash occurs.

Building Magisk

  • Clone sources: git clone --recurse-submodules https://github.com/topjohnwu/Magisk.git
  • Magisk builds on any OS Android Studio supports. Install Android Studio and import the project.
  • Python 3.6+. For Windows only, install Colorama with pip install colorama in admin shell.
  • Use the JDK bundled in Android Studio:
    • macOS: export JAVA_HOME="/Applications/Android Studio.app/Contents/jre/jdk/Contents/Home"
    • Linux: export PATH="/path/to/androidstudio/jre/bin:$PATH"
    • Windows: Add C:\Path\To\Android Studio\jre\bin to environment variable PATH
  • Set environment variable ANDROID_HOME to the Android SDK folder
  • Download / clone FrankeNDK and set environment variable ANDROID_NDK_HOME to the folder
  • Set configurations in config.prop. A sample file config.prop.sample is provided.
  • Run build.py to see help messages. For each supported actions, use -h to access help (e.g. ./build.py all -h)
  • By default, the script builds everything in debug mode. If you want to build Magisk Manager in release mode (with the -r, --release flag), you need a Java Keystore (only JKS format is supported) to sign APKs and zips. For more information, check Google's Documentation.

Translation Contributions

Default string resources for Magisk Manager and its stub APK are located here:

  • app/src/main/res/values/strings.xml
  • stub/src/main/res/values/strings.xml

Translate each and place them in the respective locations ([module]/src/main/res/values-[lang]/strings.xml).

License

Magisk, including all git submodules are free software:
you can redistribute it and/or modify it under the terms of the
GNU General Public License as published by the Free Software Foundation,
either version 3 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.

You should have received a copy of the GNU General Public License
along with this program.  If not, see <http://www.gnu.org/licenses/>.