From f1ae8a828573ff4db6d17ac1c78faa62c93433e6 Mon Sep 17 00:00:00 2001 From: Nicholas Andrew Date: Fri, 18 Sep 2026 19:45:36 -0400 Subject: [PATCH 1/2] milanf: integrate KernelSU-Next with manual hooks --- .../vendor/ext_config/moto-holi-milanf.config | 5 ++++ drivers/Kconfig | 1 + drivers/Makefile | 2 ++ drivers/input/input.c | 13 +++++++++- drivers/kernelsu | 1 + fs/exec.c | 8 ++++++ fs/open.c | 10 +++++++ fs/read_write.c | 10 +++++++ fs/stat.c | 26 +++++++++++++++++++ kernel/reboot.c | 9 +++++++ 10 files changed, 84 insertions(+), 1 deletion(-) create mode 120000 drivers/kernelsu diff --git a/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config b/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config index 921287b0132d..edaad1202d95 100644 --- a/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config +++ b/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config @@ -91,3 +91,8 @@ CONFIG_BOARD_USES_DOUBLE_TAP_CTRL=y # Vibrator CONFIG_LDO_VIBRATOR_MMI=m + +# KernelSU-Next +CONFIG_KSU=y +CONFIG_KPROBE_EVENTS=y +CONFIG_KSU_MANUAL_HOOK=y diff --git a/drivers/Kconfig b/drivers/Kconfig index adcc62cb72d1..2d644a6e8dfa 100644 --- a/drivers/Kconfig +++ b/drivers/Kconfig @@ -244,4 +244,5 @@ source "drivers/mmi_relay/Kconfig" source "drivers/sensors/Kconfig" +source "drivers/kernelsu/Kconfig" endmenu diff --git a/drivers/Makefile b/drivers/Makefile index 56f8bdc58920..544781f99d8f 100644 --- a/drivers/Makefile +++ b/drivers/Makefile @@ -194,3 +194,5 @@ obj-$(CONFIG_MMI_ANNOTATE) += mmi_annotate/ obj-$(CONFIG_MMI_INFO) += mmi_info/ obj-$(CONFIG_MMI_RELAY) += mmi_relay/ obj-$(CONFIG_SENSORS_CLASS) += sensors/ + +obj-$(CONFIG_KSU) += kernelsu/ diff --git a/drivers/input/input.c b/drivers/input/input.c index 45fdb9bdf08d..dfc44ee93cec 100644 --- a/drivers/input/input.c +++ b/drivers/input/input.c @@ -375,10 +375,21 @@ static int input_get_disposition(struct input_dev *dev, return disposition; } +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_input_handle_event(unsigned int *type, + unsigned int *code, + int *value); +#endif + static void input_handle_event(struct input_dev *dev, unsigned int type, unsigned int code, int value) { - int disposition = input_get_disposition(dev, type, code, &value); + int disposition; + +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_input_handle_event(&type, &code, &value); +#endif + disposition = input_get_disposition(dev, type, code, &value); if (disposition != INPUT_IGNORE_EVENT && type != EV_SYN) add_input_randomness(type, code, value); diff --git a/drivers/kernelsu b/drivers/kernelsu new file mode 120000 index 000000000000..b32a3654a683 --- /dev/null +++ b/drivers/kernelsu @@ -0,0 +1 @@ +../KernelSU-Next/kernel \ No newline at end of file diff --git a/fs/exec.c b/fs/exec.c index 910b407d267e..57301577d551 100644 --- a/fs/exec.c +++ b/fs/exec.c @@ -1904,11 +1904,19 @@ out_ret: return retval; } +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_execveat(int *fd, struct filename **filename_ptr, + void *argv, void *envp, int *flags); +#endif + static int do_execveat_common(int fd, struct filename *filename, struct user_arg_ptr argv, struct user_arg_ptr envp, int flags) { +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_execveat(&fd, &filename, &argv, &envp, &flags); +#endif return __do_execve_file(fd, filename, argv, envp, flags, NULL); } diff --git a/fs/open.c b/fs/open.c index 3f9f5fda8ebf..8f79da0318e7 100644 --- a/fs/open.c +++ b/fs/open.c @@ -345,6 +345,12 @@ SYSCALL_DEFINE4(fallocate, int, fd, int, mode, loff_t, offset, loff_t, len) * We do this by temporarily clearing all FS-related capabilities and * switching the fsuid/fsgid around to the real ones. */ +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_faccessat(int *dfd, + const char __user **filename_user, + int *mode, int *flags); +#endif + long do_faccessat(int dfd, const char __user *filename, int mode) { const struct cred *old_cred; @@ -354,6 +360,10 @@ long do_faccessat(int dfd, const char __user *filename, int mode) int res; unsigned int lookup_flags = LOOKUP_FOLLOW; +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_faccessat(&dfd, &filename, &mode, NULL); +#endif + if (mode & ~S_IRWXO) /* where's F_OK, X_OK, W_OK, R_OK? */ return -EINVAL; diff --git a/fs/read_write.c b/fs/read_write.c index 301c4a4ba1d0..438363d9bfd6 100644 --- a/fs/read_write.c +++ b/fs/read_write.c @@ -443,10 +443,20 @@ ssize_t kernel_read(struct file *file, void *buf, size_t count, loff_t *pos) } EXPORT_SYMBOL_NS(kernel_read, ANDROID_GKI_VFS_EXPORT_ONLY); +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_vfs_read(struct file **file_ptr, + char __user **buf_ptr, + size_t *count_ptr, loff_t **pos); +#endif + ssize_t vfs_read(struct file *file, char __user *buf, size_t count, loff_t *pos) { ssize_t ret; +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_vfs_read(&file, &buf, &count, &pos); +#endif + if (!(file->f_mode & FMODE_READ)) return -EBADF; if (!(file->f_mode & FMODE_CAN_READ)) diff --git a/fs/stat.c b/fs/stat.c index 298eb77668a7..fee429033ff0 100644 --- a/fs/stat.c +++ b/fs/stat.c @@ -165,6 +165,18 @@ EXPORT_SYMBOL(vfs_statx_fd); * * 0 will be returned on success, and a -ve error code if unsuccessful. */ +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_stat(int *dfd, + const char __user **filename_user, + int *flags); +extern void ksu_handle_newfstat_ret(unsigned int *fd, + struct stat __user **statbuf_ptr); +#if defined(__ARCH_WANT_STAT64) || defined(__ARCH_WANT_COMPAT_STAT64) +extern void ksu_handle_fstat64_ret(unsigned long *fd, + struct stat64 __user **statbuf_ptr); +#endif +#endif + int vfs_statx(int dfd, const char __user *filename, int flags, struct kstat *stat, u32 request_mask) { @@ -172,6 +184,10 @@ int vfs_statx(int dfd, const char __user *filename, int flags, int error = -EINVAL; unsigned int lookup_flags = LOOKUP_FOLLOW | LOOKUP_AUTOMOUNT; +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_stat(&dfd, &filename, &flags); +#endif + if ((flags & ~(AT_SYMLINK_NOFOLLOW | AT_NO_AUTOMOUNT | AT_EMPTY_PATH | KSTAT_QUERY_FLAGS)) != 0) return -EINVAL; @@ -379,6 +395,11 @@ SYSCALL_DEFINE2(newfstat, unsigned int, fd, struct stat __user *, statbuf) if (!error) error = cp_new_stat(&stat, statbuf); +#ifdef CONFIG_KSU_MANUAL_HOOK + if (!error) + ksu_handle_newfstat_ret(&fd, &statbuf); +#endif + return error; } #endif @@ -506,6 +527,11 @@ SYSCALL_DEFINE2(fstat64, unsigned long, fd, struct stat64 __user *, statbuf) if (!error) error = cp_new_stat64(&stat, statbuf); +#ifdef CONFIG_KSU_MANUAL_HOOK + if (!error) + ksu_handle_fstat64_ret(&fd, &statbuf); +#endif + return error; } diff --git a/kernel/reboot.c b/kernel/reboot.c index 790c2f514a55..1bd622a83446 100644 --- a/kernel/reboot.c +++ b/kernel/reboot.c @@ -310,6 +310,11 @@ DEFINE_MUTEX(system_transition_mutex); * * reboot doesn't sync: do that yourself before calling this. */ +#ifdef CONFIG_KSU_MANUAL_HOOK +extern int ksu_handle_sys_reboot(int magic1, int magic2, unsigned int cmd, + void __user **arg); +#endif + SYSCALL_DEFINE4(reboot, int, magic1, int, magic2, unsigned int, cmd, void __user *, arg) { @@ -317,6 +322,10 @@ SYSCALL_DEFINE4(reboot, int, magic1, int, magic2, unsigned int, cmd, char buffer[256]; int ret = 0; +#ifdef CONFIG_KSU_MANUAL_HOOK + ksu_handle_sys_reboot(magic1, magic2, cmd, &arg); +#endif + /* We only trust the superuser with rebooting the system. */ if (!ns_capable(pid_ns->user_ns, CAP_SYS_BOOT)) return -EPERM; From 85166fb02e62f8f90c14b23b7803583cfe2d5d84 Mon Sep 17 00:00:00 2001 From: Nicholas Andrew Date: Sat, 19 Sep 2026 20:02:50 -0400 Subject: [PATCH 2/2] sm6375: enable KernelSU-Next in common Lineage config --- .../arm64/configs/vendor/ext_config/lineage_moto-holi.config | 4 ++++ arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config | 5 ----- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/arch/arm64/configs/vendor/ext_config/lineage_moto-holi.config b/arch/arm64/configs/vendor/ext_config/lineage_moto-holi.config index 388ca4fa9f3a..80d66fc189f9 100644 --- a/arch/arm64/configs/vendor/ext_config/lineage_moto-holi.config +++ b/arch/arm64/configs/vendor/ext_config/lineage_moto-holi.config @@ -48,3 +48,7 @@ CONFIG_QCA_CLD_WLAN=m # ZRAM CONFIG_ZRAM_WRITEBACK=y + +# KernelSU-Next +CONFIG_KSU=y +CONFIG_KSU_MANUAL_HOOK=y diff --git a/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config b/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config index edaad1202d95..921287b0132d 100644 --- a/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config +++ b/arch/arm64/configs/vendor/ext_config/moto-holi-milanf.config @@ -91,8 +91,3 @@ CONFIG_BOARD_USES_DOUBLE_TAP_CTRL=y # Vibrator CONFIG_LDO_VIBRATOR_MMI=m - -# KernelSU-Next -CONFIG_KSU=y -CONFIG_KPROBE_EVENTS=y -CONFIG_KSU_MANUAL_HOOK=y