# SukiSU Ultra: a KernelSU fork for non-GKI kernels, KPM and susfs

> SukiSU Ultra is a kernel-based Android root solution forked from KernelSU, adding KPM support, non-GKI and GKI 1.0 compatibility, and a built-in susfs management tool. It is aimed at people who build or flash kernels rather than at users who just want an APK.

**SukiSU-Ultra/SukiSU-Ultra** — Kernel-based Android Root Solution & KPM

- Repository: https://github.com/SukiSU-Ultra/SukiSU-Ultra
- Website: https://SukiSU.org
- Stars: 6,411 · Forks: 1,325
- Language: Kotlin
- License: GPL-3.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/sukisu-ultra-sukisu-ultra

## What SukiSU Ultra adds on top of KernelSU

SukiSU Ultra is a kernel-based root solution for Android, forked from tiann/KernelSU and, in the README's words, "added some interesting changes." The feature list is short and specific: kernel-based su and root access management, App Profile for confining root, support for non-GKI and GKI 1.0, KPM support, and tweaks to the manager theme plus a built-in susfs management tool.

The audience follows from that list. KernelSU proper targets GKI 2.0 devices (kernel 5.10 and newer). SukiSU Ultra keeps that path but also carries the backports needed for older trees. The README states that kernels from 4.4 upward are compatible but must be built manually, and that with more backports 3.x kernels (3.4 to 3.18) can work. Architecture support is narrower than the kernel range: only arm64-v8a, armeabi-v7a (bare) and some X86_64 builds are listed. If you maintain a kernel for a device that upstream KernelSU left behind, that is the gap this fork is aimed at.

## How the kernel side, ksud and the manager fit together

The repository splits cleanly into three parts. kernel/ holds the in-kernel code that provides su and access control. userspace/ contains Rust binaries, with ksud and ksuinit as the two workspace members declared in Cargo.toml. manager/ is the Kotlin Android app, and the justfile shows how the two connect: build_ksud compiles ksud for aarch64-linux-android, then build_manager copies the resulting binary into manager/app/src/main/jniLibs/arm64-v8a/libksud.so before invoking Gradle. The daemon is therefore shipped inside the manager APK as a native library and extracted on the device, which is a common pattern in this family of tools.

KPM, the kernel module system, is not written from scratch here. The README says it is based on KernelPatch, that features redundant with KernelSU were removed, and that only KPM support was retained; the patch repository is linked as ShirkNeko/SukiSU_KernelPatch_patch. The README also notes work in progress on expanding APatch compatibility. That is an honest description of a moving part: the KPM layer is a trimmed KernelPatch, and its compatibility story is still being extended.

## Installing SukiSU Ultra and running a first root check

The README does not inline installation steps. It points at guide/installation.md for installation and guide/how-to-integrate.md for integration, so the exact flashing sequence depends on that guide and on your device. What the repository does show is how the pieces are built, and that is the useful starting point for anyone compiling from source. The workspace is Rust with edition 2024, and the justfile wraps the cross-compilation.

```bash
just build_ksud
```

That alias runs cross build --target aarch64-linux-android --release, producing the ksud binary under target/aarch64-linux-android/release/. Building the manager is a second step that depends on the first.

```bash
just build_manager
```

This copies the ksud binary into manager/app/src/main/jniLibs/arm64-v8a/libksud.so and then runs ./gradlew aDebug inside manager/. If you only want to check the userspace code compiles cleanly, the same file defines a lint target.

```bash
just clippy
```

It runs cargo fmt followed by cross clippy --target aarch64-linux-android --release. On the kernel side, the KPM notes are configuration requirements rather than commands: CONFIG_KPM=y is required, and non-GKI devices additionally need CONFIG_KALLSYMS=y and CONFIG_KALLSYMS_ALL=y. Kernels below 4.19 need set_memory.h backported from 4.19. The manager app itself is distributed through releases; the README does not describe a package-manager install for it.

## KPM configuration is where most first builds fail

The KPM note block is the most concrete constraint in the README, and it is easy to skim past. Three separate switches matter. CONFIG_KPM=y enables the module system at all. On non-GKI devices, CONFIG_KALLSYMS=y and CONFIG_KALLSYMS_ALL=y are also required, which makes sense for a module loader that needs to resolve kernel symbols at runtime but is a real difference from a plain KernelSU build where those options may be off. And for kernels below 4.19, set_memory.h has to be backported from 4.19 before the KPM code will compile.

None of these are optional and none are detected for you at flash time. A build that omits KALLSYMS_ALL may compile and boot while KPM silently fails, which is the kind of failure that costs an afternoon. The README does not document rollback or a recovery path if a flashed kernel does not boot, and it does not list which specific devices or kernel trees have been validated. Treat the compatibility section as a statement of what is theoretically supported rather than a tested matrix.

## SukiSU Ultra against KernelSU, KernelSU Next and Magisk

The honest comparison is about where root lives. Magisk patches the boot image and runs in userspace, so it works on a locked-down stock kernel without rebuilding anything; that is why it remains the default answer for people who do not compile kernels. KernelSU and its forks move the privileged code into the kernel itself, which changes what is visible to userspace checks but requires a kernel that contains the patch.

Within that kernel-based group, the useful axis is kernel coverage and extras. Upstream KernelSU targets GKI 2.0 (5.10+); SukiSU Ultra states support for non-GKI and GKI 1.0 as well, with 4.4+ and eventually 3.x reachable through manual builds and backports. KernelSU Next is a separate fork in the same family, and the search data shows people comparing the two directly, but this README says nothing about it, so any difference beyond the feature list above is not something this material can settle. The same applies to ReSukiSU and to the older RKSU: the README credits RKSU for non-GKI support, which tells you the non-GKI work has lineage, but it does not enumerate what SukiSU Ultra changed relative to it. What this fork does claim on its own is KPM, the trimmed KernelPatch layer, and the bundled susfs management tool.

## Licence split and the cost of tracking this fork

The licence is not uniform across the tree, and the README is explicit about it. Files in the kernel directory are GPL-2.0-only. The launcher artwork matching ic_launcher(?!.*alt.*) is under a separate arrangement with named copyright holders, documented in LICENSE_icon_English and LICENSE_icon_SC. Everything else is GPL-3.0 or later. If you ship a kernel with these patches, the kernel directory's GPL-2.0-only terms are the ones that attach to your kernel source, and they are not the same as the GPL-3.0-or-later terms covering the userspace and manager. That distinction is worth checking with whoever handles licensing on your side; this is a description of what the repository says, not legal advice.

Upgrade cost is the other half. Releases are tagged, with v4.2.0 on 2026-09-01, v4.1.3 on 2026-06-02 and v4.1.2 on 2026-03-09, and the last push to main was on 2026-09-21, so the tree is moving. Because the kernel patch, the ksud Rust binary and the manager APK are versioned together, a kernel built against one release and a manager installed from another is a mismatch you have to manage yourself. The README does not describe a compatibility matrix between ksud and manager versions, and it does not document a downgrade path. Anyone maintaining a device tree should pin to a release tag and rebuild the kernel when they move, rather than updating the manager alone.

## Conclusion

SukiSU Ultra is for people who already build or patch Android kernels and want KPM, susfs and non-GKI support in one tree; anyone who expects a one-click APK install should stay on a stock KernelSU setup or a boot-image patcher. Before committing, check guide/installation.md against your kernel version, confirm CONFIG_KPM=y and, on non-GKI devices, CONFIG_KALLSYMS=y and CONFIG_KALLSYMS_ALL=y, and read the kernel directory's GPL-2.0-only terms separately from the rest of the tree's GPL-3.0-or-later terms.

## FAQ

### What is SukiSU Ultra?

It is a kernel-based root solution for Android devices, forked from tiann/KernelSU, with additional changes. Its feature list covers kernel-based su and root access management, App Profile, non-GKI and GKI 1.0 support, KPM support, and a tweaked manager theme with a built-in susfs management tool.

### How do I install SukiSU Ultra?

The README does not inline the steps; it points to guide/installation.md for installation and guide/how-to-integrate.md for integration. Building from source uses the justfile, where just build_ksud cross-compiles ksud for aarch64-linux-android and just build_manager copies it into the manager's jniLibs before running Gradle.

### How does SukiSU Ultra compare with KernelSU?

SukiSU Ultra is forked from KernelSU and keeps the same kernel-based approach, but adds KPM support, non-GKI and GKI 1.0 compatibility, and a built-in susfs management tool. Upstream KernelSU is described in this README as officially supporting GKI 2.0 devices with kernel 5.10 and newer, while older kernels here require manual builds.

### How do I root with SukiSU Ultra?

The README directs you to guide/installation.md for the installation procedure rather than listing the steps itself, and notes that non-GKI and older kernels have to be built manually with the kernel patch included. It also lists only arm64-v8a, armeabi-v7a (bare) and some X86_64 as currently supported.

### How does SukiSU Ultra compare with KernelSU Next?

This README does not mention KernelSU Next, so it gives no basis for a comparison beyond SukiSU Ultra's own feature list: kernel-based su and root access management, App Profile, non-GKI and GKI 1.0 support, KPM, and the susfs management tool.

### How does SukiSU Ultra compare with Magisk?

SukiSU Ultra is a kernel-based solution forked from KernelSU, so root lives in the kernel and the README lists non-GKI and GKI 1.0 support plus manual builds for older kernels. The README credits Magisk only as prior work in the KernelSU credit list and does not compare the two directly.

## Sources

- [License: GPL-3.0](https://github.com/SukiSU-Ultra/SukiSU-Ultra/blob/main/LICENSE)
- [Project website](https://SukiSU.org)
- [README](https://github.com/SukiSU-Ultra/SukiSU-Ultra/blob/main/README.md)
- [Releases](https://github.com/SukiSU-Ultra/SukiSU-Ultra/releases)
- [SukiSU-Ultra/SukiSU-Ultra on GitHub](https://github.com/SukiSU-Ultra/SukiSU-Ultra)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/sukisu-ultra-sukisu-ultra
