KernelSU: a kernel-level root solution for Android GKI 2.0 devices
A Kernel based root solution for Android. Compatibility state KernelSU officially supports Android GKI 2.0 devices (kernel 5.10+).
At a glance
- What is it?
- KernelSU moves root management into the Android kernel instead of patching the boot image. It supports GKI 2.0 devices on kernel 5.10 and newer, with older 4.14+ kernels requiring a manual build, and the README warns of a breaking change that can panic x86_64 kernels.
- Who is it for?
- Adopt KernelSU if you have a GKI 2.0 device on kernel 5.10 or newer and you are willing to build ksud from the workspace Cargo.toml before touching the manager app. Do not adopt it for a 4.14 kernel unless you intend to build the kernel yourself, and do not adopt it on x86_64 without reading the website warning about the breaking change that can trigger a kernel panic.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 5 days ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
DEEP OPEN-SOURCE ANALYSIS
What KernelSU solves, and which Android devices it actually covers
The README describes KernelSU as "a kernel-based root solution for Android devices", with a kernel-based su and root access management as its first feature. That phrasing matters. Root management lives in the kernel, so the mechanism does not depend on a patched boot image in the way userspace-first root tools do. The compatibility statement is narrow and honest: KernelSU officially supports Android GKI 2.0 devices, which the README defines as kernel 5.10 and above. Kernels from 4.14 upward are also supported, but the kernel must be built manually. Architectures are limited to arm64-v8a and x86_64. WSA, ChromeOS and container-based Android are listed as supported environments. Anyone running an older vendor kernel outside those architectures is outside the supported set, and the README does not offer a path for them.
How kernel-based su and metamodules fit together
Three features are listed. First, kernel-based su and root access management: the su binary and the permission decision sit on the kernel side. Second, a module system the README calls "based on metamodules", described as pluggable infrastructure for systemless modifications. Third, App Profile, which the README summarises as "Lock up the root power in a cage", meaning root grants can be scoped rather than handed out globally. The repository layout backs this up. There is a kernel/ directory, a manager/ directory holding the Android app, a userspace/ directory with Rust crates, and a uapi/ directory for the kernel-userspace interface. The workspace Cargo.toml declares two members, userspace/ksud and userspace/ksuinit, so ksud is the userspace daemon and ksuinit is the early init component. The Kotlin manager app is the UI layer on top. The GPL split follows the same boundary: kernel/ is GPL-2.0-only, everything else is GPL-3.0-or-later.
Installing KernelSU and building ksud from source
The README does not carry install steps inline. It links to https://kernelsu.org/guide/installation.html and https://kernelsu.org/guide/how-to-build.html, so the official website is the source of truth for flashing. What the repository does give is the build path. The justfile defines aliases and recipes, and build_ksud is the first step: it cross-compiles the userspace daemon for aarch64-linux-android in release mode.
just build_ksudThe build_manager recipe depends on build_ksud, copies the resulting binary into the manager app's JNI libraries as libksud.so, then runs the Gradle debug build.
just build_managerAfter that command the manager APK is produced by Gradle from the manager/ directory. The release profile in Cargo.toml is tuned for size rather than speed: strip, lto, opt-level = "z", panic = "abort", and codegen-units = 1 for the ksud package. If you only want to check the code, the clippy recipe runs cargo fmt and then cross clippy with the same Android target.
just clippyFor flashing and first-run setup, follow the website's installation guide rather than improvising from the repository.
The x86_64 kernel panic warning and other real limits
The README carries a caution block that is easy to skim past: recent kernel versions have implemented a breaking change causing KernelSU to fail and potentially trigger a kernel panic on x86_64, and it points to the website for more information. A kernel panic is not a soft failure. On an x86_64 Android environment such as WSA or a container image, that is a boot-level risk, and the README does not describe a workaround in the repository itself. The second limit is the manual kernel build requirement for 4.14+ kernels, which turns installation into a kernel development task rather than a flashing task. The third is architecture: arm64-v8a and x86_64 only, so 32-bit devices are out of scope. Finally, the README states that translation contributions via Weblate are no longer accepted and that existing English and Chinese translations are not open to modification, which is unusual for a project with a large translated README set and worth knowing before opening a language PR.
KernelSU compared with Magisk
The two take opposite approaches to the same goal. Magisk is credited in the README as "The powerful root tool", and it works by patching the boot image, which keeps root in userspace and leaves the kernel untouched. KernelSU puts su and access control in the kernel, which is why the compatibility list is tied to kernel versions and architectures rather than to device models. The trade-off is concrete: Magisk can cover a wider range of devices because it does not require a suitable kernel, while KernelSU's support surface is defined by GKI 2.0 and the two listed architectures. In exchange, KernelSU's module system is built on metamodules, its App Profile scopes root grants, and the project also lists Kernel-Assisted Superuser as the origin of the idea. If your device kernel cannot be rebuilt and is not GKI 2.0, Magisk is the more realistic option. If it is, KernelSU gives you a root mechanism that lives below the boot image.
Maintenance, licence and upgrade cost
The last push to main was on 2026-08-28, and the most recent release is v3.3.0 from the same date, following v3.2.5 on 2026-06-23 and v3.2.4 on 2026-04-06. The repository is not archived. That release cadence means upgrades arrive as tagged versions rather than as a rolling branch, so pinning to v3.3.0 is possible. The upgrade cost is not just the manager APK. Because ksud is a Rust binary built through cross for aarch64-linux-android and copied into the manager's jniLibs, a source build couples the userspace daemon to the app. On the licence side, the split is explicit: files under kernel/ are GPL-2.0-only, all other parts are GPL-3.0-or-later. Shipping a modified kernel module or a repackaged manager therefore carries different obligations depending on which directory you touched. This is a description of the licence text, not legal advice; read LICENSE and the linked GPL texts before distributing anything.
Editorial conclusion
Adopt KernelSU if you have a GKI 2.0 device on kernel 5.10 or newer and you are willing to build ksud from the workspace Cargo.toml before touching the manager app. Do not adopt it for a 4.14 kernel unless you intend to build the kernel yourself, and do not adopt it on x86_64 without reading the website warning about the breaking change that can trigger a kernel panic. Verify first that your device is arm64-v8a or x86_64, that the kernel version meets 5.10, and that you can rebuild the kernel when a new Android release lands.
Frequently asked questions
Is KernelSU better than Magisk?
The README does not rank them. Magisk is credited as the powerful root tool and works by patching the boot image, while KernelSU puts su and root access management in the kernel, which is why its support list is tied to GKI 2.0, kernel 5.10+ and the arm64-v8a and x86_64 architectures.
What is the purpose of KernelSU?
It is a kernel-based root solution for Android, offering kernel-based su and root access management, a metamodule-based module system for systemless modifications, and App Profile for scoping root grants.
How to install KernelSU?
The README does not include install steps. It links to the installation guide at https://kernelsu.org/guide/installation.html, and the repository's justfile provides build_ksud and build_manager for building from source instead.
How to root using KernelSU?
Root access is provided by the kernel-based su component and managed through the manager app. The README directs users to the official website for installation rather than describing the rooting procedure in the repository.
How to remove KernelSU root?
The README and the repository files do not document an uninstall or rollback procedure, so the material cannot answer this. Check the installation guide on kernelsu.org, which is the page the README points to for setup.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/tiann-kernelsu)
Community notes