Magisk General Support / Discussion

Search This thread

Mr Wolf

Senior Member
Aug 1, 2011
69
5
Hi, I have a Xiaomi Redmi 5 Plus with Resurrection Remix OS RR-O-v6.2.1-20181003-vince-Final.
I've just updated to Magisk 24.1 from 23.0 and now, when I boot the phone, I get this message from the Trust Platform:
This build has been signed with public keys

I've never seen this message before. I've googled a bit, but I can't understand well what it means and why it has appeared only know, and, most of all, if it can be safely ignored.
 

silver2004

Senior Member
Feb 10, 2017
92
18
Cool, LG v35 on LineageOS 18.1, Ramdisk (Yes)
update 23.0 -> 24.1 went without any problems :)
Both app&Magisk
I will miss the repo though :(
 
  • Like
Reactions: zgfg

zgfg

Senior Member
Oct 10, 2016
7,196
4,647
I see. Have you tried it using with magisk deny list procedure?
Just tested the following:
- Enabled Enforce DenyList
- Added Chrome to DenyList
- Disabled Enforce DenyList (since I'm using Shamiko that reads DenyList but acts instead of the built-in DenyList)
- Rebooted
- Opened Chrome, Incognito mode and took a screenshot (Incognito mode prevents you taking screenshots without the Secure Screenshots patch)
 

amit_coolcampus

Senior Member
Mar 30, 2013
330
45
Delhi
Samsung Galaxy Note 9
Can
Just tested the following:
- Enabled Enforce DenyList
- Added Chrome to DenyList
- Disabled Enforce DenyList (since I'm using Shamiko that reads DenyList but acts instead of the built-in DenyList)
- Rebooted
- Opened Chrome, Incognito mode and took a screenshot (Incognito mode prevents you taking screenshots without the Secure Screenshots patch)
Got it. This should ideally work then. Can you please also try any banking app for me if thats not a big trouble for you?
 

zgfg

Senior Member
Oct 10, 2016
7,196
4,647
Can

Got it. This should ideally work then. Can you please also try any banking app for me if thats not a big trouble for you?
Maybe tomorrow but give me the banking app. Btw, on my Xiaomi I cannot pass for S-PushTAN, hence I would never be able to take a screenshot there - S-PushTAB drives me immediately to the Web page saying that my phone is not secure

Better try yourself Smali Patcher - it's not prohibited like LP, there is a Smali Patcher thread on XDA

Also, for some phones and ROMs patching (preparing a zip module) fails - in that case, it would not be applicable, you must better test yourself
 
  • Like
Reactions: amit_coolcampus

amit_coolcampus

Senior Member
Mar 30, 2013
330
45
Delhi
Samsung Galaxy Note 9
Maybe tomorrow but give me the banking app. Btw, on my Xiaomi I cannot pass for S-PushTAN, hence I would never be able to take a screenshot there - S-PushTAB drives me immediately to the Web page saying that my phone is not secure

Better try yourself Smali Patcher - it's not prohibited like LP, there is a Smali Patcher thread on XDA

Also, for some phones and ROMs patching (preparing a zip module) fails - in that case, it would not be applicable, you must better test yourself
Yeah, in that case I would give a try myself. I have jasi patches and I think that should work as well if small patches works for you, however I will try and get back.
 

Cronoss

Senior Member
Jul 23, 2013
147
37
Guys, so how are we supposed to hide magisk now from Google Play and stuff like that?
With version 23 I was able to hide magisk ticking all the boxes on Google Play until the blue bar was completely full, and my bank app worked.
What are these "modules" to hide magisk that @topjohnwu is talking about when he announced v24?
 
  • Like
Reactions: access9

amit_coolcampus

Senior Member
Mar 30, 2013
330
45
Delhi
Samsung Galaxy Note 9
Ok here are the findings.
Magisk enforce deny list doesn't allow you to use xposed modules for the apps added in deny list. Means shamiko+ zygisk is the key. Just adding the secured app in the deny list and then use shamiko module. After that you can any patches or stand alone module to disable secure flag, its good to go to use any xposed module.
 

m0han

Senior Member
Apr 30, 2012
4,801
1,890
....- Opened Chrome, Incognito mode and took a screenshot (Incognito mode prevents you taking screenshots without the Secure Screenshots patch)
tried this (did everything as you wrote), but i couldn't get a screenshot. is it because i don't have 'smali patcher for secure flag' module at all? i was thinking you had disabled the module to try the denylist procedure, so reckoned it would work for me without the module. is it a must to have 'smali patcher for secure flag' module installed and enabled, for getting screenshots in secure apps?
 

m0han

Senior Member
Apr 30, 2012
4,801
1,890

yasnac and network_error

not able to get yasnac to work since morning (everything else seems fine atm). anyone else face this issue? not sure if there is a connection, but this issue surfaced (was noticed) after i updated to the latest alpha. what could be the reason? tips to get this resolved would be nice.
 

Attachments

  • Screenshot_20220129-085549_YASNAC.png
    Screenshot_20220129-085549_YASNAC.png
    101.3 KB · Views: 70
  • Screenshot_20220129-093602_MyJisk.png
    Screenshot_20220129-093602_MyJisk.png
    139.2 KB · Views: 67

Homeboy76

Senior Member
Aug 24, 2012
3,169
1,728
Google Pixel XL

yasnac and network_error

not able to get yasnac to work since morning (everything else seems fine atm). anyone else face this issue? not sure if there is a connection, but this issue surfaced (was noticed) after i updated to the latest alpha. what could be the reason? tips to get this resolved would be nice.
 
  • Like
Reactions: m0han

zgfg

Senior Member
Oct 10, 2016
7,196
4,647
tried this (did everything as you wrote), but i couldn't get a screenshot. is it because i don't have 'smali patcher for secure flag' module at all? i was thinking you had disabled the module to try the denylist procedure, so reckoned it would work for me without the module. is it a must to have 'smali patcher for secure flag' module installed and enabled, for getting screenshots in secure apps?
There are apps that don't allow screenshots - like Chrome in Incognito mode, and there are solutions to trick them (to allow the so called Secure screenshots) - like Smali patcher (check-box Secure screenshots while patching)
 

Top Liked Posts

  • 4
    NP but did you resolve?
    Yes, I removed the modules in /data/adb and it worked, thanks to you!
    2
    I need help, I just upgraded my Oneplus 6 from lineage 18 to 19 (Android 12) and when I want to flash magisk, I always end up in a bootloop with the both of the methods, the one with apk renamed as zip and the one with the recovery flashed as boot (I followed this tutorial btw)
    Probably you have Magisk modules, not compatible with A12, that you didn't disable/uninstall before upgrading. They are installed at /dara/adb, hence they were not removed if you didn't ask for Factory reset

    This problem has been discussed here several times, you can check in the previous posts
    Actually, on Magisk GitHub, Wiki, there is a chapter on how to resolve
    2
    When did Magisk Manager app stop displaying some mention of "A/B"-ness? I do not see any mention in @lindsaysxda's screenshot.
    Yeah, I noticed this too, but some time back; doubt you'll see it for any device now... Maybe changed in this?:
    https://github.com/topjohnwu/Magisk/commit/ca9f9fee9a9197b6a56f4bf5ed3d4ae26a7a6dd7

    ... did we lose encryption (cryptotype) info even earlier?

    Seems John likes to simplify Magisk (for good reasons). My guess is that SAR, A/B, Crypto etc. states may now be considered confusing and largely irrelevant for Magisk purposes, and have been dispensed with in favour of Ramdisk and Zygisk state info... PW
    2
    View attachment 5623771

    i'm just wondering, does my device doesn't support the current version of magisk? because i can't open the menu to download the magic modules at all. i had to download it manually from external site and i read the solution online and it said i should downgrade it to version 21.4

    i just wondering if there's a way to access the menu without downgrading it
    As has been mentioned many, many times here, the module repository was closed long ago. Use this instead:

    https://github.com/Fox2Code/FoxMagiskModuleManager
    1
    I have lineage 19.1 gravitybox is not compatible
    if you're cool with using gestures, try this. (i'm not sure if it works with the standard navbar.) i started using it since there is no gravitybox yet for Android 12.x. (there was a lot of discussion of this on this thread :D)
  • 7
    Latest Shamiko:

    Shamiko v0.5.0

    0.5.0​

    • Better hiding Zygisk
    "... Momo enjoys helping Shamiko become stronger in all aspects despite Shamiko's goal of defeating her..."

    👍 PW
    6

    Latest Official TJW debug Canary Magisk:​

    Magisk (cc79a96f) (24307)​

    • [App] Update libsu with 100% new I/O layer
    • [MagiskInit] Mock enforce file with regular file to prevent possible race condition
    • Switch normal NDK with ONDK, preparing the toolchain to introduce Rust

    Diffs to v24.3​

    • [MagiskInit] Update 2SI implementation, significantly increase device compatibility (e.g. Sony Xperia devices)
    • [MagiskInit] Introduce new sepolicy injection mechanism
    • [MagiskInit] Support Oculus Go
    • [App] [MagiskSU] Properly support apps using shared UID
    • [MagiskSU] Fix a possible crash in magiskd
    • [Zygisk] Fix function hooking on devices running Android 12 with old kernels
    • [BusyBox] Add workaround for devices running old kernels
    https://github.com/topjohnwu/magisk-files/blob/a66dfce1bf88a70e86bf86c5427b1c58e71a4fc2/notes.md

    👍 PW
    6
    Looks like major libsu release is now imminent; most fixes are now merged.

    Should see major stability improvements in Magisk and root app implementation... Should see new commits for Magisk proper again soon too!

    John has made some major libsu changes (see libsu GitHub).

    Here are extra comments on vvb2060 fixes from her TG (Chinese translated....


    👀 PW
    libsu 5.0.0 is out!

    libsu/CHANGELOG.md

    5.0.0​

    Check the updated Javadoc and the example app for details on how to use the remote file system in the new nio module.

    New Features​

    • Introduce a new module: nio
      • Includes file system implementations for local and remote processes
      • New FileSystemManager class to access either local or remote file system implementations
      • New ExtendedFile class to extend functionality of the old Java File API
    • [core] New API Shell.isAppGrantedRoot() returns a nullable Boolean:
      • true if a root shell has been created
      • false if it has been determined that root access is impossible to get
      • null if the library has not, or could not determine the current root grant state. Future invocations of this method may return a non-null value if the library gained more information during shell creation.
    • [core] New API Shell.Builder.setContext(context): allow the developer to explicitly provide a Context object
    • [io] SuFile is updated to also extend ExtendedFile, which adds some new features and APIs

    Deprecation​

    • Version 5.0.0 will be the final release of the busybox module. If you cannot remove the usage of the module, you can pin the busybox module to version 5.0.0, as it is updated to be fully self contained, making it guaranteed to work with future libsu versions.
    • Usage of SuFile/SuFileOutputStream/SuFileInputStream/SuRandomAccessFile is discouraged. Although these APIs will remain for the foreseeable future, please migrate to use RootService + the nio module for all root I/O operations.
    • Shell.rootAccess() is deprecated. Please switch to use the more accurate Shell.isAppGrantedRoot() API

    John Wu, 2h

    Major libsu update 5.0.0!

    Introduces a new module "nio" to perform I/O operations through root services, moving away from the error prone, inefficient shell command backed I/O the library used to provide.

    It's already using splice under-the-hood. There is already some Linux magic!

    New readme etc. Read how you can Attach Debugger to Android Process in Root Services and more!
    https://github.com/topjohnwu/libsu

    👏👍🥳

    ... Back to regular Magisk programming... PW
    6
    Latest Official TJW debug Canary Magisk:

    Magisk (985249c3) (24309)​

    Pixel 6 Android 13 Beta 2 support is here!

    • [App] Support requesting root from non app process
    • [App] Fix deadlocking a background thread on non-root devices
    • [MagiskInit] Support GKIs with no ramdisk (Pixel 6 Android 13)

    Diffs to v24.3​

    • [MagiskInit] Update 2SI implementation, significantly increase device compatibility (e.g. Sony Xperia devices)
    • [MagiskInit] Introduce new sepolicy injection mechanism
    • [MagiskInit] Support Oculus Go
    • [MagiskInit] Support GKIs with no ramdisk (Pixel 6 Android 13)
    • [App] [MagiskSU] Properly support apps using shared UID
    • [MagiskSU] Fix a possible crash in magiskd
    • [Zygisk] Fix function hooking on devices running Android 12 with old kernels
    • [BusyBox] Add workaround for devices running old kernels
    https://github.com/topjohnwu/magisk-files/blob/56da1fe5430b2c04701ce73d1658ba698ee92283/notes.md

    👍 PW
    5

    Latest Official TJW debug Canary Magisk:​

    Magisk (42e5f515) (24308)​

    • Several minor bug fixes

    Diffs to v24.3​

    • [MagiskInit] Update 2SI implementation, significantly increase device compatibility (e.g. Sony Xperia devices)
    • [MagiskInit] Introduce new sepolicy injection mechanism
    • [MagiskInit] Support Oculus Go
    • [App] [MagiskSU] Properly support apps using shared UID
    • [MagiskSU] Fix a possible crash in magiskd
    • [Zygisk] Fix function hooking on devices running Android 12 with old kernels
    • [BusyBox] Add workaround for devices running old kernels
    https://github.com/topjohnwu/magisk-files/blob/ba1cf1081e1fe6fce7fda626dfdb0a0faab27d4e/notes.md

    👍 PW
  • 1077
    This is the place for general support and discussion regarding "Public Releases", which includes both stable and beta releases.
    All information, including troubleshoot guides and notes, are in the Announcement Thread
    156
    Hello, I haven't given much support on XDA lately. It can be resulted from
    • University started and I have limited free time. In fact, I mostly develop during midnight
    • I live in Taiwan, which has large time zone differences between my European/American contributors/testers, which usually forces me to stay up late at night to discuss/test stuffs.
    • The new version is about to come, I don't want to spend effort on supporting old releases
    The planned update is delayed again and again, to some point I think I'll shed some light about what has been happening lately, also along with some announcements.

    New Forum!
    As you might have already discovered, Magisk got its own subforum on XDA! Many thanks to all the support you gave me, and much more information/features/support is about to come!
    **For developers supporting all the devices that are not using standard Android boot format, feel free to create threads in this section (actually, PLEASE do so) for your favorite devices after v7 is out. As I currently know, Asus devices require signing the boot image before flashing, and is model dependant; Sony devices seems to use ELF kernel that is unpatchable, or some has two ramdisks (inner + outer), both requires different workarounds; LG bootloader locked devices has to manually "BUMP" the boot image after flashing Magisk..... and there may be lots of other crazy boot image formats that haven't come up to my attention yet.
    It is impossible for me to support all these non-standard boot images, and I hope the community can collaborate to make Magisk running across all the devices. Overall, community collaboration is what XDA about :D

    The Pixel Phone
    Some of you might already know this news, that the next Pixel Phone right around the corner seems like it does not have ramdisk in boot image, which pretty much wrecked Magisk in all ways. However, it pretty much doomed root itself too. Kernel modifications is inevitable IMO, so I'll try to migrate my scripts to C programs that could possibly be included into the kernel itself. Note that I'm not familiar with linux kernel, I'm not even sure if my idea and concept is correct or not. But once the device is available, I think developers will find a way to bypass all the difficulties, and I'll do my best to learn things ;)

    Current Progress
    In the past month, I've spent quite some time learning SELinux, so that I can avoid using SuperSU's sepolicy patches. Thanks to the helps and tips from @phhusson and @Chainfire, I finally have a much clearer understanding of how SELinux works. The Magisk core parts (the scripts, boot image patches, new features, more supports) are actually done some time ago. What is causing all the delays is the Magisk Manager.
    To be completely honest, although I can code in Java without much issues, Magisk Manager is actually my first Android application, I had to reach out for assistance, and fortunately awesome developers like @DVDandroid and @digitalhigh contributed a lot, which makes the current Manager awesome.
    After the repo system and module management is mostly done, I was about to do some adjustments and release, but what we really done is decided to add another feature: auto-unroot with per-app settings. I decided to wait for it to be finished, and then do my adjustments. Due to reasons that'll be mentioned later, this feature will likely not be available for the next release (should come in future updates)

    Safety Net Disaster
    Those who are using Magisk for Safety Net bypass purposes must have known that Google recently updated the detection method of my Systemless Xposed. I still have no idea what Safety Net is detecting, so currently I cannot fix it on my side (also because I'm busy working on the next update). However, suhide developed by @Chainfire is able to hide Xposed and worked fine.
    However, only my Systemless Xposed v86.2, which is based on SuperSU's su.d, is supported using that method. v86.2 and v86.5 (latest, Magisk based) have nearly identical binaries, and the only difference is the path where the binaries are stored.
    I'm still not sure what's the real issue for it not being supported, I just hope it is not done intentionally.

    Conclusion
    Due to the fact that my Safety Net bypass is not 100% perfect now, I do not want to spend any more time waiting for auto-unroot to be polished. What I'm doing now is finishing up all the things I'd like to change in Magisk Manager (it has been a while since I last contributed to Manager, my fellow developers are doing all the heavy job), which might take a little more time, after that, packed with tons of information to be announced in Magisk Section, I'll release the long awaited update.

    Hope this lengthy post gives you the idea of the whole situation, and again thanks for all your support!!
    121
    Ah, some Chainfire bashing, I hope it is not too late for me to exercise additional villainy.

    First, let me make clear I have nothing against @topjohnwu, nor against Magisk. Magisk is an interesting project and it certainly displays @topjohnwu ingenuity and persistence. I don't doubt we will see more interesting things from his hands.

    -------------------------

    What has happened here is not all that dark and complicated, from either end. I returned from holidays, and someone pointed me at Magisk. My first thought: interesting!

    Among other things, the thread lists some issues with SuperSU, which in combination with the phrase The developer also requests users to not bug Chainfire with compatibility requests for SuperSU with Magisk from the portal article, raised my left eyebrow by nigh half an inch. The popular systemless xposed mod is apparently now based on it, and apparently it now no longer works with SuperSU, and apparently I'm not supposed to fix that, nor any of the other found issues. I found that a bit weird. So yes, I have told @topjohnwu that I was a bit surprised he was posting about issues with SuperSU without notifying me about them (I can't fix or help fix issues I'm not aware of, after all).

    He's also spreading a modified version of the SuperSU package, which is not all that uncommon, nor necessarily a problem. I have not looked into what he modified, I only ran a few quick tests on one of my devices, and found some commonly used commands run as root to be broken. I have informed him of this as well.

    It appears the tool of choice for Magisk is phh's Superuser, because of some of the mentioned issues with SuperSU. That's fine by itself, but fixing issues in that superuser by incorporating SuperSU's binaries into it is a somewhat questionable practise. After all, SuperSU is a commercial closed-source package that helps pay for my dinner, and superuser is a direct competitor. I have informed him that I was surprised he did this without asking for permission. I have expressed similar surprise on him spreading a modified version of LiveBoot (which helps pay for a snack now and then).
    @topjohnwu has also stated that Magisk's scripts are largely influenced by mine (I have not checked). Scripts based on mine are used all over the place on XDA, some people have crafted amazing things based on them, I have never made an issue of this (otherwise I would have just made them binaries). But yes, I have also stated to him that I don't think it's very nice to base something on one program, and then using that to (almost exclusively) push something directly competing with that program.

    tl;dr Towards @topjohnwu, I have:
    - expressed surprise he has issues getting Magisk to work with SuperSU, and has chosen not to inform me about those
    - expressed surprise he is using SuperSU binaries in a competing superuser without permission
    - expressed surprise he is posting a modified LiveBoot without permission
    - informed him of issues with the modified SuperSU he has posted
    - let him know I thought it wasn't very nice to be applying my scripts to benefit seemingly exclusively that same competing superuser

    To be crystal clear:
    - I have not asked for an apology
    - I have not asked for Magisk to be abandoned, neither the root hiding nor systemless module parts, and certainly not systemless xposed
    - I have not made an issue of any of this anywhere, until this post
    - I have not even specifically asked for anything to be taken down (though obviously in my opinion the other superuser package mixed with SuperSU's binaries, as well as the LiveBoot package, should go)
    - I have not reported this thread to XDA moderators for copyright violations or otherwise

    While my conversation with @topjohnwu may not win any awards for being friendly (though it may win some for brevity), I think all things considered my response has been rather mild. To be perfectly honest, until the apology post, I thought this was over with already. I think the apology post was triggered because I haven't replied to his last PM for a while - I was in the zone, it happens.

    To emphasize again, I have nothing against @topjohnwu, Magisk, or systemless xposed, and it is certainly not my goal to see any of them go. If it can be made to work together with SuperSU, great.

    I get it though: you think of something, you want to see if you can make it work, you finally get it to work, you publish it, it takes off - enthusiasm gets the better of you. Maybe in the rush some mistakes are made. That doesn't mean you have to just drop it and run. None of my stuff would make it past 0.1 if I stopped at the first big mistake :)

    Aside from said being in the zone coding, I usually regret actually responding to these sort of things the day after, which has made me hesitant to reply. Surprise me.
    76
    Thread temporarily closed so everyone sees this.

    The flood of "SafetyNet isn't working for me either!" posts are not helpful, at all. Please refrain from posting further, it will be looked into. Please do not forget that not passing SafetyNet is 100% NORMAL AND INTENDED when you have an unlocked booloader or running custom firmware. These are workarounds and they will be worked around in turn.

    The Flash
    Forum Moderator

    EDIT: Thread is reopened... I will be cleaning any SafetyNet posts for a while to keep the thread clean for real issues.
    75
    Hello everyone!

    I am aware that Google has updated Safety Net that makes Magisk itself a no go for Android Pay. In fact, I witnessed the change live while I am developing the new magiskhide, which should hide all Magisk modules and Magisk installed root.

    Google is serious about Safety Net now, clearly hunting down all possibility to run Xposed with Safety Net passed. I spend quite some time examining the new security measures last midnight, and fortunately it seems that it is possible to run Magisk and root along with Safety Net if no Xposed is running. I'm glad I removed the old root toggle at the right time lol, that is no longer feasible with the latest detection.

    So stay tuned for the next update, it will come with bug fixes, along with the new magiskhide to bypass that Safety Net.

    Google, how will a few systemless mods do any harm :p:p