Archive:APatch
APatch is an open-source, kernel-based root solution for Android devices. It modifies the Android kernel to provide root access to userspace applications and supports both Android Patch Modules (APM), which are conceptually similar to Magisk modules, and Kernel Patch Modules (KPM), which allow code to operate in kernel space. APatch is built on the KernelPatch project and its user interface and module-management components incorporate code derived and modified from KernelSU.
The project is distributed under the GNU General Public License version 3 (GPLv3).
History
APatch was developed as an Android kernel-rooting project by bmax121 and other contributors. The project's documentation identifies 2023 as the beginning of its copyright period.
The project subsequently developed into a broader framework combining kernel-level rooting with a module system. Its architecture incorporates KernelPatch as its underlying kernel-patching component, while drawing on concepts and code from projects including KernelSU and Magisk.
The project's documentation is maintained through the APatchDocs repository and is published at the APatch website.
Architecture
Unlike traditional Android root implementations that primarily modify the userspace boot environment, APatch patches the Linux kernel contained within the device's boot image. The project describes this as a kernel-based approach to obtaining root privileges.
APatch depends on KernelPatch, which provides the underlying kernel-level mechanisms. APatch adds a management application and support for Android-specific modules and root-access management.
KernelPatch introduces a system-call mechanism referred to by the project as SuperCall. Applications or userspace programs attempting to use this mechanism must provide a credential known as the SuperKey. According to the APatch documentation, a SuperCall succeeds only when the supplied SuperKey is valid.
The project explicitly warns that the SuperKey has privileges exceeding ordinary root access and that compromise or exposure of the key can give an attacker extensive control over the device.
Features
Root access
APatch provides root privileges to Android applications through kernel-level mechanisms. Its documentation describes the system as allowing permitted applications to obtain root access while limiting visibility of root functionality to applications that have not been authorized.
Android Patch Modules
Android Patch Modules (APM) provide a module system similar in concept to the Magisk module ecosystem. Modules can be used to modify or extend aspects of an Android installation without directly modifying the original system files.
Kernel Patch Modules
Kernel Patch Modules (KPM) are designed to execute code in kernel space. APatch documentation compares their role to Linux Loadable Kernel Modules and states that KPMs can provide kernel-level capabilities such as inline hooking and system-call-table hooking.
KPMs can currently be embedded into a kernel or loaded through the available APatch/KernelPatch mechanisms; the APatch documentation states that KPM installation as a conventional installed module was not yet implemented in the documented version.
SELinux
APatch and KernelPatch use kernel hooks to provide their rooting functionality without necessarily changing the Android SELinux context. APatch additionally incorporates magiskpolicy for certain SELinux-related operations.
Compatibility
According to the current APatch project documentation, APatch supports ARM64 devices and Android Linux kernel versions 3.18 through 6.12, subject to additional kernel requirements.
The project specifies requirements involving the Linux kernel's KALLSYMS configuration. In particular, its documentation lists CONFIG_KALLSYMS=y and, for full support, CONFIG_KALLSYMS_ALL=y; it also documents initial support for configurations where CONFIG_KALLSYMS_ALL is disabled.
Compatibility therefore depends not only on the Android version but also on the device's processor architecture, kernel version, kernel configuration, boot-image format and vendor-specific security mechanisms.
Installation
APatch normally operates by patching a device's boot image. The official installation documentation instructs users to unlock the bootloader, obtain the appropriate stock boot.img, verify the kernel requirements and use APatch Manager to produce a patched image.
The resulting image can be installed using mechanisms such as fastboot, depending on the device. The exact procedure varies considerably between manufacturers and device models.
Unlocking a bootloader can erase user data on some Android devices, and incorrectly flashing a boot image can prevent the device from booting. Consequently, APatch's installation documentation recommends retaining a backup of the original boot image.
Comparison with other Android root solutions
APatch occupies a position between approaches represented by Magisk and KernelSU, although its implementation is distinct.
| Characteristic | APatch | Magisk | KernelSU |
| Primary approach | Kernel patching | Boot-image/ramdisk modification | Kernel-based |
| Root access | Kernel-based | Userspace/init-based | Kernel-based |
| Module system | APM | Magisk modules | KernelSU modules |
| Kernel modules | KPM | Not its primary mechanism | Kernel-level capabilities |
| Stock boot.img | Used as patching input | Used as patching input | Depends on kernel integration |
| Kernel source required | APatch documentation says no |
The APatch documentation specifically contrasts its approach with Magisk by stating that Magisk modifies the init system in the boot image's ramdisk, whereas APatch patches the kernel directly. It also states that APatch can work from a stock boot.img, whereas KernelSU traditionally requires access to the device's kernel source. These differences do not mean that the three systems are mutually exclusive in every configuration; compatibility depends on the particular device, Android build and modules being used.
Security considerations
Rooting an Android device changes its security model by allowing privileged software to modify protected parts of the operating system. APatch adds an additional kernel-level mechanism through KernelPatch and KPMs, meaning that a malicious or incorrectly implemented module can potentially operate with very high privileges.
The APatch developers specifically identify the SuperKey as a security-sensitive credential and warn users to protect it against exposure.
APatch also distinguishes the official project from third-party distributions. Its documentation states that the developers cannot review every third-party distribution and do not provide a warranty for problems arising from such distributions.
Development and licensing
APatch is free and open-source software licensed under GPLv3. The project credits KernelPatch as its core, Magisk for components including magiskpolicy, and KernelSU for elements of its application interface and module-support implementation.
The primary source repositories and project documentation are hosted on GitHub and the APatch documentation website.
See also
- Magisk
- KernelSU
- Linux kernel
- Android (operating system)
- SELinux
- Rooting (Android)
References
External links
- "APatch Root方案安裝教學,相容KernelSU與Magisk模組" (in zh). 2026-08-06. https://ivonblog.com/posts/apatch-android-root/.
- "APatch". bmax121. https://github.com/bmax121/APatch.
- "What is APatch?". https://apatch.dev/what-is-apatch.html.
- ("FAQ". https://apatch.dev/faq.html.
- "Installation". https://apatch.dev/install.html.