{"id":51454928,"url":"https://github.com/ravindu644/Ubuntu-Chroot","last_synced_at":"2026-07-24T16:01:10.278Z","repository":{"id":321561978,"uuid":"1086077708","full_name":"ravindu644/Ubuntu-Chroot","owner":"ravindu644","description":"Run Ubuntu 24.04 on Android With full Hardware Access and pure namespace isolation..!","archived":true,"fork":false,"pushed_at":"2025-12-08T17:44:48.000Z","size":6702,"stargazers_count":106,"open_issues_count":3,"forks_count":17,"subscribers_count":4,"default_branch":"main","last_synced_at":"2026-03-05T19:38:01.398Z","etag":null,"topics":["chroot","docker","docker-on-android","kernelsu","magisk","nethunter","samsung","ubuntu"],"latest_commit_sha":null,"homepage":"https://t.me/SamsungTweaks","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ravindu644.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-10-29T23:11:53.000Z","updated_at":"2026-02-28T13:08:21.000Z","dependencies_parsed_at":"2025-10-30T10:25:47.376Z","dependency_job_id":"93a9b413-f867-4f12-ac4f-aaf89499a250","html_url":"https://github.com/ravindu644/Ubuntu-Chroot","commit_stats":null,"previous_names":["ravindu644/ubuntu-chroot"],"tags_count":28,"template":false,"template_full_name":null,"purl":"pkg:github/ravindu644/Ubuntu-Chroot","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ravindu644%2FUbuntu-Chroot","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ravindu644%2FUbuntu-Chroot/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ravindu644%2FUbuntu-Chroot/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ravindu644%2FUbuntu-Chroot/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ravindu644","download_url":"https://codeload.github.com/ravindu644/Ubuntu-Chroot/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ravindu644%2FUbuntu-Chroot/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35847531,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-24T02:00:07.870Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["chroot","docker","docker-on-android","kernelsu","magisk","nethunter","samsung","ubuntu"],"created_at":"2026-07-06T00:00:29.231Z","updated_at":"2026-07-24T16:01:10.268Z","avatar_url":"https://github.com/ravindu644.png","language":"Python","funding_links":[],"categories":["Developer Tools"],"sub_categories":["Install and Run Linux Environments"],"readme":"\u003cimg src=\"Screenshots/banner.png\" alt=\"Ubuntu Chroot banner\" width=\"900\" /\u003e\n\n[![Latest release](https://img.shields.io/github/v/release/ravindu644/ubuntu-chroot?label=Latest%20Release\u0026style=for-the-badge)](https://github.com/ravindu644/ubuntu-chroot/releases/latest)\n[![Telegram channel](https://img.shields.io/badge/Telegram-Channel-2CA5E0?style=for-the-badge\u0026logo=telegram\u0026logoColor=white)](https://t.me/SamsungTweaks)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg?style=for-the-badge)](./LICENSE)\n[![Android support](https://img.shields.io/badge/-Android-3DDC84?style=for-the-badge\u0026logo=android\u0026logoColor=white)](#requirements)\n[![Linux desktop](https://img.shields.io/badge/-Linux-FCC624?style=for-the-badge\u0026logo=linux\u0026logoColor=black)](#why-this-is-different)\n\n---\n\n# 🟠 Ubuntu-Chroot\n\nA comprehensive Android Linux environment featuring **Ubuntu 24.04** with a built-in WebUI Control Panel, Beautiful desktop environment, advanced namespace isolation, and in-built development tools for a seamless Linux desktop experience on Android - **with full hardware access and x86_64 emulation**.\n\n#### Quick Navigation\n\n- [Requirements](#requirements)\n- [Why This Is Different](#why-this-is-different)\n- [Installation](#installation)\n- [Get Started](#usage)\n- [Access the GUI](#gui)\n- [Experimental Features](#experimental-features)\n- [Kernel Requirements (Optional)](#kernel-requirements)\n- [Running Docker inside Chroot](#docker)\n- [To-Do](#to-do)\n- [Known issues](#known-issues)\n- [Credits](#credits)\n\n\u003ca id=\"requirements\"\u003e\u003c/a\u003e\n## 👀 Requirements\n\n- Android device with arm64 architecture\n- Unlocked bootloader\n- Rooted with APatch/KernelSU\n  - Magisk is not supported due to **TTY issues starts with version 29**. If using Magisk, use a version below v29.\n- [Custom Kernel with these configs enabled (optional)](#kernel-requirements)\n\n\u003ca id=\"why-this-is-different\"\u003e\u003c/a\u003e\n## ❔ Why This Is Different\n\n**Advanced Namespace Isolation**\n- Utilizes Linux namespaces (mount, PID, UTS, IPC) for true namespace isolation. Unlike basic chroot setups, this creates separate filesystem mounts, process IDs, hostnames, and IPC spaces - preventing interference between the chroot and Android host.\u003csup\u003e[\u003ca href=\"#01-core-namespace-support-required-for-isolation\"\u003e1\u003c/a\u003e]\u003c/sup\u003e\n\n  \u003cdetails\u003e\n  \u003csummary\u003eProcess isolation demonstration\u003c/summary\u003e\n\n  \u003cp align=\"center\"\u003e\n    \u003cimg src=\"Screenshots/namespace-isolation.png\" alt=\"Namespace isolation diagram\" width=\"650\" /\u003e\n    \u003cbr\u003e\u003cem\u003eIllustration of isolated namespaces\u003c/em\u003e\n  \u003c/p\u003e\n  \u003c/details\u003e\n\n\u003e [!TIP]\n\u003e\n\u003e **Why Namespaces Matter:**\n\u003e\n\u003e Traditional chroot only changes the root directory. **Namespaces create isolated environments,** ensuring processes inside the chroot cannot see or affect host system processes, hostnames, or IPC resources.\n\u003e\n\u003e This allows full Linux services to run without conflicts, security risks, or performance loss.\n\n**Full Hardware Access**\n- Complete access to all hardware features of your Android device, including WiFi adapters, ADB, Odin, and more.\u003csup\u003e[\u003ca href=\"#02-essential-filesystems-for-hardware-access\"\u003e2\u003c/a\u003e]\u003c/sup\u003e\n\n  \u003cdetails\u003e\n  \u003csummary\u003eUsing an external WIFI adapter inside chroot\u003c/summary\u003e\n\n  \u003cp align=\"center\"\u003e\n    \u003cimg src=\"Screenshots/hardware-access.png\" alt=\"Hardware access screenshot\" width=\"650\" /\u003e\n    \u003cbr\u003e\u003cem\u003eExample tools running with full device access\u003c/em\u003e\n  \u003c/p\u003e\n  \u003c/details\u003e\n\n**x86_64 Emulation**\n- Preconfigured x86_64 emulation enables you to run x86_64 applications and binaries directly on your Android device with full hardware access.\u003csup\u003e[\u003ca href=\"#03-running-x86_64-binaries-natively\"\u003e3\u003c/a\u003e]\u003c/sup\u003e\n\n  \u003cdetails\u003e\n  \u003csummary\u003eOdin4 x86_64 running with full hardware access\u003c/summary\u003e\n\n  \u003cp align=\"center\"\u003e\n    \u003cimg src=\"Screenshots/x86.png\" alt=\"Odin4 x86_64 binary running\" width=\"650\" /\u003e\n    \u003cbr\u003e\u003cem\u003eRebooting a phone in Download Mode using x86_64 Odin4 on an ARM64 device\u003c/em\u003e\n  \u003c/p\u003e\n  \u003c/details\u003e\n\n**\"It Just Works\" Philosophy**\n- No complex terminal commands required. The desktop environment starts automatically when the chroot launches, and most developer tools are preconfigured and ready to use out of the box.\n\n**Containerization Ready**\n- When you flash the module, it extracts the Ubuntu rootfs to `/data/local/ubuntu-chroot`, which the backend uses as the installed rootfs.\n\n- Under **Experimental Features** in the WebUI, you can migrate your directory-based chroot to an ext4 sparse image, containerizing your environment into a single `.img` file.\n- The Linux environment runs on an ext4 image outside Android partitions, benefiting from improved I/O, caching, and flexibility.\n- You can freely shrink, grow, and FSTRIM your sparse image after migration.\n- A sparse image can be created at any size (even 1TB) but only consumes real storage as data is written - an efficient storage method for your Linux environment.\n\n**Seamless Desktop Experience**\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003e📸 Desktop Screenshots (click to expand)\u003c/strong\u003e\u003c/summary\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"Screenshots/landscape.png\" alt=\"Ubuntu Chroot desktop landscape\" width=\"800\" /\u003e\n  \u003cbr\u003e\u003cem\u003eLandscape mode\u003c/em\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"Screenshots/portrait.jpg\" alt=\"Ubuntu Chroot desktop portrait\" width=\"350\" /\u003e\n  \u003cbr\u003e\u003cem\u003ePortrait mode\u003c/em\u003e\n\u003c/p\u003e\n\n\u003c/details\u003e\n\n- A complete Linux desktop experience on Android, capable of running GUI applications smoothly.\u003csup\u003e[\u003ca href=\"#04-gui-applications-support\"\u003e4\u003c/a\u003e]\u003c/sup\u003e\n\n**Forward Chroot Traffic to Any Network Interface**\n- Native WiFi hotspot functionality supporting both 2.4GHz and 5GHz bands. Automatically configures `hostapd` and DHCP services within the chroot environment for instant `localhost` sharing.\n- If the Native WiFi hotspot didn't work for you, you still have a separated menu to forward all the chroot traffic to any desired network interface. (e.g., USB Tethering/WiFi Hotspot created using Android userspace)\n\n\u003e **💡 Example**:\n\u003e\n\u003e Use the GUI running on your phone and project it to another large screen with near-zero latency.\n\n**Incremental OTA Updates**\n- Version-tracked incremental updates preserve user data and configurations across upgrades, eliminating the need for full reinstallation.\n\n**Backup and Restore**\n- Back up your chroot environment to a compressed archive and restore it later, or transfer it to another device.\n\n**Post-Exec Scripts and \"Run on Boot\"**\n- Define scripts to run automatically when the chroot boots.\n\n\u003e **💡 Example**:\n\u003e\n\u003e Enable \"Run on boot\" and reboot your phone - the chroot will automatically start (even while locked), executing your post-exec script so you can host bots, SSH, or background services effortlessly.\n\n**Modern WebUI**\n- Access and manage your chroot environment from KernelSU/APatch in-built WebUI.\n\n\u003cdetails\u003e\n\u003csummary\u003eWebUI screenshots\u003c/summary\u003e\n\n\u003ctable\u003e\n\u003ctr\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/1.jpg\" alt=\"WebUI screenshot 1\" width=\"270\" /\u003e\n  \u003c/td\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/2.jpg\" alt=\"WebUI screenshot 2\" width=\"270\" /\u003e\n  \u003c/td\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/3.jpg\" alt=\"WebUI screenshot 3\" width=\"270\" /\u003e\n  \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/4.jpg\" alt=\"WebUI screenshot 4\" width=\"270\" /\u003e\n  \u003c/td\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/5.jpg\" alt=\"WebUI screenshot 5\" width=\"270\" /\u003e\n  \u003c/td\u003e\n  \u003ctd align=\"left\" valign=\"top\"\u003e\n    \u003cimg src=\"Screenshots/v3.5.5/6.jpg\" alt=\"WebUI screenshot 6\" width=\"270\" /\u003e\n  \u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\u003c/details\u003e\n\n\u003ca id=\"installation\"\u003e\u003c/a\u003e\n## 🚀 Installation\n\n1. Download the latest release from [GitHub releases](https://github.com/ravindu644/ubuntu-chroot/releases)\n2. Flash the ZIP file using APatch/KernelSU managers\n3. Reboot your device\n\n\u003ca id=\"usage\"\u003e\u003c/a\u003e\n## 🧑‍💻 Get Started\n\n1. Access the chroot control panel using APatch/KernelSU's built-in WebUI\n2. On the first installation, you have to set up your user account to access GUI functionality (VNC/RDP):\n   - Start the chroot from the WebUI\n   - Copy the login command\n   - Paste it in Termux and complete the user account setup\n   - Return to the WebUI and click \"Restart\" to apply changes\n3. You can now log in as the created user via:\n   - **CLI**: Copy the login command and paste it in Termux or any other terminal emulator, including ADB Shell\n   - **GUI (VNC)**: Use the [AVNC Android app](https://github.com/gujjwal00/avnc) (recommended for best performance)\n   - **GUI (RDP)**: Uncomment the `# start_xrdp` line in the Post-exec Script from the WebUI and restart the chroot\n\n\u003e **Note**: There is currently no perfect RDP app for Android. Please create an issue if you find a better option.\n\n\u003ca id=\"gui\"\u003e\u003c/a\u003e\n## 💻 Access the GUI\n\nOnce you've set up your user account following the [Get Started](#usage) section, **the XFCE Desktop Environment will automatically start when you start the chroot from the WebUI - no need to type anything in the terminal !**\n\nThe default method to access the GUI is using the VNC protocol with a VNC viewer application.\n\n**Recommended VNC Clients:**\n\n- **Android**: [AVNC](https://github.com/gujjwal00/avnc)\n- **Windows**: [TigerVNC](https://github.com/TigerVNC/tigervnc)\n- **Linux**: [TigerVNC](https://github.com/TigerVNC/tigervnc)\n\n### Local Access (Same Device)\n\n**Connection Settings for AVNC (Android):**\n\n- **Host**: `localhost`\n- **Port**: `5901`\n- **Username**: Your chroot user account username\n- **Password**: Your chroot user account password\n\n### Remote Access (External Device)\n\nTo access the GUI from a different device (e.g., a computer or tablet), **you need to forward the chroot traffic to a network interface**. There are two methods available:\n\n#### Method 1: Built-in Hotspot\n\nThis method creates a WiFi hotspot directly from the chroot environment:\n\n1. Open the WebUI and navigate to the **Hotspot Configuration** option\n2. Configure your hotspot settings (Upstream, SSID, password, band, channel)\n3. Click **Start Hotspot**\n4. Connect your external device to the created hotspot\n5. Install a VNC client on the external device\n6. Use the IP address and port displayed in the console log along with your login credentials to connect\n\n#### Method 2: USB Tethering (Fastest)\n\nIf the built-in hotspot doesn't work, or you need the **lowest latency experience**, you can use Android's USB Tethering feature:\n\n1. Open the WebUI and click the **Refresh** button\n2. Navigate to **Forward Chroot Traffic** and note the currently available network interfaces\n3. Connect your phone to the target device using a USB cable\n4. Enable **USB Tethering** on your Android device\n5. Return to the WebUI, click **Refresh** again, and navigate to **Forward Chroot Traffic**\n6. You should now see a new network interface that wasn't present before\n7. Select the new network interface and click **Start Forwarding**\n8. Use the IP address and port displayed in the console log along with your login credentials to connect\n\n\u003e [!TIP]\n\u003e\n\u003e The IP address will be displayed in the WebUI console after starting the hotspot or forwarding.\n\u003e\n\u003e Look for messages like `Gateway IP` to determine the value for `Host` required for the VNC client. For VNC, the port is always `5901`.\n\n### Advanced: RDP Access\n\nFor advanced users who prefer RDP over VNC:\n\n1. Open the WebUI and navigate to **Options** → **Post-exec Script**\n2. Remove the comment (`#`) from the `start_xrdp` line\n3. Restart the chroot from the WebUI\n4. Use an RDP client to connect using the same connection method as VNC (hotspot or USB tethering)\n\n\u003e **Note**: There is currently no perfect RDP app for Android. VNC is recommended for the best experience.\n\n\u003ca id=\"experimental-features\"\u003e\u003c/a\u003e\n## 🧪 Experimental Features\n\n**Sparse Image Mode Installation**\n- Edit the [experimental.conf](./experimental.conf) file before installation:\n    - Set `SPARSE_IMAGE=true`\n    - Define the image size in GB using `SPARSE_IMAGE_SIZE`\n\n**Converting to Sparse Image**\n\n- You can convert your existing directory-based installation to an isolated ext4 sparse image from the WebUI under **Experimental Features**.\n\n**Downloading Firmware**\n\n- If you want to download and decompress firmware files (useful for installing WIFI firmware without installing random Magisk modules from the internet), run the following command inside the chroot:\n  ```bash\n  sudo download-firmware\n  ```\n  This script will install the `linux-firmware` package, decompress all `.zst` firmware archives, and update symlinks to point to the decompressed files. The script creates a marker file to prevent re-running, so it's safe to execute multiple times.\n\n- After downloading the firmware, restart the chroot from the WebUI to apply the changes.\n\n\u003ca id=\"to-do\"\u003e\u003c/a\u003e\n## 📋 To-Do\n\nThe following features are currently not planned for implementation by the maintainer, but **Pull Requests are always welcome** if you figure out a way to implement them:\n\n- Audio forwarding in RDP\n- Termux-independent GPU acceleration\n\n\u003ca id=\"known-issues\"\u003e\u003c/a\u003e\n\n## 🐛 Known issues\n\n1. **Snap and Flatpak support**\n\n    - Snap and Flatpak are not native applications like those we install from `.deb`, `.AppImage`, or APT. They are containerized applications running in an isolated environment without any privileged access.\n\n    - To create those isolated, containerized applications, your Android kernel must have support for various filesystems and drivers, as well as kernel patches to enable unprivileged user namespaces.\n\n    - Even if you somehow compiled a custom kernel with all the required features enabled, the functionality is not guaranteed because we are creating an isolated environment within an already isolated environment.\n\n    - Related issue: [#1](https://github.com/ravindu644/Ubuntu-Chroot/issues/4)\n\n2. **`Error: sh: \u003cstdin\u003e[5]: /system/bin/su: No such file or directory` in KernelSU LKM mode/Kernels with KernelSU KProbe Hooks**\n\n    - This is a **known limitation in KernelSU** when using **LKM mode** or **GKI kernels with KProbe hooks** or **non-GKI Kernels without proper 32-bit support hooks**.\n    - This occurs because official **KernelSU dropped support for 32-bit applications** starting from versions above v0.9.2, and all KernelSU forks have inherited this limitation.\n    - **This causes all 32-bit applications to lose their ability to detect root**, including ADB shell on devices with dual ABI support, Nethunter terminal, Root explorer, etc.\n    - **The only fix for this issue is to use a proper kernel with KernelSU manual hooks that support 32-bit applications**, instead of using LKM mode or GKI kernels with KProbe hooks.\n    - This error does not originate from this project; it's coming from KernelSU's side.\n    - More info: [telegram](https://t.me/Samsung_Tweaks/89289), [Github issue created by me in 2024](https://github.com/tiann/KernelSU/issues/2095), [Another similar issue](https://github.com/KernelSU-Next/KernelSU-Next/issues/250)\n\n\u003ca id=\"kernel-requirements\"\u003e\u003c/a\u003e\n## 🛠 Kernel Requirements\n\n**These configurations are optional**, as 80% are enabled in Android by default. However, to ensure everything works perfectly and achieve maximum potential from this project, these kernel configs should be enabled.\n\n#### 01. Core Namespace Support (Required for Isolation)\n\n```Makefile\nCONFIG_NAMESPACES=y\nCONFIG_PID_NS=y\nCONFIG_UTS_NS=y\nCONFIG_MNT_NS=y\nCONFIG_IPC_NS=y\n```\n\n#### 02. Essential Filesystems for Hardware Access\n\n```Makefile\nCONFIG_DEVTMPFS=y\nCONFIG_PROC_FS=y\nCONFIG_SYSFS=y\n```\n\n#### 03. Running x86_64 Binaries Natively\n\n```Makefile\nCONFIG_BINFMT_MISC=y\nCONFIG_BINFMT_SCRIPT=y\nCONFIG_BINFMT_ELF=y\n```\n\n#### 04. GUI Applications Support\n\n```Makefile\n# IPC mechanisms (required by many apps and daemons)\n# KDiskMark and Brave Browser will fail without these\nCONFIG_SYSVIPC=y\nCONFIG_SYSVIPC_SYSCTL=y\nCONFIG_PROC_SYSCTL=y\nCONFIG_POSIX_MQUEUE=y\n```\n\n#### 05. Docker Support in Chroot\n\n```Makefile\nCONFIG_CGROUPS=y\nCONFIG_CGROUP_DEVICE=y\nCONFIG_MEMCG=y\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eComplete Kernel Configuration\u003c/strong\u003e (click to expand)\u003c/summary\u003e\n\n```Makefile\n# Ubuntu Chroot Kernel Configuration\n# Copyright (C) 2025 ravindu644 \u003cdroidcasts@protonmail.com\u003e\n# Note: A custom kernel is not required, but most features\n# will be limited without these configurations.\n\n# CRITICAL: Essential for basic chroot functionality\n\n# Core namespace support (required for isolation)\nCONFIG_NAMESPACES=y\nCONFIG_PID_NS=y\nCONFIG_UTS_NS=y\nCONFIG_IPC_NS=y\n\n# Essential filesystems\nCONFIG_PROC_FS=y\nCONFIG_SYSFS=y\nCONFIG_DEVTMPFS=y\nCONFIG_TMPFS=y\nCONFIG_EXT4_FS=y\n\n# QEMU support\nCONFIG_BINFMT_MISC=y\nCONFIG_BINFMT_SCRIPT=y\nCONFIG_BINFMT_ELF=y\n\n# Terminal support (required for login)\nCONFIG_UNIX98_PTYS=y\nCONFIG_TTY=y\nCONFIG_DEVPTS_FS=y\n\n# Basic networking\nCONFIG_NET=y\nCONFIG_INET=y\nCONFIG_UNIX=y\n\n# Threading support\nCONFIG_FUTEX=y\n\n# File operations\nCONFIG_FILE_LOCKING=y\n\n# IMPORTANT: Common functionality requirements\n\n# IPC mechanisms (required by many apps and daemons)\n# KDiskMark and Brave Browser will fail without these\nCONFIG_SYSVIPC=y\nCONFIG_POSIX_MQUEUE=y\n\n# Device management\nCONFIG_DEVTMPFS_MOUNT=y\n\n# Extended filesystem features\nCONFIG_TMPFS_POSIX_ACL=y\nCONFIG_TMPFS_XATTR=y\nCONFIG_EXT4_FS_POSIX_ACL=y\nCONFIG_EXT4_FS_SECURITY=y\n\n# Control groups (essential for Docker)\nCONFIG_CGROUPS=y\nCONFIG_CGROUP_DEVICE=y\nCONFIG_MEMCG=y\n\n# Event handling\nCONFIG_EPOLL=y\nCONFIG_EVENTFD=y\nCONFIG_SIGNALFD=y\nCONFIG_TIMERFD=y\n\n# File monitoring\nCONFIG_INOTIFY_USER=y\n\n# Security\nCONFIG_SECCOMP=y\nCONFIG_SECCOMP_FILTER=y\n\n# Networking features\nCONFIG_IPV6=y\nCONFIG_PACKET=y\n\n# Legacy PTY (for compatibility)\nCONFIG_LEGACY_PTYS=y\nCONFIG_LEGACY_PTY_COUNT=256\n\n# OPTIONAL: Advanced features and specific use cases\n\n# Advanced cgroup controllers\nCONFIG_CGROUP_CPUACCT=y\nCONFIG_CGROUP_SCHED=y\nCONFIG_CGROUP_FREEZER=y\nCONFIG_CGROUP_PIDS=y\nCONFIG_MEMCG_SWAP=y\n\n# Overlay filesystem (for Docker-like functionality)\nCONFIG_OVERLAY_FS=y\n\n# FUSE (for userspace filesystems like sshfs, AppImage)\nCONFIG_FUSE_FS=y\n\n# Firmware loading\nCONFIG_FW_LOADER=y\nCONFIG_FW_LOADER_USER_HELPER=y\nCONFIG_FW_LOADER_COMPRESS=y\n\n# Loop devices (for mounting disk images)\nCONFIG_BLK_DEV_LOOP=y\n\n# Async I/O (for database servers and high-performance apps)\nCONFIG_AIO=y\n\n# System control interface\nCONFIG_PROC_SYSCTL=y\nCONFIG_SYSVIPC_SYSCTL=y\n```\n\n\u003c/details\u003e\n\n\u003ca id=\"docker\"\u003e\u003c/a\u003e\n## 🐳 Running Docker inside Chroot\n\n\u003e [!TIP]\n\u003e **Docker is already installed and configured by default,** so you don't need to do anything to install it.\n\n**The quick way to verify if you can run Docker containers is to check if the \"Devices Cgroups\" are mounted.**\n\n- If you see these logs in the console, then your device has minimal Docker support:\n\n  ```\n  [INFO] Setting up minimal cgroups for Docker...\n  [INFO] Cgroup devices mounted successfully.\n  ```\n\n- Otherwise, there's no way to run Docker inside the phone unless you compile a custom kernel.\n\n**Next,** verify if your `/data` partition is `ext4`.\n\n- **If it is f2fs,** you **MUST** use the migrate feature from \"Options -\u003e Experimental Features -\u003e Migrate to Sparse Image\" so Docker can properly wire up OverlayFS on top of the ext4 mounted rootfs.\n\n**After verifying your kernel supports Devices Cgroups and resolving any `ext4` filesystem issues, you need to start the Docker daemon using the command below.**\n\n- Run this inside the chroot terminal: `sudo dockerd`\n\n- If the Docker daemon started successfully, it should show something like this:\n\n  ```\n  INFO[2025-12-08T16:59:04.981797971Z] Completed buildkit initialization\n  INFO[2025-12-08T16:59:05.016738894Z] Daemon has completed initialization\n  INFO[2025-12-08T16:59:05.017061663Z] API listen on /var/run/docker.sock\n  ```\n- If it failed, that means your kernel does not support running Docker even though the \"Devices Cgroups\" are available.\n- In that case, you need to compile a custom kernel with all the required Docker configurations enabled.\n\n**To verify Docker is fully functional,** you can run this command in a new terminal: `docker run -it hello-world`\n\n**To run the Docker daemon whenever the chroot starts, you can modify the \"Post-exec Script\" from the WebUI by going into the \"Options\" menu.**\n\n- To enable it, remove the comment from the beginning of the `dockerd \u003e /dev/null 2\u003e\u00261 \u0026` line, like this:\n\n  \u003cdetails\u003e\n  \u003csummary\u003e\u003c/summary\u003e\n\n    \u003cp align=\"center\"\u003e\n      \u003cimg src=\"Screenshots/dockerd.jpg\" alt=\"Docker Daemon\" width=\"650\" /\u003e\n      \u003cbr\u003e\u003cem\u003eUncomment dockerd in post-exec\u003c/em\u003e\n    \u003c/p\u003e\n\n  \u003c/details\u003e\n\n\u003e [!NOTE]\n\u003e **Networking inside Docker**\n\u003e\n\u003e **For maximum compatibility,** we ship the pre-built rootfs with Docker networking features disabled and **force configured** to use **NAT** instead of creating Docker's own `docker0` network interface.\n\u003e\n\u003e You can modify this behavior by editing `/etc/docker/daemon.json` if needed.\n\u003e\n\u003e **Additionally,** every action you run with the `docker run` command will automatically use `docker run --net=host` via the `docker` function in [this script](./Docker/scripts/bashrc.sh), which tells Docker to use the host network for all networking tasks, including internet access.\n\n\u003e [!IMPORTANT]\n\u003e\n\u003e **Even if you have a custom kernel with all the necessary configurations enabled,** Docker still won't be able to create the `docker0` interface without flushing the existing iptables filter chains.\n\u003e\n\u003e **To do this,** first, you need to use `iptables-legacy` and `ip6tables-legacy`.\n\u003e\n\u003e Run these commands inside Ubuntu:\n\u003e ```\n\u003e update-alternatives --set iptables /usr/sbin/iptables-legacy\n\u003e update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy\n\u003e```\n\u003e **Then,** run these commands to fix the Docker iptables issue:\n\u003e ```\n\u003e iptables -t filter -F\n\u003e ip6tables -t filter -F\n\u003e```\n\u003e\n\u003e **Now,** you can edit `/etc/docker/daemon.json` to use iptables and run `dockerd` to see if it works. Keep in mind this will only work if your kernel has the necessary kernel configurations enabled.\n\n\u003ca id=\"credits\"\u003e\u003c/a\u003e\n## 🙏 Credits\n\n- [Ubuntu](https://ubuntu.com/) - The core\n- [Kali NetHunter project](https://gitlab.com/kalilinux/nethunter) for my own understanding of chroot and sysctl commands\n- [Chroot-distro](https://github.com/Magisk-Modules-Alt-Repo/chroot-distro) for the internet connectivity fix in initial versions\n- [Brutal-Busybox](https://github.com/feravolt/Brutal_busybox) for the statically-linked aarch64 BusyBox binary used in various scripts to perform certain operations.\n- [docker-systemctl-replacement](https://github.com/gdraheim/docker-systemctl-replacement) for [systemctl](./Docker/scripts/systemctl3.py) implementation in chroot\n- [optimizer](https://github.com/OptimizerS1) for the cool banner design :)\n- [Maxim-Root](https://github.com/Maxim-Root) for providing me with a server and additional resources for the project\n\n\u003ca id=\"license\"\u003e\u003c/a\u003e\n## 📜 License\n\nThis project is released under the [MIT License](./LICENSE). You are free to use, modify, and distribute it as long as the original copyright notice and license terms are preserved.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fravindu644%2FUbuntu-Chroot","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fravindu644%2FUbuntu-Chroot","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fravindu644%2FUbuntu-Chroot/lists"}