My phone is a OnePlus7 Pro with the official system, not rooted, with only the Termux app installed
The Original Intent
I wrote two blogs before:
Recently I thought about it: native termux’s functionality is definitely not as strong as native Linux. So I want to run a separate Linux system on the phone, then use frp for tunneling to expose the ssh port to the public network. The phone runs Linux and is accessible anytime, anywhere.
A Simple linux Environment
In the last blog Running vscode_remote on Android, anyfed could already run the fedora system; the principle is proot. This time I was smarter and directly searched proot linux.
I found this part of the official wiki:
https://wiki.termux.com/wiki/PRoot

You can directly use proot-distro to run and start systems:
1 | proot-distro install <alias> |
ssh Service and frp Service
ssh service
Mainly you need to edit /etc/ssh/sshd_config.
Port 22 is definitely unusable, so I switched to 8122. On the phone everything runs as root by default, and the root user also needs password login allowed:
PermitRootLogin yes
frp service
Using frp is mainly to map my port to the public network so I can connect anytime anywhere. The token and server_addr need to be prepared in advance yourself.
1 | [common] |
Service Startup and Daemon Processes
Since we use proot, it’s not a complete Linux system — there’s no way to use systemd for daemon processes.
Left with no choice, I chose supervisor for service management; currently it only manages sshd and frp.
In .bashrc, if supervisor isn’t running, start it:
1 | if [ ! -f /proc/$(cat /var/run/supervisord.pid)/status ]; then |
After starting supervisor, I found supervisorctl couldn’t connect — mainly a unix socket reading problem; proot has rather many restrictions. My replacement solution here: switch to a tcp port.
Main modification: /etc/supervisor/supervisord.conf
1 | [inet_http_server] |
1 | # now running the command works normally |
Discussion of Security and Usability
Security
Reviewing the operations in the blog just now, can you count how many unsafe operations I have? Let me list them:
- Daily operations as the root user
PermitRootLogin yesallows root password login- After frp tunneling, the IP and port exposed to the public network
- supervisor using a tcp socket means all users on the machine have management privileges
I suggest everyone absolutely never use the above practices at work!!!
Since I use proot inside Termux, this root privilege has very little capability, so it can be used this way; there are no other users in this system, and supervisor can also be used directly like this.
frp tunneling only happens when I start the app — that is, with Termux normally closed, no port is exposed to the public network.
Usability
- Unlike using
Termuxdirectly, a fairly complete Linux system experience is much better: it has glibc, can run all kinds of Linux software — no different from a development server - Customized startup and shutdown: for colleagues doing ops on the road with only a phone at hand (hardcore friends can even do ops directly on the phone). A more comfortable option is finding a computer in an internet cafe, ssh-ing to your own phone; vscode remote can also serve as a temporary development machine
- I normally install the company-provided VPN on the phone; termux can also go through the VPN, so this little Linux system gets the same experience as the office network
Summary
The blog just introduces a remote ops solution I use daily myself. I rarely carry a computer out; being able to run a Linux system on the phone is really much more convenient. Also, what a terminal alone can do is limited — the ops management web side should ideally have supporting facilities too, so problems outside working hours can be handled better and faster.