Skip to content

Commit 745b5e6

Browse files
K2GO-446 fix(terminal): run iiab orchestrator through the interpreter
At targetSdk 35 Android W^X (neverallow app_data_file:file execute_no_trans) blocks execve of a file in the app data dir, so the host shell could not run the generated iiab script directly ("Permission denied") and iiab --login was unreachable. Define iiab as a .mkshrc function that runs the script through /system/bin/sh; read and interpret are allowed, only execute is blocked. The ninja symlinks and proot run from nativeLibraryDir and are unaffected.
1 parent 087362a commit 745b5e6

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

‎controller/app/src/main/java/org/appdevforall/k2go/TerminalController.java‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -977,6 +977,10 @@ public void addNewSession() {
977977
// persistent history would require replacing /system/bin/sh with a fuller
978978
// shell (e.g. a bundled bash / busybox ash) — see ADFA-4709.
979979
mkshrc.append("export HISTSIZE=5000\n");
980+
// K2GO-446: targetSdk 35 W^X blocks execve of app-data-dir files, so run the
981+
// generated iiab script through the interpreter instead of exec'ing it directly.
982+
String iiabFnPath = new File(new File(workingDirectory, "usr/bin"), "iiab").getAbsolutePath();
983+
mkshrc.append("iiab() { /system/bin/sh \"").append(iiabFnPath).append("\" \"$@\"; }\n");
980984
fosMkshrc.write(mkshrc.toString().getBytes());
981985
fosMkshrc.close();
982986
} catch (Exception e) {

0 commit comments

Comments
 (0)