Repository navigation
K2GO-446 fix(terminal): run iiab orchestrator through the interpreter - #621
Merged
Merged
Conversation
luisguzman-adfa
force-pushed
the
fix/K2GO-446-terminal-iiab-sdk35
branch
from
October 3, 2026 03:33
3e80cb0 to
745b5e6
Compare
At targetSdk 35 Android W^X (neverallow app_data_file:file execute_no_trans)
blocks execve of a file in the app data dir, so the host shell could not run
the generated iiab script directly ("Permission denied") and iiab --login was
unreachable. Define iiab as a .mkshrc function that runs the script through
/system/bin/sh; read and interpret are allowed, only execute is blocked. The
ninja symlinks and proot run from nativeLibraryDir and are unaffected.
luisguzman-adfa
force-pushed
the
fix/K2GO-446-terminal-iiab-sdk35
branch
from
October 3, 2026 03:39
745b5e6 to
d7a6f73
Compare
Running the iiab script via mksh surfaced a latent failure: mksh spools
here-docs to $TMPDIR, which is unset, so it fell back to a non-writable path and
the login here-doc failed ("can't create temporary file ...: Permission
denied"). Point TMPDIR at the app cache dir; the iiab function subshell inherits
it. Device-confirmed: iiab --login enters Debian with no temp-file error.
Collaborator
Author
|
Follow-up c7786d0: set a writable TMPDIR (app cache dir) for the host shell, so mksh can spool the iiab script here-docs; without it the login here-doc failed with a non-fatal "can't create temporary file" error. Device-confirmed on OnePlus 7T (API 35). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
At targetSdk 35 Android W^X (neverallow app_data_file:file execute_no_trans)
blocks execve of a file in the app data dir, so the host shell could not run the
generated iiab script directly ("Permission denied") and iiab --login was
unreachable from the terminal.
Fix: define iiab as a function in the generated .mkshrc that runs the script
through /system/bin/sh. Read and interpret are allowed; only execute is blocked.
The ninja symlinks and proot run from nativeLibraryDir and are unaffected.
Device-confirmed on OnePlus 7T (API 35): "iiab --help" -> Permission denied;
"sh /iiab --help" -> prints usage; "aria2c --version" works. Regression
from the targetSdk 35 move (K2GO-438), not covered by K2GO-439.