Skip to content

K2GO-446 fix(terminal): run iiab orchestrator through the interpreter - #621

Merged
luisguzman-adfa merged 2 commits into
mainfrom
fix/K2GO-446-terminal-iiab-sdk35
Oct 3, 2026
Merged

luisguzman-adfa merged 2 commits into
mainfrom
fix/K2GO-446-terminal-iiab-sdk35

Conversation

@luisguzman-adfa

Copy link
Copy Markdown
Collaborator

At targetSdk 35 Android W^X (neverallow app_data_file:file execute_no_trans)
blocks execve of a file in the app data dir, so the host shell could not run the
generated iiab script directly ("Permission denied") and iiab --login was
unreachable from the terminal.

Fix: define iiab as a function in the generated .mkshrc that runs the script
through /system/bin/sh. Read and interpret are allowed; only execute is blocked.
The ninja symlinks and proot run from nativeLibraryDir and are unaffected.

Device-confirmed on OnePlus 7T (API 35): "iiab --help" -> Permission denied;
"sh /iiab --help" -> prints usage; "aria2c --version" works. Regression
from the targetSdk 35 move (K2GO-438), not covered by K2GO-439.

@luisguzman-adfa
luisguzman-adfa force-pushed the fix/K2GO-446-terminal-iiab-sdk35 branch from 3e80cb0 to 745b5e6 Compare October 3, 2026 03:33
At targetSdk 35 Android W^X (neverallow app_data_file:file execute_no_trans)
blocks execve of a file in the app data dir, so the host shell could not run
the generated iiab script directly ("Permission denied") and iiab --login was
unreachable. Define iiab as a .mkshrc function that runs the script through
/system/bin/sh; read and interpret are allowed, only execute is blocked. The
ninja symlinks and proot run from nativeLibraryDir and are unaffected.
@luisguzman-adfa
luisguzman-adfa force-pushed the fix/K2GO-446-terminal-iiab-sdk35 branch from 745b5e6 to d7a6f73 Compare October 3, 2026 03:39
Running the iiab script via mksh surfaced a latent failure: mksh spools
here-docs to $TMPDIR, which is unset, so it fell back to a non-writable path and
the login here-doc failed ("can't create temporary file ...: Permission
denied"). Point TMPDIR at the app cache dir; the iiab function subshell inherits
it. Device-confirmed: iiab --login enters Debian with no temp-file error.
@luisguzman-adfa

Copy link
Copy Markdown
Collaborator Author

Follow-up c7786d0: set a writable TMPDIR (app cache dir) for the host shell, so mksh can spool the iiab script here-docs; without it the login here-doc failed with a non-fatal "can't create temporary file" error. Device-confirmed on OnePlus 7T (API 35).

@luisguzman-adfa
luisguzman-adfa merged commit 7f444bb into main Oct 3, 2026
3 checks passed
@luisguzman-adfa
luisguzman-adfa deleted the fix/K2GO-446-terminal-iiab-sdk35 branch October 3, 2026 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant