@@ -590,6 +590,8 @@ public void addNewSession() {
590590
591591 String hostShell = "/system/bin/sh" ;
592592 File workingDirectory = activity .getFilesDir (); // Start in the app's secure root
593+ // K2GO-446: single source for the generated iiab script path (writer and .mkshrc wrapper).
594+ File iiabScript = new File (new File (workingDirectory , "usr/bin" ), "iiab" );
593595
594596 try {
595597 File hostBinDir = new File (activity .getFilesDir (), "usr/bin" );
@@ -653,7 +655,6 @@ public void addNewSession() {
653655 File tmpDir = new File (activity .getFilesDir (), "proot_tmp" );
654656 if (!tmpDir .exists ()) tmpDir .mkdirs ();
655657
656- File iiabCliScript = new File (hostBinDir , "iiab" );
657658 StringBuilder cliStr = new StringBuilder ();
658659
659660 // ADFA-4630: resolve the app's effective DNS (user's custom config when enabled,
@@ -890,10 +891,10 @@ public void addNewSession() {
890891 cliStr .append (" do_login\n " );
891892 cliStr .append ("fi\n " );
892893
893- java .io .FileOutputStream fosCli = new java .io .FileOutputStream (iiabCliScript );
894+ java .io .FileOutputStream fosCli = new java .io .FileOutputStream (iiabScript );
894895 fosCli .write (cliStr .toString ().getBytes ());
895896 fosCli .close ();
896- iiabCliScript .setExecutable (true );
897+ iiabScript .setExecutable (true );
897898
898899 } catch (Exception e ) {
899900 Log .e (TAG , "Failed to create host scripts" , e );
@@ -977,6 +978,9 @@ public void addNewSession() {
977978 // persistent history would require replacing /system/bin/sh with a fuller
978979 // shell (e.g. a bundled bash / busybox ash) — see ADFA-4709.
979980 mkshrc .append ("export HISTSIZE=5000\n " );
981+ // K2GO-446: targetSdk 35 W^X blocks execve of app-data-dir files, so run the
982+ // generated iiab script through the interpreter instead of exec'ing it directly.
983+ mkshrc .append ("iiab() { /system/bin/sh \" " ).append (iiabScript .getAbsolutePath ()).append ("\" \" $@\" ; }\n " );
980984 fosMkshrc .write (mkshrc .toString ().getBytes ());
981985 fosMkshrc .close ();
982986 } catch (Exception e ) {
@@ -988,6 +992,9 @@ public void addNewSession() {
988992 "TERM=xterm-256color" ,
989993 "HOME=" + workingDirectory .getAbsolutePath (),
990994 "ENV=" + mkshrcFile .getAbsolutePath (),
995+ // K2GO-446: writable TMPDIR so mksh can spool the iiab script's here-docs
996+ // (unset by default, mksh then falls back to a non-writable path).
997+ "TMPDIR=" + activity .getCacheDir ().getAbsolutePath (),
991998 // Include the system bins and our W^X fake prefix bins
992999 "PATH=/sbin:/system/sbin:/system/bin:/system/xbin:" + workingDirectory .getAbsolutePath () + "/usr/bin"
9931000 };
0 commit comments