From 49b46fb360b1681e9644967ff63d21b911cfc667 Mon Sep 17 00:00:00 2001 From: Exploit Intel Date: Tue, 15 Sep 2026 17:26:41 +0300 Subject: [PATCH 1/2] fix: keep the module verification command parseable The count-invariant message used single quotes inside the single-quoted phone command, truncating the assembled string at the device shell and failing every update at the verification step. The message is double-quoted, and the test fake now runs dash -n over the captured phone command so an unparseable string can never pass the suite again. Ports the Pixel 11 fix (observed live on its rc.11 update). --- deployment/simple-install.sh | 2 +- tests/simple-installer.test.mjs | 8 ++++++++ 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/deployment/simple-install.sh b/deployment/simple-install.sh index dae803c..972bf8b 100755 --- a/deployment/simple-install.sh +++ b/deployment/simple-install.sh @@ -248,7 +248,7 @@ verify_module_files() { push "$work/files.tar" /data/local/tmp/eip-module-files.tar push "$work/manifest" /data/local/tmp/eip-module-manifest push "$work/names" /data/local/tmp/eip-module-names - phone 'tar -xf /data/local/tmp/eip-module-files.tar -C /data/adb/modules/eip-pixel8a-forge && chown -R 0:0 /data/adb/modules/eip-pixel8a-forge && cd /data/adb/modules/eip-pixel8a-forge && /data/adb/ksu/bin/busybox sha256sum -c /data/local/tmp/eip-module-manifest -s && find . -type f | sed "s|^\\./||" | LC_ALL=C sort | LC_ALL=C comm -23 - /data/local/tmp/eip-module-names | while IFS= read -r stale; do case "$stale" in disable|remove|update|skip_mount) continue ;; esac; rm -f "$stale"; done; n_names=$(wc -l < /data/local/tmp/eip-module-names); n_files=$(find . -type f | wc -l); n_markers=0; for m in disable remove update skip_mount; do [ -f "$m" ] && n_markers=$((n_markers + 1)); done; if [ "$n_files" -ne $((n_names + n_markers)) ]; then printf 'module tree contains unexpected files beyond the payload and module-state markers\n' >&2; exit 5; fi; rm -f /data/local/tmp/eip-module-files.tar /data/local/tmp/eip-module-manifest /data/local/tmp/eip-module-names; exit 0' \ + phone 'tar -xf /data/local/tmp/eip-module-files.tar -C /data/adb/modules/eip-pixel8a-forge && chown -R 0:0 /data/adb/modules/eip-pixel8a-forge && cd /data/adb/modules/eip-pixel8a-forge && /data/adb/ksu/bin/busybox sha256sum -c /data/local/tmp/eip-module-manifest -s && find . -type f | sed "s|^\\./||" | LC_ALL=C sort | LC_ALL=C comm -23 - /data/local/tmp/eip-module-names | while IFS= read -r stale; do case "$stale" in disable|remove|update|skip_mount) continue ;; esac; rm -f "$stale"; done; n_names=$(wc -l < /data/local/tmp/eip-module-names); n_files=$(find . -type f | wc -l); n_markers=0; for m in disable remove update skip_mount; do [ -f "$m" ] && n_markers=$((n_markers + 1)); done; if [ "$n_files" -ne $((n_names + n_markers)) ]; then printf "module tree contains unexpected files beyond the payload and module-state markers" >&2; exit 5; fi; rm -f /data/local/tmp/eip-module-files.tar /data/local/tmp/eip-module-manifest /data/local/tmp/eip-module-names; exit 0' \ || die 'installed module files do not match the payload' rm -rf "$work" } diff --git a/tests/simple-installer.test.mjs b/tests/simple-installer.test.mjs index 128f3ac..e8fe761 100644 --- a/tests/simple-installer.test.mjs +++ b/tests/simple-installer.test.mjs @@ -317,6 +317,14 @@ async function fakeToolMain() { return; } if (command.startsWith("tar -xf /data/local/tmp/eip-module-files.tar")) { + // The phone command must parse before anything else: a quoting break in + // the assembled string truncated it on a real device and no other check + // caught it. + const parse = spawnSync("/bin/dash", ["-n"], { input: command, encoding: "utf8" }); + if (parse.status !== 0) { + process.stderr.write(`phone command does not parse: ${parse.stderr}\n`); + process.exit(98); + } // Reproduce the phone-side proof on the host: extract the pushed overlay // and verify it against the pushed manifest with the same flags. const staged = fs.mkdtempSync(`${env.FAKE_PUSH_DIR}/verify-`); From f7ff622e43b3b40578b1548eb8a313aa7c220ceb Mon Sep 17 00:00:00 2001 From: Exploit Intel Date: Tue, 15 Sep 2026 17:51:01 +0300 Subject: [PATCH 2/2] fix: keep the invariant message on its own line --- deployment/simple-install.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/deployment/simple-install.sh b/deployment/simple-install.sh index 972bf8b..5811a4c 100755 --- a/deployment/simple-install.sh +++ b/deployment/simple-install.sh @@ -248,7 +248,7 @@ verify_module_files() { push "$work/files.tar" /data/local/tmp/eip-module-files.tar push "$work/manifest" /data/local/tmp/eip-module-manifest push "$work/names" /data/local/tmp/eip-module-names - phone 'tar -xf /data/local/tmp/eip-module-files.tar -C /data/adb/modules/eip-pixel8a-forge && chown -R 0:0 /data/adb/modules/eip-pixel8a-forge && cd /data/adb/modules/eip-pixel8a-forge && /data/adb/ksu/bin/busybox sha256sum -c /data/local/tmp/eip-module-manifest -s && find . -type f | sed "s|^\\./||" | LC_ALL=C sort | LC_ALL=C comm -23 - /data/local/tmp/eip-module-names | while IFS= read -r stale; do case "$stale" in disable|remove|update|skip_mount) continue ;; esac; rm -f "$stale"; done; n_names=$(wc -l < /data/local/tmp/eip-module-names); n_files=$(find . -type f | wc -l); n_markers=0; for m in disable remove update skip_mount; do [ -f "$m" ] && n_markers=$((n_markers + 1)); done; if [ "$n_files" -ne $((n_names + n_markers)) ]; then printf "module tree contains unexpected files beyond the payload and module-state markers" >&2; exit 5; fi; rm -f /data/local/tmp/eip-module-files.tar /data/local/tmp/eip-module-manifest /data/local/tmp/eip-module-names; exit 0' \ + phone 'tar -xf /data/local/tmp/eip-module-files.tar -C /data/adb/modules/eip-pixel8a-forge && chown -R 0:0 /data/adb/modules/eip-pixel8a-forge && cd /data/adb/modules/eip-pixel8a-forge && /data/adb/ksu/bin/busybox sha256sum -c /data/local/tmp/eip-module-manifest -s && find . -type f | sed "s|^\\./||" | LC_ALL=C sort | LC_ALL=C comm -23 - /data/local/tmp/eip-module-names | while IFS= read -r stale; do case "$stale" in disable|remove|update|skip_mount) continue ;; esac; rm -f "$stale"; done; n_names=$(wc -l < /data/local/tmp/eip-module-names); n_files=$(find . -type f | wc -l); n_markers=0; for m in disable remove update skip_mount; do [ -f "$m" ] && n_markers=$((n_markers + 1)); done; if [ "$n_files" -ne $((n_names + n_markers)) ]; then printf "module tree contains unexpected files beyond the payload and module-state markers\n" >&2; exit 5; fi; rm -f /data/local/tmp/eip-module-files.tar /data/local/tmp/eip-module-manifest /data/local/tmp/eip-module-names; exit 0' \ || die 'installed module files do not match the payload' rm -rf "$work" }