mkdir
-
p
-
m
700
/
data
/
local
/
tmp
/
tmp
-
ca
-
copy
cp
/
apex
/
com.android.conscrypt
/
cacerts
/
*
/
data
/
local
/
tmp
/
tmp
-
ca
-
copy
/
mount
-
t tmpfs tmpfs
/
system
/
etc
/
security
/
cacerts
mv
/
data
/
local
/
tmp
/
tmp
-
ca
-
copy
/
*
/
system
/
etc
/
security
/
cacerts
/
cp
/
data
/
local
/
tmp
/
269953fb
.
0
/
system
/
etc
/
security
/
cacerts
/
cp
/
data
/
local
/
tmp
/
9a5ba575
.
0
/
system
/
etc
/
security
/
cacerts
/
cp
/
data
/
local
/
tmp
/
6e39a726
.
0
/
system
/
etc
/
security
/
cacerts
/
chown root:root
/
system
/
etc
/
security
/
cacerts
/
*
chmod
644
/
system
/
etc
/
security
/
cacerts
/
*
chcon u:object_r:system_file:s0
/
system
/
etc
/
security
/
cacerts
/
*
ZYGOTE_PID
=
$(pidof zygote || true)
ZYGOTE64_PID
=
$(pidof zygote64 || true)
for
Z_PID
in
"$ZYGOTE_PID"
"$ZYGOTE64_PID"
; do
if
[
-
n
"$Z_PID"
]; then
nsenter
-
-
mount
=
/
proc
/
$Z_PID
/
ns
/
mnt
-
-
\
/
bin
/
mount
-
-
bind
/
system
/
etc
/
security
/
cacerts
/
apex
/
com.android.conscrypt
/
cacerts
fi
done
APP_PIDS
=
$(
echo
"$ZYGOTE_PID $ZYGOTE64_PID"
| \
xargs
-
n1 ps
-
o
'PID'
-
P | \
grep
-
v PID
)
for
PID
in
$APP_PIDS; do
nsenter
-
-
mount
=
/
proc
/
$PID
/
ns
/
mnt
-
-
\
/
bin
/
mount
-
-
bind
/
system
/
etc
/
security
/
cacerts
/
apex
/
com.android.conscrypt
/
cacerts &
done
wait
echo
"System certificate injected"