我已经在字节码级别检测了一个应用程序,并从dex2oat获得了以下验证错误:
2020-09-23 19:39:04.005 4864-4864/? W/dex2oat: Verification error in int a.d.cg.b(byte[], int, int)
2020-09-23 19:39:04.005 4864-4864/? W/dex2oat: int a.d.cg.b(byte[], int, int): [0x25]
2020-09-23 19:39:04.005 4864-4864/? W/dex2oat: int a.d.cg.b(byte[], int, int): [0x27]
2020-09-23 19:39:04.005 4864-4864/? W/dex2oat: int a.d.cg.b(byte[], int, int) failed to verify: int a.d.cg.b(byte[], int, int): [0x2C] monitor-exit on non-object (Undefined)此方法的smali表示如下所示:
.method b([BII)I
.locals 4
move-object/from16 v2, p0
move-object/from16 v3, p1
move/from16 p0, p2
move/from16 p1, p3
iget-object v0, v2, La/d/cg;->a:La/d/bj;
iget-object v0, v0, La/d/bj;->p:Ljava/io/InputStream;
if-eqz v0, :cond_0
const-string p2, "La/d/cg;->b([BII)I->3"
invoke-static/range {p2 .. p2}, Lde/tracer/Tracer;->trace(Ljava/lang/String;)V
iget-object v0, v2, La/d/cg;->a:La/d/bj;
iget-object v0, v0, La/d/bj;->p:Ljava/io/InputStream;
check-cast v0, La/d/cn;
iget-object v1, v0, La/d/cn;->b:Ljava/lang/Object;
monitor-enter v1
:try_start_0
invoke-virtual {v0, v3, p0, p1}, La/d/cn;->b([BII)I
iget-object v0, v0, La/d/cn;->b:Ljava/lang/Object;
invoke-virtual {v0}, Ljava/lang/Object;->notify()V
monitor-exit v1
:cond_0
const-string p2, "La/d/cg;->b([BII)I->12"
invoke-static/range {p2 .. p2}, Lde/tracer/Tracer;->trace(Ljava/lang/String;)V
return p1
:catchall_0
move-exception v0
monitor-exit v1
:try_end_0
.catchall {:try_start_0 .. :try_end_0} :catchall_0
throw v0
.end method未插入指令的版本不包含跟踪器的调用和前面定义跟踪字符串的const-string指令。此外,前四个移动指令在原始版本中也不存在;它们用于在'end‘处获取空闲寄存器。我还用寄存器类型信息注释了smali文件,输出如下(只有验证错误描述的有趣部分):
#@1b
#v0=(Reference,La/d/cn;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
monitor-enter v1
#v0=(Reference,La/d/cn;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@1c
:try_start_1c
#v0=(Reference,La/d/cn;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
invoke-virtual {v0, v3, p0, p1}, La/d/cn;->b([BII)I
#v0=(Reference,La/d/cn;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@1f
#v0=(Reference,La/d/cn;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
iget-object v0, v0, La/d/cn;->b:Ljava/lang/Object;
#v0=(Reference,Ljava/lang/Object;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@21
#v0=(Reference,Ljava/lang/Object;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
invoke-virtual {v0}, Ljava/lang/Object;->notify()V
#v0=(Reference,Ljava/lang/Object;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@24
#v0=(Reference,Ljava/lang/Object;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
monitor-exit v1
#v0=(Reference,Ljava/lang/Object;);v1=(Reference,Ljava/lang/Object;);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@25
:cond_25
#v0=(Reference,Ljava/lang/Object;):merge{0xc:(Reference,Ljava/io/InputStream;),0x24:(Reference,Ljava/lang/Object;)}
#v1=(Conflicted):merge{0xc:(Uninit),0x24:(Reference,Ljava/lang/Object;)}
#v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);
#p2=(Conflicted):merge{0xc:(Integer),0x24:(Reference,Ljava/lang/String;)}
#p3=(Integer);
const-string p2, "La/d/cg;->b([BII)I->12"
#v0=(Reference,Ljava/lang/Object;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@27
#v0=(Reference,Ljava/lang/Object;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
invoke-static/range {p2 .. p2}, Lde/tracer/Tracer;->trace(Ljava/lang/String;)V
#v0=(Reference,Ljava/lang/Object;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@2a
#v0=(Reference,Ljava/lang/Object;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
return p1
#v0=(Reference,Ljava/lang/Object;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Reference,Ljava/lang/String;);p3=(Integer);
#@2b
:catchall_2b
#v0=(Reference,Ljava/lang/Object;):merge{0xc:(Reference,Ljava/io/InputStream;),0x1b:(Reference,La/d/cn;),0x1c:(Reference,La/d/cn;),0x1f:(Reference,Ljava/lang/Object;),0x21:(Reference,Ljava/lang/Object;),0x24:(Reference,Ljava/lang/Object;),0x25:(Reference,Ljava/lang/Object;),0x2b:(Reference,Ljava/lang/Throwable;)}
#v1=(Conflicted):merge{0xc:(Uninit),0x1b:(Reference,Ljava/lang/Object;),0x1c:(Reference,Ljava/lang/Object;),0x1f:(Reference,Ljava/lang/Object;),0x21:(Reference,Ljava/lang/Object;),0x24:(Reference,Ljava/lang/Object;),0x25:(Conflicted),0x2b:(Conflicted)}
#v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);
#p2=(Conflicted):merge{0xc:(Integer),0x1b:(Reference,Ljava/lang/String;),0x1c:(Reference,Ljava/lang/String;),0x1f:(Reference,Ljava/lang/String;),0x21:(Reference,Ljava/lang/String;),0x24:(Reference,Ljava/lang/String;),0x25:(Reference,Ljava/lang/String;),0x2b:(Conflicted)}
#p3=(Integer);
move-exception v0
#v0=(Reference,Ljava/lang/Throwable;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Conflicted);p3=(Integer);
#@2c
#v0=(Reference,Ljava/lang/Throwable;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Conflicted);p3=(Integer);
monitor-exit v1
#v0=(Reference,Ljava/lang/Throwable;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Conflicted);p3=(Integer);
:try_end_2d
.catchall {:try_start_1c .. :try_end_2d} :catchall_2b
#@2d
#v0=(Reference,Ljava/lang/Throwable;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Conflicted);p3=(Integer);
throw v0
#v0=(Reference,Ljava/lang/Throwable;);v1=(Conflicted);v2=(Reference,La/d/cg;);v3=(Reference,[B);p0=(Integer);p1=(Integer);p2=(Conflicted);p3=(Integer);
.end method当查看位置0x2C时,我只观察到v1处于冲突状态,而0x2B处描述的合并告诉我uninit已与引用类型合并。我假设这就是问题所在,并导致验证错误(https://android.googlesource.com/platform/art/+/master/runtime/verifier/register_line.cc#367)。但是,当考虑附加了寄存器类型信息的原始smali文件时,我观察到v1从未处于冲突状态。此外,奇怪的是--至少对我来说--我的工具从不接触寄存器v1,那么这种冲突是如何发生的呢?
发布于 2020-09-24 02:48:11
问题是,通过在try块中添加对跟踪函数的调用,可以将该位置的边添加到catch-all异常处理程序。
有些指令能够抛出异常,有些则不能。例如,返回指令不能抛出异常,而调用指令可以抛出异常。因此,对于try块中可以抛出的任何指令,都会向该try块的任何异常处理程序添加一个边。
在原始方法中,方法开头附近的条件(if-eqz v0, :cond_0)直接跳转到返回语句,因此异常处理程序没有边,因为它不能抛出异常。因此,访问该异常处理程序的唯一方法是通过设置了v1的执行路径。
但是,通过添加invoke指令,您向异常处理程序添加了一个边缘,因此现在有一个指向异常处理程序的执行路径,其中v1未设置。
因此,基本上可以考虑这样一种情况:v0在条件语句中为null (因此进行了跳转),然后跟踪函数抛出一个异常。将调用异常处理程序,但尚未设置v1。
https://stackoverflow.com/questions/64034015
复制相似问题