Skip to content

[bug] MIUI 等启用 XOM(execute-only memory) 的 ROM 上, 注入后所有 app 启动崩溃/卡启动页 — 根因与修复 (PR #156) #157

Description

@leeduin

环境

  • 设备:Xiaomi cepheus,MIUI V12(Android 10,arm64)
  • lamda server:10.8(root 运行)
  • ROM 特性:系统库启用 execute-only memory(XOM,/proc/self/maps 中系统库段为 --x)

现象

server 一旦对任意 app 执行过注入(spawn 或 attach),之后所有经 zygote fork 出的进程均异常:

  1. 大多数 app 卡死在启动页(无 crash 弹窗,主线程已死)
  2. frida spawn() + resume() 的 app 在数秒内 SIGSEGV 退出
  3. com.miui.securitycenter.remote 等系统进程也会被一并崩掉
  4. 重启设备后恢复正常,注入一次后复现 —— 与具体 app 无关

根因

MIUI 对 zygote 内系统库启用 XOM(段权限 --x,可执行但禁读)。server 内嵌 frida 运行时在 zygote fork 特化路径上 hook 时,gum 需要读取目标内存构建 trampoline,读 libmedia.so 等系统库 .text 触发 SEGV_ACCERR,zygote 内的崩溃状态被后续所有 fork 的进程继承。

用 debuggerd -b <pid> 抓卡死 app 的主线程可见崩溃点落在系统库只读段访问;将 zygote64 内 --x 段恢复 r-x 后一切正常。

修复方案

已提交 PR #156:新增客户端方法 Device.fix_execute_only_memory(),通过 server 内嵌 frida attach zygote 并将 /system /apex /vendor 后备的 --x 段 mprotect() 回 r-x。设备/server 重启后调用一次即可,实测恢复 294 个段,注入后 app 正常存活。

也建议在 server 端注入流程内自动执行该恢复逻辑,免去手动调用。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions