Skip to content

fix(meta-loader): repackage obfuscated classes to prevent namespace collisions in inject mode - #122

Open
s1ddhants1 wants to merge 1 commit into
JingMatrix:masterfrom
s1ddhants1:fix/metaloader-repackage-classes
Open

s1ddhants1 wants to merge 1 commit into
JingMatrix:masterfrom
s1ddhants1:fix/metaloader-repackage-classes

Conversation

@s1ddhants1

Copy link
Copy Markdown

Problem

When patching an application with --injectdex (injectDex = true), metaloader.dex is appended as classes(N+1).dex alongside the target application's original DEX files.

Because meta-loader/proguard-rules.pro only kept LSPAppComponentFactoryStub without specifying -repackageclasses, R8/ProGuard shrinks and obfuscates internal dependencies (HiddenApiBypass, projects.share.java) into single-letter classes in the default root package (La;, Lb;, Lc;, Ld;, Le;, Lf;, Lg;, Lh;, Li;).

If the target application is also compiled with R8/ProGuard, its primary classes.dex often already contains classes La; through Li;. When Android's PathClassLoader attempts to resolve HiddenApiBypass helper classes (such as dummy stub class g.class used to compute artMethod and artField offsets), Android resolves the target app's unrelated class from classes.dex instead of the loader's class in classes(N+1).dex.

This causes a NoSuchMethodException during <clinit>, causing HiddenApiBypass to fail with ExceptionInInitializerError. As a result, LSPAppComponentFactoryStub fails to query IPackageManager and crashes immediately on launch with:

java.lang.IllegalStateException: No installed LSPatch manager carries the loader (tried org.lsposed.lspatch); re-patch this app or reinstall the manager

Solution

  • Add -repackageclasses org.lsposed.lspatch.metaloader to meta-loader/proguard-rules.pro.
  • This ensures all minified classes are placed under the org.lsposed.lspatch.metaloader namespace, preventing collisions with root-level classes in target multi-dex APKs.

Validation

  1. Ran ./gradlew :meta-loader:assembleRelease and inspected the resulting classes.dex with dexdump. Verified all classes reside strictly under Lorg/lsposed/lspatch/metaloader/*:
    • Lorg/lsposed/lspatch/metaloader/LSPAppComponentFactoryStub;
    • Lorg/lsposed/lspatch/metaloader/a; .. i;
  2. Verified with an R8-obfuscated multi-dex application patched with injectDex = true. The loader bootstraps successfully without the previous IllegalStateException / collision crash.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant