Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Bug] Temporary-root (locked BL, KernelSU LKM late-load) on Android 17 / HyperOS 4: VectorDaemon dies with StackOverflowError (kk.onTransact recursion 32×) → framework never activates

Abierto
#996 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
35/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
android, kotlin
Área
backend

Línea de trabajo

Start by examining /data/tombstones/tombstone_00 and the repeated kk.onTransact / JavaBBinderExt::onTransact frames, then compare with the verbose boot logs and the related reports #939 and #904. The report identifies a daemon Binder recursion ending in StackOverflowError; done means the daemon stays alive, vector-cli status works, and the framework activates on the described setup.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Steps to reproduce/复现步骤
  1. Device: Redmi 25060RK16C (dali), Xiaomi HyperOS 4.0 / Android 17 (SDK 37). Bootloader is locked, so root is obtained with a temporary-root exploit that loads KernelSU as an LKM via ksud late-load after the system has already booted. KernelSU's post-fs-data / service stages therefore run long after zygote is already up.
  2. Install zygisk_vector (Vector v2.2, 3111-efb82883-JingMatrix-Vector) + zygisksu (Zygisk Next 1.5.0 (843-5217106-release)).
  3. Because Zygisk Next starts after zygote, zygiskd status reports zygote_states:0 and no app gets the framework. Restarting zygote once lets ZN inject successfully:
    zygote_states:1, modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk
  4. Use the device normally, and/or open the manager:
    am start -c org.matrix.vector.manager.LAUNCH_MANAGER com.android.shell/.BugreportWarningActivity
Expected behaviour/预期行为

The daemon stays alive, vector-cli status works, the manager activates, and the framework is injected into scoped apps — on every boot.

Actual behaviour/实际行为

The daemon dies and the framework goes inactive. Observed sequence:

(a) Binder transactions to the daemon are extremely slow (2.3–2.5 s each):

[ 2026-10-04T23:34:47.553     0: 25633: 26451 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2346ms. Data bytes: 172 Reply bytes: 32 Flags: 18
[ 2026-10-04T23:34:47.553     0: 25633: 25943 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2502ms. Data bytes: 188 Reply bytes: 32 Flags: 18

(b) system_server keeps dying and re-injection fails (System Server died occurred 4× in this one log):

[ 2026-10-04T23:33:36.652     0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...
[ 2026-10-04T23:33:42.668     0: 25633: 25633 E/VectorDaemon ] Failed to inject VectorService into system_server
[ 2026-10-04T23:33:42.668     0: 25633: 25633 W/VectorDaemon ] Restarting system_server...
[ 2026-10-04T23:34:30.103     0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...

(c) A freshly started system_server cannot fetch the framework DEX because the daemon is already gone:

[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] android.os.DeadObjectException
[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] DEX fetch transaction failed.
[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] Failed to fetch framework DEX for system_server.

(d) Manager never activates:

W/VectorManager: splash: no daemon binder after 2500ms, continuing unactivated
java.lang.IllegalStateException: Daemon is not active
	at org.matrix.vector.manager.ipc.DaemonClient$runIpc$2.invokeSuspend(DaemonClient.kt:39)

/data/adb/lspd/cli status at that point returns Error: Socket Failure: Connection refused, and VectorZygiskBridge GET_BINDER count stays at 0.

(e) The daemon's actual death — /data/tombstones/tombstone_00, verbatim:

Cmdline: vectord
signal 11 (SIGSEGV), code 2 (SEGV_ACCERR), fault addr 0x0000007139b0df60 (write)
Abort message: 'JNI FatalError called: java.lang.Error thrown during binder transaction: (Unknown exception message) (Error was StackOverflowError) (toString() error was StackOverflowError)'

The crashing thread's native stack alternates between exactly two frames, 32 times (kk is an obfuscated class inside daemon.apk):

      #27 pc 00000000001ae574  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+964)
      #35 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      #42 pc 00000000001ae258  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+168)
      #50 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      #57 pc 00000000001ae258  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(...)+168)
      #65 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      ... (the pair repeats 32× in total; frame count reaches #170+) ...

Counted occurrences in that tombstone: (kk.onTransact+20) 32×, JavaBBinderExt::onTransact 31×. This is unbounded recursion inside the daemon's binder onTransact handler, which overflows the stack and kills the daemon.

(f) Separately, a "fatal coroutine exception" in a background daemon task (drawable load for the status notification). This one goes through a MediaTek resource-cache path:

[ 2026-10-04T23:34:57.667     0: 25633: 25978 E/VectorDaemon ] Caught fatal coroutine exception in background task!
android.content.res.Resources$NotFoundException: Drawable org.matrix.vector.daemon:drawable/ic_statue_monochrome with resource ID #0x7f010000
Caused by: java.lang.NullPointerException: Attempt to invoke virtual method 'boolean java.lang.Object.equals(java.lang.Object)' on a null object reference
	at com.mediatek.res.AsyncDrawableCache.putCacheList(AsyncDrawableCache.java:189)
	at com.mediatek.res.ResOptExtImpl.putCacheList(ResOptExtImpl.java:69)
	at android.content.res.ResourcesImpl.cacheDrawable(ResourcesImpl.java:1069)
	at android.content.res.ResourcesImpl.loadDrawable(ResourcesImpl.java:1000)
	at android.content.res.MiuiResourcesImpl.loadDrawable(MiuiResourcesImpl.java:334)
	at android.content.res.Resources.loadDrawable(Resources.java:1170)
	at android.content.res.Resources.getDrawableForDensity(Resources.java:1158)
	at android.content.res.Resources.getDrawable(Resources.java:1097)
	at hh.d(r8-map-id-94e6fafa64eec1c2091f734c0f848aff0b26c70900661e2a6f4e6038da2c292f:17)
	at hh.g(...:54)
	at w2.h(...:41)
	at w2.f(...:6)
	at bk.d(...:8)
	at q9.run(...:114)
	at xe.run(...:4)
	at ok.run(...:3)
	at i8.run(...:85)

(g) On every system_server injection:

[ 2026-10-04T23:34:31.474  1000:  9486:  9486 E/LSPlant ] mmap dual mapping failed with 13: Permission denied

module/sepolicy.rule is loaded and already includes allow system_server system_server process execmem and allow zygote zygote process execmem (zygiskd shows these applied).

Relation to existing reports/与已有 issue 的关系
  • #939 — same scenario (temporary/tethered root, locked bootloader, KernelSU + Zygisk Next + Vector, daemon dies, framework inactive). That report shows DeadSystemException; here the daemon dies from a StackOverflowError inside onTransact. Filing separately because the crash signature differs, but it may be the same underlying temporary-root problem you said you are working on.
  • #904 — identical manager-side symptom (no daemon binder after 2500ms, Daemon is not active) on Xiaomi HyperOS.
  • The same vectord crash (SIGSEGV + StackOverflowError) also appears in a KernelSU bugreport captured earlier on this device (tombstone_26, tombstone_27), i.e. it reproduces across boots, not just once.
Xposed Module List/Xposed 模块列表
com.github.tianma8023.xposed.smscode  10168  enabled
io.github.a13e300.fusefixer           10100  enabled
me.hd.wauxv                           10093  enabled
org.lsposed.corepatch                 10417  enabled
org.xiyu.starx                        10314  enabled
io.github.bitstandbyyou.bilisb        10115  disabled
Root implementation/Root 方案

Temporary root on a locked-bootloader device: KernelSU 32601 (manager package me.weishu.kernelsu, versionName v3.3.0, ksud 3.3.0, uapi 2), kernel module loaded via ksud late-load from a temporary-root exploit. Zygisk Next reports root_impl:3, root_ver:32601, root_status:✅KernelSU (32601).

System Module List/系统模块列表
zygisksu                    Zygisk Next 1.5.0 (843-5217106-release)      enabled
zygisk_vector               Vector v2.2 (3111-efb82883-JingMatrix-Vector) enabled
playintegrityfix            v4.7-1-inject-s                             enabled
tricky_store                TEESimulator-RS v6.0.1-307                  enabled
hma_oss_zygisk              HMA-OSS Zygisk oss-164                      enabled
TA_enhanced                 -                                           enabled
miui_theme_mod              v7                                          enabled
zygisk-storage-isolation    v29.0.1                                     DISABLED
Vector version/Vector 版本

v2.2 (3111-efb82883-JingMatrix-Vector) (versionCode 3111)

Android version/Android 版本

Android 17 (SDK 37), Xiaomi HyperOS 4.0 (OS4.0.0.8.XONCNXM), Redmi 25060RK16C (dali),
fingerprint Redmi/dali/dali:17/CP2A.260605.016/OS4.0.0.8.XONCNXM:user/release-keys,
kernel 6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64, SELinux enforcing.

Version requirement/版本要求
Logs/日志

All excerpts above are verbatim from the device (no editing of the log lines themselves). Available on request, not pasted in full here:

  • /data/tombstones/tombstone_00 — the vectord SIGSEGV/StackOverflowError tombstone (full, including native stack)
  • /data/adb/lspd/log/verbose_*.log — full verbose log for the boot
  • /data/adb/modules/zygisksu/ state + zygiskd status output

zygiskd status on a boot where the daemon later died:

version_local:1.5.0-843-5217106-release
abi:arm64-v8a (primary)
uname:6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64
android_sdk:37
version:1.5.0-843-5217106-release
zygote_states:1
zygote_state_0:1,0,9205,zygote,3
inject_state:1
root_status:✅KernelSU (32601)
enforce_denylist:2
memory_type:1
linker:1
hook_mode:1
root_impl:3
root_ver:32601
modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk
modules32:0
modules_with_issue:0
Lenguaje dominante
Kotlin
Estrellas
12.6k
Forks
850
Merge medio
20 min
PR fusionados (30 d)
1

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de JingMatrix/Vector

Todos los issues de JingMatrix/Vector

Issues similares

Más issues de Kotlin

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.