[Bug] Temporary-root (locked BL, KernelSU LKM late-load) on Android 17 / HyperOS 4: VectorDaemon dies with StackOverflowError (kk.onTransact recursion 32×) → framework never activates
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start by examining /data/tombstones/tombstone_00 and the repeated kk.onTransact / JavaBBinderExt::onTransact frames, then compare with the verbose boot logs and the related reports #939 and #904. The report identifies a daemon Binder recursion ending in StackOverflowError; done means the daemon stays alive, vector-cli status works, and the framework activates on the described setup.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Steps to reproduce/复现步骤
- Device: Redmi 25060RK16C (
dali), Xiaomi HyperOS 4.0 / Android 17 (SDK 37). Bootloader is locked, so root is obtained with a temporary-root exploit that loads KernelSU as an LKM viaksud late-loadafter the system has already booted. KernelSU'spost-fs-data/servicestages therefore run long afterzygoteis already up. - Install
zygisk_vector(Vector v2.2,3111-efb82883-JingMatrix-Vector) +zygisksu(Zygisk Next1.5.0 (843-5217106-release)). - Because Zygisk Next starts after zygote,
zygiskd statusreportszygote_states:0and no app gets the framework. Restarting zygote once lets ZN inject successfully:
zygote_states:1,modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk - Use the device normally, and/or open the manager:
am start -c org.matrix.vector.manager.LAUNCH_MANAGER com.android.shell/.BugreportWarningActivity
Expected behaviour/预期行为
The daemon stays alive, vector-cli status works, the manager activates, and the framework is injected into scoped apps — on every boot.
Actual behaviour/实际行为
The daemon dies and the framework goes inactive. Observed sequence:
(a) Binder transactions to the daemon are extremely slow (2.3–2.5 s each):
[ 2026-10-04T23:34:47.553 0: 25633: 26451 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2346ms. Data bytes: 172 Reply bytes: 32 Flags: 18
[ 2026-10-04T23:34:47.553 0: 25633: 25943 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2502ms. Data bytes: 188 Reply bytes: 32 Flags: 18
(b) system_server keeps dying and re-injection fails (System Server died occurred 4× in this one log):
[ 2026-10-04T23:33:36.652 0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...
[ 2026-10-04T23:33:42.668 0: 25633: 25633 E/VectorDaemon ] Failed to inject VectorService into system_server
[ 2026-10-04T23:33:42.668 0: 25633: 25633 W/VectorDaemon ] Restarting system_server...
[ 2026-10-04T23:34:30.103 0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...
(c) A freshly started system_server cannot fetch the framework DEX because the daemon is already gone:
[ 2026-10-04T23:25:20.141 1000: 29157: 29157 E/VectorNative ] android.os.DeadObjectException
[ 2026-10-04T23:25:20.141 1000: 29157: 29157 E/VectorNative ] DEX fetch transaction failed.
[ 2026-10-04T23:25:20.141 1000: 29157: 29157 E/VectorNative ] Failed to fetch framework DEX for system_server.
(d) Manager never activates:
W/VectorManager: splash: no daemon binder after 2500ms, continuing unactivated
java.lang.IllegalStateException: Daemon is not active
at org.matrix.vector.manager.ipc.DaemonClient$runIpc$2.invokeSuspend(DaemonClient.kt:39)
/data/adb/lspd/cli status at that point returns Error: Socket Failure: Connection refused, and VectorZygiskBridge GET_BINDER count stays at 0.
(e) The daemon's actual death — /data/tombstones/tombstone_00, verbatim:
Cmdline: vectord
signal 11 (SIGSEGV), code 2 (SEGV_ACCERR), fault addr 0x0000007139b0df60 (write)
Abort message: 'JNI FatalError called: java.lang.Error thrown during binder transaction: (Unknown exception message) (Error was StackOverflowError) (toString() error was StackOverflowError)'
The crashing thread's native stack alternates between exactly two frames, 32 times (kk is an obfuscated class inside daemon.apk):
#27 pc 00000000001ae574 /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+964)
#35 pc 000000000006dcbc [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
#42 pc 00000000001ae258 /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+168)
#50 pc 000000000006dcbc [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
#57 pc 00000000001ae258 /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(...)+168)
#65 pc 000000000006dcbc [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
... (the pair repeats 32× in total; frame count reaches #170+) ...
Counted occurrences in that tombstone: (kk.onTransact+20) 32×, JavaBBinderExt::onTransact 31×. This is unbounded recursion inside the daemon's binder onTransact handler, which overflows the stack and kills the daemon.
(f) Separately, a "fatal coroutine exception" in a background daemon task (drawable load for the status notification). This one goes through a MediaTek resource-cache path:
[ 2026-10-04T23:34:57.667 0: 25633: 25978 E/VectorDaemon ] Caught fatal coroutine exception in background task!
android.content.res.Resources$NotFoundException: Drawable org.matrix.vector.daemon:drawable/ic_statue_monochrome with resource ID #0x7f010000
Caused by: java.lang.NullPointerException: Attempt to invoke virtual method 'boolean java.lang.Object.equals(java.lang.Object)' on a null object reference
at com.mediatek.res.AsyncDrawableCache.putCacheList(AsyncDrawableCache.java:189)
at com.mediatek.res.ResOptExtImpl.putCacheList(ResOptExtImpl.java:69)
at android.content.res.ResourcesImpl.cacheDrawable(ResourcesImpl.java:1069)
at android.content.res.ResourcesImpl.loadDrawable(ResourcesImpl.java:1000)
at android.content.res.MiuiResourcesImpl.loadDrawable(MiuiResourcesImpl.java:334)
at android.content.res.Resources.loadDrawable(Resources.java:1170)
at android.content.res.Resources.getDrawableForDensity(Resources.java:1158)
at android.content.res.Resources.getDrawable(Resources.java:1097)
at hh.d(r8-map-id-94e6fafa64eec1c2091f734c0f848aff0b26c70900661e2a6f4e6038da2c292f:17)
at hh.g(...:54)
at w2.h(...:41)
at w2.f(...:6)
at bk.d(...:8)
at q9.run(...:114)
at xe.run(...:4)
at ok.run(...:3)
at i8.run(...:85)
(g) On every system_server injection:
[ 2026-10-04T23:34:31.474 1000: 9486: 9486 E/LSPlant ] mmap dual mapping failed with 13: Permission denied
module/sepolicy.rule is loaded and already includes allow system_server system_server process execmem and allow zygote zygote process execmem (zygiskd shows these applied).
Relation to existing reports/与已有 issue 的关系
- #939 — same scenario (temporary/tethered root, locked bootloader, KernelSU + Zygisk Next + Vector, daemon dies, framework inactive). That report shows
DeadSystemException; here the daemon dies from aStackOverflowErrorinsideonTransact. Filing separately because the crash signature differs, but it may be the same underlying temporary-root problem you said you are working on. - #904 — identical manager-side symptom (
no daemon binder after 2500ms,Daemon is not active) on Xiaomi HyperOS. - The same
vectordcrash (SIGSEGV +StackOverflowError) also appears in a KernelSU bugreport captured earlier on this device (tombstone_26,tombstone_27), i.e. it reproduces across boots, not just once.
Xposed Module List/Xposed 模块列表
com.github.tianma8023.xposed.smscode 10168 enabled
io.github.a13e300.fusefixer 10100 enabled
me.hd.wauxv 10093 enabled
org.lsposed.corepatch 10417 enabled
org.xiyu.starx 10314 enabled
io.github.bitstandbyyou.bilisb 10115 disabled
Root implementation/Root 方案
Temporary root on a locked-bootloader device: KernelSU 32601 (manager package me.weishu.kernelsu, versionName v3.3.0, ksud 3.3.0, uapi 2), kernel module loaded via ksud late-load from a temporary-root exploit. Zygisk Next reports root_impl:3, root_ver:32601, root_status:✅KernelSU (32601).
System Module List/系统模块列表
zygisksu Zygisk Next 1.5.0 (843-5217106-release) enabled
zygisk_vector Vector v2.2 (3111-efb82883-JingMatrix-Vector) enabled
playintegrityfix v4.7-1-inject-s enabled
tricky_store TEESimulator-RS v6.0.1-307 enabled
hma_oss_zygisk HMA-OSS Zygisk oss-164 enabled
TA_enhanced - enabled
miui_theme_mod v7 enabled
zygisk-storage-isolation v29.0.1 DISABLED
Vector version/Vector 版本
v2.2 (3111-efb82883-JingMatrix-Vector) (versionCode 3111)
Android version/Android 版本
Android 17 (SDK 37), Xiaomi HyperOS 4.0 (OS4.0.0.8.XONCNXM), Redmi 25060RK16C (dali),
fingerprint Redmi/dali/dali:17/CP2A.260605.016/OS4.0.0.8.XONCNXM:user/release-keys,
kernel 6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64, SELinux enforcing.
Version requirement/版本要求
- I am using the latest debug build from GitHub Actions./我正在使用 GitHub Actions 中最新的调试版本。
Logs/日志
All excerpts above are verbatim from the device (no editing of the log lines themselves). Available on request, not pasted in full here:
/data/tombstones/tombstone_00— thevectordSIGSEGV/StackOverflowError tombstone (full, including native stack)/data/adb/lspd/log/verbose_*.log— full verbose log for the boot/data/adb/modules/zygisksu/state +zygiskd statusoutput
zygiskd status on a boot where the daemon later died:
version_local:1.5.0-843-5217106-release
abi:arm64-v8a (primary)
uname:6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64
android_sdk:37
version:1.5.0-843-5217106-release
zygote_states:1
zygote_state_0:1,0,9205,zygote,3
inject_state:1
root_status:✅KernelSU (32601)
enforce_denylist:2
memory_type:1
linker:1
hook_mode:1
root_impl:3
root_ver:32601
modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk
modules32:0
modules_with_issue:0
- Lenguaje dominante
- Kotlin
- Estrellas
- 12.6k
- Forks
- 850
- Merge medio
- 20 min
- PR fusionados (30 d)
- 1
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de JingMatrix/Vector
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 80/100
JingMatrix/Vector#999 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
JingMatrix/Vector#1000 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 42/100
JingMatrix/Vector#997 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Modules not visibleAbiertobug
Dificultad 3/5 1-2 días Aptitud para principiantes 52/100
JingMatrix/Vector#991 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
JingMatrix/Vector#990 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de JingMatrix/Vector
Issues similares
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
MetrolistGroup/Metrolist#4435 ·
Los mantenedores suelen responder en 1 día
-
feat: 工作区文件菜单增加「复制文件路径」选项Abiertoenhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
good first issue help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
bug 🐞 Untriaged user issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
valkey-io/valkey-glide#7306 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
Bookmarking an article that is already bookmarked under its redirect URL deletes both bookmarksPosiblemente ocupada @aakarshitv la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
kiwix/kiwix-android#5176 ·
Los mantenedores suelen responder en 1 día