Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Method with argument of type array of array cannot be instrumented

Aperta
#313 2 commenti 1 reazione 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
java, javascript
Ambito
devtools

Direzione di ricerca

Inizia in lib/types.js, nella zona di getArrayType(), quindi riproduci il problema con il metodo fornito TestA.array_of_array(byte[][]) e overload('[[B'). Verifica come viene convertito il nome del tipo array prima di factory.use() e del casting. Il lavoro è completato quando l’instrumentazione riesce senza ClassNotFoundException e il metodo può essere invocato tramite Java bridge.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Hello,
I run into a problem while trying to instrument methods that take an array of array of byte as argument. For exemple:

package com.example.testclassloader;

public class TestA {
    public static int array_of_array(byte[][] arrays) {
        int size = 0;
        for (byte[] arr: arrays) {
            size += arr.length;
        }
        return size;
    }
}
[Android Emulator 5554::TestClassLoader ]-> Java.performNow(() => { })
[Android Emulator 5554::TestClassLoader ]-> TestA =  Java.use("com.example.testclassloader.TestA")
"<class: com.example.testclassloader.TestA>"
[Android Emulator 5554::TestClassLoader ]-> method = TestA.array_of_array
function
[Android Emulator 5554::TestClassLoader ]-> method.argumentTypes
[
    {
        "className": "[[B",
        "defaultValue": "0x0",
        "name": "[[B",
        "size": 1,
        "type": "pointer"
    }
]
[Android Emulator 5554::TestClassLoader ]-> method.overload('[[B').implementation = function(arrays) { s =
 method(arrays); console.log(s); return s; };
function

# after triggering the method in the app:

[Android Emulator 5554::TestClassLoader ]-> Process crashed: java.lang.ClassNotFoundException: Didn't find class "[L[B;" on path: DexPathList[[dex file "/data/data/com.example.testclassloader/code_cache/.overlay/base.apk/classes3.dex", zip file "/data/app/~~NRqmDlxjA4t3ccEvxe4Qlw==/com.example.testclassloader-JhUO40ypsrxE2AIa8f1k4A==/base.apk"],nativeLibraryDirectories=[/data/app/~~NRqmDlxjA4t3ccEvxe4Qlw==/com.example.testclassloader-JhUO40ypsrxE2AIa8f1k4A==/lib/x86_64, /system/lib64, /system_ext/lib64]]

I believe the issue comes from here: https://github.com/frida/frida-java-bridge/blob/1e23abb71fd26726d59627e4da3ad8e10ba849aa/lib/types.js#L480

I think something like this could be a rough solution, but I did not manage to get frida to use patched version of frida-java-bridge:

diff --git a/lib/types.js b/lib/types.js
index 6a0f977..9b8d91f 100644
--- a/lib/types.js
+++ b/lib/types.js
@@ -477,7 +477,13 @@ function getArrayType (typeName, unbox, factory) {
       }

       // The type name we get is not always the correct representation of the type so we make it so here.
-      const internalTypeName = '[L' + elementTypeName.replace(/\./g, '/') + ';';
+      let internalElementTypeName = '';
+      if (elementTypeName.replace[0] === '[') {
+        internalElementTypeName = elementTypeName.replace(/\./g, '/');
+      } else {
+        internalElementTypeName = 'L' + elementTypeName.replace(/\./g, '/') + ';';
+      }
+      const internalTypeName = '[' + internalElementTypeName;
       try {
         result.$w = factory.cast(arr, factory.use(internalTypeName), owned);
       } catch (e) {

PS: Is there some documentation for running a patched java-bridge? I tried https://github.com/frida/frida-tools?tab=readme-ov-file#loading-your-custom-frida-java-bridge and failled

Lingua principale
JavaScript
Stelle
413
Fork
173
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di frida/frida-java-bridge

Tutte le issue di frida/frida-java-bridge

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.