Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug] Temporary-root (locked BL, KernelSU LKM late-load) on Android 17 / HyperOS 4: VectorDaemon dies with StackOverflowError (kk.onTransact recursion 32×) → framework never activates

オープン
#996 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
android, kotlin
領域
backend

調査の方向性

Start by examining /data/tombstones/tombstone_00 and the repeated kk.onTransact / JavaBBinderExt::onTransact frames, then compare with the verbose boot logs and the related reports #939 and #904. The report identifies a daemon Binder recursion ending in StackOverflowError; done means the daemon stays alive, vector-cli status works, and the framework activates on the described setup.

索引モデルが issue の本文から書いたものです。

説明

Steps to reproduce/复现步骤
  1. Device: Redmi 25060RK16C (dali), Xiaomi HyperOS 4.0 / Android 17 (SDK 37). Bootloader is locked, so root is obtained with a temporary-root exploit that loads KernelSU as an LKM via ksud late-load after the system has already booted. KernelSU's post-fs-data / service stages therefore run long after zygote is already up.
  2. Install zygisk_vector (Vector v2.2, 3111-efb82883-JingMatrix-Vector) + zygisksu (Zygisk Next 1.5.0 (843-5217106-release)).
  3. Because Zygisk Next starts after zygote, zygiskd status reports zygote_states:0 and no app gets the framework. Restarting zygote once lets ZN inject successfully:
    zygote_states:1, modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk
  4. Use the device normally, and/or open the manager:
    am start -c org.matrix.vector.manager.LAUNCH_MANAGER com.android.shell/.BugreportWarningActivity
Expected behaviour/预期行为

The daemon stays alive, vector-cli status works, the manager activates, and the framework is injected into scoped apps — on every boot.

Actual behaviour/实际行为

The daemon dies and the framework goes inactive. Observed sequence:

(a) Binder transactions to the daemon are extremely slow (2.3–2.5 s each):

[ 2026-10-04T23:34:47.553     0: 25633: 26451 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2346ms. Data bytes: 172 Reply bytes: 32 Flags: 18
[ 2026-10-04T23:34:47.553     0: 25633: 25943 W/libbinder.Binder ] Binder transaction to org.matrix.vector.ipc.IVectorDaemon, function: UNKNOWN_FUNCTION_NAME, code: 1, took 2502ms. Data bytes: 188 Reply bytes: 32 Flags: 18

(b) system_server keeps dying and re-injection fails (System Server died occurred 4× in this one log):

[ 2026-10-04T23:33:36.652     0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...
[ 2026-10-04T23:33:42.668     0: 25633: 25633 E/VectorDaemon ] Failed to inject VectorService into system_server
[ 2026-10-04T23:33:42.668     0: 25633: 25633 W/VectorDaemon ] Restarting system_server...
[ 2026-10-04T23:34:30.103     0: 25633: 26451 W/VectorDaemon ] System Server died! Clearing caches and re-injecting...

(c) A freshly started system_server cannot fetch the framework DEX because the daemon is already gone:

[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] android.os.DeadObjectException
[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] DEX fetch transaction failed.
[ 2026-10-04T23:25:20.141  1000: 29157: 29157 E/VectorNative ] Failed to fetch framework DEX for system_server.

(d) Manager never activates:

W/VectorManager: splash: no daemon binder after 2500ms, continuing unactivated
java.lang.IllegalStateException: Daemon is not active
	at org.matrix.vector.manager.ipc.DaemonClient$runIpc$2.invokeSuspend(DaemonClient.kt:39)

/data/adb/lspd/cli status at that point returns Error: Socket Failure: Connection refused, and VectorZygiskBridge GET_BINDER count stays at 0.

(e) The daemon's actual death — /data/tombstones/tombstone_00, verbatim:

Cmdline: vectord
signal 11 (SIGSEGV), code 2 (SEGV_ACCERR), fault addr 0x0000007139b0df60 (write)
Abort message: 'JNI FatalError called: java.lang.Error thrown during binder transaction: (Unknown exception message) (Error was StackOverflowError) (toString() error was StackOverflowError)'

The crashing thread's native stack alternates between exactly two frames, 32 times (kk is an obfuscated class inside daemon.apk):

      #27 pc 00000000001ae574  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+964)
      #35 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      #42 pc 00000000001ae258  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(unsigned int, android::Parcel const&, android::Parcel*, unsigned int)+168)
      #50 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      #57 pc 00000000001ae258  /system/lib64/libandroid_runtime.so (JavaBBinderExt::onTransact(...)+168)
      #65 pc 000000000006dcbc  [anon:dalvik-classes.dex extracte...y from /data/adb/modules/zygisk_vector/daemon.apk] (kk.onTransact+20)
      ... (the pair repeats 32× in total; frame count reaches #170+) ...

Counted occurrences in that tombstone: (kk.onTransact+20) 32×, JavaBBinderExt::onTransact 31×. This is unbounded recursion inside the daemon's binder onTransact handler, which overflows the stack and kills the daemon.

(f) Separately, a "fatal coroutine exception" in a background daemon task (drawable load for the status notification). This one goes through a MediaTek resource-cache path:

[ 2026-10-04T23:34:57.667     0: 25633: 25978 E/VectorDaemon ] Caught fatal coroutine exception in background task!
android.content.res.Resources$NotFoundException: Drawable org.matrix.vector.daemon:drawable/ic_statue_monochrome with resource ID #0x7f010000
Caused by: java.lang.NullPointerException: Attempt to invoke virtual method 'boolean java.lang.Object.equals(java.lang.Object)' on a null object reference
	at com.mediatek.res.AsyncDrawableCache.putCacheList(AsyncDrawableCache.java:189)
	at com.mediatek.res.ResOptExtImpl.putCacheList(ResOptExtImpl.java:69)
	at android.content.res.ResourcesImpl.cacheDrawable(ResourcesImpl.java:1069)
	at android.content.res.ResourcesImpl.loadDrawable(ResourcesImpl.java:1000)
	at android.content.res.MiuiResourcesImpl.loadDrawable(MiuiResourcesImpl.java:334)
	at android.content.res.Resources.loadDrawable(Resources.java:1170)
	at android.content.res.Resources.getDrawableForDensity(Resources.java:1158)
	at android.content.res.Resources.getDrawable(Resources.java:1097)
	at hh.d(r8-map-id-94e6fafa64eec1c2091f734c0f848aff0b26c70900661e2a6f4e6038da2c292f:17)
	at hh.g(...:54)
	at w2.h(...:41)
	at w2.f(...:6)
	at bk.d(...:8)
	at q9.run(...:114)
	at xe.run(...:4)
	at ok.run(...:3)
	at i8.run(...:85)

(g) On every system_server injection:

[ 2026-10-04T23:34:31.474  1000:  9486:  9486 E/LSPlant ] mmap dual mapping failed with 13: Permission denied

module/sepolicy.rule is loaded and already includes allow system_server system_server process execmem and allow zygote zygote process execmem (zygiskd shows these applied).

Relation to existing reports/与已有 issue 的关系
  • #939 — same scenario (temporary/tethered root, locked bootloader, KernelSU + Zygisk Next + Vector, daemon dies, framework inactive). That report shows DeadSystemException; here the daemon dies from a StackOverflowError inside onTransact. Filing separately because the crash signature differs, but it may be the same underlying temporary-root problem you said you are working on.
  • #904 — identical manager-side symptom (no daemon binder after 2500ms, Daemon is not active) on Xiaomi HyperOS.
  • The same vectord crash (SIGSEGV + StackOverflowError) also appears in a KernelSU bugreport captured earlier on this device (tombstone_26, tombstone_27), i.e. it reproduces across boots, not just once.
Xposed Module List/Xposed 模块列表
com.github.tianma8023.xposed.smscode  10168  enabled
io.github.a13e300.fusefixer           10100  enabled
me.hd.wauxv                           10093  enabled
org.lsposed.corepatch                 10417  enabled
org.xiyu.starx                        10314  enabled
io.github.bitstandbyyou.bilisb        10115  disabled
Root implementation/Root 方案

Temporary root on a locked-bootloader device: KernelSU 32601 (manager package me.weishu.kernelsu, versionName v3.3.0, ksud 3.3.0, uapi 2), kernel module loaded via ksud late-load from a temporary-root exploit. Zygisk Next reports root_impl:3, root_ver:32601, root_status:✅KernelSU (32601).

System Module List/系统模块列表
zygisksu                    Zygisk Next 1.5.0 (843-5217106-release)      enabled
zygisk_vector               Vector v2.2 (3111-efb82883-JingMatrix-Vector) enabled
playintegrityfix            v4.7-1-inject-s                             enabled
tricky_store                TEESimulator-RS v6.0.1-307                  enabled
hma_oss_zygisk              HMA-OSS Zygisk oss-164                      enabled
TA_enhanced                 -                                           enabled
miui_theme_mod              v7                                          enabled
zygisk-storage-isolation    v29.0.1                                     DISABLED
Vector version/Vector 版本

v2.2 (3111-efb82883-JingMatrix-Vector) (versionCode 3111)

Android version/Android 版本

Android 17 (SDK 37), Xiaomi HyperOS 4.0 (OS4.0.0.8.XONCNXM), Redmi 25060RK16C (dali),
fingerprint Redmi/dali/dali:17/CP2A.260605.016/OS4.0.0.8.XONCNXM:user/release-keys,
kernel 6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64, SELinux enforcing.

Version requirement/版本要求
Logs/日志

All excerpts above are verbatim from the device (no editing of the log lines themselves). Available on request, not pasted in full here:

  • /data/tombstones/tombstone_00 — the vectord SIGSEGV/StackOverflowError tombstone (full, including native stack)
  • /data/adb/lspd/log/verbose_*.log — full verbose log for the boot
  • /data/adb/modules/zygisksu/ state + zygiskd status output

zygiskd status on a boot where the daemon later died:

version_local:1.5.0-843-5217106-release
abi:arm64-v8a (primary)
uname:6.6.118-android15-8-gb9cc6ec16bc8-abogki536571621-4k aarch64
android_sdk:37
version:1.5.0-843-5217106-release
zygote_states:1
zygote_state_0:1,0,9205,zygote,3
inject_state:1
root_status:✅KernelSU (32601)
enforce_denylist:2
memory_type:1
linker:1
hook_mode:1
root_impl:3
root_ver:32601
modules64:3,zygisk_vector,playintegrityfix,hma_oss_zygisk
modules32:0
modules_with_issue:0
主要言語
Kotlin
スター
12.6k
フォーク
850
平均マージ
20分
マージ済み PR(30日)
1

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

JingMatrix/Vector のほかの issue

JingMatrix/Vector の issue をすべて見る

似ている issue

Kotlin の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。