Repository navigation
[OneUI] Native crashes of background applications during art::Thread::Attach #127
Description
Activity
Could you try this CI version by me?Since I can't simulate your device environment, it may still be like this
Could you try this CI version by me?
Hello! Thanks for your assistance. I have installed your fork, the device has booted properly. I will keep you updated.
One of the changes I have noticed, is that I'm once again able to launch the parasitic manager, because previously on the latest Nightly build LSPosed-v1.10.1-7159-zygisk-debug I was having this error:⚠️ java.io.IOException: apk signature not verified2024-12-16 15:20:15.136 7246 26439 root E LSPosedService : failed to open manager apk java.io.IOException: java.io.IOException: apk signature not verified at org.lsposed.lspd.util.InstallerVerifier.verifyInstallerSignature(InstallerVerifier.java:28) at org.lsposed.lspd.service.ConfigFileManager.getManagerApk(ConfigFileManager.java:162) at org.lsposed.lspd.service.ConfigManager.getManagerApk(ConfigManager.java:1078) at org.lsposed.lspd.service.LSPApplicationService.requestInjectedManagerBinder(LSPApplicationService.java:157) at org.lsposed.lspd.service.ILSPApplicationService$Stub.onTransact(ILSPApplicationService.java:110) at org.lsposed.lspd.service.LSPApplicationService.onTransact(LSPApplicationService.java:107) at android.os.Binder.execTransactInternal(Unknown Source:94) at android.os.Binder.execTransact(Unknown Source:39) Caused by: java.io.IOException: apk signature not verified at org.lsposed.lspd.util.InstallerVerifier.verifyInstallerSignature(InstallerVerifier.java:20) ... 7 more
Reacted by JingMatrix@JingMatrix Are you set the apk signature into the github secrets?
Action "Write key" need this- name: Write key if: ${{ ( github.event_name != 'pull_request' && github.ref == 'refs/heads/master' ) || github.ref_type == 'tag' }} run: | if [ ! -z "${{ secrets.KEY_STORE }}" ]; then echo androidStorePassword='${{ secrets.KEY_STORE_PASSWORD }}' >> gradle.properties echo androidKeyAlias='${{ secrets.ALIAS }}' >> gradle.properties echo androidKeyPassword='${{ secrets.KEY_PASSWORD }}' >> gradle.properties echo androidStoreFile='key.jks' >> gradle.properties echo ${{ secrets.KEY_STORE }} | base64 --decode > key.jks fiReacted by JingMatrix and bushman74Ah, I didn't. I should have done that, thanks for reminding me of it!
The latest CI debug build is causing the following problem according to user's report:
2025-01-09 22:23:21.103 30264 30264 root V zygisk-core64: module.cpp:364#void ZygiskContext::nativeSpecializeAppProcess_pre(): pre specialize [org.lsposed.manager] 2025-01-09 22:23:21.104 7477 7673 system I ActivityManager: Start proc 30264:org.lsposed.manager/2000 for top-activity {com.android.shell/com.android.shell.BugreportWarningActivity} 2025-01-09 22:23:21.106 30264 30264 com.android.shell E SELinux: seapp_context_lookup_internal: No match for app with uid 2000, seinfo platform, name org.lsposed.manager username shell appid 2000 2025-01-09 22:23:21.107 30264 30264 com.android.shell F zygote64: jni_internal.cc:828] JNI FatalError called: (org.lsposed.manager) frameworks/base/core/jni/com_android_internal_os_Zygote.cpp:2011: selinux_android_setcontext(2000, 0, "platform:privapp:targetSdkVersion=34:complete", "org.lsposed.manager") failed 2025-01-09 22:23:21.330 30267 30267 com.android.shell F DEBUG: Abort message: 'JNI FatalError called: (org.lsposed.manager) frameworks/base/core/jni/com_android_internal_os_Zygote.cpp:2011: selinux_android_setcontext(2000, 0, "platform:privapp:targetSdkVersion=34:complete", "org.lsposed.manager") failed' 2025-01-09 22:23:21.369 7477 30272 system I LSPosed-Bridge: [AppErrorsTracking][I][android] Received crash application data --pid 30264 2025-01-09 22:23:24.827 7477 7657 system V ActivityManager: Skipped removedTask org.lsposed.manager 2025-01-09 22:23:25.277 7477 7942 system D LSPosed: LoadedApk#<init> starts: pkg=null, prc=null 2025-01-09 22:23:25.277 7477 7942 system D LSPosed: LoadedApk#<init> ends: /data/app/~~QXKpbCMclD8VVdGSIqkqsw==/it.octogramx.android-JzUCbhF9Yjt8HaO6QogJgA==/base.apk: pkg=null, prc=null 2025-01-09 22:23:25.827 7477 30482 system I LSPosed-Bridge: [AppErrorsTracking][I][android] Received crash application data --pid 30425 2025-01-09 22:23:31.103 7477 7672 system W ActivityManager: Process ProcessRecord{55520e5 30264:org.lsposed.manager/2000} failed to attach 2025-01-09 22:23:32.103 7477 7672 system W ActivityManager: Spurious death for ProcessRecord{55520e5 30264:org.lsposed.manager/2000}, curProc for 30264: nullIt seems that the system server is not hooked correctly. The crash happens at selinux_android_setcontext.
- changed the title
[-][OneUI] [Exynos] Native crashes[/-][+][OneUI] Native crashes[/+]on Jan 12, 2025 ⚠️ Caution! Significant changes have been made to the head content of the issue ticket! Restudy of the content is required by the observers and participants!
Regards- addedquestionFurther information is requestedFurther information is requestedcannot reproduceThe issue may be invalidThe issue may be invalidand removedbugSomething isn't workingSomething isn't working
on Jan 13, 2025 No worries, I will keep this issue open. We should first classify the crashes since there are many different types of native crashes. And it could happen that a special crash is causing all the rest.
Reacted by bushman74- Occurs with 🔴 LSP disabled & 🔴 Zygisk disabled.
Speaking about this item: it still requires total confirmation. I think I might not just be able to reproduce in a Zygisk-less environment, but I might try asking other people + initiate an experiment myself.
Please, consider that some information might still be changed. It's a very complicated issue, and it's very time-consuming. Pardon all inaccurate information, but for the most part of it the content is largely beyond refutation or dispute.
New logs updated:
tombstones.zipSince only three app crashed, I believe this is a problem of those apps probably.
Since only three app crashed, I believe this is a problem of those apps probably.
This information has been refuted upon internal testing — there's no connection between applications crashing. They are random.
- Occurs with 🔴 LSP disabled & 🟢 Zygisk enabled.
- Occurs with 🔴 LSP disabled & 🔴 Zygisk disabled.
Information has been confirmed: the issue is not reproducible without Zygisk enabled; Zygisk has been defined as the core issue.
The crash happens at tracing of Runtime::AttachCurrentThread.
The assembly codes are┌ 1360: sym.art::Runtime::AttachCurrentThread_char_const__bool___jobject__bool__bool_ (int64_t arg1, int64_t arg2, int64_t arg3, int64_t arg4, int64_t arg5, int64_t arg6, int64_t arg_a0h); │ `- args(x0, x1, x2, x3, x4, x5, sp[0xa0..0xa0]) vars(20:sp[0x8..0x9c]) ; art::Runtime::AttachCurrentThread(char const*, bool, _jobject*, bool ; , bool) │ 0x00676030 ff8302d1 sub sp, sp, 0xa0 │ 0x00676034 fd7b05a9 stp x29, x30, [var_50h] │ 0x00676038 f93300f9 str x25, [var_60h] │ 0x0067603c f85f07a9 stp x24, x23, [var_70h] │ 0x00676040 f65708a9 stp x22, x21, [var_80h] │ 0x00676044 f44f09a9 stp x20, x19, [var_90h] │ 0x00676048 fd430191 add x29, sp, 0x50 │ 0x0067604c 59d03bd5 mrs x25, tpidr_el0 │ 0x00676050 f50300aa mov x21, x0 ; arg1 │ 0x00676054 40cfffd0 adrp x0, case.0x9426bc.0 ; case.0x9426bc.0 │ ; 0x60000 │ 0x00676058 00200991 add x0, x0, 0x248 ; 0x60248 ; "AttachCurrentThread" │ 0x0067605c 281740f9 ldr x8, [x25, 0x28] │ 0x00676060 f303052a mov w19, w5 ; arg6 │ 0x00676064 f603042a mov w22, w4 ; arg5 │ 0x00676068 f40303aa mov x20, x3 ; arg4 │ 0x0067606c f703022a mov w23, w2 ; arg3 │ 0x00676070 f80301aa mov x24, x1 ; arg2 │ 0x00676074 a8831ff8 stur x8, [x29, -8] │ 0x00676078 92040d94 bl sym.imp.PaletteTraceBeginand
┌ 16: sym.imp.PaletteTraceBegin (); │ 0x009b72c0 500300f0 adrp x16, 0xa22000 │ 0x009b72c4 11a642f9 ldr x17, [x16, 0x548] ; [0x9b6aa0:4]=0xa9bf7bf0 ; section..plt │ [16] -r-x section size 21952 named .plt │ 0x009b72c8 10221591 add x16, x16, 0x548 └ 0x009b72cc 20021fd6 br x17Reacted by bushman74The crash happen at
0x009b72c0with op code adrp.
According to the log,x16is0000007c9a335300, located at/apex/com.android.art/lib64/libsigchain.so.New tombstones: Tombstones_2.zip 📦
- changed the title
[-][OneUI] Native crashes[/-][+][OneUI] Native crashes of background applications during `art::Thread::Attach`[/+]on Jan 22, 2025 - Repository owner locked and limited conversation to collaborators
on Jan 22, 2025
General information:
Android version:
14OEM:
OneUI 6.1Model name:
SM-G988BCodename:
z3sRoot solution:
KernelSU NEXT v12200Zygisk solution:
ReZygiskKernel (non-GKI):
4.19.87-VulcanKernel-v3ᅠ ᅠ
Brief description
On Samsung Galaxy with OneUI (includes both Exynos and Snapdragon variants) applications suffer from systematic and chaotic/unpredictable native crashes. Occurs only in the background, but in seldom situations might happen during the launching.
⚠️ P.S. It now includes Snapdragon Samsung devices! Hence all Samsung devices seem to have been affected! PLEASE, STUDY THE ISSUE ONCE AGAIN, SIGNIFICANT CHANGES HAVE BEEN MADE! 🚨
ᅠ ᅠ
Important notes
ᅠ ᅠ
ᅠ ᅠ
Misc information
It's been happening for approximately 2 years. And it's not anyhow related to the ROM, or any specific root solution, or any specific Zygisk implementation.
It's impossible to manually reproduce the issue, because it only happens by itself and about 14 times a day.
In addition, @DanGLES3 said that, basically, ART libraries are now identical disregard of the OEM due to introduction of universal Google Play System Update APEX distribution.
Example of the described crash
🐞 Native crash: d.app.dressroom
1 — ported from S22.
2 — no relevance between injection of a particular app and crashes frequency has been found. In fact, the vast majority of apps crashes are non-injected ones.
3 — yes, I have to admit that it can crash during the launching or when running an application, but this happens basically in 0,00001% of situations.
Upon a deeper investigation, it's been revealed that the issue, in fact, is not related to LSPosed! (Maybe LSPosed provokes more frequent occurrences [in the worst case scenario], but is not the core issue per se).
In addition, my partner @ExtremeXT has discovered that not only Exynos 990, and not only Exynos devices in general are affected! This now includes even Snapdragon devices.
Here is an instance from another repository, exemplifying that this happens on a stock based ROM on S24 Ultra (
SM-G980B):🐞 Native crash: com.samsung.android.app.routines