Skip to content

BinderInvocationStub · 假 IBinder ​

BinderInvocationStub 继承 MethodInvocationStub<IInterface> 并实现 IBinder。它是一个假的 IBinder——queryLocalInterface 返回带满 MethodProxy 的动态代理,从而让 ServiceManager.getService(name) 拿到的就是这个假 binder。45 个服务代理替换 ServiceManager.sCache 的物理基础就是它。

与父类的区别 ​

MethodInvocationStub 包的是「接口调用」;BinderInvocationStub 多包了一层「binder 句柄」:

层谁负责干什么
IBinderBinderInvocationStub实现 transact/queryLocalInterface,伪装成真 binder
IInterface父类 MethodInvocationStub动态代理按方法名分发到 MethodProxy

构造方式 ​

构造用途
BinderInvocationStub(RefStaticMethod asInterfaceMethod, IBinder binder)用 mirror 反射的 asInterface 把原 binder 转接口
BinderInvocationStub(Class<?> stubClass, IBinder binder)用 StubClass.asInterface 反射转换
BinderInvocationStub(IInterface mBaseInterface)已有接口直接包

replaceService ​

java
public void replaceService(String name)

把自己写进 ServiceManager.sCache[name](或对应版本的缓存字段),此后所有 Context.getSystemService / ServiceManager.getService 拿到的都是这个假 binder。这是整个 hook 注入的「临门一脚」。

内嵌 AsBinder ​

AsBinder 是内部 MethodProxy,hook 的是 asBinder() 方法——当 App 通过接口取底层 binder 时,返回 BinderInvocationStub 自己,保持闭环。

binder 替换闭环 ​

关联 ​

基于 VirtualApp 与 epic,仅供学习研究。VirtualApp 禁止商用。