Skip to content

BinderInvocationProxy · Binder 注入器 ​

BinderInvocationProxy 继承 MethodInvocationProxy<BinderInvocationStub>,是 45 个服务代理注入器的实际基类。它专门负责「替换 ServiceManager 缓存里的真 binder」这一步。

构造 ​

四种构造方式,按拿到原接口的途径选:

构造入参场景
(IInterface stub, String serviceName)已有接口直接包装
(RefStaticMethod asInterfaceMethod, String serviceName)mirror 反射的 asInterface跨版本取接口
(Class<?> stubClass, String serviceName)Stub 类反射 asInterface
(BinderInvocationStub hookDelegate, String serviceName)已构造的 stub复用 stub

serviceName 决定要替换 ServiceManager.sCache 的哪个槽位(如 "activity"、"package")。

inject() ​

java
public void inject() throws Throwable {
    // 把 BinderInvocationStub 写进 ServiceManager.sCache[serviceName]
    getInvocationStub().replaceService(serviceName);
}

inject() 是 IInjector 的实现,触发 BinderInvocationStub.replaceService 完成替换。此后系统服务的 binder 句柄就是假的。

binder 注入与替换 ​

isEnvBad() ​

java
public boolean isEnvBad();

检查运行环境是否就绪(原 binder 是否能取到)。若环境异常,InvocationStubManager 会跳过本注入器,避免崩溃。

关联 ​

基于 VirtualApp 与 epic,仅供学习研究。VirtualApp 禁止商用。