Skip to content

iOS 14.5 crashed #82

Description

@cfxiao
0 perform_rebinding_with_section(fishhook.c:137)
1 perform_rebinding_with_section(fishhook.c:131)
2 rebind_symbols_for_image(fishhook.c:208)
3 rebind_symbols(fishhook.c:252)

iOS 14.5 crashed when hook GCD.

Activity

  1. cfxiao commented on Feb 3, 2021

    @cfxiao
    Author

    image

  2. cfxiao commented on Feb 3, 2021

    @cfxiao
    Author

    Hook fsync also crashes.

  3. feikang commented on Feb 3, 2021

    @feikang

    have the same problem. I can reproduce the crash with iPhone Xs and OS version 14.5(18E5140j) beta. but iPhone 7 can't reproduce it.

  4. leirenbaobao commented on Feb 4, 2021

    @leirenbaobao

    @cfxiao can you supply detail codes? which func been hooked?

  5. biosli commented on Feb 4, 2021

    @biosli

    @leirenbaobao it seems that he hook the dispatch_sync.
    And I try to hook malloc / realloc get same crash report.

    I'm pretty sure the iOS 14.5 beta at newer phones such as iPhoneXs, has change the memory offset of core library.

  6. leirenbaobao commented on Feb 7, 2021

    @leirenbaobao

    @biosli I tested some funcs. some crashes. what puzzle me is that even offset changed normal dynamic binding still work without hook.maybe it's nothing to do with offset.

  7. leirenbaobao commented on Feb 8, 2021

    @leirenbaobao
  8. maniackk commented on Feb 28, 2021

    @maniackk

    I found some case that vm_protect return KERN_SUCCESS , but memory don't set VM_PROT_WRITE success. like mprotect method

    oldProtection = get_protection(rebindings); is wrong, It save struct rebindings_entry *rebindings memory protection. We should save section protection.

    I commit code that oldProtection = get_protection((void *)trunc_address);.

    and I found a problem when program set same section protection in multithread(iOS 14.5).

    https://github.com/facebook/fishhook/pull/84/files

  9. maniackk commented on Mar 4, 2021

    @maniackk

    @leirenbaobao it seems that he hook the dispatch_sync.
    And I try to hook malloc / realloc get same crash report.

    I'm pretty sure the iOS 14.5 beta at newer phones such as iPhoneXs, has change the memory offset of core library.

    #84 fix bug

  10. daybreak1024 commented on Apr 29, 2021

    @daybreak1024

    When will the crash be fixed?

    I used #84 code and it worked.But it's not merged into the main branch,so can I use it?

  11. maniackk commented on Apr 29, 2021

    @maniackk

    When will the crash be fixed?

    I used #84 code and it worked.But it's not merged into the main branch,so can I use it?

    you can use it !

    crash reason:

    1. int mprotect(void *address, size_t size, int protect); function Require address alignment at all iOS version(Not only iOS 14.5). apple doc
    2. The memory mapped to the __DATA_CONST section is readable and writable before iOS 14.5; but in iOS 14.5 maybe readwrite,maybe readonly。
  12. d6638219 commented on Jun 9, 2021

    @d6638219

    iOS15 crash

  13. kaspesla commented on Jun 9, 2021

    @kaspesla

    Thanks for the fix!! In case anyone else is using fishhook on the Mac, you will need this fix for macOS 12.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions