Commit Graph
294 Commits
Author SHA1 Message Date
Tim PerryandGitHub de989d79c2 Merge pull request #238 from httptoolkit/dependabot/npm_and_yarn/test/android/proxy-addr-2.0.8
Bump proxy-addr from 2.0.7 to 2.0.8 in /test/android
2026-10-09 09:40:34 +02:00
dependabot[bot]andGitHub babcb6c339 Bump proxy-addr from 2.0.7 to 2.0.8 in /test/android
Bumps [proxy-addr](https://github.com/jshttp/proxy-addr) from 2.0.7 to 2.0.8.
- [Release notes](https://github.com/jshttp/proxy-addr/releases)
- [Changelog](https://github.com/jshttp/proxy-addr/blob/master/HISTORY.md)
- [Commits](https://github.com/jshttp/proxy-addr/compare/v2.0.7...v2.0.8)

---
updated-dependencies:
- dependency-name: proxy-addr
  dependency-version: 2.0.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-10-08 14:32:10 +00:00
Tim PerryandGitHub 3cfda1657a Merge pull request #237 from httptoolkit/dependabot/npm_and_yarn/test/native/serialize-javascript-7.1.2
Bump serialize-javascript from 7.1.1 to 7.1.2 in /test/native
2026-10-08 16:30:55 +02:00
dependabot[bot]andGitHub adce7f3842 Bump serialize-javascript from 7.1.1 to 7.1.2 in /test/native
Bumps [serialize-javascript](https://github.com/yahoo/serialize-javascript) from 7.1.1 to 7.1.2.
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](https://github.com/yahoo/serialize-javascript/compare/v7.1.1...v7.1.2)

---
updated-dependencies:
- dependency-name: serialize-javascript
  dependency-version: 7.1.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-10-08 13:29:49 +00:00
Tim PerryandGitHub b3ea8f63a1 Merge pull request #234 from az-xx/cronet-pinning-bypass
Handle Cronet by re-enabling pinning bypass for local trust anchors
2026-09-18 14:14:26 +02:00
az-xx 939a5963cd Handle Cronet by re-enabling pinning bypass for local trust anchors
Cronet (Chromium's network stack, used by many Google apps, gRPC and
other SDKs) runs TLS in native code and ignores the JVM proxy, OkHttp
and TrustManager layers, so none of the existing unpinning hooks affect
it. It trusts locally-installed CAs by default, but only while
public-key-pinning bypass for local trust anchors is left enabled, which
an app can turn off with a single CronetEngine.Builder call.

Hook enablePublicKeyPinningBypassForLocalTrustAnchors to always pass
true, so our injected CA is accepted while pinning stays intact for
connections chaining to a real (non-local) trust anchor - matching the
"disable only the extra restrictions" approach the other hooks take.
2026-09-18 13:44:25 +02:00
Tim PerryandGitHub 330b00d675 Merge pull request #235 from az-xx/fix/ipv6-connect-hook-logging
Format real IPv6 addresses correctly in connect-hook debug logs
2026-09-18 13:27:42 +02:00
az-xx c2c1d58dc4 Format real IPv6 addresses correctly in connect-hook debug logs
getReadableAddress() formatted real (non-IPv4-mapped) IPv6 destinations
by mapping each of the 16 address bytes to hex and joining them with ':'.
That produces 16 single-byte groups with per-byte leading zeros stripped,
so e.g. 2001:db8::1 was logged as '[20:1:d:b8:0:0:0:0:0:0:0:0:0:0:0:1]'.

Group the bytes into the 8 standard hextets instead, and collapse the
longest run of zero hextets to '::' (RFC 5952), so the same address now
logs as '[2001:db8::1]'. IPv4 and IPv4-mapped formatting are unchanged.

This only affects DEBUG_MODE output, but readable addresses are the whole
point of getReadableAddress when checking which connections are being
intercepted or blocked.
2026-09-18 07:12:23 +02:00
Tim Perry a277db78b7 Try to improve test checks & timeouts 2026-09-09 16:20:40 +02:00
Tim Perry 91da7f3d77 Drop the SOCKS timeout (per op, not per handshake) 2026-09-09 14:45:53 +02:00
Tim Perry b78026662c Add API 36 to CI and tighten script checks in tests 2026-09-09 14:27:52 +02:00
Tim Perry ccb1746ec7 Apply Android proxy overrides independently to improve resilience 2026-09-09 14:26:19 +02:00
Tim Perry fd395cb11f Improve accuracy & resilient in root detectin patches 2026-09-09 14:13:49 +02:00
Tim Perry 560cf161b4 Improve Android certificate transparency hook approach for Android 17 2026-09-09 13:02:18 +02:00
Tim Perry bfec937be0 Update test framework deps to fix irrelevant vuln warnings 2026-09-08 18:31:20 +02:00
Tim PerryandGitHub bc909326da Merge pull request #231 from xax/patch-1
Add overload for `checkServerTrusted` method in *Appmattus* hooks
2026-09-08 18:30:42 +02:00
Tim Perry 31946e9999 Set up a native testing harness for low-level network testing
Primarily relevant for SOCKS, but probably more generally in future.
2026-09-08 17:40:47 +02:00
Tim Perry 9c12198b5d Add various native hook fixes, especially for SOCKS 2026-09-08 15:16:31 +02:00
Tim Perry 18b532e6c8 Improve handling of possible NPE in the iOS script
This doesn't actually fix anything - but does ensure it would fail at
the right point, rather than imploding unpredictably later on.
2026-09-08 15:16:30 +02:00
Tim Perry 5d3553a30a Support multiple callbacks in waitForModule 2026-09-08 15:16:29 +02:00
xaxaandGitHub f7b0afea0f Add overload for checkServerTrusted method in *Appmattus* hooks
This overload was ignored beforehand because of an ill-formed data structure.
2026-09-03 23:11:59 +02:00
Tim PerryandGitHub 2c9fcb9505 Merge pull request #228 from httptoolkit/dependabot/npm_and_yarn/test/android/multi-e11ec19f64
Bump qs and mockttp in /test/android
2026-09-03 12:43:56 +01:00
dependabot[bot]andGitHub 2e2ae11410 Bump qs and mockttp in /test/android
Bumps [qs](https://github.com/ljharb/qs) to 6.16.0 and updates ancestor dependency [mockttp](https://github.com/httptoolkit/mockttp). These dependencies need to be updated together.


Updates `qs` from 6.15.3 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ljharb/qs/compare/v6.15.3...v6.16.0)

Updates `mockttp` from 4.0.1 to 4.6.2
- [Release notes](https://github.com/httptoolkit/mockttp/releases)
- [Commits](https://github.com/httptoolkit/mockttp/compare/v4.0.1...v4.6.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
- dependency-name: mockttp
  dependency-version: 4.6.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-03 11:15:29 +00:00
Tim Perry f1329a7f3c Validate that native hooks really hit the native lib 2026-08-28 19:42:38 +01:00
Tim Perry 6df52b9dc6 Fix iOS native hook to return a working pointer
Previously we returned a string, expecting Frida to implicitly turn this
into a pointer. This doesn't work in practice, and ends up returning
null, which makes this hook non-functional. We now allocate a real
string with a proper pointer and return that explicitly so this works
correctly.
2026-08-28 18:08:35 +01:00
Tim Perry e004f1d8f3 Don't break ssl_verify_retry from native TLS validation callbacks 2026-08-28 18:00:38 +01:00
Tim Perry 58f1f63321 Improve lock & error handling in TLS callback wrapper 2026-08-28 17:38:22 +01:00
Tim Perry fa9ed69a36 Avoid duplicate work & logging in the native TLS hook
This reduces log noise in serious failure scenarios, and improves
performance by not hitting a native function repeatedly in the loop.
2026-08-28 17:38:22 +01:00
Tim Perry 9c56acd8c8 Fix native TLS hook, by calling callback only for cronet
Previously we blacklisted boringssl, but did call it for others,
including Conscrypt, where it seems that this can actually result in JNI
crashes on Android due to exception side effects. We now whitelist
cronet instead - everywhere else, the callback is skipped and we
override the result directly.
2026-08-28 16:21:21 +01:00
Tim Perry fb2e3cb162 Add a legacy path to support Android 26 in native TLS hook 2026-08-28 16:20:56 +01:00
Tim Perry 535b5a1c8c Wait for libnetwork on iOS in case to make connect script more reliable
This notably applied in simulator testing, but presumably could also be
required on devices in some real scenarios too.
2026-08-27 18:18:55 +01:00
Tim Perry ad96df8386 Tighten up native TLS hook especially for iOS 26 2026-08-27 18:18:54 +01:00
Tim Perry 628b00e69c Don't swallow errors in waitForModule callback 2026-08-27 18:18:39 +01:00
Tim PerryandGitHub 3b2a9b9296 Merge pull request #226 from httptoolkit/dependabot/npm_and_yarn/test/android/js-yaml-4.3.1
Bump js-yaml from 4.2.0 to 4.3.1 in /test/android
2026-08-21 11:49:28 +01:00
Tim PerryandGitHub 4c0a1980ee Merge pull request #224 from b1gb1t/fix/ios-fcntl-native-hook
Fix native-connect-hook on iOS: resolve libc symbols via global fallback
2026-08-20 11:45:33 +02:00
b1gb1t 7e4951d15d Resolve libc symbols by scanning known system modules
Replace the global export lookup with a fixed list of system
libraries (libc.so, libc.so.6, libsystem_c/kernel/pthread), using
whichever are present, to avoid matching same-named exports from the
app's own code, per review feedback.
2026-08-15 12:43:51 +02:00
dependabot[bot]andGitHub 1fca6f0cec Bump js-yaml from 4.2.0 to 4.3.1 in /test/android
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 19:13:42 +00:00
b1gb1t b2c72f66d1 Fix native-connect-hook on iOS: resolve libc symbols via global fallback
fcntl is not exported by libsystem_c.dylib on Darwin (it lives in
libsystem_kernel.dylib), so the setup block threw and aborted all
native hooks, leaving connect() uninstrumented. Resolve each symbol
from the module first, then fall back to a global lookup.
2026-08-05 16:36:01 +02:00
Tim PerryandGitHub 92f2ab3384 Merge pull request #221 from httptoolkit/dependabot/npm_and_yarn/test/android/brace-expansion-2.1.4
Bump brace-expansion from 2.0.3 to 2.1.4 in /test/android
2026-08-04 11:10:05 +02:00
dependabot[bot]andGitHub 9b6dee00e7 Bump brace-expansion from 2.0.3 to 2.1.4 in /test/android
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.0.3 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v2.0.3...v2.1.4)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-04 08:53:04 +00:00
Tim PerryandGitHub 8b0eec01ae Merge pull request #220 from httptoolkit/dependabot/npm_and_yarn/test/android/ip-address-10.4.0
Bump ip-address from 10.2.0 to 10.4.0 in /test/android
2026-08-04 10:51:58 +02:00
dependabot[bot]andGitHub 13ab9ca5c7 Bump ip-address from 10.2.0 to 10.4.0 in /test/android
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-04 00:01:20 +00:00
Tim PerryandGitHub 0a915656f9 Merge pull request #219 from httptoolkit/dependabot/npm_and_yarn/test/android/path-to-regexp-0.1.13
Bump path-to-regexp from 0.1.12 to 0.1.13 in /test/android
2026-08-03 16:48:33 +02:00
Tim Perry 425f09ccd0 Update assorted outdated GHA steps 2026-08-03 16:32:45 +02:00
dependabot[bot]andGitHub c6ceec0851 Bump path-to-regexp from 0.1.12 to 0.1.13 in /test/android
Bumps [path-to-regexp](https://github.com/pillarjs/path-to-regexp) from 0.1.12 to 0.1.13.
- [Release notes](https://github.com/pillarjs/path-to-regexp/releases)
- [Changelog](https://github.com/pillarjs/path-to-regexp/blob/v.0.1.13/History.md)
- [Commits](https://github.com/pillarjs/path-to-regexp/compare/v0.1.12...v.0.1.13)

---
updated-dependencies:
- dependency-name: path-to-regexp
  dependency-version: 0.1.13
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-03 14:29:01 +00:00
Tim Perry ec34453530 Clean up test code Android dialog/ANR handling 2026-08-03 16:27:04 +02:00
Tim Perry 55684f9cd1 Move waitForModule to Frida's attachModuleObserver API
This fixes Flutter for Android 26, drops a load of awkward workaround
code, and probably fixes bugs in various other cases too.
2026-08-03 15:53:43 +02:00
Tim Perry bc73628efc More test hardening to make CI reliable 2026-07-31 19:46:44 +02:00
Tim Perry 3696f6674f Massive Flutter script update so it now works on release versions 2026-07-31 19:43:51 +02:00
Tim Perry f77528bc91 Pre-init classes to fix OkHttp tests on API 30 2026-07-31 19:42:14 +02:00