Previously we blacklisted boringssl, but did call it for others,
including Conscrypt, where it seems that this can actually result in JNI
crashes on Android due to exception side effects. We now whitelist
cronet instead - everywhere else, the callback is skipped and we
override the result directly.
It's unclear why, but in some scenarios the hook would reliably hit a
null pointer within the native realCallback() call if the call is made
while another is already in progress (even though without Frida that's
presumably happening just fine, and they're different cb pointers etc
etc).
We could use Frida's exclusive scheduling to fix this, but that raises
the risk of a deadlock here a bit in, so instead we do a very simple
locking setup with a polling unlock. Very quick & rough but works
nicely, and allows reentrant locks in a single thread in case some apps
use SSL to verify SSL somehow. Hard to imagine a cross-thread deadlock
here so hopefully that'll be sufficient...
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.
Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.