Commit Graph
12 Commits
Author SHA1 Message Date
Tim Perry fa9ed69a36 Avoid duplicate work & logging in the native TLS hook
This reduces log noise in serious failure scenarios, and improves
performance by not hitting a native function repeatedly in the loop.
2026-08-28 17:38:22 +01:00
Tim Perry 9c56acd8c8 Fix native TLS hook, by calling callback only for cronet
Previously we blacklisted boringssl, but did call it for others,
including Conscrypt, where it seems that this can actually result in JNI
crashes on Android due to exception side effects. We now whitelist
cronet instead - everywhere else, the callback is skipped and we
override the result directly.
2026-08-28 16:21:21 +01:00
Tim Perry fb2e3cb162 Add a legacy path to support Android 26 in native TLS hook 2026-08-28 16:20:56 +01:00
Tim Perry ad96df8386 Tighten up native TLS hook especially for iOS 26 2026-08-27 18:18:54 +01:00
AnyISalIn dd05b46cab fix potential null pointer issue
Signed-off-by: AnyISalIn <anyisalin@gmail.com>
2025-11-18 18:47:49 +08:00
Tim Perry aacc1579cb Update native TLS & iOS hooks to Frida 17 too 2025-06-20 16:59:52 +02:00
Tim Perry 5b0fd454b9 Fix parallel TLS hook issue
It's unclear why, but in some scenarios the hook would reliably hit a
null pointer within the native realCallback() call if the call is made
while another is already in progress (even though without Frida that's
presumably happening just fine, and they're different cb pointers etc
etc).

We could use Frida's exclusive scheduling to fix this, but that raises
the risk of a deadlock here a bit in, so instead we do a very simple
locking setup with a polling unlock. Very quick & rough but works
nicely, and allows reentrant locks in a single thread in case some apps
use SSL to verify SSL somehow. Hard to imagine a cross-thread deadlock
here so hopefully that'll be sufficient...
2024-06-17 15:39:34 +02:00
Tim Perry e99740babb Fix native TLS hook null-callback handler 2024-06-17 15:38:09 +02:00
Tim Perry 8ca3cb5b94 Handle null TLS callback in native-tls-hook
This doesn't seem to be widely used, but it can come up, and it's easy
enough for us to handle correctly.
2024-06-14 17:30:59 +02:00
Tim Perry 0499961831 Move native module detection into a reusable method 2024-03-05 17:49:06 +01:00
Tim Perry 9731e4bc52 Hook native Android OpenSSL too 2024-03-05 17:08:23 +01:00
Tim Perry a1223136cd Extend iOS BoringSSL hook to hook BoringSSL in other cases too
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.

Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.
2024-03-05 15:46:41 +01:00