create: reFlutter 对此 App 无效(snapshot hash 不兼容)

MemRelay-Operation: memory-save:rapdrama-exp-reflutter-fail-20260925-0605
MemRelay-Resource: 09fa2312-2d68-47d8-afe2-fe9c362ebb8b
This commit is contained in:
2026-09-25 06:04:45 +08:00
parent cab6ca46cc
commit 4bd7a7ed37
@@ -0,0 +1,30 @@
---
title: reFlutter 对此 App 无效(snapshot hash 不兼容)
type: experience
permalink: main/projects/280dd2a0-d23d-4a71-91e1-dce4353163be/re-flutter-对此-app-无效-snapshot-hash-不兼容
stable_id: 09fa2312-2d68-47d8-afe2-fe9c362ebb8b
scope: project
memory_type: experience
project_id: 280dd2a0-d23d-4a71-91e1-dce4353163be
usage_profile_id: 0c9feb46-d06e-43cd-9ef0-c5813c84a998
status: active
revision: 1
request_id: rapdrama-exp-reflutter-fail-20260925-0605
created_at: '2026-09-24T22:04:42.543823+00:00'
updated_at: '2026-09-24T22:04:42.543823+00:00'
tags:
- reflutter
- flutter
- 失败
---
reFlutter 0.9.8 对此 App 无效。App 的 Flutter 引擎 snapshot hash 78da37fed6bf1489361a312568249f3f 不在 reFlutter 支持列表中,reFlutter 替换的 libflutter.so(12560440 bytes)与原版(12565024 bytes)不兼容,引擎初始化失败 App 直接退出。
即使解决了 Flutter 引擎兼容问题,重签 APK 后 Google Play Protect 会弹出系统级拦截界面(从 Play 获取此应用)。禁用 Play Store 可以绕过这个拦截,但 App 本身的 Flutter 引擎不兼容问题仍然存在。
Frida 16.5.9 的 Java bridge 正常工作,已确认可以 Java.perform + hook Activity/Dialog。frida-server-16.5.9 已推送到 /data/local/tmp/frida-server-16。如果未来能解决 reFlutter 兼容问题,Frida 16 的 Java bridge 可以用来绕过签名校验。
剩余可探索方向:
1. 手动 patch 原版 libflutter.so(不用 reFlutter,直接用 Ghidra 找到 socket.cc 里的代理地址字段并修改)
2. 用 HTTP Toolkit(专业 Android 抓包工具,内置 VPN + 透明代理)
3. 用真机而不是模拟器(Frida 对真机的 libc hook 可能正常工作)