????混淆apk是一個很基礎(chǔ)的工作赦肃,博客上也有一堆介紹溅蛉,本文提供一下這類工作的解決思路。在安卓源碼下面和android studio里面的做法差異不大他宛,本文以android源碼舉例船侧。
????首先在對應(yīng)mk文件里面添加proguard enabled的語句,系統(tǒng)有一個自帶的build/core/proguard.flags,默認(rèn)是使用這個文件,而且一般項目默認(rèn)是關(guān)閉的厅各,這也是有原因的镜撩。因為這里的proguard.flags是沒有針對app的配置的,使用默認(rèn)的混淆讯检,app很有可能就不工作了琐鲁。
LOCAL_PROGUARD_ENABLED := obfuscation full
LOCAL_PROGUARD_FLAGS := -include $(LOCAL_PATH)/proguard.flags
????添加了mk文件修改之后,在Android.mk同級根目錄創(chuàng)建本app自有的proguard.flags人灼。新增內(nèi)容如下围段,這里需要注意,網(wǎng)上很多demo投放,基本分為三部分奈泪,一部是保留app基礎(chǔ)功能部分的內(nèi)容不混淆;2是保持app對外接口,例如get灸芳、set涝桅、isxx、AIDL烙样、public冯遂、native層的接口或者類;3.是第三方j(luò)ar包或接口≮嘶瘢混淆的基本原理就是將上訴類或接口進(jìn)行統(tǒng)一簡單字母的替換蛤肌,如果改變了這些對外接口的名字壁却,很有可能被別人使用的時候就找不到對應(yīng)哦接口
#第一部分是基礎(chǔ)部分,可照搬的配置
#obfuscate nonpubulic element
-dontskipnonpubliclibraryclasses
-dontskipnonpubliclibraryclassmembers
#ignore native method 這個挺重要的裸准,保留native方法不被混淆
-keepclasseswithmembernames class * {
native <methods>;
}
#ignore support.v4/v7 support包不混淆
-keep class android.support.** { *; }
-keep class android.support.v4.** { *; }
-keep public class * extends android.support.v4.**
-keep interface android.support.v4.app.** { *; }
-keep class android.support.v7.** { *; }
-keep public class * extends android.support.v7.**
-keep interface android.support.v7.app.** { *; }
-libraryjars libs/android-support-v4.jar
-dontwarn android.support.** # ignore warning
#ignore basic setting 四大組件什么的不混淆展东,事實上,基礎(chǔ)部分混淆意義不大
-keep public class * extends android.app.Activity
-keep public class * extends android.app.Fragment
-keep public class * extends android.app.Application
-keep public class * extends android.app.Service
-keep public class * extends android.app.Instrumentation
-keep public class * extends android.media.AudioManager
-keep public class * extends android.view.KeyEvent
-keep public class * extends android.content.Intent
-keep public class * extends android.content.IntentFilter
-keep public class * extends android.content.Context
-keep public class * extends android.content.BroadcastReceiver
-keep public class * extends android.content.ContentProvider
-keep public class * extends android.app.backup.BackupAgentHelper
-keep public class * extends android.preference.Preference
-keep public class * extends android.bluetooth.**
-keep public class * extends android.os.**
#keep annotation not obfuscate
-keep class * extends java.lang.annotation.Annotation {*;}
#keep JSON reflection
-keepattributes Signature
#keep line number when exception 這個也挺重要的炒俱,混淆的時候保留異常行號盐肃,方便debug
-keepattributes SourceFile,LineNumberTable
#obfuscate non public class
-dontskipnonpubliclibraryclasses
-keepnames class * implements java.io.Serializable
-keepclassmembers class * implements java.io.Serializable {
static final long serialVersionUID;
private static final java.io.ObjectStreamField[] serialPersistentFields;
private void writeObject(java.io.ObjectOutputStream);
private void readObject(java.io.ObjectInputStream);
java.lang.Object writeReplace();
java.lang.Object readResolve();
}
#resource
-keepclassmembers class **.R$* {
public static <fields>;
}
-dontusemixedcaseclassnames
-keep class * implements android.os.Parcelable {
public static final android.os.Parcelable$Creator *;
}
-keepclassmembers enum * {
public static **[] values();
public static ** valueOf(java.lang.String);
}
-keep public class * extends android.view.View {
public <init>(android.content.Context);
public <init>(android.content.Context, android.util.AttributeSet);
public <init>(android.content.Context, android.util.AttributeSet, int);
public void set*(...);
}
-keep class com.google.** { *; }
-keepclassmembers class * {
void *(**On*Event);
void *(**On*Listener);
}
-assumenosideeffects class android.util.Log {
public static boolean isLoggable(java.lang.String, int);
public static int v(...);
public static int i(...);
public static int w(...);
public static int d(...);
public static int e(...);
}
#下面是自己的AIDL和相關(guān)類的混淆,可以將所有public的方法都保留权悟,也可以保留所有方法
-keep public class com.android.xxx.EventInstance{
*;
}
-keep public class com.android.xxx.MessageEvent{
*;
}
-keep public class com.android.xxx.AIDLListener{
*;
}
-keep public class com.android.xxx.AIDLControllerUtil{
*;
}
-keep public class com.android.xxx.AIDLControllerService{
public protected <methods>;
}
-keep public interface com.android.xxx.AIDLController{
*;
}
-keep public interface com.android.xxx.EventListener{
*;
}
-keep public class com.google.vr.vrcore.controller.api.IControllerListener
-keep public class com.google.vr.vrcore.controller.api.IControllerService
-keep public class com.google.vr.vrcore.controller.ControllerService$Bt_node_data
-keep public class com.google.vr.vrcore.controller.ControllerService{
public protected <methods>;
}
????一些第三方的庫如何不進(jìn)行混淆砸王,這個根據(jù)項目特點,可以自行搜索僵芹,比如百度的地圖包什么的处硬。
????然后是如何驗證和解決混淆過程遇到的問題小槐,因為是對接口名進(jìn)行替換拇派,如果出現(xiàn)混淆問題的話,log里面一定會有類似
com.google.vr.vrcore.controller. b//無法找到的異常
這個時候只需要對相關(guān)接口進(jìn)行例外(-keep)即可凿跳,然后用android-studio件豌,直接打開或者dex2jar進(jìn)行反解可以看到相關(guān)的接口是否被簡單替換。