ProGuard混淆失效求助:Android反编译器可还原代码
安卓ProGuard混淆失效修复方案
问题描述
已使用ProGuard对Java代码进行混淆,但通过反编译工具(按住Ctrl+左键点击类即可还原)能完全暴露原代码,变量、方法名被完整还原,混淆未起到作用。
混淆后代码片段
public static final String Q = "Main"; public static boolean R; public static boolean S; public static int T; public static LinearLayout U; public static LinearLayout V; public static final String W = "com.android.example.USB_PERMISSION"; public static final int X = 516; public static final int Y = 515; public static final int Z = 514; public g a; public UsbManager b;
反编译后代码片段
private static final String TAG = "Main"; protected static boolean log_dbg = true; protected static boolean loc_srv = true; protected static int urlConn = 0; Variables variables; static LinearLayout ll_history_view; static LinearLayout ll_reading_view; private UsbManager usbManager; private UsbDevice deviceFound; private UsbDeviceConnection usbDeviceConnection = null; private UsbInterface usbInterfaceFound = null; private UsbEndpoint endpointOut = null; private UsbEndpoint endpointIn = null; private PendingIntent UsbPermissionPI; private static final String ACTION_USB_PERMISSION = "com.android.example.USB_PERMISSION";
当前配置
proguard-rules.pro
-keepparameternames -dontshrink -dontoptimize
build.gradle
plugins { id 'com.android.library' } android { namespace 'com.example.application' compileSdk 34 defaultConfig { minSdk 30 multiDexEnabled true testInstrumentationRunner "androidx.test.runner.AndroidJUnitRunner" consumerProguardFiles "consumer-rules.pro" } buildTypes { release { minifyEnabled true proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro' consumerProguardFiles 'proguard-rules.pro' } } compileOptions { sourceCompatibility JavaVersion.VERSION_11 targetCompatibility JavaVersion.VERSION_11 } } dependencies { implementation 'androidx.appcompat:appcompat:1.6.1' implementation 'com.google.android.material:material:1.10.0' implementation libs.core implementation 'com.android.support:multidex:1.0.3' testImplementation 'junit:junit:4.13.2' androidTestImplementation 'androidx.test.ext:junit:1.2.1' androidTestImplementation 'androidx.test.espresso:espresso-core:3.6.1' }
修复方案
1. 重置ProGuard核心规则
当前配置的-dontshrink、-dontoptimize直接关闭了代码压缩与优化,-keepparameternames保留了参数名,这些是混淆失效的核心原因。替换为以下规则:
# 开启优化与压缩 -optimizationpasses 5 -optimizations !code/simplification/cast,!field/*,!class/merging/* -dontpreverify # 保留Library对外暴露的公共API(根据实际业务调整,避免对外接口被混淆) -keep public class com.example.application.** { public protected *; } # 保留必要的元数据,避免运行时异常 -keepattributes *Annotation*,Signature,InnerClasses,EnclosingMethod -keepnames class * implements java.io.Serializable # 混淆非公共类、方法与变量,合并包结构强化混淆 -repackageclasses '' -flattenpackagehierarchy
2. 调整build.gradle配置
修正release构建类型的配置,确保资源压缩开启,同时区分自身混淆规则与对外暴露的规则:
buildTypes { release { minifyEnabled true shrinkResources true // 可选,开启资源压缩 proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro' // consumerProguardFiles仅存放给依赖方的规则,不要复用自身混淆规则 consumerProguardFiles "consumer-rules.pro" } }
3. 额外强化措施
- 确保R8优化启用:Android Studio默认用R8替代ProGuard,无需额外配置,不要添加
android.enableR8=false - 避免不必要的保留规则:不要随意添加
-keepclassmembers保留变量名,仅在必须保留(如反射用到)时添加 - 验证混淆效果:每次构建后用反编译工具检查,确保非公共变量、方法名已被混淆为无意义字符,且无法被还原
内容的提问来源于stack exchange,提问作者sunled
相关产品推荐
相关产品推荐

