LDPlayer Android9中custom.rc已执行但frida-server未启动求助
排查LDPlayer Android 9中frida-server开机自启失败的步骤
已知custom.rc已执行(here.txt生成),但frida-server未启动,可按以下步骤逐一排查:
验证frida-server的路径与可执行性
- 手动执行
/system/bin/frida-server,观察是否能正常启动、有无报错(如架构不匹配、权限问题)。 - 用
ls -l /system/bin/frida-server确认文件存在,且权限为rwxr-xr-x(755)。注意:/system/bin默认是只读分区,若未通过Magisk等工具挂载为可写,直接放入的文件可能重启后消失,建议将frida-server移至/data/local/tmp目录下测试。
- 手动执行
查看init进程的执行日志
通过以下命令抓取init相关日志,定位exec_background执行失败的具体原因:logcat | grep init # 或 dmesg | grep init日志中会包含执行frida-server时的错误信息,如路径不存在、权限不足、SELinux上下文冲突等。
通过脚本重定向日志输出
直接用exec_background执行二进制无法捕获输出,可改用脚本记录启动日志:- 创建启动脚本
/data/local/tmp/start_frida.sh:#!/system/bin/sh nohup /system/bin/frida-server > /data/local/tmp/frida_start.log 2>&1 & - 给脚本添加可执行权限:
chmod 755 /data/local/tmp/start_frida.sh - 修改
custom.rc内容:on property:sys.boot_completed=1 write /data/local/tmp/here.txt here exec_background u:r:magisk:s0 -- /data/local/tmp/start_frida.sh
重启后查看
/data/local/tmp/frida_start.log,里面会记录frida-server启动失败的具体原因。- 创建启动脚本
调整SELinux上下文与启动方式
- 尝试去掉
exec_background后的SELinux上下文参数,直接执行:exec_background -- /system/bin/frida-server - 若进程容易被init回收,可改用
sh -c配合nohup后台启动:exec_background u:r:magisk:s0 -- /system/bin/sh -c "nohup /system/bin/frida-server > /dev/null 2>&1 &"
- 尝试去掉
确认frida-server架构匹配
LDPlayer多为x86/x86_64架构,需确保下载的frida-server对应android-x86_64版本,若架构不匹配,即使权限正确也无法执行。
内容的提问来源于stack exchange,提问作者Martijn Deleij
相关产品推荐
相关产品推荐

