Flutter应用中FreeRASP配置正确却未正常工作的问题排查
问题:Flutter集成FreeRASP后模拟器检测失效
我们开发了一款Flutter应用,近期集成了FreeRASP(适用于Flutter的Runtime App Self Protection库),代码如下:
import 'dart:io'; import 'package:flutter/material.dart'; import 'package:freerasp/talsec_app.dart'; void main() async { WidgetsFlutterBinding.ensureInitialized(); ... runApp(MyApp(...)); } class MyApp extends StatefulWidget { const MyApp({...}) : super(key: key); ... @override _MyAppState createState() => _MyAppState(...); } class _MyAppState extends State<MyApp> { _MyAppState({...}); ... @override void initState() { super.initState(); initSecurityState(); } Future<void> initSecurityState() async { TalsecConfig config = TalsecConfig( // For Android androidConfig: AndroidConfig( expectedPackageName: 'com.company.mypackage', expectedSigningCertificateHash: 'xxxxxxxx', supportedAlternativeStores: ["com.sec.android.app.samsungapps"], ), // Common email for Alerts and Reports watcherMail: 'xxx@xxx.com', ); TalsecCallback callback = TalsecCallback( // For Android androidCallback: AndroidCallback( onRootDetected: () => exit(0), onEmulatorDetected: () => exit(0), onHookDetected: () => exit(0), onTamperDetected: () => exit(0), onDeviceBindingDetected: () => print('device binding'), onUntrustedInstallationDetected: () => print('untrusted install'), ), // Common for both platforms onDebuggerDetected: () => print('debugger'), ); TalsecApp app = TalsecApp( config: config, callback: callback, ); app.start(); } @override Widget build(BuildContext context) { return MaterialApp(...); } }
但在模拟器上运行时,FreeRASP并未检测到模拟器,尽管已配置检测到模拟器时执行exit(0)。调试执行app.start()时出现以下日志:
W/india.mobileap( 4242): Accessing hidden method Lcom/android/internal/os/PowerProfile;-><init>(Landroid/content/Context;)V (unsupported, reflection, allowed) W/PowerProfile( 4242): ambient.on is deprecated! Use ambient.on.display0 instead. W/PowerProfile( 4242): screen.on is deprecated! Use screen.on.display0 instead. W/PowerProfile( 4242): screen.full is deprecated! Use screen.full.display0 instead. W/india.mobileap( 4242): Accessing hidden method Lcom/android/internal/os/PowerProfile;->getBatteryCapacity()D (unsupported, reflection, allowed) I/DrmHal ( 4242): found instance=clearkey version=android.hardware.drm@1.4::IDrmFactory I/DrmHal ( 4242): found instance=default version=android.hardware.drm@1.0::IDrmFactory I/DrmHal ( 4242): found instance=widevine version=android.hardware.drm@1.4::IDrmFactory E/HMSSDK_HMSPackageManager( 4242): resolveInfoList is null or empty E/HMSSDK_HMSPackageManager( 4242): PackagePriorityInfo list is null E/HMSSDK_HMSPackageManager( 4242): <initHmsPackageInfoForMultiService> Failed to find HMS apk I/HMSSDK_HMSPackageManager( 4242): Enter getHMSPackageNameForMultiService E/HMSSDK_HMSPackageManager( 4242): resolveInfoList is null or empty E/HMSSDK_HMSPackageManager( 4242): PackagePriorityInfo list is null E/HMSSDK_HMSPackageManager( 4242): <initHmsPackageInfoForMultiService> Failed to find HMS apk I/HMSSDK_HuaweiMobileServicesUtil( 4242): hmsPackageName is com.huawei.hwid E/HMSSDK_HMSPackageManager( 4242): resolveInfoList is null or empty E/HMSSDK_HMSPackageManager( 4242): PackagePriorityInfo list is null E/HMSSDK_HMSPackageManager( 4242): <initHmsPackageInfoForMultiService> Failed to find HMS apk I/HMSSDK_HuaweiMobileServicesUtil( 4242): HMS is not installed I/HMSSDK_HMSPackageManager( 4242): enter asyncOnceCheckMDMState I/HMSSDK_HMSPackageManager( 4242): quit asyncOnceCheckMDMState W/System ( 4242): A resource failed to call close. I/TestLibrary( 4242): Failed with error code 7 W/System ( 4242): A resource failed to call close
解决方案
- 修正配置参数:
- 确认
expectedPackageName与AndroidManifest.xml中的包名完全一致,大小写也不能出错 - 替换
expectedSigningCertificateHash为当前运行环境的签名哈希:调试运行时用调试签名的哈希,发布版本用正式签名的哈希。可通过keytool -list -v -keystore <你的密钥库路径>命令获取哈希值(取SHA-256的前40位,去掉冒号)
- 确认
- 处理错误码7:日志中的
Failed with error code 7表示FreeRASP的配置验证未通过,这会直接导致所有检测逻辑无法启动。必须先解决配置匹配问题,模拟器检测才会正常工作 - 更换测试模拟器:部分定制化模拟器可能绕过了FreeRASP的检测规则,建议使用Android Studio官方自带的模拟器进行测试
- 检查初始化时机:确保
initSecurityState()在应用启动时被正确调用,没有被其他异步操作延迟。可尝试将初始化逻辑移到main函数中(确保在runApp之前完成) - 升级库版本:如果使用的是旧版FreeRASP,可能存在模拟器检测的bug,建议升级到最新版本
- 忽略HMS相关日志:日志中关于HMS的错误是因为设备未安装华为服务,这和模拟器检测失效无关,可以忽略
内容的提问来源于stack exchange,提问作者6nagi9
相关产品推荐
相关产品推荐

