Android Studio中AAR库ProGuard混淆失效问题求助
Hey there, I’ve run into this exact frustration when building obfuscated Android AAR libraries before—let’s break down the key checks and fixes to get ProGuard working correctly:
1. Ensure Obfuscation is Enabled in Your Build Configuration
First things first: ProGuard won’t run at all unless you explicitly enable it for your release build variant. Open your library module’s build.gradle (not the project-level one) and verify the release build type has minifyEnabled set to true:
android { buildTypes { release { minifyEnabled true // Critical—this turns on ProGuard shrinkResources true // Optional, but removes unused resources proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro' } } }
Note: Using proguard-android-optimize.txt (instead of the default proguard-android.txt) enables more aggressive optimizations and obfuscation, which is ideal for closed-source libraries.
2. Audit Your ProGuard Rules for Overly Broad -keep Statements
The auto-generated proguard-rules.pro might have default rules that accidentally preserve too much of your code. ProGuard won’t obfuscate any classes/methods marked with -keep, so you need to make sure you’re only keeping the public API your library exposes.
For example, if your library has a single public entry point like AuthManager, your rules should look like this:
# Keep only your public API—everything else gets obfuscated -keep public class com.yourpackage.auth.AuthManager { public <methods>; public <fields>; } # Remove any overly broad rules like this (they completely kill obfuscation): # -keep class com.yourpackage.** { *; }
If you use annotations, reflection, or third-party libraries, you’ll need targeted -keep rules for those, but avoid blanket statements that preserve all your code.
3. Verify You’re Building the Release Variant
It’s easy to accidentally build a debug variant (which defaults to no obfuscation). Make sure you’re:
- Using Build > Generate Signed Bundle/APK and selecting the
releasevariant when exporting your AAR. - Or running the correct Gradle command from the terminal:
./gradlew :your-library-module-name:assembleRelease
Always double-check that you’re inspecting the release AAR from your-library-module/build/outputs/aar/ (not the debug version).
4. Confirm ProGuard Actually Ran
Check if ProGuard executed by:
- Looking at your build logs: Search for "ProGuard"—you should see logs about the version running, input/output files, and any warnings. If there’s no mention of ProGuard, go back to step 1 to fix your build configuration.
- Checking for the
mapping.txtfile: After a successful release build, you’ll find this inyour-library-module/build/outputs/mapping/release/. This file maps original class/method names to obfuscated ones—if it exists, ProGuard ran.
5. Check the AAR’s Classes Jar Correctly
When you unzip the AAR, open classes.jar with a tool like JD-GUI to inspect the code. Remember:
- Your public API classes (the ones you kept with
-keep) will still have their original names—this is expected, since other apps need to use them. - Internal classes, private methods, and non-public fields should be renamed to short, meaningless names like
a,b,C, etc. If these are still using original names, your-keeprules are too broad.
6. Handle Kotlin-Specific Configuration (If Applicable)
If your library uses Kotlin, the default ProGuard rules might not cover Kotlin’s internal structures. Add these rules to proguard-rules.pro to ensure proper obfuscation without breaking Kotlin code:
-keep class kotlin.** { *; } -keep class kotlin.Metadata { *; } -dontwarn kotlin.** -keepclassmembers class **$WhenMappings { <fields>; } -keepclassmembers class kotlin.Metadata { public <methods>; }
Final Quick Checks
- Make sure your Android Studio and Gradle versions are up to date—older versions have known bugs with ProGuard and AARs.
- If you’re using R8 (the modern replacement for ProGuard), the configuration is almost identical—just ensure
minifyEnabled trueis set, and R8 will handle the rest.
内容的提问来源于stack exchange,提问作者Joe Bennett

