Skip to content

Support explicitly scoped isolated services - #998

Open
kalanihelekunihi wants to merge 1 commit into
JingMatrix:masterfrom
kalanihelekunihi:support-scoped-isolated-processes
Open

kalanihelekunihi wants to merge 1 commit into
JingMatrix:masterfrom
kalanihelekunihi:support-scoped-isolated-processes

Conversation

@kalanihelekunihi

Copy link
Copy Markdown

Summary

  • allow the Zygisk half of Vector to consult the daemon for isolated application processes
  • inherit an explicitly selected base package scope for an isolated process in the same Android user
  • keep unscoped isolated processes excluded because the daemon returns no binder or modules for them

Why

Android services that use isolatedProcess, including on-device ML runtimes, receive a transient isolated UID and a generated process name such as:

com.google.android.aicore:isolated_service:com.google.android.apps.aicore.service.isolated.AiCoreIsolatedService

Vector previously rejected every isolated UID in preAppSpecialize, before the daemon could apply the user's package scope. Adding the generated process as a separate scope is not durable because its UID changes between process starts.

This change lets the daemon derive the base package from the colon-delimited process name and inherit only that package's explicit scope for the same Android user. A process without a matching explicit base-package scope receives no framework binder and remains uninjected.

Device proof

Tested on a rooted Google Pixel 11 Pro Fold (yogi) running Android 17 build DP11.260918.005 (16443917), fingerprint:

google/yogi_beta/yogi:17/DP11.260918.005/16443917:user/release-keys

With an Xposed module scoped only to com.google.android.aicore, repeated isolated-service starts used changing isolated UIDs (99000, 99006, and 99016). Vector logged:

Process 'com.google.android.aicore:isolated_service:com.google.android.apps.aicore.service.isolated.AiCoreIsolatedService' ... is marked for injection
Inherited com.google.android.aicore scope for isolated process .../99016

The scoped module then loaded in the isolated service, and AICore completed its local Edge TPU model initialization with repeated Successfully loaded offline-compiled model events. This behavior survived cold process starts and UID changes.

The device test used this capability to restore access to a locally present factory model for rooted users after Google's protected model download service rejected the unlocked boot chain. The change itself is generic and does not contain Google package special cases or alter attestation.

Validation

  • git diff --check
  • ./gradlew zipDebug with OpenJDK 21 and Android SDK: BUILD SUCCESSFUL
  • the resulting debug module was built for all configured ABIs
  • live device logs confirmed that an explicitly scoped base package inherited into the isolated service across multiple transient UIDs
  • live device logs confirmed native model loading after injection

The repository-wide ktfmtCheck currently reports pre-existing formatting differences in unrelated files on the base branch. The changed Kotlin block was formatted with the repository's ktfmtFormatMain task, then unrelated formatter changes were discarded.

Security and scope behavior

  • exact non-isolated scopes still take precedence
  • inheritance is limited to Android isolated UID ranges
  • the process name must have a colon-delimited base package
  • the matching base package scope must belong to the same Android user
  • shared RELRO remains excluded
  • isolated processes without an explicit matching base-package scope receive no modules

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant