溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊(cè)×
其他方式登錄
點(diǎn)擊 登錄注冊(cè) 即表示同意《億速云用戶服務(wù)條款》

Android webveiw 出現(xiàn)棧錯(cuò)誤解決辦法

發(fā)布時(shí)間:2020-10-07 19:12:55 來(lái)源:腳本之家 閱讀:199 作者:lqh 欄目:移動(dòng)開(kāi)發(fā)

Android webveiw 出現(xiàn)棧錯(cuò)誤解決辦法

前言:

最近做一個(gè)項(xiàng)目,項(xiàng)目調(diào)試基礎(chǔ)庫(kù)的一個(gè)調(diào)試工具展示設(shè)備信息頁(yè)面使用WebView。有一個(gè)應(yīng)用集成調(diào)試基礎(chǔ)庫(kù)展示內(nèi)容時(shí)出現(xiàn)

java.lang.UnsupportedOperationException: For security reasons, WebView is not allowed in privileged processes

因?yàn)閼?yīng)用是系統(tǒng)級(jí)別的,在AndroidManifest.xml中添加了android:sharedUserId="android.uid.system"

根據(jù)exception提示出于安全原因,所以初步斷定很可能跟應(yīng)用為系統(tǒng)應(yīng)用有很大關(guān)系,于是開(kāi)始了查找代碼尋源之旅

首先我們看一下具體的錯(cuò)誤堆棧

at android.app.ActivityThread.performLaunchActivity(ActivityThread.java:2325) 
at android.app.ActivityThread.handleLaunchActivity(ActivityThread.java:2387) 
at android.app.ActivityThread.access$800(ActivityThread.java:151) 
at android.app.ActivityThread$H.handleMessage(ActivityThread.java:1303) 
at android.os.Handler.dispatchMessage(Handler.java:102) 
at android.os.Looper.loop(Looper.java:135) 
at android.app.ActivityThread.main(ActivityThread.java:5257) 
at java.lang.reflect.Method.invoke(Native Method) 
at java.lang.reflect.Method.invoke(Method.java:372) 
at com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:955) 
at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:750) 
aused by: android.view.InflateException: Binary XML file line #17: Error inflating class android.webkit.WebView 
at android.view.LayoutInflater.createView(LayoutInflater.java:633) 
at com.android.internal.policy.impl.PhoneLayoutInflater.onCreateView(PhoneLayoutInflater.java:55) 
at android.view.LayoutInflater.onCreateView(LayoutInflater.java:682) 
at android.view.LayoutInflater.createViewFromTag(LayoutInflater.java:741) 
at android.view.LayoutInflater.rInflate(LayoutInflater.java:806) 
at android.view.LayoutInflater.inflate(LayoutInflater.java:504) 
at android.view.LayoutInflater.inflate(LayoutInflater.java:414) 
at android.view.LayoutInflater.inflate(LayoutInflater.java:365) 
at com.android.internal.policy.impl.PhoneWindow.setContentView(PhoneWindow.java:379) 
at android.app.Activity.setContentView(Activity.java:2145) 
at com.mipt.store.activity.InfoActivity.onCreate(Unknown Source) 
at android.app.Activity.performCreate(Activity.java:5990) 
at android.app.Instrumentation.callActivityOnCreate(Instrumentation.java:1106) 
at android.app.ActivityThread.performLaunchActivity(ActivityThread.java:2278) 
... 10 more 
aused by: java.lang.reflect.InvocationTargetException 
at java.lang.reflect.Constructor.newInstance(Native Method) 
at java.lang.reflect.Constructor.newInstance(Constructor.java:288) 
at android.view.LayoutInflater.createView(LayoutInflater.java:607) 
... 23 more 
aused by: java.lang.UnsupportedOperationException: For security reasons, WebView is not allowed in privileged processes 
at android.webkit.WebViewFactory.getProvider(WebViewFactory.java:96) 
at android.webkit.WebView.getFactory(WebView.java:2194) 
at android.webkit.WebView.ensureProviderCreated(WebView.java:2189) 
at android.webkit.WebView.setOverScrollMode(WebView.java:2248) 
at android.view.View.<init>(View.java:3588) 
at android.view.View.<init>(View.java:3682) 
at android.view.ViewGroup.<init>(ViewGroup.java:497) 
at android.widget.AbsoluteLayout.<init>(AbsoluteLayout.java:55) 
at android.webkit.WebView.<init>(WebView.java:544) 
at android.webkit.WebView.<init>(WebView.java:489) 
at android.webkit.WebView.<init>(WebView.java:472) 
at android.webkit.WebView.<init>(WebView.java:459) 
... 26 more 

錯(cuò)誤提示顯示為“Caused by: java.lang.UnsupportedOperationException: For security reasons, WebView is not allowed in privileged processes”

security reasons即安全原因。為了查明原因直接查看android源碼。經(jīng)過(guò)一番查找,發(fā)現(xiàn)拋出Exception的在

frameworks/base/master/core/java/android/webkit/WebViewFactory.java

static WebViewFactoryProvider getProvider() { 
 synchronized (sProviderLock) { 
  // For now the main purpose of this function (and the factory abstraction) is to keep 
  // us honest and minimize usage of WebView internals when binding the proxy. 
  if (sProviderInstance != null) return sProviderInstance; 
  final int uid = android.os.Process.myUid(); 
  if (uid == android.os.Process.ROOT_UID || uid == android.os.Process.SYSTEM_UID) { 
   throw new UnsupportedOperationException( 
     "For security reasons, WebView is not allowed in privileged processes"); 
  } 
  StrictMode.ThreadPolicy oldPolicy = StrictMode.allowThreadDiskReads(); 
  Trace.traceBegin(Trace.TRACE_TAG_WEBVIEW, "WebViewFactory.getProvider()"); 
  try { 
   Class<WebViewFactoryProvider> providerClass = getProviderClass(); 
   Trace.traceBegin(Trace.TRACE_TAG_WEBVIEW, "providerClass.newInstance()"); 
   try { 
    sProviderInstance = providerClass.getConstructor(WebViewDelegate.class) 
      .newInstance(new WebViewDelegate()); 
    if (DEBUG) Log.v(LOGTAG, "Loaded provider: " + sProviderInstance); 
    return sProviderInstance; 
   } catch (Exception e) { 
    Log.e(LOGTAG, "error instantiating provider", e); 
    throw new AndroidRuntimeException(e); 
   } finally { 
    Trace.traceEnd(Trace.TRACE_TAG_WEBVIEW); 
   } 
  } finally { 
   Trace.traceEnd(Trace.TRACE_TAG_WEBVIEW); 
   StrictMode.setThreadPolicy(oldPolicy); 
  } 
 } 
} 

WebView在初始化的時(shí)候會(huì)檢查初始化進(jìn)程的id.

final int uid = android.os.Process.myUid(); 
if (uid == android.os.Process.ROOT_UID || uid == android.os.Process.SYSTEM_UID) { 
 throw new UnsupportedOperationException( 
  "For security reasons, WebView is not allowed in privileged processes"); 
} 

如果進(jìn)程ID是root或者system,就會(huì)拋出UnsupportedOperationException。為什么會(huì)有這種安全機(jī)制呢?因?yàn)閣ebview允許運(yùn)行js,如果用戶通過(guò)js注入安全代碼,那么js就可以肆無(wú)忌憚的使用系統(tǒng)權(quán)限,這無(wú)疑是一個(gè)漏洞,可謂門戶大開(kāi)。

果不其然就是android:sharedUserId="android.uid.system"的問(wèn)題,因?yàn)槭窍到y(tǒng)應(yīng)用所以只能修改基礎(chǔ)調(diào)試庫(kù)的展示控件,把展示調(diào)試信息的webview改為textview。

感謝閱讀,希望能通過(guò)本文幫助到大家,謝謝大家對(duì)本站的支持,如有疑問(wèn)請(qǐng)留言或者到本站社區(qū)交流討論,大家共同進(jìn)步!

向AI問(wèn)一下細(xì)節(jié)

免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如果涉及侵權(quán)請(qǐng)聯(lián)系站長(zhǎng)郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。

AI