test(huya): b87_ harness直调执行通过(ret=-1=初始化态缺失) (R21补)

This commit is contained in:
yml2213
2026-08-29 07:07:59 +08:00
parent dc109c5dba
commit 47bc38d638
2 changed files with 15 additions and 4 deletions
+6
View File
@@ -1221,3 +1221,9 @@ dfpReport: tReq = [10B 魔数 57 18 82 cf 66 4b b3 94 01 ee][3988B 加密采
1. **直调 b87_@0x25c98** (JNI 封送: vaList/int-handle) — 喂真实捕获 blob → 输出 SparseArray = 证据事件 = 明文!
2. JNI_OnLoad x0: 追踪 onLoad 内部分配链 (0x12b6c 原子函数的调用者)
3. ga 侧 JNI 表 (turingga.so 同法解剖) → a209202_ 族入口
### R21-补充: b87_ harness 直调结果 (2026-08-29)
- addLocalObject 句柄封送 (int 句柄作 jobject) — **调用执行成功** (不再 Unsupported arg)
- 三种输入 (全POST/cipher-only/magic+cipher) × int{0,1} = 全部确定性 **ret=-1**
- 判定: jobject 封送通; -1 = turing 全局初始化态缺失 (config/dat 未载入) 或 SparseArray 内容格式不符
- 下一步: (a) onLoad 初始化链修复后直调 (x0 原子问题先解), (b) 或喂 SparseArray 事件内容探格式