关闭

关于android打jar文件混淆问题

标签: jarandroidsdk插件
252人阅读 评论(0) 收藏 举报
分类:

公司目前要做一个sdk插件,需要提供给第三方一个接入包,为了jar包的安全性问题,于是乎自己就google了jar如何混淆,无奈网上的帖子前篇一律,没有真正能把混淆包讲的特别明白的东东,还是自己写一个吧。当然也非常感谢google给的思路。


1. 首先将自己的工程编译好,保证工程bin目录下生成classes文件夹,见截图

2. 将自己工程目录下编译好的classes文件夹复制到E:\androidEnv\adt-bundle-windows-x86-20130514\sdk\tools\proguard\bin目录下,当然存在于当前工程目录下也没什么问题;

3. 运行..\sdk\tools\proguard\bin目录下的“proguardgui.bat”,会看到截图界面

4. 在刚运行出的界面ProGuard选项卡下点击按钮,会弹出文件选择框如下图所示


5. 选择android.pro(此文件是自己已经写好的配置问题,具体的写法)如下所示,跟android项目下的proguard.cfg文件大体一致,详情见一下代码

#
# This ProGuard configuration file illustrates how to process Android
# applications.
# Usage:
# java -jar proguard.jar @android.pro
#
# If you're using the Android SDK (version 2.3 or higher), the android tool
# already creates a file like this in your project, called proguard.cfg.
# It should contain the settings of this file, minus the input and output paths
# (-injars, -outjars, -libraryjars, -printmapping, and -printseeds).
# The generated Ant build file automatically sets these paths.

# Specify the input jars, output jars, and library jars.
# Note that ProGuard works with Java bytecode (.class),
# before the dex compiler converts it into Dalvik code (.dex).

#-injars bin/classes
#-injars libs
#-outjars /classes-processed.jar

#-libraryjars /usr/local/android-sdk/platforms/android-9/android.jar
#-libraryjars /usr/local/android-sdk/add-ons/google_apis-7_r01/libs/maps.jar
# ...

# Save the obfuscation mapping to a file, so you can de-obfuscate any stack
# traces later on.

#-printmapping bin/classes-processed.map

# You can print out the seeds that are matching the keep options below.

#-printseeds bin/classes-processed.seeds

# Preverification is irrelevant for the dex compiler and the Dalvik VM.

-dontpreverify

# Reduce the size of the output some more.
-dontusemixedcaseclassnames
-dontskipnonpubliclibraryclasses
#-dontskipnonpubliclibraryclassmembers
#-repackageclasses ''
-allowaccessmodification
-verbose
# Switch off some optimizations that trip older versions of the Dalvik VM.

-optimizations !code/simplification/arithmetic

# Keep a fixed source file attribute and all line number tables to get line
# numbers in the stack traces.
# You can comment this out if you're not interested in stack traces.

-renamesourcefileattribute SourceFile
-keepattributes SourceFile,LineNumberTable

# RemoteViews might need annotations.

-keepattributes *Annotation*

# Preserve all fundamental application classes.

-keep public class * extends android.app.Activity
-keep public class * extends android.app.Application
-keep public class * extends android.app.Service
-keep public class * extends android.content.BroadcastReceiver
-keep public class * extends android.content.ContentProvider
-keep public class * extends android.app.backup.BackupAgentHelper
-keep public class * extends android.preference.Preference
-keep public class com.android.vending.licensing.ILicensingService
-dontnote com.android.vending.licensing.ILicensingService

# Preserve all View implementations, their special context constructors, and
# their setters.

-keep public class * extends android.view.View {
public <init>(android.content.Context);
public <init>(android.content.Context, android.util.AttributeSet);
public <init>(android.content.Context, android.util.AttributeSet, int);
public void set*(...);
}

# Preserve all classes that have special context constructors, and the
# constructors themselves.

-keepclasseswithmembers class * {
public <init>(android.content.Context, android.util.AttributeSet);
}

# Preserve all classes that have special context constructors, and the
# constructors themselves.

-keepclasseswithmembers class * {
public <init>(android.content.Context, android.util.AttributeSet, int);
}

# Preserve the special fields of all Parcelable implementations.

-keepclassmembers class * implements android.os.Parcelable {
static android.os.Parcelable$Creator CREATOR;
}

# Preserve static fields of inner classes of R classes that might be accessed
# through introspection.

-keepclassmembers class **.R$* {
public static <fields>;
}

# Preserve the required interface from the License Verification Library
# (but don't nag the developer if the library is not used at all).

-keep public interface com.android.vending.licensing.ILicensingService

-dontnote com.android.vending.licensing.ILicensingService

# The Android Compatibility library references some classes that may not be
# present in all versions of the API, but we know that's ok.

-dontwarn android.support.**


# Preserve all native method names and the names of their classes.

-keepclasseswithmembernames class * {
native <methods>;
}

# Preserve the special static methods that are required in all enumeration
# classes.

-keepclassmembers class * extends java.lang.Enum {
public static **[] values();
public static ** valueOf(java.lang.String);
}

# Explicitly preserve all serialization members. The Serializable interface
# is only a marker interface, so it wouldn't save them.
# You can comment this out if your application doesn't use serialization.
# If your code contains serializable classes that have to be backward
# compatible, please refer to the manual.

-keepclassmembers class * implements java.io.Serializable {
static final long serialVersionUID;
static final java.io.ObjectStreamField[] serialPersistentFields;
private void writeObject(java.io.ObjectOutputStream);
private void readObject(java.io.ObjectInputStream);
java.lang.Object writeReplace();
java.lang.Object readResolve();
}

# Your application may contain more items that need to be preserved;
# typically classes that are dynamically created using Class.forName:

# -keep public class mypackage.MyClass
# -keep public interface mypackage.MyInterface
# -keep public class * implements mypackage.MyInterface

当然此文件是参照“..\sdk\tools\proguard\examples”下的android.pro修改而来,在此文件中添加自己不想做混淆的类和jar包等等信息,注意“#-repackageclasses ''”这句话我在混淆的时候给注释掉了,这样不会在生成好的jar根目录下搞出很多的a,b...等文件


6. 点击按钮,此时会看到如下界面

将自己引用的第三方jar文件及要混淆的classes文件通过按钮添加,然后通过按钮选择要导出的文件名(xxx.jar),注意:通过“Add input”选择的文件在上,“Add output”文件的选择在下!

7. 一切配置正常以后,可以直接选择此选项卡中的“Process”,出现如下界面


此时点击按钮,如果一切顺利的话,会在自己所选的"Add output"文件目录下生成自己想要的jar包!


最后祝大家混淆jar包成功!微笑




























































0
0

查看评论
* 以上用户言论只代表其个人观点,不代表CSDN网站的观点或立场
    个人资料
    • 访问:552次
    • 积分:24
    • 等级:
    • 排名:千里之外
    • 原创:2篇
    • 转载:0篇
    • 译文:0篇
    • 评论:0条
    文章分类
    文章存档