Files
Claude b52f5651de build: pin the Arti NDK and rebuild libarti_android.so on r27d
The committed libraries were built with NDK r25b (25.1.8937393) while the
build docs told everyone to install r27. Nothing pinned the NDK, so
build-arti.sh took the first directory matching ~/Android/Sdk/ndk/*/. The
NDK supplies the clang that compiles Arti's C dependencies (ring, zstd-sys,
libsqlite3-sys) and the lld that links the cdylib, so its revision is baked
into the output bytes exactly like rustc's is. The reproducible-build
promise therefore only held by accident of which NDK a verifier happened to
have installed.

- Pin the revision in ANDROID_NDK_VERSION (27.3.13750724, r27d) and resolve
  it by name. A different revision now fails the build with the sdkmanager
  line that fixes it, instead of silently producing unverifiable bytes.
- Record the verified cargo-ndk release in CARGO_NDK_VERSION. Warning only:
  it wraps the NDK rather than generating code.
- Re-read .note.android.ident after each build, so the output has to carry
  the pinned NDK's stamp to pass.
- Rebuild both ABIs on r27d (clang 18.0.4, lld 18.0.4, rustc 1.94.1).
  verify-reproducible.sh: two clean builds byte-for-byte identical, all 8
  JNI symbols exported, 16 KiB LOAD alignment kept, same libc/libm/libdl
  dependency set as before.
- Fix verify_jni_symbols reporting every exported symbol as missing: piping
  nm into `grep -q` per symbol lets grep exit first, nm dies of SIGPIPE, and
  `set -o pipefail` fails the pipeline. Pre-existing, reproduces on the old
  binary too.
- Docs: the 16 KiB page alignment comes from rustc's Android target spec,
  not from "NDK 25+".

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011cSuXeu4bUTNRAUCZJcLLW
2026-09-13 16:43:33 +00:00

2 lines
6 B
Plaintext