diff --git a/REPRODUCIBLE_BUILD.md b/REPRODUCIBLE_BUILD.md index 7832595..bc82a32 100644 --- a/REPRODUCIBLE_BUILD.md +++ b/REPRODUCIBLE_BUILD.md @@ -162,3 +162,13 @@ Notes: - F-Droid will build from source and **re-sign** the APK. - For reproducibility checks, compare the **unsigned** APK generated by the build step above (same source revision + same pinned toolchain). + +## Why host hashes can differ from Docker + +It is normal for a **host build** (e.g. macOS) to produce a different APK hash than the **Docker proof** (Linux), even when both are reproducible **within their own environments**. Reproducibility here means: + +- **Same inputs + same toolchain + same environment** → identical output. + +The host and Docker proofs use **different environments** (OS, Java runtime, Android toolchain, filesystem behavior), so their outputs can legitimately differ while still being deterministic. + +If you need host and Docker hashes to match, you must align the environment as closely as possible (e.g. use **JDK 17** locally and build on the same OS/toolchain). Even then, cross‑OS builds can still differ, which is why the Docker proof is the preferred reference.