SQLCipher (legacy android-database-sqlcipher) 16 KB page-size status: no aligned release found
Artifact net.zetetic:android-database-sqlcipher · measured 2026-10-01 · all libraries
no aligned release found
No measured release of SQLCipher (legacy android-database-sqlcipher) is 16 KB-aligned. The newest measured version, 4.5.4, is still offending.
- Non-monotone history. An aligned stable release exists before a later offending one (parallel release lines or backports). A higher version number does not guarantee alignment: pick your exact version and measure it. The version below is only the lowest aligned stable version above the highest offending one.
- NON-MONOTONE: an aligned release can be followed by an offending one; do not assume newer is safe. Per-release-line guidance: 4.x -> no aligned release measured after offending 4.5.4; 4.4.3 was aligned before the regression. Re-run the checker on the version you resolve
- Sampled, not exhaustive: 19 of 31 published versions were measured with native code; unmeasured versions in between are unknown.
Measured evidence
| Version | Library file | p_align | File date | Source | |
|---|---|---|---|---|---|
| Last offending | 4.5.4 | jni/arm64-v8a/libsqlcipher.so | 4 KB (2^12) | Thu, 27 Apr 2023 14:06:19 GMT | artifact |
p_align is the smallest PT_LOAD segment alignment of the ELF. 16 KB-compatible needs at least 16384 (2^14). Method: min PT_LOAD p_align of arm64-v8a/x86_64 .so inside the published AAR/JAR; aligned = >=16384 for every lib. Dates are repository file times, not official release dates.
Offending versions measured (6)
4.4.1, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4
Native libraries seen: libsqlcipher.so.
The Gradle change
no 16 KB-aligned release of net.zetetic:android-database-sqlcipher measured (latest measured 4.5.4); ask the vendor, check for a fork, or re-link the .so yourself; replacing is the last resort // NON-MONOTONE: an aligned release can be followed by an offending one; do not assume newer is safe. Per-release-line guidance: 4.x -> no aligned release measured after offending 4.5.4; 4.4.3 was aligned before the regression. Re-run the checker on the version you resolve
Confirm what Gradle actually resolves, since another dependency may pull an older version:
./gradlew :app:dependencyInsight --dependency android-database-sqlcipher --configuration releaseRuntimeClasspathRe-verify it yourself
Download the artifact and run the free checker (check16k.py, Python 3, no dependencies):
curl -LO https://repo1.maven.org/maven2/net/zetetic/android-database-sqlcipher/4.5.4/android-database-sqlcipher-4.5.4.aar
python3 check16k.py android-database-sqlcipher-4.5.4.aarExit 0 = aligned, 1 = an unaligned library found. Better still, run it on your final .aab/.apk.
The paid kit ($12, v2) contains the complete measured fix map for all 80+ libraries as JSON and a table, every raw per-version measurement, the spot-check evidence, and the step-by-step guide for Play's 16 KB requirement. This page and the checker script stay free.
Get the kit ($12)Related artifacts
- SQLCipher (sqlcipher-android) (net.zetetic:sqlcipher-android)