Android 16 KB fix map

SQLCipher (legacy android-database-sqlcipher) 16 KB page-size status: no aligned release found

Artifact net.zetetic:android-database-sqlcipher · measured 2026-10-01 · all libraries

no aligned release found

No measured release of SQLCipher (legacy android-database-sqlcipher) is 16 KB-aligned. The newest measured version, 4.5.4, is still offending.

Caveats

Measured evidence

VersionLibrary filep_alignFile dateSource
Last offending4.5.4jni/arm64-v8a/libsqlcipher.so4 KB (2^12)Thu, 27 Apr 2023 14:06:19 GMTartifact

p_align is the smallest PT_LOAD segment alignment of the ELF. 16 KB-compatible needs at least 16384 (2^14). Method: min PT_LOAD p_align of arm64-v8a/x86_64 .so inside the published AAR/JAR; aligned = >=16384 for every lib. Dates are repository file times, not official release dates.

Offending versions measured (6)

4.4.1, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4

Native libraries seen: libsqlcipher.so.

The Gradle change

no 16 KB-aligned release of net.zetetic:android-database-sqlcipher measured (latest measured 4.5.4); ask the vendor, check for a fork, or re-link the .so yourself; replacing is the last resort // NON-MONOTONE: an aligned release can be followed by an offending one; do not assume newer is safe. Per-release-line guidance: 4.x -> no aligned release measured after offending 4.5.4; 4.4.3 was aligned before the regression. Re-run the checker on the version you resolve

Confirm what Gradle actually resolves, since another dependency may pull an older version:

./gradlew :app:dependencyInsight --dependency android-database-sqlcipher --configuration releaseRuntimeClasspath

Re-verify it yourself

Download the artifact and run the free checker (check16k.py, Python 3, no dependencies):

curl -LO https://repo1.maven.org/maven2/net/zetetic/android-database-sqlcipher/4.5.4/android-database-sqlcipher-4.5.4.aar
python3 check16k.py android-database-sqlcipher-4.5.4.aar

Exit 0 = aligned, 1 = an unaligned library found. Better still, run it on your final .aab/.apk.

Need the full map for every library, not just SQLCipher (legacy android-database-sqlcipher)?

The paid kit ($12, v2) contains the complete measured fix map for all 80+ libraries as JSON and a table, every raw per-version measurement, the spot-check evidence, and the step-by-step guide for Play's 16 KB requirement. This page and the checker script stay free.

Get the kit ($12)

Related artifacts