Sample report: check16k + the fix map, run on a public F-Droid app
This is what the kit’s workflow looks like end to end, on a real app, not a mocked example. We downloaded the arm64-v8a build of VLC for Android (version 3.7.1) straight from F-Droid’s own repo — F-Droid serves per-ABI APKs, not an AAB, since it builds and signs the APKs itself; this is the same checker run you’d do on your own .apk or .aab.
1. Download the app
curl -LO https://f-droid.org/repo/org.videolan.vlc_13070106.apk
shasum -a 256 org.videolan.vlc_13070106.apkExpected sha256 for the file we checked: 355ff246a0348c094a256926ea31cbec92701a2faca3d41d49170798c550ee3b. F-Droid serves this over HTTPS from its own repo; re-run the command yourself to get the current release.
2. Run the free checker
curl -LO https://android-16kb-fixmap.pages.dev/check16k.py
python3 check16k.py org.videolan.vlc_13070106.apkReal output:
ALIGNED p_align=2**14 lib/arm64-v8a/libc++_shared.so
ALIGNED p_align=2**14 lib/arm64-v8a/libmla.so
ALIGNED p_align=2**14 lib/arm64-v8a/libvlc.so
ALIGNED p_align=2**14 lib/arm64-v8a/libvlcjni.so
4 libs checked (ABIs: arm64-v8a), 0 unaligned
NOT CHECKED: RELRO segment alignment, AAB BundleConfig page alignment, runtime behavior.Exit code 0: every 64-bit native library in this build is 16 KB-aligned.
3. Cross-reference against the fix map
libvlc.so and libvlcjni.so come from libVLC (org.videolan.android:libvlc-all), a library in our measured dataset. We measured it as aligned from version 3.6.3; VLC for Android 3.7.1 bundles a build well past that boundary, so the checker’s ALIGNED result for those two files is consistent with our own measurement — two independent methods agreeing. libc++_shared.so is the standard NDK C++ runtime (not a tracked third-party SDK, but the checker reads it directly regardless). libmla.so is VLC’s own native code and isn’t one of our 80+ tracked libraries either — which is the point of running the checker on the actual build: it doesn’t need to recognize a library by name to measure its ELF alignment.
This app happened to come back clean. The library pages linked from the home page show real offending/fixed boundaries for the cases where an upgrade is actually needed.
The paid kit ($12, v2.1) contains the complete measured fix map for all 80+ libraries as JSON and a table, every raw per-version measurement, the spot-check evidence, and the CI checker. This page and the checker script stay free.
Get the kit ($12)Full refund within 14 days if the kit didn't help you find or fix your blocker, no questions — email us and we process it via Polar's Refunds API.