Skip to content

Build Android with NDK r27c, api 29, 16 KB page alignment - #1

Merged
guiyanakuang merged 5 commits into
mainfrom
android-ndk-r27c-16kb
Aug 23, 2026
Merged

guiyanakuang merged 5 commits into
mainfrom
android-ndk-r27c-16kb

Conversation

@guiyanakuang

Copy link
Copy Markdown
Member

Prepares the Android libcrypto.so builds for bundling with CrossPaste mobile (pairing v3 SPAKE2 backend, mirroring the desktop bundling that consumes this fork's releases).

Profiles-only change — no workflow or recipe delta, keeping the provenance story identical to the 3.6.3 release: upstream build scripts + this fork's documented deviations.

  • android-ndk r20b → r27c (clang 18), the newest recipe available in the pinned conan-center-index. The upstream r20b pin exists for Kotlin/Native android-toolchain compatibility, which does not apply here (CrossPaste mobile consumes libcrypto from the JVM via JNA).
  • api_level 21 → 29, matching the mobile app's minSdk.
  • -Wl,-z,max-page-size=16384 via tools.build:sharedlinkflags (flows into the recipe's AutotoolsToolchain.ldflags): Google Play requires 16 KB page-size support for apps targeting Android 15+; NDK r27 supports 16 KB but does not default to it, and r28 is not in the pinned index. Harmless padding for 4 KB devices and the 32-bit ABI.

Verification plan (before attaching assets to the 3.6.3 release): llvm-readelf -l libcrypto.so LOAD segments aligned 0x4000; embedded version string OpenSSL 3.6.3; ecp_nistz256 symbols present on arm64; required EC_*/BN_* symbols exported; RFC 9382 suite green against the arm64 .so on a device/emulator.

https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX

…ste mobile libcrypto

Android joins the same one-run provenance chain that already feeds the
desktop (bare dylib/so/dll assets) and iOS (static libs in the aggregate
archive): profiles-only change, no workflow delta.

- android-ndk r20b -> r27c (clang 18), the newest recipe in the pinned
  conan-center-index. The r20b pin existed for Kotlin/Native android
  toolchain compatibility, which does not apply to CrossPaste mobile
  (JVM + JNA consumer).
- api_level 21 -> 29, matching the app's minSdk.
- -Wl,-z,max-page-size=16384 via tools.build:sharedlinkflags: Google Play
  requires 16 KB page-size support for apps targeting Android 15+; NDK r27
  supports it but does not default to it (r28 is not in the pinned index).

Claude-Session: https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX
…gets

The upstream-pinned recipe maps Android armv7/armv8 to linux-generic32/64,
which disables ALL assembly - silently dropping the ecp_nistz256
constant-time P-256 implementation the CrossPaste pairing v3 backend is
reviewed against (found during 3.6.3 android verification: no armcap/asm
markers in the .so). The fork commit maps them to linux-armv4 /
linux-aarch64, the same asm-enabled targets the desktop linux builds use.

Claude-Session: https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX
@guiyanakuang

Copy link
Copy Markdown
Member Author

Verification of the first 3.6.3 run caught a blocker: the Android builds had NO assembly at all.

The arm64 libcrypto.so.3 from run 32578352006 passed 16 KB LOAD alignment (0x4000 ✔), version string ✔, and all 22 JNA-required symbols ✔ — but contained zero ecp_nistz256 / OPENSSL_armcap / aes_v8 markers. Root cause: the pinned conan recipe maps Android-armv7/armv8 to linux-generic32/64 (a 2018-era workaround citing openssl/openssl#7398), which builds with no-asm — silently dropping the constant-time P-256 assembly the pairing v3 backend's review premise rests on.

Fix (second commit): the submodule now points at the org fork CrossPaste/conan-center-index @ c846006b, whose only change maps Android-armv7 → linux-armv4 and Android-armv8 → linux-aarch64 — the same asm-enabled targets the desktop linux builds use (the desktop linux-arm64 release asset has 37 ecp_nistz256 symbols). The ARM asm modules are OS-agnostic ELF, and bionic supports the getauxval-based OPENSSL_armcap runtime detection.

Rebuild triggered: run 32579106526. Will re-verify alignment + asm markers + symbols on its artifacts before attaching anything to the 3.6.3 release.

https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX

…ctually used

Verification round 2 showed byte-identical Android artifacts: conan install
resolves the openssl recipe from the floating conancenter remote, so the
submodule pin (and its Android asm-target fix) never took effect. Add a
'conan export conan-center-index/recipes/openssl/3.x.x' step to every job
before the installs - the local cache then takes precedence, pinning recipe
provenance to the submodule's git SHA for all platforms.

Applied in build.main.kts and the generated build.yaml (same convention as
the vs_version fix).

Claude-Session: https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX
Run 3 failed with KeyError: '3.6.3' in source() - the vendored conandata
predates 3.6.3 and only worked before because the recipe silently came
from the floating conancenter remote.

Claude-Session: https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX
The 3.6.3 iOS static libs (and the upstream whyoleg prebuilt 0.6.0 the
mobile app currently ships) contain zero ecp_nistz256/armcap markers:
iphoneos-cross is a no-asm generic target. The pinned recipe now maps
iOS/armv8 by os.sdk to ios64-xcrun / iossimulator-arm64-xcrun.

Claude-Session: https://claude.ai/code/session_019wycxR1g64gXPsgaQeFAaX
@guiyanakuang
guiyanakuang merged commit 5425a33 into main Aug 23, 2026
5 checks passed
@guiyanakuang
guiyanakuang deleted the android-ndk-r27c-16kb branch August 23, 2026 06:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant