Repository navigation
Compile SQLite from a vendored amalgamation instead of downloading it - #99
Merged
Merged
Conversation
package:sqlite3's build hook downloads a prebuilt libsqlite3.so per ABI from its GitHub releases unless told otherwise, and that binary is what the APK shipped. F-Droid requires native libraries built from source; a maintainer confirmed it applies here (fdroiddata!47901). Because the published APKs are verified against F-Droid's build, compiling only in the recipe would break that match, so the copy lives here and the release build compiles it too. third_party/sqlite3 holds the unmodified 3.53.4 amalgamation, checked against the SHA3-256 sqlite.org publishes, and pubspec.yaml points the hook at it with the default compile options left on. 3.53.4 is also what package:sqlite3 3.7.0 ships prebuilt, so SQLite itself does not change. Bumping package:sqlite3 no longer moves the SQLite version, so tool/update_sqlite.sh takes the current release off sqlite.org, refuses an archive that does not match the published hash, and rewrites the provenance block in the README. Tested end to end against a copy whose version was wound back. Measured: two cold release builds give byte-identical APKs, and the library carries no GNU build ID and no embedded path, so the verified builds need no extra flag. It is compiled with the NDK the app pins (r28c, as the recipe does). Cost: 10-22 KB per ABI, and about a minute on a cold build (198 s against 139 s); the hook caches the result. A new CI step fails an Android build that downloads SQLite again. Supersedes #45, whose branch predates 57 commits on main and argued that F-Droid would probably not mind. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This was referenced Oct 4, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
F-Droid requires native libraries to be built from source, and a maintainer confirmed on fdroiddata!47901 that this applies to the
libsqlite3.sothatpackage:sqlite3's build hook downloads from GitHub. Because our published APKs are verified against F-Droid's build, the release build has to compile SQLite too, so the source lives here.What changes
third_party/sqlite3/: the unmodified SQLite 3.53.4 amalgamation (sqlite3.c,sqlite3.h), checked against the SHA3-256 sqlite.org publishes. 3.53.4 is also whatpackage:sqlite33.7.0 ships prebuilt, so SQLite itself does not change.pubspec.yaml:hooks.user_defines.sqlite3withsource: source, default compile options left on.tool/update_sqlite.sh: takes the current release off sqlite.org, refuses an archive that does not match the published hash, replaces the two files, and rewrites the provenance block in the README. Needed because bumpingpackage:sqlite3no longer moves the SQLite version, and Dependabot cannot see the vendored copy..gitattributesmarksthird_party/**as vendored, so GitHub's language statistics are not dominated by 9 MB of C.Measured
flutter cleaneach time) produce byte-identical APKs for all three ABIs.libdartjni.sonon-reproducible, so no extra linker flag is needed.main). The hook runner caches the result, so incremental builds pay nothing.mainbuilds create threedownload-*directories under.dart_tool/hooks_runner; this branch creates none, which is what the CI step checks.flutter test(1606 tests),flutter analyze,dart format: all pass. The host library used by the tests is compiled from the vendored copy too.tool/update_sqlite.shtested end to end against a copy whose version was wound back to 3.53.3: it restored both files and the README block byte for byte.Not yet verified
The Linux and Windows builds now compile SQLite as well. Linux is covered by the tests above; Windows can only be checked by this PR's CI.
After merging
A new release (the reviewer asked for a new tag so the reference APKs match), then the F-Droid recipe is updated and all three ABIs are re-verified with
fdroid buildbefore pushing to the MR.Supersedes #45, whose branch predates 57 commits on
mainand argued that F-Droid would probably not mind.🤖 Generated with Claude Code