# Rebuilding and replacing libVLC 3.7.5-mango-lgpl.2

This guide applies to the separately loaded libVLC fallback covered by its
open-source licences. It does not grant rights in Mango Player's proprietary
code, content or marks. The exact inputs and hashes are listed in
`source-index.json` and `SHA256SUMS`.

## Rebuild

1. Download either ABI evidence archive and verify its SHA-256 hash.
2. Use the files in `artifacts/source/`. They contain the exact upstream
   archives, 20-patch manifest, effective patches, dependency source tarballs,
   build recipe, merge recipe, licence review and checksums used by CI run
   `30290562594`.
3. Rebuild ARM and ARM64 in equivalent Android NDK environments. The expected
   VLC base is `ac6c2a405d652b5576128ceb9fec2c342f0e83ec`; the patched tree is
   `22ea56034ab7fb6228dbb5dfe4c43a0e03f0a492`.
4. Apply `merge-aars.sh` to the two audited ABI AARs. The expected merged AAR
   SHA-256 is
   `4B54F457858443905EC46221A52D245823007F825B0C448CA2F23ACE3B166ADB`.

## Replace and test

The Android application loads libVLC as native shared libraries contained in
the AAR. To test a compatible modified build, unpack a test APK, replace the
matching `lib/<abi>/libvlc.so`, `libvlcjni.so` and `libc++_shared.so` payloads
while preserving their filenames and public ABI, then repack, zip-align and
sign that APK with a key controlled by the modifier. Android will not accept
it as an in-place update of a package signed with a different key.

Mango Player does not add a runtime libVLC hash check or another technical
restriction on replacement. Store variants exclude Jellyfin's GPL decoder;
the direct-download variant has its own separate legal gate.

The technical closure recorded here is not legal advice. An independent
FreeType/FTL opinion remains required before Mango declares the Store
distribution legally cleared. Questions: `legal@mangoplayer.app`.
