# Rebuilding and replacing libVLC 3.7.5-mango-lgpl.3

This guide applies to the separately loaded libVLC fallback covered by its
open-source licences. It does not grant rights in Mango Player's proprietary
code, content or marks. The exact files and hashes are recorded in
`source-index.json`, `ARTIFACT-MANIFEST.json` and `SHA256SUMS`.

## Verify and rebuild

1. Download the ARM, ARM64 and Maven archives named in `SHA256SUMS`, and verify
   all three SHA-256 hashes. All three archives came from CI run
   `35812920709`, attempt `2`, recipe commit
   `8ee9e9bf9337c34667d01ffd47f20dcd05b5d95d`.
2. Extract the ABI archives. Each `ci-work-<abi>/artifacts/source/` directory
   contains the corresponding upstream and patched sources, dependency source
   tarballs, patch inputs, the build and merge recipes, licence review and
   `SHA256SUMS`. The `artifacts/link-evidence/` directory contains native
   relink objects and its own checksums. Build logs, toolchain provenance,
   licence reports and final-link reports are in the same ABI archive.
3. Follow `source/build.sh` and `source/merge-aars.sh` in an equivalent
   Android NDK environment. The reference VLC base is
   `ac6c2a405d652b5576128ceb9fec2c342f0e83ec`; the patched runtime HEAD
   and tree are `f2a151edf8a532c6c2421ed6b86ab9a0f517f3e7` and
   `22ea56034ab7fb6228dbb5dfe4c43a0e03f0a492`.
4. Compare the result with the reference AAR in the Maven archive. Its
   SHA-256 is `92ca13944cd2c5f65859225600116cab329c207126271a4a51f436a4655e0d34`.
   The Maven archive also contains the POM and Java sources JAR.

The release build enables `NDEBUG` in the effective FFmpeg configuration.
The independent audit found no active `__assert2` import in `libvlc.so` or
`libvlcjni.so` on either ABI. The prebuilt ARMv7 NDK
`libc++_shared.so` still imports `__assert2`; this is separately recorded in
the merged evidence archive and is not a claim that every native object is
assertion-free.

## Replace and test

The Android application loads libVLC as native shared libraries in the AAR.
To test a compatible modified build, unpack a test APK, replace the matching
`lib/<abi>/libvlc.so`, `libvlcjni.so` and `libc++_shared.so` payloads while
preserving their filenames and public ABI, then repack, zip-align and sign
the APK with a key controlled by the modifier. Android will not accept that
APK as an in-place update of a package signed with a different key.

The technical closure recorded here is not legal advice. An independent
FreeType/FTL opinion remains required before Mango declares the Store
distribution legally cleared. Questions: `legal@mangoplayer.app`.
