# Filester v3.3.1-foss reproducibility diagnostic (issue #71)

Rebuilt from source at tag f07acd0543f3157dee0ac48437642f0efcb006be in a clean container (Ubuntu, JDK 17, Android SDK platform 37.0, build-tools 35.0.0, Gradle 9.4.1 wrapper, AGP 9.2.1, Kotlin 2.3.10).

## Result
- Two independent rebuilds (different source paths) produced **byte-identical** classes.dex:
  SHA256 623565d80e4d9611ae99c4c3643e612b059479963b1099624837fd40fe1a414a
- Official APK classes.dex: a5bb8951a818c36094e61a8eb841f53ca0b4fbd7254fd7370606c06c3ca0efe9

## Root-cause analysis of the dex diff
- Parsed both dex files directly: identical section counts (15746 strings, 5122 types, 5889 protos, 13910 fields, 22891 methods, 4044 classes).
- 22,878 of 22,891 method names match position-for-position. All 13 mismatches are R8-synthetic hash names (e.g. `143840814292239a4` vs `5fb25a84d93e286ba`). No real code differences at identifier level.
- R8 synthetic-name hashing depends on the compiler version / environment. The original release was built with a slightly different toolchain than a from-scratch rebuild resolves today. The issue-71 diff (baseline.prof 1 byte, classes.dex 4 bytes) is downstream: baseline.prof embeds dex checksums.

## Recommendation
The build itself is deterministic (same input = same output). To reproduce the official APK bit-for-bit, build on the maintainer's exact CI image (same JDK, same AGP/R8 patch version). Pinning the JDK via Gradle toolchains and CI image digest would lock this in.

*This analysis was produced by an automated software agent; full environment details above so you can verify independently.*
