# Core 0.12.10 — source and compilation instructions

This package accompanies the identified stock single-thread core, SHA-256
`9f57947a5bd530d8f00c5b3f2cb2a3492faa7e5d823315342d6a8656d0a6b7b7`,
with wrapper 0.12.15. Sources are preferred-form source archives, not binaries
or repository links alone. All source components, interfaces and controlling
scripts identified in the official release recipe are supplied here.

Byte-identical reproducibility is not a prerequisite asserted by this package.
Source correspondence is assessed using release identity, source/ref history,
actual binary configuration and component metadata, and the included C/JS
modifications. No new core was built during this investigation.

## Download and verify

Download distribution-manifest.json, prepare_sources.py, Dockerfile.locked and
Dockerfile.locked.CHANGES.txt to one directory. Download every source file linked
on this page into an `archives/` subdirectory, retaining its filename. Larger
archives use ordered .part0 and .part1 files; do not extract a part by itself.

With Python 3.12 or newer, run:

```sh
python prepare_sources.py --verify-only
```

This verifies each file and the reassembled archive hash without writing joined
archives into the download folder. Full notices are retained inside the source archives and are
provided separately under notices/ and in NOTICES.txt.

## Original build recipe

The ffmpeg.wasm archive at commit
`71aa99d37c02a7b4c435275ca9ef50e612f6efa1` supplies Dockerfile, Makefile,
build/*.sh, src/bind/ffmpeg/*, src/fftools/*, package manifests, wrapper
TypeScript and its interface files. The original production command is
`make prd`: single-thread, `-O3 -msimd128`. The core configure flags reported by
the actual stock binary are preserved in binary-runtime-inventory.json.

The original Docker build uses emscripten/emsdk:3.1.40 and GNU/POSIX build tools.
Its dependency recipe uses pkg-config, autoconf, automake, libtool, ragel, CMake,
make, gcc/g++, Python and Node. A prebuilt SDK supplies emcc/em++, emar/emranlib,
emnm, embuilder and emconfigure/emmake. The SDK installer source and exact
3.1.40 download manifest are included. Ordinary compiler/OS tools are not new
linked media libraries; linked SDK runtime sources and SDL are supplied.

The original recipes include the HarfBuzz pthread configure.ac adjustment,
FriBidi install fallback, static library commands, x265 multi-bit-depth archive
merge, and exact core compile/link/export scripts. These remain in the source.

## Build from the supplied source snapshots

To populate an entirely new directory, run:

```sh
python prepare_sources.py NEW_OUTPUT_DIRECTORY
```

The helper refuses to overwrite an existing directory. It verifies/reassembles
the archives, safely extracts them, and prepares a build directory containing
the unchanged upstream source and a Dockerfile adaptation using local source
copies. It does not install anything or run compilation. In a suitable Linux
Docker/Buildx environment:

```sh
cd NEW_OUTPUT_DIRECTORY/build
make prd
```

Expected outputs are packages/core/dist/esm/ffmpeg-core.js and .wasm, plus UMD
outputs. Preserve the generated code's license information and distribute the
preferred source if redistributing a changed core. Do not label a new build as
the original npm bytes when its hash differs.

Dockerfile.locked replaces source Git fetches with copies from the supplied
snapshots and supplies zimg's googletest submodule explicitly. It pins the
currently observed SDK image digest, which is a reconstruction aid rather than
an assertion about the historic stock image. It removes an unnecessary mutable
experimental Docker frontend directive. Compile, configure, link, binding and
export settings remain those of the release. The SDK SDL port's original
source hash stays fixed; its exact source zip is supplied in this package.

Docker/SDK and ordinary system packages may need installation or network access.
No claim is made that this build procedure has been executed or validated in the
current Windows environment. Lack of that execution is not itself evidence of
missing corresponding source. Additional logs/maps/attestations can improve
confidence and troubleshooting but are not imposed as independent source duties.

References: [release](https://github.com/ffmpegwasm/ffmpeg.wasm/releases/tag/v12.15),
[original build scripts](https://github.com/ffmpegwasm/ffmpeg.wasm/tree/71aa99d37c02a7b4c435275ca9ef50e612f6efa1/build),
[GNU FAQ on exact binary hashes](https://www.gnu.org/licenses/gpl-faq.html#MustSourceBuildToMatchExactHashOfBinary),
[GPLv2 section 3](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html).
