# Local build and replacement instructions

Use a private new working directory. Do not run build scripts inside a live
site, the original application, the source distribution directory, or a
directory containing personal files. These instructions do not publish,
deploy, purchase services, or access a VPS. Node 24 and local Docker are
needed for the controlled FFmpeg build. Sufficient disk space for compiler
images and build volumes is required.

## Verify and restore the recorded workspace

Download the complete materials directory, keeping its relative paths.
Run `node recipes/verify-public.mjs`, then:

```powershell
node recipes/materialize.mjs C:/my-video-rebuild/Tools
```

Materialization preserves original source names, reconstructs the 20 source
archives and the recorded WASM, verifies every chunk and assembled hash,
restores the controlled controllers/recipes, and writes the two application
lockfiles plus the exact adapter-tool lockfile into the new workspace.
It does not install packages or launch Docker.

## Rebuild FFmpeg

From the newly materialized `Tools` directory:

```powershell
node scripts/rebuild-video.mjs --build
```

This is the exact supplied controller and `controlled-build.sh`. It verifies
the 20 frozen archives, uses base image
`emscripten/emsdk@sha256:c1e807a6e03ac5bd5b37bae2ace3c46c08579e2ddeb951037a3b8dac7067f2cc`
(Emscripten 3.1.40), and records the derived compiler image ID. The accepted
derived compiler ID is
`sha256:58916c5df89deaeb8da4ff0ffb82d1df622e051c0aed043f94844ef2fd22bd79`.
The original Dockerfile installs pkg-config, autoconf, automake, libtool,
ragel and unzip using apt. Those package repository versions were not pinned
individually: a newly derived image may differ and gets a new recorded
fingerprint. No bit-for-bit compiler reconstruction is promised.

The initial compiler image preparation can download public compiler/build
packages. The actual source compiler container has no network or host
secrets, a read-only input mount, two CPUs, 3500 MB memory, 256 process slots,
two build jobs and a 90 minute bound. It retains labelled build/cache volumes
and checkpoints. Read the complete `integrations/video-rebuild/REBUILD.md`
and actual `controlled-build.sh` for library order and all compile/link flags.
Do not replace its static pkg-config flag, generated zlib.pc installation,
SDL local-port override or resource bounds without revalidating the result.

The build creates ESM and UMD JS/WASM pairs and a build manifest. Run:

```powershell
node integrations/video-rebuild/runtime-probe.mjs <output-directory>
```

Use the directory recorded by the new `audit/video-rebuild.json`. The probe
checks licence/version/configuration, features, real H.264 encode/decode and
decoded byte count. Application acceptance is still separate.

## Compile the supplied readable Video application

Use only the materialized workspace. Install the exact locks there with
`npm ci --ignore-scripts --no-audit --no-fund` in each of:

- `baseline/utility` (the three fixed AST/HTML parser packages)
- `integrations/video-app/source`
- `integrations/video-app/source/omniclip-main`

The original engine lock lacks integrity fields for most packages. Its
specific versions and published notices are preserved; registry reinstall
of the entire historical closure has not been independently proven.
Do not claim that this installation step was acceptance-tested merely
because the original copied installed tree passed the project audit.

Copy the newly built ESM `ffmpeg-core.js` and `ffmpeg-core.wasm` to
`integrations/video-app/source/node_modules/@ffmpeg/core/dist/esm/`.
The retained `@ffmpeg/core` npm metadata says 0.12.5; the two files in this
directory are deliberately replaced by the controlled source build.
Use the supplied readable MediaInfo static adapter on newly installed glue:

```powershell
node integrations/video-app/patch-mediainfo.mjs
```

Then, from `integrations/video-app/source`:

```powershell
node scripts/build-brand-assets.mjs
node scripts/build-engine.mjs
node scripts/build-dist.mjs --production
```

This compiles TypeScript, traces the actual ESM dependency graph, emits the
browser JS, and splits the chosen core WASM into <=8 MiB parts with SHA-256
checks. The complete integrated `/video/` prefix adaptation recipe is in
`integration/scripts/adapt-video.mjs`; `recipes/prefix-output.mjs` applies
its HTML/CSS route rewrite and service-worker exclusion to your private
new `dist/` without requiring an original checkout or production assets.
From the materials directory, run:

```powershell
node recipes/prefix-output.mjs C:/my-video-rebuild/Tools
```

Its output is `Tools/staged-apps/video`. Apply the site's scoped CSP/headers
when hosting your private copy and run the complete Video browser/export
acceptance before distributing that new output. The unchanged screenshot
source supplied here is the existing real editor capture; the original
adaptation controller documents how to produce a new browser screenshot.

## Modify, relink or replace libraries

Extract the desired complete frozen library archive and edit its preferred
source. Update the matching private archive and its SHA-256 in the private
`audit/video-source-bundle.json`; keep the original copyright notices and
record your modifications. The controller derives a new fingerprint when
inputs/recipe/compiler identity change, so it cannot reuse incompatible
old checkpoints. Modify the library build/link flags in the readable
`controlled-build.sh` when needed, then rebuild and run the runtime probe.
Install the new core into your private app dependency directory and rebuild
the application as above; its chunk loader regenerates and verifies your
new manifest. GPL/LGPL-covered modifications and their source/build material
must accompany any redistributed new covered output under the applicable
licence. Use a new artifact/source audit and do not reuse the accepted hashes.

For an unchanged recorded WASM, join the local supplied parts using:

```powershell
node recipes/join-wasm.mjs <manifest-file> <new-wasm-file>
```

The command checks each part and the final length/hash, and refuses to
overwrite an existing output. It is not an authorization to modify a live
site. No package here forces use of the original core or forbids users from
changing the readable loader/manifest and running their modified build.

## MediaInfo native source

The exact 0.3.2 `gulp/constants.ts` chooses MediaInfoLib 24.06 and ZenLib
0.4.41. `gulp/compile/` contains the configure, compile, link and WASM
optimization flags; the full release archive includes the original pnpm
lock and `packageManager: pnpm@9.1.2`. Place the supplied `.tar.bz2` files
into the release's `build/vendor/` so its download task reuses them.
Its upstream build also needs Emscripten, autoconf/automake/libtool,
wasm-objdump, wasm-metadce and wasm-opt. The release did not pin the
historical compiler or zlib port revision. A native rebuild is therefore a
new build requiring its own verification, not a claim to reproduce the
shipped WASM. This BSD release has no LGPL election; its full original
notices and default licence are retained regardless of this limitation.
