# OpusDesk Hub Tools — Video source materials

These are local distribution materials for the integrated Video editor and
its controlled FFmpeg replacement. Publish this entire directory alongside
the Video assets at `/licenses/materials/video-source/`. A link to upstream
alone is not this source distribution. No public Git repository is needed.

`MANIFEST.json` identifies every delivered file, its SHA-256 and size,
the 20 complete source archives, archive parts, build fingerprint,
replacement artifacts, readable frontend and dependency locks. Every
public file is at most 25 MiB. The two large source archives use numbered
parts; reconstruct and verify them before extraction. HTML source and
licence files have `.source.txt` appended to prevent execution/indexing;
the manifest records the original names and materialization restores them.

The replacement fingerprint is
`b83d6d535941df63c982d96701ae23a5aff38c5c9c99e5280d80a63dad54e5b0`.
The accepted ESM JS SHA-256 is
`d484cb3a6f2d2a833cf25b40bbbd136d7c7e46c15dbc3179afb0187b6113e108`.
The accepted WASM SHA-256 is
`fa8b08e6b5ee3e0e7cb7fd867a3c0aaa5ccf5654c8825aac4297636c310fb1f1`.
The WASM is 31,723,782 bytes; `artifacts/esm/` contains the four exact
8 MiB-or-smaller parts and their manifest. `build-evidence/` contains the
actual build manifest, configuration, compiler identity and bounded core
runtime probe. The historical npm WASM has a different hash; these materials
do not claim that its historical build has been reproduced.

`frontend/` is the readable, modified integrated editor source, configuration,
site content, assets and both unchanged dependency locks. It excludes
installed dependencies, generated output, test media, audit logs and private
configuration. `integration/` contains the original adaptation controller,
controlled build recipe, build controller, runtime probe and MediaInfo patch.
`dependencies/` contains exact-version installed metadata and original
notices for the two accepted installed dependency sets (107 and 912).
The full lock records also include optional platform packages. Most entries
in the original engine lock lack integrity and resolved URLs. The locks are
preserved honestly; registry reinstallation of those versions has not been
proven to reproduce the identical historical dependency files.

`mediainfo-sources/` contains the integrity-verified npm 0.3.2 package,
the full v0.3.2 release source pinned to commit
`8a9a9f2d3540261ea3bebdf8bcea1f0c443d55fa`, and the exact MediaInfoLib
24.06 and ZenLib 0.4.41 source archives named by that release's build recipe.
The installed WASM contains the MediaInfoLib 24.06 version string. Its
compiler version and compiler-provided zlib port revision are not established,
and no historical bit-identical MediaInfo WASM rebuild is claimed.
`interfaces/mediainfo-0.3.2/` includes the actual modified JS glue,
unmodified WASM, C++/TypeScript wrapper sources and original BSD notice.
Read `RIGHTS.md`, `BUILD.md` and `mediainfo-sources/release-evidence.json`.

This package verifies source/material correspondence for the new FFmpeg core.
Browser, export and product acceptance are separate root audit records;
these source materials are not themselves a deployment or release approval.

Run the portable local checks and materialize into a new, empty directory:

```powershell
node recipes/verify-public.mjs
node recipes/materialize.mjs C:/my-video-rebuild/Tools
```

The commands read only these local materials. The latter writes solely to
the explicitly named new directory and refuses an existing nonempty target.
