#!/bin/sh
# Build the separate FFmpeg/ffprobe executables OverCue ships.  No GPL,
# nonfree, or third-party codec components are enabled.
set -eu

here=$(cd "$(dirname "$0")" && pwd)
source_archive="$here/vendor/ffmpeg/ffmpeg-7.0.tar.xz"
[ -f "$source_archive" ] || source_archive="$here/ffmpeg-7.0.tar.xz"
source_sha256=4426a94dd2c814945456600c8adfc402bee65ec14a70e8c531ec9a2cd651da7b
output=${1:?usage: build-ffmpeg-lgpl.sh OUTPUT_DIR}
deployment_target=14.0
# Sources compile their own absolute path in as __FILE__, and that cannot be
# remapped without putting the build path into `ffmpeg -buildconf` instead.  So
# build under a fixed location that names neither the user nor the repository.
work=${OVERCUE_FFMPEG_WORK:-/tmp/overcue-ffmpeg-7.0-build}
source="$work/ffmpeg-7.0"
jobs=$(/usr/sbin/sysctl -n hw.ncpu)

[ -f "$source_archive" ] || {
    echo "FFmpeg 7.0 source archive is missing" >&2
    exit 1
}
[ "$(/usr/bin/shasum -a 256 "$source_archive" | /usr/bin/awk '{print $1}')" = "$source_sha256" ] || {
    echo "FFmpeg 7.0 source archive failed verification" >&2
    exit 1
}

/bin/rm -rf "$output" "$work"
/bin/mkdir -p "$work"
/usr/bin/tar -xf "$source_archive" -C "$work"

build_one()
{
    arch=$1
    cc="clang -arch $arch -mmacosx-version-min=$deployment_target"
    extra=
    [ "$arch" != x86_64 ] || extra=--disable-x86asm

    build="$work/$arch"
    install="$output/$arch"
    log="$output/build-$arch.log"
    # configure records --prefix verbatim in `ffmpeg -buildconf`, which any user
    # can run, so it must not name this machine.  Build against a neutral prefix
    # and redirect the actual install with DESTDIR.
    prefix=/opt/overcue/ffmpeg-7.0
    /bin/mkdir -p "$build" "$install"
    cd "$build"
    "$source/configure" \
        --prefix="$prefix" \
        --arch="$arch" \
        --cc="$cc" \
        --extra-ldflags="-arch $arch -mmacosx-version-min=$deployment_target" \
        --disable-gpl \
        --disable-nonfree \
        --disable-autodetect \
        --disable-doc \
        --disable-debug \
        --disable-ffplay \
        --disable-network \
        --disable-devices \
        --enable-static \
        --disable-shared \
        $extra >"$log" 2>&1 || { /usr/bin/tail -100 "$log" >&2; exit 1; }
    /usr/bin/make -s -j"$jobs" >>"$log" 2>&1 || {
        /usr/bin/tail -100 "$log" >&2; exit 1;
    }
    /usr/bin/make -s install DESTDIR="$build/stage" >>"$log" 2>&1 || {
        /usr/bin/tail -100 "$log" >&2; exit 1;
    }
    /bin/cp -R "$build/stage$prefix/." "$install/"
    "$install/bin/ffmpeg" -buildconf 2>&1 | /usr/bin/grep -q -- --disable-gpl
    "$install/bin/ffmpeg" -buildconf 2>&1 | /usr/bin/grep -q -- --disable-nonfree
    ! "$install/bin/ffmpeg" -buildconf 2>&1 | /usr/bin/grep -q -- --enable-gpl
    ! "$install/bin/ffmpeg" -buildconf 2>&1 | /usr/bin/grep -q -- --enable-nonfree
}

build_one arm64
build_one x86_64

/bin/cp "$source/COPYING.LGPLv2.1" "$output/COPYING.LGPLv2.1"
# The complete corresponding source travels with the binaries, so the LGPL
# offer holds with no network and no website.
/bin/cp "$source_archive" "$output/ffmpeg-7.0.tar.xz"
/bin/cp "$here/build-ffmpeg-lgpl.sh" "$output/ffmpeg-7.0-overcue-build.sh"
{
    echo 'FFmpeg 7.0 — OverCue LGPL-only build'
    echo
    echo 'The complete corresponding source for these executables is included'
    echo 'beside them in this app, so nothing needs to be downloaded:'
    echo
    echo '  MediaTools/ffmpeg-7.0.tar.xz            unmodified FFmpeg 7.0 source'
    echo '  MediaTools/ffmpeg-7.0-overcue-build.sh  the exact script that built them'
    echo '  MediaTools/COPYING.LGPLv2.1             the full licence'
    echo
    echo "Source SHA-256: $source_sha256"
    echo 'No source changes were made.'
    echo
    echo 'The same files are also published at https://overcue.gg/source/ .'
    echo
    echo 'The exact configure command is recorded by each executable:'
    echo '  ffmpeg -buildconf'
    echo
    echo 'Both builds explicitly use --disable-gpl and --disable-nonfree.'
} > "$output/BUILD-AND-SOURCE.txt"

echo "$output"
