Audio Studio browser core r1: slim1 source delivery, build and relink materials STATUS AND SCOPE Runtime component: audio-studio-core-r1-e49d84d7c280 (unchanged). Source delivery: audio-studio-core-source-r1-slim1. Download filename: audio-studio-core-source-r1-slim1.tar.gz. Extraction root remains audio-studio-core-source-r1/. This isolated slim1 delivery omits only Emscripten test/third_party/ and site/. The actual driver, src/, tools/, third_party/, system runtime sources/headers, docs/, test/hello_world.c and every other Emscripten member are preserved. The upstream end-user installer itself excludes those two omitted trees. Its root licence, original notices and all retained file bytes, modes, types, links and effective metadata remain unchanged. Archive representation may use PAX long-path fields where the original used GNU long-name fields. A later clean bootstrap, fresh runtime-cache compilation, complete LAME/Opus/ FFmpeg/core build and static-library relink succeeded from this pruned delivery. The rebuilt WASM was exercised in Node with worker globals and the existing product processor on nine MP4/MOV/WebM formats. Native FFmpeg independently verified copied video packet bytes, decoded picture pixels and complete decode. See receipts/conservative-source-validation.json for this later validation. This media check did not repeat browser-worker cancellation tests or paid API processing. The published runtime bytes and runtime identity remain unchanged. sources.json and the archival derivation receipt preserve their original cleanBuildFromPrunedDeliveryVerified=false fields from candidate creation. They have not been rewritten as later claims; the dated validation receipt above records the later successful clean build, relink and rebuilt-core media checks. Its sourceManifestSha256 identifies those exact archived input locks. The initial source build succeeded. Reference output hashes are in expected-artifacts.json and the redacted producer receipt is in receipts/initial-source-build.json. A relocated clean rebuild from this slim1 source delivery succeeded; its output hashes differ from the published historical runtime. Source availability, successful rebuilding and byte-for-byte binary reproducibility are different claims. Binary byte-for-byte reproducibility remains unverified (false). Relocation changes recorded build paths and may change the binary's embedded configure text. Modified builds normally have different hashes. This package supplies six locked build-source inputs: FFmpeg n5.1.4, ffmpeg.wasm bindings/tool overrides at 71aa99d3, LAME at 2badea19, the official Opus 1.3.1 source release, Emscripten 3.1.40 at 5c27e79d with those two unused trees excluded (including all musl, compiler-rt and C++ runtime sources), and pkgconf 2.2.0. Their original notices, file-level licenses and documentation remain inside archives/. License copies are in licenses/. sources.json fixes their provenance, full commits and SHA256 values. The Emscripten upstream record separately retains the original URL, size, SHA256 and commit. Its archive field locks the derived input, not the original upstream archive. Derivation script, exclusion policy, retained-member digest and exact removed-member inventory are locked in sources.json and provenance/. The complete inventory is a compressed JSON file, emscripten-prune-members.json.gz, with fixed gzip metadata; its exact compressed bytes are also integrity-locked. No x264, x265, SDL, VPX or other unused external encoder is linked into this core. Test-only Git submodules from ffmpeg.wasm and Emscripten are not build inputs. HOST PREREQUISITES The operational bootstrap is for macOS on Apple Silicon (arm64), with Apple Command Line Tools already available: native cc, make, curl and Python 3.9+. The bootstrap does not install system software. Run from a user-writable folder with several GB of free disk space. Choose a build work directory without whitespace for the upstream configure/make tools. The LLVM/Binaryen tool SDK is fetched from the official Emscripten release URL and verified by its locked SHA256. It is approximately 340 MB. Native Node 22.23.1 is fetched from nodejs.org using its published SHA256, unless --node selects an existing native installation of exactly that version with sibling npm. No Rosetta, Docker, autoconf, automake, cmake or ragel installation is needed. The supplied Opus release and pkgconf source have generated configure files. These compiler tools are standard build tools downloaded separately. The SDK's precompiled Emscripten runtime cache is not used: the emcc driver and runtime sources come from the bundled fixed source archive; EM_CACHE points to a new local cache, FROZEN_CACHE is disabled, and needed runtime libraries are compiled from those sources. Emscripten JavaScript build dependencies are installed from its original package-lock.json using npm ci --ignore-scripts --omit=dev. The bootstrap uses empty local npm configuration files; no product accounts, .env files, R2, Replicate or paid services are involved. OFFLINE CHECK OF A DOWNLOADED SOURCE BUNDLE After extracting this tar.gz, change into its audio-studio-core-source-r1 folder: python3 scripts/bootstrap.py --self-check This checks the six archived source hashes, extraction paths, binding patch and Emscripten derivation/script/receipt/member-inventory locks. It performs no downloads or compilation. It does not establish repeat-build reproducibility. BUILD FROM CLEAN SOURCES From the package root: python3 scripts/bootstrap.py --work-dir ./work python3 scripts/build-core.py --work-dir ./work python3 scripts/compare-artifacts.py --output-dir ./work/output The bootstrap downloads/verifies standard compiler tools, extracts the clean source archives, builds native pkgconf in work/host-tools, configures the fixed Emscripten driver, and compiles/runs a small smoke test with a new runtime cache. Then build-core.py builds LAME, Opus, FFmpeg and finally the ESM core. Generated outputs are work/output/ffmpeg-core.js and work/output/ffmpeg-core.wasm. Logs, configure/link arguments and fresh build receipts remain under work/. --work-dir can be another empty directory without whitespace. The scripts compute paths after extraction; they contain no producer-machine path. They do not delete unrelated files. Use a new directory if a bootstrap failed partway through runtime compilation. To extract source only before inspection: python3 scripts/bootstrap.py --prepare-only --work-dir ./inspection The prepared inspection folder can subsequently be bootstrapped normally with the same --work-dir. Existing downloaded SDK archives may be reused while still requiring the exact SHA256: python3 scripts/bootstrap.py --work-dir ./work --sdk-archive /path/to/wasm-binaries-arm64.tbz2 --node /path/to/node BUILD DETAILS AND MODIFICATION build-core.py is adapted from the successful producer build recipe. It enables native audio decoders, H.264/VP8/VP9 metadata/decoding, MOV/MP4 and Matroska/WebM inputs, MP3 audio, AAC/MP3/Opus output, and the audio filters used by the product. GPL-only, version3 and nonfree FFmpeg features are disabled. Exact flags are in the script and producer receipt. The browser core is single-threaded with WASM SIMD, 32 MB initial memory and memory growth. It needs no SDL graphics port. The source-level ffprobe return-value patch is applied during the final link. patches/ffprobe-return-value.patch and patches/patched-bind.js give the diff and the entire modified binding source, with original/patched hashes in patches/binding-patch.json. The build copies upstream src/fftools overrides from the pinned ffmpeg.wasm archive. It does not patch minified generated JavaScript. You may inspect and modify the extracted source files and rebuild. For example, a change to FFmpeg sources can be compiled and linked using: python3 scripts/build-core.py --work-dir ./work ffmpeg link To rebuild modified LAME/Opus as well: python3 scripts/build-core.py --work-dir ./work libraries ffmpeg link Do not assume a cache compiled from one modified Emscripten source tree is valid for another. Use a new clean bootstrap/workspace when changing runtime sources. This recipe sets SOURCE_DATE_EPOCH; byte-for-byte repeat-build equivalence still has to be measured, rather than inferred from fixed inputs. RELINK WITH REPLACEMENT LIBRARIES A complete build retains the FFmpeg .a libraries, other .a libraries, tool C sources and link arguments. No proprietary object is needed to relink this core. Replacement static archives must be compiled for wasm32 with a compatible Emscripten toolchain. The helper preserves the original work/output files: python3 scripts/relink.py --work-dir ./work --library mp3lame=/path/to/libmp3lame.a --library opus=/path/to/libopus.a You may similarly replace avcodec, avfilter, avformat, avutil or swresample. New outputs and a relink receipt are written to work/relinked/. Running without --library simply links the current prepared objects again. To change tool or binding source, modify it and run the relevant normal build/link phase instead. To use a modified result in a copy of the application, replace both core files as a matched pair and update that copy's asset integrity lock/preparation metadata. A digest mismatch is expected after modification; do not disguise a modified binary with the producer's old hashes. This source material does not remove users' rights to modify or replace LGPL-covered libraries. RECREATE THE SOURCE DELIVERY AFTER A FRESH GIT CHECKOUT A checkout may track only the small materials and ignore source/archive blobs. All missing build-source archives can be recovered explicitly from locked URLs. For Emscripten, the fetcher downloads and verifies the exact full upstream input in a temporary host directory, runs the locked pruning script, and verifies the exact derived size/SHA256 before accepting it. The temporary full upstream input is removed on success or failure; no persistent full archive is created beneath the delivery or a live public asset tree. An explicitly provided exact original at .upstream-cache/ is supported as read-only offline input; an invalid cache is rejected. The cache is not automatically populated or included in the delivery. All other archives remain byte-identical to their fixed snapshots. The excluded Emscripten third-party tests and website are not needed for this product-core build. To run/rebuild the complete upstream Emscripten test suite or website, recover the original full archive using the separately preserved upstream URL and SHA256; the slim1 delivery does not contain those excluded trees. Only test/third_party/ and site/ are excluded. Do not delete the whole test/ or docs/ trees: emcc --cflags uses test/hello_world.c and --help uses docs/emcc.txt. FFmpeg's Makefile also includes test/documentation Makefiles even when the corresponding build targets are disabled; this delivery does not prune FFmpeg. Derived inner-gzip headers have fixed mtime and no filename, but gzip compression uses Python 3.9.6 / zlib 1.2.12 in this producer environment. Identical output across other compression implementations has not been verified. Fresh recovery must reproduce the recorded derived SHA256; any difference stops recovery. It never accepts a new hash silently. A received complete source delivery already includes the locked derived archive, so self-check/bootstrap needs no derivation or matching compressor when that archive is present. Run: python3 scripts/fetch-inputs.py python3 scripts/package-source.py --output ./audio-studio-core-source-r1-slim1.tar.gz Or combine recovery and packaging: python3 scripts/package-source.py --fetch-missing --output ./audio-studio-core-source-r1-slim1.tar.gz Packaging verifies the source and derivation locks and fixes outer gzip/tar timestamps, ownership, permissions and file ordering. The same input archive and material bytes produce the same delivery bytes. Gzip stored blocks avoid a dependency on a particular zlib compression implementation. This packaging property is independently testable and is not a claim that FFmpeg compilation itself is reproducible. A changed upstream archive that no longer matches its locked SHA256 is rejected, even if the URL or tag name is unchanged. Keep the published delivery available while its core is being distributed; a generic upstream homepage is not its source download.