# FFmpegKit Android LGPL — rebuild and replacement

This directory accompanies the exact Maven coordinate
`app.mangoplayer.native:ffmpeg-kit-mango-lgpl:8.1.2-mango.1` built by GitHub
Actions run `30432038467` from commit
`c12645c458f6bf6fd047199b23c7eb0b184e297b`.

The complete corresponding-source archive is published at:

`https://mangoplayer.app/open-source/maven/app/mangoplayer/native/ffmpeg-kit-mango-lgpl/8.1.2-mango.1/ffmpeg-kit-mango-lgpl-8.1.2-mango.1-sources.tar.xz`

Its SHA-256 is:

`b1e3c52d02025a4f7127ca364d5078f55402206a68a6e5b5c763693075f9d3ef`

## Rebuild

1. Extract the source archive on Ubuntu 22.04 or a compatible Linux host.
2. Install the packages listed by the captured workflow/build log.
3. Configure Android NDK r27c (`27.2.12479018`) and Java 17.
4. From the extracted root, run:

   `./rebuild-from-source.sh /absolute/path/ffmpeg-kit-mango-lgpl.aar`

The driver recreates the local Git metadata required by the pinned upstream
build, applies the recorded Mango patch and namespace contract, rebuilds the
three Android ABIs, packages the AAR and reruns the fail-closed audit.

## Replacement and relinking

The artifact contains FFmpeg under LGPL version 3 or later, OpenSSL 3.5.7
linked statically, and cpu_features linked statically. GPL and nonfree options
are disabled. The source archive contains FFmpegKit, FFmpeg, OpenSSL,
cpu_features, gnu-config, patches, audit tools and the reconstruction driver.

An application integrator may replace the AAR with a modified rebuild while
retaining the same Java/JNI API contract. The expected namespace is
`com.antonkarpenko.ffmpegkit`; the three packaged ABIs are `arm64-v8a`,
`armeabi-v7a` and `x86_64`. This profile intentionally does not package or
depend on `libc++_shared.so`.

See `ARTIFACT-MANIFEST.json`, `source-index.json`, `audit/aar-audit.json` and
`SHA256SUMS` for exact binary identity and evidence.

Technical compliance evidence only; not legal advice.
