# eastbook-rebuild-1

This is a controlled rebuild of libheif 1.23.5 and libde265 1.0.16 for the heic-to 1.6.5 CSP wrapper. It is not the original author's unpublished Emscripten build. `installedCspSha256` in `source-manifest.json` is the npm CSP. `generated/heic-to-csp.js` is this derivative.

## Bootstrap order

The manifest is not inside the wrapper archive. The scripts are written first, then copied into `sources/heic-to-1.6.5-eastbook-rebuild-1.tgz`. The manifest records that archive hash and the `scripts/` hashes after packing. A rebuild reads those hashes as arguments. It does not repack the archive, so the recipe does not hash a file that contains itself.

Use `scripts/rebuild-one.sh`, `scripts/bundle-csp.mjs`, and `scripts/reproduce.sh`. The copies under `recipe/` inside the wrapper archive are the same bytes at pack time. `bundle-csp.mjs` reads `src/index.js` and `src/worker.js` from that archive. It overwrites the archived generated library in its fresh work tree with the `libheif.js` just compiled. It does not use `node_modules`.

## Tool bootstrap

Install only these pinned tools, outside the product package:

- Emscripten SDK 3.1.64. `emcc --version` must contain `3.1.64`. Commit recorded on the accepted compiler: `a1fe3902bf73a3802eae0357d273d0e37ea79898`.
- CMake 3.31.8. `cmake --version` must contain `3.31.8`. The macos-universal tarball sha256 is `d1449f969c54d5c00886d5b643340d493dfb3c81cb39ee29b35453395c11ebf7`.
- esbuild 0.25.12. Pass the directory that contains its `package.json`. The script rejects any other version.
- GNU Make, python3, and `shasum` for the archive checks and the upstream libde265 build. This host used GNU Make 3.81.

Codec flags are not parameters. They are fixed in `scripts/rebuild-one.sh`: `USE_WASM=0`, `USE_UNSAFE_EVAL=0`, `USE_TYPESCRIPT=0`, `LIBDE265_VERSION=1.0.16`, and AOM, webcodecs, uncompressed, and OpenJPEG off.

## Command

`--work` must not already exist. The script does not delete it. `--receipt-dir` must already exist.

```sh
scripts/reproduce.sh \
  --libheif sources/libheif-1.23.5.tar.gz \
  --libheif-sha256 fd9036064c4432f0550d15072ddf34956a248279ee9aeaff0fba3fa0f77d8f1a \
  --libde265 sources/libde265-1.0.16.tar.gz \
  --libde265-sha256 b92beb6b53c346db9a8fae968d686ab706240099cdd5aff87777362d668b0de7 \
  --wrapper sources/heic-to-1.6.5-eastbook-rebuild-1.tgz \
  --wrapper-sha256 aa3c5d7282df746690ebcf5b025b9610d6067e04dfa55b485d56242daee7b060 \
  --expect-lib-sha256 8c11f36a8d03c9b08f79fc11cef01585a54d0699da3ddb4bb6dac9c68920a557 \
  --expect-csp-sha256 caaedd6dc268e8cc4c53a2131e78b68cc23563b3522f0346cbeef803af18e2b7 \
  --work /path/to/fresh-work \
  --emsdk /path/to/emsdk \
  --cmake /path/to/cmake \
  --esbuild /path/to/esbuild \
  --receipt-dir /path/to/existing-receipt-dir
```

A checksum mismatch, missing input, unexpected tool version, existing work directory, or unsafe archive member exits 2 before extraction. If `build-emscripten.sh` exits nonzero, this recipe exits with that status. A hash mismatch against the expected library or CSP exits 3.

## Linked compiler runtime

Emscripten 3.1.64 links musl as libc, dlmalloc, compiler-rt, libc++, libc++abi, and libunwind. Their notices are the `licenses/emscripten-*` files listed in `runtimeNotices`. `licenses/GPL-3.0.txt` and `licenses/LGPL-3.0.txt` are the standalone texts copied from the libheif release `COPYING`.

No file-prefix map is used. Earlier clean runs in different directories produced the same `libheif.js`.
