# Reproducible build environment for the Android arm64 FFmpeg used by PlayaMedia.
# The image pins the NDK; the script pins FFmpeg/mbedTLS refs. Both are recorded
# in VERSION.txt (LGPL corresponding-source obligation).
#
# Build:  docker build -t playamedia-ffmpeg-android .
# Run:    docker run --rm -v <repo>\Plugins\PlayaMedia\third_party\ffmpeg:/out playamedia-ffmpeg-android
#
# Image is ~4 GB (NDK dominates). Keep it — rebuilding FFmpeg for a new ref then
# takes minutes instead of re-downloading the toolchain.

FROM debian:bookworm-slim

RUN apt-get update && apt-get install -y --no-install-recommends \
        build-essential \
        ca-certificates \
        cmake \
        curl \
        file \
        git \
        ninja-build \
        patchelf \
        pkg-config \
        python3 \
        unzip \
    && rm -rf /var/lib/apt/lists/*

ARG NDK_VERSION=r27c
RUN curl -fsSL -o /tmp/ndk.zip \
        "https://dl.google.com/android/repository/android-ndk-${NDK_VERSION}-linux.zip" \
    && unzip -q /tmp/ndk.zip -d /opt \
    && rm /tmp/ndk.zip
ENV ANDROID_NDK="/opt/android-ndk-${NDK_VERSION}"
ENV NDK_VERSION="${NDK_VERSION}"

# Build-time deps of the sources themselves, deliberately in a layer AFTER the
# NDK download: adding one later must not re-fetch 700 MB of toolchain.
# mbedTLS generates psa_crypto_driver_wrappers from JSON templates.
RUN apt-get update && apt-get install -y --no-install-recommends \
        python3-jsonschema \
        python3-jinja2 \
    && rm -rf /var/lib/apt/lists/*

COPY build_ffmpeg_android.sh /usr/local/bin/build_ffmpeg_android.sh
RUN chmod +x /usr/local/bin/build_ffmpeg_android.sh

VOLUME /out
ENTRYPOINT ["/usr/local/bin/build_ffmpeg_android.sh"]
