Multi-arch docker image with ffmpeg/ffprobe binaries built as hardened static PIE binaries
1M+
# bump: alpine /FROM alpine:([\d.]+)/ docker:alpine|^3
# bump: alpine link "Release notes" https://alpinelinux.org/posts/Alpine-$LATEST-released.html
FROM alpine:3.13.5 AS builder
# bump: ffmpeg /FFMPEG_VERSION=([\d.]+)/ https://github.com/FFmpeg/FFmpeg.git|^4
# bump: ffmpeg after ./hashupdate Dockerfile FFMPEG $LATEST
# bump: ffmpeg link "Changelog" https://github.com/FFmpeg/FFmpeg/blob/n$LATEST/Changelog
# bump: ffmpeg link "Source diff $CURRENT..$LATEST" https://github.com/FFmpeg/FFmpeg/compare/n$CURRENT..n$LATEST
ARG FFMPEG_VERSION=4.4
ARG FFMPEG_URL="https://ffmpeg.org/releases/ffmpeg-$FFMPEG_VERSION.tar.bz2"
ARG FFMPEG_SHA256=42093549751b582cf0f338a21a3664f52e0a9fbe0d238d3c992005e493607d0e
# bump: mp3lame /MP3LAME_VERSION=([\d.]+)/ svn:http://svn.code.sf.net/p/lame/svn|/^RELEASE__(.*)$/|/_/./|*
# bump: mp3lame after ./hashupdate Dockerfile MP3LAME $LATEST
# bump: mp3lame link "ChangeLog" http://svn.code.sf.net/p/lame/svn/trunk/lame/ChangeLog
ARG MP3LAME_VERSION=3.100
ARG MP3LAME_URL="https://sourceforge.net/projects/lame/files/lame/$MP3LAME_VERSION/lame-$MP3LAME_VERSION.tar.gz/download"
ARG MP3LAME_SHA256=ddfe36cab873794038ae2c1210557ad34857a4b6bdc515785d1da9e175b1da1e
# bump: fdk-aac /FDK_AAC_VERSION=([\d.]+)/ https://github.com/mstorsjo/fdk-aac.git|*
# bump: fdk-aac after ./hashupdate Dockerfile FDK_AAC $LATEST
# bump: fdk-aac link "ChangeLog" https://github.com/mstorsjo/fdk-aac/blob/master/ChangeLog
# bump: fdk-aac link "Source diff $CURRENT..$LATEST" https://github.com/mstorsjo/fdk-aac/compare/v$CURRENT..v$LATEST
ARG FDK_AAC_VERSION=2.0.2
ARG FDK_AAC_URL="https://github.com/mstorsjo/fdk-aac/archive/v$FDK_AAC_VERSION.tar.gz"
ARG FDK_AAC_SHA256=7812b4f0cf66acda0d0fe4302545339517e702af7674dd04e5fe22a5ade16a90
# bump: ogg /OGG_VERSION=([\d.]+)/ https://github.com/xiph/ogg.git|*
# bump: ogg after ./hashupdate Dockerfile OGG $LATEST
# bump: ogg link "CHANGES" https://github.com/xiph/ogg/blob/master/CHANGES
# bump: ogg link "Source diff $CURRENT..$LATEST" https://github.com/xiph/ogg/compare/v$CURRENT..v$LATEST
ARG OGG_VERSION=1.3.5
ARG OGG_URL="https://downloads.xiph.org/releases/ogg/libogg-$OGG_VERSION.tar.gz"
ARG OGG_SHA256=0eb4b4b9420a0f51db142ba3f9c64b333f826532dc0f48c6410ae51f4799b664
# bump: vorbis /VORBIS_VERSION=([\d.]+)/ https://github.com/xiph/vorbis.git|*
# bump: vorbis after ./hashupdate Dockerfile VORBIS $LATEST
# bump: vorbis link "CHANGES" https://github.com/xiph/vorbis/blob/master/CHANGES
# bump: vorbis link "Source diff $CURRENT..$LATEST" https://github.com/xiph/vorbis/compare/v$CURRENT..v$LATEST
ARG VORBIS_VERSION=1.3.7
ARG VORBIS_URL="https://downloads.xiph.org/releases/vorbis/libvorbis-$VORBIS_VERSION.tar.gz"
ARG VORBIS_SHA256=0e982409a9c3fc82ee06e08205b1355e5c6aa4c36bca58146ef399621b0ce5ab
# bump: opus /OPUS_VERSION=([\d.]+)/ https://github.com/xiph/opus.git|^1
# bump: opus after ./hashupdate Dockerfile OPUS $LATEST
# bump: opus link "Release notes" https://github.com/xiph/opus/releases/tag/v$LATEST
# bump: opus link "Source diff $CURRENT..$LATEST" https://github.com/xiph/opus/compare/v$CURRENT..v$LATEST
ARG OPUS_VERSION=1.3.1
ARG OPUS_URL="https://archive.mozilla.org/pub/opus/opus-$OPUS_VERSION.tar.gz"
ARG OPUS_SHA256=65b58e1e25b2a114157014736a3d9dfeaad8d41be1c8179866f144a2fb44ff9d
# bump: theora /THEORA_VERSION=([\d.]+)/ https://github.com/xiph/theora.git|*
# bump: theora after ./hashupdate Dockerfile THEORA $LATEST
# bump: theora link "Release notes" https://github.com/xiph/theora/releases/tag/v$LATEST
# bump: theora link "Source diff $CURRENT..$LATEST" https://github.com/xiph/theora/compare/v$CURRENT..v$LATEST
ARG THEORA_VERSION=1.1.1
ARG THEORA_URL="https://downloads.xiph.org/releases/theora/libtheora-$THEORA_VERSION.tar.bz2"
ARG THEORA_SHA256=b6ae1ee2fa3d42ac489287d3ec34c5885730b1296f0801ae577a35193d3affbc
# bump: libvpx /VPX_VERSION=([\d.]+)/ https://github.com/webmproject/libvpx.git|*
# bump: libvpx after ./hashupdate Dockerfile VPX $LATEST
# bump: libvpx link "CHANGELOG" https://github.com/webmproject/libvpx/blob/master/CHANGELOG
# bump: libvpx link "Source diff $CURRENT..$LATEST" https://github.com/webmproject/libvpx/compare/v$CURRENT..v$LATEST
ARG VPX_VERSION=1.10.0
ARG VPX_URL="https://github.com/webmproject/libvpx/archive/v$VPX_VERSION.tar.gz"
ARG VPX_SHA256=85803ccbdbdd7a3b03d930187cb055f1353596969c1f92ebec2db839fa4f834a
# x264 only have a stable branch no tags and we checkout commit so no hash is needed
# bump: x264 /X264_VERSION=([[:xdigit:]]+)/ gitrefs:https://code.videolan.org/videolan/x264.git|re:#^refs/heads/stable$#|@commit
# bump: x264 after ./hashupdate Dockerfile X264 $LATEST
# bump: x264 link "Source diff $CURRENT..$LATEST" https://code.videolan.org/videolan/x264/-/compare/$CURRENT...$LATEST
ARG X264_URL="https://code.videolan.org/videolan/x264.git"
ARG X264_VERSION=5db6aa6cab1b146e07b60cc1736a01f21da01154
# bump: x265 /X265_VERSION=([\d.]+)/ https://bitbucket.org/multicoreware/x265_git.git|^3
# bump: x265 after ./hashupdate Dockerfile X265 $LATEST
# bump: x265 link "releasenotes" https://bitbucket.org/multicoreware/x265_git/src/master/doc/reST/releasenotes.rst
ARG X265_VERSION=3.5
ARG X265_URL="https://bitbucket.org/multicoreware/x265_git/get/$X265_VERSION.tar.bz2"
ARG X265_SHA256=7ebc5d2de6ce5dfefb434e422e59a0c4715fe939c784ac2f3d41af5775adc706
# bump: libwebp /LIBWEBP_VERSION=([\d.]+)/ https://github.com/webmproject/libwebp.git|*
# bump: libwebp after ./hashupdate Dockerfile LIBWEBP $LATEST
# bump: libwebp link "Release notes" https://github.com/webmproject/libwebp/releases/tag/v$LATEST
# bump: libwebp link "Source diff $CURRENT..$LATEST" https://github.com/webmproject/libwebp/compare/v$CURRENT..v$LATEST
ARG LIBWEBP_VERSION=1.2.0
ARG LIBWEBP_URL="https://github.com/webmproject/libwebp/archive/v$LIBWEBP_VERSION.tar.gz"
ARG LIBWEBP_SHA256=d60608c45682fa1e5d41c3c26c199be5d0184084cd8a971a6fc54035f76487d3
# bump: speex /SPEEX_VERSION=([\d.]+)/ https://github.com/xiph/speex.git|*
# bump: speex after ./hashupdate Dockerfile SPEEX $LATEST
# bump: speex link "ChangeLog" https://github.com/xiph/speex//blob/master/ChangeLog
# bump: speex link "Source diff $CURRENT..$LATEST" https://github.com/xiph/speex/compare/$CURRENT..$LATEST
ARG SPEEX_VERSION=1.2.0
ARG SPEEX_URL="https://github.com/xiph/speex/archive/Speex-$SPEEX_VERSION.tar.gz"
ARG SPEEX_SHA256=4781a30d3a501abc59a4266f9bbf8b1da66fd509bef014697dc3f61e406b990c
# bump: aom /AOM_VERSION=([\d.]+)/ git:https://aomedia.googlesource.com/aom|*
# bump: aom after ./hashupdate Dockerfile AOM $LATEST
# bump: aom after COMMIT=$(git ls-remote https://aomedia.googlesource.com/aom v$LATEST^{} | awk '{print $1}') && sed -i -E "s/^ARG AOM_COMMIT=.*/ARG AOM_COMMIT=$COMMIT/" Dockerfile
# bump: aom link "CHANGELOG" https://aomedia.googlesource.com/aom/+/refs/tags/v$LATEST/CHANGELOG
ARG AOM_VERSION=3.1.1
ARG AOM_URL="https://aomedia.googlesource.com/aom"
ARG AOM_COMMIT=7fadc0e77130efb05f52979b0deaba9b6a1bba6d
# bump: vid.stab /VIDSTAB_VERSION=([\d.]+)/ https://github.com/georgmartius/vid.stab.git|*
# bump: vid.stab after ./hashupdate Dockerfile VIDSTAB $LATEST
# bump: vid.stab link "Changelog" https://github.com/georgmartius/vid.stab/blob/master/Changelog
ARG VIDSTAB_VERSION=1.1.0
ARG VIDSTAB_URL="https://github.com/georgmartius/vid.stab/archive/v$VIDSTAB_VERSION.tar.gz"
ARG VIDSTAB_SHA256=14d2a053e56edad4f397be0cb3ef8eb1ec3150404ce99a426c4eb641861dc0bb
# bump: kvazaar /KVAZAAR_VERSION=([\d.]+)/ https://github.com/ultravideo/kvazaar.git|^2
# bump: kvazaar after ./hashupdate Dockerfile KVAZAAR $LATEST
# bump: kvazaar link "Release notes" https://github.com/ultravideo/kvazaar/releases/tag/v$LATEST
ARG KVAZAAR_VERSION=2.0.0
ARG KVAZAAR_URL="https://github.com/ultravideo/kvazaar/archive/v$KVAZAAR_VERSION.tar.gz"
ARG KVAZAAR_SHA256=213edca448f127f9c6d194cdfd21593d10331f9061d95751424e1001bae60b5d
# bump: libass /LIBASS_VERSION=([\d.]+)/ https://github.com/libass/libass.git|*
# bump: libass after ./hashupdate Dockerfile LIBASS $LATEST
# bump: libass link "Release notes" https://github.com/libass/libass/releases/tag/$LATEST
ARG LIBASS_VERSION=0.15.1
ARG LIBASS_URL="https://github.com/libass/libass/releases/download/$LIBASS_VERSION/libass-$LIBASS_VERSION.tar.gz"
ARG LIBASS_SHA256=101e2be1bf52e8fc265e7ca2225af8bd678839ba13720b969883eb9da43048a6
# bump: zimg /ZIMG_VERSION=([\d.]+)/ https://github.com/sekrit-twc/zimg.git|*
# bump: zimg after ./hashupdate Dockerfile ZIMG $LATEST
# bump: zimg link "ChangeLog" https://github.com/sekrit-twc/zimg/blob/master/ChangeLog
ARG ZIMG_VERSION=3.0.1
ARG ZIMG_URL="https://github.com/sekrit-twc/zimg/archive/release-$ZIMG_VERSION.tar.gz"
ARG ZIMG_SHA256=c50a0922f4adac4efad77427d13520ed89b8366eef0ef2fa379572951afcc73f
# bump: openjpeg /OPENJPEG_VERSION=([\d.]+)/ https://github.com/uclouvain/openjpeg.git|*
# bump: openjpeg after ./hashupdate Dockerfile OPENJPEG $LATEST
# bump: openjpeg link "CHANGELOG" https://github.com/uclouvain/openjpeg/blob/master/CHANGELOG.md
ARG OPENJPEG_VERSION=2.4.0
ARG OPENJPEG_URL="https://github.com/uclouvain/openjpeg/archive/v$OPENJPEG_VERSION.tar.gz"
ARG OPENJPEG_SHA256=8702ba68b442657f11aaeb2b338443ca8d5fb95b0d845757968a7be31ef7f16d
# bump: dav1d /DAV1D_VERSION=([\d.]+)/ https://code.videolan.org/videolan/dav1d.git|^0
# bump: dav1d after ./hashupdate Dockerfile DAV1D $LATEST
# bump: dav1d link "Release notes" https://code.videolan.org/videolan/dav1d/-/tags/$LATEST
ARG DAV1D_VERSION=0.9.0
ARG DAV1D_URL="https://code.videolan.org/videolan/dav1d/-/archive/$DAV1D_VERSION/dav1d-$DAV1D_VERSION.tar.gz"
ARG DAV1D_SHA256=ad6b89340f6e1a5c0c043763c0e28bb42d8930426f7dec049a8bc5e70076dd1a
# bump: xvid /XVID_VERSION=([\d.]+)/ svn:http://anonymous:@svn.xvid.org|/^release-(.*)$/|/_/./|^1
# bump: xvid after ./hashupdate Dockerfile LIBXVID $LATEST
ARG XVID_VERSION=1.3.7
ARG XVID_URL="https://downloads.xvid.com/downloads/xvidcore-$XVID_VERSION.tar.gz"
ARG XVID_SHA256=abbdcbd39555691dd1c9b4d08f0a031376a3b211652c0d8b3b8aa9be1303ce2d
# bump: rav1e /RAV1E_VERSION=([\d.]+)/ https://github.com/xiph/rav1e.git|^0
# bump: rav1e after ./hashupdate Dockerfile RAV1E $LATEST
# bump: rav1e link "Release notes" https://github.com/xiph/rav1e/releases/tag/v$LATEST
ARG RAV1E_VERSION=0.4.1
ARG RAV1E_URL="https://github.com/xiph/rav1e/archive/v$RAV1E_VERSION.tar.gz"
ARG RAV1E_SHA256=b0be59435a40e03b973ecc551ca7e632e03190b5a20f944818afa3c2ecf4852d
# bump: srt /SRT_VERSION=([\d.]+)/ https://github.com/Haivision/srt.git|^1
# bump: srt after ./hashupdate Dockerfile SRT $LATEST
# bump: srt link "Release notes" https://github.com/Haivision/srt/releases/tag/v$LATEST
ARG SRT_VERSION=1.4.3
ARG SRT_URL="https://github.com/Haivision/srt/archive/v${SRT_VERSION}.tar.gz"
ARG SRT_SHA256=c06e05664c71d635c37207a2b5a444f2c4a95950a3548402b3e0c524f735b33d
# bump: svtav1 /SVTAV1_VERSION=([\d.]+)/ https://gitlab.com/AOMediaCodec/SVT-AV1.git|^0
# bump: svtav1 after ./hashupdate Dockerfile SVTAV1 $LATEST
# bump: svtav1 link "Release notes" https://gitlab.com/AOMediaCodec/SVT-AV1/-/releases/v$LATEST
ARG SVTAV1_VERSION=0.8.7
ARG SVTAV1_URL="https://gitlab.com/AOMediaCodec/SVT-AV1/-/archive/v$SVTAV1_VERSION/SVT-AV1-v$SVTAV1_VERSION.tar.bz2"
ARG SVTAV1_SHA256=482bbe3b0f2f41b8dd0c2426c6bf5848f7306ad14ce3a10617834dbb3ab2d847
# bump: davs2 /DAVS2_VERSION=([\d.]+)/ https://github.com/pkuvcl/davs2.git|^1
# bump: davs2 after ./hashupdate Dockerfile DAVS2 $LATEST
# bump: davs2 link "Release" https://github.com/pkuvcl/davs2/releases/tag/$LATEST
# bump: davs2 link "Source diff $CURRENT..$LATEST" https://github.com/pkuvcl/davs2/compare/v$CURRENT..v$LATEST
ARG DAVS2_VERSION=1.6
ARG DAVS2_URL="https://github.com/pkuvcl/davs2/archive/refs/tags/$DAVS2_VERSION.tar.gz"
ARG DAVS2_SHA256=de93800f016cbaf08cb40184a8069050dc625da5240a528155137052d1cf81c8
# bump: xavs2 /XAVS2_VERSION=([\d.]+)/ https://github.com/pkuvcl/xavs2.git|^1
# bump: xavs2 after ./hashupxate Dockerfile XAVS2 $LATEST
# bump: xavs2 link "Release" https://github.com/pkuvcl/xavs2/releases/tag/$LATEST
# bump: xavs2 link "Source diff $CURRENT..$LATEST" https://github.com/pkuvcl/xavs2/compare/v$CURRENT..v$LATEST
ARG XAVS2_VERSION=1.3
ARG XAVS2_URL="https://github.com/pkuvcl/xavs2/archive/refs/tags/$XAVS2_VERSION.tar.gz"
ARG XAVS2_SHA256=28f9204dc9384336de7c6210cd3317d2d6b94ec23a4d1b6113fcbe7f00d7230b
# bump: vmaf /VMAF_VERSION=([\d.]+)/ https://github.com/Netflix/vmaf.git|*
# bump: vmaf after ./hashupxate Dockerfile VMAF $LATEST
# bump: vmaf link "Release" https://github.com/Netflix/vmaf/releases/tag/v$LATEST
# bump: vmaf link "Source diff $CURRENT..$LATEST" https://github.com/Netflix/vmaf/compare/v$CURRENT..v$LATEST
ARG VMAF_VERSION=2.1.1
ARG VMAF_URL="https://github.com/Netflix/vmaf/archive/refs/tags/v$VMAF_VERSION.tar.gz"
ARG VMAF_SHA256=e7fc00ae1322a7eccfcf6d4f1cdf9c67eec8058709887c8c6c3795c617326f77
# -O3 makes sure we compile with optimization. setting CFLAGS/CXXFLAGS seems to override
# default automake cflags.
# -static-libgcc is needed to make gcc not include gcc_s as "as-needed" shared library which
# cmake will include as a implicit library.
# other options to get hardened build (same as ffmpeg hardened)
ARG CFLAGS="-O3 -static-libgcc -fno-strict-overflow -fstack-protector-all -fPIE"
ARG CXXFLAGS="-O3 -static-libgcc -fno-strict-overflow -fstack-protector-all -fPIE"
ARG LDFLAGS="-Wl,-z,relro,-z,now"
RUN apk add --no-cache \
coreutils \
openssl \
openssl-dev \
openssl-libs-static \
bash \
tar \
build-base \
autoconf \
automake \
libtool \
diffutils \
cmake \
meson \
ninja \
git \
yasm \
nasm \
rust \
cargo \
texinfo \
jq \
zlib \
zlib-dev \
zlib-static \
libbz2 \
bzip2-dev \
bzip2-static \
libxml2 \
libxml2-dev \
expat \
expat-dev \
expat-static \
fontconfig \
fontconfig-dev \
fontconfig-static \
freetype \
freetype-dev \
freetype-static \
graphite2-static \
glib-static \
libpng-static \
harfbuzz \
harfbuzz-dev \
harfbuzz-static \
fribidi \
fribidi-dev \
fribidi-static \
brotli \
brotli-dev \
brotli-static \
soxr \
soxr-dev \
soxr-static \
tcl \
xxd
# cargo-c is not in stable main yet
RUN apk add --repository=http://dl-cdn.alpinelinux.org/alpine/edge/testing cargo-c
# workaround for https://github.com/google/brotli/issues/795
# pkgconfig --static can't have different name than .so
RUN \
ln -s /usr/lib/libbrotlicommon-static.a /usr/lib/libbrotlicommon.a && \
ln -s /usr/lib/libbrotlidec-static.a /usr/lib/libbrotlidec.a
RUN \
OPENSSL_VERSION=$(pkg-config --modversion openssl) \
LIBXML2_VERSION=$(pkg-config --modversion libxml-2.0) \
EXPAT_VERSION=$(pkg-config --modversion expat) \
FREETYPE_VERSION=$(pkg-config --modversion freetype2) \
FONTCONFIG_VERSION=$(pkg-config --modversion fontconfig) \
FRIBIDI_VERSION=$(pkg-config --modversion fribidi) \
SOXR_VERSION=$(pkg-config --modversion soxr) \
jq -n \
'{ \
ffmpeg: env.FFMPEG_VERSION, \
openssl: env.OPENSSL_VERSION, \
libxml2: env.LIBXML2_VERSION, \
expat: env.EXPAT_VERSION, \
libmp3lame: env.MP3LAME_VERSION, \
"libfdk-aac": env.FDK_AAC_VERSION, \
libogg: env.OGG_VERSION, \
libvorbis: env.VORBIS_VERSION, \
libopus: env.OPUS_VERSION, \
libtheora: env.THEORA_VERSION, \
libvpx: env.VPX_VERSION, \
libx264: env.X264_VERSION, \
libx265: env.X265_VERSION, \
libwebp: env.LIBWEBP_VERSION, \
libspeex: env.SPEEX_VERSION, \
libaom: env.AOM_VERSION, \
libvidstab: env.VIDSTAB_VERSION, \
libkvazaar: env.KVAZAAR_VERSION, \
libfreetype: env.FREETYPE_VERSION, \
fontconfig: env.FONTCONFIG_VERSION, \
libfribidi: env.FRIBIDI_VERSION, \
libass: env.LIBASS_VERSION, \
libzimg: env.ZIMG_VERSION, \
libsoxr: env.SOXR_VERSION, \
libopenjpeg: env.OPENJPEG_VERSION, \
libdav1d: env.DAV1D_VERSION, \
libxvid: env.XVID_VERSION, \
librav1e: env.RAV1E_VERSION, \
libsrt: env.SRT_VERSION, \
libsvtav1: env.SVTAV1_VERSION, \
libdavs2: env.DAVS2_VERSION, \
libxavs2: env.XAVS2_VERSION, \
libvmaf: env.VMAF_VERSION, \
}' > /versions.json
RUN \
wget -O lame.tar.gz "$MP3LAME_URL" && \
echo "$MP3LAME_SHA256 lame.tar.gz" | sha256sum --status -c - && \
tar xf lame.tar.gz && \
cd lame-* && ./configure --enable-static --enable-nasm --disable-shared && make -j$(nproc) install
RUN \
wget -O fdk-aac.tar.gz "$FDK_AAC_URL" && \
echo "$FDK_AAC_SHA256 fdk-aac.tar.gz" | sha256sum --status -c - && \
tar xf fdk-aac.tar.gz && \
cd fdk-aac-* && ./autogen.sh && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O libogg.tar.gz "$OGG_URL" && \
echo "$OGG_SHA256 libogg.tar.gz" | sha256sum --status -c - && \
tar xf libogg.tar.gz && \
cd libogg-* && ./configure --enable-static --disable-shared && make -j$(nproc) install
# require libogg to build
RUN \
wget -O libvorbis.tar.gz "$VORBIS_URL" && \
echo "$VORBIS_SHA256 libvorbis.tar.gz" | sha256sum --status -c - && \
tar xf libvorbis.tar.gz && \
cd libvorbis-* && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O opus.tar.gz "$OPUS_URL" && \
echo "$OPUS_SHA256 opus.tar.gz" | sha256sum --status -c - && \
tar xf opus.tar.gz && \
cd opus-* && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O libtheora.tar.bz2 "$THEORA_URL" && \
echo "$THEORA_SHA256 libtheora.tar.bz2" | sha256sum --status -c - && \
tar xf libtheora.tar.bz2 && \
cd libtheora-* && ./configure --disable-examples --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O libvpx.tar.gz "$VPX_URL" && \
echo "$VPX_SHA256 libvpx.tar.gz" | sha256sum --status -c - && \
tar xf libvpx.tar.gz && \
cd libvpx-* && ./configure --enable-static --enable-vp9-highbitdepth --disable-shared --disable-unit-tests --disable-examples && \
make -j$(nproc) install
RUN \
git clone "$X264_URL" && \
cd x264 && \
git checkout $X264_VERSION && \
./configure --enable-pic --enable-static && make -j$(nproc) install
# -w-macro-params-legacy to not log lots of asm warnings
# https://bitbucket.org/multicoreware/x265_git/issues/559/warnings-when-assembling-with-nasm-215
RUN \
wget -O x265.tar.bz2 "$X265_URL" && \
echo "$X265_SHA256 x265.tar.bz2" | sha256sum --status -c - && \
tar xf x265.tar.bz2 && \
cd multicoreware-x265_git-*/build/linux && \
cmake -G "Unix Makefiles" -DENABLE_SHARED=OFF -DENABLE_AGGRESSIVE_CHECKS=ON ../../source -DCMAKE_ASM_NASM_FLAGS=-w-macro-params-legacy && \
make -j$(nproc) install
RUN \
wget -O libwebp.tar.gz "$LIBWEBP_URL" && \
echo "$LIBWEBP_SHA256 libwebp.tar.gz" | sha256sum --status -c - && \
tar xf libwebp.tar.gz && \
cd libwebp-* && ./autogen.sh && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O speex.tar.gz "$SPEEX_URL" && \
echo "$SPEEX_SHA256 speex.tar.gz" | sha256sum --status -c - && \
tar xf speex.tar.gz && \
cd speex-Speex-* && ./autogen.sh && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
git clone --depth 1 --branch v$AOM_VERSION "$AOM_URL" && \
cd aom && test $(git rev-parse HEAD) = $AOM_COMMIT && \
mkdir build_tmp && cd build_tmp && cmake -DBUILD_SHARED_LIBS=0 -DENABLE_TESTS=0 -DENABLE_NASM=on -DCMAKE_INSTALL_LIBDIR=lib .. && make -j$(nproc) install
RUN \
wget -O vid.stab.tar.gz "$VIDSTAB_URL" && \
echo "$VIDSTAB_SHA256 vid.stab.tar.gz" | sha256sum --status -c - && \
tar xf vid.stab.tar.gz && \
cd vid.stab-* && cmake -DBUILD_SHARED_LIBS=OFF . && make -j$(nproc) install
RUN \
wget -O kvazaar.tar.gz "$KVAZAAR_URL" && \
echo "$KVAZAAR_SHA256 kvazaar.tar.gz" | sha256sum --status -c - && \
tar xf kvazaar.tar.gz && \
cd kvazaar-* && ./autogen.sh && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O libass.tar.gz "$LIBASS_URL" && \
echo "$LIBASS_SHA256 libass.tar.gz" | sha256sum --status -c - && \
tar xf libass.tar.gz && \
cd libass-* && ./configure --enable-static --disable-shared && make -j$(nproc) && make install
RUN \
wget -O zimg.tar.gz "$ZIMG_URL" && \
echo "$ZIMG_SHA256 zimg.tar.gz" | sha256sum --status -c - && \
tar xf zimg.tar.gz && \
cd zimg-* && ./autogen.sh && ./configure --enable-static --disable-shared && make -j$(nproc) install
RUN \
wget -O openjpeg.tar.gz "$OPENJPEG_URL" && \
echo "$OPENJPEG_SHA256 openjpeg.tar.gz" | sha256sum --status -c - && \
tar xf openjpeg.tar.gz && \
cd openjpeg-* && cmake -G "Unix Makefiles" -DBUILD_SHARED_LIBS=OFF && make -j$(nproc) install
RUN \
wget -O dav1d.tar.gz "$DAV1D_URL" && \
echo "$DAV1D_SHA256 dav1d.tar.gz" | sha256sum --status -c - && \
tar xf dav1d.tar.gz && \
cd dav1d-* && meson build --buildtype release -Ddefault_library=static && ninja -C build install
# add extra CFLAGS that are not enabled by -O3
# http://websvn.xvid.org/cvs/viewvc.cgi/trunk/xvidcore/build/generic/configure.in?revision=2146&view=markup
RUN \
wget -O libxvid.tar.gz "$XVID_URL" && \
echo "$XVID_SHA256 libxvid.tar.gz" | sha256sum --status -c - && \
tar xf libxvid.tar.gz && \
cd xvidcore/build/generic && \
CFLAGS="$CLFAGS -fstrength-reduce -ffast-math" \
./configure && make -j$(nproc) && make install
RUN \
wget -O rav1e.tar.gz "$RAV1E_URL" && \
echo "$RAV1E_SHA256 rav1e.tar.gz" | sha256sum --status -c - && \
tar xf rav1e.tar.gz && \
cd rav1e-* && \
cargo cinstall --release
# cargo-c/alpine rustc results in Libs.private depend on gcc_s
# https://gitlab.alpinelinux.org/alpine/aports/-/issues/11806
RUN sed -i 's/-lgcc_s//' /usr/local/lib/pkgconfig/rav1e.pc
RUN \
wget -O libsrt.tar.gz "$SRT_URL" && \
echo "$SRT_SHA256 libsrt.tar.gz" | sha256sum --status -c - && \
tar xf libsrt.tar.gz && \
cd srt-* && ./configure --enable-shared=0 --cmake-install-libdir=lib --cmake-install-includedir=include --cmake-install-bindir=bin && \
make -j$(nproc) && make install
# sed to fix symbol name conflict with vmaf, fixed in master
# https://gitlab.com/AOMediaCodec/SVT-AV1/-/commit/75af3e6f9241f5df07ffa8c67281a9eff9a476ad
RUN \
wget -O svtav1.tar.bz2 "$SVTAV1_URL" && \
echo "$SVTAV1_SHA256 svtav1.tar.bz2" | sha256sum --status -c - && \
tar xf svtav1.tar.bz2 && \
cd SVT-AV1-* && \
sed -i 's/picture_copy(/svt_av1_picture_copy(/g' \
Source/Lib/Common/Codec/EbPictureOperators.c \
Source/Lib/Common/Codec/EbPictureOperators.h \
Source/Lib/Encoder/Codec/EbFullLoop.c \
Source/Lib/Encoder/Codec/EbProductCodingLoop.c && \
cd Build && \
cmake .. -G"Unix Makefiles" -DCMAKE_INSTALL_LIBDIR=lib -DBUILD_SHARED_LIBS=OFF -DCMAKE_BUILD_TYPE=Release && \
make -j$(nproc) install
# TODO: seems to be issus with asm on musl
RUN \
wget -O davs2.tar.gz "$DAVS2_URL" && \
echo "$DAVS2_SHA256 davs2.tar.gz" | sha256sum --status -c - && \
tar xf davs2.tar.gz && \
cd davs2-*/build/linux && ./configure --disable-asm --enable-pic && \
make -j$(nproc) install
# TODO: seems to be issus with asm on musl
RUN \
wget -O xavs2.tar.gz "$XAVS2_URL" && \
echo "$XAVS2_SHA256 xavs2.tar.gz" | sha256sum --status -c - && \
tar xf xavs2.tar.gz && \
cd xavs2-*/build/linux && ./configure --disable-asm --enable-pic && \
make -j$(nproc) install
RUN \
wget -O vmaf.tar.gz "$VMAF_URL" && \
echo "$VMAF_SHA256 vmaf.tar.gz" | sha256sum --status -c - && \
tar xf vmaf.tar.gz && \
cd vmaf-*/libvmaf && meson build --buildtype release -Ddefault_library=static && ninja -vC build install
# sed changes --toolchain=hardened -pie to -static-pie
# extra libs stdc++ is for vmaf https://github.com/Netflix/vmaf/issues/788
RUN \
wget -O ffmpeg.tar.bz2 "$FFMPEG_URL" && \
echo "$FFMPEG_SHA256 ffmpeg.tar.bz2" | sha256sum --status -c - && \
tar xf ffmpeg.tar.bz2 && \
cd ffmpeg-* && \
sed -i 's/add_ldexeflags -fPIE -pie/add_ldexeflags -fPIE -static-pie/' configure && \
./configure \
--pkg-config-flags=--static \
--extra-cflags="-fopenmp" \
--extra-ldflags="-fopenmp" \
--extra-libs="-lstdc++" \
--toolchain=hardened \
--disable-debug \
--disable-shared \
--disable-ffplay \
--enable-static \
--enable-gpl \
--enable-gray \
--enable-nonfree \
--enable-openssl \
--enable-iconv \
--enable-libxml2 \
--enable-libmp3lame \
--enable-libfdk-aac \
--enable-libvorbis \
--enable-libopus \
--enable-libtheora \
--enable-libvpx \
--enable-libx264 \
--enable-libx265 \
--enable-libwebp \
--enable-libspeex \
--enable-libaom \
--enable-libvidstab \
--enable-libkvazaar \
--enable-libfreetype \
--enable-fontconfig \
--enable-libfribidi \
--enable-libass \
--enable-libzimg \
--enable-libsoxr \
--enable-libopenjpeg \
--enable-libdav1d \
--enable-libxvid \
--enable-librav1e \
--enable-libsrt \
--enable-libsvtav1 \
--enable-libdavs2 \
--enable-libxavs2 \
--enable-libvmaf \
|| (cat ffbuild/config.log ; false) \
&& make -j$(nproc) install tools/qt-faststart \
&& cp tools/qt-faststart /usr/local/bin
# make sure binaries has no dependencies, is relro, pie and stack nx
COPY checkelf /
RUN \
/checkelf /usr/local/bin/ffmpeg &&