ci/cd: drop vcpkg; distro packages + the project FFmpeg everywhere

Linux/macOS now follow the local-build path in CI and CD:
tooling/install-deps.sh installs the distro codec packages and
tooling/ffmpeg/build-ffmpeg.sh builds the pinned static FFmpeg into
.cache/ffmpeg, with FFMPEG_DIR/PKG_CONFIG_PATH pointing there. CI caches
the built tree keyed on the script, distro and arch (the
.build-complete marker rejects partial saves); CD rebuilds it from
scratch per its no-cache policy. Windows keeps BtbN's prebuilt shared
archive, downloaded from the release page and verified against its
checksums.sha256 — no pkg-config is needed there any more.

vcpkg.json, the release-only overlay triplets and the x264 mirror
overlay are deleted; docs/build.md describes the new flow.
This commit is contained in:
2026-09-24 18:50:00 +08:00
parent 725a1d4da0
commit 563a3625ca
17 changed files with 102 additions and 633 deletions
+34 -87
View File
@@ -12,9 +12,9 @@ permissions:
# One matrix, seven platforms, the same environments CI tests in (see
# .github/workflows/ci.yml): Debian 12 / Fedora 43 / Arch / openKylin x64
# and arm64 containers plus the macOS and Windows hosts. Every package is
# built from scratch — no vcpkg/cargo caches: a restored vcpkg_installed
# or target tree has masked packaging problems before (stale ports,
# missing tools), and a release must not depend on restored state.
# built from scratch — no FFmpeg/cargo caches: a restored tree has
# masked packaging problems before (stale ports, missing tools), and a
# release must not depend on restored state.
jobs:
package:
name: Package (${{ matrix.name }})
@@ -23,7 +23,7 @@ jobs:
# "options":...}); the empty string means "run on the host"
# (actions/runner#265 allows an empty container value).
container: ${{ matrix.container != '' && fromJSON(matrix.container) || '' }}
# Cold vcpkg install + release build + packaging.
# Cold FFmpeg build + release build + packaging.
timeout-minutes: 150
strategy:
fail-fast: false
@@ -88,7 +88,7 @@ jobs:
steps:
# The container images are bare (Fedora/Arch even lack git);
# checkout and vcpkg need git/curl. First step of the job, so the
# checkout needs git/curl. First step of the job, so the
# package lists are still fresh.
- name: Bootstrap container (git, curl, wget)
if: matrix.container != ''
@@ -107,7 +107,7 @@ jobs:
# their own repo and build as path dependencies of oakapp.
submodules: true
# Defender's real-time scanning slows the MSVC/vcpkg build down
# Defender's real-time scanning slows the MSVC build down
# badly; disable it for the job and keep exclusions as the fallback
# when policy blocks the change.
- name: Disable Windows Defender scanning
@@ -125,8 +125,7 @@ jobs:
foreach ($path in @(
$env:GITHUB_WORKSPACE,
"$env:USERPROFILE\.cargo",
"$env:USERPROFILE\.rustup",
"$env:LOCALAPPDATA\vcpkg"
"$env:USERPROFILE\.rustup"
)) {
Add-MpPreference -ExclusionPath $path -ErrorAction SilentlyContinue
}
@@ -157,7 +156,7 @@ jobs:
uses: dtolnay/rust-toolchain@stable
with:
# The Windows build is MSVC-ABI (the runner carries VS 2026):
# vcpkg's FFmpeg and the vendored OCIO build both want it.
# The prebuilt FFmpeg and the vendored OCIO build both want it.
toolchain: ${{ matrix.platform == 'windows' && 'stable-x86_64-pc-windows-msvc' || 'stable' }}
# ------------------------------------------------------------------
@@ -234,10 +233,10 @@ jobs:
if: matrix.platform == 'macos'
run: |
# Homebrew's pkgconf installs a `pkg-config` symlink, which is
# the name crates/oak-ffmpeg-link/build.rs invokes; nasm is what
# vcpkg's ffmpeg port requires to build (FFmpeg libraries come
# from the vcpkg manifest). librsvg stays for rsvg-convert (app
# icon) and is bundled into the .app by the dylib script.
# the name crates/oak-ffmpeg-link/build.rs invokes; nasm is what the
# project FFmpeg build (tooling/ffmpeg/build-ffmpeg.sh) requires.
# librsvg stays for rsvg-convert (app icon) and is bundled into
# the .app by the dylib script.
brew install cmake pkg-config nasm librsvg autoconf automake libtool autoconf-archive
# Windows uses BtbN's prebuilt FFmpeg (GPL, shared): the archive
@@ -247,8 +246,8 @@ jobs:
# links these builds). Downloaded from his release page and
# verified against the checksums.sha256 published in the same
# release; nothing is mirrored here, so provenance stays upstream.
# The alternative — a cold vcpkg FFmpeg build — costs ~40 minutes
# per run on this platform.
# The alternative — a source build — costs ~40 minutes per run on
# this platform.
- name: Install prebuilt FFmpeg (Windows)
if: matrix.platform == 'windows'
shell: pwsh
@@ -272,56 +271,22 @@ jobs:
Move-Item $inner.FullName "$root\ffmpeg"
# ------------------------------------------------------------------
# vcpkg (manifest mode) — built from scratch, no caches
# FFmpeg — built from source with the distro's codec packages
# (Linux/macOS) or the prebuilt archive (Windows), no caches
# ------------------------------------------------------------------
# Bootstrap a fresh clone rather than leaning on whatever vcpkg the
# image carries: `builtin-baseline`/`overrides` are only honored by
# a recent vcpkg-tool, and every platform must behave alike.
- name: Bootstrap vcpkg
# The Linux/macOS jobs follow the local-build path
# (tooling/install-deps.sh + tooling/ffmpeg/build-ffmpeg.sh); the
# release policy is a from-scratch build, so nothing is restored
# from a cache here.
- name: Install FFmpeg dependencies
if: matrix.platform != 'windows'
shell: bash
run: |
git clone https://github.com/microsoft/vcpkg.git .cache/vcpkg
.cache/vcpkg/bootstrap-vcpkg.sh -disableMetrics
echo "$PWD/.cache/vcpkg" >> "$GITHUB_PATH"
echo "VCPKG_ROOT=$PWD/.cache/vcpkg" >> "$GITHUB_ENV"
run: tooling/install-deps.sh
- name: Bootstrap vcpkg (Windows)
if: matrix.platform == 'windows'
shell: pwsh
run: |
git clone https://github.com/microsoft/vcpkg.git "$env:GITHUB_WORKSPACE\.cache\vcpkg"
& "$env:GITHUB_WORKSPACE\.cache\vcpkg\bootstrap-vcpkg.bat" -disableMetrics
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
"$env:GITHUB_WORKSPACE\.cache\vcpkg" >> $env:GITHUB_PATH
"VCPKG_ROOT=$env:GITHUB_WORKSPACE\.cache\vcpkg" >> $env:GITHUB_ENV
- name: Install dependencies (vcpkg manifest)
- name: Build FFmpeg
if: matrix.platform != 'windows'
shell: bash
run: |
# Source tarballs come from third-party hosts (x264 lives on
# code.videolan.org); a transient connection failure aborts the
# whole install — vcpkg refuses to retry that class of curl
# error — so retry here.
for attempt in 1 2 3; do
vcpkg install --triplet ${{ matrix.triplet }} --overlay-triplets tooling/vcpkg-triplets/release --overlay-ports tooling/vcpkg-ports && exit 0
echo "vcpkg install failed (attempt $attempt); retrying"
sleep 15
done
exit 1
- name: Install dependencies (vcpkg manifest, Windows)
if: matrix.platform == 'windows'
shell: pwsh
run: |
for ($i = 1; $i -le 3; $i++) {
vcpkg install --triplet ${{ matrix.triplet }} --overlay-triplets tooling/vcpkg-triplets/release --overlay-ports tooling/vcpkg-ports
if ($LASTEXITCODE -eq 0) { exit 0 }
Write-Host "vcpkg install failed (attempt $i); retrying"
Start-Sleep -Seconds 15
}
exit 1
run: tooling/ffmpeg/build-ffmpeg.sh
# ------------------------------------------------------------------
# Build environment
@@ -340,17 +305,9 @@ jobs:
echo "CXX=clang++"
} >> "$GITHUB_ENV"
bash tooling/ocio-env.sh >> "$GITHUB_ENV"
prefix="$PWD/vcpkg_installed/${{ matrix.triplet }}"
echo "FFMPEG_DIR=$prefix" >> "$GITHUB_ENV"
echo "PKG_CONFIG_PATH=$prefix/lib/pkgconfig" >> "$GITHUB_ENV"
echo "$prefix/tools/pkgconf" >> "$GITHUB_PATH"
echo "LD_LIBRARY_PATH=$prefix/lib${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}" >> "$GITHUB_ENV"
# The Debian-family packaging tools resolve the ELF needs through
# ldd (dpkg-shlibdeps, linuxdeploy): register the vcpkg libs with
# the dynamic linker so `libva-drm.so.2` is found when a package
# is assembled.
echo "$prefix/lib" > /etc/ld.so.conf.d/oak-vcpkg.conf
ldconfig
ffmpeg="$PWD/.cache/ffmpeg"
echo "FFMPEG_DIR=$ffmpeg" >> "$GITHUB_ENV"
echo "PKG_CONFIG_PATH=$ffmpeg/lib/pkgconfig" >> "$GITHUB_ENV"
- name: Configure build environment (macOS)
if: matrix.platform == 'macos'
@@ -359,31 +316,25 @@ jobs:
# Vendored static OCIO (same as every non-Windows platform via
# tooling/ocio-env.sh); no OCIO_INSTALL_DIR override.
bash tooling/ocio-env.sh >> "$GITHUB_ENV"
prefix="$PWD/vcpkg_installed/${{ matrix.triplet }}"
echo "FFMPEG_DIR=$prefix" >> "$GITHUB_ENV"
echo "PKG_CONFIG_PATH=$prefix/lib/pkgconfig" >> "$GITHUB_ENV"
echo "$prefix/tools/pkgconf" >> "$GITHUB_PATH"
ffmpeg="$PWD/.cache/ffmpeg"
echo "FFMPEG_DIR=$ffmpeg" >> "$GITHUB_ENV"
echo "PKG_CONFIG_PATH=$ffmpeg/lib/pkgconfig" >> "$GITHUB_ENV"
- name: Configure build environment (Windows)
if: matrix.platform == 'windows'
shell: pwsh
run: |
# FFmpeg comes from the prebuilt archive extracted above (the
# manifest no longer installs it on Windows); vcpkg only
# provides pkgconf for oak-ffmpeg-link's build script.
$prefix = "$env:GITHUB_WORKSPACE\vcpkg_installed\${{ matrix.triplet }}"
# FFmpeg comes from the prebuilt archive extracted above.
$ffmpeg = "$env:GITHUB_WORKSPACE\.cache\ffmpeg"
"FFMPEG_DIR=$ffmpeg" >> $env:GITHUB_ENV
"PKG_CONFIG_PATH=$ffmpeg\lib\pkgconfig" >> $env:GITHUB_ENV
"$ffmpeg\bin" >> $env:GITHUB_PATH
"$prefix\tools\pkgconf" >> $env:GITHUB_PATH
# Bundled OCIO: ocio-sys' vendored sources build with the MSVC
# toolchain (what they need — the MSYS2 package was the
# workaround, not the preference), so no OCIO_INSTALL_DIR and
# no OCIO_RS_NO_MSVC_INCLUDES anywhere.
"OCIO_RS_ENABLE_REAL=1" >> $env:GITHUB_ENV
"OCIO_RS_LINK=static" >> $env:GITHUB_ENV
vcpkg list
- name: Install cargo-packager
if: matrix.distro == 'debian' || matrix.platform != 'linux'
@@ -424,8 +375,7 @@ jobs:
case "${{ matrix.distro }}" in
debian)
# The general Debian-family package, labeled "+debian".
VCPKG_LIB="$PWD/vcpkg_installed/${{ matrix.triplet }}/lib" \
tooling/package/build-deb.sh "$VERSION" debian
tooling/package/build-deb.sh "$VERSION" debian
# appimagetool self-extracts instead of mounting (containers
# have no FUSE).
APPIMAGE_EXTRACT_AND_RUN=1 cargo packager --release --formats appimage
@@ -438,11 +388,8 @@ jobs:
;;
openkylin)
# The openKylin build, labeled "+openkylin"; dpkg-shlibdeps
# resolves the runtime deps against openKylin's own repos
# and the vcpkg libva/libdrm ship next to the app (openKylin's
# system libva predates FFmpeg's vaMapBuffer2).
VCPKG_LIB="$PWD/vcpkg_installed/${{ matrix.triplet }}/lib" \
tooling/package/build-deb.sh "$VERSION" openkylin
# resolves the runtime deps against openKylin's own repos.
tooling/package/build-deb.sh "$VERSION" openkylin
;;
esac