CI/CD now runs this script on Linux/macOS (no more vcpkg), so:
- use sudo only when not root (the CI containers run as root without a
sudo binary);
- install clang/libclang (FFmpeg's --enable-cuda-llvm and bindgen need
them) and cmake/python3 (the vendored OCIO build), plus the VAAPI dev
packages (libva/libdrm) so hardware decode survives the move off vcpkg;
- fetch nv-codec-headers from FFmpeg's official GitHub mirror instead of
code.videolan.org (git there is behind an anti-bot challenge);
- stay idempotent (clean the header checkout first) and tolerate a
package a distro does not carry (e.g. Ubuntu's multiverse-only
libopenh264-dev): install the rest individually and let FFmpeg's
configure probes drop what is missing.
Verified in a debian:12 container (root): first run installs everything,
second run exits 0.