wpd is a Rust-written WebP decoder that aims to replace libwebp by combining verifiable memory safety with higher performance. It is designed to reduce risks from memory-safety vulnerabilities like CVE-2023-4863 by minimizing unsafe code: the core decoder is safe Rust, SIMD is implemented as optional handwritten assembly that can be omitted to leave only auditable safe code (with a single vetted unsafe dependency for zerocopy). This contrasts with libwebp’s C-based codebase, which relies heavily on unsafe constructs and has historically been a major source of high-severity security bugs. The project targets widespread deployment across browsers, messaging apps, and OS components where untrusted image input is common.
Benchmarks show wpd is faster than libwebp and image-webp: single-threaded lossy decoding is about 1.19× faster and lossless 2.74× faster; multi-threaded gains are larger (2.68× lossy, 3.19× lossless) by exploiting parallel frame decoding for animated WebP. Feature goals include full libwebp parity plus extras: raw subframe decoding, per-frame inspection without full decode, built-in crop/scale/flip, configurable threading and pixel limits, multiple output formats, a C ABI and a Rust API. The project is open-source under BSD 2-Clause and positioned as a drop-in, safer, and faster alternative for projects that need both performance and hardened decoding.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.