hn.today

Memory-Safe WebP Decoding

halide.cx68 points25 comments
Screenshot of Memory-Safe WebP Decoding

wpd is a Rust-written WebP decoder that aims to replace libwebp by combining verifiable memory safety with higher performance. It is designed to reduce risks from memory-safety vulnerabilities like CVE-2023-4863 by minimizing unsafe code: the core decoder is safe Rust, SIMD is implemented as optional handwritten assembly that can be omitted to leave only auditable safe code (with a single vetted unsafe dependency for zerocopy). This contrasts with libwebp’s C-based codebase, which relies heavily on unsafe constructs and has historically been a major source of high-severity security bugs. The project targets widespread deployment across browsers, messaging apps, and OS components where untrusted image input is common.

Benchmarks show wpd is faster than libwebp and image-webp: single-threaded lossy decoding is about 1.19× faster and lossless 2.74× faster; multi-threaded gains are larger (2.68× lossy, 3.19× lossless) by exploiting parallel frame decoding for animated WebP. Feature goals include full libwebp parity plus extras: raw subframe decoding, per-frame inspection without full decode, built-in crop/scale/flip, configurable threading and pixel limits, multiple output formats, a C ABI and a Rust API. The project is open-source under BSD 2-Clause and positioned as a drop-in, safer, and faster alternative for projects that need both performance and hardened decoding.

Read on halide.cx25 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.