Skip to main content

Module webp

Module webp 

Source
Expand description

WebP.

A RIFF container, so structurally the closest thing in this crate to the PNG handler: a flat list of chunks, each with a four-character code and its own length, walked once and filtered. Where PNG puts its metadata in tEXt, zTXt, iTXt, tIME, eXIf, and iCCP, WebP puts all of it in exactly three chunks — ICCP, EXIF, and XMP — plus whatever a producer left in an unknown chunk.

Everything here follows RFC 9649, which is the WebP container’s authoritative specification (verified 2026-08-19); section numbers below refer to it.

§Chunk surgery, never re-encoding, and no checksums anywhere

Kept chunks are copied through as raw bytes — code, length, payload, and RIFF padding byte verbatim. WebP carries no per-chunk CRC at all (§2.3), so unlike PNG there is not even a checksum to preserve, and the only field in the whole file that has to be recomputed is the RIFF chunk’s own size. A file with nothing to remove therefore strips to a byte-identical copy of itself, and idempotence follows from the design rather than from a test passing.

§VP8X is the one chunk this handler rewrites

An extended-format file opens with a VP8X chunk whose flags byte declares which optional parts the file has: an ICC profile, an alpha channel, Exif metadata, XMP metadata, an animation (§2.7, Figure 7). Remove the ICCP, EXIF, or XMP chunk and leave the matching bit set, and the file now lies about itself — some decoders warn, some refuse.

So those three bits are cleared, and nothing else in the chunk is touched: the alpha and animation bits, the reserved bits, and the canvas dimensions are copied byte for byte (ADR-0023). This is the same trade the JPEG handler already makes when it rewrites APP0 to zero a thumbnail’s dimensions (ADR-0021) — a kept structure is corrected rather than left inconsistent with what was removed. A VP8X whose metadata bits are already clear is copied through untouched, so the rewrite happens only where it changes something.

§No decompressor, again

Nothing WebP puts metadata in is compressed at the container level: ICCP holds a profile, EXIF holds a TIFF block the shared reader in [crate::formats::exif] handles directly, and XMP holds a plain XML packet. As with PNG (ADR-0022), strypt-core gains no dependency and no inflate path for this format.

§What is checked, and what is not

Every length in the file was chosen by whoever made it, so every one is read through [crate::container::riff] and every failure is a typed error rather than a panic. The declared RIFF size bounds the walk: bytes beyond it are trailing data and go, and a RIFF size that runs past the end of the file is a lie and the file is refused rather than clamped.

The chunk walk itself is not here — it moved to [crate::container::riff] when WAV became its second caller (ADR-0039). What stays is everything that is WebP rather than RIFF: the form type, VP8X’s fixed length, the shape check, the flag correction, and ANMF.

Structs§

WebpHandler
Removal of metadata from WebP images.