Expand description
WebP.
A RIFF container, so structurally the closest thing in this crate to the PNG handler: a
flat list of chunks, each with a four-character code and its own length, walked once and
filtered. Where PNG puts its metadata in tEXt, zTXt, iTXt, tIME, eXIf, and
iCCP, WebP puts all of it in exactly three chunks — ICCP, EXIF, and XMP — plus
whatever a producer left in an unknown chunk.
Everything here follows RFC 9649, which is the WebP container’s authoritative specification (verified 2026-08-19); section numbers below refer to it.
§Chunk surgery, never re-encoding, and no checksums anywhere
Kept chunks are copied through as raw bytes — code, length, payload, and RIFF padding byte verbatim. WebP carries no per-chunk CRC at all (§2.3), so unlike PNG there is not even a checksum to preserve, and the only field in the whole file that has to be recomputed is the RIFF chunk’s own size. A file with nothing to remove therefore strips to a byte-identical copy of itself, and idempotence follows from the design rather than from a test passing.
§VP8X is the one chunk this handler rewrites
An extended-format file opens with a VP8X chunk whose flags byte declares which optional
parts the file has: an ICC profile, an alpha channel, Exif metadata, XMP metadata, an
animation (§2.7, Figure 7). Remove the ICCP, EXIF, or XMP chunk and leave the
matching bit set, and the file now lies about itself — some decoders warn, some refuse.
So those three bits are cleared, and nothing else in the chunk is touched: the alpha and
animation bits, the reserved bits, and the canvas dimensions are copied byte for byte
(ADR-0023). This is the same trade the JPEG handler already makes when it rewrites APP0
to zero a thumbnail’s dimensions (ADR-0021) — a kept structure is corrected rather than
left inconsistent with what was removed. A VP8X whose metadata bits are already clear is
copied through untouched, so the rewrite happens only where it changes something.
§No decompressor, again
Nothing WebP puts metadata in is compressed at the container level: ICCP holds a profile,
EXIF holds a TIFF block the shared reader in [crate::formats::exif] handles directly,
and XMP holds a plain XML packet. As with PNG (ADR-0022), strypt-core gains no
dependency and no inflate path for this format.
§What is checked, and what is not
Every length in the file was chosen by whoever made it, so every one is read through
[crate::container::riff] and every failure is a typed error rather than a panic. The
declared RIFF size bounds the walk: bytes beyond it are trailing data and go, and a RIFF size
that runs past the end of the file is a lie and the file is refused rather than clamped.
The chunk walk itself is not here — it moved to [crate::container::riff] when WAV became its
second caller (ADR-0039). What stays is everything that is WebP rather than RIFF: the form
type, VP8X’s fixed length, the shape check, the flag correction, and ANMF.
Structs§
- Webp
Handler - Removal of metadata from WebP images.