7 ms·
Germany's Sovereign Tech Fund Now Supporting FFmpeg
- bestouff 2y ago[flagged]
- jacooper 2y agoJust read the Twitter account of ffmpeg just to see what they thinks about this, spoiler alert: he doesn't like it to say the least.
- vigneshv_psg 2y agoare you talking about a specific thread? if so, could you please link to it. i see some generic posts about how ffmpeg is written in C and Assembly and will not be re-written in C++, but nothing about Rust.
- troupo 2y agoRewrite for the sake of rewriting sounds like fun. How useful is it?
- nwah1 2y agoFor an enormous project like this, it is probably more reasonable to just use the latest version of C, and turn on lots of linters and sanitizers. You could also use one of the various strict subsets of C that is oriented for safety. Might as well tell people to rewrite WebKit or Linux in Rust. There are projects that aim at building browsers or kernels in Rust, but the man-millennia of effort put into the existing projects means catching up is no small feat. Even the coreutils rewrite has taken like a decade and isn't done. And that is a small and well-defined goal by comparison.
- wffurr 2y agoWhat other big projects like Chromium and Android are doing is writing new code in Rust and investing in interop with the existing C and C++ code, along with fuzzing and sanitizing.
- deleted 2y ago[deleted]
- 128keaton 2y ago[dead]
- devwastaken 2y agoYou're not wrong. Media codecs are a good attack vector. However, it's not so simple. You need hand crafted SIMD to reach desired performance. That is a whole area of specialized theory and research. I think it should be done, but who is going to fund it?
- blipvert 2y agoGermany’s Sovereign Tech Fund? ;-)
- deciduously 2y agoIt would involve unsafe rust anyway, which does sequester but not eliminate the concern. I think it would be difficult to make a case that this effort is worthwhile.
- mrob 2y agoYou don't necessarily need all the code to be fast. I think writing correctness validators in a memory-safe language would go a long way toward securing media formats. Run the validator on all untrusted media to confirm it strictly conforms to the specification before playing it in the fast-but-unsafe player. This should make things a lot more difficult for attackers. As a bonus, it would be a useful debugging tool for encoders.
- Scaevolus 2y agoIf your project is amenable to it, it's possible to wrap ffmpeg in a gvisor (runsc) docker container and greatly reduce the risk.
- lyu07282 2y agoI would say if you plug user uploaded files into ffmpeg, it would be complete negligence not to sandbox it in some way.
- xnyan 2y agoSerious question, let's say you had a ton of money and wanted to get this done, is there physically enough available Rust talent (at market rates) in the world today to port ffmpeg to rust in any reasonable amount of time? My understanding is that it's one of the biggest open source projects in terms of LoC, development hours needed to both create and maintain, and number of former and active developers working on the project.
- IshKebab 2y agoThere definitely is. You don't need support for all the obscure formats that ffmpeg supports. It would still cost a lot though.
- martinsnow 2y agoPerhaps you don't need it. But that doesn't mean a lot of others find them very useful.
- deleted 2y ago[deleted]
- tstrimple 2y agoIf it doesn’t support the formats, it’s not a replacement for ffmpeg. It’s a competitor with fewer capabilities. I’m sure people will flock to that just for the excuse of saying they are using a rust library.
- IshKebab 2y ago> If it doesn’t support the formats, it’s not a replacement for ffmpeg. That's dumb. Like saying a car isn't a replacement for a horse because it can't jump over hedges. Most people do not care about the obscure formats at all. > I’m sure people will flock to that just for the excuse of saying they are using a rust library. Well, for not having to worry about trivial security bugs, yes I suspect they would flock to it! Especially for server side video processing.
- aliher1911 2y agoIt will possibly kill lots of community contributions. Currently its easy to add missing features to things like filters. Who is going to do that in rust? I'm yet to see a practicing rust programmer IRL.
- IshKebab 2y agoI feel like using Wuffs would make more sense.
- Cyph0n 2y agoI am a huge Rust fan, and also a huge FFmpeg fan. What exactly does a complete rewrite of FFmpeg achieve given the absolutely monstrous complexity involved?
- LtWorf 2y agoMore bugs, but none of them are double free?
- KetoManx64 2y agoHave you ever rewritten a project in a completely different language?
- Uehreka 2y agoTo be fair, ffmpeg is highly modular, some parts of it are probably already in Rust. I feel like rewriting certain extremely high-use libraries like libx264 could be done if like, 5 really productive Rust engineers with codec experience took it on for 12 months. I’m not saying it’s needed, just that ffmpeg is the kind of thing that could be rewritten gradually if there was interest and a lot of dedicated talent.
- martinsnow 2y agoWhat on earth would that accomplish?
- tom306 2y ago[flagged]
- lyu07282 2y agoYou are getting down voted, but you aren't really wrong, there have been 142 vulnerabilities[1] in ffmpeg since 2018, 3 in this year so far. The attack surface is huge, with mostly memory corruption issues being found. Not sure rust is the answer or what else could be done, but we shouldn't pretend it isn't an issue. [1] https://stack.watch/product/ffmpeg/ffmpeg/ https://stack.watch/product/ffmpeg/ffmpeg/
- tstrimple 2y agoSo they found and fixed 142 vulnerabilities in the last 3 years and folks are advocating for them to abandon all that good work and build a new framework from scratch which reintroduces tons more bugs that are completely undiscovered. Seems like an insane path to stability to me.
- lyu07282 2y agoYou are missing the point. Nearly 100% of those bugs are due to the fact that it is written in a memory unsafe language, FFmpeg is 23 years old and we still find memory corruption bugs in it every few months. That's why people are saying to perhaps use a memory safe language instead, I don't understand why people give this such a hostile response, it has been widely accepted that C is dangerous and can not ever be made safe, to suggest anything different is denying reality.
- bogantech 2y agoA lot of it is written in ASM for performance reasons. Besides that, there's always a bunch of "this should be rewritten completely in <hot new language>" as if it's trivial to rewrite software like this from scratch but nobody ever steps up and does it, I wonder why that is?
- deleted 2y ago[deleted]
- ChrisMarshallNY 2y agoGlad to hear this. ffmpeg is one of these "Too Important to Fail" libraries. I'll lay odds that billions of dollars rely on it, and it's an open-source tool.
- deleted 2y ago[deleted]
- harha 2y agoThis is creating bad incentives - now the billions of dollars relying on that have no interest in fixing the issue and they'll do the same for other projects.
- ChrisMarshallNY 2y agoOr … we could look at it as a type of “Local Loop Unbundling,” ensuring that it acts as a neutral resource for all.
- nisa 2y agoIt's very good that ffmpeg gets support and the sovereign tech fund is a good idea but for me it again just highlights how perverted the incentives to support open source are. Millions of dollars are extracted by using ffmpeg from a lot of corporations, yet the German taxpayer pays for maintenance.
- Phelinofist 2y agoFinally my taxes are put to good use for once
- foxandmouse 2y agobefore any of us bein patting ourselves on the back, It's prolly best to acknowledge that without Frances copyright laws this project along with many others would've been killed by lawyers.
- chimeracoder 2y ago> before any of us bein patting ourselves on the back, It's prolly best to acknowledge that without Frances copyright laws this project along with many others would've been killed by lawyers. How are French copyright laws responsible for this?
- jallmann 2y agoThis is great news, but simultaneously disappointing that it is necessary. FFmpeg underpins tens of billions of dollars in value for the companies that use it, yet the support from the community is proportionally minuscule.
- jongjong 2y agoIt's weird when you consider how much money corporations waste on complete bs that they can't set aside a tiny amount to support the software they use. So weird, it sounds like a conspiracy theory.
- idle_zealot 2y agoWhat's the conspiracy? Why would a company support a Free software project if it didn't have to, out of the good of its heart?
- jongjong 2y agoFor the same reason that they hire cleaners to clean the windows of their buildings and pay people to check cables in their data centers. To make sure that their business isn't going to fall apart.
- bogantech 2y agoIt's necessary because anytime there's talk about the original authors of open source software making money rather than big corps everyone starts frothing at the mouth and forking things to protect the leeches.
- deleted 2y ago[deleted]