Skip to content

current ffmpeg · wasi · no cgo

ffmpeg-wasi

Every FFmpeg-in-WebAssembly hit the same wall. This one went under it.

Current FFmpeg as a sandboxed WebAssembly module for the server, plus a native driver for speed. It links the libav* libraries directly and drives them with its own small engine, so a Go program can transcode, filter and mux media embedded, CGO-free and sandboxed under wazero, and the same jobs run at native speed when the sandbox is not the point.

Or build it from source and run it yourself, if you want to see how it is made.

Current, not EOL

Always tracks the latest stable FFmpeg, rather than the years-old release every other WASI build pinned. For a library whose whole job is parsing untrusted media, the security backports are the point.

Under the threading wall

FFmpeg 7 made its command-line tool multithreaded, which a pure-Go runtime cannot run. ffmpeg-wasi skips the CLI, links the libraries single-threaded, and drives them with its own engine.

Sandboxed and CGO-free

One .wasm module that runs anywhere a WASI runtime does. Built for wazero, so a Go binary embeds it, cross-compiles to a single static file, and never shells out.

A native driver, same engine

The same engine and the same job spec, built for the host with real threads and SIMD. Roughly 50× (openh264) to 170× (libx264) the sandboxed software-encode speed, driven out-of-process by afmpeg.

A job spec, not a command line

The engine takes a typed, versioned job spec: probe, process with a full filter_complex, frames and version. Exactly as capable as the engine, with no half-implemented CLI to fall through.

Signed, checksummed, accounted for

Every release ships checksums.txt, a detached OpenPGP signature over it, and a provenance.json naming the FFmpeg version, build tag and commit. One signature certifies the whole release.

Where to go

Before you start, check it does what you need. Limits & what is not supported is the short list of things ffmpeg-wasi deliberately will not do: no ffmpeg command lines, no network inputs, no hardware acceleration, no HEVC or AV1 encode from the .wasm module, and a native driver for linux/amd64 only.

Status

Released. Releases ship the latest stable FFmpeg as lgpl and gpl builds, in a lean and an intermediate profile, both as portable WASI modules and as native drivers (spec 0028, threads + SIMD, driven by afmpeg's native backend). The native driver adds a third full profile with HEVC (x265) and AV1 (SVT-AV1) encode. The engine transcodes (decode → filter → encode → mux) over a virtual filesystem: the probe, process (full filter_complex), frames, and version ops all work today. Design: afmpeg spec 0007.

Further reading

Everything written about the estate, including the curated guides, is on the blog.

Ask phpbotscout

phpbotscout

He answers questions about the projects over on the Discord, citing the docs where they already cover it, and offering to raise an issue where they don't. Bring a bug, an idea, or a questionable engineering decision.

Join the Discord