Allow ffmpeg and ffprobe input arguments to be configured
From uloza+hey@proton.me · original ↗ · unsubscribe
Two new configuration parameters are introduced. config.active_storage.video_preview_input_arguments is passed to ffmpeg before -i, and config.active_storage.ffprobe_arguments is passed to ffprobe before the file path. Both default to empty string.
Allow ffmpeg and ffprobe input arguments to be configured by flavorjones · Pull Request #58461 · rails/rails · GitHub
Navigation Menu
Appearance settings
-
Platform
-
AI CODE CREATION
-
DEVELOPER WORKFLOWS
-
APPLICATION SECURITY
-
EXPLORE
-
-
Solutions
-
BY COMPANY SIZE
-
BY USE CASE
-
BY INDUSTRY
-
-
Resources
-
EXPLORE BY TOPIC
-
EXPLORE BY TYPE
-
SUPPORT & SERVICES
-
-
Open Source
-
COMMUNITY
-
PROGRAMS
-
REPOSITORIES
-
-
Enterprise
Search/
Appearance settings
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
Uh oh!
There was an error while loading. Please reload this page.
- Notifications You must be signed in to change notification settings
- Fork 22.4k
- Code
- Issues 485
- Pull requests 1.1k
- Discussions
- Actions
- Security and quality 26
- Insights
Additional navigation options
Allow ffmpeg and ffprobe input arguments to be configured - #58461
#58461
Merged
flavorjones merged 1 commit into
rails:mainrails/rails:mainfrom
flavorjones:video-input-argumentsflavorjones/rails:video-input-argumentsCopy head branch name to clipboard
Aug 12, 2026
ConversationCommits1 (1)ChecksFiles changed
Merged
##
Allow ffmpeg and ffprobe input arguments to be configured#58461
flavorjones merged 1 commit into
rails:mainrails/rails:mainfrom
flavorjones:video-input-argumentsflavorjones/rails:video-input-argumentsCopy head branch name to clipboard
Conversation
###
flavorjones commented Aug 12, 2026
Copy link
Copy Markdown
Member
Motivation / Background
Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage cannot express that constraint.
ffmpeg’s flags are position dependent. -codec_whitelist and -protocol_whitelist must appear before -i, and config.active_storage.video_preview_arguments is inserted after it.
ffprobe has no argument configuration at all.
Applying an allowlist therefore means overriding a private method in ActiveStorage::Previewer::VideoPreviewer or in either analyzer. An override of probe_from restates the whole argument list, so it drifts whenever Rails changes the probe.
Detail
This Pull Request introduces two new configuration parameters:
config.active_storage.video_preview_input_arguments, passed to ffmpeg before-iconfig.active_storage.ffprobe_arguments, passed to ffprobe before the file path
Both default to "", so the command lines are unchanged for an application that does not set them.
ffprobe_arguments is named for the tool because ActiveStorage::Analyzer::VideoAnalyzer and ActiveStorage::Analyzer::AudioAnalyzer build the same ffprobe command line.
As an example, an application that accepts only H.264 video with AAC audio would configure:
config.active_storage.video_preview_input_arguments = “-codec_whitelist h264,aac” config.active_storage.ffprobe_arguments = “-codec_whitelist h264,aac”
With that example configuration, the previewer command line changes from:
ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -
to:
ffmpeg -codec_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -
and both analyzer command lines change from:
ffprobe -print_format json -show_streams -show_format -v error /tmp/blob.mp4
to:
ffprobe -print_format json -show_streams -show_format -v error -codec_whitelist h264,aac /tmp/blob.mp4
The security guide gains a “Media Processing of File Uploads” section covering these parameters and the input flags listed above.
Additional information
This is not itself a security fix. It gives an application the means to harden media processing where it needs to.
Checklist
Before submitting the PR make sure the following are checked:
- This Pull Request is related to one change. Unrelated changes should be opened in separate PRs.
- Commit message has a detailed description of what changed and why. If this PR fixes a related issue include it in the commit message. Ex:
[Fix #issue-number] - Tests are added or updated if you fix a bug or add a feature.
- CHANGELOG files are updated for the changed libraries if there is a behavior change or additional feature. Minor bug fixes and documentation changes should not be included.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
[Allow ffmpeg and ffprobe input arguments to be configured](/rails/rails/pull/58461/commits/a79729b9cad2ae64ada2e8b478fd62c9d4577d65 "Allow ffmpeg and ffprobe input arguments to be configured Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage could not express that constraint. ffmpeg's flags are position dependent. `-codec_whitelist` and `-protocol_whitelist` must appear before `-i`, and `config.active_storage.video_preview_arguments` was inserted after it. ffprobe had no argument configuration at all. Applying an allowlist therefore meant overriding a private method in `ActiveStorage::Previewer::VideoPreviewer` or in either analyzer. An override of `probe_from` restated the whole argument list, so it drifted whenever Rails changed the probe. Two new configuration parameters will be introduced: * `config.active_storage.video_preview_input_arguments`, passed to ffmpeg before `-i` * `config.active_storage.ffprobe_arguments`, passed to ffprobe before the file path Both will default to `\"\"`, so the command lines will be unchanged for an application that does not set them. `ffprobe_arguments` will be named for the tool because `ActiveStorage::Analyzer::VideoAnalyzer` and `ActiveStorage::Analyzer::AudioAnalyzer` build the same ffprobe command line. As an example, an application that accepts only H.264 video with AAC audio would configure: config.active_storage.video_preview_input_arguments = \"-codec_whitelist h264,aac\" config.active_storage.ffprobe_arguments = \"-codec_whitelist h264,aac\" With that example configuration, the previewer command line will change from: ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 - to: ffmpeg -codec_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 - and both analyzer command lines will change from: ffprobe -print_format json -show_streams -show_format -v error /tmp/blob.mp4 to: ffprobe -print_format json -show_streams -show_format -v error -codec_whitelist h264,aac /tmp/blob.mp4 The security guide will gain a \"Media Processing of File Uploads\" section covering these parameters and the input flags listed above. This is not itself a security fix. It will give an application the means to harden media processing where it needs to.") …
[a79729b](/rails/rails/pull/58461/commits/a79729b9cad2ae64ada2e8b478fd62c9d4577d65)
Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage could not express that constraint.
ffmpeg’s flags are position dependent. `-codec_whitelist` and `-protocol_whitelist` must appear before `-i`, and `config.active_storage.video_preview_arguments` was inserted after it.
ffprobe had no argument configuration at all.
Applying an allowlist therefore meant overriding a private method in `ActiveStorage::Previewer::VideoPreviewer` or in either analyzer. An override of `probe_from` restated the whole argument list, so it drifted whenever Rails changed the probe.
Two new configuration parameters will be introduced:
* `config.active_storage.video_preview_input_arguments`, passed to ffmpeg before `-i` * `config.active_storage.ffprobe_arguments`, passed to ffprobe before the file path
Both will default to `””`, so the command lines will be unchanged for an application that does not set them.
`ffprobe_arguments` will be named for the tool because `ActiveStorage::Analyzer::VideoAnalyzer` and `ActiveStorage::Analyzer::AudioAnalyzer` build the same ffprobe command line.
As an example, an application that accepts only H.264 video with AAC audio would configure:
config.active\_storage.video\_preview\_input\_arguments = "-codec\_whitelist h264,aac"
config.active\_storage.ffprobe\_arguments = "-codec\_whitelist h264,aac"
With that example configuration, the previewer command line will change from:
ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -
to:
ffmpeg -codec\_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -
and both analyzer command lines will change from:
ffprobe -print\_format json -show\_streams -show\_format -v error /tmp/blob.mp4
to:
ffprobe -print\_format json -show\_streams -show\_format -v error -codec\_whitelist h264,aac /tmp/blob.mp4
The security guide will gain a “Media Processing of File Uploads” section covering these parameters and the input flags listed above.
This is not itself a security fix. It will give an application the means to harden media processing where it needs to.
github-actions Bot added railties docs activestorage labels Aug 12, 2026
flavorjones requested a review from jeremy August 12, 2026 18:03
jeremy approved these changes Aug 12, 2026
jeremy added this to the 8.2.0 milestone Aug 12, 2026
Hide details View details
flavorjones merged commit 7b911de into rails:main Aug 12, 2026
4 of 5 checks passed
Uh oh!
There was an error while loading. Please reload this page.
flavorjones deleted the video-input-arguments branch August 12, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
### Reviewers
jeremy jeremy approved these changes
Assignees
No one assigned
Labels
Projects
None yet
Milestone
Development
Successfully merging this pull request may close these issues.
Uh oh!
There was an error while loading. Please reload this page.
2 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Footer
Footer navigation
- Terms
- Privacy
- Security
- Status
- Community
- Docs
- Contact
- Manage cookies
- Do not share my personal information
You can’t perform that action at this time.