← Back to Issue

Allow ffmpeg and ffprobe input arguments to be configured

From uloza+hey@proton.me · original ↗ · unsubscribe

Two new configuration parameters are introduced. config.active_storage.video_preview_input_arguments is passed to ffmpeg before -i, and config.active_storage.ffprobe_arguments is passed to ffprobe before the file path. Both default to empty string.


Allow ffmpeg and ffprobe input arguments to be configured by flavorjones · Pull Request #58461 · rails/rails · GitHub

Skip to content

Sign in

Appearance settings

Search/

Sign in

Sign up

Appearance settings

You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert

Uh oh!

There was an error while loading. Please reload this page.

rails / rails Public

Additional navigation options

Allow ffmpeg and ffprobe input arguments to be configured - #58461

#58461

Merged

flavorjones merged 1 commit into

rails:mainrails/rails:mainfrom

flavorjones:video-input-argumentsflavorjones/rails:video-input-argumentsCopy head branch name to clipboard

Aug 12, 2026

ConversationCommits1 (1)ChecksFiles changed

Merged

##

Allow ffmpeg and ffprobe input arguments to be configured#58461

flavorjones merged 1 commit into

rails:mainrails/rails:mainfrom

flavorjones:video-input-argumentsflavorjones/rails:video-input-argumentsCopy head branch name to clipboard

Conversation

@flavorjones

###

@flavorjonesflavorjones commented Aug 12, 2026

Copy link

Copy Markdown

Member

Motivation / Background

Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage cannot express that constraint.

ffmpeg’s flags are position dependent. -codec_whitelist and -protocol_whitelist must appear before -i, and config.active_storage.video_preview_arguments is inserted after it.

ffprobe has no argument configuration at all.

Applying an allowlist therefore means overriding a private method in ActiveStorage::Previewer::VideoPreviewer or in either analyzer. An override of probe_from restates the whole argument list, so it drifts whenever Rails changes the probe.

Detail

This Pull Request introduces two new configuration parameters:

  • config.active_storage.video_preview_input_arguments, passed to ffmpeg before -i
  • config.active_storage.ffprobe_arguments, passed to ffprobe before the file path

Both default to "", so the command lines are unchanged for an application that does not set them.

ffprobe_arguments is named for the tool because ActiveStorage::Analyzer::VideoAnalyzer and ActiveStorage::Analyzer::AudioAnalyzer build the same ffprobe command line.

As an example, an application that accepts only H.264 video with AAC audio would configure:

config.active_storage.video_preview_input_arguments = “-codec_whitelist h264,aac” config.active_storage.ffprobe_arguments = “-codec_whitelist h264,aac”

With that example configuration, the previewer command line changes from:

ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -

to:

ffmpeg -codec_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -

and both analyzer command lines change from:

ffprobe -print_format json -show_streams -show_format -v error /tmp/blob.mp4

to:

ffprobe -print_format json -show_streams -show_format -v error -codec_whitelist h264,aac /tmp/blob.mp4

The security guide gains a “Media Processing of File Uploads” section covering these parameters and the input flags listed above.

Additional information

This is not itself a security fix. It gives an application the means to harden media processing where it needs to.

Checklist

Before submitting the PR make sure the following are checked:

  • This Pull Request is related to one change. Unrelated changes should be opened in separate PRs.
  • Commit message has a detailed description of what changed and why. If this PR fixes a related issue include it in the commit message. Ex: [Fix #issue-number]
  • Tests are added or updated if you fix a bug or add a feature.
  • CHANGELOG files are updated for the changed libraries if there is a behavior change or additional feature. Minor bug fixes and documentation changes should not be included.

Sorry, something went wrong.

Uh oh!

There was an error while loading. Please reload this page.

All reactions@flavorjones

[Allow ffmpeg and ffprobe input arguments to be configured](/rails/rails/pull/58461/commits/a79729b9cad2ae64ada2e8b478fd62c9d4577d65 "Allow ffmpeg and ffprobe input arguments to be configured Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage could not express that constraint. ffmpeg's flags are position dependent. `-codec_whitelist` and `-protocol_whitelist` must appear before `-i`, and `config.active_storage.video_preview_arguments` was inserted after it. ffprobe had no argument configuration at all. Applying an allowlist therefore meant overriding a private method in `ActiveStorage::Previewer::VideoPreviewer` or in either analyzer. An override of `probe_from` restated the whole argument list, so it drifted whenever Rails changed the probe. Two new configuration parameters will be introduced: * `config.active_storage.video_preview_input_arguments`, passed to ffmpeg before `-i` * `config.active_storage.ffprobe_arguments`, passed to ffprobe before the file path Both will default to `\"\"`, so the command lines will be unchanged for an application that does not set them. `ffprobe_arguments` will be named for the tool because `ActiveStorage::Analyzer::VideoAnalyzer` and `ActiveStorage::Analyzer::AudioAnalyzer` build the same ffprobe command line. As an example, an application that accepts only H.264 video with AAC audio would configure: config.active_storage.video_preview_input_arguments = \"-codec_whitelist h264,aac\" config.active_storage.ffprobe_arguments = \"-codec_whitelist h264,aac\" With that example configuration, the previewer command line will change from: ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 - to: ffmpeg -codec_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 - and both analyzer command lines will change from: ffprobe -print_format json -show_streams -show_format -v error /tmp/blob.mp4 to: ffprobe -print_format json -show_streams -show_format -v error -codec_whitelist h264,aac /tmp/blob.mp4 The security guide will gain a \"Media Processing of File Uploads\" section covering these parameters and the input flags listed above. This is not itself a security fix. It will give an application the means to harden media processing where it needs to.") …

[a79729b](/rails/rails/pull/58461/commits/a79729b9cad2ae64ada2e8b478fd62c9d4577d65)

Constraining which demuxers and decoders ffmpeg and ffprobe will use is a hardening measure for the media-processing attack surface, and Active Storage could not express that constraint.

ffmpeg’s flags are position dependent. `-codec_whitelist` and `-protocol_whitelist` must appear before `-i`, and `config.active_storage.video_preview_arguments` was inserted after it.

ffprobe had no argument configuration at all.

Applying an allowlist therefore meant overriding a private method in `ActiveStorage::Previewer::VideoPreviewer` or in either analyzer. An override of `probe_from` restated the whole argument list, so it drifted whenever Rails changed the probe.

Two new configuration parameters will be introduced:

* `config.active_storage.video_preview_input_arguments`, passed to ffmpeg before `-i` * `config.active_storage.ffprobe_arguments`, passed to ffprobe before the file path

Both will default to `””`, so the command lines will be unchanged for an application that does not set them.

`ffprobe_arguments` will be named for the tool because `ActiveStorage::Analyzer::VideoAnalyzer` and `ActiveStorage::Analyzer::AudioAnalyzer` build the same ffprobe command line.

As an example, an application that accepts only H.264 video with AAC audio would configure:

config.active\_storage.video\_preview\_input\_arguments = "-codec\_whitelist h264,aac"
config.active\_storage.ffprobe\_arguments = "-codec\_whitelist h264,aac"

With that example configuration, the previewer command line will change from:

ffmpeg -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -

to:

ffmpeg -codec\_whitelist h264,aac -i /tmp/blob.mp4 -vf 'select=...' -frames:v 1 -f image2 -

and both analyzer command lines will change from:

ffprobe -print\_format json -show\_streams -show\_format -v error /tmp/blob.mp4

to:

ffprobe -print\_format json -show\_streams -show\_format -v error -codec\_whitelist h264,aac /tmp/blob.mp4

The security guide will gain a “Media Processing of File Uploads” section covering these parameters and the input flags listed above.

This is not itself a security fix. It will give an application the means to harden media processing where it needs to.

@github-actions github-actions Bot added railties docs activestorage labels Aug 12, 2026

@flavorjones

flavorjones requested a review from jeremy August 12, 2026 18:03

jeremy

jeremy approved these changes Aug 12, 2026

View reviewed changes

@jeremy jeremy added this to the 8.2.0 milestone Aug 12, 2026

Hide details View details

@flavorjones

flavorjones merged commit 7b911de into rails:main Aug 12, 2026

4 of 5 checks passed

Uh oh!

There was an error while loading. Please reload this page.

@flavorjones

flavorjones deleted the video-input-arguments branch August 12, 2026 19:01

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

### Reviewers

@jeremyjeremy jeremy approved these changes

Assignees

No one assigned

Labels

activestorage docs railties

Projects

None yet

Milestone

8.2.0

Development

Successfully merging this pull request may close these issues.

Uh oh!

There was an error while loading. Please reload this page.

2 participants

@flavorjones@jeremy

Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

© 2026 GitHub, Inc.

You can’t perform that action at this time.

Highlights & notes

    Notes