giflib-rs is an AI-assisted port of giflib to Rust. It is an API-compatible drop-in replacement written in a memory safe language.
Note
If API compatibility is not a strict requirement, we recommend using the gif crate instead. It has idiomatic Rust APIs while being substantially faster.
giflib-rs does not use unsafe in any of the business logic, but requires
unsafe to provide a C API and deal with pointers passed from C.
We use
safer_cffi
to put up guardrails where possible.
- Setting
GifFile->Erroron invalid dimensions: When an image descriptor has invalid dimensions (width or height ≤ 0, or width × height overflow), C'sDGifSlurpreturnsGIF_ERRORbut does not setGifFile->Error(leaving it at 0). Rust'sdgif_slurpreturnsGIF_ERRORand setsGifFile->Error = D_GIF_ERR_DATA_TOO_BIG(108).
This is a deliberate change to remove what we consider a bug in C implementation. - File Writing: Rust checks the return code of
write()calls and returns an error on failure. The C implementation silently ignores write failures and returnsGIF_OK.
This is a deliberate change to improve over the C version. - OOM Handling: The Rust version panics on allocation error, whereas the C version returns an error code. This typically does not affect Linux-based systems, which overcommit memory and then use the OOM Killer instead of failing allocations.
This is not an officially supported Google product. This project is not eligible for the Google Open Source Software Vulnerability Rewards Program.