Sign in

jcupitt.bsky.social

@jcupitt.bsky.social
28 followers 12 following 79 posts
PostsRepliesMedia
jcupitt.bsky.social @jcupitt.bsky.social · 14h
Sorry, I skimmed your post and missed the java2d bit. I need stronger specs :(
000
jcupitt.bsky.social @jcupitt.bsky.social · 07/10/2026
You need to have the image handling code as a separate process in its own sandbox, as Hot Cell does. Though there are JVMs with sandboxes, something like that would probably fix it too.
100
jcupitt.bsky.social @jcupitt.bsky.social · 07/10/2026
I'd guess JRuby would not prevent image handling library exploits. These things are usually in native code (eg. the recent Rails exploit was in the external libmatio library), and code there is not bound by the JVM security model (as far as I know).
100
jcupitt.bsky.social @jcupitt.bsky.social · 19/09/2026
JXL and AVIF ought to work in libvips, eg. `vips copy 3198.gif[n=-1] 3198.jxl`. libvips AVIF load and save doesn't do the animation metadata yet, but you get the set of frames and it'll play. For a 140 frame video clip I see:
$ ls -lS
total 10024
-rw-r--r-- 1 john john 4617750 Sep 19 09:24 3198.png
-rw-r--r-- 1 john john 4135763 Sep 19 09:23 3198.gif
-rw-r--r-- 1 john john  716361 Sep 19 09:24 3198.jxl
-rw-r--r-- 1 john john  505200 Sep 19 09:24 3198.webp
-rw-r--r-- 1 john john  278545 Sep 19 09:24 3198.avif
000
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
That's true, it can be an easy call in some cases.
010
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
Those are the two great motors of OSS dev: trusting someone, and taking responsibility for something. gen-AI doesn't really help with either, imo. You can't trust it, and it can't take responsibility.
110
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
I think that's always been a problem :( libvips is LGPL, so we ask people to make sure their code is compatible with that (eg. no copyright infringement). We usually can't check ourselves, instead you take it on trust.
110
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
Bug reports are fine. We mostly write our own patches, since that's less work than reviewing.
010
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
I feel bad deleting what might be good code. However, no human spent any time on them, so in a way, nothing has been lost.
110
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
Reading a large LLM PR is just an awful experience. Almost no one will do it for $0. If I get even one or two PRs like that a week, I won't get anything else done, and I'll be miserable. The only choice we have is to delete all PRs that smell like gen-AI unread.
120
jcupitt.bsky.social @jcupitt.bsky.social · 16/09/2026
For me, the main issue is maintainer workload. A stranger could spend 5 on a refactor (for example) and submit a 1,000 line PR. As a maintainer, I'm *responsible* for the security of the codebase. I need to read that PR line by line and convince myself that nothing sneaky is happening.
120
jcupitt.bsky.social @jcupitt.bsky.social · 06/09/2026
libvips is three people in their spare time. Reviewing large genAI PRs is miserable, and I think almost no one will do it for fun. Combined with the legal issues, my feeling is that most OSS projects will be forced to go no-genAI in the next year or two.
030
jcupitt.bsky.social @jcupitt.bsky.social · 17/08/2026
True, though 8.13 was released five years ago, so you'd hope there would be very few people still using it.
110
jcupitt.bsky.social @jcupitt.bsky.social · 08/08/2026
So the blocking system was the third attempt. libvips operation dispatch is done via GObject, so it's easy to add a thing to the base class to block dispatch of untrusted objects. libvips users can safely turn parts of the library on and off at runtime without needing to recompile anything. Phew!
110
jcupitt.bsky.social @jcupitt.bsky.social · 08/08/2026
This is obviously terrible for web services. libvips urged people to make their own libvips binary for a while, but of course no one did haha. We also tried splitting the library into modules, so packagers could have a libvips-untrusted with the unsafe loaders, but no one used that.
110
jcupitt.bsky.social @jcupitt.bsky.social · 08/08/2026
One more factor: libvips has these exotic loaders because they are useful for scientific work with local, trusted images. Packagers like Debian and Homebrew have a policy of enabling *all* optional dependencies, even if they are dangerous with untrusted data. They don't want user compilation.
110
jcupitt.bsky.social @jcupitt.bsky.social · 29/07/2026
I'm heading this way too. It takes several rounds to get LLM PRs into a reasonable shape. It's quicker to close the PR and then rewrite by hand. Reviewing PRs used to help someone, but that's not true now. No one benefits if I talk to an LLM, and it's not fun for me.
010
jcupitt.bsky.social @jcupitt.bsky.social · 23/07/2026
Oh, perspective distort example in this ancient stackoverflow answer: stackoverflow.com/a/50219715/8...
stackoverflow.com
How to perform perspective distort transformation in VIPS?
Is it possible to do the following ImageMagick perspective distort command using VIPS? If so, what would the command be (using ruby-vips)? $ convert my_file.png -matte -virtual-pixel transparent +
010
jcupitt.bsky.social @jcupitt.bsky.social · 23/07/2026
You can do tricks like generating the map at lower resolution if the transform is expensive to compute, but it should usually be fast enough I think. For that 6k x 4k JPG I see: $ time ./cod.py ~/pics/theo.jpg x.jpg real 0m0.408s user 0m1.780s sys 0m0.360s
010
jcupitt.bsky.social @jcupitt.bsky.social · 23/07/2026
Yes, `mapim`. You can use `xyz` to make an image where the value of a pixel is its coordinate, then transform that with the formula for your transformation. There's an example in pyvips: github.com/libvips/pyvi...
before and after transformation to polar
120
jcupitt.bsky.social @jcupitt.bsky.social · 22/07/2026
libvips has arbitrary 2D transforms, though I don't think sharp exposes them.
110
jcupitt.bsky.social @jcupitt.bsky.social · 21/07/2026
Or a fancier version in webgl that'll play on your phone or in your browser. Touch, keyboard and mouse controls, no dependencies, 2900 lines of simple code, gravity, snooker ball collisions, GPU particles everywhere! jcupitt.github.io/argh-steroid...
jcupitt.github.io
Argh-steroids -- webgl game
010
jcupitt.bsky.social @jcupitt.bsky.social · 21/07/2026
I did a slightly fancier asteroids game in about 1300 lines of python: github.com/jcupitt/argh... Ancient arcade games are fun programming exercises!
github.com
GitHub - jcupitt/argh-steroids: Asteroids-like game using pygame
Asteroids-like game using pygame. Contribute to jcupitt/argh-steroids development by creating an account on GitHub.
220
jcupitt.bsky.social @jcupitt.bsky.social · 11/07/2026
What makes you think I might not want to disengage and have been misled by some aspect of your previous answers? #nobots
100
jcupitt.bsky.social @jcupitt.bsky.social · 10/07/2026
The responses are very weird, you're right. I'll disengage.
120
jcupitt.bsky.social @jcupitt.bsky.social · 10/07/2026
Sure, libvips tries to make the most of most formats and format libraries. PNG is very slow, swap them for JPG and it'll be maybe 4x faster.
110
jcupitt.bsky.social @jcupitt.bsky.social · 10/07/2026
I like lanczos3 as well, and I think it's the default (or was the default?) for imagemagick. "mks2021" might be another fun one to check.
110
jcupitt.bsky.social @jcupitt.bsky.social · 10/07/2026
Install pyvips with "pip install pyvips[binary]" and it'll download and use the correct libvips binary for you. On my PC pyvips will process 100 6k x 4k PNGs in c. 17s, vs. 35s for pillow. Though speed doesn't matter much, as you say. Quality should be the same.
120
jcupitt.bsky.social @jcupitt.bsky.social · 10/07/2026
for libvips, you'd change your script to be: img = pyvips.Image.new_from_file(photo) thumb = img.resize(WIDTH / img.width, kernel="lanczos3") out = THUMBS / (photo.stem + ".webp") thumb.write_to_file(out, Q=QUALITY) And add "import pyvips" at the top.
320
jcupitt.bsky.social @jcupitt.bsky.social · 17/06/2026
This chapter in the docs explains how this works: www.libvips.org/API/current/...
libvips.org
Vips: Technical background > Opening files
Reference for Vips-8.0: Technical background > Opening files
000
jcupitt.bsky.social @jcupitt.bsky.social · 17/06/2026
Nice! I noticed your code does this: ins = pyvips.Image.new_from_file(filename) ins.tiffsave(output_path, ...) You can make it quite a lot faster if you do this instead: ins = pyvips.Image.new_from_file(filename, access="sequential") ins.tiffsave(output_path, ...)
100
jcupitt.bsky.social @jcupitt.bsky.social · 30/05/2026
Go up a little way and set your new "google-web" engine as the default. Ta da! No more AI, no more related products, just google like it used to be way back when, when it was useful. Combine with a good ad blocker if you want to go even further.
010
jcupitt.bsky.social @jcupitt.bsky.social · 30/05/2026
If you look at the URL, "&udm=web" in the search string. All you need to do to make the web view the default is to add this to every query. In your browser prefs, look for the "search" section, then add a new search engine called eg. "google-web" with the URL: www.google.com/search?q=%s&...
google.com
Google Search
100
jcupitt.bsky.social @jcupitt.bsky.social · 30/05/2026
You can block the AI overview in FF and chrome using your browser preferences. On the google results page, click the "more" button just below the text bar, then click "web". You'll get a simple list of pages which match your search, like google used to do back in the 2000s.
200
jcupitt.bsky.social @jcupitt.bsky.social · 07/04/2026
libvips deliberately doesn't attempt to preserve image compression settings. It's not possible (with most image format libraries anyway) to do this correctly. When you write an image, you have to say how you'd like it written (`--palette` for a palette PNG, for example).
000
jcupitt.bsky.social @jcupitt.bsky.social · 28/03/2026
Where the medieval London bridge was, about 30m east of the current London Bridge. You can see the line in the current street layout -- follow Gracechurch Street due South past The Monument.
110
jcupitt.bsky.social @jcupitt.bsky.social · 09/02/2026
Hello, libvips dev here, I'd trim down the dependencies. You're adding support for a lot of formats you won't need, and with loaders which are not tested with untrusted input. You can also set the env var `VIPS_BLOCK_UNTRUSTED` and libvips will block unsafe loaders at runtime.
000
jcupitt.bsky.social @jcupitt.bsky.social · 08/01/2026
Well done! I'm a little puzzled by the libvips version though, is that correct? 8.14 is three years old. Debian trixie is on 8.16, and current stable libvips is 8.18.
000
Reposted by @jcupitt.bsky.social
Remi's RPM repository @remirepo.net · 17/12/2025
💎 Enhancement update: - vips-8.18.0-1 github.com/libvips/libv...
github.com
Release v8.18.0 · libvips/libvips
The libvips 8.18 release notes are here: https://www.libvips.org/2025/12/04/What's-new-in-8.18.html Notable changes since 8.17: add dcrawload, dcrawload_source, dcrawload_buffer: load raw camera f...
011
jcupitt.bsky.social @jcupitt.bsky.social · 17/12/2025
libvips 8.18 is out! github.com/libvips/libv... The release notes are here: www.libvips.org/2025/12/04/W... The headline features are support for UltraHDR, camera RAW images, and Oklab/Oklch colourspace. Thanks and congratulations to all contributors!
libvips.org
What's new in libvips 8.18
A fast image processing library with low memory needs.
031
jcupitt.bsky.social @jcupitt.bsky.social · 15/05/2025
Do you mean under the new pact? That has a maximum of 30,000 a year I think (not an expert).
020
jcupitt.bsky.social @jcupitt.bsky.social · 28/04/2025
v3.0 of pyvips, the libvips binding for python, is out! pypi.org/project/pyvi... This release is much easier to install -- it's just `pip install pyvips[binary]` and it'll automatically download the right libvips for your platform. Linux / macOS / Win, x64 and arm64.
pypi.org
Client Challenge
010
jcupitt.bsky.social @jcupitt.bsky.social · 26/03/2025
Have a look at eg: github.com/jcupitt/buil... Though I expect you know all this.
github.com
020
jcupitt.bsky.social @jcupitt.bsky.social · 26/03/2025
I made a nip2.app a long time ago: github.com/jcupitt/buil... and it includes the libvips dylib. It would need updating, but maybe there's something useful in there?
nip2.app
210
jcupitt.bsky.social @jcupitt.bsky.social · 20/03/2025
And the oldest bits of libvips are from 1989 o.O Though it's been mostly rewritten a couple of times in those 35 years, to be fair. I sometimes start talks with "was anyone here born before 1989?" and there have been a few times where no one has raised a hand haha.
110
jcupitt.bsky.social @jcupitt.bsky.social · 25/02/2025
nip4 has a first test release! github.com/jcupitt/nip4... This is a rewrite of nip2 for the gtk4 UI toolkit. The backend is all the same, so it should run all old workspaces, but the UI is new and quite a bit slicker. Any feedback would be very welcome!
github.com
Release v9.0.1-3 · jcupitt/nip4
First public release A windows binary is in the assets tag below. For linux, there's a PR to add nip4 to flathub here: flathub/flathub#6166 You can install one of the test releases from that PR wit...
020
jcupitt.bsky.social @jcupitt.bsky.social · 01/02/2025
- the underlying image processing library is pure, functional, and lazy, hence the low memory use - the scripting language (dynamic Haskell with classes) is also pure, functional and lazy - the GUI is built with gtk4, so it all renders on your GPU for smooth 60fps animations
020
jcupitt.bsky.social @jcupitt.bsky.social · 01/02/2025
nip4, the libvips image processing spreadsheet, is almost done! www.libvips.org/2025/01/31/n... It's correctly loading all the test workspaces I have, including a monster with 8.500 rows and 15,000 images. I'm aiming for late Feb for a first alpha release.
libvips.org
nip4 January progress
A fast image processing library with low memory needs.
140