cloudflare/boringtun
70.5
Strong · 29 September 2026
6.7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a Rust-based implementation of the WireGuard protocol, structured as a library and a command-line interface tool. It manages network tunnels by handling cryptographic operations, device configuration, and packet transmission, while exposing functionality via FFI bindings for integration with other applications. The codebase focuses on concurrency, accurate timing, and standardizing cryptographic primitives through external dependencies.
How it got here
2019 — Dependency consolidation and code cleanup
10 changes.
The project removed its custom cryptographic implementations and legacy source files, replacing them with external crates like ring and x25519-dalek. This period focused on restructuring the codebase into a workspace, updating dependencies to version 0.7.1, and eliminating homegrown concurrency and networking primitives in favor of standard libraries.
2022 — core refactoring and crypto modernization
8 changes.
This period focused on a comprehensive refactoring of the WireGuard device implementation, replacing custom cryptographic primitives with standard RustCrypto libraries and improving concurrency through better synchronization primitives. The work also introduced a new CLI tool, enhanced FFI bindings with logging and stats support, and added sleep-aware timing to ensure reliable tunnel operation across system states.
Features
Introduction of the boringtun CLI tool
A new command-line interface for boringtun has been added, allowing users to manage WireGuard tunnels directly from the terminal. The tool supports configuring tunnel interfaces, setting log verbosity and output files, controlling the number of OS threads, and running in the background as a daemon. It also provides options to disable privilege dropping, disable connected UDP sockets, and manage existing TUN device file descriptors.
boringtun-cli · high confidence
WireGuard stats extended and FFI logging API added
The FFI bindings now expose estimated network loss and round-trip time in the stats structure, allowing consumers to monitor connection quality. Additionally, a new set\_logging\_function API enables external applications to receive trace-level logs via a custom C function pointer, replacing the previous verbosity-based logging model.
boringtun/src/ffi · high confidence
Removals
Removal of custom ChaCha20-Poly1305 implementation
The custom \src/crypto/chacha20poly1305\ module, which contained hand-written Rust implementations of the ChaCha20 cipher and Poly1305 MAC along with their associated test vectors, has been deleted. This change removes the local cryptographic primitives from the codebase, indicating a shift away from this specific in-house implementation.
src/crypto/chacha20poly1305 · high confidence
Removal of legacy boringtun binary and library sources
The original \boringtun\ source files (\src/main.rs\, \src/lib.rs\, and \src/benchmarks\_example.rs\) have been deleted. This removes the standalone userspace WireGuard daemon implementation, its command-line interface (including arguments for tunnel name, logging, and privilege dropping), and the public library crate interface that exposed modules like \crypto\, \ffi\, and \noise\ to external consumers.
src · high confidence
Removal of legacy noise protocol implementation
The legacy noise protocol implementation, including the handshake logic, session management, timer handling, and FFI benchmarking utilities, has been removed from the codebase.
src/noise · high confidence
Removal of local X25519 and crypto module implementations
The local X25519 elliptic-curve implementation, along with the overarching crypto module that re-exported blake2s, chacha20poly1305, and x25519, has been removed from the codebase. This deletion eliminates the custom key structures, arithmetic logic, and ARM-specific random-number-workarounds that were previously maintained in this location, indicating a shift to rely on external or upstream cryptographic primitives instead of the bundled local code.
src/crypto/x25519 · high confidence
Removed benchmark suite for cryptographic primitives
The benchmarking module (\benches/mod.rs\) has been removed, eliminating performance tests for x25519 key generation, blake2s hashing, and chacha20poly1305 encryption/decryption operations. This change removes the ability to measure the performance of these specific cryptographic functions within the boringtun userspace Wireguard implementation.
benches · high confidence
Removed local Blake2s implementation
The custom Blake2s cryptographic module and its associated test vectors in \src/crypto/blake2s\ have been removed from the codebase. This deletion eliminates the internal implementation of the hash function, likely replacing it with an external dependency or standard library alternative.
src/crypto/blake2s · high confidence
Behavioural changes
Integration tests migrate to RustCrypto and add connection retry logic
The integration tests in boringtun have been updated to use the RustCrypto x25519 library (StaticSecret/PublicKey) instead of the previous bespoke implementation, requiring a macOS exclusion for the test suite. Additionally, the test harness now includes a retry mechanism for TCP connections to improve reliability during peer container startup, and the test module has been relocated to the boringtun workspace crate.
_boringtun/src/device/integration\tests · high confidence
Introduces sleep-aware monotonic time measurement
A new \sleepyinstant\ module has been added to provide a monotonic clock that accounts for system sleep time, ensuring timers remain accurate even when the device is suspended. On Unix-like systems (including macOS, iOS, tvOS, FreeBSD, and NetBSD), this is implemented using \CLOCK\_BOOTTIME\ (or \CLOCK\_MONOTONIC\ where \BOOTTIME\ is unavailable) via the \nix\ crate, while Windows uses the standard library's \Instant\. This change ensures that network keep-alives and timeouts in the tunnel do not expire prematurely or behave unexpectedly after the system wakes from sleep.
boringtun/src/sleepyinstant · high confidence
Removed unnecessary assembly emission and renamed Cargo config
The Cargo configuration has been renamed from \config\ to \config.toml\ to follow standard conventions. Additionally, the \\[build\]\ section containing the \--emit asm\ rustflag has been removed, as it was found to break Clippy and was unnecessary for performance.
.cargo · high confidence
Replace custom concurrency and networking primitives with standard library and external crates
The device layer removes several homegrown implementations in favor of standard or external libraries. The custom read/write lock (dev\_lock.rs) is removed, aligning with the move to parking-lot locks for synchronization. The custom IP routing trie (allowed\_ips.rs) is deleted, replaced by the ip\_network\_table crate for handling allowed IPs. Additionally, the custom UDP socket wrapper (udp\_unix.rs) is removed, indicating a shift to using standard networking primitives or external crates for socket management.
src/device · high confidence
WireGuard JNI bindings updated with preshared key support and thread-safe tunnel access
The JNI bindings in \boringtun/src/jni.rs\ have been refactored to support optional preshared keys and configurable keep-alive intervals when creating a new tunnel, allowing for more flexible peer configuration. The underlying tunnel operations (\wireguard\_read\, \wireguard\_write\, etc.) now utilize a \Mutex\ wrapper for thread safety, ensuring concurrent access is handled correctly. Additionally, the FFI header \boringtun/src/wireguard\_ffi.h\ has been updated to reflect these API changes, including the addition of a \set\_logging\_function\ for custom log handling and the removal of the deprecated \benchmark\ function.
boringtun/src · high confidence
WireGuard device implementation refactored for improved concurrency and error handling
The device module has been significantly refactored to improve reliability and performance. The custom socket implementation was replaced with the \socket2\ crate, and the event polling system now uses \parking\_lot\ instead of \spin\ for better concurrency. Error handling has been standardized to use \std::io::Error\ throughout, replacing the previous bespoke \errno\_str\ approach. Additionally, the API now supports registering via a file descriptor (\register\_api\_fd\), macOS privilege dropping uses the \nix\ crate, and the \AllowedIps\ data structure was rewritten to use \IpNetworkTable\ for more efficient IP lookups.
boringtun/src/device · high confidence
WireGuard noise protocol implementation restructured with new error types and crypto libraries
The boringtun noise protocol module has been reorganized into a workspace structure, introducing new files for handshake, session, rate limiting, and timers. The implementation replaces custom cryptographic primitives with standard libraries: XChaCha20-Poly1305 from the \ring\ crate for AEAD operations, Blake2s via the \blake2\ crate for hashing, and \x25519\_dalek\ for key exchange. New error variants \DuplicateCounter\ and \UnderLoad\ have been added to \WireGuardError\ to better handle rate-limiting and replay protection scenarios. The rate limiter now uses \AtomicU64\ for counters and \parking\_lot::Mutex\ for synchronization, improving thread safety and performance. Timer logic has been refined to account for system sleep duration, ensuring accurate session expiration and rekeying behavior.
boringtun/src/noise · high confidence
Test coverage
Add cryptographic benchmark suite using Criterion; Removal of integration test suite.
Dependencies
Boringtun workspace restructured to version 0.7.1 with updated dependencies
The project has been reorganized into a Cargo workspace containing the core \boringtun\ library and the \boringtun-cli\ binary, both set to version 0.7.1. This update brings significant dependency upgrades, including \clap\ to 4.6.0, \ring\ to 0.17, \x25519-dalek\ to 2.0.1, \base64\ to 0.22, and \thiserror\ to 2.0.18. The core library now uses \parking\_lot\ instead of \spin\, \portable-atomic\ for 64-bit atomics, and \ip\_network\_table\ for routing, while the CLI leverages \tracing\ for logging. Link-time optimization is enabled for release and bench profiles.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 72 → 70 (-1.5)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 93 → 93 (+0.0)
- Architecture 100 → 95 (-5.0)
- Maturity 52 → 52 (+0.0)
- Readiness 87 → 84 (-3.1)
- Security 86 → 89 (+3.5)
- Performance 85 (new)
Resolved (2)
- Documentation: no architecture or design documentation (README.md)
- Off-boarding risk: anonymized user #1
New (9)
- Duplicate state accessors between Tunn and Peer. The Peer type exposes getters for time_since_last_handshake and persistent_keepalive which are identical to methods on the underlying Tunn object. Since Peer wraps Tunn, these are redundant pass-throughs that violate the principle of least surprise and increase maintenance surface.
- Inconsistent naming and return types for key serialization across FFI and JNI modules. The FFI module uses x25519_key_to_* returning raw C strings, while the JNI module uses convert_x25519_key_to_* returning Java strings. The verb 'convert' vs 'to' is inconsistent, and the function prefixes differ (x25519_ vs convert_).
- Off the main sequence: boringtun
- Off-boarding risk: anonymized user #1
- Outdated: clap
- Outdated: libc
- Outdated: nix
- Outdated: portable-atomic
- Outdated: thiserror
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cloudflare/boringtun was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6dcc889a95ad82400932f785d874421d70308195 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.