cloudflare/quiche
52.1
Weak · 29 September 2026
111.5k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a Rust-based QUIC and HTTP/3 implementation library, providing core protocol handling, congestion control algorithms (including BBRv2), and an asynchronous Tokio integration layer. It includes a suite of debugging and testing tools for interactive HTTP/3 session manipulation, network log visualization, and automated fuzzing to ensure protocol compliance and stability. The codebase is structured as a modular Cargo workspace, exposing both synchronous and asynchronous APIs for building custom QUIC applications.
How it got here
2018–2021 — Workspace restructuring and HTTP/3 implementation
24 changes.
The project was restructured from a single crate into a modular Cargo workspace, introducing a comprehensive C API and initial HTTP/3 support with QPACK. This period also established robust testing and fuzzing infrastructure while modernizing the codebase with zero-copy buffers and advanced congestion control algorithms.
2022–2025 — tokio-quiche open-source and BBRv2 integration
38 changes.
This period focused on open-sourcing the tokio-quiche async wrapper, establishing a comprehensive public API for QUIC and HTTP/3 integration with Tokio. Concurrently, the core quiche library underwent significant architectural refactoring, including migrating the crypto backend to BoringSSL and introducing the BBRv2 congestion control algorithm. The release also expanded the ecosystem with new tools for debugging, such as the h3i interactive client and the qlog-dancer visualization UI.
2026 — BBR2 RTT detection and test expansion
5 changes.
This period focused on enhancing the BBR2 congestion control module by introducing a new HMM-based RTT jump detector to better distinguish network step-changes from self-queueing. Significant effort was also directed toward expanding test coverage, including round-trip validation for qlog compression, serialization checks, and integration tests for octets buffer operations. Additionally, automation skills were added to streamline the creation of GitHub draft releases for the project.
Features
Add HTTP/3 interop examples for content-length mismatch and stream limits
Added two new examples in the h3i tool to verify RFC-compliant server behavior: \content\_length\_mismatch.rs\ demonstrates sending a request with a Content-Length header indicating 5 bytes but transmitting only 4, expecting a 400 Bad Request response; \stream\_limit.rs\ tests that opening a fourth unidirectional stream against a server advertising a max\_streams\_uni of 3 correctly triggers a StreamLimit error. Both examples target cloudflare-quic.com and utilize the sync client to validate connection summaries.
h3i/examples · high confidence
Add asynchronous HTTP/3 example server
The tokio-quiche library now includes an example asynchronous HTTP/3 server located in \tokio-quiche/examples/async\_http3\_server\. This example demonstrates how to use the library to listen for QUIC connections, handle HTTP/3 streams, and serve responses. It features command-line argument parsing for configuring the server address, TLS certificates, and congestion control settings (such as cubic, reno, or bbr2), as well as options for pacing and HyStart++. The server implementation includes a service function that can stream bytes based on the request path (e.g., \/stream-bytes/\<num\_bytes\>\), showcasing the integration of \tokio-quiche\'s \ServerH3Driver\ and event handling with the \tokio\ runtime.
_tokio-quiche/examples/async\_http3\server · high confidence
Add opt-in gzip and zstd compression for qlog streaming
The qlog crate now supports optional compression for JSON-SEQ qlog streams via new Cargo features. Users can enable the \gzip\ or \zstd\ features to compress output files, which will be saved with \.sqlog.gz\ or \.sqlog.zst\ extensions respectively. The \QlogSeqReader\ automatically detects and decompresses these formats when reading, while the \QlogStreamer\ and \QlogCompression\ enum in the writer module allow producers to select the desired compression algorithm at runtime.
qlog/src · high confidence
Added Android NDK 19 build script
A new shell script, build\_android\_ndk19.sh, has been added to the tools/android directory to facilitate building quiche for Android using NDK 19 or higher. This script automates the build process for multiple architectures (arm64-v8a, armeabi-v7a, x86\_64, x86) targeting API level 21, and explicitly enables the 'ffi' feature during compilation.
tools/android · high confidence
Added Mayhem fuzzing configurations for QUIC packet and QPACK handling
New Mayhem project files have been added to configure fuzzing targets for the QUIC protocol implementation. These configurations define libfuzzer-based tests for client and server packet reception, post-handshake authentication server processing, and QPACK decoding. Each target is set to use the latest Quiche libfuzzer Docker image, with server-side targets configured to load specific certificate and key files for TLS context.
fuzz/mayhem · high confidence
Added async HTTP/3 server example with documentation and test certificates
The tokio-quiche examples now include an asynchronous HTTP/3 server (\async\_http3\_server\) that listens on a configurable address (defaulting to 127.0.0.1:5757) and supports custom TLS certificates via CLI arguments. A new README provides instructions for running the server and testing it with the included \quiche-client\, including a specific \/stream-bytes/\<n\>\ endpoint for verifying data transfer. To support local testing, self-signed TLS certificates (\cert.crt\ and \cert.key\) for \test.com\ have been added, along with a disclaimer in the documentation noting that the example is for demonstration purposes only and lacks production-grade performance, security, or reliability guarantees.
tokio-quiche/examples · high confidence
Automated fuzzing seed generation tool
A new shell script (tools/gen\_fuzz\_seeds.sh) has been added to automate the creation of fuzzing seeds. This tool builds the Quiche applications with fuzzing features enabled, runs a local client-server interaction, captures the exchanged packets, and generates minimized seed files for the client and server fuzzing corpora.
tools · high confidence
HTTP/3 module initial implementation
The HTTP/3 module (quiche/src/h3) has been introduced, providing a high-level API for sending and receiving HTTP/3 requests and responses over QUIC. This includes connection management, stream state machines, frame encoding/decoding, QPACK header compression, and a C FFI layer for external integration.
quiche/src/h3 · high confidence
Initial QPACK encoder and decoder implementation
This change introduces the core QPACK (HTTP/3 Header Compression) components in the \quiche/src/h3/qpack\ module, including the \Encoder\ and \Decoder\ structs, a static header table for efficient lookup, and Huffman encoding support. Users can now encode and decode HTTP headers using the QPACK algorithm, with the encoder supporting static table indexing and literal encoding, and the decoder handling indexed and literal representations while tracking field list sizes to prevent overflow.
quiche/src/h3/qpack · high confidence
Initial fuzzing infrastructure with libfuzzer targets
Added a new fuzzing directory containing libfuzzer-based targets for the packet receiver (client and server sides) and the QPACK decoder. The change includes a Dockerfile to build and package these fuzzers for use with Mayhem, along with a small ECDSA certificate and key required for the fuzzing environment, and a README documenting how to generate seeds, run coverage, and execute the fuzzers.
fuzz · high confidence
Initial interactive CLI prompts for HTTP/3 testing
The h3i tool now includes a new set of interactive CLI prompts for constructing HTTP/3 test actions. This location provides the user-facing interface for selecting and configuring operations such as sending headers (with optional literal encoding), data, settings, push promises, priority updates, and stream management (open, reset, stop-sending). It also supports sending datagrams, closing connections with specific error codes, and waiting for stream events or durations, all driven by the \inquire\ library for input validation and autocomplete.
h3i/src/prompts · high confidence
Initial release of qlog-dancer visualization charts
The qlog-dancer component in qlog-dancer/src/plots has been added, introducing a suite of new visualizations for QUIC connection analysis. This includes charts for connection overview, congestion control (cwnd, bytes in flight), RTT (min, latest, smoothed), packet sent/received timelines, stream multiplexing, and flow control. The implementation supports both static PNG generation and interactive HTML canvas rendering via the plotters library.
qlog-dancer/src/plots · high confidence
Initial release of the Quiche C API header
This change introduces the \quiche.h\ header file, establishing the public C interface for the Quiche QUIC library. It defines the core data structures, error codes, and function signatures required to configure connections, manage TLS settings, and handle QUIC streams from C applications.
quiche/include · high confidence
Introduce BBRv2 congestion control algorithm
Added a new BBRv2 (Bottleneck Bandwidth and Round-trip propagation time) congestion control implementation to the \gcongestion\ module, including its core logic, network model, bandwidth sampling, and pacing mechanisms. This provides an alternative to existing algorithms, offering configurable parameters for startup, drain, probe bandwidth, and probe RTT phases to optimize throughput and latency.
quiche/src/recovery/gcongestion · high confidence
Introduce async h3i client and refine connection summary serialization
The h3i client tool now supports an asynchronous execution mode via a new \async\_client\ module, allowing it to drive connections using \tokio-quiche\ instead of the synchronous \mio\-based loop. This change also updates the \ConnectionSummary\ serialization to include a \missed\_close\_trigger\_frames\ field, enabling users to verify whether all expected close-trigger frames were received during the session.
h3i/src/client · high confidence
Introduce buffer-pool crate with metrics and ConsumeBuffer
The buffer-pool crate is now available, providing a sharded object pool for \ConsumeBuffer\ instances and associated I/O traits (\RawPoolBufIo\, \RawPoolBufDatagramIo\). \ConsumeBuffer\ is a new wrapper around \Vec\<u8\>\ that allows consuming data from the front without shifting, optimizing memory operations. The pool tracks metrics for idle/active counts and bytes, including a global gauge for total \ConsumeBuffer\ memory usage, enabling better monitoring of buffer allocation and reuse.
buffer-pool · high confidence
Introduce customizable connection ID generation and structured handshake error handling
The connection module now exposes a \ConnectionIdGenerator\ trait and a \SimpleConnectionIdGenerator\ implementation, allowing server-side applications to encode custom logic into QUIC source connection IDs while clients continue to use random IDs. Additionally, a new \HandshakeError\ enum (with \Timeout\ and \ConnectionClosed\ variants) provides structured error reporting for handshake failures, replacing generic I/O errors with specific, distinguishable states for users monitoring connection setup.
tokio-quiche/src/quic/connection · high confidence
Introduce datagram-socket library with async datagram abstractions and QUIC statistics
This change introduces the \datagram-socket\ crate, providing a new set of asynchronous datagram socket abstractions. It includes a \DgramBuffer\ type for efficient datagram handling with headroom support, traits (\DatagramSocket\, \ShutdownConnection\) for unified async I/O on UDP and Unix datagram sockets, and Linux-specific \mmsg\ optimizations for batched send/recv operations. Additionally, it exposes detailed \SocketStats\ and \QuicAuditStats\ for monitoring connection metrics such as bandwidth, loss, RTT, and QUIC handshake details.
datagram-socket/src · high confidence
Introduce h3i action definitions for HTTP/3 and QUIC operations
The h3i tool now includes a new \actions\ module that defines the specific operations (actions) used to drive HTTP/3 and QUIC client behavior. This change adds \h3.rs\, which enumerates actions such as sending frames, headers, datagrams, and stream bytes, as well as managing stream lifecycle (opening, resetting, stopping sending) and connection closure. It also introduces wait conditions, allowing the client to pause for specific durations, stream events, or stream quota availability. These actions form the executable sequence that h3i iterates over to simulate and test HTTP/3 interactions.
h3i/src/actions · high confidence
Introduce h3i, an interactive HTTP/3 debugging and testing tool
Adds the h3i crate, a low-level HTTP/3 client designed for debugging and testing server behavior. It allows users to connect to HTTP/3 servers and manually control QUIC streams and HTTP/3 frames, including sending malformed requests, manipulating flow control limits, and enabling datagrams. The tool provides both a synchronous and asynchronous client, configurable via command-line arguments (using clap 4) or by replaying actions from a qlog file, and outputs detailed connection summaries for analysis.
h3i/src · high confidence
Introduce netlog crate for parsing Chrome network logs
Added the \netlog\ crate, a reverse-engineered deserializer for the Chrome netlog format, enabling users to parse line-delimited JSON network logs into structured Rust data. The crate supports QUIC and HTTP/2 and HTTP/3 events, providing modules for constants, HTTP transactions, HTTP/2 sessions, HTTP/3 sessions, and QUIC sessions to facilitate debugging interoperability and performance issues.
netlog · high confidence
Introduce qlog-dancer for visualizing and reporting on QUIC logs
This change adds the initial version of qlog-dancer, a new tool that parses qlog, sqlog, and netlog files to generate visual charts and text/HTML reports. Users can now analyze connection performance through configurable plots (overview, packet sent/received, spark charts, multiplexing, pending data, and flow control) and inspect detailed session statistics, request timing tables, and event lists in both text and HTML formats.
qlog-dancer/src · high confidence
Introduce qlog-dancer web UI for interactive log visualization
Users can now analyze qlog and Chrome netlog files directly in a browser via a new WASM-based web application. This UI, wired to the existing qlog-dancer parsing and plotting engine, allows users to load log files, view interactive charts (such as connection overviews, congestion control, RTT, and stream multiplexing), and filter events using the same Wirefilter DSL available in the CLI. The web interface supports zooming, legend toggling, and dark mode, providing an alternative to the native CLI for interactive, visual analysis.
qlog-dancer · high confidence
Introduce socket capabilities and wrapper types for QUIC networking
This change introduces a new \socket\ module containing \QuicListener\ for server-side QUIC connections and \Socket\ for connected datagram flows, both exposing a \capabilities\ field. It adds \SocketCapabilities\ and \SocketCapabilitiesBuilder\ (Linux-only) to allow users to enable performance-enhancing socket options such as UDP Generic Segmentation Offload (GSO), receive timestamps, and drop reporting, with convenience methods like \apply\_max\_capabilities()\ to enable all supported options automatically.
tokio-quiche/src/socket · high confidence
Introduce structured QUIC connection configuration API
The \tokio-quiche/src/settings\ module now provides a structured, public API for configuring QUIC connections. Users can define connection parameters via \ConnectionParams\ (constructed with \new\_server\ or \new\_client\), which aggregates \QuicSettings\ (covering ALPN, datagrams, flow control, congestion control, PMTUD, and QLOG compression), TLS certificate paths, and connection hooks. This replaces ad-hoc configuration, allowing users to explicitly control transport behavior such as 0-RTT, pacing, and key logging through a unified, type-safe interface.
tokio-quiche/src/settings · high confidence
Introduce task-killswitch library for aborting spawned Tokio tasks
Added a new \task-killswitch\ library that provides a mechanism to spawn Tokio tasks and abort them all at once via a killswitch. The implementation uses a \DashMap\ for low-contention task storage and \AbortHandle\s to terminate tasks, ensuring that tasks are properly removed from the registry even if they panic or complete before registration.
task-killswitch/src · high confidence
Introduce tokio-quiche HTTP/3 driver with configurable settings and audit stats
This change adds the \tokio-quiche/src/http3\ module, providing the core HTTP/3 integration for tokio-quiche. It introduces \Http3Settings\ to allow configuration of connection limits, header sizes, QPACK parameters, timeouts, and the Extended Connect protocol, with a default 16 KiB buffer cap for received body data. The module also exposes \H3AuditStats\ for monitoring stream-level metrics, including byte counts, error codes, and HEADERS flush duration.
tokio-quiche/src/http3 · high confidence
Introduction of zero-copy buffer abstractions and modularized core components
The library introduces a new \BufFactory\ trait and \BufSplit\ interface in \buffers.rs\, enabling applications to provide custom, zero-copy buffer implementations for streams and datagrams instead of relying on the default heap-allocated buffers. This change is accompanied by the extraction of core internal logic into dedicated modules—\buffers.rs\, \cid.rs\ (connection ID management), \dgram.rs\ (datagram queueing), \error.rs\ (error types and wire codes), \ffi.rs\ (C API bindings), \flowcontrol.rs\ (flow control logic), \frame.rs\ (QUIC frame definitions), \lib.rs\ (main connection logic), and \minmax.rs\ (windowed min/max tracking)—restructuring the codebase for better modularity and performance.
quiche/src · high confidence
New BBRv2 congestion control implementation in gcongestion
Quiche now includes a new BBRv2 congestion control implementation in the gcongestion subsystem. This adds the core BBRv2 state machine (Startup, Drain, ProbeBW, ProbeRTT modes) and the network model required to track bandwidth, RTT, and loss, enabling users to benefit from BBRv2's performance characteristics when using the gcongestion interface.
quiche/src/recovery/gcongestion/bbr2 · high confidence
New C and Rust QUIC/HTTP3 example applications
The examples directory now includes complete, buildable reference implementations for QUIC and HTTP/3 in both C and Rust. The C examples (client, server, http3-client, http3-server) are compiled via a new Makefile that links against libquiche and libev, with specific support for Apple Silicon macOS builds. The Rust examples use the mio event loop and demonstrate basic QUIC connectivity and HTTP/3 request/response flows. Additionally, standalone QPACK encode/decode utilities and a certificate generation script are provided to aid in testing and development.
quiche/examples · high confidence
New HMM-based RTT jump detector for BBR2
Added a new Hidden Markov Model (HMM) RTT jump detector to the BBR2 congestion control module, alongside an existing GlobalMin detector. The HMM detector identifies sustained increases in Round-Trip Time (RTT) by tracking the connection's operating elevation above a running minimum, using a 3-state model (Normal, Transient, Persistent) with fixed transition and emission matrices. It standardizes RTT samples against the connection's own baseline to distinguish genuine network step-changes from self-queueing, requiring both a minimum number of elevated samples and a dwell time before committing a persistent jump. This detector is available as an alternative to the simpler GlobalMin approach, which uses a fixed 3x baseline threshold.
_quiche/src/recovery/gcongestion/bbr2/rtt\_jump\detector · high confidence
New HTTP/3 integration test tool with configurable test runner
A new \http3\_test\ crate has been added to provide utilities for building and running HTTP/3 integration tests against an httpbin server. The tool includes a test runner (\runner.rs\) that supports configuring QUIC protocol versions, idle timeouts, maximum data limits, and 0-RTT connection resumption via environment variables. It also allows specifying custom HTTP headers and expected request headers for validation, enabling users to verify server behavior under various HTTP/3 conditions.
_tools/http3\test · high confidence
New bandwidth sampling and windowed filtering components for BBR congestion control
Added the \bandwidth\_sampler\ and \windowed\_filter\ modules to the \gcongestion/bbr\ directory. The \bandwidth\_sampler\ tracks per-packet rate measurements (bandwidth, RTT, send/ack rates) and manages connection state to support BBR's congestion avoidance logic, including specific fixes for A0 point selection consistency with google/quiche. The \windowed\_filter\ implements Kathleen Nichols' algorithm to track minimum or maximum estimates of sample streams over a fixed time interval, which is used by the sampler to derive robust bandwidth and RTT estimates.
quiche/src/recovery/gcongestion/bbr · high confidence
New h3i record/replay module with qlog event support
Added a new \recordreplay\ module to the h3i tool, introducing support for recording HTTP/3 actions and replaying them. This includes a \qlog\ submodule that maps h3i actions (such as sending frames, headers, and opening streams) into qlog events, enabling users to trace and debug HTTP/3 interactions via qlog-compatible logs.
h3i/src/recordreplay · high confidence
New metrics module for QUIC connection and Tokio task instrumentation
The \tokio-quiche\ crate now includes a new \metrics\ module that exposes detailed observability for QUIC connections and underlying Tokio runtime tasks. Users can now track handshake latency stages, write errors (including \WouldBlock\), handshake failures, and HTTP/3 connection closure reasons via standardized labels. Additionally, when the \tokio-task-metrics\ feature is enabled, the module instruments spawned tasks to record schedule delays, poll durations, and total poll times, helping identify waker-related performance issues without the overhead of the standard \tokio-metrics\ crate.
tokio-quiche/src/metrics · high confidence
New modular application library with configurable QUIC and HTTP/3 client options
The \apps/src\ directory has been restructured into a reusable library (\lib.rs\) exposing modules for argument parsing (\args.rs\), client logic (\client.rs\), shared utilities (\common.rs\), and network sending (\sendto.rs\). This change introduces granular configuration capabilities for the QUIC client, allowing users to explicitly set the initial congestion window (\--initial-cwnd-packets\), initial RTT (\--initial-rtt\), and source port (\--source-port\). It also adds support for custom CA certificate verification (\--trust-origin-ca-pem\), active connection migration (\--enable-active-migration\), and Linux-specific Generic Segmentation Offload (GSO) with pacing via the new \sendto\ module. The HTTP/3 client now supports datagram protocols (\--dgram-proto\) and respects flow control and stream limits defined in the new \CommonArgs\ structure.
apps/src · high confidence
New quiche draft release automation skill
Added a new 'quiche-draft-release' skill that automates creating GitHub draft releases for the quiche crate. The skill accepts a commit hash or existing tag, infers the version from Cargo.toml, generates release notes following project guidelines, and uses a helper script to create the draft via the GitHub CLI. The skill is available in both .codex and .opencode directories (the latter via a symlink).
.codex, .opencode · high confidence
Open-source tokio-quiche library
The tokio-quiche crate is now open-sourced, providing the core library files (lib.rs, buf\_factory.rs, result.rs) that bridge quiche and tokio. This release introduces the public API for connecting quiche::Connection and quiche::h3::Connection to the tokio event loop, including the BufFactory for zero-copy packet handling, the BoxError/QuicResult error types, and the listen/connect entry points for HTTP/3 and custom QUIC applications.
tokio-quiche/src · high confidence
Open-source tokio-quiche with async QUIC connection management
The tokio-quiche library is now open-source, exposing the core async QUIC connection management layer. This release introduces a structured architecture that splits socket handling into a dedicated \InboundPacketRouter\ for receiving and an \IoWorker\ loop for processing and sending, supporting both client (\connect\) and server (\listen\) workflows. Key capabilities include customizable TLS contexts via the \ConnectionHook\ trait, path event callbacks for multipath awareness, and a \raw\ submodule for manual packet injection and wrapping existing \quiche::Connection\ instances. The implementation also features optimized connection ID mapping, address validation tokens for server-side RETRY flows, and configurable QLOG file metadata.
tokio-quiche/src/quic · high confidence
Open-sourcing the tokio-quiche HTTP/3 driver
The HTTP/3 driver implementation in \tokio-quiche/src/http3/driver\ is now open-source, exposing the core async driver, client and server hooks, connection wrappers, and datagram flow handling. This change makes the internal \H3Driver\, \H3Controller\, and related types (such as \ClientH3Driver\, \ServerH3Driver\, \StreamCtx\, and \FlowCtx\) publicly available for integration, along with comprehensive test utilities and documentation to guide development.
tokio-quiche/src/http3/driver · high confidence
Open-sourcing tokio-quiche with initial documentation and build configuration
The tokio-quiche crate is now open-source, introducing the core async Tokio wrapper for quiche along with its HTTP/3 driver. This release adds essential project scaffolding including an AGENTS.md knowledge base detailing the crate's structure and conventions, a README with usage examples for HTTP/3 servers and clients, and a build script that detects boringssl version 5.x to enable appropriate configuration flags. It also includes the COPYING license file to formalize the open-source status.
tokio-quiche · high confidence
Removals
Removal of initial QUIC implementation
The initial QUIC implementation (draft-14) has been removed from the source tree. This change deletes the core library modules including \build.rs\, \crypto.rs\, \frame.rs\, \lib.rs\, \octets.rs\, \packet.rs\, and \tls.rs\, which previously provided the foundational packet handling, encryption, and TLS integration for the protocol.
src · high confidence
Remove obsolete QUIC draft-14 server example
The \examples/server.rs\ file has been removed. This example implemented the QUIC protocol using draft-14, which is no longer supported. Users relying on this specific example for server-side implementation should migrate to current examples that support newer protocol versions.
examples · high confidence
Architecture
Introduce modular QUIC packet routing with dedicated acceptor and connector components
The \tokio-quiche\ QUIC router has been restructured into distinct \acceptor.rs\ and \connector.rs\ modules to separate server-side connection acceptance from client-side connection management. The \ConnectionAcceptor\ now handles incoming server connections, including QUIC handshake initialization, connection ID generation, and optional qlog/keylog configuration. The \ClientConnector\ manages client-initiated connections, tracking their state (queued, pending, returned) and handling timeout logic. These components feed into the central \InboundPacketRouter\, which routes incoming packets to the appropriate handler based on connection state, improving code organization and maintainability of the QUIC stack.
tokio-quiche/src/quic/router · high confidence
Introduction of the octets crate for zero-copy packet handling
The \octets\ module has been extracted into its own crate, providing a zero-copy abstraction for parsing and constructing network packets. This new library includes core utilities such as the \Octets\ and \OctetsMut\ types for safe, offset-aware byte buffer manipulation, varint encoding/decoding helpers, and HPACK Huffman encoding/decoding capabilities (exposed via the \huffman\_hpack\ feature). For users, this represents a structural reorganization that centralizes low-level binary protocol handling into a reusable, standalone component.
octets/src · high confidence
Repository restructured into a Cargo workspace with new CI and documentation
The project has been converted from a single crate into a Cargo workspace containing 11 crates (including \quiche\, \tokio-quiche\, \apps\, and \qlog\), replacing the legacy Travis CI configuration with a new GitLab CI stub and Docker build targets. This change introduces a comprehensive \AGENTS.md\ knowledge base, a \RELEASING.md\ guide, and a Backstage \catalog-info.yaml\ for internal service discovery, while removing obsolete files like \README.rst\ and \TODO.rst\.
(repo-wide) · high confidence
Restructured congestion control logic into a dedicated module
The congestion control implementation has been moved from the top-level recovery directory into a new \quiche/src/recovery/congestion\ module. This change introduces separate source files for the CUBIC and Reno algorithms, along with supporting modules for HyStart++, Proportional Rate Reduction (PRR), delivery rate estimation, and the core recovery logic. This reorganization consolidates all congestion-related state and behavior in one location, making the codebase easier to navigate and maintain.
quiche/src/recovery/congestion · high confidence
Stream module refactored into separate receive and send buffer submodules
The stream handling logic in quiche has been reorganized by splitting the previous monolithic stream module into dedicated submodules for receive buffers (recv\_buf.rs) and send buffers (send\_buf.rs), while the main module (mod.rs) now coordinates stream maps and flow control. This structural change isolates the internal buffering mechanisms for incoming and outgoing stream data, improving code maintainability without altering the external API or user-facing behavior.
quiche/src/stream · high confidence
Behavioural changes
1 commit (0 fixes) modifying fuzz/corpus/packets\_posths\_server, fuzz/corpus/packets\_recv\_server
A change to existing behaviour in fuzz/corpus/packets\_posths\_server, fuzz/corpus/packets\_recv\_server — 1 commit, 4 files.
_fuzz/corpus/packets\_posths\_server, fuzz/corpus/packets\_recv\server · medium confidence · unverified
Introduce stage-based connection lifecycle and Linux GSO optimizations
The \tokio-quiche\ I/O layer now manages connections through a \ConnectionStage\ trait with distinct \Handshake\, \RunningApplication\, and \Close\ states, ensuring that application read/write processing only occurs during the \RunningApplication\ phase. On Linux, the implementation adds support for UDP Generic Segmentation Offload (GSO) via the \gso\ module, enabling batched packet sends with configurable segment sizes and transmission timing control. Additionally, a \BandwidthReporter\ is introduced to track and expose real-time bandwidth estimates and loss percentages for active connections.
tokio-quiche/src/quic/io · high confidence
Qlog event schema updated to align with latest IETF drafts
The qlog event structures have been refactored to align with the latest IETF specifications (draft-ietf-quic-qlog-quic-events-01 and draft-ietf-quic-qlog-h3-events-12). This includes renaming the HTTP/3 module from 'h3' to 'http3', removing QPACK-specific event types, and updating serialization formats for events such as MTU updates and ACK ranges. Additionally, the event time field has been changed from f32 to f64 for improved precision, and extension data support (ex\_data) has been added to events to allow for custom metadata.
qlog/src/events · high confidence
Quiche client and server binaries moved to apps/src/bin with new CLI and performance options
The quiche-client and quiche-server executables have been relocated from the examples directory to apps/src/bin, now using a shared argument-parsing library (quiche\_apps::args) for consistent CLI handling. The server binary now exposes several new configuration options: GSO support can be explicitly disabled via --disable-gso, packet pacing can be toggled with --disable-pacing, and Path MTU Discovery can be enabled via --enable-pmtud. Additionally, the server logs both source and destination addresses, and the client and server now expose initial RTT configuration via CLI. These changes provide users with finer control over QUIC connection behavior and performance tuning directly from the command line.
apps/src/bin · high confidence
Removed BoringSSL build script
The utility script \util/get\_bssl.sh\ has been removed. This script previously handled cloning the BoringSSL repository, checking out a specific commit, and building the library. Its removal indicates a shift in how BoringSSL is integrated into the project, likely moving towards a submodule approach or a different build system configuration as suggested by the commit history.
util · medium confidence
Reorganized QUIC loss detection and congestion control into a modular, dual-implementation architecture
The recovery subsystem has been restructured to support two parallel congestion control implementations: a legacy Reno/CUBIC engine and a next-generation BBR2 engine (ported from google/quiche). The \Recovery\ enum now dispatches between \LegacyRecovery\ and \GRecovery\ via the \RecoveryOps\ trait, allowing users to select the algorithm via configuration. This change introduces dedicated modules for bandwidth estimation (\bandwidth.rs\), bytes-in-flight tracking (\bytes\_in\_flight.rs\), and RTT statistics (\rtt.rs\), while moving congestion-specific logic into \congestion/\ and \gcongestion/\ subdirectories. The new architecture also exposes configuration options for BBR2 parameters, relaxed loss thresholds, and initial RTT, and includes comprehensive documentation in \AGENTS.md\ to guide future development.
quiche/src/recovery · high confidence
Switch QUIC crypto backend from Ring to BoringSSL
The QUIC cryptographic operations in the library have been migrated from the Ring library to BoringSSL. This change introduces a new BoringSSL-specific implementation module that handles AEAD encryption, header protection, and key derivation using BoringSSL's native APIs (such as EVP\_AEAD\_CTX). For users, this represents a significant architectural shift in the underlying crypto provider, potentially affecting performance characteristics and binary dependencies, while maintaining the same public API for packet encryption and decryption.
quiche/src/crypto · high confidence
TLS backend refactored to use BoringSSL with NonNull safety and new handshake APIs
The TLS module in quiche/src/tls has been rewritten to exclusively use BoringSSL, removing the previous OpenSSL backend. This change introduces safer memory management by using NonNull for owned BoringSSL pointers and LazyLock for static initialization, replacing older patterns like once\_cell and manual memory handling. It also exposes new capabilities for configuring early data (0-RTT) via set\_early\_data\_enabled and set\_quic\_early\_data\_context, and allows inspecting handshake details such as curve, signature algorithm, and peer certificate chain.
quiche/src/tls · high confidence
Updated interop runner endpoint script with new client/server options
The interop runner's endpoint script now includes specific command-line flags for the Quiche client and server to improve compatibility and test coverage. The client is configured with a higher active connection ID limit (8) and explicit wire version settings, while the server enables active migration, disables GSO and pacing, and supports early data (0-RTT) and session resumption. These changes ensure the runner correctly handles 0-RTT and resumption interop tests and aligns with the simulation environment's network constraints.
apps · high confidence
Test coverage
Added HTTP/3 integration tests for httpbin endpoints; Added integration test infrastructure for tokio-quiche; Added integration tests for octets buffer operations and Huffman encoding; Added integration tests for tokio-quiche; Added qlog serialization and deserialization tests; Added round-trip tests for qlog writer compression; Expanded QPACK decoder fuzzing corpus; Initial fuzzing infrastructure for QUIC and HTTP/3; Updated fuzzing corpus for packet\_recv\_client.
Dependencies
Quiche project restructured into a Cargo workspace
The project has been reorganized from a single crate into a Cargo workspace containing multiple independent crates: quiche (the core QUIC implementation), tokio-quiche (the async wrapper), qlog (logging), h3i (HTTP/3 testing tool), and several utility crates (buffer-pool, datagram-socket, netlog, octets, task-killswitch, qlog-dancer). This structure centralizes dependency management in the root Cargo.toml and allows each component to be developed and versioned independently while sharing common configuration and linting rules.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 52 (+1.1)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 81 → 81 (-0.0)
- Architecture 98 → 93 (-5.3)
- Maturity 76 → 77 (+0.2)
- Readiness 43 → 47 (+3.8)
- Security 61 → 61 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 41 → 41 (+0.0)
- Performance 100 (new)
Resolved (14)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (tokio-quiche/examples/README.md)
- Documentation: no usage examples (README.md)
- Documentation: written for insiders (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: quiche/src/h3/frame.rs (quiche/src/h3/frame.rs)
- Hotspot: quiche/src/recovery/mod.rs (quiche/src/recovery/mod.rs)
- Hotspot: quiche/src/stream/recv_buf.rs (quiche/src/stream/recv_buf.rs)
- Hotspot: tokio-quiche/src/quic/router/mod.rs (tokio-quiche/src/quic/router/mod.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- TodoComment (quiche/src/tests.rs)
- TodoComment (quiche/src/tests.rs)
New (18)
- Ambiguous intent between get and get_empty. It is unclear if get returns a buffer with existing data or if it is an alias for get_empty. If get is the standard allocator, get_empty is redundant or confusingly named.
- Change coupling: recv_buf.rs ↔ tests.rs (quiche/src/stream/recv_buf.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate function signature with different parameter names (fd vs _fd) in the same module. This suggests copy-paste error or unresolved conflict.
- High: security finding (details withheld)
- Hotspot: apps/src/client.rs (apps/src/client.rs)
- Hotspot: quiche/src/recovery/gcongestion/bbr2.rs (quiche/src/recovery/gcongestion/bbr2.rs)
- Inconsistent error handling for similar operations. ConsumeBuffer returns a boolean (likely success/fail), while DgramBuffer returns a Result. This forces users to handle errors differently for conceptually identical buffer manipulation.
- Inconsistent return types for 'as' accessors. as_raw_io returns a typed borrow (BorrowedFd), while as_buf_io returns a String (likely a name or path). This breaks the expectation that as_* methods return references or borrows of the underlying type.
- Naming inconsistency between send_headers_frame and send_headers_frame_literal. The distinction (literal vs encoded?) is not obvious from the name alone and lacks a consistent pattern (e.g., encode vs raw).
- Off the main sequence: netlog
- Off the main sequence: octets
- Off the main sequence: qlog
- Off the main sequence: task-killswitch
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- TodoComment (quiche/src/tests.rs)
- Unstable project tokio-quiche
Changes since last survey
- 26 commits — 25 feature/other, 1 fixes
By area
- quiche/src — 9 commits
- (root) — 6 commits
- qlog-dancer/Cargo.toml — 3 commits
- tokio-quiche/src — 2 commits
- .codex/skills — 1 commit
- .github/workflows — 1 commit
- h3i/src — 1 commit
- quiche/Cargo.toml — 1 commit
- quiche/examples — 1 commit
- tokio-quiche/tests — 1 commit
Notable commits
- fix: fix connection flow-control double-counting from zero-length STREAM frames
- change: Add BBR param to configure cwnd lower bound (#2732)
- change: build(deps): update getrandom requirement from 0.3 to 0.4
- change: build(deps): update intrusive-collections to 0.10.3
- change: build(deps): update ipnetwork requirement from 0.20 to 0.21
- change: build(deps): update nix requirement from 0.30.1 to 0.31.3
- change: build(deps): update table_to_html requirement from 0.9.0 to 0.11.0
- change: build(deps): update wasm-streams requirement from 0.4 to 0.6
- change: build: upgrade boring to 5.2 with 4.19 compatibility
- change: ci: prepare i686 multiarch builds for boring 5
- change: ci: use MSYS2 for Windows MinGW jobs
- change: examples: link the C examples with the C++ compiler driver
- change: ffi: populate max_rtt in PathStats
- change: h3i: add send capacity factor config option
- change: h3i: release 0.7.0
- change: loosen initial_cwnd's bbr2_gcongestion tolerance in tests
- change: opencode: replace .opencode/skills/ with symlink to .codex
- change: path: add PMTU path event
- change: quiche: release 0.30.0
- change: recovery: emit app-limited state in qlog
- …and 6 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cloudflare/quiche was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cdf610571c76f0a41927466b6e27c6ec12e3fc82 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-70910855e4b4.