quinn-rs/quinn
65.8
Adequate · 30 September 2026
35k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Quinn is a Rust implementation of the QUIC transport protocol that provides a flexible, runtime-agnostic library for building networked applications. It supports configurable congestion control algorithms, multiple cryptographic backends, and optimized UDP handling across various platforms, including specialized paths for Apple systems. The system includes comprehensive tooling for performance benchmarking, fuzzing, and integration testing to ensure protocol correctness and stability under load.
How it got here
2018–2019 — API overhaul and cryptographic expansion
12 changes.
This period focused on restructuring the Quinn codebase by removing legacy implementation modules and introducing a new Incoming API for connection handling. Significant updates included adopting the Rust 2024 edition, adding support for the aws-lc-rs cryptographic backend, and expanding the test suite to cover high-load stability and post-quantum key exchange.
2020–2021 — congestion control and performance optimization
10 changes.
This period focused on enhancing network efficiency and performance by introducing multiple congestion control algorithms, including CUBIC, NewReno, and BBR. Significant improvements were made to packet handling through MTU discovery, packet pacing, and platform-specific UDP optimizations like Apple's fast-path. The work also included building comprehensive benchmarking tools and expanding fuzzing coverage to validate the robustness of the QUIC protocol implementation.
2022–2025 — Runtime abstraction and platform expansion
9 changes.
The project introduced a pluggable async runtime trait to decouple core I/O from specific backends like Tokio and smol, while significantly expanding platform support to include WebAssembly, watchOS, and Solaris. Concurrently, the codebase underwent structural refactoring to modularize QUIC configuration and UDP control message handling, accompanied by the addition of comprehensive integration tests and performance benchmarks.
Features
Abstracted async runtime support for Tokio and smol
Quinn now supports pluggable async runtimes via a new \Runtime\ trait in \quinn/src/runtime\. This change introduces dedicated implementations for Tokio (\TokioRuntime\) and smol (\SmolRuntime\), allowing users to choose their preferred async ecosystem. The abstraction decouples Quinn's core I/O and timer operations from specific runtime APIs, enabling runtime independence while maintaining performance through optimized UDP socket handling and timer integration for each backend.
quinn/src/runtime · high confidence
Add CUBIC and NewReno congestion controllers
Users can now select between CUBIC and NewReno congestion control algorithms for QUIC connections. The CUBIC implementation follows RFC 8312, optimizing for high-bandwidth, high-latency networks with features like cubic window growth and TCP-friendliness, while NewReno provides a standard, integer-based congestion avoidance mechanism suitable for general use cases. Both controllers are exposed as configurable options within the congestion module.
quinn-proto/src/congestion · high confidence
Introduce Apple fast-path UDP implementation
Added a new \apple\_fast\ module that uses the private \sendmsg\_x\ and \recvmsg\_x\ APIs on Apple platforms to batch UDP sends and receives, improving performance. This fast path is opt-in and gracefully falls back to the standard single-packet send/recv implementation if the symbols are unavailable or if the feature is disabled.
quinn-udp/src · high confidence
Introduce BBR congestion control algorithm
Adds a new BBR (Bottleneck Bandwidth and RTT) congestion controller to quinn-proto, aiming to reduce buffer bloat and improve performance on high bandwidth-delay product networks. This change introduces the core BBR implementation in \src/congestion/bbr/mod.rs\, along with supporting modules for bandwidth estimation (\bw\_estimation.rs\) and min/max tracking (\min\_max.rs\). Users can now opt into this algorithm for potentially better throughput and lower latency compared to traditional loss-based controllers.
quinn-proto/src/congestion/bbr · high confidence
Introduce aws-lc-rs as an alternative cryptographic backend
Users can now choose between the \ring\ and \aws-lc-rs\ libraries for cryptographic operations in QUIC connections. This change adds a new \ring\_like.rs\ module that implements the internal crypto traits using either \ring\ or \aws\_lc\_rs\ (selected via Cargo features), allowing \aws-lc-rs\ to be used as a drop-in replacement for \ring\ for AEAD, HMAC, and HKDF operations.
quinn-proto/src/crypto · high confidence
Introduces packet pacing and MTU discovery to improve network efficiency
The connection logic now includes a token-bucket pacer that limits the sending rate based on the congestion window and RTT, batching traffic to reduce burstiness. Additionally, Datagram Packetization Layer Path Maximum Transmission Unit Discovery (PLPMTUD) is implemented to automatically detect the optimal path MTU, with a black-hole detector to recover from MTU mismatches. These changes apply to the core connection state, datagram handling, and packet building modules.
quinn-proto/src/connection · high confidence
New Incoming API and lock-tracking diagnostics
The library introduces a new \Incoming\ type for handling server-side connection attempts, providing explicit methods to accept, refuse, retry, or ignore connections, along with an \IntoFuture\ implementation for ergonomic awaiting. A new \lock\_tracking\ feature adds a custom \Mutex\ wrapper that monitors lock acquisition and hold times, emitting warnings if locks are held for more than 1 millisecond to help identify performance bottlenecks.
quinn/src · high confidence
New QUIC example applications and documentation
The \quinn/examples\ directory now includes a set of runnable examples demonstrating core QUIC capabilities, accompanied by a \README.md\ with usage instructions. The \server\ and \client\ examples implement a simple HTTP/0.9 file transfer protocol, featuring automatic self-signed certificate generation, configurable TLS key logging, and connection limiting. The \connection\ example provides a minimal setup for establishing a basic QUIC connection. The \insecure\_connection\ example demonstrates how to bypass server certificate verification for testing purposes. Finally, the \single\_socket\ example shows how to manage multiple concurrent QUIC connections over a single UDP socket.
quinn/examples · high confidence
New QUIC performance benchmarking tool with configurable transport and optional encryption bypass
A new performance testing application has been added to the \perf\ crate, providing client and server binaries to benchmark QUIC connections. Users can now measure throughput, latency, and request rates over unidirectional and bidirectional streams, with output available in table or JSON formats. The tool exposes extensive configuration options for transport behavior, including custom send/receive buffer sizes, stream and connection flow control windows, initial MTU, congestion algorithms, and ACK frequency. It also supports disabling packet encryption and decryption via the \--no-protection\ flag to isolate network performance from cryptographic overhead, and allows selecting specific TLS 1.3 cipher suites for testing.
perf/src · high confidence
New array-based RangeSet for tracking outgoing ACKs
The protocol implementation now includes a new \ArrayRangeSet\ data structure in \quinn-proto/src/range\_set\ to track outgoing ACK ranges. This array-based set is optimized for scenarios with few ranges (typical for consecutive ACK numbers) by using an inline representation that avoids heap allocation for small sets, keeping the \SentFrame\ size under 128 bytes. It provides faster iteration due to cache-friendly contiguous storage and is exposed alongside the existing \BTreeMap\-based \RangeSet\ for different use cases within the QUIC protocol logic.
_quinn-proto/src/range\set · high confidence
New bulk benchmark tool with multi-client and bidirectional support
A new bulk benchmark binary has been added to the bench tool, enabling users to run comprehensive performance tests that support multiple concurrent clients and bidirectional data transfer. The tool utilizes clap for command-line argument parsing and integrates tracing for detailed server and client span logging, allowing for more granular performance analysis compared to previous single-direction or single-client benchmarks.
bench/src/bin · high confidence
New connection ID generators and coding infrastructure
The protocol library now exposes a \ConnectionIdGenerator\ trait with two implementations: \RandomConnectionIdGenerator\ for purely random IDs and \HashedConnectionIdGenerator\ which uses a keyed hash to allow efficient validation of incoming connection IDs. Additionally, a new \coding\ module provides a \Codec\ trait for encoding and decoding QUIC primitives (u8, u16, u32, u64, IP addresses) and helper extensions for \Buf\ and \BufMut\.
quinn-proto/src · high confidence
Removals
Removal of echo example
The echo example has been removed from the codebase. This example previously demonstrated a basic QUIC endpoint setup using rustls for TLS configuration.
examples · high confidence
Removal of legacy QUIC implementation modules
The \endpoint\, \lib\, and \varint\ source files have been deleted from the \src\ directory. This removes the previous basic QUIC endpoint logic, the library's public exports, and the custom variable-length integer encoding implementation, indicating a structural cleanup or migration away from this initial codebase version.
src · high confidence
Behavioural changes
Add synchronous benchmark suite for stream throughput
The \quinn/benches\ directory now includes a new \bench.rs\ file that replaces the previous criterion-based benchmarks with a synchronous \bencher\ implementation. This suite measures data transfer performance across one and multiple concurrent streams (both large and small payloads) by spawning a local server and client within the benchmark loop, allowing users to track performance changes in stream handling and throughput.
quinn/benches · high confidence
Expanded platform support and build configuration for quinn-udp
The quinn-udp crate now officially supports additional operating systems, including watchOS, illumos, and Solaris, by updating its build configuration to recognize these targets. It also introduces conditional compilation flags for Apple platforms to enable a faster UDP/IO datapath when the 'fast-apple-datapath' feature is enabled, and adds support for WebAssembly browser targets. Additionally, license files are now included in the published crate to ensure compliance.
quinn-udp · high confidence
QUIC configuration module restructured into dedicated transport and endpoint files
The configuration logic for the QUIC protocol has been reorganized to improve clarity and maintainability. The \EndpointConfig\ and \TransportConfig\ structs, along with their associated builder methods and documentation, have been moved from a single monolithic module into separate files (\config/mod.rs\ for endpoint-level settings and \config/transport.rs\ for transport-level settings). This change exposes public types like \QlogConfig\, \AckFrequencyConfig\, \IdleTimeout\, and \MtuDiscoveryConfig\ from the transport module, making it easier for users to configure specific aspects of QUIC connections such as MTU discovery, logging, and stream limits without navigating a large, single file.
quinn-proto/src/config · high confidence
Quinn crate now includes license files and configures WASM browser target support
The Quinn crate now includes symlinks to the Apache and MIT license files, ensuring they are present in published packages. Additionally, a build script has been added to define a \wasm\_browser\ configuration alias for targets where the target family is wasm and the OS is unknown, facilitating conditional compilation for browser-based WebAssembly environments.
quinn · medium confidence
Refactored control message handling into a generic, cross-platform module
The \cmsg\ module has been restructured to provide a unified, generic interface for encoding and decoding socket control messages across Unix and Windows platforms. This change introduces platform-specific implementations (\unix.rs\ and \windows.rs\) that abstract native APIs (like \libc::msghdr\ and \WinSock::WSAMSG\) behind common traits, ensuring correct memory alignment and safe pointer handling. The new \Encoder\ and \Iter\ structs manage control message buffers with strict lifetime guarantees, fixing previous aliasing violations and improving robustness on macOS and NetBSD.
quinn-udp/src/cmsg · high confidence
Restructured bulk benchmark with configurable transport and multi-stream support
The benchmark tool in bench/src has been restructured to support more flexible performance testing. Users can now specify the number of concurrent clients and streams, configure the initial MTU, and enable the ACK frequency extension for finer-grained control over transport behavior. The benchmark also supports bidirectional data transfer (upload and download) and provides detailed statistical output, including throughput and duration histograms, for both overall and per-stream metrics.
bench/src · high confidence
Simplified example endpoint construction with explicit configuration
The common example module now provides \make\_client\_endpoint\ and \make\_server\_endpoint\ helpers that construct QUIC endpoints using explicit \ClientConfig\ and \ServerConfig\ objects rather than a builder pattern. This change aligns with the library's shift to opaque config structs and requires users to provide trusted certificates for clients and generates self-signed certificates for servers, while also setting the maximum concurrent unidirectional streams to zero for server configurations.
quinn/examples/common · high confidence
Stream management logic refactored into dedicated modules
The stream handling logic in \quinn-proto\ has been reorganized into separate \recv\, \send\, and \state\ modules. This change introduces dedicated \RecvStream\ and \SendStream\ interface types to access receive and send streams respectively, replacing the previous unified access pattern. The refactoring also includes the addition of a \BytesArray\ send interface for array-based data transmission and updates to stream prioritization and flow control handling within the new module structure.
quinn-proto/src/connection/streams · high confidence
Unified performance tool binary with optional Tokio console profiling
The performance testing tool is now distributed as a single binary that supports both client and server modes via subcommands, replacing separate binaries. This unified entry point also introduces a new 'tokio-console' feature that, when enabled, integrates the console subscriber to allow real-time asynchronous runtime profiling.
perf/src/bin · high confidence
Test coverage
Add UDP throughput benchmarking for GSO, GRO, and recvmmsg; Added comprehensive test suite for quinn-proto; Added fuzzing targets for QUIC protocol components; Added integration tests for the UDP layer; Added tests for high-load connection stability and post-quantum key exchange.
Dependencies
Quinn 0.12 release with Rust 2024 edition and MSRV 1.88
The Quinn QUIC library has been updated to version 0.12, raising the Minimum Supported Rust Version (MSRV) to 1.88 and adopting the Rust 2024 edition. This release introduces a flattened workspace structure that centralizes dependency management, updating core libraries such as \rustls\ to 0.23.5, \ring\ to 0.17, and \tokio\ to 1.28.1. The \quinn-udp\ crate is also updated to version 0.6.2, and the project now includes dedicated workspaces for fuzzing, benchmarking, and documentation.
(dependencies) · high confidence
Housekeeping
Added license symlinks to quinn-proto crate; Initial project setup and documentation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 66 (+2.9)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 88 → 88 (+0.1)
- Architecture 98 → 91 (-7.0)
- Maturity 54 → 54 (+0.1)
- Readiness 69 → 70 (+0.3)
- Security 57 → 71 (+14.4)
- Event Sourcing 100 → 100 (+0.0)
- Performance 89 (new)
Resolved (9)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: quinn-proto/src/connection/stats.rs (quinn-proto/src/connection/stats.rs)
- Hotspot: quinn-proto/src/transport_parameters.rs (quinn-proto/src/transport_parameters.rs)
- MethodTooLong: Connection.handle_packet (quinn-proto/src/connection/mod.rs)
- MethodTooLong: Endpoint.accept (quinn-proto/src/endpoint.rs)
- Off-boarding risk: anonymized user #1
- TodoComment (quinn-proto/src/connection/mod.rs)
- TodoComment (quinn-proto/src/connection/mod.rs)
New (19)
- Ambiguous naming for similar operations. closed() and close_reason() both return a ConnectionError. It is unclear if they return the same error, different aspects of the error, or if one is deprecated. The names suggest closed might be a status check (bool) and close_reason the error, but both return ConnectionError.
- Duplicate constructors with different abstraction levels. Similar to rebind, new and new_with_abstract_socket create an Endpoint but differ only in the socket type. This forces users to choose the correct constructor based on whether they have a concrete socket or a boxed trait object, which is confusing.
- Duplicate operations with different abstraction levels. rebind and rebind_abstract perform the same logical operation (changing the underlying socket) but differ only in the type of the socket argument (concrete vs boxed trait object). This suggests an inconsistency in how the API handles abstraction, likely due to historical reasons or specific runtime requirements.
- Duplicate operations with unclear distinction. accept and start_accept in quinn_proto.endpoint.Endpoint have identical signatures and likely perform the same function. The naming suggests a two-phase acceptance process, but the signatures do not reflect this (both return Result).
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low cohesion: EndpointConfig (LCOM4 4) (quinn-proto/src/config/mod.rs)
- Low cohesion: UdpSocketState (LCOM4 5) (quinn-udp/src/unix.rs)
- MethodTooLong: Connection.new (quinn-proto/src/connection/mod.rs)
- MethodTooLong: Endpoint.start_accept (quinn-proto/src/endpoint.rs)
- Off the main sequence: quinn-proto
- Off the main sequence: quinn-udp
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- Redundant acceptance methods. accept is a convenience wrapper for accept_with using the default server config. This creates two entry points for the same operation, forcing users to choose between convenience and explicit configuration.
- Redundant connection initiation methods. connect is a convenience wrapper for connect_with using the default client config. This creates two entry points for the same operation, forcing users to choose between convenience and explicit configuration without a clear architectural distinction.
- Repeated repair: quinn-udp/src/windows.rs (quinn-udp/src/windows.rs)
- TodoComment (quinn-proto/src/connection/mod.rs)
Changes since last survey
- 42 commits — 37 feature/other, 5 fixes
By area
- quinn-proto/src — 23 commits
- (root) — 7 commits
- quinn-udp/src — 5 commits
- quinn/src — 4 commits
- .github/workflows — 3 commits
Notable commits
- fix: fix: cleanup state if transmit failed
- fix: fix: potential CID leak in connect()
- fix: udp: fix aliasing violation in Linux error queue decoding
- fix: udp: fix aliasing violation in cmsg Encoder
- fix: udp: fix aliasing violation when decoding cmsgs
- change: Reject Retry packets bearing a SCID that matches the initial DCID
- change: Take semver-compatible dependency updates
- change: build(deps): bump aws-lc-rs from 1.18.0 to 1.18.1
- change: build(deps): bump rand from 0.10.2 to 0.10.3
- change: build(deps): bump rustls from 0.23.43 to 0.23.44
- change: build(deps): bump rustls-platform-verifier from 0.7.0 to 0.7.1
- change: build(deps): bump thiserror from 2.0.20 to 2.0.21
- change: build(deps): bump wasm-bindgen-test from 0.3.78 to 0.3.79
- change: ci: fix workflow formatting
- change: ci: run cmsg tests under Miri
- change: ci: work around Android SDK component changes
- change: proto: avoid panic on high minimum ACK delay
- change: proto: bound sent-packet storage by live entries
- change: proto: buffer 1-RTT packets that arrive during the handshake
- change: proto: factor packet post-processing out of handle_packet
- …and 22 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
quinn-rs/quinn was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ffa809c223efc7aeae2882f4b13233effcb19d39 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-505904ce13c1.