valyala/fasthttp
69.2
Adequate · 24 September 2026
23k
lines of production code
Go
primary language
5
measurements over time
What this system is
This system is a high-performance HTTP library and server framework for Go, designed to minimize memory allocations and maximize throughput. It provides core networking capabilities including TLS, proxy support, and multi-process scaling via SO\_REUSEPORT and preforking. The codebase also includes utilities for in-process communication, standard net/http interoperability, and secure exposure of runtime metrics and profiling data.
How it got here
2015 — reuseport support and example enhancements
4 changes.
This period focused on adding SO\_REUSEPORT support via a new platform-specific package to improve multi-CPU server scaling, alongside a security fix for CRLF injection in cookie handling. It also expanded the example suite with a comprehensive static file server featuring TLS and compression, and a zero-allocation HelloWorld server demonstrating high-performance best practices.
2016 — Performance optimization utilities
4 changes.
This period focused on enhancing high-performance capabilities by introducing the fasthttpadaptor for seamless net/http integration and the stackless package to reduce goroutine stack usage. Additional features included in-memory communication tools in fasthttputil and a JSON-based expvar metrics handler to support efficient, low-latency server operations.
2018 — profiling security and proxy enhancements
4 changes.
This period focused on enhancing security and connectivity features by introducing a strict-path pprof handler to prevent debug data exposure and refactoring the proxy package for unified dual-stack dialing. It also added a multidomain TLS example to demonstrate per-host routing and updated core dependencies to newer versions.
2020–2025 — Performance optimization and example expansion
4 changes.
This period focused on enhancing server performance through the introduction of a prefork package for multi-process handling and the integration of the tcplisten library for advanced TCP optimizations. Additionally, the project expanded its documentation by adding comprehensive examples for Let's Encrypt HTTPS configuration and client usage patterns.
Features
Add Let's Encrypt HTTPS example
A new example file (examples/letsencrypt/letsencryptserver.go) demonstrates how to serve an HTTPS server using Let's Encrypt via autocert. The example configures a fasthttp server with TLS, using autocert to automatically obtain and manage certificates for a whitelisted domain (defaulting to example.com) and caching them in a local directory. It specifically listens on port 443 to support the tls-alpn-01 challenge required by Let's Encrypt.
examples/letsencrypt · high confidence
Add client and host\_client usage examples
New example programs have been added to demonstrate how to use the fasthttp client library. The client example shows how to configure a general-purpose client for multiple hosts, including setting timeouts, limiting response body size, and handling JSON payloads. The host\_client example demonstrates a simpler setup for single-host communication, including basic authentication and URI reuse.
examples/client · high confidence
Add expvarhandler for serving expvar metrics as JSON
A new expvarhandler package has been added to provide a fasthttp-compatible request handler that exposes Go's expvar metrics as JSON. The handler supports filtering metrics via an 'r' query parameter using a regular expression, with a default pattern that matches all variables. This allows users to expose and query expvar data directly through HTTP requests in a structured JSON format.
expvarhandler · high confidence
Add fasthttp pprof handler with strict path matching
Introduces a new \pprofhandler\ package that provides a fasthttp-compatible handler for Go runtime profiling data (cmdline, profile, symbol, trace, and named profiles like heap and goroutine). The implementation uses exact path matching instead of prefix matching to prevent debug data exposure, ensuring that paths with trailing slashes or extra characters (e.g., \/debug/pprof/cmdlineFoo\) are rejected or fall through to the index handler rather than leaking sensitive information.
pprofhandler · high confidence
Add reuseport package with platform-specific TCP listener support
Introduces a new \reuseport\ package providing a \net.Listener\ that enables \SO\_REUSEPORT\ on supported platforms (Linux, macOS, BSD) to allow linear scaling of server performance on multi-CPU systems. The implementation uses \github.com/valyala/fasthttp/tcplisten\ for these platforms, enabling \TCP\_DEFER\_ACCEPT\ and \TCP\_FASTOPEN\ by default. Platform-specific files handle AIX, Solaris, and Windows: AIX and Solaris set both \SO\_REUSEADDR\ and \SO\_REUSEPORT\, while Windows falls back to \SO\_REUSEADDR\ only, noting the lack of same-user isolation. The package includes tests for TCP4 and TCP6 listeners and an example usage with \fasthttp\.
reuseport · high confidence
Add zero-allocation HelloWorld server example
A new example server is available in the examples/helloworldserver directory that demonstrates high-performance request handling with zero allocations per operation in the uncompressed path. The example includes a Makefile for building, a .gitignore to exclude binaries, and a test suite (TestZeroAllocation) that verifies the allocation-free claim. It showcases best practices such as using a sync.Pool for buffer reuse, avoiding fmt in the hot path, setting custom headers and cookies, and optionally enabling transparent response compression via a command-line flag.
examples/helloworldserver · high confidence
Introduce fasthttpadaptor for net/http to fasthttp conversion
This change adds the fasthttpadaptor package, providing NewFastHTTPHandler and ConvertRequest to wrap standard net/http handlers for use with the fasthttp server. The implementation supports buffered responses, streaming via Flush, and connection hijacking, while ensuring duplicate headers are preserved and context is forwarded correctly.
fasthttpadaptor · high confidence
Introduce prefork package for multi-process server performance
Adds a new \prefork\ package that wraps a \fasthttp.Server\ to run across multiple child processes, leveraging file descriptor passing or \SO\_REUSEPORT\ to increase performance by avoiding Go's global memory management overhead across cores. The implementation includes a master process that spawns and supervises children, handles graceful shutdowns with configurable grace periods, and detects master process death in children via a configurable callback. It also provides hooks for custom command production, child spawn/recovery notifications, and enforces a warning against using global state (like in-memory caches) in preforked mode.
prefork · high confidence
Introduce stackless package for reducing goroutine stack usage
The new \stackless\ package provides utilities to reduce stack space consumption for high numbers of concurrently running goroutines. It introduces \NewFunc\, which wraps CPU-bound functions to execute them in a dedicated worker pool, allowing callers to proceed without blocking the calling goroutine's stack; this wrapper returns false if the worker pool is under high load. Additionally, it provides a \Writer\ interface and \NewWriter\ function to wrap standard compression writers (like gzip or flate) in a stackless manner, deferring the actual I/O operations to the worker pool to minimize stack usage during concurrent compression tasks.
stackless · high confidence
Introduce unified Dialer with dual-stack and environment variable support
The fasthttpproxy package has been refactored to use a new Dialer struct that embeds fasthttp.TCPDialer and httpproxy.Config, enabling users to configure HTTP, HTTPS, and NO\_PROXY settings directly or via environment variables. This change adds support for dual-stack (IPv4/IPv6) connections through the DialDualStack field and introduces new convenience functions like FasthttpHTTPDialer, FasthttpSocksDialer, and FasthttpProxyHTTPDialer to simplify proxy configuration for fasthttp clients.
fasthttpproxy · high confidence
Migrate valyala/tcplisten into the repository
The \tcplisten\ package, derived from \valyala/tcplisten\, is now included in the repository. It provides a customizable TCP \net.Listener\ that supports performance options such as \SO\_REUSEPORT\ for multi-CPU scaling, \TCP\_DEFER\_ACCEPT\, and \TCP\_FASTOPEN\ (on Linux). The implementation includes platform-specific socket handling for Linux, macOS, BSDs, and z/OS s390x, along with a dummy implementation for JavaScript/WASM targets.
tcplisten · high confidence
New in-memory listener and pipe connections for fast in-process communication
The fasthttputil package now includes InmemoryListener and PipeConns, enabling fast, in-process client-server communication without network stack overhead. InmemoryListener implements net.Listener for use in tests or internal services, while PipeConns provides a bi-directional in-memory connection pipe with support for read/write deadlines and buffered writes. These utilities are designed for high-performance scenarios where network latency is undesirable.
fasthttputil · high confidence
New multidomain TLS example demonstrating per-host routing
Added a new example in the examples/multidomain directory that demonstrates how to serve multiple domains over TLS using fasthttp. The example configures a single server to route requests to different handlers based on the Host header, using generated test certificates for localhost and 127.0.0.1.
examples/multidomain · high confidence
New static file server example with TLS, compression, and stats
Added a new example file server that serves static files from a specified directory. This server supports transparent response compression, byte range requests, and directory index page generation. It also includes TLS (HTTPS) support using provided sample certificates, virtual hosting capabilities, and exports various performance statistics (such as request counts and response sizes) via the /stats endpoint.
examples/fileserver · high confidence
Security
Sanitize cookie setters to prevent CRLF injection
The library now sanitizes values passed to cookie setters to prevent CRLF injection attacks, addressing security issue \#2185.
(repo-wide) · high confidence
Dependencies
Update Go version and dependencies
The project now requires Go 1.25.0 and updates several key dependencies: github.com/klauspost/compress to v1.20.0, golang.org/x/crypto to v0.55.0, golang.org/x/net to v0.58.0, golang.org/x/sys to v0.47.0, and golang.org/x/text to v0.41.0. Additionally, the Brotli compression library has been switched from github.com/andybalholm/brotli to github.com/molecule-man/go-brrr v1.0.1.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 65 → 69 (+3.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 64 → 79 (+15.1)
- Architecture 100 → 92 (-8.1)
- Maturity 61 → 61 (+0.0)
- Readiness 75 → 71 (-3.7)
- Security 68 → 83 (+14.8)
Resolved (37)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (header.go)
- Duplicated block (10 lines × 2) (header.go)
- Duplicated block (10 lines × 2) (header.go)
- Duplicated block (10 lines × 2) (tcplisten/tcplisten.go)
- Duplicated block (11 lines × 2) (client.go)
- Duplicated block (12 lines × 2) (fs.go)
- Duplicated block (13 lines × 2) (cookie.go)
- Duplicated block (13 lines × 2) (header.go)
- Duplicated block (13 lines × 2) (header.go)
- Duplicated block (14 lines × 2) (client.go)
- Duplicated block (14 lines × 2) (http.go)
- Duplicated block (14 lines × 2) (http.go)
- Duplicated block (14 lines × 2) (server.go)
- Duplicated block (19 lines × 2) (http.go)
- Duplicated block (6 lines × 2) (header.go)
- Duplicated block (7 lines × 2) (header.go)
- Duplicated block (7 lines × 2) (uri.go)
- Duplicated block (8 lines × 2) (server.go)
- …and 17 more
New (72)
- ClassTooLong: Request (http.go)
- ClassTooLong: RequestHeader (header.go)
- ClassTooLong: ResponseHeader (header.go)
- ClassTooLong: Server (server.go)
- ClassTooLong: fsHandler (fs.go)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (10 lines × 2) (header.go)
- Duplicated block (10 lines × 2) (server.go)
- Duplicated block (10 lines × 3) (client.go)
- Duplicated block (10 lines × 3) (fasthttputil/inmemory_listener.go)
- Duplicated block (11 lines × 2) (header.go)
- Duplicated block (11–12 lines × 2) (client.go)
- Duplicated block (12 lines × 2) (cookie.go)
- Duplicated block (12 lines × 2) (header.go)
- Duplicated block (12 lines × 2) (tcplisten/tcplisten.go)
- Duplicated block (13 lines × 2) (args.go)
- Duplicated block (13–14 lines × 2) (header.go)
- Duplicated block (14 lines × 2) (server.go)
- Duplicated block (15 lines × 2) (header.go)
- Duplicated block (15 lines × 2) (header.go)
- …and 52 more
Changes since last survey
- 35 commits — 21 feature/other, 14 fixes
By area
- (root) — 33 commits
- .github/workflows — 1 commit
- examples/helloworldserver — 1 commit
Notable commits
- fix: Fix a pooled timer panic and a test data race (#2351)
- fix: fix: don't close the shutdown done channel twice (#2340)
- fix: fix: keep a chunked requestStream at EOF once the body ends (#2379)
- fix: fix: let request timeouts override client timeouts (#2372)
- fix: fix: normalize a trailing /. path segment (#2392)
- fix: fix: preserve redirect path normalization setting in Request.CopyTo (#2389)
- fix: fix: preserve zero Max-Age when parsing cookies (#2405)
- fix: fix: prevent stale query string after clearing query args (#2380)
- fix: fix: request time left at zero, and an opt in Server.LazyRequestTime (#2404)
- fix: fix: send / as the path when the request-target is query-only (#2371)
- fix: fix: small read buffer error doesn't match the ignored string anymore (#2356)
- fix: fix: synchronize RequestCtx.Done() with ShutdownWithContext (#2402)
- fix: fix: wait for streaming reads before releasing pooled resources (#2353)
- fix: fix: write trailers for buffered bodies in Request.Write and Response.Write (#2378)
- change: Always stream response bodies when requested (#2373)
- change: Document VisitHeaderParams invalid param behaviour
- change: Rename ChunkedBodyWriterTo to BodyWriterTo and use in more places (#2348)
- change: Replace github.com/andybalholm/brotli with github.com/molecule-man/go-brrr (#2366)
- change: Return no values from PeekAll for absent special headers (#2401)
- change: Skip empty elements in VisitHeaderParams (#2388)
- …and 15 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
valyala/fasthttp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5687435d22d12c3bedb8080e66703720c40c017f — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.