Skip to content
CAI
Software that uses CAICheck a score

valyala/fasthttp

69.2

Adequate · 24 September 2026

23k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance HTTP library and server framework for Go, designed to minimize memory allocations and maximize throughput. It provides core networking capabilities including TLS, proxy support, and multi-process scaling via SO\_REUSEPORT and preforking. The codebase also includes utilities for in-process communication, standard net/http interoperability, and secure exposure of runtime metrics and profiling data.

How it got here

2015 — reuseport support and example enhancements

4 changes.

This period focused on adding SO\_REUSEPORT support via a new platform-specific package to improve multi-CPU server scaling, alongside a security fix for CRLF injection in cookie handling. It also expanded the example suite with a comprehensive static file server featuring TLS and compression, and a zero-allocation HelloWorld server demonstrating high-performance best practices.

2016 — Performance optimization utilities

4 changes.

This period focused on enhancing high-performance capabilities by introducing the fasthttpadaptor for seamless net/http integration and the stackless package to reduce goroutine stack usage. Additional features included in-memory communication tools in fasthttputil and a JSON-based expvar metrics handler to support efficient, low-latency server operations.

2018 — profiling security and proxy enhancements

4 changes.

This period focused on enhancing security and connectivity features by introducing a strict-path pprof handler to prevent debug data exposure and refactoring the proxy package for unified dual-stack dialing. It also added a multidomain TLS example to demonstrate per-host routing and updated core dependencies to newer versions.

2020–2025 — Performance optimization and example expansion

4 changes.

This period focused on enhancing server performance through the introduction of a prefork package for multi-process handling and the integration of the tcplisten library for advanced TCP optimizations. Additionally, the project expanded its documentation by adding comprehensive examples for Let's Encrypt HTTPS configuration and client usage patterns.

Features

Add Let's Encrypt HTTPS example

A new example file (examples/letsencrypt/letsencryptserver.go) demonstrates how to serve an HTTPS server using Let's Encrypt via autocert. The example configures a fasthttp server with TLS, using autocert to automatically obtain and manage certificates for a whitelisted domain (defaulting to example.com) and caching them in a local directory. It specifically listens on port 443 to support the tls-alpn-01 challenge required by Let's Encrypt.

examples/letsencrypt · high confidence

Add client and host\_client usage examples

New example programs have been added to demonstrate how to use the fasthttp client library. The client example shows how to configure a general-purpose client for multiple hosts, including setting timeouts, limiting response body size, and handling JSON payloads. The host\_client example demonstrates a simpler setup for single-host communication, including basic authentication and URI reuse.

examples/client · high confidence

Add expvarhandler for serving expvar metrics as JSON

A new expvarhandler package has been added to provide a fasthttp-compatible request handler that exposes Go's expvar metrics as JSON. The handler supports filtering metrics via an 'r' query parameter using a regular expression, with a default pattern that matches all variables. This allows users to expose and query expvar data directly through HTTP requests in a structured JSON format.

expvarhandler · high confidence

Add fasthttp pprof handler with strict path matching

Introduces a new \pprofhandler\ package that provides a fasthttp-compatible handler for Go runtime profiling data (cmdline, profile, symbol, trace, and named profiles like heap and goroutine). The implementation uses exact path matching instead of prefix matching to prevent debug data exposure, ensuring that paths with trailing slashes or extra characters (e.g., \/debug/pprof/cmdlineFoo\) are rejected or fall through to the index handler rather than leaking sensitive information.

pprofhandler · high confidence

Add reuseport package with platform-specific TCP listener support

Introduces a new \reuseport\ package providing a \net.Listener\ that enables \SO\_REUSEPORT\ on supported platforms (Linux, macOS, BSD) to allow linear scaling of server performance on multi-CPU systems. The implementation uses \github.com/valyala/fasthttp/tcplisten\ for these platforms, enabling \TCP\_DEFER\_ACCEPT\ and \TCP\_FASTOPEN\ by default. Platform-specific files handle AIX, Solaris, and Windows: AIX and Solaris set both \SO\_REUSEADDR\ and \SO\_REUSEPORT\, while Windows falls back to \SO\_REUSEADDR\ only, noting the lack of same-user isolation. The package includes tests for TCP4 and TCP6 listeners and an example usage with \fasthttp\.

reuseport · high confidence

Add zero-allocation HelloWorld server example

A new example server is available in the examples/helloworldserver directory that demonstrates high-performance request handling with zero allocations per operation in the uncompressed path. The example includes a Makefile for building, a .gitignore to exclude binaries, and a test suite (TestZeroAllocation) that verifies the allocation-free claim. It showcases best practices such as using a sync.Pool for buffer reuse, avoiding fmt in the hot path, setting custom headers and cookies, and optionally enabling transparent response compression via a command-line flag.

examples/helloworldserver · high confidence

Introduce fasthttpadaptor for net/http to fasthttp conversion

This change adds the fasthttpadaptor package, providing NewFastHTTPHandler and ConvertRequest to wrap standard net/http handlers for use with the fasthttp server. The implementation supports buffered responses, streaming via Flush, and connection hijacking, while ensuring duplicate headers are preserved and context is forwarded correctly.

fasthttpadaptor · high confidence

Introduce prefork package for multi-process server performance

Adds a new \prefork\ package that wraps a \fasthttp.Server\ to run across multiple child processes, leveraging file descriptor passing or \SO\_REUSEPORT\ to increase performance by avoiding Go's global memory management overhead across cores. The implementation includes a master process that spawns and supervises children, handles graceful shutdowns with configurable grace periods, and detects master process death in children via a configurable callback. It also provides hooks for custom command production, child spawn/recovery notifications, and enforces a warning against using global state (like in-memory caches) in preforked mode.

prefork · high confidence

Introduce stackless package for reducing goroutine stack usage

The new \stackless\ package provides utilities to reduce stack space consumption for high numbers of concurrently running goroutines. It introduces \NewFunc\, which wraps CPU-bound functions to execute them in a dedicated worker pool, allowing callers to proceed without blocking the calling goroutine's stack; this wrapper returns false if the worker pool is under high load. Additionally, it provides a \Writer\ interface and \NewWriter\ function to wrap standard compression writers (like gzip or flate) in a stackless manner, deferring the actual I/O operations to the worker pool to minimize stack usage during concurrent compression tasks.

stackless · high confidence

Introduce unified Dialer with dual-stack and environment variable support

The fasthttpproxy package has been refactored to use a new Dialer struct that embeds fasthttp.TCPDialer and httpproxy.Config, enabling users to configure HTTP, HTTPS, and NO\_PROXY settings directly or via environment variables. This change adds support for dual-stack (IPv4/IPv6) connections through the DialDualStack field and introduces new convenience functions like FasthttpHTTPDialer, FasthttpSocksDialer, and FasthttpProxyHTTPDialer to simplify proxy configuration for fasthttp clients.

fasthttpproxy · high confidence

Migrate valyala/tcplisten into the repository

The \tcplisten\ package, derived from \valyala/tcplisten\, is now included in the repository. It provides a customizable TCP \net.Listener\ that supports performance options such as \SO\_REUSEPORT\ for multi-CPU scaling, \TCP\_DEFER\_ACCEPT\, and \TCP\_FASTOPEN\ (on Linux). The implementation includes platform-specific socket handling for Linux, macOS, BSDs, and z/OS s390x, along with a dummy implementation for JavaScript/WASM targets.

tcplisten · high confidence

New in-memory listener and pipe connections for fast in-process communication

The fasthttputil package now includes InmemoryListener and PipeConns, enabling fast, in-process client-server communication without network stack overhead. InmemoryListener implements net.Listener for use in tests or internal services, while PipeConns provides a bi-directional in-memory connection pipe with support for read/write deadlines and buffered writes. These utilities are designed for high-performance scenarios where network latency is undesirable.

fasthttputil · high confidence

New multidomain TLS example demonstrating per-host routing

Added a new example in the examples/multidomain directory that demonstrates how to serve multiple domains over TLS using fasthttp. The example configures a single server to route requests to different handlers based on the Host header, using generated test certificates for localhost and 127.0.0.1.

examples/multidomain · high confidence

New static file server example with TLS, compression, and stats

Added a new example file server that serves static files from a specified directory. This server supports transparent response compression, byte range requests, and directory index page generation. It also includes TLS (HTTPS) support using provided sample certificates, virtual hosting capabilities, and exports various performance statistics (such as request counts and response sizes) via the /stats endpoint.

examples/fileserver · high confidence

Security

The library now sanitizes values passed to cookie setters to prevent CRLF injection attacks, addressing security issue \#2185.

(repo-wide) · high confidence

Dependencies

Update Go version and dependencies

The project now requires Go 1.25.0 and updates several key dependencies: github.com/klauspost/compress to v1.20.0, golang.org/x/crypto to v0.55.0, golang.org/x/net to v0.58.0, golang.org/x/sys to v0.47.0, and golang.org/x/text to v0.41.0. Additionally, the Brotli compression library has been switched from github.com/andybalholm/brotli to github.com/molecule-man/go-brrr v1.0.1.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 65 → 69 (+3.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 64 → 79 (+15.1)
  • Architecture 100 → 92 (-8.1)
  • Maturity 61 → 61 (+0.0)
  • Readiness 75 → 71 (-3.7)
  • Security 68 → 83 (+14.8)

Resolved (37)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (header.go)
  • Duplicated block (10 lines × 2) (header.go)
  • Duplicated block (10 lines × 2) (header.go)
  • Duplicated block (10 lines × 2) (tcplisten/tcplisten.go)
  • Duplicated block (11 lines × 2) (client.go)
  • Duplicated block (12 lines × 2) (fs.go)
  • Duplicated block (13 lines × 2) (cookie.go)
  • Duplicated block (13 lines × 2) (header.go)
  • Duplicated block (13 lines × 2) (header.go)
  • Duplicated block (14 lines × 2) (client.go)
  • Duplicated block (14 lines × 2) (http.go)
  • Duplicated block (14 lines × 2) (http.go)
  • Duplicated block (14 lines × 2) (server.go)
  • Duplicated block (19 lines × 2) (http.go)
  • Duplicated block (6 lines × 2) (header.go)
  • Duplicated block (7 lines × 2) (header.go)
  • Duplicated block (7 lines × 2) (uri.go)
  • Duplicated block (8 lines × 2) (server.go)
  • …and 17 more

New (72)

  • ClassTooLong: Request (http.go)
  • ClassTooLong: RequestHeader (header.go)
  • ClassTooLong: ResponseHeader (header.go)
  • ClassTooLong: Server (server.go)
  • ClassTooLong: fsHandler (fs.go)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (10 lines × 2) (header.go)
  • Duplicated block (10 lines × 2) (server.go)
  • Duplicated block (10 lines × 3) (client.go)
  • Duplicated block (10 lines × 3) (fasthttputil/inmemory_listener.go)
  • Duplicated block (11 lines × 2) (header.go)
  • Duplicated block (11–12 lines × 2) (client.go)
  • Duplicated block (12 lines × 2) (cookie.go)
  • Duplicated block (12 lines × 2) (header.go)
  • Duplicated block (12 lines × 2) (tcplisten/tcplisten.go)
  • Duplicated block (13 lines × 2) (args.go)
  • Duplicated block (13–14 lines × 2) (header.go)
  • Duplicated block (14 lines × 2) (server.go)
  • Duplicated block (15 lines × 2) (header.go)
  • Duplicated block (15 lines × 2) (header.go)
  • …and 52 more

Changes since last survey

  • 35 commits — 21 feature/other, 14 fixes

By area

  • (root) — 33 commits
  • .github/workflows — 1 commit
  • examples/helloworldserver — 1 commit

Notable commits

  • fix: Fix a pooled timer panic and a test data race (#2351)
  • fix: fix: don't close the shutdown done channel twice (#2340)
  • fix: fix: keep a chunked requestStream at EOF once the body ends (#2379)
  • fix: fix: let request timeouts override client timeouts (#2372)
  • fix: fix: normalize a trailing /. path segment (#2392)
  • fix: fix: preserve redirect path normalization setting in Request.CopyTo (#2389)
  • fix: fix: preserve zero Max-Age when parsing cookies (#2405)
  • fix: fix: prevent stale query string after clearing query args (#2380)
  • fix: fix: request time left at zero, and an opt in Server.LazyRequestTime (#2404)
  • fix: fix: send / as the path when the request-target is query-only (#2371)
  • fix: fix: small read buffer error doesn't match the ignored string anymore (#2356)
  • fix: fix: synchronize RequestCtx.Done() with ShutdownWithContext (#2402)
  • fix: fix: wait for streaming reads before releasing pooled resources (#2353)
  • fix: fix: write trailers for buffered bodies in Request.Write and Response.Write (#2378)
  • change: Always stream response bodies when requested (#2373)
  • change: Document VisitHeaderParams invalid param behaviour
  • change: Rename ChunkedBodyWriterTo to BodyWriterTo and use in more places (#2348)
  • change: Replace github.com/andybalholm/brotli with github.com/molecule-man/go-brrr (#2366)
  • change: Return no values from PeekAll for absent special headers (#2401)
  • change: Skip empty elements in VisitHeaderParams (#2388)
  • …and 15 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

valyala/fasthttp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5687435d22d12c3bedb8080e66703720c40c017f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.