- C 68.2%
- JavaScript 26.5%
- CMake 2.4%
- CSS 1.2%
- HTML 0.7%
- Other 0.8%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
A server probing a client's new address abandoned its first PATH_CHALLENGE whenever the packet that revealed the address was small: QIR's rebind-addr and connectionmigration showed "probe path anti-amplification limit reached (sent 0, rx 44)" and only the next packet from the address got a probe out. - The abandon threshold, LWS_QUIC_PROBE_MIN_DATAGRAM, was a fixed 160 bytes, several times what a packet carrying just a PATH_CHALLENGE needs. It is now what the tx bundler actually needs for one: this packet's header, the bundler's fit margins (now named, LWS_QUIC_FRAME_HDR_MAX and LWS_QUIC_FIT_SLACK, and used by the bundler itself) and the 8-byte challenge. - The allowance, 3x the datagram bytes received from the address, is in datagram bytes but was applied as the path MTU, which the bundler then took another 48 bytes of IP and UDP headers off. The connection-wide anti-amplification limit had the same mix-up, and with exactly 48 bytes of it left the bundler's "mtu > 48" test fell back to a 1200-byte datagram, past the limit. Both now cap the datagram directly. RFC 9000 8.2.1 already lets the probe's padding stop short of 1200 bytes at the allowance, which the probe padding does. Locally, a client moving to its preferred address sends a 44-byte first packet from its new port: before, the server abandoned that probe exactly as on QIR; now it goes out padded to the 132-byte allowance and commits. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
| .github | ||
| assets | ||
| cmake | ||
| contrib | ||
| doc-assets | ||
| fuzz | ||
| include | ||
| lib | ||
| lwsws | ||
| minimal-examples | ||
| minimal-examples-lowlevel | ||
| plugin-standalone | ||
| plugins | ||
| READMEs | ||
| scripts | ||
| test-apps | ||
| win32port | ||
| .clangd | ||
| .gitignore | ||
| .gitmodules | ||
| .mailmap | ||
| .sai.json | ||
| AGENTS.md | ||
| bug_report.md | ||
| changelog | ||
| CMakeLists-implied-options.txt | ||
| CMakeLists.txt | ||
| component.mk | ||
| Kconfig | ||
| lgtm.yml | ||
| libwebsockets.dox | ||
| LICENSE | ||
| Makefile.projbuild | ||
| README.md | ||
| SECURITY.md | ||
| sonar-project.properties | ||
Libwebsockets
Libwebsockets is a simple-to-use, MIT-license, pure C library providing client and server for http/1, http/2, http/3, websockets, webtransport, MQTT and other protocols in a security-minded, lightweight, configurable, scalable and flexible way. It's easy to build and cross-build via cmake and is suitable for tasks from embedded RTOS through mass cloud serving.
It supports a lot of lightweight ancilliary implementations for things like JSON, CBOR, JOSE, COSE, and supports OpenSSL and MbedTLS v2/3/4 out of the box for everything. It's very gregarious when it comes to event loop sharing, supporting libuv, libevent, libev, sdevent, glib and uloop, as well as custom event libs.
100+ independent minimal examples for various scenarios, CC0-licensed (public domain) for cut-and-paste, allow you to get started quickly.
There are a lot of READMEs on a variety of topics. Doxygen API docs
We do a huge amount of CI testing per push
V5.0 now available... please upgrade to this or preferably v5.0-stable or main, as there are many security fixes only available on v5.0-stable and main; pre-5.0 releases are effectively deprecated.
There's a continuous incremental security audit in place finding and fixing new problems all the time at the moment, it's not a sign the code is weak: it's a sign I am using frontier models to make it extremely strong.
** NEW features available on v5.0 **
- Support for SChannel (windows native TLS, no need for OpenSSL build!), GnuTLS, openHiTLS and BearSSL added
- QUIC + H3 + Webtransport implementation, using aws-lc, wolfssl, boringssl, libressl, gnutls, and schannel (OpenSSL is h1/h2 -only; mbedtls can do it via a patch)
- WebRTC mixing (like your own zoom)
- HLS serving
| LWS version | Platform | Protocols | Default TLS |
|---|---|---|---|
| <= 4.5 | non-FreeRTOS | any | OpenSSL |
| <= 4.5 | FreeRTOS | any | mbedTLS |
| 5.0+ | Windows | any | schannel |
| 5.0+ | *nix | h1, h2 | OpenSSL |
| 5.0+ | *nix | quic/h3 | GnuTLS |
| 5.0+ | FreeRTOS | any | mbedTLS |
quic/h3 is enabled for build by default... necessitating GnuTLS instead of OpenSSL to make quic/h3 work.
| TLS Library | Server TLS | Client TLS | QUIC Transport (TLS 1.3) | WSS / HTTPS | MQTT over TLS | ALPN (HTTP/2) | DTLS (WebRTC) | Session Cache | JIT Trust | GenCrypto |
|---|---|---|---|---|---|---|---|---|---|---|
| GnuTLS | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| OpenSSL | Yes | Yes | No* | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| LibreSSL | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| AWS-LC | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| BoringSSL | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| wolfSSL | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| mbedTLS | Yes | Yes | Needs patch | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| SChannel | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
| BearSSL | Yes | Yes | No | Yes | Yes | Yes | No | Yes | Yes | Yes |
| openHiTLS | Yes | Yes | No | Yes | Yes | Yes | Yes (not SRTP) | Yes | Yes | Yes |
* Note: 1) Upstream OpenSSL does not provide the necessary QUIC TLS API (SSL_set_quic_method) to act as a cryptographic engine for LWS's QUIC transport. If you need QUIC/HTTP3 support, we recommend using BoringSSL or GnuTLS.
* *Note: 2) openHiTLS does not provide the necessary QUIC TLS API *
- DHT support built-in:
-DLWS_WITH_DHT=1
