canonical libwebsockets.org networking library https://libwebsockets.org
  • C 68.2%
  • JavaScript 26.5%
  • CMake 2.4%
  • CSS 1.2%
  • HTML 0.7%
  • Other 0.8%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Andy Green 0bf532a643 quic: a path probe fits the anti-amplification allowance it was given
A server probing a client's new address abandoned its first PATH_CHALLENGE
whenever the packet that revealed the address was small: QIR's rebind-addr
and connectionmigration showed "probe path anti-amplification limit reached
(sent 0, rx 44)" and only the next packet from the address got a probe out.

 - The abandon threshold, LWS_QUIC_PROBE_MIN_DATAGRAM, was a fixed 160
   bytes, several times what a packet carrying just a PATH_CHALLENGE needs.
   It is now what the tx bundler actually needs for one: this packet's
   header, the bundler's fit margins (now named, LWS_QUIC_FRAME_HDR_MAX and
   LWS_QUIC_FIT_SLACK, and used by the bundler itself) and the 8-byte
   challenge.

 - The allowance, 3x the datagram bytes received from the address, is in
   datagram bytes but was applied as the path MTU, which the bundler then
   took another 48 bytes of IP and UDP headers off.  The connection-wide
   anti-amplification limit had the same mix-up, and with exactly 48 bytes
   of it left the bundler's "mtu > 48" test fell back to a 1200-byte
   datagram, past the limit.  Both now cap the datagram directly.

RFC 9000 8.2.1 already lets the probe's padding stop short of 1200 bytes
at the allowance, which the probe padding does.

Locally, a client moving to its preferred address sends a 44-byte first
packet from its new port: before, the server abandoned that probe exactly
as on QIR; now it goes out padded to the 132-byte allowance and commits.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 11:00:55 +00:00
.github codeql: js: ignore the lhp-dlo vectors, exclude log-injection and user-controlled-bypass 2026-09-12 04:04:22 +01:00
assets minimal-crypto-dnssec 2026-03-29 05:38:02 +01:00
cmake remove: LWS_WITH_ABSTRACT and LWS_WITH_SMTP leftovers 2026-09-27 14:16:03 +00:00
contrib dlo: file-backed mcufonts, resident by dictionary and glyph as reclaimable occupants 2026-09-16 16:34:45 +00:00
doc-assets remove: LWS_WITH_ABSTRACT and LWS_WITH_SMTP leftovers 2026-09-27 14:16:03 +00:00
fuzz sans-io: the halves are directories, lib/sansio and lib/io 2026-09-28 05:49:30 +00:00
include dir-notify: kqueue monitors could never be created on Darwin 2026-09-28 09:02:00 +00:00
lib quic: a path probe fits the anti-amplification allowance it was given 2026-09-28 11:00:55 +00:00
lwsws lwsws: config dir up to 255 chars, and never open a truncated config path 2026-09-27 14:46:56 +00:00
minimal-examples examples: leave headroom in the fd limits 2026-09-28 08:36:31 +00:00
minimal-examples-lowlevel api-test-openhitls-session-dump: use a real context and only public apis 2026-09-28 10:38:57 +00:00
plugin-standalone oauth-debug 2026-08-11 04:53:23 +01:00
plugins cert-dist: the plugins can be composed into an application 2026-09-28 06:44:14 +00:00
READMEs sans-io: ws's extension drain asks IO to flag pending rx through io_ops 2026-09-28 08:46:06 +00:00
scripts cmake: LWS_WITH_SANSIO_LINK_TEST links the sansIO half alone 2026-09-28 08:02:27 +00:00
test-apps examples: leave headroom in the fd limits 2026-09-28 08:36:31 +00:00
win32port sonarqube: fix all blocker maintainability 2026-07-21 13:29:21 +01:00
.clangd linter: fixes 2026-03-14 18:01:37 +00:00
.gitignore git: stop tracking build products committed with c5b92c871 2026-09-27 14:10:44 +00:00
.gitmodules gitmodules: add missing entry for qifs 2026-06-05 13:18:38 +01:00
.mailmap mailmap 2018-08-14 08:00:30 +08:00
.sai.json cmake: LWS_WITH_SANSIO_LINK_TEST links the sansIO half alone 2026-09-28 08:02:27 +00:00
AGENTS.md selfdns: explicitly enable plugins 2026-09-26 17:06:35 +00:00
bug_report.md docs: switch to use main 2020-10-19 16:35:03 +01:00
changelog LWS_PRE: changelog note for the ABI change and compile-time guards at the in-place prepends 2026-09-17 14:40:37 +00:00
CMakeLists-implied-options.txt remove: LWS_WITH_ABSTRACT and LWS_WITH_SMTP leftovers 2026-09-27 14:16:03 +00:00
CMakeLists.txt cmake: LWS_WITH_SANSIO_LINK_TEST links the sansIO half alone 2026-09-28 08:02:27 +00:00
component.mk Fixes to track updates in esp-idf 2018-06-20 16:41:28 +08:00
Kconfig esp32: enforce ssl nonblocking 2017-04-03 14:09:37 +08:00
lgtm.yml lgtm.yml 2022-03-15 10:28:09 +00:00
libwebsockets.dox plugins: lws_rtc_camera 2026-04-03 14:13:12 +01:00
LICENSE auth 2026-03-29 05:38:54 +01:00
Makefile.projbuild esp32-selfsigned 2017-12-01 11:37:35 +08:00
README.md README: pre-5.0 security warning 2026-08-29 05:33:04 +01:00
SECURITY.md Create SECURITY.md 2024-03-05 06:47:53 +00:00
sonar-project.properties sonar-push-settings: take the token from the environment or a fixed path 2026-09-21 15:42:08 +00:00

CI status Coverity Scan Build Status CII Best Practices

Libwebsockets

Libwebsockets is a simple-to-use, MIT-license, pure C library providing client and server for http/1, http/2, http/3, websockets, webtransport, MQTT and other protocols in a security-minded, lightweight, configurable, scalable and flexible way. It's easy to build and cross-build via cmake and is suitable for tasks from embedded RTOS through mass cloud serving.

It supports a lot of lightweight ancilliary implementations for things like JSON, CBOR, JOSE, COSE, and supports OpenSSL and MbedTLS v2/3/4 out of the box for everything. It's very gregarious when it comes to event loop sharing, supporting libuv, libevent, libev, sdevent, glib and uloop, as well as custom event libs.

100+ independent minimal examples for various scenarios, CC0-licensed (public domain) for cut-and-paste, allow you to get started quickly.

There are a lot of READMEs on a variety of topics. Doxygen API docs

We do a huge amount of CI testing per push

overview

V5.0 now available... please upgrade to this or preferably v5.0-stable or main, as there are many security fixes only available on v5.0-stable and main; pre-5.0 releases are effectively deprecated.

There's a continuous incremental security audit in place finding and fixing new problems all the time at the moment, it's not a sign the code is weak: it's a sign I am using frontier models to make it extremely strong.

** NEW features available on v5.0 **

  • Support for SChannel (windows native TLS, no need for OpenSSL build!), GnuTLS, openHiTLS and BearSSL added
  • QUIC + H3 + Webtransport implementation, using aws-lc, wolfssl, boringssl, libressl, gnutls, and schannel (OpenSSL is h1/h2 -only; mbedtls can do it via a patch)
  • WebRTC mixing (like your own zoom)
  • HLS serving
LWS version Platform Protocols Default TLS
<= 4.5 non-FreeRTOS any OpenSSL
<= 4.5 FreeRTOS any mbedTLS
5.0+ Windows any schannel
5.0+ *nix h1, h2 OpenSSL
5.0+ *nix quic/h3 GnuTLS
5.0+ FreeRTOS any mbedTLS

quic/h3 is enabled for build by default... necessitating GnuTLS instead of OpenSSL to make quic/h3 work.

TLS Library Server TLS Client TLS QUIC Transport (TLS 1.3) WSS / HTTPS MQTT over TLS ALPN (HTTP/2) DTLS (WebRTC) Session Cache JIT Trust GenCrypto
GnuTLS Yes Yes Yes Yes Yes Yes Yes Yes No Yes
OpenSSL Yes Yes No* Yes Yes Yes Yes Yes Yes Yes
LibreSSL Yes Yes Yes Yes Yes Yes Yes Yes No Yes
AWS-LC Yes Yes Yes Yes Yes Yes Yes Yes No Yes
BoringSSL Yes Yes Yes Yes Yes Yes Yes Yes No Yes
wolfSSL Yes Yes Yes Yes Yes Yes Yes Yes No Yes
mbedTLS Yes Yes Needs patch Yes Yes Yes Yes Yes Yes Yes
SChannel Yes Yes Yes Yes Yes Yes Yes Yes No Yes
BearSSL Yes Yes No Yes Yes Yes No Yes Yes Yes
openHiTLS Yes Yes No Yes Yes Yes Yes (not SRTP) Yes Yes Yes

* Note: 1) Upstream OpenSSL does not provide the necessary QUIC TLS API (SSL_set_quic_method) to act as a cryptographic engine for LWS's QUIC transport. If you need QUIC/HTTP3 support, we recommend using BoringSSL or GnuTLS. * *Note: 2) openHiTLS does not provide the necessary QUIC TLS API *

  • DHT support built-in: -DLWS_WITH_DHT=1