🛡️ Memory-Safety Verified
ASan + UBSan clean — 101/101 tests, zero leaks, nightly CI.
A lightweight, embeddable C99 HTTP/1.1 & WebSocket library — the only one in its class verified clean under ASan and UBSan. Runs 32-bit embedded, serves 83K RPS on CI, leaks nothing. Throughput you can measure, memory safety you can prove.
Performance baselines are measured on GitHub Actions ubuntu-latest runners for hardware consistency. Previous local baselines (v2.6.x, ~20K RPS) were measured on developer hardware with 40%+ variance from CPU thermal throttling. The CI runner eliminates this variance (CV 0.4–2.4%), providing an authoritative, reproducible baseline.
| Metric | Value | Notes |
|---|---|---|
| Peak Throughput | ~83K RPS | 10 conn, HTTP/1.1, GitHub CI runner |
| High Concurrency | ~55K RPS | 1000 concurrent connections |
| Static Files | 5.7K RPS | ~100KB body, benchmark_unified |
| API Routing | 82K RPS | JSON endpoint |
| Average Latency | ~117µs | P50, 10 connections |
| Error Rate | 0% | Zero socket errors under load (10 conn) |
| Test Suite | 101/101 pass | ASan + UBSan verified clean |
.github/workflows/ci-nightly.yml)make verify-memory-safety — see Memory SafetyMost lightweight C HTTP libraries optimize for peak RPS and stop there. UVHTTP optimizes for the property that breaks production: memory safety. A per-connection leak or use-after-free that survives a 10-second benchmark will OOM an embedded device over a week. UVHTTP is the lightweight, embeddable, 32-bit-capable C library that proves — under both AddressSanitizer and UndefinedBehaviorSanitizer, on every nightly CI run — that those bugs are gone. |---------|:----------------😐:------😐:---------------------😐:-----------------------😐 | UVHTTP | ✅ | ✅ | ✅ 101/101, nightly CI | ✅ 101/101, nightly CI | | libuv-http | ✅ | ⚠️ | ❓ not advertised | ❓ not advertised | | microhttpd | ✅ | ⚠️ | ❓ not advertised | ❓ not advertised | | mongoose | ✅ | ✅ | ❓ not advertised | ❓ not advertised | | nginx | ❌ (standalone) | ✅ | ✅ (large team) | ❓ |
"not advertised" means the project publishes no sanitizer-clean test gate, so the absence of a finding is not verifiable. UVHTTP's is reproducible with
make verify-memory-safety.
TCP_NODELAY and TCP_KEEPALIVE enabled by defaultUVHTTP handles HTTP/1.1 and WebSocket protocol details; it does not impose business logic. The application keeps control over authentication, databases, and other features.
Abstractions are compile-time macros with no runtime cost in production builds. The library calls libuv directly, with no intermediate layers.
The codebase favors simplicity. Self-contained dependencies and a clean architecture keep maintenance cost low.
Production code contains no test-specific code. Tests use linker wrapping and external mock frameworks, so the library ships clean.
All state is held in libuv data pointers (loop->data or server->context). This enables multi-instance support and unit testing without global-state pollution.
A unified error type carries codes, descriptions, and recovery hints. Every failure point is checked and reported.
UVHTTP targets Linux, with 32-bit embedded support. Cross-platform expansion is on the roadmap.
# Clone repository with submodules
git clone --recurse-submodules https://github.com/adam-ikari/uvhttp.git
cd uvhttp
# Build with default options
make build
# Run example server
./build/dist/bin/hello_worldFor detailed installation instructions and build options, see the Installation Guide.