Skip to content

UVHTTP Roadmap ​

Vision ​

A lightweight, production-grade HTTP/1.1 server library for C — with no hidden layer between your application and libuv.

Scope Boundary ​

What this library is deliberately not responsible for. Each was evaluated and excluded; the reasoning for the protocol choices is recorded in PHILOSOPHY.

ConcernWhy it is out of scope
HTTP/2Multiplexing is incompatible with libuv's transparent per-connection event model
HTTP/3 (QUIC)Requires a different transport layer; outside the scope of a lightweight C library
IPv6 listeningGateway / network-stack concern. Client-side IPv6 address extraction is supported
YAML/JSON config filesThe framework or application embedding this library owns its own configuration format
Per-user / per-IP rate limitingGateway / reverse-proxy concern. A global token bucket with whitelist is provided
Observability (metrics, tracing, dashboards)Prometheus / OpenTelemetry territory
Auth, DDoS protection, certificate managementGateway / security-layer concern
Plugin system, microservices, cloud-native, serverlessInfrastructure. Compile-time feature selection (27 CMake options) covers capability needs
Hot reloadProcess/supervisor concern

Current Status (v2.9.1) ​

Delivered ​

  • HTTP/1.1 — ~85K RPS on CI runners (paired-gate measured)
  • WebSocket — full-duplex, RFC 6455, Ping/Pong with heartbeat
  • TLS 1.2/1.3 via mbedtls, with session cache (2048 entries / 24h)
  • Static files — sendfile zero-copy with chunked fallback; path resolution fuzz-verified
  • gzip compression with LRU cache
  • Rate limiting — global token bucket + whitelist
  • Middleware — compile-time, zero runtime overhead
  • 32-bit embedded support
  • 27 compile-time options for capability trimming

Quality Infrastructure ​

  • 102 unit tests, all green
  • ASan gate on every PR; UBSan, stress, and coverage runs nightly
  • 4 libFuzzer harnesses (router / request / websocket / static-path)
  • Same-runner paired performance gate: head vs base, 10% threshold, fail-closed
  • cppcheck static analysis, zero warnings
  • CI GITHUB_TOKEN scoped to contents: read

Open Work ​

Genuine gaps, ordered by value.

Performance ​

  • [ ] Connection pooling optimization
  • [ ] Memory usage reduction per request
  • [ ] CPU efficiency on the hot path

Developer Experience ​

  • [ ] Enhanced logging framework (structured levels, pluggable sinks)
  • [ ] API reference completeness pass

Documentation ​

  • [ ] Architecture diagrams
  • [ ] Performance tuning guide

Platform — no schedule, on demand ​

  • [ ] macOS
  • [ ] FreeBSD

Technology Stack ​

LayerChoice
CoreC99, libuv 1.52, llhttp
TLSmbedtls
Memorymimalloc (optional)
HashingxxHash
JSONcJSON (optional)
TestingGoogle Test, libFuzzer

Measured Performance ​

From the paired gate (same runner, head vs base, 10 alternating rounds):

EndpointRPSNote
/~85KIn-memory response
/json~85KJSON serialization
/large~9.6K100KB body

Absolute values drift roughly 40% across runs on shared runners, so only paired ratios are meaningful. The gate fails when the median ratio drops below 90% and most individual pairs also fall below 90% — absolute RPS thresholds would gate on runner luck rather than on code.

Released under MIT License