Repository navigation
CWIST v3.5
CWIST v3.5 — HTTP/3 client, websocket RFC 6455 hardening wave, and C1M reactor scaling
Major changes compared to v3.4:
-
HTTP/3 Client (489a976)
- The HTTP/3 client is ported from dev to main: QUIC/HTTP3 request path over the pinned lsquic master, without the WebTransport extension.
-
C1M Reactor Scaling (28941cc)
- One reactor loop per CPU the worker actually owns, sized from the worker's real affinity instead of the machine's core count.
-
GC: Header-Scoped Malloc Interception (037c24d)
- CWIST_INTERCEPT_MALLOC lets a request handler route libc allocations through the header-scoped GC arena for the duration of a request.
-
WebSocket RFC 6455 Hardening Wave
- Validate Sec-WebSocket-Version on upgrade and reject non-13 (68a3bf8, 57481d8).
- Reject frames with non-zero RSV bits per section 5.2 (971fb8e).
- Reassemble fragmented messages per section 5.4 and cap the total reassembled size at 64 MiB (24bf4d2, fe4e709).
- Auto-reply PONG to PING frames per section 5.5.3 and echo CLOSE on receipt per section 5.5.1 (55062f8, 5d8a7a6).
- Per-frame payload cap to prevent OOM DoS (ce61941).
-
Security Fixes
- jwt: validate the alg header field in cwist_jwt_verify() per RFC 8725 section 3.1 (13b372e).
- http_client: cap response bodies at CWIST_HTTP_MAX_BODY_SIZE and response header counts at 200 against OOM DoS (d01c3d5, 44d9ca6).
- Security headers: HSTS removed from the generic set, Permissions-Policy added (73d5a30).
-
Benchmark CI
-
Reliability and Fixes
- flash: allocation return checks and zero-sized map guard (f872cae).
- writer_fast: null check and P2C worker selection seed safeguard (8c8f72d).
- healthz: reuse inactive probe slots, guard the null probe buffer (7249a10).
- json_builder: escape strings per RFC 8259 with null safety (51abac7).
- scheduler: disown the delayed-job heap from the growing thread's GC scope (f2404f4).
- sstring_data_or_empty renamed to sstring_as_text (1eec306).
Notes:
- Source tarball builds the same way as v3.4: vendored dependencies included,
makeat the top level produces libcwist.a, the CLI, and cwist.pc. - Homebrew formula in this release line: packaging/homebrew/cwist.rb.