Skip to content

CWIST v3.7

Choose a tag to compare

@gg582 gg582 released this 24 Sep 12:52
· 0 commits to e20ea028a5aa7c748b517866d985bf3f04246271 since this release

CWIST v3.7 — the last experimental train before v4

v3.7 is the release that implements 90% of planned feature of long-term roadmaps. where new or experimental capability may land. Everything rides here behind flags or marked experimental so v4.0 can freeze features and focus on stabilization. Major changes compared to v3.6:

  1. WASM edge deployment (issue #201)

    • Promote WASI 0.2 (wasm32-wasip2) from experimental to supported: CI gate, wasi:sockets smoke test, and docs/api/wasi.md reframed as reference documentation.
    • example/wasip2-kv/: edge persistence demo that round-trips a cwist_db blob through a preopened host directory and survives a wasmtime restart.
    • docs/deployment/wasmtime-appliance.md: production appliance guide with isolated state, restart verification, backup, and rollback.
    • Streaming producer API: cwist_http_response_stream_begin/write/end delivers chunked response bodies chunk-by-chunk from handlers.
  2. WASI component pipeline experiment (issue #203 / PR #204)

    • WIT-world validation in CI, jco guests over preview2-shim and preview3-shim under JSPI, browser-bundle packaging gate, and an async host.send-chunk streaming world.
    • The Emscripten bundle swap itself remains gated on WASI 0.3 stabilization and unflagged JSPI — a v4.0 decision.
    • Retire the WASI preview1 target (wasi-smoke).
  3. HTTP/HTTPS hot-path improvements (issue #237)

    • Wave A: request-string and static-header borrowing, route-lookup residue removal, and response serialization shortcuts.
    • Wave B: TLS record coalescing and non-blocking async file streams (Linux-only burst path).
    • Wave C: serializer fast path, static-cache residue, and route-lookup residue.
    • C1M-on + drain-chunk 8 is now the default deployment baseline (45b07f5).
  4. Reactor hardening for C1M tail latency (issue #166)

    • Grace-peek the CQ ring before committing to the kernel wait (62cfb06).
    • Grow the slot pool without holding the pool lock (#258, af30263).
    • Serialize SQ-consuming enters to stop tail-behind-head wedge (#259, 26bc314).
    • Flush parked re-arms when a dispatch round runs long (#260, c49345c).
    • Serve h2c connections on a per-connection thread, off the reactor (b0dec33).
    • Per-event latency probe remains env-gated (CWIST_LATENCY_PROBE=1); the HTTP batch-shed counter stays always-on.
  5. Full-stack framework primitives (issue #94)

    • Reusable HTML component render units (Phase 1), component-scoped CSS class names (Phase 2), HTML-over-the-wire page/fragment responses (Phase 3), content-hashed in-memory assets (Phase 4), and CSS minification/bundling (Phase 4).
    • Component-rendered fragment view in the WASM service worker example (Phase 5).
    • append_ok() CSS composer refactor with documented trust boundary.
  6. Full-GC tracking overhead fix (issue #65)

    • Replace the linear pending-sweep scan with O(1) hash-set lookups and a thread-local fast path (46ab2ec).
    • Add live-set-scaled benchmark (test_full_gc_tracking) and refresh docs/GC.md measurements (8d01489, 0cdc33b).
  7. HTTP correctness and hardening

    • Reject CR/LF in cwist_http_header_add and handle header string allocation failure.
    • Send the full body in cwist_send_error_response.
    • Check sstring and header results on the right error channel in SSE, cookies, WebTransport, and Redis paths.
    • Reject a chunked request when appending a chunk fails.
    • Constant-time HMAC comparison in session signature verification.
  8. Experimental ecosystem support (shipped behind flags)

    • GraphQL subscriptions over the non-blocking WebSocket transport (cwist/graphql_ws.h, topic broker, test_graphql_subscriptions).
    • Durable Redis/NATS job queue backends (cwist/sys/job/durable_queue.h).
  9. QUIC/WebTransport slipped to v3.8

    • WebTransport on the stable line and HTTP/3 connection-close correctness are blocked on upstream lsquic merges, so they move to the v3.8 queue rather than pinning to a topic branch.
  10. Also in this release

    • CWIST_PROFILE preset env var with performance / lowmem / lowlat / default overlays (issue #171).
    • Tutorial API corrections across all 30 tutorials; template engine, routing, hello-world, and CSS-composer examples rewritten against the current API.
    • Rate-limiter fail-open when the IP bucket table is exhausted; sstring rtrim returns OKAY for empty strings; db_sync rejects oversized blobs; template nesting-depth tracking and empty apply_filter trim guard.
    • Benchmark comments now describe mechanisms instead of pasting run numbers.

Notes:

  • lib/lsquic stays pinned to upstream master (2b30189), the same stable pin as v3.6.
  • Source tarball builds like v3.6: vendored dependencies included; make at the top level produces libcwist.a, the CLI, and cwist.pc.
  • Homebrew formula in this release line: packaging/homebrew/cwist.rb (tap: c4punks/homebrew-cwist).