mod_http3 v0.0.72 RPM and DEB packages released

mod_http3 v0.0.72 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

Major changes:

  • On Linux, with ListenCoresBucketsRatio, the parent binds one SO_REUSEPORT QUIC socket per listener bucket and one child serves each, so more than one child serves HTTP/3. The sockets stay bound when children start and stop, so the kernel keeps each peer on the same socket.
  • On Linux the parent binds the QUIC socket while it still runs as root, so H3Port 443 works without CAP_NET_BIND_SERVICE. The socket stays bound across graceful restarts and the children inherit it; one child at a time serves it.
  • Linux: QUIC packets to one peer now go out in one sendmsg with UDP_SEGMENT (GSO), and reads use UDP_GRO. Without kernel support the module sends one packet at a time. A stream read now sends the new flow-control window at once, so a blocked client does not wait.
  • Added H3MaxWindow (default 6 MiB). Flow-control windows for client uploads now grow when a client fills them within a few round trips, up to this cap, so uploads on long, fast paths are no longer held to a fixed 1 MiB window.
  • Added H3EarlyData (default off). A resumed client may send its first request as 0-RTT data and gets the response one round trip sooner. Only safe methods run before the handshake completes; other methods wait for it, because 0-RTT data can be replayed (RFC 8470).
  • Moved the QUIC transport from the OpenSSL QUIC server to ngtcp2, with OpenSSL as the TLS backend through its QUIC TLS API. OpenSSL still drops server-side 0-RTT packets. ngtcp2 >= 1.25.0 is a new build dependency (WITH_NGTCP2). Stream data is no longer copied: nghttp3 releases a buffer when the peer acknowledges it. H3IdleTimeout now always closes with NO_ERROR; the QUIC idle timer runs 2 seconds longer and closes silently.

Leave a Reply

Your email address will not be published. Required fields are marked *