1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
//! Courierust — a self-contained HTTP/1.1 + HTTP/2 + HTTP/3 + WebSocket + gRPC stack.
//!
//! The protocol core (`courierust_http`, `courierust_h1`,
//! `courierust_hpack`, `courierust_h2`, `courierust_ws`,
//! `courierust_deflate`, `courierust_quic`, `courierust_h3`,
//! `courierust_fingerprint`, `courierust_crypto`, `courierust_bytes`,
//! `courierust_io`, `courierust_error`) compiles on `no_std + alloc`
//! with **zero** third-party dependencies. The `std` feature (enabled by
//! default) adds the threaded networking layer: `courierust_pool`
//! (work-stealing scheduler), `courierust_net`, `courierust_tls` (the
//! TLS 1.2/1.3 stack), `courierust_body` (channel-backed streaming
//! bodies), `courierust_client` (the h1 pool, the h2/h3 drivers and the
//! WebSocket client), `courierust_server` (the event-driven scheduler
//! plus the WebSocket upgrade path) and `courierust_grpc`.
//!
//! Every public module carries the crate's `courierust_` prefix so no
//! module path collides with a third-party crate of the same short name
//! (e.g. `h2`, `http`, `bytes`, `grpc`, `tls`).
//!
//! Design highlights:
//!
//! * **Multi-core parallelism** — a work-stealing thread pool with
//! per-worker LIFO caches and a global FIFO steal queue; client pools
//! are shared per authority, and up to `max_connections_per_host` a
//! request opens a fresh HTTP/2 connection. At that cap the pool picks
//! the *least-loaded* connection — active streams plus in-flight
//! request-body bytes (64 KiB units) plus a capped EWMA of per-request
//! service time — and always prefers an idle connection for reuse
//! regardless of its history.
//! * **RFC 9218 client priority frames** (`PRIORITY_UPDATE`, frame type
//! `0x10`) with a Weighted-Urgency Calendar Scheduler (WUCS): eight
//! urgency buckets combined with Deficit Round Robin anti-starvation
//! and round-robin interleaving for incremental streams — O(1)
//! scheduling decision.
//! * **Batched Credit Reflow (BCR)** flow control — received data is
//! acknowledged in batches rather than one `WINDOW_UPDATE` per frame,
//! cutting control-frame overhead.
//! * **Table-driven HPACK** — 8-bit two-level Huffman decode tables and a
//! hash-accelerated static/dynamic header index fast path.
//! * **WebSocket** — RFC 6455 framing, masking, UTF-8 validation, the
//! close handshake and RFC 7692 `permessage-deflate`, in
//! `courierust_ws`. Masking is XORed in 16-byte lanes (a 4-byte
//! repeating key cannot vectorise, but 16 is a multiple of four, so
//! every lane starts at the same key phase), a payload over 8 KiB is
//! read straight into the message buffer instead of through the
//! buffered reader, and the DEFLATE context is reused per message
//! rather than rebuilt. A live HTTP/1.1 connection is upgraded in
//! place by both server drivers — in the event reactor an idle
//! WebSocket costs a poller slot, not a thread — and the client speaks
//! `ws://` / `wss://` over the crate's own TLS stack.
//! * **HTTP/3 over QUIC v1** — `courierust_quic` (packet and frame
//! codecs, varints, header protection, key update) plus `courierust_h3`
//! (QPACK, H3 framing, and a poller-driven UDP reactor whose poll
//! timeout is an absolute protocol deadline rather than a fixed tick).
//! * **Fingerprint profiles** — exact Chrome HTTP/2 settings/header
//! ordering plus JA3/JA4 TLS `ClientHello` parameter profiles with
//! self-contained MD5/SHA-256, so a browser-shaped fingerprint can be
//! fed to an external TLS layer of your choice.
//!
//! TLS 1.3 (RFC 8446) and TLS 1.2 (RFC 5246 / RFC 8422) are implemented
//! from scratch under the `std` feature (`courierust_tls` module) —
//! client and server handshakes, X25519 key exchange, AES-GCM /
//! ChaCha20-Poly1305 record protection (over TLS 1.2 only the AEAD ECDHE
//! suites are offered; CBC/HMAC, static-RSA and RC4 never are), and X.509
//! chain validation — so `https://` is a first-class capability on both
//! the client and the server. The protocol core stays `no_std + alloc`
//! with zero third-party dependencies; the transport traits let the same
//! codecs also run over an externally supplied TLS stream.
extern crate alloc;
extern crate std;
/// Lock a [`std::sync::Mutex`], recovering from poisoning.
///
/// A poisoned lock means some thread panicked while holding it. For a
/// server that must not escalate: the panic already failed one request,
/// and `unwrap()` would turn it into a permanent failure of every later
/// operation on the same pool, pool registry or health state — an outage
/// caused by a bug that would otherwise have cost a single request.
///
/// Recovery is sound for the structures this crate puts behind these
/// locks: each is one standard-library call away from a consistent state
/// (a map insert/remove, a queue push/pop, a counter), so there is no
/// multi-step invariant a panic could tear. Where a panic *could* leave
/// torn state, the lock is not shared in the first place.
pub
pub use Bytes;
pub use ;
/// The crate README, compiled as doctests by `cargo test --doc`.
///
/// Every `rust` block in `README.md` is therefore a test: a sample that
/// stops compiling fails CI instead of shipping to `docs.rs` and being
/// copied by a user. Blocks that open a socket or read a file are marked
/// `no_run`, so they are compiled and type-checked but never executed.
///
/// `README_CN.md` is not included a second time — `tests/readme_parity.rs`
/// requires the two READMEs to contain byte-identical code blocks and the
/// same layout graph, so the doctests below cover both.
;
/// The per-module `README.md` files, compiled as doctests by
/// `cargo test --doc` under the same contract as [`ReadmeDoctests`]: a
/// `rust` block in a module README that stops compiling fails CI.
///
/// The Chinese counterparts are covered by `tests/readme_parity.rs`,
/// which requires every `src/<module>/README.md` / `README_CN.md` pair to
/// carry the same code (comments may be translated), so a block fixed here
/// cannot drift there.
/// The `wiki/en` pages, compiled as doctests by `cargo test --doc`.
///
/// The wiki is what a new user reads first, and it is synced to GitHub —
/// a snippet that has stopped compiling is worse than no snippet. The
/// Chinese pages are not included a second time: `tests/readme_parity.rs`
/// requires each `wiki/en/<Page>.md` to carry the same code as its
/// `wiki/zh/<页面>.md` counterpart, so these doctests cover both.