Sitelet https://github.com/zatrano/rawhttp
Skip to content

Latest commit

 

History

37 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

RawHTTP

Independent HTTP/1.1 engine for Go. Zero external dependencies.

Tests Static Analysis Coding Style Security Performance

gosec govulncheck Semgrep Trivy

Go License: MIT Version Latest Release Security Policy

Peak RPS Errors Max connections Peak memory Deps


Status: v0.2.2 (GA for application embedding). Suitable for production application servers (e.g. ZATRANO V3). Not positioned as a reverse proxy. Read SECURITY.md before public exposure.

Your app / framework
        ↓
     RawHTTP
        ↓
     Network

RawHTTP owns listen, connections, HTTP/1.1 parse/write, Ctx, limits, and the keep-alive client. Routing and application concerns stay in your code (or your framework).

Install

go get github.com/zatrano/rawhttp@v0.2.2

Tests live in a separate module (test/); run with: cd test && go test ./...

Quick start

package main

import (
	"log"

	"github.com/zatrano/rawhttp"
)

func main() {
	log.Fatal(rawhttp.ListenAndServe(":8080", func(ctx *rawhttp.Ctx) {
		ctx.SetBody([]byte("Hello, World!"))
	}))
}

Full guides: Documentation.

Features

  • HTTP/1.1 server (Serve / ServeConn / ListenAndServe / TLS / reuseport / prefork)
  • Keep-alive client (Client / HostClient / PipelineClient / LBClient)
  • Hot-path request parsing keeps Method / Path / headers as buffer slices; plaintext hello is 0 allocs/op (CI gate)
  • Protocol hardening (Host, CL/TE, smuggling corpus, fuzz CI) — see SECURITY.md
  • Forms, multipart, cookies, JSON helpers, static files (FS / SendFile)
  • Streaming (request/response), connection Hijack, optional AllowUpgrade for standards-shaped WebSocket handshakes (no frame codec)
  • Middleware helpers (CORS, compress, rate limit, auth, …) — compose by wrapping Handler
  • Proxy dialers (HTTP CONNECT / SOCKS5), TCPDialer + DNS cache

Not included in v0.2.2: path-parameter router (:id / {id}), header-name normalization disable API, WebSocket frame codec. By default Upgrade / Connection: upgrade are rejected with 400; set Server.AllowUpgrade to admit a standards-shaped handshake to Hijack — see Hijacking.

Documentation

Doc Topic
Getting started Install → first server
Concepts Server / Conn / Request / Response / Handler
Server Config, Serve, Shutdown
Request / Response Ctx I/O
Headers / Cookies / Body
Routing Manual routing patterns
Middleware Wrap Handler
Forms / Files urlencoded, multipart, FS
Streaming / Hijacking
Errors / Timeouts / Concurrency
Performance Model + benchmarks
Production Deploy checklist
API reference Exported surface
Examples Hello, JSON, middleware, upload

Benchmarks

Measured on 2026-10-02, v0.2.2, Go 1.25.13, Windows/amd64, GOMAXPROCS=8, CPU i5-1135G7 @ 2.40GHz. Absolute ns/RPS are host-specific and vary with load; treat CI ServeConn floors as authoritative (see docs/performance.md).

Numbers below mix a 2026-09-30 TCP multibench snapshot (RPS tables) with 2026-10-02 ServeConn gates + microbench on this host. CI ServeConn floors are the regression contract (see docs/performance.md).

TCP multi-rival (scripts/multibench)

cd scripts/multibench && go run . -c 64 -d 3s -rounds 3

Conditions: keep-alive HTTP/1.1; same fasthttp.HostClient for every server; c=64; 1s warmup + 3s timed; 3 rounds median per server with rotated start order; scenarios plaintext, json, headers, chunked. Optional -strict is local-only (see performance); CI uses ServeConn gates.

Notes: Hertz on Windows used network library=standard. Multibench uses a shared fasthttp.HostClient for all servers.

plaintext — median RPS (snapshot)

Rank Server req/s
1 RawHTTP 149 613
2 fasthttp 126 166
3 gnet 115 031
4 Hertz 108 968
5 net/http 76 284

json — median RPS (snapshot)

Rank Server req/s
1 RawHTTP 141 835
2 fasthttp 132 769
3 gnet 131 427
4 Hertz 112 718
5 net/http 69 777

headers — median RPS (snapshot)

Rank Server req/s
1 RawHTTP 133 871
2 fasthttp 119 144
3 gnet 104 071
4 Hertz 95 492
5 net/http 89 328

chunked (POST body echo) — median RPS (snapshot)

Rank Server req/s
1 RawHTTP 139 057
2 fasthttp 130 533
3 gnet 129 751
4 Hertz 126 293
5 net/http 76 300

ServeConn microbench (test/)

cd test && go test -run=^$ -bench='Benchmark(RawHTTP|FastHTTP|NetHTTP)_Plaintext$' -benchmem -benchtime=2s -count=3
cd test && go test -run=^$ -bench='Benchmark(RawHTTP|FastHTTP)_JSONPost$' -benchmem -benchtime=2s -count=3

Absolute ns/op below are host-specific (median of 5 runs, -count=5; re-measure on your machine).

Plaintext hello

Server ns/op B/op allocs/op vs RawHTTP
RawHTTP 257 0 0 —
fasthttp 735 0 0 2.86×
net/http 7562 1347 13 29.4×

JSON POST

Server ns/op B/op allocs/op vs RawHTTP
RawHTTP 458 0 0 —
fasthttp 863 0 0 1.88×

ServeConn gate trimmed medians (this host, 2026-10-02)

Scenario vs Ratio Floor
plaintext fasthttp 2.84× 2.35×
JSON POST fasthttp 2.08× 1.65×
headers fasthttp 3.59× 1.50×
chunked fasthttp 2.09× 1.50×
plaintext net/http 24.9× 8.0×
JSON POST net/http 17.3× 4.0×

CI performance contract (v0.2.2)

ServeConn gates enforce “never slower” on trimmed rounds (≥1.00×) plus scenario floors (see docs/performance.md for soft 0.85× / trim / soft-retry). Floors today:

Gate Floor
ServeConn vs fasthttp plaintext / JSON / headers / chunked ≥2.35× / ≥1.65× / ≥1.5× / ≥1.5×
ServeConn vs net/http plaintext / JSON ≥8.0× / ≥4.0×
HostClient vs fasthttp measured in tests; not a CI floor
plaintext hello 0 allocs/op
cd test && go test -run 'Gate|Allocs' -v

vs net/http / fasthttp / Hertz / gnet

RawHTTP net/http fasthttp Hertz gnet
Role HTTP/1.1 engine stdlib HTTP HTTP engine CloudWeGo HTTP Event-loop net framework
Deps none stdlib compress libs larger tree event-loop
Router bring your own ServeMux bring your own built-in N/A (raw)
Ctx model *Ctx ResponseWriter+Request RequestCtx RequestContext custom
Typical use engine under apps general Go Fiber / custom microservices custom protocols
This-host plaintext TCP (median snapshot) 149.6k 76.3k 126.2k 109.0k 115.0k
This-host ServeConn plaintext 257 ns, 0 alloc 7562 ns, 13 alloc 735 ns, 0 alloc — —

Snapshot ranking is host-specific. Methodology and gate floors: docs/performance.md.

Client

c := &rawhttp.Client{}
resp := rawhttp.AcquireResponse()
defer rawhttp.ReleaseResponse(resp)
if err := c.Get("http://127.0.0.1:8080/", resp); err != nil {
	log.Fatal(err)
}

Quality gates (CI)

Job What
unit + security test/ + security corpus
race race detector; also -tags rawhttp_poison
coverage / style / vuln / build standard
gate ServeConn rival floors + allocs (TestGate_* / TestAllocs_*)
fuzz ServeConn, request-line, headers, chunked, differential ReadRequest
nightly fuzz longer fuzz (schedule + workflow_dispatch)

Used by

ZATRANO V3 uses RawHTTP as its HTTP foundation.

License

See LICENSE.

About

HTTP/1.1 engine for Go. Zero external dependencies.

Resources

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages