http2
HTTP/2 library
https://github.com/kazu-yamamoto/http2
| LTS Haskell 24.62: | 5.3.10@rev:1 |
| Stackage Nightly 2026-10-08: | 5.4.8 |
| Latest on Hackage: | 5.4.8 |
BSD-3-Clause licensed and maintained by Kazu Yamamoto
This version can be pinned in stack with:
http2-5.4.8@sha256:a75c02eb2cccb36160b1e17dff580358de60e0d77f9d2bee6f81aa615e25281b,10670Module documentation for 5.4.8
- Network
Depends on 28 packages(full list with versions):
aeson, aeson-pretty, array, async, base, base16-bytestring, bytestring, case-insensitive, containers, crypton, directory, filepath, http2, http-semantics, http-types, iproute, network, network-byte-order, network-control, network-run, stm, text, time-manager, unix-time, unordered-containers, utf8-string, vector, word8
Used by 4 packages in nightly-2026-10-08(full list with versions):
HTTP/2 library including frames, HPACK, client and server.
Changes
ChangeLog for http2
5.4.8
- Reset a stream cancelled with an asynchronous exception instead of closing the connection. #214
- Server: tickle the worker’s timer on sending, so that a response streamed longer than the timeout is not killed. #174
freeSimpleConfigno longer calls the no-opkillManager. Timeout actions registered withconfTimeoutManagermust be cancelled by their owner. #215
5.4.7
- Decode a Huffman-coded field value longer than 4096 octets. #201
- Accept a header block with no fields, as empty trailers are sent. #202
- Decode a malformed field block to the end and reset only its stream. #211
- Give the padding of DATA frames back to the flow control windows. #204
- Charge refused or ignored DATA to the connection window. #205
- Client: reset with CANCEL a response not read to the end. #207
- Client: give back the window used by unwanted pushes. #208
- Do not count padding into the length checked against content-length. #203
- Make no push when the client allows no concurrent streams. #206
- Include running streams in the last stream identifier of GOAWAY. #209
- Let streams up to the last stream identifier finish after a GOAWAY with NO_ERROR. #210
- Send frames other than DATA while the connection window is shut. #212
5.4.6
- Security: count the resets we send against
rstRateLimit(MadeYouReset, CVE-2025-8671). #190 - Security: do not create a stream for a PRIORITY frame. #195
- Security: treat an overflowing SETTINGS_INITIAL_WINDOW_SIZE as FLOW_CONTROL_ERROR. #196
- Fix the HPACK dynamic table when it is full. #192
- Fix encoding a Huffman-coded string of 16K or more. #188
- Send and receive large header blocks with CONTINUATION frames, and keep decoding the header blocks of reset streams. Thanks to Edsko de Vries. #187 #189
- Fix a race that lost a stream’s half-closed state. #193
- Client: accept a response with no content but a non-zero content-length. #194
- Client: a request that fails before it is queued no longer blocks later ones. #198
- Server push: send PUSH_PROMISE before the response and close pushed streams. #199
- Fix an upload through
runIOlarger than the stream’s window. #200 - Tests: work around a GHC 9.12 miscompilation. #197
5.4.5
- Security: check the length of a frame payload before decoding its fixed-size fields. #182
- Security: bound HPACK integer decoding. #181
- Give a stream’s concurrency slot back only once on RST_STREAM. #178
- Stop the worker of a stream reset while its response is produced. #179
- Reset the stream, not the connection, on a stream error. #183
- Refuse a stream over
SETTINGS_MAX_CONCURRENT_STREAMSwith RST_STREAM(REFUSED_STREAM). #184 DecodeErrorhas a new constructor,TooLargeInteger.- A malformed request reaches a client as
StreamResetIsReceived.
5.4.4
- Improvements for dealing with RST_STREAM #172
5.4.3
- auxSendInformational: gate usage with CPP to http-semantics >= 0.4.1 #170
5.4.2
- Support informational (1xx) responses, e.g. 103 Early Hints. Servers can send
them via
auxSendInformational; clients can observe them via the newconfOnInformationalcallback inConfig. #168
5.4.1
- Ensure sender notices when receiver has terminated. #167
5.4.0
- Providing
defaultConfig. - Except the item above, this version is identical to v5.3.11 which includes breaking changes and is thus deprecated.
5.3.11
- Implementing
auxSendPingfor client. - Server and client terminates their threads in the right order.
- Using
copyin frame decoders to avoid potential fragmentation ofByteString. - Defining
confReadNTimeout(default toFalse). IfconfReadNimplements timeout by itself, set it toTrue. - TCP closing is now treaated as
ConnectionIsClosedinstead ofConnectionIsTimeout. - GOAWAY now contains a right last streamd ID.
5.3.10
- Introducing closure. #157
5.3.9
- Using
ThreadManageroftime-manager.
5.3.8
forkManagedTimeoutensures that only one asynchronous exception is thrown. Fixing the thread leak viaWeak ThreadIdandmodifyTVar'. #156
5.3.7
- Using
withHandleof time-manager. - Getting
Handlefor each thread. - Providing allocSimpleConfig’ to enable customizing WAI tiemout manager.
- Monitor option (-m) for h2c-client and h2c-server.
5.3.6
- Making
runIOfriendly with the new synchronism mechanism. #152 - Re-throwing asynchronous exceptions to prevent thread leak.
- Simplifying the synchronism mechanism between workers and the sender. #148
5.3.5
- Using
http-semanticsv0.3. - Deprecating
numberOfWorkers. - Removing
unliftio. - Avoid
undefinedin client. #146
5.3.4
- Support stream cancellation #142
5.3.3
- Enclosing IPv6 literal authority with square brackets. #143
5.3.2
- Avoid unnecessary empty data frames at end of stream #140
- Removing unnecessary API from ServerIO
5.3.1
5.3.0
- New server architecture: spawning worker on demand instead of the worker pool. This reduce huge numbers of threads for streaming into only 2. No API changes but workers do not terminate quicly. Rather workers collaborate with the sender after queuing a response and finish after all response data are sent.
- All threads are labeled with
labelThread. You can see them bylistThreadsif necessary.
5.2.6
- Recover rxflow on closing. #126
- Fixing ClientSpec for stream errors.
- Allowing negative window. (h2spec http2/6.9.2)
- Update for latest http-semantics #122
5.2.5
- Setting peer initial window size properly. #123
5.2.4
- Update for latest http-semantics #122
- Measuring performance concurrently for h2c-client
5.2.3
5.2.2
- Mark final chunk as final #116
5.2.1
- Using time-manager v0.1.0. #115
5.2.0
- Using http-semantics #114
Headerofhttp-typesshould be used as high-level header.TokenHeaderofhttp-semanticsshould be used as low-level header.- Breaking change:
encodeHeadertakesHeaderofhttp-types. - Breaking change:
decodeHeaderreturnsHeaderofhttp-types. - Breaking change:
HeaderNameasByteStringis removed.
5.1.4
- Using network-control v0.1.
5.1.3
- Defining SendRequest type synonym. #111
5.1.2
- Make ping rate limit configurable #108
5.1.1
- Deal with RST_STREAM in HalfClosedLocal state #107
5.1.0
- Drop frames after reset #106
- BREAKING CHANGE: Use String for Authority #105
- Properly close streams #104
5.0.1
- Allowing bytestring 0.12.
5.0.0
- Using the network-control package.
- The limits of resources can be specified in ServerConfig and ClientConfig.
- Open streams based on peer’s MaxStreams.
- Rejecting Data if it is over the receiving limit.
- Informing MaxStreams properly.
- Informing WindowUpdate properly.
- New API: Server.Internal.runIO and Client.Internal.runIO.
4.2.2
- Adding rate limit for RST_STREAM to work around CVE-2023-44487. #94
4.2.1
- This version is identical to v4.2.0 by accident.
4.2.0
- Treating HALF_CLOSED_LOCAL correctly. #90
- Ensuring that GOAWAY is sent after DATA in the client side. #89
- Test uses a random port instead of 8080.
- Breaking change: adding two optional
SockAddrs toConfigto be copied intoAux. - Close all streams on termination. #83
- Introducing
OutBodyStreamingUnmask#80 - Introducing
KilledByHttp2ThreadManagerinstead ofThreadKilled. #79 #81 #82 - Handle RST_STREAM with NO_ERROR. #78
- Internal changes: #74
- Breaking change:
Clientis generalized into(forall b. Request -> (Response -> IO b) -> IO b) -> IO a. TheRankNTypeslanguage extension is required. #72
4.1.3
- Using crypton instead of cryptonite.
4.1.2
- Removing the race of frameSender and frameReceiver in the server side. This fixes the loss of RST_Stream and TLS bad MAC error. #67
4.1.1
4.1.0
- Implementing streaming from the client side. #41
- Making use of SettingsMaxFrameSize #44 #57
- Disabling flow control #55
- Fixing buffer overrun by trailers #52
- Proper use of settings
- Breaking change: the data structure of
Nextwas changed. Thehttp3package is influenced.
4.0.0
- Breaking change:
HTTP2Erroris redefined. - Breaking change:
FrameTypeId,SettingsKeyIdandErrorCodeIdare removed. UseFrameType,SettingsKeyandErrorCodeinstead. - A client can receive a concrete
HTTP2Error. - Catching up RFC 9113. Host: and :authority cannot disagree.
- Breaking change:
Network.HTTP2andNetwork.HTTP2.Priorityare removed. - Breaking change: obsoleted stuff are removed.
3.0.3
- Return correct status messages in HTTP2 client #31
- Follow changes in Aeson 2 #32
- Make sure connection preface is always sent first #33
- Avoid empty data #34
3.0.2
- Skip inserting entries that do not fit in the encoding table #28
3.0.1
- Including a necessary file for testing.
3.0.0
- DOS preventions.
- Providing Network.HTTP.Client.
Internalmodules are exported.- Dropping the priority feature from Network.HTTP.Server.
Network.HTTP2.Priorityis deprecated.Network.HTTP2module is deprecated. UseNetwork.HTTP2.Frameinstead.- Adding some tokens.
2.0.6
- Dropping support of GHC 7.x
2.0.5
- Passing the correct request
2.0.4
- Freeing dynamic tables.
2.0.3
- Using shutdown instead of close in the example. This is important to send GOAWAY properly.
2.0.2
- Bug fix of flush limit.
2.0.1
- Bug fix for defaultReadN.
- Providing allocSimpleConfig and freeSimpleConfig.
- Deprecating makeSimpleConfig.
2.0.0
- Providing Network.HTTP.Server.
1.6.5
- Deny shrink of dynamic table to zero size #17
1.6.4
- checkFrameHeader for FrameHeaders. #15
1.6.3
- Fixing two bugs of HPACK pointed out by h2spec v2.
1.6.2
- Improving the performance of HPACK.
- Huffman encoding is now based on H2O’s one.
1.6.1
- Improving the performance of HPACK.
1.6.0
- Reverse indices of HPACK are now based on tokens.
- New APIs: encodeTokenHeader and decodeTokenHeader.
- Deleted API: encodeHeaderBuffer – use encodeTokenHeader instead.
- New module: Network.HPACK.Token
1.5.4
- Fixing a bug due to misuse of memcpy(). (#8)
1.5.3
- Adding debug information.
1.5.2
- Minor optimization for HPACK.
1.5.1
- Adding a missing file for testing.
1.5.0
- New API for HPACK. HPACK is much faster than 1.4.x (roughly x3.2). The default encoding is now Linear instead of LinearH.
1.4.5
- Removing zero reset from priority queues.
1.4.4
- Fixing a bug of reverse index.
1.4.3
- Priority benchmark is now external information versions.
- Using proper baseDeficit for deletion.
1.4.2
- Test files are now self-contained.
1.4.1
- The reverse indices for static and dynamic are combined for performance.
1.4.0
-
Providing dequeueSTM, isEmpty and isEmptySTM. Users can compose their own control queue with dequeueSTM and isEmptySTM.
-
Removing enqueueControl: it appeared that PriorityTree is not suitable for control frames. For example, the dependency of all control frames is stream 0. So, PSQ does not contain multiple control frames at the same time. We removed enqueueControl. Users should prepare a queue for control frames by themselves.
1.3.1
- Defining IllegalTableSizeUpdate.
1.3.0
- APIs
Network.HTTP2.Priorityare changed again.Precedenceis introduced.
1.2.0
- APIs of
Network.HTTP2.Priorityare changed.deleteis provided. Internal data structure is changed from random skew heap to priority search queue.