Skip to content

Repository files navigation

zig-libs

CI

A curated collection of foundational Zig modules — performance-minded, universal where possible, and built against something that already exists: a published specification, a set of released test vectors, or a proven implementation in another language, rather than invented from scratch. Which of those a module was built against is stated in its own README's Provenance: line, and they are not interchangeable — many modules here are clean-room from a spec and studied no third-party implementation at all.

Not a dumping ground: ship solid, not many. Every member is a foundational, cross-project-reusable capability — a production-grade implementation of a protocol/format/algorithm, or a fill for a genuine gap in the Zig ecosystem. zig-libs is the canonical home for these; the authors' other projects depend on it, not the reverse.

Status: 243 modules (Zig 0.16, tests green in ReleaseSafe and ReleaseFast) · MIT (see LICENSE). NOTICE answers one question — whether consuming zig-libs obliges you to anything beyond MIT — and lists the modules that carry their own attribution; it does not catalogue provenance.

⚠ Written by an AI agent. Read this before a sensitive deployment.

Every module here was implemented by an LLM agent working under human direction, then reviewed, tested and audited the same way. That is worth knowing because the failure mode differs from human code: it is fluent, it is consistent, and it is confident in exactly the places it is wrong. Several defects found here had passed a green suite for weeks — a guard compiled out in ReleaseFast, a test asserting the shape of the bug it was meant to catch, a public entry point no non-test consumer could compile.

What has been done about it, so you can judge rather than take a word for it: tests run in three release modes; mutation audits across the collection ask whether each test would actually go red; constant-time claims are machine-checked where a row in scripts/checks/ctgrind-expected.tsv says so; zig build check-fuzz requires a fuzz harness on every module that parses foreign bytes; zig build check-portable cross-compiles every module for each target it declares beyond 64-bit Linux (32-bit big-endian Linux, Windows, wasm32 — see "Portability" below), which no CI lane runs natively; and each module's SPEC.md carries an anchor grade saying where its expected values come from — EXTERNAL (published vectors, bytes captured from a foreign implementation, or a live foreign peer) down to SELF (we wrote them from our own reading of the spec).

What that still cannot tell you. A green gate means nothing contradicted the code, not that the code is right; a grade of EXTERNAL on one path says nothing about the others, which is what MIXED is for. Nothing here has been through third-party review or a security audit. If you are putting a module in front of untrusted input or in anything safety- or money-critical, read that module's SPEC.md first — start with its maturity card and anchor grade, its constant-time section and its "deliberately not done" list — and review the code yourself. The documentation is written to make that possible, including where it says the evidence is weak.

Using a module

Three ways to declare the dependency, and a fourth that overrides whichever you picked. The build.zig half is identical for all of them.

1. Local path — developing against an unpushed checkout. Relative, so the manifest carries no home-dir path:

// build.zig.zon
.zig_libs = .{ .path = "../zig-libs" },

2. Fetch, unpinned — zig fetch writes the entry for you, resolving the default branch to whatever it points at today:

zig fetch --save git+https://github.com/zaxified/zig-libs
// build.zig.zon — what --save leaves behind
.zig_libs = .{
    .url = "git+https://github.com/zaxified/zig-libs#<resolved-commit>",
    .hash = "zig_libs-0.0.0-<content-hash>",
},

3. Fetch, pinned to a release — what every consumer here uses. ?ref= records which tag was meant, the # fragment is the commit it stood for:

zig fetch --save "git+https://github.com/zaxified/zig-libs?ref=2026-08-15#84332afefbbc22f2e6254ee9412cd5e9f91f27fd"
// build.zig.zon
.zig_libs = .{
    .url = "git+https://github.com/zaxified/zig-libs?ref=2026-08-15#84332afefbbc22f2e6254ee9412cd5e9f91f27fd",
    .hash = "zig_libs-0.0.0-WiQ0Gkuq3gJ9oVeW_X5KH_WCwedy4T3uXFl5-DAcgr3J",
},

Pin a tag or commit, never a branch.

⚠ ?ref= is an annotation, not a pin. Zig's fetcher ignores the query string entirely and reads only the # fragment. Measured 2026-09-17 against this repo: ?ref=2026-09-02, ?ref=no-such-ref-xyz, and no ref at all all resolve to the same thing — the tip of the default branch — and none of them errors. Only #2026-09-02 resolves to the tag, and a fragment naming nothing (#no-such-ref-xyz) fails loudly with ref not found. The tag name in the query is there for the next human to read; drop the fragment while keeping it and you get an untagged commit that looks pinned. (?ref= is a Nix flake convention. It is easy to reach for, and it fails silently here.)

Two things are enforced mechanically, and neither is the one that sounds most reassuring:

  • The url must carry a fragment — ?ref=2026-09-02 with no # is rejected (url field is missing an explicit ref). But ?ref=main is rejected for exactly the same reason: the check asks whether a fragment exists, not whether the ref names a tag. A branch in the fragment (#main) is accepted without complaint.
  • A url naming a commit must carry a hash (dependency is missing hash field).

So the hash is what actually holds the pin. It is content-addressed, which means a ref that moves under you fails the build rather than silently changing it — that, not the ref syntax, is why there is no floating "latest" to opt into. Upstream movement can only arrive as a deliberate re-run of the command above, which is what makes a bump reviewable. CHANGELOG.md says what each release changed.

4. --fork, on top of any of the above — build against a live checkout without touching the manifest. Useful when you are changing a module and its consumer together, and the honest alternative to editing a pinned entry down to a .path and remembering to put it back:

zig build --fork=../zig-libs
→ info: fork ../zig-libs matched 1 zig_libs packages

It overrides every package matching that project across the whole dependency tree, so a module reached only transitively is covered too. The manifest stays pinned and reproducible; the override lives in the command that asked for it.

Then, in build.zig, whichever declaration you chose:

const libs = b.dependency("zig_libs", .{ .target = target, .optimize = optimize });
exe.root_module.addImport("http", libs.module("http"));
exe.root_module.addImport("jwt", libs.module("jwt"));

Two things that bite if skipped:

  • Pass .target and .optimize through. The modules are declared with this build's own standardTargetOptions/standardOptimizeOption, so an empty .{} resolves them against this package's defaults instead of yours.
  • Resolve the dependency once and hand the same module object to everyone who needs it. Two dependency() graphs make one module's types two incompatible types — and this bites transitively: a module that imports a sibling (tz imports datefmt) resolves that sibling within its own graph, so a consumer wanting both must take both from the one handle or end up with two date cores.

zig fetch can't target a subdirectory (ziglang/zig#23012), so the whole collection is one package however you declare it. You still import only the modules you name; the rest are never compiled.

Build

scripts/test.sh          # the gate — every module not yet proven at its current content
scripts/test.sh all      # every check and every module, ignoring what is proven
zig build test           # run all module tests
zig build test-<name>    # run one module's tests
zig build check-catalog  # verify build.zig's module_list ↔ modules/ ↔ this README agree
zig build check-changelog # verify every module has a dated, well-formed CHANGELOG.md
zig build check-portable  # verify every meta.targets claim against scripts/checks/portable-known-failures.tsv
zig build check-portable-table # verify the README "Portability" table matches meta.targets + the baseline
zig build gen-portable-table   # regenerate that table (run after changing a module's meta.targets)

scripts/test.sh is the entry point for contributors: scripts/test.sh changed runs each module that has no green stamp at its current fingerprint (its own sources, its dependencies, the build machinery) together with the check-* gates the change can affect, and a change to the harness itself adds every check plus a smoke run. See scripts/README.md, "Which modules run: stamps". Reach for zig build test when you actually want everything regardless of what changed.

zig build -l lists the rest, including the other check-* gates.

Versioning & stability

Releases are dated git tags (YYYY-MM-DD), not semantic versions, and there are no per-module versions; a tag asserts exactly one thing, that every module cleared every lane at that commit. scripts/tag.sh cuts one, on the owner's word and over a green full matrix, and every tag gets a GitHub Release. v0.1.0 remains as history and is not a version anything after it follows; dated releases exist, so pin the newest one that suits you (git tag, or the tags page) rather than a bare commit. Detail lives in modules/<name>/CHANGELOG.md with breaking changes flagged BREAKING; zig build check-changelog enforces that every module has one and that it is dated and well-formed. The root CHANGELOG.md carries the release policy and per-release notes — it stopped indexing which modules have a changelog on 2026-08-14, since all of them do and the index was a copy kept only so a gate could notice the copy had gone stale. Module maturity is carried by the grade in the catalog below (see Module grades), computed from each module's ## Maturity card, and by the explicit caveat lines beside it — every module meets the same floor (tests green in both test lanes — ReleaseSafe and ReleaseFast; plus oracle/KAT verification where one exists); what varies above it is scope, evidence and audit, and the card says which. The full versioning + spin-off policy is CONVENTIONS.md §8.

Layout & conventions

build.zig      # single root build — registers every module by name + a test step each
build.zig.zon  # one package manifest for the whole collection
CHANGELOG.md   # per-release changes, grouped by module
CONVENTIONS.md # naming + `meta` tag vocabulary + provenance/SPDX + versioning rules
SURVEY-PLAYBOOK.md # how a module is surveyed against other implementations before it ships an example
modules/<name>/src/root.zig  # `// SPDX-License-Identifier: MIT`, `pub const meta`, API, tests
modules/<name>/README.md     # what it is + a Provenance line
modules/<name>/SPEC.md       # wire format, limits, anchoring, what is deliberately not done
modules/<name>/CHANGELOG.md  # dated entries, breaking changes flagged
modules/<name>/NOTICE        # only when something is attributed or a provenance argument is needed

CONVENTIONS.md has the full rules; modules/_template/ is the starting point for a new module. What a module still owes is in its own SPEC.md, under "What is deliberately not done".

Licensing

zig-libs is MIT. Using or redistributing it requires nothing beyond the MIT license's own terms.

Detailed provenance — third-party origin, design references and any upstream license notices — is recorded with each module that has any, not at the repository root.

Modules

Module grades

Every catalog row carries a grade on the school scale, 1 (best) to 5 (fix now), so you can tell at a glance whether a module is ready for production or still being filled in:

Grade Means
1 Production quality, comparable with the reference implementation: nothing a user would notice is missing, the tests are anchored to an outside truth, and it has been both audited in-house and mutation-checked (no module has had a third-party review — see the warning above).
2 Usable in production; the known gaps are listed in its SPEC.md.
3 Works on the main path; gaps a user will hit, or weaker evidence, or no audit recorded.
4 A proof of concept, or tests checked only against our own reading of the spec. Not for production.
5 A known open defect. Do not rely on it until it is fixed.
? Provisional: nobody has yet surveyed this module against other implementations, so the number is an upper bound — the survey can lower it, never raise it.

The grade is not chosen, it is computed: the worst of four axes recorded in the ## Maturity card at the top of each module's SPEC.md — scope against other implementations, evidence (the anchor grade), audit, and known defects — and the card names the axis that caps it. The rule is maturityGrade in build.zig; zig build gen-catalog writes the card's Grade line and this column from the same computation, and zig build check-catalog-table fails when either is stale. zig build maturity-report lists every module worst first.

Libraries

zig-libs is a plural: a lib is one of the six groupings below, and every module is filed in exactly one of them — the section its catalog row is printed under. A module may additionally be tagged into libraries it is worth reaching for from, which is what the last column lists: if you are building on net, those crypto and format modules are yours too without going looking.

Library Filed here Also worth reaching for from here (own library in brackets)
web 35 netaddr (net) · zstd (format) · entropy (crypto) · rsa (crypto) · protobuf (format) · p256 (crypto)
net 75 http (web) · ramcache (storage) · resilience (web) · kvtree (storage) · rsa (crypto) · xml (web) · x509 (crypto) · tlsclient (crypto) · sphinx (crypto) · aesgcm (crypto)
storage 15 zstd (format) · crc32 (format) · crc32c (format) · hashdigest (crypto)
crypto 81 http (web) · aescbc (web)
format 24 http (web) · decimal (storage)
os 13 framing (format)

Every module is imported by its name (@import("http")); hyphenated names work too (@import("security-headers")). Deps are sibling modules; everything else is std-only.

Portability — claimed vs. verified

Every one of the 243 modules above claims .linux64 (Linux, amd64 or arm64) — the collection's mandatory baseline (CONVENTIONS.md §4), and the one target actually run, not merely compiled: the CI matrix executes every module's tests in ReleaseSafe and ReleaseFast, plus a separate arm64 lane. That claim is not repeated below for all 243 modules — a linux64-only module has nothing further to show here.

39 of them additionally claim a cross-compile target in meta.targets (CONVENTIONS.md §4). zig build check-portable compiles (never runs — none of these targets has a host to run on here) each declared pair TWICE — the test binary, and a second root that takes a reference to every non-generic public declaration, because Zig analyses a body only when something references it and a pub fn no test reaches would otherwise never meet this target at all — and checks the result against scripts/checks/portable-known-failures.tsv: of 41 declared pairs, 40 currently compile clean and 1 are known-failing, tracked there with the real compiler error rather than silently dropped.

A blank cell means the module never claimed that target. That is a different fact from a known-failing cell next to it — one is an absent claim, the other is a claim currently broken and tracked — and this table exists so the two are never shown as the same thing.

A row states that the module's tests and its whole public surface compile for that target. It does not state that a binary containing the module links for it. Link-time reach limits are a property of the consuming binary's total text size, not of any single module: on 32-bit MIPS a branch's PC16 fixup reaches ±128 KB, and a large enough consumer overruns it no matter which modules it picked. What that looks like, and what to do about it, is under Consumer gotchas below.

Module linux32 windows wasm32
blobmsg compiles — —
conntrack compiles — —
csvstream — compiles —
datefmt — compiles —
decimal — compiles —
diagnostics — compiles —
diskfree compiles — —
diskusage compiles — —
dns compiles — —
encoding — compiles —
framing compiles — —
hashdigest compiles — —
icmp compiles — —
json5 — compiles —
l2disco compiles — —
mcp — compiles —
minisign — compiles —
mqtt compiles — —
netlink compiles — —
nl80211 compiles — —
numparse — compiles —
pathmtu compiles — —
probe compiles — —
procnet compiles — —
procrun — compiles —
qr — — compiles
qrscan — — compiles
rawsock compiles — —
reconcilable — compiles compiles
sealedbox compiles — —
sntp compiles — —
stun compiles — —
tar compiles — —
traceroute compiles — —
tz — compiles —
uci compiles — —
wireguard known-failing — —
zipstream — compiles —
zstd compiles compiles —

Consumer gotchas

Failures that are not a defect in any module, and whose error message does not say so.

out of range PC16 fixup when cross-building for 32-bit MIPS. Seen on mips-linux-musl with -Dcpu=mips32,soft_float in ReleaseSmall: a large function that inlines many call-site bodies grows past the ±128 KB reach of a MIPS PC16 branch fixup, and the link fails. The message names no symbol, no module and no file, so the natural first suspect is whichever module was added last — but the threshold belongs to the binary's total text size, and adding any code can cross it. The fix is on the consumer side: mark the inlined leaf bodies noinline, at the cost of one call each. Neither mips32r2 nor ReleaseSafe reproduces it, so comparing against either one is the quickest way to recognise it.

Web / HTTP & API — an internet-facing service, no reverse proxy required

Module Grade What it does Platform Deps
aaa-gate 2 Bearer + API-key auth (constant-time) + audit hook + denied-request throttle any router, http
abuseguard 3 Per-IP + global connection caps, ban/greylist, strike→ban (accept-time) posix http, netaddr, router
accesslog 2 Structured HTTP access-log formatter — JSON Lines/logfmt/Apache Combined with log-injection escaping (untrusted UA/path/referer can't forge a line); http-request→Entry bridge any http
acme 2 Let's Encrypt / ACME v2 (RFC 8555) — HTTP-01, TLS-ALPN-01 and DNS-01 (wildcard) issuance + renewal, ES256 JWS, CSR any http, router, entropy
aescbc 2 Raw AES-CBC (NIST SP800-38A) + PKCS#7/XML-Enc padding helpers, zero-alloc; padding-oracle caveat — consumers own authenticate-before-unpad any —
aeskw 2 RFC 3394 AES Key Wrap (AES-128/256 KEK) — constant-time integrity check + scratch zeroization, byte-exact vs RFC 3394 test vectors any —
brotli 2 Pure-Zig Brotli (RFC 7932) — byte-exact decompressor + a compressing encoder (LZ77 + Huffman, ~2.8x on text); the Content-Encoding: br companion to std gzip any —
cors 2 CORS preflight + header injection (secure defaults) any router, http
grpc 3 gRPC client and server over HTTP/2 (over protobuf) — no code generation; all four call shapes (unary/streaming/bidi); untrusted declared length never sizes an allocation any http, protobuf
health 2 Liveness (/healthz) + readiness (/readyz) probe middleware — 200/503 from registered dependency checks (k8s probe contract) any router, http
http 2 HTTP/1.1 client and server, hardened for direct exposure (slowloris caps, gzip, multipart, Range, negotiation); also speaks HTTP/2 (h2c/h2 client+server). Not std.http. any netaddr, datefmt, tlsclient, crc32
idempotency 2 Idempotency-Key dedup of unsafe retries — middleware + ramcache-backed store replaying a cached response without re-running the handler any router, http, ramcache
jwe 2 JSON Web Encryption (RFC 7516/7518) compact serialization — RSA-OAEP/AxxxKW/ECDH-ES key management + AES-GCM/CBC-HMAC content encryption; A192* unsupported (no AES-192 in std) any rsa, p256, aescbc, aeskw
jwt 2 JWT/JWS + OIDC resource-server validator — parse/claims/verify (HS/ES/EdDSA/RSA and post-quantum ML-DSA per RFC 9964, alg-confusion-safe), JWKS-by-kid incl. kty:AKP, OIDC discovery, plus a router Bearer middleware any http, router, p256
llmclient 3 Anthropic Messages API client (buffered + streaming SSE) over http — no third-party SDK any http
metrics 2 Prometheus registry (counter/gauge/histogram) + /metrics + request middleware + access-log writer (combined/JSON) posix router, http
openapi 2 OpenAPI 3.1 spec generated from the route table + /openapi.json any router, http
ratelimit 2 Token-bucket per-client rate limit → 429 + Retry-After; per-user connection-rate limit for on_connect any router, http, netaddr
rbac 2 Authorization decision engine — NIST RBAC (hierarchical + static SoD) and a depth-bounded ABAC condition-tree evaluator with structural default-deny any —
requestid 2 Request/correlation-ID middleware — adopts incoming X-Request-Id or generates one, echoes on response, exposed via current() any router, http
resilience 2 Circuit breaker + retry/backoff + timeout + bulkhead (concurrency limiter) for calling upstreams (generic) posix —
router 2 REST routing — trie matcher (params/wildcards), middleware chain, groups, 404/405 any http
saml 3 SAML 2.0 SSO service-provider — XSW-hardened Response verification against an IdP key, AuthnRequest builder, IdP-metadata parser; decrypts EncryptedAssertion via xmlenc any xmldsig, xml, xmlenc, rsa, x509, datefmt
security-headers 2 Secure-by-default response headers (HSTS/CSP/nosniff/frame/referrer/COOP/CORP) any router, http
sessions 2 Server-side web sessions + OWASP-hardened cookies + signed double-submit CSRF middleware any router, http, cookies, ramcache, entropy, kv
staticfiles 2 Path-traversal-safe static file handler over http — MIME by extension, ETag/conditional 304, byte-range 206/416; symlinks not followed, dotfiles refused by default any http
throttle 2 Global concurrency limit + load-shedding → 503 posix router, http
tracecontext 2 W3C Trace Context — traceparent/tracestate parse + generate + propagation middleware (child span per hop) for distributed tracing any router, http
upstream 3 Load-balanced upstream pool + failover — round-robin/weighted/least-conn/EWMA, per-upstream breaker+bulkhead, active+passive health checks any resilience, probe
validate 2 Request body/query/params validation → aggregated 400 (typed + schema + string-format checks) + JSON DoS caps (depth/array/field size) any router, http, netaddr
webhooksig 3 HMAC webhook signatures (GitHub-style sha256=<hex>) — sign/verify (constant-time) + gating middleware, key rotation. Stripe's scheme not implemented any router, http
websocket 2 RFC 6455 WebSocket — handshake + frame layer (masking, fragmentation, UTF-8 validation, size caps), transport-agnostic client + server; no permessage-deflate any http
xml 3 Namespace-aware, security-hardened XML 1.0 parser → C14N-ready infoset tree; DOCTYPE-reject default blocks XXE/billion-laughs/depth-bomb. Foundation for xmldsig/saml any —
xmldsig 2 XML Canonicalization (C14N) + XML-Signature verification only — RSA/ECDSA, algorithm allow-list (XSLT/XPath rejected); KeyInfo cert is untrusted, caller must pin trust any xml, rsa, p256
xmlenc 2 XML-Encryption (xmlenc-core-1) decryption only — recovers EncryptedAssertion plaintext (RSA-OAEP/AES-KW key transport + AES-GCM/CBC content), decrypt-then-verify any xml, rsa, aescbc, aeskw

Also worth reaching for from web — these are filed under another library (in brackets), and appear here because a consumer working in web has a use for them:

Module Grade What it does Platform Deps
entropy (crypto) 1 Fail-closed entropy source — fill draws from std.Io.randomSecure or aborts the process; no generator, no silent degrade. Panics on failure. any —
netaddr (net) 2 IP parse/format (RFC 5952) + RFC 6724 source/dest selection + CIDR/Prefix ops (contains/overlaps/supernet, range↔prefix) any —
p256 (crypto) 2 asm-accelerated NIST P-256 — Solinas field, constant-time comb sign, vartime wNAF verify; bit-exact vs std.crypto.ecc.P256 and RFC 6979. amd64 asm + portable fallback —
protobuf (format) 3 Protocol Buffers wire format (proto3) codec — schema derived at comptime from Zig structs, no .proto compiler; untrusted-input hardened. any —
rsa (crypto) 2 Pure-Zig RSA (PKCS#1 v2.2, RFC 8017) — keygen, PKCS1-v1.5/PSS sign+verify, OAEP/PKCS1 encrypt+decrypt, DER/PEM/OpenSSH key parsing. any montint
zstd (format) 1 Zstandard (RFC 8878) compressor, levels 1-22 and negative levels — byte-identical to libzstd 1.5.7 ZSTD_compress2 and ZSTD_compressStream2, with libzstd's advanced parameters (magicless frames, explicit window/strategy, splitters, block size, long-distance matching as --long, targetCBlockSize superblocks), the sequence-level API (compressSequences, generateSequences, a block-level sequence producer) and reusable contexts in one workspace of exactly estimated size, caller-provided if wanted — and a decoder ported from libzstd's, one-shot and streaming (ZSTD_decompressStream, a std.Io.Reader), checksums, concatenated and skippable frames, frame queries any —

Networking

Module Grade What it does Platform Deps
bacnet 3 BACnet building automation over BACnet/IP and BACnet/SC — BVLL/BVLC framing, core APDU services (Read/WriteProperty, WhoIs/IAm, COV), SC secure-connect over websocket any netaddr, websocket
bumtree 3 SPB per-source loop-free BUM distribution tree + RPF check over spf-ect — per-node replication next-hops (pruned source SPT) + single RPF ingress for an I-SID member set any spf-ect
coap 3 CoAP (RFC 7252) — full client and server stack: message codec, options (URI↔options), reliability (CON retransmission + dedup), correlated client/server. Zero-alloc any —
conntrack 2 Linux ctnetlink (NETLINK_NETFILTER) client — typed conntrack flow dump/get/delete plus event subscription, over netlink's write engine linux netlink, netaddr
devlink 3 Linux devlink over genetlink — device/port enumeration, port split/unsplit, parameter/resource inspection, region snapshots, health reporters, eswitch mode linux genetlink, netlink
df-elect 3 EVPN-style Designated-Forwarder election for N-member segments (RFC 7432 mod-N, RFC 8584 HRW) with DF-wait failover + split-horizon, from a link-state flood; model-checked in netsim any netsim
dnp3 3 DNP3 (IEEE 1815) base protocol — data-link framing + CRC-16/DNP, application layer, core object library; master + outstation. Secure Auth (g120) scaffolded only, no crypto any aeskw
dns 2 RFC 1035 resolver — A/AAAA/PTR/CNAME/NS/MX/TXT/SOA/SRV/CAA over UDP/TCP + DoH any netaddr, http
dnssec 2 Resolver-side DNSSEC validation (RFC 4033/4034/4035 + NSEC3) — DNSKEY/RRSIG/DS parsing, signature verify (ECDSA/Ed25519/RSA), NSEC/NSEC3 denial-of-existence any dns, rsa
ebpf 3 eBPF program generation over std.os.linux.bpf — bytecode builders (kprobe counter, XDP filter, ring-buffer emitter); real-kernel verifier acceptance unverified in CI linux netlink
enip 3 EtherNet/IP + CIP — encapsulation layer (register/SendRRData/SendUnitData), CIP messaging, connection manager, tag/symbolic path client for Logix controllers any netaddr
ethfrag 2 Hardened inner-frame fragmentation/reassembly codec — RFC 5722 overlap rejection, bounded per-datagram memory, caller-clocked timeout, fuzz-tested never-panic any —
ethtool 2 Ethernet device control over the ethtool netlink family — link settings/state, ring/coalesce/pause/channel params, feature flags, per-queue/driver stats linux genetlink, netlink
fleetsim 2 In-process simulated device fleet — hosts protocol responders (Modbus, DNP3, IEC 104, S7comm, BACnet, EtherNet/IP, OPC UA) as nodes on one deterministic scheduler any modbus, dnp3, iec104, s7comm, bacnet, enip, opcua, netsim
genetlink 2 Generic-netlink (genl) transport — genlmsghdr framing + nlctrl family-id resolution; shared foundation for ethtool/devlink/nl80211/wireguard clients linux netlink
icmp 2 ICMP echo (ping) engine — v4/v6 codec, batched socket, pacing linux seqmap, netaddr
iec104 2 IEC 60870-5-104 telecontrol — APCI/APDU framing, I/S/U formats with k/w flow control, ASDU codec, transport-agnostic master (controlling station) any —
iec61850 2 IEC 61850 substation automation — MMS (ISO 9506) client over ISO-on-TCP with the ACSI object model, plus GOOSE publish/subscribe + SV sampled values any xml
iec62351 2 IEC 62351 power-systems security — GOOSE/SV authentication (62351-6) over caller-supplied PDU bytes, MMS application authentication (62351-4), checkable TLS policy any x509, rsa
imap 3 IMAP4rev2 (RFC 9051) client — mailbox-name codec, wire grammar, FETCH/ENVELOPE/BODYSTRUCTURE, SEARCH, IDLE; transport-agnostic (owns no socket, speaks no TLS) any —
isis 3 IS-IS (ISO/IEC 10589) PDU codec — common header + TLV framework + IIH/LSP PDUs + SPB (802.1aq) TLVs; pure bounds-checked encode/decode, wire foundation for an SPB control plane any —
isis-adj 3 IS-IS point-to-point adjacency state machine (ISO 10589 §8.2 + RFC 5303) — pure time-injected FSM driving one P2P neighbour Down→Init→Up from IIH PDUs any isis
isis-dis 2 IS-IS LAN Designated-IS election (ISO 10589 §8.4.5) — elects DIS from priority + SNPA (tie-break, preemptive), derives the pseudonode LSP-ID; pure time-injected any isis
isis-flood 3 IS-IS flooding transmit scheduler — drains isis-lsdb SRM/SSN flags into ordered PDUs to send, paces LSP (re)transmission + periodic CSNPs; pure time-injected any isis, isis-lsdb
isis-lsdb 3 IS-IS link-state database — stores LSPs by LSP-ID, ISO 10589 §7.3 newer-LSP comparison, time-injected aging + MaxAge purge, per-interface SRM/SSN flooding flags; pure any isis
isis-sim 3 Headless multi-node IS-IS/SPB fabric convergence simulator over netsim — asserts LSDBs synchronise and reconverge after an injected link failure any netsim, isis, isis-lsdb, isis-flood, isis-spf, isis-dis
isis-spf 3 Computes IS-IS shortest-path forwarding table from an isis-lsdb — TLVs → topology graph → Dijkstra + ECT tie-break → route table (dest → next-hop + metric); pure any isis, isis-lsdb, spf-ect
l2disco 3 Layer-2/neighbor discovery codec — LLDP (802.1AB) + CDP + ARP (RFC 826) + DHCP options (RFC 2131/2132) + MAC helper any netaddr
l2encap 2 Tenant-tagged (24-bit I-SID) L2-over-tunnel encapsulation for a multi-tenant L2VPN fabric — lean versioned header over a customer Ethernet frame; bounds-checked decode any —
l2forward 3 E-LAN edge forwarding table — per-I-SID customer-MAC learning (MAC→remote PE) with aging + BUM ingress-replication set + split-horizon; pairs with l2encap any —
latency-stats 2 Online RTT stats — min/max/mean/stddev + RFC 3550 jitter + loss %, O(1)/sample, no alloc; plus an HdrHistogram for bounded-error percentiles (p50–p99.9) any —
liveness-hyst 3 BFD-like link-liveness estimator with EWMA hysteresis — echo-probe timing + jitter/loss stats, Babel-style metric smoothing; fast detection without flap-driven oscillation any netsim, latency-stats
lockfree 3 Lock-free concurrency primitives for shared-memory worker pools — Michael & Scott MPMC queue + Fraser/crossbeam epoch-based reclamation, under a strict seq_cst discipline any —
loopfree-reconv 3 Loop-free reconvergence transitions — two-class ordered-FIB schedule (provably no transient forwarding loop, TTL backstop); netsim-verified under fuzzing any netsim, spf-ect
loopix 4 Loopix mixnet (Piotrowska et al. — Nym's design) — Poisson mix + cover traffic over sphinx, model-checked in netsim against a global-passive-adversary anonymity invariant any netsim, sphinx
modbus 2 Modbus TCP (MBAP) + RTU (CRC-16) codec, master client and slave server — core function codes, diagnostics, exceptions, transport-agnostic seam any —
mqtt 2 MQTT 3.1.1 + 5.0 client and broker — all control packets incl. AUTH and properties, QoS 0/1/2 both ways, sessions with expiry, shared subscriptions, transport-agnostic seam any —
netaddr 2 IP parse/format (RFC 5952) + RFC 6724 source/dest selection + CIDR/Prefix ops (contains/overlaps/supernet, range↔prefix) any —
netconf 2 NETCONF client (RFC 6241) over SSH — RFC 6242 framing, hello/capability exchange, get/get-config/edit-config/commit RPCs with typed replies any ssh, xml
netlink 3 rtnetlink read and write — dumps (links/addresses/routes/neighbors) and RTM_NEW*/DEL* writes; byte-exact vs iproute2 goldens + netns round-trip linux —
netsim 3 Deterministic seeded discrete-event network simulator (latency/loss/partition/clock-skew, failure fuzzer, byte-exact replay) — model-checking harness for fabric algorithms any —
nftables 3 Typed firewall-ruleset builder → libnftables JSON for nft -j -f - (families/chains/rules/sets, match + verdict statements) any (apply: linux) netlink
nl80211 3 Wi-Fi control over nl80211 genetlink — interface/wiphy enumeration, scan trigger + BSS results, connect/disconnect, station/link stats, regulatory domain linux genetlink, netlink
opcua 3 OPC-UA (IEC 62541) client and server — opc.tcp transport, secure channel (#None or Basic256Sha256 at Sign/SignAndEncrypt, both client and server), sessions, Read/Write/Browse/Call + subscriptions any rsa, x509
pagecache 2 Bounded write-through page cache between kvtree's pager and its Storage — hot-cold tiering (W-TinyLFU via ramcache) with an RSS budget; transparent to callers any kvtree, ramcache
pathmtu 2 Path MTU discovery — kernel-cache read (query) and an authoritative DF-bit binary search (probe) that detects ICMP black holes the cache can't see linux icmp, netaddr
pbb 2 IEEE 802.1ah Provider Backbone Bridge (MAC-in-MAC) codec — wraps a customer frame in a backbone header + I-TAG (24-bit I-SID); real-Ethernet SPB encap, distinct from l2encap any —
pping 3 Passive RTT estimation from TCP TSval/TSecr echo matching (RFC 7323 / Pollere pping) — bounded per-direction table, no double-counting of duplicate/delayed ACKs any —
probe 2 TCP-connect reachability prober — up/refused/timeout + RTT, fan-out with bounded concurrency, latency aggregation any netaddr, latency-stats
procnet 3 Linux /proc+/sys parsers — ARP/routes/TCP+UDP sockets/conntrack/process stats/device health, typed linux netaddr
raft 4 Raft consensus (Ongaro & Ousterhout) — leader election + log replication, model-checked in netsim against all five formal safety properties; membership changes are design-only any netsim
rawsock 3 Linux AF_PACKET raw-frame capture + inject — BPF filter, promiscuous mode, typed frame decode linux netaddr
rdap 2 RDAP client (RFC 7480–7484) — JSON-over-HTTPS whois successor: query URLs, typed response model, IANA bootstrap, fetch seam any http, netaddr
readthrough 2 Backend-agnostic read-through cache coordinator — serve-from-cache or single-flight-coalesce a miss into one backend fetch, TTL + invalidation + negative caching any ramcache
reconcilable 2 Generic desired-vs-actual reconciler (controller-runtime shape) — bounded, deduplicating work queue with backoff+jitter; caller-driven tick(), no clock or thread any resilience
s7comm 3 Siemens S7 communication — ISO-on-TCP (RFC 1006) plus S7 protocol: connection setup, area read/write (DB/M/I/Q/T/C), PLC info and cyclic services any —
seqmap 2 Fixed 65,536-slot 16-bit request/reply correlation map, O(1) any —
shardstore 3 Key-sharding router over N independent kvtree stores — multi-core write parallelism (per-shard single-writer, cross-shard parallel) any kvtree
simio 4 Deterministic std.Io for simulation testing — real std.Io code runs unchanged on fibers in virtual time, over simulated streams, datagrams and ICMP on routed faulty links, a crash-consistent disk, host crashes and a shrinking fault search linux (x86_64, aarch64, riscv64: std.Io.fiber) netsim
smtp 2 SMTP client (RFC 5321) — ESMTP EHLO negotiation, STARTTLS seam, AUTH PLAIN/LOGIN, pipelining, MIME message composition (RFC 5322/2045) any netaddr
snmp 2 SNMP v1/v2c/v3 — BER/ASN.1 codec, manager client (get/next/bulk/set/walk) + trap/notification receiver + USM auth (HMAC-MD5/SHA-1 and RFC 7860 SHA-224/256/384/512, constant-time) and privacy (DES-CBC, AES-128-CFB), KAT- and net-snmp-anchored any —
sntp 2 SNTP client (RFC 4330) — NTP packet codec + UDP query, clock offset / round-trip delay any —
spbfib 3 SPB (802.1aq) forwarding addressing — unicast B-MAC FIB from an isis-spf route table + SPBM multicast-DA construction; one congruent ECT path per dest, no per-flow ECMP any isis-spf
spf-ect 3 Deterministic symmetric shortest-path (Dijkstra) with a reversal-invariant ECT tie-break (RFC 6329 idea generalized) + maximally-disjoint second tree; pure graph algorithm any —
ssh 3 SSH-2.0 (RFC 4253) client + server — KEX incl. ML-KEM-768 hybrid, userauth (publickey/password) + channels (exec/subsystem); vs OpenSSH-validated. Linux-only linux rsa
stun 3 STUN client (RFC 8489) — NAT reflexive-address discovery: XOR-MAPPED-ADDRESS + MESSAGE-INTEGRITY + FINGERPRINT any netaddr
syslog 2 RFC 5424 syslog formatter + emitter, RFC 3164 legacy encoder, RFC 6587 TCP octet framing, local delivery (unix socket, journald native protocol) any (local delivery: linux) datefmt
tc 3 Traffic control over rtnetlink — qdiscs (netem/htb/tbf/fq_codel/cake), htb classes, u32/flower filters + action families; byte-exact to iproute2 (retires tc shell-outs) linux netlink
tcplan 3 Compiles a hierarchical shaping topology (site→AP→subscriber) into a deterministic ordered plan of tc ops — mq root + per-CPU HTB trees + CAKE leaves; pure, caller executes linux tc
traceroute 3 ICMP-echo path discovery — TTL-stepped probes, per-hop address + RTT stats, load-balanced-path aware linux icmp, netaddr, latency-stats
whois 2 RFC 3912 whois client — query format + referral chasing (IANA→registrar) + field extraction, transport-agnostic seam any netaddr
wireguard 2 Native WireGuard device config over genetlink (retires wg shell-outs), plus the Noise_IKpsk2 handshake and the transport-data seal/open crypto data plane linux netlink, genetlink, chachapoly, entropy, netaddr
workerpool 2 In-process fixed-width worker pool over lockfree.MpmcQueue — type-erased closure jobs, Io-futex idle wakeup (no busy-spin, no lost-wakeup), graceful drain / abrupt shutdown any lockfree
writebehind 3 Crash-safe write-behind cache coordinator — fast in-memory acks, async flush to a durable Sink via workerpool; WAL written before ack so a crash-recovered write survives any ramcache, workerpool, jobqueue, kvtree
xdp-classifier 3 XDP packet classifier for a LibreQoS-style edge shaper — IPv4 prefix→traffic-class via LPM-trie lookup, per-CPU scratch handoff, CPUMAP steering (bpf_redirect_map) linux ebpf

Also worth reaching for from net — these are filed under another library (in brackets), and appear here because a consumer working in net has a use for them:

Module Grade What it does Platform Deps
aesgcm (crypto) 2 AES-GCM (AES-128/256) — stateful context caching the key schedule and GHASH powers, x86-64 AES-NI+PCLMULQDQ stitched one-pass kernel picked at run time, std fallback; std-shaped stateless API. any (x86-64 AES-NI/PCLMULQDQ asm, run-time detected + std fallback) —
http (web) 2 HTTP/1.1 client and server, hardened for direct exposure (slowloris caps, gzip, multipart, Range, negotiation); also speaks HTTP/2 (h2c/h2 client+server). Not std.http. any netaddr, datefmt, tlsclient, crc32
kvtree (storage) 2 Ordered transactional KV store — copy-on-write B-tree (LMDB/BoltDB lineage), MVCC snapshots, crash-safe range scans. any kv, crc32
ramcache (storage) 2 Bounded in-memory cache — W-TinyLFU admission/eviction, TTL, generation invalidation; sharded thread-safe wrapper. any —
resilience (web) 2 Circuit breaker + retry/backoff + timeout + bulkhead (concurrency limiter) for calling upstreams (generic) posix —
rsa (crypto) 2 Pure-Zig RSA (PKCS#1 v2.2, RFC 8017) — keygen, PKCS1-v1.5/PSS sign+verify, OAEP/PKCS1 encrypt+decrypt, DER/PEM/OpenSSH key parsing. any montint
sphinx (crypto) 3 Lightning BOLT#4 Sphinx onion routing — forward ECDH blinding chain, layered packet construction, constant-time layer peeling. any k256
tlsclient (crypto) 3 std's TLS 1.3/1.2 client with the server chain verified by RFC 5280 (x509.verifyChain) — closes ziglang/zig #35877 (no basicConstraints check). any x509
x509 (crypto) 2 X.509 certificate-chain / path validation (RFC 5280 §6) — trust-store chain building, extension, name, and signature checks, including post-quantum ML-DSA (RFC 9881) and SLH-DSA (RFC 9882) certificates, plus CRL revocation checking (RFC 5280 §6.3). any rsa, slhdsa
xml (web) 3 Namespace-aware, security-hardened XML 1.0 parser → C14N-ready infoset tree; DOCTYPE-reject default blocks XXE/billion-laughs/depth-bomb. Foundation for xmldsig/saml any —

Data & storage

Module Grade What it does Platform Deps
blobstore 2 Content-addressed blob store (git-object/restic style) with refcounted GC, configurable fan-out and a cross-process ingest lock, plus name-addressed and small named-record layers; crash-safe. posix hashdigest
dataset 3 Canonical in-memory columnar-typed table — the normalization seam between data sources and consumers. any —
decimal 2 Exact i128 fixed-point decimal for money math with IEEE/GDA rounding modes and rescale — float-free arithmetic, f64 only at an explicit fromFloat/toFloat boundary. any —
filestore 2 DB-less durable keyed document store — one atomically-written file per record, plus a typed-JSON convenience layer. posix —
finstats 3 Portfolio/financial statistics over dataset — XIRR, TWR, risk, beta, Monte-Carlo, correlation matrix. any dataset
fuzzysearch 2 Bounded-edit-distance typo-tolerant lookup over a static string set — DoS-bounded, the typo-tolerant sibling of trie. any trie
geoindex 3 Static spatial index for bbox and nearest-neighbour queries over a large fixed geo-point set — DoS-bounded, zero-copy. any —
jobqueue 3 Durable background-job queue over kv — lease/retry/dead-letter queue, per-partition FIFO under priority. posix kv
jsonshape 3 JSON → dataset reshaping — dot-path descent and typed column projection (a minimal jq-style subset). any dataset
kv 2 Crash-consistent embedded KV store, Bitcask-style log, with randomized fuzz-tested crash recovery. any —
kvtree 2 Ordered transactional KV store — copy-on-write B-tree (LMDB/BoltDB lineage), MVCC snapshots, crash-safe range scans. any kv, crc32
ramcache 2 Bounded in-memory cache — W-TinyLFU admission/eviction, TTL, generation invalidation; sharded thread-safe wrapper. any —
tabular 3 Dataset algebra (pandas/dplyr-style verbs) over dataset — aggregate/pivot/resample/rolling/join, fx-aware. any dataset
trie 3 Prefix index for instant autocomplete over a large static string set. any —
tsdb 3 Time-series persistence over kvtree — ordered (series, timestamp) key codec, streaming range scans, crash-safe retention-by-age. any kvtree

Also worth reaching for from storage — these are filed under another library (in brackets), and appear here because a consumer working in storage has a use for them:

Module Grade What it does Platform Deps
crc32 (format) 3 CRC-32 (IEEE: gzip/zlib/PNG) — x86-64 PCLMULQDQ folding and ARMv8 CRC instructions picked at run time, slicing-by-8 fallback; drop-in for std.hash.Crc32, streaming, extend, combine. any (x86-64 PCLMULQDQ / arm64 CRC asm + portable fallback) —
crc32c (format) 2 CRC-32C (Castagnoli) — SSE4.2 and ARMv8 CRC instructions picked at run time (three interleaved streams), slicing-by-8 fallback; streaming, extend, combine. any (x86-64 SSE4.2 / arm64 CRC asm + portable fallback) —
hashdigest (crypto) 2 Streaming digests — one-shot, incremental, and file hashing; SHA-256 convenience plus a multi-algorithm SHA-2/SHA-3/BLAKE2b/BLAKE3 layer. any —
zstd (format) 1 Zstandard (RFC 8878) compressor, levels 1-22 and negative levels — byte-identical to libzstd 1.5.7 ZSTD_compress2 and ZSTD_compressStream2, with libzstd's advanced parameters (magicless frames, explicit window/strategy, splitters, block size, long-distance matching as --long, targetCBlockSize superblocks), the sequence-level API (compressSequences, generateSequences, a block-level sequence producer) and reusable contexts in one workspace of exactly estimated size, caller-provided if wanted — and a decoder ported from libzstd's, one-shot and streaming (ZSTD_decompressStream, a std.Io.Reader), checksums, concatenated and skippable frames, frame queries any —

Crypto

Module Grade What it does Platform Deps
adaptor 2 Schnorr adaptor signatures over BIP340 (scriptless scripts for Lightning PTLCs / atomic swaps) — preSign, adapt, extract. any bip340, k256
aeadframe 2 Per-key AEAD record layer — seal/open with a monotonic nonce (never reused), epoch rekey, anti-replay window, AAD binding. any chachapoly
aesgcm 2 AES-GCM (AES-128/256) — stateful context caching the key schedule and GHASH powers, x86-64 AES-NI+PCLMULQDQ stitched one-pass kernel picked at run time, std fallback; std-shaped stateless API. any (x86-64 AES-NI/PCLMULQDQ asm, run-time detected + std fallback) —
bbs 3 BBS selective-disclosure signatures over bls12_381 (draft-irtf-cfrg-bbs-04) — sign many messages, later reveal a chosen subset in zero knowledge. any bls12_381, entropy
bech32 2 Bitcoin address encodings — bech32 (BIP173) / bech32m (BIP350) codec, segwit address encode/decode, base58check, P2PKH/P2WPKH. any ripemd160
bfv 3 BFV leveled homomorphic encryption (Fan-Vercauteren) over Z_q[X]/(X^N+1), RNS — exact-integer keygen/encrypt/decrypt/multiply/relinearize. No security level claimed. any entropy
bip32 2 BIP-39 mnemonic seed phrases + BIP-32 hierarchical-deterministic keys over secp256k1 — the wallet key-derivation foundation. any k256, ripemd160, bech32
bip340 1 BIP340 Schnorr signatures over secp256k1 (Bitcoin Taproot's signature scheme) — sign, verify, batch verify, x-only keys. any k256
bitcoinscript 2 Bitcoin Script consensus interpreter — full opcode set, CHECKSIG/CHECKMULTISIG; verifies bare/P2SH/segwit/P2TR key-path scripts. any bitcointx, k256, bip340, ripemd160
bitcointx 2 Bitcoin transaction (de)serialization + signature hashing — legacy, BIP143 segwit-v0, and BIP341 taproot key-path sighash. any bip340
blindrsa 1 RSA Blind Signatures (RFC 9474, RSABSSA) over rsa — the anonymous-token / Privacy Pass primitive: blind, sign, finalize, verify. any rsa
bls12_381 3 BLS12-381 pairing-friendly curve — field tower/groups, optimal-ate pairing, hash-to-curve, BLS signatures, KZG commitments, threshold BLS. any entropy
bn254 2 BN254 / alt-bn128 curve — field tower/groups, optimal-ate pairing, EIP-196/197 EVM precompiles, and a Groth16 zkSNARK verifier. any —
bolt3 3 Lightning BOLT#3 key derivation — per-commitment blinded keys, split-secret revocation keys, shachain secret generation. any k256
bolt8 2 Lightning BOLT#8 encrypted transport (Noise_XK_secp256k1_ChaChaPoly_SHA256) — handshake plus transport with periodic key rotation. any noise, k256
btcaddr 3 Bitcoin address layer -- scriptPubKey <-> address (P2PKH/P2SH/P2WPKH/P2WSH/P2TR/witness v1-16), network detection, WIF keys, P2SH/P2WSH helpers. any bech32, ripemd160
btcp2p 3 Bitcoin P2P wire-message codec — envelope, version/verack handshake, inventory/data messages. Codec only: no chain state or validation. any bitcointx
bulletproofs 2 Bulletproofs — zero-knowledge range proofs over Ristretto255, proving a Pedersen-committed value is in range with logarithmic proof size. linux ct25519
chachapoly 2 SIMD-accelerated ChaCha20-Poly1305 AEAD (RFC 8439) — a throughput-specialized, byte-exact duplicate of std.crypto.aead.chacha_poly. any (SIMD via @Vector) —
coconut 3 Coconut threshold-issuance anonymous credentials over bls12_381 — t-of-n issued Pointcheval-Sanders credentials with selective-disclosure showing. any bls12_381
ct25519 2 Constant-time-on-secrets scalar multiplication for Edwards25519/Ristretto255 — drops std's secret-dependent rejectIdentity branch. Caller must validate points. X25519 with key generation on the fixed-base comb (2.4× std). any —
ctap2 3 CTAP2 (FIDO2) authenticatorClientPIN command layer over a caller-supplied transport: GetInfo, PIN retries/set/change/token-with-permissions, both PIN protocols, CTAPHID packet codec. any cbor, ctap2pin
ctap2pin 2 CTAP2 pinUvAuthProtocol (FIDO2/WebAuthn) — both protocol versions: ECDH-P256 key agreement, encrypt/decrypt, authenticate/verify. any p256
decaf448 3 decaf448 prime-order group (RFC 9496) over ed448 — eliminates cofactor-4 pitfalls for threshold signing, VRFs, anonymous credentials. any ed448
dkg 3 Dealer-free Distributed Key Generation (GJKR) for threshold_ecdsa — bias-resistant secp256k1 key sharing feeding threshold signing. any threshold_ecdsa, paillier
drand 3 drand randomness-beacon client — chain-info and round codec, BLS-verifies a round signature against the chain public key. Transport-agnostic. any bls12_381, tlock
dtls 3 DTLS 1.3 (RFC 9147), PSK mode — key schedule, AEAD record layer, handshake fragmentation/reassembly, anti-replay window. any rsa, x509, chachapoly
ecvrf 2 ECVRF-EDWARDS25519-SHA512-TAI (RFC 9381 Verifiable Random Function) — prove/verify a deterministic, unbiasable output under a public key. any ct25519
ed448 2 Ed448 + X448 — the 448-bit "Goldilocks" curve (RFC 8032 + RFC 7748): constant-time X448 DH and Ed448/Ed448ph EdDSA signing. any entropy
entropy 1 Fail-closed entropy source — fill draws from std.Io.randomSecure or aborts the process; no generator, no silent degrade. Panics on failure. any —
falcon 2 FN-DSA — Falcon-512 and Falcon-1024 NIST post-quantum lattice signatures: keygen, sign, verify, and key/signature codecs. any —
frost 3 FROST threshold Schnorr signatures (RFC 9591), secp256k1 — t-of-n keygen, 2-round signing, aggregate. Not BIP340-compatible. any bip340, k256
fss 3 Function Secret Sharing — 2-party single-point Distributed Point Function (BGI16), plus multi-point FSS; the primitive under pir and private analytics. any —
groth16 4 Groth16 zk-SNARK prover over BN254 — R1CS→QAP, produces proofs bn254.groth16Verify accepts. setup is a toy, insecure trusted setup. any bn254
hashdigest 2 Streaming digests — one-shot, incremental, and file hashing; SHA-256 convenience plus a multi-algorithm SHA-2/SHA-3/BLAKE2b/BLAKE3 layer. any —
hpke 2 HPKE — Hybrid Public Key Encryption (RFC 9180): DHKEM(X25519/P-256) encap/decap, all four key-schedule modes, AEAD seal/open + export. any p256, chachapoly, entropy
hqc 2 HQC — code-based post-quantum KEM, NIST's structurally-independent backup to lattice-based ML-KEM. Complete keygen, encrypt, decrypt. any —
ibe 2 Standalone Boneh-Franklin Identity-Based Encryption over bls12_381 — a self-run PKG extracts per-identity keys. Not post-quantum; key escrow is inherent. any bls12_381, entropy
k256 2 asm-accelerated secp256k1 — Solinas field + GLV verify, bit-exact vs std.crypto.ecc.Secp256k1/BIP340. GLV is vartime/public-only, not for secrets. amd64 asm + portable fallback —
lms 3 LMS / HSS (RFC 8554), SHA-256 — stateful hash-based signatures (SP 800-208, CNSA 2.0). A leaf signs once; sign advances the position first. any —
lninvoice 2 Lightning BOLT#11 payment requests (+ BOLT#12 offer decode) — decode/verify and encode/sign, with node-pubkey signature recovery. any bech32, k256, lnwire, bip340
lnwire 3 Lightning BOLT#1/2/7 wire messages — base frame, BigSize/TLV codec, channel-management and gossip messages, over bolt8. any —
megolm 3 Megolm — Matrix's group-messaging ratchet: a one-way HMAC hash ratchet (fast-forward only, never rewinds) plus Ed25519-signed message frames. any aescbc, entropy
minisign 2 minisign file format (jedisct1/minisign) — Ed25519 sign/verify for signed files/releases, including scrypt-encrypted secret keys. any entropy
mls 3 MLS — Messaging Layer Security (RFC 9420): cipher-suite/codec foundation plus TreeKEM (ratchet tree), for scalable group messaging. any hpke
montint 3 Constant-time Montgomery modular arithmetic over arbitrary odd moduli — faster native-Zig alternative to std.crypto.ff, x86-64 asm + portable fallback. x86-64 asm + portable fallback —
musig2 2 MuSig2 multi-signature (BIP327) producing BIP340 signatures — rogue-key-safe key aggregation, 2-round nonces, partial sign/verify. any bip340, k256
noise 3 Generic Noise Protocol Framework (spec rev 34) — handshake patterns (NN/NK/XX/IK) over a comptime-parameterized DH/AEAD/hash suite. any chachapoly
ocsp 2 RFC 6960 OCSP — build an OCSP request and cryptographically verify an OCSP response, for TLS OCSP-stapling. any x509, rsa, p256
ocspcache 2 OCSP-stapling fetch + cache over ocsp — AIA responder discovery, verify-before-cache, refresh-ahead expiry, soft-fail on outage. any ocsp, http, x509
opaque 3 OPAQUE — an asymmetric PAKE (RFC 9807), ristretto255-SHA-512 + 3DH — registration and login/AKE. Server compromise reveals no password. any voprf, ct25519
oscore 2 OSCORE (RFC 8613) — end-to-end object security for CoAP: HKDF context derivation, AES-CCM AEAD, anti-replay sliding window. any —
otp 2 HOTP + TOTP one-time passwords (RFC 4226 / RFC 6238) — the 2FA-authenticator primitive; caller supplies the counter/time (no wall clock); otpauth:// provisioning-URI parse/format (base32 secrets). any base32
p256 2 asm-accelerated NIST P-256 — Solinas field, constant-time comb sign, vartime wNAF verify; bit-exact vs std.crypto.ecc.P256 and RFC 6979. amd64 asm + portable fallback —
paillier 2 Paillier additively-homomorphic public-key encryption (EUROCRYPT 1999) — 2048-bit keygen, encrypt/decrypt, homomorphic add; const-time decrypt path. any montint
pir 3 Two-server Private Information Retrieval over fss's DPF — fetch a record without either server learning the index. Two colluding servers recover it immediately. any fss
poseidon 1 Poseidon — the ZK-friendly hash over prime fields (HADES permutation), for BN254 and BLS12-381; cheap Merkle/commitment hashing inside circuits. any bn254, bls12_381
psbt 3 BIP174 Partially Signed Bitcoin Transaction (PSBT) v0 — binary (de)serialization plus the Combiner (merge) role, over bitcointx. any bitcointx, bitcoinscript, ripemd160
quic-crypto 2 RFC 9001 (TLS for QUIC) crypto seam — secret derivation, AEAD packet protection, header protection, key update, Retry integrity tag, QUIC v1 + v2 (RFC 9369); engine-agnostic. any chachapoly
rescue 2 Rescue-Prime Optimized (RPO) — arithmetization-oriented hash over the Goldilocks field, the alternative to poseidon for STARK circuits. any —
ripemd160 1 RIPEMD-160 (ISO/IEC 10118-3) streaming hash, plus hash160 (RIPEMD160(SHA256(x))), the Bitcoin pubkey-hash primitive. any —
rsa 2 Pure-Zig RSA (PKCS#1 v2.2, RFC 8017) — keygen, PKCS1-v1.5/PSS sign+verify, OAEP/PKCS1 encrypt+decrypt, DER/PEM/OpenSSH key parsing. any montint
sealedbox 1 NaCl crypto_box_seal — anonymous-sender X25519 public-key encryption, plus base64/hex key serialization. any —
sha2 3 SHA-224/256/384/512 (FIPS 180-4) — drop-in for std.crypto.hash.sha2 (also under std's Hmac/Hkdf); an AVX2 multi-block message schedule makes runs of 2+ blocks 1.24–1.40× std on x86-64 without SHA-NI, std's own SHA-NI/ARMv8 path where the target has it. any (AVX2 SIMD schedule on x86-64 + portable scalar fallback) —
signal 3 Signal Protocol — X3DH and PQXDH key agreement, XEdDSA signing, and the Double Ratchet: E2EE sessions with forward secrecy, post-compromise security and a post-quantum initial handshake. any chachapoly, ct25519, entropy
slhdsa 2 SLH-DSA (FIPS 205, standardized SPHINCS+) — post-quantum stateless hash-based signatures, all twelve parameter sets, NIST-KAT-verified. any —
spake2plus 2 SPAKE2+ — an augmented PAKE (RFC 9383), P-256/SHA-256 (the Matter/Thread commissioning PAKE); resists server-compromise. any p256
sphinx 3 Lightning BOLT#4 Sphinx onion routing — forward ECDH blinding chain, layered packet construction, constant-time layer peeling. any k256
taproot 2 BIP341 Taproot output construction — key tweaking (tweakPublicKey/tweakSecretKey) and script trees (Merkle root, per-leaf control blocks) built over bip340. any bip340, k256
tenantkex 2 Per-tenant key exchange — a Noise_IK handshake (via noise) between provider edges, deriving directional channel keys for aeadframe. any noise
tfhe 3 TFHE gate bootstrapping — unbounded-depth FHE on encrypted bits: binary gates, programmable bootstrap, tfhe-rs's boolean parameter sets and key/ciphertext layouts (interoperates with tfhe-rs 1.8.1 both ways). any entropy
threshold_ecdsa 3 GG20 threshold ECDSA over secp256k1 (t-of-n) — dealer keygen, per-signer presigning state machine with identifiable abort, one-round online signing; standard verifiable ECDSA sigs. Audit warranted before production use. any paillier, montint
timelock_envelope 3 Hybrid sealed envelope — unlocks only once both a drand timelock round publishes AND the recipient holds the PQ-KEM secret; AEAD-sealed content. any tlock, hqc, chachapoly, entropy
tlock 3 drand-style timelock encryption (Boneh-Franklin IBE over bls12_381) — encrypt to a future drand round; decryptable once it publishes. Not post-quantum. any bls12_381, entropy
tlsclient 3 std's TLS 1.3/1.2 client with the server chain verified by RFC 5280 (x509.verifyChain) — closes ziglang/zig #35877 (no basicConstraints check). any x509
tlsresume 2 Server-side TLS 1.3 session-ticket resumption (RFC 8446) — ticket seal/open, PSK binder derivation, 0-RTT early-data key schedule. any —
vdf 3 Wesolowski Verifiable Delay Function over an RSA hidden-order group — sequential-squaring delay with prove/verify. A caller-supplied modulus needs a trusted setup. any montint
voprf 3 (V)OPRF — Oblivious Pseudorandom Functions (RFC 9497), ristretto255-SHA-512: OPRF, verifiable, and partially-oblivious modes with DLEQ proofs. any ct25519
webauthn 2 WebAuthn / FIDO2 Relying-Party verifier (W3C Level 3) — assertion + registration ceremony checks, plus attestation verification. Verification only. any cbor, rsa, p256, x509
x509 2 X.509 certificate-chain / path validation (RFC 5280 §6) — trust-store chain building, extension, name, and signature checks, including post-quantum ML-DSA (RFC 9881) and SLH-DSA (RFC 9882) certificates, plus CRL revocation checking (RFC 5280 §6.3). any rsa, slhdsa
xmss 3 XMSS (RFC 8391), single-tree SHA-256 — stateful hash-based signatures. Index reuse breaks the scheme; sign advances the index first. any —

Also worth reaching for from crypto — these are filed under another library (in brackets), and appear here because a consumer working in crypto has a use for them:

Module Grade What it does Platform Deps
aescbc (web) 2 Raw AES-CBC (NIST SP800-38A) + PKCS#7/XML-Enc padding helpers, zero-alloc; padding-oracle caveat — consumers own authenticate-before-unpad any —
http (web) 2 HTTP/1.1 client and server, hardened for direct exposure (slowloris caps, gzip, multipart, Range, negotiation); also speaks HTTP/2 (h2c/h2 client+server). Not std.http. any netaddr, datefmt, tlsclient, crc32

Serialization / formats

Module Grade What it does Platform Deps
base32 3 Base32 codec (RFC 4648 §6 + base32hex §7) — strict by default (canonical trailing bits, exact padding), opt-in lenient decode (optional padding, lowercase, whitespace); the encoding of TOTP secrets. any —
blobmsg 2 OpenWRT ubus client + blob/blobmsg wire codec. linux (codec itself: any) —
cbor 3 CBOR (RFC 8949) codec — all 8 major types, canonical encoding option, untrusted-input hardened; plus a minimal COSE (RFC 9052) layer. any —
cookies 2 HTTP cookies (RFC 6265) — request Cookie parser plus Set-Cookie builder (Secure/HttpOnly/SameSite), injection-guarded. any http
crc32 3 CRC-32 (IEEE: gzip/zlib/PNG) — x86-64 PCLMULQDQ folding and ARMv8 CRC instructions picked at run time, slicing-by-8 fallback; drop-in for std.hash.Crc32, streaming, extend, combine. any (x86-64 PCLMULQDQ / arm64 CRC asm + portable fallback) —
crc32c 2 CRC-32C (Castagnoli) — SSE4.2 and ARMv8 CRC instructions picked at run time (three interleaved streams), slicing-by-8 fallback; streaming, extend, combine. any (x86-64 SSE4.2 / arm64 CRC asm + portable fallback) —
csvsafe 2 CSV formula-injection guard: OWASP's =/+/-/@/tab/CR cell leads, plus LF, ` and%`. any
csvstream 2 Streaming RFC 4180 CSV reader that preserves byte offsets, with bounded memory regardless of file size. any —
datefmt 2 Civil calendar plus token-based date/time parse/format and calendar arithmetic, correct before 1970. any —
encoding 3 Legacy single-byte code page ↔ UTF-8 transcoding (5 European code pages: windows-125x, ISO-8859-1/2/15). any —
framing 3 Length-prefixed stream framing (writeFrame/readFrame) plus a generic JSON tagged-union envelope codec. any —
ini 3 INI reader — sections, key = value, comments; Python configparser and Desktop Entry (GKeyFile) dialects. any —
jinja 3 Jinja2-compatible template engine — expressions, control flow, template inheritance/macros/imports, over a symlink-contained loader. any —
json5 2 Single-pass JSON5→JSON preprocessor (comments, unquoted keys, trailing commas, single-quoted strings, JSON5 numbers, line continuations). any —
linkheader 3 Web Linking (RFC 8288) Link header build + parse (rel/title/type), plus pagination helpers and find(rel); zero-alloc. any —
numparse 3 Locale-aware grouped-number parsing (thousands/decimal separators) into an exact decimal.Decimal. any decimal
protobuf 3 Protocol Buffers wire format (proto3) codec — schema derived at comptime from Zig structs, no .proto compiler; untrusted-input hardened. any —
qr 2 QR Code encoder and decoder (ISO/IEC 18004 model 2) — versions 1–40, levels L/M/Q/H, numeric/alphanumeric/byte modes, Reed-Solomon error correction, structured append; SVG and terminal renderers, allocation-free. any —
qrscan 3 Locate a QR symbol in a grayscale image (luma + stride, camera or canvas) at any rotation and moderate tilt, and sample it into a qr.Matrix; block-adaptive binarisation, connected-component finder location, allocation-free. any qr
tar 2 ustar/GNU tar reader+writer (preserves uid/gid/mtime) + gzip. any (packer: linux) —
tz 2 IANA time-zone offset lookup — zone name → UTC offset/DST at a given instant (598 zones + POSIX-TZ footer). any datefmt
yaml 3 YAML 1.2 reader (not 1.1) — scanner → parser → composer over the core schema (no yes/no booleans); cyclic aliases rejected. any —
zipstream 2 Streaming ZIP archive reader — walks the central directory once, streams decompressed member bytes on demand. any —
zstd 1 Zstandard (RFC 8878) compressor, levels 1-22 and negative levels — byte-identical to libzstd 1.5.7 ZSTD_compress2 and ZSTD_compressStream2, with libzstd's advanced parameters (magicless frames, explicit window/strategy, splitters, block size, long-distance matching as --long, targetCBlockSize superblocks), the sequence-level API (compressSequences, generateSequences, a block-level sequence producer) and reusable contexts in one workspace of exactly estimated size, caller-provided if wanted — and a decoder ported from libzstd's, one-shot and streaming (ZSTD_decompressStream, a std.Io.Reader), checksums, concatenated and skippable frames, frame queries any —

Also worth reaching for from format — these are filed under another library (in brackets), and appear here because a consumer working in format has a use for them:

Module Grade What it does Platform Deps
decimal (storage) 2 Exact i128 fixed-point decimal for money math with IEEE/GDA rounding modes and rescale — float-free arithmetic, f64 only at an explicit fromFloat/toFloat boundary. any —
http (web) 2 HTTP/1.1 client and server, hardened for direct exposure (slowloris caps, gzip, multipart, Range, negotiation); also speaks HTTP/2 (h2c/h2 client+server). Not std.http. any netaddr, datefmt, tlsclient, crc32

Host / OS / agent — process, sandboxing, IPC, and the agent-side glue

Module Grade What it does Platform Deps
argsafe 2 Allowlist validators + a typed argv builder — neutralizes argument/flag injection into an exec argv. any —
diagnostics 3 LSP-style structured validation-finding collector — severity, dot-path, position, code, suggestion. any —
diskfree 3 statfs/statfs64 disk-space query (total/free/available, inodes, block size) + /proc/self/mounts+mountinfo parsers — what's mounted and how full, no df/mount subprocess linux —
diskusage 2 du-style tree walk over a raw statx/fstatat metadata wrapper — apparent size and real allocation in one pass, hard links counted once, one-filesystem boundary linux —
fastmem 3 Vectorised memset (32-byte stores, overlapping head/tail) that an executable without libc can export to replace compiler_rt's byte-at-a-time one for every caller, std included; opt-in. any (portable @Vector code; the export refuses libc-linked builds) —
ipcbus 3 Same-host unix-socket control plane — a request/reply server plus a capped in-memory scratch key→bytes bus. linux framing
mcp 2 Model Context Protocol server (JSON-RPC 2.0) — tools, resources, prompts, plus server→client sampling and elicitation requests. any —
mcp-http 2 MCP Streamable HTTP transport (2026-07-28 stateless + 2025-06-18 sessions) — POST /mcp with JSON or live SSE, header/body validation, Origin (DNS-rebind) guard. any router, http, mcp
pollworker 3 Single-owner poll(2) loop plus a lock-free fork/exec job table, for offloading blocking work off the loop thread. linux —
procrun 2 Subprocess runner — reap-race-tolerant wait, deadlock-free capped stdio capture, timeout, streaming, and cancel. any argsafe
sandbox 3 Process self-hardening for an internet-facing server — privilege drop, setrlimit/no core dumps, Landlock fs allow-list, seccomp-bpf. linux —
testkit 2 Test-only shared harness (hex decoding for KAT vectors, golden byte-comparison, verbose-skip convention); wired via build.zig test_deps, absent from consumer imports any —
uci 3 OpenWRT UCI config parser + serializer + typed model, with stable round-trip. any —

Also worth reaching for from os — these are filed under another library (in brackets), and appear here because a consumer working in os has a use for them:

Module Grade What it does Platform Deps
framing (format) 3 Length-prefixed stream framing (writeFrame/readFrame) plus a generic JSON tagged-union envelope codec. any —

Non-goals — deliberately not built here

Capabilities this collection will not own, and what to reach for instead. A row here is a scope decision with a reason, not a promise — the reason is what to argue with if it should change. zig build check-catalog refuses to let this table name a capability that has since become a module.

Capability Adopt instead Why not a module
Hardened/read-only SQLite vrischmann/zig-sqlite or karlseguin/zqlite.zig, wrapped consumer-side The enforcement (authorizer/PRAGMA query_only/open_v2(READONLY)) is raw C-API — breaks the pure-Zig/no-libc invariant
Kafka bind librdkafka A choice, not an impossibility: the wire protocol is public and binary, so a port is perfectly writable — it is just long and uninteresting (dozens of API keys, each independently versioned). The trade is one C dependency against a lot of mechanical work, and the dependency wins until a consumer says otherwise
Regex mnemnion/mvzr (no captures) or zig-utils/zig-regex (captures) Two mature pure-Zig libs already exist
PostgreSQL (wire v3) karlseguin/pg.zig Mature MIT lib, pooling + TLS
MySQL/MariaDB speed2exe/myzql Only viable option
TOML mattyhall/tomlz Mature MIT config parser
Structured logging karlseguin/log.zig Cleanest "just use it"
S3 lobo/aws-sdk-for-zig SigV4 built in
Redis/Valkey kristoff-it/zig-okredis (partial/alpha) Best available design
xz compression bind liblzma; or compress outside the process (the xz CLI in the consumer's pipeline) Decoding is covered: std 0.16 ships an std.compress.xz decoder, and zstd is a module both ways (zstd: every level 1–22, and a decoder). What remains is an LZMA2 encoder — a large arc with no in-process consumer yet; today's consumers write plain bytes and compress in a backup/build step
HTTP/3 transport ngtcp2 The transport (streams, loss detection, ACK logic, flight scheduling) is a bigger arc than SSH or OPC-UA were, and ngtcp2 is crypto-agnostic by design — it takes a TLS backend, which is the shape quic-crypto already has. The RFC 9001 crypto seam is ours; the state machine is not

About

Foundational Zig 0.16 modules — pure-Zig, no C/libc/external deps. Protocols (HTTP/2, DNS, MQTT, CoAP, SNMPv3), crypto (BLS12-381, post-quantum, ZK, FHE), Bitcoin/Lightning, industrial OT (Modbus, DNP3, IEC 61850, OPC UA), Linux netlink/eBPF/XDP.

Topics

Resources

Security policy

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages