curl / Development / Experimental

Experimental

Some features and functionality in curl and libcurl are considered EXPERIMENTAL.

Experimental support in curl means:

  1. Experimental features are provided to allow users to try them out and provide feedback on functionality and API etc before they ship and get "carved in stone".
  2. You must enable the feature when invoking configure as otherwise curl is not built with the feature present.
  3. We strongly advise against using this feature in production.
  4. We reserve the right to change behavior of the feature without sticking to our API/ABI rules as we do for regular features, as long as it is marked experimental.
  5. Experimental features are clearly marked so in documentation. Beware.
  6. Vulnerabilities in experimental features are not considered security problems; please report them as regular bugs/feedback instead.

Graduation

  1. Each experimental feature should have a set of documented requirements of what is needed for that feature to graduate. Graduation means being removed from the list of experiments.
  2. An experiment should NOT graduate if it needs test cases to be disabled, unless they are for minor features that are clearly documented as not provided by the experiment and then the disabling should be managed inside each affected test case.

Experimental features right now

HTTP/3 support (non-ngtcp2 backends)

Graduation requirements:

HTTP/3 proxy and CONNECT-UDP support

Support for HTTP/3 proxy and CONNECT-UDP tunneling is experimental and requires an explicit build-time opt-in (--enable-proxy-http3 for autotools, -DUSE_PROXY_HTTP3=ON for CMake).

Graduation requirements:

The quiche backend

Graduation requirements:

The Rustls backend

Graduation requirements:

ECH

Use of the HTTPS resource record and Encrypted Client Hello (ECH) when using DoH

Graduation requirements:

SSL session import/export

Import/Export of SSL sessions tickets in libcurl and curl command line option '--ssl-session ' for faster TLS handshakes and use of TLSv1.3/QUIC Early Data (0-RTT).

Graduation requirements:

HTTPS RR

HTTPS records support is a requirement for ECH but is provided as a stand-alone feature that is itself considered EXPERIMENTAL.

Graduation requirements:

HTTP Message Signatures (RFC 9421)

Sign outgoing HTTP requests according to RFC 9421 using the --httpsig-algo, --httpsig-key, --httpsig-keyid and --httpsig-headers command line options, or the corresponding CURLOPT_HTTPSIG_* libcurl options. Built only when configured with --enable-httpsig.

Graduation requirements: