When the server sends off-path PATH_CHALLENGEs for NAT traversal, each probe consumes a reserved CID from the sending path's queue. If the probes fail (no PATH_RESPONSE), those CIDs were never retired, permanently reducing the available CID budget. After enough failed rounds, remaining() drops below 2 and no more probes can be sent — holepunching is broken. This was the root cause of holepunch failure after 5G→WiFi switch: initial 5G rounds consumed all probe CIDs on failed attempts, and after switching to WiFi the server couldn't probe the client's new addresses. Fix: when a new NAT traversal round's REACH_OUT arrives, clear the previous round's unconfirmed off-path challenges and rotate the CID queue (via next()) to retire the consumed CIDs. The peer then issues replacement CIDs via NEW_CONNECTION_ID, restoring the probe budget. Includes: - ServerState::current_round() accessor - PathData::has_off_path_challenges() / clear_off_path_challenges() - Failing test: off_path_probe_cids_recovered_after_timeout
noq
General purpose implementation of the QUIC transport
protocol in pure
Rust. Noq is built as an async-friendly API in the noq crate on top
of a sans-io protocol library in noq-proto.
Noq started out as a fork of the excellent Quinn project. The main focus of development has been towards adding support for more QUIC (draft) extensions:
Features
- Easy to use futures-based async API.
- Client and server server functionality.
- 0-RTT and 0.5-RTT data support.
- Ordered and unordered stream reads.
- Custom and zero-length connection identifiers.
- Fully pluggable crypto API with a Rustls implementation using ring or aws-lc-rs provided by default for convenience.
- Broad platform support, including Linux, Windows, macOS, android, iOS and wasm.
Standards
The noq library aims to be correct implementation of various QUIC standards:
- Supports the core QUIC specifications:
- RFC 8999 - Version-Independent Properties of QUIC.
- RFC 9000 - QUIC: A UDP-Based Multiplexed and Secure Transport.
- [RFC 9001 - Using TLS to Secure QUIC].
- RFC 9002 - QUIC Loss Detection and Congestion Control.
- The standardised QUIC extensions:
- Draft extensions:
- qlog: Structured Logging for Network Protocols.
- QUIC Multipath.
- With experimental qlog support.
- QUIC Address Discovery (QAD).
- Using QUIC to traverse NATs (QNT).
Getting started
Examples at https://github.com/n0-computer/noq/blob/main/noq/examples
$ cargo run --example server ./
$ cargo run --example client https://localhost:4433/Cargo.toml
This launches an HTTP 0.9 server over the QUIC transport on the loopback address serving the current working directory, with the client fetching ./Cargo.toml. By default, the server generates a self-signed certificate and stores it to disk, where the client will automatically find and trust it.
License
Copyright 2025 The quinn developers Copyright 2025 N0, INC.
This project is licensed under either of
- Apache License, Version 2.0, (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option.
Contribution
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this project by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.