NAME

Alien::ngtcp2 - Find or build the native libraries needed for QUIC

SYNOPSIS

use Alien::ngtcp2;

my $cflags = Alien::ngtcp2->cflags;
my $libs   = Alien::ngtcp2->libs;

my $backend       = Alien::ngtcp2->crypto_backend;
my $crypto_cflags = Alien::ngtcp2->crypto_cflags;
my $crypto_libs   = Alien::ngtcp2->crypto_libs;

DESCRIPTION

Alien::ngtcp2 supplies the native ngtcp2 libraries needed by Perl QUIC distributions.

QUIC needs two native pieces:

  • libngtcp2, which handles the QUIC protocol

  • an ngtcp2 TLS helper, which connects ngtcp2 to a TLS library

Most users do not need to choose a TLS library. Alien::ngtcp2 checks the machine and uses a suitable one automatically.

The original cflags and libs methods still describe only the core libngtcp2 library. This keeps the interface from version 0.01 working.

HOW INSTALLATION WORKS

If a compatible libngtcp2 and TLS helper are already installed, Alien::ngtcp2 uses them.

If ngtcp2 must be built from source, Alien::ngtcp2 tries to use TLS software already on the machine:

1. OpenSSL 3.5 or newer

Build the ngtcp2 OpenSSL helper.

2. Otherwise, GnuTLS 3.7.5 or newer

Build the ngtcp2 GnuTLS helper.

3. Otherwise, OpenSSL 1.1.1 through 3.4

Use Picotls with that existing OpenSSL.

4. No suitable TLS library on Unix

Alien::OpenSSL can provide a private OpenSSL for the Picotls fallback.

Alien::ngtcp2 does not replace or upgrade the operating system TLS library.

Windows

On Windows the fallback uses the OpenSSL that belongs to the active Perl and compiler toolchain.

If that OpenSSL is older than 1.1.1, installation stops with a clear error instead of silently installing a different TLS stack.

Strawberry Perl 5.30 and newer meet this requirement. Historical Strawberry Perl 5.28 contains OpenSSL 1.1.0j and is too old for the fallback.

METHODS

cflags

Returns compiler flags for the core libngtcp2 library.

libs

Returns linker flags for the core libngtcp2 library.

crypto_backend

Returns the selected TLS backend name, such as openssl, gnutls, boringssl, wolfssl, or picotls.

crypto_package

Returns the pkg-config package name for the selected ngtcp2 TLS helper.

crypto_cflags

Returns the compiler flags needed to use the selected ngtcp2 TLS helper.

crypto_libs

Returns the linker flags needed to use the selected ngtcp2 TLS helper.

BACKEND OVERRIDE

Most users should let Alien::ngtcp2 choose automatically.

Packagers and developers may set ALIEN_NGTCP2_CRYPTO to auto or one of:

openssl
gnutls
boringssl
wolfssl
picotls

An explicit choice is mainly useful for testing and packaging.

VERSIONS

Alien::ngtcp2 requires Perl 5.20 or newer and Alien::Build 2.84 or newer.

A system libngtcp2 must be version 1.25.0 or newer.

The bundled ngtcp2 source is version 1.25.0.

BUNDLED PICOTLS SOURCE

The Picotls fallback contains the MIT-licensed Picotls TLS core and OpenSSL binding from commit:

f07f1c8c68b237f1468bc1f1fe1b68aba3ff23b4

That is the Picotls revision documented by ngtcp2 1.25.0.

The Picotls minicrypto backend and its third-party dependencies are not included.

SEE ALSO

Alien::Base

Alien::OpenSSL

https://github.com/ngtcp2/ngtcp2

https://github.com/h2o/picotls

AUTHOR

Joshua S. Day

COPYRIGHT AND LICENSE

This software is Copyright (c) 2026 by Joshua S. Day.

This is free software, licensed under:

The MIT (X11) License