NAME
Alien::ngtcp2 - Find or build the native libraries needed for QUIC
SYNOPSIS
use Alien::ngtcp2;
my $cflags = Alien::ngtcp2->cflags;
my $libs = Alien::ngtcp2->libs;
my $backend = Alien::ngtcp2->crypto_backend;
my $crypto_cflags = Alien::ngtcp2->crypto_cflags;
my $crypto_libs = Alien::ngtcp2->crypto_libs;
DESCRIPTION
Alien::ngtcp2 supplies the native ngtcp2 libraries needed by Perl QUIC distributions.
QUIC needs two native pieces:
libngtcp2, which handles the QUIC protocolan ngtcp2 TLS helper, which connects ngtcp2 to a TLS library
Most users do not need to choose a TLS library. Alien::ngtcp2 checks the machine and uses a suitable one automatically.
The original cflags and libs methods still describe only the core libngtcp2 library. This keeps the interface from version 0.01 working.
HOW INSTALLATION WORKS
If a compatible libngtcp2 and TLS helper are already installed, Alien::ngtcp2 uses them.
If ngtcp2 must be built from source, Alien::ngtcp2 tries to use TLS software already on the machine:
- 1. OpenSSL 3.5 or newer
-
Build the ngtcp2 OpenSSL helper.
- 2. Otherwise, GnuTLS 3.7.5 or newer
-
Build the ngtcp2 GnuTLS helper.
- 3. Otherwise, OpenSSL 1.1.1 through 3.4
-
Use Picotls with that existing OpenSSL.
- 4. No suitable TLS library on Unix
-
Alien::OpenSSL can provide a private OpenSSL for the Picotls fallback.
Alien::ngtcp2 does not replace or upgrade the operating system TLS library.
Windows
On Windows the fallback uses the OpenSSL that belongs to the active Perl and compiler toolchain.
If that OpenSSL is older than 1.1.1, installation stops with a clear error instead of silently installing a different TLS stack.
Strawberry Perl 5.30 and newer meet this requirement. Historical Strawberry Perl 5.28 contains OpenSSL 1.1.0j and is too old for the fallback.
METHODS
cflags
Returns compiler flags for the core libngtcp2 library.
libs
Returns linker flags for the core libngtcp2 library.
crypto_backend
Returns the selected TLS backend name, such as openssl, gnutls, boringssl, wolfssl, or picotls.
crypto_package
Returns the pkg-config package name for the selected ngtcp2 TLS helper.
crypto_cflags
Returns the compiler flags needed to use the selected ngtcp2 TLS helper.
crypto_libs
Returns the linker flags needed to use the selected ngtcp2 TLS helper.
BACKEND OVERRIDE
Most users should let Alien::ngtcp2 choose automatically.
Packagers and developers may set ALIEN_NGTCP2_CRYPTO to auto or one of:
openssl
gnutls
boringssl
wolfssl
picotls
An explicit choice is mainly useful for testing and packaging.
VERSIONS
Alien::ngtcp2 requires Perl 5.20 or newer and Alien::Build 2.84 or newer.
A system libngtcp2 must be version 1.25.0 or newer.
The bundled ngtcp2 source is version 1.25.0.
BUNDLED PICOTLS SOURCE
The Picotls fallback contains the MIT-licensed Picotls TLS core and OpenSSL binding from commit:
f07f1c8c68b237f1468bc1f1fe1b68aba3ff23b4
That is the Picotls revision documented by ngtcp2 1.25.0.
The Picotls minicrypto backend and its third-party dependencies are not included.
SEE ALSO
https://github.com/ngtcp2/ngtcp2
https://github.com/h2o/picotls
AUTHOR
Joshua S. Day
COPYRIGHT AND LICENSE
This software is Copyright (c) 2026 by Joshua S. Day.
This is free software, licensed under:
The MIT (X11) License