XCurl
daniel.haxx.se
daniel.haxx.se
> The provided functionality is certainly a very stripped down and limited version of the libcurl API. A fun detail is that the quite bluntly just link to the libcurl API documentation to describe how xCurl works.
is IMO a major dick move. It seems inevitable that doing this will cause users with questions about xCurl to seek out curl maintainers/forums for support with xCurl (as with the email that prompted this article), even though they have no insight at all into how xCurl works. And some of those people might not be very happy with the response "we have no idea - try contacting Microsoft".
Now, that might not have been Microsoft's deliberate intent, but I don't see how it's anything but completely forseeable, and should have been avoided.
(Yes, Microsoft need to credit curl with the copyright info and license, but the place for that is the "Credits" and/or "License" parts of the documentation, not the "Usage"/"API reference" parts.)
https://github.com/mackyle/sqlite/blob/3cf493d/src/os.h#L52-...
Honestly though, that's life. I don't think its that big a deal, if you've ever done open source user support you'll know that people ask about all sorts of crazy things. You're lucky if they are even asking about software and not how to wash a car.
I doubt this will be a large number of people. If xCurl is only available via the GDK, then you get access to it you need to be working for a company that has developer contract signed with Microsoft. If you are such a dev, you will also have access to the Xbox dev forums which _should_ be your first stop for GDK-related questions.
People are assuming this is meant to be a general-purpose, generic replacement; but it is quite narrowly focused on gamedev.
Is this true? I've been wanting to be able to develop my own console stuff for a long time, but the hoops have seemed insurmountable so far. Can I really deploy my own stuff to Xbox without having to pay huge fees and have calls with a sales team?
For publishing to some store, that's fine, but just for development I just wanna be able to get a build running without too much red tape, otherwise it's not fun and therefore not worth it.
https://learn.microsoft.com/en-us/windows/uwp/xbox-apps/devk...
Lots of guides available for different scenarios (C++, Unity or HTML/JS)
From the GDK GitHub (https://github.com/microsoft/gdk):
> How do I run a GDK game built for the Xbox App on Windows 10 or Xbox Game Pass for PC on Xbox Consoles?
> Xbox console development requires the “Microsoft Game Development Kit with Xbox Extensions (GDKX)”. Games will need to retarget and rebuild for Xbox One or Xbox Series X|S with the GDKX installed.
> You need to download, install, and retarget your project for Xbox consoles using the GDKX
> The GDKX is currently only available under confidential license within an NDA Xbox program (e.g. ID@Xbox).
Sorry for giving you false hope!
I do wish they made Xbox more available to students in gamedev/cs degrees. When I was in school, Microsoft actually sponsored the program I was in, and I had a chance to work on Xbox stuff that as a student I would not have had any access to otherwise; That ended up being really useful to my early career -- not a lot of college grads have experience with developing and publishing for real on Xbox.
Yes, they should make it clear that xCurl has nothing to do with real curl.
But if it intends to implement the same interface, I don't see any problem with saying look at the curl docs for what its supposed to do. I don't see how that would be much different then if you implemented your own web browser and was like, look at MDN for how its supposed to work.
<2 pages of back-and-forth posts later>
"Oh you're using xCurl, yeah you need to talk to Microsoft."
It probably depends on the reach this has within the intended audience (people wanting to deploy libcurl on Xbox?) as to how much of a support burden it will end up, but I suspect more than Mozilla has to deal with from similar situations.
But we’re talking about curl here. MS could have an intern copy paste the curl document, delete the stuff that doesn’t apply to XCurl, and host it on a shared OneDrive Word document all within a day, and it would be orders of magnitude a significantly better experience.
Instead curl maintainers will end up spending man years supporting XCurl issues instead.
I get the feeling people think MS is different now it has embraced open source.
...Is SEO even a thing now in the GPT era?
Ludicrous and insulting, like it is saying LMGTFY.
I was actually at one point (years ago) tasked with determining if we could use curl in a project I was working on. There was indeed much surgery needed to ensure that the code even compiled, much less worked correctly. We ended up just using WinHTTP directly instead.
As for getting access to the source code for xCurl, that will likely not be possible without actually signing up as a dev with Microsoft and going through the whole process. And even then, you'd be under a NDA.
(My information is several years old though, so it might be somewhat outdated)
> xCurl differs from libCurl in that xCurl is implemented on top of WinHttp and automatically follows all the extra Microsoft Game Development Kit (GDK) requirements and best practices. While libCurl itself doesn’t meet the security requirements for the Microsoft Game Development Kit (GDK) console platform, use xCurl to maintain your same libCurl HTTP implementation across all platforms while changing only one header include and library linkage.
"With large invasive changes of this kind we can certainly hope that the team making it has invested time and spent serious effort on additional testing, both before release and ongoing."
"...since I can’t find the source code I cannot really get a grip of exactly how much and how invasive Microsoft has patched this."
It's not a patch of libcurl if they just implement a mostly compatible API from scratch.
"Fork" and "API compatible wrapper" are also not two mutually exclusive things. Often, one of the easiest ways to build an API compatible wrapper is to start by forking the original project, scoop out the internals and replace them with what you are trying to wrap, and then discard all the dangling code (e.g. features that you couldn't wire up because your custom internals don't support it).
It could just mean that Microsoft copied over the header file from libcurl without using any of the implementation.
Could it be simply that WinHTTP collects usage telemetry and MS wants to ensure their valuable feed by forcing all traffic through their library?
A lot of studios that ship on multiple platforms have abstraction layers that can internally be switched out to every platform specific API.
Exactly this. At one point, I was the man responsible for that abstraction layer. Even most of our engine devs never even saw those low layers of the console APIs -- the single exception being the graphics peeps who by necessity had to work at the same layer I was. I basically wrote a Xbox/Playstation/Nintendo/PC libc/runtime that the rest of our engine was based on. I Imagine a lot of other studios that shipped cross-platform had some level of this as well.
This is why the MIT license is great. If it was GPL'd or something, they would have to rip out curl entirely and develop a completely in-house library, which takes more time, costs more, adds bugs, etc. On top of adapting any programs that normally use libcurl to use their custom thing, or creating a shim library (either way more work). MIT-licensed code allows corporations to still build on top of open source, and monkey-patch their own shittiness in the process. Many of us OSS devs choose MIT for this reason: we just want more people to be able to use it.
Edit: Answer is in the comments. So they should have just implemented a wrapper ontop of libcurl. But I guess the real effort here is to promote WinHttp as a replacement for libcurl. And since the developer community at large is so used to libcurl they made a wrapper for WinHttp instead. Oh lord.
Extend.
Extinguish.
...standard MS behavior.
WinHttp itself is relatively high level, comparable to curl. Most likely this is using curl headers, but a complete custom implementation, nothing upstreamable. (Especially as Daniel probably won't like the burden of supporting a proprietary platform he doesn't have access to)
How that improves "Microsoft security requirements" is beyond me, really.
So security vulnerabilities in curl are not necessarily present here, since the two implementations would have matching forward declarations but little in common in terms of implementation.
And at the same time, missing out on the continual stream of bugs that are being put in. (I found it interesting how Daniel was able to give such a positive spin to the comment, "We merge bugfixes at a rate of around three bugfixes per day.")
C:\Windows\System32\curl.exe
failing handshakes with such HTTP2 servers, whilst any other CURL (from e.g. git-for-windows, even with lover version) could connect to the same server correctly?I think it will be somewhere in here. It will probably get installed on your PC with this thing.
https://github.com/microsoft/GDK
edit: you can see references to xurl.dll and xurl.h here, which is GDK examples
https://github.com/search?q=repo%3Amicrosoft%2FXbox-GDK-Samp...
so the xcurl.dll and xurl.h is really probably in the installer.
If i remember correctly, ages ago (Windows Server 2003?) Microsoft introduced in-kernel HTTP-handling for the IIS web-server. I think it was for performance improvements with less copying between kernel- and user-space memory.
I suspect the for me unknown WinHTTP apis mentioned here could use these optimizations? Maybe that's why they mention security requirements? (Which would obviously be needed when doing parsing in the kernel.)
WinHTTP doesn't have anything to do with http.sys it just listens for HTTP requests and then hands them off to the right bits inside IIS.
WinHTTP is essentially a HTTP stack for client services running on Windows Server to allow them to make HTTP requests. It has a sibling API named WinINet which is aimed at use in desktop environments. I think the threading models are main differentiator (I been a while since I looked at this).
WinHTTP is fairly well documented:
https://learn.microsoft.com/en-us/windows/win32/winhttp/abou...
Their position on a previous name collision involving an overseas trademark sounds like "we are bigger, nobody ever confuses us for you, but we'll be sure to redirect anyone who we notice is looking for your project!"
Not sure what that says about the inverse, but since the post mentions nothing about trademark concerns, I imagine the author isn't too worried now either
Also, as explained in other comments, it's unlikely this is actually a fork of curl. It's more likely it's just a wrapper around winhttp with a curl-like API.
I didn't get that at all. It reads like he is slightly annoyed that he is getting detail requests for a half baked fork though.
[1]: https://daniel.haxx.se/blog/2016/08/19/removing-the-powershe...
That has to be good enough since Microsoft insists on having "curl" as an alias for Invoke-Webrequest.
Also, this is about the library libcurl, not a command line program that uses the library.
But curl.exe should still bring the actual curl, I think.
> It is an MIT license that I was unclever enough to slightly modify many years ago
(emphasis mine)
So legally tricky, much legal busywork. Very courageous.