Describes how the HTTP client infrastructure uses the upgraded libcurl library, including integration, transaction flow, and improved security and maintainability.
The libcurl upgrade is an internal infrastructure improvement that replaces the embedded libcurl library version 7.30 with version 8.17.0. This change aligns the HTTP client stack with modern standards for protocols, security, and maintainability. The upgrade is transparent to users; no changes to commands or configuration are required. Application components continue to function as before, preserving backward compatibility. Security updates, platform-specific features, and operational observability are maintained through integration of upstream fixes and Cisco patches.
-
The upgrade is internal and does not alter configuration workflows.
-
All existing APIs and application interactions continue to be supported.
-
Security and feature enhancements are introduced through targeted patches to the upgraded library.
Summary
The HTTP client infrastructure processes HTTP and HTTPS transactions through coordinated components that use a stable API and asynchronous communication.
-
Application component: Initiates HTTP or HTTPS operations by calling the HTTP client library API.
-
HTTP client library: Serves as the API interface and manages communication with the HTTP client process.
-
HTTP client process: Handles request and response states, session management, concurrency, and calls libcurl.
-
libcurl library: Executes protocol operations and network communication, with enhancements for XR integration.
Workflow
These stages describe the transaction flow for HTTP requests by using the upgraded libcurl library:
-
An application component, such as Smart Licensing, Install Manager, Zero Touch Provisioning, or the Copy utility, starts an HTTP or HTTPS request by calling the HTTP client library API.
-
The API remains unchanged, so existing feature components continue to work without modification.
-
The HTTP client library receives and processes the request.
-
-
The HTTP client library packages the request, adds required parameters, and sends the request asynchronously to the HTTP client process.
-
Asynchronous interprocess communication prevents operations from blocking.
-
Request details, such as VRF information and metadata, are included for execution.
-
The HTTP client process receives the prepared request.
-
-
The HTTP client process manages the request by queuing transactions and maintaining session state for multiple requests.
-
The process uses the libcurl multi interface to scale concurrent requests efficiently.
-
The process performs error handling and allocates required system resources.
-
Requests are sequenced and validated before dispatch to the communication layer. The process then prepares to call libcurl for protocol execution.
-
-
The HTTP client process calls the
curl_multi_performAPI for efficient asynchronous network operations.-
Handles XR-custom socket management, VRF context, and SSL using Cisco extensions.
-
Manages concurrency by using
selectand the libcurl multi interface.
This stage provides reliable, efficient transaction processing. Network protocol negotiation and TLS setup occur in the updated, security-patched libcurl library.
-
-
The libcurl library establishes the network connection, negotiates SSL or TLS as needed, and completes the HTTP transaction by using HTTP/1.0 or HTTP/1.1.
-
Maintains socket management, SSL via
libssl_xr/libcrypto_xr, and TCP settings. -
Security patches and protocol improvements are applied in this stage.
-
The library sends response and transaction state information to the HTTP client process.
-
-
The HTTP client process parses the libcurl response, updates transaction status, logs actions or errors, and tracks operational state.
-
Uses standardized error codes and logging to simplify troubleshooting and monitoring.
-
Makes status information available through show commands.
Transaction results are passed to the client library. The HTTP client library supplies the response and status to the application.
-
-
The application receives the response from the HTTP client library and continues normal operation.
The HTTP transaction process completes, and resources are released. No user or application-level awareness or adaptation is needed for the upgrade.
Result
The system benefits from a secure, up-to-date HTTP client infrastructure with improved protocol support, stronger security, and better operational efficiency, with no change to applications or user experience.