Northstar is a minimalist, free-software web browser implemented from scratch in C (~160k lines) and distributed under GPLv3+. It intentionally avoids upstream engines (no Gecko/WebKit/Blink) and runs as a single window, single page, single process to maximize auditability. Linux builds run behind a Landlock filesystem sandbox with PR_SET_NO_NEW_PRIVS and a default-deny seccomp filter; there is no JIT. Privacy is built in: no telemetry or update pings, on-device safe-browsing via a local SHA-256 blocklist, and partitioned cookies, storage and cache. The project emphasizes measurable specification compliance rather than inherited behavior.
Functionally it implements a broad slice of modern web platform features: an in-engine cascade and layout with flex, grid, transforms, animations, container queries and color() spaces; JavaScript via quickjs-ng (or original QuickJS), DOM/Shadow DOM, Canvas2D, WebCrypto over OpenSSL, workers, IndexedDB over SQLite, service workers, WebExtensions, HTTP/2 (HTTP/3 via libcurl/alt‑svc), image codecs via Wuffs/libavif and in-engine SVG, WebAssembly via WAMR, printing and a headless mode. Northstar 1.0.12 adds UI polish, an 8 MB engine stack and a QuickJS build. Deliberate omissions include no multi-tab/multi-window model, no WebGL/WebGPU, no H.264 or Media Source Extensions (so many streaming sites won’t play), and limited media codec support (MPEG‑1, MP3, Ogg).
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.