nordstjernen-web/nordstjernen-browser

Nordstjernen web browser. A open source web browser with dual GPL 3+ or NSL license, written from scratch in 2026.

C

161

2,198 commits

updated Oct 4, 2026

See the code

See what people are saying

SourceMessageScoreDate

Show HN: Northstar Web Browser 1.0.28

3

Oct 4, 2026

Show HN: Nordstjernen Web Browser 1.0.24

3

Sep 19, 2026

Switch to Northstar web browser: https://github.com/nordstjernen-web/nordstjernen-browser

on Actively exploited sandbox RCE in all Chromium versions

0

Sep 5, 2026

README

Nordstjernen web browser

Nordstjernen is a web browser written from scratch in C, focused on support for modern HTML, CSS and JavaScript standards. It is built in Norway.

Nordstjernen showing a Wikipedia article in the light theme

Desktop builds run on Windows, macOS, Linux, FreeBSD and NetBSD. The same engine also powers Android and iOS shells and a Java/JVM binding.

Current release: 1.0.28 (October 2026) — see Changelog.md.

Standards. Behaviour is measured against the spec text, section by section, not against another browser. The walk-through of the in-scope WHATWG HTML standard (§1–§16) in docs/HTML-compatibility.md records 140 spec rows fully implemented, 31 partial, 0 absent (July 2026), besides a handful that are non-goals by design: embed/object plugins, frame/frameset, applet/marquee, telemetry, and AI-style web APIs.

Security. Each tab's engine runs in its own sandboxed process (seccomp + Landlock on Linux) behind an IPC + shared-memory-framebuffer boundary. No JIT.

Minimalism. The core engine is about 210,000 lines of project C and headers, excluding vendored libraries and generated assets — small enough for one person to read and audit end-to-end.

See northstar-browser-gpl for the GPL-licensed sibling project.

Nordstjernen Now!

Download

PlatformDownload
WindowsWindows store
AndroidGoogle Play
Java/JVMorg.nordstjernen:nordstjernen-java on GitHub Packages (Maven)
Sourcerelease tags

Windows 10 or later is required (the GTK 4 frontend links DirectComposition). Every other platform builds from source — see "Build" below and the per-platform install notes in docs/.

Browser features

  • HTML/CSS — HTML is parsed by the in-tree lexbor engine; the CSS engine covers the modern cascade and CSSOM, Media Queries Level 4, container queries and units, flex, grid, transforms, gradients, animations and vertical writing modes.
  • Text layout — desktop builds shape text with ns-pango, a Pango fork pinned as a meson subproject that caches finished glyph strings and font metrics across layouts, so measuring and painting a run reach HarfBuzz once instead of three times. Android and iOS link the system Pango; -Dns-pango=disabled builds that path on the desktop too.
  • JavaScript on the QuickJS interpreter — DOM, Shadow DOM, observer APIs, Canvas 2D (Path2D, ImageBitmap, DOMMatrix), WebCrypto (crypto.subtle over OpenSSL), custom elements including customized built-ins (is= / {extends}), and the Navigation API for single-page routing, plus Web Workers, IndexedDB (over SQLite), WebSocket and EventSource. The engine binding is a build-time seam: an experimental V8 backend (-Djs_engine=v8, external V8 monolith, never vendored) runs page scripts with live core DOM bindings while QuickJS stays the default — see docs/V8.md. The QuickJS itself is selectable too: the in-tree quickjs-ng fork by default, or Fabrice Bellard's original QuickJS with -Dquickjs=quickjs — see docs/quickjs.md.
  • Networking over HTTP/2 with libcurl — HSTS, CSP, subresource-integrity checks, partitioned cookies, speculative subresource loading, request coalescing and a Vary-aware HTTP cache. An in-tree libnghttp2 transport backend is selectable at build time (-Dhttp_backend=nghttp2), with HTTP/3 over QUIC via ngtcp2 + nghttp3 + gnutls when present. Both backends fetch byte-identically, so the independent transports cross-check each other. See docs/http-backends.md.
  • Images and graphics — Wuffs decodes PNG/APNG, GIF, BMP, JPEG and lossy WebP; libwebp handles lossless and animated WebP; ICO and SVG are rendered in-engine, with optional AVIF and inline PDF support.
  • Media — <video> plays inline for MPEG-1 (decoded in-tree by pl_mpeg) and, when FFmpeg's libav is present at build time, WebM (VP9/VP8 + Opus/Vorbis). MSE/blob: streaming and HLS/DASH manifests play through the nordstjernen-video helper, and a <track default> WebVTT file is drawn over the video. Other codecs render a poster and play overlay. See docs/media.md.
  • WebGL / WebGPU / WebAssembly — WebGL 1/2 mapped onto OpenGL ES, on by default (docs/webgl.md); experimental navigator.gpu over external wgpu-native, built only when that library is installed and gated behind --enable-webgpu (docs/webgpu.md); the full WebAssembly JS API over a vendored WAMR interpreter (docs/webassembly.md).
  • MathML — a minimalist presentation-MathML renderer (src/mathml.c) laid out over Pango/Cairo and embedded inline on the text baseline.
  • Spell checking — optional, via Enchant: misspelled words in editable text get a red wavy underline, honouring the spellcheck attribute.
  • Safe browsing — a top-level navigation's host is checked against a local SHA-256 blocklist before it is fetched, entirely on-device; a match shows a full-page warning. Overridable via ~/.config/nordstjernen/safebrowsing.list.
  • Process-per-tab — each tab's engine runs in its own sandboxed nordstjernen-renderer process; the GTK app is a thin shell that blits the renderer's shared-memory framebuffer and forwards input over an IPC control channel, so a page can't take down the UI (docs/tab-isolation.md). --single-process runs every tab's engine in the shell process instead (docs/single-process-mode.md).
  • Privacy — no telemetry or update pings, standards-compliant client hints, local-only safe browsing, partitioned cookies and a --private session mode.
  • UI — tabs, bookmarks, history, downloads, find-in-page, printing and save-to-PDF, a JavaScript console, settings, headless mode, and a C embedding API (docs/Embedding.md). The interface is translated into 40 languages and follows the operating-system language (docs/i18n.md).
  • Extensions — initial support for simple, page-facing WebExtensions (docs/extensions.md).
  • Java/JVM — org.nordstjernen.Nordstjernen drives fetch / parse / layout / script / render from Java over a JNI bridge, or RemoteBrowser / RemotePage drive a separate renderer process so an engine crash can't take down the JVM. The fat jar is both the embedding library and a standalone Swing browser (java -jar nordstjernen-java.jar <url>). See java/README.md.

Build

sudo apt install build-essential git pkg-config meson ninja-build \
    libgtk-4-dev libepoxy-dev libcurl4-openssl-dev libssl-dev libuchardet-dev \
    libpsl-dev libsqlite3-dev libseccomp-dev libwebp-dev libsdl2-dev \
    libavformat-dev libavcodec-dev libavutil-dev libswscale-dev libswresample-dev
meson setup builddir && meson compile -C builddir
./builddir/src/gtk/nordstjernen

Windows, Fedora, openSUSE and macOS instructions are in docs/; keyboard, mouse and touch controls are in docs/Controls.md.

Dependencies

Nordstjernen is an independent engine — no upstream browser code.

Vendored in-tree, built from the main tree with no submodules: lexbor (HTML5 → DOM parser, CSS, and the WHATWG URL module), QuickJS (quickjs-ng fork, no JIT), WAMR (WebAssembly interpreter), Wuffs (memory-safe image decoding), pl_mpeg (MPEG-1 video + MP2 audio) and minimp3 (MP3). The only setup-time download is ns-pango, the text-shaping fork; -Dns-pango=disabled links the system Pango and needs no network.

Required system libraries:

LibraryMin versionRole
GTK 4≥ 4.22.1 on Windows (MSYS2 stock), ≥ 4.14 elsewhere (≥ 4.22 preferred)UI toolkit, GSK renderer
GLib / GModule, Pango(ship with GTK)core types, dynamic module loading, text shaping
libepoxy—OpenGL/ES function dispatch for WebGL
libcurl≥ 8.5 (≥ 8.11 for WebSocket)HTTP/2 networking, HSTS, cookies, native WebSocket
OpenSSL (libcrypto)—WebCrypto (crypto.subtle)
uchardet—charset detection
libpsl—public-suffix list for cookie scoping
SQLite—IndexedDB persistent storage
libwebp—animated, lossless and fallback WebP decoding
SDL2—audio output for the nordstjernen-audio helper
libseccomp— (Linux only)syscall sandbox; no-op on macOS/Windows

Optional, auto-detected or build-time-selected: FFmpeg libav* (inline WebM playback — required on Linux and Windows, auto-detected on macOS), poppler-glib (inline PDF), libavif (AVIF images), Enchant (spell checking), fontconfig / pangoft2 (extra font backends), libnghttp2 (the in-tree HTTP/2 backend), ngtcp2 + nghttp3 + GnuTLS (HTTP/3 over QUIC inside it), wgpu-native (experimental WebGPU), a V8 monolith (experimental -Djs_engine=v8) and Fabrice Bellard's original QuickJS (-Dquickjs=quickjs, fetched through a meson wrap).

License

Nordstjernen is dual-licensed: use it under either the Nordstjernen Source License v1.0 or the GNU General Public License version 3 or later, at your option (LicenseRef-NSL-1.0 OR GPL-3.0-or-later).

  • GPL-3.0-or-later — free software: use, modify and redistribute it for any purpose, provided derivative works are also released under the GPL. See COPYING.
  • NSL-1.0 — use, modify and redistribute freely, except as a competing browser; each release becomes MIT after ten years. It is inspired by the Functional Source License.

See License.md for the full terms. Commercial licenses by agreement. Bundled third-party components keep their own licenses (THIRD-PARTY-LICENSES.md).

Project home: https://nordstjernen.org · Copyright 2026 Andreas Røsdal · Join the Discord

Builds

linux macos windows android java

Best viewed in Nordstjernen
browser
c
css
html
java
javascript
nordstjernen
northstar
northstar-browser
web
web-browser

Significant stargazers

Kenta Moriuchi

152 followers · starred May 2026

文宇祥

328 followers · starred Jun 2026

Dialga

62 followers · starred Jul 2026

Alexander Wennerstrøm

18 followers · starred Jun 2026

nordstjernen-web/nordstjernen-browser

Nordstjernen web browser. A open source web browser with dual GPL 3+ or NSL license, written from scratch in 2026.

C

161

2,198 commits

updated Oct 4, 2026

See the code

See what people are saying

SourceMessageScoreDate

Show HN: Northstar Web Browser 1.0.28

3

Oct 4, 2026

Show HN: Nordstjernen Web Browser 1.0.24

3

Sep 19, 2026

Switch to Northstar web browser: https://github.com/nordstjernen-web/nordstjernen-browser

on Actively exploited sandbox RCE in all Chromium versions

0

Sep 5, 2026

README

Nordstjernen web browser

Nordstjernen is a web browser written from scratch in C, focused on support for modern HTML, CSS and JavaScript standards. It is built in Norway.

Nordstjernen showing a Wikipedia article in the light theme

Desktop builds run on Windows, macOS, Linux, FreeBSD and NetBSD. The same engine also powers Android and iOS shells and a Java/JVM binding.

Current release: 1.0.28 (October 2026) — see Changelog.md.

Standards. Behaviour is measured against the spec text, section by section, not against another browser. The walk-through of the in-scope WHATWG HTML standard (§1–§16) in docs/HTML-compatibility.md records 140 spec rows fully implemented, 31 partial, 0 absent (July 2026), besides a handful that are non-goals by design: embed/object plugins, frame/frameset, applet/marquee, telemetry, and AI-style web APIs.

Security. Each tab's engine runs in its own sandboxed process (seccomp + Landlock on Linux) behind an IPC + shared-memory-framebuffer boundary. No JIT.

Minimalism. The core engine is about 210,000 lines of project C and headers, excluding vendored libraries and generated assets — small enough for one person to read and audit end-to-end.

See northstar-browser-gpl for the GPL-licensed sibling project.

Nordstjernen Now!

Download

PlatformDownload
WindowsWindows store
AndroidGoogle Play
Java/JVMorg.nordstjernen:nordstjernen-java on GitHub Packages (Maven)
Sourcerelease tags

Windows 10 or later is required (the GTK 4 frontend links DirectComposition). Every other platform builds from source — see "Build" below and the per-platform install notes in docs/.

Browser features

  • HTML/CSS — HTML is parsed by the in-tree lexbor engine; the CSS engine covers the modern cascade and CSSOM, Media Queries Level 4, container queries and units, flex, grid, transforms, gradients, animations and vertical writing modes.
  • Text layout — desktop builds shape text with ns-pango, a Pango fork pinned as a meson subproject that caches finished glyph strings and font metrics across layouts, so measuring and painting a run reach HarfBuzz once instead of three times. Android and iOS link the system Pango; -Dns-pango=disabled builds that path on the desktop too.
  • JavaScript on the QuickJS interpreter — DOM, Shadow DOM, observer APIs, Canvas 2D (Path2D, ImageBitmap, DOMMatrix), WebCrypto (crypto.subtle over OpenSSL), custom elements including customized built-ins (is= / {extends}), and the Navigation API for single-page routing, plus Web Workers, IndexedDB (over SQLite), WebSocket and EventSource. The engine binding is a build-time seam: an experimental V8 backend (-Djs_engine=v8, external V8 monolith, never vendored) runs page scripts with live core DOM bindings while QuickJS stays the default — see docs/V8.md. The QuickJS itself is selectable too: the in-tree quickjs-ng fork by default, or Fabrice Bellard's original QuickJS with -Dquickjs=quickjs — see docs/quickjs.md.
  • Networking over HTTP/2 with libcurl — HSTS, CSP, subresource-integrity checks, partitioned cookies, speculative subresource loading, request coalescing and a Vary-aware HTTP cache. An in-tree libnghttp2 transport backend is selectable at build time (-Dhttp_backend=nghttp2), with HTTP/3 over QUIC via ngtcp2 + nghttp3 + gnutls when present. Both backends fetch byte-identically, so the independent transports cross-check each other. See docs/http-backends.md.
  • Images and graphics — Wuffs decodes PNG/APNG, GIF, BMP, JPEG and lossy WebP; libwebp handles lossless and animated WebP; ICO and SVG are rendered in-engine, with optional AVIF and inline PDF support.
  • Media — <video> plays inline for MPEG-1 (decoded in-tree by pl_mpeg) and, when FFmpeg's libav is present at build time, WebM (VP9/VP8 + Opus/Vorbis). MSE/blob: streaming and HLS/DASH manifests play through the nordstjernen-video helper, and a <track default> WebVTT file is drawn over the video. Other codecs render a poster and play overlay. See docs/media.md.
  • WebGL / WebGPU / WebAssembly — WebGL 1/2 mapped onto OpenGL ES, on by default (docs/webgl.md); experimental navigator.gpu over external wgpu-native, built only when that library is installed and gated behind --enable-webgpu (docs/webgpu.md); the full WebAssembly JS API over a vendored WAMR interpreter (docs/webassembly.md).
  • MathML — a minimalist presentation-MathML renderer (src/mathml.c) laid out over Pango/Cairo and embedded inline on the text baseline.
  • Spell checking — optional, via Enchant: misspelled words in editable text get a red wavy underline, honouring the spellcheck attribute.
  • Safe browsing — a top-level navigation's host is checked against a local SHA-256 blocklist before it is fetched, entirely on-device; a match shows a full-page warning. Overridable via ~/.config/nordstjernen/safebrowsing.list.
  • Process-per-tab — each tab's engine runs in its own sandboxed nordstjernen-renderer process; the GTK app is a thin shell that blits the renderer's shared-memory framebuffer and forwards input over an IPC control channel, so a page can't take down the UI (docs/tab-isolation.md). --single-process runs every tab's engine in the shell process instead (docs/single-process-mode.md).
  • Privacy — no telemetry or update pings, standards-compliant client hints, local-only safe browsing, partitioned cookies and a --private session mode.
  • UI — tabs, bookmarks, history, downloads, find-in-page, printing and save-to-PDF, a JavaScript console, settings, headless mode, and a C embedding API (docs/Embedding.md). The interface is translated into 40 languages and follows the operating-system language (docs/i18n.md).
  • Extensions — initial support for simple, page-facing WebExtensions (docs/extensions.md).
  • Java/JVM — org.nordstjernen.Nordstjernen drives fetch / parse / layout / script / render from Java over a JNI bridge, or RemoteBrowser / RemotePage drive a separate renderer process so an engine crash can't take down the JVM. The fat jar is both the embedding library and a standalone Swing browser (java -jar nordstjernen-java.jar <url>). See java/README.md.

Build

sudo apt install build-essential git pkg-config meson ninja-build \
    libgtk-4-dev libepoxy-dev libcurl4-openssl-dev libssl-dev libuchardet-dev \
    libpsl-dev libsqlite3-dev libseccomp-dev libwebp-dev libsdl2-dev \
    libavformat-dev libavcodec-dev libavutil-dev libswscale-dev libswresample-dev
meson setup builddir && meson compile -C builddir
./builddir/src/gtk/nordstjernen

Windows, Fedora, openSUSE and macOS instructions are in docs/; keyboard, mouse and touch controls are in docs/Controls.md.

Dependencies

Nordstjernen is an independent engine — no upstream browser code.

Vendored in-tree, built from the main tree with no submodules: lexbor (HTML5 → DOM parser, CSS, and the WHATWG URL module), QuickJS (quickjs-ng fork, no JIT), WAMR (WebAssembly interpreter), Wuffs (memory-safe image decoding), pl_mpeg (MPEG-1 video + MP2 audio) and minimp3 (MP3). The only setup-time download is ns-pango, the text-shaping fork; -Dns-pango=disabled links the system Pango and needs no network.

Required system libraries:

LibraryMin versionRole
GTK 4≥ 4.22.1 on Windows (MSYS2 stock), ≥ 4.14 elsewhere (≥ 4.22 preferred)UI toolkit, GSK renderer
GLib / GModule, Pango(ship with GTK)core types, dynamic module loading, text shaping
libepoxy—OpenGL/ES function dispatch for WebGL
libcurl≥ 8.5 (≥ 8.11 for WebSocket)HTTP/2 networking, HSTS, cookies, native WebSocket
OpenSSL (libcrypto)—WebCrypto (crypto.subtle)
uchardet—charset detection
libpsl—public-suffix list for cookie scoping
SQLite—IndexedDB persistent storage
libwebp—animated, lossless and fallback WebP decoding
SDL2—audio output for the nordstjernen-audio helper
libseccomp— (Linux only)syscall sandbox; no-op on macOS/Windows

Optional, auto-detected or build-time-selected: FFmpeg libav* (inline WebM playback — required on Linux and Windows, auto-detected on macOS), poppler-glib (inline PDF), libavif (AVIF images), Enchant (spell checking), fontconfig / pangoft2 (extra font backends), libnghttp2 (the in-tree HTTP/2 backend), ngtcp2 + nghttp3 + GnuTLS (HTTP/3 over QUIC inside it), wgpu-native (experimental WebGPU), a V8 monolith (experimental -Djs_engine=v8) and Fabrice Bellard's original QuickJS (-Dquickjs=quickjs, fetched through a meson wrap).

License

Nordstjernen is dual-licensed: use it under either the Nordstjernen Source License v1.0 or the GNU General Public License version 3 or later, at your option (LicenseRef-NSL-1.0 OR GPL-3.0-or-later).

  • GPL-3.0-or-later — free software: use, modify and redistribute it for any purpose, provided derivative works are also released under the GPL. See COPYING.
  • NSL-1.0 — use, modify and redistribute freely, except as a competing browser; each release becomes MIT after ten years. It is inspired by the Functional Source License.

See License.md for the full terms. Commercial licenses by agreement. Bundled third-party components keep their own licenses (THIRD-PARTY-LICENSES.md).

Project home: https://nordstjernen.org · Copyright 2026 Andreas Røsdal · Join the Discord

Builds

linux macos windows android java

Best viewed in Nordstjernen
browser
c
css
html
java
javascript
nordstjernen
northstar
northstar-browser
web
web-browser

Significant stargazers

Kenta Moriuchi

152 followers · starred May 2026

文宇祥

328 followers · starred Jun 2026

Dialga

62 followers · starred Jul 2026

Alexander Wennerstrøm

18 followers · starred Jun 2026

Languages

C

93.9%

JavaScript

2.8%