Skip to content
CAI
Software that uses CAICheck a score

dtolnay/cxx

60.2

Adequate · 29 September 2026

19.2k

lines of production code

Rust

with C

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the CXX library, a tool for generating safe, zero-cost Foreign Function Interface (FFI) bindings between Rust and C++. It provides a macro-driven bridge that allows Rust and C++ code to share structs, enums, and functions while managing memory ownership through smart pointers like UniquePtr and SharedPtr. The project includes a code generator, build script integrations for Cargo and Bazel, and a runtime library that handles type conversions and exception safety across the language boundary.

How it got here

2020 — Rust 2024 migration and cxxbridge1 overhaul

25 changes.

The project upgraded to Rust 2024 edition and syn 3, while introducing the cxxbridge1 namespace with significant API changes including no-std support and improved exception handling. The cxxbridge command-line tool and legacy demo code were removed, replaced by a restructured macro crate and new FFI test suites. Infrastructure was modernized with Bazel and Buck support, and comprehensive documentation and development environment configurations were added.

2021–2026 — Build system centralization and analytics integration

7 changes.

This period focused on centralizing the Buck2 toolchain configuration for C++ and Rust while restructuring the CXX code generator into a modular bridge crate. Concurrently, the project integrated GDPR-compliant Google Analytics 4 tracking into the book theme and updated third-party dependencies to align with newer Rust editions.

Features

Add C++ header for BlobstoreClient

A new header file (demo/include/blobstore.h) is introduced, defining the C++ interface for the BlobstoreClient. This header exposes methods for putting data, tagging blobs, and retrieving metadata, along with a factory function to create client instances, enabling C++ code to interact with the blobstore service.

demo/include · high confidence

Add GitHub Codespaces dev container configuration

Developers can now use GitHub Codespaces to run the project in a pre-configured cloud environment. This change introduces a new .devcontainer directory containing a Dockerfile based on dtolnay/devcontainer, a build.Dockerfile that installs Rust, Clang, LLD, Zstd, Bazel (via bazelisk), Buck2, Buildifier, and Rust analyzer components, and a devcontainer.json that configures VS Code with C++ tools, Bazel extensions, and LLDB debugging capabilities.

.devcontainer · high confidence

Add mdBook-based documentation site with custom build and styling

Introduces a new documentation book located in the \book/\ directory, built using mdBook. The setup includes a \book.toml\ configuration for the CXX library, a \build.sh\ script to orchestrate the build process, and a \build.js\ script that post-processes the generated HTML. This post-processing adds Open Graph and Twitter metadata, injects a GitHub link into the sidebar, applies syntax highlighting via highlight.js, and implements custom CSS styles for hiding boring lines and managing code visibility. The entry also includes ESLint configuration for the build scripts and a README for local development.

book · high confidence

Macro implementation refactored with new module structure and expanded derive support

The macro crate has been restructured into distinct modules (attrs, cfg, derive, generics, tests, tokens, type\_id) to improve code organization and maintainability. This change introduces comprehensive support for deriving standard traits (Copy, Clone, Debug, Default, Eq, PartialEq, Ord, PartialOrd, Hash) and serialization traits (Serialize, Deserialize) on shared structs and enums, automatically generating the necessary implementations. It also adds support for bitwise operation derives (BitAnd, BitOr, BitXor) on enums. The macro now processes outer attributes on the bridge module, propagating cfg, lint, and passthrough attributes to generated code. Lifetime handling has been improved to correctly preserve and elide lifetimes in generated impl blocks, and the namespace attribute syntax has been updated to accept quoted paths. Additionally, the macro now supports parsing pinned UniquePtrs and generates code to enforce Unpin constraints where necessary.

macro/src · high confidence

New syntax tree modules for parsing and type resolution

The syntax crate now includes dedicated modules for parsing and representing the bridge module structure (\file.rs\), handling derive attributes (\derive.rs\), managing namespaces (\namespace.rs\), and resolving types (\resolve.rs\, \instantiate.rs\). It also introduces modules for computing mangled symbols (\mangle.rs\), checking improper C types (\improper.rs\), and validating POD types (\pod.rs\). These changes provide a more structured and modular foundation for the CXX bridge parser, enabling better error reporting and type checking.

syntax · high confidence

Removals

Remove gen module and associated error handling infrastructure

The \gen\ module and its supporting files (\error.rs\, \include.rs\, \mod.rs\, \out.rs\, \write.rs\) have been deleted. This removes the internal code generation logic, error formatting utilities, and output file handling previously located in this directory.

gen · high confidence

Removed C++ demo implementation files

The C++ demo implementation files (demo.cc and demo.h) have been removed from the demo-cxx directory. This eliminates the previous C++ code that defined the ThingC class and associated FFI bindings, effectively removing this specific C++ demonstration component from the project.

demo-cxx · high confidence

Removed Rust/C++ interop demo code

The Rust/C++ interop demonstration code in \demo-rs/src/main.rs\ has been removed. This file previously contained the \cxx\ bridge definitions and logic for calling C++ methods from Rust and vice versa, including handling of \std::vector\ and \std::vec::Vec\. Its removal eliminates this specific example of safe FFI usage from the project.

demo-rs/src · high confidence

Removed cmd binary and associated modules

The \cmd\ directory's main binary (\main.rs\), its \gen\ module, and \syntax\ module have been deleted. This removes the standalone \cxxbridge\ command-line tool that previously accepted an input Rust source file and emitted either a header or a bridge implementation to stdout.

cmd · high confidence

Behavioural changes

Add C++ standard version flag and license files to flags crate

The \flags\ crate now includes symbolic links to the project's Apache-2.0 and MIT license files, ensuring they are included in the crate distribution. Additionally, the crate exposes a \STD\ constant that allows consumers to select the C++ standard version (defaulting to C++11, with options for C++14, C++17, or C++20) via Cargo features, facilitating consistent C++ standard configuration across dependent crates like \cxx\ and \cxx-build\.

flags · high confidence

Add Google Analytics 4 tracking with GDPR-compliant settings

The book theme now includes a new head.hbs template that injects the Google Analytics 4 global site tag (ID: G-DG41MK6DDN). This integration configures the tracker to anonymize IP addresses and sets the SameSite attribute to 'strict' with the 'secure' flag, ensuring analytics data collection complies with GDPR requirements without requiring explicit cookie consent.

book/theme · high confidence

CXX code generator restructured into dedicated bridge crate

The CXX code generator has been reorganized into a new \bridge\ crate, exposing three distinct integration points: a \cmd\ binary (\cxxbridge\) for command-line usage, a \build\ crate for \build.rs\ integration, and a \lib\ crate for embedding in higher-level code generators. This change also includes the addition of comprehensive C++ builtin headers (such as \shared\_ptr\, \vector\, and \trycatch\) and a new \cfg\ evaluation system that allows conditional compilation of generated code based on build configuration flags.

bridge · high confidence

Centralized Buck2 toolchain configuration for C++, Rust, and testing

The build system now defines a consolidated set of Buck2 toolchains in the \tools/buck/toolchains\ module. This configuration explicitly sets C++17 as the standard for Linux and macOS builds, enables exception handling (\/EHsc\) for Windows C++ builds, and links the standard C++ library (\-lstdc++\/\-lc++\) on Unix systems. For Rust, the toolchain is configured to use the default edition and enables doctests. Additionally, the setup includes toolchains for system genrules, Python bootstrapping, a no-op test toolchain, and remote test execution, providing a unified entry point for these build capabilities.

tools/buck/toolchains · high confidence

Demo now uses a C++ blobstore client instead of the previous implementation

The demo application has been updated to demonstrate interop with a C++ blobstore client. The Rust side now defines the FFI bindings via cxx to call into a new C++ implementation (blobstore.cc) that manages an in-memory store of blobs and tags, replacing the prior approach.

demo/src · high confidence

Demo project build configuration updated to Rust 2024 edition

The demo application's build files (BUCK, BUILD.bazel, and build.rs) have been consolidated and updated to use the Rust 2024 edition. This change aligns the Bazel and Buck build definitions, switching Bazel to use \link\_deps\ for linking C++ dependencies and ensuring consistent linkage behavior. The demo now explicitly targets the 2024 Rust edition and uses a unified bridge configuration via \rust\_cxx\_bridge\ for both Bazel and Buck, while Cargo continues to use \cxx\_build\ with C++14 standard.

demo · high confidence

The build process now provides clearer, platform-specific guidance when \cxx\ is compiled from a git clone and symlink support is missing or denied. On Windows, if Developer Mode is not enabled or symlinks are disabled, the build fails with a specific message instructing users how to enable Developer Mode or configure git to handle symlinks correctly. This change distinguishes between general symlink absence and permission-denied scenarios, helping users resolve build failures more easily when working from a local repository clone rather than a crates.io package.

tools/cargo · high confidence

Major API overhaul: new namespace, C++ exception handling, and no-std support

This release introduces a comprehensive overhaul of the CXX runtime. The C++ namespace has been bumped to \cxxbridge1\ (previously \cxxbridge00\), requiring a rebuild of C++ code. Exception handling is now automatically detected: if the compiler lacks exception support, the \RUST\_CXX\_NO\_EXCEPTIONS\ flag is set and panics abort via stderr instead of throwing. The crate now supports \no\_std\ and \no\_alloc\ environments, with the \alloc\ feature gate controlling standard library dependencies. The \cxxbridge.cc\ implementation has been removed in favor of a new \cxx.cc\ and Rust-side runtime modules (\exception.rs\, \result.rs\, \weak\_ptr.rs\, etc.). The \let\_cxx\_string\ macro now returns a \Pin\<&mut CxxString\>\, and \CxxString\ methods like \push\ and \clear\ require pinned mutable references. \WeakPtr\ bindings for C++ \std::weak\_ptr\ are now available, along with improved error handling via the new \Exception\ type.

src · high confidence

New C++ ABI symbols for Rust string, slice, and vector types

The \src/symbols\ module now provides the concrete C-compatible symbol implementations for \rust::String\, \rust::Slice\, \rust::Vec\, and \&str\. This includes new entry points for initializing strings from UTF-8 and UTF-16 (including lossy variants), accessing capacity and reserving memory, and managing vector lifecycles (new, drop, truncate, reserve). These symbols enable C++ code to interact with Rust's standard collection types through the updated ABI.

src/symbols · high confidence

Removal of custom C++ build configuration in demo-rs

The custom build script (build.rs) that previously compiled the C++ source files (demo.cc) with the C++11 standard and linked them into the Rust demo application has been removed. This change indicates a shift in how the C++ components are integrated or built, likely deferring to external build systems or crate defaults, which may affect how the demo is compiled locally if it relied on this specific build.rs logic.

demo-rs · medium confidence

Renamed and reorganized C++ types in the rust namespace

The C++ header \include/cxx.h\ introduces the current \rust::cxxbridge1\ namespace, replacing the legacy \cxxbridge00\ namespace defined in the now-deleted \include/cxxbridge.h\. This change renames \RustString\ to \String\, \RustStr\ to \Str\, and \RustBox\ to \Box\, while also adding new capabilities such as \std::string\_view\ conversion for \Str\ (C++17), lossy Unicode constructors for \String\, and iterators for \Str\, \String\, and \Slice\.

include · high confidence

Restructure macro crate with symlinked license files and shared build script

The macro crate now includes symlinked LICENSE-APACHE and LICENSE-MIT files pointing to the parent directory, ensuring license visibility in the package. A new README.md clarifies that this crate contains the Rust code generator procedural macro and is not intended for direct user dependency, but rather invoked via the main cxx crate. The build.rs file now includes a shared build script from the tools directory, centralizing build logic.

macro · high confidence

Switched overview diagram generation to LaTeX/TikZ

The build process for the book's overview diagram has been updated to generate the image from a new LaTeX source file (overview.tex) using TikZ, replacing the previous SVG-based approach. A new Makefile and .gitignore have been added to automate the compilation of the diagram into PDF, SVG, and PNG formats, ensuring consistent rendering of the architecture visualization.

book/diagram · high confidence

Third-party crate restructured to use lib.rs

The third-party crate's source root has been consolidated into a single lib.rs file, replacing the previous directory structure. This change affects how the library's public API is exposed and organized within the project.

third-party/src · low confidence

Upgrade minimum Rust version to 1.88 and migrate to Rust 2024 edition

The project now requires Rust 1.88 or newer and has updated its build targets to use the Rust 2024 edition. This change is enforced in the build script (build.rs), which checks the compiler version and emits a warning if the requirement is not met, and is reflected in the Bazel and Buck build definitions where all Rust targets now specify edition = "2024". Additionally, the Travis CI configuration has been removed, and the README has been updated to reflect the new compiler requirements and the updated example code.

(repo-wide) · high confidence

cxx-build 1.0.202: New build script API and improved header export handling

The \cxx-build\ crate has been updated to version 1.0.202, introducing a new \bridge\ and \bridges\ API for constructing C++ builds from Cargo build scripts. This release adds support for configuring exported header directories and prefixes via the \CFG\ global, allowing downstream crates to correctly \\#include\ headers from direct dependencies. It also improves robustness by tolerating unavailable shared header directories and handling case-insensitive configuration evaluation for Cargo features.

bridge/build · high confidence

Test coverage

Add Bazel and Buck build targets for the test suite; Added C++ compilation smoke tests; Comprehensive FFI test suite for CXX bridge capabilities; Expanded UI test coverage for cxx::bridge validation.

Dependencies

Third-party dependencies now managed via reindeer-generated Buck targets and Bazel crates\_vendor

The third-party dependency management has shifted to use the reindeer tool for generating Buck build targets (BUCK) and a Bazel configuration (BUILD.bazel) using crates\_vendor. This change introduces explicit http\_archive definitions for crates like clap 4.6.6, cc 1.4.5, and codespan-reporting 0.13.1, replacing previous vendoring or manual target setups. A .gitignore file is added to exclude generated /target and /vendor directories, ensuring clean version control of the build infrastructure.

third-party · high confidence

Updated third-party Rust dependencies and Bazel build rules

The third-party Bazel build files have been regenerated to update several Rust crate dependencies, including syn to version 3.0.5, clap to 4.6.6, and foldhash to 0.2.0. Additionally, the Rust edition for several crates (such as clap, clap\_builder, clap\_lex, and indexmap) has been upgraded to 2024, and the codespan-reporting dependency has been updated to version 0.13.1.

third-party/bazel · high confidence

cxx 1.0.202: Rust 2024 edition, syn 3, and dependency overhaul

The cxx crate and its sub-crates (cxx-build, cxx-gen, cxxbridge-cmd) have been updated to version 1.0.202, adopting the Rust 2024 edition and raising the minimum supported Rust version to 1.88. This release migrates the core dependency from syn 1 to syn 3, replaces the structopt argument parser with clap 4, and swaps the error handling library from thiserror to handwritten implementations. Additionally, the codebase now uses foldhash for hashing, indexmap for ordered maps, and scratch for temporary directories, while removing older dependencies like codespan, anyhow, and rustversion. The project structure has also been reorganized, with the command-line tool moved to bridge/cmd and the demo renamed to demo.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 65 → 60 (-5.3)
  • Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 82 → 82 (+0.0)
  • Architecture 98 → 95 (-2.7)
  • Maturity 60 → 61 (+0.2)
  • Readiness 63 → 48 (-14.3)
  • Security 63 → 76 (+13.3)

Resolved (10)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Hotspot: bridge/src/cfg.rs (bridge/src/cfg.rs)
  • Hotspot: bridge/src/write.rs (bridge/src/write.rs)
  • Hotspot: macro/src/derive.rs (macro/src/derive.rs)
  • Hotspot: macro/src/expand.rs (macro/src/expand.rs)
  • Hotspot: syntax/attrs.rs (syntax/attrs.rs)
  • Hotspot: syntax/check.rs (syntax/check.rs)
  • Hotspot: syntax/types.rs (syntax/types.rs)
  • TooManyFields: Builtins (bridge/src/builtin.rs)

New (11)

  • Ambiguous distinction between as_string and into_string. Typically as_ implies borrowing (returning &str) and into_ implies consuming (returning String). Here, both return String, suggesting as_string might be a copy or the naming is misleading regarding ownership semantics.
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Inverted test pyramid
  • Low cohesion: SharedPtr (LCOM4 5) (src/shared_ptr.rs)
  • Medium CVE: [GHSA redacted] (book/package-lock.json)
  • Off the main sequence: cxx-build
  • Off the main sequence: cxxbridge-cmd
  • Projects may be oversized for their cohesion
  • Redundant constructors with ambiguous intent. from_ref and from_mut take owned String arguments, which contradicts the naming convention of ref/mut implying borrowing. Furthermore, from and from_ref appear to have identical signatures and likely identical behavior, creating unnecessary duplication.
  • Same ambiguity as RustString. Both return T (likely Vec<T>), making it unclear if as_vec borrows or copies. Standard Rust conventions use as_slice/as_ref for borrowing and into_vec for consuming.
  • Same redundancy and naming confusion as RustString. from_ref/from_mut taking owned types is confusing, and from vs from_ref likely duplicates functionality.

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • tests/ui — 2 commits

Notable commits

  • change: Update ui test suite to nightly-2026-09-22
  • change: Update ui test suite to nightly-2026-09-26

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

dtolnay/cxx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b2971717da380618ea8ab5a3bf9ee68434e1f684 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.