mozilla/sccache
71.1
Strong · 29 September 2026
41.7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a distributed compilation caching service that accelerates build processes by storing and retrieving compiler artifacts across local and remote storage backends. It supports multi-level caching with automatic backfilling, allowing clients to bypass the central server for direct cache access while maintaining a distributed architecture for remote execution. The system integrates with various compilers and cloud storage providers, featuring robust authentication mechanisms and comprehensive testing infrastructure to ensure reliability across different operating systems and build environments.
How it got here
2014–2016 — Client-side caching and multi-level storage
6 changes.
The project introduced a client-side mode allowing direct cache access, bypassing the background server for storage operations. It also implemented multi-level caching with automatic backfilling to optimize hit rates across different storage backends. These features were supported by a comprehensive refactor of compiler execution into a unified trait and the establishment of robust test infrastructure.
2017–2018 — distributed compilation infrastructure
5 changes.
This period focused on implementing the core infrastructure for distributed compilation, including toolchain packaging, HTTP abstractions, and OAuth/PKCE authentication. It also expanded platform support to FreeBSD using container isolation and introduced comprehensive integration tests to validate the new distributed features across various compilers and environments.
2021–2026 — Infrastructure and testing expansion
7 changes.
This period focused on establishing the core LRU disk cache implementation and refactoring the sccache-dist CLI for better usability. It also involved significant investment in test infrastructure, including Docker-based integration suites, performance benchmarks, and helpers to ensure robustness across various storage backends and build tools.
Features
Add FreeBSD CI test script and extended test runner
Introduces \scripts/freebsd-ci-test.sh\ to automate end-to-end distributed compilation testing on FreeBSD, including setting up a ZFS-backed \pot\ environment, configuring \sccache-dist\ schedulers and servers, and verifying cache usage. Additionally, adds \scripts/extratest.sh\ to run comprehensive \cargo check\ suites across multiple feature combinations (dist-client, dist-server, dist-tests) for both Linux and Windows targets.
scripts · high confidence
Distributed compilation support for FreeBSD and enhanced client authentication
The sccache-dist server now supports distributed compilation on FreeBSD, utilizing the 'pot' container system for build isolation alongside the existing Linux bubblewrap implementation. Additionally, the scheduler's client authentication has been expanded to support multiple strategies, including fixed tokens, JWT validation against a JWKS endpoint, and proxy-based token forwarding, allowing for more flexible and secure integration with identity providers.
src/bin/sccache-dist · high confidence
Introduce client-side mode with direct cache access
sccache now supports a client-side mode where the client binary can directly access the cache storage backend, bypassing the need for a long-running background server for cache operations. This is implemented via new \StorageHandshake\, \StorageGetPath\, \StorageGetRaw\, and \StoragePutRaw\ RPCs in the protocol, allowing the client to fetch and store cache entries directly. The server still handles compilation execution, but the client can now act as a cache client independently, improving reliability and reducing server dependency for cache lookups.
src · high confidence
Introduce distributed compilation support with OAuth/PKCE authentication and toolchain packaging
This change adds the core infrastructure for distributed compilation. It introduces a client-side toolchain cache (\src/dist/cache.rs\) that manages custom toolchain overrides, disabled toolchains, and weak/strong hash mapping for integrity verification. It implements PKCE-based OAuth client authentication (\src/dist/client\_auth.rs\) to secure communication with the scheduler. The module also provides HTTP client/server abstractions (\src/dist/http.rs\) for binary protocol communication, platform-specific path transformation for Windows (\src/dist/mod.rs\), and toolchain packaging logic (\src/dist/pkg.rs\) that bundles compiler executables and their dynamic library dependencies into tar archives for remote execution.
src/dist · high confidence
New multi-level caching with fallback and backfilling
The cache subsystem now supports multi-level storage chains, allowing you to combine multiple backends (such as local disk, Redis, S3, or GCS) into a single cache. The system reads from faster levels first and automatically backfills slower levels with data found in deeper tiers, improving hit rates and reducing latency for remote storage. This is implemented via the new \MultiLevelStorage\ and \MultiLevelStats\ components in \src/cache/multilevel.rs\, which coordinate the fallback logic and expose per-level statistics.
src/cache · high confidence
Repository initialization and development environment setup
The repository is initialized with essential configuration files to standardize the development workflow and packaging. A Nix flake (flake.nix) and its lock file are added to provide reproducible build environments and package definitions for sccache and sccache-dist across multiple platforms. Development tooling is configured via .pre-commit-config.yaml (running rustfmt and clippy), .rustfmt.toml (setting edition 2024), and .taplo.toml (formatting TOML files). Project governance and contributor guidelines are established through AGENTS.md and CODE\_OF\_CONDUCT.md. Additionally, .envrc is added to support nix-direnv integration, and .gitignore is updated to exclude build artifacts, lockfiles, and IDE files. The legacy Python-based sccache.py script is removed.
(repo-wide) · high confidence
Architecture
Refactor compiler implementations to use a unified CompileCommand trait
The compiler subsystem has been refactored to replace the previous compilation execution model with a new \CompileCommand\ trait and its \CCompileCommand\ wrapper. This change introduces a standardized interface for executing compiler invocations, allowing compiler-specific logic in \clang.rs\, \gcc.rs\, \msvc.rs\, and others to delegate command generation and execution through this trait. This unification simplifies how different compilers (GCC, Clang, MSVC, NVCC, etc.) are integrated into the caching and distributed compilation pipelines by providing a consistent abstraction for compile commands.
src/compiler · high confidence
Behavioural changes
Internal LRU disk cache implementation and module structure
The \src/lru\_disk\_cache\ location now contains the core implementation of the LRU disk cache, including the \LruDiskCache\ struct for managing file storage on disk with size limits and the \LruCache\ generic LRU data structure. This change introduces the underlying caching logic, file I/O handling via \fs\_err\, and the module hierarchy (\mod.rs\ and \lru\_cache.rs\) that supports the cache's functionality, such as tracking file sizes and managing eviction based on last-modified times.
_src/lru\_disk\cache · medium confidence
Redesigned sccache-dist CLI with explicit subcommands and improved token generation options
The command-line interface for sccache-dist has been refactored to use the clap builder API, introducing explicit subcommands for authentication, scheduler, and server modes. Users can now generate JWT HS256 server tokens with specific server addresses and secret keys, or generate shared tokens with configurable bit lengths (defaulting to 256 bits, with validation ensuring divisibility by 8 and bounds between 64 and 4096 bits). The CLI also enforces mutual exclusion between config file paths and direct secret key arguments for token generation, and provides clearer error messages for invalid token bit lengths.
src/bin/sccache-dist/cmdline · high confidence
Test coverage
Added MSBuild C++ test project; Added integration test library to randomize directory listing order; Added performance benchmarks for sccache core operations; Added test harness for distributed compilation scenarios; Added test helper infrastructure for sccache integration testing; Added test infrastructure with mock storage and server utilities; Expanded test coverage for sccache functionality; New Docker-based integration test suite for sccache.
Dependencies
Update to Rust 2024 edition and MSRV 1.91
The project has been upgraded to the Rust 2024 edition and the minimum supported Rust version (MSRV) is now 1.91.0. This change requires users to compile sccache with a newer Rust toolchain and may involve updating dependencies to versions compatible with the new edition and compiler version.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 66 → 71 (+5.3)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 82 → 82 (+0.4)
- Architecture 100 → 89 (-11.2)
- Maturity 74 → 73 (-0.3)
- Readiness 75 → 72 (-2.8)
- Security 51 → 65 (+13.7)
- Performance 100 (new)
Resolved (9)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: src/bin/sccache-dist/main.rs (src/bin/sccache-dist/main.rs)
- Hotspot: src/cache/multilevel.rs (src/cache/multilevel.rs)
- Hotspot: src/compiler/compiler.rs (src/compiler/compiler.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/compiler/cicc.rs)
- Off-boarding risk: anonymized user #1
- sccache::compiler::gcc::preprocess_cmd (cognitive 16) (src/compiler/gcc.rs)
New (43)
- Ambiguous and overlapping read operations. get and get_with_raw appear to serve similar purposes (retrieving data), but the distinction between 'raw' and non-raw is unclear. Furthermore, get_raw exists separately, creating a triad of read methods with unclear semantic boundaries. It is unclear if get returns deserialized objects while get_raw returns bytes, or if get_with_raw is an alias for one of them.
- Documentation: no project overview (README.md)
- Duplicate intent in TcCache. get and get_file have nearly identical signatures and likely return the same type (LruResult). It is unclear why there are two methods for retrieving a toolchain, unless one returns a file handle and the other returns a path or bytes, but the return type LruResult is opaque and suggests identical behavior.
- Flaky test: sccache::system.test_stats_no_server
- Further sole-owners (lower concentration)
- Inconsistent naming for write operations. put takes a structured CacheWrite object, while put_raw takes raw bytes. While the distinction is logical, the naming convention put vs put_raw is less standard than put vs put_bytes or store vs store_raw. More importantly, get vs get_raw inconsistency (see above) suggests a broader pattern of confusing 'raw' terminology.
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/compiler/cicc.rs)
- Off-boarding risk: anonymized user #1
- Outdated: anyhow
- Outdated: async-trait
- Outdated: blake3
- Outdated: bytes
- Outdated: chrono
- Outdated: clap
- Outdated: encoding_rs
- Outdated: env_logger
- Outdated: filetime
- Outdated: flate2
- Outdated: fs-err
- …and 23 more
Changes since last survey
- 24 commits — 17 feature/other, 7 fixes
By area
- src/compiler — 14 commits
- (root) — 2 commits
- src/cache — 2 commits
- src/server.rs — 2 commits
- tests/integration — 2 commits
- docs/Configuration.md — 1 commit
- tests/system.rs — 1 commit
Notable commits
- fix: Fix preprocessor cache include validation
- fix: Revert "Add cache hit variant for direct mode"
- fix: Revert "Add primitive printing for direct cache hit"
- fix: Revert "Change match to if"
- fix: Revert "Rename to DirectCacheType"
- fix: Revert "Wire the variant into actual generate_hash_key"
- fix: fix(cache): avoid duplicate multilevel reads
- change: Add cache hit variant for direct mode
- change: Add primitive printing for direct cache hit
- change: Change match to if
- change: Don't hand the jobserver to children that can't use it
- change: Rename to DirectCacheType
- change: Strip basedirs from the compiler arguments too
- change: Wire the variant into actual generate_hash_key
- change: chore(deps): update rust crate tar to v0.4.45
- change: chore: Remove dependency status badge (#2856)
- change: dist: refuse to trim rlibs from crates that also emit a cdylib
- change: docs: SCCACHE_CACHE_MULTIARCH enables multi-arch caching
- change: gcc, clang: don't distribute multi-arch compilations
- change: gcc, clang: preprocess multi-arch compilations once per -arch
- …and 4 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
mozilla/sccache was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 54b6f72a5d3583e8ccb8b83d44e5d41400d8039c — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-705631bb727e.