rust-lang/rustup
45.4
Weak · 29 September 2026
15.7k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is rustup, a command-line tool for managing Rust toolchain installations and updates across multiple operating systems and architectures. It handles the download, installation, and configuration of compiler components, supporting features like self-updates, toolchain overrides, and concurrent downloads with robust error recovery. The tool ensures system stability through transactional installs, memory-constrained I/O fallbacks, and secure DLL loading, while providing a modern CLI interface with comprehensive shell integration.
How it got here
2015–2016 — Initial scaffolding and infrastructure setup
6 changes.
This period established the foundational project structure, developer tooling, and CI/CD infrastructure for rustup. It involved significant internal refactoring to modernize the codebase architecture and dependencies, alongside the initial deployment of the rustup.rs website.
2019–2020 — Infrastructure modernization and stability
8 changes.
This period focused on modernizing the project's core infrastructure, including migrating CI from Travis to GitHub Actions and rewriting the CLI with clap-derive and tracing. Significant architectural changes were made to the distribution and component systems to support v2 manifests, ZStd compression, and transactional rollbacks, while also introducing async execution and memory-constrained I/O for improved stability.
2023–2026 — Test infrastructure and download refactoring
7 changes.
This period focused on modernizing the test suite by migrating to a new CLI testing API and expanding coverage for distribution and toolchain behaviors. Concurrently, core subsystems were refactored, including consolidating download logic to support partial file resumption and updating terminal output handling for better color management.
Features
Initial deployment of the rustup.rs website
The rustup.rs website is now live, providing an installer landing page that automatically detects the user's operating system (including Windows on ARM, Linux variants, macOS, FreeBSD, NetBSD, and Solaris) and displays the appropriate installation instructions. The site features a copy-to-clipboard button for the installation command, supports dark mode, and enforces security best practices via strict HTTP headers (HSTS, CSP, X-Frame-Options) defined in the site configuration.
www · high confidence
Initial repository scaffolding and developer tooling
This change establishes the initial project structure for rustup, adding essential configuration files for development workflows. It introduces a \.dockerignore\ to optimize Docker builds, a Nix flake (\flake.nix\) and \.envrc\ for developer environment management, and configuration files for code formatting and linting (\.oxfmtrc.json\, \.rustfmt.unstable.toml\, \.taplo.toml\). It also adds standard repository metadata files such as \LICENSE-APACHE\, \LICENSE-MIT\, \README.md\, \CHANGELOG.md\, and \CONTRING.md\, along with a \rust-analyzer.example.toml\ for IDE integration.
(repo-wide) · high confidence
New CI deployment and release helper scripts
The CI infrastructure now includes a suite of new scripts to manage the release process and deployment artifacts. \ci/deploy.bash\ and \ci/sync-dist.py\ automate the synchronization of binaries and release metadata between local, development, and production S3 environments, including CloudFront invalidations. \ci/prepare-deploy.bash\ and \ci/prepare-deploy.ps1\ handle the generation of SHA-256 hashes and the preparation of distribution files for upload. Additionally, \ci/changelog\_helper.py\ provides utilities to format release notes by replacing PR numbers with links and extracting contributor usernames, while \ci/cloudfront-invalidation.txt\ defines the specific artifact paths requiring cache invalidation upon release.
ci · high confidence
New shell environment scripts and self-update locking
The self-update module now includes dedicated environment scripts for Fish, Nushell, PowerShell, tcsh, and Xonsh, alongside the existing POSIX shells, to correctly configure the PATH for these interpreters. It also introduces a file-based locking mechanism (SelfUpdateLock) to serialize self-updates and prevent race conditions during binary replacement.
_src/cli/self\update · high confidence
Behavioural changes
Add musl-based sccache installation script with checksum verification
The CI pipeline now includes a dedicated bash script to install sccache version 0.2.12 for the x86\_64-unknown-linux-musl target. This script downloads the binary from the official Mozilla releases, verifies its integrity using a hardcoded SHA-256 checksum, and installs it to /usr/local/bin, ensuring a consistent and secure build cache environment for musl-based builds.
ci/docker/scripts · high confidence
Async runtime integration and Windows DLL security hardening
The rustup-init binary now runs on a manual Tokio multi-threaded runtime, enabling asynchronous execution for CLI modes and improving I/O performance. On Windows, the binary now explicitly configures DLL loading to search the system32 directory first, mitigating risks from malicious DLLs in user download folders. Additionally, the binary now reports a specific error when invoked without a recognizable executable name (arg0).
src/bin · high confidence
Download logic consolidated into a new module with improved partial-file handling
The download implementation has been refactored into a dedicated \src/download\ module, introducing a builder-style API (\DownloadOptions\ and \Download\) that simplifies how downloads are configured and executed. A key behavioral improvement is that partial downloads are no longer deleted when a network failure occurs, allowing users to resume interrupted transfers more reliably. The module also supports configuring the TLS backend via the \RUSTUP\_USE\_RUSTLS\ environment variable (defaulting to rustls when available) and allows overriding the download timeout via \RUSTUP\_DOWNLOAD\_TIMEOUT\. Tests have been added to verify proxy handling, partial file resumption, and the new retention behavior on network errors.
src/download · high confidence
Major internal refactoring and metadata version bump
The internal architecture of the toolchain manager has been significantly restructured, including the introduction of new modules for CLI, installation, and process handling, alongside a refactor of the configuration and toolchain resolution logic. The metadata version has been bumped from 2 to 12, requiring a migration for existing installations. Additionally, the system now supports TOML-based toolchain override files (rust-toolchain.toml) and introduces a new \ActiveSource\ enum to better track how the active toolchain was determined (e.g., default, environment, command line, or override).
src · high confidence
New component installation and transactional rollback system
The component distribution layer has been refactored to use a new \src/dist/component\ module that implements a transactional file system interface for installing and uninstalling toolchain components. This change introduces a \Transaction\ struct that tracks file system changes (add, copy, move, remove) and allows for automatic rollback if an installation fails before commit. It also adds support for ZStd compression in package unpacking and normalizes path separators during component manifest encoding/decoding to ensure cross-platform compatibility.
src/dist/component · high confidence
New disk I/O executor with memory-constrained fallback
The \src/diskio\ module now implements a new disk I/O execution model that supports both immediate (single-threaded) and threaded (pool-based) modes. A key behavioral change is that when the available RAM budget is below 512MB, the system automatically falls back to single-threaded unpacking to prevent out-of-memory errors on constrained systems. This is enforced by limiting the effective I/O thread count based on the \RUSTUP\_IO\_THREADS\ environment variable and the current memory budget, ensuring stability during large installations.
src/diskio · high confidence
Redesigned distribution system with v2 manifest support and ZStd compression
The distribution module has been refactored to support the Rust distribution v2 manifest format, introducing a new \Config\ structure to manage installed components and a \Manifest\ parser that handles package renames and target-specific availability. The download engine now supports ZStd compression in addition to XZ, validates file hashes during download, and allows concurrent component downloads controlled by the \RUSTUP\_CONCURRENT\_DOWNLOADS\ environment variable. Users will see improved error messaging for missing components, better handling of interrupted downloads, and the ability to install or update toolchains using the new manifest structure.
src/dist · high confidence
Refactored terminal output and color handling
The terminal output subsystem has been refactored to use the \anstream\ and \anstyle\ libraries instead of \termcolor\, enabling more robust color choice detection and ANSI escape code handling. This change introduces new internal modules (\file\_source\ and \terminal\_source\) to manage stdin/stdout/stderr streams and test writers, while simplifying locking mechanisms for log writes and test scenarios. Users will see consistent color behavior based on the \RUSTUP\_TERM\_COLOR\ environment variable and TTY detection, with improved safety in test environments where ANSI codes are stripped unless explicitly forced.
src/process · high confidence
Rename triple module to target\_tuple
The internal module previously named 'triple' has been renamed to 'target\_tuple', and a new file \known.rs\ has been added to this location to define static lists of supported architectures, operating systems, and environments. This change reflects a structural reorganization of how target specifications are stored and accessed within the distribution logic, without altering the external API or user-facing behavior.
_src/dist/target\tuple · high confidence
Replaced Travis CI with GitHub Actions templates
The CI infrastructure has been migrated from Travis CI to GitHub Actions. This change introduces a new templating system in \ci/actions-templates\ that generates the final workflow files, supporting builds on Linux, macOS, Windows, FreeBSD, and Solaris across multiple architectures. The new system handles triggers for pull requests, merges to \main\ and \stable\, scheduled rebuilds, and backport branches, and includes specific jobs for formatting, clippy, and documentation generation.
ci/actions-templates · high confidence
Restructure and modernize the utils crate
The utils module has been reorganized into dedicated files (mod.rs, raw.rs, notify.rs, units.rs) to improve code clarity. This change introduces a new \ExitCode\ type for semantic exit status handling, replaces the legacy logging system with \tracing\ for better observability, and adds a \Size\ struct for human-readable file size formatting. Additionally, file I/O operations now use \anyhow\ for error context, and the notification system has been simplified to log directly via tracing levels.
src/utils · high confidence
Rewrite CLI with clap-derive and modernize logging and styling
The CLI implementation has been rewritten to use \clap-derive\ for argument parsing, replacing the previous manual parser. This change introduces consistent color styling via \anstyle\ and \anstream\, and migrates the internal logging system from \log\/\termcolor\ to \tracing\ with \tracing-subscriber\. Additionally, the installer (\rustup-init\) now respects \--verbose\ and \--quiet\ flags to control log levels when \RUSTUP\_LOG\ is not explicitly set, and the \rustup doc\ command gains a \--serve\ option to host documentation via a local HTTP server, bypassing browser sandbox restrictions on \file://\ URLs.
src/cli · high confidence
Support for toolchain aliases and stricter name validation
Users can now use the alias 'default' to refer to the configured default toolchain in contexts like RUSTUP\_TOOLCHAIN, and toolchain names starting with '+' or '-' are explicitly forbidden with clear error messages. This change also introduces a new \ToolchainAlias\ enum and \Override\ wrapper in the names module to handle these aliases, while validating toolchain names against stricter security profiles.
src/toolchain · high confidence
Test coverage
Added tests for v2 distribution server updates; Comprehensive CLI test suite migration and expansion; New test infrastructure for CLI and distribution mocking.
Dependencies
Rustup 1.30.0: Modernized dependency stack and edition upgrade
The rustup package has been updated to version 1.30.0, upgrading the Rust edition to 2024 and significantly modernizing the dependency tree. Key changes include upgrading the CLI framework from clap 1 to clap 4 (with derive support), replacing the hyper 0.6 HTTP backend with hyper 1.0 and tokio, and updating the TLS implementation to use reqwest 0.13 with rustls 0.23 and rustls-platform-verifier 0.7. The project also migrates from error-chain to thiserror 2 and anyhow, updates the random number generator to rand 0.10, and adopts anstyle 1 for terminal output. These updates improve build performance, security, and compatibility with modern Rust standards.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 45 (+0.1)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 87 → 88 (+0.8)
- Architecture 99 → 87 (-12.0)
- Maturity 58 → 58 (+0.4)
- Readiness 76 → 78 (+1.6)
- Security 15 → 15 (+0.0)
- Accessibility 80 → 80 (+0.0)
- Performance 100 (new)
Resolved (12)
- DistributableToolchain::get_component_suggestion (cognitive 17) (src/toolchain/distributable.rs)
- Documentation: no project overview (README.md)
- Duplicated block (6 lines × 2) (src/cli/self_update/unix.rs)
- Duplicated block (8 lines × 2) (src/toolchain/names.rs)
- FileTooLong: self_update/windows.rs (src/cli/self_update/windows.rs)
- FixmeComment (src/cli/self_update/unix.rs)
- Further sole-owners (lower concentration)
- Hotspot: src/cli/self_update/windows.rs (src/cli/self_update/windows.rs)
- Hotspot: src/dist/component/package.rs (src/dist/component/package.rs)
- Hotspot: src/test.rs (src/test.rs)
- Off-boarding risk: anonymized user #1
- TodoComment (src/toolchain/distributable.rs)
New (10)
- Documentation: no installation or build instructions (ci/actions-templates/README.md)
- Duplicate file writing operations. utils.write_file and raw.write_file perform the same core operation (writing string content to a file path). The presence of both suggests a lack of abstraction or a split between 'high-level' and 'low-level' utilities that isn't clearly justified by distinct signatures (e.g., one doesn't take a mode/encoding parameter that the other lacks).
- Duplicated block (15–16 lines × 2) (src/toolchain/distributable.rs)
- Duplicated block (8 lines × 2) (src/toolchain/names.rs)
- Inconsistent naming and scope for file system removal. utils exposes remove_file but raw exposes remove_dir. There is no raw.remove_file or utils.remove_dir shown, creating an asymmetry. Furthermore, utils.remove_file takes an unused name argument, while raw.remove_dir does not. This suggests utils is a wrapper that might be incomplete or inconsistently implemented compared to raw.
- Inconsistent return types for existence checks. path_exists returns a boolean, while is_file also returns a boolean. However, other operations in raw (like open_dir_following_links) return Result. While not a direct name collision, the inconsistency in error handling (bool vs Result) for similar 'check' operations is a design flaw. More critically, raw lacks a file_exists or dir_exists specific check, relying on path_exists + type check, whereas is_file is specific. This is a minor API design inconsistency rather than a direct duplicate, but combined with the remove asymmetry, it lowers consistency.
- Inverted test pyramid
- Naming inconsistency in test assertion helpers. expect is a generic name that implies checking the result of a command, but it doesn't specify what is being expected (stdout? stderr? exit code?). expect_with_env is also vague. The Assert type has specific methods like is_ok, with_stdout, etc. The factory methods on Config should likely be named more descriptively, e.g., run_command or execute, returning an Assert builder, rather than expect_* which conflates execution with assertion.
- Projects may be oversized for their cohesion
- rustup::cli::self_update::stage::cleanup_at (cognitive 16) (src/cli/self_update/stage.rs)
Changes since last survey
- 91 commits — 75 feature/other, 16 fixes
By area
- src/cli — 39 commits
- src/install.rs — 12 commits
- (root) — 7 commits
- src/dist — 6 commits
- tests/suite — 6 commits
- .github/workflows — 4 commits
- ci/actions-templates — 4 commits
- src/errors.rs — 3 commits
- src/toolchain — 3 commits
- doc/user-guide — 2 commits
- ci/run.bash — 1 commit
- src/anchors.rs — 1 commit
- src/config.rs — 1 commit
- src/download — 1 commit
- src/process.rs — 1 commit
Notable commits
- fix: fix(cli): log empty toolchain message with info
- fix: fix(dist): add DistError::HostTupleUnsupported to nightly backtracking flow
- fix: fix(dist): refine message of DistError::HostTupleUnsupported
- fix: fix(error): exclude source in RustupError's Display impl
- fix: fix(installer): format shell command as code block
- fix: fix(rustup-init/sh): dont let an external local pass for the builtin
- fix: fix(rustup-mode): make "remove last target" warning more robust
- fix: fix(self-update): fix detection logic for xonsh
- fix: fix(self-update): move the updater under RUSTUP_HOME and mark its outcome
- fix: fix(self-update): publish the rustup binary atomically
- fix: fix(self-update): record DisplayVersion from the replacer on Windows
- fix: fix(self-update): remove abandoned pending binaries once stale
- fix: fix(self-update): remove abandoned updaters only once stale
- fix: fix(self-update): serialize self-updates with a lock
- fix: fix(uninstall): reuse resolved cargo home during cleanup
- fix: fix(windows): attempt GC cleanup after uninstall errors
- change: Upgrade faster-hex to 1
- change: Upgrade opentelemetry etc to 0.33
- change: chore(anchor): bump static roots
- change: chore(deps): lock file maintenance
- …and 71 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rust-lang/rustup was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f2763b72b6b3442112a13f78fa9da6141ebfa5ee — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.