tokio-rs/prost
70.5
Strong · 30 September 2026
11.9k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is the Prost library, a Rust implementation for Protocol Buffers that generates native Rust code from .proto definitions. It provides core functionality for serializing and deserializing protobuf messages, including support for well-known types and both proto2 and proto3 specifications. The project also includes a code generator (prost-build), a derive macro crate (prost-derive), and comprehensive tooling for testing, fuzzing, and benchmarking to ensure correctness and performance.
How it got here
2017 — Prost 0.14.4 release and architectural restructuring
16 changes.
This period focused on releasing Prost 0.14.4, which involved restructuring the codebase into a modular Cargo workspace and refactoring prost-build and prost-derive for improved maintainability. The work introduced prost-derive, expanded prost-types with well-known type support, and established comprehensive testing infrastructure including fuzzing targets and a Rust conformance test binary.
2021–2026 — testing, fuzzing, and encoding refactoring
13 changes.
This period focused on expanding test coverage and performance validation through new fuzzing infrastructure, benchmark suites, and comprehensive test fixtures for well-known types and include generation. Concurrently, the codebase underwent structural improvements by refactoring encoding logic into dedicated modules and fixing specific issues related to package-less protos and proto3 packing defaults.
Features
Add Rust conformance test binary
Introduces a new Rust-based conformance test binary that reads protobuf-encoded test requests from standard input and writes responses to standard output. The binary supports roundtrip encoding and decoding for Protobuf wire format for both proto2 and proto3 test message types, while explicitly skipping JSON, JSPB, and TextFormat outputs as they are not implemented.
conformance/src · high confidence
Add protobuf crate with conformance and test message modules
A new \protobuf\ crate has been introduced, providing a \conformance\ module that exposes a test runner binary path and includes generated conformance test code, alongside a \test\_messages\ module that exposes generated Rust bindings for proto2, proto3, and unittest message definitions.
protobuf/src · high confidence
Added fuzzing infrastructure for proto3 messages
Added a new fuzzing target for proto3 messages using AFL, including a main fuzzing entry point, a reproduction script for crashes, and a test corpus. This enables automated fuzz testing of proto3 message encoding and decoding to identify potential issues in the protobuf implementation.
fuzz/afl, fuzz/afl/proto3 · high confidence
Initial release of prost-derive with configurable prost path and recursion limit
The prost-derive crate is introduced as a new component for generating Protocol Buffers implementations. This initial version includes a configurable prost path via the \prost\_path\ attribute, allowing users to specify the location of the prost library. It also sets a recursion limit of 4096 to handle complex message structures. The derive macro supports generating Message implementations for structs, handling both named and unnamed fields, and includes basic error handling for invalid field tags.
prost-derive/src · high confidence
Preserve legacy protobuf benchmark definitions for prost
The repository now includes a copy of the protobuf v3.14 benchmark protos and datasets in the \third\_party/old\_protobuf\_benchmarks\ directory. This ensures that these specific benchmark definitions remain available for the prost library, even though they have been changed or removed in newer upstream versions of the original protobuf library.
_third\party · high confidence
Well-known types are now available in prost-types
The \prost-types\ crate now exposes the full set of Protocol Buffers well-known types (such as \Any\, \Duration\, \Timestamp\, and \Value\) as native Rust structs. This change introduces dedicated modules for handling these types, including robust serialization and deserialization logic for \Any\ (with type URL validation), RFC-3339 parsing and formatting for \Timestamp\, and canonical normalization for \Duration\. It also adds convenient conversion traits (\From\/\TryFrom\) to interoperate with standard library types like \std::time::SystemTime\ and \std::time::Duration\, as well as optional support for the \chrono\ crate.
prost-types/src · high confidence
Architecture
Refactored field code generation into modular submodules
The field code generation logic in \prost-derive\ has been reorganized from a single monolithic file into distinct modules for scalar, message, map, oneof, and group fields. This structural change improves maintainability and clarity of the generated code paths without altering the external API or behavior for users.
prost-derive/src/field · high confidence
prost-build source code restructured into modular components
The prost-build code generation logic has been reorganized from a monolithic structure into distinct modules to improve maintainability. The new layout includes \ast.rs\ for Protobuf AST definitions (such as \Comments\, \Service\, and \Method\ descriptors), \code\_generator.rs\ for the core generation engine, and specialized sub-modules for C-string escaping (\c\_escaping.rs\) and syntax handling (\syntax.rs\). Configuration and type mapping logic are now separated into \config.rs\ and \collections.rs\ (defining \MapType\ and \BytesType\), while \context.rs\ centralizes global generation state and \extern\_paths.rs\ handles external type resolution. This refactoring also introduces dedicated fixtures for testing specific behaviors, such as deprecated field attributes and field boxing.
prost-build/src · high confidence
Behavioural changes
Internal protobuf build system now fetches and compiles version 25.8
The \protobuf\ crate, used internally by \prost\ for conformance and integration tests, has been updated to automatically download, compile, and install the Protobuf project version 25.8 (tag v25.8) during the build process. This change replaces previous methods with a CMake-based build that fetches sources via Git, ensuring the conformance test runner and \libprotobuf\ are available in the Cargo target directory. The build script includes platform-specific adjustments, such as disabling the conformance runner on Windows and handling library paths on macOS, to support cross-platform testing.
protobuf · high confidence
Prost 0.14.4 release and maintenance status update
This release updates the Minimum Supported Rust Version (MSRV) to 1.85 and marks the project as 'Passively Maintained', indicating that the maintainer is no longer contributing new features but will continue to review bug fixes and security improvements. Key changes include making the \is\_valid\ function in \prost-derive\ a constant function, fixing C++ builds on GCC 15, and updating dependencies such as \criterion\ to 0.8 and \rand\ to 0.10. The release also adds fuzzing tests using AFL and Kani, improves documentation with examples for \decode\_length\_delimiter\, and fixes issues with enumeration default identifiers and type name conflicts.
(repo-wide) · high confidence
Prost 0.14.4 release with well-known type support and error fixes
This release updates the prost crate to version 0.14.4. It adds implementations of the \Message\ and \Name\ traits for Rust primitive types (bool, u32, u64, i32, i64) to support Protobuf well-known wrapper types like \google.protobuf.BoolValue\. It also fixes a bug where \Name::full\_name()\ returned an incorrect name for messages in empty packages, and restores the \DecodeError::new\ constructor which was previously removed but remained in use by downstream consumers (now marked deprecated).
prost/src · high confidence
Refactor encoding logic into dedicated modules
The encoding implementation has been reorganized into separate modules for varint, wire type, and length delimiter handling. This structural change improves code maintainability and clarity without altering the external API or behavior of the library.
prost/src/encoding · high confidence
Updated benchmark build configuration to include additional protobuf datasets
The benchmark build process has been updated to compile a broader set of protobuf definitions. The new build script explicitly includes standard Google benchmark messages (proto2 and proto3 variants of message1, and message2) alongside the existing legacy protobuf benchmarks, ensuring that performance testing covers these additional well-known types.
benchmarks · high confidence
Fixes
Correct packed encoding defaults for proto3 repeated fields
The generated code for proto3 repeated fields now correctly omits the \packed = "false"\ attribute when no explicit packing option is specified, aligning with the proto3 specification where packing is the default. This fix ensures that the generated Rust structs for proto3 messages match the expected behavior, while proto2 messages continue to explicitly mark fields as unpacked when no options are provided.
_prost-build/src/fixtures/packed\encoding · high confidence
Fix include generation for protos without a package
The \include\file\ logic in \prost-build\ now correctly handles \.proto\ files that lack a package declaration. Previously, such files could cause issues during code generation; this fix ensures that the generated include structure (as seen in the \\.includes.rs\ fixture) properly wraps modules and includes, allowing protos without explicit packages to be processed without errors.
_prost-build/src/fixtures/write\includes · high confidence
Test coverage
Added Protocol Buffers test fixtures for well-known types and compiler plugin; Added alphabet fixture for deterministic include generation; Added conformance test runner for protobuf; Added fuzzing targets for date, duration, and protocol buffer parsing; Added protobuf dataset benchmarks using prost; Added test coverage for single-include file generation with custom output directories; Added tests for nested package resolution; Added tests for re-exported prost dependencies; Added varint encoding/decoding benchmarks; Consolidated build script for test code generation; Consolidated integration test suite for prost code generation.
Dependencies
Prost 0.14.4 workspace restructure and dependency updates
The project has been reorganized into a Cargo workspace (version 0.14.4) with a minimum supported Rust version (MSRV) of 1.85. Key dependency updates include upgrading \prost-build\ to use \petgraph\ 0.8, \pulldown-cmark-to-cmark\ 22, and \itertools\ up to 0.15, while \prost-derive\ now depends on \syn\ 2 and \anyhow\. The \prost-types\ crate introduces an optional \arbitrary\ feature for fuzzing support, and the \benchmarks\ crate now uses \criterion\ 0.8. New workspace members include \fuzz\ (with \libfuzzer-sys\ 0.4 and \afl\ 0.4 targets), \conformance\, and \protobuf\, alongside test crates for Rust editions 2015, 2018, and 2024.
(dependencies) · high confidence
Housekeeping
Empty benchmark library crate added; Removed empty test module from src/lib.rs.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 72 → 71 (-1.9)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 91 → 91 (+0.0)
- Architecture 100 → 89 (-11.1)
- Maturity 52 → 52 (+0.2)
- Readiness 96 → 86 (-10.0)
- Security 85 → 90 (+4.9)
- Performance 85 (new)
Resolved (3)
- Hotspot: prost-build/src/code_generator.rs (prost-build/src/code_generator.rs)
- Hotspot: prost-derive/src/field/scalar.rs (prost-derive/src/field/scalar.rs)
- Off-boarding risk: anonymized user #1
New (9)
- Ambiguous distinction between encode and encode_raw. In many serialization libraries, raw implies skipping length prefixes or specific wire format details, but without documentation, it is unclear if encode_raw is a performance optimization or a different wire format. They appear to do the same thing (serialize to buffer) but with different signatures/returns.
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Documentation: no architecture or design documentation
- Duplicate functionality at module level vs instance level. prost_build::compile_protos is a convenience function that likely creates a default Config and calls Config::compile_protos. This is acceptable, but Config::compile_protos and Config::generate (which takes Vec<Request>) and Config::load_fds/Config::compile_fds create a fragmented API for different input sources (paths vs FDs vs Requests).
- Inconsistent error handling strategy across similar operations. Timestamp offers three variants: normalize() (likely panics or is deprecated?), try_normalize() (returns Result), and normalized() (returns Self, likely panicking or assuming validity). Duration only has normalize() and normalized(). This inconsistency between Duration and Timestamp regarding error handling (Result vs panic/void) is confusing.
- Low cohesion: Config (LCOM4 4) (prost-build/src/config.rs)
- Off-boarding risk: anonymized user #1
- Redundant methods with ambiguous semantics. normalize() likely mutates in place (void return), while normalized() returns a new instance. However, the naming is confusingly similar, and normalize() without a clear 'mut' implication in the name (though Rust conventions usually imply mutability via &mut self) is less discoverable than normalized(). More critically, having both creates a choice paralysis for users.
- Return type error: encode_to_vec returns u8 instead of Vec<u8>. This is likely a typo in the signature description, but if accurate, it is a critical API flaw. Even assuming it's a typo, the naming encode_to_vec vs encode_length_delimited_to_vec is consistent, but the return type u8 is nonsensical for a 'to_vec' operation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tokio-rs/prost was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit aed74ad0e844959ee6948f29c4e9cff0f278e89e — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.