Skip to content
CAI
Software that uses CAICheck a score

tokio-rs/prost

70.5

Strong · 30 September 2026

11.9k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Prost library, a Rust implementation for Protocol Buffers that generates native Rust code from .proto definitions. It provides core functionality for serializing and deserializing protobuf messages, including support for well-known types and both proto2 and proto3 specifications. The project also includes a code generator (prost-build), a derive macro crate (prost-derive), and comprehensive tooling for testing, fuzzing, and benchmarking to ensure correctness and performance.

How it got here

2017 — Prost 0.14.4 release and architectural restructuring

16 changes.

This period focused on releasing Prost 0.14.4, which involved restructuring the codebase into a modular Cargo workspace and refactoring prost-build and prost-derive for improved maintainability. The work introduced prost-derive, expanded prost-types with well-known type support, and established comprehensive testing infrastructure including fuzzing targets and a Rust conformance test binary.

2021–2026 — testing, fuzzing, and encoding refactoring

13 changes.

This period focused on expanding test coverage and performance validation through new fuzzing infrastructure, benchmark suites, and comprehensive test fixtures for well-known types and include generation. Concurrently, the codebase underwent structural improvements by refactoring encoding logic into dedicated modules and fixing specific issues related to package-less protos and proto3 packing defaults.

Features

Add Rust conformance test binary

Introduces a new Rust-based conformance test binary that reads protobuf-encoded test requests from standard input and writes responses to standard output. The binary supports roundtrip encoding and decoding for Protobuf wire format for both proto2 and proto3 test message types, while explicitly skipping JSON, JSPB, and TextFormat outputs as they are not implemented.

conformance/src · high confidence

Add protobuf crate with conformance and test message modules

A new \protobuf\ crate has been introduced, providing a \conformance\ module that exposes a test runner binary path and includes generated conformance test code, alongside a \test\_messages\ module that exposes generated Rust bindings for proto2, proto3, and unittest message definitions.

protobuf/src · high confidence

Added fuzzing infrastructure for proto3 messages

Added a new fuzzing target for proto3 messages using AFL, including a main fuzzing entry point, a reproduction script for crashes, and a test corpus. This enables automated fuzz testing of proto3 message encoding and decoding to identify potential issues in the protobuf implementation.

fuzz/afl, fuzz/afl/proto3 · high confidence

Initial release of prost-derive with configurable prost path and recursion limit

The prost-derive crate is introduced as a new component for generating Protocol Buffers implementations. This initial version includes a configurable prost path via the \prost\_path\ attribute, allowing users to specify the location of the prost library. It also sets a recursion limit of 4096 to handle complex message structures. The derive macro supports generating Message implementations for structs, handling both named and unnamed fields, and includes basic error handling for invalid field tags.

prost-derive/src · high confidence

Preserve legacy protobuf benchmark definitions for prost

The repository now includes a copy of the protobuf v3.14 benchmark protos and datasets in the \third\_party/old\_protobuf\_benchmarks\ directory. This ensures that these specific benchmark definitions remain available for the prost library, even though they have been changed or removed in newer upstream versions of the original protobuf library.

_third\party · high confidence

Well-known types are now available in prost-types

The \prost-types\ crate now exposes the full set of Protocol Buffers well-known types (such as \Any\, \Duration\, \Timestamp\, and \Value\) as native Rust structs. This change introduces dedicated modules for handling these types, including robust serialization and deserialization logic for \Any\ (with type URL validation), RFC-3339 parsing and formatting for \Timestamp\, and canonical normalization for \Duration\. It also adds convenient conversion traits (\From\/\TryFrom\) to interoperate with standard library types like \std::time::SystemTime\ and \std::time::Duration\, as well as optional support for the \chrono\ crate.

prost-types/src · high confidence

Architecture

Refactored field code generation into modular submodules

The field code generation logic in \prost-derive\ has been reorganized from a single monolithic file into distinct modules for scalar, message, map, oneof, and group fields. This structural change improves maintainability and clarity of the generated code paths without altering the external API or behavior for users.

prost-derive/src/field · high confidence

prost-build source code restructured into modular components

The prost-build code generation logic has been reorganized from a monolithic structure into distinct modules to improve maintainability. The new layout includes \ast.rs\ for Protobuf AST definitions (such as \Comments\, \Service\, and \Method\ descriptors), \code\_generator.rs\ for the core generation engine, and specialized sub-modules for C-string escaping (\c\_escaping.rs\) and syntax handling (\syntax.rs\). Configuration and type mapping logic are now separated into \config.rs\ and \collections.rs\ (defining \MapType\ and \BytesType\), while \context.rs\ centralizes global generation state and \extern\_paths.rs\ handles external type resolution. This refactoring also introduces dedicated fixtures for testing specific behaviors, such as deprecated field attributes and field boxing.

prost-build/src · high confidence

Behavioural changes

Internal protobuf build system now fetches and compiles version 25.8

The \protobuf\ crate, used internally by \prost\ for conformance and integration tests, has been updated to automatically download, compile, and install the Protobuf project version 25.8 (tag v25.8) during the build process. This change replaces previous methods with a CMake-based build that fetches sources via Git, ensuring the conformance test runner and \libprotobuf\ are available in the Cargo target directory. The build script includes platform-specific adjustments, such as disabling the conformance runner on Windows and handling library paths on macOS, to support cross-platform testing.

protobuf · high confidence

Prost 0.14.4 release and maintenance status update

This release updates the Minimum Supported Rust Version (MSRV) to 1.85 and marks the project as 'Passively Maintained', indicating that the maintainer is no longer contributing new features but will continue to review bug fixes and security improvements. Key changes include making the \is\_valid\ function in \prost-derive\ a constant function, fixing C++ builds on GCC 15, and updating dependencies such as \criterion\ to 0.8 and \rand\ to 0.10. The release also adds fuzzing tests using AFL and Kani, improves documentation with examples for \decode\_length\_delimiter\, and fixes issues with enumeration default identifiers and type name conflicts.

(repo-wide) · high confidence

Prost 0.14.4 release with well-known type support and error fixes

This release updates the prost crate to version 0.14.4. It adds implementations of the \Message\ and \Name\ traits for Rust primitive types (bool, u32, u64, i32, i64) to support Protobuf well-known wrapper types like \google.protobuf.BoolValue\. It also fixes a bug where \Name::full\_name()\ returned an incorrect name for messages in empty packages, and restores the \DecodeError::new\ constructor which was previously removed but remained in use by downstream consumers (now marked deprecated).

prost/src · high confidence

Refactor encoding logic into dedicated modules

The encoding implementation has been reorganized into separate modules for varint, wire type, and length delimiter handling. This structural change improves code maintainability and clarity without altering the external API or behavior of the library.

prost/src/encoding · high confidence

Updated benchmark build configuration to include additional protobuf datasets

The benchmark build process has been updated to compile a broader set of protobuf definitions. The new build script explicitly includes standard Google benchmark messages (proto2 and proto3 variants of message1, and message2) alongside the existing legacy protobuf benchmarks, ensuring that performance testing covers these additional well-known types.

benchmarks · high confidence

Fixes

Correct packed encoding defaults for proto3 repeated fields

The generated code for proto3 repeated fields now correctly omits the \packed = "false"\ attribute when no explicit packing option is specified, aligning with the proto3 specification where packing is the default. This fix ensures that the generated Rust structs for proto3 messages match the expected behavior, while proto2 messages continue to explicitly mark fields as unpacked when no options are provided.

_prost-build/src/fixtures/packed\encoding · high confidence

Fix include generation for protos without a package

The \include\file\ logic in \prost-build\ now correctly handles \.proto\ files that lack a package declaration. Previously, such files could cause issues during code generation; this fix ensures that the generated include structure (as seen in the \\.includes.rs\ fixture) properly wraps modules and includes, allowing protos without explicit packages to be processed without errors.

_prost-build/src/fixtures/write\includes · high confidence

Test coverage

Added Protocol Buffers test fixtures for well-known types and compiler plugin; Added alphabet fixture for deterministic include generation; Added conformance test runner for protobuf; Added fuzzing targets for date, duration, and protocol buffer parsing; Added protobuf dataset benchmarks using prost; Added test coverage for single-include file generation with custom output directories; Added tests for nested package resolution; Added tests for re-exported prost dependencies; Added varint encoding/decoding benchmarks; Consolidated build script for test code generation; Consolidated integration test suite for prost code generation.

Dependencies

Prost 0.14.4 workspace restructure and dependency updates

The project has been reorganized into a Cargo workspace (version 0.14.4) with a minimum supported Rust version (MSRV) of 1.85. Key dependency updates include upgrading \prost-build\ to use \petgraph\ 0.8, \pulldown-cmark-to-cmark\ 22, and \itertools\ up to 0.15, while \prost-derive\ now depends on \syn\ 2 and \anyhow\. The \prost-types\ crate introduces an optional \arbitrary\ feature for fuzzing support, and the \benchmarks\ crate now uses \criterion\ 0.8. New workspace members include \fuzz\ (with \libfuzzer-sys\ 0.4 and \afl\ 0.4 targets), \conformance\, and \protobuf\, alongside test crates for Rust editions 2015, 2018, and 2024.

(dependencies) · high confidence

Housekeeping

Empty benchmark library crate added; Removed empty test module from src/lib.rs.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 72 → 71 (-1.9)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 91 → 91 (+0.0)
  • Architecture 100 → 89 (-11.1)
  • Maturity 52 → 52 (+0.2)
  • Readiness 96 → 86 (-10.0)
  • Security 85 → 90 (+4.9)
  • Performance 85 (new)

Resolved (3)

  • Hotspot: prost-build/src/code_generator.rs (prost-build/src/code_generator.rs)
  • Hotspot: prost-derive/src/field/scalar.rs (prost-derive/src/field/scalar.rs)
  • Off-boarding risk: anonymized user #1

New (9)

  • Ambiguous distinction between encode and encode_raw. In many serialization libraries, raw implies skipping length prefixes or specific wire format details, but without documentation, it is unclear if encode_raw is a performance optimization or a different wire format. They appear to do the same thing (serialize to buffer) but with different signatures/returns.
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Documentation: no architecture or design documentation
  • Duplicate functionality at module level vs instance level. prost_build::compile_protos is a convenience function that likely creates a default Config and calls Config::compile_protos. This is acceptable, but Config::compile_protos and Config::generate (which takes Vec<Request>) and Config::load_fds/Config::compile_fds create a fragmented API for different input sources (paths vs FDs vs Requests).
  • Inconsistent error handling strategy across similar operations. Timestamp offers three variants: normalize() (likely panics or is deprecated?), try_normalize() (returns Result), and normalized() (returns Self, likely panicking or assuming validity). Duration only has normalize() and normalized(). This inconsistency between Duration and Timestamp regarding error handling (Result vs panic/void) is confusing.
  • Low cohesion: Config (LCOM4 4) (prost-build/src/config.rs)
  • Off-boarding risk: anonymized user #1
  • Redundant methods with ambiguous semantics. normalize() likely mutates in place (void return), while normalized() returns a new instance. However, the naming is confusingly similar, and normalize() without a clear 'mut' implication in the name (though Rust conventions usually imply mutability via &mut self) is less discoverable than normalized(). More critically, having both creates a choice paralysis for users.
  • Return type error: encode_to_vec returns u8 instead of Vec<u8>. This is likely a typo in the signature description, but if accurate, it is a critical API flaw. Even assuming it's a typo, the naming encode_to_vec vs encode_length_delimited_to_vec is consistent, but the return type u8 is nonsensical for a 'to_vec' operation.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tokio-rs/prost was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit aed74ad0e844959ee6948f29c4e9cff0f278e89e — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.