Weavatrix Git
weavatrix-git is a dependency-free, read-only Git storage engine written in
safe Rust. Repository-analysis tools get direct, typed evidence without
launching git, loading a C library, executing hooks, evaluating filters, or
contacting a remote.
The crate is not a second Git client. Its contract is deterministic local intelligence: objects, refs, history, reachability, index state, and changes.
Why a separate crate?
A scanner discovers files. A code graph models relationships. This crate owns version-control evidence. Keeping that boundary independent lets any Rust application reuse Git intelligence without importing a larger product.
Supported contract
| Area | Support |
|---|---|
| Layouts | worktree, bare, .git indirection, linked worktree commondir |
| Hashes | SHA-1 and SHA-256 object identifiers |
| Refs | loose, symbolic, detached HEAD, packed refs, reflogs |
| Objects | commit, tree, blob, annotated tag |
| Loose storage | bounded zlib/DEFLATE decoded by this crate |
| Packed storage | PACK v2/v3, index v2, OFS_DELTA, REF_DELTA |
| Object lookup | alternates, classic MIDX, configurable object/delta caches |
| Commit acceleration | monolithic and split commit-graph chains |
| Path acceleration | changed-path Bloom filters v1/v2 |
| Reachability | pack and MIDX EWAH bitmaps with RIDX ordering |
| Index | DIRC v2, v3, and prefix-compressed v4 |
| Queries | typed reads, lazy revwalk, history, tracked status, tree diff |
| Scale-out | bounded parallel batches and cross-repository correlation |
| Extension | ordered, thread-safe, read-only custom ODB backends |
All public reads are in-process. Library code contains no subprocess fallback. Unsupported data returns a typed error rather than an approximate answer.
Usage
use ;
Custom stores use the same object contract:
use Arc;
use ;
let backend = new;
let repository =
open_with_backends?;
# Ok::
For cross-repository analysis, RepositorySet keeps object stores isolated and
returns deterministic serial or parallel results:
use ;
let repositories = open?;
let histories = repositories.histories_parallel?;
let shared = repositories.shared_commits?;
# Ok::
The diagnostic CLI uses the library:
weavatrix-git [-C repository] head
weavatrix-git [-C repository] log [revision] [max-count]
weavatrix-git [-C repository] cat <object>
weavatrix-git [-C repository] diff <old-commit> <new-commit>
Architecture
Repository
+-- refs + reflog
+-- commit-graph chain + changed-path Bloom
+-- index -> tracked status
+-- custom ODB backends
+-- object directories + alternates
+-- loose object -> bounded zlib
+-- MIDX -> pack -> bounded delta chain
+-- pack/MIDX bitmap -> reachable object IDs
Limits bounds object bytes, cache bytes, delta/ref/tree depth, tree and index
entries, reflog/history length, parent count, and bitmap expansion. The crate
forbids unsafe Rust.
Correctness
The suite creates real Git repositories and verifies:
- loose and aggressively packed OFS/REF delta objects;
- SHA-1 and SHA-256 repositories;
- bare and linked-worktree layouts;
- classic MIDX lookup;
- multi-layer split commit-graphs and changed-path Bloom answers;
- pack and MIDX bitmap reachability against
git rev-list --objects; - index v2 and v4, reflog order, revwalk hide/reset, and tracked status;
- deterministic parallel and cross-repository results;
- hostile format and configured-limit failures.
Current line coverage is 85.70%. CI runs Rust 1.88 on Linux, Windows, and macOS, Clippy with warnings denied, coverage, audit, docs, and package verification.
Performance
Release measurements on Windows, 2026-07-27:
| Exact-parity operation | weavatrix-git p50 |
git.exe p50 |
|---|---|---|
| 6,000-object bitmap reachability | 0.431 ms | 72.656 ms |
| one-entry index read | 0.033 ms | 60.758 ms |
| clean tracked status | 0.186 ms | 72.735 ms |
| cached commit lookup | 0.001 ms | 65.267 ms |
| 1,000-commit history, reused repository | 0.416 ms | 68.145 ms |
These rows compare an in-process direct reader with a new CLI process. They are
not claims against in-process gix or libgit2. Every harness checks output
parity before recording time. See BENCHMARKS.md.
Position among alternatives
| Capability | weavatrix-git |
Git CLI | gix |
libgit2 |
|---|---|---|---|---|
| In-process | yes | no | yes | yes |
| Pure safe Rust | yes | no | yes | no, C core |
| Crate dependencies | zero | n/a | many modular crates | native library |
| Object/delta caches | yes | yes | yes | yes |
| MIDX and reachability bitmap reads | yes | yes | yes | yes |
| Split commit-graph and path Bloom reads | yes | yes | yes | commit-graph |
| Custom read-only ODB | yes | n/a | store abstractions | yes |
| Lazy revwalk, reflog, index, tracked status | yes | yes | yes | yes |
| Network and mutation | no | yes | yes | yes |
The deliberate remaining exclusions are pack index v1, reftable, incremental MIDX chains, split/sparse index extensions, shallow and replace-object semantics, revision-expression grammar, untracked/ignore/filter-aware status, submodule worktree status, network operations, and mutation.
Use Git, gix, or libgit2 for a complete client. Use this crate when bounded
local evidence, a small audit surface, deterministic reads, and zero
dependencies matter.
License
MIT