mrkeyoor.com_
Wed 30 Sept 19:48 UTC
Dev Toolsevaluationupdated 30 Sept 2026

roundhouse review

Roundhouse reads a Rails application without booting it, infers types and request paths, and can turn the app into a standalone project in another language. The same Rust binary also provides a checker, editor server, browser IDE, and MCP tools for coding agents.

Verdict

Our Roundhouse run built in 152 seconds, then cargo test ended with 1,644 passes and 82 failures, so commit 497ff91 cannot clear a strict fresh-container release gate. Try the checker and MCP server first because they can expose an app's unsupported surface without changing its runtime. Ship generated code only after the app reports clean and its real requests, tests, and security controls agree with Rails.

We ran it

Lab card: what happened when we ran roundhouseScreenshot of roundhouse (rubys.github.io/roundhouse)
Install✓ · 18s62 packages
Build✓ · 152s
Tests✗ · 254s1644 passed · 82 failed of 1726 (cargo test)
Repo1520 files~401,364 lines of source · 19.8 MB · 2 CI workflows · tests dir

Answers from our run

Does roundhouse build from source?

Dependencies installed in 18 seconds (62 packages), and the build succeeded in 152 seconds. We cloned commit 497ff91 into a clean Debian container with 3 CPUs and no project-specific setup.

Do roundhouse's tests pass?

Not all of them: 1644 of 1726 passed and 82 failed when we ran the project's own test command (cargo test). Some failures need services or credentials a bare container does not have.

Who should not use roundhouse?

Teams expecting a drop-in conversion of any Rails app: the current guide guarantees every target only against its Rails 8 blog fixture, while wider Campfire coverage belongs to the Ruby and Spinel lanes.

What are the alternatives to roundhouse?

Sorbet, Ruby LSP, Spinel. Our Roundhouse run built in 152 seconds, then cargo test ended with 1,644 passes and 82 failures, so commit 497ff91 cannot clear a strict fresh-container release gate.

Setup3/5Prebuilt binary is simple, source needs Rust, clang, and libclang
Docs5/5Coverage, target limits, security gaps, and prerequisites are explicit
Community3/5Active September work, 301 stars, and 84 open issues and PRs
Maturity2/5First snapshot is recent, and our suite finished with 82 failures

Who it’s for

Rails teams that want a static inventory of types, nil risks, request paths, N+1 findings, and unsupported gems.
Developers evaluating whether a conventional Rails app can move to Rust, Go, TypeScript, or another supported target.
Claude Code or Cursor users who want source-derived answers about filters, views, routes, and model relationships.
Compiler researchers willing to verify generated output against the original Rails application.

Who it’s NOT for

Teams expecting a drop-in conversion of any Rails app: the current guide guarantees every target only against its Rails 8 blog fixture, while wider Campfire coverage belongs to the Ruby and Spinel lanes.
Apps built around runtime metaprogramming, dynamic loading, framework monkey patches, or unknown gem DSLs: the coverage guide lists those shapes as unsupported or survey gaps.
Browser-facing services that need Rails-equivalent CSRF protection on a strict target: those targets issue no token and perform no check.
Windows or Intel Mac teams that require a fully exercised binary: release archives exist, but CI tests only roundhouse --version on those builds.
Release gates that require a green fresh-container suite: our cargo test run ended with 82 failures.

Setup reality

Our sandbox installed commit 497ff91 in 18 seconds, pulling 62 packages. The build succeeded in 152 seconds. Cargo test failed with exit 101 after 254 seconds: 1,644 tests passed and 82 failed out of 1,726. The final library result shown in the log was 822 passed and 41 failed.

The release binary needs no Ruby, gems, database, or credentials to analyze source. Building Roundhouse itself requires Rust 1.85 or later plus clang and libclang. Generated projects need their target toolchain, and Spinel output needs the separate Spinel compiler.

Linux x86-64 and Apple silicon macOS are the daily-tested binary platforms. Intel macOS and Windows archives only get a version check. Server targets default to SQLite and port 3000, and strict targets do not verify CSRF tokens.

Roundhouse analyzes Rails source without booting the app

Roundhouse reads routes, models, controllers, templates, schema, and framework conventions without booting the application or touching its database. From that source it infers types, nil risks, request traces, unsupported gems, and possible N+1 queries. The result appears through roundhouse check, an LSP server, a browser IDE, or an MCP server. For a Rails team, this is the least disruptive part of the project because it produces a report instead of a replacement application.

The binary accepts 13 target names across server runtimes, Ruby variants, and Spinel. Static findings can help even when coverage is incomplete. Generated services take ownership of HTTP behavior, persistence, sessions, templates, and security, so every unsupported construct becomes a migration decision rather than a diagnostic you can postpone.

What happened when we ran it

Our sandbox installed commit 497ff91 in 18 seconds and pulled 62 packages. The build succeeded in 152 seconds. Our lab measured those steps in an unprivileged Debian container with 3 CPUs, 12 GB of RAM, Rust, and no secrets. The checkout held 1,520 files, about 401,364 lines of source, and occupied 19.8 MB. We also found 2 CI workflow files, a tests directory, and no Dockerfile.

Cargo test failed with exit 101 after 254 seconds. Across the supplied run, 1,644 tests passed and 82 failed out of 1,726. The log tail repeated a library result of 822 passed and 41 failed, then suggested rerunning with --lib. Named failures covered MCP traces and type resolution, stale seed replacement, application seed generation, and a web-push stub. The tail does not show why those assertions failed, so assigning one common cause would be guesswork.

The 1,644 passes show substantial coverage, but 82 failures block a clean release claim. Roundhouse's README says the default suite must pass before any commit. Other ignored checks exercise generated toolchains and frameworks, while our measurement covers the cargo test result in the supplied sandbox. We did not verify emitted applications against live Rails or measure their request speed.

Unknown constructs stop all 13 transpile targets by default

Roundhouse uses strict ingestion before any of its 13 target names. An unrecognized construct stops transpilation, while --survey records gaps and --allow-unsupported emits marked stubs. The guide calls that combined output a survey rather than something deployable. A missing controller filter or route hidden by a successful command would be much worse than a refusal to emit.

Generated projects bring their own toolchains. Rust needs Rust 1.85 or later and SQLite, Go needs Go 1.24 or later, Swift needs Swift 6 or later, and the other targets have similar floors. Every emitted tree also carries seed SQL and target-specific tests. Generate into a clean directory because the command overwrites matching files but does not remove files left by an older run.

The source app also decides whether conversion is realistic. Roundhouse cannot lower method names built at runtime, eval, method_missing, computed requires, some framework monkey patches, or behavior supplied only through an unknown gem DSL. Its survey names these gaps and their locations. On a dynamic Rails codebase, that inventory may be the project's most useful output even if none of the 13 emitters is ready to ship it.

All targets cover Rails 8 blog features, Campfire is Ruby and Spinel only

The coverage guide defines two levels. Every server target is checked against a Rails 8 blog fixture with standard models, nested routes, validations, Turbo Streams, Action Cable, Tailwind, and JSON endpoints. The larger Campfire application proves more Rails behavior only for the emitted Ruby shape and Spinel. Features such as richer Active Record relations, attachments, full text, sessions, and more controller behavior do not automatically inherit the blog's all-target promise.

The first snapshot reports the gap honestly. Its Mastodon analysis found 674 errors, 138 ingest gaps across 20 kinds, and 61 gems the analyzer did not model. Those are project-reported results, separate from our 1,726-test sandbox run. An open issue also documents a ViewComponent app that passed check with zero diagnostics yet emitted code that raised NameError while loading. A clean report therefore needs a generated build, translated tests, and differential requests against Rails behind it.

Strict targets do not verify CSRF tokens

Security behavior varies by target. The current guide says the Ruby family verifies CSRF when the application explicitly declares protect_from_forgery with: :exception. Strict targets issue no token and perform no verification. Even the Ruby family does not apply Rails' implicit default, and its session cookies are signed rather than encrypted. An operator must read these as runtime differences, not compiler trivia.

The 82 failed tests in our run do not establish a CSRF defect. The security limit comes from Roundhouse's coverage guide. If you expose generated code to browsers, put strict-target output behind a trusted protection layer and test form, session, Origin, and WebSocket behavior. DOM comparison can prove response shape, but matching HTML alone does not prove the same security boundary.

The September 18 snapshot has active follow-up work

Release v2026.9.18 is labeled the first snapshot. GitHub recorded a push on September 30, 2026, with 73 open issues and 11 open pull requests that day. Current reports cover route emission and output that differs between runs. The work continues after the tag, but the compatibility surface is young.

Roundhouse is worth installing for check, request tracing, and agent questions because those uses leave Rails in charge. Transpilation deserves a narrower trial on one application and one target. Our 152-second build shows the Rust project compiles at 497ff91, while the 82 failures show why generated production code still needs its own Rails comparison and security review before traffic moves.

Alternatives

ProjectWhat it isPick it when
SorbetA mature static type checker for Ruby with an annotation-based workflow.pick this instead when type checking the existing Ruby application matters more than generating a new runtime.
Ruby LSPAn editor language server focused on navigation, completion, diagnostics, and Ruby development tasks.pick this instead when editor assistance is the goal and you do not need whole-app transpilation.
SpinelMatz's ahead-of-time compiler for turning Ruby programs into native executables.pick this instead when native Ruby compilation is the only target and Rails-specific analysis is outside the job.

What people are saying

  1. [github-trending] rubys/roundhouse

Sources

  1. Roundhouse repository and README
  2. Roundhouse installation guide
  3. Roundhouse Rails coverage and security posture
  4. Roundhouse transpilation guide
  5. Roundhouse v2026.9.18 release
  6. ViewComponent clean-check emission issue

More dev tools reviews

lipgloss · GhostTrack · Codex-Dream-Skin · TokenTracker · firebase-ios-sdk · awesome-cli-apps · the whole board →