Buz Forks Bun to Prove Zig Was Fast Enough
A post-Rust-rewrite fork hits sub-second incremental builds — but speed was never the official reason Bun left Zig.
A pseudonymous developer going by jazzzooo has forked Bun at its last commit before the runtime's move to Rust, ported the whole thing to current Zig master, and collapsed its notoriously gnarly build — JavaScriptCore and ICU included — into a single build.zig that rebuilds incrementally in under a second. The project is called Buz, and on the merits it's an early-stage experiment that its own README tells you not to run. But that's not really the point. Buz is a counterfactual with a repo attached: a demonstration of what the Zig-era Bun could have been, published two months after its corporate parent decided Zig-era Bun was over.
The context, because the context is everything
Anthropic acquired Oven, the company behind Bun, in December 2025. In May 2026, Bun creator Jarred Sumner announced that the runtime had been ported from Zig to Rust in eleven days, using roughly 64 Claude agents running in parallel — 6,502 commits, about a million lines of Rust, an estimated $165,000 in API costs. Version 1.3.14 was declared the last Bun written in Zig. Sumner's stated rationale was memory safety: a dozen recurring categories of heap-use-after-free, double-free, and leak bugs that manual discipline and defer weren't containing at the scale of a roughly 600,000-line codebase.
The Zig community did not take it gracefully, and not without cause. Zig creator Andrew Kelley called the result "unreviewed slop" and made a sharper argument underneath the insult: if Bun's test suite failed to catch the memory bugs in the original Zig code, it's a strange instrument for certifying a million lines of machine-generated Rust. There's also history here — Anthropic's Bun team had maintained a Zig compiler fork claiming roughly 4× faster debug compilation, and the Zig project declined those contributions under its policy against AI-generated patches.
Buz walks straight into that fight. Its fork point is the last pre-Rust commit. Its README pointedly notes it is "not endorsed by or affiliated with Oven or its parent company, Anthropic."
What Buz actually demonstrates
Strip away the drama and there's a genuinely interesting engineering artifact here. Bun's Zig build was infamous: a pinned, aging Zig toolchain, a custom WebKit fork built out-of-band with CMake, and from-source builds painful enough that almost nobody did them. Buz replaces all of that with one unified build graph that tracks Zig's master branch and compiles JavaScriptCore and ICU from vendored source. The author also deleted over 11,000 lines of dead code along the way — about 2% of the codebase, which says less about negligence than about what accumulates in any project that ships as aggressively as Bun did.
The sub-second incremental rebuild claim is plausible precisely because of what's happened to Zig since Bun stopped upgrading. Zig's self-hosted x86_64 backend became the default for debug builds in 0.15.1, roughly 5× faster than going through LLVM, and the compiler's incremental compilation now handles external libraries and C sources on x86_64 Linux. Buz is arguably the largest public stress test of that machinery: a 600K-line codebase with heavyweight C++ dependencies, iterating in under a second. Per the author, the bottleneck is no longer the compiler at all — mold linking accounts for around 60% of remaining rebuild time, which Zig's in-progress self-hosted ELF linker (already demonstrating ~30ms incremental relinks on real projects) could eventually eliminate.
That's the uncomfortable irony for both sides. Zig's headline promise since 2020 — lightning-fast incremental compilation via in-place binary patching — finally landed at scale right as its flagship user walked out the door.
What it doesn't demonstrate
Here's where the editorial line has to be drawn: Buz refutes an argument Sumner never officially made. The Rust rewrite's public justification was memory safety, not compile times. A one-second dev loop is lovely, but it doesn't fix a use-after-free in node:http2. Buz inherits, byte for byte, the codebase Sumner described as unsalvageable — along with the same test suite Kelley says can't be trusted, which Buz imports to track its own progress.
And the fork's remediation plan is the same methodology everyone's fighting about. The contribution policy requires that all patches be LLM-assisted, and the roadmap calls for extensive LLM-driven refactoring to pay down technical debt. Commenters on Ziggit and Hacker News spotted the loop immediately: using LLMs to clean up what LLMs allegedly ruined. Whether you find that ironic or pragmatic mostly predicts your position on the whole Bun affair.
The practical read
If you ship on Bun today, nothing here changes your week. Buz builds only for x86_64-linux-gnu, doesn't pass the upstream test suite, and carries known unpatched vulnerabilities plus a JavaScriptCore old enough to be missing current security fixes — the README says "do not use in production" and means it. Upstream Rust Bun, whatever you think of its provenance, has 128 bug fixes since the port, closed its instrumentable memory leaks, and has a funded team tracking WebKit security patches. That last item is the quiet killer for any JSC-based fork: keeping a vendored JavaScript engine current is a full-time treadmill, and a solo maintainer accrues CVEs by default.
Who should actually look at Buz: Zig developers, and anyone doing build engineering on large mixed-language codebases. A working build.zig that wrangles JavaScriptCore and ICU from source is reference material that didn't exist before, and the incremental-build numbers are the best real-world evidence yet for Zig's compilation model at scale.
My honest bet: Buz-the-runtime doesn't survive — one anonymous maintainer against a security treadmill and a million-line divergence is not a fair fight, and even sympathetic commenters question who'd maintain it long-term. But Buz-the-benchmark already succeeded. It established, in public and with receipts, that the Zig toolchain of 2026 delivers the dev loop Bun spent years working around. The Bun–Zig split was about diverging values and development velocity, with memory safety as the shipping label. Buz can't relitigate the divorce. It just makes sure the record shows what got left behind.
Sources & further reading
- Buz - A drop-in replacement for Bun using modern Zig, with sub-1s incremental builds — ziggit.dev
- Buz - A fork of Bun using modern Zig, with sub-1s incremental builds — news.ycombinator.com
- jazzzooo/buz — github.com
- Rewriting Bun in Rust — bun.com
- Zig creator calls Bun's Claude Rust rewrite 'unreviewed slop' — theregister.com
Mariana covers the fast-moving world of machine learning and generative AI, with a particular focus on how these technologies are reshaping development workflows. When she isn't stress-testing the latest foundation models, she's usually at a local hackathon.
Discussion 0
No comments yet
Be the first to weigh in.