Turvo is the Servo integration home for the Theorem desktop. It owns the exact engine pin, migration lane, hosted engine proof, and desktop bundling path. GPUI owns Theorem's native windows and chrome; Turvo supplies the in-process Servo embedding. The existing Tauri runtime is one consumer of that embedding, not Turvo's product boundary.
The project is aiming for an Electron-class application shell without bundling Chromium. Performance, memory, startup-time, and binary-size claims are deliberately deferred until Turvo has a reproducible benchmark suite.
Active integration work is Linux/macOS-first on next, through draft PR #3.
That lane pins Travis-Gilbert/servo:theorem/v0.5.0 at an exact revision before
promotion to main; Windows is explicitly deferred, not verified. The
published-engine release contract remains gated. See
Record 003 for the ownership
and scope change.
Turvo is pre-release software. The repository currently contains:
- an in-process Servo 0.5.0 runtime over Tao and
tauri-runtime2.11.3; - Tauri
Runtime,RuntimeHandle, window, and webview dispatcher implementations; - bundled-asset/custom-protocol plumbing and a Servo-compatible Tauri IPC bridge;
- a
turvo::builder()entry point; - opt-in Firefox remote devtools via
builder_with_options; - a minimal bundled-HTML example;
- an API probe for invoke, events, and runtime-managed windows; and
- required compile/test CI for Linux and macOS, with Windows deferred.
Cross-platform compilation is not the same as cross-platform runtime proof.
The published-engine baseline's native IPC/security fixture passes on Linux and
macOS. Windows boots with ANGLE and reaches IPC, but its mapped-asset path fails
cross-origin and CSP checks. The public integration's ordinary
fetch()/HEAD/static-module/dynamic-module tests pass on Linux/macOS; full native
acceptance still awaits the sandbox-probe correction and exact-tip rerun.
Source and automated review are not runtime proof.
Do not use this pre-release bootstrap in production until its required
origin-boundary and third-party compatibility gates pass. Arbitrary remote
pages and frames are nevertheless part of the supported product scope.
The protocol audit
records the engine API limitations and required negative tests.
The acceptance matrix in Record 001 tracks which behaviors are wired, compiled, and actually observed.
Turvo 0.1.0 is not published yet. The two edits below describe the release interface; until publication, use the checked-out examples in this repository. The integration's root-level Cargo overrides are not inherited by external consumers. Copying the two-edit example into another workspace cannot use these unreleased APIs yet; that clean-consumer check remains a release gate.
Disable Tauri's default Wry runtime and add Turvo:
[dependencies]
tauri = { version = "=2.11.5", default-features = false, features = [
"common-controls-v6",
] }
turvo = "0.1.0"Then change the application builder:
fn main() {
turvo::builder()
.run(tauri::generate_context!())
.expect("failed to run the application");
}For Firefox remote debugging, configure a non-zero loopback port before the first webview starts.
fn main() {
let options = turvo::TurvoOptions::default()
.try_with_devtools_port(7000)
.expect("the DevTools port must be non-zero")
// Servo calls this only when a client did not present its generated token.
// Replace this development-only approval with an application prompt.
.with_devtools_connection_handler(|| cfg!(debug_assertions));
turvo::builder_with_options(options)
.expect("Turvo options were configured too late")
.run(tauri::generate_context!())
.expect("failed to run the application");
}Connect from Firefox's about:debugging page. Turvo binds the server to
127.0.0.1. Tokenless clients are denied unless the application-supplied
connection handler approves them. A with_devtools_server_handler callback is
available for clients that can use Servo's generated authentication token;
Turvo redacts that token from debug output and never logs it.
Turvo 0.1 attaches a fixed DevTools port to the first Servo engine only. Port
0 is rejected because Servo 0.5 does not report its actual ephemeral port to
the embedder.
cargo run -p helloworld
cargo run -p turvo-apiThe first Servo build is large. Keep MOZJS_FROM_SOURCE unset so mozjs_sys
can use a prebuilt SpiderMonkey artifact where one is available. Do not start a
local build without ample free disk space; hosted CI is the authoritative
compile lane for the active Linux/macOS integration targets.
mainpins the current Servo LTS release exactly.nextis the monthly migration lane. Its scheduled workflow asks a coding agent to update Servo and repair API churn. The agent receives prefetched dependencies but no GitHub token or shell network access; fresh jobs validate its scoped patch and open a draft PR againstnext.- A failing
nextmigration does not blockmain; it is an early warning for the next LTS update.
The scheduled agent workflow expects an OPENAI_API_KEY Actions secret. Its
default model is GPT-5.3 Codex Spark and can be overridden with the
TURVO_MIGRATION_MODEL repository variable.
Turvo is the desktop home of Theorem's Servo integration. It must preserve web origin boundaries for application content and third-party sites alike; remote, nested, opaque, and sandboxed callers never inherit local application capabilities or bundled-asset authority. Compatibility defects against third-party sites are in scope when they violate the supported web-platform or security contract. Mobile targets keep Tauri's Wry runtime; Turvo is desktop-only.
For an application that also ships on mobile, make the runtime dependency target-specific so the desktop graph does not enable Wry and the mobile graph does not compile Turvo:
[target.'cfg(not(any(target_os = "android", target_os = "ios")))'.dependencies]
tauri = { version = "=2.11.5", default-features = false, features = [
"common-controls-v6",
] }
turvo = "0.1.0"
[target.'cfg(any(target_os = "android", target_os = "ios"))'.dependencies]
tauri = { version = "=2.11.5" }Select turvo::builder() in the desktop entry point and
tauri::Builder::default() in the mobile entry point. Keep application setup
behind a shared function so runtime selection is the only platform-specific
branch.
The runtime began from the dual-licensed implementation in
copse-dev/tauri-runtime-servo
at commit
b9d4ef11.
Original copyright and SPDX headers are preserved. Turvo's changes include the
public builder API, exact engine policy, devtools configuration, acceptance
tracking, and the maintenance workflows.
Licensed under either MIT or Apache-2.0, at your option. Servo remains MPL-2.0 as a dependency.