Skip to content

feat(runtime): integrate public Servo HTTP app origins on Unix - #1

Merged
Travis-Gilbert merged 9 commits into
mainfrom
integration/servo-0.5-unix
Sep 8, 2026
Merged

Travis-Gilbert merged 9 commits into
mainfrom
integration/servo-0.5-unix

Conversation

@Travis-Gilbert

@Travis-Gilbert Travis-Gilbert commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • adopt exact-revision public Servo and Tauri integration sources for the Unix runtime lane
  • serve ordinary assets and modules through HTTP tuple origins while preserving authenticated IPC, CSP, CORS, and frame-denial boundaries
  • reject worker IPC callers even when they share a document identity
  • keep versioned public-source patches and lock-family checks in the repository
  • exercise Linux and macOS compile, API, and native security lanes

Current proof

  • authenticated IPC fix at be7bb18 passed exact CI run 33567283891 on Linux and macOS
  • both native lanes passed local-frame-worker while recording no worker command dispatch
  • current PR head 8137e2f has green Linux/macOS builds, format/package, Servo integration policy, Tauri opener compatibility, CodeRabbit, and GitGuardian checks
  • completion graph generation 6 closes W02I/V02I and leaves W03 as the current frontier

Deliberate release boundaries

  • Windows remains deferred as O13/WX1
  • crates.io publication remains blocked on the published-engine E02 requirement
  • popup behavior and the shared-engine milestone remain open
  • performance, memory, startup-time, and binary-size claims remain unevidenced until benchmark receipts exist

This PR remains draft while the remaining integration and publication gates are executed.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: 96f9589c-7373-444e-95c8-1e6f6c1e737e


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ecc-tools

ecc-tools Bot commented Sep 1, 2026

Copy link
Copy Markdown

Analyzing 200 commits...

@ecc-tools

ecc-tools Bot commented Sep 1, 2026

Copy link
Copy Markdown

Analysis Complete

Generated ECC bundle from 5 commits | Confidence: 65%

View Pull Request #2

Repository Profile
Attribute Value
Language Rust
Framework Rust
Commit Convention conventional
Test Directory separate
Changed Files (78)
Metric Value
Files changed 78
Additions 4570
Deletions 519

Top hotspots

Path Status +/-
patches/servo/0001-policy-preserving-http-interception.patch added +1669 / -0
plans/TURVO-1.0-COMPLETION/plan-definition.json modified +1059 / -240
patches/tauri/0002-runtime-http-app-origins.patch added +548 / -0
Cargo.lock modified +65 / -127
crates/turvo/src/servo/protocols.rs modified +142 / -6

Top directories

Directory Files Total changes
patches/servo 5 1803
plans/TURVO-1.0-COMPLETION 11 1466
patches/tauri 3 599
plans/TURVO-1.0-COMPLETION/nodes 32 284
. 5 249
Analysis Depth Readiness (evidence-backed, 57%)

ECC Tools uses this to decide whether recommendations should stay at commit-history/setup guidance or expand into CI, security, harness, reference-set, AI-routing, and team backlog work.

Area Status Evidence / Next Step
Commit history Ready 5 commits sampled
CI/CD signals Ready .github/workflows/ci.yml, .github/workflows/integration-lockfile.yml, .github/workflows/servo-integration.yml
Security evidence Ready examples/security/README.md, examples/security/attacker.js, examples/security/dynamic-module.js
Harness configuration Missing Add Claude, Codex, OpenCode, Zed, dmux, MCP, plugin, or cross-harness config evidence for harness-agnostic recommendations.
Reference/eval evidence Missing Add fixtures, golden traces, reference sets, or evaluator benchmarks so deeper recommendations have regression evidence.
AI routing and cost controls Ready plans/TURVO-1.0-COMPLETION/CONTINUITY.md, plans/TURVO-1.0-COMPLETION/disagreements.md, plans/TURVO-1.0-COMPLETION/edges.md
Team handoff and project tracking Missing Add roadmap, runbook, project, Linear, or follow-up tracking docs so generated work can land in a team queue.
Reference Set Readiness (1/7, 14%)
Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Present examples/security/README.md, examples/security/attacker.js, examples/security/dynamic-module.js
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.
Likely Future Issues (4)
Severity Signal Why it may show up
HIGH Regression coverage may lag behind the diff 6 generic code paths changed; 0 test files changed
MEDIUM Runtime config changes may ship without example or template updates 1 runtime config paths changed; 0 example or template config files changed
MEDIUM CI workflow changes may ship without failure-mode evidence 6 CI/test-runner paths changed; 0 CI failure-mode evidence artifacts changed
MEDIUM Dependency or CI drift could surface after merge CI/workflow files changed; no lockfile changes detected
  • Regression coverage may lag behind the diff: The PR changes multiple code paths but does not touch any obvious test files.
  • Runtime config changes may ship without example or template updates: The PR changes runtime config or deployment settings but does not update any obvious example env file or config template.
  • CI workflow changes may ship without failure-mode evidence: The PR changes CI workflows or test-runner entrypoints without touching CI failure fixtures, captured logs, troubleshooting notes, or regression evidence.
  • Dependency or CI drift could surface after merge: Package or workflow changes landed without an accompanying lockfile update, which often turns into CI or release noise later.
Suggested Follow-up Work (4)
Type Suggested title Targets
PR test: add regression coverage for crates/turvo/src/lib.rs + crates/turvo/src/servo/embedder.rs crates/turvo/src/lib.rs, crates/turvo/src/servo/embedder.rs
PR chore: sync config templates for examples/security/tauri.conf.json examples/security/tauri.conf.json
PR ci: add failure-mode evidence for .github/workflows/ci.yml + .github/workflows/integration-lockfile.yml .github/workflows/ci.yml, .github/workflows/integration-lockfile.yml
PR chore: refresh lockfile and validate CI after dependency updates .github/workflows/ci.yml, .github/workflows/integration-lockfile.yml, .github/workflows/servo-integration.yml
  • test: add regression coverage for crates/turvo/src/lib.rs + crates/turvo/src/servo/embedder.rs: Backfill regression coverage before another change set lands on the touched code paths.
  • chore: sync config templates for examples/security/tauri.conf.json: Backfill example env files or config templates before a fresh setup drifts from the shipped runtime surface.
  • ci: add failure-mode evidence for .github/workflows/ci.yml + .github/workflows/integration-lockfile.yml: Backfill CI failure-mode evidence before another workflow or test-runner change lands on the touched surface.
  • chore: refresh lockfile and validate CI after dependency updates: Package or workflow changes without a lockfile refresh tend to turn into noisy follow-up fixes after merge.

Copy-ready bodies

test: add regression coverage for crates/turvo/src/lib.rs + crates/turvo/src/servo/embedder.rs

## Summary
- Add regression coverage for the recently touched code paths before more changes stack on top.

## Why
- Backfill regression coverage before another change set lands on the touched code paths.

## Touched paths
- `crates/turvo/src/lib.rs`
- `crates/turvo/src/servo/embedder.rs`

## Validation
- Add or extend focused tests that exercise the touched paths.
- Run the affected test suite and verify the new coverage closes the gap.

chore: sync config templates for examples/security/tauri.conf.json

## Summary
- Update the example env files, sample configs, or deployment templates that should mirror the changed runtime configuration surface.

## Why
- Backfill example env files or config templates before a fresh setup drifts from the shipped runtime surface.

## Touched paths
- `examples/security/tauri.conf.json`

## Validation
- Update the repo example env file or config template that should reflect the new runtime settings.
- Run the setup, boot, or deployment validation flow that depends on the changed config surface.

ci: add failure-mode evidence for .github/workflows/ci.yml + .github/workflows/integration-lockfile.yml

## Summary
- Add CI failure-mode evidence for the recently changed workflow or test-runner surface.

## Why
- Backfill CI failure-mode evidence before another workflow or test-runner change lands on the touched surface.

## Touched paths
- `.github/workflows/ci.yml`
- `.github/workflows/integration-lockfile.yml`

## Validation
- Add or update a CI failure fixture, captured failing log, troubleshooting note, workflow dry-run evidence, or regression test for the changed CI/test-runner behavior.
- Run the affected workflow or test-runner entrypoint locally or in CI and record pass/fail evidence.

chore: refresh lockfile and validate CI after dependency updates

## Summary
- Refresh the lockfile and rerun CI after the dependency or workflow changes in this PR.

## Why
- Package or workflow changes without a lockfile refresh tend to turn into noisy follow-up fixes after merge.

## Touched paths
- `.github/workflows/ci.yml`
- `.github/workflows/integration-lockfile.yml`
- `.github/workflows/servo-integration.yml`

## Validation
- Refresh the lockfile in the same package manager used by the repo.
- Run the repo typecheck / test / CI entrypoints that depend on the updated package graph.
Generated Instincts (6)
Domain Count
git 2
code-style 3
testing 1

After merging, import with:

/instinct-import .claude/homunculus/instincts/inherited/Turvo-instincts.yaml

Files

  • .claude/ecc-tools.json
  • .claude/skills/Turvo/SKILL.md
  • .agents/skills/Turvo/SKILL.md
  • .agents/skills/Turvo/agents/openai.yaml
  • .claude/identity.json
  • .codex/config.toml
  • .codex/AGENTS.md
  • .codex/agents/explorer.toml
  • .codex/agents/reviewer.toml
  • .codex/agents/docs-researcher.toml
  • .claude/homunculus/instincts/inherited/Turvo-instincts.yaml

ECC Tools | Everything Claude Code

@Travis-Gilbert
Travis-Gilbert marked this pull request as ready for review September 1, 2026 22:11
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T22:19:41.286854Z 44de561 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 44de561f4c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +78 to +82
Url::parse(&format!(
"{transport}://{}.localhost{}",
url.scheme(),
&url[url::Position::BeforePath..]
))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reject worker IPC before enabling tuple app origins

When a same-origin child frame passes the invoke key to a Worker, this HTTP mapping gives that worker the top document's tuple origin, while SourceTracker::authenticate only rejects client.is_nested_browsing_context; Servo represents workers as non-nested clients, so the worker reaches privileged IPC despite its owning frame being denied. The newly added local-frame-worker probe exercises exactly this path, but no production guard distinguishes a Window from a worker, so tuple-origin mapping should not be enabled until worker callers are rejected or bound to their owning document.

AGENTS.md reference: AGENTS.md:L130-L133

Useful? React with 👍 / 👎.

Comment on lines +57 to +58
git apply --check ../patches/tauri/0002-runtime-http-app-origins.patch
git apply ../patches/tauri/0002-runtime-http-app-origins.patch

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Test the Tauri revision that Cargo actually consumes

When the public integration revision contains any follow-up or otherwise differs from the base plus these two patches, this job still tests a reconstructed tree at the hardcoded upstream base rather than e84733018d84c8004645e04cbc8fea8511ae36b1, which is the revision selected by Cargo.toml and patches/tauri/integration.json. Because the workflow never reads that repository/revision, a green compatibility result does not validate the Tauri source shipped in the runtime; check out the recorded revision and reverse-check the patches (as the Servo lane does), or explicitly compare its tree with the reconstructed one.

AGENTS.md reference: AGENTS.md:L93-L95

Useful? React with 👍 / 👎.

Comment thread crates/turvo/src/lib.rs
}

impl<T: UserEvent> Runtime<T> for Servo<T> {
const CUSTOM_PROTOCOLS_USE_HTTP: bool = true;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve frame isolation when making app documents same-origin

When an application embeds an unsandboxed app-origin iframe, opting the runtime into HTTP tuple origins makes that child same-origin with the top document, so it can access window.top.__TAURI__ or window.top.__TAURI_INTERNALS__ even though initialization scripts were not injected into the child. Calling the parent's invoke function executes its fetch in the top-level realm, which presents top-Window provenance and the local origin to both SourceTracker and Tauri, bypassing the nested-client rejection entirely. The local-frame fixture only checks that globals are absent on the child and sends raw IPC from the child realm, so it does not cover this direct parent-capability borrowing path; the top-level API must be isolated from same-origin children or validate the actual caller before frame denial can be claimed.

AGENTS.md reference: AGENTS.md:L93-L95

Useful? React with 👍 / 👎.

@Travis-Gilbert
Travis-Gilbert marked this pull request as draft September 1, 2026 22:28
@Travis-Gilbert
Travis-Gilbert marked this pull request as ready for review September 6, 2026 17:15
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@Travis-Gilbert
Travis-Gilbert merged commit 37ca044 into main Sep 8, 2026
7 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant