Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
components: rustfmt
toolchain: 1.94.0
toolchain: 1.95.0
- name: Check formatting
run: cargo fmt --all --check
- name: Test JavaScript IPC transport
Expand Down Expand Up @@ -87,7 +87,7 @@ jobs:
with:
components: clippy
targets: ${{ matrix.platform.target }}
toolchain: 1.94.0
toolchain: 1.95.0

- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
Expand All @@ -101,6 +101,9 @@ jobs:
- name: Test runtime
run: cargo test -p turvo --lib --tests --locked --target ${{ matrix.platform.target }}

- name: Verify origin-boundary negative cases
run: cargo test -p turvo --lib --locked --target ${{ matrix.platform.target }} servo::ipc::tests

- name: Lint runtime
run: cargo clippy -p turvo --lib --tests --locked --target ${{ matrix.platform.target }} -- -D warnings

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/integration-lockfile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
persist-credentials: false
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: 1.94.0
toolchain: 1.95.0
- name: Verify public source metadata
run: python3 scripts/check_integration.py --metadata-only
- name: Resolve new sources while retaining other locked versions
Expand Down
68 changes: 58 additions & 10 deletions .github/workflows/servo-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,18 @@ name: Servo integration policy

on:
push:
branches: ['integration/**']
branches: ['integration/**', next]
paths:
- Cargo.toml
- Cargo.lock
- rust-toolchain.toml
- patches/servo/**
- .github/workflows/servo-integration.yml
pull_request:
paths:
- Cargo.toml
- Cargo.lock
- rust-toolchain.toml
- patches/servo/**
- .github/workflows/servo-integration.yml
workflow_dispatch:
Expand Down Expand Up @@ -38,14 +44,15 @@ jobs:
- name: Read the versioned public engine pin
id: engine
shell: bash
run: jq -r '"repository=\(.repository)\nrevision=\(.revision)"' patches/servo/integration.json >> "$GITHUB_OUTPUT"
run: jq -r '"upstream_repository=\(.upstream_repository)\nrepository=\(.repository)\nrevision=\(.revision)\nbranch=\(.branch)\nbase_revision=\(.base_revision)\nahead_by=\(.ahead_by)\nbehind_by=\(.behind_by)\nrust_channel=\(.rust_channel)"' patches/servo/integration.json >> "$GITHUB_OUTPUT"
- name: Check out the exact public engine revision
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
repository: ${{ steps.engine.outputs.repository }}
ref: ${{ steps.engine.outputs.revision }}
path: pinned-servo
persist-credentials: false
fetch-depth: 0
sparse-checkout: |
.cargo
components
Expand All @@ -55,12 +62,43 @@ jobs:
support
tests/unit
tests/capi
- name: Verify the versioned patch is present
- name: Verify the published branch and v0.5.0 lineage
working-directory: pinned-servo
shell: bash
run: |
test "$(git rev-parse HEAD)" = "${{ steps.engine.outputs.revision }}"
test "$(git ls-remote https://github.com/${{ steps.engine.outputs.repository }}.git refs/heads/${{ steps.engine.outputs.branch }} | cut -f1)" = "${{ steps.engine.outputs.revision }}"
git fetch "https://github.com/${{ steps.engine.outputs.upstream_repository }}.git" refs/tags/v0.5.0:refs/tags/v0.5.0
test "$(git rev-parse refs/tags/v0.5.0^{commit})" = "${{ steps.engine.outputs.base_revision }}"
git merge-base --is-ancestor "${{ steps.engine.outputs.base_revision }}" HEAD
read -r behind_by ahead_by < <(git rev-list --left-right --count "${{ steps.engine.outputs.base_revision }}...HEAD")
echo "lineage: ahead_by=$ahead_by behind_by=$behind_by"
test "$ahead_by" = "${{ steps.engine.outputs.ahead_by }}"
test "$behind_by" = "${{ steps.engine.outputs.behind_by }}"
engine_channel="$(python3 -c 'import pathlib, tomllib; print(tomllib.loads(pathlib.Path("rust-toolchain.toml").read_text())["toolchain"]["channel"])')"
embedder_channel="$(python3 -c 'import pathlib, tomllib; print(tomllib.loads(pathlib.Path("../rust-toolchain.toml").read_text())["toolchain"]["channel"])')"
echo "rust channel: servo=$engine_channel turvo=$embedder_channel"
test "$engine_channel" = "${{ steps.engine.outputs.rust_channel }}"
test "$embedder_channel" = "${{ steps.engine.outputs.rust_channel }}"
- name: Verify the ordered versioned patch stack
shell: bash
run: |
git apply --reverse --check ../patches/servo/0003-shared-network-test-runtime.patch
git apply --reverse --check ../patches/servo/0002-cancellation-feature-lockfile.patch
git apply --reverse --check ../patches/servo/0001-policy-preserving-http-interception.patch
patch_index="$RUNNER_TEMP/pinned-servo-patch-stack.index"
test ! -e "$patch_index"
GIT_INDEX_FILE="$patch_index" git -C pinned-servo read-tree HEAD
for patch in \
0009-web-locks-and-window-proxies.patch \
0008-indexeddb-conformance-slice.patch \
0007-sendable-web-resource-responders.patch \
0006-align-jemalloc-consumer-graph.patch \
0005-storage-engine-factories.patch \
0004-fix-security-identify-window-backed-requests.patch \
0003-shared-network-test-runtime.patch \
0002-cancellation-feature-lockfile.patch \
0001-policy-preserving-http-interception.patch
do
GIT_INDEX_FILE="$patch_index" git -C pinned-servo apply --cached --reverse "$GITHUB_WORKSPACE/patches/servo/$patch"
done
- name: Install Linux networking test prerequisites
if: runner.os == 'Linux'
run: |
Expand All @@ -69,7 +107,7 @@ jobs:
echo "RUSTFLAGS=-C link-arg=-fuse-ld=lld" >> "$GITHUB_ENV"
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
toolchain: 1.94.0
toolchain: 1.95.0
components: rustfmt
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
Expand All @@ -78,15 +116,23 @@ jobs:
cache-on-failure: true
- name: Check new adapter and regression-test formatting
working-directory: pinned-servo
run: rustfmt +1.94.0 --edition 2024 --check components/net/request_interceptor.rs components/net/tests/interception.rs
run: rustfmt +1.95.0 --edition 2024 --check components/net/request_interceptor.rs components/net/tests/interception.rs
- name: Check the file-manager fixture in isolation
working-directory: pinned-servo
shell: bash
run: cargo +1.94.0 test -p servo-net --test main --locked filemanager_thread::test_filemanager -- --exact 2>&1 | tee filemanager-test.log
run: cargo +1.95.0 test -p servo-net --test main --locked filemanager_thread::test_filemanager -- --exact 2>&1 | tee filemanager-test.log
- name: Run all engine networking regression tests
working-directory: pinned-servo
shell: bash
run: cargo +1.94.0 test -p servo-net --test main --locked 2>&1 | tee net-tests.log
run: cargo +1.95.0 test -p servo-net --test main --locked 2>&1 | tee net-tests.log
- name: Run storage engine regression tests
working-directory: pinned-servo
shell: bash
run: cargo +1.95.0 test -p servo-storage --lib --locked 2>&1 | tee storage-tests.log
- name: Run request-client identity tests
working-directory: pinned-servo
shell: bash
run: cargo +1.95.0 test -p servo-net-traits --test request_client --locked 2>&1 | tee request-client-tests.log
- name: Retain exact engine test receipt
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand All @@ -95,4 +141,6 @@ jobs:
path: |
pinned-servo/net-tests.log
pinned-servo/filemanager-test.log
pinned-servo/storage-tests.log
pinned-servo/request-client-tests.log
if-no-files-found: ignore
31 changes: 17 additions & 14 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,10 +74,11 @@ Tech Stack: Rust, Tauri 2, Servo, Tao, GitHub Actions

## Overview

Turvo is a desktop-only Tauri runtime that embeds a pinned Servo engine in
process. It aims to provide an Electron-class application shell without a
bundled Chromium runtime while keeping engine choice deterministic across
Linux, Windows, and macOS.
Turvo is the Servo integration home for the Theorem desktop. It owns the exact
Servo pin, migration lane, hosted engine proof, and desktop bundling path. GPUI
owns Theorem's native windows and chrome. Turvo's existing desktop-only Tauri
runtime is one consumer of the in-process Servo embedding, not the repository's
product boundary.

Performance, memory, startup-time, and binary-size claims require benchmark
receipts and must not be presented as established project facts.
Expand All @@ -91,12 +92,12 @@ receipts and must not be presented as established project facts.
| API parity probe | Invoke/events/window commands implemented, not locally launched | `examples/api` |
| DevTools | Secure configuration implemented, native attachment pending | Record 001 A4 |
| Cross-platform CI | Linux/macOS required for current integration; Windows explicitly deferred with failing security receipts retained | Record 002; graph O13/WX1 |
| Completion graph | W02I/V02I complete on `integration/servo-0.5-unix`; W03 and W05 are the next implementation frontier | `plans/TURVO-1.0-COMPLETION/CONTINUITY.md` |
| Public integration | Exact public Servo/Tauri pins adopted; ordinary assets/modules and worker/hostile-frame denials pass natively on Linux/macOS | CI run 33567283891; Record 002; `patches/servo` |
| Completion graph | The prior standalone completion graph retains historical receipts; the Theorem desktop-shell addendum governs the current cross-repository migration | Record 003; `plans/TURVO-1.0-COMPLETION/CONTINUITY.md` |
| Public integration | `next` pins the unified `Travis-Gilbert/servo:theorem/v0.5.0` fork at `e92cdaa7`; promotion awaits required Linux/macOS CI | draft PR #3; Record 003; `patches/servo/FORK.md` |
| Tauri opener proposal | Public opener seam adopted and compatibility green; actual Servo popup metadata and integration remain open | CI run 33357076684; `patches/tauri` |
| Monthly Servo lane | Defined, not demonstrated | `.github/workflows/servo-next.yml` |
| Monthly Servo lane | Active on `next`; draft migration PR opened | draft PR #3; `.github/workflows/servo-next.yml` |
| crates.io release | Pending | Acceptance A7 in Record 001 |
| Theorem integration | Pending and separately owned | Acceptance A8 in Record 001 |
| Theorem integration | Pending after Turvo promotion; Turvo owns Servo integration and Theorem consumes it without a duplicate pin | Record 003 |

## Recent Decisions

Expand All @@ -108,6 +109,8 @@ receipts and must not be presented as established project facts.
| 2026-08-30 | Separate compile CI from native behavior proof | Successful compilation does not demonstrate rendering, IPC, origin security, or window behavior. |
| 2026-08-30 | Relay monthly agent changes as a scoped patch through fresh jobs | The migration agent should not receive a GitHub token, and credentialed PR creation must not execute agent-modified code. |
| 2026-08-30 | Proceed with public exact-revision Servo/Tauri integration without repeated confirmation; defer Windows | Explicit user correction; preserve Linux/macOS security checks, published-release gates, and Theorem-owned branches. See Record 002. |
| 2026-09-13 | Make Turvo the sole home of Theorem's Servo integration while GPUI retains native window and chrome ownership | Removes duplicate engine-pin authority; the Tauri runtime remains one consumer. See Record 003. |
| 2026-09-13 | Treat arbitrary third-party pages as supported scope | The Theorem desktop compatibility matrix requires remote sites; origin-boundary negative tests are mandatory. See Record 003. |

## Development Commands

Expand All @@ -127,9 +130,9 @@ build graph.

## Next Step

Continue W03 on `integration/servo-0.5-unix`; read `CONTINUITY.md` and Record 002.
Public pinned Servo/Tauri patches are authorized. Complete the real Servo popup
metadata and runtime integration without fabricating Wry-native state. Linux/macOS
native behavior remains mandatory. Windows is O13/WX1; published-engine release
is E02. Neither deferred obligation is complete, and existing Theorem branches
stay intact.
Finish the `next` migration in draft PR #3 and require the Servo policy plus
ordinary Linux/macOS CI to pass before promotion to `main`. Then let Theorem
consume Turvo and remove its duplicate Servo pin authority. Read Record 003
before the older standalone completion graph: its W03/W05 backlog remains, but
it does not override the current ownership, branch, or third-party-site scope.
Windows remains deferred under O13/WX1, and publication remains gated by E02.
Loading