Commit Graph
5 Commits
Author SHA1 Message Date
Ryan Hughes 1512cb48d8 chore: sync t3code-bin to 0.0.34
Matches what is already published to edge: 0.0.34 was built on the server
before the bump reached git, so the checkout read as out of date and queued a
rebuild of the older 0.0.33-2 that promotion then refused. Produced by
bin/sync-upstream, the same path the scheduled workflow uses.
2026-08-27 01:16:55 -04:00
Omabot f6d441c235 Drop "(Alpha)" from the T3 Code desktop entry
The entry comes from upstream's AppImage rather than a hand-written one, because that is what carries the t3code:// scheme handlers, and it arrives named "T3 Code (Alpha)" from electron-builder's productName. That name is stale: the app's own code calls it `legacyUserDataDirName` and has already moved its data to ~/.config/t3code, so the launcher was advertising an identity upstream has moved off.

Rewrite Name= alongside the Exec= rewrite already there. The scheme handlers, the MimeType line and the rest of upstream's entry are untouched.

pkgrel goes to 2 because 0.0.33-1 is already published, and a packaging-only change reaches an installed machine only through a new release.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 07:39:16 -07:00
OmabotandCodex XHigh 7ee0003106 Keep the sandbox up on hardened kernels, and stop deleting what we have not read
Three fixes from a review of the previous commit.

Chromium's sandbox helper ships setuid, the way Arch's own electron and chromium packages ship theirs. Dropping --no-sandbox was right, but it left the app relying on unprivileged user namespaces alone: on linux-hardened, or anywhere else they are denied, Electron falls back to the helper and aborts because it is not root-owned 4755.

The AppImage's usr/ tree is now read before it is removed. Deleting it wholesale is correct for what upstream ships today, and the version bumps arrive unattended, so a release that starts putting something needed in there would have had it dropped on the way past without anyone seeing it. Anything that is not a known icon or a known compatibility library stops the build instead.

The upstream hook checks that the feed still names the asset the PKGBUILD builds. It hashes whatever the feed points at, so a rename — or an arm64 build reaching the Linux feed first — would have pinned that file's checksum to a URL nobody fetches, and the failure would have surfaced a build later as a checksum mismatch.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Codex XHigh <codex@openai.com>
2026-08-19 02:56:22 -07:00
Omabot 17b06216fb Own the T3 Code PKGBUILD instead of syncing the AUR's
The AUR package installs the AppImage payload as it comes out of the image: AppRun, .DirIcon, the app's own desktop file and six compatibility libraries — libgconf, libappindicator, libindicator, libXss, libXtst, libnotify — bundled for distributions that do not ship them. Arch does, and nothing in the tree links the bundled copies anyway, so they were only along for the ride. The launcher's APPDIR, PATH, XDG_DATA_DIRS and GSETTINGS_SCHEMA_DIR exports existed to serve that layout, and CODEX_CLI_PATH is not a variable the app reads at all.

So the tree now goes to /usr/lib/t3code as a plain Electron install, next to how openai-codex-desktop ships. Cleaning that up meant rewriting most of package(), which is more than a patch should carry over an upstream we do not control, hence a local PKGBUILD and an .omarchy/upstream.sh that follows the electron-builder feed the app updates itself from.

Three things the AUR package lost that this keeps: the AppImage's own 16px-512px icons, rather than a separately downloaded 1024px PNG; upstream's desktop entry, which carries the t3code:// scheme handlers a hand-written one drops; and libnotify in depends, which Electron dlopens for notifications.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 02:41:15 -07:00
Omabot ab154a00dd feat(t3code-bin): add T3 Code desktop from the AUR
T3 Code is an open-source control plane for coding agents — Claude Code, Codex, OpenCode, Cursor and Grok driven from one desktop app, on the user's own subscriptions. Upstream ships a Linux x86_64 AppImage only, and the AUR's t3code-bin already tracks it, so this syncs from there in the fast ring.

One Omarchy patch: the AUR launcher runs Electron with --no-sandbox. Chromium falls back to a user-namespace sandbox when it finds no setuid helper, which is what happens on Arch, so the flag only turns the sandbox off. Verified both ways against the built package — sandboxed it reaches display setup, and only with namespaces restricted does it abort on the setuid helper.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 02:28:30 -07:00