Files
omarchy-pkgs/pkgbuilds/t3code-bin/PKGBUILD
T
OmabotandCodex XHigh 7ee0003106 Keep the sandbox up on hardened kernels, and stop deleting what we have not read
Three fixes from a review of the previous commit.

Chromium's sandbox helper ships setuid, the way Arch's own electron and chromium packages ship theirs. Dropping --no-sandbox was right, but it left the app relying on unprivileged user namespaces alone: on linux-hardened, or anywhere else they are denied, Electron falls back to the helper and aborts because it is not root-owned 4755.

The AppImage's usr/ tree is now read before it is removed. Deleting it wholesale is correct for what upstream ships today, and the version bumps arrive unattended, so a release that starts putting something needed in there would have had it dropped on the way past without anyone seeing it. Anything that is not a known icon or a known compatibility library stops the build instead.

The upstream hook checks that the feed still names the asset the PKGBUILD builds. It hashes whatever the feed points at, so a rename — or an arm64 build reaching the Linux feed first — would have pinned that file's checksum to a URL nobody fetches, and the failure would have surfaced a build later as a checksum mismatch.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Codex XHigh <codex@openai.com>
2026-08-19 02:56:22 -07:00

113 lines
3.7 KiB
Bash

# Maintainer: David Heinemeier Hansson <david@hey.com>
# T3 Code ships Linux as an AppImage and nothing else, so Omarchy unpacks it and
# keeps only the Electron tree. AppRun, the compatibility libraries bundled for
# distributions that do not ship their own, and the AppImage's icon shims are all
# dead weight here. .omarchy/upstream.sh rewrites the version and checksum below
# from the release feed the app updates itself from.
pkgname=t3code-bin
pkgver=0.0.33
pkgrel=1
pkgdesc="Open-source control plane for coding agents"
arch=('x86_64')
url="https://t3.codes"
license=('MIT')
depends=(
'alsa-lib'
'at-spi2-core'
'cairo'
'dbus'
'expat'
'gcc-libs'
'glib2'
'glibc'
'gtk3'
'hicolor-icon-theme'
'libcups'
'libnotify'
'libx11'
'libxcb'
'libxcomposite'
'libxdamage'
'libxext'
'libxfixes'
'libxkbcommon'
'libxrandr'
'mesa'
'nspr'
'nss'
'pango'
'systemd-libs'
'xdg-utils'
)
optdepends=(
'claude-code: drive Claude Code from the app'
'cursor-cli: drive Cursor from the app'
'github-copilot-cli: drive Copilot from the app'
'openai-codex: drive Codex from the app'
)
provides=("t3code=${pkgver}")
conflicts=('t3code')
options=('!debug' '!strip')
_appimage="T3-Code-${pkgver}-x86_64.AppImage"
source=('t3code-launcher.sh' 'LICENSE')
source_x86_64=("${_appimage}::https://github.com/pingdotgg/t3code/releases/download/v${pkgver}/${_appimage}")
noextract=("${_appimage}")
sha256sums=('cb905ff341372ef2ef6e402cf485959f8bd1df8f0efebee4cda1afdd5e6abc0a'
'935d8f2af0c703f9c39517ee57cc4930b19d02d533be930b63f0e82f93614b43')
sha256sums_x86_64=('415c8648f43c3d22d572f27f2c50fdc8c310ea7fcde9537b903e1e2f1c8775a1')
prepare() {
chmod +x "${srcdir}/${_appimage}"
rm -rf "${srcdir}/squashfs-root"
"${srcdir}/${_appimage}" --appimage-extract >/dev/null
}
package() {
cd "${srcdir}/squashfs-root"
# The AppImage's usr/ tree is compatibility libraries for distributions that
# lack them, and Arch is not one; its icons are the only part worth keeping.
# A release that starts shipping something else there stops the build rather
# than having it deleted quietly on the way past.
local unexpected
unexpected=$(find usr \( -type f -o -type l \) | grep -vE \
'^usr/share/icons/hicolor/[0-9]+x[0-9]+/apps/t3code\.png$|^usr/lib/lib(Xss\.so\.1|Xtst\.so\.6|appindicator\.so\.1|gconf-2\.so\.4|indicator\.so\.7|notify\.so\.4)$' || true)
if [[ -n "${unexpected}" ]]; then
echo "Unexpected files in the AppImage's usr/ tree:" >&2
echo "${unexpected}" >&2
return 1
fi
local icon size
for icon in usr/share/icons/hicolor/*/apps/t3code.png; do
size="${icon#usr/share/icons/hicolor/}"
install -Dm644 "${icon}" "${pkgdir}/usr/share/icons/hicolor/${size%%/*}/apps/t3code.png"
done
# Upstream's own entry rather than a hand-written one: it carries the
# t3code:// scheme handlers that make the app's deep links resolve.
sed -e 's|^Exec=.*|Exec=t3code %U|' -e '/^X-AppImage-Version=/d' t3code.desktop \
> "${srcdir}/t3code.desktop.arch"
install -Dm644 "${srcdir}/t3code.desktop.arch" \
"${pkgdir}/usr/share/applications/t3code.desktop"
rm -rf AppRun .DirIcon usr t3code.desktop t3code.png
install -d "${pkgdir}/usr/lib/t3code"
cp -a . "${pkgdir}/usr/lib/t3code/"
chmod -R a+rX "${pkgdir}/usr/lib/t3code"
# Arch ships Chromium's and Electron's own sandbox helper setuid, which is
# what keeps the sandbox up on a kernel that denies unprivileged user
# namespaces -- linux-hardened, mainly -- instead of aborting the app.
chmod 4755 "${pkgdir}/usr/lib/t3code/chrome-sandbox"
install -Dm755 "${srcdir}/t3code-launcher.sh" "${pkgdir}/usr/bin/t3code"
install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}