Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 21 additions & 8 deletions docs/t3x/SEAMS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,10 +2,19 @@

**The authoritative list of every upstream-owned file this fork edits.**

Measured, not asserted: **36 upstream-owned files, +1733 / -257 lines**, against merge-base
Measured, not asserted: **37 upstream-owned files, +1944 / -919 lines**, against merge-base
`64bf01619` (the 2026-08-02 upstream sync). Everything else the fork adds lives in new files upstream
has never seen and cannot conflict.

> **Read the two dependency rows with their note, not their number.** The 2026-08-08 security sweep
> took `pnpm-lock.yaml` to +318 / -731 and so to risk **67136**, five times the next row. That figure
> is the formula working as designed on a file the formula does not describe: the lockfile is
> **regenerated** at every sync, never merged, so a thousand changed lines cost one `pnpm install`,
> not a thousand conflict decisions. What actually carries the sweep across a sync is the 18-line
> `overrides:` block in `pnpm-workspace.yaml` (risk 522) — that is the row to defend. Most of the
> lockfile delta is not even fork intent: it is astro 7.0.3 → 7.2.0 shedding its old
> remark/rehype/hast pipeline, which is why the file **shrinks** by 413 net lines.

> **Update delivery adds no NEW rows.** Almost all of the feature
> (`docs/superpowers/specs/2026-08-03-update-delivery-design.md`) is new fork-owned files —
> `infra/t3x-update-relay/`, `.github/workflows/t3x-release.yml`, `scripts/t3x/`,
Expand DownExpand Up@@ -54,11 +63,14 @@ recurring rebase conflict in a file this doc said the fork did not touch) went u
> **Tripwire:** the surface is already far past "a handful of rows". Before adding row 36, re-isolate
> something instead. Prefer fork-owned files even when an in-place edit is smaller.
>
> Row 36 (`apps/desktop/package.json`) was added on 2026-08-08 for an electron security pin. It is
> the one shape the tripwire cannot redirect: a dependency version has no fork-owned home, and the
> only alternative — a pnpm `overrides` entry — sits in `pnpm-workspace.yaml`, an upstream file, for
> the same cost and worse legibility. It is a single version string and it retires itself as soon as
> upstream passes `41.10.3`.
> Rows 36 and 37 were both added on 2026-08-08, by the Dependabot cleanup. They are the one shape
> the tripwire cannot redirect: a dependency version has no fork-owned home. `pnpm-workspace.yaml`
> (row 37) holds the transitive security `overrides:`, appended to a block upstream already
> maintains; `apps/desktop/package.json` (row 36) holds the one pin on a package this repo declares
> directly. Both are version strings with no logic in them, and both retire themselves as upstream's
> tree floats past — check them at every sync and delete what is no longer needed. If the override
> list ever stops shrinking, that is the signal to re-ask whether the fork should be tracking
> upstream's dependency advisories at all.
>
> Row 35 (`AGENTS.md`) was added knowingly on 2026-08-05, against this tripwire. The alternatives —
> a tracked `.claude/settings.json` SessionStart hook, or an untracked `CLAUDE.local.md` — were
Expand All@@ -83,7 +95,7 @@ Sorted by risk, worst first.

| Upstream file | fork Δ | churn | risk | Why the fork touches it |
| ----------------------------------------------------------------------- | -------- | ----- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `pnpm-lock.yaml` | +125/-69 | 64 | **12416** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 security bump re-resolves the electron tree (+32/-69, a net **shrink** — `@electron/get` 2.0.3 + 3.1.0 collapse into 5.1.0). Unavoidable and always conflicts; regenerate rather than merge |
| `pnpm-lock.yaml` | +318/-731 | 64 | **67136** | Web Push adds `web-push` + `@types/web-push`; update delivery adds the `t3x-update-relay` workspace entry (+6, `effect` + `@cloudflare/workers-types` only — `wrangler` is run via `pnpm dlx` precisely to keep it out of here, it would have cost ~500); the electron 41.10.3 pin re-resolves the electron tree; the 2026-08-08 security sweep re-floats astro / postcss / svgo / js-yaml / undici@7 and applies the `overrides:` block below. Net **-413 lines** — astro 7.2.0 drops its old remark/rehype/hast pipeline. Unavoidable and always conflicts; **regenerate rather than merge**, which is why this row's risk number overstates it — see the note under the header |
| `apps/web/src/components/ChatView.tsx` | +181/-1 | 63 | **11466** | Thread outbox: `handleQueueComposerSubmission`, queue-mode state, `onSend` early-return, `<ThreadOutboxQueueList>`, `sendLabel`, steer-vs-queue predicate, dispatch breadcrumb |
| `packages/client-runtime/src/connection/supervisor.test.ts` | +363 | 5 | **1815** | Issue #21: 356-line appended `describe` + harness plumbing |
| `packages/client-runtime/src/connection/supervisor.ts` | +186/-63 | 5 | **1245** | Issue #21: in-place rewrite of the reconnect/backoff state machine; now also owns the shared `runLivenessProbe` helper upstream's probe path uses |
Expand All@@ -92,6 +104,7 @@ Sorted by risk, worst first.
| `apps/server/src/serverRuntimeStartup.test.ts` | +149/-1 | 6 | **900** | Crash-recovery reconciler coverage |
| `apps/web/src/components/chat/ComposerPrimaryActions.tsx` | +130/-64 | 4 | **776** | Queue button; hoists upstream's inline stop and send buttons so the running-turn footer can pair Stop with either. Must mirror upstream's `sendDisabledReason` gate |
| `apps/web/src/components/chat/ChatComposer.tsx` | +16/-2 | 34 | **612** | Threads `sendLabel` / `canQueue` through the composer |
| `pnpm-workspace.yaml` | +18 | 29 | **522** | **Row 37, added 2026-08-08.** 12 major-scoped entries appended to upstream's existing `overrides:` block, closing 57 of 64 transitive advisories that Dependabot cannot auto-fix (brace-expansion ×3 lines, builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6). Additive and contiguous inside a block upstream already owns, so it conflicts as one hunk. This is the row that carries the sweep across a sync — the lockfile is regenerated from it. Drop entries as upstream's tree floats past them |
| `apps/mobile/src/features/threads/ThreadComposer.tsx` | +26/-4 | 16 | **480** | Mobile Return-key send/queue |
| `apps/desktop/src/preload.ts` | +29 | 13 | **377** | `showNotification` + `onNotificationActivated` on the exposed bridge, plus the `t3xUpdate` bridge object (get / subscribe / restart / dismiss) |
| `apps/mobile/modules/t3-composer-editor/ios/T3ComposerEditorView.swift` | +33 | 6 | **198** | Shift+Return newline vs. bare Return submit |
Expand All@@ -111,7 +124,7 @@ Sorted by risk, worst first.
| `AGENTS.md` | +6 | 10 | **60** | `## Agent skills` pointer block for the mattpocock engineering skills. Three one-line links into `docs/t3x/agents/`; no config lives here. Placed between `## How it works` and `## Where code lives` — stable anchors, deliberately not appended at EOF where upstream adds tips (the issue #29 add/add pattern) |
| `apps/web/src/connection/platform.ts` | +7/-1 | 7 | **56** | Lazy `import()` of outbox cleanup to dodge a module-init cycle |
| `apps/mobile/…/T3ComposerEditorView.kt` | +51 | 1 | **51** | Android bare-Enter intercept |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. There is no fork-owned way to pin a dependency — an `overrides` entry would land in `pnpm-workspace.yaml`, another upstream file, for the same cost. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/desktop/package.json` | +1/-1 | 15 | **30** | **Row 36, added 2026-08-08 against the tripwire below.** `electron` pinned to `41.10.3`, not upstream's `41.5.0`, for GHSA advisories #94 (high: sandboxed iframe bypasses `allow-popups` via OpenURL) and #92 (medium: `ProtocolResponse.url` reuses the default session cache). Upstream is still on `41.5.0`, so the sync does **not** carry this fix and the fork ships its own desktop builds. Deliberately **not** folded into row 37's `overrides:` block: electron is a dependency `apps/desktop` *declares*, and an override would leave that manifest reading `41.5.0` while resolving `41.10.3`. Overrides are for transitive packages no manifest here declares. Retire this row the moment upstream passes `41.10.3`: take upstream's side of the conflict |
| `apps/server/package.json` | +2 | 15 | **30** | `web-push` dependency |
| `apps/mobile/src/native/T3ComposerEditor.types.ts` | +5/-1 | 3 | **18** | Reworded `onSubmit` doc comment |
| `apps/desktop/src/settings/DesktopClientSettings.test.ts` | +1 | 7 | **7** | `notifyOnNeedsInput` in a fixture |
Expand Down
Loading
Loading