refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

refactor(coil): retire the local desktop autobuild - #92

Merged
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild
Aug 12, 2026
Merged

refactor(coil): retire the local desktop autobuild#92
radroid merged 1 commit into
mainfrom
t3x/retire-autobuild

Conversation

@radroid

Copy link
Copy Markdown
Owner

Update delivery superseded the local autobuild. Removing it.

Why

scripts/coil/auto-build-desktop.sh polled origin/main every 12h, built a dmg on the maintainer's Mac and copied it over /Applications. Since #51/#55, CI builds every green merge to main, signs it with the same identity, and the app offers the restart itself — so the two mechanisms now race to replace the same bundle.

It has not run since 2026-08-07, and its LaunchAgent is not loaded. This mostly records a fact.

The one behavioural difference

Releases gate on green CI: coil-release.yml triggers on workflow_run of coil fork CI with conclusion == 'success'. The autobuild did not care. So a flaky test now withholds a build rather than merely reddening CI — main's known Reactor.test.ts flake already skipped one release today.

Escape hatch, unchanged: gh workflow run coil-release.yml -f sha=<sha>.

What goes

FileWhy
scripts/coil/auto-build-desktop.shthe watcher itself
docs/coil/auto-build-runbook.mdits runbook
scripts/coil/hooks/post-mergeopt-in git hook whose only job was invoking the script

Plus the stale prose it left in mac-signing-runbook.md, SEAMS.md, setup-mac-signing.sh and two updateDelivery comments.

What deliberately stays

  • The T3X_DESKTOP_APP_ID seam in scripts/build-desktop-artifact.ts. The autobuild was one of two things that set it; the release workflow is the other, and still needs it. The row is unchanged at +11/-1, so the ledger header (47 files, +2234/-1067) does not move.
  • Its guard, mac-signature.test.ts, minus the arm that read the deleted script. The remaining three assertions still fail loudly if a sync reverts the seam.
  • A short note in SEAMS.md explaining that the local build loop existed and why it went, because "why is there no local build loop" is a question the next reader will have.

Verification

vp test scripts/coil/ 47 passed
vp test apps/desktop/src/coil/updateDelivery 118 passed
vp run -r typecheck clean (suggestions only)
git diff --numstat <merge-base> -- scripts/build-desktop-artifact.ts
→ 11 1 (identical before and after)

🤖 Generated with Claude Code

Update delivery superseded it. `auto-build-desktop.sh` polled `origin/main`
every 12h, built a dmg on this Mac and copied it over `/Applications`;
since #51/#55 CI builds every green merge to main, signs it with the same
identity, and the app offers the restart itself. Two mechanisms racing to
replace the same bundle is worse than either alone — and the local one has
not run since 2026-08-07, so this is recording a fact rather than making a
decision.
One behavioural difference, stated rather than discovered later: releases
now gate on green CI, because coil-release.yml triggers on `workflow_run`
of the CI workflow with `conclusion == 'success'`. The autobuild did not
care. A flaky test therefore withholds a build until CI is green — the
escape hatch is `gh workflow run coil-release.yml -f sha=<sha>`.
Goes with it: the opt-in `post-merge` git hook (its only job was invoking
the script) and the runbook. The bundle-id test drops its autobuild arm —
`build-desktop-artifact.ts`'s env hook is still set by the release
workflow, so the seam and its guard both stay, unchanged at +11/-1. The
ledger header is untouched: nothing upstream-owned moved.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 52fa8672-013a-4a7d-b4b9-739968b33fe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroid
radroid merged commit fdeb528 into mainAug 12, 2026
2 checks passed
radroid added a commit that referenced this pull request Aug 12, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@radroid
radroid deleted the t3x/retire-autobuild branch August 12, 2026 19:00
radroid pushed a commit that referenced this pull request Aug 17, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 17, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 17, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid pushed a commit that referenced this pull request Aug 18, 2026
…dored subtrees
Closes two advisories against the desktop app the fork ships. Upstream is still on 41.5.0, so the sync does not deliver this — it is a fork-owned pin that retires itself once upstream passes 41.10.3.
- GHSA #94 (high): a sandboxed iframe can bypass the `allow-popups` restriction via the OpenURL navigation path. Fixed in 41.10.3.
- GHSA #92 (medium): `ProtocolResponse.url` reuses the default session cache instead of the registering session. Fixed in 41.9.1.
Dependabot bumped `apps/desktop/package.json` alone, so `vp install` failed on the frozen lockfile in 40s and CI never reached typecheck. Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only`; the diff stays inside the electron tree and nets -37 lines.
Also adds `.github/dependabot.yml` (fork-owned; upstream has none) ignoring `.repos/**`, and records the seam-ledger rows the change owes: `apps/desktop/package.json` as row 36, and `pnpm-lock.yaml` grown to risk 12416, now the top row.
radroid added a commit that referenced this pull request Aug 18, 2026
`SEAMS.md` cited `scripts/t3x/mac-signature.test.ts`,
`scripts/t3x/verify-mac-signature.ts` and `docs/t3x/agents/` — all three
moved under `coil/` in #71 and the ledger's prose did not follow. The
files themselves were fine; `AGENTS.md` already links the right paths, so
this was drift in the description, not a broken link.
The bundle-id row also said "every build path sets it". Since #92 there is
one build path — the release workflow.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
radroid added a commit that referenced this pull request Aug 18, 2026
app.asar 189.66 MiB / 14,765 files -> 99.02 MiB / 3,429 files (-47.8%, -76.8%
files). The updater's .zip drops 20.1 MB; the electron-builder phase drops 62%.
Three cuts, each measured from the packed asar rather than the install tree:
- Web renderer source maps (37.4 MiB) via T3CODE_WEB_SOURCEMAP=0, an existing
upstream variable. All 385 renderer chunks are byte-identical afterwards apart
from the trailing sourceMappingURL comment.
- Third-party source maps (18.2 MiB). First-party maps are kept, so
NODE_OPTIONS=--enable-source-maps still gives readable frames for our code.
- Two renderer-only dependency trees: Clerk's browser SDK (23.2 MiB, 16
packages) and @pierre/diffs' shiki tree (21.0 MiB, 50 packages). Both are
bundled by a client build before staging, and the renderer runs sandboxed with
nodeIntegration off, so neither is resolvable at runtime.
Sync cost is one upstream file, +21/-0. The seam is an env hook on
scripts/build-desktop-artifact.ts rather than an edited literal: upstream's test
asserts DESKTOP_FILE_EXCLUSIONS deep-equals exactly its one entry, and the fork's
list is 67 globs and grows, so an inline list would make every future size fix an
edit to an upstream test assertion. An unset environment packages exactly what
upstream packages. No new seam rows, no new deletions.
Two new fork-owned tools:
- desktop-bundle-reachability.mjs analyses a staged build. It follows literal
import edges AND string-mention edges, because PlaywrightInjectedRuntime.ts
resolves playwright-core through a const and an import-only scan calls 10.2 MiB
of live code dead.
- verify-desktop-bundle.mjs gates every release on both platforms, failing any
packaged import that is not loadable. Found two bugs in itself under test: it
would have failed every Windows release by ignoring app.asar.unpacked, and an
earlier severity split passed a deliberately-broken build.
Re-measured on 136b351, after the #71 Coil rename, #58's dependency
re-resolution and #92 retiring the local autobuild. The packed asar is the same
size on both sides of the rename, and all 66 non-wildcard globs still match a
shipped package.
Corrects issue #53 on five points, recorded in docs/coil/desktop-bundle-size.md —
its size table measured `du` block allocation (core-js "15 MB" is 1.25 MiB of
content), it misses source maps entirely, DESKTOP_FILE_EXCLUSIONS is not
fork-owned, the mac leg is not the release critical path, and the pnpm store is
already cached.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid