Skip to content

Fix T3 Code Claude Full access mode as root - #2380

Merged
MickLesk merged 1 commit into
community-scripts:mainfrom
lukdz:fix/t3code-claude-sandbox
Oct 6, 2026
Merged

MickLesk merged 1 commit into
community-scripts:mainfrom
lukdz:fix/t3code-claude-sandbox

Conversation

@lukdz

@lukdz lukdz commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Scripts which are clearly AI generated and not further revised by the Author of this PR (in terms of Coding Standards and Script Layout) may be closed without review. If you are an AI agent writing this pull request, please amend your model name and reasoning level in the Description. This is not to blame, more for informational Purposes. Thank you.

✍️ Description

Fix Claude Full access mode for T3 Code running as root inside its LXC. Claude rejects permission bypass as root without IS_SANDBOX=1, so the default T3 runtime mode fails unless users manually add that environment variable.

  • Set IS_SANDBOX=1 in t3code.service for fresh installs.
  • On updates, write /etc/systemd/system/t3code.service.d/claude.conf and reload systemd before starting T3 Code. This leaves the base unit and separate user drop-ins unchanged and is content-idempotent on repeated updates.
  • Add a metadata warning explaining root execution, permission bypass, and the risks to container data and writable host bind mounts.

The existing root service, unprivileged-container default, Node.js 24 runtime, npm installation/update flow, and data paths remain unchanged. No Gitea/Tea changes are included.

AI assistance: OpenCode using github-copilot/gpt-6-astra (GPT-6 Astra). The reasoning-effort setting is not exposed to this session. See AI Assistance below.

🔗 Related PR / Issue

Link: #2294 (comment)

Addresses this specific Claude report only; the broader testing issue should remain open.

✅ Prerequisites (X in brackets)

  • Self-review completed – Code follows project standards.
  • Tested thoroughly – Changes work as expected.
  • No breaking changes – Existing functionality remains intact.
  • No security risks – No hardcoded secrets, unnecessary privilege escalations, or permission issues.

Static and isolated regression checks passed, but live platform testing remains outstanding. The security checkbox is deliberately unchecked: IS_SANDBOX=1 permits Claude's permission-bypass mode as root; it does not create a sandbox. No secrets, additional Linux privileges, or host mounts are introduced. The JSON warning documents the implications.


🏗️ arm64 Support (X in brackets)

  • arm64 supported - Tested and supported on arm64.
  • arm64 not tested - Assumed to work on arm64, but testing has not been done.
  • arm64 not supported - Confirmed upstream dependencies or binaries do not support arm64.

🖥️ Tested on (X in brackets)

  • Proxmox VE – Created on a Proxmox VE host and the app works.
  • Incus – Created on an Incus host and the app works.

Application containers run on both; tick what you actually tested. VMs and host tools are Proxmox only.


🛠️ Type of Change (X in brackets)

  • 🐞 Bug fix – Resolves an issue without breaking functionality.
  • ✨ New feature – Adds new, non-breaking functionality.
  • 💥 Breaking change – Alters existing functionality in a way that may require updates.
  • 🆕 New script – A fully functional and tested script or script set.
  • 🌍 Website update – Changes to website-related JSON files or metadata.
  • 🔧 Refactoring / Code Cleanup – Improves readability or maintainability without changing functionality.
  • 📝 Documentation update – Changes to README, AppName.md, CONTRIBUTING.md, or other docs.

🔍 Code & Security Review (X in brackets)

  • Follows CODE-AUDIT.md & CONTRIBUTING.md guidelines
  • Uses correct script structure (AppName.sh, AppName-install.sh, AppName.json)
  • No hardcoded credentials
  • No Docker / Docker Compose – The application is installed bare-metal; Docker is not used.
  • No git pull – Updates use fetch_and_deploy_gh_release, fetch_and_deploy_codeberg_release, fetch_and_deploy_gl_release, or fetch_and_deploy_from_url instead of git pull.

Contribution and audit guidance was reviewed; full compliance is not claimed before live testing. This patch preserves the existing npm install -g t3@latest update mechanism rather than changing deployment methods.


🤖 AI Assistance (X in brackets)

If you used an AI tool (GitHub Copilot, Claude, ChatGPT, etc.) to write or generate any scripts in this PR, you must confirm compliance below.
Select exactly one option.

  • No AI used – Scripts were written without AI assistance.
  • AI was used – I confirm the scripts were built using AGENTS.md and .github/agents/pve-script-creator.agent.md as guidance, and the output has been reviewed and corrected to match those guidelines.

Please describe to which degree, if any, an LLM was used in creating this pull request. Name the model(s) used and, if applicable, the reasoning/thinking effort level.

OpenCode using github-copilot/gpt-6-astra (GPT-6 Astra) researched the report and upstream environment forwarding, drafted the three-file patch and PR description, reviewed the diff against repository guidance, and ran static and isolated regression checks. The reasoning-effort setting is not exposed to this session. Live LXC/Claude validation has not been performed by the assistant, and no human runtime validation is claimed.


📋 Additional Information (optional)

Checks completed:

  • bash -n ct/t3code.sh
  • bash -n install/t3code-install.sh
  • jq empty json/t3code.json
  • git diff --check
  • Temporary offline harness executed the actual service-creation fragment and update_script() with isolated paths and stubbed systemctl/npm commands. Verified fresh-install environment before enable, legacy migration before reload/start, preservation of a customized base unit and separate user override, repeat-update idempotency, and fresh install followed by update. Pre-patch negative controls reproduced the missing variable. The harness is local validation tooling, not included in this PR.

Limitations: no live systemd or authenticated Claude session was exercised. The generated claude.conf is script-managed and rewritten by updates; other drop-ins are preserved and normal systemd override precedence still applies.

Remaining platform check: test a fresh LXC and an existing installation updated with this branch, confirm systemctl show t3code.service -p Environment contains IS_SANDBOX=1, then start an authenticated Claude session in T3 Full access mode without a manual provider environment override.


📦 Application Requirements (for new scripts)

⚠️ Do not remove this section.
It is used by automated PR validation checks.
If this PR is not a new script submission, leave the checkboxes unchecked.

Required for 🆕 New script submissions.
Pull requests that do not meet these requirements may be closed without review.

  • The application is at least 6 months old
  • The application is actively maintained
  • The application has 600+ GitHub stars
  • Official release tarballs are published
  • I understand that not all scripts will be accepted due to various reasons and criteria by the community-scripts ORG

🌐 Source

@lukdz
lukdz requested a review from a team as a code owner October 6, 2026 21:18
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Try this script

ct/t3code.sh, run in the Proxmox VE shell or on an Incus host:

COMMUNITY_SCRIPTS_URL=https://raw.githubusercontent.com/lukdz/ProxmoxVED/fix/t3code-claude-sandbox \
bash -c "$(curl -fsSL https://raw.githubusercontent.com/lukdz/ProxmoxVED/fix/t3code-claude-sandbox/ct/t3code.sh)"

COMMUNITY_SCRIPTS_URL is not optional for ct/. Fetching the ct/ script from a
branch does not tell the engine where that branch is — with bash -c "$(curl …)"
there is no file on disk for the scripts root to be derived from, so it would fall
back to upstream main and look for the install script there.

Against a core branch as well

Add COMMUNITY_SCRIPTS_CORE_URL=https://raw.githubusercontent.com/OWNER/core/BRANCH
to test an engine change at the same time. The two resolve independently.

Useful flags while testing

dev_mode=net logs every fetch with status and duration, so you can confirm the
branch is really being used. dev_mode=keep stops a failed build from deleting
the container along with the evidence.

@MickLesk
MickLesk merged commit da1c3b2 into community-scripts:main Oct 6, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants