[Guix packaging] codemodsquad/astx #104
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#104
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Candidate
9f0ee21ce3b1e34a0122a50a5e604a109fa9a09aonbeta(default branch snapshot reviewed 2026-08-14).astxstructural JavaScript/TypeScript search-and-replace CLIpackage.json,pnpm-lock.yaml, Babel parser)LICENSE.mdcontains MIT andpackage.jsondeclares MIT.Scope and blockers
Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Pin the old custom toolchain/Babel parser closure and define the published CLI artifact, since upstream marks the package as development-only.
Acceptance checks
guix lint -L. astxpasses with no new errors.guix build -L. astxsucceeds from the pinned source with tests enabled where practical.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:25Z.
Goocastle recorded disposition: implementation-ready.
Created implementation ticket: #638.
Canonical source and fixed revision: https://github.com/codemodsquad/astx at beta commit 9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a (upstream package.json version 0.0.0-development; use a Guix version derived from that version plus the fixed revision). The requested deliverable is the upstream structural JavaScript/TypeScript search-and-replace CLI. At that exact revision, package.json declares MIT and LICENSE.md contains the MIT grant (
github.com/codemodsquad/astx@9f0ee21ce3/LICENSE.md). The local channel already has codemodsquad-astx-source at this same commit, but only as a source snapshot. Guix has ast-grep 0.42.1 as a related structural-search CLI; it is a different Rust implementation/API and is not an equivalent astx package, so no installable package for this upstream origin exists.Source-build assessment is viable. The pinned tree has no Git submodules, no non-registry URLs in pnpm-lock.yaml, and its lockfile is v6.0. The fixed pnpm 8.11.0 registry archive is also MIT-licensed: its package.json declares MIT and its LICENSE contains the grant, with registry integrity sha512-nfh8FsmNsntOBR14fmfyIH7EfoCcywe/e17ErNzRYTNVg5o40LkAFEkj1qcFdwC3TSoMyxVYvrJBZHoSBqmnqw== (https://registry.npmjs.org/pnpm/-/pnpm-8.11.0.tgz). The lock has 793 integrity-pinned package records; the non-optional installed closure has 576 unique exact name@version package manifests, every one with an explicit license/licenses field and no missing or UNLICENSED value. Evidence for each registry origin is its package.json license field at the exact version selected by the lock's sha512 integrity record in
github.com/codemodsquad/astx@9f0ee21ce3/pnpm-lock.yaml; observed license families are MIT, ISC, BSD-2/3-Clause, Apache-2.0, 0BSD, BlueOak-1.0.0, Python-2.0, CC-BY-4.0, WTFPL, and MIT/CC0 alternatives, all are explicit free/permissive grants; preserve notices and any attribution conditions. The only native helper needed for the full TypeScript-transform-file runtime is matching esbuild 0.25.0: upstream tag v0.25.0 is commit e9174d671b1882758cd32ac5e146200f5bee3e45, has MIT evidence in LICENSE.md and npm/esbuild/LICENSE.md, and has no submodules (github.com/evanw/esbuild@e9174d671b/LICENSE.md). Build that helper from this source with Guix Go inputs; do not ship the npm prebuilt platform binary. No required independently fetched origin lacks a clear redistribution grant.Create a new module (tay packages astx), preferably using gnu-build-system with fully custom offline phases (or replace every automatic npm phase if node-build-system is used). Native/build inputs must include Guix node 22.x or newer (the upstream astx engine says >=16, but locked tsx and esbuild require >=18), fixed pnpm 8.11.0, the exact non-optional registry archives for the complete pnpm lock closure, and the source-built matching esbuild 0.25.0 helper. Materialize the locked node_modules tree from those archives, then run pnpm install --offline --frozen-lockfile --ignore-scripts followed by the toolchain binary's build subcommand and, with tests enabled, its test subcommand. Do not invoke pnpm run build (the upstream package has no build script), the bare tc alias (it only prints usage), or prepublishOnly (it deliberately exits 1). The clean upstream build produced dist/index.js, dist/index.mjs, declarations, and dist/cli/index.js; all 1,171 upstream tests passed with 16 pending. Install dist as lib/node_modules/astx, retain package.json, README.md, LICENSE.md, and dependency notices, and provide bin/astx as a Node launcher for dist/cli/index.js. Set ESBUILD_BINARY_PATH to the matching source-built esbuild binary so local .ts/.cts/.mts transform files work without npm optional-dependency downloads; omit fsevents and all other platform-optional artifacts. Normal operation has no service, credentials, downloaded assets, or required network integration; a user-supplied transform URL can intentionally perform its own network access and must not be fetched during build.
The wrapper must retain a positive worker pool (set ASTX_WORKERS=1 only when unset, or otherwise do not force workers=0): this pinned CLI's single-process path passes the result wrapper incorrectly and crashes with path.relative(..., undefined), while the default worker path works. There is no upstream --dry-run flag. Acceptance proof: after the package is implemented, run guix lint -L. astx and guix build -L. astx with tests enabled; then in a fresh temporary directory create a small .ts fixture and a .cts transform exporting find/replace for a deliberately absent pattern, run the installed bin/astx with ASTX_WORKERS=1 and ESBUILD_BINARY_PATH set, without --yes, and assert exit 0, the reported unchanged/no-match result, and identical pre/post sha256 hashes. This isolated no-match transform exercises the Babel TypeScript parser, the tsx/esbuild loader, worker wrapper, and the no-write dry-run behavior. Guix lint/build were not claimed here because the host Guix daemon socket was unavailable; they are the stated implementation acceptance gates, not evidence of an existing package proof.
Imported from GitHub comment. Originally posted by htayj on 2026-08-28T17:43:33Z.