[Guix packaging] codemodsquad/astx #104

Open
opened 2026-08-14 13:17:25 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:25 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/codemodsquad/astx
  • Source pinned commit/release when known: 9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a on beta (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: astx structural JavaScript/TypeScript search-and-replace CLI
  • Primary category: developer-tool
  • Tags: build-tool
  • Primary language normalized: TypeScript
  • Build system: pnpm workspace/toolchain (package.json, pnpm-lock.yaml, Babel parser)
  • SPDX expression: MIT
  • License status: confirmed-free
  • License evidence: LICENSE.md contains MIT and package.json declares MIT.
  • Difficulty: moderate — Pin the old custom toolchain/Babel parser closure and define the published CLI artifact, since upstream marks the package as development-only.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Pin the old custom toolchain/Babel parser closure and define the published CLI artifact, since upstream marks the package as development-only.

Acceptance checks

  • guix lint -L. astx passes with no new errors.
  • guix build -L. astx succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Build offline and run a local fixture transformation in dry-run mode, checking unchanged output on a no-match case.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:25Z.

## Candidate - Upstream canonical URL: https://github.com/codemodsquad/astx - Source pinned commit/release when known: `9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a` on `beta` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: `astx` structural JavaScript/TypeScript search-and-replace CLI - Primary category: developer-tool - Tags: build-tool - Primary language normalized: TypeScript - Build system: pnpm workspace/toolchain (`package.json`, `pnpm-lock.yaml`, Babel parser) - SPDX expression: MIT - License status: confirmed-free - License evidence: `LICENSE.md` contains MIT and `package.json` declares MIT. - Difficulty: moderate — Pin the old custom toolchain/Babel parser closure and define the published CLI artifact, since upstream marks the package as development-only. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Pin the old custom toolchain/Babel parser closure and define the published CLI artifact, since upstream marks the package as development-only. ## Acceptance checks - `guix lint -L. astx` passes with no new errors. - `guix build -L. astx` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Build offline and run a local fixture transformation in dry-run mode, checking unchanged output on a no-match case. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/104). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:25Z.
htayj commented 2026-08-28 17:43:33 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #638.

Canonical source and fixed revision: https://github.com/codemodsquad/astx at beta commit 9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a (upstream package.json version 0.0.0-development; use a Guix version derived from that version plus the fixed revision). The requested deliverable is the upstream structural JavaScript/TypeScript search-and-replace CLI. At that exact revision, package.json declares MIT and LICENSE.md contains the MIT grant (github.com/codemodsquad/astx@9f0ee21ce3/LICENSE.md). The local channel already has codemodsquad-astx-source at this same commit, but only as a source snapshot. Guix has ast-grep 0.42.1 as a related structural-search CLI; it is a different Rust implementation/API and is not an equivalent astx package, so no installable package for this upstream origin exists.

Source-build assessment is viable. The pinned tree has no Git submodules, no non-registry URLs in pnpm-lock.yaml, and its lockfile is v6.0. The fixed pnpm 8.11.0 registry archive is also MIT-licensed: its package.json declares MIT and its LICENSE contains the grant, with registry integrity sha512-nfh8FsmNsntOBR14fmfyIH7EfoCcywe/e17ErNzRYTNVg5o40LkAFEkj1qcFdwC3TSoMyxVYvrJBZHoSBqmnqw== (https://registry.npmjs.org/pnpm/-/pnpm-8.11.0.tgz). The lock has 793 integrity-pinned package records; the non-optional installed closure has 576 unique exact name@version package manifests, every one with an explicit license/licenses field and no missing or UNLICENSED value. Evidence for each registry origin is its package.json license field at the exact version selected by the lock's sha512 integrity record in github.com/codemodsquad/astx@9f0ee21ce3/pnpm-lock.yaml; observed license families are MIT, ISC, BSD-2/3-Clause, Apache-2.0, 0BSD, BlueOak-1.0.0, Python-2.0, CC-BY-4.0, WTFPL, and MIT/CC0 alternatives, all are explicit free/permissive grants; preserve notices and any attribution conditions. The only native helper needed for the full TypeScript-transform-file runtime is matching esbuild 0.25.0: upstream tag v0.25.0 is commit e9174d671b1882758cd32ac5e146200f5bee3e45, has MIT evidence in LICENSE.md and npm/esbuild/LICENSE.md, and has no submodules (github.com/evanw/esbuild@e9174d671b/LICENSE.md). Build that helper from this source with Guix Go inputs; do not ship the npm prebuilt platform binary. No required independently fetched origin lacks a clear redistribution grant.

Create a new module (tay packages astx), preferably using gnu-build-system with fully custom offline phases (or replace every automatic npm phase if node-build-system is used). Native/build inputs must include Guix node 22.x or newer (the upstream astx engine says >=16, but locked tsx and esbuild require >=18), fixed pnpm 8.11.0, the exact non-optional registry archives for the complete pnpm lock closure, and the source-built matching esbuild 0.25.0 helper. Materialize the locked node_modules tree from those archives, then run pnpm install --offline --frozen-lockfile --ignore-scripts followed by the toolchain binary's build subcommand and, with tests enabled, its test subcommand. Do not invoke pnpm run build (the upstream package has no build script), the bare tc alias (it only prints usage), or prepublishOnly (it deliberately exits 1). The clean upstream build produced dist/index.js, dist/index.mjs, declarations, and dist/cli/index.js; all 1,171 upstream tests passed with 16 pending. Install dist as lib/node_modules/astx, retain package.json, README.md, LICENSE.md, and dependency notices, and provide bin/astx as a Node launcher for dist/cli/index.js. Set ESBUILD_BINARY_PATH to the matching source-built esbuild binary so local .ts/.cts/.mts transform files work without npm optional-dependency downloads; omit fsevents and all other platform-optional artifacts. Normal operation has no service, credentials, downloaded assets, or required network integration; a user-supplied transform URL can intentionally perform its own network access and must not be fetched during build.

The wrapper must retain a positive worker pool (set ASTX_WORKERS=1 only when unset, or otherwise do not force workers=0): this pinned CLI's single-process path passes the result wrapper incorrectly and crashes with path.relative(..., undefined), while the default worker path works. There is no upstream --dry-run flag. Acceptance proof: after the package is implemented, run guix lint -L. astx and guix build -L. astx with tests enabled; then in a fresh temporary directory create a small .ts fixture and a .cts transform exporting find/replace for a deliberately absent pattern, run the installed bin/astx with ASTX_WORKERS=1 and ESBUILD_BINARY_PATH set, without --yes, and assert exit 0, the reported unchanged/no-match result, and identical pre/post sha256 hashes. This isolated no-match transform exercises the Babel TypeScript parser, the tsx/esbuild loader, worker wrapper, and the no-write dry-run behavior. Guix lint/build were not claimed here because the host Guix daemon socket was unavailable; they are the stated implementation acceptance gates, not evidence of an existing package proof.


Imported from GitHub comment. Originally posted by htayj on 2026-08-28T17:43:33Z.

<!-- goocastle-disposition:sequential-reviewer:104:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #638. Canonical source and fixed revision: https://github.com/codemodsquad/astx at beta commit 9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a (upstream package.json version 0.0.0-development; use a Guix version derived from that version plus the fixed revision). The requested deliverable is the upstream structural JavaScript/TypeScript search-and-replace CLI. At that exact revision, package.json declares MIT and LICENSE.md contains the MIT grant (https://github.com/codemodsquad/astx/blob/9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a/LICENSE.md). The local channel already has codemodsquad-astx-source at this same commit, but only as a source snapshot. Guix has ast-grep 0.42.1 as a related structural-search CLI; it is a different Rust implementation/API and is not an equivalent astx package, so no installable package for this upstream origin exists. Source-build assessment is viable. The pinned tree has no Git submodules, no non-registry URLs in pnpm-lock.yaml, and its lockfile is v6.0. The fixed pnpm 8.11.0 registry archive is also MIT-licensed: its package.json declares MIT and its LICENSE contains the grant, with registry integrity sha512-nfh8FsmNsntOBR14fmfyIH7EfoCcywe/e17ErNzRYTNVg5o40LkAFEkj1qcFdwC3TSoMyxVYvrJBZHoSBqmnqw== (https://registry.npmjs.org/pnpm/-/pnpm-8.11.0.tgz). The lock has 793 integrity-pinned package records; the non-optional installed closure has 576 unique exact name@version package manifests, every one with an explicit license/licenses field and no missing or UNLICENSED value. Evidence for each registry origin is its package.json license field at the exact version selected by the lock's sha512 integrity record in https://github.com/codemodsquad/astx/blob/9f0ee21ce3b1e34a0122a50a5e604a109fa9a09a/pnpm-lock.yaml; observed license families are MIT, ISC, BSD-2/3-Clause, Apache-2.0, 0BSD, BlueOak-1.0.0, Python-2.0, CC-BY-4.0, WTFPL, and MIT/CC0 alternatives, all are explicit free/permissive grants; preserve notices and any attribution conditions. The only native helper needed for the full TypeScript-transform-file runtime is matching esbuild 0.25.0: upstream tag v0.25.0 is commit e9174d671b1882758cd32ac5e146200f5bee3e45, has MIT evidence in LICENSE.md and npm/esbuild/LICENSE.md, and has no submodules (https://github.com/evanw/esbuild/blob/e9174d671b1882758cd32ac5e146200f5bee3e45/LICENSE.md). Build that helper from this source with Guix Go inputs; do not ship the npm prebuilt platform binary. No required independently fetched origin lacks a clear redistribution grant. Create a new module (tay packages astx), preferably using gnu-build-system with fully custom offline phases (or replace every automatic npm phase if node-build-system is used). Native/build inputs must include Guix node 22.x or newer (the upstream astx engine says >=16, but locked tsx and esbuild require >=18), fixed pnpm 8.11.0, the exact non-optional registry archives for the complete pnpm lock closure, and the source-built matching esbuild 0.25.0 helper. Materialize the locked node_modules tree from those archives, then run pnpm install --offline --frozen-lockfile --ignore-scripts followed by the toolchain binary's build subcommand and, with tests enabled, its test subcommand. Do not invoke pnpm run build (the upstream package has no build script), the bare tc alias (it only prints usage), or prepublishOnly (it deliberately exits 1). The clean upstream build produced dist/index.js, dist/index.mjs, declarations, and dist/cli/index.js; all 1,171 upstream tests passed with 16 pending. Install dist as lib/node_modules/astx, retain package.json, README.md, LICENSE.md, and dependency notices, and provide bin/astx as a Node launcher for dist/cli/index.js. Set ESBUILD_BINARY_PATH to the matching source-built esbuild binary so local .ts/.cts/.mts transform files work without npm optional-dependency downloads; omit fsevents and all other platform-optional artifacts. Normal operation has no service, credentials, downloaded assets, or required network integration; a user-supplied transform URL can intentionally perform its own network access and must not be fetched during build. The wrapper must retain a positive worker pool (set ASTX_WORKERS=1 only when unset, or otherwise do not force workers=0): this pinned CLI's single-process path passes the result wrapper incorrectly and crashes with path.relative(..., undefined), while the default worker path works. There is no upstream --dry-run flag. Acceptance proof: after the package is implemented, run guix lint -L. astx and guix build -L. astx with tests enabled; then in a fresh temporary directory create a small .ts fixture and a .cts transform exporting find/replace for a deliberately absent pattern, run the installed bin/astx with ASTX_WORKERS=1 and ESBUILD_BINARY_PATH set, without --yes, and assert exit 0, the reported unchanged/no-match result, and identical pre/post sha256 hashes. This isolated no-match transform exercises the Babel TypeScript parser, the tsx/esbuild loader, worker wrapper, and the no-write dry-run behavior. Guix lint/build were not claimed here because the host Guix daemon socket was unavailable; they are the stated implementation acceptance gates, not evidence of an existing package proof. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/104#issuecomment-5455799071). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T17:43:33Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#104
No description provided.