[Guix packaging] cookinrelaxin/persephil #107

Open
opened 2026-08-14 13:17:27 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:27 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/cookinrelaxin/persephil
  • Source pinned commit/release when known: 1e10afbbcb8c6f56d2cc22db0c915a9d64ecd8d6 on main (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: Persephil Node CLI exporting Perseus corpus search results to .xlsx
  • Primary category: command-line-tool
  • Tags: None
  • Primary language normalized: JavaScript
  • Build system: npm (package.json; single main.js downloader using got/jsdom/exceljs)
  • SPDX expression: GPL-3.0 AND ISC
  • License status: mixed-review
  • License evidence: LICENSE contains GPLv3 while package.json declares ISC; resolve this source/package license conflict before publication.
  • Difficulty: moderate — The README warns the upstream service changed and the code is untested; pin dependencies, inspect remote HTML parsing, and resolve the conflicting license declarations.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. The README warns the upstream service changed and the code is untested; pin dependencies, inspect remote HTML parsing, and resolve the conflicting license declarations.

Acceptance checks

  • guix lint -L. persephil passes with no new errors.
  • guix build -L. persephil succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Run the CLI against a recorded local KWIC HTML fixture with network disabled and verify deterministic .xlsx output.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:27Z.

## Candidate - Upstream canonical URL: https://github.com/cookinrelaxin/persephil - Source pinned commit/release when known: `1e10afbbcb8c6f56d2cc22db0c915a9d64ecd8d6` on `main` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: Persephil Node CLI exporting Perseus corpus search results to `.xlsx` - Primary category: command-line-tool - Tags: None - Primary language normalized: JavaScript - Build system: npm (`package.json`; single `main.js` downloader using got/jsdom/exceljs) - SPDX expression: GPL-3.0 AND ISC - License status: mixed-review - License evidence: `LICENSE` contains GPLv3 while `package.json` declares ISC; resolve this source/package license conflict before publication. - Difficulty: moderate — The README warns the upstream service changed and the code is untested; pin dependencies, inspect remote HTML parsing, and resolve the conflicting license declarations. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. The README warns the upstream service changed and the code is untested; pin dependencies, inspect remote HTML parsing, and resolve the conflicting license declarations. ## Acceptance checks - `guix lint -L. persephil` passes with no new errors. - `guix build -L. persephil` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Run the CLI against a recorded local KWIC HTML fixture with network disabled and verify deterministic `.xlsx` output. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/107). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:27Z.
htayj commented 2026-08-29 07:46:24 +00:00 (Migrated from github.com)

Goocastle recorded disposition: blocked.

BLOCKED. Canonical upstream is https://github.com/cookinrelaxin/persephil; upstream metadata calls the project version 1.0.0 (tag v1.0.0 is 36260f20114e62450675e80e35b4cecb9ddaeb18), but the requested fixed source is main commit 1e10afbbcb8c6f56d2cc22db0c915a9d64ecd8d6. The exact codeload archive is reproducible with Guix nix-base32 SHA-256 10jpc44cnlfph1h9zzy01xlvird0ay0a5x84la5fjk7s2wd7xf6h. Its commit tree has only .gitignore, LICENSE, README.md, main.js, package-lock.json, and package.json; there is no .gitmodules file or submodule entry.

The primary legal blocker is unresolved source metadata: LICENSE at that exact commit is the full GNU GPL version 3 text (GitHub's license endpoint for ref 1e10af... reports GPL-3.0), while package.json declares "license": "ISC" and has no author. The local channel's existing preservation snapshot uses GPL-3.0, but that does not resolve the contradictory upstream declaration for publication. Unblock only when the upstream copyright holder clarifies the intended license or publishes a corrected, newly pinned revision, with the source/package license evidence agreeing.

There is an additional required-origin rights blocker. package-lock.json is lockfileVersion 1 with 196 exact npm registry tarball origins; every resolved URL is registry.npmjs.org and every lock entry has integrity. The direct locked inputs are exceljs 4.2.0, got 11.8.1, jsdom 16.4.0, and moment 2.29.1; exact npm metadata identifies each as MIT. The exact locked transitive origin buffers@0.1.1 (https://registry.npmjs.org/buffers/0.1.1; tarball integrity sha512-9q/rDEGSb/Qsvv2qvzIzdluL5k7AaJOTrw23z9reQthrbF7is4CtlT0DXyO1oei2DCp4uojjzQ7igaSHp1kAEQ==; fetched archive SHA-256 f8de49c60e467005182d9687b5d87775bbcec6385ac63220b7741327441deb6d) has null license and licenses metadata, no LICENSE/ COPYING/NOTICE file in the tarball, and its README.markdown grants no redistribution license. It is required by binary@0.3.0 through unzipper@0.10.11, an ExcelJS dependency. The other locked package origins had explicit package license metadata in the exact installed versions; this one does not. Unblock only by obtaining an explicit grant from the buffers copyright holder for version 0.1.1 or replacing that dependency with a fixed origin having clear redistribution terms, and record that evidence.

The source is syntactically valid: node --check passed, and npm ci --ignore-scripts --no-audit --no-fund succeeded in a temporary checkout without changing package-lock.json. The upstream test script intentionally exits 1 (no tests). Guix build/lint proof was not claimed: the host had no /var/guix/daemon-socket/socket. No equivalent installable package exists in this local channel: tay/packages contains only cookinrelaxin-persephil-source, the preservation snapshot; the issue inventory also found no equivalent in the checked Guix channel families.

A future implementation would belong in module (tay packages persephil), package persephil, using node-build-system and fixed native inputs for the complete lockfile closure, with no package-manager network access. The wrapper should invoke the installed main.js with Guix Node, preserve the caller's writable current directory because upstream writes "Latin corpus search MM-DD-YY HH mm ss.xlsx" there, and pass the user-supplied URL; there are no credentials, services, or optional integrations. A build-time source patch is required even apart from the blockers: Linux cannot resolve upstream's require('excelJS') because the npm package is lowercase exceljs (unmodified execution fails MODULE_NOT_FOUND). A temporary module alias made a two-row local fixture produce a Data worksheet with Text/Extract/Work/Passage values and bold extraction, so this typo is patchable, not proof of a package.

The documented live input is also stale: https://perseus.uchicago.edu/Latin.html and the Greek equivalent now return 404; the official home says the old PhiloLogic3 server was unplugged and points to PhiloLogic4. The current endpoint https://artflsrv03.uchicago.edu/philologic4/Latin/reports/kwic.py?q=amor&report=kwic returns JSON results[].context fragments, while the current template uses .kwic_line and result.context. main.js only searches HTML .content nodes, takes nextSibling title elements, and expects nested b/a metadata, so it produces no usable rows for the current service. Unblock the technical target by selecting and documenting a maintained input contract: an upstream-compatible parser update for the PhiloLogic4 JSON/HTML response with a fixed fixture, or an explicit decision that legacy HTML-only export is the supported deliverable.

After all blockers are cleared, the isolated smoke proof should serve a recorded KWIC fixture from an ephemeral loopback server while external network egress is disabled, invoke the wrapper from a fresh writable directory, and assert a deterministic .xlsx (fixed output/time behavior) has sheet Data, the four headers, the expected row count, exact text/work/passage values, and the highlighted extraction. Repeat from the same fixture and compare normalized workbook bytes, then run guix lint -L. persephil and guix build -L. persephil with tests enabled where practical. Until the license decisions, dependency grant, and input-contract/parser decision are recorded, unattended Guix publication is unsafe.


Imported from GitHub comment. Originally posted by htayj on 2026-08-29T07:46:24Z.

<!-- goocastle-disposition:sequential-reviewer:107:1:blocked --> Goocastle recorded disposition: blocked. BLOCKED. Canonical upstream is https://github.com/cookinrelaxin/persephil; upstream metadata calls the project version 1.0.0 (tag v1.0.0 is 36260f20114e62450675e80e35b4cecb9ddaeb18), but the requested fixed source is main commit 1e10afbbcb8c6f56d2cc22db0c915a9d64ecd8d6. The exact codeload archive is reproducible with Guix nix-base32 SHA-256 10jpc44cnlfph1h9zzy01xlvird0ay0a5x84la5fjk7s2wd7xf6h. Its commit tree has only .gitignore, LICENSE, README.md, main.js, package-lock.json, and package.json; there is no .gitmodules file or submodule entry. The primary legal blocker is unresolved source metadata: LICENSE at that exact commit is the full GNU GPL version 3 text (GitHub's license endpoint for ref 1e10af... reports GPL-3.0), while package.json declares "license": "ISC" and has no author. The local channel's existing preservation snapshot uses GPL-3.0, but that does not resolve the contradictory upstream declaration for publication. Unblock only when the upstream copyright holder clarifies the intended license or publishes a corrected, newly pinned revision, with the source/package license evidence agreeing. There is an additional required-origin rights blocker. package-lock.json is lockfileVersion 1 with 196 exact npm registry tarball origins; every resolved URL is registry.npmjs.org and every lock entry has integrity. The direct locked inputs are exceljs 4.2.0, got 11.8.1, jsdom 16.4.0, and moment 2.29.1; exact npm metadata identifies each as MIT. The exact locked transitive origin buffers@0.1.1 (https://registry.npmjs.org/buffers/0.1.1; tarball integrity sha512-9q/rDEGSb/Qsvv2qvzIzdluL5k7AaJOTrw23z9reQthrbF7is4CtlT0DXyO1oei2DCp4uojjzQ7igaSHp1kAEQ==; fetched archive SHA-256 f8de49c60e467005182d9687b5d87775bbcec6385ac63220b7741327441deb6d) has null license and licenses metadata, no LICENSE/ COPYING/NOTICE file in the tarball, and its README.markdown grants no redistribution license. It is required by binary@0.3.0 through unzipper@0.10.11, an ExcelJS dependency. The other locked package origins had explicit package license metadata in the exact installed versions; this one does not. Unblock only by obtaining an explicit grant from the buffers copyright holder for version 0.1.1 or replacing that dependency with a fixed origin having clear redistribution terms, and record that evidence. The source is syntactically valid: node --check passed, and npm ci --ignore-scripts --no-audit --no-fund succeeded in a temporary checkout without changing package-lock.json. The upstream test script intentionally exits 1 (no tests). Guix build/lint proof was not claimed: the host had no /var/guix/daemon-socket/socket. No equivalent installable package exists in this local channel: tay/packages contains only cookinrelaxin-persephil-source, the preservation snapshot; the issue inventory also found no equivalent in the checked Guix channel families. A future implementation would belong in module (tay packages persephil), package persephil, using node-build-system and fixed native inputs for the complete lockfile closure, with no package-manager network access. The wrapper should invoke the installed main.js with Guix Node, preserve the caller's writable current directory because upstream writes "Latin corpus search MM-DD-YY HH mm ss.xlsx" there, and pass the user-supplied URL; there are no credentials, services, or optional integrations. A build-time source patch is required even apart from the blockers: Linux cannot resolve upstream's require('excelJS') because the npm package is lowercase exceljs (unmodified execution fails MODULE_NOT_FOUND). A temporary module alias made a two-row local fixture produce a Data worksheet with Text/Extract/Work/Passage values and bold extraction, so this typo is patchable, not proof of a package. The documented live input is also stale: https://perseus.uchicago.edu/Latin.html and the Greek equivalent now return 404; the official home says the old PhiloLogic3 server was unplugged and points to PhiloLogic4. The current endpoint https://artflsrv03.uchicago.edu/philologic4/Latin/reports/kwic.py?q=amor&report=kwic returns JSON results[].context fragments, while the current template uses .kwic_line and result.context. main.js only searches HTML .content nodes, takes nextSibling title elements, and expects nested b/a metadata, so it produces no usable rows for the current service. Unblock the technical target by selecting and documenting a maintained input contract: an upstream-compatible parser update for the PhiloLogic4 JSON/HTML response with a fixed fixture, or an explicit decision that legacy HTML-only export is the supported deliverable. After all blockers are cleared, the isolated smoke proof should serve a recorded KWIC fixture from an ephemeral loopback server while external network egress is disabled, invoke the wrapper from a fresh writable directory, and assert a deterministic .xlsx (fixed output/time behavior) has sheet Data, the four headers, the expected row count, exact text/work/passage values, and the highlighted extraction. Repeat from the same fixture and compare normalized workbook bytes, then run guix lint -L. persephil and guix build -L. persephil with tests enabled where practical. Until the license decisions, dependency grant, and input-contract/parser decision are recorded, unattended Guix publication is unsafe. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/107#issuecomment-5461130971). Originally posted by [htayj](https://github.com/htayj) on 2026-08-29T07:46:24Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#107
No description provided.