[Guix packaging] excalidraw/excalidraw #117
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#117
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Candidate
abeeaeba217ab3b5193b78c8d8d63c373b518cedonmaster(default branch snapshot reviewed 2026-08-14).@excalidraw/excalidrawpackagespackage.json,yarn.lock; React/Vite packages)LICENSEcontains MIT and the README identifies the open-source Excalidraw editor/packages.Scope and blockers
Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Separate the distributable editor/package from hosted collaboration services, reproduce the Yarn monorepo build, and disable telemetry/network calls in the offline app.
Acceptance checks
guix lint -L. excalidrawpasses with no new errors.guix build -L. excalidrawsucceeds from the pinned source with tests enabled where practical.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:36Z.
Goocastle recorded disposition: blocked.
Upstream excalidraw/excalidraw at pinned commit abeeaeba217ab3b5193b78c8d8d63c373b518ced (https://github.com/excalidraw/excalidraw) is legally clear but not deliverable unattended as a Guix package under current evidence.
License/provenance evidence: fetched the pinned tarball (sha256 9ee14ba24df043fdf87e451bf48131f2e308bfc6c05937ddc4060051e711ac01) and the named files at that exact revision. LICENSE reads 'MIT License, Copyright (c) 2020 Excalidraw'; packages/excalidraw/package.json declares "license": "MIT" for @excalidraw/excalidraw 0.18.0. No .gitmodules exists at that revision (HTTP 404), so there is no separately fetched submodule origin requiring independent license evidence. Existing channel coverage: guix/tay/packages/starred-d-h.scm defines only excalidraw-excalidraw-source, a make-github-source-snapshot at the identical commit with hash 00dc27km2006qkfkfnf0qszhiqzj660z86s5gvwgshzh9ni4pqcy and license:expat. That is a source-only snapshot, not a built deliverable, and there is no prior closed delivery issue for a built excalidraw package, so this is not a terminal duplicate.
Blocker 1 (source-buildability): the root package.json is a private Yarn 1.22.22 workspaces monorepo (workspaces excalidraw-app, packages/, examples/) whose build scripts (build:packages, build:app via cross-env + vite build) require a full npm dependency closure resolved from yarn.lock at build time. Direct dependencies alone span Vite 5, React 19, esbuild, sass, firebase 11.3.1, @sentry/browser 9.0.1, socket.io-client, radix-ui, harfbuzzjs and dozens more, expanding transitively to thousands of unpackaged npm modules. Guix builds are offline, the channel provides no vendored node_modules or corresponding node-* input set, and none of those transitive origins have recorded fixed revisions or license evidence. Unblocking condition: a reviewed, offline-resolvable dependency closure (vendored yarn offline mirror as a hashed origin, or generated node-* package definitions) with per-origin license evidence at fixed revisions.
Blocker 2 (missing runtime contract): the deliverable is a browser bundle plus React library, not an installed executable. excalidraw-app/index.tsx boots a DOM root via createRoot and registerSW and imports ../excalidraw-app/sentry; upstream ships no noninteractive CLI smoke mode. The only serving path is 'npx http-server build' / 'vite preview', i.e. a network listener, and there is no upstream invocation producing a single deterministic stdout success marker. The package would therefore need a purpose-written wrapper executable performing a headless export; no such wrapper or headless entry point exists upstream at this revision, and specifying one requires deciding on a headless browser runtime input that the channel does not currently provide. Unblocking condition: a defined wrapper executable with fixed argv and a single-line stdout marker (for example a headless PNG/SVG export of a fixed fixture) plus its declared headless browser input.
Also telemetry: excalidraw-app pulls @sentry/browser and firebase unconditionally; build:app:docker sets VITE_APP_DISABLE_SENTRY=true, so an offline variant must pin that and strip firebase/socket.io collaboration paths, which is additional unreviewed patch scope.
Environment and tooling limitations recorded: no Guix daemon was available to this phase, so no guix shell, guix lint, or guix build was attempted and no package proof is claimed. The reviewed manifest's libarchive/bsdtar was not present on PATH and no /gnu/store/libarchive/bin/bsdtar existed; the intended command 'bsdtar -xf excalidraw.tar.gz -C ' failed with 'bsdtar: command not found', so archive-internal inspection (notably full yarn.lock contents) could not be gathered and build metadata was read via raw.githubusercontent.com at the pinned commit instead.