[Guix packaging] excalidraw/excalidraw #117

Open
opened 2026-08-14 13:17:36 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:36 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/excalidraw/excalidraw
  • Source pinned commit/release when known: abeeaeba217ab3b5193b78c8d8d63c373b518ced on master (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: Excalidraw offline whiteboard web application and @excalidraw/excalidraw packages
  • Primary category: desktop-application
  • Tags: image-processing
  • Primary language normalized: TypeScript
  • Build system: Yarn workspaces (package.json, yarn.lock; React/Vite packages)
  • SPDX expression: MIT
  • License status: confirmed-free
  • License evidence: LICENSE contains MIT and the README identifies the open-source Excalidraw editor/packages.
  • Difficulty: hard — Separate the distributable editor/package from hosted collaboration services, reproduce the Yarn monorepo build, and disable telemetry/network calls in the offline app.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Separate the distributable editor/package from hosted collaboration services, reproduce the Yarn monorepo build, and disable telemetry/network calls in the offline app.

Acceptance checks

  • guix lint -L. excalidraw passes with no new errors.
  • guix build -L. excalidraw succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Build the editor/packages offline and serve a local bundle under a headless browser, creating and exporting a PNG/SVG fixture.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:36Z.

## Candidate - Upstream canonical URL: https://github.com/excalidraw/excalidraw - Source pinned commit/release when known: `abeeaeba217ab3b5193b78c8d8d63c373b518ced` on `master` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: Excalidraw offline whiteboard web application and `@excalidraw/excalidraw` packages - Primary category: desktop-application - Tags: image-processing - Primary language normalized: TypeScript - Build system: Yarn workspaces (`package.json`, `yarn.lock`; React/Vite packages) - SPDX expression: MIT - License status: confirmed-free - License evidence: `LICENSE` contains MIT and the README identifies the open-source Excalidraw editor/packages. - Difficulty: hard — Separate the distributable editor/package from hosted collaboration services, reproduce the Yarn monorepo build, and disable telemetry/network calls in the offline app. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Separate the distributable editor/package from hosted collaboration services, reproduce the Yarn monorepo build, and disable telemetry/network calls in the offline app. ## Acceptance checks - `guix lint -L. excalidraw` passes with no new errors. - `guix build -L. excalidraw` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Build the editor/packages offline and serve a local bundle under a headless browser, creating and exporting a PNG/SVG fixture. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/117). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:36Z.
Owner

Goocastle recorded disposition: blocked.

Upstream excalidraw/excalidraw at pinned commit abeeaeba217ab3b5193b78c8d8d63c373b518ced (https://github.com/excalidraw/excalidraw) is legally clear but not deliverable unattended as a Guix package under current evidence.

License/provenance evidence: fetched the pinned tarball (sha256 9ee14ba24df043fdf87e451bf48131f2e308bfc6c05937ddc4060051e711ac01) and the named files at that exact revision. LICENSE reads 'MIT License, Copyright (c) 2020 Excalidraw'; packages/excalidraw/package.json declares "license": "MIT" for @excalidraw/excalidraw 0.18.0. No .gitmodules exists at that revision (HTTP 404), so there is no separately fetched submodule origin requiring independent license evidence. Existing channel coverage: guix/tay/packages/starred-d-h.scm defines only excalidraw-excalidraw-source, a make-github-source-snapshot at the identical commit with hash 00dc27km2006qkfkfnf0qszhiqzj660z86s5gvwgshzh9ni4pqcy and license:expat. That is a source-only snapshot, not a built deliverable, and there is no prior closed delivery issue for a built excalidraw package, so this is not a terminal duplicate.

Blocker 1 (source-buildability): the root package.json is a private Yarn 1.22.22 workspaces monorepo (workspaces excalidraw-app, packages/, examples/) whose build scripts (build:packages, build:app via cross-env + vite build) require a full npm dependency closure resolved from yarn.lock at build time. Direct dependencies alone span Vite 5, React 19, esbuild, sass, firebase 11.3.1, @sentry/browser 9.0.1, socket.io-client, radix-ui, harfbuzzjs and dozens more, expanding transitively to thousands of unpackaged npm modules. Guix builds are offline, the channel provides no vendored node_modules or corresponding node-* input set, and none of those transitive origins have recorded fixed revisions or license evidence. Unblocking condition: a reviewed, offline-resolvable dependency closure (vendored yarn offline mirror as a hashed origin, or generated node-* package definitions) with per-origin license evidence at fixed revisions.

Blocker 2 (missing runtime contract): the deliverable is a browser bundle plus React library, not an installed executable. excalidraw-app/index.tsx boots a DOM root via createRoot and registerSW and imports ../excalidraw-app/sentry; upstream ships no noninteractive CLI smoke mode. The only serving path is 'npx http-server build' / 'vite preview', i.e. a network listener, and there is no upstream invocation producing a single deterministic stdout success marker. The package would therefore need a purpose-written wrapper executable performing a headless export; no such wrapper or headless entry point exists upstream at this revision, and specifying one requires deciding on a headless browser runtime input that the channel does not currently provide. Unblocking condition: a defined wrapper executable with fixed argv and a single-line stdout marker (for example a headless PNG/SVG export of a fixed fixture) plus its declared headless browser input.

Also telemetry: excalidraw-app pulls @sentry/browser and firebase unconditionally; build:app:docker sets VITE_APP_DISABLE_SENTRY=true, so an offline variant must pin that and strip firebase/socket.io collaboration paths, which is additional unreviewed patch scope.

Environment and tooling limitations recorded: no Guix daemon was available to this phase, so no guix shell, guix lint, or guix build was attempted and no package proof is claimed. The reviewed manifest's libarchive/bsdtar was not present on PATH and no /gnu/store/libarchive/bin/bsdtar existed; the intended command 'bsdtar -xf excalidraw.tar.gz -C ' failed with 'bsdtar: command not found', so archive-internal inspection (notably full yarn.lock contents) could not be gathered and build metadata was read via raw.githubusercontent.com at the pinned commit instead.

<!-- goocastle-disposition:sequential-reviewer:117:1:blocked --> Goocastle recorded disposition: blocked. Upstream excalidraw/excalidraw at pinned commit abeeaeba217ab3b5193b78c8d8d63c373b518ced (https://github.com/excalidraw/excalidraw) is legally clear but not deliverable unattended as a Guix package under current evidence. License/provenance evidence: fetched the pinned tarball (sha256 9ee14ba24df043fdf87e451bf48131f2e308bfc6c05937ddc4060051e711ac01) and the named files at that exact revision. LICENSE reads 'MIT License, Copyright (c) 2020 Excalidraw'; packages/excalidraw/package.json declares "license": "MIT" for @excalidraw/excalidraw 0.18.0. No .gitmodules exists at that revision (HTTP 404), so there is no separately fetched submodule origin requiring independent license evidence. Existing channel coverage: guix/tay/packages/starred-d-h.scm defines only excalidraw-excalidraw-source, a make-github-source-snapshot at the identical commit with hash 00dc27km2006qkfkfnf0qszhiqzj660z86s5gvwgshzh9ni4pqcy and license:expat. That is a source-only snapshot, not a built deliverable, and there is no prior closed delivery issue for a built excalidraw package, so this is not a terminal duplicate. Blocker 1 (source-buildability): the root package.json is a private Yarn 1.22.22 workspaces monorepo (workspaces excalidraw-app, packages/*, examples/*) whose build scripts (build:packages, build:app via cross-env + vite build) require a full npm dependency closure resolved from yarn.lock at build time. Direct dependencies alone span Vite 5, React 19, esbuild, sass, firebase 11.3.1, @sentry/browser 9.0.1, socket.io-client, radix-ui, harfbuzzjs and dozens more, expanding transitively to thousands of unpackaged npm modules. Guix builds are offline, the channel provides no vendored node_modules or corresponding node-* input set, and none of those transitive origins have recorded fixed revisions or license evidence. Unblocking condition: a reviewed, offline-resolvable dependency closure (vendored yarn offline mirror as a hashed origin, or generated node-* package definitions) with per-origin license evidence at fixed revisions. Blocker 2 (missing runtime contract): the deliverable is a browser bundle plus React library, not an installed executable. excalidraw-app/index.tsx boots a DOM root via createRoot and registerSW and imports ../excalidraw-app/sentry; upstream ships no noninteractive CLI smoke mode. The only serving path is 'npx http-server build' / 'vite preview', i.e. a network listener, and there is no upstream invocation producing a single deterministic stdout success marker. The package would therefore need a purpose-written wrapper executable performing a headless export; no such wrapper or headless entry point exists upstream at this revision, and specifying one requires deciding on a headless browser runtime input that the channel does not currently provide. Unblocking condition: a defined wrapper executable with fixed argv and a single-line stdout marker (for example a headless PNG/SVG export of a fixed fixture) plus its declared headless browser input. Also telemetry: excalidraw-app pulls @sentry/browser and firebase unconditionally; build:app:docker sets VITE_APP_DISABLE_SENTRY=true, so an offline variant must pin that and strip firebase/socket.io collaboration paths, which is additional unreviewed patch scope. Environment and tooling limitations recorded: no Guix daemon was available to this phase, so no guix shell, guix lint, or guix build was attempted and no package proof is claimed. The reviewed manifest's libarchive/bsdtar was not present on PATH and no /gnu/store/*libarchive*/bin/bsdtar existed; the intended command 'bsdtar -xf excalidraw.tar.gz -C <workspace> <named files>' failed with 'bsdtar: command not found', so archive-internal inspection (notably full yarn.lock contents) could not be gathered and build metadata was read via raw.githubusercontent.com at the pinned commit instead.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#117
No description provided.