[Guix packaging] fedarovich/qbittorrent-cli #119

Open
opened 2026-08-14 13:17:37 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:37 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/fedarovich/qbittorrent-cli
  • Source pinned commit/release when known: c5794123bd204e629729e52e7177834c4ba3bfc2 on master (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: qbittorrent-cli C# remote qBittorrent command-line client
  • Primary category: networking-client
  • Tags: bittorrent
  • Primary language normalized: C#
  • Build system: dotnet/MSBuild (*.sln, *.csproj, WiX packaging)
  • SPDX expression: MIT
  • License status: confirmed-free
  • License evidence: LICENSE contains MIT and the repository contains .NET project/solution manifests.
  • Difficulty: moderate — Pin the .NET SDK and generated packaging targets, and test Web API behavior against a local mock rather than a remote qBittorrent instance.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Pin the .NET SDK and generated packaging targets, and test Web API behavior against a local mock rather than a remote qBittorrent instance.

Acceptance checks

  • guix lint -L. qbittorrent-cli passes with no new errors.
  • guix build -L. qbittorrent-cli succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Run dotnet test/build offline and execute qbittorrent-cli --help against a local mock HTTP endpoint with no external network.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:37Z.

## Candidate - Upstream canonical URL: https://github.com/fedarovich/qbittorrent-cli - Source pinned commit/release when known: `c5794123bd204e629729e52e7177834c4ba3bfc2` on `master` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: `qbittorrent-cli` C# remote qBittorrent command-line client - Primary category: networking-client - Tags: bittorrent - Primary language normalized: C# - Build system: dotnet/MSBuild (`*.sln`, `*.csproj`, WiX packaging) - SPDX expression: MIT - License status: confirmed-free - License evidence: `LICENSE` contains MIT and the repository contains .NET project/solution manifests. - Difficulty: moderate — Pin the .NET SDK and generated packaging targets, and test Web API behavior against a local mock rather than a remote qBittorrent instance. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Pin the .NET SDK and generated packaging targets, and test Web API behavior against a local mock rather than a remote qBittorrent instance. ## Acceptance checks - `guix lint -L. qbittorrent-cli` passes with no new errors. - `guix build -L. qbittorrent-cli` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Run `dotnet test`/build offline and execute `qbittorrent-cli --help` against a local mock HTTP endpoint with no external network. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/119). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:37Z.
htayj commented 2026-08-29 09:22:32 +00:00 (Migrated from github.com)

Goocastle recorded disposition: blocked.

The request is legally plausible but is blocked for unattended Guix implementation by concrete toolchain and provenance gaps. Authoritative upstream is https://github.com/fedarovich/qbittorrent-cli at fixed commit c5794123bd204e629729e52e7177834c4ba3bfc2 (2024-10-11, “Fix compatibility with qBittorrent 5.0.0”); its exact tree has LICENSE granting MIT, no .gitmodules, and no test project/files. The executable source is src/QBittorrent.CommandLineInterface/QBittorrent.CommandLineInterface.csproj, an SDK-style Microsoft.NET.Sdk project targeting net6;netcoreapp3.1;netcoreapp2.1;net46, with LangVersion 10 and fixed direct PackageReferences including Alba.CsConsoleFormat 1.0.0, BencodeNET 2.3.0, CsvHelper 12.1.2, IPNetwork2 2.5.235, McMaster.Extensions.CommandLineUtils 2.4.4, conditional Mono.Posix.NETStandard 1.0.0/Mono.Posix 5.4.0.201, Newtonsoft.Json 13.0.3, NJsonSchema 9.14.1, Portable.BouncyCastle 1.8.8, QBittorrent.Client 1.9.24285.1, System.Security.Cryptography.ProtectedData 5.0.0, and conditional System.Memory 4.5.5. It has neither global.json nor packages.lock.json and adds https://www.myget.org/F/fedarovich/api/v3/index.json to restore sources. The parent origin is therefore redistributable at the fixed revision and has no submodule origins, but every dependency origin still needs to be materialized and audited separately: exact NuGet nuspecs provide explicit expressions for BencodeNET 2.3.0 (Unlicense), McMaster.Extensions.CommandLineUtils 2.4.4 (Apache-2.0, repository commit 3c2a4909757a51602dcca9b961d577511b85fd31), Newtonsoft.Json 13.0.3 (MIT, repository commit 0a2e291c0d9c0c7675d445703e51750363a549ef), QBittorrent.Client 1.9.24285.1 (MIT), and System.Security.Cryptography.ProtectedData 5.0.0 (MIT, dotnet/runtime commit cf258a14b70ad9069470a108f13765e0e5988f51); the remaining direct packages expose only project-license URLs in their exact nuspecs and the transitive closure is not fixed. In particular, the required-as-written net46 branch’s exact Mono.Posix 5.4.0.201 nuspec has no licenseUrl, projectUrl, repository, or source revision, so its redistribution grant is unproven. Local channel evidence: tay/packages/starred-d-h.scm:295 is only a source-snapshot package (not an installed executable); sbcl-qbcl in tay/packages/qbcl.scm is the unrelated GPL Common Lisp htayj/qbcl client; and Guix’s qBittorrent search results contain GUI/server packages, not this CLI. The current Guix 1.5 package set provides mono 6.12.0.206 and msbuild 15.7.179, but guix show reports no dotnet SDK, dotnet runtime, or nuget package; the msbuild definition installs the MSBuild engine/tasks but no Microsoft.NET.Sdk or net6 targeting packs. Consequently the SDK-style project cannot be restored/built offline, and a framework-dependent net6 output would have no channel runtime; Mono/net46 is not an as-is fallback. Unblock only when a reviewed, fixed .NET SDK plus compatible targeting packs/runtime (or an explicitly scoped, proven net46 conversion) is available, the MyGet/network restore is removed or overridden, the complete direct/transitive dependency closure is fixed with hashes and explicit license evidence for every separately fetched origin (or Mono.Posix is removed/replaced with a clearly licensed source at a fixed revision), and the package preserves LICENSE/notices. The implementation brief should then use a Guix package in a new networking-client module, build only the Linux CLI target, install qbt with a store-absolute runtime wrapper, keep settings/credential key material in the user’s ~/.qbt rather than the store, and avoid fetching plugins, torrents, or remote assets during build. Acceptance proof should be network-disabled lint/build with tests enabled where present (the upstream tree has no tests), followed by an isolated temp HOME/XDG smoke: run qbt --help, start a loopback-only mock qBittorrent Web API that answers login and one read-only request, assert expected output, and verify no external network, credentials, downloads, or store writes. No package proof is claimed.


Imported from GitHub comment. Originally posted by htayj on 2026-08-29T09:22:32Z.

<!-- goocastle-disposition:sequential-reviewer:119:1:blocked --> Goocastle recorded disposition: blocked. The request is legally plausible but is blocked for unattended Guix implementation by concrete toolchain and provenance gaps. Authoritative upstream is https://github.com/fedarovich/qbittorrent-cli at fixed commit c5794123bd204e629729e52e7177834c4ba3bfc2 (2024-10-11, “Fix compatibility with qBittorrent 5.0.0”); its exact tree has LICENSE granting MIT, no .gitmodules, and no test project/files. The executable source is src/QBittorrent.CommandLineInterface/QBittorrent.CommandLineInterface.csproj, an SDK-style Microsoft.NET.Sdk project targeting net6;netcoreapp3.1;netcoreapp2.1;net46, with LangVersion 10 and fixed direct PackageReferences including Alba.CsConsoleFormat 1.0.0, BencodeNET 2.3.0, CsvHelper 12.1.2, IPNetwork2 2.5.235, McMaster.Extensions.CommandLineUtils 2.4.4, conditional Mono.Posix.NETStandard 1.0.0/Mono.Posix 5.4.0.201, Newtonsoft.Json 13.0.3, NJsonSchema 9.14.1, Portable.BouncyCastle 1.8.8, QBittorrent.Client 1.9.24285.1, System.Security.Cryptography.ProtectedData 5.0.0, and conditional System.Memory 4.5.5. It has neither global.json nor packages.lock.json and adds https://www.myget.org/F/fedarovich/api/v3/index.json to restore sources. The parent origin is therefore redistributable at the fixed revision and has no submodule origins, but every dependency origin still needs to be materialized and audited separately: exact NuGet nuspecs provide explicit expressions for BencodeNET 2.3.0 (Unlicense), McMaster.Extensions.CommandLineUtils 2.4.4 (Apache-2.0, repository commit 3c2a4909757a51602dcca9b961d577511b85fd31), Newtonsoft.Json 13.0.3 (MIT, repository commit 0a2e291c0d9c0c7675d445703e51750363a549ef), QBittorrent.Client 1.9.24285.1 (MIT), and System.Security.Cryptography.ProtectedData 5.0.0 (MIT, dotnet/runtime commit cf258a14b70ad9069470a108f13765e0e5988f51); the remaining direct packages expose only project-license URLs in their exact nuspecs and the transitive closure is not fixed. In particular, the required-as-written net46 branch’s exact Mono.Posix 5.4.0.201 nuspec has no licenseUrl, projectUrl, repository, or source revision, so its redistribution grant is unproven. Local channel evidence: tay/packages/starred-d-h.scm:295 is only a source-snapshot package (not an installed executable); sbcl-qbcl in tay/packages/qbcl.scm is the unrelated GPL Common Lisp htayj/qbcl client; and Guix’s qBittorrent search results contain GUI/server packages, not this CLI. The current Guix 1.5 package set provides mono 6.12.0.206 and msbuild 15.7.179, but guix show reports no dotnet SDK, dotnet runtime, or nuget package; the msbuild definition installs the MSBuild engine/tasks but no Microsoft.NET.Sdk or net6 targeting packs. Consequently the SDK-style project cannot be restored/built offline, and a framework-dependent net6 output would have no channel runtime; Mono/net46 is not an as-is fallback. Unblock only when a reviewed, fixed .NET SDK plus compatible targeting packs/runtime (or an explicitly scoped, proven net46 conversion) is available, the MyGet/network restore is removed or overridden, the complete direct/transitive dependency closure is fixed with hashes and explicit license evidence for every separately fetched origin (or Mono.Posix is removed/replaced with a clearly licensed source at a fixed revision), and the package preserves LICENSE/notices. The implementation brief should then use a Guix package in a new networking-client module, build only the Linux CLI target, install qbt with a store-absolute runtime wrapper, keep settings/credential key material in the user’s ~/.qbt rather than the store, and avoid fetching plugins, torrents, or remote assets during build. Acceptance proof should be network-disabled lint/build with tests enabled where present (the upstream tree has no tests), followed by an isolated temp HOME/XDG smoke: run qbt --help, start a loopback-only mock qBittorrent Web API that answers login and one read-only request, assert expected output, and verify no external network, credentials, downloads, or store writes. No package proof is claimed. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/119#issuecomment-5461526095). Originally posted by [htayj](https://github.com/htayj) on 2026-08-29T09:22:32Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#119
No description provided.