[Guix packaging] herdrdev/herdr #124
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#124
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Candidate
d76657f2c7fc18dcce3b9af43842c8afaba1646bonmaster(default branch snapshot reviewed 2026-08-14).herdrpersistent terminal workspace manager for coding agentsCargo.toml,build.rs,vendor/libghostty-vt)LICENSEcontains Apache-2.0; vendored portable-pty/Ghostty/native assets have separate notices that need an audit.Scope and blockers
Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Reproduce the Rust/native Ghostty build without Zig downloads, package the daemon/socket protocol safely, and audit vendored notices.
Acceptance checks
guix lint -L. herdrpasses with no new errors.guix build -L. herdrsucceeds from the pinned source with tests enabled where practical.herdr --helpplus a local temporary workspace/server smoke with no agents or network.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:41Z.
Goocastle recorded disposition: implementation-ready.
Created implementation ticket: #655.
Implementation-ready delivery brief for herdr. Canonical upstream is https://github.com/herdrdev/herdr; fetch the Git revision d76657f2c7fc18dcce3b9af43842c8afaba1646b from master, whose Cargo package version is 0.8.0. The intended Guix package name is herdr, in the terminal package module (gnu packages terminals), for x86_64-linux initially; the static Guix metadata confirms zig@0.15.2 for x86_64-linux, while aarch64 support should be added only after a matching Zig input is verified; build.rs maps those targets to x86_64-linux-gnu and aarch64-linux-gnu. The local channel and the issue's GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix 'R Us/RDE coverage check found no equivalent package with this upstream origin.
License and provenance are actionable but mixed: the pinned herdr tree's LICENSE is Apache-2.0; vendor/libghostty-vt.vendor.json records Ghostty source commit c5a21edfcbc2d5b46540ad91b7980aca31f5f1f3 and vendor/libghostty-vt/LICENSE grants MIT; vendor/portable-pty is portable-pty 0.9.0 from crates.io, fixed by the registry crate archive SHA-256 b4a596a2b3d2752d94f51fac2d4a96737b8705dddd311a32b9af47211f08671e, and its LICENSE.md grants MIT; the vendored SIMD closure uses uucode 0.2.0 from https://deps.files.ghostty.org/uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9.tar.gz (Zig content hash uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9; observed archive SHA-256 d0abee0f4f8bd6eae3c051777e16e7c42d8964aaaa015591c4e565703f465f95), whose LICENSE.md is MIT and whose bundled Unicode and Bjoern Hoehrmann notices are explicit; Highway is fixed at Google Highway commit 66486a10623fa0d72fe91260f96c892e41aceb06 via https://deps.files.ghostty.org/highway-66486a10623fa0d72fe91260f96c892e41aceb06.tar.gz (observed archive SHA-256 87d4f8893ef4e08f224973608ffebf94268a81380ba79c12e8841968c80aa212), with Apache-2.0 and BSD-3-Clause notices; checked-in simdutf is version 9.0.0, dual Apache-2.0/MIT, in vendor/libghostty-vt/pkg/simdutf/vendor/simdutf.h and .cpp. There are no Git submodules (.gitmodules is absent and git submodule status is empty). Retain root and all vendor notices in the source/output license material; do not install optional full-Ghostty GUI/test resources or invoke update/integration features without preserving their notices. In particular, the emit-lib-vt path avoids the GUI-only LGPL libintl dependency and the test-only CC BY-NC-SA shader, while vendor/libghostty-vt/pkg/afl++/LICENSE is MIT. Cargo.lock version 4 has only the crates.io registry source kind and fixes the Rust dependency closure by version/checksum; use those locked registry inputs and their package license metadata rather than treating the root Apache license as covering them.
The source build is technically viable offline. Cargo build.rs unconditionally invokes Zig and links a static ghostty-vt archive; rust-toolchain.toml and vendor/libghostty-vt/build.zig.zon require Zig 0.15.2. With the default ReleaseFast and SIMD=true settings, the Linux -Demit-lib-vt build requires the fixed uucode archive, local vendored simdutf 9.0.0, and the fixed Highway archive; GUI/full-executable lazy dependencies are not in this closure. Guix has a matching zig@0.15.2 package. Implement the package with cargo-build-system, Cargo.lock-driven cargo inputs, and native inputs at least zig@0.15.2, pkg-config, git, and zstd as needed to materialize the Zig cache. Precompute/package a fixed offline Zig global/system cache from vendor/libghostty-vt/build.zig.zon (equivalent to the pinned checkout's vendor/libghostty-vt/build.zig.zon.nix), and set ZIG to Zig 0.15.2, LIBGHOSTTY_VT_ZIG_SYSTEM_DIR to that cache, LIBGHOSTTY_VT_OPTIMIZE=ReleaseFast, and LIBGHOSTTY_VT_SIMD=true. The source fileset must include Cargo.toml, Cargo.lock, build.rs, src, vendor/libghostty-vt, vendor/libghostty-vt.vendor.json, vendor/portable-pty, the API schema, required assets/skills, README, LICENSE, and vendor notices. Do not permit Cargo or Zig network access during the build. The pinned upstream nix/package.nix and vendor/libghostty-vt/nix/libghostty-vt.nix demonstrate this cache/system-directory strategy, but are evidence of feasibility, not Guix package proof.
No installed runtime wrapper, system service, credentials, agent binary, or network endpoint is required. Install the single executable herdr. It starts the user-owned persistent server/session on normal use; the headless server owns local Unix sockets, restricts the socket to mode 0600, and uses HERDR_CONFIG_PATH and HERDR_SOCKET_PATH overrides. State/log/session files remain under the user's XDG config/state directories. Keep self-update, manifest-update, remote, and agent integrations explicit and unused by the package smoke; those features can reach the network or launch user-selected external programs, but --help and the local server/workspace API do not require them.
Deferred acceptance proof for the authorized Guix phase: run guix lint -L. herdr with no new errors; run guix build -L. herdr from this exact source with tests enabled where practical and an offline Cargo/Zig cache; run the Rust/Zig tests that do not require external agents, and run each external runtime check through node /opt/goocastle/bin/bounded-validation.mjs with argv-only execution. For the isolated smoke, set HOME/XDG config and state plus HERDR_CONFIG_PATH and HERDR_SOCKET_PATH beneath one validated temporary directory, run herdr --help and assert the exact stdout marker in runtimeEvidence, start herdr server, wait for the temporary local socket, assert herdr status server --json reports running, create one workspace with herdr workspace create --cwd --label guix-smoke --no-focus, assert the JSON response/list contains that label, close the returned workspace, and finish with herdr server stop. Use no agent command, credentials, update command, remote target, or network; assert the temporary socket is closed/removed and that any state/log files remain confined below the temporary directory. Research did not run guix build or guix shell because the trusted phase boundary declares the Guix daemon unavailable; cargo is also unavailable on this host, so no direct compile was claimed. The authoritative pinned Cargo/Zig metadata and the upstream offline-cache implementation are sufficient for handoff, with those exact acceptance commands left to the later daemon-backed phase.
Imported from GitHub comment. Originally posted by htayj on 2026-08-31T19:08:25Z.