[Guix packaging] justinpopa/mushkin #246

Closed
opened 2026-08-22 05:13:22 +00:00 by htayj · 2 comments
htayj commented 2026-08-22 05:13:22 +00:00 (Migrated from github.com)

Candidate

User-facing deliverable

Cross-platform Qt rewrite implementing most MUSHclient Lua APIs and file/plugin compatibility.

Packaging approach

Package with Clang and cmake-build-system, source and audit the yuescript submodule, and validate MUSHclient compatibility with representative worlds/plugins.

Known blockers and investigation points

Requires Qt 6.9.3 versus audited Guix 6.9.2, C++26/Clang 19+, LuaJIT, libssh, multimedia/spatial audio, and a submodule.

Acceptance checks

  • Pin an immutable upstream release or commit and record a real Guix source hash.
  • Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build.
  • Preserve all applicable project and bundled-component license notices.
  • Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it.
  • Keep profiles, logs, maps, plugins, and other mutable state outside the store.

Existing-package coverage

Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct.


Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-22T05:13:22Z.

## Candidate - Canonical upstream: [https://github.com/justinpopa/mushkin](https://github.com/justinpopa/mushkin) - Packaging target: v0.5.1 (2026-06-01) - Category: MUD client - Tags: mud-client, desktop, Qt, MUSHclient-compatible, Lua, GMCP, plugins - Primary language/build ecosystem: C++26, CMake/Ninja, Qt6, LuaJIT - License: MIT, with separately documented third-party components - License evidence: https://github.com/justinpopa/mushkin/blob/main/LICENSE - Expected Guix packaging difficulty: hard ## User-facing deliverable Cross-platform Qt rewrite implementing most MUSHclient Lua APIs and file/plugin compatibility. ## Packaging approach Package with Clang and cmake-build-system, source and audit the yuescript submodule, and validate MUSHclient compatibility with representative worlds/plugins. ## Known blockers and investigation points Requires Qt 6.9.3 versus audited Guix 6.9.2, C++26/Clang 19+, LuaJIT, libssh, multimedia/spatial audio, and a submodule. ## Acceptance checks - Pin an immutable upstream release or commit and record a real Guix source hash. - Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build. - Preserve all applicable project and bundled-component license notices. - Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it. - Keep profiles, logs, maps, plugins, and other mutable state outside the store. ## Existing-package coverage Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/246). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T05:13:22Z.
htayj commented 2026-08-22 12:49:43 +00:00 (Migrated from github.com)

Feasibility research is complete: Mushkin v0.5.1 is source-packageable on the authenticated Guix Qt 6.9.2 and Clang 21 stack, so this issue is moving to state:ready while retaining difficulty:hard.

Evidence and mandatory implementation items:

  • Canonical upstream is justinpopa/mushkin. Pin v0.5.1 commit 1199f8e68167eee07123f08983fdf5f775b7c5bd recursively, including YueScript submodule 3c8531d33e1de84a7c5f70e0a4cb3d95e7a44c0a; recursive NAR hash 0i6h8500l5jsql25lfv5227vp6ylf04xmxapgs1klwlg4rmfmx7s.
  • Qt 6.9.3 is not a source gate. Offline configuration against Guix Qt 6.9.2 succeeded and a bounded Clang/C++26 probe compiled 244 application objects plus all bundled runtime Lua modules. The package must explicitly use store libglvnd to avoid host OpenGL contamination.
  • Disconnect the unconditional GoogleTest FetchContent using the Guix GoogleTest source. Upstream offers about 1,275 cases across 69 discovered test executables.
  • Install the executable under libexec with its complete Lua/C module tree. Patch runtime state to honor MUSHKIN_HOME and wrap it to an XDG data directory; upstream otherwise changes cwd to the executable directory and attempts to write preferences, worlds, logs, plugins, sounds, and SSH keys into the Guix store.
  • Correct the stale upstream CMake version 0.1.0 to 0.5.1.
  • Before publication, reject absolute or non-basename MSP filenames and verify sound-cache containment. Current server-controlled filenames can traverse outside the intended cache directory.
  • Main code is MIT/Expat. Preserve all bundled Lua/YueScript notices and add missing Feather and Tabler icon notices plus an asset provenance manifest; obtain confirmation that the project grant covers the custom icon and fantasy-name corpus.
  • Acceptance should run all offscreen tests, verify immutable store and XDG state, exercise Telnet/MCCP2/GMCP/MXP/TLS locally, test MSP traversal and bounded caching, and run representative MUSHclient/Aardwolf compatibility fixtures. Upstream compatibility is broad beta coverage, not complete parity.

The same-day audit found no Mushkin package in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, or RDE.


Imported from GitHub comment. Originally posted by htayj on 2026-08-22T12:49:43Z.

Feasibility research is complete: Mushkin v0.5.1 is source-packageable on the authenticated Guix Qt 6.9.2 and Clang 21 stack, so this issue is moving to state:ready while retaining difficulty:hard. Evidence and mandatory implementation items: - Canonical upstream is justinpopa/mushkin. Pin v0.5.1 commit 1199f8e68167eee07123f08983fdf5f775b7c5bd recursively, including YueScript submodule 3c8531d33e1de84a7c5f70e0a4cb3d95e7a44c0a; recursive NAR hash 0i6h8500l5jsql25lfv5227vp6ylf04xmxapgs1klwlg4rmfmx7s. - Qt 6.9.3 is not a source gate. Offline configuration against Guix Qt 6.9.2 succeeded and a bounded Clang/C++26 probe compiled 244 application objects plus all bundled runtime Lua modules. The package must explicitly use store libglvnd to avoid host OpenGL contamination. - Disconnect the unconditional GoogleTest FetchContent using the Guix GoogleTest source. Upstream offers about 1,275 cases across 69 discovered test executables. - Install the executable under libexec with its complete Lua/C module tree. Patch runtime state to honor MUSHKIN_HOME and wrap it to an XDG data directory; upstream otherwise changes cwd to the executable directory and attempts to write preferences, worlds, logs, plugins, sounds, and SSH keys into the Guix store. - Correct the stale upstream CMake version 0.1.0 to 0.5.1. - Before publication, reject absolute or non-basename MSP filenames and verify sound-cache containment. Current server-controlled filenames can traverse outside the intended cache directory. - Main code is MIT/Expat. Preserve all bundled Lua/YueScript notices and add missing Feather and Tabler icon notices plus an asset provenance manifest; obtain confirmation that the project grant covers the custom icon and fantasy-name corpus. - Acceptance should run all offscreen tests, verify immutable store and XDG state, exercise Telnet/MCCP2/GMCP/MXP/TLS locally, test MSP traversal and bounded caching, and run representative MUSHclient/Aardwolf compatibility fixtures. Upstream compatibility is broad beta coverage, not complete parity. The same-day audit found no Mushkin package in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, or RDE. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/246#issuecomment-5380503792). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T12:49:43Z.
htayj commented 2026-08-22 17:14:07 +00:00 (Migrated from github.com)

Implemented and published in signed commit 8fdf5e8d96ee0c85fe75063698db32e2695e283f (GitHub signature verification: valid).

Validation:

  • exact source-built output: /gnu/store/0dhwbk2x06wjzaskqrkfy0sdz276vha2-mushkin-0.5.1
  • upstream CTest: 1,279/1,279 passed
  • guix build -L . --no-grafts --check mushkin: passed with no nondeterminism report
  • full user/network-namespace Xvfb smoke: two independent loopback MUD sessions, Lua world.Version() = 0.5.1, MSP traversal rejection, immutable store output, and installed LuaSocket/LuaSec loopback TLS
  • no-network Guix lint: no Mushkin diagnostics
  • staged Gitleaks scan: no leaks

The package uses the recursive YueScript pin, an offline/system-GTest build, XDG-scoped mutable state, bundled read-only Lua runtime with notices, the MSP cache-path hardening patch, and desktop/icon integration.


Imported from GitHub comment. Originally posted by htayj on 2026-08-22T17:14:07Z.

Implemented and published in signed commit `8fdf5e8d96ee0c85fe75063698db32e2695e283f` (GitHub signature verification: valid). Validation: - exact source-built output: `/gnu/store/0dhwbk2x06wjzaskqrkfy0sdz276vha2-mushkin-0.5.1` - upstream CTest: 1,279/1,279 passed - `guix build -L . --no-grafts --check mushkin`: passed with no nondeterminism report - full user/network-namespace Xvfb smoke: two independent loopback MUD sessions, Lua `world.Version()` = 0.5.1, MSP traversal rejection, immutable store output, and installed LuaSocket/LuaSec loopback TLS - no-network Guix lint: no Mushkin diagnostics - staged Gitleaks scan: no leaks The package uses the recursive YueScript pin, an offline/system-GTest build, XDG-scoped mutable state, bundled read-only Lua runtime with notices, the MSP cache-path hardening patch, and desktop/icon integration. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/246#issuecomment-5381618524). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T17:14:07Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#246
No description provided.