[Guix packaging] bozimmerman/Sip #250

Closed
opened 2026-08-22 05:13:25 +00:00 by htayj · 2 comments
htayj commented 2026-08-22 05:13:25 +00:00 (Migrated from github.com)

Candidate

User-facing deliverable

Cross-platform Electron desktop MUD client supporting modern MUD protocols.

Packaging approach

First provide or reuse a source-built Electron package compatible with the pinned app, then package the npm graph offline and wrap the installed Electron entry point.

Known blockers and investigation points

The audited Guix has no desktop Electron runtime; upstream has no test suite and electron-builder must not download binaries during the build.

Acceptance checks

  • Pin an immutable upstream release or commit and record a real Guix source hash.
  • Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build.
  • Preserve all applicable project and bundled-component license notices.
  • Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it.
  • Keep profiles, logs, maps, plugins, and other mutable state outside the store.

Existing-package coverage

Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct.


Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-22T05:13:25Z.

## Candidate - Canonical upstream: [https://github.com/bozimmerman/Sip](https://github.com/bozimmerman/Sip) - Packaging target: v3.3.4 (2026-01-14) - Category: MUD client - Tags: mud-client, desktop, Electron, JavaScript, MXP, GMCP, MSP - Primary language/build ecosystem: JavaScript, npm, Electron - License: Apache-2.0 declared in package.json - License evidence: https://github.com/bozimmerman/Sip/blob/master/package.json - Expected Guix packaging difficulty: hard ## User-facing deliverable Cross-platform Electron desktop MUD client supporting modern MUD protocols. ## Packaging approach First provide or reuse a source-built Electron package compatible with the pinned app, then package the npm graph offline and wrap the installed Electron entry point. ## Known blockers and investigation points The audited Guix has no desktop Electron runtime; upstream has no test suite and electron-builder must not download binaries during the build. ## Acceptance checks - Pin an immutable upstream release or commit and record a real Guix source hash. - Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build. - Preserve all applicable project and bundled-component license notices. - Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it. - Keep profiles, logs, maps, plugins, and other mutable state outside the store. ## Existing-package coverage Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/250). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T05:13:25Z.
htayj commented 2026-08-22 12:55:54 +00:00 (Migrated from github.com)

Feasibility research is complete and this issue is blocked.

Primary blocker: Sip v3.3.4 is a real Electron application requiring Node builtins and @electron/remote. The authenticated Guix revision has Node and Chromium but no Electron runtime, and upstream electron-builder/npm workflows download prebuilt Electron/AppImage tooling. The 92 MB deb/AppImage must not be repackaged. Reopen only when an audited source-built Electron compatible with Electron 36.9.5 is available without build-time downloads.

Additional blockers:

  • Pin v3.3.4 commit 1ccc622d28cb84bc16505fcf11ee6dd18ac9269b, NAR hash 1sbgl8pi24ld126canggfhxcjalfcxyw4xhhc1igc8ddxq92rvk4.
  • The tag has no lockfile. Current ranges resolve 322 packages; a future package should include only fixed production @electron/remote 2.1.3 plus channel Electron, never electron-builder.
  • The tag declares Apache-2.0 but omits the linked LICENSE. CodeMirror/pako notices and per-asset provenance are also missing. Keep needs:license-investigation until upstream supplies these or questionable assets are removed.
  • Security defaults are unsuitable for publication: Node integration is enabled, context isolation is off, every Chromium certificate error is accepted, MUD TLS uses rejectUnauthorized:false, security response headers are stripped, and an unsigned remote plugin catalog can deliver arbitrary plugin JSON/code. Credentials are documented as plaintext localStorage. TLS verification and a plugin trust/integrity policy need an explicit upstream or channel decision before packaging.
  • Upstream has no tests. All 23 JS sources pass syntax checking, but no Electron build was attempted.

Reopen gates: audited Electron runtime; fixed offline production closure; complete license/asset notices; and a resolved TLS/plugin remote-code policy. Acceptance must include wrong-certificate rejection, loopback plain and trusted TLS MUDs, ANSI/MCCP/MXP/GMCP/MSP/audio, plugin integrity, fresh XDG state, and no store writes or updater traffic.

No package was found in the same-day GNU Guix, Nonguix, Guix Science/HPC/Past/R Us/RDE audit.


Imported from GitHub comment. Originally posted by htayj on 2026-08-22T12:55:54Z.

Feasibility research is complete and this issue is blocked. Primary blocker: Sip v3.3.4 is a real Electron application requiring Node builtins and @electron/remote. The authenticated Guix revision has Node and Chromium but no Electron runtime, and upstream electron-builder/npm workflows download prebuilt Electron/AppImage tooling. The 92 MB deb/AppImage must not be repackaged. Reopen only when an audited source-built Electron compatible with Electron 36.9.5 is available without build-time downloads. Additional blockers: - Pin v3.3.4 commit 1ccc622d28cb84bc16505fcf11ee6dd18ac9269b, NAR hash 1sbgl8pi24ld126canggfhxcjalfcxyw4xhhc1igc8ddxq92rvk4. - The tag has no lockfile. Current ranges resolve 322 packages; a future package should include only fixed production @electron/remote 2.1.3 plus channel Electron, never electron-builder. - The tag declares Apache-2.0 but omits the linked LICENSE. CodeMirror/pako notices and per-asset provenance are also missing. Keep needs:license-investigation until upstream supplies these or questionable assets are removed. - Security defaults are unsuitable for publication: Node integration is enabled, context isolation is off, every Chromium certificate error is accepted, MUD TLS uses rejectUnauthorized:false, security response headers are stripped, and an unsigned remote plugin catalog can deliver arbitrary plugin JSON/code. Credentials are documented as plaintext localStorage. TLS verification and a plugin trust/integrity policy need an explicit upstream or channel decision before packaging. - Upstream has no tests. All 23 JS sources pass syntax checking, but no Electron build was attempted. Reopen gates: audited Electron runtime; fixed offline production closure; complete license/asset notices; and a resolved TLS/plugin remote-code policy. Acceptance must include wrong-certificate rejection, loopback plain and trusted TLS MUDs, ANSI/MCCP/MXP/GMCP/MSP/audio, plugin integrity, fresh XDG state, and no store writes or updater traffic. No package was found in the same-day GNU Guix, Nonguix, Guix Science/HPC/Past/R Us/RDE audit. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/250#issuecomment-5380526779). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T12:55:54Z.
htayj commented 2026-08-22 17:20:01 +00:00 (Migrated from github.com)

Rechecked upstream and current Guix channels. Nonguix now has Electron 36.9.5, but that package wraps the prebuilt Electron ZIP and is marked nonfree; it does not satisfy this ticket source-built Electron requirement. Sip v3.3.4 also remains unlocked, untested, license-incomplete, and dependent on unresolved TLS/plugin-code policy.

Closing as not planned. Reopen when a source-built compatible Electron exists, or a binary policy exception is explicitly approved, and the fixed offline production closure, notices, certificate verification, and plugin integrity requirements are resolved.


Imported from GitHub comment. Originally posted by htayj on 2026-08-22T17:20:01Z.

Rechecked upstream and current Guix channels. Nonguix now has Electron 36.9.5, but that package wraps the prebuilt Electron ZIP and is marked nonfree; it does not satisfy this ticket source-built Electron requirement. Sip v3.3.4 also remains unlocked, untested, license-incomplete, and dependent on unresolved TLS/plugin-code policy. Closing as not planned. Reopen when a source-built compatible Electron exists, or a binary policy exception is explicitly approved, and the fixed offline production closure, notices, certificate verification, and plugin integrity requirements are resolved. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/250#issuecomment-5381642947). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T17:20:01Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#250
No description provided.