[Guix packaging] N0NJY/mushtato #251

Closed
opened 2026-08-22 05:13:26 +00:00 by htayj · 1 comment
htayj commented 2026-08-22 05:13:26 +00:00 (Migrated from github.com)

Candidate

User-facing deliverable

Cross-platform Python MUSH client inspired by Potato and TinyFugue, with sandboxed Python scripting.

Packaging approach

Package with pyproject-build-system, recursively add missing Python dependencies, install desktop integration, and test fresh-profile writes outside the store.

Known blockers and investigation points

Audit the third-party inventory and verify the GUI/toolkit, SSH, TLS, and sandbox dependencies available in Guix.

Acceptance checks

  • Pin an immutable upstream release or commit and record a real Guix source hash.
  • Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build.
  • Preserve all applicable project and bundled-component license notices.
  • Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it.
  • Keep profiles, logs, maps, plugins, and other mutable state outside the store.

Existing-package coverage

Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct.


Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-22T05:13:26Z.

## Candidate - Canonical upstream: [https://github.com/N0NJY/mushtato](https://github.com/N0NJY/mushtato) - Packaging target: v1.9.3 (2026-07-30) - Category: MUD client - Tags: mud-client, desktop, Python, MUSH, scripting, TLS, SSH - Primary language/build ecosystem: Python, pyproject - License: MIT with a third-party license inventory - License evidence: https://github.com/N0NJY/mushtato/blob/main/LICENSE - Expected Guix packaging difficulty: moderate ## User-facing deliverable Cross-platform Python MUSH client inspired by Potato and TinyFugue, with sandboxed Python scripting. ## Packaging approach Package with pyproject-build-system, recursively add missing Python dependencies, install desktop integration, and test fresh-profile writes outside the store. ## Known blockers and investigation points Audit the third-party inventory and verify the GUI/toolkit, SSH, TLS, and sandbox dependencies available in Guix. ## Acceptance checks - Pin an immutable upstream release or commit and record a real Guix source hash. - Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build. - Preserve all applicable project and bundled-component license notices. - Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it. - Keep profiles, logs, maps, plugins, and other mutable state outside the store. ## Existing-package coverage Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/251). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T05:13:26Z.
htayj commented 2026-08-22 09:46:39 +00:00 (Migrated from github.com)

Implemented and published in signed commit 0e1b2a61984bd6c196bf9d780d32859bac230e1d.

Evidence:

  • Packages annotated tag v1.9.3 at commit 3fc327a07efff7b421c24022f017b3837add3dec, NAR hash 11hs8k41mfc3a25qhs6vig3g3np6g7lmymbzfvjbfz2al2s661ai (MIT/Expat).
  • Adds hash-pinned RestrictedPython 8.5 and google-re2 1.1.20251105, using Guix re2-next/Abseil and the Guix PySide6, AsyncSSH, and platformdirs graph. Applicable Qt and dependency notices are installed.
  • Real output: /gnu/store/ym90z4s41psgxvb72pgy4f3ipz41ikg5-mushtato-1.9.3.
  • Reproducibility build passed all 258 engine tests, covering loopback TLS, SOCKS4, SSH and TLS key/certificate changes, Telnet, RE2 bounds, and sandbox cases.
  • Smoke proves real first-run settings persistence from empty XDG state, then runs Xvfb GUI and fake MUD inside a user-mapped loopback-only network namespace. It contacts no public MUD.
  • Focused no-network lint and independent review passed.

Imported from GitHub comment. Originally posted by htayj on 2026-08-22T09:46:39Z.

Implemented and published in signed commit `0e1b2a61984bd6c196bf9d780d32859bac230e1d`. Evidence: - Packages annotated tag v1.9.3 at commit `3fc327a07efff7b421c24022f017b3837add3dec`, NAR hash `11hs8k41mfc3a25qhs6vig3g3np6g7lmymbzfvjbfz2al2s661ai` (MIT/Expat). - Adds hash-pinned RestrictedPython 8.5 and google-re2 1.1.20251105, using Guix `re2-next`/Abseil and the Guix PySide6, AsyncSSH, and platformdirs graph. Applicable Qt and dependency notices are installed. - Real output: `/gnu/store/ym90z4s41psgxvb72pgy4f3ipz41ikg5-mushtato-1.9.3`. - Reproducibility build passed all 258 engine tests, covering loopback TLS, SOCKS4, SSH and TLS key/certificate changes, Telnet, RE2 bounds, and sandbox cases. - Smoke proves real first-run settings persistence from empty XDG state, then runs Xvfb GUI and fake MUD inside a user-mapped loopback-only network namespace. It contacts no public MUD. - Focused no-network lint and independent review passed. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/251#issuecomment-5379615777). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T09:46:39Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#251
No description provided.