[Guix packaging] fuzzball-muck/trebuchet #256

Closed
opened 2026-08-22 05:13:31 +00:00 by htayj · 1 comment
htayj commented 2026-08-22 05:13:31 +00:00 (Migrated from github.com)

Candidate

User-facing deliverable

Tcl/Tk graphical MUD/MUCK/MUSH chat client with MCP and GUI support.

Packaging approach

Package a pinned commit with copy/gnu-build-system, wrap Tcl/Tk dependencies, and relocate scripts/resources without embedding build paths.

Known blockers and investigation points

Old release and minimal tests; confirm modern Tcl/Tk compatibility and writable configuration behavior.

Acceptance checks

  • Pin an immutable upstream release or commit and record a real Guix source hash.
  • Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build.
  • Preserve all applicable project and bundled-component license notices.
  • Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it.
  • Keep profiles, logs, maps, plugins, and other mutable state outside the store.

Existing-package coverage

Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct.


Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-22T05:13:31Z.

## Candidate - Canonical upstream: [https://github.com/fuzzball-muck/trebuchet](https://github.com/fuzzball-muck/trebuchet) - Packaging target: current master; last release v1081 (2016) - Category: MUD client - Tags: mud-client, desktop, Tcl, Tk, MUSH, MUCK, MCP - Primary language/build ecosystem: Tcl/Tk with Makefile installation - License: GPL-2.0-only - License evidence: https://github.com/fuzzball-muck/trebuchet/blob/master/LICENSE - Expected Guix packaging difficulty: moderate ## User-facing deliverable Tcl/Tk graphical MUD/MUCK/MUSH chat client with MCP and GUI support. ## Packaging approach Package a pinned commit with copy/gnu-build-system, wrap Tcl/Tk dependencies, and relocate scripts/resources without embedding build paths. ## Known blockers and investigation points Old release and minimal tests; confirm modern Tcl/Tk compatibility and writable configuration behavior. ## Acceptance checks - Pin an immutable upstream release or commit and record a real Guix source hash. - Build without network access using Guix-provided dependencies; do not download runtimes or plugins during the build. - Preserve all applicable project and bundled-component license notices. - Verify the installed launcher/version output and run an offline protocol smoke test against a local fake MUD endpoint where the platform permits it. - Keep profiles, logs, maps, plugins, and other mutable state outside the store. ## Existing-package coverage Checked on 2026-08-22 against GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix R Us, and RDE, plus all states of this repository issue tracker. No same-upstream package or existing ticket was found. GNU Guix already packages TinTin++ and POWWOW; this candidate is distinct. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/256). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T05:13:31Z.
htayj commented 2026-08-22 08:44:13 +00:00 (Migrated from github.com)

Implemented and published in signed commit 181351aae9e89c3c637ad2ba16388738160edc14.

Evidence:

  • Pins upstream commit 1418ab604d870c154887adf2b0b6c8ec91457abe as Trebuchet 1082 with NAR hash 138d5p4pmhgdnmgzn2fsmwvnj5a1sv8a32z6z4kdlqg4cy3x12n6.
  • Correct license metadata is mixed GPL-2.0-or-later, LGPL-2.0-or-later, and public-domain; applicable embedded notices are preserved.
  • Two-round no-substitute build passed. Output: /gnu/store/b8x0b0a249k7qvh23gb733z02531dlwf-trebuchet-1082.
  • Hardened upstream TLS behavior to use current package-owned CA trust, reject all certificate-verification failures, and disconnect on STARTTLS failure instead of downgrading to plaintext.
  • Remote control is bound only to loopback.
  • Fresh-HOME Xvfb/loopback smokes verify Tcl/Tk protocol behavior, wrong-certificate rejection before credentials, and no plaintext fallback after failed STARTTLS. They contact no public MUD.
  • Focused no-network lint and repeated independent security review passed.

Imported from GitHub comment. Originally posted by htayj on 2026-08-22T08:44:13Z.

Implemented and published in signed commit `181351aae9e89c3c637ad2ba16388738160edc14`. Evidence: - Pins upstream commit `1418ab604d870c154887adf2b0b6c8ec91457abe` as Trebuchet 1082 with NAR hash `138d5p4pmhgdnmgzn2fsmwvnj5a1sv8a32z6z4kdlqg4cy3x12n6`. - Correct license metadata is mixed GPL-2.0-or-later, LGPL-2.0-or-later, and public-domain; applicable embedded notices are preserved. - Two-round no-substitute build passed. Output: `/gnu/store/b8x0b0a249k7qvh23gb733z02531dlwf-trebuchet-1082`. - Hardened upstream TLS behavior to use current package-owned CA trust, reject all certificate-verification failures, and disconnect on STARTTLS failure instead of downgrading to plaintext. - Remote control is bound only to loopback. - Fresh-HOME Xvfb/loopback smokes verify Tcl/Tk protocol behavior, wrong-certificate rejection before credentials, and no plaintext fallback after failed STARTTLS. They contact no public MUD. - Focused no-network lint and repeated independent security review passed. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/256#issuecomment-5379382192). Originally posted by [htayj](https://github.com/htayj) on 2026-08-22T08:44:13Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#256
No description provided.