[Guix packaging] htayj/flaghack #3

Open
opened 2026-08-14 10:45:34 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 10:45:34 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/htayj/flaghack
  • Source pinned commit/release when known: 772c47e77c952eaa96c627079683768533c0ce93 (default-branch snapshot checked 2026-08-14)
  • Target concrete installed deliverable: Flaghack server and Charm terminal client
  • Primary category: terminal-application
  • Tags: terminal-ui
  • Primary language normalized: Mixed
  • Build system: pnpm workspace plus Go modules
  • SPDX expression: AGPL-3.0-only
  • License status: declared-free
  • License evidence: GitHub repository metadata declares AGPL-3.0-only; the upstream license text still needs package-review confirmation.
  • Difficulty: hard — The pnpm and Go dependency closures must be made fully offline and the multi-process lifecycle tested.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package both the TypeScript Effect server and Go terminal client without network access.

Acceptance checks

  • guix lint -L. <package-name> and guix build -L. <package-name> pass once a package definition exists.
  • Start server and connect the terminal client to a local loopback endpoint.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T10:45:34Z.

## Candidate - Upstream canonical URL: https://github.com/htayj/flaghack - Source pinned commit/release when known: `772c47e77c952eaa96c627079683768533c0ce93` (default-branch snapshot checked 2026-08-14) - Target concrete installed deliverable: Flaghack server and Charm terminal client - Primary category: terminal-application - Tags: terminal-ui - Primary language normalized: Mixed - Build system: pnpm workspace plus Go modules - SPDX expression: AGPL-3.0-only - License status: declared-free - License evidence: GitHub repository metadata declares AGPL-3.0-only; the upstream license text still needs package-review confirmation. - Difficulty: hard — The pnpm and Go dependency closures must be made fully offline and the multi-process lifecycle tested. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package both the TypeScript Effect server and Go terminal client without network access. ## Acceptance checks - `guix lint -L. <package-name>` and `guix build -L. <package-name>` pass once a package definition exists. - Start server and connect the terminal client to a local loopback endpoint. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/3). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T10:45:34Z.
htayj commented 2026-08-25 11:35:55 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #602.

Canonical source and fixed identity: package https://github.com/htayj/flaghack at version 20260713-1.772c47e, commit 772c47e77c952eaa96c627079683768533c0ce93; the local channel already provides this exact source as htayj-flaghack-source, but only as a source snapshot. No release tag was found, so retain the date plus abbreviated commit version. Legal/source-build assessment: the pinned checkout contains a complete AGPLv3 LICENSE at the root and identical LICENSE files in packages/cli, packages/domain, and packages/server; root, cli, domain, and server manifests all declare AGPL-3.0-or-later. The issue snapshot's AGPL-3.0-only value is therefore not the canonical metadata; use license:agpl3+ and install the upstream notice. No non-free assets were found in the application tree. Third-party Node and Go inputs must retain their own LICENSE/NOTICE files in collision-safe documentation paths; the channel's existing Guix metadata covers the Charmbracelet/Go closure with free ASL-2.0, Expat, BSD, and similar licenses, subject to normal per-input review. The source is technically buildable: a temporary checkout installed the frozen pnpm graph with pnpm 9.10.0 and --ignore-scripts, and the upstream API smoke passed on an isolated bot port, including JSON API reads, client-state SSE content/revision, mutation-header behavior, and save/restore/quit lifecycle; this is research evidence only, not Guix package proof. A direct esbuild 0.25.5 server bundle passed node syntax checking but failed at runtime in undici 7.10.0 with a dynamic require of node:assert, so do not use an unqualified bundle as the delivery path. Package module and concrete outputs: add tay/packages/flaghack.scm, with primary package flaghack and a private or exported flaghack-charm helper. Install /bin/flaghack-server for the TypeScript Effect server and /bin/flaghack for the compiled Go Charm client; optionally expose the helper as /bin/flaghack-charm only if it does not create a duplicate user-facing contract. Build the server from packages/domain/src and packages/server/src with the root tsconfig.base.json path aliases, retaining the minimal source tree, package manifests, and a private node_modules tree under share/flaghack; run it with node --import tsx packages/server/src/server.ts rather than the fragile upstream build-utils/codegen/publish path. The server's exact direct runtime graph is @effect/platform 0.85.2, @effect/platform-node 0.86.4, effect 3.16.8, immutable 4.3.7, and the @flaghack/domain workspace source; the filtered production graph resolved 53 package identities in research, while the complete pnpm-lock.yaml has 646 integrity-pinned registry archives. Guix 1.5 has no pnpm, Effect, or Immutable package suitable for this closure, so provide a fixed pnpm 9.10.0 executable as a native build input, enumerate the lock-resolved npm registry tarballs with Guix hashes, populate a build-local pnpm store from those inputs, and run pnpm install --offline --frozen-lockfile --ignore-scripts with the server/domain production filter. Retain tsx 4.20.3 as an explicit runtime input for the source launcher together with its lock-resolved esbuild 0.25.5, get-tsconfig 4.10.1, and the target-platform @esbuild binary; no Corepack download or npm lifecycle script may run in the build. Preserve the runtime dependency notices after pruning build/test-only packages. The Go helper should use go-build-system with go-1.24 because packages/cli/charm/go.mod declares go 1.24.0, import path flaghack/charm, and unpack path flaghack/charm; build and test ./... with GO111MODULE=off and only Guix inputs. Its exact direct modules are github.com/charmbracelet/bubbletea v1.3.10, github.com/charmbracelet/lipgloss v1.1.0, and github.com/charmbracelet/x/ansi v0.10.1; the go.sum closure additionally names go-osc52/v2 2.0.1, colorprofile 0.2.3-0.20250311203215-f60798e515dc, x/cellbuf 0.0.13, x/term 0.2.1, erikgeiser/coninput 20211004153227-1c3628e74d0f, go-colorful 1.2.0, mattn/go-isatty 0.0.20, go-localereader 0.0.1, go-runewidth 0.0.16, muesli/ansi 0.0.0-20230316100256-276c6243b2f6, muesli/cancelreader 0.2.2, muesli/termenv 0.16.0, rivo/uniseg 0.4.7, xo/terminfo 20220910002029-abceb7e1c41e, golang.org/x/sys 0.36.0, and golang.org/x/text 0.3.8. Reuse exact existing channel inputs where possible; define exact source snapshots for mismatches such as x/ansi 0.10.1 versus the channel's 0.10.2 and the older indirect versions, and never let Go fetch modules. Wrapper/runtime requirements: flaghack-server must exec the installed Node entrypoint so SIGINT, SIGTERM, and SIGUSR2 reach the upstream autosave/shutdown handlers; preserve FLAGHACK_PORT then PORT precedence, FLAGHACK_SAVE_PATH, XDG_STATE_HOME, and HOME, with the upstream default port 3000 and save path semantics. flaghack must preserve FLAGHACK_API_URL, whose upstream default is http://127.0.0.1:3000, and remain a terminal-attached Bubble Tea process; it must not silently start a server. Equivalent coverage: local PROJECTS.md and tay/packages/projects.scm show only htayj-flaghack-source, and guix search flaghack returned no installable equivalent in the available Guix set; unrelated MUD clients and Charm libraries are not the same upstream deliverable. Isolated smoke proof to add as an after-install check: create a temporary HOME/XDG_STATE_HOME and FLAGHACK_SAVE_PATH plus a free loopback port, start flaghack-server, poll /client-state until HTTP 200 and assert a nonempty roles/world JSON, open /client-state/stream with Accept text/event-stream and assert the content type plus an initial event: client-state revision, then launch flaghack in a disposable tmux 120x40 session with FLAGHACK_API_URL set to that port, wait for the Charm UI, send v, y, Enter, and j, capture the pane and assert the Flag Hack Charmbracelet UI/player board remains live after the action. Send SIGTERM to the server, wait for clean exit, assert the isolated save file was written, and kill the tmux session; all requests must target 127.0.0.1 and all build inputs must already be present offline. Once implemented, the precise acceptance commands are guix lint -L. flaghack and guix build -L. flaghack; do not treat the research smoke or this disposition as package proof.


Imported from GitHub comment. Originally posted by htayj on 2026-08-25T11:35:55Z.

<!-- goocastle-disposition:sequential-reviewer:3:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #602. Canonical source and fixed identity: package https://github.com/htayj/flaghack at version 20260713-1.772c47e, commit 772c47e77c952eaa96c627079683768533c0ce93; the local channel already provides this exact source as htayj-flaghack-source, but only as a source snapshot. No release tag was found, so retain the date plus abbreviated commit version. Legal/source-build assessment: the pinned checkout contains a complete AGPLv3 LICENSE at the root and identical LICENSE files in packages/cli, packages/domain, and packages/server; root, cli, domain, and server manifests all declare AGPL-3.0-or-later. The issue snapshot's AGPL-3.0-only value is therefore not the canonical metadata; use license:agpl3+ and install the upstream notice. No non-free assets were found in the application tree. Third-party Node and Go inputs must retain their own LICENSE/NOTICE files in collision-safe documentation paths; the channel's existing Guix metadata covers the Charmbracelet/Go closure with free ASL-2.0, Expat, BSD, and similar licenses, subject to normal per-input review. The source is technically buildable: a temporary checkout installed the frozen pnpm graph with pnpm 9.10.0 and --ignore-scripts, and the upstream API smoke passed on an isolated bot port, including JSON API reads, client-state SSE content/revision, mutation-header behavior, and save/restore/quit lifecycle; this is research evidence only, not Guix package proof. A direct esbuild 0.25.5 server bundle passed node syntax checking but failed at runtime in undici 7.10.0 with a dynamic require of node:assert, so do not use an unqualified bundle as the delivery path. Package module and concrete outputs: add tay/packages/flaghack.scm, with primary package flaghack and a private or exported flaghack-charm helper. Install /bin/flaghack-server for the TypeScript Effect server and /bin/flaghack for the compiled Go Charm client; optionally expose the helper as /bin/flaghack-charm only if it does not create a duplicate user-facing contract. Build the server from packages/domain/src and packages/server/src with the root tsconfig.base.json path aliases, retaining the minimal source tree, package manifests, and a private node_modules tree under share/flaghack; run it with node --import tsx packages/server/src/server.ts rather than the fragile upstream build-utils/codegen/publish path. The server's exact direct runtime graph is @effect/platform 0.85.2, @effect/platform-node 0.86.4, effect 3.16.8, immutable 4.3.7, and the @flaghack/domain workspace source; the filtered production graph resolved 53 package identities in research, while the complete pnpm-lock.yaml has 646 integrity-pinned registry archives. Guix 1.5 has no pnpm, Effect, or Immutable package suitable for this closure, so provide a fixed pnpm 9.10.0 executable as a native build input, enumerate the lock-resolved npm registry tarballs with Guix hashes, populate a build-local pnpm store from those inputs, and run pnpm install --offline --frozen-lockfile --ignore-scripts with the server/domain production filter. Retain tsx 4.20.3 as an explicit runtime input for the source launcher together with its lock-resolved esbuild 0.25.5, get-tsconfig 4.10.1, and the target-platform @esbuild binary; no Corepack download or npm lifecycle script may run in the build. Preserve the runtime dependency notices after pruning build/test-only packages. The Go helper should use go-build-system with go-1.24 because packages/cli/charm/go.mod declares go 1.24.0, import path flaghack/charm, and unpack path flaghack/charm; build and test ./... with GO111MODULE=off and only Guix inputs. Its exact direct modules are github.com/charmbracelet/bubbletea v1.3.10, github.com/charmbracelet/lipgloss v1.1.0, and github.com/charmbracelet/x/ansi v0.10.1; the go.sum closure additionally names go-osc52/v2 2.0.1, colorprofile 0.2.3-0.20250311203215-f60798e515dc, x/cellbuf 0.0.13, x/term 0.2.1, erikgeiser/coninput 20211004153227-1c3628e74d0f, go-colorful 1.2.0, mattn/go-isatty 0.0.20, go-localereader 0.0.1, go-runewidth 0.0.16, muesli/ansi 0.0.0-20230316100256-276c6243b2f6, muesli/cancelreader 0.2.2, muesli/termenv 0.16.0, rivo/uniseg 0.4.7, xo/terminfo 20220910002029-abceb7e1c41e, golang.org/x/sys 0.36.0, and golang.org/x/text 0.3.8. Reuse exact existing channel inputs where possible; define exact source snapshots for mismatches such as x/ansi 0.10.1 versus the channel's 0.10.2 and the older indirect versions, and never let Go fetch modules. Wrapper/runtime requirements: flaghack-server must exec the installed Node entrypoint so SIGINT, SIGTERM, and SIGUSR2 reach the upstream autosave/shutdown handlers; preserve FLAGHACK_PORT then PORT precedence, FLAGHACK_SAVE_PATH, XDG_STATE_HOME, and HOME, with the upstream default port 3000 and save path semantics. flaghack must preserve FLAGHACK_API_URL, whose upstream default is http://127.0.0.1:3000, and remain a terminal-attached Bubble Tea process; it must not silently start a server. Equivalent coverage: local PROJECTS.md and tay/packages/projects.scm show only htayj-flaghack-source, and guix search flaghack returned no installable equivalent in the available Guix set; unrelated MUD clients and Charm libraries are not the same upstream deliverable. Isolated smoke proof to add as an after-install check: create a temporary HOME/XDG_STATE_HOME and FLAGHACK_SAVE_PATH plus a free loopback port, start flaghack-server, poll /client-state until HTTP 200 and assert a nonempty roles/world JSON, open /client-state/stream with Accept text/event-stream and assert the content type plus an initial event: client-state revision, then launch flaghack in a disposable tmux 120x40 session with FLAGHACK_API_URL set to that port, wait for the Charm UI, send v, y, Enter, and j, capture the pane and assert the Flag Hack Charmbracelet UI/player board remains live after the action. Send SIGTERM to the server, wait for clean exit, assert the isolated save file was written, and kill the tmux session; all requests must target 127.0.0.1 and all build inputs must already be present offline. Once implemented, the precise acceptance commands are guix lint -L. flaghack and guix build -L. flaghack; do not treat the research smoke or this disposition as package proof. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/3#issuecomment-5409783613). Originally posted by [htayj](https://github.com/htayj) on 2026-08-25T11:35:55Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#3
No description provided.