[Guix packaging] Diabaig #329

Closed
opened 2026-08-24 17:29:07 +00:00 by htayj · 2 comments
htayj commented 2026-08-24 17:29:07 +00:00 (Migrated from github.com)

Candidate

  • Project: Diabaig
  • Candidate upstream/homepage: https://conornally.itch.io/diabaig
  • Discovery evidence: IRLDb
  • Reported license: Open source MIT
  • License status: reported free license; verify exact terms and asset coverage against the pinned upstream source
  • Catalog note: IRLDb status: stable.

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:29:07Z.

## Candidate - Project: Diabaig - Candidate upstream/homepage: https://conornally.itch.io/diabaig - Discovery evidence: [IRLDb](https://forums.roguetemple.com/irldb/index.php?i=47e013c) - Reported license: Open source [[MIT]] - License status: reported free license; verify exact terms and asset coverage against the pinned upstream source - Catalog note: IRLDb status: stable. ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/329). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:29:07Z.
htayj commented 2026-09-02 19:49:22 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #674.

Canonical maintained upstream is https://github.com/conornally/diabaig. The latest stable upstream tag is diabaig-v1.0.1 at immutable commit b90d35847070d3de27d4656b3316e0e932884b25; VERSION.txt is 1.0.1, and the tag and main point to that commit. The fixed git checkout has SHA-256 Guix/Nix-base32 hash 1pw0c63bvn8yda694489547d8vw1bfddnacc04456i278rv45qdp. The author’s itch release/devlog at https://conornally.itch.io/diabaig and https://conornally.itch.io/diabaig/devlog/1045742/diabaig-v101-autoexplore-and-bug-fixes identifies v1.0.1 as released and supplies platform binaries, but this package must use the public source repository. At the fixed revision, LICENSE is the sole license file and states MIT License, copyright 2025 conornally; the git tree has no .gitmodules, submodules, language registries, vendored dependencies, or separately fetched origins. The source contains C code and embedded text resources, with no runtime fonts, tiles, sounds, maps, or bundled third-party code. Do not install the optional docs/images marketing artwork unless its coverage is separately confirmed; install the upstream LICENSE alongside docs/README.md, docs/guide.txt, res/credits.txt, and the Debian man page if those documents are shipped. This supports license:expat for the upstream origin and leaves no independent origin whose license must be audited. The Makefile has no configure, check, or test target; it builds on Linux with make, gcc, xxd-generated build/data_embedded.h, and -lncurses -lm. A read-only make -n all CC=gcc PLATFORM=linux completed and showed the full C compile/link plan. Use module (tay packages diabaig), package name diabaig, guix gnu-build-system with git-fetch at the fixed commit/hash, gcc-toolchain and xxd as native inputs, and ncurses as the runtime input; bash-minimal/coreutils-minimal plus a small Python PTY helper are appropriate package-owned wrapper inputs. The source build has no network or registry phase and must not use the itch prebuilt binaries. Exact official and local-channel queries for package name diabaig returned no equivalent; the local channel also has no Diabaig match, so this is not a duplicate. The research host has no Guix daemon and the trusted boundary forbids guix shell/build/lint here; the dry-run and authoritative metadata are feasibility evidence only, not package proof. Static inspection found no updater, telemetry, socket, download, or runtime network behavior. Upstream writes mutable files relative to its working directory: .diabaigrc, save/diabaig.save.N and save/diabaig.autosave, and diabaig.scr; verbose mode also hardcodes /tmp/diabaig.log. The launcher should keep the real binary private under libexec, set TERMINFO_DIRS to the declared ncurses input, run with cwd ${XDG_STATE_HOME:-$HOME/.local/state}/diabaig, avoid -v by default, and forward normal arguments, so state never targets the store. Add a package-owned --smoke mode with no extra arguments. It must use a fixed PTY of at least 78x33 and TERM=xterm-256color, run the real binary as diabaig -t -s 329, select New Game, enter a fixed player name and the default class, perform a legal movement plus inventory display, save to slot 1 with S/Enter/y, assert save/diabaig.save.1 and return to the home menu, select Continue then slot 1, assert the loaded message and inventory, quit with Q/y, leave the home menu with q, and assert cleanup of the autosave. Run this in fresh HOME/XDG config/data/cache/state/runtime and TMPDIR trees, capture a meaningful dungeon frame as .goocastle/evidence/issue-329.png, compare the package output/store metadata before and after to prove no store writes, and assert the single stdout line DIABAIG_RUNTIME_OK. Execute the final PTY/runtime validation only through the host bounded-validation argv executor. The source provides no automated upstream tests, so the isolated save/load flow is the meaningful acceptance smoke; later authorized Guix phases must perform lint, offline build, no-grafts check, and reproducibility verification.


Imported from GitHub comment. Originally posted by htayj on 2026-09-02T19:49:22Z.

<!-- goocastle-disposition:sequential-reviewer:329:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #674. Canonical maintained upstream is https://github.com/conornally/diabaig. The latest stable upstream tag is diabaig-v1.0.1 at immutable commit b90d35847070d3de27d4656b3316e0e932884b25; VERSION.txt is 1.0.1, and the tag and main point to that commit. The fixed git checkout has SHA-256 Guix/Nix-base32 hash 1pw0c63bvn8yda694489547d8vw1bfddnacc04456i278rv45qdp. The author’s itch release/devlog at https://conornally.itch.io/diabaig and https://conornally.itch.io/diabaig/devlog/1045742/diabaig-v101-autoexplore-and-bug-fixes identifies v1.0.1 as released and supplies platform binaries, but this package must use the public source repository. At the fixed revision, LICENSE is the sole license file and states MIT License, copyright 2025 conornally; the git tree has no .gitmodules, submodules, language registries, vendored dependencies, or separately fetched origins. The source contains C code and embedded text resources, with no runtime fonts, tiles, sounds, maps, or bundled third-party code. Do not install the optional docs/images marketing artwork unless its coverage is separately confirmed; install the upstream LICENSE alongside docs/README.md, docs/guide.txt, res/credits.txt, and the Debian man page if those documents are shipped. This supports license:expat for the upstream origin and leaves no independent origin whose license must be audited. The Makefile has no configure, check, or test target; it builds on Linux with make, gcc, xxd-generated build/data_embedded.h, and -lncurses -lm. A read-only make -n all CC=gcc PLATFORM=linux completed and showed the full C compile/link plan. Use module (tay packages diabaig), package name diabaig, guix gnu-build-system with git-fetch at the fixed commit/hash, gcc-toolchain and xxd as native inputs, and ncurses as the runtime input; bash-minimal/coreutils-minimal plus a small Python PTY helper are appropriate package-owned wrapper inputs. The source build has no network or registry phase and must not use the itch prebuilt binaries. Exact official and local-channel queries for package name diabaig returned no equivalent; the local channel also has no Diabaig match, so this is not a duplicate. The research host has no Guix daemon and the trusted boundary forbids guix shell/build/lint here; the dry-run and authoritative metadata are feasibility evidence only, not package proof. Static inspection found no updater, telemetry, socket, download, or runtime network behavior. Upstream writes mutable files relative to its working directory: .diabaigrc, save/diabaig.save.N and save/diabaig.autosave, and diabaig.scr; verbose mode also hardcodes /tmp/diabaig.log. The launcher should keep the real binary private under libexec, set TERMINFO_DIRS to the declared ncurses input, run with cwd ${XDG_STATE_HOME:-$HOME/.local/state}/diabaig, avoid -v by default, and forward normal arguments, so state never targets the store. Add a package-owned --smoke mode with no extra arguments. It must use a fixed PTY of at least 78x33 and TERM=xterm-256color, run the real binary as diabaig -t -s 329, select New Game, enter a fixed player name and the default class, perform a legal movement plus inventory display, save to slot 1 with S/Enter/y, assert save/diabaig.save.1 and return to the home menu, select Continue then slot 1, assert the loaded message and inventory, quit with Q/y, leave the home menu with q, and assert cleanup of the autosave. Run this in fresh HOME/XDG config/data/cache/state/runtime and TMPDIR trees, capture a meaningful dungeon frame as .goocastle/evidence/issue-329.png, compare the package output/store metadata before and after to prove no store writes, and assert the single stdout line DIABAIG_RUNTIME_OK. Execute the final PTY/runtime validation only through the host bounded-validation argv executor. The source provides no automated upstream tests, so the isolated save/load flow is the meaningful acceptance smoke; later authorized Guix phases must perform lint, offline build, no-grafts check, and reproducibility verification. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/329#issuecomment-5515420853). Originally posted by [htayj](https://github.com/htayj) on 2026-09-02T19:49:22Z.
Owner

The source package was delivered through #674; its remaining gameplay-evidence defect is now fixed and independently verified in #675, signed/authenticated commit 3281b08243b434b4e71814534959e34ef47de75d. See #675 comment 2677 for the complete build, reproducibility, offline lint, network-isolated new-game/movement/inventory/save/load/quit and immutable-store proof, plus the actual 80×34 dungeon screenshot. Installed MIT notices and package layout were checked by the smoke. Closing this research parent on the same verified delivery, not on source-snapshot presence.

The source package was delivered through #674; its remaining gameplay-evidence defect is now fixed and independently verified in #675, signed/authenticated commit `3281b08243b434b4e71814534959e34ef47de75d`. See #675 comment 2677 for the complete build, reproducibility, offline lint, network-isolated new-game/movement/inventory/save/load/quit and immutable-store proof, plus the actual 80×34 dungeon screenshot. Installed MIT notices and package layout were checked by the smoke. Closing this research parent on the same verified delivery, not on source-snapshot presence.
tay closed this issue 2026-09-29 21:59:23 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#329
No description provided.