[Guix packaging] drbeefsupreme/tassh #38
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#38
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Candidate
672569a55e6f2a0ae4274103a99b8b9abac87f4d(default-branch snapshot checked 2026-08-14)Scope and blockers
Package the user CLI/daemon; keep service integration and optional X11/Wayland clipboard support explicit.
Acceptance checks
guix lint -L. <package-name>andguix build -L. <package-name>pass once a package definition exists.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T11:43:29Z.
Goocastle recorded disposition: implementation-ready.
Created implementation ticket: #603.
Canonical upstream is https://github.com/drbeefsupreme/tassh at fixed merge commit 672569a55e6f2a0ae4274103a99b8b9abac87f4d (2026-02-28; upstream Cargo version 0.1.0); use Guix version 20260228-1.672569a and the already recorded git-fetch base32 hash 1r14hx37jz04cvjljc8vy063qy10sy8lmlaxsn2ckmxafl6qhw7y. The pinned checkout contains the tassh CLI/daemon in src/, Cargo.toml, Cargo.lock, and an explicit LICENSE whose text is the standard MIT License for drbeefsupreme, so the application license is license:expat and source redistribution is legally clear; retain LICENSE plus every locked crate license/copyright/notice file in share/doc/tassh/third-party-licenses because the Rust closure is statically linked. Cargo.lock has 182 package records including tassh and 181 external registry records, all source = registry+https://github.com/rust-lang/crates.io-index, with no git or bundled dependency; guix import crate --lockfile=/tmp/tassh-research.SKUcHb/Cargo.lock tassh successfully enumerates immutable crate sources, so source-build is bounded and offline-vendorable with current Guix Rust 1.93.0. No equivalent installed CLI/daemon exists: the local channel’s tay/packages/drbeefsupreme/tassh.scm and PROJECTS.md:92 provide only drbeefsupreme-tassh-source, a copy-build-system source snapshot, not an executable package. Add the installable tassh package in the existing (tay packages drbeefsupreme tassh) module, keeping that source snapshot separate, with cargo-build-system, #:install-source? #f, release build/test/install using --offline --locked --no-track, and phases that save Cargo.lock before cargo-build-system configure deletes it, generate vendor checksums, restore the lockfile with registry checksum lines removed for directory sources, and restore it before both test and cargo install. Define crate-source inputs for all 181 lockfile records, including target-only crates and duplicate name/version lines such as cpufeatures 0.2.17/0.3.0, hashbrown 0.15.5/0.16.1, and windows-sys 0.60.2/0.61.2; direct inputs are anyhow 1, arboard 3 with wayland-data-control, async-pidfd 0.1.5, clap 4 derive/env, image 0.25 PNG-only, libc 0.2, rand 0.10, serde derive, serde_json, sha2, socket2, thiserror, tokio full, tracing, and tracing-subscriber env-filter. Add pkg-config as a native input and wayland as a build/link input for wayland-sys; restrict the package to Linux (at least x86_64-linux) because daemon mode always starts Xvfb and async-pidfd is Linux-oriented. Runtime behavior is part of the package contract: wrap tassh with PATH prefixes for xorg-server/bin (Xvfb), xclip/bin, wl-clipboard/bin, which/bin, procps/bin (pgrep), and inetutils/bin (hostname), and add wayland/lib to LD_LIBRARY_PATH if the linked wayland-client library is not already resolved by the executable; append rather than replace the user PATH so externally installed tailscale, ssh, systemctl, and loginctl remain discoverable. Tailscale is not packaged in the current Guix channel, and upstream runs tailscale ip -4 to bind the daemon, so document a configured user-provided tailscale executable as a hard runtime prerequisite rather than silently claiming a turnkey tailnet. OpenSSH is likewise an integration prerequisite: setup writes Host * / PermitLocalCommand yes / LocalCommand tassh notify --host %h --port %p --ssh-pid $PPID, while notify intentionally exits zero after a short timeout so it cannot break an SSH login. Upstream setup.rs currently assumes the cargo-install path $HOME/.cargo/bin/tassh and invokes systemctl --user plus loginctl; the implementation must patch binary_path to use the running packaged executable/current_exe (or the absolute store output path) and must document setup daemon as systemd-only, user-home-mutating convenience, not as a Guix service; preserve host PATH for those commands and do not run setup in the build. The daemon writes only mutable user state under $HOME/.tassh (daemon.sock and display), always launches Xvfb for the remote paste display, uses xclip for Xvfb/X11 writes, and uses wl-paste only when the original local session has WAYLAND_DISPLAY; make those X11 and Wayland paths explicit in the synopsis/description. Acceptance after implementation is guix lint -L. tassh and guix build -L. tassh, followed by an isolated no-external-network smoke: use two temporary HOME directories and distinct loopback ports, provide a fake PATH-first tailscale script returning 127.0.0.1, launch one tassh daemon per HOME, start a live sleep helper as the synthetic SSH PID, run tassh notify --host 127.0.0.1 --ssh-pid , assert both status commands report one syncing session, inject a known PNG with tassh inject --png-file, compare the destination xclip image/png SHA-256 with the source, kill the helper, and assert the peer disappears while each daemon remains one process. Exercise X11 separately by running a Guix Xvfb :99 and feeding the source clipboard through xclip; exercise Wayland separately with a temporary XDG_RUNTIME_DIR and Guix Weston headless compositor plus wl-copy/wl-paste, setting WAYLAND_DISPLAY only for the source watcher and verifying the destination Xvfb clipboard hash. Also run tassh --help, the subcommand help paths, and the upstream loopback transport tests; this plan proves CLI, daemon IPC, framed PNG delivery, lifecycle cleanup, X11, and Wayland behavior without a public tailnet, while any full two-node Tailscale/SSH run remains an optional integration check rather than a package-build prerequisite.
Imported from GitHub comment. Originally posted by htayj on 2026-08-25T11:55:48Z.