[Guix packaging] Grippy Socks #383

Open
opened 2026-08-24 17:30:27 +00:00 by htayj · 1 comment
htayj commented 2026-08-24 17:30:27 +00:00 (Migrated from github.com)

Candidate

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:30:27Z.

## Candidate - Project: Grippy Socks - Candidate upstream/homepage: http://www.astrolog.org/labyrnth/daedalus/gripsox.htm - Discovery evidence: [IRLDb](https://forums.roguetemple.com/irldb/index.php?i=47e013c) - Reported license: [[GPL]]v2 - License status: reported free license; verify exact terms and asset coverage against the pinned upstream source - Catalog note: IRLDb status: stable. ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/383). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:30:27Z.
htayj commented 2026-09-05 05:38:39 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #689.

Canonical upstream is the author mirror https://github.com/CruiserOne/Daedalus at tag v3.5, fixed commit 32af46ddf22e53c9bfd7bd7eacca1e249c60a5e8 (tag resolves to that commit); official source archive https://www.astrolog.org/labyrnth/daedalus/dae35zip.zip has SHA-256 19ec305be102c8425d8a0d16475ba1ba9b7b04e3bd58c341525b808d81f364b0. The official Daedalus 3.5 documentation identifies GRIPSOX.DS as the Grippy Socks script, dates 3.5 to 2024-10-31, and says the distribution includes complete C++ source and a Unix Makefile; the Makefile builds with g++ and -lm, while util.h documents the command-line Unix mode obtained by disabling WIN. The source headers and retained license.htm identify Walter D. Pullen and GPL-2.0-or-later; all shipped Grippy Socks content is from this one fixed upstream origin. The script has no external file references or separately fetched dependencies: its map/bitmap content is embedded in gripsox.ds, and the package should install only that script, the rebuilt engine, and upstream license/author documentation, with no fonts, tiles, sounds, submodules, language registries, updater, telemetry, runtime download, or network path. There is no same-project package in the local channel or audit files. tay/packages/dragonslayer.scm is a distinct Daedalus-script package with issue #681 runtime contract/evidence; it shares the engine but installs dragon.ds, so grippy-socks is a separately justified variant, not a duplicate. Deliver tay/packages/grippy-socks.scm with gnu-build-system/git-fetch at the fixed commit (the existing Daedalus precedent records the matching Git checkout hash base32 0fdzx2zzqbd3p99yljksmbh0s3mbzzmq2dq42a9yz5rfkn9gjy2r), no configure phase, and native gcc-toolchain plus bash-minimal/coreutils-minimal for the wrapper. Apply the proven Unix patches: disable WIN and PC, use unsigned int for the bitmap dword on LP64, and add the Linux-sized-delete compatibility definition; build with upstream make daedalus. Install the engine privately under libexec and a package-owned grippy-socks launcher that uses a state directory only for ordinary interactive play, never writes the store, and supports exactly --smoke. That mode must load the installed gripsox.ds and perform a deterministic normal movement/interaction through the command-line engine before printing the declared marker. Research could not run Guix because the host explicitly provides no daemon; this is an authoritative metadata assessment, not package proof. Delivery acceptance: preflight package load/parser, guix lint -L . grippy-socks with no package-specific findings, offline guix build -L . --no-grafts --no-substitutes grippy-socks, upstream has no test target so run the bounded wrapper smoke, then guix build -L . --no-grafts --no-substitutes --check grippy-socks. The isolated proof must use fresh HOME/XDG directories, empty PATH and proxy-disabled network, bounded-validation with util-linux unshare --user --map-root-user --net --fork, assert stdout GRIPPY_SOCKS_SMOKE_OK plus a visible Grippy Socks start/gameplay line, verify no files appear in HOME/XDG/work, compare the output NAR hash before/after, and assert the installed tree is non-writable; capture the screenshot at .goocastle/evidence/issue-383.png. Retain license.htm and the upstream author notices in share/doc/grippy-socks.


Imported from GitHub comment. Originally posted by htayj on 2026-09-05T05:38:39Z.

<!-- goocastle-disposition:sequential-reviewer:383:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #689. Canonical upstream is the author mirror https://github.com/CruiserOne/Daedalus at tag v3.5, fixed commit 32af46ddf22e53c9bfd7bd7eacca1e249c60a5e8 (tag resolves to that commit); official source archive https://www.astrolog.org/labyrnth/daedalus/dae35zip.zip has SHA-256 19ec305be102c8425d8a0d16475ba1ba9b7b04e3bd58c341525b808d81f364b0. The official Daedalus 3.5 documentation identifies GRIPSOX.DS as the Grippy Socks script, dates 3.5 to 2024-10-31, and says the distribution includes complete C++ source and a Unix Makefile; the Makefile builds with g++ and -lm, while util.h documents the command-line Unix mode obtained by disabling WIN. The source headers and retained license.htm identify Walter D. Pullen and GPL-2.0-or-later; all shipped Grippy Socks content is from this one fixed upstream origin. The script has no external file references or separately fetched dependencies: its map/bitmap content is embedded in gripsox.ds, and the package should install only that script, the rebuilt engine, and upstream license/author documentation, with no fonts, tiles, sounds, submodules, language registries, updater, telemetry, runtime download, or network path. There is no same-project package in the local channel or audit files. tay/packages/dragonslayer.scm is a distinct Daedalus-script package with issue #681 runtime contract/evidence; it shares the engine but installs dragon.ds, so grippy-socks is a separately justified variant, not a duplicate. Deliver tay/packages/grippy-socks.scm with gnu-build-system/git-fetch at the fixed commit (the existing Daedalus precedent records the matching Git checkout hash base32 0fdzx2zzqbd3p99yljksmbh0s3mbzzmq2dq42a9yz5rfkn9gjy2r), no configure phase, and native gcc-toolchain plus bash-minimal/coreutils-minimal for the wrapper. Apply the proven Unix patches: disable WIN and PC, use unsigned int for the bitmap dword on LP64, and add the Linux-sized-delete compatibility definition; build with upstream make daedalus. Install the engine privately under libexec and a package-owned grippy-socks launcher that uses a state directory only for ordinary interactive play, never writes the store, and supports exactly --smoke. That mode must load the installed gripsox.ds and perform a deterministic normal movement/interaction through the command-line engine before printing the declared marker. Research could not run Guix because the host explicitly provides no daemon; this is an authoritative metadata assessment, not package proof. Delivery acceptance: preflight package load/parser, guix lint -L . grippy-socks with no package-specific findings, offline guix build -L . --no-grafts --no-substitutes grippy-socks, upstream has no test target so run the bounded wrapper smoke, then guix build -L . --no-grafts --no-substitutes --check grippy-socks. The isolated proof must use fresh HOME/XDG directories, empty PATH and proxy-disabled network, bounded-validation with util-linux unshare --user --map-root-user --net --fork, assert stdout GRIPPY_SOCKS_SMOKE_OK plus a visible Grippy Socks start/gameplay line, verify no files appear in HOME/XDG/work, compare the output NAR hash before/after, and assert the installed tree is non-writable; capture the screenshot at .goocastle/evidence/issue-383.png. Retain license.htm and the upstream author notices in share/doc/grippy-socks. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/383#issuecomment-5549725437). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T05:38:39Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#383
No description provided.