[Guix packaging] NLarn #457

Closed
opened 2026-08-24 17:32:13 +00:00 by htayj · 2 comments
htayj commented 2026-08-24 17:32:13 +00:00 (Migrated from github.com)

Candidate

  • Project: NLarn
  • Candidate upstream/homepage: https://nlarn.github.io/
  • Discovery evidence: RogueBasin
  • Reported license: GPL
  • License status: reported free license; verify exact terms and asset coverage against the pinned upstream source

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:32:13Z.

## Candidate - Project: NLarn - Candidate upstream/homepage: https://nlarn.github.io/ - Discovery evidence: [RogueBasin](https://www.roguebasin.com/index.php/Category:Open_source) - Reported license: GPL - License status: reported free license; verify exact terms and asset coverage against the pinned upstream source ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/457). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:32:13Z.
htayj commented 2026-09-11 15:25:34 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #710.

Canonical maintained source: https://github.com/nlarn/nlarn, release tag NLarn-0.8.0 at immutable commit 1873599a5682e4645e2801f7de6bd11ce54c2dfd; the GitHub tag archive fetched for this brief has SHA-256 8f671fcbcec9d662648707fce4318ae3b2c7c68535c85848b55f8af346dfe735. NLarn is an independently playable C/ncurses rewrite of Larn, not the parent game or a local channel duplicate; no equivalent nlarn package or index entry exists in the inspected channel. Upstream LICENSE, source headers, Makefile, and nlarn.spec identify the project and shipped game data as GPLv3. The Unix build path does not use the declared PDCurses submodule or bundled Fira Mono font; do not enable SDLPDCURSES. The installed closure should be audited as project GPLv3 code/data plus the explicitly marked bundled cJSON MIT code and enumFactory.h CC-BY-SA Stack Overflow adaptation, with LICENSE and matching third-party notices installed. Curses runtime data required by the Makefile/spec are lib/fortune*, lib/maze, lib/nlarn.hlp*, lib/nlarn.msg*, and generated locale catalogs; no sounds or tiles are consumed by this path. Use gnu-build-system with release configuration and inputs gcc-toolchain/make, pkg-config, glib, ncurses (wide curses and panel), zlib, and gettext/msgfmt; link math as upstream does. Remove or justify upstream -Werror only if the authorized Guix build exposes a warning. Package as tay/packages/nlarn.scm, patch the named /usr/share/nlarn default_lib_dir in src/nlarn.c to $out/share/nlarn (or keep the real binary beside a sibling lib directory), and keep all mutable state outside the store; do not enable upstream SETGID system-scoreboard behavior. Upstream runtime uses HOME/.nlarn for config/save data and a highscores file; focused source inspection found no updater, telemetry, runtime download, or network code. The deterministic runtime contract is nlarn --highscores, which exercises the normal Hall of Fame path and exits with stdout marker NLarn Hall of Fame; a fresh HOME makes the missing highscores read-only. Acceptance plan: run lint/build/check offline with no submodules and no opaque binaries; install all notices; in a fresh HOME/XDG directory, use bounded-validation PTY input to select New Game, enter a fixed character name/gender, make a movement, press Ctrl-S to save and exit, relaunch to continue the save, then quit, asserting the save/config files are only in the isolated user directory and there are no store writes; separately run the declared deterministic contract and capture .goocastle/evidence/issue-457.png. The research sandbox had no Guix daemon per phase boundary, so no package build, lint, runtime, or reproducibility proof is claimed here; those are authorized later-phase acceptance gates.


Imported from GitHub comment. Originally posted by htayj on 2026-09-11T15:25:34Z.

<!-- goocastle-disposition:sequential-reviewer:457:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #710. Canonical maintained source: https://github.com/nlarn/nlarn, release tag NLarn-0.8.0 at immutable commit 1873599a5682e4645e2801f7de6bd11ce54c2dfd; the GitHub tag archive fetched for this brief has SHA-256 8f671fcbcec9d662648707fce4318ae3b2c7c68535c85848b55f8af346dfe735. NLarn is an independently playable C/ncurses rewrite of Larn, not the parent game or a local channel duplicate; no equivalent `nlarn` package or index entry exists in the inspected channel. Upstream LICENSE, source headers, Makefile, and nlarn.spec identify the project and shipped game data as GPLv3. The Unix build path does not use the declared PDCurses submodule or bundled Fira Mono font; do not enable SDLPDCURSES. The installed closure should be audited as project GPLv3 code/data plus the explicitly marked bundled cJSON MIT code and enumFactory.h CC-BY-SA Stack Overflow adaptation, with LICENSE and matching third-party notices installed. Curses runtime data required by the Makefile/spec are lib/fortune*, lib/maze, lib/nlarn.hlp*, lib/nlarn.msg*, and generated locale catalogs; no sounds or tiles are consumed by this path. Use gnu-build-system with release configuration and inputs gcc-toolchain/make, pkg-config, glib, ncurses (wide curses and panel), zlib, and gettext/msgfmt; link math as upstream does. Remove or justify upstream -Werror only if the authorized Guix build exposes a warning. Package as `tay/packages/nlarn.scm`, patch the named `/usr/share/nlarn` default_lib_dir in src/nlarn.c to `$out/share/nlarn` (or keep the real binary beside a sibling lib directory), and keep all mutable state outside the store; do not enable upstream SETGID system-scoreboard behavior. Upstream runtime uses HOME/.nlarn for config/save data and a highscores file; focused source inspection found no updater, telemetry, runtime download, or network code. The deterministic runtime contract is `nlarn --highscores`, which exercises the normal Hall of Fame path and exits with stdout marker `NLarn Hall of Fame`; a fresh HOME makes the missing highscores read-only. Acceptance plan: run lint/build/check offline with no submodules and no opaque binaries; install all notices; in a fresh HOME/XDG directory, use bounded-validation PTY input to select New Game, enter a fixed character name/gender, make a movement, press Ctrl-S to save and exit, relaunch to continue the save, then quit, asserting the save/config files are only in the isolated user directory and there are no store writes; separately run the declared deterministic contract and capture `.goocastle/evidence/issue-457.png`. The research sandbox had no Guix daemon per phase boundary, so no package build, lint, runtime, or reproducibility proof is claimed here; those are authorized later-phase acceptance gates. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/457#issuecomment-5636722615). Originally posted by [htayj](https://github.com/htayj) on 2026-09-11T15:25:34Z.
Owner

Published signed/authenticated af8b55a57d with fresh OMP-only NLarn0.8.0 proof. Existing native recipe/source unchanged; local daemon build,--check reproducibility, offline lint and integrated make check-source-count check-nlarn passed. Standalone proof removes Goocastle/Node/bounded-validation dependency and obsolete710marker contract. Real100x30PTY creates strong maleOmpProof STR20DEX15CON16INT12WIS12 HP21/21 MP17/17; actual equipped leather+1/dagger+0; moves Town(52,13)T1->(52,12)T2, nativegzipJSONsave/exit, secondprocess restores exactHUD/position/stats/XP/inventory/equipment thenmoves(53,12)T3 andresaves. NAR1l4v2sannym0gwcpp8f3r83i70vfqb8vd8rv5q4f4ychpjqajr9d unchanged underreadonlystore/networkisolation. Finalreceipt /tmp/nlarn-smoke-GzZPx0/proof/receipt.json; actualcontinuedframe inspected .goocastle/evidence/issue-457.png. Accurate terminal decoding adds ncursesCSI REP; player distinguished from townNPC shared@ by actualWHEATstyle, notrandomseedretry. GPL3-only,cJSONMIT,enumFactoryCCBYSA3 notices retained. No upstreamsuiteclaimed, no userprofiledeployment; unrelatedFourkwarning remains.

Published signed/authenticated af8b55a57ddbc4abc28c069ed02c45335f27dcab with fresh OMP-only NLarn0.8.0 proof. Existing native recipe/source unchanged; local daemon build,--check reproducibility, offline lint and integrated make check-source-count check-nlarn passed. Standalone proof removes Goocastle/Node/bounded-validation dependency and obsolete710marker contract. Real100x30PTY creates strong maleOmpProof STR20DEX15CON16INT12WIS12 HP21/21 MP17/17; actual equipped leather+1/dagger+0; moves Town(52,13)T1->(52,12)T2, nativegzipJSONsave/exit, secondprocess restores exactHUD/position/stats/XP/inventory/equipment thenmoves(53,12)T3 andresaves. NAR1l4v2sannym0gwcpp8f3r83i70vfqb8vd8rv5q4f4ychpjqajr9d unchanged underreadonlystore/networkisolation. Finalreceipt /tmp/nlarn-smoke-GzZPx0/proof/receipt.json; actualcontinuedframe inspected .goocastle/evidence/issue-457.png. Accurate terminal decoding adds ncursesCSI REP; player distinguished from townNPC shared@ by actualWHEATstyle, notrandomseedretry. GPL3-only,cJSONMIT,enumFactoryCCBYSA3 notices retained. No upstreamsuiteclaimed, no userprofiledeployment; unrelatedFourkwarning remains.
tay closed this issue 2026-10-02 16:01:45 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#457
No description provided.