[Guix packaging] Vapors of Insanity #578

Open
opened 2026-08-24 17:35:08 +00:00 by htayj · 1 comment
htayj commented 2026-08-24 17:35:08 +00:00 (Migrated from github.com)

Candidate

  • Project: Vapors of Insanity
  • Candidate upstream/homepage: http://www.roguetemple.com/z/vapors/
  • Discovery evidence: IRLDb
  • Reported license: GNU GPL v2
  • License status: reported free license; verify exact terms and asset coverage against the pinned upstream source
  • Catalog note: IRLDb status: beta.

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:35:08Z.

## Candidate - Project: Vapors of Insanity - Candidate upstream/homepage: http://www.roguetemple.com/z/vapors/ - Discovery evidence: [IRLDb](https://forums.roguetemple.com/irldb/index.php?i=47e013c) - Reported license: GNU GPL v2 - License status: reported free license; verify exact terms and asset coverage against the pinned upstream source - Catalog note: IRLDb status: beta. ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/578). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:35:08Z.
Owner

Goocastle recorded disposition: blocked.

Blocked by missing redistribution evidence for the custom shipped assets and by the absence of a specified meaningful isolated runtime proof. Authoritative upstream download page https://www.roguetemple.com/z/vapors/download.php fixes the latest normal release as Vapors of Insanity 0.56n (seventh preview, 2012-06-26), origin http://www.roguetemple.com/z/vapors/vapors-056n.zip with SHA-256 c0b79f5a0c8f6204f15a3d3dd49b011d01957660a4d7dd9b4cd246a0e2a44936; the dev release is 0.56d (2012-06-27), origin http://www.roguetemple.com/z/vapors/vapors-056d.zip with SHA-256 cd2db360cafab684bc0bd91d0f6fe0d42ecb61ea37dfd82be60e483362d41bfb. The normal archive contains vapors/COPYING (GPL-2.0-only text) and C++ engine source under vapors/src, while its Makefile declares direct builds for curses/SDL from gcc/g++, ncurses, zlib, SDL, optional SDL_mixer, plus the GSL compiler in the dev distribution. However, the upstream page states that the normal release omits VaporGS sources for most game logic, and the normal archive instead ships opaque compiled .gsl files alongside opaque .voi fonts/tiles, .bmp images, help and config data. The dev archive supplies .gsc/.gsi VaporGS sources but no license notice specific to those sources or to the custom assets. A parent GPL-2.0-only engine notice does not establish redistribution or modification rights for those independently opaque origins, so a complete Guix source-only closure cannot be safely established. There is no equivalent Vapors of Insanity package in the local guix tree. Runtime inspection found only interactive options -r RECORD, -v RECORD, and -c CONFIG in player.cpp:2516-2522; startup then opens a recording, initializes video, and enters mainMenu, with no noninteractive application mode or safe deterministic argv contract evidenced by source 0.56n. This research environment also has no Guix daemon and lacks bsdtar, but this blocker is upstream provenance/runtime evidence rather than a local toolchain result. Unblocking requires, at the same fixed origin/revision, explicit written upstream permission or independently licensed replacements covering every installed .voi, .bmp, .gsl, help/config, and documentation artifact, plus a maintained Unix build adaptation and a demonstrable safe deterministic smoke invocation that exercises meaningful local game state without runtime downloads or store writes.

<!-- goocastle-disposition:sequential-reviewer:578:1:blocked --> Goocastle recorded disposition: blocked. Blocked by missing redistribution evidence for the custom shipped assets and by the absence of a specified meaningful isolated runtime proof. Authoritative upstream download page https://www.roguetemple.com/z/vapors/download.php fixes the latest normal release as Vapors of Insanity 0.56n (seventh preview, 2012-06-26), origin http://www.roguetemple.com/z/vapors/vapors-056n.zip with SHA-256 c0b79f5a0c8f6204f15a3d3dd49b011d01957660a4d7dd9b4cd246a0e2a44936; the dev release is 0.56d (2012-06-27), origin http://www.roguetemple.com/z/vapors/vapors-056d.zip with SHA-256 cd2db360cafab684bc0bd91d0f6fe0d42ecb61ea37dfd82be60e483362d41bfb. The normal archive contains vapors/COPYING (GPL-2.0-only text) and C++ engine source under vapors/src, while its Makefile declares direct builds for curses/SDL from gcc/g++, ncurses, zlib, SDL, optional SDL_mixer, plus the GSL compiler in the dev distribution. However, the upstream page states that the normal release omits VaporGS sources for most game logic, and the normal archive instead ships opaque compiled .gsl files alongside opaque .voi fonts/tiles, .bmp images, help and config data. The dev archive supplies .gsc/.gsi VaporGS sources but no license notice specific to those sources or to the custom assets. A parent GPL-2.0-only engine notice does not establish redistribution or modification rights for those independently opaque origins, so a complete Guix source-only closure cannot be safely established. There is no equivalent Vapors of Insanity package in the local guix tree. Runtime inspection found only interactive options -r RECORD, -v RECORD, and -c CONFIG in player.cpp:2516-2522; startup then opens a recording, initializes video, and enters mainMenu, with no noninteractive application mode or safe deterministic argv contract evidenced by source 0.56n. This research environment also has no Guix daemon and lacks bsdtar, but this blocker is upstream provenance/runtime evidence rather than a local toolchain result. Unblocking requires, at the same fixed origin/revision, explicit written upstream permission or independently licensed replacements covering every installed .voi, .bmp, .gsl, help/config, and documentation artifact, plus a maintained Unix build adaptation and a demonstrable safe deterministic smoke invocation that exercises meaningful local game state without runtime downloads or store writes.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#578
No description provided.