[Guix packaging] Xenocide #588

Open
opened 2026-08-24 17:35:22 +00:00 by htayj · 1 comment
htayj commented 2026-08-24 17:35:22 +00:00 (Migrated from github.com)

Candidate

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:35:22Z.

## Candidate - Project: Xenocide - Candidate upstream/homepage: https://github.com/rsaarelm/xenocide - Discovery evidence: [RogueBasin](https://www.roguebasin.com/index.php/Category:Open_source) - Reported license: NOASSERTION - License status: needs authoritative upstream verification before packaging ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/588). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:35:22Z.
Owner

Goocastle recorded disposition: blocked.

Blocked by missing authoritative license/build prerequisites. The issue candidate https://github.com/rsaarelm/xenocide returns HTTP 404 for both exact-cased variants, GitHub reports no Xenocide repository among rsaarelm's first 94 repositories, and a GitHub repository-name search returns no matching canonical maintained source. RogueBasin revision 37608 identifies http://xeno.chaosforge.org/ as the official site. That page advertises the latest stable release as 2007.03.28 and its source archive as http://xeno.chaosforge.org/files/xeno-src-2007-03-28.zip. The retrieved archive is 269586 bytes with SHA-256 a96cd74cf67a4937bf4ca9a0f2016c39dc707e297af3c9f0e928b18858e108da and contains 61 entries. It has no README, COPYING, LICENSE, or other license declaration. Its Xenocide.vcproj is a Win32 Visual C++ application linking bundled binary pdcurses.lib and FMOD 3.75 fmodvc.lib; there is no Makefile or other declared offline build system for Guix targets. Embedded FMOD headers identify Firelight Technologies but provide no redistribution grant, and no authoritative grant is available for the Xenocide source itself. Unblocking requires written upstream authorization/FOSS licensing for the complete source closure and a source-only build strategy with non-opaque dependencies (for example replacement of the bundled libraries and a maintained portable build), plus a deterministic meaningful runtime contract. The environment also lacked bsdtar, so the ZIP was inspected with the reviewed Python standard library; no Guix daemon-backed build was attempted because source legality and buildability already fail.

<!-- goocastle-disposition:sequential-reviewer:588:1:blocked --> Goocastle recorded disposition: blocked. Blocked by missing authoritative license/build prerequisites. The issue candidate https://github.com/rsaarelm/xenocide returns HTTP 404 for both exact-cased variants, GitHub reports no Xenocide repository among rsaarelm's first 94 repositories, and a GitHub repository-name search returns no matching canonical maintained source. RogueBasin revision 37608 identifies http://xeno.chaosforge.org/ as the official site. That page advertises the latest stable release as 2007.03.28 and its source archive as http://xeno.chaosforge.org/files/xeno-src-2007-03-28.zip. The retrieved archive is 269586 bytes with SHA-256 a96cd74cf67a4937bf4ca9a0f2016c39dc707e297af3c9f0e928b18858e108da and contains 61 entries. It has no README, COPYING, LICENSE, or other license declaration. Its Xenocide.vcproj is a Win32 Visual C++ application linking bundled binary pdcurses.lib and FMOD 3.75 fmodvc.lib; there is no Makefile or other declared offline build system for Guix targets. Embedded FMOD headers identify Firelight Technologies but provide no redistribution grant, and no authoritative grant is available for the Xenocide source itself. Unblocking requires written upstream authorization/FOSS licensing for the complete source closure and a source-only build strategy with non-opaque dependencies (for example replacement of the bundled libraries and a maintained portable build), plus a deterministic meaningful runtime contract. The environment also lacked bsdtar, so the ZIP was inspected with the reviewed Python standard library; no Guix daemon-backed build was attempted because source legality and buildability already fail.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#588
No description provided.