[Guix packaging] Zerogue #597

Open
opened 2026-08-24 17:35:35 +00:00 by htayj · 1 comment
htayj commented 2026-08-24 17:35:35 +00:00 (Migrated from github.com)

Candidate

  • Project: Zerogue
  • Candidate upstream/homepage: http://sourceforge.net/projects/zerogue/
  • Discovery evidence: IRLDb
  • Reported license: GPL
  • License status: reported free license; verify exact terms and asset coverage against the pinned upstream source
  • Catalog note: IRLDb status: beta.

Scope

Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary.

Research checklist

  • Identify the canonical maintained source repository and immutable release/commit.
  • Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency.
  • Check GNU Guix and the channel audit set for an equivalent same-upstream package.
  • Determine the offline build system and source closure, including submodules or language registries.
  • Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration.

Acceptance checks

  • guix lint -L . <package> has no package-specific findings.
  • guix build -L . --no-grafts <package> succeeds without network access or opaque binaries.
  • Upstream tests run where available, and guix build -L . --no-grafts --check <package> verifies reproducibility.
  • A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes.
  • Installed license and third-party notices cover the shipped closure and assets.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-24T17:35:35Z.

## Candidate - Project: Zerogue - Candidate upstream/homepage: http://sourceforge.net/projects/zerogue/ - Discovery evidence: [IRLDb](https://forums.roguetemple.com/irldb/index.php?i=47e013c) - Reported license: GPL - License status: reported free license; verify exact terms and asset coverage against the pinned upstream source - Catalog note: IRLDb status: beta. ## Scope Package the independently playable roguelike from source. The canonical repository, latest stable release, source hash, complete dependency closure, and relationship to parent games or sibling forks must be established before implementation. Do not substitute an opaque prebuilt binary. ## Research checklist - Identify the canonical maintained source repository and immutable release/commit. - Verify the exact FOSS license for code and every installed font, tile, sound, map, documentation, and bundled dependency. - Check GNU Guix and the channel audit set for an equivalent same-upstream package. - Determine the offline build system and source closure, including submodules or language registries. - Identify updater, telemetry, runtime download, mutable-state, and network behavior that needs Guix integration. ## Acceptance checks - `guix lint -L . <package>` has no package-specific findings. - `guix build -L . --no-grafts <package>` succeeds without network access or opaque binaries. - Upstream tests run where available, and `guix build -L . --no-grafts --check <package>` verifies reproducibility. - A fresh HOME/XDG smoke test starts a real local game, exercises meaningful gameplay or save/load behavior, and proves no store writes. - Installed license and third-party notices cover the shipped closure and assets. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/597). Originally posted by [htayj](https://github.com/htayj) on 2026-08-24T17:35:35Z.
Owner

Goocastle recorded disposition: blocked.

Zerogue 0.4.6 at https://github.com/zerobandwidth-net/zerogue, fixed commit 101215a4c0939dbfbf15cad48fad79d0477be944, is not a safe Guix package outcome. The repository contains a top-level GPL-2.0-only text, but 23 of its 54 fixed C source/header files carry per-file notices permitting modification and distribution only with three restrictions, including that the code is 'not to be traded, sold, or used for personal gain or profit'. That noncommercial clause conflicts with GPL section 9 and gives no clear redistribution grant sufficient for Guix. Files appraise.c through zap.h include these 23 restricted files while the remaining 31 lack any source notice, so authorship and licensing for the latter are also unclear at this revision; there are no submodules or bundled assets, only a documentation file. The canonical origin is this active GitHub repository and the latest release commit is dated 2019-12-23; the newer SourceForge files are opaque 2011 prebuilt i586 zips and cannot substitute. The source closure is technically viable in principle: 54 self-contained C/header files, a Makefile building executable rogue with GCC and -lncurses, and no runtime downloads, telemetry, updater, submodules, or language registries. However, upstream offers no noninteractive, safe deterministic gameplay or save/load runtime contract. Every initialization path enters curses; -s enters put_scores, opens ./.roguescores read-write and can create it, then calls md_exit(0) without emitting a useful success marker. The legacy setuid score-file flow is also incompatible with the unprivileged Guix store binary and fresh-HOME no-store-write proof. Concrete blockers are therefore the contradictory/unclear fixed-revision licensing and the absence of a suitable headless runtime contract. Unblocking requires upstream written relicensing or authoritative explicit permission resolving all fixed-revision source notices under a packageable FOSS license with copyright attribution records, plus a package wrapper or upstream change providing a deterministic noninteractive gameplay or save/load proof with single-line stdout and no store writes. The local channel has no Zerogue package; no Guix daemon was available, so no build was claimed.

<!-- goocastle-disposition:sequential-reviewer:597:1:blocked --> Goocastle recorded disposition: blocked. Zerogue 0.4.6 at https://github.com/zerobandwidth-net/zerogue, fixed commit 101215a4c0939dbfbf15cad48fad79d0477be944, is not a safe Guix package outcome. The repository contains a top-level GPL-2.0-only text, but 23 of its 54 fixed C source/header files carry per-file notices permitting modification and distribution only with three restrictions, including that the code is 'not to be traded, sold, or used for personal gain or profit'. That noncommercial clause conflicts with GPL section 9 and gives no clear redistribution grant sufficient for Guix. Files appraise.c through zap.h include these 23 restricted files while the remaining 31 lack any source notice, so authorship and licensing for the latter are also unclear at this revision; there are no submodules or bundled assets, only a documentation file. The canonical origin is this active GitHub repository and the latest release commit is dated 2019-12-23; the newer SourceForge files are opaque 2011 prebuilt i586 zips and cannot substitute. The source closure is technically viable in principle: 54 self-contained C/header files, a Makefile building executable `rogue` with GCC and `-lncurses`, and no runtime downloads, telemetry, updater, submodules, or language registries. However, upstream offers no noninteractive, safe deterministic gameplay or save/load runtime contract. Every initialization path enters curses; `-s` enters `put_scores`, opens `./.roguescores` read-write and can create it, then calls `md_exit(0)` without emitting a useful success marker. The legacy setuid score-file flow is also incompatible with the unprivileged Guix store binary and fresh-HOME no-store-write proof. Concrete blockers are therefore the contradictory/unclear fixed-revision licensing and the absence of a suitable headless runtime contract. Unblocking requires upstream written relicensing or authoritative explicit permission resolving all fixed-revision source notices under a packageable FOSS license with copyright attribution records, plus a package wrapper or upstream change providing a deterministic noninteractive gameplay or save/load proof with single-line stdout and no store writes. The local channel has no Zerogue package; no Guix daemon was available, so no build was claimed.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#597
No description provided.