Implement researched Guix package outcome for #40: [Guix packaging] DoctorWkt/Apout #604

Closed
opened 2026-08-25 12:14:02 +00:00 by htayj · 1 comment
htayj commented 2026-08-25 12:14:02 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #40 ([Guix packaging] DoctorWkt/Apout).

The host-validated research finding follows:

Canonical upstream is https://github.com/DoctorWkt/Apout at the fixed master commit bd9af21bd8bb2fa956dcda5db0b0aeec2cffc8f7 (the local source snapshot larsbrinkhoff-apout-source records Guix version 0-bd9af21, codeload hash 1w7xckknr3acdsf2d7vg4vib93m7kh65lr212gqwhr0db9nxn551; upstream identifies this tree as Apout 2.4.0). The pinned tree contains the complete host C emulator and Makefile target apout, has no configure step, generated assets, vendored dependency graph, or build-time downloads, and links only -lm against the normal target C/POSIX runtime, so it is source-buildable with gnu-build-system plus the standard target GCC/make/libc toolchain and no nonstandard inputs or guest OS image. Use a new module tay/packages/apout.scm importing (tay packages larsbrinkhoff-a-f), guix build-system gnu, guix gexp, guix build utils, and guix packages; define package apout from that exact source, delete configure, replace build with an explicit make apout phase using CC=$(cc-for-target), and disable the nonexistent upstream check target. Do not use upstream install, which hard-codes /usr/local: install apout to $out/bin, apout.1 to $out/share/man/man1, and README/CHANGES/LIMITATIONS/TODO/LICENSE/COPYRIGHT under $out/share/doc/apout-0-bd9af21. Apply one small Makefile patch changing the default preprocessor flag -DEMUv1 to -DEMUV1: the README, defines.h, aout.c, ke11a.c, and v1trap.c all use EMUV1, so the upstream spelling otherwise silently omits first/second-edition support. Pass deterministic APOUT_OPTIONS=-DEMU211 -DEMUV1 -DNATIVES -DAPOUT_DONT_ASSUME_ROOT in the make flags; the last supported upstream option makes invocation fail rather than defaulting absolute guest paths to the host /. No wrapper or guest filesystem belongs in the output. At runtime users must set APOUT_ROOT to a user-owned guest root; preserve optional APOUT_UNIX_VERSION for ambiguous 0407 a.out files. NATIVES and the trap code deliberately execute native programs and directly call host filesystem/process/socket APIs, so document that APOUT_ROOT is not a security sandbox and do not claim network isolation from the package itself. The upstream LICENSE is GPL version 3 only; COPYRIGHT records Warren Toomey and the Eric A. Edwards-derived PDP-11 simulator code, and bsd_signal.c preserves the Berkeley notice. Use Guix license:gpl3 and install both LICENSE and COPYRIGHT; no other bundled executable or asset needs a separate license review. Local inspection shows no apout executable package: larsbrinkhoff-apout-source is preservation-only, and the issue inventory found no same-origin equivalent in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, or RDE. Add tests/apout-smoke.sh as the meaningful proof: require a supplied, provenance- and redistribution-cleared historical PDP-11 a.out fixture (prefer a fixed V7 cal/echo fixture with an expected transcript; do not fetch or package an unlicensed TUHS binary or a guest image), obtain the apout output path with guix build -L. apout or accept it as the sole argument, and fail if the fixture is absent. Run the probe from a fresh temporary HOME, XDG_CONFIG_HOME, XDG_DATA_HOME, XDG_CACHE_HOME, current directory, and APOUT_ROOT, under unshare --user --map-root-user --net or the Guix no-network build sandbox with failure if an isolated namespace cannot be established. Set APOUT_UNIX_VERSION=V7 when applicable, invoke $out/bin/apout against the fixture with its fixed argument and assert exit status plus the exact expected historical-program output, verify unset APOUT_ROOT is rejected with the supported diagnostic, grep installed LICENSE/COPYRIGHT notices, and compare a pre/post manifest of the package output to prove the run wrote only into temporary state. After implementation, the precise acceptance commands are guix lint -L. apout and guix build -L. apout; this research disposition does not claim either package proof.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-25T12:14:02Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:40:1:implementation-ready --> ## Context This delivery ticket was created from research issue #40 ([Guix packaging] DoctorWkt/Apout). The host-validated research finding follows: Canonical upstream is https://github.com/DoctorWkt/Apout at the fixed master commit bd9af21bd8bb2fa956dcda5db0b0aeec2cffc8f7 (the local source snapshot larsbrinkhoff-apout-source records Guix version 0-bd9af21, codeload hash 1w7xckknr3acdsf2d7vg4vib93m7kh65lr212gqwhr0db9nxn551; upstream identifies this tree as Apout 2.4.0). The pinned tree contains the complete host C emulator and Makefile target apout, has no configure step, generated assets, vendored dependency graph, or build-time downloads, and links only -lm against the normal target C/POSIX runtime, so it is source-buildable with gnu-build-system plus the standard target GCC/make/libc toolchain and no nonstandard inputs or guest OS image. Use a new module tay/packages/apout.scm importing (tay packages larsbrinkhoff-a-f), guix build-system gnu, guix gexp, guix build utils, and guix packages; define package apout from that exact source, delete configure, replace build with an explicit make apout phase using CC=$(cc-for-target), and disable the nonexistent upstream check target. Do not use upstream install, which hard-codes /usr/local: install apout to $out/bin, apout.1 to $out/share/man/man1, and README/CHANGES/LIMITATIONS/TODO/LICENSE/COPYRIGHT under $out/share/doc/apout-0-bd9af21. Apply one small Makefile patch changing the default preprocessor flag -DEMUv1 to -DEMUV1: the README, defines.h, aout.c, ke11a.c, and v1trap.c all use EMUV1, so the upstream spelling otherwise silently omits first/second-edition support. Pass deterministic APOUT_OPTIONS=-DEMU211 -DEMUV1 -DNATIVES -DAPOUT_DONT_ASSUME_ROOT in the make flags; the last supported upstream option makes invocation fail rather than defaulting absolute guest paths to the host /. No wrapper or guest filesystem belongs in the output. At runtime users must set APOUT_ROOT to a user-owned guest root; preserve optional APOUT_UNIX_VERSION for ambiguous 0407 a.out files. NATIVES and the trap code deliberately execute native programs and directly call host filesystem/process/socket APIs, so document that APOUT_ROOT is not a security sandbox and do not claim network isolation from the package itself. The upstream LICENSE is GPL version 3 only; COPYRIGHT records Warren Toomey and the Eric A. Edwards-derived PDP-11 simulator code, and bsd_signal.c preserves the Berkeley notice. Use Guix license:gpl3 and install both LICENSE and COPYRIGHT; no other bundled executable or asset needs a separate license review. Local inspection shows no apout executable package: larsbrinkhoff-apout-source is preservation-only, and the issue inventory found no same-origin equivalent in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, or RDE. Add tests/apout-smoke.sh as the meaningful proof: require a supplied, provenance- and redistribution-cleared historical PDP-11 a.out fixture (prefer a fixed V7 cal/echo fixture with an expected transcript; do not fetch or package an unlicensed TUHS binary or a guest image), obtain the apout output path with guix build -L. apout or accept it as the sole argument, and fail if the fixture is absent. Run the probe from a fresh temporary HOME, XDG_CONFIG_HOME, XDG_DATA_HOME, XDG_CACHE_HOME, current directory, and APOUT_ROOT, under unshare --user --map-root-user --net or the Guix no-network build sandbox with failure if an isolated namespace cannot be established. Set APOUT_UNIX_VERSION=V7 when applicable, invoke $out/bin/apout against the fixture with its fixed argument and assert exit status plus the exact expected historical-program output, verify unset APOUT_ROOT is rejected with the supported diagnostic, grep installed LICENSE/COPYRIGHT notices, and compare a pre/post manifest of the package output to prove the run wrote only into temporary state. After implementation, the precise acceptance commands are guix lint -L. apout and guix build -L. apout; this research disposition does not claim either package proof. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/604). Originally posted by [htayj](https://github.com/htayj) on 2026-08-25T12:14:02Z.
htayj commented 2026-08-26 05:06:10 +00:00 (Migrated from github.com)

Recovered after the Gooflow proof self-block: the smoke test now generates its own documented V7 write/exit fixture, so the full mandatory proof passes without a redistribution-restricted artifact. Merged and pushed as 55194f2.


Imported from GitHub comment. Originally posted by htayj on 2026-08-26T05:06:10Z.

Recovered after the Gooflow proof self-block: the smoke test now generates its own documented V7 write/exit fixture, so the full mandatory proof passes without a redistribution-restricted artifact. Merged and pushed as 55194f2. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/604#issuecomment-5420860770). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T05:06:10Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#604
No description provided.