Implement researched Guix package outcome for #72: [Guix packaging] Heroic-Games-Launcher/heroic-gogdl #622

Closed
opened 2026-08-25 20:32:42 +00:00 by htayj · 3 comments
htayj commented 2026-08-25 20:32:42 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #72 ([Guix packaging] Heroic-Games-Launcher/heroic-gogdl).

The host-validated research finding follows:

Delivery brief: package heroic-gogdl (the installed executable remains gogdl) from the canonical upstream repository https://github.com/Heroic-Games-Launcher/heroic-gogdl at release v1.3.0, fixed commit 4fe373914d625cbce75973e92f6c5c4faf9815e2 (commit date 2026-08-07); a recursive checkout of that parent plus its submodule has the Guix base32 tree hash 0pcs9drldv48lqbdw7khf8x13law0xfx8h5sq3bycg7iwzb7hdxm when hashed with guix hash -rx. The parent source is source-buildable: pyproject.toml declares setuptools.build_meta, requires Python >=3.8, declares only requests at runtime, exposes the gogdl console entry point, and builds the gogdl_xdelta3 stable-ABI C extension from gogdl_xdelta3.c and the checked-in submodule source; no opaque binary, game, download, or build-time network fetch is needed. Parent license evidence is the exact-revision pyproject metadata and LICENSE at github.com/Heroic-Games-Launcher/heroic-gogdl@4fe373914d/pyproject.toml and github.com/Heroic-Games-Launcher/heroic-gogdl@4fe373914d/LICENSE, which support GPL-3.0-only. The only independently fetched submodule is declared at the exact parent revision in github.com/Heroic-Games-Launcher/heroic-gogdl@4fe373914d/.gitmodules and is jmacd/xdelta commit 0525275fe4b553a10f38e455d30c60dc6ed9b45d; its own exact-revision LICENSE is Apache-2.0 at github.com/jmacd/xdelta@0525275fe4/xdelta3/LICENSE. Both origins therefore have clear redistribution grants; retain both license texts in the installed documentation and represent the package legal closure as GPL-3.0-only plus the bundled Apache-2.0 component. Add the package in (gnu packages games) using pyproject-build-system and a git-fetch/git-reference with (recursive? #t); use python-requests as a propagated runtime input and python-setuptools plus python-wheel as native build inputs matching pyproject.toml, with the normal Guix C toolchain supplied by the build environment and no separate xdelta runtime input. The local channel has no equivalent installed package: tay/packages/starred-d-h.scm contains only heroic-games-launcher-heroic-gogdl-source, a codeload preservation snapshot that does not provide the CLI/module and does not replace the recursive package source; the issue-supplied coverage also reports no equivalent in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, or RDE. The upstream tree has no test suite, so set #:tests? #f, add an install phase for the parent LICENSE and xdelta3/xdelta3/LICENSE, and rely on the package-specific smoke. Do not use upstream zipapp_main.py or PyInstaller: the PEP 517 build generates gogdl, and Guix's pyproject wrapper must preserve GUIX_PYTHONPATH so the installed gogdl_xdelta3.abi3.so remains importable. Leave authentication and paths to the caller: --auth-config-path is the explicit token-file contract, while XDG_CONFIG_HOME/GOGDL_CONFIG_PATH control non-secret state; do not add credential files or wrappers that set credentials. Smoke proof plan for tests/heroic-gogdl-smoke.sh: accept an optional built output path, create fresh temporary HOME, XDG_CONFIG_HOME, GOGDL_CONFIG_PATH, and work directories, clear proxy variables, run the help/version and parser-only checks in an isolated no-network process (prefer unshare --user --map-root-user --net when available), assert gogdl --version is exactly 1.3.0, gogdl --help exposes the downloader/auth commands, and an installed-Python snippet imports gogdl_xdelta3, calls gogdl.args.init_parser() with ['gogdl','lang-match','en'], and asserts the parsed command/language without contacting GOG; assert the fresh state directories remain empty, the output tree digest is unchanged, the output is not writable, and both installed license documents contain the GPL and Apache notices. Then run guix lint -L. heroic-gogdl, guix build -L. heroic-gogdl, and the smoke with the built output; these are implementation acceptance checks and are not claimed as completed here. Upstream issue https://github.com/Heroic-Games-Launcher/heroic-gogdl/issues/72 reports a live GOG auth endpoint failure for an older gogdl release, and the pinned 1.3.0 auth module retains the same external authentication design; this is outside the stated credential-free offline acceptance, so the package must make no live-login claim, and any future requirement to prove current GOG login must be re-evaluated against a newer upstream fixed revision rather than solved by packaging credentials.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-25T20:32:42Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:72:1:implementation-ready --> ## Context This delivery ticket was created from research issue #72 ([Guix packaging] Heroic-Games-Launcher/heroic-gogdl). The host-validated research finding follows: Delivery brief: package `heroic-gogdl` (the installed executable remains `gogdl`) from the canonical upstream repository https://github.com/Heroic-Games-Launcher/heroic-gogdl at release v1.3.0, fixed commit 4fe373914d625cbce75973e92f6c5c4faf9815e2 (commit date 2026-08-07); a recursive checkout of that parent plus its submodule has the Guix base32 tree hash 0pcs9drldv48lqbdw7khf8x13law0xfx8h5sq3bycg7iwzb7hdxm when hashed with `guix hash -rx`. The parent source is source-buildable: pyproject.toml declares setuptools.build_meta, requires Python >=3.8, declares only `requests` at runtime, exposes the `gogdl` console entry point, and builds the `gogdl_xdelta3` stable-ABI C extension from `gogdl_xdelta3.c` and the checked-in submodule source; no opaque binary, game, download, or build-time network fetch is needed. Parent license evidence is the exact-revision pyproject metadata and LICENSE at https://github.com/Heroic-Games-Launcher/heroic-gogdl/blob/4fe373914d625cbce75973e92f6c5c4faf9815e2/pyproject.toml and https://github.com/Heroic-Games-Launcher/heroic-gogdl/blob/4fe373914d625cbce75973e92f6c5c4faf9815e2/LICENSE, which support GPL-3.0-only. The only independently fetched submodule is declared at the exact parent revision in https://github.com/Heroic-Games-Launcher/heroic-gogdl/blob/4fe373914d625cbce75973e92f6c5c4faf9815e2/.gitmodules and is jmacd/xdelta commit 0525275fe4b553a10f38e455d30c60dc6ed9b45d; its own exact-revision LICENSE is Apache-2.0 at https://github.com/jmacd/xdelta/blob/0525275fe4b553a10f38e455d30c60dc6ed9b45d/xdelta3/LICENSE. Both origins therefore have clear redistribution grants; retain both license texts in the installed documentation and represent the package legal closure as GPL-3.0-only plus the bundled Apache-2.0 component. Add the package in `(gnu packages games)` using `pyproject-build-system` and a `git-fetch`/`git-reference` with `(recursive? #t)`; use `python-requests` as a propagated runtime input and `python-setuptools` plus `python-wheel` as native build inputs matching pyproject.toml, with the normal Guix C toolchain supplied by the build environment and no separate xdelta runtime input. The local channel has no equivalent installed package: `tay/packages/starred-d-h.scm` contains only `heroic-games-launcher-heroic-gogdl-source`, a codeload preservation snapshot that does not provide the CLI/module and does not replace the recursive package source; the issue-supplied coverage also reports no equivalent in GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, or RDE. The upstream tree has no test suite, so set `#:tests? #f`, add an install phase for the parent LICENSE and `xdelta3/xdelta3/LICENSE`, and rely on the package-specific smoke. Do not use upstream zipapp_main.py or PyInstaller: the PEP 517 build generates `gogdl`, and Guix's pyproject wrapper must preserve `GUIX_PYTHONPATH` so the installed `gogdl_xdelta3.abi3.so` remains importable. Leave authentication and paths to the caller: `--auth-config-path` is the explicit token-file contract, while `XDG_CONFIG_HOME`/`GOGDL_CONFIG_PATH` control non-secret state; do not add credential files or wrappers that set credentials. Smoke proof plan for `tests/heroic-gogdl-smoke.sh`: accept an optional built output path, create fresh temporary HOME, XDG_CONFIG_HOME, GOGDL_CONFIG_PATH, and work directories, clear proxy variables, run the help/version and parser-only checks in an isolated no-network process (prefer `unshare --user --map-root-user --net` when available), assert `gogdl --version` is exactly `1.3.0`, `gogdl --help` exposes the downloader/auth commands, and an installed-Python snippet imports `gogdl_xdelta3`, calls `gogdl.args.init_parser()` with `['gogdl','lang-match','en']`, and asserts the parsed command/language without contacting GOG; assert the fresh state directories remain empty, the output tree digest is unchanged, the output is not writable, and both installed license documents contain the GPL and Apache notices. Then run `guix lint -L. heroic-gogdl`, `guix build -L. heroic-gogdl`, and the smoke with the built output; these are implementation acceptance checks and are not claimed as completed here. Upstream issue https://github.com/Heroic-Games-Launcher/heroic-gogdl/issues/72 reports a live GOG auth endpoint failure for an older gogdl release, and the pinned 1.3.0 auth module retains the same external authentication design; this is outside the stated credential-free offline acceptance, so the package must make no live-login claim, and any future requirement to prove current GOG login must be re-evaluated against a newer upstream fixed revision rather than solved by packaging credentials. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/622). Originally posted by [htayj](https://github.com/htayj) on 2026-08-25T20:32:42Z.
htayj commented 2026-08-25 22:34:54 +00:00 (Migrated from github.com)

Classified as complexity:medium (recursive Python source with bundled C extension and submodule). This preserves the requested easy-to-hard queue: the existing low-complexity package tickets run first.


Imported from GitHub comment. Originally posted by htayj on 2026-08-25T22:34:54Z.

Classified as `complexity:medium` (recursive Python source with bundled C extension and submodule). This preserves the requested easy-to-hard queue: the existing low-complexity package tickets run first. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/622#issuecomment-5417772373). Originally posted by [htayj](https://github.com/htayj) on 2026-08-25T22:34:54Z.
htayj commented 2026-08-26 03:37:21 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-08-26T03:37:21Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/622#issuecomment-5420233389). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T03:37:21Z.
Owner

Published signed Guix-authenticated commit74918398a3a73d7c1998a127b03b9a7c7fd00f8e. Main independently passed source build, --check and integrated offline runtime for /gnu/store/fsw0yxhzlf5v3bwnmwg2yf2js6bim793-heroic-gogdl-1.3.0. Offline lint advisory python-wheel retained: pinned pyproject requires it and build system does not implicitly supply it. Actual CLI language/import/parser checks, v2 manifest DLC/language/size and chunk offsets, local checksum boundary, deterministic gzip/UTC SyncFile metadata and native VCDIFF COPY+ADD exact output passed under network isolation. PNG622 actual CLI output visually inspected. Existing native C warnings disclosed. No GOG accounts/credentials/live downloads/cloud calls or deployed profile changes; no new independent reviewer approval claimed.

Published signed Guix-authenticated commit74918398a3a73d7c1998a127b03b9a7c7fd00f8e. Main independently passed source build, --check and integrated offline runtime for /gnu/store/fsw0yxhzlf5v3bwnmwg2yf2js6bim793-heroic-gogdl-1.3.0. Offline lint advisory python-wheel retained: pinned pyproject requires it and build system does not implicitly supply it. Actual CLI language/import/parser checks, v2 manifest DLC/language/size and chunk offsets, local checksum boundary, deterministic gzip/UTC SyncFile metadata and native VCDIFF COPY+ADD exact output passed under network isolation. PNG622 actual CLI output visually inspected. Existing native C warnings disclosed. No GOG accounts/credentials/live downloads/cloud calls or deployed profile changes; no new independent reviewer approval claimed.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#622
No description provided.