Implement researched Guix package outcome for #77: [Guix packaging] MetricsHub/winrm-java #627

Open
opened 2026-08-26 09:57:19 +00:00 by htayj · 1 comment
htayj commented 2026-08-26 09:57:19 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #77 ([Guix packaging] MetricsHub/winrm-java).

The host-validated research finding follows:

Implement an installable Guix package for the canonical upstream project https://github.com/MetricsHub/winrm-java at the exact pinned commit ac4521509ad5056f6739078c4fd34b8ad3d22cf8 (GitHub source hash 08d039fgr8ymjib9kfm0y2l8k2qd95h1mdn9p68bc8krqjrqhv18). The POM at that revision identifies version 2.2.00-SNAPSHOT, Java release 11, and the pinned commit is the post-v2.1.00 main-branch merge snapshot; fetch only that revision. The repository has no Git submodules or other separately checked-out source trees. Its root LICENSE is the complete Apache License 2.0, the POM declares Apache-2.0, and Java sources carry Apache headers; preserve LICENSE, README.md, and notices in the output. The project is source-buildable with Maven and has no runtime library dependencies: the regular JAR is sufficient, while the upstream shade/quality/site/reporting configuration is not required for the deliverable. No equivalent package with this upstream origin exists in the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix R Us/RDE coverage; python-pywinrm is a different implementation and is not an equivalent. Define winrm-java in a new tay/packages/winrm-java.scm using (tay packages winrm-java), so guix build -L. winrm-java resolves the package. Use maven-build-system with the exact GitHub source, #:jdk openjdk17 for the JUnit 6 test runtime, while retaining upstream --release 11; include the Maven 3.9.0/build-system plugin inputs plus fixed Maven inputs for org.metricshub:oss-parent:5, com.github.spotbugs:spotbugs-annotations:4.10.3 (provided/build-only), org.junit:junit-bom:6.1.3, org.junit.platform:junit-platform-launcher:6.1.3, org.junit.jupiter:junit-jupiter-engine:6.1.3, and their fixed closure org.junit.jupiter:junit-jupiter-api:6.1.3, org.junit.platform:junit-platform-engine:6.1.3, org.junit.platform:junit-platform-commons:6.1.3, org.apiguardian:apiguardian-api:1.1.2, org.opentest4j:opentest4j:1.3.0, and org.jspecify:jspecify:1.0.0. The separately fetched helper-origin evidence is: MetricsHub/oss-parent tag v5 peeled to commit 2b9a7fb05c09ac96136c2cc79477c734b65613d5, whose exact-revision LICENSE and POM grant Apache-2.0; junit-team/junit-framework tag r6.1.3 peeled to f59f60d2cebdf2224235d81f781b1f310cbc8138, whose exact-revision LICENSE.md grants EPL-2.0 and NOTICE records component notices; and spotbugs/spotbugs tag 4.10.3 peeled to 8d5cad4536ae263448c09181268bbca70f0c0712, whose exact-revision root LICENSE grants LGPL-2.1. The fixed Maven closure coordinates have explicit POM license grants at those revisions: apiguardian-api 1.1.2 Apache-2.0, opentest4j 1.3.0 Apache-2.0, and jspecify 1.0.0 Apache-2.0; retain the associated license files/notices when introducing any new Guix inputs. Exclude or neutralize unavailable upstream-only formatter, PMD, Checkstyle, SpotBugs, site, release, source/javadoc/license, and failsafe/reporting executions (including net.revelc.code.formatter:formatter-maven-plugin, org.codehaus.mojo:license-maven-plugin, org.apache.maven.plugins:maven-site-plugin/maven-source-plugin/maven-javadoc-plugin/maven-pmd-plugin/maven-checkstyle-plugin/maven-release-plugin/maven-artifact-plugin/maven-failsafe-plugin, com.github.spotbugs:spotbugs-maven-plugin, and site skin tooling) while keeping compile, resource, JAR, and unit-test phases; do not add the shade plugin solely for the standalone artifact because the upstream README documents zero runtime dependencies. Install the regular JAR under share/java/winrm-java.jar and provide bin/winrm as a fixed-runtime wrapper using openjdk11 to invoke org.metricshub.winrm.cli.WinRmCli with all user arguments; install upstream README.md and LICENSE under share/doc/winrm-java. The package has no service, daemon, downloaded asset, credential, or optional integration requirement. Runtime network access occurs only when a WinRM operation is executed; --help/--version and client construction must not connect. Preserve the explicit security behavior: HTTPS certificate and hostname validation is enabled by default, Kerberos/NTLM selection and ticket-cache/truststore paths are supplied by the user, and trustAllCertificates/--https-permissive is an explicit insecure opt-in. The isolated smoke proof must use a temporary HOME and no live-server properties, run Maven tests offline from the fixed tree with mvn test -o (or the equivalent Guix phase), including WsmanProtocolTest's in-process fake-server NTLM/encrypted-framing/WQL/command lifecycle coverage, LightTlsTest's default-validation and explicit-insecure assertions, FallbackAuthSchemeTest's Kerberos-to-NTLM fallback without a KDC, WinRMClientBuilderTest's no-connect and validation cases, and CLI argument parsing; leave disabled WinRMLiveTest disabled. Then package offline, run the wrapper with --help and --version, and compile/run a tiny Java 11 smoke class against the installed JAR that builds WinRMClient.builder("host").https().port(5987).build() without invoking an operation, while asserting no socket connection is attempted. Final acceptance is guix lint -L. winrm-java with no new errors and guix build -L. winrm-java succeeding with the offline tests enabled where practical; record those command results as implementation acceptance, not as research proof.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-26T09:57:19Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:77:1:implementation-ready --> ## Context This delivery ticket was created from research issue #77 ([Guix packaging] MetricsHub/winrm-java). The host-validated research finding follows: Implement an installable Guix package for the canonical upstream project https://github.com/MetricsHub/winrm-java at the exact pinned commit ac4521509ad5056f6739078c4fd34b8ad3d22cf8 (GitHub source hash 08d039fgr8ymjib9kfm0y2l8k2qd95h1mdn9p68bc8krqjrqhv18). The POM at that revision identifies version 2.2.00-SNAPSHOT, Java release 11, and the pinned commit is the post-v2.1.00 main-branch merge snapshot; fetch only that revision. The repository has no Git submodules or other separately checked-out source trees. Its root LICENSE is the complete Apache License 2.0, the POM declares Apache-2.0, and Java sources carry Apache headers; preserve LICENSE, README.md, and notices in the output. The project is source-buildable with Maven and has no runtime library dependencies: the regular JAR is sufficient, while the upstream shade/quality/site/reporting configuration is not required for the deliverable. No equivalent package with this upstream origin exists in the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix R Us/RDE coverage; python-pywinrm is a different implementation and is not an equivalent. Define winrm-java in a new tay/packages/winrm-java.scm using (tay packages winrm-java), so guix build -L. winrm-java resolves the package. Use maven-build-system with the exact GitHub source, #:jdk openjdk17 for the JUnit 6 test runtime, while retaining upstream --release 11; include the Maven 3.9.0/build-system plugin inputs plus fixed Maven inputs for org.metricshub:oss-parent:5, com.github.spotbugs:spotbugs-annotations:4.10.3 (provided/build-only), org.junit:junit-bom:6.1.3, org.junit.platform:junit-platform-launcher:6.1.3, org.junit.jupiter:junit-jupiter-engine:6.1.3, and their fixed closure org.junit.jupiter:junit-jupiter-api:6.1.3, org.junit.platform:junit-platform-engine:6.1.3, org.junit.platform:junit-platform-commons:6.1.3, org.apiguardian:apiguardian-api:1.1.2, org.opentest4j:opentest4j:1.3.0, and org.jspecify:jspecify:1.0.0. The separately fetched helper-origin evidence is: MetricsHub/oss-parent tag v5 peeled to commit 2b9a7fb05c09ac96136c2cc79477c734b65613d5, whose exact-revision LICENSE and POM grant Apache-2.0; junit-team/junit-framework tag r6.1.3 peeled to f59f60d2cebdf2224235d81f781b1f310cbc8138, whose exact-revision LICENSE.md grants EPL-2.0 and NOTICE records component notices; and spotbugs/spotbugs tag 4.10.3 peeled to 8d5cad4536ae263448c09181268bbca70f0c0712, whose exact-revision root LICENSE grants LGPL-2.1. The fixed Maven closure coordinates have explicit POM license grants at those revisions: apiguardian-api 1.1.2 Apache-2.0, opentest4j 1.3.0 Apache-2.0, and jspecify 1.0.0 Apache-2.0; retain the associated license files/notices when introducing any new Guix inputs. Exclude or neutralize unavailable upstream-only formatter, PMD, Checkstyle, SpotBugs, site, release, source/javadoc/license, and failsafe/reporting executions (including net.revelc.code.formatter:formatter-maven-plugin, org.codehaus.mojo:license-maven-plugin, org.apache.maven.plugins:maven-site-plugin/maven-source-plugin/maven-javadoc-plugin/maven-pmd-plugin/maven-checkstyle-plugin/maven-release-plugin/maven-artifact-plugin/maven-failsafe-plugin, com.github.spotbugs:spotbugs-maven-plugin, and site skin tooling) while keeping compile, resource, JAR, and unit-test phases; do not add the shade plugin solely for the standalone artifact because the upstream README documents zero runtime dependencies. Install the regular JAR under share/java/winrm-java.jar and provide bin/winrm as a fixed-runtime wrapper using openjdk11 to invoke org.metricshub.winrm.cli.WinRmCli with all user arguments; install upstream README.md and LICENSE under share/doc/winrm-java. The package has no service, daemon, downloaded asset, credential, or optional integration requirement. Runtime network access occurs only when a WinRM operation is executed; --help/--version and client construction must not connect. Preserve the explicit security behavior: HTTPS certificate and hostname validation is enabled by default, Kerberos/NTLM selection and ticket-cache/truststore paths are supplied by the user, and trustAllCertificates/--https-permissive is an explicit insecure opt-in. The isolated smoke proof must use a temporary HOME and no live-server properties, run Maven tests offline from the fixed tree with mvn test -o (or the equivalent Guix phase), including WsmanProtocolTest's in-process fake-server NTLM/encrypted-framing/WQL/command lifecycle coverage, LightTlsTest's default-validation and explicit-insecure assertions, FallbackAuthSchemeTest's Kerberos-to-NTLM fallback without a KDC, WinRMClientBuilderTest's no-connect and validation cases, and CLI argument parsing; leave disabled WinRMLiveTest disabled. Then package offline, run the wrapper with --help and --version, and compile/run a tiny Java 11 smoke class against the installed JAR that builds WinRMClient.builder("host").https().port(5987).build() without invoking an operation, while asserting no socket connection is attempted. Final acceptance is guix lint -L. winrm-java with no new errors and guix build -L. winrm-java succeeding with the offline tests enabled where practical; record those command results as implementation acceptance, not as research proof. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/627). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T09:57:19Z.
htayj commented 2026-08-27 00:54:18 +00:00 (Migrated from github.com)

Goocastle validation is blocked; no commit was made.

Evidence:

  • The pin ac4521509ad5056f6739078c4fd34b8ad3d22cf8 resolves, but the issue-supplied hash is incorrect. Guix computed 0gkna78wci13b82nn45m3s9mx6kp8hhflsrvr7sxhxh7yvccka0h.
  • guix build -L . winrm-java reached the source-built JUnit 6.1.3 closure. After distinct Java 17 and JPMS-descriptor corrections, that closure still fails compiling junit-platform-commons because Kotlin optional APIs are unavailable.
  • A fully reproducible package must first provide/repair the appropriate Kotlin/JUnit closure (or use an upstream-compatible, documented dependency set).

The uncommitted draft is retained in the Goocastle recovery worktree for the follow-up.


Imported from GitHub comment. Originally posted by htayj on 2026-08-27T00:54:18Z.

Goocastle validation is blocked; no commit was made. Evidence: - The pin `ac4521509ad5056f6739078c4fd34b8ad3d22cf8` resolves, but the issue-supplied hash is incorrect. Guix computed `0gkna78wci13b82nn45m3s9mx6kp8hhflsrvr7sxhxh7yvccka0h`. - `guix build -L . winrm-java` reached the source-built JUnit 6.1.3 closure. After distinct Java 17 and JPMS-descriptor corrections, that closure still fails compiling `junit-platform-commons` because Kotlin optional APIs are unavailable. - A fully reproducible package must first provide/repair the appropriate Kotlin/JUnit closure (or use an upstream-compatible, documented dependency set). The uncommitted draft is retained in the Goocastle recovery worktree for the follow-up. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/627#issuecomment-5432914583). Originally posted by [htayj](https://github.com/htayj) on 2026-08-27T00:54:18Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#627
No description provided.