Implement researched Guix package outcome for #81: [Guix packaging] Toqozz/wired-notify #629

Closed
opened 2026-08-26 12:05:01 +00:00 by htayj · 1 comment
htayj commented 2026-08-26 12:05:01 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #81 ([Guix packaging] Toqozz/wired-notify).

The host-validated research finding follows:

Implementation-ready delivery brief for the requested wired executable. Canonical upstream is https://github.com/Toqozz/wired-notify at fixed Git commit 6b6f3c15b1a1304120f80ebf56c3accace40095a; that commit's Cargo.toml identifies package version 0.10.7. The local channel already records the same codeload source as toqozz-wired-notify-source in tay/packages/starred-s-z.scm, with immutable source hash 0q7fd416nrzczyc25qyn711v2zr5x2gl1nr5xq0l2w2kn6lhd0i5. The commit tree's LICENSE is the complete MIT License naming Michael Palmos and copyright 2020; wired_derive is an in-tree path crate at that same Git revision, not a separately fetched origin. The tree has no .gitmodules, no submodule entries, no Git dependency, and no other independently fetched upstream source. For the 295 crates.io package entries in the exact Cargo.lock (each fixed by its locked name, version, and checksum), exact-version crates.io API metadata checked on 2026-08-26 returned a nonempty license expression for all 295: 110 MIT OR Apache-2.0, 73 MIT, 49 MIT/Apache-2.0, 8 Apache-2.0/MIT, 6 Apache-2.0, 6 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT, 5 Apache-2.0 OR MIT, 5 BSD-3-Clause, 4 ISC, 4 Unlicense/MIT, 3 MIT OR Apache-2.0 OR Zlib, 3 MIT / Apache-2.0, 3 MPL-2.0, 2 BSD-2-Clause OR Apache-2.0 OR MIT, 2 BSD-3-Clause OR MIT OR Apache-2.0, 2 MIT OR Zlib OR Apache-2.0, 2 Zlib OR Apache-2.0 OR MIT, and one each of (MIT OR Apache-2.0) AND Unicode-3.0, 0BSD OR MIT OR Apache-2.0, Apache-2.0 OR BSL-1.0, BSD-2-Clause, CC0-1.0, MIT OR Apache-2.0 OR LGPL-2.1-or-later, Unlicense OR MIT, and Zlib. The three yanked lock entries remain fixed downloadable archives and have clear grants: crossbeam-channel@0.5.1 checksum 06ed27e177f16d65f0f0c22a213e17c696ace5dd64b14258b52f9417ccb52db4 is MIT OR Apache-2.0, futures-util@0.3.19 checksum d9b5cf40b47a271f77a8b1bec03ca09044d99d2372c0de244e66430761127164 is MIT OR Apache-2.0, and rgb@0.8.32 checksum e74fdc210d8f24a7dbfedc13b04ba5764f5232754ccebfdf5fff1bad791ccbc6 is MIT. Thus no required source origin lacks a clear redistribution grant, including the separately fetched registry origins. The source is technically source-buildable: upstream uses ordinary Cargo with edition 2021, a checked-in lockfile, and no parent build script or runtime download; its installer.sh is deliberately unsuitable because it requires root, DNF, nc google.com, and an unpinned networked Cargo build. The local channel has no installable wired definition and the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix RDE coverage has no equivalent package from this upstream; dunst is only a different notification-daemon alternative. Implement a dedicated (tay packages wired) module, reusing (package-source toqozz-wired-notify-source), cargo-build-system, #:install-source? #f, and the channel's stable rust toolchain. Enumerate all 295 locked crates as immutable crate-source inputs (the local guix import crate --lockfile Cargo.lock result matches the 295 registry entries), preserve and restore Cargo.lock around Guix's configure phase because this Guix cargo system deletes it, and invoke build/tests with --locked; Cargo's Guix phases must remain offline. Required native/system inputs are pkg-config, cairo, pango, glib, dbus, libx11, libxscrnsaver, libxi, libxrandr, libxcursor, and libxkbcommon, matching the cairo/pango/DBus/X11/XSS features in the Rust graph and upstream's X11 build inputs. Install only the wired binary, the MIT notice, and the two declarative examples wired.ron and wired_multilayout.ron; omit README demo media, AUR/Nix files, and the networked installer. Preserve wired.service as user-managed data but rewrite its /usr/bin/wired ExecStart to the immutable package $out/bin/wired; retain its Type=dbus, BusName=org.freedesktop.Notifications, and ConditionEnvironment=DISPLAY contract without enabling any service automatically. The daemon requires a session D-Bus and X11 or XWayland DISPLAY (it forces winit's X11 event loop); it does not provide native Wayland support. Its font and icon lookups remain external system/user resources and must not download assets. The only optional subprocess integration is xdg-open for clicked URL actions; either add xdg-utils as an explicit runtime input and prepend it in a wrapper PATH, or document it as optional, and do not invoke it in the offline smoke. No credentials or credential files are needed. Add an isolated tests/wired-smoke.sh proof that builds the package with tests enabled, runs wired --help and wired --version against the installed output, then in unshare -Urnm with a private tmpfs /tmp, fresh HOME/XDG directories, an in-namespace Xvfb, and dbus-run-session, starts wired --config with a temporary text-only RON config, calls GetServerInformation and Notify over the session bus to verify the wired service and a rendered notification path, invokes wired --kill through the private /tmp/wired.sock, asserts clean exit, forbids network and host state, and compares the package-output file manifest before and after while checking the installed MIT notice, both RON examples, and rewritten service. Acceptance is guix lint -L . --no-network --exclude=cve,refresh,archival wired with no new errors and guix build -L . wired succeeding from commit 6b6f3c15b1a1304120f80ebf56c3accace40095a with the locked graph and tests enabled; this research did not claim either proof because the host Guix daemon socket is unavailable.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-26T12:05:01Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:81:1:implementation-ready --> ## Context This delivery ticket was created from research issue #81 ([Guix packaging] Toqozz/wired-notify). The host-validated research finding follows: Implementation-ready delivery brief for the requested `wired` executable. Canonical upstream is https://github.com/Toqozz/wired-notify at fixed Git commit `6b6f3c15b1a1304120f80ebf56c3accace40095a`; that commit's `Cargo.toml` identifies package version `0.10.7`. The local channel already records the same codeload source as `toqozz-wired-notify-source` in `tay/packages/starred-s-z.scm`, with immutable source hash `0q7fd416nrzczyc25qyn711v2zr5x2gl1nr5xq0l2w2kn6lhd0i5`. The commit tree's `LICENSE` is the complete MIT License naming Michael Palmos and copyright 2020; `wired_derive` is an in-tree path crate at that same Git revision, not a separately fetched origin. The tree has no `.gitmodules`, no submodule entries, no Git dependency, and no other independently fetched upstream source. For the 295 crates.io package entries in the exact `Cargo.lock` (each fixed by its locked name, version, and checksum), exact-version crates.io API metadata checked on 2026-08-26 returned a nonempty license expression for all 295: 110 MIT OR Apache-2.0, 73 MIT, 49 MIT/Apache-2.0, 8 Apache-2.0/MIT, 6 Apache-2.0, 6 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT, 5 Apache-2.0 OR MIT, 5 BSD-3-Clause, 4 ISC, 4 Unlicense/MIT, 3 MIT OR Apache-2.0 OR Zlib, 3 MIT / Apache-2.0, 3 MPL-2.0, 2 BSD-2-Clause OR Apache-2.0 OR MIT, 2 BSD-3-Clause OR MIT OR Apache-2.0, 2 MIT OR Zlib OR Apache-2.0, 2 Zlib OR Apache-2.0 OR MIT, and one each of (MIT OR Apache-2.0) AND Unicode-3.0, 0BSD OR MIT OR Apache-2.0, Apache-2.0 OR BSL-1.0, BSD-2-Clause, CC0-1.0, MIT OR Apache-2.0 OR LGPL-2.1-or-later, Unlicense OR MIT, and Zlib. The three yanked lock entries remain fixed downloadable archives and have clear grants: `crossbeam-channel@0.5.1` checksum `06ed27e177f16d65f0f0c22a213e17c696ace5dd64b14258b52f9417ccb52db4` is MIT OR Apache-2.0, `futures-util@0.3.19` checksum `d9b5cf40b47a271f77a8b1bec03ca09044d99d2372c0de244e66430761127164` is MIT OR Apache-2.0, and `rgb@0.8.32` checksum `e74fdc210d8f24a7dbfedc13b04ba5764f5232754ccebfdf5fff1bad791ccbc6` is MIT. Thus no required source origin lacks a clear redistribution grant, including the separately fetched registry origins. The source is technically source-buildable: upstream uses ordinary Cargo with edition 2021, a checked-in lockfile, and no parent build script or runtime download; its `installer.sh` is deliberately unsuitable because it requires root, DNF, `nc google.com`, and an unpinned networked Cargo build. The local channel has no installable `wired` definition and the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix RDE coverage has no equivalent package from this upstream; `dunst` is only a different notification-daemon alternative. Implement a dedicated `(tay packages wired)` module, reusing `(package-source toqozz-wired-notify-source)`, `cargo-build-system`, `#:install-source? #f`, and the channel's stable `rust` toolchain. Enumerate all 295 locked crates as immutable `crate-source` inputs (the local `guix import crate --lockfile Cargo.lock` result matches the 295 registry entries), preserve and restore `Cargo.lock` around Guix's configure phase because this Guix cargo system deletes it, and invoke build/tests with `--locked`; Cargo's Guix phases must remain offline. Required native/system inputs are `pkg-config`, `cairo`, `pango`, `glib`, `dbus`, `libx11`, `libxscrnsaver`, `libxi`, `libxrandr`, `libxcursor`, and `libxkbcommon`, matching the cairo/pango/DBus/X11/XSS features in the Rust graph and upstream's X11 build inputs. Install only the `wired` binary, the MIT notice, and the two declarative examples `wired.ron` and `wired_multilayout.ron`; omit README demo media, AUR/Nix files, and the networked installer. Preserve `wired.service` as user-managed data but rewrite its `/usr/bin/wired` `ExecStart` to the immutable package `$out/bin/wired`; retain its `Type=dbus`, `BusName=org.freedesktop.Notifications`, and `ConditionEnvironment=DISPLAY` contract without enabling any service automatically. The daemon requires a session D-Bus and X11 or XWayland `DISPLAY` (it forces winit's X11 event loop); it does not provide native Wayland support. Its font and icon lookups remain external system/user resources and must not download assets. The only optional subprocess integration is `xdg-open` for clicked URL actions; either add `xdg-utils` as an explicit runtime input and prepend it in a wrapper PATH, or document it as optional, and do not invoke it in the offline smoke. No credentials or credential files are needed. Add an isolated `tests/wired-smoke.sh` proof that builds the package with tests enabled, runs `wired --help` and `wired --version` against the installed output, then in `unshare -Urnm` with a private tmpfs `/tmp`, fresh HOME/XDG directories, an in-namespace `Xvfb`, and `dbus-run-session`, starts `wired --config` with a temporary text-only RON config, calls `GetServerInformation` and `Notify` over the session bus to verify the `wired` service and a rendered notification path, invokes `wired --kill` through the private `/tmp/wired.sock`, asserts clean exit, forbids network and host state, and compares the package-output file manifest before and after while checking the installed MIT notice, both RON examples, and rewritten service. Acceptance is `guix lint -L . --no-network --exclude=cve,refresh,archival wired` with no new errors and `guix build -L . wired` succeeding from commit `6b6f3c15b1a1304120f80ebf56c3accace40095a` with the locked graph and tests enabled; this research did not claim either proof because the host Guix daemon socket is unavailable. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/629). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T12:05:01Z.
htayj commented 2026-08-27 04:56:47 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-08-27T04:56:47Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/629#issuecomment-5434564508). Originally posted by [htayj](https://github.com/htayj) on 2026-08-27T04:56:47Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#629
No description provided.