Implement researched Guix package outcome for #101: [Guix packaging] charlesrosenbauer/Clojure-Roguelike #636

Closed
opened 2026-08-28 11:22:26 +00:00 by htayj · 6 comments
htayj commented 2026-08-28 11:22:26 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #101 ([Guix packaging] charlesrosenbauer/Clojure-Roguelike).

The host-validated research finding follows:

Delivery brief for the exact pinned tree: package canonical upstream https://github.com/charlesrosenbauer/Clojure-Roguelike at revision 16102d6123a19dbac03f457a13e8b9f1e181f577 (2018-09-21), using the existing codeload origin and Guix base32 source hash 0qr8frwyig2qjmm0b3mzrzy9j8c782wkkxjc48pdfi3lyryj8l3l recorded by tay/packages/starred-a-c.scm. The tree contains project.clj, src/roguelike/core.clj, test/roguelike/core_test.clj, documentation, and LICENSE; git ls-tree shows no submodules, and there are no assets, services, credentials, network calls, or optional integrations. LICENSE is the Eclipse Public License v1.0 text and project.clj independently declares Eclipse Public License, so the application source and object code have a clear redistribution grant. The only declared application dependency is org.clojure/clojure 1.8.0. The local Guix channel has only the preservation package charlesrosenbauer-clojure-roguelike-source, and Guix search/local package inspection found no equivalent installable package from this origin. Source-build assessment: use a new tay/packages/clojure-roguelike.scm module with clojure-build-system, source-dirs src, test-dirs test, main class roguelike.core, and AOT of roguelike.core; pass a private exact Clojure 1.8 runtime built from the separate canonical origin https://github.com/clojure/clojure at dereferenced tag commit 4ff462372c29ff2bc22b4d39962ad526f7e2c73d. At that fixed Clojure revision, readme.txt and epl-v10.html provide EPL-1.0 evidence, readme.txt records the embedded ASM three-clause BSD notice and Guava Murmur3 Apache-2.0 notice, and the package must retain those notices alongside the application LICENSE/README/CHANGELOG. Clojure 1.8 is not exported by the current channel (current clojure is 1.12.4), so this private runtime is required to honor the pinned dependency; build it with Guix ant-build-system, an empty maven-classpath.properties, tests disabled for the runtime, and existing Guix icedtea/OpenJDK 8 because the fixed Clojure build.xml targets Java 1.6. The Clojure 1.8 POM lists jsr166y only as provided and test.generative/test.check only for tests; the application uses only Clojure core and clojure.string, so no Maven artifacts or network resolution are needed. The application package should disable Guix tests with a documented reason: test/roguelike/core_test.clj contains the sole test, named FIXME, I fail, and asserts (= 0 1); do not report that upstream test as passing. After the normal Clojure compilation, create one deterministic uberjar at share/java/clojure-roguelike.jar by merging the AOT application classes/source with the exact built Clojure 1.8 runtime jar, replacing the runtime manifest with Main-Class roguelike.core, and preserving the Clojure runtime notices in installed documentation. Install a /bin/clojure-roguelike wrapper with a fixed Guix bash interpreter that execs the fixed Guix Java runtime with that jar and forwards argv; the pinned -main performs only one-shot terminal rendering and does not read stdin or write state, so no XDG/state wrapper or service is needed. Specific smoke proof: build the package with Guix's network-isolated builder from the pinned application and private Clojure source, with no Leiningen/Maven invocation; inspect the output for the single jar, Main-Class, launcher, application notices, and Clojure EPL/ASM/Apache notices; then run the launcher through a PTY (script -qefc) from a fresh temporary HOME/XDG tree and private temporary cwd, feed only q\n, and use a fail-closed private network namespace (or equivalent network-denied runner). Require exit status 0, no created files outside the temporary tree, no network access, and stdout exactly ########\n#......#\n#......#\n.......#\n#......#\n#......#\n#......#\n########\n, which is the room emitted by the pinned -main. Final gates for implementation are guix lint -L. clojure-roguelike with no new errors and guix build -L. clojure-roguelike succeeding from the fixed sources; this research run makes no package-proof claim because the host lacks /var/guix/daemon-socket/socket.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-28T11:22:26Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:101:1:implementation-ready --> ## Context This delivery ticket was created from research issue #101 ([Guix packaging] charlesrosenbauer/Clojure-Roguelike). The host-validated research finding follows: Delivery brief for the exact pinned tree: package canonical upstream https://github.com/charlesrosenbauer/Clojure-Roguelike at revision 16102d6123a19dbac03f457a13e8b9f1e181f577 (2018-09-21), using the existing codeload origin and Guix base32 source hash 0qr8frwyig2qjmm0b3mzrzy9j8c782wkkxjc48pdfi3lyryj8l3l recorded by tay/packages/starred-a-c.scm. The tree contains project.clj, src/roguelike/core.clj, test/roguelike/core_test.clj, documentation, and LICENSE; git ls-tree shows no submodules, and there are no assets, services, credentials, network calls, or optional integrations. LICENSE is the Eclipse Public License v1.0 text and project.clj independently declares Eclipse Public License, so the application source and object code have a clear redistribution grant. The only declared application dependency is org.clojure/clojure 1.8.0. The local Guix channel has only the preservation package charlesrosenbauer-clojure-roguelike-source, and Guix search/local package inspection found no equivalent installable package from this origin. Source-build assessment: use a new tay/packages/clojure-roguelike.scm module with clojure-build-system, source-dirs `src`, test-dirs `test`, main class `roguelike.core`, and AOT of `roguelike.core`; pass a private exact Clojure 1.8 runtime built from the separate canonical origin https://github.com/clojure/clojure at dereferenced tag commit 4ff462372c29ff2bc22b4d39962ad526f7e2c73d. At that fixed Clojure revision, readme.txt and epl-v10.html provide EPL-1.0 evidence, readme.txt records the embedded ASM three-clause BSD notice and Guava Murmur3 Apache-2.0 notice, and the package must retain those notices alongside the application LICENSE/README/CHANGELOG. Clojure 1.8 is not exported by the current channel (current clojure is 1.12.4), so this private runtime is required to honor the pinned dependency; build it with Guix ant-build-system, an empty maven-classpath.properties, tests disabled for the runtime, and existing Guix `icedtea`/OpenJDK 8 because the fixed Clojure build.xml targets Java 1.6. The Clojure 1.8 POM lists jsr166y only as provided and test.generative/test.check only for tests; the application uses only Clojure core and clojure.string, so no Maven artifacts or network resolution are needed. The application package should disable Guix tests with a documented reason: test/roguelike/core_test.clj contains the sole test, named `FIXME, I fail`, and asserts `(= 0 1)`; do not report that upstream test as passing. After the normal Clojure compilation, create one deterministic uberjar at share/java/clojure-roguelike.jar by merging the AOT application classes/source with the exact built Clojure 1.8 runtime jar, replacing the runtime manifest with Main-Class `roguelike.core`, and preserving the Clojure runtime notices in installed documentation. Install a /bin/clojure-roguelike wrapper with a fixed Guix bash interpreter that execs the fixed Guix Java runtime with that jar and forwards argv; the pinned -main performs only one-shot terminal rendering and does not read stdin or write state, so no XDG/state wrapper or service is needed. Specific smoke proof: build the package with Guix's network-isolated builder from the pinned application and private Clojure source, with no Leiningen/Maven invocation; inspect the output for the single jar, Main-Class, launcher, application notices, and Clojure EPL/ASM/Apache notices; then run the launcher through a PTY (`script -qefc`) from a fresh temporary HOME/XDG tree and private temporary cwd, feed only `q\n`, and use a fail-closed private network namespace (or equivalent network-denied runner). Require exit status 0, no created files outside the temporary tree, no network access, and stdout exactly `########\n#......#\n#......#\n.......#\n#......#\n#......#\n#......#\n########\n`, which is the room emitted by the pinned -main. Final gates for implementation are `guix lint -L. clojure-roguelike` with no new errors and `guix build -L. clojure-roguelike` succeeding from the fixed sources; this research run makes no package-proof claim because the host lacks /var/guix/daemon-socket/socket. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/636). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T11:22:26Z.
htayj commented 2026-08-28 14:48:44 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the package before retrying.

Bounded failure evidence:
Failed command: sh .goocastle/prove-guix-package.sh
Exit status: 1
Final failure lines:
[stderr] adding: clojure/instant$fail.class (stored 0%)
[stderr] error: in phase 'generate-jar-indices': uncaught exception:
[stderr] %exception #<&invoke-error program: "jar" arguments: ("-i" "/gnu/store/4d744zrzn2q0jjsbja9lad6xwcs53cgc-clojure-1.8-1.8.0-0.4ff4623/share/java/clojure-1.8.0.jar") exit-status: 1 term-signal: #f stop-signal: #f>
[stderr] phase generate-jar-indices' failed after 0.0 seconds [stderr] command "jar" "-i" "/gnu/store/4d744zrzn2q0jjsbja9lad6xwcs53cgc-clojure-1.8-1.8.0-0.4ff4623/share/java/clojure-1.8.0.jar" failed with status 1 [stderr] builder for /gnu/store/f7x0nix8s55iyi257qb7jahprfa31rj9-clojure-1.8-1.8.0-0.4ff4623.drv' failed with exit code 1
[stderr] build of /gnu/store/f7x0nix8s55iyi257qb7jahprfa31rj9-clojure-1.8-1.8.0-0.4ff4623.drv failed
[stderr] guix build: error: build of `/gnu/store/y9b2ixj6zc6afxfibpkyn0s38x0nli9a-clojure-roguelike-0.1.0-0.16102d6.drv' failed
[earlier or oversized output omitted]


Imported from GitHub comment. Originally posted by htayj on 2026-08-28T14:48:44Z.

<!-- goocastle-repair-blocked:636:safe-package-proof --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the package before retrying. Bounded failure evidence: Failed command: sh .goocastle/prove-guix-package.sh Exit status: 1 Final failure lines: [stderr] adding: clojure/instant$fail.class (stored 0%) [stderr] error: in phase 'generate-jar-indices': uncaught exception: [stderr] %exception #<&invoke-error program: "jar" arguments: ("-i" "/gnu/store/4d744zrzn2q0jjsbja9lad6xwcs53cgc-clojure-1.8-1.8.0-0.4ff4623/share/java/clojure-1.8.0.jar") exit-status: 1 term-signal: #f stop-signal: #f> [stderr] phase `generate-jar-indices' failed after 0.0 seconds [stderr] command "jar" "-i" "/gnu/store/4d744zrzn2q0jjsbja9lad6xwcs53cgc-clojure-1.8-1.8.0-0.4ff4623/share/java/clojure-1.8.0.jar" failed with status 1 [stderr] builder for `/gnu/store/f7x0nix8s55iyi257qb7jahprfa31rj9-clojure-1.8-1.8.0-0.4ff4623.drv' failed with exit code 1 [stderr] build of /gnu/store/f7x0nix8s55iyi257qb7jahprfa31rj9-clojure-1.8-1.8.0-0.4ff4623.drv failed [stderr] guix build: error: build of `/gnu/store/y9b2ixj6zc6afxfibpkyn0s38x0nli9a-clojure-roguelike-0.1.0-0.16102d6.drv' failed [earlier or oversized output omitted] --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5453983824). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T14:48:44Z.
htayj commented 2026-08-28 16:44:33 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the package before retrying.

Bounded failure evidence:
Failed command: sh .goocastle/prove-guix-package.sh
Exit status: 1
Final failure lines:
[stderr] guix build: warning: failed to load '(tay packages opencode-desktop)':
[stderr] error: in phase 'build': uncaught exception:
[stderr] %exception #<&invoke-error program: "ant" arguments: ("jar") exit-status: 143 term-signal: #f stop-signal: #f>
[stderr] phase build' failed after 1.4 seconds [stderr] command "ant" "jar" failed with status 143 [stderr] builder for /gnu/store/bz0kam0li60r5v8fl37q76nz6za3428c-clojure-1.8-1.8.0-0.4ff4623.drv' failed with exit code 1
[stderr] build of /gnu/store/bz0kam0li60r5v8fl37q76nz6za3428c-clojure-1.8-1.8.0-0.4ff4623.drv failed
[stderr] guix build: error: build of `/gnu/store/4llnn83xb14q6rl2pnf34ivxxpkwnpbf-clojure-roguelike-0.1.0-0.16102d6.drv' failed
[earlier or oversized output omitted]


Imported from GitHub comment. Originally posted by htayj on 2026-08-28T16:44:33Z.

<!-- goocastle-repair-blocked:636:safe-package-proof --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the package before retrying. Bounded failure evidence: Failed command: sh .goocastle/prove-guix-package.sh Exit status: 1 Final failure lines: [stderr] guix build: warning: failed to load '(tay packages opencode-desktop)': [stderr] error: in phase 'build': uncaught exception: [stderr] %exception #<&invoke-error program: "ant" arguments: ("jar") exit-status: 143 term-signal: #f stop-signal: #f> [stderr] phase `build' failed after 1.4 seconds [stderr] command "ant" "jar" failed with status 143 [stderr] builder for `/gnu/store/bz0kam0li60r5v8fl37q76nz6za3428c-clojure-1.8-1.8.0-0.4ff4623.drv' failed with exit code 1 [stderr] build of /gnu/store/bz0kam0li60r5v8fl37q76nz6za3428c-clojure-1.8-1.8.0-0.4ff4623.drv failed [stderr] guix build: error: build of `/gnu/store/4llnn83xb14q6rl2pnf34ivxxpkwnpbf-clojure-roguelike-0.1.0-0.16102d6.drv' failed [earlier or oversized output omitted] --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5455213837). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T16:44:33Z.
htayj commented 2026-08-28 17:18:59 +00:00 (Migrated from github.com)

Goocastle verified runtime evidence.

Runtime screenshot

Runtime receipt
  • Package: Guix package issue #636
  • Safe package proof phase: safe-package-proof
  • Safe package proof argv: ["sh",".goocastle/prove-guix-package.sh"]
  • Screenshot phase: runtime-screenshot
  • Screenshot argv: ["sh",".goocastle/capture-guix-package-screenshot.sh"]
  • Artifact path: .goocastle/evidence/issue-636.png
  • Artifact SHA-256: b41b1ce4a4f7af0620e3c8564d464721f35b1e5d499ab8cf6e5309d63c318c6b
  • Artifact commit: 1d627b366f6478d52e917dd2ee3e64543db604dd
  • Artifact size/format: 1775575 bytes / png

Imported from GitHub comment. Originally posted by htayj on 2026-08-28T17:18:59Z.

<!-- goocastle-runtime-evidence:sequential-reviewer:636:1 --> Goocastle verified runtime evidence. ![Runtime screenshot](https://github.com/htayj/guix-channel/blob/1d627b366f6478d52e917dd2ee3e64543db604dd/.goocastle/evidence/issue-636.png?raw=1) <details><summary>Runtime receipt</summary> - Package: <code>Guix package issue #636</code> - Safe package proof phase: <code>safe-package-proof</code> - Safe package proof argv: <code>[&quot;sh&quot;,&quot;.goocastle/prove-guix-package.sh&quot;]</code> - Screenshot phase: <code>runtime-screenshot</code> - Screenshot argv: <code>[&quot;sh&quot;,&quot;.goocastle/capture-guix-package-screenshot.sh&quot;]</code> - Artifact path: <code>.goocastle/evidence/issue-636.png</code> - Artifact SHA-256: <code>b41b1ce4a4f7af0620e3c8564d464721f35b1e5d499ab8cf6e5309d63c318c6b</code> - Artifact commit: <code>1d627b366f6478d52e917dd2ee3e64543db604dd</code> - Artifact size/format: <code>1775575 bytes / png</code> </details> --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5455553399). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T17:18:59Z.
htayj commented 2026-08-28 17:19:03 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-08-28T17:19:03Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5455553977). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T17:19:03Z.
htayj commented 2026-08-29 01:02:53 +00:00 (Migrated from github.com)

Evidence correction: the earlier artifact did not visibly demonstrate the packaged application.

The package has now been rebuilt and tests/clojure-roguelike-smoke.sh passed using a fresh HOME/XDG tree and a networkless user namespace. The launcher was then invoked directly through a PTY with q input; it exited successfully and rendered the map shown here: actual packaged Clojure Roguelike runtime screenshot.

This is program output from clojure-roguelike, rather than a build or smoke-test transcript.


Imported from GitHub comment. Originally posted by htayj on 2026-08-29T01:02:53Z.

Evidence correction: the earlier artifact did not visibly demonstrate the packaged application. The package has now been rebuilt and `tests/clojure-roguelike-smoke.sh` passed using a fresh HOME/XDG tree and a networkless user namespace. The launcher was then invoked directly through a PTY with `q` input; it exited successfully and rendered the map shown here: [actual packaged Clojure Roguelike runtime screenshot](https://github.com/htayj/guix-channel/blob/master/.goocastle/evidence/issue-636-runtime.png?raw=1). This is program output from `clojure-roguelike`, rather than a build or smoke-test transcript. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5459355973). Originally posted by [htayj](https://github.com/htayj) on 2026-08-29T01:02:53Z.
htayj commented 2026-08-29 01:02:54 +00:00 (Migrated from github.com)

Resolved after replacing the insufficient evidence with an inspected screenshot of the actual packaged program running.


Imported from GitHub comment. Originally posted by htayj on 2026-08-29T01:02:54Z.

Resolved after replacing the insufficient evidence with an inspected screenshot of the actual packaged program running. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/636#issuecomment-5459356062). Originally posted by [htayj](https://github.com/htayj) on 2026-08-29T01:02:54Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#636
No description provided.