Implement researched Guix package outcome for #124: [Guix packaging] herdrdev/herdr #655

Closed
opened 2026-08-31 19:08:07 +00:00 by htayj · 1 comment
htayj commented 2026-08-31 19:08:07 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #124 ([Guix packaging] herdrdev/herdr).

The host-validated research finding follows:

Implementation-ready delivery brief for herdr. Canonical upstream is https://github.com/herdrdev/herdr; fetch the Git revision d76657f2c7fc18dcce3b9af43842c8afaba1646b from master, whose Cargo package version is 0.8.0. The intended Guix package name is herdr, in the terminal package module (gnu packages terminals), for x86_64-linux initially; the static Guix metadata confirms zig@0.15.2 for x86_64-linux, while aarch64 support should be added only after a matching Zig input is verified; build.rs maps those targets to x86_64-linux-gnu and aarch64-linux-gnu. The local channel and the issue's GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix 'R Us/RDE coverage check found no equivalent package with this upstream origin.

License and provenance are actionable but mixed: the pinned herdr tree's LICENSE is Apache-2.0; vendor/libghostty-vt.vendor.json records Ghostty source commit c5a21edfcbc2d5b46540ad91b7980aca31f5f1f3 and vendor/libghostty-vt/LICENSE grants MIT; vendor/portable-pty is portable-pty 0.9.0 from crates.io, fixed by the registry crate archive SHA-256 b4a596a2b3d2752d94f51fac2d4a96737b8705dddd311a32b9af47211f08671e, and its LICENSE.md grants MIT; the vendored SIMD closure uses uucode 0.2.0 from https://deps.files.ghostty.org/uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9.tar.gz (Zig content hash uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9; observed archive SHA-256 d0abee0f4f8bd6eae3c051777e16e7c42d8964aaaa015591c4e565703f465f95), whose LICENSE.md is MIT and whose bundled Unicode and Bjoern Hoehrmann notices are explicit; Highway is fixed at Google Highway commit 66486a10623fa0d72fe91260f96c892e41aceb06 via https://deps.files.ghostty.org/highway-66486a10623fa0d72fe91260f96c892e41aceb06.tar.gz (observed archive SHA-256 87d4f8893ef4e08f224973608ffebf94268a81380ba79c12e8841968c80aa212), with Apache-2.0 and BSD-3-Clause notices; checked-in simdutf is version 9.0.0, dual Apache-2.0/MIT, in vendor/libghostty-vt/pkg/simdutf/vendor/simdutf.h and .cpp. There are no Git submodules (.gitmodules is absent and git submodule status is empty). Retain root and all vendor notices in the source/output license material; do not install optional full-Ghostty GUI/test resources or invoke update/integration features without preserving their notices. In particular, the emit-lib-vt path avoids the GUI-only LGPL libintl dependency and the test-only CC BY-NC-SA shader, while vendor/libghostty-vt/pkg/afl++/LICENSE is MIT. Cargo.lock version 4 has only the crates.io registry source kind and fixes the Rust dependency closure by version/checksum; use those locked registry inputs and their package license metadata rather than treating the root Apache license as covering them.

The source build is technically viable offline. Cargo build.rs unconditionally invokes Zig and links a static ghostty-vt archive; rust-toolchain.toml and vendor/libghostty-vt/build.zig.zon require Zig 0.15.2. With the default ReleaseFast and SIMD=true settings, the Linux -Demit-lib-vt build requires the fixed uucode archive, local vendored simdutf 9.0.0, and the fixed Highway archive; GUI/full-executable lazy dependencies are not in this closure. Guix has a matching zig@0.15.2 package. Implement the package with cargo-build-system, Cargo.lock-driven cargo inputs, and native inputs at least zig@0.15.2, pkg-config, git, and zstd as needed to materialize the Zig cache. Precompute/package a fixed offline Zig global/system cache from vendor/libghostty-vt/build.zig.zon (equivalent to the pinned checkout's vendor/libghostty-vt/build.zig.zon.nix), and set ZIG to Zig 0.15.2, LIBGHOSTTY_VT_ZIG_SYSTEM_DIR to that cache, LIBGHOSTTY_VT_OPTIMIZE=ReleaseFast, and LIBGHOSTTY_VT_SIMD=true. The source fileset must include Cargo.toml, Cargo.lock, build.rs, src, vendor/libghostty-vt, vendor/libghostty-vt.vendor.json, vendor/portable-pty, the API schema, required assets/skills, README, LICENSE, and vendor notices. Do not permit Cargo or Zig network access during the build. The pinned upstream nix/package.nix and vendor/libghostty-vt/nix/libghostty-vt.nix demonstrate this cache/system-directory strategy, but are evidence of feasibility, not Guix package proof.

No installed runtime wrapper, system service, credentials, agent binary, or network endpoint is required. Install the single executable herdr. It starts the user-owned persistent server/session on normal use; the headless server owns local Unix sockets, restricts the socket to mode 0600, and uses HERDR_CONFIG_PATH and HERDR_SOCKET_PATH overrides. State/log/session files remain under the user's XDG config/state directories. Keep self-update, manifest-update, remote, and agent integrations explicit and unused by the package smoke; those features can reach the network or launch user-selected external programs, but --help and the local server/workspace API do not require them.

Deferred acceptance proof for the authorized Guix phase: run guix lint -L. herdr with no new errors; run guix build -L. herdr from this exact source with tests enabled where practical and an offline Cargo/Zig cache; run the Rust/Zig tests that do not require external agents, and run each external runtime check through node /opt/goocastle/bin/bounded-validation.mjs with argv-only execution. For the isolated smoke, set HOME/XDG config and state plus HERDR_CONFIG_PATH and HERDR_SOCKET_PATH beneath one validated temporary directory, run herdr --help and assert the exact stdout marker in runtimeEvidence, start herdr server, wait for the temporary local socket, assert herdr status server --json reports running, create one workspace with herdr workspace create --cwd --label guix-smoke --no-focus, assert the JSON response/list contains that label, close the returned workspace, and finish with herdr server stop. Use no agent command, credentials, update command, remote target, or network; assert the temporary socket is closed/removed and that any state/log files remain confined below the temporary directory. Research did not run guix build or guix shell because the trusted phase boundary declares the Guix daemon unavailable; cargo is also unavailable on this host, so no direct compile was claimed. The authoritative pinned Cargo/Zig metadata and the upstream offline-cache implementation are sufficient for handoff, with those exact acceptance commands left to the later daemon-backed phase.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Runtime evidence contract

Implementation workflow: guix-package-quality-gates
Reviewed contract file: .goocastle/runtime-evidence-contracts.json
Required proof phase: safe-package-proof; screenshot phase: runtime-screenshot
Evidence adapter: github-issue-comment
Copy this reviewed contract into the named file before running the package proof workflow.

{
  "version": 1,
  "contracts": [
    {
      "issueNumber": 655,
      "packageName": "herdr",
      "artifactPath": ".goocastle/evidence/issue-655.png",
      "runtime": {
        "executable": "herdr",
        "invocation": {
          "file": "herdr",
          "args": [
            "--help"
          ]
        },
        "successMarker": "herdr — terminal workspace manager for AI coding agents"
      }
    }
  ]
}

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-31T19:08:07Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:124:1:implementation-ready --> ## Context This delivery ticket was created from research issue #124 ([Guix packaging] herdrdev/herdr). The host-validated research finding follows: Implementation-ready delivery brief for herdr. Canonical upstream is https://github.com/herdrdev/herdr; fetch the Git revision d76657f2c7fc18dcce3b9af43842c8afaba1646b from master, whose Cargo package version is 0.8.0. The intended Guix package name is herdr, in the terminal package module (gnu packages terminals), for x86_64-linux initially; the static Guix metadata confirms zig@0.15.2 for x86_64-linux, while aarch64 support should be added only after a matching Zig input is verified; build.rs maps those targets to x86_64-linux-gnu and aarch64-linux-gnu. The local channel and the issue's GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix 'R Us/RDE coverage check found no equivalent package with this upstream origin. License and provenance are actionable but mixed: the pinned herdr tree's LICENSE is Apache-2.0; vendor/libghostty-vt.vendor.json records Ghostty source commit c5a21edfcbc2d5b46540ad91b7980aca31f5f1f3 and vendor/libghostty-vt/LICENSE grants MIT; vendor/portable-pty is portable-pty 0.9.0 from crates.io, fixed by the registry crate archive SHA-256 b4a596a2b3d2752d94f51fac2d4a96737b8705dddd311a32b9af47211f08671e, and its LICENSE.md grants MIT; the vendored SIMD closure uses uucode 0.2.0 from https://deps.files.ghostty.org/uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9.tar.gz (Zig content hash uucode-0.2.0-ZZjBPqZVVABQepOqZHR7vV_NcaN-wats0IB6o-Exj6m9; observed archive SHA-256 d0abee0f4f8bd6eae3c051777e16e7c42d8964aaaa015591c4e565703f465f95), whose LICENSE.md is MIT and whose bundled Unicode and Bjoern Hoehrmann notices are explicit; Highway is fixed at Google Highway commit 66486a10623fa0d72fe91260f96c892e41aceb06 via https://deps.files.ghostty.org/highway-66486a10623fa0d72fe91260f96c892e41aceb06.tar.gz (observed archive SHA-256 87d4f8893ef4e08f224973608ffebf94268a81380ba79c12e8841968c80aa212), with Apache-2.0 and BSD-3-Clause notices; checked-in simdutf is version 9.0.0, dual Apache-2.0/MIT, in vendor/libghostty-vt/pkg/simdutf/vendor/simdutf.h and .cpp. There are no Git submodules (.gitmodules is absent and git submodule status is empty). Retain root and all vendor notices in the source/output license material; do not install optional full-Ghostty GUI/test resources or invoke update/integration features without preserving their notices. In particular, the emit-lib-vt path avoids the GUI-only LGPL libintl dependency and the test-only CC BY-NC-SA shader, while vendor/libghostty-vt/pkg/afl++/LICENSE is MIT. Cargo.lock version 4 has only the crates.io registry source kind and fixes the Rust dependency closure by version/checksum; use those locked registry inputs and their package license metadata rather than treating the root Apache license as covering them. The source build is technically viable offline. Cargo build.rs unconditionally invokes Zig and links a static ghostty-vt archive; rust-toolchain.toml and vendor/libghostty-vt/build.zig.zon require Zig 0.15.2. With the default ReleaseFast and SIMD=true settings, the Linux -Demit-lib-vt build requires the fixed uucode archive, local vendored simdutf 9.0.0, and the fixed Highway archive; GUI/full-executable lazy dependencies are not in this closure. Guix has a matching zig@0.15.2 package. Implement the package with cargo-build-system, Cargo.lock-driven cargo inputs, and native inputs at least zig@0.15.2, pkg-config, git, and zstd as needed to materialize the Zig cache. Precompute/package a fixed offline Zig global/system cache from vendor/libghostty-vt/build.zig.zon (equivalent to the pinned checkout's vendor/libghostty-vt/build.zig.zon.nix), and set ZIG to Zig 0.15.2, LIBGHOSTTY_VT_ZIG_SYSTEM_DIR to that cache, LIBGHOSTTY_VT_OPTIMIZE=ReleaseFast, and LIBGHOSTTY_VT_SIMD=true. The source fileset must include Cargo.toml, Cargo.lock, build.rs, src, vendor/libghostty-vt, vendor/libghostty-vt.vendor.json, vendor/portable-pty, the API schema, required assets/skills, README, LICENSE, and vendor notices. Do not permit Cargo or Zig network access during the build. The pinned upstream nix/package.nix and vendor/libghostty-vt/nix/libghostty-vt.nix demonstrate this cache/system-directory strategy, but are evidence of feasibility, not Guix package proof. No installed runtime wrapper, system service, credentials, agent binary, or network endpoint is required. Install the single executable herdr. It starts the user-owned persistent server/session on normal use; the headless server owns local Unix sockets, restricts the socket to mode 0600, and uses HERDR_CONFIG_PATH and HERDR_SOCKET_PATH overrides. State/log/session files remain under the user's XDG config/state directories. Keep self-update, manifest-update, remote, and agent integrations explicit and unused by the package smoke; those features can reach the network or launch user-selected external programs, but --help and the local server/workspace API do not require them. Deferred acceptance proof for the authorized Guix phase: run guix lint -L. herdr with no new errors; run guix build -L. herdr from this exact source with tests enabled where practical and an offline Cargo/Zig cache; run the Rust/Zig tests that do not require external agents, and run each external runtime check through node /opt/goocastle/bin/bounded-validation.mjs with argv-only execution. For the isolated smoke, set HOME/XDG config and state plus HERDR_CONFIG_PATH and HERDR_SOCKET_PATH beneath one validated temporary directory, run herdr --help and assert the exact stdout marker in runtimeEvidence, start herdr server, wait for the temporary local socket, assert herdr status server --json reports running, create one workspace with herdr workspace create --cwd <temporary-empty-directory> --label guix-smoke --no-focus, assert the JSON response/list contains that label, close the returned workspace, and finish with herdr server stop. Use no agent command, credentials, update command, remote target, or network; assert the temporary socket is closed/removed and that any state/log files remain confined below the temporary directory. Research did not run guix build or guix shell because the trusted phase boundary declares the Guix daemon unavailable; cargo is also unavailable on this host, so no direct compile was claimed. The authoritative pinned Cargo/Zig metadata and the upstream offline-cache implementation are sufficient for handoff, with those exact acceptance commands left to the later daemon-backed phase. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. <!-- goocastle-runtime-evidence-contract --> ## Runtime evidence contract Implementation workflow: `guix-package-quality-gates` Reviewed contract file: `.goocastle/runtime-evidence-contracts.json` Required proof phase: `safe-package-proof`; screenshot phase: `runtime-screenshot` Evidence adapter: `github-issue-comment` Copy this reviewed contract into the named file before running the package proof workflow. ```json { "version": 1, "contracts": [ { "issueNumber": 655, "packageName": "herdr", "artifactPath": ".goocastle/evidence/issue-655.png", "runtime": { "executable": "herdr", "invocation": { "file": "herdr", "args": [ "--help" ] }, "successMarker": "herdr — terminal workspace manager for AI coding agents" } } ] } ``` <!-- goocastle-runtime-evidence-contract-end --> --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/655). Originally posted by [htayj](https://github.com/htayj) on 2026-08-31T19:08:07Z.
htayj commented 2026-08-31 20:51:11 +00:00 (Migrated from github.com)

Completed in signed commit fbf09d783a.

Verification passed:

  • guix build -L . --no-grafts herdr
  • fresh reproducibility rebuild: guix build -L . --no-grafts --check herdr
  • isolated, networkless package smoke test: the installed Herdr executable started its server, reported live JSON status, created/listed/closed a workspace, and stopped cleanly (HERDR_RUNTIME_OK).

Runtime evidence from the installed Guix store package (inspected before close):

Herdr server and workspace lifecycle


Imported from GitHub comment. Originally posted by htayj on 2026-08-31T20:51:11Z.

Completed in signed commit fbf09d783a220b253a5bd9dbb6721cccb44e6b0f. Verification passed: - `guix build -L . --no-grafts herdr` - fresh reproducibility rebuild: `guix build -L . --no-grafts --check herdr` - isolated, networkless package smoke test: the installed Herdr executable started its server, reported live JSON status, created/listed/closed a workspace, and stopped cleanly (`HERDR_RUNTIME_OK`). Runtime evidence from the installed Guix store package (inspected before close): ![Herdr server and workspace lifecycle](https://raw.githubusercontent.com/htayj/guix-channel/fbf09d783a220b253a5bd9dbb6721cccb44e6b0f/.goocastle/evidence/issue-655.png) --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/655#issuecomment-5484389995). Originally posted by [htayj](https://github.com/htayj) on 2026-08-31T20:51:11Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#655
No description provided.