Implement researched Guix package outcome for #329: [Guix packaging] Diabaig #674

Closed
opened 2026-09-02 19:49:09 +00:00 by htayj · 2 comments
htayj commented 2026-09-02 19:49:09 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #329 ([Guix packaging] Diabaig).

The host-validated research finding follows:

Canonical maintained upstream is https://github.com/conornally/diabaig. The latest stable upstream tag is diabaig-v1.0.1 at immutable commit b90d35847070d3de27d4656b3316e0e932884b25; VERSION.txt is 1.0.1, and the tag and main point to that commit. The fixed git checkout has SHA-256 Guix/Nix-base32 hash 1pw0c63bvn8yda694489547d8vw1bfddnacc04456i278rv45qdp. The author’s itch release/devlog at https://conornally.itch.io/diabaig and https://conornally.itch.io/diabaig/devlog/1045742/diabaig-v101-autoexplore-and-bug-fixes identifies v1.0.1 as released and supplies platform binaries, but this package must use the public source repository. At the fixed revision, LICENSE is the sole license file and states MIT License, copyright 2025 conornally; the git tree has no .gitmodules, submodules, language registries, vendored dependencies, or separately fetched origins. The source contains C code and embedded text resources, with no runtime fonts, tiles, sounds, maps, or bundled third-party code. Do not install the optional docs/images marketing artwork unless its coverage is separately confirmed; install the upstream LICENSE alongside docs/README.md, docs/guide.txt, res/credits.txt, and the Debian man page if those documents are shipped. This supports license:expat for the upstream origin and leaves no independent origin whose license must be audited. The Makefile has no configure, check, or test target; it builds on Linux with make, gcc, xxd-generated build/data_embedded.h, and -lncurses -lm. A read-only make -n all CC=gcc PLATFORM=linux completed and showed the full C compile/link plan. Use module (tay packages diabaig), package name diabaig, guix gnu-build-system with git-fetch at the fixed commit/hash, gcc-toolchain and xxd as native inputs, and ncurses as the runtime input; bash-minimal/coreutils-minimal plus a small Python PTY helper are appropriate package-owned wrapper inputs. The source build has no network or registry phase and must not use the itch prebuilt binaries. Exact official and local-channel queries for package name diabaig returned no equivalent; the local channel also has no Diabaig match, so this is not a duplicate. The research host has no Guix daemon and the trusted boundary forbids guix shell/build/lint here; the dry-run and authoritative metadata are feasibility evidence only, not package proof. Static inspection found no updater, telemetry, socket, download, or runtime network behavior. Upstream writes mutable files relative to its working directory: .diabaigrc, save/diabaig.save.N and save/diabaig.autosave, and diabaig.scr; verbose mode also hardcodes /tmp/diabaig.log. The launcher should keep the real binary private under libexec, set TERMINFO_DIRS to the declared ncurses input, run with cwd ${XDG_STATE_HOME:-$HOME/.local/state}/diabaig, avoid -v by default, and forward normal arguments, so state never targets the store. Add a package-owned --smoke mode with no extra arguments. It must use a fixed PTY of at least 78x33 and TERM=xterm-256color, run the real binary as diabaig -t -s 329, select New Game, enter a fixed player name and the default class, perform a legal movement plus inventory display, save to slot 1 with S/Enter/y, assert save/diabaig.save.1 and return to the home menu, select Continue then slot 1, assert the loaded message and inventory, quit with Q/y, leave the home menu with q, and assert cleanup of the autosave. Run this in fresh HOME/XDG config/data/cache/state/runtime and TMPDIR trees, capture a meaningful dungeon frame as .goocastle/evidence/issue-329.png, compare the package output/store metadata before and after to prove no store writes, and assert the single stdout line DIABAIG_RUNTIME_OK. Execute the final PTY/runtime validation only through the host bounded-validation argv executor. The source provides no automated upstream tests, so the isolated save/load flow is the meaningful acceptance smoke; later authorized Guix phases must perform lint, offline build, no-grafts check, and reproducibility verification.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Runtime evidence contract

Implementation workflow: guix-package-quality-gates
Reviewed contract file: .goocastle/runtime-evidence-contracts.json
Required proof phase: safe-package-proof; screenshot phase: runtime-screenshot
Evidence adapter: github-issue-comment
Copy this reviewed contract into the named file before running the package proof workflow.

{
  "version": 1,
  "contracts": [
    {
      "issueNumber": 674,
      "packageName": "diabaig",
      "artifactPath": ".goocastle/evidence/issue-674.png",
      "runtime": {
        "executable": "diabaig",
        "invocation": {
          "file": "diabaig",
          "args": [
            "--smoke"
          ]
        },
        "successMarker": "DIABAIG_RUNTIME_OK"
      }
    }
  ]
}

Imported from GitHub issue/PR. Originally posted by htayj on 2026-09-02T19:49:09Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:329:1:implementation-ready --> ## Context This delivery ticket was created from research issue #329 ([Guix packaging] Diabaig). The host-validated research finding follows: Canonical maintained upstream is https://github.com/conornally/diabaig. The latest stable upstream tag is diabaig-v1.0.1 at immutable commit b90d35847070d3de27d4656b3316e0e932884b25; VERSION.txt is 1.0.1, and the tag and main point to that commit. The fixed git checkout has SHA-256 Guix/Nix-base32 hash 1pw0c63bvn8yda694489547d8vw1bfddnacc04456i278rv45qdp. The author’s itch release/devlog at https://conornally.itch.io/diabaig and https://conornally.itch.io/diabaig/devlog/1045742/diabaig-v101-autoexplore-and-bug-fixes identifies v1.0.1 as released and supplies platform binaries, but this package must use the public source repository. At the fixed revision, LICENSE is the sole license file and states MIT License, copyright 2025 conornally; the git tree has no .gitmodules, submodules, language registries, vendored dependencies, or separately fetched origins. The source contains C code and embedded text resources, with no runtime fonts, tiles, sounds, maps, or bundled third-party code. Do not install the optional docs/images marketing artwork unless its coverage is separately confirmed; install the upstream LICENSE alongside docs/README.md, docs/guide.txt, res/credits.txt, and the Debian man page if those documents are shipped. This supports license:expat for the upstream origin and leaves no independent origin whose license must be audited. The Makefile has no configure, check, or test target; it builds on Linux with make, gcc, xxd-generated build/data_embedded.h, and -lncurses -lm. A read-only make -n all CC=gcc PLATFORM=linux completed and showed the full C compile/link plan. Use module (tay packages diabaig), package name diabaig, guix gnu-build-system with git-fetch at the fixed commit/hash, gcc-toolchain and xxd as native inputs, and ncurses as the runtime input; bash-minimal/coreutils-minimal plus a small Python PTY helper are appropriate package-owned wrapper inputs. The source build has no network or registry phase and must not use the itch prebuilt binaries. Exact official and local-channel queries for package name diabaig returned no equivalent; the local channel also has no Diabaig match, so this is not a duplicate. The research host has no Guix daemon and the trusted boundary forbids guix shell/build/lint here; the dry-run and authoritative metadata are feasibility evidence only, not package proof. Static inspection found no updater, telemetry, socket, download, or runtime network behavior. Upstream writes mutable files relative to its working directory: .diabaigrc, save/diabaig.save.N and save/diabaig.autosave, and diabaig.scr; verbose mode also hardcodes /tmp/diabaig.log. The launcher should keep the real binary private under libexec, set TERMINFO_DIRS to the declared ncurses input, run with cwd ${XDG_STATE_HOME:-$HOME/.local/state}/diabaig, avoid -v by default, and forward normal arguments, so state never targets the store. Add a package-owned --smoke mode with no extra arguments. It must use a fixed PTY of at least 78x33 and TERM=xterm-256color, run the real binary as diabaig -t -s 329, select New Game, enter a fixed player name and the default class, perform a legal movement plus inventory display, save to slot 1 with S/Enter/y, assert save/diabaig.save.1 and return to the home menu, select Continue then slot 1, assert the loaded message and inventory, quit with Q/y, leave the home menu with q, and assert cleanup of the autosave. Run this in fresh HOME/XDG config/data/cache/state/runtime and TMPDIR trees, capture a meaningful dungeon frame as .goocastle/evidence/issue-329.png, compare the package output/store metadata before and after to prove no store writes, and assert the single stdout line DIABAIG_RUNTIME_OK. Execute the final PTY/runtime validation only through the host bounded-validation argv executor. The source provides no automated upstream tests, so the isolated save/load flow is the meaningful acceptance smoke; later authorized Guix phases must perform lint, offline build, no-grafts check, and reproducibility verification. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. <!-- goocastle-runtime-evidence-contract --> ## Runtime evidence contract Implementation workflow: `guix-package-quality-gates` Reviewed contract file: `.goocastle/runtime-evidence-contracts.json` Required proof phase: `safe-package-proof`; screenshot phase: `runtime-screenshot` Evidence adapter: `github-issue-comment` Copy this reviewed contract into the named file before running the package proof workflow. ```json { "version": 1, "contracts": [ { "issueNumber": 674, "packageName": "diabaig", "artifactPath": ".goocastle/evidence/issue-674.png", "runtime": { "executable": "diabaig", "invocation": { "file": "diabaig", "args": [ "--smoke" ] }, "successMarker": "DIABAIG_RUNTIME_OK" } } ] } ``` <!-- goocastle-runtime-evidence-contract-end --> --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/674). Originally posted by [htayj](https://github.com/htayj) on 2026-09-02T19:49:09Z.
htayj commented 2026-09-02 20:54:07 +00:00 (Migrated from github.com)

Goocastle verified runtime evidence.

Runtime screenshot

Runtime receipt
  • Package: diabaig
  • Safe package proof phase: safe-package-proof
  • Safe package proof argv: ["sh",".goocastle/prove-guix-package.sh"]
  • Screenshot phase: runtime-screenshot
  • Screenshot argv: ["sh",".goocastle/capture-guix-package-screenshot.sh"]
  • Runtime executable (Guix store/profile): /gnu/store/h5nyyny9a1f874a8fn4wc4r4sdrkvvc9-diabaig-1.0.1/bin/diabaig
  • Runtime invocation: ["/gnu/store/h5nyyny9a1f874a8fn4wc4r4sdrkvvc9-diabaig-1.0.1/bin/diabaig","--smoke"]
  • Expected runtime invocation: ["diabaig","--smoke"]
  • Expected runtime marker: DIABAIG_RUNTIME_OK
  • Per-issue runtime contract: .goocastle/runtime-evidence-contracts.json (issue #674, SHA-256 526e45853c44111f83cd0360f9c9ca2f6af3c32de72811158fd491d10887b5b4)
  • Artifact path: .goocastle/evidence/issue-674.png
  • Artifact SHA-256: b64542cf3fa345a7feaf8eb724b79751eb8be2ee8b51e2951bbcc61a0c7f58b9
  • Artifact commit: f53064972e958b2d01d14972cc9daf5ed24a5e47
  • Artifact size/format: 30230 bytes / png

Imported from GitHub comment. Originally posted by htayj on 2026-09-02T20:54:07Z.

<!-- goocastle-runtime-evidence:sequential-reviewer:674:1:b64542cf3fa345a7feaf8eb724b79751eb8be2ee8b51e2951bbcc61a0c7f58b9 --> Goocastle verified runtime evidence. ![Runtime screenshot](https://github.com/htayj/guix-channel/blob/f53064972e958b2d01d14972cc9daf5ed24a5e47/.goocastle/evidence/issue-674.png?raw=1) <details><summary>Runtime receipt</summary> - Package: <code>diabaig</code> - Safe package proof phase: <code>safe-package-proof</code> - Safe package proof argv: <code>[&quot;sh&quot;,&quot;.goocastle/prove-guix-package.sh&quot;]</code> - Screenshot phase: <code>runtime-screenshot</code> - Screenshot argv: <code>[&quot;sh&quot;,&quot;.goocastle/capture-guix-package-screenshot.sh&quot;]</code> - Runtime executable (Guix store/profile): <code>/gnu/store/h5nyyny9a1f874a8fn4wc4r4sdrkvvc9-diabaig-1.0.1/bin/diabaig</code> - Runtime invocation: <code>[&quot;/gnu/store/h5nyyny9a1f874a8fn4wc4r4sdrkvvc9-diabaig-1.0.1/bin/diabaig&quot;,&quot;--smoke&quot;]</code> - Expected runtime invocation: <code>[&quot;diabaig&quot;,&quot;--smoke&quot;]</code> - Expected runtime marker: <code>DIABAIG_RUNTIME_OK</code> - Per-issue runtime contract: <code>.goocastle/runtime-evidence-contracts.json (issue #674, SHA-256 526e45853c44111f83cd0360f9c9ca2f6af3c32de72811158fd491d10887b5b4)</code> - Artifact path: <code>.goocastle/evidence/issue-674.png</code> - Artifact SHA-256: <code>b64542cf3fa345a7feaf8eb724b79751eb8be2ee8b51e2951bbcc61a0c7f58b9</code> - Artifact commit: <code>f53064972e958b2d01d14972cc9daf5ed24a5e47</code> - Artifact size/format: <code>30230 bytes / png</code> </details> --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/674#issuecomment-5516256541). Originally posted by [htayj](https://github.com/htayj) on 2026-09-02T20:54:07Z.
htayj commented 2026-09-02 20:54:12 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-09-02T20:54:12Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/674#issuecomment-5516257491). Originally posted by [htayj](https://github.com/htayj) on 2026-09-02T20:54:12Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#674
No description provided.