Implement researched Guix package outcome for #331: [Guix packaging] dNetHack #679

Closed
opened 2026-09-02 23:09:29 +00:00 by htayj · 2 comments
htayj commented 2026-09-02 23:09:29 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #331 ([Guix packaging] dNetHack).

The host-validated research finding follows:

Package the ordinary dNetHack variant as Guix package dnethack from the canonical maintained repository https://github.com/Chris-plus-alphanumericgibberish/dNAO, stable branch compat-3.26.0, fixed commit a6f0a1c43e66f4fb1bcac34d7d9709706682ec19 (2026-05-28 18:03:32 UTC), internal version 3.26.0, Guix recursive source hash 0lakz0czfkymnnb64q7yjvm3r3yfj3xqbylrha3cpc2ix07x0cvj. The only upstream tag is the older v3.21.3.1; the default/current stable branch is the materially newer 3.26.0 line. Upstream README and GNUmakefile establish a Unix source build: make all compiles the C tty/curses game and recover utility, regenerates yacc/flex products, generates dat/nhdat from the repository's maps/data, and links only pkg-config --libs ncursesw plus -lm; git submodule status is empty and there is no language registry or runtime download. This phase was explicitly daemonless, so no guix build or upstream compile was attempted and this is not package proof. Implement with gnu-build-system, no configure phase, serialized generation/build if needed, native bison/flex/pkg-config plus the standard GCC toolchain, and ncurses (including the tinfo linkage as exposed by the Guix ncurses package); use bash-minimal/coreutils-minimal only for the launcher. Do not run upstream make install: install the built executable as libexec data, nhdat and the NGPL notice under share/dnethack, and retained upstream documentation under share/doc/dnethack. Override the makefile's Git description with the fixed revision and patch util/makedefs.c's wall-clock time() input to the pinned commit epoch 1779991412 so generated date/verinfo/data and --check are reproducible. Upstream README at the pinned source says dNetHack is under the NetHack General Public License; dat/license contains the exact grant and generated map/data source files carry the same NetHack redistribution notice. The Unix target installs no fonts, graphical tiles, sound samples, or submodules; util/MacroMagicMarker.py is separately MIT-licensed but is not an installed runtime origin. Retain dat/license, README, Guidebook.txt, and relevant man/documentation notices. The local channel audit found no dNetHack/dNAO package or same-upstream module; acehack is a separate historical variant and is not a duplicate. The wrapper named dnethack must create a per-invocation private playground, expose immutable nhdat/license from the store by symlink, keep saves, locks, scores, logs, dumps, panic/hangup and other mutable files under $XDG_DATA_HOME/dnethack (falling back to HOME), set HACKDIR/NETHACKDIR to that playground, and never write the store. Disable the compiled Unix MAIL feature or otherwise bind mailbox checks to private state, leave the upstream shell escape disabled, and do not invoke updater, telemetry, network, or runtime-download behavior (static inspection found none). For the isolated proof, the wrapper's --guix-smoke mode must run the real tty/curses executable twice in a fresh temporary playground: start a fully specified discovery character with -X -n -u goocastle-tourist-human-neutral-male, perform a movement/rest command and save/confirm, relaunch the same character, confirm restoration, quit/confirm, assert the save/load and mutable-file checks, then print the standalone marker dnethack guix smoke passed. The host runtime proof must call only the reviewed dnethack --guix-smoke contract under a fresh HOME/XDG environment via bounded PTY validation and verify the screenshot and absence of store writes; later delivery must also run upstream tests where available, guix lint, offline no-grafts build, and reproducibility check.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Runtime evidence contract

Implementation workflow: guix-package-quality-gates
Reviewed contract file: .goocastle/runtime-evidence-contracts.json
Required proof phase: safe-package-proof; screenshot phase: runtime-screenshot
Evidence adapter: github-issue-comment
Copy this reviewed contract into the named file before running the package proof workflow.

{
  "version": 1,
  "contracts": [
    {
      "issueNumber": 679,
      "packageName": "dnethack",
      "artifactPath": ".goocastle/evidence/issue-679.png",
      "runtime": {
        "executable": "dnethack",
        "invocation": {
          "file": "dnethack",
          "args": [
            "--guix-smoke"
          ]
        },
        "successMarker": "dnethack guix smoke passed"
      }
    }
  ]
}

Imported from GitHub issue/PR. Originally posted by htayj on 2026-09-02T23:09:29Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:331:1:implementation-ready --> ## Context This delivery ticket was created from research issue #331 ([Guix packaging] dNetHack). The host-validated research finding follows: Package the ordinary dNetHack variant as Guix package `dnethack` from the canonical maintained repository https://github.com/Chris-plus-alphanumericgibberish/dNAO, stable branch `compat-3.26.0`, fixed commit `a6f0a1c43e66f4fb1bcac34d7d9709706682ec19` (2026-05-28 18:03:32 UTC), internal version 3.26.0, Guix recursive source hash `0lakz0czfkymnnb64q7yjvm3r3yfj3xqbylrha3cpc2ix07x0cvj`. The only upstream tag is the older v3.21.3.1; the default/current stable branch is the materially newer 3.26.0 line. Upstream README and GNUmakefile establish a Unix source build: `make all` compiles the C tty/curses game and recover utility, regenerates yacc/flex products, generates `dat/nhdat` from the repository's maps/data, and links only `pkg-config --libs ncursesw` plus `-lm`; `git submodule status` is empty and there is no language registry or runtime download. This phase was explicitly daemonless, so no guix build or upstream compile was attempted and this is not package proof. Implement with `gnu-build-system`, no configure phase, serialized generation/build if needed, native bison/flex/pkg-config plus the standard GCC toolchain, and ncurses (including the tinfo linkage as exposed by the Guix ncurses package); use bash-minimal/coreutils-minimal only for the launcher. Do not run upstream `make install`: install the built executable as libexec data, `nhdat` and the NGPL notice under `share/dnethack`, and retained upstream documentation under `share/doc/dnethack`. Override the makefile's Git description with the fixed revision and patch `util/makedefs.c`'s wall-clock `time()` input to the pinned commit epoch `1779991412` so generated date/verinfo/data and `--check` are reproducible. Upstream README at the pinned source says dNetHack is under the NetHack General Public License; `dat/license` contains the exact grant and generated map/data source files carry the same NetHack redistribution notice. The Unix target installs no fonts, graphical tiles, sound samples, or submodules; `util/MacroMagicMarker.py` is separately MIT-licensed but is not an installed runtime origin. Retain `dat/license`, README, Guidebook.txt, and relevant man/documentation notices. The local channel audit found no dNetHack/dNAO package or same-upstream module; `acehack` is a separate historical variant and is not a duplicate. The wrapper named `dnethack` must create a per-invocation private playground, expose immutable `nhdat`/license from the store by symlink, keep saves, locks, scores, logs, dumps, panic/hangup and other mutable files under `$XDG_DATA_HOME/dnethack` (falling back to HOME), set HACKDIR/NETHACKDIR to that playground, and never write the store. Disable the compiled Unix MAIL feature or otherwise bind mailbox checks to private state, leave the upstream shell escape disabled, and do not invoke updater, telemetry, network, or runtime-download behavior (static inspection found none). For the isolated proof, the wrapper's `--guix-smoke` mode must run the real tty/curses executable twice in a fresh temporary playground: start a fully specified discovery character with `-X -n -u goocastle-tourist-human-neutral-male`, perform a movement/rest command and save/confirm, relaunch the same character, confirm restoration, quit/confirm, assert the save/load and mutable-file checks, then print the standalone marker `dnethack guix smoke passed`. The host runtime proof must call only the reviewed `dnethack --guix-smoke` contract under a fresh HOME/XDG environment via bounded PTY validation and verify the screenshot and absence of store writes; later delivery must also run upstream tests where available, guix lint, offline no-grafts build, and reproducibility check. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. <!-- goocastle-runtime-evidence-contract --> ## Runtime evidence contract Implementation workflow: `guix-package-quality-gates` Reviewed contract file: `.goocastle/runtime-evidence-contracts.json` Required proof phase: `safe-package-proof`; screenshot phase: `runtime-screenshot` Evidence adapter: `github-issue-comment` Copy this reviewed contract into the named file before running the package proof workflow. ```json { "version": 1, "contracts": [ { "issueNumber": 679, "packageName": "dnethack", "artifactPath": ".goocastle/evidence/issue-679.png", "runtime": { "executable": "dnethack", "invocation": { "file": "dnethack", "args": [ "--guix-smoke" ] }, "successMarker": "dnethack guix smoke passed" } } ] } ``` <!-- goocastle-runtime-evidence-contract-end --> --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/679). Originally posted by [htayj](https://github.com/htayj) on 2026-09-02T23:09:29Z.
htayj commented 2026-09-03 01:34:04 +00:00 (Migrated from github.com)

Goocastle verified runtime evidence.

Runtime screenshot

Runtime receipt
  • Package: dnethack
  • Safe package proof phase: safe-package-proof
  • Safe package proof argv: ["sh",".goocastle/prove-guix-package.sh"]
  • Screenshot phase: runtime-screenshot
  • Screenshot argv: ["sh",".goocastle/capture-guix-package-screenshot.sh"]
  • Runtime executable (Guix store/profile): /gnu/store/zpmr7c6bbxvifwl724sdgi740xlfi58g-dnethack-3.26.0/bin/dnethack
  • Runtime invocation: ["/gnu/store/zpmr7c6bbxvifwl724sdgi740xlfi58g-dnethack-3.26.0/bin/dnethack","--guix-smoke"]
  • Expected runtime invocation: ["dnethack","--guix-smoke"]
  • Expected runtime marker: dnethack guix smoke passed
  • Per-issue runtime contract: .goocastle/runtime-evidence-contracts.json (issue #679, SHA-256 7cbb33bd39b00297e10384dece4cc5e6407000ce3b777e5aead8bbdc384966cb)
  • Artifact path: .goocastle/evidence/issue-679.png
  • Artifact SHA-256: a20fa153019632f9e906435f775c766eda377c72ea8572802c93173f5d578cd1
  • Artifact commit: 09b2c78e9c97c9059bc3818cfc8e2e272b09cb80
  • Artifact size/format: 22674 bytes / png

Imported from GitHub comment. Originally posted by htayj on 2026-09-03T01:34:04Z.

<!-- goocastle-runtime-evidence:sequential-reviewer:679:1:a20fa153019632f9e906435f775c766eda377c72ea8572802c93173f5d578cd1 --> Goocastle verified runtime evidence. ![Runtime screenshot](https://github.com/htayj/guix-channel/blob/09b2c78e9c97c9059bc3818cfc8e2e272b09cb80/.goocastle/evidence/issue-679.png?raw=1) <details><summary>Runtime receipt</summary> - Package: <code>dnethack</code> - Safe package proof phase: <code>safe-package-proof</code> - Safe package proof argv: <code>[&quot;sh&quot;,&quot;.goocastle/prove-guix-package.sh&quot;]</code> - Screenshot phase: <code>runtime-screenshot</code> - Screenshot argv: <code>[&quot;sh&quot;,&quot;.goocastle/capture-guix-package-screenshot.sh&quot;]</code> - Runtime executable (Guix store/profile): <code>/gnu/store/zpmr7c6bbxvifwl724sdgi740xlfi58g-dnethack-3.26.0/bin/dnethack</code> - Runtime invocation: <code>[&quot;/gnu/store/zpmr7c6bbxvifwl724sdgi740xlfi58g-dnethack-3.26.0/bin/dnethack&quot;,&quot;--guix-smoke&quot;]</code> - Expected runtime invocation: <code>[&quot;dnethack&quot;,&quot;--guix-smoke&quot;]</code> - Expected runtime marker: <code>dnethack guix smoke passed</code> - Per-issue runtime contract: <code>.goocastle/runtime-evidence-contracts.json (issue #679, SHA-256 7cbb33bd39b00297e10384dece4cc5e6407000ce3b777e5aead8bbdc384966cb)</code> - Artifact path: <code>.goocastle/evidence/issue-679.png</code> - Artifact SHA-256: <code>a20fa153019632f9e906435f775c766eda377c72ea8572802c93173f5d578cd1</code> - Artifact commit: <code>09b2c78e9c97c9059bc3818cfc8e2e272b09cb80</code> - Artifact size/format: <code>22674 bytes / png</code> </details> --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/679#issuecomment-5518963689). Originally posted by [htayj](https://github.com/htayj) on 2026-09-03T01:34:04Z.
htayj commented 2026-09-03 01:34:08 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-09-03T01:34:08Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/679#issuecomment-5518964196). Originally posted by [htayj](https://github.com/htayj) on 2026-09-03T01:34:08Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#679
No description provided.