Implement researched Guix package outcome for #457: [Guix packaging] NLarn #710

Closed
opened 2026-09-11 15:25:19 +00:00 by htayj · 2 comments
htayj commented 2026-09-11 15:25:19 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #457 ([Guix packaging] NLarn).

The host-validated research finding follows:

Canonical maintained source: https://github.com/nlarn/nlarn, release tag NLarn-0.8.0 at immutable commit 1873599a5682e4645e2801f7de6bd11ce54c2dfd; the GitHub tag archive fetched for this brief has SHA-256 8f671fcbcec9d662648707fce4318ae3b2c7c68535c85848b55f8af346dfe735. NLarn is an independently playable C/ncurses rewrite of Larn, not the parent game or a local channel duplicate; no equivalent nlarn package or index entry exists in the inspected channel. Upstream LICENSE, source headers, Makefile, and nlarn.spec identify the project and shipped game data as GPLv3. The Unix build path does not use the declared PDCurses submodule or bundled Fira Mono font; do not enable SDLPDCURSES. The installed closure should be audited as project GPLv3 code/data plus the explicitly marked bundled cJSON MIT code and enumFactory.h CC-BY-SA Stack Overflow adaptation, with LICENSE and matching third-party notices installed. Curses runtime data required by the Makefile/spec are lib/fortune*, lib/maze, lib/nlarn.hlp*, lib/nlarn.msg*, and generated locale catalogs; no sounds or tiles are consumed by this path. Use gnu-build-system with release configuration and inputs gcc-toolchain/make, pkg-config, glib, ncurses (wide curses and panel), zlib, and gettext/msgfmt; link math as upstream does. Remove or justify upstream -Werror only if the authorized Guix build exposes a warning. Package as tay/packages/nlarn.scm, patch the named /usr/share/nlarn default_lib_dir in src/nlarn.c to $out/share/nlarn (or keep the real binary beside a sibling lib directory), and keep all mutable state outside the store; do not enable upstream SETGID system-scoreboard behavior. Upstream runtime uses HOME/.nlarn for config/save data and a highscores file; focused source inspection found no updater, telemetry, runtime download, or network code. The deterministic runtime contract is nlarn --highscores, which exercises the normal Hall of Fame path and exits with stdout marker NLarn Hall of Fame; a fresh HOME makes the missing highscores read-only. Acceptance plan: run lint/build/check offline with no submodules and no opaque binaries; install all notices; in a fresh HOME/XDG directory, use bounded-validation PTY input to select New Game, enter a fixed character name/gender, make a movement, press Ctrl-S to save and exit, relaunch to continue the save, then quit, asserting the save/config files are only in the isolated user directory and there are no store writes; separately run the declared deterministic contract and capture .goocastle/evidence/issue-457.png. The research sandbox had no Guix daemon per phase boundary, so no package build, lint, runtime, or reproducibility proof is claimed here; those are authorized later-phase acceptance gates.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Runtime evidence contract

Implementation workflow: guix-package-quality-gates
Reviewed contract file: .goocastle/runtime-evidence-contracts.json
Required proof phase: safe-package-proof; screenshot phase: runtime-screenshot
Evidence adapter: github-issue-comment
Copy this reviewed contract into the named file before running the package proof workflow.

{
  "version": 1,
  "contracts": [
    {
      "issueNumber": 710,
      "packageName": "nlarn",
      "packageModulePath": "tay/packages/nlarn.scm",
      "artifactPath": ".goocastle/evidence/issue-710.png",
      "runtime": {
        "executable": "nlarn",
        "invocation": {
          "file": "nlarn",
          "args": [
            "--highscores"
          ]
        },
        "successMarker": "NLarn Hall of Fame"
      }
    }
  ]
}

Imported from GitHub issue/PR. Originally posted by htayj on 2026-09-11T15:25:19Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:457:1:implementation-ready --> ## Context This delivery ticket was created from research issue #457 ([Guix packaging] NLarn). The host-validated research finding follows: Canonical maintained source: https://github.com/nlarn/nlarn, release tag NLarn-0.8.0 at immutable commit 1873599a5682e4645e2801f7de6bd11ce54c2dfd; the GitHub tag archive fetched for this brief has SHA-256 8f671fcbcec9d662648707fce4318ae3b2c7c68535c85848b55f8af346dfe735. NLarn is an independently playable C/ncurses rewrite of Larn, not the parent game or a local channel duplicate; no equivalent `nlarn` package or index entry exists in the inspected channel. Upstream LICENSE, source headers, Makefile, and nlarn.spec identify the project and shipped game data as GPLv3. The Unix build path does not use the declared PDCurses submodule or bundled Fira Mono font; do not enable SDLPDCURSES. The installed closure should be audited as project GPLv3 code/data plus the explicitly marked bundled cJSON MIT code and enumFactory.h CC-BY-SA Stack Overflow adaptation, with LICENSE and matching third-party notices installed. Curses runtime data required by the Makefile/spec are lib/fortune*, lib/maze, lib/nlarn.hlp*, lib/nlarn.msg*, and generated locale catalogs; no sounds or tiles are consumed by this path. Use gnu-build-system with release configuration and inputs gcc-toolchain/make, pkg-config, glib, ncurses (wide curses and panel), zlib, and gettext/msgfmt; link math as upstream does. Remove or justify upstream -Werror only if the authorized Guix build exposes a warning. Package as `tay/packages/nlarn.scm`, patch the named `/usr/share/nlarn` default_lib_dir in src/nlarn.c to `$out/share/nlarn` (or keep the real binary beside a sibling lib directory), and keep all mutable state outside the store; do not enable upstream SETGID system-scoreboard behavior. Upstream runtime uses HOME/.nlarn for config/save data and a highscores file; focused source inspection found no updater, telemetry, runtime download, or network code. The deterministic runtime contract is `nlarn --highscores`, which exercises the normal Hall of Fame path and exits with stdout marker `NLarn Hall of Fame`; a fresh HOME makes the missing highscores read-only. Acceptance plan: run lint/build/check offline with no submodules and no opaque binaries; install all notices; in a fresh HOME/XDG directory, use bounded-validation PTY input to select New Game, enter a fixed character name/gender, make a movement, press Ctrl-S to save and exit, relaunch to continue the save, then quit, asserting the save/config files are only in the isolated user directory and there are no store writes; separately run the declared deterministic contract and capture `.goocastle/evidence/issue-457.png`. The research sandbox had no Guix daemon per phase boundary, so no package build, lint, runtime, or reproducibility proof is claimed here; those are authorized later-phase acceptance gates. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. <!-- goocastle-runtime-evidence-contract --> ## Runtime evidence contract Implementation workflow: `guix-package-quality-gates` Reviewed contract file: `.goocastle/runtime-evidence-contracts.json` Required proof phase: `safe-package-proof`; screenshot phase: `runtime-screenshot` Evidence adapter: `github-issue-comment` Copy this reviewed contract into the named file before running the package proof workflow. ```json { "version": 1, "contracts": [ { "issueNumber": 710, "packageName": "nlarn", "packageModulePath": "tay/packages/nlarn.scm", "artifactPath": ".goocastle/evidence/issue-710.png", "runtime": { "executable": "nlarn", "invocation": { "file": "nlarn", "args": [ "--highscores" ] }, "successMarker": "NLarn Hall of Fame" } } ] } ``` <!-- goocastle-runtime-evidence-contract-end --> --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/710). Originally posted by [htayj](https://github.com/htayj) on 2026-09-11T15:25:19Z.
htayj commented 2026-09-11 16:39:49 +00:00 (Migrated from github.com)

Goocastle verified runtime evidence.

Runtime screenshot

Runtime receipt
  • Package: nlarn
  • Safe package proof phase: safe-package-proof
  • Safe package proof argv: ["node","/opt/goocastle/bin/guix-package-proof.mjs","--package-name","nlarn","--module-path","tay/packages/nlarn.scm","--runtime-json","{&quot;executable&quot;:&quot;nlarn&quot;,&quot;invocation&quot;:{&quot;file&quot;:&quot;nlarn&quot;,&quot;args&quot;:[&quot;--highscores&quot;]},&quot;successMarker&quot;:&quot;NLarn Hall of Fame&quot;}"]
  • Screenshot phase: runtime-screenshot
  • Screenshot argv: ["sh",".goocastle/capture-guix-package-screenshot.sh"]
  • Runtime executable (Guix store/profile): /gnu/store/2bb19ym7w1d1myiqh41m4582asd7r6ax-nlarn-0.8.0/bin/nlarn
  • Runtime invocation: ["/gnu/store/2bb19ym7w1d1myiqh41m4582asd7r6ax-nlarn-0.8.0/bin/nlarn","--highscores"]
  • Expected runtime invocation: ["nlarn","--highscores"]
  • Expected runtime marker: NLarn Hall of Fame
  • Per-issue runtime contract: .goocastle/runtime-evidence-contracts.json (issue #710, SHA-256 bad58bc73d30b0718abfe1df2cda36d55aa9baf7f646992b867fe97b0bf93889)
  • Artifact path: .goocastle/evidence/issue-710.png
  • Artifact SHA-256: 385313b018691d8f63d543bc4206789cbc9bc5ee69451057251eea9e5c1d8148
  • Artifact commit: a8341e2caa3393e0823c7656a580c1cffd4ae5f2
  • Artifact size/format: 60907 bytes / png

Imported from GitHub comment. Originally posted by htayj on 2026-09-11T16:39:49Z.

<!-- goocastle-runtime-evidence:sequential-reviewer:710:1:385313b018691d8f63d543bc4206789cbc9bc5ee69451057251eea9e5c1d8148 --> Goocastle verified runtime evidence. ![Runtime screenshot](https://github.com/htayj/guix-channel/blob/a8341e2caa3393e0823c7656a580c1cffd4ae5f2/.goocastle/evidence/issue-710.png?raw=1) <details><summary>Runtime receipt</summary> - Package: <code>nlarn</code> - Safe package proof phase: <code>safe-package-proof</code> - Safe package proof argv: <code>[&quot;node&quot;,&quot;/opt/goocastle/bin/guix-package-proof.mjs&quot;,&quot;--package-name&quot;,&quot;nlarn&quot;,&quot;--module-path&quot;,&quot;tay/packages/nlarn.scm&quot;,&quot;--runtime-json&quot;,&quot;{\&quot;executable\&quot;:\&quot;nlarn\&quot;,\&quot;invocation\&quot;:{\&quot;file\&quot;:\&quot;nlarn\&quot;,\&quot;args\&quot;:[\&quot;--highscores\&quot;]},\&quot;successMarker\&quot;:\&quot;NLarn Hall of Fame\&quot;}&quot;]</code> - Screenshot phase: <code>runtime-screenshot</code> - Screenshot argv: <code>[&quot;sh&quot;,&quot;.goocastle/capture-guix-package-screenshot.sh&quot;]</code> - Runtime executable (Guix store/profile): <code>/gnu/store/2bb19ym7w1d1myiqh41m4582asd7r6ax-nlarn-0.8.0/bin/nlarn</code> - Runtime invocation: <code>[&quot;/gnu/store/2bb19ym7w1d1myiqh41m4582asd7r6ax-nlarn-0.8.0/bin/nlarn&quot;,&quot;--highscores&quot;]</code> - Expected runtime invocation: <code>[&quot;nlarn&quot;,&quot;--highscores&quot;]</code> - Expected runtime marker: <code>NLarn Hall of Fame</code> - Per-issue runtime contract: <code>.goocastle/runtime-evidence-contracts.json (issue #710, SHA-256 bad58bc73d30b0718abfe1df2cda36d55aa9baf7f646992b867fe97b0bf93889)</code> - Artifact path: <code>.goocastle/evidence/issue-710.png</code> - Artifact SHA-256: <code>385313b018691d8f63d543bc4206789cbc9bc5ee69451057251eea9e5c1d8148</code> - Artifact commit: <code>a8341e2caa3393e0823c7656a580c1cffd4ae5f2</code> - Artifact size/format: <code>60907 bytes / png</code> </details> --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/710#issuecomment-5637634999). Originally posted by [htayj](https://github.com/htayj) on 2026-09-11T16:39:49Z.
htayj commented 2026-09-11 16:39:53 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-09-11T16:39:53Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/710#issuecomment-5637635771). Originally posted by [htayj](https://github.com/htayj) on 2026-09-11T16:39:53Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#710
No description provided.