[Guix packaging] MetricsHub/winrm-java #77

Open
opened 2026-08-14 13:17:04 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:04 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/MetricsHub/winrm-java
  • Source pinned commit/release when known: ac4521509ad5056f6739078c4fd34b8ad3d22cf8 on main (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: WinRM Java client library and its winrm command-line examples
  • Primary category: networking-client
  • Tags: None
  • Primary language normalized: Java
  • Build system: Maven (pom.xml; Java 11 release)
  • SPDX expression: Apache-2.0
  • License status: confirmed-free
  • License evidence: LICENSE contains Apache-2.0 and pom.xml declares Apache-2.0.
  • Difficulty: moderate — Resolve the Maven parent/dependency closure and exercise NTLM/Kerberos and TLS certificate-validation paths without a live server.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Resolve the Maven parent/dependency closure and exercise NTLM/Kerberos and TLS certificate-validation paths without a live server.

Acceptance checks

  • guix lint -L. winrm-java passes with no new errors.
  • guix build -L. winrm-java succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Run mvn test offline from the fixed source tree and a Java smoke test that parses --help/constructs a client without connecting.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:04Z.

## Candidate - Upstream canonical URL: https://github.com/MetricsHub/winrm-java - Source pinned commit/release when known: `ac4521509ad5056f6739078c4fd34b8ad3d22cf8` on `main` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: WinRM Java client library and its `winrm` command-line examples - Primary category: networking-client - Tags: None - Primary language normalized: Java - Build system: Maven (`pom.xml`; Java 11 release) - SPDX expression: Apache-2.0 - License status: confirmed-free - License evidence: `LICENSE` contains Apache-2.0 and `pom.xml` declares Apache-2.0. - Difficulty: moderate — Resolve the Maven parent/dependency closure and exercise NTLM/Kerberos and TLS certificate-validation paths without a live server. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Resolve the Maven parent/dependency closure and exercise NTLM/Kerberos and TLS certificate-validation paths without a live server. ## Acceptance checks - `guix lint -L. winrm-java` passes with no new errors. - `guix build -L. winrm-java` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Run `mvn test` offline from the fixed source tree and a Java smoke test that parses `--help`/constructs a client without connecting. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/77). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:04Z.
htayj commented 2026-08-26 09:57:23 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #627.

Implement an installable Guix package for the canonical upstream project https://github.com/MetricsHub/winrm-java at the exact pinned commit ac4521509ad5056f6739078c4fd34b8ad3d22cf8 (GitHub source hash 08d039fgr8ymjib9kfm0y2l8k2qd95h1mdn9p68bc8krqjrqhv18). The POM at that revision identifies version 2.2.00-SNAPSHOT, Java release 11, and the pinned commit is the post-v2.1.00 main-branch merge snapshot; fetch only that revision. The repository has no Git submodules or other separately checked-out source trees. Its root LICENSE is the complete Apache License 2.0, the POM declares Apache-2.0, and Java sources carry Apache headers; preserve LICENSE, README.md, and notices in the output. The project is source-buildable with Maven and has no runtime library dependencies: the regular JAR is sufficient, while the upstream shade/quality/site/reporting configuration is not required for the deliverable. No equivalent package with this upstream origin exists in the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix R Us/RDE coverage; python-pywinrm is a different implementation and is not an equivalent. Define winrm-java in a new tay/packages/winrm-java.scm using (tay packages winrm-java), so guix build -L. winrm-java resolves the package. Use maven-build-system with the exact GitHub source, #:jdk openjdk17 for the JUnit 6 test runtime, while retaining upstream --release 11; include the Maven 3.9.0/build-system plugin inputs plus fixed Maven inputs for org.metricshub:oss-parent:5, com.github.spotbugs:spotbugs-annotations:4.10.3 (provided/build-only), org.junit:junit-bom:6.1.3, org.junit.platform:junit-platform-launcher:6.1.3, org.junit.jupiter:junit-jupiter-engine:6.1.3, and their fixed closure org.junit.jupiter:junit-jupiter-api:6.1.3, org.junit.platform:junit-platform-engine:6.1.3, org.junit.platform:junit-platform-commons:6.1.3, org.apiguardian:apiguardian-api:1.1.2, org.opentest4j:opentest4j:1.3.0, and org.jspecify:jspecify:1.0.0. The separately fetched helper-origin evidence is: MetricsHub/oss-parent tag v5 peeled to commit 2b9a7fb05c09ac96136c2cc79477c734b65613d5, whose exact-revision LICENSE and POM grant Apache-2.0; junit-team/junit-framework tag r6.1.3 peeled to f59f60d2cebdf2224235d81f781b1f310cbc8138, whose exact-revision LICENSE.md grants EPL-2.0 and NOTICE records component notices; and spotbugs/spotbugs tag 4.10.3 peeled to 8d5cad4536ae263448c09181268bbca70f0c0712, whose exact-revision root LICENSE grants LGPL-2.1. The fixed Maven closure coordinates have explicit POM license grants at those revisions: apiguardian-api 1.1.2 Apache-2.0, opentest4j 1.3.0 Apache-2.0, and jspecify 1.0.0 Apache-2.0; retain the associated license files/notices when introducing any new Guix inputs. Exclude or neutralize unavailable upstream-only formatter, PMD, Checkstyle, SpotBugs, site, release, source/javadoc/license, and failsafe/reporting executions (including net.revelc.code.formatter:formatter-maven-plugin, org.codehaus.mojo:license-maven-plugin, org.apache.maven.plugins:maven-site-plugin/maven-source-plugin/maven-javadoc-plugin/maven-pmd-plugin/maven-checkstyle-plugin/maven-release-plugin/maven-artifact-plugin/maven-failsafe-plugin, com.github.spotbugs:spotbugs-maven-plugin, and site skin tooling) while keeping compile, resource, JAR, and unit-test phases; do not add the shade plugin solely for the standalone artifact because the upstream README documents zero runtime dependencies. Install the regular JAR under share/java/winrm-java.jar and provide bin/winrm as a fixed-runtime wrapper using openjdk11 to invoke org.metricshub.winrm.cli.WinRmCli with all user arguments; install upstream README.md and LICENSE under share/doc/winrm-java. The package has no service, daemon, downloaded asset, credential, or optional integration requirement. Runtime network access occurs only when a WinRM operation is executed; --help/--version and client construction must not connect. Preserve the explicit security behavior: HTTPS certificate and hostname validation is enabled by default, Kerberos/NTLM selection and ticket-cache/truststore paths are supplied by the user, and trustAllCertificates/--https-permissive is an explicit insecure opt-in. The isolated smoke proof must use a temporary HOME and no live-server properties, run Maven tests offline from the fixed tree with mvn test -o (or the equivalent Guix phase), including WsmanProtocolTest's in-process fake-server NTLM/encrypted-framing/WQL/command lifecycle coverage, LightTlsTest's default-validation and explicit-insecure assertions, FallbackAuthSchemeTest's Kerberos-to-NTLM fallback without a KDC, WinRMClientBuilderTest's no-connect and validation cases, and CLI argument parsing; leave disabled WinRMLiveTest disabled. Then package offline, run the wrapper with --help and --version, and compile/run a tiny Java 11 smoke class against the installed JAR that builds WinRMClient.builder("host").https().port(5987).build() without invoking an operation, while asserting no socket connection is attempted. Final acceptance is guix lint -L. winrm-java with no new errors and guix build -L. winrm-java succeeding with the offline tests enabled where practical; record those command results as implementation acceptance, not as research proof.


Imported from GitHub comment. Originally posted by htayj on 2026-08-26T09:57:23Z.

<!-- goocastle-disposition:sequential-reviewer:77:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #627. Implement an installable Guix package for the canonical upstream project https://github.com/MetricsHub/winrm-java at the exact pinned commit ac4521509ad5056f6739078c4fd34b8ad3d22cf8 (GitHub source hash 08d039fgr8ymjib9kfm0y2l8k2qd95h1mdn9p68bc8krqjrqhv18). The POM at that revision identifies version 2.2.00-SNAPSHOT, Java release 11, and the pinned commit is the post-v2.1.00 main-branch merge snapshot; fetch only that revision. The repository has no Git submodules or other separately checked-out source trees. Its root LICENSE is the complete Apache License 2.0, the POM declares Apache-2.0, and Java sources carry Apache headers; preserve LICENSE, README.md, and notices in the output. The project is source-buildable with Maven and has no runtime library dependencies: the regular JAR is sufficient, while the upstream shade/quality/site/reporting configuration is not required for the deliverable. No equivalent package with this upstream origin exists in the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix R Us/RDE coverage; python-pywinrm is a different implementation and is not an equivalent. Define winrm-java in a new tay/packages/winrm-java.scm using (tay packages winrm-java), so guix build -L. winrm-java resolves the package. Use maven-build-system with the exact GitHub source, #:jdk openjdk17 for the JUnit 6 test runtime, while retaining upstream --release 11; include the Maven 3.9.0/build-system plugin inputs plus fixed Maven inputs for org.metricshub:oss-parent:5, com.github.spotbugs:spotbugs-annotations:4.10.3 (provided/build-only), org.junit:junit-bom:6.1.3, org.junit.platform:junit-platform-launcher:6.1.3, org.junit.jupiter:junit-jupiter-engine:6.1.3, and their fixed closure org.junit.jupiter:junit-jupiter-api:6.1.3, org.junit.platform:junit-platform-engine:6.1.3, org.junit.platform:junit-platform-commons:6.1.3, org.apiguardian:apiguardian-api:1.1.2, org.opentest4j:opentest4j:1.3.0, and org.jspecify:jspecify:1.0.0. The separately fetched helper-origin evidence is: MetricsHub/oss-parent tag v5 peeled to commit 2b9a7fb05c09ac96136c2cc79477c734b65613d5, whose exact-revision LICENSE and POM grant Apache-2.0; junit-team/junit-framework tag r6.1.3 peeled to f59f60d2cebdf2224235d81f781b1f310cbc8138, whose exact-revision LICENSE.md grants EPL-2.0 and NOTICE records component notices; and spotbugs/spotbugs tag 4.10.3 peeled to 8d5cad4536ae263448c09181268bbca70f0c0712, whose exact-revision root LICENSE grants LGPL-2.1. The fixed Maven closure coordinates have explicit POM license grants at those revisions: apiguardian-api 1.1.2 Apache-2.0, opentest4j 1.3.0 Apache-2.0, and jspecify 1.0.0 Apache-2.0; retain the associated license files/notices when introducing any new Guix inputs. Exclude or neutralize unavailable upstream-only formatter, PMD, Checkstyle, SpotBugs, site, release, source/javadoc/license, and failsafe/reporting executions (including net.revelc.code.formatter:formatter-maven-plugin, org.codehaus.mojo:license-maven-plugin, org.apache.maven.plugins:maven-site-plugin/maven-source-plugin/maven-javadoc-plugin/maven-pmd-plugin/maven-checkstyle-plugin/maven-release-plugin/maven-artifact-plugin/maven-failsafe-plugin, com.github.spotbugs:spotbugs-maven-plugin, and site skin tooling) while keeping compile, resource, JAR, and unit-test phases; do not add the shade plugin solely for the standalone artifact because the upstream README documents zero runtime dependencies. Install the regular JAR under share/java/winrm-java.jar and provide bin/winrm as a fixed-runtime wrapper using openjdk11 to invoke org.metricshub.winrm.cli.WinRmCli with all user arguments; install upstream README.md and LICENSE under share/doc/winrm-java. The package has no service, daemon, downloaded asset, credential, or optional integration requirement. Runtime network access occurs only when a WinRM operation is executed; --help/--version and client construction must not connect. Preserve the explicit security behavior: HTTPS certificate and hostname validation is enabled by default, Kerberos/NTLM selection and ticket-cache/truststore paths are supplied by the user, and trustAllCertificates/--https-permissive is an explicit insecure opt-in. The isolated smoke proof must use a temporary HOME and no live-server properties, run Maven tests offline from the fixed tree with mvn test -o (or the equivalent Guix phase), including WsmanProtocolTest's in-process fake-server NTLM/encrypted-framing/WQL/command lifecycle coverage, LightTlsTest's default-validation and explicit-insecure assertions, FallbackAuthSchemeTest's Kerberos-to-NTLM fallback without a KDC, WinRMClientBuilderTest's no-connect and validation cases, and CLI argument parsing; leave disabled WinRMLiveTest disabled. Then package offline, run the wrapper with --help and --version, and compile/run a tiny Java 11 smoke class against the installed JAR that builds WinRMClient.builder("host").https().port(5987).build() without invoking an operation, while asserting no socket connection is attempted. Final acceptance is guix lint -L. winrm-java with no new errors and guix build -L. winrm-java succeeding with the offline tests enabled where practical; record those command results as implementation acceptance, not as research proof. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/77#issuecomment-5423654348). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T09:57:23Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#77
No description provided.