[Guix packaging] Nearoo/music-tool #79

Open
opened 2026-08-14 13:17:05 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:05 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/Nearoo/music-tool
  • Source pinned commit/release when known: b4f183ad71e175ea92af3b31d8c9a941cc3f64ee on main (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: Music Tool static React DAW bundle (build/)
  • Primary category: multimedia
  • Tags: audio, music-client
  • Primary language normalized: JavaScript
  • Build system: Yarn/npm (React application; package.json + yarn.lock)
  • SPDX expression: MIT
  • License status: confirmed-free
  • License evidence: LICENSE contains the MIT license and package.json identifies the private React application.
  • Difficulty: hard — The private web app has no release artifact; pin the legacy React/Tone.js dependency closure and define an offline static install and browser smoke.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. The private web app has no release artifact; pin the legacy React/Tone.js dependency closure and define an offline static install and browser smoke.

Acceptance checks

  • guix lint -L. music-tool passes with no new errors.
  • guix build -L. music-tool succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Build with the frozen Yarn tree and serve the bundle locally; verify the node-add and offline audio graph UI without network requests.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:05Z.

## Candidate - Upstream canonical URL: https://github.com/Nearoo/music-tool - Source pinned commit/release when known: `b4f183ad71e175ea92af3b31d8c9a941cc3f64ee` on `main` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: Music Tool static React DAW bundle (`build/`) - Primary category: multimedia - Tags: audio, music-client - Primary language normalized: JavaScript - Build system: Yarn/npm (React application; `package.json` + `yarn.lock`) - SPDX expression: MIT - License status: confirmed-free - License evidence: `LICENSE` contains the MIT license and `package.json` identifies the private React application. - Difficulty: hard — The private web app has no release artifact; pin the legacy React/Tone.js dependency closure and define an offline static install and browser smoke. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. The private web app has no release artifact; pin the legacy React/Tone.js dependency closure and define an offline static install and browser smoke. ## Acceptance checks - `guix lint -L. music-tool` passes with no new errors. - `guix build -L. music-tool` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Build with the frozen Yarn tree and serve the bundle locally; verify the node-add and offline audio graph UI without network requests. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/79). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:05Z.
htayj commented 2026-08-26 11:17:20 +00:00 (Migrated from github.com)

Goocastle recorded disposition: blocked.

Blocked on redistribution rights for required bundled audio. Canonical upstream is https://github.com/Nearoo/music-tool at fixed commit b4f183ad71e175ea92af3b31d8c9a941cc3f64ee on main; that exact tree has LICENSE with an MIT grant to Silas Gyger, no .gitmodules, and the local channel contains only nearoo-music-tool-source (not an installable equivalent). package.json is a private React 17 application using react-scripts 4.0.3, Tone 14.7.77, react-flow-renderer 9.6.6, antd 4.16.13, and other direct dependencies; yarn.lock fixes 1,595 npm-registry tarball records with integrity data. A clean Yarn 1.22.22 offline install succeeded. A source build is technically actionable but needs a deterministic compatibility phase: unchanged CRA 4 fails under the available modern Node at postcss-safe-parser 5.0.2 importing postcss/lib/tokenize through postcss 8.2.6 exports; adding the required fixed subpath mapping and NODE_OPTIONS=--openssl-legacy-provider allowed the production build to complete. The upstream Jest test is not usable unchanged because Jest stops on Tone ESM (tone/build/esm/core/util/Debug.js), and App.test.js still asserts the removed Learn React text; the implementation would need to disable that test phase with this explicit rationale and use an isolated browser smoke instead. The npm archive metadata/license files inspected at their exact lock versions are permissive (MIT, BSD, Apache, ISC, CC0, CC-BY, MPL, ODC, 0BSD, WTFPL, and Unlicense); rework 1.0.1 has its MIT grant in the exact archive README despite no package.json license field, and there are no Git submodule origins. The required deliverable nevertheless includes 307 WAV files under public/sounds/drums plus DataDrive demo/cover assets. Origin: DataDrive's 80s Electronic Drum Pack, identified by the creator's SoundCloud item https://soundcloud.com/datadrive/80s-drum-pack and its linked immutable Mega file identifier BCPdPgDUo1LVG1f3GMkuvlqtJ2ZR_mPe15jqrVlkAb8; the files entered the Nearoo repository at exact commit 1be92134a3eb77a26633cb93fcd858df3f4ec9c8 and are present at the parent revision above. The exact-revision evidence in public/sounds/drums/readme.txt is only attribution/social links, not a copyright license or redistribution grant; the creator page is marked all-rights-reserved, while the secondary listing https://soundpacks.com/free-sound-packs/80s-retro-futuristic-drum-pack/ says free download but supplies no redistribution license. Nearoo's MIT LICENSE cannot prove rights to this separately identified audio origin. Unattended Guix delivery is unsafe until DataDrive or an authorized rights holder provides an explicit license permitting redistribution of the exact archive (with attribution terms recorded at that fixed identifier), or the requested deliverable is explicitly changed to omit/replace every unlicensed audio asset with a separately fixed, clearly licensed source and the offline sampler acceptance is revised.


Imported from GitHub comment. Originally posted by htayj on 2026-08-26T11:17:20Z.

<!-- goocastle-disposition:sequential-reviewer:79:1:blocked --> Goocastle recorded disposition: blocked. Blocked on redistribution rights for required bundled audio. Canonical upstream is https://github.com/Nearoo/music-tool at fixed commit b4f183ad71e175ea92af3b31d8c9a941cc3f64ee on main; that exact tree has LICENSE with an MIT grant to Silas Gyger, no .gitmodules, and the local channel contains only nearoo-music-tool-source (not an installable equivalent). package.json is a private React 17 application using react-scripts 4.0.3, Tone 14.7.77, react-flow-renderer 9.6.6, antd 4.16.13, and other direct dependencies; yarn.lock fixes 1,595 npm-registry tarball records with integrity data. A clean Yarn 1.22.22 offline install succeeded. A source build is technically actionable but needs a deterministic compatibility phase: unchanged CRA 4 fails under the available modern Node at postcss-safe-parser 5.0.2 importing postcss/lib/tokenize through postcss 8.2.6 exports; adding the required fixed subpath mapping and NODE_OPTIONS=--openssl-legacy-provider allowed the production build to complete. The upstream Jest test is not usable unchanged because Jest stops on Tone ESM (tone/build/esm/core/util/Debug.js), and App.test.js still asserts the removed Learn React text; the implementation would need to disable that test phase with this explicit rationale and use an isolated browser smoke instead. The npm archive metadata/license files inspected at their exact lock versions are permissive (MIT, BSD, Apache, ISC, CC0, CC-BY, MPL, ODC, 0BSD, WTFPL, and Unlicense); rework 1.0.1 has its MIT grant in the exact archive README despite no package.json license field, and there are no Git submodule origins. The required deliverable nevertheless includes 307 WAV files under public/sounds/drums plus DataDrive demo/cover assets. Origin: DataDrive's 80s Electronic Drum Pack, identified by the creator's SoundCloud item https://soundcloud.com/datadrive/80s-drum-pack and its linked immutable Mega file identifier BCPdPgDUo1LVG1f3GMkuvlqtJ2ZR_mPe15jqrVlkAb8; the files entered the Nearoo repository at exact commit 1be92134a3eb77a26633cb93fcd858df3f4ec9c8 and are present at the parent revision above. The exact-revision evidence in public/sounds/drums/readme.txt is only attribution/social links, not a copyright license or redistribution grant; the creator page is marked all-rights-reserved, while the secondary listing https://soundpacks.com/free-sound-packs/80s-retro-futuristic-drum-pack/ says free download but supplies no redistribution license. Nearoo's MIT LICENSE cannot prove rights to this separately identified audio origin. Unattended Guix delivery is unsafe until DataDrive or an authorized rights holder provides an explicit license permitting redistribution of the exact archive (with attribution terms recorded at that fixed identifier), or the requested deliverable is explicitly changed to omit/replace every unlicensed audio asset with a separately fixed, clearly licensed source and the offline sampler acceptance is revised. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/79#issuecomment-5424509234). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T11:17:20Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#79
No description provided.