[Guix packaging] Nearoo/music-tool #79
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#79
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Candidate
b4f183ad71e175ea92af3b31d8c9a941cc3f64eeonmain(default branch snapshot reviewed 2026-08-14).build/)package.json+yarn.lock)LICENSEcontains the MIT license andpackage.jsonidentifies the private React application.Scope and blockers
Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. The private web app has no release artifact; pin the legacy React/Tone.js dependency closure and define an offline static install and browser smoke.
Acceptance checks
guix lint -L. music-toolpasses with no new errors.guix build -L. music-toolsucceeds from the pinned source with tests enabled where practical.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:05Z.
Goocastle recorded disposition: blocked.
Blocked on redistribution rights for required bundled audio. Canonical upstream is https://github.com/Nearoo/music-tool at fixed commit b4f183ad71e175ea92af3b31d8c9a941cc3f64ee on main; that exact tree has LICENSE with an MIT grant to Silas Gyger, no .gitmodules, and the local channel contains only nearoo-music-tool-source (not an installable equivalent). package.json is a private React 17 application using react-scripts 4.0.3, Tone 14.7.77, react-flow-renderer 9.6.6, antd 4.16.13, and other direct dependencies; yarn.lock fixes 1,595 npm-registry tarball records with integrity data. A clean Yarn 1.22.22 offline install succeeded. A source build is technically actionable but needs a deterministic compatibility phase: unchanged CRA 4 fails under the available modern Node at postcss-safe-parser 5.0.2 importing postcss/lib/tokenize through postcss 8.2.6 exports; adding the required fixed subpath mapping and NODE_OPTIONS=--openssl-legacy-provider allowed the production build to complete. The upstream Jest test is not usable unchanged because Jest stops on Tone ESM (tone/build/esm/core/util/Debug.js), and App.test.js still asserts the removed Learn React text; the implementation would need to disable that test phase with this explicit rationale and use an isolated browser smoke instead. The npm archive metadata/license files inspected at their exact lock versions are permissive (MIT, BSD, Apache, ISC, CC0, CC-BY, MPL, ODC, 0BSD, WTFPL, and Unlicense); rework 1.0.1 has its MIT grant in the exact archive README despite no package.json license field, and there are no Git submodule origins. The required deliverable nevertheless includes 307 WAV files under public/sounds/drums plus DataDrive demo/cover assets. Origin: DataDrive's 80s Electronic Drum Pack, identified by the creator's SoundCloud item https://soundcloud.com/datadrive/80s-drum-pack and its linked immutable Mega file identifier BCPdPgDUo1LVG1f3GMkuvlqtJ2ZR_mPe15jqrVlkAb8; the files entered the Nearoo repository at exact commit 1be92134a3eb77a26633cb93fcd858df3f4ec9c8 and are present at the parent revision above. The exact-revision evidence in public/sounds/drums/readme.txt is only attribution/social links, not a copyright license or redistribution grant; the creator page is marked all-rights-reserved, while the secondary listing https://soundpacks.com/free-sound-packs/80s-retro-futuristic-drum-pack/ says free download but supplies no redistribution license. Nearoo's MIT LICENSE cannot prove rights to this separately identified audio origin. Unattended Guix delivery is unsafe until DataDrive or an authorized rights holder provides an explicit license permitting redistribution of the exact archive (with attribution terms recorded at that fixed identifier), or the requested deliverable is explicitly changed to omit/replace every unlicensed audio asset with a separately fixed, clearly licensed source and the offline sampler acceptance is revised.
Imported from GitHub comment. Originally posted by htayj on 2026-08-26T11:17:20Z.