[Guix packaging] Toqozz/wired-notify #81

Closed
opened 2026-08-14 13:17:07 +00:00 by htayj · 2 comments
htayj commented 2026-08-14 13:17:07 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/Toqozz/wired-notify
  • Source pinned commit/release when known: 6b6f3c15b1a1304120f80ebf56c3accace40095a on master (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: wired desktop notification daemon
  • Primary category: system-tool
  • Tags: None
  • Primary language normalized: Rust
  • Build system: Cargo (Cargo.toml/Cargo.lock; GTK/Pango/Cairo, X11/DBus)
  • SPDX expression: MIT
  • License status: confirmed-free
  • License evidence: LICENSE contains the MIT license and Cargo.toml declares the Rust package.
  • Difficulty: moderate — Provide system inputs for Cairo/Pango/X11/DBus and preserve the declarative layout configuration while avoiding installer-side network access.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Provide system inputs for Cairo/Pango/X11/DBus and preserve the declarative layout configuration while avoiding installer-side network access.

Acceptance checks

  • guix lint -L. wired passes with no new errors.
  • guix build -L. wired succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Run cargo test/Guix build offline and launch wired --help with a temporary config, checking clean startup and shutdown.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:07Z.

## Candidate - Upstream canonical URL: https://github.com/Toqozz/wired-notify - Source pinned commit/release when known: `6b6f3c15b1a1304120f80ebf56c3accace40095a` on `master` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: `wired` desktop notification daemon - Primary category: system-tool - Tags: None - Primary language normalized: Rust - Build system: Cargo (`Cargo.toml`/`Cargo.lock`; GTK/Pango/Cairo, X11/DBus) - SPDX expression: MIT - License status: confirmed-free - License evidence: `LICENSE` contains the MIT license and `Cargo.toml` declares the Rust package. - Difficulty: moderate — Provide system inputs for Cairo/Pango/X11/DBus and preserve the declarative layout configuration while avoiding installer-side network access. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Provide system inputs for Cairo/Pango/X11/DBus and preserve the declarative layout configuration while avoiding installer-side network access. ## Acceptance checks - `guix lint -L. wired` passes with no new errors. - `guix build -L. wired` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Run `cargo test`/Guix build offline and launch `wired --help` with a temporary config, checking clean startup and shutdown. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/81). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:07Z.
htayj commented 2026-08-26 12:05:06 +00:00 (Migrated from github.com)

Goocastle recorded disposition: implementation-ready.

Created implementation ticket: #629.

Implementation-ready delivery brief for the requested wired executable. Canonical upstream is https://github.com/Toqozz/wired-notify at fixed Git commit 6b6f3c15b1a1304120f80ebf56c3accace40095a; that commit's Cargo.toml identifies package version 0.10.7. The local channel already records the same codeload source as toqozz-wired-notify-source in tay/packages/starred-s-z.scm, with immutable source hash 0q7fd416nrzczyc25qyn711v2zr5x2gl1nr5xq0l2w2kn6lhd0i5. The commit tree's LICENSE is the complete MIT License naming Michael Palmos and copyright 2020; wired_derive is an in-tree path crate at that same Git revision, not a separately fetched origin. The tree has no .gitmodules, no submodule entries, no Git dependency, and no other independently fetched upstream source. For the 295 crates.io package entries in the exact Cargo.lock (each fixed by its locked name, version, and checksum), exact-version crates.io API metadata checked on 2026-08-26 returned a nonempty license expression for all 295: 110 MIT OR Apache-2.0, 73 MIT, 49 MIT/Apache-2.0, 8 Apache-2.0/MIT, 6 Apache-2.0, 6 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT, 5 Apache-2.0 OR MIT, 5 BSD-3-Clause, 4 ISC, 4 Unlicense/MIT, 3 MIT OR Apache-2.0 OR Zlib, 3 MIT / Apache-2.0, 3 MPL-2.0, 2 BSD-2-Clause OR Apache-2.0 OR MIT, 2 BSD-3-Clause OR MIT OR Apache-2.0, 2 MIT OR Zlib OR Apache-2.0, 2 Zlib OR Apache-2.0 OR MIT, and one each of (MIT OR Apache-2.0) AND Unicode-3.0, 0BSD OR MIT OR Apache-2.0, Apache-2.0 OR BSL-1.0, BSD-2-Clause, CC0-1.0, MIT OR Apache-2.0 OR LGPL-2.1-or-later, Unlicense OR MIT, and Zlib. The three yanked lock entries remain fixed downloadable archives and have clear grants: crossbeam-channel@0.5.1 checksum 06ed27e177f16d65f0f0c22a213e17c696ace5dd64b14258b52f9417ccb52db4 is MIT OR Apache-2.0, futures-util@0.3.19 checksum d9b5cf40b47a271f77a8b1bec03ca09044d99d2372c0de244e66430761127164 is MIT OR Apache-2.0, and rgb@0.8.32 checksum e74fdc210d8f24a7dbfedc13b04ba5764f5232754ccebfdf5fff1bad791ccbc6 is MIT. Thus no required source origin lacks a clear redistribution grant, including the separately fetched registry origins. The source is technically source-buildable: upstream uses ordinary Cargo with edition 2021, a checked-in lockfile, and no parent build script or runtime download; its installer.sh is deliberately unsuitable because it requires root, DNF, nc google.com, and an unpinned networked Cargo build. The local channel has no installable wired definition and the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix RDE coverage has no equivalent package from this upstream; dunst is only a different notification-daemon alternative. Implement a dedicated (tay packages wired) module, reusing (package-source toqozz-wired-notify-source), cargo-build-system, #:install-source? #f, and the channel's stable rust toolchain. Enumerate all 295 locked crates as immutable crate-source inputs (the local guix import crate --lockfile Cargo.lock result matches the 295 registry entries), preserve and restore Cargo.lock around Guix's configure phase because this Guix cargo system deletes it, and invoke build/tests with --locked; Cargo's Guix phases must remain offline. Required native/system inputs are pkg-config, cairo, pango, glib, dbus, libx11, libxscrnsaver, libxi, libxrandr, libxcursor, and libxkbcommon, matching the cairo/pango/DBus/X11/XSS features in the Rust graph and upstream's X11 build inputs. Install only the wired binary, the MIT notice, and the two declarative examples wired.ron and wired_multilayout.ron; omit README demo media, AUR/Nix files, and the networked installer. Preserve wired.service as user-managed data but rewrite its /usr/bin/wired ExecStart to the immutable package $out/bin/wired; retain its Type=dbus, BusName=org.freedesktop.Notifications, and ConditionEnvironment=DISPLAY contract without enabling any service automatically. The daemon requires a session D-Bus and X11 or XWayland DISPLAY (it forces winit's X11 event loop); it does not provide native Wayland support. Its font and icon lookups remain external system/user resources and must not download assets. The only optional subprocess integration is xdg-open for clicked URL actions; either add xdg-utils as an explicit runtime input and prepend it in a wrapper PATH, or document it as optional, and do not invoke it in the offline smoke. No credentials or credential files are needed. Add an isolated tests/wired-smoke.sh proof that builds the package with tests enabled, runs wired --help and wired --version against the installed output, then in unshare -Urnm with a private tmpfs /tmp, fresh HOME/XDG directories, an in-namespace Xvfb, and dbus-run-session, starts wired --config with a temporary text-only RON config, calls GetServerInformation and Notify over the session bus to verify the wired service and a rendered notification path, invokes wired --kill through the private /tmp/wired.sock, asserts clean exit, forbids network and host state, and compares the package-output file manifest before and after while checking the installed MIT notice, both RON examples, and rewritten service. Acceptance is guix lint -L . --no-network --exclude=cve,refresh,archival wired with no new errors and guix build -L . wired succeeding from commit 6b6f3c15b1a1304120f80ebf56c3accace40095a with the locked graph and tests enabled; this research did not claim either proof because the host Guix daemon socket is unavailable.


Imported from GitHub comment. Originally posted by htayj on 2026-08-26T12:05:06Z.

<!-- goocastle-disposition:sequential-reviewer:81:1:implementation-ready --> Goocastle recorded disposition: implementation-ready. Created implementation ticket: #629. Implementation-ready delivery brief for the requested `wired` executable. Canonical upstream is https://github.com/Toqozz/wired-notify at fixed Git commit `6b6f3c15b1a1304120f80ebf56c3accace40095a`; that commit's `Cargo.toml` identifies package version `0.10.7`. The local channel already records the same codeload source as `toqozz-wired-notify-source` in `tay/packages/starred-s-z.scm`, with immutable source hash `0q7fd416nrzczyc25qyn711v2zr5x2gl1nr5xq0l2w2kn6lhd0i5`. The commit tree's `LICENSE` is the complete MIT License naming Michael Palmos and copyright 2020; `wired_derive` is an in-tree path crate at that same Git revision, not a separately fetched origin. The tree has no `.gitmodules`, no submodule entries, no Git dependency, and no other independently fetched upstream source. For the 295 crates.io package entries in the exact `Cargo.lock` (each fixed by its locked name, version, and checksum), exact-version crates.io API metadata checked on 2026-08-26 returned a nonempty license expression for all 295: 110 MIT OR Apache-2.0, 73 MIT, 49 MIT/Apache-2.0, 8 Apache-2.0/MIT, 6 Apache-2.0, 6 Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT, 5 Apache-2.0 OR MIT, 5 BSD-3-Clause, 4 ISC, 4 Unlicense/MIT, 3 MIT OR Apache-2.0 OR Zlib, 3 MIT / Apache-2.0, 3 MPL-2.0, 2 BSD-2-Clause OR Apache-2.0 OR MIT, 2 BSD-3-Clause OR MIT OR Apache-2.0, 2 MIT OR Zlib OR Apache-2.0, 2 Zlib OR Apache-2.0 OR MIT, and one each of (MIT OR Apache-2.0) AND Unicode-3.0, 0BSD OR MIT OR Apache-2.0, Apache-2.0 OR BSL-1.0, BSD-2-Clause, CC0-1.0, MIT OR Apache-2.0 OR LGPL-2.1-or-later, Unlicense OR MIT, and Zlib. The three yanked lock entries remain fixed downloadable archives and have clear grants: `crossbeam-channel@0.5.1` checksum `06ed27e177f16d65f0f0c22a213e17c696ace5dd64b14258b52f9417ccb52db4` is MIT OR Apache-2.0, `futures-util@0.3.19` checksum `d9b5cf40b47a271f77a8b1bec03ca09044d99d2372c0de244e66430761127164` is MIT OR Apache-2.0, and `rgb@0.8.32` checksum `e74fdc210d8f24a7dbfedc13b04ba5764f5232754ccebfdf5fff1bad791ccbc6` is MIT. Thus no required source origin lacks a clear redistribution grant, including the separately fetched registry origins. The source is technically source-buildable: upstream uses ordinary Cargo with edition 2021, a checked-in lockfile, and no parent build script or runtime download; its `installer.sh` is deliberately unsuitable because it requires root, DNF, `nc google.com`, and an unpinned networked Cargo build. The local channel has no installable `wired` definition and the inspected GNU Guix/Nonguix/Guix Science/Guix HPC/Guix Past/Guix RDE coverage has no equivalent package from this upstream; `dunst` is only a different notification-daemon alternative. Implement a dedicated `(tay packages wired)` module, reusing `(package-source toqozz-wired-notify-source)`, `cargo-build-system`, `#:install-source? #f`, and the channel's stable `rust` toolchain. Enumerate all 295 locked crates as immutable `crate-source` inputs (the local `guix import crate --lockfile Cargo.lock` result matches the 295 registry entries), preserve and restore `Cargo.lock` around Guix's configure phase because this Guix cargo system deletes it, and invoke build/tests with `--locked`; Cargo's Guix phases must remain offline. Required native/system inputs are `pkg-config`, `cairo`, `pango`, `glib`, `dbus`, `libx11`, `libxscrnsaver`, `libxi`, `libxrandr`, `libxcursor`, and `libxkbcommon`, matching the cairo/pango/DBus/X11/XSS features in the Rust graph and upstream's X11 build inputs. Install only the `wired` binary, the MIT notice, and the two declarative examples `wired.ron` and `wired_multilayout.ron`; omit README demo media, AUR/Nix files, and the networked installer. Preserve `wired.service` as user-managed data but rewrite its `/usr/bin/wired` `ExecStart` to the immutable package `$out/bin/wired`; retain its `Type=dbus`, `BusName=org.freedesktop.Notifications`, and `ConditionEnvironment=DISPLAY` contract without enabling any service automatically. The daemon requires a session D-Bus and X11 or XWayland `DISPLAY` (it forces winit's X11 event loop); it does not provide native Wayland support. Its font and icon lookups remain external system/user resources and must not download assets. The only optional subprocess integration is `xdg-open` for clicked URL actions; either add `xdg-utils` as an explicit runtime input and prepend it in a wrapper PATH, or document it as optional, and do not invoke it in the offline smoke. No credentials or credential files are needed. Add an isolated `tests/wired-smoke.sh` proof that builds the package with tests enabled, runs `wired --help` and `wired --version` against the installed output, then in `unshare -Urnm` with a private tmpfs `/tmp`, fresh HOME/XDG directories, an in-namespace `Xvfb`, and `dbus-run-session`, starts `wired --config` with a temporary text-only RON config, calls `GetServerInformation` and `Notify` over the session bus to verify the `wired` service and a rendered notification path, invokes `wired --kill` through the private `/tmp/wired.sock`, asserts clean exit, forbids network and host state, and compares the package-output file manifest before and after while checking the installed MIT notice, both RON examples, and rewritten service. Acceptance is `guix lint -L . --no-network --exclude=cve,refresh,archival wired` with no new errors and `guix build -L . wired` succeeding from commit `6b6f3c15b1a1304120f80ebf56c3accace40095a` with the locked graph and tests enabled; this research did not claim either proof because the host Guix daemon socket is unavailable. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/81#issuecomment-5424999985). Originally posted by [htayj](https://github.com/htayj) on 2026-08-26T12:05:06Z.
Owner

Implemented and published in signed, Guix-authenticated commit 62f09e33feb2119a835d7b346606d7811d9d3500.

Wired: real isolated D-Bus Notify/CloseNotification, rendered X11 notification, clean --kill and unchanged store digest. Cargo check runs successfully but upstream contains zero tests. Output wrxmykhlfpaifvc28qzg9f4asas5cl6x.

Source build, final reproducibility --check, offline lint without package-specific findings, standalone and integrated Make acceptance passed. README records exact commands and limits; unrelated Fourk/flex/legacy Cargo diagnostics are not claimed clean. No deployed system changed; no OKF deployment update applies.

Implemented and published in signed, Guix-authenticated commit `62f09e33feb2119a835d7b346606d7811d9d3500`. Wired: real isolated D-Bus Notify/CloseNotification, rendered X11 notification, clean --kill and unchanged store digest. Cargo check runs successfully but upstream contains zero tests. Output wrxmykhlfpaifvc28qzg9f4asas5cl6x. Source build, final reproducibility `--check`, offline lint without package-specific findings, standalone and integrated Make acceptance passed. README records exact commands and limits; unrelated Fourk/flex/legacy Cargo diagnostics are not claimed clean. No deployed system changed; no OKF deployment update applies.
tay closed this issue 2026-10-03 10:08:35 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#81
No description provided.