[Guix packaging] browsh-org/browsh #96

Open
opened 2026-08-14 13:17:19 +00:00 by htayj · 1 comment
htayj commented 2026-08-14 13:17:19 +00:00 (Migrated from github.com)

Candidate

  • Upstream canonical URL: https://github.com/browsh-org/browsh
  • Source pinned commit/release when known: 499ef386d45cd1e2b5457dd04887c017f77b7e27 on master (default branch snapshot reviewed 2026-08-14).
  • Target concrete installed deliverable: Browsh terminal web browser (browsh Go binary plus Firefox web extension)
  • Primary category: browser
  • Tags: browser-engine, terminal-ui
  • Primary language normalized: Mixed
  • Build system: Go modules + npm/webpack (Go interfacer/go.mod, web extension webext/package.json)
  • SPDX expression: LGPL-2.1
  • License status: mixed-review
  • License evidence: LICENSE contains LGPL-2.1; the browser extension bundles fonts/assets and depends on a Firefox headless runtime requiring separate notice review.
  • Difficulty: hard — Package the Go binary, web extension, and Firefox runtime contract without downloading browser data at runtime; complete asset/font license review.
  • Workflow state: research
  • Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found.

Scope and blockers

Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Package the Go binary, web extension, and Firefox runtime contract without downloading browser data at runtime; complete asset/font license review.

Acceptance checks

  • guix lint -L. browsh passes with no new errors.
  • guix build -L. browsh succeeds from the pinned source with tests enabled where practical.
  • App-specific offline smoke: Build Go and web-extension components offline, then run Browsh against a local HTML fixture with a pinned Firefox binary.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-14T13:17:19Z.

## Candidate - Upstream canonical URL: https://github.com/browsh-org/browsh - Source pinned commit/release when known: `499ef386d45cd1e2b5457dd04887c017f77b7e27` on `master` (default branch snapshot reviewed 2026-08-14). - Target concrete installed deliverable: Browsh terminal web browser (`browsh` Go binary plus Firefox web extension) - Primary category: browser - Tags: browser-engine, terminal-ui - Primary language normalized: Mixed - Build system: Go modules + npm/webpack (Go `interfacer/go.mod`, web extension `webext/package.json`) - SPDX expression: LGPL-2.1 - License status: mixed-review - License evidence: `LICENSE` contains LGPL-2.1; the browser extension bundles fonts/assets and depends on a Firefox headless runtime requiring separate notice review. - Difficulty: hard — Package the Go binary, web extension, and Firefox runtime contract without downloading browser data at runtime; complete asset/font license review. - Workflow state: research - Existing Guix coverage: Checked 2026-08-14: GNU Guix, Nonguix, Guix Science, Guix HPC, Guix Past, Guix 'R Us, and RDE; no equivalent package with the same upstream origin was found. ## Scope and blockers Package the pinned upstream source as the stated deliverable, retaining upstream notices and making runtime services, credentials, downloaded assets, and optional integrations explicit. Package the Go binary, web extension, and Firefox runtime contract without downloading browser data at runtime; complete asset/font license review. ## Acceptance checks - `guix lint -L. browsh` passes with no new errors. - `guix build -L. browsh` succeeds from the pinned source with tests enabled where practical. - App-specific offline smoke: Build Go and web-extension components offline, then run Browsh against a local HTML fixture with a pinned Firefox binary. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/96). Originally posted by [htayj](https://github.com/htayj) on 2026-08-14T13:17:19Z.
Owner

Goocastle recorded disposition: blocked.

Blocked for unattended delivery. Canonical upstream is https://github.com/browsh-org/browsh at commit 499ef386d45cd1e2b5457dd04887c017f77b7e27 (tree 0563c9264c8e73c596dd62e9448d25d55a554cc6, committed 2025-07-05); it was cloned and checked out at that revision. The local channel has no browsh package, only browsh-org-browsh-source in guix/tay/packages/starred-a-c.scm at lines 211-215, so this is not a delivered duplicate. The parent LICENSE at the revision is LGPL-2.1. The two bundled fonts were introduced upstream at commit 02bc0aad937b2f1508eac3eae898a80b8d6bfca9; their TTF metadata says only 'Copyright (c) 2018, tombh' and contains no license grant, while webext/contrib/font_maker.py at the pinned revision is same-origin generator source. The icons were introduced upstream at commit b387f66c692dc3af87cdb5a2a730a0cfea892921. These facts support same-origin LGPL treatment but do not supply the complete independent asset/font notice review demanded by the issue. A concrete build/runtime blocker also remains: interfacer/src/browsh/browsh.xpi is absent from the pinned source; webext has package-lock.json, but scripts/bundling.bash lines 19-36 and 53-64 require Mozilla signing credentials/network or download of a release XPI, and firefox.go lines 237-248 embeds and installs that resulting XPI. Source-only webpack/web-ext output cannot establish the required offline, credential-free, reproducible Firefox runtime contract. Exact blockers: (1) obtain explicit redistribution/license notices for the generated fonts and icons at revision 499ef386d45cd1e2b5457dd04887c017f77b7e27, or replace them with fixed origins having license evidence at their exact revisions; (2) provide or authorize a source-only offline contract that produces the web extension and installs it in the packaged Firefox without Mozilla signing credentials or runtime downloads, with all separately fetched Go and npm dependency origins/license evidence resolved at their locked revisions. Unblock by upstreaming those notices and an offline signing-free runtime path, or by supplying reviewed replacement assets and a complete fixed-origin dependency/license manifest; only then can a browsh package in guix/tay/packages/browsh.scm and an implementation-ready runtime proof be specified safely.

<!-- goocastle-disposition:sequential-reviewer:96:1:blocked --> Goocastle recorded disposition: blocked. Blocked for unattended delivery. Canonical upstream is https://github.com/browsh-org/browsh at commit 499ef386d45cd1e2b5457dd04887c017f77b7e27 (tree 0563c9264c8e73c596dd62e9448d25d55a554cc6, committed 2025-07-05); it was cloned and checked out at that revision. The local channel has no browsh package, only browsh-org-browsh-source in guix/tay/packages/starred-a-c.scm at lines 211-215, so this is not a delivered duplicate. The parent LICENSE at the revision is LGPL-2.1. The two bundled fonts were introduced upstream at commit 02bc0aad937b2f1508eac3eae898a80b8d6bfca9; their TTF metadata says only 'Copyright (c) 2018, tombh' and contains no license grant, while webext/contrib/font_maker.py at the pinned revision is same-origin generator source. The icons were introduced upstream at commit b387f66c692dc3af87cdb5a2a730a0cfea892921. These facts support same-origin LGPL treatment but do not supply the complete independent asset/font notice review demanded by the issue. A concrete build/runtime blocker also remains: interfacer/src/browsh/browsh.xpi is absent from the pinned source; webext has package-lock.json, but scripts/bundling.bash lines 19-36 and 53-64 require Mozilla signing credentials/network or download of a release XPI, and firefox.go lines 237-248 embeds and installs that resulting XPI. Source-only webpack/web-ext output cannot establish the required offline, credential-free, reproducible Firefox runtime contract. Exact blockers: (1) obtain explicit redistribution/license notices for the generated fonts and icons at revision 499ef386d45cd1e2b5457dd04887c017f77b7e27, or replace them with fixed origins having license evidence at their exact revisions; (2) provide or authorize a source-only offline contract that produces the web extension and installs it in the packaged Firefox without Mozilla signing credentials or runtime downloads, with all separately fetched Go and npm dependency origins/license evidence resolved at their locked revisions. Unblock by upstreaming those notices and an offline signing-free runtime path, or by supplying reviewed replacement assets and a complete fixed-origin dependency/license manifest; only then can a browsh package in guix/tay/packages/browsh.scm and an implementation-ready runtime proof be specified safely.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#96
No description provided.