- Scheme 92.3%
- Shell 7.7%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| etc | ||
| securityops | ||
| .dir-locals.el | ||
| .gitignore | ||
| .guix-authorizations | ||
| .guix-channel | ||
| AUDIT.md | ||
| CHANGELOG.md | ||
| LICENSE | ||
| README.md | ||
| README.pt-BR.md | ||
| update-channel | ||
securityops — a personal GNU Guix channel
Latest upstream versions of the securityops workstation's most-used applications, packaged the Guix way — real source hashes, every definition inheriting from upstream so it stays small and auditable.
🌐 Language: English · Português (Brasil)
This channel curates the programs this machine lives in and keeps them at the newest official release. Packages the pinned Guix already ships at the latest upstream version are re-exported unchanged (so the channel is the single place you install them from, and they track Guix automatically); packages that are ahead of Guix/nonguix carry a real, downloaded source hash.
- Host:
predator-helios-intel(the live/etc/config.scmmachine) - Pinned Guix: commit
d1e9e23(June 2026); depends onnonguix - Built/verified: 2026-06-21; re-validated 2026-06-22 (Mullvad → 2026.3, LibreWolf → 152.0.1-2); 2026-06-23 (torando-gui 1.0.1 added, then → 1.1.0: native GUI + connectivity fixes — built & installed); 2026-06-24 (vaptvupt 4.0.0 CLI + vaptvupt-gui 1.3.0 added — built from source; steam bootstrap bumped 1.0.0.85 → 1.0.0.86); 2026-06-25 (turborec 2.2.0 added — built from source; CLI + bash launcher run, Tkinter GUI works via the python
tkoutput; LibreWolf 152.0.1-2 + torbrowser 15.0.16 fully compiled & run-verified — full Firefox source builds, unblocked by a 24 GiB swapfile); 2026-06-30 (glances 4.5.5 added — from-source bump, new(securityops packages monitoring)module + private pyinstrument 5.1.2 dep; built,glances --version→ 4.5.5,--stdout cpu,memreturns live data; lynis 3.1.7 added; tor → 0.4.9.11; batch bumps steam 1.0.0.87 / google-chrome 150.0.7871.46 / ungoogled-chromium-bin 149.0.7827.200-1 / torbrowser 15.0.17 / turborec 3.0.0 — built & verified; openshot 3.5.1 build fixed (stale test path)); 2026-07-01 (esquema 0.2.0 added — new(securityops packages containers)module: rootless Guile-native container runtime, built from source, libseccomp-backed;guix build -L . esquemaverified); 2026-07-09 (batch bumps google-chrome 150.0.7871.114 / ungoogled-chromium-bin 150.0.7871.100-1 / librewolf 152.0.5-1 / turborec 3.1.0 / vaptvupt 4.1.0 / vaptvupt-gui 4.1.0 / moneyprinterturbo 1.3.1 — all built & run-verified; vaptvupt is source-only upstream now, itsmake checkcrypto/security suite runs in-build; librewolf source assembly verified with new l10n pin6ee6f5c4); 2026-07-10 (vaptvupt(+gui) → 4.2.0 — critical--dedupAES-CTR keystream-reuse fix + pure-PQ--pq-onlymode; built, full check suite incl. the new dedup-nonce regression green, run-verified; then → 4.2.1 —infonow reads the real envelope type and labels--pq-onlyarchives "ML-KEM-768 only, no classical layer" instead of hybrid; fix run-verified on a real--pq-onlyarchive; then → 5.0.0 — ML-KEM-768 made genuinely FIPS 203-conformant, cross-validated against OpenSSL 3.5 inside the build (openssl native-input); BREAKING: regenerate PQ keys, re-encrypt PQ archives from ≤ 4.2.1;--pq-onlykeygen→encrypt→decrypt round-trip verified); 2026-07-11/12 (vaptvupt(+gui) → 5.1.0 → 5.2.0 → 5.2.1 — codec 2.65.0→2.65.3 with large ratio gains and ~2× faster extreme; GUI compress-crash fix (thread-safe_Jobcontroller), robust auto-detect Verify/Extract, XWayland fallback on Sway; wire format v1.6 unchanged; all built + profile-verified, GUI--selftestOK; turborec → 3.2.0 —-R/--resolutionnative/720p/1080p/1440p/4k lanczos output scaling; built & run-verified; ungoogled-chromium-bin → 150.0.7871.114-1 — the .114 prebuilt landed, run-verified; moneyprinterturbo → 1.3.2 — re-vendored, same prune policy; streamlit 1.59.1 + google-genai in the first-run venv); 2026-07-13 (turborec → 3.3.0 — live YouTube/RTMPS streaming (record --stream), adaptive quality; built & run-verified; then → 3.4.0 — security-audit fixes; then → 3.5.0 — webcam PiP overlay + mic noise suppression; then → 3.6.0 —turborecorderWayland (wf-recorder) capture + static-screen stop fix; all built & run-verified); 2026-07-15 (batch bumps google-chrome 150.0.7871.124 / librewolf 152.0.6-1 (l10n pine42882cf) / torbrowser 15.0.18 / torbrowser-assets 15.0.18 / mirim 1.1.0 — chrome/mirim/tb-assets built & run-verified, librewolf+torbrowser source assemblies verified (full compile deferred to reconfigure); mirim 1.1.0 moved binaries to the archive root + added an unpackagedmirim-gui); 2026-07-17 (evelin-bin → 4.2.0 — 7 static binaries (addsev/evelin-keyscan/evelin-multisig-verify); built,evelin-client 4.2.0, installed; batch bumps google-chrome 150.0.7871.128 / ungoogled-chromium-bin 150.0.7871.128-1 — built & run-verified (Chromium 150.0.7871.128); fixed the moneyprinterturbo version field (was mislabelled 1.3.4 — upstream's newest tag is v1.3.2); README re-synced to the torando-gui 1.3.4 commits; then google-chrome → 150.0.7871.181 / librewolf → 153.0-3 (MAJOR 152→153, l10n pin235fd5b0) / torbrowser → 15.0.19 / torbrowser-assets → 15.0.19 — chrome/tb-assets built & run-verified, librewolf+torbrowser source assemblies verified (Firefox compiles at reconfigure); tor confirmed at 0.4.9.11 — the newest tor that exists (no 0.4.10/alpha); ranguix home reconfigureto install torbrowser 15.0.19 + tor + chrome + the rest at latest); 2026-07-23 (torbrowser version-string fix — guix'smake-torbrowserbaked its own%torbrowser-version15.0.14 into the displayed version, so a 15.0.19 engine reported 15.0.14; the recipe now rewrites--with-base-browser-version+MOZ_BUILD_DATEto 15.0.19, verified in the builtomni.ja(BASE_BROWSER_VERSION=15.0.19) and reconfigured into the home profile; kitty → 0.48.0 — one new imported Go dep (ebitengine/purego) packaged,GOTOOLCHAIN=localphase added (0.48's go.mod pins a toolchain guix can't fetch offline), built & installed,kitty --version→ 0.48.0) - 2026-07-25 refresh (built, installed, and profile-verified):
fish4.8.1,kitty0.48.1,google-chrome-stable150.0.7871.186,ungoogled-chromium-bin150.0.7871.186-1,evelin-bin4.3.0,turborec3.7.0,moneyprinterturbo1.3.3,mtr0.96,sdb2.4.8,radare26.1.8, andrizin0.9.1. All package builds passed; Fish additionally passed all 197 integration tests and 272 Cargo tests. - 2026-08-09 comprehensive refresh (authoritative audit, validation, and
Home/user profile activation complete):
kitty0.48.2,glances4.5.6 (privatepyinstrument5.1.3),google-chrome-stable151.0.7922.108,ungoogled-chromium-bin151.0.7922.108-1,librewolf153.0.3-1 (l10n pin6795ea14),sdb2.5.0,radare26.2.0, andlf42 (upstream tagr42; seven private Go modules:uax29/v22.7.0,displaywidth0.11.0,tcell/v33.4.1,fsnotify1.10.1,x/sys0.47.0,x/term0.45.0, andx/text0.40.0). Kitty, SDB, Radare2, and lf pass their exact channel builds and runtime/test checks; LibreWolf's Firefox/overlay/l10n source assembly andmach configurepass after correcting the upstream Makefile matcher and privately updatingrust-cbindgento 0.29.4 andnss-rapidto 3.126. Its exact full-LTO build passes andlibrewolf --versionreportsMozilla LibreWolf 153.0.3-1. Glances also passes its exact build and live-metrics smoke check; Chrome and ungoogled Chromium pass their exact builds and both runtime checks report 151.0.7922.108. The Home profile now carries Fish 4.8.1, Kitty 0.48.2, Chrome 151.0.7922.108, ungoogled Chromium 151.0.7922.108, LibreWolf 153.0.3-1, lf 42, and Tor Browser 15.0.19 (Firefox ESR 140.13.0;BASE_BROWSER_VERSION = 15.0.19). The direct user profile carries Fish 4.8.1, LibreWolf 153.0.3-1, SDB 2.5.0, Radare2 6.2.0, and Glances 4.5.6/PsUtil 7.2.2. A release-by-release audit of every channel definition found all other package releases current except the documented source-built ungoogled Chromium 147 fallback (the current 151 engine is provided by-bin), including every first-party app; Tor Browser's private 15.0.14 l10n-pin caveat is documented below. - Maintainer: Cristian Cezar Moisés
<ethicalhacker@riseup.net> - Home:
https://git.securityops.com.br/cristiancmoises/securityops-channel(official) · mirrors: Codeberg · GitHub - Signing: every commit is GPG-signed (ed25519
0CFA 43B9 … ECFB 46E8) and the channel is authenticated — see Publishing & authentication
The curated set
📇 Full package index (51 packages)
Every package this channel defines, its current version, and the most recent change. Class: 🅑 bumped ahead of Guix/nonguix (real downloaded hash) · 🄟 prebuilt binary · 🄡 re-exported (tracks pinned Guix; documented source-Chromium exception below) · 🄕 first-party (SecurityOps project) / vendored · 🄓 internal build dependency. The detailed per-category sections and caveats follow below.
| Package | Version | Class | Latest change / note |
|---|---|---|---|
kitty |
0.48.2 | 🅑 | ahead of Guix 0.46.2; pulls three vendored Go deps (↓); exact build/runtime passes |
tor |
0.4.9.11 | 🅑 | ahead of Guix 0.4.9.8 |
torbrowser |
15.0.19 | 🅑 | engine/branding current; inherited private l10n pins remain at 15.0.14 (caveat ↓) |
torbrowser-assets |
15.0.19 | 🅑 | standalone official fonts/torrc bundle; byte-identical to inherited 15.0.14 files |
openshot |
3.5.1 | 🅑 | ahead of Guix 3.4.0; stale-test-path build fixed |
google-chrome-stable |
151.0.7922.108 | 🅑 | ahead of nonguix; real .deb hash; exact build/runtime passes |
mullvad-vpn-desktop |
2026.3 | 🅑 | vendored .deb; the daemon service runs this build |
librewolf |
153.0.3-1 | 🅑 | Firefox 153.0.3 + l10n 6795ea14; private cbindgen 0.29.4/NSS 3.126; full-LTO build/runtime pass |
steam |
1.0.0.87 | 🅑 | current Valve stable bootstrap (nonguix container rebuilt) |
glances |
4.5.6 | 🅑 | fixes five CVEs (68520, 68519, 68518, 62982, 68517); private pyinstrument 5.1.3; build/live metrics pass |
lynis |
3.1.7 | 🅑 | ahead of Guix 3.1.1; bundled proprietary plugins stripped |
nmap |
7.99 | 🅑 | ahead of Guix 7.98 |
fping |
5.5 | 🅑 | ahead of Guix 5.3 |
hydra |
9.7 | 🅑 | THC-Hydra; ahead of Guix 9.6 |
ungoogled-chromium-bin |
151.0.7922.108-1 | 🄟 | current official PortableLinux asset; exact build/runtime passes |
alacritty |
0.17.0 | 🄡 | latest in Guix |
fish |
4.8.1 | 🅑 | hermetic Cargo source build; 197/197 integration tests + 272 Cargo tests pass |
emacs |
30.2 | 🄡 | latest in Guix |
emacs-pgtk |
30.2 | 🄡 | pure-GTK Emacs; latest in Guix |
mpv |
0.41.0 | 🄡 | latest in Guix |
vlc |
3.0.23 | 🄡 | latest stable (VLC 4.x not released) |
keepassxc |
2.7.12 | 🄡 | latest in Guix |
ueberzugpp |
2.9.10 | 🄡 | latest in Guix |
lf |
42 | 🅑 | tag r42; ahead of Guix 41; seven private go.mod modules; full build/test suite passes |
ungoogled-chromium (source) |
147.0.7727.137-1 | 🄡 | = guix's latest; 147 builds over Tor via substitute — only a newer source is Tor-blocked, use -bin ↑ |
masscan |
1.3.2 | 🄡 | latest in Guix |
arp-scan |
1.10.0 | 🄡 | latest in Guix |
netdiscover |
0.21 | 🄡 | latest in Guix |
mtr |
0.96 | 🅑 | ahead of Guix 0.95; official release builds without a downstream patch |
whois |
5.6.6 | 🄡 | latest in Guix |
proxychains-ng |
4.17 | 🄡 | latest in Guix |
aircrack-ng |
1.7 | 🄡 | latest in Guix |
reaver |
1.6.6 | 🄡 | latest in Guix |
kismet |
2025.09.R1 | 🄡 | latest in Guix |
sdb |
2.5.0 | 🅑 | ahead of Guix 2.4.2; current offline/system dependency for radare2; build/runtime passes |
radare2 |
6.2.0 | 🅑 | system Zydis/Zycore + channel sdb 2.5.0; offline build/runtime passes |
rizin |
0.9.1 | 🅑 | updated Meson flags/system libraries; offline hash implementation passes its suite |
binwalk |
3.1.0 | 🄡 | latest in Guix |
age |
1.3.1 | 🄡 | latest in Guix |
evelin-bin |
4.3.0 | 🄕 | official static-musl release tarball; quiet-by-default, scp-like client UX; protocol/key/ticket formats unchanged |
btp |
0.7 | 🄕 | Rust; binaries patchelf'd to glibc/gcc (btpctl, btpd) |
mirim |
1.1.0 | 🄕 | prebuilt Rust binaries (patchelf'd); mirim, mirim-sign (upstream also ships a mirim-gui, not packaged) |
torando-gui |
1.3.4 | 🄕 | Python daemon + GTK4/WebKit GUI; ships a Shepherd service; ip6tables IPv6 killswitch + cross-platform backends (1.3.1–1.3.4: Windows/packaging fixes, Linux build unchanged) |
vaptvupt |
5.2.1 | 🄕 | PQ backup compressor (ML-KEM-768/FIPS 203); source-only; see BREAKING note ↓ |
vaptvupt-gui |
5.2.1 | 🄕 | PySide6/Qt6 frontend; thread-safe _Job, auto-detect Verify |
turborec |
3.7.0 | 🄕 | screen/audio recorder; auto defaults, device/encoder validation, Linux Pulse fallback, cross-platform reliability fixes |
esquema |
0.2.0 | 🄕 | rootless Guile-native container runtime (libseccomp) |
moneyprinterturbo |
1.3.3 | 🄕 | vendored 3rd-party AI short-video generator; voice preview, BGM modes, clip speed/transitions, recovery/update notifications; fonts pruned |
go-github-com-emmansun-base64 |
0.10.0 | 🄓 | kitty build dependency |
go-github-com-sgtdi-fswatcher |
1.3.0 | 🄓 | kitty build dependency |
go-github-com-ebitengine-purego |
0.10.2 | 🄓 | kitty 0.48.2 build dependency (GOPATH-compatible; call C from Go, no cgo) |
Glances' Pyinstrument and lf's seven exact go.mod modules are private build definitions, not public exports, so lf remains one public package and the index remains at 51.
🔌 Services (2)
Two native GNU Shepherd service types for guix system reconfigure — the
systemd units shipped in the upstream packages are inert on Guix System, so the
channel supplies real Shepherd services:
| Service type | Module | Configuration (fields) | Purpose |
|---|---|---|---|
torando-gui-service-type |
(securityops services torando) |
torando-gui-configuration: package, host (def. 127.0.0.1), port (def. 8088), config-file, extra-options, seed-config |
Runs the Torando Control daemon (torando-guid) as root under Shepherd — programs netfilter, pins resolv.conf, manages torrc — and serves the token-injected UI on http://127.0.0.1:8088/. Auto-seeds /etc/torando-gui/config.json on first activation (so GUI changes persist). Requires the networking target; pair with tor-service-type. |
esquema-service-type |
(esquema esquema-service) — shipped by the esquema package |
esquema-configuration (positional): name, rootfs, command, scheme-dir |
Supervises a single rootless esquema container as a Shepherd service (declarative <container>, all namespaces + seccomp + full capability drop). |
Full (operating-system …) examples are below: torando-gui service and esquema service.
⬆️ Bumped ahead of Guix / nonguix (real downloaded hashes)
| Package | This channel | Upstream had | Source |
|---|---|---|---|
| kitty | 0.48.2 | 0.46.2 (guix) | git tag v0.48.2 |
| fish | 4.8.1 | 4.7.1 (guix) | official source + Cargo.lock-matched offline crate set |
| tor | 0.4.9.11 | 0.4.9.8 (guix) | dist.torproject.org tarball |
| torbrowser | 15.0.19 | 15.0.14 (guix) | source build (see caveat) |
| torbrowser-assets | 15.0.19 | (private in guix) | official bundle (fonts + torrc-defaults) |
| openshot | 3.5.1 | 3.4.0 (guix) | git tag v3.5.1 |
| google-chrome-stable | 151.0.7922.108 | 148.0.7778.215 (nonguix) | dl.google.com .deb |
| mullvad-vpn-desktop | 2026.3 | 2025.8 (small-guix) | cdn.mullvad.net .deb (vendored) |
| librewolf | 153.0.3-1 | 151.0.4-1 (guix) | source build (Firefox 153.0.3 + LibreWolf overlay; l10n 6795ea14) |
| steam | 1.0.0.87 (Valve stable) | 1.0.0.85 (nonguix) | Valve precise archive (nonguix container rebuilt around bumped bootstrap) |
| glances | 4.5.6 | 4.3.0 (guix) | git tag v4.5.6 (pyproject; private pyinstrument 5.1.3) |
| lynis | 3.1.7 | 3.1.1 (guix) | git tag 3.1.7 (shell; plugins stripped) |
| mtr | 0.96 | 0.95 (guix) | official release tarball |
| sdb | 2.5.0 | 2.4.2 (guix) | upstream git revision 2.5.0 |
| radare2 | 6.2.0 | 6.1.4 (guix) | upstream git revision 6.2.0; system Zydis/Zycore |
| rizin | 0.9.1 | 0.8.2 (guix) | official release tarball; updated Meson/system-dependency flags |
| lf | 42 | 41 (guix) | git tag r42; private exact go.mod graph: uax29/v2 2.7.0, displaywidth 0.11.0, tcell/v3 3.4.1, fsnotify 1.10.1, x/sys 0.47.0, x/term 0.45.0, x/text 0.40.0 |
✅ Re-exported — already latest in Guix/nonguix (track upstream automatically)
alacritty 0.17.0 · emacs 30.2 · emacs-pgtk 30.2 · mpv 0.41.0 ·
vlc 3.0.23 · keepassxc 2.7.12 · ueberzugpp 2.9.10
⚠️ Re-exported — newer upstream exists but a bump is impractical here
| Package | This channel (= guix) | Upstream | Why not bumped |
|---|---|---|---|
| ungoogled-chromium (source) | 147.0.7727.137-1 | 151.0.7922.108-1 | 147 builds over Tor (source is a bordeaux substitute); a newer-version source-bump is impossible over Tor — the "-lite" base tarball lives only on Google's GCS, which 403-blocks every Tor exit and has no substitute yet (see caveat). Use the current ungoogled-chromium-bin ↓ |
ungoogled-chromium-bin —
151.0.7922.108-1is the current upstream PortableLinux x86_64 release. Its GitHub-hosted asset is Tor-reachable, pinned by its downloaded hash, and wrapped with nonguix'schromium-binary-build-system. The exact build passes,chromium --versionreportsChromium 151.0.7922.108, and that release is active in the Home profile as the recommended current Chromium.librewolf was in this table; it is now bumped to 153.0.3-1 (see the table above and the LibreWolf caveat).
The 2026-08-09 authoritative audit covered every channel definition, not only updater-visible packages, and found every package outside this refresh current apart from the documented source-Chromium 147 fallback, including all first-party apps. The separate system/Home snapshot audit is in AUDIT.md — 391 packages: 124 current, 139 outdated, 128 unknown.
SecurityOps / first-party apps
The package home-page fields now point to each active public project: Evelin
and BTP use the canonical Forgejo projects, while
Mirim,
Torando,
VaptVupt (CLI and GUI),
TurboRecorder, and
Esquema use their berkeley Codeberg
mirrors. The channel itself remains canonical on git.securityops.com.br and
mirrored on Codeberg and GitHub. To keep builds self-contained, package
sources/artifacts are still vendored into securityops/packages/sources/ and
referenced with local-file (content-addressed, no hash field) rather than
fetched at build time.
| Package | Version | How | Status |
|---|---|---|---|
| evelin-bin | 4.3.0 | official static-musl release tarball (7 fully-static binaries: ev, evelin-agent/-client/-keygen/-keyscan/-server, evelin-multisig-verify). 4.3.0 makes the client quiet by default and adds scp-like copy UX; protocol, key, and ticket formats are unchanged |
✅ builds & runs (evelin-client 4.3.0) |
| btp | 0.7 | built from source (cargo), binaries patchelf'd to glibc/gcc |
✅ builds & runs (btpctl, btpd) |
| mirim | 1.1.0 | prebuilt x86_64 release binaries (copy-build-system + patchelf to store glibc/gcc), like btp/evelin-bin. v1.1.0 moved the binaries to the archive root and adds a mirim-gui (not packaged — needs a graphical runtime) |
✅ builds & runs (mirim, mirim-sign) |
| torando-gui | 1.3.4 | built from source (pure Python daemon; native GTK4/WebKit GUI optional, browser fallback). 1.2.0/1.3.0: ip6tables IPv6 killswitch (closes the v6 leak) + native macOS/BSD/Windows backends; 1.3.1–1.3.4: Windows all-in-one + packaging fixes — Linux channel build unchanged | ✅ builds, installs & runs (torando-gui, torando-guid) |
| vaptvupt | 5.2.1 | built from source (C11 Makefile; source-only since 4.1.0, links only -lm -lpthread; make check crypto/security suite runs in-build — since 5.0.0 incl. FIPS 203 cross-validation against OpenSSL 3.5, verified green). 5.0.0: ML-KEM-768 now genuinely FIPS 203-conformant; BREAKING — --pq/--pq-only keys & archives from ≤ 4.2.1 no longer decrypt: regenerate keys + re-encrypt (password mode/plain compression unaffected). 5.1.0–5.2.1: codec 2.65.0→2.65.3 (large text-ratio gains, ~2× faster extreme, byte-identical output); wire format stays v1.6, interoperable with 5.0.x. 4.2.0: critical --dedup keystream-reuse fix (re-encrypt --dedup archives from ≤ 4.1.0) |
✅ builds & runs; --pq-only round-trip verified |
| vaptvupt-gui | 5.2.1 | PySide6/Qt6 frontend from the same tarball (versioned with the CLI); 5.0.0 reworks it for source-only builds (build-aware Hybrid/Full-PQ selector, PQ-key auto-detect) + XWayland fallback so it appears on Sway; 5.2.x: thread-safe _Job controller (fixes compress crash/hang/corruption), CR progress frames parsed, robust Verify/Extract with encryption auto-detect + guided credentials; launcher pins the CLI via VAPTVUPT_BIN |
✅ builds (vaptvupt-gui, zupt-gui); GUI --selftest OK |
| turborec | 3.7.0 | built from source (pure-Python CLI + Tkinter GUI + bash X11 launcher; self-contained #!/bin/sh shims pin python3/bash + ffmpeg/pactl/xrandr/xdpyinfo/lspci, + Wayland wf-recorder/wlr-randr/swaymsg + wmctrl; 3.1.0 --audio-channels, 3.2.0 -R/--resolution scaling, 3.3.0 live streaming record --stream KEY (YouTube/RTMPS default) + adaptive quality, 3.4.0 security-audit fixes, 3.5.0 webcam PiP overlay (--camera) + mic noise suppression (--denoise), 3.6.0 Wayland capture, 3.7.0 auto defaults, device/encoder validation, Linux Pulse fallback, and cross-platform reliability fixes) |
✅ builds & runs (turborec, turborecorder) |
| esquema | 0.2.0 | built from source (C core libesquema.so via make + libseccomp; Guile modules byte-compiled; ships the (esquema esquema-service) Shepherd service) |
✅ builds & FFI-loads (esquema-init → 42); functional/security/ASan suites green |
| moneyprinterturbo | 1.3.3 | vendored third-party (harry0703; not a forge repo). AI one-click short-video generator; adds voice preview, generated/matched/custom BGM modes, clip speed/transitions, recovery, and update notifications. The same source-pruning policy remains: proprietary CJK fonts are dropped and references point to bundled WenQuanYi Zen Hei; the self-contained launcher builds a first-run venv over Tor | ✅ builds; launcher/version metadata verified (venv on first run) |
To re-vendor an updated app: rebuild/redownload its artifact into
packages/sources/, bump version, and guix build -L . <pkg>.
Running torando-gui as a Shepherd service (Guix System)
Guix System runs daemons under the GNU Shepherd, not systemd — so the
systemd unit inside the torando-gui package is inert on Guix. The channel
ships a native service type in (securityops services torando). Add it to your
operating-system:
(use-modules (securityops services torando))
(operating-system
;; …
(services
(cons* (service torando-gui-service-type) ; daemon on 127.0.0.1:8088
(service tor-service-type) ; Tor itself
%desktop-services))) ; provides the 'networking target torando-gui requires
guix system reconfigure, then herd start torando-gui (or reboot). The daemon
runs as root under Shepherd, logs to /var/log/torando-gui.log, and serves the
token-injected UI on http://127.0.0.1:8088/; run the torando-gui launcher to
open it. Configuration fields: host, port, package, config-file,
seed-config, extra-options.
Turnkey on Guix.
/etc/tor/torrcis a read-only store symlink owned bytor-service-type, so torando-gui's own torrc management cannot write it. The service therefore auto-seeds/etc/torando-gui/config.jsonon first activation (only if absent, so GUI changes persist) with"manage_torrc": falseand"dns_port": 5353— matching ator-service-typeconfigured with(dns-port 5353)(as on this host; torando's own default is 53, and TransPort 9040 / SocksPort 9050 / ControlPort 9051 are already torando's defaults). Override via theseed-configfield (a JSON string, or#fto seed nothing). Netfilter rules, DNS pinning, killswitch and status all work; Tor service control from the GUI usessystemctland is a no-op on Guix — manage Tor withherd.
Esquema — rootless Guile-native container runtime
esquema (new module (securityops packages containers)) is a first-party,
security-first container runtime built natively in Scheme. A small C core
(libesquema.so, seccomp-BPF via libseccomp) performs the whole isolation
sequence in async-signal-safe code between fork and execve: user + mount +
PID + UTS + IPC + net + cgroup namespaces, rootless uid/gid maps, pivot_root
into the rootfs with the host tree detached, a full capability drop
(bounding set + ambient + capset + securebits + no_new_privs), a seccomp
allowlist with a stacked filter that kills TIOCSTI/TIOCLINUX terminal
injection, and best-effort cgroup v2 limits — stronger isolation than a plain
guix shell while staying daemon-free and rootless (~13 ms startup).
guix pull # or: -L ~/securityops-channel for the working tree
guix install esquema
(use-modules (esquema runtime) (esquema container))
(run-container
(make-container "web" "/path/to/rootfs" '("/bin/httpd" "-p" "8080")
#:rootfs-ro? #t
#:limits (make-limits (* 256 1024 1024) 128 50000 100000)))
make-container is secure-by-default (all namespaces, seccomp on, every
capability dropped). Installing the package puts the (esquema …) Guile
modules on GUILE_LOAD_PATH and repoints the FFI at the store libesquema.so,
so a bare (use-modules (esquema runtime)) works. To supervise a container as
a Guix System service, use the bundled service type:
(use-modules (esquema esquema-service)
(securityops packages containers)) ; for the esquema package binding
;; esquema-configuration is a plain SRFI-9 record — POSITIONAL args, in order:
;; name, rootfs, command, scheme-dir.
(service esquema-service-type
(esquema-configuration
"web"
"/srv/web"
'("/bin/httpd" "-p" "8080")
(file-append esquema "/share/guile/site/3.0")))
Security toolset
security.scm provides a curated security toolset, re-exporting current Guix
packages and carrying eight definitions ahead of Guix (inherit + version +
real source hash): nmap 7.99, fping 5.5, mtr 0.96, hydra 9.7, sdb
2.5.0, radare2 6.2.0, rizin 0.9.1, and lynis 3.1.7. The earlier
MTR/Radare2/Rizin deferrals are superseded: MTR's official source contains both
required utils.h files; Radare2 now uses Guix's system Zydis/Zycore with the
channel's current SDB; and Rizin's 0.9 Meson flags and offline hash backend are
wired explicitly. The exact SDB 2.5.0 and Radare2 6.2.0 channel builds and
runtime checks pass, as does Rizin's previously verified complete test suite.
nmap 7.99 · masscan · arp-scan · netdiscover · fping 5.5 · mtr 0.96 · whois · proxychains-ng · aircrack-ng · reaver · kismet · hydra 9.7 (THC) · sdb 2.5.0 · radare2 6.2.0 · rizin 0.9.1 · binwalk · age · lynis 3.1.7 (bold = bumped ahead of Guix)
Not yet in Guix (TODO — package on request; quick: Go/Rust single-binaries;
heavy: zaproxy/volatility3): sqlmap · nikto · gobuster · ffuf ·
rustscan · dirb · wfuzz · whatweb · sslscan · wapiti · zaproxy ·
john-the-ripper · hashid · bettercap · ettercap · mitmproxy · dsniff ·
foremost · sleuthkit · volatility3 · american-fuzzy-lop · honggfuzz ·
exploitdb · theharvester · recon-ng · dnsenum · fierce · zmap.
Install
This channel depends on nonguix (for google-chrome, steam and Mullvad's
build system) — keep your nonguix entry in channels.scm. Add securityops with
its (introduction …) so guix pull verifies every commit's signature:
(channel
(name 'securityops)
(url "https://git.securityops.com.br/cristiancmoises/securityops-channel")
(branch "main")
(introduction
(make-channel-introduction
"af46f5cce66179f3e53f87c86ca2538c8fc63f98"
(openpgp-fingerprint
"0CFA 43B9 AA96 42EA AF2B E983 C4C6 61C9 ECFB 46E8"))))
The official URL clones over HTTPS with no account. Prefer a mirror? Swap the
url — the introduction is identical:
(url "https://codeberg.org/berkeley/securityops-channel") ; or
(url "https://github.com/cristiancmoises/securityops-channel")
Then:
guix pull
guix install kitty fish tor torbrowser openshot glances librewolf \
google-chrome-stable \
ungoogled-chromium-bin mullvad-vpn-desktop lf mtr sdb radare2 rizin
Because every package here has a version ≥ what guix/nonguix ships,
guix install <pkg> transparently prefers this channel for the bumped ones.
Adding
securityopswithout a(commit …)line tracks itsmainbranch; add one to pin a fully reproducible pull. The(introduction …)is set once and is independent of any later pin.
Clone or pull over HTTPS
Clone over HTTPS from the official forge — or any mirror — with no account:
git clone https://git.securityops.com.br/cristiancmoises/securityops-channel # official
git clone https://codeberg.org/berkeley/securityops-channel # mirror
git clone https://github.com/cristiancmoises/securityops-channel # mirror
Verify the introduction and signatures
The (introduction …) pins the first signed commit and the maintainer key, so
guix pull authenticates every commit — a tampered or unsigned commit aborts the
pull. To check the key out of band:
gpg --recv-keys 0CFA43B9AA9642EAAF2BE983C4C661C9ECFB46E8
gpg --fingerprint 0CFA43B9AA9642EAAF2BE983C4C661C9ECFB46E8
# → 0CFA 43B9 AA96 42EA AF2B E983 C4C6 61C9 ECFB 46E8
git -C securityops-channel log --show-signature -1
Troubleshooting
guix pullsays the channel is unauthenticated / introduction mismatch. Yourchannels.scmentry is missing the(introduction …)above (copy it verbatim) or pins a commit older than the introduction commit.failed to authenticate commit … signature verification failed. Import0CFA43B9AA9642EAAF2BE983C4C661C9ECFB46E8into your keyring; authentication applies from the introduction commit forward.- nonguix introduction conflict. Keep your
nonguixpin at or after its introduction commit897c1a47…so both channels authenticate.
Consuming the channel from /etc/config.scm and home.scm
A bare bumped package such as kitty, fish, radare2, or
google-chrome-stable written against (gnu packages …) / (nongnu packages …) resolves to guix's own (older) package, not this channel's — module
bindings are resolved by the module you import, while guix install <name> is
what picks the highest version by name. To run the bumped versions
declaratively, import the channel module with a prefix and reference the
prefixed symbol:
;; in (use-modules …)
((securityops packages terminals) #:prefix so:) ; so:kitty 0.48.2 (gnu 0.46.2)
((securityops packages shells) #:prefix so:) ; so:fish 4.8.1 (gnu 4.7.1)
((securityops packages tor) #:prefix so:) ; so:tor 0.4.9.11, so:torbrowser 15.0.19
((securityops packages browsers) #:prefix so:) ; so:google-chrome-stable 151, so:librewolf 153.0.3-1
((securityops packages utils) #:prefix so:) ; so:lf 42 (gnu 41; tag r42)
((securityops packages security) #:prefix so:) ; so:mtr, so:sdb, so:radare2, so:rizin
((securityops packages vpn) #:prefix so:) ; so:mullvad-vpn-desktop 2026.3
((securityops packages video) #:prefix so:) ; so:openshot 3.5.1 (gnu 3.4.0)
((securityops packages games) #:prefix so:) ; so:steam 1.0.0.87 (nonguix 1.0.0.85)
((securityops packages monitoring) #:prefix so:) ; so:glances 4.5.6 (gnu 4.3.0)
;; …then in the package list use so:kitty, so:fish, so:radare2, …
;; and for the daemon, override the service field:
(service mullvad-daemon-service-type
(mullvad-daemon-configuration
(mullvad-vpn-desktop so:mullvad-vpn-desktop)))
Use this pattern for every package carried ahead of guix/nonguix. The remaining
re-exports (alacritty, emacs, mpv, vlc, keepassxc, and ueberzugpp)
are byte-identical to guix's and can remain bare symbols.
To apply after a channel edit: guix pull (picks up the new securityops
commit), then guix system reconfigure /etc/config.scm and guix home reconfigure ~/.config/guix/home.scm — or skip the pull and pass
-L ~/securityops-channel to reconfigure to use the working tree directly.
Layout
securityops-channel/
├── update-channel # check + auto-apply upstream updates (one command)
├── .guix-channel # manifest: version, news-file, public url, nonguix dep
├── .guix-authorizations # OpenPGP keys allowed to sign commits (channel auth)
├── etc/news.txt # `guix pull --news` entries (per release)
├── securityops/packages/
│ ├── terminals.scm # kitty 0.48.2 (bump) + its three Go deps, alacritty (re-export)
│ ├── tor.scm # tor, torbrowser, torbrowser-assets (bumps)
│ ├── shells.scm # fish 4.8.1 hermetic Cargo source build
│ ├── fish-crates.scm # Fish 4.8.1 Cargo.lock-matched offline sources
│ ├── emacs.scm # emacs, emacs-pgtk (re-export)
│ ├── video.scm # openshot (bump), mpv, vlc (re-export)
│ ├── utils.scm # lf 42/tag r42 (bump) + seven private Go modules; keepassxc/ueberzugpp (re-export)
│ ├── browsers.scm # google-chrome (bump), librewolf + ungoogled-chromium-bin (re-export of ↓), ungoogled-chromium (re-export)
│ ├── librewolf.scm # librewolf 153.0.3-1 (vendored make-librewolf-source)
│ ├── chromium.scm # ungoogled-chromium-bin 151.0.7922.108-1 (prebuilt)
│ ├── vpn.scm # mullvad-vpn-desktop (vendored bump)
│ ├── games.scm # steam 1.0.0.87 stable (nonguix container, bumped bootstrap)
│ ├── apps.scm # first-party: evelin-bin, btp, mirim, torando-gui, vaptvupt(+gui), turborec, moneyprinterturbo (vendored)
│ ├── security.scm # curated toolset; mtr/sdb/radare2/rizin + other bumps/re-exports
│ ├── monitoring.scm # glances 4.5.6 (bump) + python-pyinstrument 5.1.3 (private dep)
│ ├── containers.scm # esquema 0.2.0 — rootless Guile-native container runtime (first-party, from source)
│ └── sources/ # vendored release/built artifacts (local-file)
├── securityops/services/
│ └── torando.scm # torando-gui-service-type (GNU Shepherd service)
├── README.md CHANGELOG.md AUDIT.md LICENSE
└── .dir-locals.el .gitignore
Each module imports the matching upstream module with a prefix
(#:use-module ((gnu packages tor) #:prefix tor:)) and either re-exports the
binding or defines (package (inherit tor:tor) (version …) (source …)). Most
definitions are a few lines, so upstream bugfixes flow through automatically.
Caveats (read before relying on a build)
Tor Browser (source build). Guix's make-torbrowser and torbrowser-assets
are module-private, so torbrowser here inherits guix's package and overrides
version + source (the 15.0.19 Firefox source, 140.13.0esr-15.0-1-build2)
plus the two version constants guix's make-torbrowser bakes from its own
%torbrowser-version (15.0.14): without this the browser would report 15.0.14
on a 15.0.19 engine, so the recipe rewrites --with-base-browser-version →
15.0.19 and MOZ_BUILD_DATE → the official 15.0.19 BuildID 20260720080000
(from the upstream bundle's application.ini) — the About dialog now reads
15.0.19. The engine, displayed base-browser version, and MOZ_BUILD_DATE
are therefore 15.0.19. The inherited fonts and torrc-defaults still come from
Guix's private 15.0.14 asset package, but a byte comparison confirms that all
147 font files and torrc-defaults are identical to the official 15.0.19
bundle, so those assets are equivalent. Only localization is known-stale:
the private l10n pins remain at 15.0.14 even though 15.0.19 moved the
base-browser translation revision 6749f7ce→38c3b4e6 and the tor-browser
revision a2e92e2c→510b52a6. The standalone torbrowser-assets 15.0.19
package supplies the current public bundle, but it cannot update the inherited
package's private l10n inputs. Tor Browser spoofs navigator.buildID to web
content regardless.
LibreWolf 153.0.3-1 (full build and runtime verified). The module
securityops/packages/librewolf.scm vendors guix's private
make-librewolf-source (Firefox 153.0.3 source + LibreWolf 153.0.3-1 overlay +
l10n) and then inherits guix's librewolf. It overrides the release source,
the official MOZ_BUILD_DATE/BuildID 20260804215502, and the two Firefox 153
minimum-version dependencies missing from the pinned Guix: private
rust-cbindgen 0.29.4 instead of 0.29.2 and private nss-rapid 3.126 instead
of 3.124. The l10n commit is the revision from
firefox-153.0.3/browser/locales/l10n-changesets.json (6795ea14). After the
upstream Makefile matcher was corrected for the current variable assignment,
the complete Firefox/overlay/l10n computed-origin source assembled and verified
successfully, and the exact inherited build reaches a successful mach configure with cbindgen, NSPR, and NSS accepted. The full multi-hour,
swap-backed LTO build also passes (see the RAM note below). Its exact ungrafted
output is /gnu/store/acyszcmi1h01qb4258ribxlx1fa86j88-librewolf-153.0.3-1;
runtime reports Mozilla LibreWolf 153.0.3-1, and both application.ini and
platform.ini carry BuildID 20260804215502. Grafted variants of that build
are active in both the Home and direct user profiles and report the same
version/BuildID. The package remains wired into /etc/config.scm and
home.scm as so:librewolf.
Building Firefox-class packages (librewolf / torbrowser / icecat) on a RAM-constrained host. Their final rust crate
gkrustis whole-program LTO — a single rustc that needs ~14 GiB — so on a 15 GiB box it OOM-kills at every-j(24 down to 1), with or without--disable-lto. The fix is swap: a 24 GiB disk swapfile (now declared inconfig-xlibre.scmviaswap-devices) lets the full-LTO build complete (peaks spill to disk); thenguix build --cores=4 librewolffinishes cleanly and the browser runs.
ungoogled-chromium — the shipped source build (147) works over Tor; a newer
source is what's blocked. To be precise: the re-exported source
ungoogled-chromium 147.0.7727.137-1 (= the version the pinned guix ships)
builds fine on this Tor-only host — its source comes as a .tar.zst
substitute from bordeaux.guix.gnu.org, which is Tor-reachable (verified
2026-07-23: guix build -S ungoogled-chromium → 0 built, 1.1 GB downloaded as
chromium-147.0.7727.137-lite.tar.zst). What is impossible over Tor is a
from-source bump to a newer version: guix assembles the source
from a Chromium "-lite" base tarball that lives only on Google's
commondatastorage GCS bucket, and that bucket 403-blocks every Tor exit
(verified across 6+ rotated circuits — even the tiny .hashes integrity file and
guix's own known-good 147 tarball; no Wayback copy exists). guix can build
existing versions only because that source is on bordeaux; a brand-new release
has no substitute yet, so its base tarball must come straight from Google. Bumping
this package per-hand isn't viable either — it would mean vendoring guix's whole
newer recipe (version-specific ungoogled patch set) and still hitting the
Google-only tarball. (It would also be a multi-hour / ~30GB-RAM compile on 15GB
RAM regardless.) For a current engine: the channel ships
ungoogled-chromium-bin — the official upstream prebuilt portable Linux
x86_64 binary 151.0.7922.108-1. Its PortableLinux asset is hosted on GitHub
(Tor-reachable), pinned by its downloaded hash, and wrapped with nonguix's
chromium-binary-build-system (patchelf onto the Guix glibc loader + library
set; no bundled chrome-sandbox, so Chromium uses the unprivileged
user-namespace sandbox). The exact build passes and chromium --version
reports Chromium 151.0.7922.108. The source-built ungoogled-chromium (147)
remains re-exported for anyone wanting the substitutable build;
google-chrome-stable 151 is the other current engine active in the Home
profile.
Mullvad (vendored, x86_64-only). Bumped to 2026.3 — Mullvad's published
stable desktop release as of 2026-06-22 (the deb/latest redirect resolves to
.../releases/2026.3/; 2026.4+ aren't promoted yet — re-check the redirect
before bumping further). The source URL moved off GitHub (which no longer carries
desktop .debs) to cdn.mullvad.net. Vendored rather than inherited because the
build phases bake version into the .deb unpack step. The
mullvad-daemon-service-type in /etc/config.scm is pointed at this package so
the daemon itself runs 2026.3 (not just a profile entry). Add the aarch64
variant + hash if you need it.
Verification
Done 2026-06-21 against the live daemon (egress works through Tor):
- Real hashes, from actual downloads: tarballs via
guix download; git tags (kitty,openshot) viaguix hash -rxovergit clone -b <tag>;.debs (google-chrome,mullvad) viaguix download. - Channel evaluates:
guix build -L . [-L <nonguix>] -n <all packages>computes the full derivation graph with no errors (modules load exactly as a channel does). - Sources fetch + hash-match:
guix build -L . -Ssucceeds for every bumped package (tor,torbrowser,torbrowser-assets,kitty,openshot,google-chrome-stable,mullvad-vpn-desktop;librewolf's computed-origin source was assembled & verified 2026-06-22) —kitty/openshotactually re-ran theirgit-fetchderivations and matched. - 2026-07-23 — built, installed & run-verified into the home profile:
kitty0.48.0 (kitty --version→ 0.48.0) andtorbrowser15.0.19, the latter checked at the string level (the builtomni.ja'smodules/AppConstants.sys.mjshasBASE_BROWSER_VERSION = 15.0.19). Also confirmed the re-exported sourceungoogled-chromium147 fetches over Tor as abordeauxsubstitute (guix build -S→ 0 built, 1.1 GB downloaded). - 2026-07-25 — final refresh built, installed, and profile-verified:
fish4.8.1,kitty0.48.1,google-chrome-stable150.0.7871.186,ungoogled-chromium-bin150.0.7871.186-1,evelin-bin4.3.0,turborec3.7.0,moneyprinterturbo1.3.3,mtr0.96,sdb2.4.8,radare26.1.8, andrizin0.9.1. Fish passed 197/197 integration tests and 272 Cargo tests; Rizin's complete suite passed; version/runtime smoke checks passed for the applicable browser, terminal, and vendored-app outputs. The vendored-source and font-pruning policies remain unchanged. The Home profile carries Fish, Kitty, Chrome, ungoogled Chromium, and MoneyPrinterTurbo; the user profile carries Evelin, TurboRecorder, MTR, SDB, Radare2, and Rizin. - 2026-08-09 — authoritative channel audit and refresh, validation and
profile activation complete: the audit checked every public package and
private dependency and found all releases outside the listed refresh current,
apart from the documented source-Chromium 147 fallback, including Tor 0.4.9.11,
Tor Browser 15.0.19, Steam 1.0.0.87 stable, and all first-party
apps. Tor Browser's engine/branding is current, while its inherited private
translation pins have the documented 15.0.14 caveat. Exact build/runtime or
test checks pass for Kitty 0.48.2, Glances 4.5.6
with private Pyinstrument 5.1.3, SDB 2.5.0, Radare2 6.2.0, and lf 42 (
r42) with its exact seven-module private go.mod graph. LibreWolf 153.0.3-1's complete Firefox/overlay/l10n source assembles with l10n pin6795ea14; private cbindgen 0.29.4, NSS 3.126, and official BuildID20260804215502satisfy the exactmach configure; the full Firefox/LTO build passes and runtime reportsMozilla LibreWolf 153.0.3-1. Exact builds and runtime checks also pass for Chrome 151 and ungoogled Chromium 151; both report 151.0.7922.108. The Home profile is verified with Fish 4.8.1, Kitty 0.48.2, Chrome 151.0.7922.108, ungoogled Chromium 151.0.7922.108, LibreWolf 153.0.3-1, lf 42, and Tor Browser 15.0.19 (Firefox ESR 140.13.0;BASE_BROWSER_VERSION = 15.0.19). The direct user profile is verified with Fish 4.8.1, LibreWolf 153.0.3-1, SDB 2.5.0, Radare2 6.2.0, and Glances 4.5.6/PsUtil 7.2.2.
Future multi-hour compiles (emacs, vlc, and Firefox-based browser bumps) are
left to the corresponding guix pull / reconfigure.
Keeping packages current — ./update-channel
One command reports updater-visible releases for its registered subset and can apply the recipe edits that Guix's updater supports. It is a convenience helper, not a replacement for the release-by-release audit of all 51 public packages:
./update-channel # report current vs updater-visible candidates
./update-channel update --build --commit # apply supported edits, build them, sign the commit
A failed upstream or current-version lookup is counted as unknown/failed and
makes check exit nonzero, so an incomplete network audit cannot look green.
Esquema has no public release tags, so its checker reads the authoritative
ESQUEMA_VERSION_STRING from the upstream header instead.
- Auto where supported (via
guix refresh -u— rewritesversion+ realsha256): github/gnu/pypi-backed packages (kitty,openshot,tor,glances, …).--buildvalidates the derivations produced by those edits; a check alone does not validate builds, runtime behavior, or profile activation. - Reported, apply deliberately: source-builds (
torbrowser,librewolf— auto-bumping triggers multi-hour compiles) and binary/vendored packages (google-chrome-stable,steam,mullvad-vpn-desktop,ungoogled-chromium-bin, the first-party apps). Reported tags also need artifact inspection: the updater candidates and binary assets can appear at different times, so verify each selected artifact and its runtime independently.
Bumping a package later
guix refresh <pkg> # find latest
guix download <tarball-url> # url-fetch hash
git clone --depth 1 -b <tag> <repo> /tmp/s && guix hash -rx /tmp/s # git hash
# edit version + base32 in securityops/packages/*.scm
guix build -L ~/securityops-channel -S <pkg> # verify source
guix build -L ~/securityops-channel -n <pkg> # verify it evaluates
When a re-exported package falls behind upstream, turn its
(define-public foo bar:foo) into a full (package (inherit bar:foo) (version …) (source …)).
Publishing & authentication
The channel is published and authenticated. Everyone clones and pulls over
HTTPS from git.securityops.com.br (or the Codeberg/GitHub mirrors above); push
is restricted to the maintainer. Every commit is GPG-signed with ed25519
0CFA 43B9 AA96 42EA AF2B E983 C4C6 61C9 ECFB 46E8; .guix-authorizations lists
that key as the sole authorized signer, and the channel (introduction …) in
Install pins the first signed commit — so guix pull verifies the whole history
and refuses a tampered or unsigned commit. The authorized public key is published
on the channel's keyring branch (the standard guix git authenticate layout),
which guix pull fetches automatically. To rotate the key, add the new
fingerprint to .guix-authorizations in a commit signed by the old key.
License
Channel code: GPL-3.0-or-later (see LICENSE); vpn.scm carries
the upstream small-guix copyright headers it was vendored from. Each packaged
program keeps its own upstream license, declared in its definition.