Music on a Wikven site is engraved once, while the site is being built, and what the reader gets is the engraving. Score is the extension for it. Like a chart it wants a program of its own beside the wiki, and unlike one it is not bundled, so a site says where to fetch it as well as where the program is.

This page engraves one:

\relative c' { c d e f g a b c }

A rising scale, and in the page it is an <svg> with a PNG beside it for a browser that wants one. Both are files this build wrote; nothing is fetched while you read.

What a site declares

extensions:
  - Score
config:
  ScoreSafeMode: false
  ScoreUseSvg: true
  ShellboxUrls:
    score: http://host.docker.internal:8080
  ShellboxSecretKey: a long random string
  WikvenRepositories:
    Score:
      repository: https://github.com/wikimedia/mediawiki-extensions-Score.git
      commit: acf9e50a3a5afde00ad755665e70114d63cba64b

ScoreUseSvg asks for the engraving as a drawing rather than a photograph of one, and trims the page down to the music; without it you get a whole sheet of paper with a scale in the corner.

Where LilyPond is

Score does not run LilyPond itself. It sends the command to a Shellbox — a small service whose one job is to run a command somewhere other than where the wiki is — and LilyPond lives there. So what a site needs beside it is a Shellbox with LilyPond in it, at an address, exactly as a chart needs a renderer.

That is also the answer to ScoreSafeMode. LilyPond has had no safe mode since version 2.23.12, and a <score> is a program it will run; Score refuses to draw anything until you say you know. Setting it false is honest when LilyPond is in a container of its own, and is what the sandbox is for.

ShellboxSecretKey is not optional here even though MediaWiki lets it be. Without it the build quietly runs the command itself instead of sending it, and a bake has no LilyPond, so the page fills with an error rather than music. The same string goes in the Shellbox's own configuration file.

The key under ShellboxUrls is score, which is what Score calls the service. It is not score-lilypond, which is the route it asks that service for, and naming that instead fails the same quiet way.

This site runs two such services, a chart renderer and this, so it cannot call both host.docker.internal; its own configuration file names this one score-shellbox. With one service the name above is the one to use — see Charts for which name belongs to which way of baking.

Writing music

<score>\relative c' { c d e f g a b c }</score>

Between the tags is LilyPond, and lang="ABC" takes ABC instead. Music LilyPond cannot read stops the build rather than publishing an error where the notes should be.

← Math