[Guix packaging] Claude Code terminal CLI #232

Closed
opened 2026-08-17 06:56:26 +00:00 by htayj · 0 comments
htayj commented 2026-08-17 06:56:26 +00:00 (Migrated from github.com)

Candidate

Package the official Claude Code terminal CLI for Guix.

  • Product documentation: https://code.claude.com/docs/en/overview
  • Installation and release verification: https://code.claude.com/docs/en/setup
  • Installed deliverable: claude agentic coding CLI
  • Official Linux targets: x86_64 and aarch64, with glibc and musl variants
  • Distribution: signed native binaries, plus apt, RPM, apk, Homebrew, WinGet, and npm installers
  • Runtime access: Claude Pro, Max, Team, Enterprise, Console, or a supported third-party provider

Packaging approach

Anthropic's current npm package installs the same per-platform native executable as the standalone installer; it is not a conventional Node application build. Prefer a versioned official Linux binary from Anthropic's release repository rather than running the network installer or npm postinstall hook. Pin its SHA-256 from the release manifest.json, retain the manifest/signature provenance, and investigate the applicable license and redistribution terms before merging.

Research and document:

  • the latest or stable release version chosen for the channel and its immutable artifact URL;
  • license terms for the CLI, bundled components, and redistribution through a Guix channel;
  • native library requirements and whether the glibc executable needs patching or an FHS compatibility environment;
  • the bundled ripgrep behavior and whether USE_BUILTIN_RIPGREP=0 should select Guix's ripgrep;
  • shell, Git, sandboxing, browser-login, MCP, plugin, hook, and credential-storage behavior;
  • architecture support for x86_64 and aarch64;
  • disabling every self-update path with DISABLE_UPDATES=1, since upgrades must remain Guix-managed.

Do not execute curl | bash, configure Anthropic's system package repositories, or permit a build/install phase to fetch the executable dynamically.

Acceptance checks

  • guix lint -L . claude-code passes without new errors.
  • guix build -L . claude-code succeeds without build-time network access.
  • claude --version and non-authenticated help/diagnostic smoke checks run in a clean Guix environment.
  • The package supports each declared architecture with independently pinned hashes.
  • The installed launcher cannot replace itself or download another Claude Code version.
  • Authentication tokens, settings, plugins, MCP configuration, and session state remain in user directories and are never embedded in the package or store.
  • Proprietary-service requirements and the resolved license/redistribution status are documented clearly.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-17T06:56:26Z.

## Candidate Package the official **Claude Code terminal CLI** for Guix. - Product documentation: https://code.claude.com/docs/en/overview - Installation and release verification: https://code.claude.com/docs/en/setup - Installed deliverable: `claude` agentic coding CLI - Official Linux targets: x86_64 and aarch64, with glibc and musl variants - Distribution: signed native binaries, plus apt, RPM, apk, Homebrew, WinGet, and npm installers - Runtime access: Claude Pro, Max, Team, Enterprise, Console, or a supported third-party provider ## Packaging approach Anthropic's current npm package installs the same per-platform native executable as the standalone installer; it is not a conventional Node application build. Prefer a versioned official Linux binary from Anthropic's release repository rather than running the network installer or npm postinstall hook. Pin its SHA-256 from the release `manifest.json`, retain the manifest/signature provenance, and investigate the applicable license and redistribution terms before merging. Research and document: - the latest or stable release version chosen for the channel and its immutable artifact URL; - license terms for the CLI, bundled components, and redistribution through a Guix channel; - native library requirements and whether the glibc executable needs patching or an FHS compatibility environment; - the bundled ripgrep behavior and whether `USE_BUILTIN_RIPGREP=0` should select Guix's `ripgrep`; - shell, Git, sandboxing, browser-login, MCP, plugin, hook, and credential-storage behavior; - architecture support for x86_64 and aarch64; - disabling every self-update path with `DISABLE_UPDATES=1`, since upgrades must remain Guix-managed. Do not execute `curl | bash`, configure Anthropic's system package repositories, or permit a build/install phase to fetch the executable dynamically. ## Acceptance checks - `guix lint -L . claude-code` passes without new errors. - `guix build -L . claude-code` succeeds without build-time network access. - `claude --version` and non-authenticated help/diagnostic smoke checks run in a clean Guix environment. - The package supports each declared architecture with independently pinned hashes. - The installed launcher cannot replace itself or download another Claude Code version. - Authentication tokens, settings, plugins, MCP configuration, and session state remain in user directories and are never embedded in the package or store. - Proprietary-service requirements and the resolved license/redistribution status are documented clearly. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/232). Originally posted by [htayj](https://github.com/htayj) on 2026-08-17T06:56:26Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#232
No description provided.