[Guix packaging] Enable Claude Cowork virtualization #234
Labels
No labels
accessibility
bug
category:ai-tool
category:browser
category:command-line-tool
category:compiler-toolchain
category:desktop-application
category:developer-tool
category:editor-extension
category:emulator
category:font
category:game
category:input-accessibility
category:library-framework
category:mud-client
category:multimedia
category:networking-client
category:programming-language
category:roguelike
category:storage-media-tool
category:system-tool
category:terminal-application
complexity:high
complexity:low
complexity:medium
difficulty:blocked
difficulty:easy
difficulty:hard
difficulty:moderate
documentation
duplicate
enhancement
good first issue
gooflow:guix-package-high
gooflow:guix-package-moderate
gooflow:guix-package-quality-gates
gooflow:guix-research-disposition
gooflow:guix-runtime-evidence-refresh
help wanted
invalid
kind:disposition
kind:packaging
needs:license-investigation
priority:quick
question
ready-for-agent
state:available-elsewhere
state:blocked
state:deferred
state:out-of-scope
state:ready
state:research
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/guix-channel#234
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Enable and test Claude Cowork in the Guix
claude-desktoppackage added by #233.Anthropic documents Cowork on Linux as a beta feature that runs tasks inside an isolated local virtual machine. The core desktop package intentionally leaves this virtualization path unconfigured.
Requirements to investigate
/dev/kvmwithout making unsafe system-wide permission changes;qemu-system-x86_64orqemu-system-aarch64);OVMFon x86_64 and AArch64 firmware on arm64);virtiofsdand its communication with the bundled Electron application;smol-binworkspace image and architecture parity;Upstream currently specifies hardware virtualization, KVM permission, QEMU, firmware,
virtiofsd, about 25 GB of free disk space, and at least 8 GB of RAM. The workspace uses approximately 4 GB of RAM while running.Packaging approach
Prefer explicit Guix inputs and wrapper configuration over relying on host-distribution paths. Do not add users to groups, alter
/dev/kvmpermissions, enable firmware virtualization, or allocate large mutable images during package installation. Document the required Guix System/user configuration separately.Determine whether the bundled
virtiofsdshould be patched and used or replaced with Guix's implementation. Verify all helper paths rather than extracting and running Debian maintainer scripts.Acceptance checks
guix lint -L . claude-desktoppasses without new errors.guix build -L . claude-desktopsucceeds without build-time network access.Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-17T07:58:57Z.
Goocastle recorded disposition: blocked.
Claude Cowork virtualization is technically viable but lacks a safe deterministic runtime-proof contract required for an unattended Guix package delivery. The local channel already delivers the core proprietary claude-desktop 1.30096.1 in guix/tay/packages/claude-desktop.scm and explicitly leaves Cowork unconfigured; issue #233 is closed and #234 remains open, so this is a distinct enhancement rather than a duplicate. Official Linux documentation (support.claude.com article 10065433) requires KVM, architecture-specific QEMU plus firmware, virtiofsd, about 25 GB free disk, and at least 8 GB RAM, with 4 GB used while a workspace runs. The fixed upstream origins are the official AMD64 artifact claude-desktop_1.30096.1_amd64.deb (SHA256 09e41a20a5b47ea0e5bc226d4fffa77af43ad450c7cbf5e66e56d6e4fd4ad2e9) and ARM64 artifact claude-desktop_2.2553.1_arm64.deb (SHA256 0003a6f9605a210f03c38670d62cd59c71153c2702aa4427e4cabe2e2e5f3390) from downloads.claude.ai. Inspecting only the Debian data layers found architecture-matched resources/cowork-linux-helper and resources/smol-bin.x64.img or smol-bin.arm64.img, plus resources/virtiofsd accompanied by Apache-2.0 and BSD-3-Clause license files; each helper is statically linked and each bundled virtiofsd needs only libc/libgcc/libcap-ng/libseccomp. The Debian copyright identifies Claude Desktop itself as proprietary, consistent with the existing non-substitutable package. ASAR and ELF inspection confirms Electron invokes the helper with -socket and then startVM with bundlePath and optional memoryGB/cpuCount; the helper supports start, status, connect, and shutdown protocol methods and has actionable messages for missing image, missing firmware/virtiofsd paths, and missing EFI vars. However, there is no upstream-documented CLI or noninteractive smoke mode, and the protocol requires an origin-validated Electron session to supply a Cowork bundle. A meaningful workspace start also needs /dev/kvm and VM-capable hardware, 8 GB RAM, about 25 GB disk, and a large mutable image, which cannot be a bounded deterministic package proof in this research phase. The Guix daemon is intentionally unavailable, so no daemon-backed build or runtime proof is claimed. Delivery is blocked until Anthropic documents or supplies a safe noninteractive Cowork startup/diagnostic mode with a fixed test bundle, or until the implementation contract explicitly permits a deterministic bounded helper test that validates the same bundled helper/image/QEMU/firmware/virtiofsd execution path without booting the full workspace VM. The test must emit a fixed stdout marker and satisfy the host runtime-proof contract; merely recording the current helper socket startup/shutdown is insufficient because it does not exercise workspace virtualization.