[Guix packaging] Enable Claude Cowork virtualization #234

Open
opened 2026-08-17 07:58:57 +00:00 by htayj · 1 comment
htayj commented 2026-08-17 07:58:57 +00:00 (Migrated from github.com)

Goal

Enable and test Claude Cowork in the Guix claude-desktop package added by #233.

Anthropic documents Cowork on Linux as a beta feature that runs tasks inside an isolated local virtual machine. The core desktop package intentionally leaves this virtualization path unconfigured.

Requirements to investigate

  • KVM availability and user access to /dev/kvm without making unsafe system-wide permission changes;
  • architecture-specific QEMU runtime (qemu-system-x86_64 or qemu-system-aarch64);
  • UEFI firmware (OVMF on x86_64 and AArch64 firmware on arm64);
  • virtiofsd and its communication with the bundled Electron application;
  • the bundled smol-bin workspace image and architecture parity;
  • dynamic dependencies and invocation paths of the bundled Cowork helpers;
  • mutable workspace/image storage outside the Guix store;
  • folder sharing, network-egress controls, and isolation boundaries;
  • graceful diagnostics when virtualization, firmware, memory, or disk space is unavailable.

Upstream currently specifies hardware virtualization, KVM permission, QEMU, firmware, virtiofsd, about 25 GB of free disk space, and at least 8 GB of RAM. The workspace uses approximately 4 GB of RAM while running.

Packaging approach

Prefer explicit Guix inputs and wrapper configuration over relying on host-distribution paths. Do not add users to groups, alter /dev/kvm permissions, enable firmware virtualization, or allocate large mutable images during package installation. Document the required Guix System/user configuration separately.

Determine whether the bundled virtiofsd should be patched and used or replaced with Guix's implementation. Verify all helper paths rather than extracting and running Debian maintainer scripts.

Acceptance checks

  • guix lint -L . claude-desktop passes without new errors.
  • guix build -L . claude-desktop succeeds without build-time network access.
  • Cowork starts a workspace VM from a clean user profile on supported x86_64 hardware.
  • The architecture-specific aarch64 package evaluates successfully and its QEMU/firmware/helper paths are validated.
  • Shared-folder reads and writes work only for explicitly connected folders.
  • Workspace state and large mutable images remain outside the immutable Guix store.
  • Missing KVM access, firmware, disk space, and other prerequisites produce actionable failures.
  • Core Claude Desktop remains usable on systems that do not enable Cowork dependencies.
  • Runtime requirements, security boundaries, resource usage, and Guix System setup are documented.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-17T07:58:57Z.

## Goal Enable and test **Claude Cowork** in the Guix `claude-desktop` package added by #233. Anthropic documents Cowork on Linux as a beta feature that runs tasks inside an isolated local virtual machine. The core desktop package intentionally leaves this virtualization path unconfigured. - Linux installation and Cowork requirements: https://support.claude.com/en/articles/10065433-install-claude-desktop - Existing Claude Desktop package: #233 ## Requirements to investigate - KVM availability and user access to `/dev/kvm` without making unsafe system-wide permission changes; - architecture-specific QEMU runtime (`qemu-system-x86_64` or `qemu-system-aarch64`); - UEFI firmware (`OVMF` on x86_64 and AArch64 firmware on arm64); - `virtiofsd` and its communication with the bundled Electron application; - the bundled `smol-bin` workspace image and architecture parity; - dynamic dependencies and invocation paths of the bundled Cowork helpers; - mutable workspace/image storage outside the Guix store; - folder sharing, network-egress controls, and isolation boundaries; - graceful diagnostics when virtualization, firmware, memory, or disk space is unavailable. Upstream currently specifies hardware virtualization, KVM permission, QEMU, firmware, `virtiofsd`, about 25 GB of free disk space, and at least 8 GB of RAM. The workspace uses approximately 4 GB of RAM while running. ## Packaging approach Prefer explicit Guix inputs and wrapper configuration over relying on host-distribution paths. Do not add users to groups, alter `/dev/kvm` permissions, enable firmware virtualization, or allocate large mutable images during package installation. Document the required Guix System/user configuration separately. Determine whether the bundled `virtiofsd` should be patched and used or replaced with Guix's implementation. Verify all helper paths rather than extracting and running Debian maintainer scripts. ## Acceptance checks - `guix lint -L . claude-desktop` passes without new errors. - `guix build -L . claude-desktop` succeeds without build-time network access. - Cowork starts a workspace VM from a clean user profile on supported x86_64 hardware. - The architecture-specific aarch64 package evaluates successfully and its QEMU/firmware/helper paths are validated. - Shared-folder reads and writes work only for explicitly connected folders. - Workspace state and large mutable images remain outside the immutable Guix store. - Missing KVM access, firmware, disk space, and other prerequisites produce actionable failures. - Core Claude Desktop remains usable on systems that do not enable Cowork dependencies. - Runtime requirements, security boundaries, resource usage, and Guix System setup are documented. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/234). Originally posted by [htayj](https://github.com/htayj) on 2026-08-17T07:58:57Z.
Owner

Goocastle recorded disposition: blocked.

Claude Cowork virtualization is technically viable but lacks a safe deterministic runtime-proof contract required for an unattended Guix package delivery. The local channel already delivers the core proprietary claude-desktop 1.30096.1 in guix/tay/packages/claude-desktop.scm and explicitly leaves Cowork unconfigured; issue #233 is closed and #234 remains open, so this is a distinct enhancement rather than a duplicate. Official Linux documentation (support.claude.com article 10065433) requires KVM, architecture-specific QEMU plus firmware, virtiofsd, about 25 GB free disk, and at least 8 GB RAM, with 4 GB used while a workspace runs. The fixed upstream origins are the official AMD64 artifact claude-desktop_1.30096.1_amd64.deb (SHA256 09e41a20a5b47ea0e5bc226d4fffa77af43ad450c7cbf5e66e56d6e4fd4ad2e9) and ARM64 artifact claude-desktop_2.2553.1_arm64.deb (SHA256 0003a6f9605a210f03c38670d62cd59c71153c2702aa4427e4cabe2e2e5f3390) from downloads.claude.ai. Inspecting only the Debian data layers found architecture-matched resources/cowork-linux-helper and resources/smol-bin.x64.img or smol-bin.arm64.img, plus resources/virtiofsd accompanied by Apache-2.0 and BSD-3-Clause license files; each helper is statically linked and each bundled virtiofsd needs only libc/libgcc/libcap-ng/libseccomp. The Debian copyright identifies Claude Desktop itself as proprietary, consistent with the existing non-substitutable package. ASAR and ELF inspection confirms Electron invokes the helper with -socket and then startVM with bundlePath and optional memoryGB/cpuCount; the helper supports start, status, connect, and shutdown protocol methods and has actionable messages for missing image, missing firmware/virtiofsd paths, and missing EFI vars. However, there is no upstream-documented CLI or noninteractive smoke mode, and the protocol requires an origin-validated Electron session to supply a Cowork bundle. A meaningful workspace start also needs /dev/kvm and VM-capable hardware, 8 GB RAM, about 25 GB disk, and a large mutable image, which cannot be a bounded deterministic package proof in this research phase. The Guix daemon is intentionally unavailable, so no daemon-backed build or runtime proof is claimed. Delivery is blocked until Anthropic documents or supplies a safe noninteractive Cowork startup/diagnostic mode with a fixed test bundle, or until the implementation contract explicitly permits a deterministic bounded helper test that validates the same bundled helper/image/QEMU/firmware/virtiofsd execution path without booting the full workspace VM. The test must emit a fixed stdout marker and satisfy the host runtime-proof contract; merely recording the current helper socket startup/shutdown is insufficient because it does not exercise workspace virtualization.

<!-- goocastle-disposition:sequential-reviewer:234:1:blocked --> Goocastle recorded disposition: blocked. Claude Cowork virtualization is technically viable but lacks a safe deterministic runtime-proof contract required for an unattended Guix package delivery. The local channel already delivers the core proprietary claude-desktop 1.30096.1 in guix/tay/packages/claude-desktop.scm and explicitly leaves Cowork unconfigured; issue #233 is closed and #234 remains open, so this is a distinct enhancement rather than a duplicate. Official Linux documentation (support.claude.com article 10065433) requires KVM, architecture-specific QEMU plus firmware, virtiofsd, about 25 GB free disk, and at least 8 GB RAM, with 4 GB used while a workspace runs. The fixed upstream origins are the official AMD64 artifact claude-desktop_1.30096.1_amd64.deb (SHA256 09e41a20a5b47ea0e5bc226d4fffa77af43ad450c7cbf5e66e56d6e4fd4ad2e9) and ARM64 artifact claude-desktop_2.2553.1_arm64.deb (SHA256 0003a6f9605a210f03c38670d62cd59c71153c2702aa4427e4cabe2e2e5f3390) from downloads.claude.ai. Inspecting only the Debian data layers found architecture-matched resources/cowork-linux-helper and resources/smol-bin.x64.img or smol-bin.arm64.img, plus resources/virtiofsd accompanied by Apache-2.0 and BSD-3-Clause license files; each helper is statically linked and each bundled virtiofsd needs only libc/libgcc/libcap-ng/libseccomp. The Debian copyright identifies Claude Desktop itself as proprietary, consistent with the existing non-substitutable package. ASAR and ELF inspection confirms Electron invokes the helper with -socket and then startVM with bundlePath and optional memoryGB/cpuCount; the helper supports start, status, connect, and shutdown protocol methods and has actionable messages for missing image, missing firmware/virtiofsd paths, and missing EFI vars. However, there is no upstream-documented CLI or noninteractive smoke mode, and the protocol requires an origin-validated Electron session to supply a Cowork bundle. A meaningful workspace start also needs /dev/kvm and VM-capable hardware, 8 GB RAM, about 25 GB disk, and a large mutable image, which cannot be a bounded deterministic package proof in this research phase. The Guix daemon is intentionally unavailable, so no daemon-backed build or runtime proof is claimed. Delivery is blocked until Anthropic documents or supplies a safe noninteractive Cowork startup/diagnostic mode with a fixed test bundle, or until the implementation contract explicitly permits a deterministic bounded helper test that validates the same bundled helper/image/QEMU/firmware/virtiofsd execution path without booting the full workspace VM. The test must emit a fixed stdout marker and satisfy the host runtime-proof contract; merely recording the current helper socket startup/shutdown is insufficient because it does not exercise workspace virtualization.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#234
No description provided.