Authorize Guix daemon in package implementation and audit Gooflow phases #637

Closed
opened 2026-08-28 16:54:39 +00:00 by htayj · 1 comment
htayj commented 2026-08-28 16:54:39 +00:00 (Migrated from github.com)

Context

The enforced guix-package-quality-gates Gooflow grants guixDaemon only to inventory, safe proof, and runtime screenshot phases. Package implementation and edge-case audit are instructed to run Guix build/lint diagnostics but currently receive no daemon socket, producing false host-limit failures. Goocastle #381 has verified the phase-local capability plumbing; this issue deploys the capability declaration in this channel.

Acceptance criteria

  • The package implementation and edge-case audit phases explicitly request guixDaemon while unrelated phases remain unprivileged.
  • The Gooflow remains valid and its generated runner is synchronized.
  • A focused check demonstrates the selected package workflow materializes daemon access for implementation, audit, proof, and screenshot phases only.
  • The change is committed, signed, pushed, and remotely verified by Goocastle.
  • A previously blocked package proof can be resumed only after this workflow semantic change is present.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-28T16:54:39Z.

## Context The enforced `guix-package-quality-gates` Gooflow grants `guixDaemon` only to inventory, safe proof, and runtime screenshot phases. Package implementation and edge-case audit are instructed to run Guix build/lint diagnostics but currently receive no daemon socket, producing false host-limit failures. Goocastle #381 has verified the phase-local capability plumbing; this issue deploys the capability declaration in this channel. ## Acceptance criteria - The package implementation and edge-case audit phases explicitly request `guixDaemon` while unrelated phases remain unprivileged. - The Gooflow remains valid and its generated runner is synchronized. - A focused check demonstrates the selected package workflow materializes daemon access for implementation, audit, proof, and screenshot phases only. - The change is committed, signed, pushed, and remotely verified by Goocastle. - A previously blocked package proof can be resumed only after this workflow semantic change is present. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/637). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T16:54:39Z.
htayj commented 2026-08-28 17:00:39 +00:00 (Migrated from github.com)

Completed by operator takeover because the enforced package workflow could not modify its own Gooflow and failed its package-only proof before a package module existed.

Evidence:

  • Commit 7d87807da1d3e6612b53e952a6a87b564c028b9c is GPG-signed, pushed, and Guix-authenticated.
  • Both package workflows now declare guixDaemon: true for implementation, audit, proof, and screenshot phases; research remains unprivileged.
  • Passed JSON parse, Goocastle workflow discovery, git diff --check, and guix shell -m .goocastle/manifest.scm -- make check-source-count.

Follow-up Goocastle routing defect: htayj/goocastle#382.


Imported from GitHub comment. Originally posted by htayj on 2026-08-28T17:00:39Z.

Completed by operator takeover because the enforced package workflow could not modify its own Gooflow and failed its package-only proof before a package module existed. Evidence: - Commit `7d87807da1d3e6612b53e952a6a87b564c028b9c` is GPG-signed, pushed, and Guix-authenticated. - Both package workflows now declare `guixDaemon: true` for implementation, audit, proof, and screenshot phases; research remains unprivileged. - Passed JSON parse, Goocastle workflow discovery, `git diff --check`, and `guix shell -m .goocastle/manifest.scm -- make check-source-count`. Follow-up Goocastle routing defect: htayj/goocastle#382. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/637#issuecomment-5455368911). Originally posted by [htayj](https://github.com/htayj) on 2026-08-28T17:00:39Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#637
No description provided.