[Guix packaging] block/buzz desktop application #726

Open
opened 2026-09-13 06:05:17 +00:00 by htayj · 5 comments
htayj commented 2026-09-13 06:05:17 +00:00 (Migrated from github.com)

Context

Package the end-user Buzz desktop application from Block. Upstream is https://github.com/block/buzz, licensed Apache-2.0. The current desktop release is desktop-v0.5.23 (target commit b9392d9d78744df365f9276e1ffe8c1baa5ea903). Buzz is a self-hostable workspace desktop client built with Tauri, Rust, React, and pnpm.

Acceptance criteria

  • Add a source-built Guix package for the Linux x86_64 Buzz desktop application; do not repackage an opaque upstream AppImage or Debian binary.
  • Pin source provenance and accurately account for the Rust, JavaScript, Tauri, and bundled-asset licenses.
  • Provide a launcher that preserves user configuration/state outside the immutable store.

Candidate

Use upstream tag desktop-v0.5.23 / commit b9392d9d78744df365f9276e1ffe8c1baa5ea903 as the initial source candidate. Investigate the upstream release process and lockfiles to select reproducible Guix inputs.

Scope and blockers

This is the desktop application, not the relay/server, mobile clients, or buzz-cli. A valid package may require substantial dependency packaging or a documented blocker if the current source build cannot be reproduced without nonfree, network-at-build-time, or unpackageable dependencies.

Acceptance checks

  • guix lint -L . --no-network --exclude=cve,refresh,archival buzz is clean.
  • guix build -L . buzz succeeds from source.
  • A package-specific safe smoke proof launches the built desktop binary with isolated HOME/XDG state and exercises a real safe startup path without store writes.
  • Capture and attach a runtime screenshot from that built package before closing the issue.

Imported from GitHub issue/PR. Originally posted by htayj on 2026-09-13T06:05:17Z.

## Context Package the end-user Buzz desktop application from Block. Upstream is https://github.com/block/buzz, licensed Apache-2.0. The current desktop release is `desktop-v0.5.23` (target commit `b9392d9d78744df365f9276e1ffe8c1baa5ea903`). Buzz is a self-hostable workspace desktop client built with Tauri, Rust, React, and pnpm. ## Acceptance criteria - Add a source-built Guix package for the Linux x86_64 Buzz desktop application; do not repackage an opaque upstream AppImage or Debian binary. - Pin source provenance and accurately account for the Rust, JavaScript, Tauri, and bundled-asset licenses. - Provide a launcher that preserves user configuration/state outside the immutable store. ## Candidate Use upstream tag `desktop-v0.5.23` / commit `b9392d9d78744df365f9276e1ffe8c1baa5ea903` as the initial source candidate. Investigate the upstream release process and lockfiles to select reproducible Guix inputs. ## Scope and blockers This is the desktop application, not the relay/server, mobile clients, or `buzz-cli`. A valid package may require substantial dependency packaging or a documented blocker if the current source build cannot be reproduced without nonfree, network-at-build-time, or unpackageable dependencies. ## Acceptance checks - `guix lint -L . --no-network --exclude=cve,refresh,archival buzz` is clean. - `guix build -L . buzz` succeeds from source. - A package-specific safe smoke proof launches the built desktop binary with isolated HOME/XDG state and exercises a real safe startup path without store writes. - Capture and attach a runtime screenshot from that built package before closing the issue. --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/726). Originally posted by [htayj](https://github.com/htayj) on 2026-09-13T06:05:17Z.
htayj commented 2026-09-13 06:22:31 +00:00 (Migrated from github.com)

Goocastle blocked this legacy delivery issue because its per-issue runtime contract is not safely derivable.

Workflow: guix-package-high
Contract file: .goocastle/runtime-evidence-contracts.json
Issue body digest: a0afea304ee8d41d095de52b4b083d5476eb36788a18f3d20a9098e925ed5561

Bounded audit evidence:

  • Invalid runtime evidence: no runtime evidence contract for issue #726 in ".goocastle/runtime-evidence-contracts.json"; add an entry for this issue and resume

Manual repair: review the original handoff, add only exact package/runtime/artifact values to the named contract file, commit it, then rerun goocastle audit-runtime-contracts --write and goocastle explain-readiness ISSUE before restoring ready-for-agent.


Imported from GitHub comment. Originally posted by htayj on 2026-09-13T06:22:31Z.

<!-- goocastle-runtime-contract-recovery:v1:guix-package-high:726:manual-repair:a0afea304ee8d41d095de52b4b083d5476eb36788a18f3d20a9098e925ed5561 --> Goocastle blocked this legacy delivery issue because its per-issue runtime contract is not safely derivable. Workflow: `guix-package-high` Contract file: `.goocastle/runtime-evidence-contracts.json` Issue body digest: `a0afea304ee8d41d095de52b4b083d5476eb36788a18f3d20a9098e925ed5561` Bounded audit evidence: - Invalid runtime evidence: no runtime evidence contract for issue #726 in ".goocastle/runtime-evidence-contracts.json"; add an entry for this issue and resume Manual repair: review the original handoff, add only exact package/runtime/artifact values to the named contract file, commit it, then rerun `goocastle audit-runtime-contracts --write` and `goocastle explain-readiness ISSUE` before restoring `ready-for-agent`. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/726#issuecomment-5651642000). Originally posted by [htayj](https://github.com/htayj) on 2026-09-13T06:22:31Z.
htayj commented 2026-09-13 08:14:20 +00:00 (Migrated from github.com)

Runtime-evidence recovery completed in 2c3c835: added the exact buzz --guix-smoke isolated-startup contract and screenshot path. goocastle audit-runtime-contracts --write reports #726 valid, and goocastle explain-readiness 726 reports it ready once the stale recovery label is removed. Restoring scheduler eligibility.


Imported from GitHub comment. Originally posted by htayj on 2026-09-13T08:14:20Z.

Runtime-evidence recovery completed in 2c3c835: added the exact `buzz --guix-smoke` isolated-startup contract and screenshot path. `goocastle audit-runtime-contracts --write` reports #726 valid, and `goocastle explain-readiness 726` reports it ready once the stale recovery label is removed. Restoring scheduler eligibility. --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/726#issuecomment-5652153322). Originally posted by [htayj](https://github.com/htayj) on 2026-09-13T08:14:20Z.
htayj commented 2026-09-13 08:25:12 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying.

Bounded failure evidence:
Failed command: node /opt/goocastle/bin/guix-package-proof.mjs '--package-name' buzz '--module-path' tay/packages/buzz.scm '--runtime-json' '{"executable":"buzz","invocation":{"file":"buzz","args":["--guix-smoke"]},"successMarker":"BUZZ_GUIX_SMOKE_OK"}'
Exit status: 1
Final failure lines:
[stderr] Guix package proof failed: target module is missing or not a regular file: /workspace/tay/packages/buzz.scm


Imported from GitHub comment. Originally posted by htayj on 2026-09-13T08:25:12Z.

<!-- goocastle-repair-blocked:726:safe-package-proof --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying. Bounded failure evidence: Failed command: node /opt/goocastle/bin/guix-package-proof.mjs '--package-name' buzz '--module-path' tay/packages/buzz.scm '--runtime-json' '{"executable":"buzz","invocation":{"file":"buzz","args":["--guix-smoke"]},"successMarker":"BUZZ_GUIX_SMOKE_OK"}' Exit status: 1 Final failure lines: [stderr] Guix package proof failed: target module is missing or not a regular file: /workspace/tay/packages/buzz.scm --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/726#issuecomment-5652201800). Originally posted by [htayj](https://github.com/htayj) on 2026-09-13T08:25:12Z.
Owner

Goocastle deferred this package on 2026-09-16 so the end-user package queue can continue.

The source-build implementation remains preserved in its issue worktree. It evaluates and lints, but the full build repeatedly reached Vite's render-chunks stage and was terminated by host memory pressure with swap exhausted. A deterministic low-memory Vite override is prepared for the next retry. This is a local builder-capacity blocker, not evidence that the package definition or upstream source is invalid.

No runtime screenshot or completion claim is made; the issue stays open with state:blocked and without state:ready.

Goocastle deferred this package on 2026-09-16 so the end-user package queue can continue. The source-build implementation remains preserved in its issue worktree. It evaluates and lints, but the full build repeatedly reached Vite's render-chunks stage and was terminated by host memory pressure with swap exhausted. A deterministic low-memory Vite override is prepared for the next retry. This is a local builder-capacity blocker, not evidence that the package definition or upstream source is invalid. No runtime screenshot or completion claim is made; the issue stays open with `state:blocked` and without `state:ready`.
Owner

OMP work update: source implementation and dependency work are in progress, but this delivery is NOT proved or closed. Local one-core builds were externally terminated with SIGTERM under severe memory/swap pressure; the exact killer remains unconfirmed because /var/log/earlyoom.log requires sudo (noninteractive sudo was denied). Live earlyoom configuration and full swap make userspace memory protection the leading explanation, not a compiler error. The user chose to continue lighter issues first. No memory protection, vault state, host service or installed profile changes were made. Successful prerequisite builds do not substitute for this package’s full build/reproducibility/isolated runtime/screenshot acceptance.

OMP work update: source implementation and dependency work are in progress, but this delivery is NOT proved or closed. Local one-core builds were externally terminated with SIGTERM under severe memory/swap pressure; the exact killer remains unconfirmed because /var/log/earlyoom.log requires sudo (noninteractive sudo was denied). Live earlyoom configuration and full swap make userspace memory protection the leading explanation, not a compiler error. The user chose to continue lighter issues first. No memory protection, vault state, host service or installed profile changes were made. Successful prerequisite builds do not substitute for this package’s full build/reproducibility/isolated runtime/screenshot acceptance.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#726
No description provided.