Files
openclaw/apps/linux
Peter Steinberger b363d5a293 feat(linux): canvas UI via CLI-node + Tauri app IPC bridge (#107633)
* feat(linux): canvas via CLI-node + Tauri app IPC bridge

* refactor: extract gateway helper modules

* build(linux-canvas): register plugin package in lockfile

* fix(linux-canvas): move canvas advertise test out of core, regen docs/protocol/deadcode

* fix(gateway): break node-catalog/registry import cycle via leaf normalize module; add canvas glossary term

* style: oxfmt invoke.ts and runtime.ts after buildNodeEventParams extraction

* fix(linux): load Canvas WebView via dedicated data_directory context

Wry's Linux/WebKitGTK incognito mode discards Tauri's registered
WebContext (wry webkitgtk/mod.rs), so the Canvas window got a fresh
ephemeral context without the openclaw-canvas:// scheme handler — the
bundled A2UI page never committed (stayed about:blank) and every A2UI
command timed out. Use an isolated cache-backed data_directory instead,
which keeps the protocol handler while still isolating Canvas storage
from the dashboard window.

* fix(linux): keep Canvas WebView ephemeral via incognito + data_directory

Autoreview flagged that a dedicated data_directory alone persists Canvas
browser state (cookies, localStorage, IndexedDB, service workers) across
restarts, so an agent that navigates Canvas to a site could leak an
authenticated session into a later session. iOS uses a non-persistent
store; Linux should match.

Add .incognito(true) alongside .data_directory(): the distinct directory
gives Tauri a fresh WebContext key so it still attaches the
openclaw-canvas:// protocol closure, and incognito makes Wry swap in a
fresh *ephemeral* context carrying those protocols. Live-verified on a
Wayland/WebKitGTK box: the bundled page still loads
(location.href=openclaw-canvas://localhost/index.html, openclawA2UI
present, A2UI renders) and the canvas-webview dir holds no persistent
cookie/storage files.
2026-07-14 16:05:14 -07:00
..

OpenClaw for Linux

The Linux companion is a Tauri v2 desktop shell for a local OpenClaw Gateway. It installs the CLI when needed, delegates Gateway service management to openclaw gateway, opens the Gateway-served Control UI with its resolved auth URL, and stays available in the system tray.

Linux prerequisites

Debian and Ubuntu development packages:

sudo apt update
sudo apt install libwebkit2gtk-4.1-dev build-essential curl wget file \
  libxdo-dev libssl-dev libayatana-appindicator3-dev librsvg2-dev

Install a current stable Rust toolchain with rustup.

Develop and build

The frontend is static HTML, CSS, and JavaScript. It has no package install or build step.

cd apps/linux/src-tauri
cargo run
cargo build

The app uses OPENCLAW_DESKTOP_CLI when set. Otherwise it checks ~/.openclaw/bin/openclaw, then openclaw on PATH.

Canvas bridge

The running app gives the headless openclaw node run host a single Canvas WebView. The bundled linux-canvas plugin advertises canvas.* only while the app socket exists. The app listens at $XDG_RUNTIME_DIR/openclaw-canvas.sock (or /tmp/openclaw-canvas-$UID.sock) with mode 0600; a headless Linux node without the app does not advertise Canvas.

The plugin-generated A2UI renderer in extensions/canvas/src/host/a2ui/ remains the source of truth. The app embeds its committed, synced OpenClawKit mirror from apps/shared/OpenClawKit/Sources/OpenClawKit/Resources/CanvasA2UI/. Run node scripts/sync-native-a2ui.mjs --check from the repository root after changing those assets.

Installer resource

tauri.conf.json bundles the repository's canonical scripts/install-cli.sh directly as install-cli.sh. The app never keeps a forked copy. Stable, beta, and dev installs select latest, beta, and a managed Git main checkout respectively, always under ~/.openclaw.

Icons

The icon sources of truth live next to the PNGs: icons/icon.svg (transparent claw mark, used by the tray) and icons/icon-tile.svg (claw mark on the dark brand tile, used for the app and package icons). Regenerate the committed PNGs with librsvg:

cd apps/linux/src-tauri/icons
rsvg-convert -w 32 --keep-aspect-ratio icon.svg -o 32x32.png
magick 32x32.png -background none -gravity center -extent 32x32 PNG32:32x32.png
rsvg-convert -w 128 -h 128 icon-tile.svg -o 128x128.png
rsvg-convert -w 256 -h 256 icon-tile.svg -o 128x128@2x.png
rsvg-convert -w 512 -h 512 icon-tile.svg -o icon.png

Packaging

Build a .deb and AppImage locally (the same command CI runs):

cd apps/linux/src-tauri
pnpm dlx @tauri-apps/cli@2.11.4 build --bundles deb,appimage

Bundles land in target/release/bundle/{deb,appimage}/. The Linux App CI workflow uploads them as the openclaw-linux-companion artifact on pull requests touching apps/linux/** and on manual dispatch.

Releases

The Linux App Release workflow (manual dispatch, release operators) builds the bundles from an existing stable release tag (prerelease tags are rejected: their semver suffix breaks Debian upgrade ordering) and attaches them to that tag's GitHub release with a SHA256SUMS.linux-app.txt checksum file. It refuses tags whose commit is not reachable from main: Linux bundles ship for main-based releases only.