Open Science Desktop: a local-first, model-agnostic AI research workbench
Abstract
Install & first launch macOS — Apple Silicon: …_aarch64.dmg · Intel: …_x64.dmg (requires macOS 13+) Developer ID-signed and notarized. Open the DMG and drag Open Science into Applications. When you use an existing project in place, allow access to its folder if macOS asks. Windows — …_x64-setup.exe (start here) · …_x64_en-US.msi (IT-managed deployment only) SmartScreen shows "Windows protected your PC" → More info → Run anyway. Upgrading: choose "Install over it, keeping my data". Removing the old version first is only for repairing a failed upgrade. Uninstalling: leave "Also delete my sessions, run history and settings" unchecked unless you mean it — it erases %APPDATA%\com.ai4s.workbench. Pick one format and stay on it. Installing the .exe over an .msi install (or the reverse) registers the app twice; uninstall the old one from Settings → Apps first. Linux — Intel/AMD: …_amd64.deb / …x86_64.rpm · ARM64 (incl. NVIDIA DGX Spark): …_arm64.deb / …aarch64.rpm (Ubuntu 22.04+ or equivalent) sudo apt install ./…_amd64.deb (or _arm64.deb) · sudo dnf install ./…x86_64.rpm (or aarch64.rpm) Check your machine with uname -m: x86_64 → amd64/x86_64, aarch64 → arm64/aarch64. A package for the other architecture fails with a dependency error that looks unrelated. No in-app auto-update — download new versions from this Releases page. (The .app.tar.gz assets are build artifacts, not an update channel.) 0.6.0 — a workbench, not only a chat Until now every pane held a conversation. A research workbench spends most of its time somewhere else: running a build, reading a notebook, watching a port, driving the instrument software on the bench. 0.6.0 is about that time — terminals, editors and files beside the conversation; an agent that can operate the apps on your own machine; and a conversation that folds its working down to the answer. Four fixes from outside contributors landed after the first 0.6.0 tag, and the release was re-cut to include them. One is a security fix for anyone running Remote Access on a network: please upgrade. Security: a file link could be turned into a read of any file (#150) A Remote Access file link names a path that was checked to be inside the workspace when the link was issued. Between then and when it was opened, an agent run in the workspace could replace that file with a symlink pointing elsewhere — the SSH key, auth.json, the runtime config holding API keys — and redemption happened before the token check. On a gateway exposed to the LAN, anyone who saw a link could read the file behind it. Every link is now re-verified at the moment it is served: it must still be a regular file (the symlink is caught, not followed), and its real target must still sit inside the workspace or a registered project. Loopback-only gateways, the default, were not reachable from other machines. Terminals, files and editors in panes A pane can now hold a terminal (a real PTY, kept alive across splits and moves), a file tree, a Monaco editor, or a notebook, from the + menu. Projects own their Screens, and ⌘J (Ctrl+Shift+J) jumps between projects, returning to the Screen each was last on. Terminals come back as you left them. On relaunch each reopens in its last folder, and if Claude Code or Codex was running in it, it is resumed. Variables you exported by hand survive the relaunch, and terminals inherit the app's proxy settings, so a resumed agent can reach its API. Claude Code and Codex also render correctly now: a box-drawing character split across two reads used to become ��� and push the whole TUI out of alignment. A status bar along the bottom shows each agent's plan usage, read from the provider itself rather than estimated from transcripts, plus ports, resources and remote hosts. Hosts from ~/.ssh/config skip git-only aliases, show their cores, memory and GPUs on hover, and open a terminal running ssh when clicked. The agent can drive apps on this machine (early) The browser connector could never reach instrument control software, Origin/GraphPad/ImageJ or a desktop reference manager. Computer Use can: the agent reads an app's accessibility tree, acts on a numbered element from it, and uses screenshots only as confirmation (off by default). By default every use asks first, behind its own computer permission. On macOS it runs as a separate signed helper, Open Science Computer Use, so Accessibility is granted to that helper and not to the whole workbench. It is verified on macOS. The Linux (AT-SPI) and Windows (UI Automation) providers ship but are less exercised, so reports from those platforms are especially welcome. Settings → Computer Use. A conversation that reads like an answer A finished turn folds its working, narration and commands together, behind Worked for 2m 41s ›, leaving the question and the answer. Anything the app adds, such as reviewer findings, figures and tables, stays visible. Thinking moves back to the Working line and is no longer printed in the same ink as the reply. Find (⌘F / Ctrl+F) works in conversations and terminals, with match case, regex and a count. A turn rail on the right edge previews each turn and jumps to it. A Trajectory pane lays every step of a conversation out as one table. URLs and paths that exist on this machine are clickable, in answers and in terminals. The composer previews what you attached on hover, actually deletes a file it copied in when you remove it (never one that was already yours), and accepts pasted files. Appearance gains Light / Warm / Dark / System and a conversation font size. Fixes Browser control was refused on every fresh install (#151, #153). The bundled goal-plugin/package.json declared a main entry, and the runtime reads that file for every plugin in the same folder. So the browser-guard and history-guard plugins silently loaded the goal plugin in their place, with nothing in the logs. The field is now stripped, and existing installs are repaired on launch. Workspace snapshots stopped on non-English systems (#148). The snapshot code works around one git error by reading its message, and git translates that message. On a Chinese, German or any other non-English locale the match failed and snapshots stopped for good. Git now always runs in the C locale. A restored tab could show "Failed to load messages" for the whole run (#139, #140). It asked for history before the runtime was ready and cached the failure as a successful load. Reopening now refetches, and the error line has a Retry. A failed first message in a new pane vanished (#149). The error was written to a draft slot that no pane showed any more. Molecule preview on Linux (#143). WebKitGTK's DMA-BUF renderer gives no WebGL on many NVIDIA, VM and Wayland setups. The app now turns it off unless you have set it yourself, and the viewer says when WebGL is missing instead of failing inside 3Dmol. Windows follows the system proxy (#147). "Follow system" read nothing on Windows, so a Clash or v2rayN system proxy was ignored. It now reads manual and PAC settings as Chromium does. SOCKS proxies are refused with a pointer to the HTTP port, because the runtime cannot use them. Turn cost is priced from the catalog the runtime already caches. The old hand-kept table charged some cached reads at four times the real rate. The domain check no longer leaves a "0 findings" card at the end of ordinary turns. It runs when asked, or when auto-review is on. For headless and cluster users --state-dir DIR / OSD_STATE_DIR runs fully separate osd installs on one machine, for example an unattended shard next to the desktop app (#125, #137). A second osd server refusal now explains the concurrency model: one server already runs many sessions, each in its own folder. The README has a new section on it in all seven languages (#126, #136). Linux ARM64 .deb / .rpm packages, built natively, for NVIDIA DGX Spark and other aarch64 machines. Bundled runtime pinned to OpenCode 1.18.32. Removed: the browser pane An embedded web view floats above every menu and dialog in the app and cannot be clipped. That is the wrong foundation and not something positioning can fix. The agent's own browser connector is unaffected. Thank you @HaoyanZhang123 and @longzhenren wrote much of what makes this release safe to ship. @longzhenren for three precise fixes. The gateway symlink escape (#150) is a real security hole, found and closed with a regression test that performs the swap. The locale-dependent snapshots (#148) reproduced the bug on a zh_CN host and added a test that needs no git at all. #149 traced a vanished error to a slot that had already been deleted. @HaoyanZhang123 for the plugin hijack fix (#153), a cause the reporter could not have found, reproduced offline against the exact shipped files. Also for --state-dir (#137), the concurrency docs in all seven READMEs (#136), the stuck history load (#140), the Windows test fixes (#138), and the Windows verification behind several of them. And to the people whose reports became fixes: @Cloud-Sure for #151, with the full chain laid out: config correct, plugin correct, hook never run. That ruled out everything except the one place the cause actually was. @Anthonyhangprinter for #139, with an exact repro and the observation that timing mattered: the runtime takes about 6 s to start on that machine. That observation was the diagnosis. @alvarovm for #143 and the sample .xyz file. A broken molecule preview turned out to be a missing WebGL context on Linux. @suqi-z for #147. A 403 from a sign-in led to Windows finally following the system proxy. Computer Use, the terminal search and parts of the layout are ported from Orca (MIT). Thanks to its authors for giving good design away. If you hit something, please open an issue.