Skip to main content

Elsewindow

elsewindow starts one GUI application on a remote Linux host and shows its windows through Xpra. One owned OpenSSH ControlMaster carries every Xpra control channel; the command opens no forwarding or Xpra TCP listener and cleans only the server, application process group, sockets, and runtime state created by that invocation.

The application renders through the remote Wayland compositor and remote GPU. Only Xpra picture, input, clipboard, notification, and control traffic crosses SSH.

Install And Run

The Python distribution requires Linux, CPython 3.13 or 3.14, OpenSSH, false, a local graphical session, and compatible Xpra packages on both systems. Optional desktop features have separate system prerequisites: missing support produces a warning and disables only that feature for the session. Startup never installs packages. Install the latest published release with pip or pipx:

python3.14 -m pip install elsewindow
# or: pipx install elsewindow
elsewindow --prepare-xpra
elsewindow --ssh-alias agents-a -- xterm

The version prepared by this source tree is recorded only in .version.

Check packaged versions, profile digests, Linux support, and local commands without opening a connection:

elsewindow --diagnose

The published distribution resolves the exact reviewed ssh-wrapper release pinned only in requirements.in. For a source checkout, prepare the hash-locked runtime and use the repository launcher from any working directory:

make runtime-venv
./bin/elsewindow --help

This one make target prepares the isolated Elsewindow runtime and a separate system-Python venv for local Xpra. The latter keeps GTK and native Xpra modules in their system packages while installing a hash-locked matching PyOpenGL and accelerator pair. Session startup never invokes pip or changes system packages. Both environments are selected automatically beneath .venvs/<machine-user-key>/, so each machine prepares its own Python and native additions in a shared checkout. See checkout setup for migration and system-command behavior.

Use a direct authority when an OpenSSH alias is not appropriate:

elsewindow \
  --host host.example \
  --user desktop-user \
  --port 2222 \
  -- /opt/application/bin/application

See the CLI reference for every option, default, and allowed value, including encoding/network profiles, clipboard policy, logging, and persistence. Repeat --env to set remote application variables or copy explicitly named local values. Reviewed profile arguments come from the packaged YAML mirrors. The Xpra guide covers hardware, application, and lifecycle behavior; the security model explains clipboard and logging trust boundaries.

Installing The Maintained Xpra Build

tools/install_xpra_release.py is a standalone standard-library installer for Debian 13 and Ubuntu 26.04. It resolves the newest canonical package release from kogeler/xpra:develop, verifies archive and DEB contents before mutation, prints the exact installed Xpra inventory, and requires interactive confirmation before purging that inventory. It uses APT for the validated local packages and dependencies.

Elsewindow deliberately uses this maintained fork rather than treating a generic upstream Xpra build as interchangeable. Project development uncovered dozens of blocking Xpra defects: some fixes were accepted as direct upstream contributions, some were implemented by the upstream maintainer after issue reports, and some were not accepted after technical disagreements. The last category requires continued maintenance of additional fork patches. The Xpra guide explains the resulting user compatibility boundary.

Review the installer and the security contract. The streamed route below is pending until the first reviewed main push; it must not be treated as available before then:

( set -o pipefail; curl --proto '=https' --tlsv1.2 -fsSL 'https://raw.githubusercontent.com/kogeler/elsewindow/main/tools/install_xpra_release.py' | /usr/bin/python3 - )

Do not prefix the pipeline or Python process with sudo. When privilege is needed, the reviewed script reads purge confirmation from the controlling terminal and invokes /usr/bin/sudo itself only for its root-owned staging and APT transaction.

Standalone Linux Executables

After the first release, GitHub Releases provide elsewindow-linux-amd64 and elsewindow-linux-arm64. These native one-file ELF executables bundle Elsewindow, CPython, ssh-wrapper, version metadata, and the reviewed YAML profiles, and the local Xpra setup code and dependency lock. They do not bundle OpenSSH, Xpra, Podman, GPU drivers, VA-API, or distribution packages. Verify the release's SHA256SUMS.txt, make the selected file executable, run ./elsewindow-linux-amd64 --prepare-xpra, then ./elsewindow-linux-amd64 --diagnose (or the arm64 equivalents) before starting a session. Preparation uses the system Xpra Python, not the bundled interpreter, and needs neither a checkout nor GNU Make. See the setup reference for prerequisites and storage.

Documentation

The Pages workflow renders these same maintained Markdown files and validates every generated route, local link, anchor, canonical URL, sitemap, crawler file, and advertised llms.txt route without network access.

Automatic Live Validation

make live-test resolves the newest fork release, builds checksum-bound Ubuntu target and Debian client images, and runs ordinary and persistent lifecycle cases on a private rootless Podman network. The payload excludes elsewindow/ source and clean-installs the already verified wheel. The harness generates a fresh Ed25519 key, performs exactly one authentication per invocation, verifies a visible window and picture updates through the production profile assembler, preserves an unrelated session, and removes only its labelled containers and network. All wheel, test, and key material enters through validated tar streams; the test uses no host bind, data volume, or copy channel.

Persistent cases exercise real systemd user services, linger consent, resumption after client/SSH loss, stable application identity and cleanup on application exit. The same matrix checks all four local/remote log sources in the local journal and terminal, and only remote sources in the server journal, at the selected log level. Enable this opt-in mode with --persistent; see the CLI reference.

Released under the MIT License.

Release files for elsewindow 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for elsewindow 0.2.1
File Size Uploaded
elsewindow-0.2.1.tar.gz 68.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for elsewindow 0.2.1
File Interpreter ABI Platform
elsewindow-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 142.2 kB

Release files / elsewindow-0.2.1.tar.gz

Download URL elsewindow-0.2.1.tar.gz
Size 68.7 kB
Tags Source
SHA-256 checksum
How to use checksums
431918d64eec5443381e9d0b458eefafcef5d41e6e488d346cee749ba21d2dc9
BLAKE2b-256 checksum
How to use checksums
187f34c09f139e5c5427b27cd60f815a7418c735b3e5dd628b6dec6adc789094
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / elsewindow-0.2.1-py3-none-any.whl

Download URL elsewindow-0.2.1-py3-none-any.whl
Size 73.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c2a5c0184c1546b7061cb5afa8670962612fddd5518d4c202c1d80aff3c8d403
BLAKE2b-256 checksum
How to use checksums
99277872f2e752c10e56c50432113e13fb94bbd22b0be3ad127dddd0bee4927c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page